Compliance · Crypto

Crypto Compliance & Certification

A crypto licence opens the door; compliance evidence is what gets you through it. Banks, EMIs, exchanges and institutional clients all ask for the same file — ISO 27001, SOC 2, an audited AML programme. We build it and run the audits.

2
SOC 2 report types: Type I (design) · Type II (operating over time)
3-yr
ISO 27001 cycle with annual surveillance
1
goal: pass counterparty diligence the first time
Not sure what your counterparties will ask for? Tell us who you need to onboard with — we'll map the exact certificates and evidence they'll request, free.
Scoping call →

overview

What you actually need.

Licensed crypto businesses hit the same wall right after authorisation: counterparty diligence. Banks and EMIs ask for an audited AML programme and security evidence before opening accounts; exchanges and custodians ask for ISO 27001 or SOC 2 before listing or integrating; institutional clients send diligence questionnaires that a licence alone doesn't answer. The licence proves you may operate — this file proves you operate properly.

The instruments are three. ISO/IEC 27001 — the information-security management certificate, issued by accredited bodies on a three-year cycle, the default ask from EU counterparties. SOC 2 — an attestation report (Type I on control design, Type II on controls operating over an observation period), issued by CPA firms, the default ask from US counterparties. And the AML layer: a real AML/CFT programme — policies, Travel-Rule flow, screening and monitoring tooling — plus the independent AML audit that VASP/CASP regimes and banks increasingly require.

As with our certification work in gaming: we are not an audit firm and not a certification body — accredited bodies and CPA firms issue. We do the part that consumes teams: the gap analysis, the programme and ISMS build, evidence collection, auditor selection and engagement, and the dialogue to a clean report — then the banking-onboarding file that packages it all for account applications.

Diligence is the productEvery serious counterparty — bank, EMI, exchange, fund — runs the same checklist. One prepared file answers all of them.
ISO for the EU, SOC 2 for the USEU counterparties default to ISO 27001; US ones to SOC 2. Which you need first depends on who you're onboarding with.
AML audit is becoming standardVASP/CASP regimes and banking partners increasingly expect an independent AML review, not just a policy PDF.

your options

The routes that work.

01ISO/IEC 27001

The security-management certificate EU banks, exchanges and enterprise clients ask for — accredited-body issued, three-year cycle, annual surveillance.

02SOC 2 Type I / Type II

The US-market attestation: Type I proves control design, Type II proves controls operating over months. CPA-firm issued; the report institutional US counterparties expect.

03AML programme + audit

Policies, Travel-Rule flow, screening/monitoring tooling — built properly, then independently audited, then packaged into the banking-onboarding file.

head to head

The compliance stack at a glance

InstrumentWhat it provesWho asks for itCycle
ISO/IEC 27001Security management systemEU banks · exchanges · enterprise clients3 years + annual surveillance
SOC 2 Type IControl design at a point in timeUS counterparties — the entry reportPoint-in-time
SOC 2 Type IIControls operating over timeUS institutions — the serious askObservation window, renewed annually
Independent AML auditAML/CFT programme actually worksBanks · EMIs · VASP/CASP regulatorsTypically annual
Banking-onboarding packThe whole file, bank-shapedEvery account applicationMaintained continuously

requirements

Eligibility & docs.

Gap analysis against the target instrument(s) — prices everything downstream
Counterparty mapping: who you must satisfy in the next 12 months
Scope statement: systems, custody architecture, data flows
Auditor/body shortlist matched to your markets
AML/CFT programme: policies, risk assessment, Travel-Rule flow
Screening & transaction-monitoring tooling selection and setup
ISMS build for ISO / control set for SOC 2 (we draft, you own)
Internal dry-run before any external auditor looks
Accredited body (ISO) or CPA firm (SOC 2) engagement
Evidence collection and audit-dialogue management to issuance
Independent AML audit coordination
Banking-onboarding file: the certificates + programme, packaged for account applications
Check my eligibility →

step by step

From product to licence.

  1. DiscoveryYour licence(s), custody model and the counterparties you need — we map which instruments unlock them and in what order.Day 1
  2. Gap analysisFixed-fee assessment against the target instruments — exact scope, sequence and cost before you commit.Week 1–2
  3. BuildAML programme, ISMS/controls, tooling — built to pass, not to decorate a data room.Weeks–months by scope
  4. AuditAccredited body, CPA firm or AML auditor engaged; we run evidence and dialogue to a clean report.Auditor-dependent
  5. Onboard & maintainBanking files out, surveillance and renewals calendared — the evidence stays current as you grow.Ongoing

Want the shortlist for your exact product?

Tell us your product, target markets and payment mix — we'll confirm the route that gets you live fastest at the lowest all-in cost, with the number itemised.

Get my quote →

costs

What it costs.

Regulator fee schedules
Gap analysisfixed fee, scoped on the call
Certification body fees (ISO)quoted by the accredited body
CPA firm fees (SOC 2)firm-quoted per scope
Independent AML auditauditor-quoted per scope
Our build & management feefixed-scope after gap analysis

Auditor and body fees depend on scope, so we don't publish flat figures — after the gap analysis you get a fixed-scope estimate for the whole path. Reports and certificates are issued by accredited bodies and CPA firms; we build, prepare and manage.

go deeper

Jurisdictions & related services.

FAQ

Do we need ISO 27001 or SOC 2?

Usually whichever your counterparties default to: EU banks and exchanges ask for ISO 27001; US institutions ask for SOC 2. Growing firms often end up with both — the control work overlaps heavily, so sequencing them together is cheaper than doing them twice.

Do you issue the certificates or reports?

No — ISO certificates come from accredited certification bodies and SOC 2 reports from CPA firms; independent AML audits from qualified auditors. We build the programme, prepare the evidence and manage the engagement to a clean result.

What AML evidence do regulators actually require?

VASP/CASP regimes require a real AML/CFT programme — policies, risk assessment, Travel-Rule handling, screening and monitoring — and increasingly an independent review of it. Banks ask for the same file before opening accounts, which is why we build it once, bank-shaped.

How long does SOC 2 take?

Type I — as fast as the controls are genuinely in place. Type II — requires an observation window of several months with controls operating, plus the audit. If you need something on paper quickly, the standard path is Type I first, Type II at the next cycle.

Will this get us a bank account?

It's the biggest controllable factor — most crypto banking rejections cite compliance evidence, not the licence. We package the certificates and programme into the onboarding file banks actually read. No honest adviser guarantees an approval; we make the file as strong as it can be.

other products

Licensing a different product?

Reviewed by the Vantegris licensing team. This page is general information, not legal advice. Fee schedules and timelines mirror our jurisdiction pages and change when regulators change them.

Proven track record
300+ operators licensed across 40+ jurisdictions.

From crypto casinos to B2B platform providers, operators trust Vantegris to move fast without cutting compliance corners.

Itemised feesRegulator schedule shown separately from our service fee.
We stay after issuanceRenewals, reporting and banking, handled long-term.
NDA on requestConfidential from the first message.

Free consultation

Start your licence file.

Tell us the product — we'll map the licence, banking and structure that gets it live. Free, confidential, no obligation — most enquiries get a reply within 24 hours.

Book a free consult Book a call