Go back

Scaling Crypto Compliance Without Slowing Innovation

20m 55s

Scaling Crypto Compliance Without Slowing Innovation

In this podcast, host Chris Foyce interviews Azri Effendi, Financial Crime Program Manager at blockchain.com, about the compliance challenges facing crypto platforms. Azri emphasizes the need to align controls with national risk assessments, as regional crime patterns dictate specific regulatory expectations. On-chain transaction monitoring adds complexity, requiring analysts to trace funds across multiple hops and address behavioral alerts, such as frequent gambling transactions. To manage this, orchestration tools consolidate KYC, sanctions, and transaction monitoring workflows, automating low-risk tasks to reduce operational load and improve efficiency. Azri advises traditional financial institutions entering crypto to invest in on-chain analytics, train teams on crypto-specific typologies, and define clear risk appetites for hop analysis. Looking ahead, regulators will likely focus on AI’s role in operations and second-line compliance, though human oversight remains essential to prevent errors. The discussion underscores the balance between innovation, seamless user experience, and robust compliance in a rapidly evolving regulatory landscape.

Transcription

3762 Words, 21202 Characters

English
[Music] Hello and welcome to the REC Tech Pulse Podcast. I'm your host, Chris Foyce, Senior Director of Market Planning at Lexus Nexus Ristolutions and I'm very excited to be joined by Azri Effendi, Financial Crime Program Manager at blockchain.com. Azri leads blockchain's global financial crime strategy and played a key role in the meek authorization and also FCA money laundering regs registration as well. He's well placed to help us navigate today's topic which is the pressure on crypto platforms are under to scale at pace, deliver a seamless digital experience and keep innovating whilst meeting increasing complex expectations around KYC monitoring sanctions screening and fraud controls. Regulators, as you all know, are getting more confident when it comes to crypto and they're getting more specific around what good looks like in this space. So we're going to explore how firms can strengthen their compliance without creating unnecessary friction and white orchestration is becoming such an important part of that conversation. So first of all welcome Azri to start off can you give us a quick introduction to blockchain.com and your role there? Of course, thank you for having me. Blockchain.com was one of the first blockchain explorers so we started in 2011 and we've evolved into an exchange. We offer kind of custodial wallets as well as DeFi wallets as well and we operate globally in APAC in Africa in the EU and in the Americas as well. Amazing. Look at your background right. You've actually gone from meek authorization and also the FCA registration. So could you kind of give us some insight in what are the top three things you needed to consider as you went through those processes and whether there was any differences? The top priority I think for any compliance team looking to get into those regimes is really understanding the national risk assessment of that regime, you know, for for the various EU states, they're whilst they're risk appetite and their risk assessment might look similar. There are lots of nuances in how their populations work and how they interact with the financial ecosystem using that as a basis for your business wide risk assessment, slash your enterprise risk assessment, you know, that will really dictate how you plan your controls to those risks and how you really mitigate those. You know, it is difficult in a very kind of nascent industry where one risk may look very different today as it does next week. You know, with the rise of a genetic AI and general AI, there's a lot of risks that were not very aware of, you know, how people will perceive them will be affected by them as well. The second I would say is how you implement those controls again to the specific populations is quite an important thing that, you know, the variant is going to regulate as we look into that in a lot of detail. You know, we're not an investment bank. So, you know, any case worker can open up a blockchain.com wallet and we're going to go through that onboarding process and see, you know, what controls do we actually have? I can't obviously open up an investment account with JP Morgan or Morgan Stanley, but the barrier to entry to actually understanding what controls are live versus what you're saying in your policy is a lot less. So, you know, there's a lot more transparency there as well. Yeah, and also because I'm just thinking because I've heard this as well, like you operate an APAC and Africa. So you're everywhere pretty much. And I think in kind of regions like APAC, every country that the regulator has slightly different requirements is kind of what I've heard. I don't know if that's true. So there's different nuances. Does that mean that actually in terms of KYC and how you do onboarding and various other things than your processes? Do you actually have to have multiple processes in order to meet all those different kind of regulatory expectations or where you kind of operate? Absolutely. Yeah, it can be very descriptive as well. Some regulators will look at the metadata, you know, for IDV as an example. They're really going to focus on IP addresses or, you know, device types and device behavior and a lot of stuff that typically you wouldn't really think about as part of your typical kind of KYC process. All of that also then trickles into your transaction monitoring controls, on-chain versus, you know, the fee transaction monitoring wildly differs and in sets up and program, how then that trickles down into your compliance monitoring program as well. It is also very different. And again, a lot of this should be derived from the regulatory kind of national crime assessment and what is very pertinent to the regulator for their country. As an example, the more kind of Eastern European states and members of the EU, they're at higher risk of exposure to Russia and Belarus and that side of the world, whereas France and Spain will have more of a nexus on drug trafficking because of their proximity to cargo ships and the flow of narcotics as an example. So all of that really has to be articulated quite well in your controls and your policies and your frameworks and you really have to showcase that you've done the research into what makes something high risk for that regulator. Well, so basically the message I get is a ton of complexity right? So you have to be aware of the sanctions of Asian kind of and the different kind of channels for that in terms of when you mention kind of Russia and everything there as well. The other thing I would say with kind of crypto and whether you agree is you have all the kind of traditional financial controls right in terms of KYC, you talked about kind of fear currency transaction monitoring but you need to take it a step further right because you're actually looking at crypto transactions as well right? You've got the things like the travel rule and various other things that you need to implement. So there's additional complexity that you as a business have to manage is that kind of correct and creates a big overload operational overload either matching. Yes, it can if it's not a sell properly I would say you know on change and transaction monitoring is I say it's a whole kind of different world because you know it's a shift in mentality as well you know you can really kind of trace where sanctioned funds are going. Funds related to CSAM or you know terrorist financing you know you can think where you know whether they're ending up most wallets and you know we'll have some exposure to sanctions just as a result of the movement of funds but for most vassals or casps or exchanges that should feed into how your transaction monitoring teams or your financial investigation units also operate you know just because my wallet has sanctioned funds doesn't mean I'm interacting with a sanctioned individual or entity it means that the transaction monitoring analyst should really look at the history of those funds. Did the sanctions exposure come from something that happened a thousand hops ago or three years ago and now those funds have just trickled down into mine how exchanges also deal with funds can vary they're going to get collated into a big hot wallet and they're going to distribute it back out so it's pretty unavoidable to having at least you know 0.001% exposure to sanctions for every pound that comes through your exchange but how you deal with that and then also how you then articulate that in your policies and your frameworks back to the regulator needs to be pretty clear. When it comes through kind of tuning your thresholds there are so many different you know that's a very important thing that's been done is that help with that with the addition of a genticae as well it can help with making sure that your risks are being controlled in the best way possible and as per your client kind of psychology as well their behavior also then should feed into you know whether or not you have higher thresholds for job trafficking or dark market versus see some of terrorist financing. Yeah and I think the other fact you use the same tools that you have right in terms of looking at blockchain analytics so the expectations only increase in right in terms of what they expect organizations like yourself to do. I think the other factor as well is just the pace of innovation in your sector right so I don't even pretend to understand all the terms but you have like stable coins you have these defy wallets and I think when I looked at your website it's kind of like someone could have their defy wallet right and it could have cryptos from other kind of exchanges within that wallet right so how do you kind of assess risk assess these new products right and then what's your sense in terms of the regulators are they kind of keep it on top of all these innovations and kind of the impact just on kind of managing all this. Yeah I think the regulators are they're very aware of things that are happening in the market they're obviously part of a choice like you said where is going to be a lot of blockchain analytics firms in the market there's a lot of intelligent sharing there so you know the private kind of public partnerships side of things as as evolves in a very kind of positive way. I would say you can see the Fincent changes to the BSA earlier this month with them you know really kind of embracing the use of AI because you know it's inevitable right there's so many vendors on the market now some are doing some of these are the same as the ones but these are tools to mitigate risks in terms of defy versus stable coin. The stable coin. If you're an issuer the risks are a little bit more different you have owners is on you as an issuer to make sure your funds aren't ending up in a sanctioned wallet. And if you're aware that they are you need to blacklist that wallet and then you know that you shouldn't be interacting with this wallet because we've identified that there is some extensions risk there. From a D5 perspective it's a difficult topic I would say there's a lot of philosophical kind of debates you know it's the kind of antithesis of decentralized finance with you know with the travel kind of obligations. Cryptocurrency inherently is meant to be you know supersuper private it's decentralized for a reason when when you're in the hospital. And now the obligation to declare who I'm sending funds to or who I'm receiving funds from comes in. There is obviously a lot of friction with customer psychology and especially the kind of more OG crypto enthusiasts there are some hesitance there. But at the end of the day from most last that I want to enter the financial ecosystem. You have to buy by the regs. You know, there are rules that you have to play by and at the end of the day, that's very important to stop things like CSAM, Sanchez exposure, Tera's financing. Yeah. So that makes sense. So then you've got all of this. Obviously, I think your customer friction is a key point as well. So I imagine kind of abandonment rates is quite easy to move from one kind of provider to another. Right? So you're kind of sensitive to that. So you have all of this kind of pressure and obligations of yourself. But also you want to make that onboarding experience kind of seamless as well. You kind of touched on another aspect, which I didn't expect, which is the psychology of it as well, right? And kind of the history of crypto and how it is kind of that privacy as well. How you balance that but also maybe kind of could you touch on how, and I think I know the answer to this, but how traditional compliance workflows will struggle. Will all of this kind of different kind of factors that you need to contend with on the day to day? Yeah, it's super important to educate your customers very much from the start. There are regs that they might not agree with, but we are obligated to follow things like travel rule. We have to say by our registry regime, we have to ask this or if it's related to financial promotions. There are things that we can do from the officer that make a frictional less in terms of struggling with how innovation is moving. I think most firms at the moment are investing a lot into product compliance essentially. I see lots of firms now have kind of two set. They have one engineering team for compliance requirements and it's a very specific kind of niche of it, you know, of engineering that needs to be there working with lots of different kind of orchestration tools, you know, like Alexa's Nexus means handling data a lot more differently than payments data or FPNA related data and all your receivables data or anything like that. So there's a lot of tools and that orchestration layer helps consolidate all of that and then goal is to make sure that the operational load is lessened in some way depending on the risk appetite of the business. So when it comes to Fiat transaction monitoring, the typologies that you're looking at, the volume of transactions or the speed or rate of certain users from a certain IP address versus on-chain transactions where you're looking at transactions holistically, you're looking at wallet slash addresses holistically and then you're looking at any sort of behavioural alert. So a good example is gambling, right? There's lots of crypto led gambling firms now inherently that's not illegal, but in a lot of volume, you know, if a customer is sending a thousand pounds every hour to a gambling firm whilst it's not illegal, that's a behavioural alert that we should be very, very aware of. So that would be more akin to kind of traditional transaction monitoring, you know, with that, your two teams have to have separate tools, separate SOPs, separate workflows and this is where that orchestration layer really helps consolidate all of that. So they'll have six tabs open on their screen, it takes them half an hour to two hours to deal with an alert where in this environment, that's almost a bit too long with the kind of porosity of transactions coming in. So I think what you're saying is essential that firms break down the silos like in terms of the tech stack and the processes because you don't have the luxury of time. You don't have patient customers who are willing to wait. So you need to be quick, you need to onboard them and serve those customers quickly. So you kind of touched on kind of orchestration and it's a little bit, you kind of hear quite a bit in the industry kind of orchestration and stuff and I think we kind of alluded to what that is in terms of breaking down silos and not having fragmented tools and stuff, but be good to kind of get your perspective or for actually what it means in a compliance context orchestration. So you want to automate the low risk and medium risk transactions or on boardings, right? You want your teams to really spend the time on the higher risk activities that your customers will do. With that, there's a lot of stuff you can automate. At the first pass, we've automated quite a lot with Lexus Nexus. If there's no potential matches on a name, we let that go through automatically. That doesn't need to be resolved by a human and our screening team. That means they can spend more time looking at false positives and really spending the time in discounting and making sure that their dispossessioning analysis is very strong. Everything must be documented and again, we really want to avoid having our analysts move across different tabs. You know, fathom gear is, you know, still happen in this day and where we can mitigate that with leveraging vendors like yourselves to integrate into our customer ecosystem, the more we should be doing that. And then we'll see that goes from KYC to sanctions, to transaction monitoring, to then how you interact with potential fraud. And then also from a second line perspective, it's about how we then test those controls. As part of the compliance monitoring program, every quarter, every year, we need to analyze, you know, our controls still up, up to scratch. And orchestration makes that a lot easier because all the data is in one place, all the data is in one place. So it makes the articulation of how good the controls are a lot easier for us to explain to a regulator to an audit to the board as well. And to take it to the next level, so I've had kind of firms say that the other thing as well with orchestration is that multiple processes. Like, if you do need to vary your processes because of different regulatory expectations because of markets, you can have that all in kind of one platform and have it orchestrated for it. So it's just another consideration, right? Because there's so much that you need to manage, the more that you can centralize it and simplify it and drive efficiency, obviously, the better it is for everyone. So I'm going to touch on one, which I think is an area you're kind of passionate about from our previous discussion. So I know you're keen to educate kind of traditional financial institutions. And I think you mentioned a number of traditional financial institutions are launching crypto type products, right? So if a tradfi wanted to launch and scare a crypto product quickly, without losing control of risk, taking into account all the things that we've discussed on this podcast so far, what should they prioritize? You know, over the next 12 to 18 months, what are the top things they should be considering as they go on that journey? I think most traditional firms are looking to break into the set, dealt typically part of with infrastructure rails. So, you know, and essentially kind of banking partners, right? To provide them the kind of on and off ramp functionalities with that, it's really understanding what are their expectations to controls. Again, a traditional firm won't have an on-chain analytics program. That is something that can be quite expensive, training traditional transaction monitoring teams to account for on-chain transactions. Again, it's a completely different kind of mentality that needs to be there. There's no false positives because you can, like I said earlier, you know, you can see where the sanctions exposure is coming from. So, you know, how you articulate that risk appetite, which is another really important factor to it. You know, obviously did a report last year, you know, under going to a recommended amount of hops to look back on, T to 5, which is, I would say, pretty sufficient, but with the different types of typologies and the different types of techniques that these criminals would deploy, things like bridging or splitting and transactions can happen 20 hops before, but the risk is still very evident. So, whilst, when I'm looking back in time as one factor, it's obviously the context of the whole transaction there. Okay, that makes sense. So, thank you for that. So, for the left-field question, I'll end which is, finally, what do you expect regulators to focus on next? The use of AI in operations and then the kind of evolution of that into the second line obligations as well. So, there's lots of flaws at the moment that will do your transaction monitoring, that will disposition, name screening alerts for you. Like I said earlier, you know, Finsten have been very kind of proactive in making sure that companies are embracing that as much as possible. But, you know, operations are only one side of compliance. When you're managing a program, it's about how you keep your policies up to date. Horizon scanning is something that can be done relatively, going to simply with AI, but also, again, like testing and, you know, making sure that the models don't hallucinate. Then, it's a human review at the end of every quarter, twice a year, just to make sure that these tools are letting things slip through the cracks. I think we could have a whole separate podcast on AI. It comes pretty much every conversation these days. So, with that, I'll kind of wrap up. So, first of all, I just wanted to say thank you. I think this has been incredibly useful. I think the listeners enjoyed kind of the topics we covered today. I would say the big takeaways that I took out from this podcast is you talked about kind of focusing on the evidence, right? Make sure that it stands up to regulatory scrutiny. You added the complexity of all the different regulators and especially where you kind of operate. And there's nuances there that you need to manage as well. We talked about kind of customer friction and making sure that that's as seamless as kind of possible. And then we went into kind of how kind of traditional compliance frameworks, you know, sometimes they could struggle because data could be in silos and actually what you used to talk about is kind of the necessity in your industry for orchestration by break down those silos because you need to be as efficient as possible, give it a year of got so many different variables that you need to contend with and given the pressure to kind of onboard customers and give them a frictional experience. So with that, I'm hoping everyone enjoyed that podcast. And thanks for tuning in to this RECTEL, Pulse Podcast. So thank you. (upbeat music)

Podcast Summary

Key Points:

  1. Crypto platforms face pressure to scale quickly while managing complex compliance requirements like KYC, sanctions screening, and fraud controls, with increasing regulatory specificity.
  2. Compliance strategies must be tailored to national risk assessments, considering nuances like regional crime patterns (e.g., Eastern Europe’s Russia exposure vs. France’s drug trafficking).
  3. On-chain transaction monitoring introduces unique challenges, including tracing sanctioned funds across multiple hops and addressing behavioral alerts (e.g., frequent gambling transactions).
  4. Orchestration tools consolidate compliance workflows (e.g., KYC, sanctions, transaction monitoring) to reduce operational silos, automate low-risk tasks, and free up analysts for high-risk cases.
  5. Traditional financial institutions entering crypto should prioritize on-chain analytics, train teams on crypto-specific typologies, and define risk appetites for hop analysis (e.g., 5-7 hops recommended).
  6. Regulators are expected to focus on AI’s role in operations and second-line compliance, but human oversight remains crucial to prevent model hallucinations.

Summary:

com, about the compliance challenges facing crypto platforms. Azri emphasizes the need to align controls with national risk assessments, as regional crime patterns dictate specific regulatory expectations. On-chain transaction monitoring adds complexity, requiring analysts to trace funds across multiple hops and address behavioral alerts, such as frequent gambling transactions.

To manage this, orchestration tools consolidate KYC, sanctions, and transaction monitoring workflows, automating low-risk tasks to reduce operational load and improve efficiency. Azri advises traditional financial institutions entering crypto to invest in on-chain analytics, train teams on crypto-specific typologies, and define clear risk appetites for hop analysis. Looking ahead, regulators will likely focus on AI’s role in operations and second-line compliance, though human oversight remains essential to prevent errors.

The discussion underscores the balance between innovation, seamless user experience, and robust compliance in a rapidly evolving regulatory landscape.

FAQs

Blockchain.com is a crypto exchange and wallet provider founded in 2011. Azri Effendi is the Financial Crime Program Manager, leading global financial crime strategy and overseeing regulatory compliance.

Understand the national risk assessment of the regime, implement controls tailored to specific populations, and ensure transparency between policy and actual controls due to low entry barriers for users.

Regulators have nuanced requirements, such as focusing on metadata like IP addresses and device behavior. These differences extend to transaction monitoring and compliance, shaped by country-specific risks like sanctions exposure or drug trafficking.

They must manage on-chain transaction monitoring, the travel rule, and sanctions exposure from crypto fund flows. This requires specialized tools and mentalities, as funds can be traced across multiple hops.

Regulators are aware of market innovations and use blockchain analytics. For stablecoins, issuers must blacklist sanctioned wallets. DeFi challenges include privacy expectations versus travel rule obligations, requiring customer education.

Orchestration consolidates tools and workflows to automate low-risk tasks, reduce analyst time, and centralize data. This helps firms scale compliance efficiently, manage varied regulatory requirements, and articulate control effectiveness to regulators.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.