Compliance · 12 min read

Compliance requirements for a crypto card programme

A crypto card sits at the intersection of two regulated activities: payments and virtual assets. It inherits obligations from both. This is a map of what applies, and of who is answerable for each part.

Not legal advice
This guide describes the shape of the obligations, not their application to your circumstances. Requirements vary materially by jurisdiction and by the permissions an institution holds. Take advice from counsel qualified in each market you intend to operate in before designing a programme around any of this.

The two regimes

A crypto-funded card programme touches payment services regulation, because it issues payment instruments and holds customer funds, and virtual asset regulation, because balances are funded with cryptocurrency and stablecoins. Most programmes discover the second one later than they should, having scoped only the first.

Card scheme rules sit alongside both. They are not law, but they are contractually binding on every participant, and a scheme can end a programme faster than a regulator can.

Accountability map

In a white-label arrangement the single most important document is the one that says who owns what. This is the shape it usually takes.

ObligationAccountableTypically operated by
Holding the licence and permissionsIssuing institutionIssuing institution
Customer identification and verificationIssuing institutionInstitution, with vendor tooling
Risk-based customer due diligenceIssuing institutionIssuing institution
Enhanced due diligence on higher-risk customersIssuing institutionIssuing institution
Sanctions screening at onboarding and ongoingIssuing institutionScreening vendor, integrated
Geographic exclusion listIssuing institutionPlatform, applied at programme level
Transaction monitoringIssuing institutionPlatform engine, institution thresholds
Alert triage and investigationIssuing institutionInstitution compliance team
Suspicious activity reportingIssuing institutionIssuing institution
Travel rule on qualifying transfersThe VASP conducting the transferOn-ramp provider
Record keeping and retentionIssuing institutionPlatform stores, institution governs
Regulatory reportingIssuing institutionIssuing institution
Scheme rule adherenceBothPlatform operationally
Data protection as controllerIssuing institutionPlatform acts as processor
The rule that catches people out
Operations can be delegated. Accountability cannot. A regulator examining a programme will ask the licence holder to explain the monitoring thresholds, not the vendor who built the engine.

Onboarding

Identification and verification at onboarding is the baseline: establishing who the customer is, verifying it against reliable independent sources, and understanding the purpose and intended nature of the relationship. For a card funded by digital assets, source of funds deserves more attention than it gets in a conventional deposit account, because the funding rail itself carries risk signals.

Risk-rating at onboarding drives everything downstream. It sets the due diligence standard, the monitoring sensitivity and the refresh cycle. A programme that risk-rates every customer identically has not really implemented a risk-based approach; it has implemented a uniform one and called it risk-based.

Sanctions and geography

Sanctions screening applies at onboarding and continuously thereafter, because lists change and a customer who was clear last year may not be today. Screening covers the customer, and where relevant beneficial owners and counterparties.

Separately, every programme maintains a country exclusion list. It combines sanctioned jurisdictions, jurisdictions where the product is not licensed, jurisdictions the scheme restricts, and jurisdictions the institution has chosen to avoid on risk-appetite grounds. It is reviewed on an ongoing basis, and changes need to reach cardholders with notice rather than as a surprise decline at a terminal.

Ongoing monitoring

Monitoring is where the programme either works or generates noise. Effective monitoring is calibrated to expected behaviour for that customer's risk profile, not to a global threshold. Structuring patterns, rapid movement of funds, spending inconsistent with the stated profile, unusual geographic patterns and high-risk merchant categories are the standard typologies; the crypto funding rail adds its own, including funding from addresses with adverse on-chain exposure.

The measure of a monitoring programme is not alert volume. It is the proportion of alerts that a competent investigator finds worth investigating. A system generating thousands of alerts nobody can work through is a compliance risk dressed as a control.

What to have ready for diligence

An institution's vendor diligence, or a regulator's examination, will typically ask for the same set of artefacts: the responsibility matrix showing who owns each obligation, the AML policy and risk assessment, the customer risk-rating methodology, monitoring rules and thresholds with their rationale, the sanctions screening arrangement, the exclusion list and its review cadence, data-processing terms, retention schedules, incident and breach procedures, and evidence that the controls described are the controls operating.

The last one is where programmes fail. Documented controls that do not match observed behaviour are worse than no documentation, because they demonstrate that governance is decorative.

Frequently asked questions

Who is accountable for AML in a white-label card programme?+

The licensed institution issuing the card. A technology provider can supply monitoring engines, screening integrations and case management surfaces, but accountability for the AML programme, the risk appetite and any regulatory filings sits with the licence holder and cannot be outsourced away.

Does the travel rule apply to crypto card funding?+

It can. Where funding involves a transfer between virtual asset service providers above the applicable threshold, travel rule obligations may attach to that transfer. Whether they do depends on the jurisdictions of both parties and the structure of the on-ramp, which is a question for counsel per programme.

What is the difference between KYC and ongoing due diligence?+

KYC is the identification and verification performed at onboarding. Ongoing due diligence is the continuing obligation to keep that understanding current: refreshing records, monitoring whether behaviour matches the expected profile, and escalating when it does not. Programmes that treat onboarding as the finish line fail examination.

Can a programme operate without geographic restrictions?+

No. Every card programme maintains an exclusion list covering sanctioned jurisdictions, jurisdictions where the product is not licensed, and jurisdictions the scheme or the institution has chosen to avoid. The list is reviewed continuously, not set once.

Request the compliance pack

Institutions evaluating a Zen Card programme can request the responsibility matrix, control documentation and data-processing terms.

Zen CardZen Card

Crypto-funded cards on the Visa network, and the white-label issuing platform behind them.

Corporate information. This website is operated by Otaro Pay Ltd, FINTRAC M23150730, Suite 250 - #1585 997 Seymour St, Vancouver BC V6B 3M1. Contact: info@otaropay.com.

Regulatory notice. Otaro Pay Ltd is a FINTRAC MSB. It is not a bank and does not itself issue cards, take deposits, extend credit or provide investment services. Cards, accounts, credit and yield-bearing products described on this site are provided by licensed financial institutions, subject to their terms, their approval, and the regulations of the relevant jurisdiction. Availability varies by country. Digital assets are volatile and capital is at risk. Nothing on this website constitutes an offer, a solicitation, financial advice or investment advice.

© 2026 Otaro Pay. All rights reserved.

Launch App →