KYC (Know Your Customer) and AML (Anti-Money Laundering) are regulatory compliance frameworks that crypto exchanges and financial institutions are required to implement in most jurisdictions. KYC is the process of verifying the identity of users before allowing them to access financial services — typically requiring government-issued ID, proof of address, and a selfie for comparison. AML refers to the broader set of policies, monitoring systems, and reporting obligations designed to prevent criminals from using financial systems to launder proceeds of crime.
KYC/AML in crypto practice: Centralised exchanges (CEXs) — virtually all regulated CEXs (Binance, Coinbase, Kraken, etc.) require full KYC for withdrawals above minimal thresholds and for fiat on/off-ramps; Tiers — most exchanges have tiered KYC levels with increasing verification requirements unlocking higher withdrawal limits; Travel Rule — regulatory requirement for exchanges to share sender/receiver information on transfers above $1,000; Blockchain analytics — tools like Chainalysis and Elliptic allow exchanges to trace transaction histories and flag wallets associated with illicit activity. For DeFi users, KYC is not currently required to use DEXs or self-custody wallets, though regulators in multiple jurisdictions are pushing to extend AML obligations to decentralised protocols. The tension between KYC/AML requirements and crypto’s privacy values is one of the defining regulatory debates in the industry.
Example: A user deposits $10,000 to Coinbase. They must complete Level 2 KYC (ID + proof of address + selfie) before withdrawing. Coinbase’s AML system flags their wallet as having received funds from a mixer, temporarily freezing the account pending manual review.
Learn more: FATF — Virtual Assets Guidance