Compliance

Crypto compliance for businesses

Handling crypto or stablecoins as a business means meeting the same financial-crime standards as any payments firm, plus several that are specific to crypto. This page ties the pieces together and then addresses the decision most of that work actually turns on: whether to become a regulated entity yourself, or to settle through one.

A business that touches crypto inherits everything a payments firm must do, and a little more. Pulled into one place, “crypto compliance” means five things.

  1. Authorisation or registration for the activity you carry on — an authorised CASP in the EEA since 1 July 2026, a registered VASP under most other national regimes, a money services business in Canada.
  2. A full AML programme — KYB and KYC, sanctions, PEP and adverse-media screening, transaction monitoring, and suspicious-activity reporting.
  3. The Travel Rule — originator and beneficiary information travelling with qualifying transfers.
  4. Enhanced due diligence — proportionate additional scrutiny where the risk rating calls for it.
  5. Safeguarding — client funds segregated from company funds, and held so that they are not available to your creditors.

What changed in the EEA, and why it resets the analysis

On 1 July 2026 the MiCA transitional window closed. National VASP and DASP registrations stopped authorising crypto-asset service anywhere in the EEA; CASP authorisation became the only route.

The scale of the reset is the point. Of roughly 3,000 nationally registered firms, about 244 held MiCA authorisation at the deadline, reaching around 309 across the EEA by late July. ESMA has asked the remainder to wind down in an orderly manner.

Two things follow. If you operate in the EEA and your compliance analysis predates that date, it is not slightly stale — the legal basis it assumed no longer exists. And if you are selecting a counterparty, the terminology they use is now diagnostic: a provider still describing EEA firms as VASPs is telling you when they last looked.

Obligations stack; they do not substitute

The single most expensive misconception in cross-border crypto is that holding one permission discharges the others.

It does not. A Canadian MSB registration covers Canadian obligations. It does nothing for the EEA position of an EEA customer. Where you are authorised, where your customer is, and where the funds move all pull in their own requirements, and they accumulate.

This matters most at the edges, where the differences are real and operational:

EEACanadaUnited Kingdom
Crypto authorisationCASP under MiCAMSB registration including virtual currencyCryptoasset business registration under the MLRs
Travel Rule thresholdNone — full data at any valueCAD 1,000 for virtual currency transfersApplies to cryptoasset transfers, with reduced requirements for certain low-value intra-UK transfers
Principal AML instrumentThe 2024 anti-money-laundering packagePCMLTFA, supervised by FINTRACMoney Laundering Regulations 2017

The Travel Rule row is the one that catches systems built to a single global setting. A rule engine configured to a USD 1,000 de minimis is non-compliant on every sub-threshold EEA transfer, and it will not tell you.

Build it yourself, or settle through someone who has

Two routes, and the honest framing is not “which is cheaper” but whether being a regulated entity is your product or your plumbing.

Get authorised yourself. Full control and full optionality. Also: an authorisation process measured in quarters, minimum capital, a compliance function with real people in it, monitoring systems, audit, and permanent supervisory obligations. If crypto-asset service is your business — you run an exchange, a custody service, a brokerage — this is not optional and no provider arrangement substitutes for it.

Settle through an authorised counterparty. Build on a partner that already holds the relevant registrations and runs the programme, so funds move on a compliant rail without you becoming a regulated entity. Faster, materially cheaper, and appropriate where crypto settlement supports a business that is fundamentally something else — a marketplace, a payroll platform, a treasury operation.

The error worth naming is assuming the second route covers activity that requires the first. Using an authorised provider does not authorise you. If you are carrying on crypto-asset services on your customers’ behalf, you need your own permission, and a counterparty relationship is not a defence. If you are unsure which side of that line you sit on, that is a question for a regulatory lawyer before it is a question for a provider.

What good looks like in a counterparty

If you are assessing a provider rather than building, these are the questions that actually separate them:

  • Which entity am I contracting with, and what does it hold? A named legal entity and specific registrations — not a group name and a claim.
  • Registrations or licences? A provider that calls a registration a licence is being loose with the one description you can independently verify.
  • Where are client funds held? Segregated safeguarding accounts, and clarity on whether the same treatment applies to digital assets. Usually it does not, and a provider that blurs this is worth pressing.
  • How is the Travel Rule implemented, and to which thresholds? If they cannot answer by jurisdiction, they have one global setting and it is wrong somewhere.
  • What will they refuse? A published risk appetite is a stronger signal than a long list of what they accept.

How KwiikPay fits

KwiikPay is a trading name of KWP Finance Limited, registered in Canada as a Payment Service Provider under the Retail Payment Activities Act, supervised by the Bank of Canada, and as a FINTRAC-registered Money Services Business including dealing in virtual currency. Both are registrations rather than licences. KwiikPay is not a MiCA-authorised CASP and does not provide crypto-asset services into the EEA under MiCA.

The programme runs end to end — KYB and KYC, sanctions, PEP and adverse-media screening, transaction monitoring, reporting through a named MLRO, the Travel Rule on the stablecoin rail, and enhanced due diligence for higher-risk profiles, with fiat balances held in segregated safeguarding accounts.

We serve firms incorporated and authorised in the EEA, the United Kingdom, Gibraltar, Switzerland and Canada. Virtual-asset services, including stablecoin settlement, are not available to UK or EU customers — for those firms the offer is fiat-only. We do not onboard crypto-asset businesses holding no authorisation anywhere, and the sectors we will not serve at any level of diligence are published in the risk appetite statement.

See pricing, or talk to us if you would rather establish eligibility before anything else.

FAQs

What does crypto compliance actually require?

Authorisation or registration for the activity you carry on; a full AML programme covering KYB and KYC, sanctions and PEP screening, transaction monitoring and suspicious-activity reporting; the Travel Rule on qualifying transfers; and safeguarding of client funds. The specifics follow from where you are authorised and where your customers are, and obligations stack across jurisdictions rather than substituting for one another.

Do I need my own authorisation, or can I use a compliant provider?

Both models are legitimate, and the question is whether regulated activity is your product or your plumbing. If you carry on crypto-asset services on customers' behalf, you generally need your own permission and no provider relationship removes that. If you need crypto settlement to support a business that is something else, settling through an authorised counterparty is usually faster and cheaper. Getting this wrong in the direction of assuming a provider covers you is the expensive error.

Is stablecoin settlement treated the same as other crypto?

For financial-crime purposes, largely yes — stablecoin transfers are transfers of crypto-assets, so authorisation, AML and Travel Rule obligations apply. Prudentially the EEA treats asset-referenced and e-money tokens under their own MiCA regime, distinct from other crypto-assets. Using a fully-reserved stablecoin and an authorised rail reduces the burden; it does not remove it.

What changed in the EEA on 1 July 2026?

The MiCA transitional window closed. National VASP and DASP registrations stopped authorising crypto-asset service anywhere in the EEA, and CASP authorisation became the only route. Of roughly 3,000 nationally registered firms, about 309 held authorisation by late July. If your EEA analysis predates that date it is out of date.

What happens if a business gets crypto compliance wrong?

In practice the first consequence is commercial, not regulatory: banking and liquidity partners withdraw, usually quickly and often together. Enforcement, fines and in serious cases criminal liability follow. The order matters, because firms tend to plan for the fine and get caught by the loss of rails.

Related
FINTRAC MSB registration → Check your eligibility → MiCA CASP accounts → What is a VASP licence? → AML compliance for payments → The Travel Rule for crypto → What is KYB? → Enhanced Due Diligence (EDD) →

Open your first IBAN today.

Open a multi-currency account, subject to KYB, screening and our risk appetite.

Talk to sales