Intermediate

Compliance 101 for Crypto Businesses

A practical guide to blacklist monitoring, transaction screening, and risk management for exchanges, DeFi protocols, and OTC desks

If you operate an exchange, DeFi protocol, OTC desk, or payment processor that handles stablecoins, you need a compliance program — or at minimum, a documented risk-assessment process. Regulatory expectations have sharpened since 2021: OFAC has designated specific blockchain addresses on its sanctions list, stablecoin issuers have collectively frozen billions of dollars in USDT and USDC, and enforcement agencies worldwide increasingly expect crypto businesses to screen transactions with the same rigor applied to traditional financial services. This guide covers practical steps for blacklist monitoring, transaction screening, and defensible risk policies, drawing on the expectations reflected in OFAC's virtual currency compliance guidance, FinCEN's 2019 virtual currency guidance, and FATF's VASP guidance.

Who needs compliance?

The short answer: any business that custodies, routes, converts, or regularly accepts stablecoins should assess its compliance obligations. The regulatory landscape varies by jurisdiction, but the underlying counterparty and sanctions risk is universal. In the US, OFAC sanctions apply to all US persons regardless of whether a crypto-specific law exists. In the EU, MiCA requires licensed crypto-asset service providers to implement transaction monitoring and risk management. Globally, the FATF's travel rule is being adopted by an increasing number of jurisdictions, extending AML obligations to virtual asset service providers.

Centralized Exchanges

Highest regulatory burden. Must comply with local AML laws, typically requiring full KYC, ongoing transaction monitoring, suspicious activity reporting (SARs), and sanctions screening. Most jurisdictions require a license or registration.

Regulatory Risk: High

DeFi Protocols

Evolving landscape. Jurisdictions increasingly expect DeFi projects to implement address screening, especially those with governance tokens, admin keys, or fiat on/off ramps. The FATF has indicated that DeFi applications may qualify as VASPs depending on their degree of centralization.

Regulatory Risk: Medium-High

OTC Desks

High-value, low-volume transactions amplify per-transaction risk. Counterparty due diligence is critical because a single large transfer involving a sanctioned entity can trigger enforcement action.

Regulatory Risk: High

Payment Processors

Processing stablecoin payments for merchants requires screening both sides of each transaction — the payer's source of funds and the recipient's risk profile.

Regulatory Risk: Medium

Even without explicit regulation, there's liability

Many jurisdictions haven't passed crypto-specific compliance laws yet, but that doesn't eliminate risk. Knowingly or negligently processing funds involving blacklisted addresses can expose your business to civil liability, loss of banking relationships, and regulatory action. A documented compliance program is your strongest defense.

Core requirements

Regardless of your business type, effective stablecoin compliance rests on four pillars:

01

Real-Time Blacklist Monitoring

Know when addresses in your system get blacklisted. Retroactive blacklisting means an address that was clean when you transacted with it can be frozen days or weeks later, turning a completed transaction into a compliance incident. Issuers like Tether and Circle maintain independent blacklists that change without advance notice, separate from government sanctions lists.

What you need:
  • API access to blacklist data across all chains you support
  • Real-time alerts when blacklist events affect addresses in your system
  • Historical lookup to screen new customer addresses against past activity
02

Transaction Screening

Screen transactions before they execute. Inbound deposits from blacklisted or high-risk addresses should be flagged immediately. Outbound withdrawals to such addresses should be blocked or routed to manual review. Post-execution screening is necessary too, but catching issues before funds move is far more effective than attempting recovery afterward.

What you need:
  • Pre-transaction screening hooks for both deposits and withdrawals
  • Configurable risk thresholds tailored to your risk appetite
  • A review queue for compliance staff to evaluate flagged transactions
03

Direct Address Evidence

A defensible screening program starts with exact-address evidence. Check whether the submitted address itself appears in official sanctions sources, direct issuer blacklist/freeze/control records, or historical direct status where supported. Direct address screening gives analysts source-cited facts, freshness metadata, and coverage state so enhanced due diligence is based on certified data.

What you need:
  • Exact-address official sanctions checks
  • Direct issuer blacklist/freeze/control facts
  • Source citations, freshness metadata, and coverage state
04

Audit Trail

Document everything. When regulators, law enforcement, or auditors review your handling of a specific transaction, you need records showing what data you checked, when you checked it, what direct findings and decision were recorded, and what action was taken. Incomplete records undermine even the best screening system.

What you need:
  • Timestamped logs of all screening decisions with data inputs
  • Direct findings and source-cited facts recorded at the time of each transaction evaluation
  • Documentation of manual review decisions including reviewer and rationale

Where Eagle Virtual fits in your compliance process

Eagle Virtual supplies the on-chain facts behind the steps above — as source-cited evidence, never a risk score. Five signal types, each available at the point in your workflow where it matters: at onboarding, before a transaction settles, in continuous monitoring, and during an investigation.

01

Government sanctions

Is the wallet on OFAC, EU, UN, or another government sanctions list? Sanctions screening is included in every check — see OFAC sanctions and crypto and sanctions coverage.

Where in the process:
  • Customer / counterparty onboarding
  • Every pre-transaction deposit and withdrawal check
  • Continuous monitoring as lists are updated
02

Stablecoin blacklist & freeze

Has Tether, Circle, or another issuer frozen or blacklisted the wallet — now or in the past? These actions are separate from government lists and can land retroactively. See how stablecoin blacklists work and the stablecoin screening tracker.

Where in the process:
  • Pre-transaction screening of deposits and withdrawals
  • Continuous monitoring — alert when a held address is later frozen
  • Onboarding lookback against historical freeze and blacklist events
03

Mixer exposure

Has the wallet sent funds to, or received funds from, a mixer or privacy protocol? Eagle Virtual surfaces those interactions as facts with the transactions cited — see mixer exposure explained.

Where in the process:
  • Enhanced due diligence on flagged counterparties
  • Investigation of inbound deposits before crediting funds
04

Cross-chain bridge activity

Did the address interact with a known bridge contract? Eagle Virtual records that bridge interaction as a fact, so your team knows where to look — it is a pointer, not fund-tracing. See cross-chain bridge interaction evidence.

Where in the process:
  • Investigation and source-of-funds tracing
  • Enhanced due diligence on cross-chain counterparties
05

ENS & known names

Who is this address? Eagle Virtual attaches human-readable context — ENS names, known exchange and service labels, and publicly reported scam/abuse names — so an analyst sees an identity, not just a hex string. Names are context shown with their source; they are never a verdict.

Where in the process:
  • Onboarding triage and counterparty identification
  • Investigation context alongside the evidence above

Every signal above is returned with its source, freshness, and coverage state, so each screening decision is documented and defensible — the audit trail in pillar 04 is built from the same evidence. Eagle Virtual reports the facts; your team applies the policy.

Transaction screening framework

Here's a practical four-stage framework for implementing transaction screening:

1

Pre-Transaction Check

Before accepting a deposit or processing a withdrawal:

  • Check if the address appears on any stablecoin issuer blacklist
  • Calculate direct status to blacklisted or sanctioned addresses
  • Cross-reference against sanctions lists (OFAC SDN, EU Consolidated, UN)
  • Review transaction history for patterns associated with mixers, high-risk bridges, or rapid fund movement
2

Direct Findings & Decision

Reach a decision from the direct, source-cited findings, the coverage state, and your own policy. The factors below are illustrative — calibrate them to your risk appetite and regulatory requirements:

Blacklist Status 40%
Direct issuer-control facts 30%
Transaction Amount 15%
Historical Behavior 15%

A directly blacklisted or sanctioned address should route to block or escalation regardless of other factors. For addresses without direct hits, your decision reflects the strength of certified facts, coverage state, and the team's policy.

3

Decision Matrix

Map your decision tiers to predefined actions. These thresholds are starting points — adjust based on your business type, jurisdiction, and risk tolerance:

Score 0-30 Auto-Approve Low risk, process normally
Score 31-60 Flag for Review Medium risk, compliance review before processing
Score 61-80 Escalate High risk, senior review with full documentation
Score 81-100 Block Critical risk, reject the transaction
4

Post-Transaction Monitoring

Screening doesn't end when a transaction completes:

  • Log all screening results and the action taken
  • Monitor for retroactive blacklisting of addresses you've transacted with
  • Update user risk profiles based on accumulated transaction patterns
  • Generate periodic compliance reports for internal review and regulatory readiness

Building risk policies

Your screening framework needs clear, written policies that your team follows consistently.

Define your risk appetite

Different businesses operate under different regulatory regimes and risk tolerances. A US-regulated exchange will adopt stricter policies than a DeFi protocol serving non-US users, but both need a documented, defensible position.

Conservative
Permissive
Escalate direct issuer-control facts US exchanges, banks
Block at direct-status review, review at 2 Most exchanges
Block only direct blacklist Some DeFi protocols

Your risk appetite should reflect your regulatory jurisdiction, the assets you handle, and the nature of your transactions. Document the rationale behind your chosen thresholds — regulators want to see that you made a deliberate, informed decision, not that you picked numbers arbitrarily.

Document exception processes

Real-world compliance isn't binary. You need clear, repeatable processes for edge cases:

False positives

What happens when a legitimate user is flagged? Document the evidence required to clear them, who has authority to approve the override, and how the decision is recorded.

Time-sensitive transactions

How do you handle urgent transactions that land in manual review? Define escalation paths, maximum review times, and fallback procedures.

Borderline cases

What about transactions that score just below your block threshold? Consider requiring additional verification or enhanced monitoring for a defined period.

Consistency matters more than strictness. Regulators care more about whether you follow your own policies consistently than about exactly where you set your thresholds. Define your policies, train your team, and apply them uniformly. When you update thresholds, document the change and the reason.

Implementation checklist

Use this checklist to track your compliance program build-out. Each category represents a necessary component of effective stablecoin compliance:

Data Sources

Screening System

Policies & Documentation

Monitoring & Reporting

Frequently asked questions

Do DeFi protocols need a compliance program?

It depends on the protocol's structure and jurisdiction. The FATF considers DeFi applications with a controlling party to be VASPs subject to AML requirements. In the EU, MiCA applies to crypto-asset service providers regardless of whether they operate through smart contracts. Even where regulation is unclear, screening addresses against stablecoin blacklists and sanctions lists reduces legal and reputational risk.

How often should screening data be updated?

Blacklist events can happen at any time without advance notice. For effective compliance, your screening data should update continuously or as close to real-time as your data provider supports. At minimum, run batch updates daily. Sanctions lists from OFAC, the EU, and the UN update on their own schedules, but additions can be immediate.

What is the minimum compliance program for a small crypto business?

At minimum: screen every inbound and outbound address against current stablecoin blacklists and the OFAC SDN list before processing. Log every screening result. Document your screening policy in writing. This baseline won't satisfy every regulatory framework, but it demonstrates good-faith effort and creates a foundation to build on as your program matures.

Key takeaways

1
Every crypto business needs compliance. Even without explicit regulation, processing funds involving blacklisted addresses creates liability.
2
Screen before transactions execute. Catching issues before funds move is far more effective than post-transaction remediation.
3
Look beyond a single list. Direct address screening combines sanctions, issuer-control facts, freshness metadata, and source-cited evidence. exposure that direct lookups miss.
4
Document everything consistently. Clear policies with complete audit trails are your best defense when regulators, auditors, or law enforcement review your operations.

Primary sources