FinCEN and Crypto: The Rules Every Exchange Follows

Current Status
  • Coverage: custodial exchanges, hosted wallets, and kiosk operators are money services businesses — verified Jul 27, 2026
  • Registration: FinCEN filing, renewed every two calendar years; not a license — verified Jul 27, 2026
  • Travel rule: information and recordkeeping obligations at the $3,000 threshold — verified Jul 27, 2026
  • Developer status: non-custodial software generally outside money transmitter treatment, on guidance — verified Jul 27, 2026
  • State layer: separate money transmitter licensing required in most states — verified Jul 27, 2026

Before any question about securities or commodities arises, a crypto business that holds or moves other people’s value must register with FinCEN, build an anti-money-laundering program, and comply with the travel rule. This is the oldest and least negotiable layer of American crypto regulation, and the one that decides which platforms can legally serve you.

Who is a money services business

The governing definition is functional, not technological. Federal regulation defines a money transmitter as a person accepting currency, funds, or other value that substitutes for currency from one person and transmitting it to another, and agency guidance from 2019 applied that definition to convertible virtual currency in detail.

Under that framework, FinCEN treats custodial exchanges, hosted wallet providers, and crypto kiosk operators as money services businesses. Administrators and exchangers of convertible virtual currency are covered when they accept and transmit value. The test turns on control and on the acceptance-and-transmission of value for others, which is why the analysis in ambiguous cases — decentralized applications, front-end operators, payment processors — focuses on who actually holds and moves the assets.

The obligation attaches to the activity, not to registration status. A business meeting the definition without registering is not outside the regime; it is operating in violation of it, and unlicensed money transmission is a federal crime independent of anything specific to crypto. Our legality page covers that as one of the genuine prohibitions in American crypto law, and our money transmitter guide explains the concept in full.

What compliance requires

Registration is the beginning and not the end, and the requirements are specific.

Registration. Covered businesses file with FinCEN and renew every two calendar years, maintaining a current agent list. This is registration, not licensing: no approval is granted, and no authority reviews the business before it operates. State money transmitter licensing, which does involve approval, layers on top and is covered on our legality page.

The anti-money-laundering program. A written, risk-based program is mandatory, built on four elements: policies, procedures, and internal controls; a designated compliance officer; ongoing training for relevant staff; and independent review at a frequency proportionate to the business’s risk.

Recordkeeping and the travel rule. For transmittals at or above the $3,000 threshold, covered institutions must collect and retain specified information and ensure required originator and beneficiary details accompany the transfer to the next institution. Travel rule violations have historically been among the most commonly cited findings in examinations of crypto money transmitters, and the operational difficulty is real, since counterparty institutions must be identified and information exchanged securely at transaction speed.

Reporting and screening. Suspicious activity reports, currency transaction reports where applicable, and sanctions screening against Treasury designations complete the program. Sanctions compliance is separately administered and carries strict liability, meaning intent is not a defense.

Examinations for crypto money services businesses are generally conducted by the Internal Revenue Service on FinCEN’s behalf, which is a detail many new entrants discover late.

Where the line sits

The most consequential question in this area is what falls outside the definition, and the answer has moved toward clarity without yet becoming law.

Agency guidance has distinguished between persons who accept and transmit value and persons who merely write or publish software. A developer creating a communication or network tool has generally not been treated as a money transmitter, while the owner or operator of an application that receives and sends value on users’ behalf may be. Federal policy direction has reinforced that boundary, with the administration’s digital-asset working group recommending that travel rule implementation be harmonized without treating non-custodial software as a financial intermediary.

That is guidance and policy, not statute, which is the recurring theme across this hub: what an agency interprets, a later agency can reinterpret. Anyone building non-custodial infrastructure should treat the current position as favorable and provisional, and should document the absence of custody and control carefully, because that documentation is the entire defense.

The business models, mapped

The agency’s 2019 guidance on convertible virtual currency remains the foundational document, and its value is that it walks through business models individually instead of stating a principle and leaving firms to apply it. The mapping below reflects that framework and the supervisory practice built on it.

Custodial exchanges are money transmitters without ambiguity. They accept customer assets, hold them, and transmit value on instruction, which is the definition. Every licensed American trading platform operates on this basis.

Hosted wallet providers are covered on the same reasoning where the provider holds keys and can move assets. The distinction from self-custody wallet software is control: a wallet the provider can spend from is a custodial service, and a wallet only the user can spend from generally is not.

Kiosk operators — the crypto ATM industry — are money services businesses, and this category deserves attention disproportionate to its size because it has generated an outsized share of enforcement and consumer harm. Machines that exchange cash for digital assets sit at the intersection of anonymity, urgency, and vulnerable users, and they have become a favored channel for fraud targeting older adults, prompting state licensing regimes, transaction limits, and refund requirements alongside federal obligations.

Payment processors and merchant services handling digital assets are generally covered where they accept and transmit value, though narrow exemptions exist for processors operating under specific conditions.

Decentralized applications are the hard case. Guidance distinguishes between publishing software and operating a service: where a decentralized application receives and sends value, its owners or operators may be money transmitters, while a developer writing code that others run generally is not. In practice the analysis follows control, and the centralized access points to decentralized systems — hosted front ends and fiat on-ramps — are far likelier to trigger obligations than the underlying protocols.

Mining pools and validators have generally not been treated as money transmitters where they are compensated for computational or validation services and not for accepting and transmitting customer value, though structures vary and the analysis is fact-specific.

Peer-to-peer exchangers are covered when they conduct exchange as a business, and this has been a recurring enforcement category: individuals running informal exchange operations, sometimes at meaningful volume, without any registration, have faced federal prosecution for unlicensed money transmission.

Sanctions, and why they are different

Alongside the Bank Secrecy Act sits a separate regime administered by Treasury’s Office of Foreign Assets Control, and it is the one obligation in this area that carries no comfort for good intentions.

Sanctions compliance operates on strict liability. Transacting with a designated person, entity, or jurisdiction is a violation regardless of knowledge or intent, which distinguishes it sharply from anti-money-laundering obligations built around risk-based programs and reasonable effort. For crypto businesses the practical requirement is screening: addresses against designation lists, customers against sanctioned parties, and jurisdictions against embargo programs, continuously and at transaction speed.

The application to blockchain infrastructure has been among the most contested questions in the field. Treasury has designated addresses and, in one prominent instance, a mixing protocol itself, raising the question of whether immutable software can be a sanctioned entity, a matter subsequently litigated with consequences that reshaped the debate. The current federal posture leans toward targeting persons and entities that control infrastructure instead of software as such, consistent with the broader direction on non-custodial developers, but the underlying strict-liability exposure for anyone transacting with designated addresses is unchanged.

The practical instruction for businesses is that sanctions screening cannot be risk-based in the way an anti-money-laundering program can. There is no acceptable failure rate.

Mixing, privacy, and the special measures question

One proceeding has hung over privacy infrastructure for years and remains unresolved in ways that matter.

FinCEN proposed a rule identifying international convertible virtual currency mixing as a class of transaction of primary money laundering concern, which would impose heightened recordkeeping and reporting on covered financial institutions dealing with mixing activity. The mechanism, drawn from a section of the anti-money-laundering statutes permitting special measures against classes of transactions, is powerful precisely because it reaches an activity category, not named parties.

The industry’s objection has never been that mixing cannot be abused, since it demonstrably is, but that a class-wide designation captures privacy-preserving activity indistinguishable from ordinary financial confidentiality, and that the compliance burden falls on institutions with no practical means of distinguishing them. The counterargument from enforcement is that mixing exists substantially to defeat exactly the tracing that the Bank Secrecy Act framework depends on.

For readers, the status is what matters: the proposal exists, the underlying authority is real, and any business touching mixing-adjacent activity should treat the regulatory direction as unsettled and unfavorable. Privacy tooling occupies the sharpest edge of American crypto compliance, and it is the area where the gap between what is legal and what is practically operable is widest.

What examinations look for

Compliance obligations become concrete at examination, and knowing what examiners actually test is more useful than any summary of the rules.

Examinations of crypto money services businesses are generally conducted by the Internal Revenue Service on FinCEN’s behalf, which surprises firms expecting a banking regulator. Examiners test the program against its own terms: whether the written policies exist and match actual practice, whether the designated compliance officer has authority and resources, whether training occurred and is documented, and whether the independent review was genuinely independent and its findings addressed.

On transactions, the recurring findings cluster in predictable places. Travel rule failures — meaning required originator and beneficiary information not collected or not transmitted on covered transfers — have historically been the most commonly cited category. Suspicious activity reporting is tested for both quality and timeliness, with under-reporting and mechanical over-reporting both drawing criticism. Customer identification programs are tested against the firm’s own stated procedures. And recordkeeping is tested simply by asking for records.

The pattern worth internalizing is that examiners rarely fault a firm for having chosen a reasonable risk-based approach. They fault firms for not following the approach they wrote down, which means the most common compliance failure in this industry is not a bad program but an unimplemented one.

The state layer on top

Federal registration is necessary and rarely sufficient, and the omission of this point is the single most common error in crypto compliance planning.

Most states require money transmitter licensing separately, with their own application processes, surety bond requirements, net worth minimums, examination regimes, and reporting. New York’s regime is the strictest and effectively a separate approval for virtually any crypto business activity touching its residents. The practical consequence is that a well-funded platform serving the United States nationally holds federal registration plus dozens of state licenses, with the licensing budget and compliance headcount that implies, which is precisely the burden that makes the federal trust charter route covered on our OCC page commercially attractive.

The pending market-structure legislation would preempt conflicting state regimes for covered assets and intermediaries, narrowing but not eliminating the patchwork, a change our implementation guide covers among the bill’s immediate effects. Until then, the working assumption for any business plan should be that both layers apply.

What to watch

The developer exclusion’s fate. The pending bill’s provision excluding non-custodial software from money transmitter treatment is among the most contested in the negotiation, with law enforcement interests pressing against its scope. Whether it survives, and in what form, determines the legal position of every builder of non-custodial infrastructure in the United States.

The mixing rule. The proposed special measures on convertible virtual currency mixing remains outstanding. Finalization in anything close to its proposed form would impose new obligations on institutions touching mixing-adjacent flows and would sharpen the compliance position of privacy tooling considerably.

Travel rule harmonization. Federal policy direction has called for harmonizing implementation without treating non-custodial software as an intermediary. Concrete guidance implementing that direction would be the most practically useful development for compliance teams in this area, and its absence is a live cost.

State preemption. If market-structure legislation passes, the extent to which it displaces state money transmitter licensing for covered activity determines whether the dual-layer burden described above narrows meaningfully or persists largely intact.

The compliance build, in order

For a business determining what it must do, the sequence matters as much as the list, and the order below reflects how firms that pass examination actually sequence the work.

Determine coverage first. The threshold question is whether the business accepts and transmits value for others, and the answer drives everything downstream. This is a legal determination worth obtaining in writing from qualified counsel before building anything, because a wrong answer at this step invalidates every decision that follows and unlicensed money transmission is a federal crime.

Register, then license. Federal registration with FinCEN is a filing, quick to complete and renewed biennially. State licensing is an approval process measured in months per state, with bonds and net worth requirements attached, and it is the actual constraint on when a platform can serve customers in a given jurisdiction. Firms routinely underestimate this timeline by a factor of two.

Build the program before launch, not after. The four required elements — written policies and internal controls, a designated compliance officer with genuine authority, training, and independent review — must exist as operating practice. Examiners test the program against itself, and the most common finding in this industry is a well-drafted program that the business does not actually follow.

Instrument the transaction layer. Travel rule data collection and transmission at the threshold, sanctions screening at transaction speed, suspicious activity monitoring with defensible thresholds, and recordkeeping that can produce records on request. These are engineering requirements as much as legal ones, and retrofitting them into a live platform is materially harder than building them in.

Assume both layers apply. Federal registration and state licensing are cumulative, not alternative, and planning that treats one as sufficient produces the most expensive category of compliance failure: a business that has launched, acquired customers, and must then stop serving them.

Pending Legislation

The market-structure bill before the Senate contains a provision excluding non-custodial software developers from money transmitter treatment under the Bank Secrecy Act, which would convert the current interpretive position into law. That provision operates by force of statute rather than requiring rulemaking, meaning it would take effect immediately upon the law taking effect, a point our implementation guide covers among the bill’s self-executing elements. It has been among the most heavily contested provisions in the negotiation, with law enforcement interests opposing its scope. This section will be updated when the Senate acts.


Sources

  1. 31 CFR 1010.100(ff) — money transmitter definition (accessed Jul 27, 2026)
  2. 31 CFR 1022.380 — MSB registration requirements (accessed Jul 27, 2026)
  3. 31 CFR 1010.410(e) and (f) — recordkeeping and travel rule (accessed Jul 27, 2026)
  4. FinCEN Guidance FIN-2019-G001: Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies (accessed Jul 27, 2026)

Recent Updates

  • Jul 27, 2026 — Page launched with status strip, body content, 8 FAQs, and pending legislation tracker

Legal Disclaimer: This content is for informational purposes only and does not constitute legal or investment advice. Laws and regulations change frequently; verify current status with primary sources.


Frequently Asked Questions

Does FinCEN regulate cryptocurrency?

It regulates businesses that handle it. FinCEN administers the Bank Secrecy Act and treats custodial exchanges, hosted wallet providers, and crypto kiosk operators as money services businesses, subject to registration, anti-money-laundering program requirements, recordkeeping, the travel rule, suspicious activity reporting, and sanctions screening. It does not regulate individuals holding or trading their own assets.

Is FinCEN registration the same as a license?

No. Registration is a filing renewed every two calendar years, with no approval process and no authority reviewing the business beforehand. State money transmitter licensing, required in most states in addition to federal registration, does involve an approval process, which is why platform availability varies by state.

What is the travel rule?

A Bank Secrecy Act requirement that specified originator and beneficiary information accompany covered transmittals at or above the $3,000 threshold, alongside recordkeeping obligations at the same level. It applies to crypto transfers handled by covered institutions and is among the most frequently cited compliance failures in examinations of crypto money transmitters.

Are software developers money transmitters?

Generally not, where they do not accept and transmit value. Agency guidance distinguishes between publishing software and operating a service that receives and sends value on users’ behalf, and current federal policy direction supports keeping non-custodial software outside the definition. That position rests on guidance rather than statute, and pending legislation would codify a version of it.

Who examines crypto businesses for compliance?

Examinations of money services businesses are generally conducted by the Internal Revenue Service on FinCEN’s behalf, with FinCEN and the Department of Justice handling enforcement. Sanctions compliance is administered separately by Treasury’s Office of Foreign Assets Control and carries strict liability.

Are crypto ATMs regulated?

Yes. Kiosk operators are money services businesses subject to the full federal framework, and most states add their own licensing. The category has drawn attention disproportionate to its size because machines exchanging cash for digital assets have become a favored channel for fraud targeting older adults, prompting transaction limits, disclosure mandates, and refund requirements in several states.

How do sanctions obligations differ from anti-money-laundering rules?

Sanctions compliance carries strict liability, meaning a transaction with a designated person or jurisdiction is a violation regardless of knowledge or intent. Anti-money-laundering obligations are risk-based and judged on reasonable program design and execution. The practical difference is that sanctions screening has no acceptable failure rate, while an anti-money-laundering program is assessed on whether it was sensibly designed and actually followed.

What do examiners most commonly find?

Failures to follow the firm’s own written program. Travel rule deficiencies — meaning required information not collected or transmitted on covered transfers — are historically the most cited category, followed by suspicious activity reporting quality and timeliness, customer identification gaps, and recordkeeping. Examiners rarely fault a reasonable risk-based approach; they fault programs that exist on paper and not in practice.

← Back to US Regulation