Compliance
Oct 9, 2026

AML Risk Assessment for Crypto Businesses: A Practical Guide

How to run an AML risk assessment for a crypto business: risk factors, a scoring matrix, the five pillars of a BSA/AML program and what the EU AMLR expects.

AML Risk Assessment for Crypto Businesses: A Practical Guide

An AML risk assessment is a documented analysis of how a business could be used for money laundering, terrorist financing or sanctions evasion, how likely and serious each risk is, and how well its controls reduce it. For a crypto exchange or other virtual asset business, it is the foundation of the whole AML compliance program: it decides where to apply enhanced due diligence, what transaction monitoring rules to run and where to spend compliance budget.

This guide covers the enterprise-wide (or business-wide) risk assessment for crypto firms: the risk factors to cover, a sample scoring matrix, the US "five pillars" of a BSA/AML program, and what the EU's Anti-Money Laundering Regulation expects. It ends with a short note for users on why risk ratings affect their accounts.

Two levels of risk assessment

A risk-based approach works at two levels, and it helps to keep them apart:

  • Business-wide (enterprise-wide) risk assessment. Looks at the firm as a whole: its customer base, products, countries and channels. It sets policy, such as which customers need enhanced checks and which products need extra controls.
  • Customer risk assessment. Rates each individual customer, using the framework the business-wide assessment created. It decides how much due diligence that customer gets. Our guide to CDD vs EDD covers this level.

If the business-wide assessment is weak, every downstream control is set at the wrong level, which is why supervisors usually ask for it first.

What the EU AMLR expects

The EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (AMLR), applies from 10 July 2027. Crypto-asset service providers (CASPs) are included in its definition of financial institutions and are therefore obliged entities. Article 10 sets out the business-wide risk assessment. Firms must identify and assess their money laundering and terrorist financing risks, and the risk of not implementing or evading targeted financial sanctions, taking into account at least:

  • the risk variables in Annex I and the lower- and higher-risk factors in Annexes II and III;
  • the EU-level risk assessment by the European Commission and national risk assessments by Member States;
  • relevant publications by international standard setters, the Commission or the new Anti-Money Laundering Authority (AMLA);
  • information on risks provided by competent authorities; and
  • information on the firm's own customer base.

Article 10 also requires a fresh assessment before launching new products, services, delivery channels or technologies, or entering a new customer segment or country. The assessment must be documented, kept up to date and regularly reviewed, drawn up by the compliance officer, approved by the management body and made available to supervisors on request. Article 10(4) required AMLA to issue guidelines on its minimum content by 10 July 2026.

For crypto firms, recital 30 adds that the assessment should consider transactions with self-hosted addresses, and Article 79 bars CASPs from keeping anonymous crypto-asset accounts or accounts that allow the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins. Licensing under MiCA is a separate regime; see our guide to the CASP licence under MiCA.

What US rules expect: the five pillars

In the US, businesses that exchange or transmit convertible virtual currency are generally money services businesses (MSBs), as FinCEN set out in its 2019 guidance FIN-2019-G001. Our sibling guide on the money transmitter licence covers registration. MSBs must run an AML program under 31 CFR 1022.210, which must be written and "commensurate with the risks" of the business, and must include at minimum:

  1. Policies, procedures and internal controls covering customer identification, reports, record-keeping and law enforcement requests;
  2. A designated compliance officer responsible for day-to-day compliance;
  3. Training for appropriate staff, including on detecting suspicious transactions; and
  4. Independent review, scaled to risk, by someone other than the compliance officer.

These are the classic "four pillars". Banks and other covered financial institutions have a fifth: risk-based customer due diligence, which under 31 CFR 1020.210 means understanding the nature and purpose of customer relationships to build a customer risk profile, and ongoing monitoring. Crypto firms with bank charters or bank partners will often be held to all five.

Today's rules do not explicitly require a written risk assessment. The FFIEC BSA/AML examination manual says that while it is "not a specific legal requirement", a well-developed risk assessment helps a bank identify its risks and design controls, and it describes a two-step method: identify risk categories (products, services, customers, geography), then analyse the data in each. That may change. On 10 April 2026 FinCEN proposed a rule to reform AML/CFT program requirements, under which internal policies, procedures and controls would include risk assessment processes. Comments closed on 9 June 2026, and the rule was still at the proposal stage when we checked the Federal Register on 9 October 2026.

Risk factors to cover in a crypto business

Both regimes organise risk the same way. The AMLR's Annex I groups risk variables into customer, product/service/transaction and delivery channel risk, and Annex III adds higher-risk geography. For a crypto firm, that translates into:

  • Customers: retail vs institutional, corporate clients with complex ownership, politically exposed persons, high-net-worth users, customers in high-risk occupations, and the share of customers with past alerts.
  • Products and services: spot trading, OTC desk, fiat on- and off-ramps, custody, staking, crypto cards, token listings, and any product that favours anonymity.
  • Transactions: volumes, ticket sizes, speed of movement in and out, transfers to and from self-hosted wallets, exposure to mixers, bridges and high-risk services found through blockchain analytics.
  • Geography: where customers live, where they connect from, and exposure to countries on the FATF monitoring lists or subject to sanctions. See our OFAC sanctions list guide.
  • Delivery channels: fully remote onboarding, introducers and affiliates, API and white-label partners, and other exchanges you deal with.

A sample risk scoring matrix

There is no required format. The FFIEC manual says examiners have "no expectation for a particular method or format". A common approach scores inherent risk, assesses control effectiveness and derives residual risk. The table below is an illustrative example, not a regulatory template; your own weights should come from your data.

Risk areaInherent risk (1-5)Key controlsControl strengthResidual risk
Customers: share of high-risk and corporate clients4Risk-based onboarding, KYB, PEP and adverse media screening, EDDStrongMedium
Products: OTC desk and fiat ramps4Source of funds checks, trade limits, senior approval for large tradesAdequateMedium-high
Transactions: self-hosted wallet transfers3Wallet screening, address ownership checks, Travel Rule processAdequateMedium
Geography: users near high-risk jurisdictions3Geo-blocking, IP and document checks, sanctions screeningStrongLow-medium
Channels: affiliates and API partners2Partner due diligence, contractual controls, auditsWeakMedium

Inherent risk is often scored as likelihood multiplied by impact, using measurable indicators such as volumes, customer counts and alert rates. Control strength should be backed by evidence, such as testing results and audit findings, not by the existence of a policy. Where residual risk is above the firm's risk appetite, the assessment should end in a dated action plan with owners.

Running the assessment step by step

  1. Collect data: customer and transaction data, on-chain exposure reports, alert and suspicious activity statistics, audit findings, and relevant national and EU risk assessments.
  2. Identify risks in each category above, including new products in the pipeline.
  3. Score inherent risk with a written, repeatable method.
  4. Assess controls: onboarding, screening, transaction monitoring, Travel Rule and reporting.
  5. Derive residual risk and compare it with risk appetite.
  6. Act: tune monitoring rules, change onboarding thresholds, add EDD triggers, exit products or markets if needed.
  7. Approve and review: management sign-off, then review at least yearly and whenever something material changes, such as a new product, a new country or a major typology.

Monitoring tools should reflect the result. Many vendors let firms tune rules and risk scores to their own assessment. iDenfy's transaction monitoring software, for example, lets compliance teams write custom rules that produce configurable risk scores. Our comparison of crypto transaction monitoring software covers other options, and the crypto AML compliance guide covers the wider program.

Common mistakes

  • Copy-paste assessments that describe generic crypto risks rather than the firm's own data.
  • No link to controls: the assessment rates a product high risk, but monitoring rules never change.
  • Policies scored as controls without testing.
  • Stale documents that predate new products, chains or markets.
  • Ignoring sanctions evasion, which the AMLR now names explicitly alongside money laundering and terrorist financing.

For users: why risk ratings affect your account

Your exchange's risk assessment decides which customers get extra checks. If you use a higher-risk product, move funds from a flagged wallet, or live in or connect from a higher-risk country, you may be asked for more documents even if you have done nothing wrong. Our guide to AML red flags in crypto lists the patterns that tend to trigger reviews. JewelSwap's DeFi apps are non-custodial and do not run these checks themselves; see KYC in DeFi explained.

Frequently asked questions

What is an AML risk assessment?

An AML risk assessment is a documented analysis of how a business could be used for money laundering, terrorist financing or sanctions evasion, how likely and serious each risk is, and how well existing controls reduce it. It drives decisions on due diligence, monitoring and resources.

What is the difference between a business-wide and a customer risk assessment?

A business-wide assessment looks at the whole firm: customers, products, transactions, countries and channels. A customer risk assessment rates each individual customer using that framework and decides how much due diligence they receive.

What are the five pillars of an AML compliance program?

In the US, they are internal policies, procedures and controls; a designated compliance officer; ongoing staff training; independent testing; and risk-based customer due diligence. MSBs, which include most US crypto exchanges, are required to have the first four under 31 CFR 1022.210.

Is a written AML risk assessment mandatory?

In the EU, yes: Article 10 of the AMLR, which applies from 10 July 2027, requires a documented business-wide risk assessment approved by the management body. In the US, current rules do not explicitly require one, but examiners expect it, and a FinCEN proposal from April 2026 would make risk assessment processes part of program requirements.

How often should an AML risk assessment be updated?

The EU AMLR requires it to be kept up to date and regularly reviewed, and reassessed before launching new products, channels, technologies or markets. Many firms review it at least once a year and after any material change.

What risk factors matter most for crypto firms?

Customer type, products such as OTC and fiat ramps, transactions with self-hosted wallets and exposure to mixers or other high-risk services, geography including sanctioned and high-risk countries, and remote or partner-led delivery channels.

Keep reading

This article is educational and is not legal advice. Legal references are to Regulation (EU) 2024/1624 (the AMLR, applicable from 10 July 2027), 31 CFR 1022.210 and 1020.210, FinCEN guidance FIN-2019-G001, the FFIEC BSA/AML examination manual and FinCEN's proposed rule published on 10 April 2026, all checked on 9 October 2026. The scoring matrix is an illustrative example, not a regulatory template. Rules change; check the current versions before relying on them.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.