AML compliance for smaller digital asset firms – how deep do you go?
We're a relatively new outfit, mostly focused on bespoke OTC digital asset transactions for HNWIs. I'm finding the AML requirements for crypto pretty dense, especially regarding source of wealth/funds. For smaller volumes, is it overkill to demand bank statements going back years, or proof of income from traditional employment, when the funds are clearly coming from prior crypto gains? What's the practical threshold or 'good enough' standard for firms not dealing in the hundreds of millions? Are most just following the letter of FATF/local guidance to the absolute extreme, or is there some risk-based common sense that prevails in practice for smaller, less-resourced teams?