Prompt
I'm building a crypto onboarding flow and need sanctions screening plus KYC
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
For a crypto onboarding flow, you usually want to treat this as KYC + sanctions/PEP screening + ongoing monitoring, with the exact depth depending on your business model and jurisdictions.
What you likely need
1) Identity verification (KYC)
Core checks typically include:
- Legal name
- Date of birth
- Residential address
- Government-issued ID verification
- Selfie/liveness check
- Phone/email verification
2) Sanctions screening
Screen customers against:
- OFAC
- UN
- EU
- UK HMT
- Other relevant local sanctions lists
Also usually screen:
- Watchlists
- PEPs
- Adverse media
- Potentially known crypto-risk indicators, depending on risk appetite
3) Ongoing monitoring
Not just at onboarding:
- Re-screen when lists update
- Monitor for changes in risk profile
- Periodic refresh of KYC data
- Transaction monitoring, if required by your program
Common implementation pattern
Basic flow
- User signs up
- Collect identity data
- Collect document + selfie
- Run sanctions/PEP screening
- If pass, allow onboarding
- If hit/manual review, queue for compliance review
- Set up ongoing re-screening
Risk-based flow
- Low risk: automated approve
- Medium risk: extra checks or manual review
- High risk: enhanced due diligence or deny
Vendor options
Many teams use a provider that bundles these functions. Common categories:
- Identity/KYC: Persona, Onfido, Veriff, Sumsub, Sardine
- Sanctions/AML screening: ComplyAdvantage, Refinitiv, Dow Jones, LexisNexis Risk, Sanctions.io
- Crypto compliance / chain monitoring: Chainalysis, TRM Labs, Elliptic
Some vendors cover multiple parts so you can reduce integration complexity.
Important design considerations
False positives
Sanctions screening often creates name matches that are not actual matches. You’ll need:
- Matching thresholds
- DOB/country disambiguation
- Manual review workflow
- Audit trail for decisions
Jurisdiction
Requirements vary a lot by:
- Where your company is licensed
- Where your users are located
- Whether you custody funds
- Whether you offer fiat on/off ramp
- Whether you support retail or institutional users
Data privacy
You’ll need to think about:
- Data minimization
- Retention periods
- Encryption
- Access controls
- Consent/notice
- Cross-border data transfer rules
Practical recommendation
If you’re just starting:
- Pick one onboarding vendor for ID verification
- Add a dedicated sanctions/PEP screening API
- Build a manual review queue
- Add ongoing re-screening
- If you touch crypto transactions, add wallet/transaction screening later
Example rule set
A simple policy might be:
- Block if confirmed sanctions match
- Manual review if potential sanctions hit
- Block if user is in prohibited jurisdiction
- Enhanced due diligence if PEP or adverse media hit
- Re-screen every 24 hours or on list updates
If you want, I can help you with any of these next:
- a vendor shortlist
- a technical architecture
- a sample compliance workflow
- a database schema / API design
- a jurisdiction-specific checklist