Back to Glossary

KYC (Know Your Customer)

KYC (Know Your Customer) Definition: KYC is the process by which financial institutions and regulated businesses verify the identity of their customers, assess their risk profile, and monitor their transactions to prevent financial crimes — primarily money laundering, terrorist financing, and fraud. Regulated by national and international standards (FATF guidelines, the EU’s Anti-Money Laundering Directives, the US Bank Secrecy Act), KYC requires collecting and verifying personal identification documents, assessing the source of funds, and monitoring for suspicious transaction patterns. In crypto, KYC requirements have expanded significantly as regulators have brought exchanges and other digital asset service providers under the same frameworks that govern traditional financial institutions.

What Is KYC?

KYC is the financial system’s identity verification and risk assessment mechanism — the process that confirms you are who you say you are and that your money comes from legitimate sources before allowing you to use financial services. It exists because financial intermediaries are the primary point where illicit funds enter the formal economy; anti-money laundering regulations require these intermediaries to identify their customers and report suspicious activity to authorities.

The KYC process typically involves three layers. Customer identification: collecting government-issued identity documents (passport, national ID, driver’s licence) and verifying them against anti-fraud databases. Customer due diligence (CDD): assessing the customer’s risk profile based on their stated source of funds, occupation, expected transaction patterns, and whether they appear on watchlists (politically exposed persons, sanctions lists). Enhanced due diligence (EDD): for high-risk customers, deeper investigation into source of wealth, beneficial ownership, and business relationships.

The Financial Action Task Force (FATF) — the intergovernmental organisation that sets global AML standards — has progressively expanded its “Travel Rule” to cover virtual asset service providers (VASPs), requiring crypto exchanges and wallet providers to collect and transmit KYC information alongside transactions above certain thresholds. This effectively imported the traditional banking KYC framework into regulated crypto infrastructure.

KYC in Crypto Markets

Major regulated crypto exchanges (Coinbase, Kraken, Binance’s regulated entities) conduct comprehensive KYC before allowing trading, deposits, or withdrawals above minimal thresholds. The standard process requires: government ID upload, selfie verification (comparing face to ID photo), proof of address (utility bill, bank statement), and in some cases source of funds documentation for large amounts.

Unregulated or offshore exchanges historically operated without KYC requirements, attracting users seeking privacy or evading regulatory oversight. Regulatory pressure has narrowed the space of genuinely no-KYC options for significant trading activity — most jurisdictions now require crypto service providers to implement AML/KYC or face enforcement action. The EU’s MiCA regulation and the US’s evolving crypto regulatory framework both mandate KYC at the service provider level.

DeFi protocols present a KYC grey area. Smart contracts have no legal personality and cannot conduct KYC — participation requires only a wallet address, with no identity attached. Regulators are actively debating how to apply KYC requirements to DeFi, with approaches ranging from KYC at the fiat on-ramp (exchange) to proposed requirements for DeFi frontend operators or large liquidity providers. The Tornado Cash sanctions by OFAC in August 2022 — blacklisting a decentralised smart contract address — represented regulators treating the protocol itself as a regulated entity, a significant escalation in DeFi oversight.

KYC vs. AML

KYC AML
Full name Know Your Customer Anti-Money Laundering
Focus Identity verification and risk assessment Detecting and preventing financial crimes
When applied At onboarding and periodic review Ongoing transaction monitoring
Data collected ID documents, address, source of funds Transaction patterns, suspicious activity reports
Relationship KYC is a component of the broader AML programme AML is the overarching regulatory framework

Why Is KYC Important for Traders?

KYC affects traders in two direct ways: access and privacy. Access: without completing KYC on a regulated platform, trading limits are restricted or unavailable. Higher withdrawal limits, fiat conversion, and participation in certain products (IEOs, futures trading) typically require verified accounts. Privacy: KYC creates a regulatory record linking your real-world identity to your trading activity — important to understand for tax compliance, as most regulated exchanges share data with tax authorities in jurisdictions with mandatory crypto tax reporting.

KYC quality is also a platform safety indicator. Exchanges that implement rigorous KYC and AML procedures are more likely to be compliant with financial regulations, reducing the risk that regulatory action shuts the platform down unexpectedly. Exchanges that advertise “no KYC” are typically operating in regulatory grey zones — which may be acceptable for some users but creates uncertainty about long-term platform availability and the regulatory status of funds held there.

For large crypto transactions, the FATF Travel Rule requires exchanges to collect and verify the identity of both the sender and receiver — similar to how wire transfers require beneficiary information. Understanding that large on-chain transactions between regulated exchanges will trigger identity verification on both ends has practical implications for traders moving significant amounts across platforms.

Key Takeaways

  • KYC requires financial institutions to verify customer identity, assess risk profile, and monitor transactions — the three-layer framework (customer identification, customer due diligence, enhanced due diligence) applies to crypto exchanges under the same FATF standards as traditional banks in an increasing number of jurisdictions.
  • OFAC’s August 2022 sanctions against Tornado Cash — blacklisting a decentralised smart contract address — established that regulators are willing to apply sanctions to DeFi protocols themselves, not just the users, representing a significant escalation in regulatory reach over decentralised infrastructure.
  • The EU’s MiCA regulation, fully in effect by 2024–2025, requires all crypto asset service providers operating in the EU to implement KYC/AML programmes equivalent to those required of traditional financial institutions — eliminating the regulatory arbitrage that previously allowed some European exchanges to operate with minimal verification.
  • Most regulated exchanges share transaction data with tax authorities under mandatory reporting frameworks — completing KYC links real-world identity to trading history in regulatory databases, which traders must account for in tax planning and compliance.
  • Exchanges that implement rigorous KYC are operationally less likely to face sudden regulatory shutdown — regulatory compliance provides a legal shield that “no-KYC” platforms lack, making the short-term privacy of unverified trading a tradeoff against long-term platform availability risk.
FAQ section

What documents are typically required for crypto exchange KYC?

Government-issued photo ID (passport or national ID card), a selfie holding the ID or a live facial verification, and proof of address (utility bill or bank statement dated within 3 months). For enhanced due diligence on large accounts: source of funds documentation and sometimes proof of wealth or employment.

Is KYC required for all crypto transactions?

No — on-chain transactions between private wallets require no identity verification (the blockchain is pseudonymous). KYC applies at the interface between crypto and regulated financial infrastructure: exchanges, brokers, and other licensed service providers. Pure DeFi interactions via personal wallets currently bypass KYC requirements, though this regulatory gap is under active review globally.

Can KYC data be used against me?

KYC data is held by regulated entities subject to data protection laws (GDPR in Europe, etc.) and can only be shared with authorities pursuant to legal process. The practical risk for most users is standard: data breaches at the exchange could expose personal information. For politically sensitive jurisdictions, KYC data creates a record of financial activity that could be accessed by authorities.

What happens if I don't complete KYC on a regulated exchange?

Accounts without KYC are typically restricted to minimal functionality — read-only access, small deposit limits, no fiat withdrawal, and no access to derivatives or advanced features. Most exchanges set a threshold (e.g., $1,000 withdrawal limit) above which KYC becomes mandatory. Attempting to circumvent KYC limits (using multiple accounts, structuring transactions) violates exchange terms and potentially anti-structuring laws.

Forced Liquidation
Forced Liquidation Definition: Forced liquidation is the aut...
Isolated Margin
Isolated Margin Definition: Isolated margin is a position ma...
Checkable Deposits
Checkable Deposits Definition: Checkable deposits are bank a...
BSC (Binance Smart Chain)
BSC Definition: Binance Smart Chain (BSC), now officially re...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.