KYC isn't optional. That's the rule. The second rule is nobody does it the same way. Some platforms demand full identity plus a video call before you move a dollar. Others ask for an email. The difference isn't laziness. It's jurisdiction, business model, and how much risk the operator wants to carry.
There's no universal standard. Regulations vary. A non-custodial DEX that just matches orders faces different rules than a platform sitting on customer money. A small payment processor doesn't get the same scrutiny as a trading exchange.
The question isn't "should we do KYC." It's "what do we actually need to prevent, who are we preventing, and how much can we annoy users without losing them."
The spectrum is real
At zero you've got pure no-KYC. A DEX where users connect their wallet and trade. They never touch your infrastructure. You never hold money. You never know their name. In most places that's legally fine. But no-KYC attracts bad actors. Sanctioned people trade freely. Crime proceeds get laundered. Most jurisdictions decided that's unacceptable and started cracking down.
Then low-friction. Email. Phone. Maybe a face photo. This catches dumb stuff. Duplicate accounts. People already on blocklists. Doesn't actually verify anyone's identity but it shows you're not intentionally blind to compliance. Cuts your legal risk meaningfully.
Next step is basic ID. User uploads a government ID. Some automated system (Jumio, Onfido, whoever) does OCR to extract the information. No human looks at it. Just parsing. Works for about 95% of legitimate users. Catches obvious fraud like fake IDs and expired docs.
Full verification gets paranoid. Document quality checks. Liveness detection (video proving the person is actually real). User uploads ID, takes a selfie, system matches them together. Someone reviews it. Maybe automated, maybe human. Expensive though. Five bucks per verification sometimes. But it catches sophisticated fraud and makes demanding regulators happy.
Enhanced KYC adds source of funds. Where'd the money come from. Mostly for wire transfers and big transactions. User says they're moving $500K of crypto, you ask for proof it was theirs. Mostly a thing for traditional finance-touching operators.
What regulators actually demand
Nobody requires full KYC everywhere. EU allows under €1,000 without the heavy stuff. US demands OFAC screening but never clearly said what identity verification means. UK treats betting platforms weird compared to settlement networks.
Full KYC converts 60-70% of people trying to sign up. Low-friction converts 95%+. That matters if you want users.
For small transaction businesses, email and automated ID is fine. Institutions demand full KYC no matter what. Most platforms somewhere in the middle. Progressive works best. No verification just to see prices. Basic ID check at $1K monthly volume. Tighter stuff at $10K. Source of funds at $100K. Users get value without headache. Compliance ramps as they move bigger money.
What a real system looks like
Start with jurisdiction and business model. UK regulated payment processor? Full KYC and OFAC on everything. Non-custodial DEX where users never give you money? Maybe nothing.
For normal mid-tier custodial platforms serving regular people, six things matter.
OFAC screening on every deposit, withdrawal, user signup. Non-negotiable. Cheap. Use Chainalysis or similar. Costs cents.
Email and one-time password. Stops bots. Proves a human deliberately signed up.
Government ID check. Automated service. Jumio, Onfido, whatever. Two to five bucks per check. 95%+ coverage for developed countries. Regulators accept it as due diligence proof.
Limit unverified users. They can see prices. Small trades. Can't withdraw until they pass. Creates friction but it's tolerable.
Progressive verification. Watch money in and out per user. At certain thresholds (ten grand monthly, fifty, hundred), ask for more verification. Compliance scales with risk.
Behavioral flags. If someone normally withdraws a grand and suddenly pulls a million, flag it for your compliance team. Doesn't require anything from the user. Just internal investigation.
Actually building and shipping it
Jumio, Onfido, Sumsub do ID verification via API. Pass or fail score back to you. Chainalysis, TRM Labs, Elliptic handle blockchain screening. Query their sanctions lists. Build a dashboard for flagged users and weird behavior.
The practical approach is careful without being paranoid. Email verification now. OFAC screening now. Automated ID now. When a regulator asks for something unexpected, you already have the infrastructure to add it. Most teams that rushed this backwards spent half a year rewriting compliance logic. Do it once properly and you're done.