Digital Assets

Crypto Compliance Advisory

AML/KYC program design, VASP readiness and regulatory engagement.

01 Overview

Compliance in digital assets is judged by a different standard than in traditional finance, because the risk is different: pseudonymous counterparties, cross-border flows, unhosted wallets and a transaction graph that a conventional monitoring system was never designed to read.

We build programmes that actually work against that risk — risk assessment, KYC and onboarding, transaction monitoring and travel-rule handling, sanctions screening, and the governance that makes them operate rather than exist as policy documents.

The output has a dual purpose. It satisfies the regulator, and it is the single most persuasive document in a bank, exchange or institutional onboarding review. For most digital-asset businesses, compliance is the commercial unlock.

02 When this is the right engagement
  • You are applying for a VASP licence and need a compliant AML/CFT programme.
  • A bank, exchange or custodian has asked for your compliance documentation and found gaps.
  • You need to handle the travel rule or counterparty due diligence between VASPs.
  • Your existing programme was written for a different kind of business and does not fit.
03 How we approach it

Risk-based, not template-based

A programme copied from a bank’s policy manual does not fit a digital-asset business. We build from your actual risk profile — products, counterparties and corridors.

Monitoring the transaction graph

Chain analytics, exposure scoring and unhosted-wallet handling require tooling and thresholds that a conventional rules engine does not provide.

Compliance as the commercial unlock

The same file that satisfies a regulator is what gets you banked, listed and accepted by institutional counterparties. We build it to serve both readers.

04 What we deliver
  • Business-wide risk assessment tailored to the digital-asset model
  • AML/CFT policy, procedures and controls documentation
  • KYC, KYB and customer-risk-scoring framework
  • Transaction monitoring, chain analytics and unhosted-wallet policy
  • Sanctions screening and travel-rule handling design
  • Governance, training and independent-review framework
05 How the engagement runs
  1. 01

    Assess the risk

    Products, counterparties, corridors and channels, assessed as a whole — the analysis everything else is built on.

  2. 02

    Design the controls

    Onboarding, monitoring, screening and escalation designed against that risk profile rather than a generic checklist.

  3. 03

    Instrument correctly

    Chain analytics, screening and case-management tooling selected for the asset classes and chains you actually touch.

  4. 04

    Install the governance

    Roles, escalation, record-keeping and training so the programme operates in practice, not only on paper.

  5. 05

    Prepare for scrutiny

    Documentation packaged for a licence application, a bank review or an audit, and periodic independent review thereafter.

06 How engagements are shaped
2–3 weeks

Compliance gap review

A written assessment of the programme you have against the one your business and regulators require.

Project

Programme build

Full AML/CFT, KYC, monitoring and governance programme designed and implemented.

Scoped

Bank or licence readiness

Packaging the compliance file specifically for a banking onboarding or a licensing submission.

07 Where we are not the right fit
  • Businesses seeking documentation that appears compliant without the controls being operated — that fails on first inspection.
  • Anyone looking to obscure the nature of transactions from a bank or regulator.
10 Common questions

If you are a VASP transmitting virtual assets to another VASP in a jurisdiction that has implemented it, yes. The mechanics — whether you must collect and transmit originator and beneficiary data, and through what protocol — depend on the jurisdiction and the counterparty, and we design for the strictest market you serve.

Through address-level risk scoring, exposure analysis and documented thresholds for when a counterparty requires enhanced due diligence or is declined. Blanket refusal of unhosted wallets is neither required nor commercially sensible; a risk-based policy is.

It is necessary and not sufficient. Licensing also turns on capital, governance, fit-and-proper officers and the business plan. But compliance is the part most often deficient in first applications, and fixing it is usually the difference between a stalled file and a granted one.

Yes, and if you already have tooling we work with it — the important question is whether its coverage matches the chains and asset classes you handle. Where there is a gap, we identify it rather than assuming any provider covers everything.

Contact Blockrunner, LLC

Let’s scope it properly

A short diagnostic is the fastest way to know whether crypto compliance advisory is the right engagement — and what a realistic path looks like.

Schedule a consultation adam@adamtracy.io+1 (310) 299-49928335 W. Sunset Blvd., West Hollywood, CA 90069