AML

Documents for a Crypto Exchange AML Check

A folder of documents and a checklist, representing an AML review package for an exchange
In brief

Documents for a crypto exchange AML check should form a package tailored to the specific request: account status, case number, and a table of major amounts linked to TxIDs and evidence, not an archive of every available file. The package should answer the reviewer's question about a transaction or restriction. This differs from explaining Source of Funds (SoF); see what exchanges actually request for Source of Funds. If withdrawals are already on hold, see exchange account unfreezing.

An AML package and Source of Funds serve different purposes

An exchange usually requests AML review documents after a risk-control pause related to a deposit, withdrawal, counterparty, or account behavior. The goal is not to provide a life story, but a coherent package that addresses the exact wording in the email or case. For context on why these holds occur, see what AML means in crypto.

Source of Funds (SoF) is a separate layer: it explains the origin of a specific amount or deposit. One request may require both SoF evidence and supporting case documents. Keep the purposes distinct. The SoF article explains the chain from source to transfer to account balance; this article covers the contents of an AML case package and what should not be included. See the detailed Source of Funds guide.

As a practical starting point, read the request literally: additional verification, origin of funds, or proof of address. Then prepare one package addressing those points. For a general plan during the first day of a restriction, see frozen crypto: what to do.

Documents exchanges commonly expect in an AML package

The basic structure is similar across major exchanges:

  1. A screenshot of the account status or restriction and the exact request wording.
  2. The support case or case ID.
  3. A table of major deposits and withdrawals: date, amount, network, TxID, counterparty, and brief context such as a transfer from another exchange, P2P, OTC, or salary followed by a purchase.
  4. Evidence supporting each table row: a statement from another exchange, bank statement, asset-sale agreement, or OTC correspondence identifying the parties.
  5. If requested, proof of address and current KYC information under the same name as the profile.

Platform help materials describe this as additional information or additional verification for withdrawal. Respond through the account's official channel with one package containing legible dates and amounts. Public lists from Kraken, Bybit, and OKX illustrate common practice, but the request in your case may narrow the list to two or three items. Follow that request rather than someone else's chat template.

If the request expressly concerns the source of funds, include SoF files but build the evidence chain using the Source of Funds guide, not a bundle of balance screenshots. A counterparty's blockchain trail may sometimes require blockchain analytics; this does not replace identity or financial documents.

What not to do: files that lead to rejection

  • Statements belonging to someone else or edited statements.
  • Screenshots without dates or a name.
  • Three years of PDF records attached just in case, with no link to the requested amounts.
  • A passport photo stored together with a seed phrase.
  • Repeated copies of the same P2P chat without identifying the parties.

Attempts to accelerate the process by bypassing it are also harmful: a second account, changing location through a VPN during the review, routing transfers through friends, or using urgency across five parallel tickets. To a risk model, these can look like attempts to evade controls. A seed phrase, private keys, and 2FA codes never belong in an AML package, whether it is sent to an exchange or a Telegram helper.

If the restriction is active, first record the facts and use one communication channel. See the checklist in frozen crypto: what to do. Improving the package is more useful than resubmitting the same archive three days later.

Checklist before submitting the package

  1. Save the email or banner, account status, and case number.
  2. List each requested item; every item should correspond to a file or table row.
  3. Match major amounts to a TxID and document. Explain gaps briefly instead of hiding them under extra screenshots.
  4. Remove unnecessary personal data and all wallet secrets.
  5. Confirm that the name matches the KYC profile.
  6. Submit one package through the official channel, and keep a copy and the submission date.

Review the package as an investigator would: are the dates legible, do the amounts reconcile, and does each file address a specific item in the request? If the hold affects withdrawals, keep the exchange account unfreezing route in view. The outcome is not guaranteed and depends on platform policy and the quality of the package.

Limitations

Risks and limitations

  • Requirements and request wording change; follow the exchange's current message rather than a general checklist.
  • A complete document package does not guarantee that the restriction will be lifted or reviewed within a particular timeframe.
  • This article describes common review practice and is not legal advice for your jurisdiction.
  • Documents that belong to someone else, are forged, or are irrelevant increase the risk of rejection and enhanced review.
  • Attempts to bypass the review through a VPN, second account, or intermediaries can worsen the risk assessment.
Sources

Sources used

Next

Related resources

ServiceExchange account unfreezingBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.