AMLConsensus · course
Programme · Lesson 9.3
Section 9 · Lesson 9.3

A Minimal AML Policy for a Crypto Business

Knowing about sanctions, KYC and KYT is not enough — it all has to live in a single document that the team works by every day. An AML policy turns scattered knowledge into a reproducible process: any employee on any day makes decisions the same way, and under a regulator's inspection you have written proof of good faith. In this lesson we assemble a minimal but workable AML policy for a small crypto business: rules for accepting funds, inbound screening, a decision log, an accountable person and escalation — with a ready-made template you can adapt.

Why you need a written policy

Many small exchange desks and services operate "on the founder's intuition." This is dangerous for three reasons: intuition does not scale to new employees, leaves no trail for the regulator, and falls apart under pressure (a lucrative client, a rush, fatigue). A written policy solves all three.

Why this matters. An AML policy is not "a piece of paper for show" but a tool for managing risk and for defence. When a bank or regulator asks "why did you accept these funds?", the answer "we followed an approved procedure, here is the decision log" is dramatically stronger than "it seemed fine to me." A documented process moves you from the category of "suspicious participant" to that of "a bona fide business with controls."

Rules for accepting funds

The core of the policy is a clear algorithm by which every incoming operation is accepted or rejected. Formalise it as a sequence of steps.

  1. Counterparty identification. For amounts above an internal threshold — KYC (a document, verification). Below the threshold — minimal identification per the platform's rules.Set the threshold explicitly (e.g. the equivalent of 1000 USD as the Travel Rule reference) and stick to it without exceptions.
  2. AML screening of the sending address. Before crediting, run the address through a check: sanctions (OFAC/EU/UK), taint analysis, sources of risk (mixers, darknet, hacks).This is the key barrier. Sanctions exposure → unconditional refusal.
  3. Assessing the risk score and deciding. Match the result to the risk bands: low → accept, medium → additional questions/EDD, high/sanctions → refuse.See the risk bands below — they must be fixed in advance, not improvised on the spot.
  4. Requesting the source of funds at medium risk. If the score is borderline, request the SoF (source) from the client before continuing the operation.This is your CDD/EDD in action — strengthening the check in proportion to the risk.
  5. Recording the decision in the log. Every outcome (accepted/refused) is recorded with a date, the score and the basis.The log is the evidence base. Without a record, a decision "does not exist" for the regulator.
  6. Outbound screening. Before sending funds, check the recipient address — you cannot send to a sanctioned address.Liability arises both on the way in and on the way out.
Screening incoming addresses at intake

Inbound screening: the sending address is checked before crediting; the decision is made by predefined risk bands.

Risk bands for the decision

To make the decision reproducible, tie it to ranges of the risk score, not to gut feeling.

Low
accept
|
Medium
extra check / SoF
|
High / sanctions
refuse + escalate

Sanctions exposure stands outside the scale: even a small share of funds tracing back to an SDN address means an unconditional refusal, regardless of the "cleanliness" of the rest. This is the rule from Lesson 9.1 — strict liability.

The decision log: keep for 5 years

The log is the business's defence. Every operation where an AML check was applied is recorded uniformly and kept for at least 5 years (the standard retention period for AML data in most jurisdictions).

Date Client/ID Address/TXID Amount Risk score Decision Basis Accountable
24.08.26 C-0417 0x…/TXID 2,000 USDT Low (12) Accepted Clean source I.I.

This minimal set of fields answers the regulator's question of "who, when, what did they check and why did they make such a decision."

Accountable person and escalation

The policy must designate a person responsible for AML (in large companies — the MLRO, Money Laundering Reporting Officer; in a small business — a specific employee or the founder themselves). They approve contentious decisions and run escalation.

Attention. On discovering sanctioned funds you cannot "quietly return them to the sender" — the return may itself be a violation. The right step is to freeze the operation on your side, document it and act by the procedure prescribed by the law of your jurisdiction. Improvising here is the most dangerous thing of all.

Training and regular review

A policy is not a "write it and forget it" document. Sanctions lists are updated constantly, new laundering typologies appear, thresholds and regulators' requirements change. That is why two recurring processes are built into the policy. The first is a regular review of the document itself and of the list databases in use (at least once a quarter, and immediately upon major changes to sanctions regimes). The second is staff training: everyone who makes decisions about accepting funds must understand the logic of the risk bands, be able to read the result of an AML check, and know that sanctions are an unconditional stop, not something to "negotiate over."

Behaviour under pressure deserves a separate note. The most dangerous mistakes happen not from ignorance but from temptation: a big client is rushing, the rate is favourable, "just this once." That is exactly why decisions must rest on a written algorithm and the accountable person's signature, not on the operator's mood. A good policy makes "the right thing" the path of least resistance, and "going around the procedure" a conspicuous exception that stays in the log.

A ready-made template for a minimal AML policy

AML policy of [Business name] — revision of [date]

  • 1. PurposePrevent the acceptance and transfer of funds tied to laundering, sanctions and criminal activity.
  • 2. Accountable person[Name/position] is responsible for enforcing the policy, contentious decisions and escalation.
  • 3. Customer identificationKYC is mandatory for amounts from [threshold]. Data is kept for [period].
  • 4. Screening of fundsEvery incoming and outgoing address is checked against sanctions (OFAC/EU/UK) and sources of risk before the operation.
  • 5. Risk bandsLow — accept; medium — EDD/SoF request; high/sanctions — refuse and escalate.
  • 6. Decision logAll decisions are recorded with a date, the score and the basis; retention period — 5 years.
  • 7. Sanctions escalationSanctioned funds → halt the operation, document it, act under the law of the jurisdiction.
  • 8. UpdatesThe policy and the list databases are reviewed regularly; staff acknowledge them by signature.

This policy is deliberately minimal: it can be rolled out in a small exchange desk in a day, not a quarter. But it is exactly what separates a bona fide business from a "reluctant laundromat." Start with it, document decisions from day one — and you will avoid most of the freeze scenarios we examined in Section 8, now from the side of the one who prevents them.

This concludes the sections on freezes and corporate AML. You have travelled the path from understanding the mechanics of blocks to building your own process for preventing them — and that is the level of a professional in AML checking.

This material is educational and does not constitute legal advice.