Crypto AML Operations: OTC Desks, Source of Funds, and the Limits of Analytics
An OTC desk executing large, negotiated crypto trades is dealing in virtual currency under the PCMLTFA, which brings KYC/KYB, source-of-funds and source-of-virtual-currency checks, travel-rule information, recordkeeping, and reporting with it. Blockchain analytics supports those controls but cannot substitute for the documented program elements — policies, risk assessment, training, and human review of alerts — that the law prescribes.
Reader question
How should a crypto OTC desk in Canada run KYC, source-of-funds checks, and blockchain analytics as part of a real AML program?
An OTC desk is dealing in virtual currency
An over-the-counter desk that executes large, negotiated crypto trades for individuals and entities is dealing in virtual currency. Under the PCMLTFA, that is a money services business activity — s. 5(h)(iv) for businesses in Canada and s. 5(h.1)(iv) for foreign businesses directing services at people in Canada. Registration with FINTRAC and a documented, risk-based compliance program follow from that classification, not from the desk's size or how informal its trade flow feels.
The OTC model — a relationship manager, chat-based negotiation, bespoke settlement — does not soften those obligations. If anything it raises expectations, because the desk knows each counterparty and each trade individually. A desk that can quote a personalized spread can also be expected to know who it is trading with and where the assets came from.
KYC and KYB sized to the trade
For individuals, this means verifying identity using an accepted method before executing large trades. For entities, it means confirming the entity exists, who directs it, and who ultimately owns or controls it — beneficial ownership, not just the name on the incorporation record. Larger, negotiated trades warrant proportionately deeper verification: the business rationale for the trade size, the relationship between the person instructing the trade and the entity, and whether the stated purpose fits the client's profile.
OTC concentration changes the math. A handful of clients can account for most of a desk's volume, so each client file carries more weight than it would at a retail exchange. Thin files on the largest clients are the pattern reviewers notice first.
Source of funds and source of virtual currency, operationally
"Source of virtual currency" means collecting context about where the VC in a transaction came from — which wallets, which platforms, what activity generated it — with more depth on higher-risk transfers. On the fiat leg, source of funds asks the same question about the wire or deposit. Operationally, most desks handle this in layers: expected sources captured at onboarding, trade-time questions for unusually large or out-of-pattern trades, and documentation of the answer alongside the trade record.
The control only works if the answer connects to something. A stated source that contradicts what wallet screening shows should trigger escalation and, where the facts support it, a suspicious transaction report. Context that sits in a form nobody reads back is not a control; it is an unused record.
Records, the travel rule, and reporting
The desk's records should let a reviewer reconstruct any trade: the parties, the wallets involved, the source answers, the screening results, and how settlement happened. Virtual currency transaction and large virtual currency transaction records are prescribed under the PCMLTFR (ss. 36(g), 36(h), 95(1)(g), 95(1)(g.1), 129), and chat logs plus a spreadsheet rarely satisfy them on their own.
When the desk sends a virtual currency transfer, the travel rule (PCMLTFR s. 124.1) requires including originator and beneficiary name, address, and account or reference number, and taking reasonable measures to ensure that information travels with the transfer. Large virtual currency transactions are reportable to FINTRAC at the threshold and in the form set out in current FINTRAC guidance, and suspicious transactions are reportable regardless of size.
Where blockchain analytics fits — and where it stops
Blockchain analytics earns its place at an OTC desk: wallet screening before settlement, tracing on higher-risk flows, and evidence that corroborates or contradicts a client's source-of-VC answer. But analytics is one input, not the program. A VC-dealing MSB still needs the elements the law prescribes — a compliance officer, documented policies and procedures, a risk assessment, training, and a two-year effectiveness review (PCMLTFA s. 9.6; PCMLTFR ss. 156–157) — plus KYC/KYB, reporting, and recordkeeping that operate whether or not a vendor dashboard flags anything.
Analytics also has intrinsic limits. Attribution is probabilistic, coverage differs by chain and asset, and no tracing tool sees the fiat leg, the client's rationale, or the entity behind a wallet. Alerts become controls only when a person reviews them, documents the decision, and files a report when the facts warrant one. An unworked alert queue is evidence of a gap, not of monitoring.
At a glance
- An OTC desk executing large, negotiated crypto trades for individuals and entities is dealing in virtual currency — an MSB activity under PCMLTFA s. 5(h)(iv) and s. 5(h.1)(iv) — with registration and full program obligations attached.
- KYC/KYB depth should scale with trade size: verified identity for individuals, and entity existence, control, and beneficial ownership for businesses, plus the rationale for large blocks.
- "Source of virtual currency" means recorded context on where the VC came from, collected with more depth on higher-risk transfers and connected to escalation and reporting — not a standalone form field.
- VC transfers the desk sends must carry originator and beneficiary name, address, and account or reference number under the travel rule (PCMLTFR s. 124.1).
- Blockchain analytics supports screening and tracing but is not an AML program: a compliance officer, policies, risk assessment, training, and a two-year effectiveness review are still required (PCMLTFA s. 9.6; PCMLTFR ss. 156–157).
- Analytics alerts count as controls only when a human reviews them, documents the outcome, and reports when warranted.
Common mistakes
- Treating blockchain analytics as a substitute for policies, KYC/KYB, and reporting controls rather than as one input to them.
- Collecting source-of-funds and source-of-VC answers at onboarding and never checking them against actual wallet activity at trade time.
- Assuming the relationship-based OTC model justifies lighter verification, when large negotiated trades warrant deeper identity, entity, and source checks.
- Sending virtual currency transfers without originator and beneficiary information because settlement is negotiated and bespoke.
- Keeping trade records in chat logs and spreadsheets that cannot reconstruct who traded, from which wallets, on what stated source and rationale.
- Letting analytics alert queues accumulate unworked, which documents a monitoring gap instead of a monitoring control.
Sources
Regulatory anchor: PCMLTFA s. 5(h)(iv), s. 5(h.1)(iv), s. 9.6; PCMLTFR ss. 36(g), 36(h), 95(1)(g), 95(1)(g.1), 124.1, 129, 156–157.
This content is general education and industry perspective. It is not legal advice, does not create a solicitor-client relationship, and does not replace the PCMLTFA, the PCMLTFR, FINTRAC guidance, or advice from qualified legal counsel. It does not guarantee regulatory or bank acceptance. Confirm current law, current FINTRAC guidance, and the full facts before relying on it for a business decision.