The Bitcoin Legal Commons ← All resources

Compliance · Explainer

What a compliance department actually is

Who is on the other side of the email asking about your source of funds, what KYC and AML actually mean, and why the compliance function is not the legal department.

Structure and function, not current thresholds. Every firm organises this slightly differently and the rules differ by country; what follows is the shape you will meet almost anywhere.

When an exchange, a bank or a broker asks you an uncomfortable question, the request almost never comes from a lawyer. It comes from a compliance department, and knowing what that department is, what it is obliged to do and what it cannot do for you changes how you should respond.

The short version

The legal department advises the firm on what the law is. The compliance function is responsible for the firm actually following it, day to day, and for proving to a regulator that it did. Different jobs, different incentives, often different reporting lines.

What a financial intermediary is

A financial intermediary sits between you and something you want to do with money: an exchange, a bank, a broker, a payment provider, a custodian. Because it stands in that position, most legal systems make it carry obligations that do not apply to you as an individual. The intermediary is the point at which the state can impose record-keeping, identification and reporting duties without regulating every private person.

Two consequences follow, and they explain most of what feels arbitrary about dealing with these firms:

The compliance function

Compliance is the internal function responsible for making sure the firm follows the rules that apply to it, and for producing evidence that it did. Its typical work:

1

Onboarding and identification

Deciding whether a prospective client can be accepted at all, and on what conditions. This is where identity checks, document collection and initial risk classification happen.

2

Ongoing monitoring

Watching activity against the profile the client gave at onboarding. The trigger for most uncomfortable questions is not size but inconsistency: activity that does not match what the firm was told to expect.

3

Investigation and escalation

Reviewing alerts, requesting explanations and documents, and deciding whether to clear, restrict or report. This is the stage at which most people meet compliance for the first time.

4

Reporting

Where the applicable rules require it, filing a report with the designated authority. In many systems the firm is prohibited from telling you that it has done so, which is why a frozen account is often accompanied by an unhelpful answer.

5

Governance and evidence

Writing the policies, training staff, testing whether the controls work, and keeping records. Much of the function exists to be auditable later.

KYC and AML are not the same thing

The two terms are used interchangeably in conversation, which obscures a useful distinction.

AML: the objective

Anti-money laundering is the whole regime whose purpose is to prevent the financial system being used to disguise the proceeds of crime, and in most systems to counter terrorist financing alongside it.

It is the body of law, supervision and obligation. AML is the why.

KYC: one of its methods

Know your customer is the set of processes for establishing who a client is and what they are likely to do: identification, verification, understanding the purpose of the relationship, and keeping that picture current.

KYC is a component of an AML programme, not a synonym for it. KYC is part of the how.

An AML programme normally contains a good deal more than KYC: transaction monitoring, sanctions screening, risk assessment, record retention, staff training, an independent testing function and internal reporting lines. You often see the wider activity called customer due diligence, of which identification is only the first step.

Why the distinction is practically useful

If you think the only obligation is KYC, you expect the questions to stop once your passport is verified. They do not, because identification is the beginning of the process rather than the end of it. Monitoring runs for the life of the relationship, and the question that arrives three years later is a different obligation being discharged, not a failure of the first one.

Compliance is not the legal department

This is the distinction that most changes how you should read a message from a financial institution.

 Legal departmentCompliance function
Core questionWhat does the law permit or require?Are we in fact doing it, and can we show that?
OutputAdvice, opinions, contracts, litigation strategyPolicies, controls, monitoring, reports, records
OrientationOften advisory, and often after the factOperational and continuous
ClientThe firmThe firm, with duties owed toward the supervisor
Typical reporting lineGeneral counselA designated compliance officer, frequently with a direct line to the board
PrivilegeLegal advice may attract professional privilegeCompliance records are generally created to be shown to a supervisor
The consequence worth remembering

Compliance records are frequently produced in order to be examined. What you write in an explanation to a compliance team is documentation, and it is likely to be read later by people who were not part of the conversation. That is a reason to be accurate, complete and unemotional, and a reason not to improvise.

Neither department is your adviser. The legal department acts for the firm. The compliance function answers to the firm and, in practice, to its supervisor. If your position is genuinely difficult, the person you need is your own lawyer.

Who supervises them

Firms of this kind normally sit under a supervisory authority, and the word regulator covers several different kinds of body: a government department, an independent statutory authority, a central bank, or in some sectors a self-regulatory organisation that a statute recognises. Which one applies to a given firm depends on its licence and its country, and it is worth establishing rather than assuming.

Two things follow. The firm is answerable to somebody, which means there is usually a complaints route beyond the firm itself. And the supervisor's expectations, not only the statute, shape how conservatively a compliance team behaves.

How to deal with them well

If an account has already been restricted, the sequence of what to do, and what makes it worse, is set out in exchange froze your account. For what these firms collect and hold about you, see what exchanges collect at KYC.

General information, not legal advice. This site does not provide legal advice and no professional or advisory relationship is created. How compliance functions are structured, what they are obliged to do, which authority supervises them and what they may tell you all differ between countries and between firms, and change over time. This page describes a common shape, not the rule in your jurisdiction. If your account or your funds are at stake, take advice from a lawyer licensed where you live.