Five Companies Share Best Practices for Developing Risk-Based Compliance Programs for Crypto Products

Matt Van Buskirk
Co-Founder & CEO, Regulatory
(Note: this conversation originally appeared on the Blockdata Blog)

Alongside Caitlin Barnett from Chainalysis, four additional executives from the RegTech ecosystem joined in the discussion to offer their perspectives.

  • Marc Temple, Global Development Director of RiskNarrative at LexisNexis Risk Solutions, a data and analytics solution for financial crime risk management.
  • Matt Van Buskirk, co-founder and CEO at Hummingbird, a platform for customer knowledge, case management, investigations, and regulatory reporting.
  • Lana Schwartzman, Head of Regulatory and Compliance at Notabene, the first crypto pre-transaction decision-making platform.
  • Peter Singer, Deputy CCO and BSA/AML Officer at Fireblocks, a digital asset management suite and blockchain development platform for businesses.

Note: Responses have been edited and condensed for clarity.

Blockdata: How can risk assessment criteria identify, categorize, and prioritize the specific risk profiles of transactions, customers, and counterparties?

Caitlin Barnett, Chainalysis: A risk assessment is designed to incorporate relevant metrics and create a quantitative view as to how a company assesses its BSA/AML risk exposure. Common risk factors to take into account are geographic, customer, product/service, asset, transaction, and sanctions risks. For example, if a business were to offer a new product related to cryptocurrency, the business would need to evaluate all potential associated risks and identify what controls can be put in place to mitigate them.

Marc Temple, LexisNexis: Both regulated and unregulated businesses should be utilizing technology further to review and update their risk assessment criteria and continuously reassess risk profiles amidst new information and emerging trends. A 'single customer view' of risk and a unified score across KYC, Fraud, and AML allows businesses to understand their exposure more holistically and adapt as needed.

Matt Van Buskirk, Hummingbird: Have a strong marriage between your systems: KYC/EDD, Crypto forensics, Transaction Monitoring, and Compliance Case Management. The goal is to build a tech stack that allows for the streamlined, real-time flow of information across software.

Lana Schwartzman, Notabene: Crypto-specific risk assessments must go further than traditional financial compliance programs by analyzing transaction patterns, conducting thorough customer diligence and continuous monitoring, and updating based on regulatory developments. The Travel Rule – introduced by the Financial Action Task Force in 2019 – enables companies to reduce exposure to sanctions and illicit transactions.

Peter Singer, Fireblocks: As a starting point, the risk assessment must identify which products are offered, where, to whom, through which channel, and using what payment method.

Blockdata: How can organizations use technology solutions to streamline real-time monitoring and suspicious activity reporting?

Caitlin Barnett, Chainalysis: One of the unique features of Chainalysis is that our solutions enable our customers to conduct real-time monitoring. This allows compliance officers to quickly identify potential suspicious activity and promptly file suspicious activity reports.

Marc Temple, LexisNexis: Utilizing technology such as 'risk orchestration' provides a 360° view of risk across the customer lifecycle – onboarding, ongoing screening, on and off-ramp transaction monitoring, through to offboarding – helps optimize financial crime and fraud prevention efforts. Consolidating all information in one platform – where suspicious transactions and entities can be identified, reported, and mitigated.

Matt Van Buskirk, Hummingbird: Crypto provides much more – and more trackable – information than traditional financial systems. It's the opposite of a haven for crime and fraud.

Lana Schwartzman, Notabene: Technology solutions like Notabene's SafeTransact can streamline real-time pre-transaction monitoring and suspicious activity reporting.

Peter Singer, Fireblocks: Real-time monitoring can stop and prevent fraud or suspicious activity before it happens.

Blockdata: How can organizations ensure risk assessment and management practices align with industry best practices and regulatory expectations?

Caitlin Barnett, Chainalysis: Regulated financial institutions undergo annual AML audits which are conducted either by internal audit teams or third-party consulting firms.

Marc Temple, LexisNexis: Firms must ensure they can adapt quickly to remain compliant with constantly evolving regulations and differing jurisdictional obligations.

Matt Van Buskirk, Hummingbird: Utilizing the robust ecosystem of partner vendors available will support your creation of modern, tech-forward compliance practices.

Lana Schwartzman, Notabene: Embedding the Travel Rule within risk assessment processes strengthens sanctions programs, AML, and counter-terrorism financing frameworks by considering inherent risks and mitigation controls.

Peter Singer, Fireblocks: Independent, third-party BSA/AML program audits from firms specializing in those areas are crucial.

Blockdata: How can organizations stay informed about changing cryptocurrency regulations and implement timely updates?

Marc Temple, LexisNexis: As regulatory frameworks are released globally, ensure advisory both internally and externally to navigate obligations.

Matt Van Buskirk, Hummingbird: Several crypto trade associations and specialist podcasts cover the intersection between crypto, law, and politics.

Lana Schwartzman, Notabene: Leverage regulatory engagements, join industry groups and associations, and sign up for regulator bulletin boards for manual updates.

Peter Singer, Fireblocks: Joining groups such as the Blockchain Association and the MSB Association are great starting points.

Blockdata: How can organizations collaborate and share anonymized transaction data with industry peers to identify and combat potential risks?

Caitlin Barnett, Chainalysis: In the U.S., regulated entities can participate in 314(b) information sharing.

Marc Temple, LexisNexis: Collaboration is key, but so is data protection and privacy to ensure no personal identifying information is shared.

Matt Van Buskirk, Hummingbird: Blockchain can help create a true "mission first" infrastructure that allows for industry-wide sharing of secure and anonymized customer and transaction data while protecting privacy.

Peter Singer, Fireblocks: Anonymized transaction data isn't overly useful, and various laws regarding customer privacy exist that inhibit transparency.

Blockdata: How can compliance departments establish secure information-sharing channels with law enforcement and regulators?

Caitlin Barnett, Chainalysis: Many regulators have encouraged open dialogue with their licensed entities.

Matt Van Buskirk, Hummingbird: Law enforcement and regulators are most concerned with enforcing existing laws.

Lana Schwartzman, Notabene: Participating in specialized programs like the FinCEN Exchange and the Illicit Virtual Asset Notification (IVAN) platform.

Peter Singer, Fireblocks: Private sector partnerships are key for agencies to do their jobs, but compliance departments should understand that working with the government is an asymmetrical relationship.

Blockdata: How can organizations demonstrate their compliance commitment to potential banking partners, increasing the likelihood of successful onboarding and strong relationships?

Caitlin Barnett, Chainalysis: Banking partners want the assurance that compliance measures will be effectively implemented.

Matt Van Buskirk, Hummingbird: Treat compliance as a core necessity from the start, not an afterthought.

Lana Schwartzman, Notabene: Ensure full compliance with all relevant local, national, and international regulations.

Peter Singer, Fireblocks: Compliance teams play an integral role in banking relationships.

Blockdata: Which records and policies will regulators typically request to assess a compliance program's effective implementation?

Caitlin Barnett, Chainalysis: Regulators will request a number of different records and policies when assessing the effectiveness of a compliance program.

Marc Temple, LexisNexis: All regulated jurisdictions require provisions for KYC/identity verification during sign-ups and withdrawals.

Matt Van Buskirk, Hummingbird: Aside from traditional policy and procedure documents, crypto companies can provide context from blockchain data sources to support decisions for customer risk rating.

Lana Schwartzman, Notabene: Regulators review various policies and procedures, including risk assessments and suspicious activity reporting.

Peter Singer, Fireblocks: Banks will ask for your BSA AML KYC policy, OFAC compliance, anti-bribery and anti-corruption policy, and sometimes the resumes of your head of compliance and or BSA AML Officer.

Blockdata: How can compliance programs address the challenges of cross-border cryptocurrency transactions and varying international regulations?

Marc Temple, LexisNexis: Firms must use appropriate technology to determine customer locations and the regulatory framework their operations fall under.

Matt Van Buskirk, Hummingbird: Cross-border transactions present one of the largest challenges for financial crime prevention in traditional finance.

Lana Schwartzman, Notabene: Incorporating Travel Rule compliance mitigates these risks by adhering to various jurisdictional requirements.

Peter Singer, Fireblocks: As a non-exhaustive starting point, organizations need to have an effective KYC program in place.