KYC for an ICO verifies each participant before tokens are allocated. The identity duty usually binds the regulated service provider in the payment flow rather than the token issuer, but sanctions rules bind everyone.
An initial coin offering, or ICO, raises money by selling a new token to the public, usually in exchange for another cryptocurrency. If you are running one, you have to decide who you will let in and what you will ask them for. If you are joining one, you have to hand identity documents to a company you have never dealt with before.
The rules governing both sides changed substantially between 2023 and 2026, and most published articles still describe the older position. This guide covers what the checks involve, which rules actually bind you, and what the process looks like in practice.
What is KYC for an ICO?
KYC for an ICO is the process of verifying who each participant is before they are allowed to buy or receive tokens. In a token sale, the checks usually run as a gate. A participant registers, submits identity evidence, gets screened against financial crime data, and only then receives a purchase window or a token allocation.
What The Checks Confirm
Three separate questions sit inside the process, and a check that answers only the first is incomplete.
- Does this identity exist and is the document real? The document is examined for the security features a genuine passport or national ID carries.
- Is the person presenting the document the same person it belongs to? A biometric check compares a live selfie against the document photo and confirms a real person is present rather than a photograph or a recording.
- Is this person permitted to take part? Sanctions, politically exposed person, and adverse media screening answer that question; identity verification on its own cannot.
Why “KYC ICO” Describes Two Separate Things
Search results often shorten the topic to KYC ICO, which hides a very crucial distinction. KYC Verification is a set of identity checks, whereas an ICO is a fundraising method. Whether the first is legally required during the second depends on how the sale is structured, and that’s what we’ll cover next.
How a Token Sale Differs from Ordinary Onboarding
A bank onboards customers continuously and can spread the workload. A token sale often opens for a few days, which compresses the same volume into a short window and puts pressure on verification that runs slowly or needs manual review.
Money also arrives differently. In a bank transfer, a regulated institution has already checked the sender. In a token sale, funds often arrive on-chain from a wallet address with no institution behind it, so the receiving side has to check where the money came from.
Why do ICOs Need to Run KYC Checks?
There are two reasons for that. One is financial crime exposure, which is a legal and enforcement problem. The second is credibility with exchanges, banks, and participants, which is a commercial problem.
The Laundering Route a Token Sale Opens
A token sale converts one asset into another and issues a fresh instrument with no transaction history attached to it. Somebody holding proceeds of crime in cryptocurrency can contribute those proceeds, receive clean-looking tokens, and sell them later on an exchange. The new token carries none of the history the original funds carried, which is the specific reason regulators took an interest in token sales rather than in fundraising generally.
The scale of the surrounding problem is documented by the FBI’s Internet Crime Complaint Center, where they recorded 181,565 cryptocurrency fraud complaints in 2025 with losses above $11 billion, the highest-loss category in its annual report, published in the FBI’s April 2026 release.
The Commercial Reason Issuers Run These Checks
Even where no rule compels it, an issuer that cannot say who its holders are will struggle later, and that’s why they still run these checks. Exchanges ask about the origin of a token’s distribution before listing it. Banks ask before opening an account for the raised funds. So, that means if you skip verification, there’s no way to answer those questions afterwards.
What MiCA Requires of the Offeror
The EU’s Markets in Crypto-Assets Regulation, known as MiCA, governs offers of crypto-assets to the public. Its Title II duties on an offeror are disclosure duties rather than identity duties, and we’ve covered those in detail in our guide to MiCA regulation and EU crypto rules.
What the AML Rules Ask of the Service Provider
The identity duty sits in the anti-money laundering rules, and it attaches to the crypto-asset service provider, or CASP, which is a firm licensed to run exchange, custody or transfer services for crypto-assets. A CASP is an obliged entity and carries a full AML programme, a position now set out in Regulation (EU) 2024/1624, the Anti-Money Laundering Regulation, which applies from 10 July 2027.
As per the regulation, credit institutions and financial institutions apply customer due diligence on occasional transfers worth at least EUR 1,000, and crypto-asset service providers are carved out of that threshold by derogation. A CASP therefore verifies below the level at which a bank would, which removes the option of running a small-contribution tier with no checks on it.
Where that Leaves a Token Issuer
An issuer that is not itself a CASP is generally not an AML-obliged entity in the EU. That is a narrower point than it sounds, because almost every practical token sale touches a regulated firm somewhere. The moment contributions convert to or from ordinary money, a licensed institution sits in the path and applies its own checks to the issuer and often to the participants.
Which Entity Carries Which Duty
| Role in the sale | Rules that bind it | What it must do |
| Token offeror or issuer | MiCA Title II | Disclosure duties only. No identity duty from this Title |
| Crypto-asset service provider | AMLR and the Transfer of Funds Regulation | Verify every customer, with no lower value threshold below which checks can be skipped |
| Any party, in any role | Sanctions law | Do not make funds or assets available to a designated person or entity |
What Documents must ICO Participants Provide?
The KYC process for an ICO usually collects two types of evidence and the related documents, mentioned below.
Identity and Document Evidence
A government-issued photo document is the standard starting point, most often a passport, national identity card, or driving licence. Alongside it, the participant submits a live selfie so the platform can confirm the document belongs to the person holding it.
Some markets allow electronic identity verification eidv checks, where a participant is checked against authoritative databases such as civil registries without asking for a document upload at all.
Address and Source of Funds Evidence
Proof of address is usually a recent utility bill or bank statement, and it does more work in a token sale than people expect. Residence determines which jurisdiction’s rules apply to that participant and whether they can take part at all.
Shufti’s KYC platform routes higher-risk customers into enhanced due diligence workflows that can include additional documents, source-of-funds and source-of-wealth evidence, adverse media review and analyst decisioning. Below a defined contribution threshold, most sales do not ask for this. Above it, an issuer that cannot produce it later has no answer for a bank or an exchange.

How are Sanctions and PEP Checks Applied to ICO Investors?
The checks run after identity is confirmed and before any tokens are handed over. The platform takes the participant’s verified name, date of birth, and nationality, then looks for those details on lists of people who are either barred or who need a closer look. Anything resembling a match is reviewed by a person before the participant is approved.
Which Lists are Checked
Three lists do most of the work.
- Sanctions lists. These name people and companies that nobody is allowed to do business with. A match means the participant is refused.
- Politically exposed person lists. A politically exposed person, or PEP, holds a senior public role, such as a government minister, a judge or the director of a state-owned company. Close family members and business associates are included too. A match here does not mean refusal. It means the platform examines the source of their money more closely.
- Adverse media. This is credible news reporting that ties somebody to financial crime before any official list has recorded it.
Can Investors from Restricted Jurisdictions Take Part?
Not always. An investor can be turned away for two different reasons.
The first is sanctions. If an investor is on a sanctions list, they cannot take part. This applies to every issuer, licensed or not. Some sanctions programmes also cover a whole country, so an investor living there is refused even if their own name appears on no list.
The second is the issuer’s own decision. Issuers often turn away investors from countries that no sanctions rule covers. Sometimes it is securities law, because a regulator there might treat the token as an investment and ask for registration paperwork. Sometimes it is tax, because taking money from that country creates filings the issuer would rather avoid.
How Blocked Investors Get in Through Someone Else
Blocking a country does not stop the people in it from trying, and the usual workaround is to find somebody who can pass. That person completes the checks and holds the tokens on behalf of the investor who could not.
Verification will not catch this, because the document is real, the face matches it, and the person on camera is a willing participant rather than an impostor. Checked on its own terms, the application is clean, which is exactly why the check clears it.
How Does KYC Affect ICO Participation and Drop-off Rates?
Verification always costs some participation, and the size of that cost is a design decision rather than a fixed penalty. The largest losses come from asking for evidence a participant cannot easily produce, not from asking for evidence at all.
Where Participants Abandon the Flow
Drop-off concentrates at three points. The first is document capture, especially for participants whose document type or language the system reads poorly, since each retry loses people. The second is proof of address, because a recent bill in the right name is genuinely hard to produce for people who rent, share housing, or live in countries without that document convention. The third is manual review, where a participant who is told to wait during a sale window that closes in two days often does not come back.
What to Look for in KYC Providers for an ICO
A token sale is a short, high-volume, global event, and that shape rather than a generic feature list should drive the choice.
- Document coverage across the markets your allowlist admits. A provider that reads your hardest document types natively loses fewer participants than one that falls back to human review for them.
- Screening bound to the verified identity. A name typed into a form generates false matches that a small team cannot clear before the sale closes.
- Wallet-level screening. Identity screening alone does not tell you whether the contribution is tainted, and a token sale is one of the few onboarding events where the money often arrives before you can ask about it.
- A contribution-tiered escalation path. A small buyer and a large buyer should not face the same evidence requirements, and changing where that line sits mid-sale should not require a code release.
- Throughput inside a fixed window. Ask how a provider behaves when a month of volume arrives in three days, because a sale does not reopen.

How Shufti Helps Token Issuers Verify ICO Participants
A token sale collects money from people you have never met, in a currency that carries its own history. Identity verification tells you who the participant is. It does not tell you where the funds came from, and in a token sale that second question is usually the harder one to answer after the fact.
Shufti’s AML Screening covers both halves in one check. It screens the participant against sanctions lists, politically exposed person records, and adverse media, and it screens the inbound on-chain deposit against OFAC, global sanctions lists, and known illicit wallet databases in real time. Deposits from flagged addresses are blocked before the balance is credited to the account, so a tainted contribution is stopped at the point of receipt rather than discovered in a later review.
Frequently Asked Questions
Is KYC legally required for a token sale?
It depends on the structure. MiCA places disclosure duties on the offeror, not identity duties. The AML duty attaches to the licensed crypto-asset service provider in the payment path. Sanctions law binds every party regardless.
Can investors from restricted jurisdictions take part in an ICO?
No. Sanctioned individuals and territories are barred outright, and that applies whether or not the issuer is licensed. Issuers also exclude further countries by choice, usually for securities law or tax reasons.















