Â
Ask any centralized cryptocurrency agency to call one in every of their greatest priorities or challenges—after which rely the variety of instances they point out financial institution partnerships. For crypto companies, the lack of, or failure to amass, a financial institution partnership poses an existential risk, undermining the agency’s capacity to trade fiat (conventional forex) for cryptocurrency, and vice versa, in a course of colloquially known as “on- and off-ramping.” Whereas the cryptocurrency {industry} is certainly disrupting the way forward for finance, at this time the enterprise fashions of hottest crypto exchanges, cost processors, and stablecoin issuers stay closely depending on conventional monetary companies to assist all the things from treasury and reserve administration, payroll and accounting operations, and maybe most necessary of all, the supply of so-called fiat cost rails to assist crypto-fiat trade. Sadly for a lot of cryptocurrency companies, the previous couple of years have been particularly difficult for stability within the financial institution companion panorama.
Securing a financial institution partnership has by no means been a frictionless course of for cryptocurrency companies—usually requiring in depth due diligence by potential companion banks so as to get comfy with an {industry} notoriously thought-about to be “novel,” “excessive threat,” “risky,” and “advanced.” Many conventional monetary establishments (TradFis), particularly giant, systemically necessary banks that weathered earlier enforcement actions, have traditionally expressed a low urge for food for serving cryptocurrency companies, leading to a restricted pool of potential financial institution companions. This opened the aperture for small and mid-sized home banks to serve an {industry} confronted with exponentially rising transaction volumes. And for a time, the mannequin was working, although the incumbent banks serving the sector struggled to maintain up with demand from potential clients as crypto costs soared throughout the 2021 crypto bull run. In its heyday, the main “crypto” banking-as-a-service (BaaS) supplier, Silvergate Financial institution, estimated that it processed $1 trillion on its real-time cost community, with deposits peaking at $14 billion on the top of the 2021 bull run, largely attributable to Silvergate’s crypto buyer base,[1] till all of it got here crashing down in 2022. A confluence of occasions, seemingly precipitated by the autumn of well-liked stablecoin Terra Luna, ushered in a crypto winter so chilling that it resulted within the demise of a number of main cryptocurrency exchanges, brokerages, and lenders, resulting in the autumn of a number of tech-friendly banks in 2022 that traditionally served the sector.
Including insult to harm, the previously crypto-friendly Workplace of the Comptroller of the Foreign money (OCC) issued a joint assertion in partnership with the Board of Governors of the Federal Reserve System and the Federal Deposit Insurance coverage Company (FDIC) within the wake of those unlucky occasions, highlighting the important thing dangers to banks of partaking with the crypto {industry}, going as far as to proclaim that “issuing or holding as principal crypto-assets . . . is extremely more likely to be inconsistent with secure and sound banking practices”[2] and expressing “vital security and soundness considerations with enterprise fashions that . . . have concentrated exposures to the crypto-asset sector.”[3] The joint assertion had a chilling impact on the supply of banking companies to the cryptocurrency {industry}, as banks feared operating afoul of their regulators, leaving the remaining crypto {industry} members scrambling to seek out relationships with a restricted pool of companions and sacrificing much-needed performance, like Automated Clearing Home (ACH) entry for cheaper transactions.
However with a brand new crypto-forward U.S. administration taking workplace, many are anticipating that the boundaries to cost rail entry will quickly come down. Different crypto-friendly regimes, reminiscent of Hong Kong, have been identified to strongly encourage outstanding correspondent banks of their area to serve the crypto sector;[4] likewise, insiders anticipate an Govt Order within the first days of the Trump presidency addressing the de-banking skilled by the cryptocurrency {industry} in recent times.[5] Assuming that this Govt Order, or related regulatory readability, quickly involves cross, each banks and cryptocurrency companies ought to begin getting ready for the subsequent wave of fiat cost rail enablement and the due diligence finest practices that can inevitably emerge.
Issues for Banks/BaaS Suppliers Planning to Supply Cost Rails
The supply of fiat cost rails to crypto native companies is crucial to driving mainstream crypto adoption. As such, banks and BaaS suppliers are key to unlocking development within the crypto {industry}. As they discover service provision to crypto gamers, banks and BaaS suppliers striving to make sure monetary integrity whereas assembly the enterprise wants of this distinctive sector ought to take into accounts the weather outlined under.
- Governance, Administration Oversight, and Staffing
- Be certain that the board, senior administration, and workers throughout the three strains of protection have a sturdy understanding of cryptocurrency and the distinctive dangers related to serving the sector previous to altering your online business mannequin.
- Put money into extra specialised coaching and think about hiring extra workers with specialised expertise and expertise to handle information gaps.
- Carry out a brand new enterprise overview to establish and remediate management gaps previous to supporting a brand new enterprise mannequin, significantly one which entails provision of fiat rails to cryptocurrency companies and finish customers.
- Develop a proper threat urge for food assertion, together with threat urge for food thresholds and early warning indicators, to establish and monitor for potential focus threat, spikes in transaction volumes, and adjustments to buyer threat.
- Preserve change administration/horizon scanning processes and controls, particularly given the ever-evolving nature of the crypto regulatory panorama.
- Inside Controls
- Carry out an AML and sanctions threat evaluation that evaluates buyer, geographic, product/service, transaction, and supply channel inherent dangers and the effectiveness of the group’s management setting, so as to assess whether or not there are dangers requiring extra mitigation and enhancements to the management setting.
- Overview and replace the group’s monetary crimes compliance (FCC) program to handle the distinctive dangers related to provision of companies to the cryptocurrency {industry}, together with making updates to related insurance policies, procedures, and controls as wanted, throughout the agency’s transaction monitoring, buyer due diligence, and sanctions packages.
- Think about performing a transaction monitoring protection evaluation to make sure that the group’s transaction monitoring ruleset is designed appropriately to seize any extra dangers related to serving the cryptocurrency {industry}.
- Think about growing bespoke steady monitoring and data trade/request for info (RFI) packages with cryptocurrency trade clients to make sure simpler monitoring and reporting related to finish consumer actions.
- Think about implementing specialised business options reminiscent of blockchain analytics to carry out extra monitoring of cryptocurrency buyer exercise, guaranteeing that personnel utilizing this specialised software program have the requisite expertise and expertise to successfully make the most of these instruments.
- Know Your Buyer (KYC) Program
- Overview present buyer onboarding, due diligence, and enhanced due diligence processes, and modify as needed to make sure risk-based KYC controls for cryptocurrency {industry} clients.
- To the extent that exterior kinds just like the Wolfsberg Correspondent Banking Due Diligence or FCC Questionnaires (Wolfsberg CBDDQ or FCCQ) are leveraged, complement these questionnaires with crypto-specific due diligence inquiries to verify for Journey Rule compliance, use of specialised software program reminiscent of blockchain analytics, and controls associated to greater threat cash reminiscent of anonymity-enhancing cash and privateness cash.
- Think about performing an evaluation of cryptocurrency {industry} members to make sure applicable risk-based segmentation of consumers (i.e., primarily based on enterprise mannequin, regulatory standing, and so forth.).
- As a part of this train, think about the impression of various cryptocurrency {industry} members on the group’s buyer threat score (CRR) methodology and replace the CRR methodology as wanted.
- Think about implementing bespoke ongoing monitoring and RFI processes to complement the client due diligence program.
- Overview present buyer onboarding, due diligence, and enhanced due diligence processes, and modify as needed to make sure risk-based KYC controls for cryptocurrency {industry} clients.
- Enterprise Processes
- Designate and practice specialised account/relationship managers to pre-screen potential clients and handle crypto {industry} buyer relationships.
- Think about designing risk-based efficiency incentives to discourage undue risk-taking.
- Develop and doc the group’s crypto enterprise technique, as this can allow the technique to be communicated each internally to related stakeholders and externally to regulatory authorities.
- Develop specialised account buildings for omnibus accounts related to cryptocurrency clients.
- Think about the {industry}’s necessities for twenty-four/7/365 transaction settlement and assess what enhancements could also be required to core banking techniques and processes to satisfy these calls for.
- Put money into expertise assets and set up software programming interfaces (APIs) to allow seamless integration between your banking companies and your clients’ platforms and interfaces.
- Designate and practice specialised account/relationship managers to pre-screen potential clients and handle crypto {industry} buyer relationships.
- Regulatory Communications
- Proactively talk anticipated adjustments to product and repair choices to regulatory authorities, together with outlining any threat and management assessments carried out and any new controls being carried out to handle newly recognized dangers.
Issues for Crypto Firms Looking for Cost Rails
On the flip aspect, as crypto natives interact with financial institution companions looking for fiat cost rails, they ought to organize for heightened FCC and threat administration requirements and think about how this would possibly impression their staffing and operations, as outlined under.
- Documented and Efficient FCC Program
- Preserve a documented FCC threat evaluation methodology outlining inputs into the agency’s FCC threat evaluation, and carry out detailed, data-driven FCC threat assessments on at the least an annual foundation.
- Be ready to share the outcomes of the newest FCC threat evaluation with potential financial institution companions at onboarding and at the least yearly going ahead as a part of the financial institution’s periodic overview course of.
- Preserve a documented FCC coverage tailor-made to the distinctive services of the agency, supported by a program of associated insurance policies, procedures, and techniques (e.g., blockchain analytics, sanctions screening, id verification, and so forth.).
- Be ready to share a duplicate of the FCC coverage with potential financial institution companions and be ready to answer inquiries with respect to the agency’s FCC management framework, together with the frequency with which controls are executed.
- Think about sustaining an up to date response to an industry-standard questionnaire, such because the Wolfsberg CBDDQ, that may be shared with potential financial institution companions upon request.
- Conduct an annual impartial audit/overview of the agency’s FCC program to make sure that the FCC program and key FCC controls are working successfully.
- Be ready to share the outcomes of the impartial audit/overview with potential financial institution companions and be ready to supply particulars with respect to the standing of any relevant corrective actions.
- For companies beneath a public regulatory enforcement motion, be ready to supply particulars with respect to the standing of corrective actions and remediation plans in response to the enforcement motion.
- Preserve a sturdy course of for info sharing with financial institution companions on mutual clients, each via a proper 314(b) course of and thru any documented service-level settlement (SLA) processes maintained with the financial institution companion.
- For companies which can be early-stage start-ups with plans to depend on a BaaS supplier previous to buying cash transmitter licenses, retain certified outdoors counsel to supply a authorized opinion outlining why the agency operates with out cash transmitter licenses. Additional, early-stage start-ups ought to keep documented enterprise plans that clearly articulate the agency’s merchandise/companies, core buyer segments, geographies, and any imminent plans for geographic growth.
- Be ready to share each the authorized opinion and the agency’s enterprise technique with potential financial institution companions and be ready to have interaction with representatives of the financial institution to reply questions with respect to the agency’s enterprise mannequin, regulatory standing, merchandise/companies, deliberate use instances, and anticipated cost flows.
- Preserve a documented FCC threat evaluation methodology outlining inputs into the agency’s FCC threat evaluation, and carry out detailed, data-driven FCC threat assessments on at the least an annual foundation.
- Staffing and Resourcing
- Appoint a professional Financial institution Secrecy Act (BSA) officer with ample authority and oversight of the FCC program and keep ample and certified assets to maintain up with the operational calls for of fast development in buyer and transaction volumes.
- Preserve ample and certified personnel to answer financial institution companion inquiries in a well timed method, together with onboarding due diligence questionnaires, periodic evaluations, financial institution partner-mandated SLAs and reporting necessities, and advert hoc inquiries.
- Think about working with potential financial institution companions to doc a proper course of for periodic evaluations and RFIs so as to successfully handle assets and guarantee well timed responses to financial institution companion inquiries.
- For companies with a number of financial institution companions, think about sustaining an up to date repository of responses to regularly requested info/questions so as to streamline the response course of.
- Different Compliance and Danger Controls
- For companies serving retail clients, keep an efficient course of for monitoring and resolving buyer complaints in a well timed method.
- Preserve a documented coverage overlaying market abuse and market surveillance, supported by a system of controls to watch for market abuse and manipulation.
- Preserve a course of for third party-vendor threat administration, and specifically, be ready to talk to processes for managing vital compliance vendor relationships.
As crypto companies proceed to mature and strengthen their threat administration practices, it’s clever to assume past merely assembly financial institution companion expectations and start assessing whether or not a potential financial institution companion is an applicable match. Simply because the financial institution is doing due diligence on the crypto agency, the crypto agency should be performing due diligence on the financial institution. Some areas to think about are outlined under.
- Danger and Compliance Posture
- Be certain that the possible financial institution companion is compliant with related regulatory necessities within the jurisdictions during which each the crypto agency and the financial institution conduct enterprise.
- Does the financial institution have any public enforcement actions or is it the topic of current materials destructive information?
- Is the financial institution in good standing with related regulatory authorities?
- What’s the high quality of the financial institution’s threat and compliance management, FCC packages, and subject-matter experience?
- What’s the measurement of the financial institution’s threat and compliance departments versus the dimensions of its buyer portfolio and transaction exercise?
- Think about the soundness of the financial institution and whether or not the financial institution’s buyer portfolio is overly concentrated within the crypto sector such that there could also be potential for systemic threat.
- Does the financial institution seem to have strong threat administration controls and educated threat management?
- Be certain that the possible financial institution companion is compliant with related regulatory necessities within the jurisdictions during which each the crypto agency and the financial institution conduct enterprise.
- Product/Service Match
- Assess whether or not the financial institution has ample experience and companies to assist the crypto {industry}.
- Does the financial institution possess the suitable technical capabilities to assist a crypto agency’s operations (e.g., APIs, settlement community)?
- Does the financial institution serve equally sized crypto market members, and may the financial institution deal with the crypto agency’s anticipated transaction volumes, values, and buyer segments?
- Does the financial institution have entry to essentially the most in-demand fiat currencies for the agency’s operations (e.g., USD, GBP, EUR)? Does the financial institution have a robust correspondent banking community to assist wanted cross-border funds to the extent that that is necessary for the crypto agency’s enterprise mannequin?
- Can the financial institution scale with the crypto agency’s product and repair ambitions by supporting completely different cost strategies and merchandise (e.g., playing cards, demand deposit accounts, and so forth.)?
- Assess whether or not the financial institution has ample experience and companies to assist the crypto {industry}.
How K2 Integrity Can Assist
Given the numerous concerns and potential program updates needed for each banks and crypto companies to unlock crypto-fiat rails, listed below are some ways in which K2 Integrity might help TradFi, Fintech, and crypto native companies:
Â
[1] Celarier, M. (24 January 2023), “The Crypto Business’s Favourite Financial institution Is in Deep Bother,” New York Journal, https://nymag.com/intelligencer/2023/01/silvergate-crypto-industrys-favorite-bank-in-deep-trouble.html.
[2] U.S. Treasury (3 January 2023), “Joint Assertion on Crypto-Asset Dangers to Banking Organizations,” Board of Governors of the Federal Reserve System, Federal Deposit Insurance coverage Company, and Workplace of the Comptroller of the Foreign money, https://www.occ.treas.gov/news-issuances/news-releases/2023/nr-ia-2023-1a.pdf.
[3] Ibid.
[4] Fintech Information Hong Kong (3 July 2023), “HKMA Steps Up Strain for Banks to Settle for Crypto Corporations as Purchasers,” https://fintechnews.hk/22662/hong-kong/hkma-steps-up-pressure-for-banks-to-accept-crypto-companies-as-clients/.
[5] Zakrzewski, C., and Alemany, J. (13 January 2025), “Elon Musk Isn’t the Solely Tech Chief Serving to Form the Trump Administration,” Washington Publish, https://www.washingtonpost.com/politics/2025/01/13/andreessen-tech-industry-trump-administration-doge.