Sanctuary Compliance Team

Every AML program starts with a risk assessment. This is not a checkbox exercise — it determines every subsequent decision. For a crypto startup, the key risk factors are:
1. Product type: Are you a custodial exchange (highest risk), a non-custodial wallet (medium risk), a DeFi protocol (evolving regulatory status), or a payment processor (high risk)?
2. Customer base: Are you serving retail users, institutional clients, or businesses? Geographic distribution matters — users from FATF grey-list countries require enhanced due diligence.
3. Transaction types: Fiat-to-crypto on-ramps carry the highest AML risk. Crypto-to-crypto services have lower fiat integration risk but higher sanctions screening requirements.
4. Volume: Higher volume = higher risk = more resources needed. A startup processing $10K/month needs a different AML stack than one processing $10M/month.
5. Jurisdictions: Where are you incorporated? Where are your customers? EU (MiCA), US (FinCEN/OFAC), UK (FCA), Singapore (MAS) each have different requirements.
Document your risk assessment. Update it annually. It is the foundation that regulators will ask to see first.
Know Your Customer (KYC) and Know Your Business (KYB) processes must match your risk assessment:
1. Customer Identification Program (CIP): At minimum, collect and verify: full name, date of birth, address, government-issued ID. For business accounts: company name, registration number, beneficial owners.
2. Risk-based tiering: Not every customer needs the same level of diligence. - Low risk (standard KYC): Retail users, verified ID, low transaction volume. - Medium risk (enhanced KYC): Higher volume users, users from elevated-risk jurisdictions. - High risk (enhanced due diligence): PEPs, high-net-worth individuals, businesses from high-risk sectors.
3. Ongoing monitoring: KYC is not a one-time event. Re-verify customers periodically (annually for low risk, quarterly for high risk). Monitor for changes in transaction patterns that might indicate escalated risk.
4. Sanctions screening on onboarding: Screen every new customer name against OFAC SDN, EU, UN, UK lists before account activation.
Transaction monitoring is where most of the ongoing AML work happens. For a crypto startup, this means:
1. Wallet screening: Every deposit address and withdrawal address should be screened for AML risk. Sanctuary API handles this with a single POST request per address.
2. Rule-based monitoring: Implement rules that flag suspicious patterns: - Structuring near reporting thresholds - Unusual increase in transaction volume or frequency - Mixer or obfuscation exposure - Sanctions exposure under your policy - Round-trip movement through intermediate wallets
3. Review routing: Define which score bands or evidence categories trigger review, escalation, block, or quarantine under your policy.
4. Alert triage: Build a process for reviewing flagged transactions. Document decisions (approve/block/escalate) with reasoning.
Regulatory reporting requirements vary by jurisdiction, but the universal requirements are:
1. Suspicious Activity Reports (SARs): File when you identify transactions or behavior that you know, suspect, or have reason to suspect involve illicit funds. Filing deadlines vary: 30 days in the US (FinCEN), 14 days in the UK (NCA), varies across EU member states.
2. Currency Transaction Reports (CTRs): Required in some jurisdictions for transactions above a threshold (e.g., $10,000 in the US). Less common in pure crypto operations but relevant for fiat on-ramps.
3. Record retention: Minimum 5 years for transaction records and KYC documents. 7 years is safer and required in some jurisdictions.
4. Audit trail: Every AML decision must be documented. Sanctuary provides timestamped, cryptographically signed check records that serve as auditable compliance evidence.
5. Annual compliance report: Prepare an internal report summarizing AML activity: number of checks, alerts, SARs filed, false positives, system changes. Present to your board or compliance committee.
Here is the practical toolkit to launch your AML program on day one:
1. Sanctuary Professional plan ($199/month): 1,000 checks/month for wallet screening. Covers early-stage operations.
2. KYC provider: Sumsub, Jumio, or Onfido for identity verification. Choose based on your geographic coverage needs.
3. Compliance officer: Designate someone as your compliance officer. For a seed-stage startup, this is often the CEO or COO. As you scale, hire a dedicated compliance lead.
4. Written AML policy: Document your risk assessment, KYC procedures, transaction monitoring rules, and reporting processes. This does not need to be 100 pages — a clear, practical 10-15 page document is sufficient.
5. Training: Train all employees who handle customer funds or customer data. Document the training. Annual refresher training is the standard.
6. Ongoing monitoring: Upgrade to Sanctuary Business ($499/month) as volume grows. Add KYT module for continuous transaction monitoring. Implement watchlists for counterparty monitoring.
Total cost for a seed-stage startup AML program: $250-$700/month (screening + KYC). This is a fraction of the cost of a single compliance incident.
Scam alerts, new sanctions, and investigation techniques. One email per week. Unsubscribe anytime.