Three terms, three different jobs
KYC, KYT, and AML are often used as if they describe the same check. They do not. KYC focuses on the customer. KYT focuses on transaction activity. AML is the wider system that decides how a business identifies, assesses, monitors, documents, and responds to money laundering risk.
The distinction matters in crypto because a verified customer can still send funds from an unexplained wallet, while a wallet with no strong risk signals does not reveal who legally controls it. A business needs to connect identity, transaction evidence, and policy without treating any one result as a complete answer.
The quick comparison
- KYC asks who: Who is the customer or business? Who owns or controls a legal entity? Is the identity information reliable, and does the relationship make sense?
- KYT asks what happened: Which asset and network were used? Which addresses were involved? What patterns, counterparties, and direct or indirect exposures appear in the transaction activity?
- AML asks what the organization must do: Which risks apply, which controls are proportionate, who reviews an alert, what is recorded, and when must the matter be escalated or reported?
These are working descriptions, not universal legal definitions. In particular, KYT is an industry term rather than one consistently defined legal control across every jurisdiction. Laws and regulators more often refer to transaction monitoring, ongoing scrutiny, suspicious activity detection, and related due diligence.
What KYC means in a crypto business
Know Your Customer is the familiar name for identity and customer due diligence controls. The exact requirements depend on the business and jurisdiction, but a KYC process may include:
- collecting and verifying a person's identity using reliable information;
- identifying a company and understanding its ownership and control structure;
- identifying the beneficial owner where required;
- understanding the purpose and intended nature of the relationship;
- assessing customer, product, geographic, and delivery channel risk;
- refreshing information when circumstances or risk change.
The FATF Recommendations place customer identification, beneficial ownership, the purpose of the relationship, and ongoing scrutiny within customer due diligence. That final point is important. KYC is not always a single identity check completed at onboarding.
KYC still has a clear boundary. A passport, registry extract, or company document does not explain the history of a blockchain address. It also does not prove that a specific customer controls every wallet they provide. Identity evidence and blockchain evidence answer related but different questions.
What KYT means in crypto
Know Your Transaction is a practical label for examining transactions and related wallet activity. In a crypto workflow, the review may consider the network, asset, transaction hash, sending and receiving addresses, timing, value, known attribution, counterparties, transaction patterns, and available direct or indirect exposure.
KYT can happen at several points:
- Before an outgoing transfer: review the destination before funds leave your control.
- When a payment arrives: examine the source and transaction before releasing goods or crediting a balance.
- During a relationship: identify activity that is inconsistent with the expected customer profile or stated purpose.
- After an alert: preserve the transaction record and investigate the relevant wallet and paths.
Wallet screening is one part of this work. It can surface risk signals and help a reviewer understand the blockchain context. The practical guide to crypto wallet screening explains that process in detail.
KYT does not reliably identify the legal owner of a self hosted wallet. It does not prove knowledge or criminal intent, and a distant connection is not equal to a direct transfer. The output should support triage and investigation rather than act as an automatic verdict.
AML is the operating system around both
Anti money laundering is broader than an identity form or a transaction score. An AML framework may include governance, a documented risk assessment, customer due diligence, transaction monitoring, escalation, suspicious activity reporting where required, record keeping, staff training, quality assurance, and independent review.
That framework determines how KYC and KYT work together. It defines which customers and transactions are in scope, what information is needed, how risk changes the depth of review, who owns a case, and what action follows an unresolved concern.
Sanctions controls often operate alongside AML, but the two should not be treated as identical. A sanctions rule may prohibit or require action even when there is no evidence of money laundering. The relevant legal regime and jurisdiction determine the obligation.
FATF's guidance for virtual assets and service providers applies the wider risk based AML framework to the sector. The European Banking Authority guidance also describes customer, product, geographic, and delivery channel risk factors, together with measures that include blockchain analytics.
One payment shows how the three fit together
Imagine a corporate customer paying a large invoice in a stablecoin from a new address.
- KYC establishes the relationship: the business verifies the company, relevant representatives, and beneficial owners as required. It records the expected purpose, geography, and payment profile.
- KYT examines the payment: the reviewer confirms the network, token, address, amount, and transaction hash. Wallet analysis shows the available attribution, counterparties, and exposure paths.
- AML controls the response: the policy compares the identity and transaction evidence, assigns the reviewer, sets the escalation threshold, and records why the payment was accepted, paused, rejected, or referred.
If the payment route does not fit the customer's explanation, the team may request more information about the source of funds. Passing KYC does not make that mismatch disappear. An elevated transaction signal also does not cancel reliable customer information. Both belong in the review.
Four mistakes that weaken the process
1. Treating passed KYC as approval for every transaction
Identity verification reduces one uncertainty. It does not make every future wallet, counterparty, amount, or transaction path expected.
2. Treating a KYT score as a legal conclusion
A transaction or wallet result can prioritize review. It does not by itself establish ownership, intent, a crime, or a reporting obligation.
3. Calling one tool an AML program
Software can support checks and preserve evidence. An AML program also needs ownership, rules, escalation, records, review, and decisions.
4. Collecting more data without a purpose
A risk based process is not a contest to gather the most documents. Collect information that addresses a defined risk and handle it under applicable privacy and retention requirements.
A practical design for a growing business
- Map your legal position: determine whether the business is regulated, which jurisdictions apply, and where specialist advice is required.
- Define separate questions: write down what KYC must establish, what transaction review must examine, and what the wider policy decides.
- Connect the records: keep customer context, wallet identifiers, transaction evidence, review time, and decision in one case trail.
- Use event based triggers: consider a new wallet, unusual amount, unexplained geography, changed behavior, or fresh risk information as reasons for review.
- Keep a human decision point: strong or ambiguous signals need a reviewer who can compare evidence and explain the action.
Where Farona fits
Farona supports the wallet and transaction risk part of the process. It converts available blockchain risk signals into a Farona score, Farona level, plain language verdict, and supporting evidence that a reviewer can document.
Farona is not an identity verification service and does not provide a complete AML program. It does not establish the legal owner of every wallet or decide whether a report to an authority is required. Use it to strengthen the KYT layer and connect blockchain evidence to your own KYC context and AML policy. For the next step, see how to read a Farona wallet risk report.
Sources and further reading
- FATF Recommendations, including customer due diligence and ongoing scrutiny
- FATF guidance for virtual assets and virtual asset service providers
- EBA guidance on money laundering and terrorist financing risk factors for crypto asset service providers
- FinCEN customer due diligence rule for covered United States financial institutions
Sources were checked on 23 August 2026. This article provides general information and is not legal advice. Requirements differ by jurisdiction, regulatory status, service, and customer relationship.





