KYC/AML for smaller digital asset platforms – where's the line?
I'm trying to wrap my head around the various global KYC/AML requirements, especially for platforms dealing with digital assets but operating on a smaller scale, maybe sub-$10M AUM. It feels like the larger exchanges have teams dedicated to this, but what about the newer, more niche platforms? Is there a general threshold or a commonly accepted framework that smaller players lean on before full-blown bank-level compliance becomes absolutely mandatory? I've seen some talk about a tiered approach, but no clear guidance on when those tiers kick in, particularly when crossing borders with users. For example, if a platform is registered in one jurisdiction but serves users globally, how do you practically navigate the patchwork of regulations without massive overhead? What's the pragmatic approach here for those not yet at the institutional level?