Compliance · Crypto
Crypto Compliance & Certification
A crypto licence opens the door; compliance evidence is what gets you through it. Banks, EMIs, exchanges and institutional clients all ask for the same file — ISO 27001, SOC 2, an audited AML programme. We build it and run the audits.
overview
What you actually need.
Licensed crypto businesses hit the same wall right after authorisation: counterparty diligence. Banks and EMIs ask for an audited AML programme and security evidence before opening accounts; exchanges and custodians ask for ISO 27001 or SOC 2 before listing or integrating; institutional clients send diligence questionnaires that a licence alone doesn't answer. The licence proves you may operate — this file proves you operate properly.
The instruments are three. ISO/IEC 27001 — the information-security management certificate, issued by accredited bodies on a three-year cycle, the default ask from EU counterparties. SOC 2 — an attestation report (Type I on control design, Type II on controls operating over an observation period), issued by CPA firms, the default ask from US counterparties. And the AML layer: a real AML/CFT programme — policies, Travel-Rule flow, screening and monitoring tooling — plus the independent AML audit that VASP/CASP regimes and banks increasingly require.
As with our certification work in gaming: we are not an audit firm and not a certification body — accredited bodies and CPA firms issue. We do the part that consumes teams: the gap analysis, the programme and ISMS build, evidence collection, auditor selection and engagement, and the dialogue to a clean report — then the banking-onboarding file that packages it all for account applications.
your options
The routes that work.
The security-management certificate EU banks, exchanges and enterprise clients ask for — accredited-body issued, three-year cycle, annual surveillance.
The US-market attestation: Type I proves control design, Type II proves controls operating over months. CPA-firm issued; the report institutional US counterparties expect.
Policies, Travel-Rule flow, screening/monitoring tooling — built properly, then independently audited, then packaged into the banking-onboarding file.
head to head
The compliance stack at a glance
| Instrument | What it proves | Who asks for it | Cycle |
|---|---|---|---|
| ISO/IEC 27001 | Security management system | EU banks · exchanges · enterprise clients | 3 years + annual surveillance |
| SOC 2 Type I | Control design at a point in time | US counterparties — the entry report | Point-in-time |
| SOC 2 Type II | Controls operating over time | US institutions — the serious ask | Observation window, renewed annually |
| Independent AML audit | AML/CFT programme actually works | Banks · EMIs · VASP/CASP regulators | Typically annual |
| Banking-onboarding pack | The whole file, bank-shaped | Every account application | Maintained continuously |
requirements
Eligibility & docs.
step by step
From product to licence.
- DiscoveryYour licence(s), custody model and the counterparties you need — we map which instruments unlock them and in what order.Day 1
- Gap analysisFixed-fee assessment against the target instruments — exact scope, sequence and cost before you commit.Week 1–2
- BuildAML programme, ISMS/controls, tooling — built to pass, not to decorate a data room.Weeks–months by scope
- AuditAccredited body, CPA firm or AML auditor engaged; we run evidence and dialogue to a clean report.Auditor-dependent
- Onboard & maintainBanking files out, surveillance and renewals calendared — the evidence stays current as you grow.Ongoing
Want the shortlist for your exact product?
Tell us your product, target markets and payment mix — we'll confirm the route that gets you live fastest at the lowest all-in cost, with the number itemised.
costs
What it costs.
Auditor and body fees depend on scope, so we don't publish flat figures — after the gap analysis you get a fixed-scope estimate for the whole path. Reports and certificates are issued by accredited bodies and CPA firms; we build, prepare and manage.
go deeper
Jurisdictions & related services.
FAQ
Do we need ISO 27001 or SOC 2?
Usually whichever your counterparties default to: EU banks and exchanges ask for ISO 27001; US institutions ask for SOC 2. Growing firms often end up with both — the control work overlaps heavily, so sequencing them together is cheaper than doing them twice.
Do you issue the certificates or reports?
No — ISO certificates come from accredited certification bodies and SOC 2 reports from CPA firms; independent AML audits from qualified auditors. We build the programme, prepare the evidence and manage the engagement to a clean result.
What AML evidence do regulators actually require?
VASP/CASP regimes require a real AML/CFT programme — policies, risk assessment, Travel-Rule handling, screening and monitoring — and increasingly an independent review of it. Banks ask for the same file before opening accounts, which is why we build it once, bank-shaped.
How long does SOC 2 take?
Type I — as fast as the controls are genuinely in place. Type II — requires an observation window of several months with controls operating, plus the audit. If you need something on paper quickly, the standard path is Type I first, Type II at the next cycle.
Will this get us a bank account?
It's the biggest controllable factor — most crypto banking rejections cite compliance evidence, not the licence. We package the certificates and programme into the onboarding file banks actually read. No honest adviser guarantees an approval; we make the file as strong as it can be.
other products
Licensing a different product?
Reviewed by the Vantegris licensing team. This page is general information, not legal advice. Fee schedules and timelines mirror our jurisdiction pages and change when regulators change them.
Free consultation
Start your licence file.
Tell us the product — we'll map the licence, banking and structure that gets it live. Free, confidential, no obligation — most enquiries get a reply within 24 hours.