Beyond the Enforcement Gap: What Crypto Exchanges Must Build Before Regulators Catch Up

Key Takeaways

  • Static KYC does not survive continuous KYT scrutiny.
  • Sanctions screening belongs inside the Travel Rule workflow, not beside it.
  • Alerts are not reports; case management is the gap regulators test first.
  • Retrofitted data protection becomes an audit finding.
  • Governance on paper is not governance under examination.
  • Over-automated compliance is a liability, not a shortcut.
  • Building ahead of enforcement is a business advantage.

 

The Gap Between Passed Laws and Active Enforcement

Passing a law and enforcing it are two different things. In its 2026 update, FATF reported that 83% of jurisdictions had passed Travel Rule legislation, but only around 40% have taken enforcement action.

That gap is temporary. Regulators are already shifting from asking “does a program exist?” to “does it actually work?” The six sections that follow cover what a compliant exchange program needs before enforcement arrives: continuous KYC/KYT monitoring, combined sanctions and Travel Rule screening, proper case management, built-in data protection, governance that holds up under scrutiny, and automation kept in its proper place.

The enforcement gap isn’t breathing room. It’s the window to build a program properly, rather than scramble under regulatory pressure. That’s why compliance management, not just compliance requirements, is the more useful frame. At its core is a risk-based framework that assesses your specific exposure and determines how strong each control needs to be.

The Foundation: A Risk-Based Compliance Framework

A risk-based approach is the foundational expectation of both FATF standards and national AML/CFT regulations. Rather than applying uniform controls to every customer and transaction, it requires an exchange to assess its specific exposure and calibrate controls accordingly.

The risk factors that should shape framework design include:

  • Products and services offered
  • Customer base, spanning retail, institutional, and high-risk segments
  • Jurisdictions where the business operates or accepts customers
  • Asset types supported, particularly those with elevated anonymity features
  • Self-hosted wallet exposure, which affects counterparty visibility

A well-designed framework does not produce a checklist. It produces a tiered control structure that allocates enhanced due diligence where risk is highest and allows proportionate controls where risk is demonstrably lower. Regulators review this framework as evidence that a business understands its own risk profile.

1. Static KYC Does Not Survive Continuous KYT Scrutiny

Know Your Customer (KYC) procedures are the entry point of a compliance program, not its entirety. At onboarding, KYC verifies identity, screens against sanctions and Politically Exposed Persons (PEP) lists, and assigns an initial risk classification. Enhanced due diligence applies where that classification warrants deeper scrutiny, such as customers from high-risk jurisdictions or those with complex ownership structures.

The limitation is that KYC is static. A customer who passes onboarding may present very different risk signals six months later based on their transaction behavior, counterparty exposure, or a change in their jurisdiction’s regulatory status. That is where Know Your Transaction (KYT) monitoring takes over.

KYC KYT
Question answered Who is the customer? What is the customer doing?
Timing Onboarding and periodic review Continuous, per transaction
Focus Identity, sanctions/PEP screening, risk tier Fund movement, counterparties, behavior patterns
Role Sets the risk baseline Tests the baseline over time

Effective KYT requires real-time or near-real-time blockchain analytics on each transaction. In practice that means:

  • Screening wallet addresses against known illicit actors
  • Assessing proximity of funds to high-risk sources such as darknet markets or sanctioned entities
  • Flagging transaction patterns that deviate from expected behavior

Cross-chain activity and DeFi protocol usage raise the bar for what KYT must see. A typical high-risk flow runs like this: funds leave an exploit wallet, pass through a cross-chain bridge, are swapped on a decentralized exchange, move to a new chain, and arrive at an exchange deposit address.

The on-chain trail is technically continuous but operationally fragmented if monitoring tools are not built to follow it. Exchanges that accept deposits without visibility into cross-chain provenance are accepting risk they cannot measure, so enhanced due diligence should account for customers whose activity includes significant cross-chain or DeFi flows, particularly where source-of-funds verification is otherwise limited.

As digital asset compliance programs mature, KYT is increasingly treated as a baseline expectation rather than an advanced capability. For more details, see how KYC protects crypto exchanges and their users.

2. Sanctions Screening Fails When Treated as a Travel Rule Side-Task

Sanctions compliance requires a broader operational scope than name-list screening alone. OFAC and equivalent authorities have shown a willingness to designate blockchain addresses directly, which makes wallet-level screening a practical necessity, not an optional enhancement.

Effective sanctions screening covers three moments:

  • Real-time wallet address screening at the point of transaction
  • Screening of originator and beneficiary information during Travel Rule data exchange
  • Periodic re-screening of existing customers as sanctions lists update

That middle point is why sanctions screening and the Travel Rule work best as one transfer-level workflow rather than two separate checks. 

The Travel Rule requires VASPs to collect, transmit, and receive originator and beneficiary information for virtual asset transfers above applicable thresholds, and that same data flow is a primary screening surface for sanctions exposure. 

As of the FATF’s 2026 targeted update, 83% of jurisdictions have passed Travel Rule legislation, with a further 11 reporting implementation underway.

In practice, the combined workflow requires:

  • Counterparty VASP identification and verification
  • Secure transmission of required data fields
  • Screening of the named parties against sanctions lists
  • Procedures for transfers with missing or incomplete counterparty information
  • Comprehensive audit records for regulatory review

The European Banking Authority’s guidelines (EBA/GL/2024/11), applicable from 30 December 2024, set out the specific steps crypto-asset service providers must take to detect missing or incomplete originator and beneficiary information, and how to manage transfers where that data is absent.

Blockchain proximity analysis adds a risk-based layer. When funds have passed through one or more hops from a designated address, that proximity is a decision input, not automatic evidence of wrongdoing.

The response, whether enhanced review, a transaction hold, or suspicious activity reporting, should be proportionate and documented. Screening that flags exposure without a structured analyst workflow produces alerts, not compliance outcomes. For more detail, see what the crypto Travel Rule requires and AML compliance requirements for crypto businesses.

3. Alerts Are Not Reports, and That Is the Gap Regulators Test First

Suspicious activity reporting is a legal obligation in most AML/CFT regimes, but its effectiveness depends on the infrastructure behind it. Generating an alert is not the same as filing a report. Between the two sits a case management process that must be documented, auditable, and consistent.

A connected operating model links these layers in sequence:

  • Transaction monitoring raises the alert
  • Case management captures the investigation and decision
  • Regulatory reporting produces the filing
  • Audit trails preserve the evidence

Where these systems are siloed, cases fall through gaps, reporting timelines are missed, and the record available during examination is incomplete. Regulators assess not only whether reports are filed, but whether the process that produced them is systematic and defensible. Good case management infrastructure captures analyst decisions, supporting documentation, escalation records, and filing outcomes in a format built for both internal governance and external review.

4. Retrofitted Data Protection Is an Audit Finding Waiting to Happen

Diagram showing exploit wallet funds moving through a cross-chain bridge, DEX swap, new chain, and exchange deposit.

Crypto compliance programs process significant volumes of personal data: identity documents, transaction records, and wallet addresses linked to identified individuals. In jurisdictions subject to GDPR and equivalent frameworks, that creates obligations which must be reconciled with AML/CFT retention rules.

The core tension is simple:

  • Data minimization requires limiting retention to what is necessary.
  • AML/CFT mandates require retaining customer and transaction data for defined periods.

Resolving it means embedding privacy-by-design from the outset, not retrofitting it after deployment. Practical steps include:

  • Defining retention schedules that satisfy AML requirements without excess
  • Implementing access controls that restrict personal data to functions with a legitimate need
  • Maintaining records of processing activities available for regulatory inspection

Data protection is not a separate workstream. It is a design constraint on the compliance program itself.

5. Governance on Paper Is Not Governance Under Examination

A program that exists in documentation but is not embedded in operations offers limited protection. Governance, training, and testing are what turn documented policy into demonstrable execution.

  • Governance: Clear accountability for compliance decisions, board-level awareness of material risks, and documented escalation paths.
  • Training: Staff across customer-facing, operations, and technical functions understand their obligations and how to apply procedures in practice.
  • Testing: Internal audit, independent review, or regulatory examination confirms controls work as designed and surfaces gaps before they become findings.

Regulators in major jurisdictions have made clear that governance and training deficiencies are treated as program-level failures, not procedural oversights. Ultimately, a program’s strength is judged by whether the people and processes behind it can demonstrate consistent, documented execution.

6. Over-Automated Compliance Is a Liability, Not a Shortcut

Automation is necessary at scale. Transaction volumes on exchanges routinely exceed what manual review can handle, and real-time monitoring depends on automated rule sets and risk scoring to function at all. Blockchain analytics, sanctions screening, and Travel Rule data routing all rely on it.

The key is treating automation as a decision-support layer, not a decision-making one.

Best handled by automation Requires analyst judgment
Flagging transactions above a threshold Alert disposition
Screening addresses against known lists Suspicious activity reporting decisions
Routing Travel Rule data to counterparty VASPs Enhanced due diligence determinations
High-volume, rule-based tasks Novel cases and ambiguous fact patterns

Regulatory guidance consistently reflects this split. A well-designed program calibrates automation to cut analyst workload on routine cases while preserving human review for the cases that need it. See how RegTech supports crypto compliance and security for a closer look at where automation fits in the broader stack.

Compliance Baked Into Infrastructure Becomes a Business Advantage

Compliance built ahead of enforcement does more than reduce regulatory risk. It determines where an exchange can operate, who will transact with it, and how fast it can move when a new market opens. Three commercial outcomes depend directly on program maturity:

  • Market entry: Jurisdictions with robust licensing frameworks, including the EU, UAE, Singapore, and Hong Kong, require demonstrated compliance capability as a baseline condition of entry. Programs that cannot be evidenced do not get licensed.
  • Banking and institutional access: Counterparties, liquidity providers, and banking partners run compliance due diligence before establishing a relationship. A business that cannot demonstrate maturity does not pass that diligence, and this often decides whether it can operate at scale.
  • Customer trust: Where user confidence is a competitive variable, visible compliance infrastructure is part of the product, not a cost center attached to it.

The direction of travel is clear. Compliance is moving from a process layered on top of operations to logic baked into the infrastructure itself. 

Screening, threshold checks, and transfer-level data requirements are increasingly enforced at the system level, and in some architectures defined automatically by smart contracts, so compliant behavior becomes the platform’s default state rather than the output of after-the-fact review. 

An exchange built this way does not scramble to evidence its controls during examination; the controls are the infrastructure. Viewed that way, crypto compliance management is a structural investment in business viability, not merely a cost of regulatory participation.

How ChainUp Supports a Connected Compliance Operating Model

Crypto compliance management is not a single control or a one-time project. It is a set of interconnected capabilities: risk assessment, customer due diligence, transaction monitoring, sanctions screening, Travel Rule workflows, case management, and governance working as one system under a single risk-based framework. 

Each component reinforces the others: KYT data informs case management, case management supports suspicious activity reporting, and governance keeps decisions across every function consistent and documented.

Building that connected model requires infrastructure spanning transaction monitoring, Travel Rule data workflows, and regulatory and licensing support. ChainUp provides compliance infrastructure and consultancy support across these functions for exchanges and other VASPs at various stages of program development:

  • KYT solution: Real-time transaction monitoring and risk-scoring built for digital asset environments, helping VASPs operationalize blockchain analytics within existing workflows.
  • Travel Rule support: Counterparty identification, data transmission, and exception handling across the transfer workflow.
  • Regulatory and licensing support: Broader guidance through ChainUp’s crypto regulation, compliance, and licensing services.

Ready to strengthen your exchange’s compliance infrastructure?

ChainUp’s KYT and Travel Rule compliance solutions are built for exchanges and VASPs that need operationally credible controls across the full transaction lifecycle. Talk to the ChainUp team today for a demo.

Frequently Asked Questions

What is crypto compliance management?

Crypto compliance management is the operational framework through which a virtual asset service provider designs, implements, and maintains controls to satisfy AML/CFT and related regulatory obligations. It encompasses risk assessment, customer due diligence, transaction monitoring, sanctions screening, Travel Rule workflows, regulatory reporting, and governance.

What is a risk-based compliance framework?

A risk-based framework is a control structure calibrated to a business’s specific exposure rather than a uniform checklist. It assesses risk across products, customer segments, jurisdictions, and asset types, then allocates enhanced due diligence where risk is highest and proportionate controls where risk is demonstrably lower.

What is the difference between KYC and KYT?

KYC (Know Your Customer) refers to identity verification and customer due diligence conducted at onboarding and at defined review intervals. KYT (Know Your Transaction) refers to continuous monitoring of transaction behavior and blockchain activity throughout the customer lifecycle. KYC establishes who a customer is; KYT monitors what they do.

Why is the Travel Rule important for crypto businesses?

The Travel Rule requires VASPs to transmit originator and beneficiary information with virtual asset transfers above defined thresholds. It is a core component of international AML/CFT standards and is now law in 83% of surveyed jurisdictions as of the FATF’s 2026 targeted update. Non-compliance exposes VASPs to regulatory action and exclusion from compliant financial networks.

Can crypto compliance be automated?

Automation is a necessary component of crypto compliance at scale, particularly for transaction monitoring, sanctions screening, and Travel Rule data routing. It works best as a decision-support layer paired with analyst review for complex or novel cases. Regulatory expectations require human judgment in alert disposition, suspicious activity reporting, and enhanced due diligence decisions.

What should a crypto exchange compliance program include?

A complete program starts with a risk-based framework and includes:

  • KYC and enhanced due diligence paired with continuous KYT monitoring, including cross-chain and DeFi visibility
  • A combined sanctions screening and Travel Rule workflow
  • Connected case management and regulatory reporting
  • Data protection controls
  • Governance, training, and periodic testing
  • Appropriate use of automation supported by analyst review

Share this article :

Speak to our experts

Tell us what you're interested in

Select the solutions you'd like to explore further.

When are you looking to implement the above solution(s)?

Do you have an investment range in mind for the solution(s)?

Remarks

Advertising Billboard:

Subscribe to The Latest Industry Insights

Explore more

Ooi Sang Kuang

Chairman, Non-Executive Director

Mr. Ooi is the former Chairman of the Board of Directors of OCBC Bank, Singapore. He served as a Special Advisor in Bank Negara Malaysia and, prior to that, was the Deputy Governor and a Member of the Board of Directors.

ChainUp: Leading Provider of Digital Asset Exchange & Custody Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.