KYC is not one form or a universal Bitcoin rule. It is risk-based customer due diligence with reliable-source verification, updates and monitoring. A VASP may apply the Travel Rule and source-of-funds checks; UTXO analytics remain supporting evidence.
FATF places KYC or customer due diligence inside a wider AML/CFT framework that includes risk assessment, records, sanctions controls and suspicious-transaction reporting. An ID check is not the whole programme, and a KYC label cannot prove that every crime will be prevented.
The institution identifies a customer and verifies information using reliable independent sources. For legal entities it also seeks the beneficial owner, control structure and purpose of the relationship. A valid document proves limited attributes; it does not prove ownership of UTXO or lawful origin of every fund.
FATF requires a risk-based approach. Scope varies by customer, product, amount, delivery channel and country; lower risk can permit simplified measures and higher risk enhanced due diligence. No document list is globally constant: applicable law and documented risk govern it.
Customer due diligence continues after onboarding. Providers update profiles, compare transactions with expected activity and may ask for source of funds or source of wealth. The first concerns a particular transaction and the second broader wealth creation; requests should be proportionate.
Bitcoin validates signatures and transactions without civil names. Exchanges, brokers, custodians or other VASPs perform KYC at the edge. A self-custody wallet is not automatically a VASP, but a transfer to or from a regulated service can trigger its checks under local law.
The Travel Rule requires regulated providers to transmit or retain specified originator and beneficiary data for covered transfers. It is not a Bitcoin transaction field or consensus rule. EU Regulation 2023/1113 distinguishes provider-involved transfers from person-to-person transfers without one.
Chain analysis may attribute addresses to services, create a UTXO cluster or score exposure. Heuristics can be wrong, CoinJoin and internal transfers change interpretation, and a score is neither legal nor cryptographic proof of identity or criminal origin. Context, review and correction matter.
KYC databases join names, documents, biometrics, devices, accounts and sometimes Bitcoin addresses, creating a target for leaks, coercion and surveillance. Mandatory processing still requires purpose limitation, minimisation, security, recipient controls and lawful retention; customers should know the controller and data flow.
Incomplete checks may delay, reject or end service. Suspicion may trigger confidential reporting or a lawful hold, not a finding of guilt. Sanctions, thresholds, deadlines and remedies vary; FATF standards are not themselves directly applicable law for every person.
Before sending data, verify the legal entity, licence or registration, reason and legal basis, exact scope, recipients, retention, secure channel and correction route. Separate mandatory from optional fields and learn the consequence of refusal. A KYC badge proves neither solvency, insurance, safe custody nor best price. Sources: FATF Recommendations — Recommendation 10; FATF — Virtual Assets and VASPs Guidance; EU Regulation 2023/1113 — crypto-asset transfers; EBA — Travel Rule Guidelines; FinCEN — Customer Due Diligence Final Rule.
Protocol data and customer data are different layers
A Bitcoin transaction can reveal addresses and amounts publicly while the exchange separately stores a passport, residence and account history. Combining those layers can connect on-chain activity to a legal identity.
For the clearest picture, read this entry together with Bitcoin Privacy, Custodial Exchange, Self-custody, Pseudonymity, UTXO, CoinJoin. The reverse links also lead from CoinJoin, Bitcoin Privacy, Pseudonymity, Custodial Exchange.
01Is KYC required by Bitcoin?+
No. Bitcoin nodes validate signatures, scripts, amounts and consensus rules. Identity checks arise from the laws, policies and risk controls applied to particular service providers.
02Does deleting an exchange account delete all KYC records?+
Usually not immediately. Providers may have legal retention duties. Read the privacy notice and applicable law for the serving entity instead of assuming account closure erases regulated records.