CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Digital Asset AML and Sanctions: BDO's Best Practices for Firms

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Digital Asset AML and Sanctions: BDO'sBest Practices for Firms

Regulatory pressure on digital asset compliance is no longer a background concern. The US Securities and Exchange Commission and the Department of Justice are both sharpening their enforcement posture toward cryptocurrency exchanges and investment holders, and BDO's advisory practice has responded with a framework of best practices that accounting firms, auditors, and CFOs should treat as an operational baseline, not an aspirational checklist. At the center of that framework is a direct challenge: the same blockchain properties that make digital assets efficient also give bad actors meaningful tools to obscure the origin, ownership, and movement of funds.

Digital Asset AML and Sanctions: BDO's Best Practices for Firms

Why Digital Assets Complicate AML and Sanctions Programs

Traditional AML programs were built around financial intermediaries: banks, brokers, and payment processors that sit between counterparties and collect identifying information. Digital assets disrupt that model in several ways.

Pseudonymity and Decentralization

Blockchain addresses are not inherently tied to legal identities. A wallet address reveals nothing about who controls it unless additional on-chain or off-chain intelligence is layered on top. Combined with the decentralized nature of many networks, this means a transaction can settle in minutes across borders without a single intermediary having full visibility of the counterparty chain.

Speed and Global Reach

Cryptocurrency transactions can clear globally in seconds. The speed that makes blockchain attractive for legitimate cross-border payments is the same speed that allows layering strategies to move funds through multiple wallets before a compliance team has even generated an alert. Stablecoins, which are now achieving scale in both retail and institutional markets, add a further dimension: they combine the near-instant settlement of crypto with a value peg that removes volatility risk, making them a practical vehicle for moving large sums efficiently.

Volume and Data Complexity

A single blockchain can record millions of transactions per day. The raw volume of on-chain data that is relevant to a firm's customer base, whether directly through exchange accounts or indirectly through counterparties that hold digital assets, quickly exceeds what manual review teams can process. BDO's guidance is explicit: firms must exploit that data through automated tools rather than rely on sample-based or periodic reviews.

The Regulatory Backdrop: SEC, DOJ, and a Shifting Landscape

BDO notes that both the SEC and the DOJ have intensified enforcement activity targeting digital asset exchanges and investment holders. That dual-agency posture is significant for compliance teams because it means exposure can arise on two distinct tracks: securities law violations and criminal money laundering or sanctions evasion charges. Firms that treat digital assets as a niche product category rather than a mainstream compliance obligation are therefore carrying unpriced risk on both tracks simultaneously.

The broader regulatory landscape is also evolving. Bitcoin ETF approvals have drawn institutional capital into the space, raising the stakes for firms that service asset managers, fund administrators, or corporate treasuries with digital asset holdings. Stablecoin adoption is accelerating in cross-border payments, and regulators globally are moving to bring stablecoin issuers and distributors within formal AML perimeters. For context on how enforcement can follow quickly when those perimeters are breached, the case study of how sanctions and blockchain analytics collapsed a ruble stablecoin is instructive.

BDO's Core Best Practices for AML and Sanctions Programs

The guidance consolidates into several interdependent pillars. Each one has direct implications for how accounting firms structure client onboarding, how CFOs design internal controls, and what digital asset accounting software needs to support.

Continuous Reassessment of Direct and Indirect Exposure

BDO's first recommendation is that firms continually reassess their exposure to digital assets, both directly, through products and accounts they offer, and indirectly, through counterparties, correspondent relationships, and investment portfolios. This is not a point-in-time exercise. The asset class is evolving quickly: a corporate client that held no crypto two years ago may now hold a stablecoin treasury position, and a payment processor may have quietly added crypto off-ramps. Exposure mapping needs to be embedded in the annual risk assessment cycle and triggered by material changes in the client base or product mix.

Automated Customer Due Diligence

Manual CDD processes cannot scale to the data demands of digital asset compliance. BDO calls specifically for automated CDD tools that can ingest on-chain data alongside traditional identity and beneficial ownership information. For accounting firms running client onboarding workflows, this means integrating blockchain analytics outputs into the risk-scoring model at the point of onboarding, not as an afterthought. For CFOs, it means ensuring that the firm's compliance technology stack is capable of handling the data formats and volumes that blockchain intelligence vendors produce.

Sanctions Screening with Blockchain Intelligence

Name-and-address screening against OFAC's SDN list is necessary but not sufficient when the counterparty is a wallet address. Firms need screening tools that can match wallet addresses against sanctions designations, identify addresses that have transacted with designated entities, and flag indirect exposure through tainted transaction histories. The importance of that capability is illustrated by OFAC's recent actions, including the designation of wallets linked to a Hamas financing network, covered in our analysis of OFAC's sanctions action against a Hamas financing network.

Transaction Monitoring Calibrated to Crypto Behavior

Standard transaction monitoring scenarios, built for bank transfers and card payments, do not translate directly to blockchain activity. On-chain patterns that indicate layering, such as rapid pass-through transactions across multiple wallets, use of privacy-enhancing protocols, or conversion through decentralized exchanges, require monitoring rules and machine-learning models trained on crypto-specific typologies. BDO's view is that the volume and complexity of blockchain data make automated monitoring not just preferable but essential. Firms that are still relying on periodic manual reviews of digital asset activity are operating with a material gap.

Intelligence Gathering and Analysis

BDO frames the blockchain's public and immutable record not only as a compliance challenge but as an intelligence asset. Every transaction leaves a trace. Firms that invest in tools and skills to analyze that trace, tracing fund flows, identifying clustering patterns, and correlating on-chain activity with off-chain intelligence, have a structural advantage in both detecting suspicious activity and defending their compliance posture to regulators. Crypto accounting software that integrates transaction-level blockchain data, rather than only summarized balances, is a prerequisite for this kind of analysis.

Accounting and Audit Implications

For accounting firms and auditors, the BDO framework has implications that reach beyond the compliance function into financial reporting and audit methodology.

Client Risk Classification and Onboarding

Firms that advise or audit clients with digital asset exposure need to classify those clients at an appropriate risk tier from the outset. That classification should feed into the scope of audit procedures, the depth of beneficial ownership verification, and the frequency of transaction monitoring review. Digital asset accounting software used in the engagement must be capable of pulling transaction-level data directly from on-chain sources, so that the audit trail is grounded in primary blockchain data rather than client-prepared summaries.

Internal Controls Assessment for CFOs

CFOs carrying digital assets on the balance sheet, whether as treasury holdings, collateral, or customer deposits, need to satisfy themselves that the firm's internal controls cover the full AML and sanctions risk surface. That means asking whether the controls documentation addresses wallet screening, transaction monitoring thresholds calibrated to digital assets, and a clear escalation path when a sanctions alert fires. For firms operating across multiple jurisdictions, the controls framework also needs to account for divergent regulatory requirements: FATF guidance, FinCEN rules, EU AML directives, and bilateral sanctions regimes do not always align neatly.

Forward-Looking Risk: An Increasing Threat Environment

BDO is explicit that the risk of digital assets being used to facilitate money laundering and circumvent sanctions is expected to increase. Stablecoin growth is a particular watch point: as stablecoin volumes rise, so does their attractiveness for sanctions evasion, because they offer the liquidity and transferability of fiat currency with the pseudonymity characteristics of crypto. Firms that are building out stablecoin-related services, or that audit clients doing so, should treat BDO's framework as a floor, not a ceiling, for their compliance design.

Digital Asset AML and Sanctions: BDO's Best Practices for Firms

What Accounting Firms and CFOs Should Do Now

Translating the BDO framework into concrete action steps means prioritizing three areas in the near term. First, conduct an exposure mapping exercise that captures both direct and indirect digital asset risk, including any client or counterparty relationships that have evolved since the last formal risk assessment. Second, audit the technology stack: confirm that CDD, sanctions screening, and transaction monitoring tools are capable of ingesting and analyzing blockchain data at the required volume and frequency. Third, review the calibration of existing monitoring scenarios against crypto-specific typologies, and close any gaps before the next regulatory examination cycle.

Firms that are early in building their digital asset compliance capability should also look at how the regulatory framework is developing internationally. The FATF's targeted updates on virtual asset service providers, the EU's MiCA licensing wave, and ongoing DOJ and SEC enforcement in the US are all converging toward a world where digital asset AML compliance is a standard expectation, not an advanced specialty. Getting the infrastructure in place now, including the right crypto accounting software to support transaction-level analysis, reduces the cost and disruption of catching up later.

Source: BDO Insights

Frequently Asked Questions

Why are digital assets considered high-risk for AML and sanctions compliance?

Blockchain transactions are pseudonymous, borderless, and settle within seconds. Those properties make it easier for bad actors to move funds across jurisdictions without a traditional financial intermediary capturing full counterparty information, creating gaps that standard AML controls are not designed to close.

What does automated customer due diligence look like for a firm with crypto-exposed clients?

It means integrating on-chain data, such as wallet activity and transaction histories from blockchain analytics tools, into the CDD risk-scoring model at onboarding, alongside standard identity and beneficial ownership checks. The goal is a risk score that reflects both traditional and blockchain-specific red flags from day one of the client relationship.

How should sanctions screening differ for digital asset clients compared to traditional clients?

In addition to name-and-address matching against published sanctions lists, firms need to screen wallet addresses directly against OFAC and equivalent designations, and identify addresses that have transacted with designated wallets, even indirectly. This requires blockchain analytics capability that goes beyond standard sanctions screening software.

What role does crypto accounting software play in AML compliance?

Effective crypto accounting software should pull transaction-level data directly from blockchain sources, enabling both accurate financial reporting and the kind of granular transaction history that AML monitoring and audit procedures require. Software that only aggregates balances is insufficient for either purpose in a robust compliance environment.

How should CFOs approach the growing stablecoin risk flagged by BDO?

CFOs should treat stablecoin holdings and payment flows as a distinct risk category within their AML controls framework, applying wallet screening and transaction monitoring rules calibrated to stablecoin-specific patterns. They should also monitor regulatory developments, since stablecoin-specific AML requirements are being introduced across multiple jurisdictions and the compliance baseline is rising quickly.

USGLOBALGeneral#stablecoinsEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Huione Guarantee: $11B USDT Marketplace and the AML Obligations It Creates
AML/KYC & Licensing
Huione Group: World's Largest Illicit Marketplace and the USDH Stablecoin Risk
AML/KYC & Licensing
FBI vs Huione Group: The $134B Illicit Marketplace Case
AML/KYC & Licensing
US Sanctions Iran's Strait of Hormuz Bitcoin Insurance Scheme: What Accounting Firms and CFOs Must Act On Now