Compliance in digital assets is judged by a different standard than in traditional finance, because the risk is different: pseudonymous counterparties, cross-border flows, unhosted wallets and a transaction graph that a conventional monitoring system was never designed to read.
We build programmes that actually work against that risk — risk assessment, KYC and onboarding, transaction monitoring and travel-rule handling, sanctions screening, and the governance that makes them operate rather than exist as policy documents.
The output has a dual purpose. It satisfies the regulator, and it is the single most persuasive document in a bank, exchange or institutional onboarding review. For most digital-asset businesses, compliance is the commercial unlock.
- You are applying for a VASP licence and need a compliant AML/CFT programme.
- A bank, exchange or custodian has asked for your compliance documentation and found gaps.
- You need to handle the travel rule or counterparty due diligence between VASPs.
- Your existing programme was written for a different kind of business and does not fit.
Risk-based, not template-based
A programme copied from a bank’s policy manual does not fit a digital-asset business. We build from your actual risk profile — products, counterparties and corridors.
Monitoring the transaction graph
Chain analytics, exposure scoring and unhosted-wallet handling require tooling and thresholds that a conventional rules engine does not provide.
Compliance as the commercial unlock
The same file that satisfies a regulator is what gets you banked, listed and accepted by institutional counterparties. We build it to serve both readers.
- Business-wide risk assessment tailored to the digital-asset model
- AML/CFT policy, procedures and controls documentation
- KYC, KYB and customer-risk-scoring framework
- Transaction monitoring, chain analytics and unhosted-wallet policy
- Sanctions screening and travel-rule handling design
- Governance, training and independent-review framework
- 01
Assess the risk
Products, counterparties, corridors and channels, assessed as a whole — the analysis everything else is built on.
- 02
Design the controls
Onboarding, monitoring, screening and escalation designed against that risk profile rather than a generic checklist.
- 03
Instrument correctly
Chain analytics, screening and case-management tooling selected for the asset classes and chains you actually touch.
- 04
Install the governance
Roles, escalation, record-keeping and training so the programme operates in practice, not only on paper.
- 05
Prepare for scrutiny
Documentation packaged for a licence application, a bank review or an audit, and periodic independent review thereafter.
Compliance gap review
A written assessment of the programme you have against the one your business and regulators require.
Programme build
Full AML/CFT, KYC, monitoring and governance programme designed and implemented.
Bank or licence readiness
Packaging the compliance file specifically for a banking onboarding or a licensing submission.
- Businesses seeking documentation that appears compliant without the controls being operated — that fails on first inspection.
- Anyone looking to obscure the nature of transactions from a bank or regulator.
If you are a VASP transmitting virtual assets to another VASP in a jurisdiction that has implemented it, yes. The mechanics — whether you must collect and transmit originator and beneficiary data, and through what protocol — depend on the jurisdiction and the counterparty, and we design for the strictest market you serve.
Through address-level risk scoring, exposure analysis and documented thresholds for when a counterparty requires enhanced due diligence or is declined. Blanket refusal of unhosted wallets is neither required nor commercially sensible; a risk-based policy is.
It is necessary and not sufficient. Licensing also turns on capital, governance, fit-and-proper officers and the business plan. But compliance is the part most often deficient in first applications, and fixing it is usually the difference between a stalled file and a granted one.
Yes, and if you already have tooling we work with it — the important question is whether its coverage matches the chains and asset classes you handle. Where there is a gap, we identify it rather than assuming any provider covers everything.