RegTech for Crypto: The Compliance Technology Stack Powering Digital Asset Businesses
The crypto RegTech stack combines transaction monitoring, wallet screening, travel rule compliance, and sanctions checking in one platform.
Every digital asset business that touches fiat, processes withdrawals, or onboards customers needs a compliance technology stack. The crypto RegTech market has grown from a handful of blockchain analytics startups into a multi-billion-dollar industry with specialized tools for every layer of the compliance workflow: wallet screening, real-time transaction monitoring, travel rule data exchange, KYC/AML verification, and sanctions screening. Choosing the right stack determines not just regulatory survival but also user experience, operational cost, and how quickly a company can enter new markets.
This guide maps the crypto compliance technology stack layer by layer, compares the leading vendors, and examines how compliance architecture differs for custodial versus self-custodial wallet models.
What Is Crypto RegTech?
RegTech (regulatory technology) refers to software that automates compliance processes that would otherwise require large teams of manual analysts. In traditional finance, RegTech covers everything from trade surveillance to regulatory reporting. In crypto, the stack centers on a narrower but technically demanding set of problems: identifying who controls a wallet address, tracing the flow of funds across blockchains, and exchanging counterparty information across jurisdictions with inconsistent rules.
The crypto compliance market is estimated at $2.5 billion to $4.4 billion in 2025, depending on scope definitions, and is projected to reach $10 billion or more by 2032 at roughly 22% annual growth. That growth is driven by regulatory expansion: the EU's Markets in Crypto-Assets Regulation (MiCA) has been in full enforcement since December 2024, with over 40 CASP licenses issued and more than EUR 540 million in penalties already levied. In the US, the GENIUS Act is reshaping stablecoin oversight. Globally, 85 of 117 FATF-monitored jurisdictions have enacted travel rule legislation as of early 2026.
The Five Layers of Crypto Compliance
A complete crypto compliance stack has five distinct functional layers. Some companies buy all five from a single vendor; most assemble a best-of-breed combination. Each layer solves a different regulatory requirement and operates at a different point in the user lifecycle.
Layer 1: KYC/KYB Identity Verification
Before a user can transact, regulated platforms must verify their identity. KYC (Know Your Customer) and KYB (Know Your Business) verification sits at the onboarding gate. Modern providers use document capture with OCR, biometric selfie matching, liveness detection certified to the ISO/IEC 30107-3 standard (the iBeta Level 2 benchmark), NFC chip reading from identity documents, and database registry checks against government records.
The leading providers each bring different strengths. Persona was named a Leader in the 2026 Gartner Magic Quadrant for Identity Verification and partners with Kraken, Bridge, and BitGo. In May 2026, Persona partnered with Chainlink to launch a Cross-Chain Identity framework enabling verify-once credentials that port across blockchains. Sumsub offers the broadest single-vendor coverage, combining KYC, KYB, AML screening, and travel rule compliance in one platform. Sumsub reported a 1,100% increase in deepfake fraud attempts in North America during Q1 2025 and responded with adaptive detection claiming 99.98% synthetic media identification. Onfido, acquired by Entrust for $650 million in April 2024, specializes in passive injection attack and deepfake video detection through its Atlas AI system.
Layer 2: Wallet Screening and Blockchain Analytics
Wallet screening is the crypto-native compliance layer with no direct equivalent in traditional finance. Before processing a deposit or withdrawal, a compliant platform checks the counterparty address against risk databases: sanctioned addresses, darknet marketplace wallets, ransomware collection points, and addresses associated with mixing services.
Chainalysis is the most widely deployed platform among regulated US exchanges. Its KYT (Know Your Transaction) product covers 100+ blockchains with automatic onboarding of new chains and tokens that follow widely adopted standards. Chainalysis has raised $538 million across 11 rounds and generates an estimated $157 million to $190 million in annual revenue. TRM Labs reached unicorn status in February 2026 with a $70 million Series C led by Blockchain Capital and Goldman Sachs, valuing the company at $1 billion. TRM covers 100+ blockchains with real-time indexing on 45+ chains. Elliptic closed a $120 million Series D in May 2026 from Deutsche Bank and Nasdaq Ventures, and its Nexus engine traces cross-chain flows across 60+ blockchains and 250+ bridges covering over 1 billion addresses.
False positive problem: Industry-wide false positive rates for AML transaction monitoring run upwards of 90%, causing alert fatigue that buries genuine risk signals. Chainalysis reports that platforms tuning alert thresholds quarterly produce 40% fewer false positives than those that configure rules once at implementation.
Layer 3: Real-Time Transaction Monitoring
Transaction monitoring operates continuously after onboarding, scoring every inbound and outbound transfer against risk models. Systems work in two modes: pre-alert enrichment, where every transaction is scored against external risk databases before alert rules trigger, and post-alert enrichment, where flagged transactions are automatically queried against external platforms to provide context for analysts.
Sardine combines device intelligence, behavioral biometrics, and machine learning into a single real-time fraud, AML, and credit-risk decisioning engine that screens over $1.48 trillion in payments across 300+ enterprise customers. Sardine raised $70 million in its Series C in February 2025 and integrates with Chainalysis and TRM Labs for on-chain data. Merkle Science takes a behavior-based approach with configurable jurisdiction-specific compliance policies covering 10,000+ assets and 200+ bridges.
For a deeper look at how fraud prevention intersects with payment compliance, including the role of behavioral analytics and device fingerprinting, see our companion article on fraud prevention in digital payments.
Layer 4: Travel Rule Data Exchange
The FATF Recommendation 16 (the “Travel Rule”) requires VASPs to attach sender and recipient identifying information to qualifying crypto transfers, analogous to the wire transfer rule in traditional banking. The US threshold is $3,000; the EU's Transfer of Funds Regulation dropped the threshold to zero in 2026, meaning every crypto transfer between regulated entities must carry counterparty data.
Notabene is the leading Travel Rule infrastructure provider, aggregating multiple messaging protocols (TRP, TRISA, IVMS 101) into a single SaaS platform used by exchanges including Bitstamp, Luno, and Copper. Their 2025 report documented a 431% year-over-year increase in VASPs blocking withdrawals until beneficiary information is confirmed. Sygna Bridge, built by CoolBitX, is particularly strong in APAC markets. TRISA (Travel Rule Information Sharing Alliance) provides an open-source gRPC protocol with a directory of certified VASPs, while OpenVASP/TRP offers a RESTful standard backed by BitGo and Fidelity Digital Assets with adoption concentrated among European Tier 1 VASPs.
The sunrise problem: As of early 2026, 85 jurisdictions have enacted travel rule legislation, but 50 of those (59%) have not yet taken enforcement action. When a VASP's counterparty is in a non-enforcing jurisdiction, that counterparty has no obligation to exchange personal data. This creates compliance gaps that platforms typically handle by sending travel rule data to the counterparty's general contact email and retaining records of the attempt.
Layer 5: Sanctions Screening
Sanctions screening checks wallet addresses and customer identities against the OFAC SDN list, EU consolidated sanctions lists, and UN sanctions registers. OFAC has added cryptocurrency addresses to the SDN list since November 2018. Penalties can reach $20 million per violation plus criminal referral.
The challenge is that OFAC's published addresses represent only a fraction of addresses controlled by sanctioned actors. Compliance tools must trace associations: wallets that have received funds from or sent funds to designated addresses, using cluster analysis and transaction tracing to map broader exposure. This is where blockchain analytics and sanctions screening overlap: the same graph traversal that powers wallet screening also identifies indirect sanctions exposure.
In a notable policy reversal, OFAC delisted Tornado Cash from the SDN list in March 2025, following the Fifth Circuit's ruling that immutable smart contracts are not “property” of a foreign national. The delisting does not change broader compliance obligations, and criminal charges against co-founders remain pending.
Blockchain Analytics Vendors Compared
The three dominant blockchain analytics platforms compete on chain coverage, investigation tooling, and pricing. All three have expanded significantly in 2025 and 2026 through major funding rounds.
| Vendor | Chains Covered | Key Products | Notable Investors / Funding |
|---|---|---|---|
| Chainalysis | 100+ | KYT (monitoring), Reactor (investigation), Address Screening | $538M total; Series F Oct 2025 |
| TRM Labs | 100+ (real-time on 45+) | TRM Forensics, wallet screening APIs, risk scoring | $220M total; $70M Series C Feb 2026 ($1B valuation) |
| Elliptic | 60+ chains, 250+ bridges | Lens (screening), Navigator (investigation), Nexus (cross-chain) | $120M Series D May 2026 (Deutsche Bank, Nasdaq Ventures) |
| Crystal Intelligence | Multi-chain | Crystal analytics platform, Scam Alert (acquired May 2025) | Bitfury Group; Tether investment 2025 |
Mid-tier alternatives exist for earlier-stage companies. Providers like AMLBot and Didit offer transparent per-check pricing starting at roughly $0.15 per wallet screening check with no monthly minimums and free tiers of 500 checks per month.
All-in-One Platform vs. Best-of-Breed Stack
The central architectural decision for any crypto compliance team is whether to consolidate with a single vendor or assemble specialized tools. The market has converged on two primary integration patterns.
Pattern 1: Single-Vendor Platform
Sumsub is the most complete single-vendor offering, covering KYC, KYB, AML screening, and travel rule compliance from one dashboard. This pattern suits earlier-stage companies prioritizing speed to market and simpler vendor management. The tradeoff is that blockchain analytics depth typically lags dedicated providers: Sumsub integrates with Chainalysis and TRM Labs for on-chain data rather than building its own graph engine.
Pattern 2: Best-of-Breed Assembly
Most regulated exchanges and licensed CASPs pair a dedicated blockchain analytics platform (Chainalysis, TRM Labs, or Elliptic) with a specialized KYC provider (Persona, Veriff, or Jumio) and a travel rule solution (Notabene or Sygna). This approach requires more integration work but delivers deeper capabilities in each layer. The consensus among large regulated entities in 2026 is that best-of-breed remains the standard.
| Factor | Single-Vendor Platform | Best-of-Breed Stack |
|---|---|---|
| Vendor management | One contract, one dashboard | 3-5 vendor relationships |
| Integration effort | Days to weeks | Weeks to months |
| Analytics depth | Adequate for most cases | Best available per layer |
| Cost (mid-market) | $80K-$200K/year | $150K-$400K/year |
| Flexibility | Locked to vendor roadmap | Swap any layer independently |
| Best for | Startups, speed-to-market | Licensed exchanges, high-volume platforms |
How Compliance Costs Scale
Compliance tooling costs scale with transaction volume, number of supported chains, and the jurisdictions a business operates in. Pricing models vary: blockchain analytics vendors use annual contracts with volume-based tiers, KYC providers charge per verification check, and travel rule solutions price per message or per monthly active user.
Typical Annual Spend by Company Stage
- Early-stage startup (pre-revenue or seed): $30,000 to $80,000 per year using budget analytics providers and a basic KYC integration
- Mid-market exchange or licensed CASP: $150,000 to $400,000 per year for enterprise analytics, KYC, and travel rule tooling
- Large exchange or multi-jurisdictional platform: $500,000 to $2 million or more per year for a full compliance stack including dedicated compliance engineering headcount
Chainalysis enterprise deployments for mid-sized CASPs reportedly run EUR 120,000 to 250,000 per year. KYC verification ranges from $0.33 to $3.00 per check depending on verification depth, with ongoing AML monitoring at roughly $0.05 to $0.10 per customer per month for sanctions and PEP re-screening.
The cost pressure is real: crypto exchanges were the single most-fined category of financial business for AML/CFT failures in 2025, exceeding money transmitters, securities firms, and casinos combined. Under-investing in compliance tooling creates existential regulatory risk.
Compliance for Self-Custodial Wallets
The compliance architecture for self-custodial wallets differs fundamentally from custodial platforms. When a user controls their own keys, there is no receiving VASP to transmit travel rule data to. The originating VASP must perform enhanced due diligence: proof-of-wallet ownership (typically asking the user to sign a message with their private key), blockchain analytics to verify the address is not associated with sanctioned entities, and ongoing monitoring of the address.
The EU's MiCA framework, under Article 37, mandates the European Commission to assess self-hosted address risks by July 2026 and may introduce additional restrictions on transfers to and from self-custodial wallets. This regulatory uncertainty shapes how wallet developers architect compliance: building proof-of-ownership flows into onboarding, integrating analytics APIs for real-time address screening, and designing data retention policies that satisfy multiple jurisdictions simultaneously.
The Interoperability Challenge
Increasingly replacing the sunrise problem as the primary travel rule headache: a counterparty VASP is compliant and willing to exchange data, but uses a different travel rule messaging protocol that is not interoperable with yours. Notabene addresses this by aggregating TRP, TRISA, and IVMS 101 into a single platform, but fragmentation persists. Standardization efforts are ongoing, though no single protocol has achieved universal adoption.
Integration Architecture for Wallet Developers
For developers building wallets or payment applications, compliance tooling integrates at four points in the transaction lifecycle.
- Onboarding: KYC provider API verifies identity before the user can deposit or transact. Most providers offer drop-in SDKs for mobile and web with configurable verification flows.
- Pre-transaction screening: before processing a send or receive, the wallet queries a blockchain analytics API to score the counterparty address. High-risk scores trigger holds or blocks. API response times typically run under 200 milliseconds.
- Post-transaction monitoring: continuous background screening of all addresses the user has interacted with. If a previously clean address later appears on a sanctions list or is linked to illicit activity, the system generates an alert.
- Reporting: automated generation of Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs) based on monitoring outputs, filed with FinCEN or equivalent national FIU.
Wallet developers building on Spark face a specific design consideration: Spark's self-custodial architecture means users hold their own keys, so compliance tooling must integrate at the application layer rather than relying on custodial controls. The wallet application becomes the compliance enforcement point, making RegTech API integration choices a core architectural decision rather than an afterthought. Developers can explore the Spark SDK documentation for guidance on building compliant wallet experiences on top of self-custodial infrastructure.
Emerging Trends in Crypto Compliance Technology
On-Chain Identity and Verifiable Credentials
The Persona-Chainlink partnership launched in May 2026 represents a shift toward portable, on-chain identity: verifiable credentials issued after KYC verification that can be reused across applications and blockchains without re-running identity checks. This verify-once model could reduce onboarding friction and compliance costs simultaneously. Sumsub launched a similar initiative in March 2025 with Binance through the Sumsub ID program, enabling attestation-based onboarding.
AI-Powered Compliance Automation
Elliptic launched an AI-powered copilot for compliance analysts in April 2025 that reduces alert review time by automating the triage of low-risk alerts. Sardine is investing in agentic AI for autonomous compliance workflows: systems that can investigate alerts, gather context, and draft SARs without human intervention. The trajectory is toward compliance systems that handle routine cases autonomously while escalating genuinely suspicious activity to human analysts.
Cross-Chain Analytics
As users move assets across chains through bridges and atomic swaps, compliance tools must trace flows holistically. Elliptic's June 2025 Data Fabric update extended coverage across 60+ chains and 250+ bridges. Chainalysis automatically onboards new chains and tokens following widely adopted standards. The ability to trace a transaction from Bitcoin through a bridge to Ethereum and back is becoming table stakes for enterprise analytics platforms.
Choosing the Right Stack
The right compliance stack depends on three factors: the jurisdictions you operate in, your custody model, and your transaction volume. A stablecoin payment app serving US customers needs different tooling than a global exchange supporting dozens of assets across the EU and APAC.
For companies building on self-custodial infrastructure, the compliance burden shifts from platform-level controls to application-level integration. This makes the choice of analytics API, KYC provider, and travel rule solution more consequential: these tools become the primary compliance enforcement mechanism, not a supplement to custodial controls.
The RegTech market is consolidating rapidly, with 23 acquisitions in the sector through June 2026 alone. Vendors are expanding into adjacent layers: analytics companies adding KYC, KYC companies adding on-chain screening, and travel rule specialists building sanctions checking. The boundaries between layers are blurring, but specialization still matters for the most demanding compliance requirements.
For further reading on how travel rule compliance applies specifically to stablecoin transfers, or how VASP licensing requirements vary by jurisdiction, see our dedicated research articles on each topic.
This article is for educational purposes only. It does not constitute financial or investment advice. Bitcoin and Layer 2 protocols involve technical and financial risk. Always do your own research and understand the tradeoffs before using any protocol.

