Prompt
I’m building a crypto onboarding flow and need compliance-friendly identity checks
Latest observation
Oct 1, 2026
OpenAI APIWeb search: off
For a compliance-friendly crypto onboarding flow, you usually want a risk-based KYC/KYB + sanctions screening + fraud controls setup that is strong enough for regulators but not so heavy that it kills conversion.
1) Core identity checks to include
For individuals (KYC)
- Email + phone verification
- Legal name, DOB, address
- Government ID capture
- Passport, national ID, or driver’s license
- Document authenticity checks
- Expiration date, MRZ/barcode validation, tamper detection
- Selfie / liveness check
- Match face to document
- Sanctions and watchlist screening
- OFAC, UN, EU, UK, local lists as applicable
- PEP screening
- Politically exposed persons
- Adverse media screening
- Address verification
- Utility bill, bank statement, or database verification depending on jurisdiction
- IP/device risk scoring
- VPN/proxy detection, geolocation mismatch, device fingerprinting
- Source of funds / wealth checks
- For higher-risk users or higher transaction thresholds
For businesses (KYB)
- Business registration details
- Beneficial ownership collection
- UBO verification
- Director/representative identity checks
- Sanctions/PEP/adverse media screening on company and owners
- Business activity / industry classification
- Tax ID / registration number validation
- Proof of address / incorporation documents
2) Risk-tiered onboarding design
A good pattern is progressive verification:
- Tier 0: account creation, email/phone verification, no crypto activity
- Tier 1: low-risk users, basic ID + sanctions screening, limited limits
- Tier 2: full KYC with liveness and stronger verification, moderate limits
- Tier 3: enhanced due diligence, source-of-funds, manual review, higher limits
This keeps friction low while still being defensible.
3) Controls regulators expect
- Audit logs for every verification decision
- Clear retention policy for identity data
- Manual review queue for failed/ambiguous cases
- Case management for escalations
- Ongoing monitoring, not just one-time onboarding
- Periodic re-verification for expired IDs or changed risk
- Geographic restrictions if you don’t serve certain jurisdictions
4) Important implementation considerations
- Collect only what you need
- Minimize data for privacy and regulatory simplicity
- Separate identity verification from transaction monitoring
- Onboarding ≠ ongoing AML monitoring
- Make rules configurable by jurisdiction
- Requirements vary a lot by country/state
- Have a fallback for manual review
- Especially for OCR failures, poor image quality, edge cases
- Avoid over-reliance on one vendor
- If possible, use providers with fallback logic or multi-vendor redundancy
5) Common crypto-specific red flags
- Rapid account creation from same device/IP
- Mismatched country, phone, IP, and ID jurisdiction
- Use of VPN/proxy/Tor
- Reused documents or selfies
- High-risk jurisdictions
- Names linked to sanctions, fraud, or darknet activity
- Multiple accounts tied to same identity signals
6) A practical onboarding flow
- Account creation
- Email/phone verification
- Jurisdiction screening
- ID upload + OCR
- Selfie/liveness
- Sanctions/PEP/adverse media checks
- Risk scoring
- Approve / step-up / manual review / reject
- Ongoing transaction monitoring
7) Compliance notes
I’m not a lawyer, but in practice you should align the flow with:
- AML/KYC requirements in your operating jurisdictions
- Travel Rule obligations if you’re a VASP/CASP where applicable
- Data privacy laws like GDPR/UK GDPR, CCPA, etc.
- Recordkeeping and auditability
If you want, I can help you design:
- a risk-based onboarding decision tree,
- a field-by-field KYC/KYB requirements list, or
- a vendor-neutral compliance architecture for your app.