The Bank Secrecy Act and the anti-money-laundering rules built on it require US financial institutions — including money services businesses, which is how they reach crypto firms — to identify their customers, monitor for suspicious activity, keep records and file reports with FinCEN. It is the regime that turns identity verification and transaction monitoring from a product decision into a legal obligation.
BSA / AML
Statute United States
BSA and the AML rules are why a crypto exchange asks for a passport. Registering as a money services business brings customer identification, sanctions screening, transaction monitoring, recordkeeping and suspicious activity reporting — a set of obligations that generate enormous volumes of machine-processed data and almost no published interfaces.
- Customer identification - Know-your-customer programmes as a legal minimum rather than a risk preference.
- Sanctions screening - OFAC list checking on parties and, in this market, on wallet addresses.
- Transaction monitoring and SARs - Suspicious activity detection and reporting, on timelines that reward automation.
- Recordkeeping - Retention obligations that shape what a platform must be able to reconstruct.
- Reaches non-banks - The money services business definition is what pulls exchanges, custodians and payment firms into scope.
In The State of Blockchain & Crypto APIs this regime explains a segment: compliance, identity and risk vendors exist because these obligations do, and the market’s institutional tier — custody, stablecoins, regulated payments — publishes idempotency and error semantics at the highest rates in the cohort, because it answers to supervisors who ask what happened and when. The same tier publishes scopes at a fraction of that rate, which is the report’s open question rather than its conclusion.