Compliance requirements for a crypto card programme
A crypto card sits at the intersection of two regulated activities: payments and virtual assets. It inherits obligations from both. This is a map of what applies, and of who is answerable for each part.
The two regimes
A crypto-funded card programme touches payment services regulation, because it issues payment instruments and holds customer funds, and virtual asset regulation, because balances are funded with cryptocurrency and stablecoins. Most programmes discover the second one later than they should, having scoped only the first.
Card scheme rules sit alongside both. They are not law, but they are contractually binding on every participant, and a scheme can end a programme faster than a regulator can.
Accountability map
In a white-label arrangement the single most important document is the one that says who owns what. This is the shape it usually takes.
| Obligation | Accountable | Typically operated by |
|---|---|---|
| Holding the licence and permissions | Issuing institution | Issuing institution |
| Customer identification and verification | Issuing institution | Institution, with vendor tooling |
| Risk-based customer due diligence | Issuing institution | Issuing institution |
| Enhanced due diligence on higher-risk customers | Issuing institution | Issuing institution |
| Sanctions screening at onboarding and ongoing | Issuing institution | Screening vendor, integrated |
| Geographic exclusion list | Issuing institution | Platform, applied at programme level |
| Transaction monitoring | Issuing institution | Platform engine, institution thresholds |
| Alert triage and investigation | Issuing institution | Institution compliance team |
| Suspicious activity reporting | Issuing institution | Issuing institution |
| Travel rule on qualifying transfers | The VASP conducting the transfer | On-ramp provider |
| Record keeping and retention | Issuing institution | Platform stores, institution governs |
| Regulatory reporting | Issuing institution | Issuing institution |
| Scheme rule adherence | Both | Platform operationally |
| Data protection as controller | Issuing institution | Platform acts as processor |
Onboarding
Identification and verification at onboarding is the baseline: establishing who the customer is, verifying it against reliable independent sources, and understanding the purpose and intended nature of the relationship. For a card funded by digital assets, source of funds deserves more attention than it gets in a conventional deposit account, because the funding rail itself carries risk signals.
Risk-rating at onboarding drives everything downstream. It sets the due diligence standard, the monitoring sensitivity and the refresh cycle. A programme that risk-rates every customer identically has not really implemented a risk-based approach; it has implemented a uniform one and called it risk-based.
Sanctions and geography
Sanctions screening applies at onboarding and continuously thereafter, because lists change and a customer who was clear last year may not be today. Screening covers the customer, and where relevant beneficial owners and counterparties.
Separately, every programme maintains a country exclusion list. It combines sanctioned jurisdictions, jurisdictions where the product is not licensed, jurisdictions the scheme restricts, and jurisdictions the institution has chosen to avoid on risk-appetite grounds. It is reviewed on an ongoing basis, and changes need to reach cardholders with notice rather than as a surprise decline at a terminal.
Ongoing monitoring
Monitoring is where the programme either works or generates noise. Effective monitoring is calibrated to expected behaviour for that customer's risk profile, not to a global threshold. Structuring patterns, rapid movement of funds, spending inconsistent with the stated profile, unusual geographic patterns and high-risk merchant categories are the standard typologies; the crypto funding rail adds its own, including funding from addresses with adverse on-chain exposure.
The measure of a monitoring programme is not alert volume. It is the proportion of alerts that a competent investigator finds worth investigating. A system generating thousands of alerts nobody can work through is a compliance risk dressed as a control.
What to have ready for diligence
An institution's vendor diligence, or a regulator's examination, will typically ask for the same set of artefacts: the responsibility matrix showing who owns each obligation, the AML policy and risk assessment, the customer risk-rating methodology, monitoring rules and thresholds with their rationale, the sanctions screening arrangement, the exclusion list and its review cadence, data-processing terms, retention schedules, incident and breach procedures, and evidence that the controls described are the controls operating.
The last one is where programmes fail. Documented controls that do not match observed behaviour are worse than no documentation, because they demonstrate that governance is decorative.
Frequently asked questions
Who is accountable for AML in a white-label card programme?+
The licensed institution issuing the card. A technology provider can supply monitoring engines, screening integrations and case management surfaces, but accountability for the AML programme, the risk appetite and any regulatory filings sits with the licence holder and cannot be outsourced away.
Does the travel rule apply to crypto card funding?+
It can. Where funding involves a transfer between virtual asset service providers above the applicable threshold, travel rule obligations may attach to that transfer. Whether they do depends on the jurisdictions of both parties and the structure of the on-ramp, which is a question for counsel per programme.
What is the difference between KYC and ongoing due diligence?+
KYC is the identification and verification performed at onboarding. Ongoing due diligence is the continuing obligation to keep that understanding current: refreshing records, monitoring whether behaviour matches the expected profile, and escalating when it does not. Programmes that treat onboarding as the finish line fail examination.
Can a programme operate without geographic restrictions?+
No. Every card programme maintains an exclusion list covering sanctioned jurisdictions, jurisdictions where the product is not licensed, and jurisdictions the scheme or the institution has chosen to avoid. The list is reviewed continuously, not set once.
Request the compliance pack
Institutions evaluating a Zen Card programme can request the responsibility matrix, control documentation and data-processing terms.
