Sanctuary Compliance Team

The regulatory landscape for Virtual Asset Service Providers (VASPs) has shifted from guidance to enforcement in 2025–2026. Key developments:
• MiCA: Fully enforceable in the EU. Grandfathering expires July 1, 2026. • GENIUS Act: Signed into U.S. law July 2025. Stablecoin-specific compliance requirements. • FATF Travel Rule: Active enforcement. VASPs must transmit originator/beneficiary data for transactions above $1,000. • OFAC: Record enforcement activity. 1,245 crypto addresses on the SDN list. Settlements against non-custodial wallets. • FATF Stablecoin Report: March 2026 targeted report emphasizing secondary market monitoring.
Compliance is no longer a competitive differentiator — it is a license to operate.
□ Screen every incoming deposit and outgoing withdrawal against OFAC SDN, EU, UN, and UK HMT lists □ Update sanctions lists daily (minimum) — Sanctuary does this automatically □ Implement automated blocking for direct SDN matches (score ≥ 90 = auto-block) □ Define secondary exposure policy (1-hop, 2-hop proximity to sanctioned addresses) □ Document all matches and false positives in an auditable log □ Assign a sanctions compliance officer with decision authority □ Test your screening system annually against known sanctioned addresses
□ Monitor all customer transactions for unusual patterns □ Define risk-based thresholds for manual review (e.g., score 34–66 = review, score ≥ 67 = escalate) □ Implement velocity monitoring (transaction count, volume) with configurable alerts □ Track behavioral anomalies: dormant-then-active accounts, rapid fund movement, structuring patterns □ Monitor for address poisoning indicators (micro-transactions from lookalike addresses) □ Set up ongoing counterparty watchlists — retroactive flag alerts are essential □ Generate and retain transaction monitoring records for the legally required period (typically 5–7 years)
□ Collect originator information for transactions ≥ $1,000 (or local threshold): name, account number, address/date of birth/ID □ Collect beneficiary information: name and account number (minimum) □ Implement a Travel Rule protocol for transmitting information to counterparty VASPs □ Verify incoming Travel Rule data from counterparty VASPs □ Maintain records of Travel Rule data for the required retention period □ Handle unhosted (self-hosted) wallet transactions according to local requirements — some jurisdictions require enhanced due diligence for transfers to/from non-custodial wallets
□ Define SAR triggers aligned with your risk appetite and regulatory requirements □ File SARs with the relevant Financial Intelligence Unit (FIU) within the legally mandated timeframe □ Do not tip off the subject of a SAR — this is a legal requirement in most jurisdictions □ Train staff on red flag indicators specific to crypto: mixer interaction, sanctions proximity, rapid cross-chain movement, newly created wallets transacting large volumes □ Maintain a SAR filing log with case references, dates, and outcomes □ Review and update SAR procedures annually
□ Retain customer identification records for minimum 5 years after relationship ends □ Retain transaction records for minimum 5 years (7 years in many jurisdictions) □ Store all AML check results with timestamps and signed snapshots — Sanctuary provides this automatically □ Maintain a compliance training log showing staff completion dates □ Conduct an annual risk assessment updated for new products, geographies, and customer types □ Prepare for examinations: organize your compliance documentation, check logs, and SAR filings in advance
Sanctuary's API generates timestamped, cryptographically signed check records that serve as auditable compliance evidence. Every check is retained per your configured retention period.
Scam alerts, new sanctions, and investigation techniques. One email per week. Unsubscribe anytime.