Cryptocurrency businesses operate across borders, but their regulatory obligations do not.
A crypto exchange may need anti-money laundering registration in one country, full financial-services authorisation in another and several federal and state permissions elsewhere. Requirements can also change depending on whether a business provides custody, exchange, brokerage, transfers, lending, advice or token-issuance services.
This guide compares crypto compliance regulations by country across 15 major markets. It explains the main licensing, registration, AML, Know Your Customer (KYC), customer due diligence (CDD), transaction monitoring, reporting and Travel Rule requirements.
It also distinguishes current laws from future and proposed regulatory changes.
Disclaimer: This guide is provided for educational purposes and does not constitute legal advice. Cryptocurrency regulations change frequently. Businesses should verify the latest rules with the relevant regulator and obtain jurisdiction-specific legal advice before operating.
Why crypto regulations differ by country
The Financial Action Task Force (FATF) has established international standards for regulating virtual assets and Virtual Asset Service Providers (VASPs). However, FATF recommendations do not automatically become national law.
Each jurisdiction implements them through its own legislation. As a result, cryptocurrency regulations differ in several areas.
Asset classification
A digital asset may be classified as:
- a cryptoasset;
- a security;
- a commodity;
- electronic money;
- a payment token;
- a stablecoin; or
- an unregulated utility token.
This classification can determine which regulator and licence apply.
Regulated services
Most countries regulate custodial exchanges. However, the position may be different for:
- non-custodial wallets;
- software developers;
- decentralised finance platforms;
- staking services;
- lending;
- token issuers;
- advisers; and
- businesses trading only for themselves.
Cross-border activity
Regulation may be triggered when a business:
- operates from a country;
- has local employees;
- serves local customers;
- markets to local consumers;
- holds local customer assets; or
- provides services from overseas.
Using an offshore company does not automatically remove local regulatory obligations.
Essential crypto compliance terminology
Registration versus licensing
Registration usually places a business under AML supervision. The regulator may assess its owners, managers and financial crime controls.
A licence or authorisation normally permits particular regulated activities. It may include additional requirements covering capital, governance, custody, safeguarding, consumer protection and regulatory reporting.
An AML registration must not be presented as a general regulatory approval. 
VASP and CASP
A Virtual Asset Service Provider, or VASP, is the FATF term for businesses conducting specified virtual-asset activities for customers.
A Crypto-Asset Service Provider, or CASP, is the term used under the European Union’s Markets in Crypto-Assets Regulation (MiCA).
Although the terms overlap, their exact legal meanings depend on the applicable framework. 
The crypto Travel Rule
The Travel Rule requires regulated businesses to collect, retain and transmit specified information about the originator and beneficiary of a virtual-asset transfer.
Countries differ over:
- monetary thresholds;
- required customer information;
- verification standards;
- self-hosted wallets;
- incomplete information; and
- transfers involving overseas VASPs.
Crypto regulations in the United Kingdom
The Financial Conduct Authority (FCA) is the principal regulator for in-scope UK cryptoasset businesses.
Current requirements
Cryptoasset exchange providers and custodian wallet providers generally need to register with the FCA under the Money Laundering Regulations before conducting in-scope UK business.
This is AML registration, not full financial-services authorisation.
Registered businesses must implement:
- customer and beneficial-owner verification;
- enhanced due diligence for higher-risk customers;
- ongoing transaction monitoring;
- sanctions screening;
- suspicious activity reporting;
- record-keeping; and
- staff training.
The UK cryptoasset Travel Rule has applied since 1 September 2023. In addition, the cryptoasset financial promotions regime has applied since 8 October 2023, including to overseas businesses marketing to UK consumers.
Future authorisation regime
The UK’s broader cryptoasset authorisation regime is expected to begin on 25 October 2027. The FCA application gateway is scheduled to open on 30 September 2026.
Therefore, these wider authorisation requirements are announced but not yet in force.
Official source: FCA cryptoasset regulation
Crypto regulations in the United States
The United States does not have one general federal cryptocurrency licence.
Crypto businesses may face overlapping federal and state requirements.
FinCEN registration
A crypto exchange, administrator or transmitter may qualify as a money services business under the Bank Secrecy Act.
An in-scope business generally must:
- register with the Financial Crimes Enforcement Network;
- maintain a written AML programme;
- appoint a responsible compliance person;
- conduct customer identification;
- monitor transactions;
- retain prescribed records;
- file suspicious activity reports; and
- comply with applicable Funds Travel Rule requirements.
FinCEN registration does not replace state licensing.
State and product regulation
Custodial exchanges and payment businesses may need money-transmitter licences in individual states. New York operates its own BitLicense framework for specified virtual currency activities.
The Securities and Exchange Commission may regulate cryptoassets or arrangements that qualify as securities. Meanwhile, the Commodity Futures Trading Commission regulates crypto derivatives and can pursue fraud and manipulation involving commodity markets.
The GENIUS Act, enacted in July 2025, established a federal framework for permitted payment-stablecoin issuers. It did not introduce a universal federal licence for all crypto businesses.
Official source: FinCEN virtual currency guidance
Professionals working with US requirements can explore the Academy’s MSB Registration and FinCEN Basics course.
Crypto regulations in the European Union
The Markets in Crypto-Assets Regulation, or MiCA, creates an EU-wide regulatory framework for cryptoassets and CASPs.
MiCA’s stablecoin provisions applied from 30 June 2024, while its wider CASP requirements applied from 30 December 2024.
The maximum MiCA transition ended on 1 July 2026.
CASP authorisation
Businesses providing regulated cryptoasset services generally require authorisation from the competent authority in their home member state.
Regulated services include:
- custody;
- operating a trading platform;
- exchange;
- order execution;
- placing cryptoassets;
- receiving and transmitting orders;
- advice;
- portfolio management; and
- cryptoasset transfers.
Authorised CASPs can use MiCA’s passporting process to provide covered services across the EU.
MiCA also establishes requirements covering governance, capital, custody, complaints, conflicts, outsourcing and consumer disclosures.
AML and Travel Rule
CASPs must follow national laws implementing the EU AML framework. They must also comply with Regulation (EU) 2023/1113 on information accompanying cryptoasset transfers.
For transfers exceeding €1,000 involving a self-hosted address, the CASP must take measures to assess whether the address is owned or controlled by its customer.
The EU’s new directly applicable AML Regulation is generally scheduled to apply from 10 July 2027. It should not be presented as fully applicable in 2026.
Official source: ESMA MiCA information
Crypto regulations in Germany
The Federal Financial Supervisory Authority, or BaFin, is Germany’s main crypto regulator.
Businesses providing MiCA cryptoasset services in Germany generally require CASP authorisation. An authorised German CASP can passport covered services across the EU.
Germany’s earlier national crypto-custody framework should not be treated as an alternative route for new businesses following the end of the MiCA transition.
However, some tokenised products fall outside MiCA because they qualify as financial instruments. These products may instead trigger German banking, investment or securities legislation.
German CASPs must implement:
- KYC and beneficial-owner checks;
- enhanced due diligence;
- transaction monitoring;
- sanctions screening;
- suspicious transaction reporting to the German Financial Intelligence Unit;
- Travel Rule controls; and
- client-asset and governance measures.
Official source: BaFin MiCA information
Crypto regulations in France
France has moved from its domestic Digital Asset Service Provider framework to MiCA.
The French transition ended on 30 June 2026. Therefore, from 1 July 2026, businesses providing MiCA services in France generally need:
- MiCA CASP authorisation; or
- an eligible financial-services authorisation and the relevant MiCA notification.
The Autorité des Marchés Financiers is the principal CASP regulator, with the Autorité de Contrôle Prudentiel et de Résolution involved where required.
French CASPs must conduct KYC, beneficial-owner checks, enhanced due diligence, transaction monitoring and sanctions screening. Suspicious transactions must be reported to TRACFIN.
Businesses must also meet MiCA requirements concerning governance, capital, custody, complaints and consumer disclosures.
A previous French DASP registration should not be described as current MiCA authorisation.
Official source: AMF guidance on MiCA
Crypto regulations in Switzerland
Switzerland does not have one universal crypto licence. The required permission depends on the activity and asset.
A business may require:
- membership of a FINMA-recognised self-regulatory organisation;
- direct FINMA supervision;
- a FinTech licence;
- a banking licence;
- a securities-firm licence; or
- a Distributed Ledger Technology trading-facility licence.
Swiss financial intermediaries must identify customers and beneficial owners, investigate unusual transactions, maintain records and report suspicions to the Money Laundering Reporting Office Switzerland.
FINMA also applies a strict approach to blockchain transfers. A supervised institution must obtain required transfer information and manage the risks of sending assets to external wallets.
Capital, custody and safeguarding requirements depend on the particular licence.
Official source: FINMA FinTech authorisations
Crypto regulations in Singapore
The Monetary Authority of Singapore regulates digital payment token services under the Payment Services Act.
Depending on its services and statutory position, a provider may require a Standard Payment Institution or Major Payment Institution licence.
Regulated activities can include:
- buying or selling digital payment tokens;
- facilitating exchanges;
- transferring tokens; and
- safeguarding or administering tokens.
Licensed providers must comply with MAS Notice PSN02. This includes customer and beneficial-owner verification, risk assessment, enhanced due diligence, sanctions screening, monitoring, suspicious transaction reporting and Travel Rule controls.
A separate Digital Token Service Provider regime took effect on 30 June 2025. It can regulate Singapore-incorporated entities and individuals providing digital-token services solely outside Singapore.
MAS has stated that the licensing threshold for these overseas-only providers is high.
Official source: MAS digital payment token AML notice
Crypto regulations in Hong Kong
The Securities and Futures Commission regulates centralised Virtual Asset Trading Platforms.
Since 1 June 2023, a platform operating in Hong Kong or actively marketing to Hong Kong investors generally requires an SFC licence.
Licensed platforms must meet requirements covering:
- customer identification;
- transaction monitoring;
- Travel Rule information;
- token admission;
- custody and wallet security;
- client-asset segregation;
- market surveillance;
- conflicts;
- financial resources; and
- consumer disclosures.
Hong Kong also introduced a separate regime for fiat-referenced stablecoin issuers. The Stablecoins Ordinance took effect on 1 August 2025, with licensing administered by the Hong Kong Monetary Authority.
Broader regimes for virtual asset dealing, custody, advisory and management services have been considered separately. Consultation proposals should not be treated as effective legislation.
Official source: SFC virtual asset resources
Crypto regulations in Japan
Japan regulates cryptoasset exchange services under the Payment Services Act.
A business providing regulated exchange or custody services generally must register through the Financial Services Agency and the relevant Local Finance Bureau.
Registered providers must implement:
- customer and beneficial-owner verification;
- enhanced due diligence;
- transaction monitoring;
- suspicious transaction reporting;
- sanctions screening;
- Travel Rule procedures;
- customer-asset segregation;
- secure wallet controls; and
- consumer disclosures.
Crypto derivatives and security tokens may be regulated under the Financial Instruments and Exchange Act.
The Japan Virtual and Crypto Assets Exchange Association also maintains self-regulatory standards. However, membership does not replace statutory registration.
Official source: FSA register of cryptoasset exchange providers
Crypto regulations in the United Arab Emirates
The United Arab Emirates has several crypto regulators. One licence does not automatically cover the entire country.
Dubai
The Virtual Assets Regulatory Authority regulates virtual asset businesses in Dubai, excluding the Dubai International Financial Centre.
VARA licensing can apply to:
- exchanges;
- custodians;
- broker-dealers;
- advisers;
- lenders;
- transfer providers; and
- asset-management services.
Financial free zones
The Dubai Financial Services Authority regulates relevant crypto-token activities inside the Dubai International Financial Centre.
The Financial Services Regulatory Authority operates a separate virtual asset framework within the Abu Dhabi Global Market.
Across these regimes, providers may face capital, governance, custody, technology, AML, Travel Rule and market-conduct requirements.
Businesses must also consider UAE federal AML legislation, beneficial-ownership requirements, sanctions and suspicious transaction reporting through the goAML system.
Official source: VARA regulations and rulebooks
Crypto regulations in Australia
Australia’s virtual-asset AML framework expanded in 2026.
Previously, AUSTRAC registration focused mainly on fiat-to-virtual-asset exchange. The wider perimeter now covers additional designated services, including specified:
- virtual-asset-to-virtual-asset exchange;
- transfers;
- safekeeping or administration; and
- offering or sale-related services.
In-scope businesses with an Australian geographical connection must register with AUSTRAC as virtual asset service providers.
They must implement AML programmes, KYC, beneficial-owner checks, transaction monitoring, suspicious matter reporting, Travel Rule controls and record-keeping.
Some obligations are subject to activity-specific transitional arrangements.
AUSTRAC registration is not an Australian Financial Services Licence. An additional ASIC licence may be required when a token or service constitutes a financial product.
Official source: AUSTRAC virtual asset services
Crypto regulations in Canada
Canada combines federal AML registration with provincial securities regulation.
Businesses dealing in virtual currency may need to register with FINTRAC as domestic or foreign money services businesses.
FINTRAC registration is not a licence or endorsement.
Registered businesses must maintain:
- a compliance programme;
- a compliance officer;
- risk assessments;
- KYC and beneficial-owner controls;
- ongoing monitoring;
- suspicious transaction reports;
- large virtual currency transaction reports;
- Travel Rule procedures; and
- compliance training and testing.
Cryptoasset trading platforms may also need registration with a provincial securities regulator. Depending on the platform, investment-dealer or restricted-dealer registration and membership of the Canadian Investment Regulatory Organization may be required.
Official source: FINTRAC money services business guidance
Crypto regulations in South Korea
Virtual Asset Service Providers must file the required report with the Korea Financial Intelligence Unit.
Entry requirements may include:
- Information Security Management System certification;
- suitable management and AML systems; and
- a real-name bank-account arrangement for Korean-won exchange services.
VASPs must conduct customer and beneficial-owner verification, enhanced due diligence, sanctions screening, transaction monitoring and suspicious transaction reporting. Travel Rule requirements apply to covered transfers.
The Virtual Asset User Protection Act took effect on 19 July 2024. It introduced requirements covering customer deposits, virtual-asset custody, insurance or reserve arrangements and unfair trading.
Further amendments in 2026 tightened aspects of registration and AML supervision. Providers should check current Korea Financial Intelligence Unit notices for applicable thresholds and commencement dates.
Official source: Korea Financial Services Commission
Crypto regulations in India
India does not currently have a comprehensive general crypto licence. However, specified Virtual Digital Asset Service Providers are regulated for AML purposes.
Since the Ministry of Finance notification of 7 March 2023, covered businesses must register with the Financial Intelligence Unit–India as reporting entities.
Relevant activities include:
- crypto-to-fiat exchange;
- crypto-to-crypto exchange;
- transfers;
- custody or administration; and
- financial services connected with token offers or sales.
Reporting entities must perform KYC, beneficial-owner identification, enhanced due diligence, transaction monitoring, sanctions screening and suspicious transaction reporting.
FIU registration is not a general licence approving every product or service.
India’s taxation of virtual digital assets is also separate from regulatory authorisation. Tax treatment does not mean that a crypto business or token has received government approval.
Official source: Financial Intelligence Unit–India
Crypto regulations in Brazil
Brazil’s crypto framework is based on Law No. 14,478 of 2022 and Central Bank regulations.
Central Bank Resolutions 519, 520 and 521 took effect on 2 February 2026. They introduced an authorisation and operating framework for virtual asset service providers.
The framework addresses:
- authorisation;
- corporate governance;
- internal controls;
- customer-asset segregation;
- cyber security;
- risk management;
- AML;
- customer disclosures; and
- virtual-asset transfers.
Existing businesses are subject to transitional application arrangements. They should confirm the filing deadline applying to their business category.
The Central Bank is the principal regulator for virtual asset services. However, the Brazilian Securities and Exchange Commission regulates tokens and activities that fall within securities law.
Official source: Central Bank of Brazil virtual asset information
Other important crypto jurisdictions
Cayman Islands
The Cayman Islands Monetary Authority supervises VASPs under the Virtual Asset Service Providers Act. Depending on the activity, a business may require registration, licensing or approval. Custody and trading-platform services are subject to licensing.
Bermuda
The Bermuda Monetary Authority licenses digital asset businesses under the Digital Asset Business Act 2018. Requirements cover governance, capital, custody, cyber security and AML controls.
Liechtenstein
As part of the European Economic Area, Liechtenstein applies MiCA. Its national transition ended on 1 July 2026. The Token and Trusted Technology Service Provider Act remains relevant to certain services outside MiCA.
South Africa
Cryptoassets have been declared financial products under the Financial Advisory and Intermediary Services Act. Relevant providers may require Financial Sector Conduct Authority authorisation and must follow Financial Intelligence Centre AML requirements.
Thailand
Digital asset exchanges, brokers and dealers require licensing under Thailand’s Digital Asset Business framework. Additional Travel Rule requirements announced in 2026 are scheduled to take effect on 27 February 2027.
Global crypto regulation comparison
|
Country or region |
Main regulator |
Licence or registration |
AML and KYC |
Travel Rule |
Key consideration |
|
United Kingdom |
FCA |
AML registration; wider authorisation from 2027 |
Yes |
In force |
Registration is not authorisation |
|
United States |
FinCEN, states, SEC, CFTC |
Federal registration plus state or product permissions |
Yes |
Yes |
No single federal crypto licence |
|
European Union |
National authorities |
MiCA CASP authorisation |
Yes |
EU-wide rule |
Passporting is available |
|
Germany |
BaFin |
MiCA authorisation |
Yes |
EU-wide rule |
Financial instruments may fall outside MiCA |
|
France |
AMF |
MiCA authorisation |
Yes |
EU-wide rule |
Old DASP transition has ended |
|
Switzerland |
FINMA and SROs |
Activity-specific permission |
Yes |
Yes |
No universal crypto licence |
|
Singapore |
MAS |
Payment or DTSP licence |
Yes |
Yes |
Overseas-only services can be regulated |
|
Hong Kong |
SFC and HKMA |
VATP or stablecoin licence |
Yes |
Yes |
Separate platform and stablecoin regimes |
|
Japan |
FSA |
Exchange-provider registration |
Yes |
Yes |
Strong custody requirements |
|
UAE |
VARA, DFSA, FSRA |
Location-specific licence |
Yes |
Yes |
One licence does not cover the UAE |
|
Australia |
AUSTRAC and ASIC |
AML registration; AFSL where relevant |
Yes |
Yes |
AML scope expanded in 2026 |
|
Canada |
FINTRAC and provincial regulators |
MSB and securities registration |
Yes |
Yes |
Multiple regulatory layers |
|
South Korea |
KoFIU and FSC |
VASP filing |
Yes |
Yes |
Bank and security requirements apply |
|
India |
FIU-IND |
AML registration |
Yes |
Transfer controls |
No general crypto licence |
|
Brazil |
Central Bank and CVM |
Central Bank authorisation |
Yes |
Transfer controls |
New rules took effect in 2026 |
Common crypto compliance requirements
Although crypto regulations by country differ, most regulated VASPs and CASPs need the following controls. 
Customer due diligence
Businesses must identify customers, verify their identities and understand the purpose of the relationship.
For companies, this includes identifying the natural persons who ultimately own or control the business.
Enhanced due diligence
Additional checks may be necessary for:
- politically exposed persons;
- high-risk jurisdictions;
- complex ownership structures;
- unusual sources of funds;
- privacy-enhancing services; and
- customers with exposure to illicit or sanctioned wallets.
Transaction monitoring
Effective crypto transaction monitoring should combine customer information with blockchain activity.
Businesses may need to review:
- rapid movement of assets;
- unusual transaction values;
- exposure to mixers;
- chain-hopping;
- links to darknet markets;
- scam or ransomware wallets; and
- sanctions exposure.
The Academy’s Crypto AML and Transaction Monitoring course explains how these controls support investigations. 
Suspicious activity reporting
Businesses need clear procedures for investigating alerts, documenting decisions and reporting suspicious transactions to the relevant financial intelligence unit.
They must also prevent prohibited disclosure to the customer.
Sanctions compliance
Sanctions screening should cover customers, beneficial owners, counterparties and wallet addresses. Screening should continue throughout the relationship because sanctions lists and ownership structures change.
Travel Rule controls
Travel Rule compliance should address:
- originator and beneficiary information;
- counterparty VASP checks;
- missing information;
- self-hosted wallets;
- rejected or suspended transfers;
- record retention; and
- data protection.
Professionals can develop practical knowledge through the Academy’s Travel Rule Compliance for VASPs course.
How to build a global crypto compliance programme
A global programme should begin with an accurate map of the business. 
Identify the services
Determine whether the business provides exchange, custody, transfers, brokerage, advice, lending, staking or token issuance.
Map the jurisdictions
Record where the company is established, where its teams operate, where customers live and where marketing is directed.
Create a licensing matrix
For each market, document:
- the regulated activities;
- required registration or licence;
- responsible regulator;
- application status;
- local restrictions;
- reporting obligations; and
- renewal deadlines.
Apply local compliance rules
A global AML standard can provide the foundation. However, local procedures must address different KYC, reporting, Travel Rule, safeguarding and record-keeping requirements.
Monitor regulatory changes
Crypto regulatory frameworks change quickly. Businesses should assign responsibility for regulatory monitoring and document how new requirements are assessed and implemented.
Common mistakes crypto businesses should avoid
- Treating AML registration as full regulatory approval.
- Assuming one licence permits global operations.
- Marketing to customers before obtaining permission.
- Applying one Travel Rule threshold worldwide.
- Failing to classify tokens correctly.
- Using one-time KYC without ongoing monitoring.
- Ignoring beneficial ownership.
- Relying entirely on compliance software.
- Failing to protect or segregate customer assets.
- Treating proposed legislation as current law.
Frequently asked questions
Which country has the strictest crypto regulations?
There is no single answer. Japan, Singapore, Hong Kong and the EU impose detailed licensing, governance and custody requirements. The United States can be especially complex because federal and state rules overlap.
Do all crypto businesses need a licence?
No. The answer depends on the services, assets, custody model and customer locations. Exchanges, custodians and transfer providers are more likely to require registration or authorisation.
What is a VASP licence?
It is a general expression for regulatory permission to provide virtual asset services. Depending on the jurisdiction, the permission may legally be called a licence, registration, authorisation or filing.
What is a CASP licence under MiCA?
It is an authorisation to provide specified cryptoasset services in the European Union. An authorised CASP can generally use MiCA passporting to provide covered services in other EU countries.
Is KYC mandatory for crypto businesses?
KYC is normally mandatory for regulated exchanges, custodians and other VASPs. It may not apply in the same way to every software provider or non-custodial service.
What AML requirements apply to crypto businesses?
Common requirements include risk assessments, KYC, beneficial-owner checks, enhanced due diligence, sanctions screening, monitoring, suspicious transaction reporting, staff training and record-keeping.
What is the crypto Travel Rule?
The Travel Rule requires specified information about the sender and recipient to accompany or be associated with a virtual-asset transfer.
Are crypto regulations the same in every country?
No. Countries apply different licensing categories, thresholds, token classifications, custody standards and reporting rules.
How can a business determine which licence it needs?
It should analyse its services, custody model, assets, customer countries and marketing. These facts should then be compared with each jurisdiction’s regulated activities.
What happens if a crypto business operates without permission?
Possible consequences include fines, criminal action, website blocking, customer offboarding, cease-and-desist orders and difficulty obtaining future authorisation.
Conclusion
Understanding crypto compliance regulations by country requires more than comparing licence names.
Businesses must distinguish AML registration from full authorisation, identify how each token is classified and consider both their location and the countries they serve.
A strong global compliance programme should connect licensing, KYC, transaction monitoring, sanctions, safeguarding, suspicious activity reporting and Travel Rule controls to the company’s actual products and customer activity.
Professionals seeking practical knowledge can explore the Academy’s crypto compliance training courses, including courses on AML, KYC, blockchain investigations, sanctions and regulatory compliance.
Sources and references
- Financial Action Task Force: Virtual Assets
- UK Financial Conduct Authority: Cryptoassets
- FinCEN: Virtual Currency Guidance
- EUR-Lex: MiCA
- EUR-Lex: Transfer of Funds Regulation
- AMF France: MiCA
- FINMA: FinTech
- Monetary Authority of Singapore: PSN02
- Japan FSA: Registered Cryptoasset Providers
- AUSTRAC: Virtual Asset Services
- Korea Financial Services Commission
- Financial Intelligence Unit–India


