Section 9 · Lesson 9.2
Travel Rule, KYC/CDD and KYT in Practice
Behind the acronyms of the AML world sits a clear logic. The regulator wants a business to know who its customer is (KYC/CDD), to accompany transfers with data about the sender and recipient (the Travel Rule), and to monitor the nature of transactions continuously (KYT). In this lesson we lay these concepts out plainly without the bureaucratic jargon, show the thresholds and the difference between levels of due diligence, and explain how it all looks in practice for an exchange desk and a P2P operator.
Travel Rule: "the data travels with the money"
The Travel Rule is an FATF recommendation (Recommendation 16) carried over into crypto. The essence: when one regulated organisation (a VASP — Virtual Asset Service Provider, i.e. an exchange, an exchange desk, a custodian) sends funds to another, it is obliged to transmit data along with the transfer about the sender and the recipient. A name, an account/wallet identifier, sometimes an address and a document.
The idea is simple: in traditional bank transfers the data about the payer and the payee always accompanies the payment. The Travel Rule extends the same principle to crypto transfers between services, so a transaction is not an anonymous "from nowhere to nowhere."
- ThresholdThe FATF recommends applying the rule to transfers from the equivalent of 1000 USD/EUR. Jurisdictions set their own thresholds, but 1000 is the baseline reference point. Below the threshold requirements are lighter; above it, the full set of data applies.
- Who is obligedRegulated VASPs: exchanges, licensed exchange desks, custodians. The transfer of data runs between services, not between private wallets.
- What is transmittedIdentifying data on the sender and recipient: name, account number/address, and for the sender often also a residential address or an ID document.
- The "self-hosted" problemA transfer to a private (non-VASP) wallet is a hard case: the recipient is not connected to the data-exchange system. Here the VASP collects data about the wallet's owner from its own client.
KYC vs CDD vs EDD: three levels of "know your customer"
These three acronyms are often confused. In reality they are successive levels of depth in customer due diligence — from basic identification to enhanced investigation.
- KYC (Know Your Customer) — identification. The basic level: establish and confirm the client's identity. A passport/ID, a selfie, sometimes proof of address. It answers the question "who are you?".This is the entry point to the system. Without completed KYC a client should not gain full access to operations.
- CDD (Customer Due Diligence) — due diligence. Broader than KYC: not just "who are you," but "what do you do, what is the expected nature of the operations, what is the source of funds." A client risk profile is formed.CDD includes KYC as a part and adds an understanding of the economic sense of the relationship with the client.
- EDD (Enhanced Due Diligence) — enhanced due diligence. Applied to high-risk clients: PEPs (politically exposed persons), high-risk jurisdictions, large unusual turnover. It requires more documents, management approval, and an in-depth check of the source of funds.EDD is the "red carpet in reverse": the higher the risk, the more questions and documents, up to refusing service.
Why this matters. The levels of due diligence must be
risk-based. You cannot apply the same template to everyone: for a client with $100 of turnover basic KYC is enough, while for a client with $500k of turnover and PEP markers EDD is mandatory. The regulator expects exactly this gradation: you must be able to explain why a given level of due diligence was applied to a given client.
KYC
who you are
→
CDD
risk profile
→
EDD
high risk
KYT: transaction monitoring
If KYC/CDD answer the question "who is the client," then KYT (Know Your Transaction) answers "what is their money doing." It is continuous analysis of transactions for suspicious patterns and the origin of funds. KYT is precisely the system that triggers a freeze on an exchange (Lesson 8.1).
- Origin analysisEvery incoming transfer is traced: whether the funds come from a mixer, a sanctioned address, the darknet, a hacked exchange. A risk score is assigned.
- Pattern analysisDetecting laundering structures: rapid transit, splitting (smurfing), peel chains, circular schemes.
- Thresholds and alertsOperations above certain amounts or with a high score generate an alert for the compliance officer.
- ContinuityKYT runs constantly, not just once at registration. A client may pass KYC cleanly and then start accepting dirty funds — KYT catches this.
Technically KYT is implemented through blockchain-analytics engines (Chainalysis, Elliptic, TRM Labs) or in-house solutions built on labelled address data. For a small business this may be an AML-screening API embedded into the funds-intake process.
How it looks for an exchange desk
Let's put it all together with the example of a crypto exchange desk that accepts USDT and pays out rubles.
The client's path through the exchange desk's compliance
- Registration → KYC. The client passes identification: a document, a selfie. A profile is created.For small amounts some desks operate without KYC, but this raises their own risk and is often illegal.
- Accepting funds → KYT + sanctions screening. The USDT sending address is run through an AML check: taint, sanctions, sources of risk.Sanctions exposure or a high score → refusal before crediting.
- Assessing the operation → CDD/EDD. A large amount or an unusual profile → enhanced due diligence, a request for the source of funds.The threshold at which EDD kicks in is set by the desk in its policy.
- Paying out rubles → logging. The decision and screening results are recorded in the log with a date.Under a bank's or regulator's inspection this is evidence of the desk's good faith.
How it looks for a P2P operator
A P2P trader has no corporate infrastructure, but the logic is the same in miniature. The KYC analogue is identifying the counterparty on the platform (a verified account, a rating). The KYT analogue is AML screening of the address the crypto arrives from. The CDD analogue is sensible judgement: why is the counterparty offering an off-market rate, are they in a hurry to offload problematic coins. The journal is the very trade register from Lesson 8.3.
Attention. For P2P, the temptation to "work without checks for the sake of speed" ends in a block under 115-FZ and receiving stolen goods. Minimal KYT (checking the sender's address) and register discipline are not bureaucracy, but direct protection of your money and your freedom.
We have broken down what makes up the corporate AML framework. In the section's final lesson we assemble it into a concrete document — a minimal AML policy for a crypto business: rules for accepting funds, inbound screening, a decision log, an accountable person and escalation, with a ready-made template.
This material is educational and does not constitute legal advice.