Fiatside

가이드 5/6

Identity verification and compliance

Why a crypto service verifies your identity, what is asked at each tier, what happens to your documents, and why a payout can be blocked.

Published
Updated
Reading time
14 min read
Collective byline (Collective editorial byline): this text is not attributed to any individual person. It has not yet been reviewed by a named editorial owner. Figures come from product data or from public sources cited in the text.

Converting a digital asset into legal tender is not a regulatorily neutral operation. It is precisely the exit point from the crypto system into the banking system, and that is where anti-money-laundering regulation concentrates its requirements.

This guide explains what is asked, why, and what a serious service does — or does not do — with your documents.

Why verification exists

A digital asset service provider is subject to anti-money-laundering and counter-terrorist financing obligations, in the same way as a bank. Those obligations have three strands:

  1. Know your customer. Identify the person, verify that the documents supplied are genuine, and understand the nature of the business relationship.
  2. Monitor operations. Detect patterns that diverge from what the declared profile predicts.
  3. Report suspicions. Notify the competent financial intelligence unit of operations where a suspicion exists.

The third point implies something few services state plainly: a suspicious activity report is not communicated to you. It is a legal obligation, and the prohibition on informing the person concerned is part of it.

The tiers, and why they exist

Verification is graduated. A first tier, for small amounts, asks for little; higher tiers ask for more. Exact thresholds are published on the identity verification page.

The general principle: the level required depends on your cumulative amount over a rolling period, not on an isolated operation. Five 900 EUR operations are not five small operations, they are one 4,500 EUR operation broken up.

That point deserves stating explicitly: deliberately splitting an operation to stay under a control threshold has a name in law, structuring, and it is in itself a suspicion indicator. The behaviour triggers exactly the review it is trying to avoid.

What is asked, tier by tier

Base tier. Declared identity, verified email address, phone number. Enough for small amounts.

Standard tier. A valid official identity document, and a check that the person present is the one on the document — what is called a liveness check. The document must be legible in full, with no glare on the machine-readable zone.

Enhanced tier. Recent proof of address and, depending on the case, proof of source of funds. The latter is not a suspicion: above certain amounts it is mandatory, and its absence blocks the operation however good the file is otherwise.

Politically exposed persons. Someone holding or having held a prominent public function, along with their close associates, is subject to enhanced due diligence. It is neither a refusal nor a judgement: it is a legal obligation, applied systematically.

Causes of rejection, by frequency

  1. An unusable ID photo. Blurry, cropped, glare across the bottom band. This is the leading cause and the easiest to avoid: shoot flat, in indirect light, no flash.
  2. Proof of address too old. The usual limit is three months.
  3. Payout account name different from the verified identity. Even a missing first name is enough to block. The destination account must be in the exact name of the verified person.
  4. A document in an unsupported language. A translation is then required.
  5. An address in a restricted country. Service is refused, with the reason stated on the geographic restrictions page.

The on-chain source of funds check

Alongside identity verification, a second check covers the funds themselves. Addresses that received assets directly from a sanctioned service, a mixer or an identified theft trigger a manual review.

Two honest caveats:

  • This check produces false positives. An address may have received, several hops upstream, funds of dubious origin without its holder knowing anything about it. Manual review exists precisely to separate those cases.
  • The result is not negotiable once established. If the analysis concludes there is a direct link with a sanctioned entity, the operation cannot be executed, whatever explanations are offered.

The full policy is on the AML policy page.

The Travel Rule

When digital assets move between two regulated providers, regulation requires originator and beneficiary information to travel with the transfer. It is the transposition to digital assets of a rule that has long existed for bank transfers.

Practical consequence for you: a withdrawal to a self-hosted wallet may prompt a request for proof of control of the address — signing a message with the matching key, for example. That is not a suspicion, it is the rule being applied.

The term is defined in the glossary.

What happens to your documents

A serious service must be able to answer four questions precisely.

Who processes them? Identification is performed by a specialised provider, which is the industry norm. The provider's name and role are on the privacy page.

How long are they kept? Regulation imposes a minimum retention period after the end of the business relationship. That period is an obligation, not a choice: a deletion request cannot override it while the clock runs.

Where are they hosted? Data location and the safeguards applying to any transfer outside the relevant area must be documented.

Who can access them? Access must be restricted to teams with an operational need, and logged.

If a service cannot answer those four questions, its reliability is a question that comes before its pricing.

What a service should never ask you for

  • Your wallet's recovery phrase. No legitimate reason exists. Ever. Such a request is an attempt at theft, without exception.
  • A password for another service.
  • Remote access to your computer.
  • A payment to unblock a withdrawal. Fees are taken out of the operation, never requested separately.

Those four are the constant signatures of scams in this sector. They are repeated on the security page.

How long it takes

Automated verification — reading the document, liveness check, comparison — resolves in minutes when the documents are usable. That is the majority case.

Three situations fall outside it, with different timings.

Manual file review. Triggered by a name discrepancy, a document in an unusual format, or a document whose authenticity must be confirmed. Expect a few business hours.

Source of funds verification. It requires documents you have to find: the bank statement of the original purchase, a contract, a payslip. Timing depends mostly on you. Preparing those in advance, when the amount you plan to sell warrants it, is the biggest time saving available.

On-chain analysis review. Triggered by a link to a flagged address. It is the least predictable: it can resolve in hours or take several business days if additional documents are needed.

During a review your order is not cancelled and your funds are not lost. But the locked rate expires on its own clock. If the review overruns the window, the order is re-quoted at the current rate and you must accept the new amount.

That is the operational reason, not the administrative one, why we keep saying to verify your identity before quoting: the only real cost of late verification is a rate that moved.

Preparing your verification

The best time to verify your identity is before creating an order. Doing it while a rate is running is the surest way to miss the lock window.

To prepare:

  • a valid official identity document;
  • proof of address less than three months old;
  • for large amounts, proof of source of funds: a bank statement showing the original purchase, a sale contract, a payslip;
  • a payout account opened in exactly the same name.

What compliance is not

Two misunderstandings come up often enough to be worth stating plainly.

Compliance is not a guarantee that your funds are safe. Verifying an identity and screening a deposit tells you nothing about how a provider holds assets, segregates client money or handles an incident. Those are separate questions, answered on the security page, and a provider that answers only the first is answering the easier one.

A verified account is not an unlimited account. Verification unlocks a tier, not the absence of limits. Rail ceilings, per-payment caps set by your own bank, and operational limits on our side continue to apply and are published on the limits page.

Being clear about both is part of the same discipline as the rest of this guide: describing what a control actually does, rather than letting it suggest a broader assurance it does not provide.

Articles attached to this guide

이 가이드의 문서

각 문서는 여기서 다룬 주제를 더 깊이 다루며, 수치와 예외 사례를 포함합니다.

유용한 자료