Skip to main content
Category: Virtual Assets and Technology

Cryptocurrency

Also known as: crypto, digital currency
Simply put

Cryptocurrency is a type of digital asset that typically uses distributed ledger or blockchain technology to enable secure transactions. It is generally designed to operate on decentralized networks without relying on central authorities such as governments or traditional banks, and it may be used for internet-based payments or as a store of value. The way any given cryptocurrency is treated and regulated can vary significantly by jurisdiction.

Formal definition

A cryptocurrency is a category of digital asset that generally records and validates transactions on a distributed ledger (commonly a blockchain), typically without reliance on a central issuing authority or intermediary. Cryptocurrencies are often designed to operate on decentralized networks and may function as a medium of exchange for electronic payments, a store of value, or both. Note that this describes the general technical and market character of cryptocurrency and is not a legal definition; the classification, scope, and regulatory treatment of specific cryptocurrencies differ across regimes and should be confirmed against the applicable regulatory framework.

Why it matters

Cryptocurrency matters to financial crime professionals because its core design characteristics, operation on decentralized networks, and the absence in many cases of a central issuing authority or intermediary, create both opportunities and challenges for AML and counter-terrorist-financing efforts. The same features that enable internet-based payments and cross-border value transfer without traditional banks can also complicate the identification of the parties to a transaction, the tracing of funds, and the attribution of activity to a real-world individual. As a result, cryptocurrency has become a significant focus area for regulators, obliged entities, and investigators.

Because cryptocurrencies can function as a medium of exchange, a store of value, or both, they interact with a range of financial crime typologies, including the placement, layering, and integration of illicit proceeds. However, the presence of cryptocurrency activity is not itself evidence of wrongdoing, the vast majority of use may be legitimate, and professionals should treat crypto-related indicators as risk factors to be assessed rather than as proof of criminality.

A critical point for compliance officers is that there is no single global definition or regulatory treatment of cryptocurrency. The classification, scope, and obligations attaching to any given cryptocurrency differ across jurisdictions, and the general technical and market description of cryptocurrency should not be mistaken for a legal definition. Whether a particular asset or activity falls within a regulatory perimeter must be confirmed against the applicable framework in each relevant jurisdiction.

Who it's relevant to

Compliance Officers
Compliance officers need to understand cryptocurrency's decentralized character and the absence, in many cases, of a central authority or intermediary, because these features affect how customer due diligence, transaction monitoring, and risk assessment are designed. They should be alert to the fact that the regulatory treatment of specific cryptocurrencies differs by jurisdiction and must be confirmed against the applicable framework rather than assumed to be uniform.
Financial Intelligence Analysts and Investigators
Analysts and investigators encounter cryptocurrency when tracing the movement of value across distributed ledgers. Because cryptocurrencies typically operate without a central intermediary, attributing activity to a real-world party can be more complex than in traditional banking, and analysts should treat crypto-related indicators as risk factors to be assessed rather than as evidence of criminality in themselves.
Legal and Risk Professionals
Legal and risk professionals must recognize that the general technical and market description of cryptocurrency is not a legal definition. The classification and scope of any given cryptocurrency, and the obligations that may attach to activity involving it, vary across regimes and should be confirmed against the relevant regulatory framework in each applicable jurisdiction.

Inside Cryptocurrency

Convertible virtual currency (CVC)
A digital representation of value that can be exchanged for fiat currency or other assets. In the US, FinCEN treats CVC as subject to the Bank Secrecy Act, and administrators or exchangers of CVC may qualify as money services businesses (MSBs). Terminology and legal characterization vary by jurisdiction, so the applicable classification should be confirmed against local rules.
Virtual asset (VA) and virtual asset service provider (VASP)
Terms used in the FATF Recommendations to describe digital assets and the intermediaries (such as exchanges, custodians, and certain transfer services) that may be brought within AML/CFT obligations. FATF Recommendations are standards rather than binding law, and how each jurisdiction transposes the VA/VASP definitions differs.
Distributed ledger and pseudonymity
Many cryptocurrencies operate on public blockchains where transactions are recorded on a distributed ledger. Addresses are generally pseudonymous rather than anonymous, meaning transactions are visible but not inherently linked to verified identities without additional information.
Travel Rule application to virtual assets
The FATF standard extending originator and beneficiary information-sharing requirements to VASPs for qualifying transfers. Implementation, thresholds, and effective enforcement vary significantly across jurisdictions and should be verified against the applicable regime.
On-ramps, off-ramps, and fiat gateways
Points at which value moves between fiat currency and crypto, typically at exchanges or other obliged entities. These points are often where customer due diligence and monitoring obligations are most directly applied.
Higher-risk features and services
Elements such as privacy-enhancing coins, mixers or tumblers, decentralized platforms, and non-custodial wallets that may present elevated AML/CFT risk. Their presence is a risk indicator to assess, not proof of illicit activity.

Common questions

Answers to the questions practitioners most commonly ask about Cryptocurrency.

Is cryptocurrency anonymous and therefore untraceable by investigators?
This is a common misconception. Most widely used cryptocurrencies operate on public, distributed ledgers that record transactions transparently, making them more accurately described as pseudonymous rather than anonymous. Addresses are not directly tied to identities on-chain, but blockchain analytics and off-chain data (such as information collected by regulated exchanges) can often support attribution. Certain privacy-enhancing coins and techniques may complicate tracing, but this should not be treated as a blanket rule across all crypto-assets.
Does cryptocurrency fall outside AML regulation because it is decentralized?
Not generally. While the underlying networks may be decentralized, many intermediaries that provide crypto-asset services, commonly referred to in various regimes as virtual asset service providers (VASPs) or crypto-asset service providers, are typically brought within the scope of AML obligations. The FATF Recommendations set out standards for VASPs, and jurisdictions including the EU, US, and UK have implemented obligations for such entities, though the precise scope, definitions, and thresholds vary by regime and should be confirmed against the applicable rules.
How does the 'travel rule' apply to cryptocurrency transfers?
The travel rule, derived from FATF standards, generally requires obliged entities transmitting value to obtain, hold, and pass on specified originator and beneficiary information. As applied to crypto-asset transfers, many jurisdictions extend comparable requirements to VASPs, though implementation details, applicable thresholds, and the treatment of transfers involving unhosted or self-hosted wallets differ across regimes. Firms should confirm the exact scope and data fields against the specific regulation applicable to them.
What CDD measures are typically applied to customers using crypto-assets?
Obliged entities generally apply customer due diligence on a risk-sensitive basis, which may include identifying and verifying the customer, understanding the nature and purpose of the relationship, and ongoing monitoring. For crypto-asset activity this often extends to blockchain analytics to assess wallet exposure and transaction risk. Enhanced due diligence may be applied where higher-risk factors are present. The specific measures depend on the applicable regime and the entity's risk assessment, and none of these controls should be treated as a guarantee against financial crime.
What are commonly cited risk indicators when monitoring cryptocurrency activity?
Indicators cited in guidance may include exposure to high-risk counterparties, use of mixing or tumbling services, rapid movement of funds across multiple wallets, links to darknet marketplaces, and inconsistency with a customer's expected profile. These are illustrative typologies, not an exhaustive list, and the presence of one or more indicators does not by itself establish wrongdoing. They are intended to inform risk assessment and, where appropriate, further investigation.
When might crypto-related activity give rise to a suspicious activity or transaction report?
Where an obliged entity forms knowledge or suspicion (or, in some regimes, has reasonable grounds to suspect) that funds or activity involve the proceeds of crime or terrorist financing, it may be required to file a report, referred to as a SAR or STR depending on the jurisdiction. The reporting trigger, thresholds, and the receiving financial intelligence unit differ by regime. Filing such a report reflects suspicion for compliance purposes and does not itself establish that a criminal offense has occurred.

Common misconceptions

Cryptocurrency transactions are anonymous and therefore untraceable.
Transactions on many public blockchains are pseudonymous rather than anonymous. They are typically recorded on a distributed ledger and may be analyzed, though linking activity to a verified identity generally requires additional information, such as data held at a fiat on-ramp or off-ramp.
Cryptocurrency operates entirely outside AML regulation.
In many jurisdictions, intermediaries handling virtual assets may fall within AML/CFT obligations, for example as VASPs under the FATF standards or as MSBs administering or exchanging convertible virtual currency under FinCEN rules. Scope, definitions, and enforcement differ by jurisdiction and should be confirmed against the applicable regime.
Detecting a mixer, privacy coin, or high-risk crypto feature confirms money laundering.
These features are risk indicators to be assessed within a risk-based approach, not evidence of a criminal offense. A red flag or alert supports further review and, where appropriate, a suspicious activity report, but does not establish wrongdoing.

Best practices

Confirm the regulatory classification of each crypto-related product or counterparty against the applicable jurisdiction, distinguishing FATF VA/VASP terminology from local transpositions and from US CVC/MSB concepts under the BSA.
Apply a risk-based approach that assesses higher-risk features, such as privacy coins, mixers, and non-custodial wallets, as indicators to investigate rather than as conclusive findings.
Concentrate customer due diligence and transaction monitoring at fiat on-ramps and off-ramps, where identity verification and value-transfer visibility are typically strongest.
Implement Travel Rule controls consistent with the obligations in force in each relevant jurisdiction, verifying applicable thresholds and required originator and beneficiary information against local rules.
Use blockchain analytics to support tracing of pseudonymous activity, while recognizing that attribution to a verified identity generally depends on additional off-chain information.
Document the basis for escalations and any suspicious activity reporting, ensuring internal records reflect that alerts and matches inform review and do not by themselves establish criminal conduct.