How Mature Is Your Crypto Compliance Operation?
Nine capability pillars, five maturity levels, and a score from 0 to 100
Regulatory compliance is the floor. This framework measures what sits above it, so a compliance leader can see where an operation stands today, which gaps cap it, and what to fix next.
Schedule a DemoKey takeaways
- 01Regulatory compliance is the floor of a crypto compliance operation. What sits above it decides cost, resilience, and how far the operation can grow.
- 02102 of 109 surveyed jurisdictions have Travel Rule legislation in force or in progress, so meeting it marks an operation as present, not advanced.
- 03Every level from 2 upwards carries a binary gate and an evidence test, so a rating can be failed rather than argued.
- 04The pillar profile matters more than the score. Two operations can share an Index and look nothing alike.
- 05Any pillar two or more levels below the overall level is a critical gap, and it caps the whole operation.
Why is compliance the floor rather than the finish line?
In its seventh targeted update of 15 July 2026, the Financial Action Task Force (FATF) reported that 91 of 109 surveyed jurisdictions had Travel Rule legislation in force, with a further 11 in progress, taking the combined figure to 102 of 109. Adoption at that scale changes what the rule signals, because a control almost every material market has legislated no longer marks an operation out as advanced. It marks it as present.
Legislating the rule and supervising it are not the same thing. The same update found that of the 91 jurisdictions with Travel Rule legislation in force, 55 have not yet issued findings or directives or taken enforcement action against VASPs on Travel Rule compliance.
Two virtual asset service providers can both satisfy the Travel Rule and run completely different operations. One clears a compliant transfer in minutes at a few cents of cost, while the other takes a week, leans on spreadsheets, and adds headcount for every rise in volume. Both meet their obligations, but only one is built to scale.
That gap in compliance operations is what this framework measures. The market has spent years asking crypto businesses which protocol they support and whether they are compliant, and those questions are close to binary. The questions that predict cost, resilience, and growth are harder. How much manual effort does a compliant transfer take? How quickly can the operation absorb a new regulation or a new market? How well do the compliance systems actually work together? This framework turns those into a score.
Figure 01 · The Travel Rule across FATF, the EU, and the US| Regime | Instrument | Binds | Threshold | Status |
|---|---|---|---|---|
| FATF (global standard) | Recommendation 16, via the Interpretive Note to Recommendation 15 | VASPs | USD/EUR 1,000 for occasional transactions | Travel Rule extended June 2019. Recommendation 16 revised June 2025, in effect by end 2030 |
| European Union | Regulation (EU) 2023/1113 (Transfer of Funds Regulation) | CASPs | No de minimis for crypto transfers | Applies from 30 December 2024 |
| United States | 31 CFR 1010.410(e) and (f) (Bank Secrecy Act) | Financial institutions | USD 3,000 | In force. 2020 proposal to lower the cross-border threshold not finalized |
Regulatory position verified against primary sources on 12 August 2026. Thresholds, effective dates, and scope vary by jurisdiction and change over time. Confirm the current position for your own markets before relying on any figure here.
The gap is not theoretical.
On 11 October 2022, Bittrex settled with both OFAC and FinCEN over conduct between 2014 and 2018.
FinCEN found the exchange relied on as few as two employees to manually review every transaction for suspicious activity, at volumes that reached an average of 23,800 transactions a day worth about $97.9 million. OFAC found that Bittrex collected IP address and physical address data from every customer at onboarding and did not screen it against sanctioned jurisdictions, letting through 116,421 apparent violations worth $263.5 million. Bittrex was a licensed, operating exchange with a compliance program. The program did not scale, and its systems did not talk to each other. The penalties came to roughly $29.3 million.
A program built to clear one obligation, in one jurisdiction, at one threshold, on one messaging rail can be fully compliant today and structurally fragile tomorrow, because it breaks the first time a transfer crosses a border, meets a different threshold, or lands on a counterparty using a different protocol. An operation that meets the baseline is in the game. That says little about whether that operation can carry the load as volume, jurisdictions, and attack patterns multiply.
What is the Crypto Compliance Maturity Model?
The Crypto Compliance Maturity Model is a self-assessment framework that rates a crypto compliance operation across nine capability pillars and five maturity levels, then summarizes the result as a single score from 0 to 100, the Crypto Compliance Maturity Index.
The framework exists to answer the harder questions, the ones about manual effort, speed of adaptation, and how well the systems work together. It gives a compliance leader a structured way to benchmark where an operation sits today, see where the biggest gaps are, decide what capability to invest in next, and understand how to grow without cost and headcount rising at the same rate. It is built for Heads of Compliance, Money Laundering Reporting Officers (MLROs), Chief Compliance Officers, and the operations, risk, and engineering leaders who carry the same responsibility at virtual asset service providers (VASPs), crypto-asset service providers (CASPs), exchanges, and financial institutions.
What it produces
Three things, in order of importance. A rating on each of the nine pillars, which is the primary output. An Index from 0 to 100, which is the shorthand and the language to use with a board, an auditor, or a partner. And a flag on any pillar sitting far enough below the rest to cap the whole operation, because a single weak link limits real-world resilience no matter how strong everything around it looks.
What it is not
A qualitative self-assessment instrument rather than an empirical study or a validated benchmark. Every level from 2 upwards carries a binary gate and an evidence test, which makes a rating harder to inflate and easier for an internal audit function to check. The limits are set out in the methodology note at the end.
What are the five maturity levels?
The framework places a compliance operation on a five-level curve, and every level answers one question. What is actually doing the work?
Figure 02 · The five maturity levelsBar length shows maturity, not how many operations sit at each level. This framework makes no claim about how maturity is distributed across the market.
The person is the system. Capability lives in individuals and static documents, and work starts when something outside prompts it, whether a regulator, a bank, an alert, or a complaint. Costs are high, visibility is low, and the only way to handle more volume is to hire.
The capability exists, but nothing joins its parts. Tooling is in place and the basics work. Travel Rule messaging runs on at least one rail, screening happens, obligations are documented, and someone is accountable. The pieces do not talk to each other, so a person still does the joining. Compliant, and not yet efficient.
Policy decides, and people handle exceptions. Risk-based decisioning clears the routine and routes only genuine exceptions to a human. Customer, counterparty, wallet, and jurisdiction signals feed decisions, and policy changes are made by configuration, not engineering. The operation is consistent, explainable, and noticeably leaner.
One data layer, tuned against measured outcomes. The stack behaves as one platform on a single authoritative record, and the operation improves against numbers rather than opinion. Automation is high, exceptions are low, and audit-readiness is a standing state rather than a scramble.
Change is absorbed as an input. New rules, rails, jurisdictions, and risk typologies are taken on without re-architecting, often ahead of enforcement dates, and compliance scales with volume without a matching rise in headcount. Level 5 should be rare.
How is a level claimed?
Every cell carries three things.
- Descriptor. How the operation works at that level.
- Gate. The one binary sentence that decides the rating.
- Evidence test. The artifact, measurement, or behavior that proves the gate.
All three sit inside the assessment below. Each option shows its gate, and Show detail, at the top of each step, opens the descriptor and evidence test for all five levels at once.
Four rules for claiming a level
- 1
Levels are cumulative. An operation sits at the highest level whose gate it passes, and whose lower gates it also passes, so passing the Level 4 gate while failing Level 3 scores Level 2. Start at Level 2 and climb, then stop at the first gate you fail and score the level below it. Level 1 sits at the bottom of the scale, carries no gate, and uses a recognition test instead.
- 2
Compound gates require every clause. Several gates carry more than one condition, and a failure on any single clause fails the whole gate. Partial satisfaction scores the level below, and the partial state should be recorded, because it is usually the most useful finding on that pillar.
- 3
A gate whose triggering event has not occurred is not met. Some gates ask what happened the last time the operation launched a market, onboarded a rail, or met a new typology. If that event has never arisen, score the level below and record the pillar as untested, not assumed. An untested capability is a real finding, not an administrative gap.
- 4
Instance-based gates test routine practice. Where a gate asks for a documented instance in the last twelve months, that instance is evidence the practice is routine. One deliberate exercise staged to pass the assessment does not satisfy it.
How to score honestly
Score the level the operation has fully achieved today, not the highest level for which some evidence exists somewhere, and not the level the roadmap will deliver. Partial achievement of a level scores the level below. Where the honest answer sits between two levels, take the lower one, because the framework is more useful when it is uncomfortable. Score the operation as a whole, and where a capability is mature in one business line and absent in another, score the weaker one and note the split. That split is itself the finding.
How does the Crypto Compliance Maturity Index work?
The Index summarizes nine pillar ratings into one number from 0 to 100. It is a directional summary rather than a validated benchmark, and its value depends on the honesty of the inputs. The nine-pillar profile is the primary output, and the Index is the shorthand for it.
Rate the operation on each pillar from 1 to 5, average the nine ratings, then convert to a 0 to 100 scale. The assessment below does this for you.
Index = ((average pillar level − 1) / 4) × 100- 0 to 20Reactive
- 21 to 40Enabled
- 41 to 60Intelligent
- 61 to 80Optimized
- 81 to 100Adaptive
An operation sitting at Level 1 across the board lands at 0, and one at Level 5 across the board reaches 100. The Index is rounded to the nearest whole number before it is banded, and a half value rounds to the higher whole number. All nine pillars carry equal weight in this version.
Overall level throughout this framework means the band the rounded Index falls into, rather than the rounded or floored average of the pillar levels. The critical-gap rule below is measured against it.
How do you read your results?
The framework gives three things to act on, and the order matters.
The Index and level are the headline. They place the operation overall and give a shared language for the board, auditors, and partners. A number and a named level travel further in a governance conversation than a folder of process documents.
The pillar profile is the diagnosis. Viewed as a nine-spoke radar, it shows where the operation leads and where it lags. Two operations can share an Index and look nothing alike, which is why the profile matters more than the number. Three short examples make the point, and the first and last share an Index of 44.
Figure 04 · Three profiles
A · The hidden gap
Eight pillars at Level 3, wallet and transaction assurance at Level 1. Average 2.78.
The Index reads as a solid Level 3. The wallet pillar two levels below everything else is a critical gap, and it exposes the business where a crypto operation can least afford it. The number flatters the operation, and the profile tells the truth.
B · The even climber
All nine pillars at Level 3.
A clean Level 3 with no critical gap and no uneven-profile flag. This operation is genuinely level, and its next move is to raise every pillar rather than patch a hole.
C · The uneven build
Regulatory readiness and counterparty operations at Level 5, reporting at Level 3, the remaining six pillars at Level 2.
The same Index as Profile A. No pillar sits two or more levels below the overall level, so no critical gap fires. The spread of three levels between the strongest and weakest pillars triggers the uneven-profile flag instead. This operation has invested hard in two capabilities and left seven behind.
The flags are the sequence. Any pillar two or more levels below the overall level is a critical gap, and a weak link caps real-world resilience no matter how strong the rest of the operation looks. In compliance, a single hole, such as no real wallet screening, is a risk that strength elsewhere cannot offset. Where no critical gap fires but the highest pillar sits three or more levels above the lowest, the profile is flagged as uneven instead, which says the operation has invested unevenly.
For example, an operation with mature onboarding, screening, and reporting but a Level 1 wallet pillar will verify a customer to a high standard, clear them through sanctions screening, then send funds to an address it has never screened. The strong pillars will record that transfer accurately. None of them can stop it.
The most efficient way up is usually to lift the lowest pillars to the median before pushing the whole operation to the next level, because filling a gap tends to reduce more risk and free more capacity per unit of effort than improving a pillar that is already strong. Close the gaps, then raise every pillar. That sequence repeats at every level, and it is the roadmap.
Figure 05 · The roadmap from Level 1 to Level 5The cycle repeats at every level. Close any critical gap, raise every pillar to the level above, then take on the next level’s organizing principle.
Rate your own operation
What is your Crypto Compliance Maturity Index?
Rate your operation on the nine capability pillars. For each one, start at Level 2 and climb, then stop at the first gate your operation fails and choose the level below it. Where a gate carries more than one clause, every clause must hold. Where a gate turns on an event that has never happened at your organization, the gate is not met.
The assessment computes your Index from 0 to 100, places you in one of five levels, and shows where your critical gaps sit. Nothing you enter leaves this page.
One pillar at a time, nine in all. Each option shows the gate, and Show detail, at the top of each step, opens the descriptor and evidence test for all five levels at once. You can go back at any point, and every answer can be changed from the summary at the end. The section after this one names all nine pillars and what each covers.
The Crypto Compliance Maturity Index is a self-assessment instrument. Index equals the average of your nine pillar levels, on a 1 to 5 scale, converted to a 0 to 100 range and rounded to the nearest whole number. All nine pillars carry equal weight. A critical gap is any pillar two or more levels below your overall level. An uneven profile is a spread of three or more levels between your highest and lowest pillar where no critical gap fires. The Index is a directional summary and a prompt for action, not a validated benchmark. A decision aid, not legal or regulatory advice. Crypto Compliance Maturity Model, version 1.0.
What are the nine capability pillars?
Maturity is not one thing, so the framework measures nine capabilities, grouped in three domains. The assessment above rates each one, and every option there carries the full descriptor, gate, and evidence test for that level.
Govern
How the operation is directed, decided, and kept current with the rules.
- 01Governance, accountability and people
- 02Risk assessment, policy and decisioning
- 03Regulatory and jurisdictional readiness
Know
Who and what the operation is dealing with, on both sides of a relationship and a transfer.
- 04Customer due diligence and onboarding
- 05Counterparty and network operations
- 06Wallet and transaction assurance
Prove
What the operation catches, and what it can show afterwards.
- 07Screening, monitoring and suspicious activity
- 08Reporting and auditability
Every domain above depends on this one. An operation cannot govern, know, or prove on data its systems do not share.
Three pillars carry a metric you can use as a second check on your rating. Take the highest level whose band the operation meets. The bands start at Level 2 because a Level 1 operation has no consistent process to measure. Its numbers land in the Level 2 band.
Share of in-scope activity touched by a human
Elapsed time from decision to live in a new market
In-scope outbound transfers where the required data was delivered and acknowledged
Band widths are drawn to scale on each metric’s own axis. Time uses a logarithmic scale.
These are reasoned anchors derived from the logic of the levels, not measured industry benchmarks, and where an anchor and a gate disagree the gate wins. A gate is a structural fact about how the operation works, whereas a metric can be distorted by product mix, customer base, or volume.
For example, an operation serving mostly low-risk retail customers can show a manual-review rate under 15% while still routing every exception to a person by hand. The metric reads Level 4. The gate, which asks whether policy makes the decision, does not.
What does higher maturity actually buy?
The nine pillars describe what an operation builds. They do not, on their own, prove the building was worth it. That proof lives in a second layer of measures the framework tracks but does not score. An operation does not become efficient by aiming at efficiency. It becomes efficient because the capabilities beneath it matured.
Figure 06 · The outcome layerOperational efficiency
The cost and effort per unit of compliance work
- Compliance cost per transaction
- Manual-review rate
- Average investigation time
Scalability
Whether the operation grows with volume without growing headcount
- Time to stand up a new jurisdiction
- Transfer volume per analyst
- Time to implement a regulatory change
Customer experience
The friction the compliance process imposes on legitimate users
- Transfer completion rate
- False-positive rate
- Onboarding drop-off
If an operation climbs the pillars and these numbers do not move, it has added sophistication without adding value, and the framework has surfaced a finding that matters. Maturity that does not show up in cost, scale, and customer experience is not yet doing its job.
Two of these metrics also appear as indicative bands inside the pillars they most directly reflect. Manual-review rate anchors Pillar 2, and time to stand up a new jurisdiction anchors Pillar 3. Those bands are reasoned anchors to calibrate against rather than measured industry benchmarks, and where a band and a gate disagree, the gate wins. The gate is a structural fact about how the operation works, whereas the metric is an outcome that product mix, customer base, or volume can distort.
Does higher maturity require a single platform?
Trace any pillar from Level 1 up to Level 5 and the same pattern emerges. Maturity is in large part a story about consolidation. Reactive operations are fragmented, with many systems, many manual seams, and no shared view of a customer or a transfer. Adaptive operations run on one unified data layer, where identity, screening, monitoring, counterparty, wallet, and messaging draw on the same record and inform the same decisions.
That pattern helps explain why so many operations stall between Enabled and Optimized. The problem is usually not a missing point system. It is that the point systems do not operate as one. Every disconnected system can add another silo to reconcile, another integration to maintain, and another seam where risk hides and audit trails break.
For instance, an operation that adds a dedicated wallet-screening tool to a stack where onboarding, sanctions screening, and case management already sit apart now has a fourth risk signal an analyst must open a fourth window to see. The capability is real. The decision it should inform still gets made without it.
Past a certain point, more capability on a fragmented stack can lower maturity rather than raise it, because it adds coordination cost faster than it adds coverage.
Figure 07 · A mature operating model, nine pillars on one shared layerThe pillars, though, score outcomes rather than architecture. What the framework rewards is unified data, low coordination cost, and decisions that draw on shared context. A single platform is one way to reach that. A well-governed modular estate, with disciplined integration and a genuine shared data layer, can reach the same place. Consolidation is the common route to high maturity, not the only one, so read the pillars as a description of the destination and choose the architecture that gets there.
Figure 08 · How a single transfer moves through a mature decisioning layerWhat does this model not cover?
This framework covers the financial crime compliance operation of a virtual asset service provider, crypto-asset service provider, exchange, or financial institution handling crypto. Several adjacent disciplines sit outside it deliberately.
| Area | Why it is excluded | |
|---|---|---|
| Custody, safeguarding of client assets, proof of reserves | Prudential and operational obligations rather than financial crime compliance, with a different maturity curve. | |
| Capital, liquidity, and financial resilience | Prudential, and outside the financial crime remit entirely. | |
| Cyber security and operational resilience | Adjacent and important, with its own established maturity frameworks. This framework would duplicate that mature work poorly. | |
| Consumer protection, marketing, financial promotions | Conduct regulation rather than financial crime. | |
| Tax reporting regimes | A separate reporting obligation with its own architecture. | |
| Payment fraud and scam prevention | Related, and often run by the same team, but a distinct discipline. | |
Glossary
a business that exchanges, transfers, or safekeeps virtual assets on behalf of others.
the equivalent term used in EU regulation.
the obligation to obtain, hold, and transmit originator and beneficiary information alongside a transfer.
the shared data format for the originator and beneficiary information exchanged under the Travel Rule.
resolving which provider, if any, controls the wallet on the other end of a transfer. A self-hosted wallet has no provider on the other side, so ownership is proven instead.
a wallet controlled directly by an individual rather than by a service provider.
the situation where the counterparty or its jurisdiction is not yet set up to receive Travel Rule data at all, which differs from two systems being unable to interoperate.
the documented assessment of the financial crime risks a business faces across its customers, products, channels, and markets, from which its policy and controls derive.
any pillar rated two or more levels below the overall level.
a shared record that lets separate compliance functions draw on the same customer and transaction context.
Methodology and scope
This is a qualitative self-assessment framework rather than an empirical study. The five levels and nine pillars are an analytical model, and the Crypto Compliance Maturity Index is a computed self-assessment instrument rather than a validated metric. An operation’s Index is the average of its nine self-rated pillar levels, each on a 1 to 5 ordinal scale, normalized to a 0 to 100 range with the formula stated above and rounded to the nearest whole number before banding. All nine pillars are weighted equally. Equal weighting is a deliberate starting choice that keeps the instrument neutral and avoids implying a precision the inputs do not support, and a later version may re-weight if evidence supports it. The scoring space was checked by enumerating every one of the 1,953,125 possible nine-pillar combinations: the Index takes 37 distinct values and none of them lands exactly on 20, 40, 60, or 80, so no score falls ambiguously on a band boundary.
Known limitations
The inputs are ordinal self-ratings, so the Index carries the usual limits of self-assessment. The binary gates and evidence tests improve consistency between raters and make a rating harder to inflate, and they do not make the instrument validated. It has not been tested for inter-rater reliability and is not calibrated against a benchmark distribution, which is why the framework leads with the pillar profile and treats the number as a directional summary. Equal weighting is a starting choice, not an evidenced claim that the pillars matter equally. The framework carries no proprietary dataset and makes no empirical claim about how maturity is distributed across the market. The indicative metric bands on Pillars 2, 3, and 5 are reasoned anchors derived from the logic of the levels, not measured industry benchmarks. Statements about the effect of maturity on risk, cost, and customer experience are propositions of the model, offered as reasoning rather than measured findings.
Verification
The regulatory statements in this guide were verified against primary sources on 12 August 2026 and are date-stamped accordingly. Regulatory thresholds, effective dates, and scope change over time, and readers should confirm the current position for their own jurisdictions. This framework is offered as a decision aid, not as legal or regulatory advice.
Frequently asked questions (FAQs)
It is a framework that rates a crypto compliance operation across nine capability pillars and five maturity levels, then summarizes the result as a score from 0 to 100. It is designed to benchmark where an operation sits, surface its biggest gaps, and guide what to improve next.
No. Travel Rule compliance is a regulatory baseline that many operations meet at Level 2. Maturity measures how efficiently, consistently, and sustainably an operation meets that baseline and everything around it, so an operation can be fully compliant and still sit at Level 2.
No. The Index is a directional summary of nine self-ratings. It has not been tested for inter-rater reliability and is not calibrated against an external distribution. Treat it as a shared language and a prompt for action, and rely on the pillar profile for the detail.
Rate each of the nine pillars from 1 to 5, average the nine ratings, then convert to a 0 to 100 scale with the formula ((average pillar level minus 1) divided by 4) multiplied by 100. The result is rounded to the nearest whole number before it is banded, and all nine pillars carry equal weight.
Every level from 2 upwards carries a binary gate and an evidence test. A gate can be failed, and the evidence test names the artifact or measurement that proves it, so a rating can be checked by an internal audit function, not just asserted.
Start with any critical gap, meaning any pillar two or more levels below your overall level. A filled gap tends to reduce more risk and free more capacity per unit of effort than an improvement to a pillar that is already strong.
Score the level below and record the pillar as untested. A capability nobody has exercised is a real finding rather than an administrative gap, and treating it as passed would overstate the result.
No framework guarantees an outcome. A higher level means the operation is more automated, more consistent, and more able to absorb change, which tends to lower the likelihood and the cost of failures. Residual risk always remains and still needs active management.























