Non-custodial design doesn’t automatically mean compliance-free. For a crypto swap, AML compliance depends on more than who holds the assets: the service’s role, control over transaction steps, and jurisdictions involved all matter. That’s why AML compliance for crypto swaps starts with a clear map of how a transaction works.
It can be difficult to assess responsibilities when a swap involves a business, an infrastructure provider, and other third parties. The product label alone won’t show who receives a user’s instruction, routes the order, or handles an issue. This guide explains how to map those responsibilities, compare custodial, non-custodial, and third-party models, and identify practical controls for your setup. It offers a framework for review, not a substitute for advice from qualified U.S. counsel.
You’ll learn how to document each transaction stage, assess partner and integration risks, and organize due diligence, monitoring, governance, and escalation. The aim is a consistent operating-model review that helps you identify the right legal questions and build controls around your actual role and transaction flows.
Key Takeaways
- Map each step of a swap, including who controls execution and interacts with users, before assessing potential AML responsibilities.
- Use activity, role, and jurisdiction to frame AML compliance for crypto swaps. Don’t rely on custodial or non-custodial labels alone.
- Compare operating models using the same criteria: custody, control, execution, user relationships, and third-party dependencies.
- Build a sequenced control framework, then assign owners for applicable checks, monitoring, escalation, records, and reporting.
- Assess infrastructure partners through documented transaction flows and control boundaries. Outsourcing a service doesn’t automatically transfer every responsibility.
Table of Contents
- AML compliance for crypto swaps starts with the transaction flow
- How US AML rules may apply to crypto swap businesses
- Custodial, non-custodial, and third-party swap models compared
- Build an AML control framework around each swap lifecycle
- Evaluate crypto swap infrastructure without outsourcing accountability
AML compliance for crypto swaps starts with the transaction flow
Start with what the service does, not what it’s called. AML compliance refers to the policies, controls, and reporting processes that may apply to an entity’s activities. For a crypto swap business, the assessment depends on the facts, the jurisdictions connected to those activities, and each entity’s role. “Non-custodial” describes an aspect of architecture. It doesn’t, by itself, settle a legal question.
Keep two tasks distinct: an operating model is a factual map of how a swap is offered, initiated, executed, settled, and supported; a legal determination assesses what rules apply to the entities performing those activities. The map gives qualified counsel a concrete basis for analysis without treating a product description as a regulatory conclusion.
What counts as a crypto swap service?
A service might exchange assets through its own transaction process, or provide an interface that routes a user’s order to a third-party provider. In either case, identify who displays the terms, receives the user’s instruction, selects or connects the execution venue, handles settlement steps, and answers user questions. A user may see one seamless swap even when several businesses perform different parts of the transaction.
Also distinguish a swap service from a cryptocurrency tumbler, which is designed to obscure the trail of funds. The Cryptocurrency tumbler reference describes that separate concept. Don’t assume that routing or exchanging assets makes a swap service a tumbler. Document the service’s actual function and transaction flow.
Which facts shape the AML assessment?
Map the transaction from the first customer interaction through post-transaction support. For each stage, record the responsible entity, information exchanged, decision rights, and assets or instructions handled. Note whether a business takes custody, can control or redirect assets, has discretion over execution, or relies on another provider. Also record which entity contracts with or communicates with the user, and where the relevant businesses and users are located.
These details help frame, but don’t answer, the legal questions. Ask qualified U.S. counsel to assess whether an entity’s activities bring it within relevant Bank Secrecy Act or FinCEN requirements, and whether state laws also apply. The analysis may differ by entity and service arrangement, even when the customer-facing experience looks identical.
- Map: Interface, order initiation, execution, settlement, and support.
- Assign: Each step to the entity that performs or controls it.
- Review: Custody, discretion, user relationships, third parties, and jurisdictions with counsel.
This record turns an abstract AML question into a reviewable operating picture. It also gives you a consistent factual basis for comparing service models.
How US AML rules may apply to crypto swap businesses
The transaction map is a starting point, not a legal conclusion. In the United States, the Bank Secrecy Act (BSA) and the Financial Crimes Enforcement Network (FinCEN) are central reference points for AML analysis. Their relevance to a particular business depends on what it actually does. A useful rule for review is: regulatory analysis turns on an entity’s activities and operating model, not its product label alone.
That distinction matters for AML compliance for crypto swaps. A business that executes or arranges transactions may raise different questions from one that supplies software or routes orders. But labels such as “decentralized,” “non-custodial,” or “technology provider” don’t independently establish an exemption. Ask qualified U.S. counsel to assess the specific activities against current federal and state requirements.
FinCEN and the BSA
FinCEN’s guidance on virtual currencies is a useful starting point for understanding how its regulations may apply to businesses involved in virtual-currency activity. Read it alongside current FinCEN materials and the facts of your service. General guidance isn’t a determination for every swap arrangement.
For each entity in the transaction flow, counsel should assess whether its activities raise questions about money-services-business classification and, if so, what registration, AML program, reporting, and recordkeeping requirements may apply. These are separate applicability questions, not automatic consequences of offering an API, operating an interface, or using non-custodial architecture. Record the rationale for the assessment and revisit it when the service or transaction flow changes.
State and cross-border review
Federal analysis is only one layer. State money-transmission laws and other applicable state requirements may need separate review, including how a business’s activities and user relationships connect to particular jurisdictions. Don’t assume that a federal analysis resolves state questions or that one state’s approach answers them all.
Cross-border activity adds another review track. Where applicable, assess sanctions obligations and screening expectations with qualified legal and compliance professionals, including whether OFAC requirements apply to the entities and activities involved. FATF recommendations can inform risk analysis and international standards, but they aren’t themselves binding U.S. law. Check the rules relevant to each jurisdiction and transaction rather than applying one country’s framework to every situation.
- Federal: Assess activity under current FinCEN and BSA materials.
- State: Identify jurisdictions that may have relevant licensing or other requirements.
- Cross-border: Review sanctions exposure and applicable foreign rules.
Once counsel has assessed the model, use that analysis to guide infrastructure diligence. Businesses comparing a non-custodial exchange API or other swap infrastructure should review current documentation and clarify which party performs each transaction function. Architecture informs the review; it doesn’t replace it.
Custodial, non-custodial, and third-party swap models compared
These models describe how a service is structured, not whether it meets a legal standard. For AML compliance for crypto swaps, compare the actual control points and responsibilities in each transaction. A custodial service may hold assets or control customer accounts. A non-custodial service may facilitate swaps without holding user funds. A third-party model may route orders or rely on an external provider for execution. Each arrangement calls for its own review.
How custody and control change the questions
Look beyond whether a business technically possesses assets. In a custodial model, examine who can access or move assets, authorize transactions, and manage customer accounts. In a non-custodial model, assess who controls the interface, routes orders, sets or presents terms, and facilitates the transaction. If a third party executes swaps, identify contractual roles, operational dependencies, and who owns user communications and escalation. For more architecture context, see the compliance benefits of non-custodial architecture.
| Model | Custody and control | Execution and user relationship | Third-party dependencies |
|---|---|---|---|
| Custodial | Determine whether the service holds assets or can access or move them. | Establish who authorizes execution and maintains the customer account or relationship. | Review external providers used for execution, custody, or operations. |
| Non-custodial | Confirm whether users retain control, and what transaction decisions the service can make. | Map who provides the interface, receives instructions, routes orders, and supports users. | Identify any infrastructure or execution partners and their precise roles. |
| Third-party execution | Clarify which party can access or direct assets at each step. | Document who accepts the user’s instruction, executes the swap, and communicates outcomes. | Assess contractual boundaries, service dependencies, and escalation ownership. |
A practical comparison framework
Assess each model against the same criteria: user experience, operational control, expected compliance workload, and partner dependence. Use a consistent rating scale, and place evidence and open questions beside every score. For example, a streamlined interface may improve the user journey while making it less obvious which entity receives instructions or handles support. Record that uncertainty as a diligence question, not as proof of who is responsible.
- User experience: Who sets expectations and responds to users?
- Operational control: Who can change, pause, or redirect transaction steps?
- Compliance workload: Which duties may apply, subject to counsel’s assessment?
- Partner dependence: What functions rely on external providers, and how are issues escalated?
No model is universally compliant or lower risk. Compare the documented transaction flow, then review assumptions with qualified counsel. The institutional guide to non-custodial crypto exchanges provides broader architecture context for evaluating these design choices.

Build an AML control framework around each swap lifecycle
A useful AML framework follows the transaction from onboarding through settlement and support. For AML compliance for crypto swaps, work in sequence: assess legal applicability, map risks, assign owners, implement controls, test performance, and update the framework when the service or its risk profile changes. Apply each control where it is relevant to the business and its obligations.
Risk assessment and control ownership
Assess risks connected to customers, transaction patterns, assets, geographies, channels, and third parties. Then identify who makes decisions, approves exceptions, handles escalations, and reviews the framework. A control without a clear owner can fail at a handoff, even when a vendor performs part of the process.
For each control, document its purpose, the party responsible for carrying it out, and the evidence that shows it was completed. Depending on the applicability analysis, controls may include identity checks, transaction monitoring, recordkeeping, or reporting procedures. Don’t assume every control applies to every swap service. Ask qualified counsel to assess the relevant requirements.
Monitoring, escalation, and partner diligence
Define how alerts are reviewed, investigated, escalated, and documented. Specify who can pause or refer a transaction for review, who decides what happens next, and how that decision is recorded. Set response expectations between your business and providers, then confirm that the agreed handoff works in practice.
Separate business-owned controls from vendor-operated controls. For each partner, review its role in the transaction flow, available control evidence, incident procedures, and arrangements for notifying you about material changes. Confirm what information can be shared and how issues reach the person accountable for the decision. An integration may perform a task, but assess your own responsibilities rather than assuming they have transferred.
Test the framework against realistic scenarios, such as an alert that needs escalation or a provider change that affects transaction routing. Record the result, address gaps, and revisit the assessment when products, partners, customer groups, or jurisdictions change. Verify reporting duties and record-retention periods with counsel. Don’t apply one threshold or timeline universally.
For additional context on how architecture can inform compliance planning, review this crypto compliance guide for US fintech developers. Treat architecture as an input to diligence, not a substitute for an applicability review.
Once you’ve mapped requirements and control boundaries, evaluate n.exchange swap infrastructure as one option for your operating model. Review current product documentation and assess how an integration fits your transaction flow and governance.
Evaluate crypto swap infrastructure without outsourcing accountability
An infrastructure provider can perform important transaction functions, but using its API, widget, or execution pathway doesn’t automatically transfer every responsibility from your business. For AML compliance for crypto swaps, diligence should establish what the provider does, what your business controls, and how the parties handle exceptions. Review the actual arrangement with qualified counsel before launch.
Questions to ask an infrastructure provider
Request a clear description of the transaction flow, including custody, order routing, execution, user interactions, and responsibility boundaries. Check each answer against current documentation and the proposed integration, rather than relying on a broad product label.
- Architecture: Which party can access or direct assets, receive instructions, or influence transaction decisions?
- Documentation: What technical specifications and operational evidence are available, and how can you verify stated capabilities?
- Support and continuity: What support processes, service-continuity arrangements, and incident procedures are documented?
- Data and escalation: What transaction information can each party access, and how are issues raised, assigned, and resolved under the contract?
Map each answer to a control owner on your side. If a provider handles a step, document what evidence you receive, who reviews it, and what happens when information is missing or an incident affects the flow.
Choose an integration model and define next steps
Compare an Exchange API, embeddable exchange widget, and white-label exchange solution against your product requirements and governance model. An API may let a business shape more of its own interface; a widget can embed an exchange experience; a white-label arrangement can support a branded trading service. Confirm capabilities and responsibilities for the specific configuration. For technical diligence questions, consult this non-custodial crypto API guide for fintechs.
Before selecting a model, record open questions about who communicates with users, handles exceptions, provides records, and communicates operational changes. Keep unresolved legal issues visible and obtain qualified counsel’s assessment. The goal is a documented division of work, not an assumption that an integration provider owns every resulting obligation.
Once your transaction flow and requirements are mapped, explore n.exchange infrastructure as an option for crypto swaps and business integrations. Review current documentation and assess how the relevant API, widget, or white-label solution fits your operating model.
Turn your transaction map into an operating plan
Sound AML decisions begin with evidence about how a swap works. Map the transaction flow, assess relevant federal and state questions with qualified U.S. counsel, and compare operating models by custody, control, execution, user relationships, and partner dependencies. Then assign owners for applicable controls, document vendor handoffs, and review the framework as your service changes.
That sequence keeps architecture and legal analysis distinct. Non-custodial design can inform diligence, but it doesn’t determine AML obligations on its own. The same applies when infrastructure partners support execution or user-facing services: define responsibilities before launch and verify them against the actual integration.
Once your requirements are clear, assess infrastructure options against your product and governance needs. n.exchange provides non-custodial crypto swap infrastructure for businesses, including an Exchange API, embeddable widget, and white-label solution. Review current documentation and determine how an option fits your transaction flow.
Explore n.exchange crypto infrastructure and take the next step with a clearer view of your operating model and responsibilities.
Frequently Asked Questions
Does a non-custodial crypto swap need AML compliance?
It depends on the business’s activities, role, and applicable jurisdictions. Non-custodial architecture may mean the service doesn’t hold user funds, but that fact alone doesn’t determine whether AML obligations apply. For AML compliance for crypto swaps, map who receives instructions, routes or executes transactions, controls relevant steps, and serves users. Then ask qualified U.S. counsel to assess the specific model under current federal and state requirements.
Are crypto swaps covered by US AML rules?
Some crypto swap businesses may fall within U.S. AML requirements, but there isn’t one answer for every service. The Bank Secrecy Act and FinCEN materials are important reference points for analyzing activities such as exchanging or transmitting virtual currency. Counsel should assess each entity’s functions, customer relationships, and transaction flow, along with relevant state requirements. A product label or technical architecture isn’t a legal determination.
What AML controls may a crypto swap business need?
Depending on the applicability and risk assessment, controls may include customer identity procedures, transaction monitoring, sanctions-related review, escalation workflows, recordkeeping, and reporting. First establish which requirements apply to the entity and its activities. Then assign owners, document decision criteria, define how alerts are investigated, and retain evidence according to applicable rules. Don’t assume every control is mandatory for every model. Confirm obligations and retention periods with qualified counsel.
Does using a crypto swap API make my business AML compliant?
No. An API can provide transaction infrastructure, but it doesn’t by itself establish that your business meets AML requirements or transfer every responsibility to its provider. Map which party receives instructions, routes or executes swaps, communicates with users, and handles exceptions. Review current technical documentation and contractual boundaries, then have counsel assess your obligations. Your controls should address the parts of the flow your business performs or controls.
How should a fintech compare custodial and non-custodial swap models?
Compare each model using the same criteria: custody, access to or control over assets, transaction discretion, execution, user relationship, and third-party dependencies. A custodial model raises questions about asset access and customer account arrangements. A non-custodial model still requires review of routing, facilitation, interface control, and service responsibilities. Document assumptions and open legal questions beside each criterion. Neither label alone establishes compliance or lower risk.
Do crypto swap businesses have to screen every transaction?
There isn’t a universal answer for every crypto swap business. Screening duties and appropriate monitoring depend on the entity’s activities, applicable legal requirements, jurisdictions, and risk assessment. Determine which sanctions, AML, or other screening rules apply, then document the covered parties or transactions, review process, escalation path, and evidence. Don’t infer a blanket requirement or exemption from non-custodial design. Verify the specific analysis with qualified counsel.
What should a business ask a crypto swap infrastructure provider?
Ask who holds or can direct assets, receives user instructions, routes and executes swaps, and communicates with users. Request current architecture documentation, operational evidence, and a clear account of each party’s responsibilities. Review data access, incident handling, service-continuity arrangements, change notifications, and contractual escalation procedures. Confirm what information your business receives and who investigates exceptions. These answers support diligence, but your business should separately assess its obligations with qualified counsel.


