A crypto AML audit checklist helps reviewers assess whether a business's anti-money laundering controls address its risks and work in practice. It should connect policies to evidence: customer files, transaction data, system settings, investigation records and management decisions.
For exchanges, custodians, crypto payment businesses and other virtual asset service providers (VASPs), that means looking beyond written procedures. A monitoring policy may appear complete while a newly supported blockchain remains outside the alert system.
This guide covers ten areas to review, the evidence to prepare and how to turn testing results into clear findings. Adapt it to the firm's products, customers, jurisdictions and applicable obligations. It is an educational planning aid, not legal advice or a universal compliance standard.
How to use this checklist
Start with the business model and follow each material risk through the controls intended to manage it. Your review should connect:
-
the business-wide risk assessment;
-
customer and product risk;
-
policies and control objectives;
-
system configuration and data coverage;
-
individual customer, alert and transfer outcomes;
-
regulatory reporting; and
-
management oversight and remediation.
The broader crypto compliance audit guide explains the complete audit lifecycle. Use the checklist below to plan detailed AML fieldwork.
For each applicable question, record the requirement, control owner, test performed, evidence reference and result. Use consistent outcomes such as effective, partially effective, ineffective or not tested. Explain any item marked not applicable. A checked box should indicate a supported conclusion, not simply that a policy exists.
Before testing: confirm scope, criteria and independence
Record the legal entities, period, products, customer types, jurisdictions, chains, tokens, systems and vendors included. Confirm which requirements apply and label each criterion accurately as law, regulation, guidance, internal policy or good practice.
For UK cryptoasset businesses, the FCA's AML/CTF regime page explains the registration and supervision context. Regulation 21 of the Money Laundering Regulations addresses an independent audit function where appropriate to the size and nature of the business. In the United States, 31 CFR 1022.210 requires covered MSBs to provide for risk-commensurate independent review of the AML program.
The reviewer should have sufficient authority, information access and competence. Document conflicts and safeguards. A reviewer should not provide independent assurance over controls they operate or own. Assess potential self-review conflicts, including involvement in control design, and document how they are addressed.
Crypto AML audit checklist
1. Governance and accountability
- Is there a named senior owner for AML/CTF and a clear reporting line?
- Do committee terms, attendance and minutes show effective oversight and challenge?
- Are material breaches, backlogs, control failures and overdue actions escalated promptly?
- Does management information explain risk and control effectiveness rather than only activity volumes?
- Are responsibilities clear across operations, compliance, risk, technology and internal audit?
- Are conflicts, delegated authorities and cover arrangements documented?
Test evidence: governance documents, committee packs, decisions, escalation records, role profiles and interviews.
2. Business-wide risk assessment
- Does the assessment cover actual products, services, customer groups, delivery channels and jurisdictions?
- Does it consider supported assets, blockchains, stablecoins, privacy-enhancing features, bridges, DeFi exposure and self-hosted wallets where relevant?
- Are money laundering, terrorist financing, proliferation financing and sanctions risks distinguished appropriately?
- Are inherent risk, control effectiveness and residual risk supported by evidence?
- Are methodology, scoring and risk appetite approved and understood?
- Are material changes and emerging typologies reflected promptly?
Reconcile the assessment to the product catalog, customer population, transaction data and chain inventory. A polished document is weak evidence if it omits a live service.
FATF's 2026 virtual asset update highlights continuing risk from fraud, stablecoins, unhosted wallets, offshore VASPs and DeFi. These themes can inform risk identification, but the firm should assess its actual exposure.
3. Policies, procedures and control inventory
- Are documents current, approved, version-controlled and accessible?
- Do procedures explain who performs each step, when, in which system and with what evidence?
- Do policies agree with system settings and operational practice?
- Are exceptions, escalation routes and approval thresholds clear?
- Does the control inventory identify owners, frequency, evidence and dependencies?
- Is regulatory change translated into controlled implementation?
During walkthroughs, ask staff to use the procedure while demonstrating a real case. Differences between the document and the process may reveal informal workarounds.
4. Customer due diligence and risk rating

Customer due diligence (CDD) establishes who the customer is and helps the firm understand the relationship. Enhanced due diligence (EDD) involves additional measures where required for higher-risk situations.
- Are identity and verification requirements defined for relevant customer types?
- Are beneficial owners and control structures identified where required?
- Does the customer risk model use relevant factors and supported data?
- Are high-risk relationships subject to appropriate EDD and approval?
- Are purpose, intended activity and source-of-funds or wealth information collected where necessary?
- Are politically exposed person (PEP), sanctions and adverse-information results resolved and documented?
- Are periodic and event-driven review triggers defined and followed?
- Can staff evidence why a customer was accepted, restricted or exited?
Select customers across risk levels, entity types, jurisdictions and onboarding routes. Include manual overrides, high-risk approvals and event-driven reviews. Reperform risk ratings and trace data fields to evidence.
The FCA's April 2026 CDD findings give useful test prompts: clear differences between CDD and EDD, documented high-risk measures, defined review cycles and evidence that firms follow their own procedures.
5. Sanctions and proliferation-financing controls
- Does the sanctions risk assessment cover customers, beneficial owners, counterparties, wallets, transactions, products and jurisdictions?
- Are relevant lists updated completely and promptly?
- Are names and wallet addresses screened at appropriate points in the relationship and transaction lifecycle?
- Are matching thresholds, transliteration, aliases and data-quality controls tested?
- Are indirect ownership and control considered where required?
- Are alerts investigated, escalated and resolved by trained staff?
- Are freezing, rejection, licensing and reporting decisions controlled and evidenced?
- Are evasion typologies and exposure through nested services or cross-chain activity considered?
Do not treat a zero-match dashboard as proof of effectiveness. Test the feed, configuration, sample inputs, investigation process and reporting outcome. The FCA's 2026 sanctions systems and controls review discusses list management, calibration, configuration, assurance testing and alert management. OFSI's general guidance should be read with the relevant legislation and regime-specific guidance.
6. Transaction monitoring and blockchain analytics

- Is every material product, chain, asset, wallet type and transaction pathway covered?
- Is on-chain activity linked accurately to customer and account information?
- Do scenarios address the risks identified by the firm?
- Are thresholds and segments supported by analysis rather than inherited defaults?
- Are vendor attribution and risk-category changes governed?
- Are alerts timely, complete, investigated consistently and quality-checked?
- Are backlogs, suppressions, overrides and technical failures visible and escalated?
- Are tuning, validation and change records retained?
Practical test: Reconcile transaction records from source systems to the monitoring platform. Then trace selected transfers through ingestion, rule evaluation, alert creation and case closure. Investigate missing records and unexpected results, including activity that generated no alert.
7. Travel Rule controls
Before testing, map the rules that apply to each transfer route. Information requirements and treatment of self-hosted wallets can differ by jurisdiction; one global workflow may need local variations.
- Are inbound and outbound transfers classified correctly?
- Is required originator and beneficiary information collected, verified, transmitted and retained as applicable?
- Are counterparties and jurisdiction implementation status assessed?
- Are missing or incomplete information cases detected and risk-assessed?
- Are releases, rejections, returns or restrictions approved consistently?
- Are vendor outages and interoperability failures handled through controlled procedures?
- Is the firm testing its own compliance rather than relying solely on vendor assurance?
The FCA says UK firms remain responsible even when using third-party suppliers. Its Travel Rule expectations also address transfers involving jurisdictions that have not implemented the rule.
8. Suspicious activity reporting and investigations
Test both decisions to file a suspicious activity report (SAR) and decisions not to file. In each case, the record should explain the reasoning and show that relevant evidence was considered.
- Are alerts and referrals assessed against documented escalation criteria?
- Are decisions supported by sufficient customer, account and on-chain analysis?
- Are required reports complete, accurate and timely?
- Are urgent escalation processes defined?
- Are confidentiality and anti-tipping-off controls effective?
- Is supporting evidence retained for the required period?
- Are post-report monitoring and customer-management decisions controlled?
- Does quality assurance identify weak narratives or inconsistent decisions?
For covered US MSBs, the official eCFR states that qualifying suspicious transactions generally require reporting under 31 CFR 1022.320 and includes timing, retention and confidentiality provisions. Firms should confirm the requirements applicable to them.
9. Training, quality assurance and independent review
Quality assurance (QA) checks the standard of completed work. Independent review assesses the wider control framework. Test how both identify weaknesses and lead to improvements.
- Is training tailored to roles and risks rather than identical for all staff?
- Are new joiners trained before performing controlled activities?
- Do knowledge checks and quality results show that training is effective?
- Does quality assurance cover high-risk and ordinary cases using clear standards?
- Are QA results fed into coaching, procedures and system changes?
- Is independent review risk-based, clearly scoped and followed by tracked actions?
10. Third parties, outsourcing and change
A vendor assurance report is useful only if it covers the service, controls and period the firm relies on. Check exclusions and any controls the firm must perform itself.
- Is due diligence performed before selecting critical compliance vendors or counterparties?
- Do contracts define data, security, service, audit, incident and exit expectations?
- Does assurance cover the exact service and period relied upon?
- Are service levels, exceptions and incidents monitored?
- Are new products, assets and chains subject to compliance approval before launch?
- Do system changes receive requirements review, testing, approval and post-implementation checks?
- Can the firm continue critical controls during vendor or system outages?
Outsourcing a task does not outsource accountability. Confirm how the firm challenges vendor information and detects a control gap.
Evidence pack to prepare

| Area | Suggested evidence |
|---|---|
| Scope and governance | Entity chart, registrations, committee responsibilities, risk appetite, reporting packs and minutes |
| Risk assessment | Current and previous assessments, methodology, data inputs, approvals and change log |
| Customers | Complete customer population, risk ratings, CDD/EDD files, review records, PEP and sanctions results |
| Transactions | Transaction population for the review period, chain and asset mappings, alerts, cases, thresholds and data lineage |
| Reporting | Filing log, reporting decisions, supporting records, timeliness data and QA results |
| Travel Rule | Inbound and outbound transfer records, exception queue, vendor logs and counterparty assessments |
| Systems and vendors | Architecture, configurations, access permissions, change records, contracts and assurance reports |
| Remediation | Previous findings, action owners, due dates, completion evidence, retesting results and closure approval |
Agree secure transfer and access arrangements before fieldwork. Minimize unnecessary personal data and never request private keys or seed phrases merely because wallets are in scope.
How to turn checklist answers into an audit conclusion
Do not calculate a simple percentage of “yes” answers. Weight the nature of the control, the significance of the risk, sample results, compensating controls and the potential impact.
Assess design, implementation and operation

For each key control, answer three questions:
-
Design: Would the control address the identified risk if performed as intended?
-
Implementation: Has the approved control been put into use across the relevant business activities?
-
Operation: Does evidence show that the control worked consistently during the review period? Link exceptions to the affected population and objective. A single failure can be significant if it reveals that a whole blockchain was unmonitored; several minor documentation errors may not have the same impact.
Record limitations. If the transaction population cannot be reconciled to a complete source, say so. The inability to establish completeness may itself be a finding and may restrict the assurance conclusion.
Write findings that management can act on
Each finding should identify the expected standard, the observed failure, its cause and its potential impact. Record the affected population where it can be established, alongside the evidence supporting your conclusion.
Agree an action owner, a realistic deadline and the evidence required for closure. Prioritize issues according to risk and the firm's rating methodology. Finally, retest the corrected control before closing a finding; an updated procedure alone does not demonstrate that the underlying problem is resolved.
Practical example

Hypothetical example — overdue customer reviews: An exchange's policy requires annual review of medium-risk customers and six-month review of high-risk customers. The customer database shows that most reviews are timely. However, the auditor reconciles the database to the case tool and identifies high-risk customers whose review dates were reset after a system migration without completed reviews.
These review intervals come from the hypothetical firm’s policy; they are not universal legal requirements.
The audit must establish whether reviews were actually completed. The auditor tests the migration control, quantifies the affected population, samples customer files and assesses whether monitoring or account restrictions compensated for the delay. Management then restores the correct dates, reviews affected customers and adds migration reconciliation to the change process.
Frequently asked questions
What is a crypto AML audit?
It is an independent, risk-based assessment of whether a crypto business's AML/CTF framework is appropriately designed, implemented and operating effectively against defined requirements and risks.
Is an AML checklist enough for an independent review?
No. A checklist helps organize coverage, but the reviewer still needs risk assessment, walkthroughs, population validation, sample or full-population testing, evidence evaluation and supported conclusions.
Should the audit test every customer and transaction?
Not necessarily. Auditors may use data analysis across full populations and select risk-based samples for detailed review. The method should reflect the objective, population, risk and desired assurance.
Can the compliance team perform the independent audit?
Independence requirements vary. A reviewer should not provide independent assurance over work they own or perform. The firm should confirm applicable rules and document the reviewer's objectivity and competence.
What is the biggest crypto-specific AML audit risk?
There is no universal single risk. Common high-impact problems include incomplete chain or asset coverage, poor customer-to-wallet linkage, unsuitable monitoring rules, weak vendor challenge and controls that do not keep pace with product change.
How should previous findings be handled?
Verify whether actions were implemented and whether the revised control now operates effectively. Repeated findings or overdue high-risk actions should influence scope, testing depth and reporting.
Develop your audit and testing knowledge
If you are responsible for assurance over crypto AML controls, the checklist should be the start of the work rather than the final product. You need to know how to test evidence, challenge systems, evaluate exceptions and report conclusions.
Ready to build your audit skills? Explore Crypto Compliance Audit and Testing for Internal Control Teams and review the course outline to see how it fits your role and learning goals.


