us

216.73.216.229

How Mature Is Your Crypto Compliance Operation? — report cover showing the five maturity levels from Reactive to Adaptive
The Crypto Compliance Maturity Model

How Mature Is Your Crypto Compliance Operation?

Nine capability pillars, five maturity levels, and a score from 0 to 100

Regulatory compliance is the floor. This framework measures what sits above it, so a compliance leader can see where an operation stands today, which gaps cap it, and what to fix next.

Schedule a Demo

Key takeaways

  1. 01Regulatory compliance is the floor of a crypto compliance operation. What sits above it decides cost, resilience, and how far the operation can grow.
  2. 02102 of 109 surveyed jurisdictions have Travel Rule legislation in force or in progress, so meeting it marks an operation as present, not advanced.
  3. 03Every level from 2 upwards carries a binary gate and an evidence test, so a rating can be failed rather than argued.
  4. 04The pillar profile matters more than the score. Two operations can share an Index and look nothing alike.
  5. 05Any pillar two or more levels below the overall level is a critical gap, and it caps the whole operation.

Why is compliance the floor rather than the finish line?

In its seventh targeted update of 15 July 2026, the Financial Action Task Force (FATF) reported that 91 of 109 surveyed jurisdictions had Travel Rule legislation in force, with a further 11 in progress, taking the combined figure to 102 of 109. Adoption at that scale changes what the rule signals, because a control almost every material market has legislated no longer marks an operation out as advanced. It marks it as present.

Legislating the rule and supervising it are not the same thing. The same update found that of the 91 jurisdictions with Travel Rule legislation in force, 55 have not yet issued findings or directives or taken enforcement action against VASPs on Travel Rule compliance.

Two virtual asset service providers can both satisfy the Travel Rule and run completely different operations. One clears a compliant transfer in minutes at a few cents of cost, while the other takes a week, leans on spreadsheets, and adds headcount for every rise in volume. Both meet their obligations, but only one is built to scale.

That gap in compliance operations is what this framework measures. The market has spent years asking crypto businesses which protocol they support and whether they are compliant, and those questions are close to binary. The questions that predict cost, resilience, and growth are harder. How much manual effort does a compliant transfer take? How quickly can the operation absorb a new regulation or a new market? How well do the compliance systems actually work together? This framework turns those into a score.

Figure 01 · The Travel Rule across FATF, the EU, and the US
RegimeInstrumentBindsThresholdStatus
FATF (global standard) Recommendation 16, via the Interpretive Note to Recommendation 15 VASPs USD/EUR 1,000 for occasional transactions Travel Rule extended June 2019. Recommendation 16 revised June 2025, in effect by end 2030
European Union Regulation (EU) 2023/1113 (Transfer of Funds Regulation) CASPs No de minimis for crypto transfers Applies from 30 December 2024
United States 31 CFR 1010.410(e) and (f) (Bank Secrecy Act) Financial institutions USD 3,000 In force. 2020 proposal to lower the cross-border threshold not finalized

Regulatory position verified against primary sources on 12 August 2026. Thresholds, effective dates, and scope vary by jurisdiction and change over time. Confirm the current position for your own markets before relying on any figure here.

Enforcement example

The gap is not theoretical.

On 11 October 2022, Bittrex settled with both OFAC and FinCEN over conduct between 2014 and 2018.

FinCEN found the exchange relied on as few as two employees to manually review every transaction for suspicious activity, at volumes that reached an average of 23,800 transactions a day worth about $97.9 million. OFAC found that Bittrex collected IP address and physical address data from every customer at onboarding and did not screen it against sanctioned jurisdictions, letting through 116,421 apparent violations worth $263.5 million. Bittrex was a licensed, operating exchange with a compliance program. The program did not scale, and its systems did not talk to each other. The penalties came to roughly $29.3 million.

A program built to clear one obligation, in one jurisdiction, at one threshold, on one messaging rail can be fully compliant today and structurally fragile tomorrow, because it breaks the first time a transfer crosses a border, meets a different threshold, or lands on a counterparty using a different protocol. An operation that meets the baseline is in the game. That says little about whether that operation can carry the load as volume, jurisdictions, and attack patterns multiply.

What is the Crypto Compliance Maturity Model?

The Crypto Compliance Maturity Model is a self-assessment framework that rates a crypto compliance operation across nine capability pillars and five maturity levels, then summarizes the result as a single score from 0 to 100, the Crypto Compliance Maturity Index.

The framework exists to answer the harder questions, the ones about manual effort, speed of adaptation, and how well the systems work together. It gives a compliance leader a structured way to benchmark where an operation sits today, see where the biggest gaps are, decide what capability to invest in next, and understand how to grow without cost and headcount rising at the same rate. It is built for Heads of Compliance, Money Laundering Reporting Officers (MLROs), Chief Compliance Officers, and the operations, risk, and engineering leaders who carry the same responsibility at virtual asset service providers (VASPs), crypto-asset service providers (CASPs), exchanges, and financial institutions.

What it produces

Three things, in order of importance. A rating on each of the nine pillars, which is the primary output. An Index from 0 to 100, which is the shorthand and the language to use with a board, an auditor, or a partner. And a flag on any pillar sitting far enough below the rest to cap the whole operation, because a single weak link limits real-world resilience no matter how strong everything around it looks.

What it is not

A qualitative self-assessment instrument rather than an empirical study or a validated benchmark. Every level from 2 upwards carries a binary gate and an evidence test, which makes a rating harder to inflate and easier for an internal audit function to check. The limits are set out in the methodology note at the end.

What are the five maturity levels?

The framework places a compliance operation on a five-level curve, and every level answers one question. What is actually doing the work?

Figure 02 · The five maturity levels
Manual, costly, fragile
01ReactiveThe person is the system
02EnabledCapability exists, nothing joins it
03IntelligentPolicy decides, people handle exceptions
04OptimizedOne data layer, tuned on measurement
05AdaptiveChange absorbed as an input
Automated, low cost, resilient

Bar length shows maturity, not how many operations sit at each level. This framework makes no claim about how maturity is distributed across the market.

Level 1Reactive

The person is the system. Capability lives in individuals and static documents, and work starts when something outside prompts it, whether a regulator, a bank, an alert, or a complaint. Costs are high, visibility is low, and the only way to handle more volume is to hire.

Level 2Enabled

The capability exists, but nothing joins its parts. Tooling is in place and the basics work. Travel Rule messaging runs on at least one rail, screening happens, obligations are documented, and someone is accountable. The pieces do not talk to each other, so a person still does the joining. Compliant, and not yet efficient.

Level 3Intelligent

Policy decides, and people handle exceptions. Risk-based decisioning clears the routine and routes only genuine exceptions to a human. Customer, counterparty, wallet, and jurisdiction signals feed decisions, and policy changes are made by configuration, not engineering. The operation is consistent, explainable, and noticeably leaner.

Level 4Optimized

One data layer, tuned against measured outcomes. The stack behaves as one platform on a single authoritative record, and the operation improves against numbers rather than opinion. Automation is high, exceptions are low, and audit-readiness is a standing state rather than a scramble.

Level 5Adaptive

Change is absorbed as an input. New rules, rails, jurisdictions, and risk typologies are taken on without re-architecting, often ahead of enforcement dates, and compliance scales with volume without a matching rise in headcount. Level 5 should be rare.

How is a level claimed?

Every cell carries three things.

  • Descriptor. How the operation works at that level.
  • Gate. The one binary sentence that decides the rating.
  • Evidence test. The artifact, measurement, or behavior that proves the gate.

All three sit inside the assessment below. Each option shows its gate, and Show detail, at the top of each step, opens the descriptor and evidence test for all five levels at once.

Four rules for claiming a level

  1. 1

    Levels are cumulative. An operation sits at the highest level whose gate it passes, and whose lower gates it also passes, so passing the Level 4 gate while failing Level 3 scores Level 2. Start at Level 2 and climb, then stop at the first gate you fail and score the level below it. Level 1 sits at the bottom of the scale, carries no gate, and uses a recognition test instead.

  2. 2

    Compound gates require every clause. Several gates carry more than one condition, and a failure on any single clause fails the whole gate. Partial satisfaction scores the level below, and the partial state should be recorded, because it is usually the most useful finding on that pillar.

  3. 3

    A gate whose triggering event has not occurred is not met. Some gates ask what happened the last time the operation launched a market, onboarded a rail, or met a new typology. If that event has never arisen, score the level below and record the pillar as untested, not assumed. An untested capability is a real finding, not an administrative gap.

  4. 4

    Instance-based gates test routine practice. Where a gate asks for a documented instance in the last twelve months, that instance is evidence the practice is routine. One deliberate exercise staged to pass the assessment does not satisfy it.

How to score honestly

Score the level the operation has fully achieved today, not the highest level for which some evidence exists somewhere, and not the level the roadmap will deliver. Partial achievement of a level scores the level below. Where the honest answer sits between two levels, take the lower one, because the framework is more useful when it is uncomfortable. Score the operation as a whole, and where a capability is mature in one business line and absent in another, score the weaker one and note the split. That split is itself the finding.

How does the Crypto Compliance Maturity Index work?

The Index summarizes nine pillar ratings into one number from 0 to 100. It is a directional summary rather than a validated benchmark, and its value depends on the honesty of the inputs. The nine-pillar profile is the primary output, and the Index is the shorthand for it.

Rate the operation on each pillar from 1 to 5, average the nine ratings, then convert to a 0 to 100 scale. The assessment below does this for you.

Index = ((average pillar level − 1) / 4) × 100
Figure 03 · The Index band scale, 0 to 100
  • 0 to 20Reactive
  • 21 to 40Enabled
  • 41 to 60Intelligent
  • 61 to 80Optimized
  • 81 to 100Adaptive

An operation sitting at Level 1 across the board lands at 0, and one at Level 5 across the board reaches 100. The Index is rounded to the nearest whole number before it is banded, and a half value rounds to the higher whole number. All nine pillars carry equal weight in this version.

Overall level throughout this framework means the band the rounded Index falls into, rather than the rounded or floored average of the pillar levels. The critical-gap rule below is measured against it.

How do you read your results?

The framework gives three things to act on, and the order matters.

The Index and level are the headline. They place the operation overall and give a shared language for the board, auditors, and partners. A number and a named level travel further in a governance conversation than a folder of process documents.

The pillar profile is the diagnosis. Viewed as a nine-spoke radar, it shows where the operation leads and where it lags. Two operations can share an Index and look nothing alike, which is why the profile matters more than the number. Three short examples make the point, and the first and last share an Index of 44.

Figure 04 · Three profiles
Radar chart of nine pillar ratings comparing three profiles: the hidden gap at Index 44, the even climber at Index 50, and the uneven build at Index 44
A. The hidden gap · Index 44 B. The even climber · Index 50 C. The uneven build · Index 44

A · The hidden gap

Index44
Critical gap

Eight pillars at Level 3, wallet and transaction assurance at Level 1. Average 2.78.

The Index reads as a solid Level 3. The wallet pillar two levels below everything else is a critical gap, and it exposes the business where a crypto operation can least afford it. The number flatters the operation, and the profile tells the truth.

B · The even climber

Index50
No flag

All nine pillars at Level 3.

A clean Level 3 with no critical gap and no uneven-profile flag. This operation is genuinely level, and its next move is to raise every pillar rather than patch a hole.

C · The uneven build

Index44
Uneven profile

Regulatory readiness and counterparty operations at Level 5, reporting at Level 3, the remaining six pillars at Level 2.

The same Index as Profile A. No pillar sits two or more levels below the overall level, so no critical gap fires. The spread of three levels between the strongest and weakest pillars triggers the uneven-profile flag instead. This operation has invested hard in two capabilities and left seven behind.

The flags are the sequence. Any pillar two or more levels below the overall level is a critical gap, and a weak link caps real-world resilience no matter how strong the rest of the operation looks. In compliance, a single hole, such as no real wallet screening, is a risk that strength elsewhere cannot offset. Where no critical gap fires but the highest pillar sits three or more levels above the lowest, the profile is flagged as uneven instead, which says the operation has invested unevenly.

For example, an operation with mature onboarding, screening, and reporting but a Level 1 wallet pillar will verify a customer to a high standard, clear them through sanctions screening, then send funds to an address it has never screened. The strong pillars will record that transfer accurately. None of them can stop it.

The most efficient way up is usually to lift the lowest pillars to the median before pushing the whole operation to the next level, because filling a gap tends to reduce more risk and free more capacity per unit of effort than improving a pillar that is already strong. Close the gaps, then raise every pillar. That sequence repeats at every level, and it is the roadmap.

Figure 05 · The roadmap from Level 1 to Level 5
1L1 · Reactive
1Close critical gaps2Raise every pillar
Put core tooling and named accountability in place.
2L2 · Enabled
1Close critical gaps2Raise every pillar
Let policy drive decisions so people handle only genuine exceptions.
3L3 · Intelligent
1Close critical gaps2Raise every pillar
Unify your data and tune the operation against measured outcomes.
4L4 · Optimized
1Close critical gaps2Raise every pillar
Make the operation absorb regulatory, market, and network change on its own.
5L5 · Adaptive
Hold position
Hold the line as rails, rules, and volumes keep changing.

The cycle repeats at every level. Close any critical gap, raise every pillar to the level above, then take on the next level’s organizing principle.

Rate your own operation

What is your Crypto Compliance Maturity Index?

Rate your operation on the nine capability pillars. For each one, start at Level 2 and climb, then stop at the first gate your operation fails and choose the level below it. Where a gate carries more than one clause, every clause must hold. Where a gate turns on an event that has never happened at your organization, the gate is not met.

The assessment computes your Index from 0 to 100, places you in one of five levels, and shows where your critical gaps sit. Nothing you enter leaves this page.

One pillar at a time, nine in all. Each option shows the gate, and Show detail, at the top of each step, opens the descriptor and evidence test for all five levels at once. You can go back at any point, and every answer can be changed from the summary at the end. The section after this one names all nine pillars and what each covers.

The Crypto Compliance Maturity Index is a self-assessment instrument. Index equals the average of your nine pillar levels, on a 1 to 5 scale, converted to a 0 to 100 range and rounded to the nearest whole number. All nine pillars carry equal weight. A critical gap is any pillar two or more levels below your overall level. An uneven profile is a spread of three or more levels between your highest and lowest pillar where no critical gap fires. The Index is a directional summary and a prompt for action, not a validated benchmark. A decision aid, not legal or regulatory advice. Crypto Compliance Maturity Model, version 1.0.

What are the nine capability pillars?

Maturity is not one thing, so the framework measures nine capabilities, grouped in three domains. The assessment above rates each one, and every option there carries the full descriptor, gate, and evidence test for that level.

Domain A

Govern

How the operation is directed, decided, and kept current with the rules.

  1. 01Governance, accountability and people
  2. 02Risk assessment, policy and decisioning
  3. 03Regulatory and jurisdictional readiness
Domain B

Know

Who and what the operation is dealing with, on both sides of a relationship and a transfer.

  1. 04Customer due diligence and onboarding
  2. 05Counterparty and network operations
  3. 06Wallet and transaction assurance
Domain C

Prove

What the operation catches, and what it can show afterwards.

  1. 07Screening, monitoring and suspicious activity
  2. 08Reporting and auditability
Foundation

Every domain above depends on this one. An operation cannot govern, know, or prove on data its systems do not share.

09Systems integration and data unification
Indicative metric anchors

Three pillars carry a metric you can use as a second check on your rating. Take the highest level whose band the operation meets. The bands start at Level 2 because a Level 1 operation has no consistent process to measure. Its numbers land in the Level 2 band.

Pillar 2Lower is better
Manual-review rate

Share of in-scope activity touched by a human

100%
40%15%5%
0%
40% or aboveL2 · Enabled
Under 40%L3 · Intelligent
Under 15%L4 · Optimized
Under 5%L5 · Adaptive
Pillar 3Lower is better
Time to stand up a new jurisdiction

Elapsed time from decision to live in a new market

24 months
6 months1 month1 week
1 day
6 months or moreL2 · Enabled
Under 6 monthsL3 · Intelligent
Under 1 monthL4 · Optimized
Under 1 weekL5 · Adaptive
Pillar 5Higher is better
Travel Rule delivery success rate

In-scope outbound transfers where the required data was delivered and acknowledged

0%
50%80%95%
100%
Under 50%L2 · Enabled
50% or aboveL3 · Intelligent
80% or aboveL4 · Optimized
95% or aboveL5 · Adaptive

Band widths are drawn to scale on each metric’s own axis. Time uses a logarithmic scale.

These are reasoned anchors derived from the logic of the levels, not measured industry benchmarks, and where an anchor and a gate disagree the gate wins. A gate is a structural fact about how the operation works, whereas a metric can be distorted by product mix, customer base, or volume.

For example, an operation serving mostly low-risk retail customers can show a manual-review rate under 15% while still routing every exception to a person by hand. The metric reads Level 4. The gate, which asks whether policy makes the decision, does not.

What does higher maturity actually buy?

The nine pillars describe what an operation builds. They do not, on their own, prove the building was worth it. That proof lives in a second layer of measures the framework tracks but does not score. An operation does not become efficient by aiming at efficiency. It becomes efficient because the capabilities beneath it matured.

Figure 06 · The outcome layer
Outcome 01

Operational efficiency

The cost and effort per unit of compliance work

  • Compliance cost per transaction
  • Manual-review rate
  • Average investigation time
Outcome 02

Scalability

Whether the operation grows with volume without growing headcount

  • Time to stand up a new jurisdiction
  • Transfer volume per analyst
  • Time to implement a regulatory change
Outcome 03

Customer experience

The friction the compliance process imposes on legitimate users

  • Transfer completion rate
  • False-positive rate
  • Onboarding drop-off

If an operation climbs the pillars and these numbers do not move, it has added sophistication without adding value, and the framework has surfaced a finding that matters. Maturity that does not show up in cost, scale, and customer experience is not yet doing its job.

Two of these metrics also appear as indicative bands inside the pillars they most directly reflect. Manual-review rate anchors Pillar 2, and time to stand up a new jurisdiction anchors Pillar 3. Those bands are reasoned anchors to calibrate against rather than measured industry benchmarks, and where a band and a gate disagree, the gate wins. The gate is a structural fact about how the operation works, whereas the metric is an outcome that product mix, customer base, or volume can distort.

Does higher maturity require a single platform?

Trace any pillar from Level 1 up to Level 5 and the same pattern emerges. Maturity is in large part a story about consolidation. Reactive operations are fragmented, with many systems, many manual seams, and no shared view of a customer or a transfer. Adaptive operations run on one unified data layer, where identity, screening, monitoring, counterparty, wallet, and messaging draw on the same record and inform the same decisions.

That pattern helps explain why so many operations stall between Enabled and Optimized. The problem is usually not a missing point system. It is that the point systems do not operate as one. Every disconnected system can add another silo to reconcile, another integration to maintain, and another seam where risk hides and audit trails break.

For instance, an operation that adds a dedicated wallet-screening tool to a stack where onboarding, sanctions screening, and case management already sit apart now has a fourth risk signal an analyst must open a fourth window to see. The capability is real. The decision it should inform still gets made without it.

Past a certain point, more capability on a fragmented stack can lower maturity rather than raise it, because it adds coordination cost faster than it adds coverage.

Figure 07 · A mature operating model, nine pillars on one shared layer
The compliance lifecycle
Onboard a customer
Screen and risk-rate
Send or receive a transfer
Monitor and investigate
Report and evidence
Nine capability pillars, each reading from and writing to the same record
GovernGovernance, accountability and peopleRisk assessment, policy and decisioningRegulatory and jurisdictional readiness
KnowCustomer due diligence and onboardingCounterparty and network operationsWallet and transaction assurance
ProveScreening, monitoring and suspicious activityReporting and auditability
One case viewEvery pillar feeds the same record
09 Systems integration and data unification Identity, screening, monitoring, Travel Rule messaging, wallet assurance, counterparty risk, and the evidence trail all draw on the same real-time record and inform the same decisions.

The pillars, though, score outcomes rather than architecture. What the framework rewards is unified data, low coordination cost, and decisions that draw on shared context. A single platform is one way to reach that. A well-governed modular estate, with disciplined integration and a genuine shared data layer, can reach the same place. Consolidation is the common route to high maturity, not the only one, so read the pillars as a description of the destination and choose the architecture that gets there.

Figure 08 · How a single transfer moves through a mature decisioning layer
Transfer initiated
Counterparty discoveryIs the destination a hosted provider or a self-hosted wallet?
Hosted providerExchange and read riskExchange Travel Rule data with the counterparty and read its risk across sanctions, licensing, and jurisdiction.
Self-hosted walletVerify and screenVerify wallet ownership and screen the address for illicit exposure and sanctions before funds move.
Policy and risk decisionRisk-based decisioning clears the routine and routes only genuine exceptions to a person
Clear automaticallyLow-risk transfers pass without a human touch
Hold for reviewThe exception path, sent to an analyst
BlockProhibited or sanctioned, stopped and logged
Record, evidence, and report

What does this model not cover?

This framework covers the financial crime compliance operation of a virtual asset service provider, crypto-asset service provider, exchange, or financial institution handling crypto. Several adjacent disciplines sit outside it deliberately.

AreaWhy it is excluded
Custody, safeguarding of client assets, proof of reservesPrudential and operational obligations rather than financial crime compliance, with a different maturity curve.
Capital, liquidity, and financial resiliencePrudential, and outside the financial crime remit entirely.
Cyber security and operational resilienceAdjacent and important, with its own established maturity frameworks. This framework would duplicate that mature work poorly.
Consumer protection, marketing, financial promotionsConduct regulation rather than financial crime.
Tax reporting regimesA separate reporting obligation with its own architecture.
Payment fraud and scam preventionRelated, and often run by the same team, but a distinct discipline.

Glossary

VASP, virtual asset service provider

a business that exchanges, transfers, or safekeeps virtual assets on behalf of others.

CASP, crypto-asset service provider

the equivalent term used in EU regulation.

Travel Rule

the obligation to obtain, hold, and transmit originator and beneficiary information alongside a transfer.

IVMS101

the shared data format for the originator and beneficiary information exchanged under the Travel Rule.

Counterparty discovery

resolving which provider, if any, controls the wallet on the other end of a transfer. A self-hosted wallet has no provider on the other side, so ownership is proven instead.

Self-hosted wallet

a wallet controlled directly by an individual rather than by a service provider.

Sunrise problem

the situation where the counterparty or its jurisdiction is not yet set up to receive Travel Rule data at all, which differs from two systems being unable to interoperate.

Business-wide risk assessment

the documented assessment of the financial crime risks a business faces across its customers, products, channels, and markets, from which its policy and controls derive.

Critical gap

any pillar rated two or more levels below the overall level.

Unified data layer

a shared record that lets separate compliance functions draw on the same customer and transaction context.

Methodology and scope

This is a qualitative self-assessment framework rather than an empirical study. The five levels and nine pillars are an analytical model, and the Crypto Compliance Maturity Index is a computed self-assessment instrument rather than a validated metric. An operation’s Index is the average of its nine self-rated pillar levels, each on a 1 to 5 ordinal scale, normalized to a 0 to 100 range with the formula stated above and rounded to the nearest whole number before banding. All nine pillars are weighted equally. Equal weighting is a deliberate starting choice that keeps the instrument neutral and avoids implying a precision the inputs do not support, and a later version may re-weight if evidence supports it. The scoring space was checked by enumerating every one of the 1,953,125 possible nine-pillar combinations: the Index takes 37 distinct values and none of them lands exactly on 20, 40, 60, or 80, so no score falls ambiguously on a band boundary.

Known limitations

The inputs are ordinal self-ratings, so the Index carries the usual limits of self-assessment. The binary gates and evidence tests improve consistency between raters and make a rating harder to inflate, and they do not make the instrument validated. It has not been tested for inter-rater reliability and is not calibrated against a benchmark distribution, which is why the framework leads with the pillar profile and treats the number as a directional summary. Equal weighting is a starting choice, not an evidenced claim that the pillars matter equally. The framework carries no proprietary dataset and makes no empirical claim about how maturity is distributed across the market. The indicative metric bands on Pillars 2, 3, and 5 are reasoned anchors derived from the logic of the levels, not measured industry benchmarks. Statements about the effect of maturity on risk, cost, and customer experience are propositions of the model, offered as reasoning rather than measured findings.

Verification

The regulatory statements in this guide were verified against primary sources on 12 August 2026 and are date-stamped accordingly. Regulatory thresholds, effective dates, and scope change over time, and readers should confirm the current position for their own jurisdictions. This framework is offered as a decision aid, not as legal or regulatory advice.

The Crypto Compliance Maturity Model — guide cover
Guide page — the five maturity levels
Guide page — the Index band scale
Guide page — the nine capability pillars
Previous
01 - 04
Next

Certifications

Independently audited and certified for enterprise-grade security and data protection.

  • GDPR Compliant
  • GDPR Fundamentals
  • ISO 27001 Certified
  • CCPA
  • iBeta Level 3 ISO 30107-3 Compliant
  • PCI DSS Compliant
  • Shufti SOC 2 Type 2 Compliant

    search_cross_mobile

    Please complete the information below 
to download the whitepaper

    By clicking the "Submit" button, you are agreeing 
to the Terms & Conditions and Privacy Policy

    Frequently asked questions (FAQs)

    It is a framework that rates a crypto compliance operation across nine capability pillars and five maturity levels, then summarizes the result as a score from 0 to 100. It is designed to benchmark where an operation sits, surface its biggest gaps, and guide what to improve next.

    Was this content helpful?

    No. Travel Rule compliance is a regulatory baseline that many operations meet at Level 2. Maturity measures how efficiently, consistently, and sustainably an operation meets that baseline and everything around it, so an operation can be fully compliant and still sit at Level 2.

    Was this content helpful?

    No. The Index is a directional summary of nine self-ratings. It has not been tested for inter-rater reliability and is not calibrated against an external distribution. Treat it as a shared language and a prompt for action, and rely on the pillar profile for the detail.

    Was this content helpful?

    Rate each of the nine pillars from 1 to 5, average the nine ratings, then convert to a 0 to 100 scale with the formula ((average pillar level minus 1) divided by 4) multiplied by 100. The result is rounded to the nearest whole number before it is banded, and all nine pillars carry equal weight.

    Was this content helpful?

    Every level from 2 upwards carries a binary gate and an evidence test. A gate can be failed, and the evidence test names the artifact or measurement that proves it, so a rating can be checked by an internal audit function, not just asserted.

    Was this content helpful?

    Start with any critical gap, meaning any pillar two or more levels below your overall level. A filled gap tends to reduce more risk and free more capacity per unit of effort than an improvement to a pillar that is already strong.

    Was this content helpful?

    Score the level below and record the pillar as untested. A capability nobody has exercised is a real finding rather than an administrative gap, and treating it as passed would overstate the result.

    Was this content helpful?

    No framework guarantees an outcome. A higher level means the operation is more automated, more consistent, and more able to absorb change, which tends to lower the likelihood and the cost of failures. Residual risk always remains and still needs active management.

    Was this content helpful?
    n-img-roi-cross

    Form submitted successfully!

    Thank you for your interest — your report is loading now.

    See what an Adaptive operation looks like on one platform

    Identity, screening, monitoring, wallet assurance and the evidence trail on a single record, in 240+ countries and territories.

      Let’s Tailor Your Journey

      Which products would you like to check out?

      VideoIdent

      Address Verification

      eIDV (Docless)

      KYB

      AML Screening

      Deepfake Detection

      Face and ID Verification

      Age Verification

      Others

      What is your expected yearly verification volume?

      1 to 1,000

      1,001 to 5,000

      5,001 to 20,000

      20,001 to 50,000

      50,001 to 100,000

      100,001 to 1,000,000

      1,000,000+

      Valid Invalid number

      By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

      Product Guide

      Qualified Electronic Signature: EU & EEA Country Guide | Shufti

      qualified-electronic-signature-eu-eea-guide-feature-img
      report

      Identity Fraud Report 2026 | Shufti

      Product Guide

      Guide to Docless Identity Verification in the US and Canada

      Product Guide

      AMLR Readiness Checklist: 2027 Gap Assessment | Shufti

      amlr-readiness-checklist Featured image
      Product Guide

      Shufti’s 2026 Context Gap in AML Risk Assessment

      the-context-gap-in-aml-risk-assessment-ftr-img
      Product Guide

      Customizable KYC Solution for KYC Product Owners

      Product Guide

      Docless KYC Verification in APAC to Onboard More Genuine Users

      Cover of the Shufti guide to docless KYC verification in APAC
      Product Guide

      EU AMLR Guide 2027: Requirements, Scope, Deadlines | Shufti

      Cover of the Shufti EU AMLR 2027 compliance guide
      Product Guide

      APAC Child Safety Age Verification Regulations

      APAC Child Safety Age Verification Regulations
      Product Guide

      Docless Identity Verification in the Middle East

      docless-identity-verification-middle-east
      Product Guide

      The Future of Docless Verification in Europe

      Onboard already verified users with Docless Verification in Europe
      Product Guide

      Cyprus 2026 KYC Operators Guide to Improve First Pass Rate

      Cyprus 2026 KYC Operators Guide to Improve First Pass Rate
      Product Guide

      Philippines KYC & Account-Owner Verification Playbook | Shufti

      Philippines KYC & Account-Owner Verification Playbook | Shufti
      Product Guide

      Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls

      Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls
      Product Guide

      CySEC Forex KYC Compliance Handbook 2026 | Shufti

      CySEC Forex KYC Compliance Handbook 2026 | Shufti
      Product Guide

      Singapore KYC & AML Compliance Guide 2026 | Shufti

      Singapore KYC & AML Compliance Guide 2026 | Shufti
      Product Guide

      Mexico 2026 KYC Handbook to Improve First Pass Rate

      Mexico 2026 KYC Handbook to Improve First Pass Rate
      Product Guide

      Where Can Identity Data Legally Live? 2026 Guide | Shufti

      Where Can Identity Data Legally Live? 2026 Guide | Shufti
      Product Guide

      Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026

      Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026
      Whitepaper

      KYC Compliance and Identity Fraud Challenge Across APAC

      KYC Compliance and Identity Fraud Challenge Across APAC
      Product Guide

      Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti

      Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti
      Product Guide

      Malta iGaming KYC & AML Readiness Guide 2026| Shufti

      Malta iGaming KYC & AML Readiness Guide 2026| Shufti
      Product Guide

      Brazil 2026 KYC Playbook to Improve First Pass Rate

      Brazil 2026 KYC Playbook to Improve First Pass Rate
      Product Guide

      Malta 2026 KYC Playbook to Improve First Pass Rate

      Malta 2026 KYC Playbook to Improve First Pass Rate
      Whitepaper

      The Deepfake Detection Gap

      The Deepfake Detection Gap
      Product Guide

      Choosing the Right Identity Verification Vendor for the Forex Sector

      Choosing the Right Identity Verification Vendor for the Forex Sector
      Product Guide

      A Comprehensive Guide to Address Verification in Complex Markets

      A Comprehensive Guide to Address Verification in Complex Markets
      Whitepaper

      Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems

      Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems
      Product Guide

      Human – Assisted Video KYC for Regulated Businesses:

      Human – Assisted Video KYC for Regulated Businesses:
      Whitepaper

      Re-Thinking RegTech for KYC Compliance

      Re-Thinking RegTech for KYC Compliance
      Product Guide

      Enterprise Guide to Choose Right Identity Verification Solution

      Enterprise Guide to Choose Right Identity Verification Solution
      report

      Global Age-Verification Laws 2025 Snapshot

      Global Age-Verification Laws 2025 Snapshot
      Whitepaper

      The Backbone of Global Trust

      The Backbone of Global Trust
      report

      State of Global AML Compliance 2025

      State of Global AML Compliance 2025
      Product Guide

      Strategic ID Verification Vendor for Crypto Industry

      Strategic ID Verification Vendor for Crypto Industry
      report

      Market Positioning and Commercial Assessment Results Presentation

      Market Positioning and Commercial Assessment Results Presentation
      Whitepaper

      Preventing Account Takeover Fraud with Multilayered Defense

      Preventing Account Takeover Fraud with Multilayered Defense
      Whitepaper

      The Critical 1% Closing Systemic Gaps In Global Identity Verification

      The Critical 1% Closing Systemic Gaps In Global Identity Verification
      Whitepaper

      Outsmarting the Deepfake Threat to Identity Trust

      Outsmarting the Deepfake Threat to Identity Trust
      Product Guide

      Scale Without Borders

      Scale Without Borders
      report

      Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust

      Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust
      report

      Top 10 Most Difficult Countries for Identity Verification

      Top 10 Most Difficult Countries for Identity Verification
      Whitepaper

      KYC & AML IN THE MENA Region White Paper 2023

      KYC & AML IN THE MENA Region White Paper 2023
      Whitepaper

      Shufti’s iGaming White Paper 2023

      Shufti’s iGaming White Paper 2023
      report

      Shufti Identity Fraud Report 2022

      Shufti Identity Fraud Report 2022
      report

      Shufti Fraud Report 2021

      Shufti Fraud Report 2021
      report

      Holiday Season – The Prime Time for ID Thieves and Financial Criminals

      Holiday Season – The Prime Time for ID Thieves and Financial Criminals
      report

      Shufti Completes 4 Years of Fighting ID Fraud

      Shufti Completes 4 Years of Fighting ID Fraud
      Product Guide

      On-premises Identity Verification for the Banking Sector

      On-premises Identity Verification for the Banking Sector
      Whitepaper

      Shrinking the Space for Travel Industry Scams with Biometric Verification

      Shrinking the Space for Travel Industry Scams with Biometric Verification
      Product Guide

      Global Gambling Compliance: Regulations, Age Checks & Financial Safety

      Global Gambling Compliance: Regulations, Age Checks & Financial Safety
      report

      A comprehensive guide to KYC and AML compliance in Canada

      A comprehensive guide to KYC and AML compliance in Canada
      n-img-roi-cross

      Form submitted successfully!

      Thank you for your interest — your report is loading now.

      Take the next steps to better security.

      Contact us

      Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

      Contact us

      Get the Shufti newsletter

      Stay ahead of the curve with fresh takes on the latest identity innovations.

        Take the next steps to better security.

        Contact us

        Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

        Contact us

        Request demo

        Get free access to our platform and try our products today.

        Get started

        Pitch a piece and get a verified byline in the Media room.

        Partnership Inquiries?
        Email us at [email protected]

        iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
        Copyright © 2026 Shufti. All rights reserved.