AML and KYC Compliance for Crypto Companies in Kazakhstan

Anti-money laundering and know-your-customer requirements have become one of the central regulatory issues for crypto businesses operating in Kazakhstan. The traditional AML model was designed around banks, payment institutions and other intermediaries that operate through identifiable accounts and conventional financial infrastructure. Crypto businesses operate differently. A customer may be identified through a passport and corporate documents, while the actual movement of value takes place through pseudonymous blockchain addresses, smart contracts, bridges, decentralised protocols and self-custodied wallets.

This creates a fundamental compliance problem.

A crypto company cannot demonstrate effective AML compliance merely by proving that it collected a customer’s identification document. It increasingly needs to establish a defensible connection between the customer, beneficial owner, source of funds, wallet, transaction, counterparty and risk profile.

Kazakhstan’s regulatory environment makes this particularly important because crypto businesses can encounter more than one regulatory layer. AIFC participants whose activities are subject to financial monitoring are required to comply with Kazakhstan’s AML/CFT legislation as well as the AIFC AML/CFT and Sanctions Rules. AFSA also identifies KYC/CDD, transaction monitoring, risk management, employee screening, training and independent audit as components of the AML control framework.

The compliance analysis therefore begins not with the question “What KYC documents should we collect?” but with a more fundamental question:

What exactly is the company doing, who is regulating that activity, and what AML risks arise from the particular crypto business model?

The regulatory perimeter: why “crypto company” is not a sufficient legal category

There is no single AML compliance model suitable for every crypto business.

An exchange, custodian, OTC broker, issuer, payment business, trading platform and technology provider may have materially different regulatory exposures. The first stage of legal analysis should therefore be an activity-by-activity assessment.

For example, an AIFC Digital Asset Trading Facility is defined by reference to a facility that regularly brings together multiple parties for contracts involving the purchase, sale or exchange of digital assets for fiat, another digital asset or a commodity under non-discretionary rules. AFSA separately identifies custody and money-services activities within its regulated framework.

This matters for AML because the regulatory perimeter determines the company’s obligations, supervisory authority, governance requirements and the nature of controls that should be implemented.

A practical classification should therefore ask:

  • Does the company operate a trading venue?
  • Does it execute trades for customers?
  • Does it hold or control customer assets?
  • Does it provide custody?
  • Does it arrange custody?
  • Does it exchange digital assets for fiat?
  • Does it transfer digital assets?
  • Does it issue digital assets?
  • Does it provide brokerage or dealing services?
  • Does it facilitate P2P transactions?
  • Does it provide technology without handling customer assets?
  • Does it operate through the AIFC or elsewhere in Kazakhstan?
  • Does it provide services to Kazakhstan residents from another jurisdiction?

The answer can materially change the AML analysis.

AFSA’s current authorisation materials expressly list Operating a Digital Asset Trading Facility as a regulated activity, alongside Providing Custody, Arranging Custody and Providing Money Services.

The first compliance document for a crypto company should therefore arguably be a regulatory-perimeter memorandum, rather than an AML policy.

Kazakhstan’s national AML regime and the AIFC framework

One of the most important issues for an AIFC crypto business is understanding that the AIFC framework should not automatically be treated as a substitute for Kazakhstan’s national AML legislation.

AFSA’s own AML FAQ states that AIFC participants whose activities are subject to financial monitoring must comply with both the Kazakhstan Law on AML/CFT and the AIFC AML/CFT and Sanctions Rules.

This creates a two-layer compliance environment.

The national framework provides the statutory AML/CFT obligations applicable to relevant financial-monitoring subjects. Article 5 of Kazakhstan’s AML law requires financial-monitoring subjects to conduct proper due diligence of customers, their representatives and beneficial owners.

The AIFC framework adds a detailed supervisory architecture. AFSA expects internal AML documents to address, among other matters:

  • AML compliance governance;
  • business and customer risk assessment;
  • KYC/CDD;
  • transaction monitoring and review;
  • employee training;
  • Know Your Employee procedures; and
  • independent audit.

For an AIFC crypto company, the correct approach is therefore not to choose whichever framework appears less burdensome. The company should map the requirements across both regimes and identify the highest applicable standard for each control.

That is particularly important where a company’s AML policy is prepared from a generic international template. A document can be FATF-compatible and still fail to address a specific Kazakhstan or AIFC requirement.

Who is actually subject to financial monitoring?

The phrase “crypto company” should never be used as the legal conclusion.

The correct analysis is whether the particular entity and its activities fall within the applicable definition of a subject of financial monitoring and, separately, whether the activity requires authorisation or registration under the relevant digital-asset framework.

This distinction becomes important for businesses that combine several activities.

Consider a company that:

  • develops a crypto exchange;
  • provides hosted wallets;
  • converts digital assets into fiat;
  • performs OTC transactions;
  • and provides institutional settlement.

Calling the business a “technology company” does not resolve the regulatory analysis. The legal character of the activities must be examined individually.

The same principle applies to outsourcing. A company cannot necessarily avoid its own compliance responsibilities simply because identification is performed by a third-party KYC provider or blockchain analytics company.

A useful internal test is:

Business activity → regulated activity → customer relationship → asset/control relationship → transaction function → applicable AML regime → responsible compliance function.

This sequence is much more reliable than starting with the company’s corporate registration documents.

KYC is more than collecting identification documents

Customer due diligence is the foundation of an AML programme.

Under Kazakhstan’s AML framework, due diligence extends to the customer, the customer’s representative and the beneficial owner. It is therefore not sufficient to establish only the identity of the person who creates an account.

For an individual, the compliance process may include:

  • full legal name;
  • date of birth;
  • nationality;
  • residence;
  • identification document;
  • identification-document verification;
  • tax or other relevant identification information where applicable;
  • occupation or business activity;
  • expected account activity;
  • source of funds;
  • source of wealth where appropriate;
  • sanctions and PEP screening;
  • adverse-media assessment; and
  • information necessary to establish the customer’s risk profile.

For a legal entity, the analysis becomes substantially more complex.

The company may need to establish:

  • legal existence;
  • registered address;
  • business activities;
  • ownership structure;
  • control structure;
  • directors;
  • authorised representatives;
  • beneficial owners;
  • source of corporate funds;
  • expected transaction activity;
  • countries in which the business operates;
  • counterparties;
  • and the purpose and expected nature of the relationship.

The key distinction is between identity verification and risk understanding.

A passport answers the question “Who is this person?”

It does not answer:

“Why is this person moving USD 20 million of stablecoins through our platform?”

That second question is the core of risk-based AML.

The crypto-specific KYC problem: identity plus blockchain activity

Traditional financial institutions can generally understand a customer’s financial behaviour through bank accounts, payment instructions and counterparties.

Crypto businesses receive another category of information: blockchain data.

A transaction may reveal:

  • a wallet address;
  • blockchain network;
  • transaction hash;
  • amount;
  • timestamp;
  • smart-contract interaction;
  • receiving address;
  • sending address;
  • token;
  • bridge interaction;
  • decentralised exchange interaction; and
  • historical transaction relationships.

The blockchain address, however, is not automatically an identity.

This produces an important compliance principle:

Wallet attribution is an analytical conclusion, not an identity document.

A crypto company’s compliance team should therefore distinguish between:

Known customer identity

and

Known or attributed blockchain address

and

Observed transaction behaviour

and

Inferred counterparty risk.

These are four different evidentiary categories.

A robust AML investigation should record which category supports each conclusion.

Beneficial ownership in crypto businesses

Beneficial ownership is particularly difficult in the crypto sector because ownership and control can be separated.

A company may have:

  • conventional shareholders;
  • nominee arrangements;
  • holding companies;
  • trusts;
  • foundations;
  • venture-capital investors;
  • token-based governance;
  • founders with disproportionate voting rights;
  • or individuals exercising practical control without majority legal ownership.

The compliance team should therefore distinguish ownership from control.

In a crypto company, practical control may arise through:

  • voting rights;
  • board appointment rights;
  • contractual arrangements;
  • control of treasury wallets;
  • control of administrative keys;
  • multisignature arrangements;
  • smart-contract upgrade rights;
  • or governance mechanisms.

The more technologically complex the business, the less reliable a simple shareholder percentage analysis can become.

This is particularly relevant to DAOs and decentralised governance arrangements, where the legal person operating the regulated business may not correspond neatly to the individuals exercising effective economic or technical control.

Customer risk assessment

A crypto AML programme should not assign risk solely according to customer nationality or transaction size.

A more useful risk model combines several dimensions.

Customer risk

Consider:

  • nationality and residence;
  • occupation;
  • business activity;
  • PEP status;
  • sanctions exposure;
  • adverse media;
  • corporate ownership;
  • source of wealth;
  • source of funds;
  • complexity of ownership;
  • expected transaction profile.

Product risk

Consider:

  • spot trading;
  • derivatives where permitted;
  • custody;
  • OTC;
  • fiat conversion;
  • stablecoins;
  • token issuance;
  • transfers;
  • P2P trading;
  • DeFi exposure;
  • cross-chain transactions.

Geographic risk

Consider:

  • customer’s residence;
  • incorporation jurisdiction;
  • source of funds;
  • destination of funds;
  • counterparty jurisdiction;
  • high-risk jurisdictions;
  • sanctioned jurisdictions.

Transaction risk

Consider:

  • amount;
  • frequency;
  • velocity;
  • unusual patterns;
  • rapid deposits and withdrawals;
  • multiple counterparties;
  • chain hopping;
  • use of bridges;
  • interaction with high-risk addresses;
  • unexplained changes in behaviour.

Blockchain risk

Consider:

  • wallet history;
  • exposure to sanctioned addresses;
  • ransomware indicators;
  • darknet exposure;
  • scams and fraud;
  • mixers;
  • privacy-enhancing technologies;
  • suspicious clustering;
  • indirect exposure.

The most useful risk-scoring model is not necessarily the one with the largest number of variables.

It is the one that allows the compliance officer to answer:

Why was this customer classified as high risk, and what additional control does that classification trigger?

A risk score without a corresponding control is largely meaningless.

Enhanced due diligence for high-risk customers

Enhanced due diligence should not mean simply asking the customer for more documents.

It should address the specific risk that caused the customer to become high risk.

For example, if the concern is source of wealth, EDD may require:

  • audited financial statements;
  • tax records;
  • sale agreements;
  • investment documentation;
  • corporate records;
  • bank statements;
  • or other independent evidence.

If the concern is wallet exposure, EDD may instead require:

  • explanation of wallet ownership;
  • explanation of transaction purpose;
  • proof of control over the wallet;
  • details of counterparties;
  • source-of-funds documentation;
  • and additional blockchain analysis.

This leads to an important principle:

EDD should resolve a risk hypothesis rather than merely increase the quantity of paperwork.

Transaction monitoring in a blockchain environment

Transaction monitoring is where crypto AML differs most dramatically from traditional banking.

A bank may monitor transactions based on account activity, beneficiary, amount, country and payment message.

A crypto company may need to monitor the same customer across multiple chains and wallets.

Relevant scenarios can include:

  • unusually rapid deposits and withdrawals;
  • repeated transactions just below internal thresholds;
  • multiple customer accounts linked to common wallets;
  • unexplained third-party funding;
  • rapid conversion between assets;
  • circular transactions;
  • chain hopping;
  • bridge activity;
  • mixer exposure;
  • ransomware exposure;
  • sanctions exposure;
  • darknet exposure;
  • unusual interaction with newly created wallets;
  • sudden changes in transaction velocity;
  • high-risk P2P activity;
  • unexplained movements between corporate and personal wallets.

The important point is that no individual indicator necessarily proves money laundering.

For example, a customer using a bridge is not inherently suspicious.

A customer using a bridge, immediately transferring funds through multiple chains, interacting with a high-risk wallet and then withdrawing to an unrelated third-party account is a different proposition.

The compliance system should therefore evaluate combinations of indicators.

Blockchain analytics should support, not replace, human investigation

Blockchain analytics can be extremely powerful, but it is not infallible.

A blockchain analytics platform may attribute an address to a particular service or risk category. That attribution is an analytical output and should be treated accordingly.

The compliance team should consider:

  • confidence level;
  • age of the attribution;
  • source of the attribution;
  • clustering methodology;
  • false-positive risk;
  • intermediary transactions;
  • exchange-controlled addresses;
  • shared infrastructure;
  • and whether the customer’s explanation is consistent with the blockchain evidence.

A robust case file should distinguish:

What the blockchain proves

from

What the analytics provider infers

from

What the customer states

from

What the compliance officer concludes.

That distinction can become extremely important during regulatory examination or litigation.

Travel Rule compliance

The Travel Rule is one of the most important AML issues for businesses transferring virtual assets.

FATF’s framework applies Recommendation 16 requirements to relevant virtual-asset transfers and requires the transmission of specified originator and beneficiary information. FATF continues to identify implementation of the Travel Rule as a major area of regulatory development.

By July 2026, FATF reported that 83% of surveyed jurisdictions had legislation implementing the Travel Rule, with further jurisdictions working toward implementation.

For a crypto company, Travel Rule compliance should therefore be treated as an operational system rather than a paragraph in an AML policy.

The system should address:

  • identifying the originator;
  • identifying the beneficiary;
  • collecting required information;
  • transmitting information;
  • receiving information;
  • identifying the counterparty VASP where applicable;
  • handling missing information;
  • handling incompatible counterparties;
  • retaining records;
  • escalation;
  • and deciding when a transaction should be delayed, rejected or investigated.

A Travel Rule message that exists technically but is not connected to the transaction-monitoring system is of limited practical value.

The ideal architecture links:

Customer → wallet → transaction → Travel Rule message → counterparty VASP → screening result → transaction decision.

Unhosted and self-custodied wallets

Self-custodied wallets present one of the most difficult AML questions.

The central problem is simple:

A regulated crypto company may know its customer, but it may not know the person controlling the other wallet.

FATF’s current materials recognise that transfers involving unhosted wallets create specific risks and that jurisdictions have adopted different approaches. FATF states that VASPs should collect required originator and beneficiary information when dealing with their customer and an unhosted wallet and should apply appropriate risk-based mitigation.

A risk-based framework can consider:

  • whether the customer can demonstrate control over the wallet;
  • whether the wallet has meaningful transaction history;
  • whether it is linked to high-risk activity;
  • whether the transaction is consistent with the customer’s profile;
  • whether the source of funds is explainable;
  • whether the wallet has exposure to sanctions or illicit activity;
  • whether the transaction is unusually large;
  • and whether the customer has repeatedly used multiple unexplained wallets.

A critical compliance distinction should be maintained:

Self-custody is not itself evidence of criminal activity.

The risk arises from the combination of self-custody with other indicators.

Sanctions, PEP and blockchain screening

Crypto screening should operate on multiple levels.

Customer screening

Screen:

  • customers;
  • beneficial owners;
  • representatives;
  • directors;
  • authorised persons.

Counterparty screening

Where relevant, identify and assess:

  • counterparties;
  • VASPs;
  • intermediaries;
  • payment providers.

Wallet screening

Assess:

  • direct sanctions exposure;
  • indirect exposure;
  • illicit-service exposure;
  • ransomware;
  • darknet;
  • scams;
  • stolen funds;
  • mixers;
  • and other relevant risk indicators.

Transaction screening

A transaction should be considered in context rather than assessed solely through the customer’s name.

The difficult cases involve indirect exposure.

For example, if a customer’s wallet received funds that passed through a sanctioned address several transactions earlier, the correct response is not necessarily automatic account closure.

The compliance question becomes:

  • How direct is the exposure?
  • How recent is it?
  • What amount was involved?
  • What is the customer’s explanation?
  • Does the transaction fit the customer’s normal activity?
  • Does the wallet interact repeatedly with the relevant cluster?
  • Is there evidence of intentional concealment?

This is where automated screening should trigger investigation rather than automatically determine the legal conclusion.

Suspicious transaction reporting

A suspicious transaction report should be the result of a documented compliance process.

The company should be able to demonstrate:

Alert → investigation → evidence → analysis → conclusion → reporting decision.

The investigation file should record:

  • why the alert was generated;
  • relevant customer information;
  • transaction history;
  • wallet analysis;
  • counterparties;
  • source-of-funds information;
  • customer explanations;
  • sanctions/PEP screening;
  • analyst findings;
  • compliance officer reasoning;
  • escalation;
  • and final decision.

There is an important distinction between:

“The transaction looks unusual.”

and:

“After reviewing the customer’s profile, transaction history, wallet exposure and explanation, the compliance team identified circumstances giving rise to a reasonable suspicion.”

The second is a defensible compliance conclusion.

The first is merely an alert.

Kazakhstan’s recent digital-asset AML developments

Kazakhstan’s AML framework is continuing to evolve specifically around digital assets.

In April 2026, the Financial Monitoring Agency published amendments concerning the rules for submitting information on transactions subject to financial monitoring and indicators of suspicious transactions and customer activity. The amended indicator specifically addresses transactions involving digital assets and digital-asset wallets associated with unlawful activity, with the amendment entering into force on 1 May 2026.

This development is important because it reinforces the idea that blockchain activity is not merely an additional source of technical data. It is becoming directly incorporated into Kazakhstan’s suspicious-activity framework.

There is also a broader regulatory development around the identification of digital-asset wallets associated with illicit purposes. Kazakhstan’s 2026 implementation materials refer to work on rules for a unified register of digital-asset wallets used for money laundering, terrorist financing, proliferation financing and/or other criminal purposes.

For compliance teams, this creates a practical reason to ensure that wallet intelligence is integrated into the AML framework rather than maintained separately by the technical department.

AML obligations for digital financial asset issuers

The AML analysis should not be limited to exchanges and custodians.

In April 2026, Kazakhstan’s Agency for Regulation and Development of the Financial Market adopted requirements for internal-control rules addressing AML/CFT/PF obligations for specified issuers of digital financial assets and issuers of financial instruments issued electronically on a digital financial asset platform.

This is significant because the issuer’s risk profile can differ from that of a trading platform.

An issuer may need to consider:

  • investors;
  • purchasers;
  • beneficial owners;
  • distribution arrangements;
  • transfer restrictions;
  • underlying assets;
  • payment flows;
  • redemption;
  • secondary-market activity;
  • and transaction monitoring.

The regulatory framework for digital financial assets is therefore developing alongside, rather than independently from, the AML framework.

AML controls for transfers of backed digital assets

Kazakhstan has also continued to refine the framework for transfers of backed digital assets.

The Financial Monitoring Agency’s 2026 amendments to the rules for transfers of backed digital assets require relevant persons to ensure accurate information concerning the sender and recipient, maintain systems and controls for monitoring and identifying reportable and suspicious activity, and implement procedures for identifying, assessing, monitoring and mitigating AML/CFT/PF risks relating to services, customers and transactions.

This illustrates an increasingly important regulatory direction:

Digital-asset transfer rules are becoming integrated with AML controls rather than treated as purely technical settlement rules.

P2P crypto transactions

P2P activity creates additional compliance complexity because the ultimate counterparty may not be another regulated institution.

AFSA currently states that regulated P2P trading is permitted on AIFC-licensed Digital Asset Trading Facilities and describes requirements including KYC/AML procedures and controlled settlement mechanisms.

For P2P businesses, AML monitoring should pay particular attention to:

  • repeated counterparties;
  • rapid turnover;
  • third-party bank accounts;
  • inconsistent names;
  • chargeback patterns;
  • unusual fiat payment descriptions;
  • transaction fragmentation;
  • high-volume retail accounts;
  • and wallet reuse across multiple customers.

The combination of fiat-side and blockchain-side analysis is essential.

A P2P transaction should not be assessed solely by looking at the blockchain transaction.

The compliance team should ideally connect:

fiat payer → platform customer → blockchain wallet → crypto recipient → counterparty → subsequent movement.

OTC crypto businesses

OTC businesses face a different set of AML risks.

The customer relationship may involve relatively few but very large transactions. The absence of conventional exchange order-book activity can make transaction monitoring more difficult.

An OTC AML programme should place particular emphasis on:

  • customer identity;
  • beneficial ownership;
  • source of wealth;
  • source of funds;
  • expected transaction size;
  • settlement instructions;
  • third-party payments;
  • wallet ownership;
  • counterparties;
  • transaction purpose;
  • and post-settlement behaviour.

A large transaction is not inherently suspicious.

The real compliance issue is whether the transaction is economically and legally coherent with the customer’s profile.

DeFi, bridges and smart contracts

Decentralised finance creates a difficult question for AML law:

Who is the customer when there is no conventional intermediary?

A regulated crypto business interacting with DeFi may encounter:

  • smart contracts;
  • decentralised exchanges;
  • liquidity pools;
  • bridges;
  • governance tokens;
  • automated market makers;
  • protocol-controlled wallets;
  • and pseudonymous counterparties.

FATF continues to identify DeFi arrangements, unhosted wallets, P2P activity and stablecoins as areas requiring attention in the virtual-asset AML framework. Its July 2026 update also highlights increasing risks associated with stablecoins, P2P transactions through unhosted wallets, offshore VASPs and DeFi arrangements.

The compliance response should not be “DeFi equals prohibited.”

Instead, the company should determine:

  • what role it is actually playing;
  • whether it is facilitating the transaction;
  • whether it controls customer assets;
  • whether it knows the customer;
  • what information is available about the counterparty;
  • what blockchain risk indicators exist;
  • and whether the transaction falls within the company’s risk appetite.

Privacy technologies, mixers and privacy-enhancing tools

Privacy-enhancing technology presents another area where AML policies can easily become overbroad.

The mere use of a privacy-enhancing technology does not necessarily establish criminal intent.

However, repeated interaction with services designed to obscure transaction provenance can materially increase the difficulty of establishing source and destination of funds.

The correct approach should therefore distinguish:

technology risk

from

customer risk

from

transaction risk

from

evidence of illicit activity.

A risk-based policy might require enhanced due diligence for certain forms of exposure rather than automatically terminating every relationship involving privacy technology.

Crypto-to-crypto transactions

Crypto AML controls often focus excessively on crypto-to-fiat transactions.

That is a mistake.

A customer can move value entirely within the digital-asset ecosystem:

BTC → ETH → stablecoin → bridge → another chain → decentralised exchange → self-custody wallet → another VASP.

No bank transfer may occur.

Nevertheless, the economic activity can involve substantial movement of value.

A transaction-monitoring system should therefore be capable of following the economic path of assets across chains where technically feasible.

The compliance challenge is not necessarily to trace every satoshi or token unit forever. It is to identify whether the observed sequence is consistent with the customer’s legitimate economic purpose.

Outsourcing KYC and blockchain analytics

Crypto businesses increasingly rely on specialised providers for:

  • identity verification;
  • sanctions screening;
  • blockchain analytics;
  • Travel Rule messaging;
  • adverse-media screening;
  • transaction monitoring;
  • and compliance case management.

This can improve the quality of controls, but it does not automatically transfer regulatory responsibility.

The company should establish:

  • what the vendor actually performs;
  • what data the vendor uses;
  • how often data is refreshed;
  • what happens when the vendor is unavailable;
  • how false positives are handled;
  • who owns the final compliance decision;
  • how vendor performance is tested;
  • and how records are retained.

The crucial principle is:

A vendor’s compliance certification is not a substitute for the regulated firm’s own control environment.

The regulated entity should be capable of explaining why a particular vendor output was accepted, rejected or escalated.

AML governance and the role of the MLRO

AML compliance must have clear ownership.

For an AIFC digital-asset business, AFSA’s current materials identify an organisational structure including designated individuals such as a Compliance Officer and MLRO, as well as broader governance and control requirements. AFSA also lists AML policies, compliance manuals, compliance monitoring and risk-management policies among the expected organisational documents for a Digital Asset Trading Facility.

A functioning AML programme should clearly allocate responsibilities among:

  • board;
  • senior management;
  • MLRO;
  • compliance;
  • risk;
  • operations;
  • customer support;
  • legal;
  • technology;
  • cybersecurity;
  • and internal audit.

Technology teams should not independently decide whether a customer is suspicious.

Likewise, compliance teams should not be expected to operate blockchain infrastructure without appropriate technical support.

The strongest model is interdisciplinary.

Know Your Employee

Employee risk is often overlooked.

AFSA specifically identifies high-standard employee screening and Know Your Employee procedures as part of its AML internal-control expectations.

This becomes particularly important in crypto businesses because employees may have privileged access to:

  • customer information;
  • wallets;
  • private-key infrastructure;
  • withdrawal systems;
  • transaction-monitoring systems;
  • sanctions controls;
  • administrative accounts;
  • and trading systems.

Employee AML controls may therefore include:

  • pre-employment screening;
  • sanctions screening;
  • conflict-of-interest checks;
  • access controls;
  • segregation of duties;
  • privileged-access monitoring;
  • periodic rescreening;
  • and escalation mechanisms.

Recordkeeping and the evidentiary trail

Recordkeeping should not be treated as an administrative obligation.

It should be designed around the question:

Could the company reconstruct and explain its AML decision six years later?

Depending on the applicable regime, the compliance archive may need to preserve:

  • identification documents;
  • verification evidence;
  • beneficial ownership information;
  • risk assessments;
  • source-of-funds documentation;
  • source-of-wealth documentation;
  • wallet addresses;
  • transaction records;
  • blockchain analytics;
  • sanctions-screening results;
  • Travel Rule messages;
  • alerts;
  • investigation files;
  • customer explanations;
  • STR/TTR decisions;
  • and internal approvals.

AFSA’s AML FAQ states that relevant records under its framework, including KYC/CDD, transaction, reporting and risk-assessment materials, are generally subject to a six-year retention period.

For blockchain businesses, preserving only the transaction hash is unlikely to be sufficient.

The company should also preserve the context in which the transaction was analysed.

Blockchain intelligence changes over time. An address classified as low risk today may receive a different attribution tomorrow.

A defensible archive should therefore preserve the compliance evidence and analytical basis available at the time the decision was made.

What a defensible crypto AML programme looks like

The most useful way to evaluate a crypto AML programme is to follow a transaction from beginning to end.

A defensible process should be capable of connecting:

Customer

→ identity verification

→ beneficial owner

→ risk classification

→ source of funds/wealth

→ expected activity

→ wallet identification

→ transaction

→ blockchain analysis

→ counterparty

→ sanctions screening

→ Travel Rule data

→ alert

→ investigation

→ compliance decision

→ reporting

→ record retention.

If one of these links is completely disconnected from the others, the AML programme may exist formally while remaining weak operationally.

A practical crypto AML case study

Consider a Kazakhstan-based corporate customer that states that it operates a technology business and expects to transact up to USD 500,000 per month.

The customer passes ordinary KYC.

Several months later, the account receives USD 3 million equivalent in stablecoins from multiple external wallets.

The customer immediately transfers the assets across two blockchain networks and eventually sends the funds to another VASP.

An automated blockchain system identifies exposure to a wallet cluster associated with a high-risk service.

A weak AML programme might simply generate an alert and close the account.

A stronger programme would investigate.

The compliance team should ask:

  • Who owns the sending wallets?
  • Are they connected to the customer?
  • Why did the transaction volume increase six-fold?
  • What is the source of the funds?
  • What commercial activity generated the funds?
  • Why were multiple chains used?
  • Why was a bridge used?
  • Who is the ultimate beneficiary?
  • What is the customer’s relationship with the high-risk wallet?
  • Is the exposure direct or indirect?
  • What does the customer say?
  • Does independent evidence support that explanation?
  • Is the transaction consistent with the customer’s business?
  • Does the transaction create reasonable grounds for suspicion?

The final decision should then be based on the complete evidentiary picture rather than one blockchain-risk label.

This is the difference between automated AML and risk-based AML.

The future of crypto AML in Kazakhstan

The direction of regulation is increasingly clear.

Crypto AML is moving away from a model based primarily on customer identification toward a model combining:

identity + ownership + transaction + wallet intelligence + counterparty information + behavioural analysis.

Internationally, FATF’s July 2026 update highlights persistent implementation gaps despite substantial progress in regulating VASPs and implementing the Travel Rule. It also identifies organised crypto-enabled fraud, stablecoins, unhosted-wallet P2P activity, offshore VASPs and DeFi as growing or continuing areas of concern.

Kazakhstan’s regulatory developments similarly show increasing attention to suspicious digital-asset transactions, digital-asset wallets and internal AML controls for digital financial asset issuers.

For crypto companies, the implication is straightforward:

AML cannot remain a PDF policy sitting inside the legal department.

It has to be embedded into the architecture of the business.

Customer onboarding, wallet infrastructure, transaction processing, blockchain analytics, Travel Rule messaging, sanctions screening, case management and reporting should ultimately operate as components of one compliance system.

For Kazakhstan crypto companies, AML/KYC compliance is no longer adequately described as a process of obtaining passports, corporate documents and beneficial-owner information.

The regulatory challenge is broader.

A compliant crypto business must be able to understand who its customer is, who ultimately controls that customer, where the customer’s money comes from, how the customer is expected to use the platform, which wallets are connected to the relationship, who the counterparties are, how transactions move across blockchain networks and why particular activity is or is not suspicious.

The strongest AML programme is therefore not the one with the longest policy.

It is the one that can produce a coherent evidentiary chain:

“We know who this customer is. We know who controls it. We understand its expected activity. We understand the source of its funds. We can identify the relevant wallets and counterparties. We monitor the customer’s behaviour. We investigate anomalies. We document our reasoning. And we can demonstrate why the final compliance decision was reasonable.”

That is the standard against which crypto AML programmes should increasingly be designed.

This article is for general informational purposes and should be adapted to the specific licensing status, business model and applicable Kazakhstan/AIFC requirements of the relevant crypto company. Kazakhstan’s digital-asset and AML framework is evolving, so the applicable legislation, subordinate regulations and AFSA requirements should be checked at the time of implementation.

Syuzanna Li

Syuzanna Li

Partner (Central Asia Desk)

Syuzanna heads the Astana and Tashkent offices. She has advised financial investors and corporate clients on a wide range of matters, including M&A, joint ventures, restructuring. Syuzanna has also particular experience in the energy sector.

View LinkedIn Profile
Other blog posts
Regulatory challenges for blockchain startups in Kazakhstan

Read Article

Read Article

Patent Registration in Kazakhstan: Procedure, Costs, Timelines and Strategic Considerations

Read Article

Read Article

Copyright Protection Under Kazakh Law (detailed guide)

Read Article

Read Article

Filing Trademarks Through National vs. International Routes: A Strategic Guide for Businesses in Kazakhstan

Read Article

Read Article

Stay Ahead in Cross-Border Law

Concise updates on India, China, Russia & Central Asia — regulatory shifts, deal trends, and compliance alerts. No spam, unsubscribe anytime.