Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.
Crypto off-ramps ask for source of funds to confirm that the stablecoins you convert came from a lawful activity that matches your business. It's part of enhanced due diligence under AML rules, triggered by risk: high volumes, unusual transactions, high-risk countries, or funds with a crypto-only history. Good evidence links a document, like an invoice, to the on-chain transfer that paid it.
It isn't personal. The off-ramp is the point where a blockchain balance becomes a bank deposit (how off-ramps work), and someone has to vouch for it.
FATF, the global standard-setter for anti-money-laundering rules, draws the line in its guidance on politically exposed persons (paragraphs 86 to 88). "Wealth" and "funds" are two different concepts. Source of funds is the origin of the particular funds in the business relationship. Source of wealth is the origin of the customer's entire body of wealth.
| Source of funds | Source of wealth | |
|---|---|---|
| Question it answers | Where did this money come from? | How did this business or person accumulate its assets? |
| Scope | One transaction, or the money moving through the account | Total assets over time |
| Typical evidence | Invoices, contracts, bank or exchange statements, on-chain history | Financial statements, tax returns, records of a company sale or investments |
| When off-ramps ask | Higher-risk customers, large or unusual transactions, limit increases | Enhanced due diligence, complex ownership, high-risk profiles |
FATF also makes a point that matters for crypto: knowing which institution the money came from isn't enough. You have to know the activity behind it.
Because their regulators and their banks require it, and stablecoins make the question both easier and harder to answer.
The rules are risk-based almost everywhere:
The crypto-specific part: every stablecoin has a public history. Blockchain analytics can show whether a deposit passed through a mixer, a sanctioned address, or a hacked exchange before it reached you. That's why an off-ramp can ask about money you received from a legitimate client. The client's wallet history comes along with the payment. Most of that screening is automated now, which is what compliance agents do, but the questions it raises still go to a person.
Regulation by country is in the stablecoin regulation tracker.
At predictable moments. Here are the usual triggers, in the order most businesses meet them:
BlindPay's source of funds guide lists the same triggers for businesses.
Two families: documents for money that came through banks, and documents for money that lives on-chain. These are the categories BlindPay accepts, and most regulated off-ramps ask for the same.
| Funds came from | Documents that prove it |
|---|---|
| Operating revenue | Invoices, customer contracts, settlement statements, receipts |
| A bank account | Bank statements or account summaries from a regulated institution |
| Investors or founders | Subscription agreements, capital injection or founder contribution records |
| Borrowing | Executed loan agreements or credit facilities |
| Selling assets | Records of a sale of business assets, securities, or property |
| A crypto wallet | Proof the business or its principals control the wallet |
| On-chain activity | Transaction history with transaction hashes and wallet addresses |
| A crypto exchange | Statements from a regulated exchange showing deposits, withdrawals, or trades |
| Minting or redeeming | Stablecoin issuance or redemption records |
| Trading or market making | Trade history, P&L summaries, liquidity provision records |
| A token sale | Allocation summaries, private placement records, use-of-funds explanations |
Tell the story of the money, then attach the receipts. A worked example:
A Mexican software company invoices a US client for 25,000 USDC. The client pays from its own wallet on Base. Three months later, the company's off-ramp asks about the deposit.
The common failure is a gap in step 5. Stablecoins that hop through three wallets with no explanation look like layering, even when they're just a messy treasury.
Usually the paperwork, not the money. BlindPay's document standards are typical: documents issued in the name of the business, showing the source and flow of funds, legible and complete with no material redactions, in PDF, JPG, or PNG.
Red flags that trigger follow-up questions or rejection:
The money stops until you do.
At BlindPay, a request for information moves the customer to compliance_request. While it's open the customer can't send or receive funds, and BlindPay emails your team on days 0, 7, and 17. With no submission by day 27, the customer is rejected automatically. For a single held transaction, the on-hold process is faster: if the request goes unanswered for 24 hours, the transaction may be refunded to the sender.
Responsibility is shared, and it's worth writing down before the first request arrives.
| Task | Usually the provider | Usually you | Evidence to ask the provider for |
|---|---|---|---|
| Verify your customers (KYC, KYB) | Runs the checks and decides | Collects data and documents from your customer | Required fields per tier, review times |
| Source of funds | Reviews and decides | Collects documents from your customer and uploads them | Accepted documents and standards |
| Sanctions and wallet screening | Runs on every customer and transfer | Nothing, beyond accurate data | What gets screened and when |
| Transaction monitoring | Flags and holds | Answers requests for information | Response deadlines |
| Records | Keeps its own | Keeps contracts and invoices behind each payment | Retention periods |
At BlindPay, requests go to your team, not straight to your customer, because collecting and uploading the documents is the platform's job. If you sit between BlindPay and your own users, build the upload path into your product before you need it.
Compliance runs inside the payment flow. BlindPay verifies customers, screens transactions, and reviews source of funds and source of wealth when an account or transaction needs enhanced due diligence. Requests arrive by email and in the dashboard, and you answer them in one submission. Read the source of funds guide for the full document list before you onboard a high-volume customer.
This article is educational content, not legal advice. Requirements vary by jurisdiction and provider; confirm your obligations with counsel.
Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.
A side-by-side comparison of automated and manual KYC/KYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.
How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.