Navigating digital asset risk in the evolving regulatory landscape

Digital asset risk and regulatory services

US Capitol Building

Overview

Digital assets introduce distinct risk, compliance, and supervisory expectations. Traditional control frameworks don’t always map cleanly to blockchain-based activity (e.g., immutability, pseudonymity, smart contracts, third-party protocols, 24/7 markets).

PwC helps clients identify the regulatory perimeter, design fit-for-purpose controls, integrate digital assets into enterprise risk management, and build regulator-ready programs across AML/sanctions, fraud, licensing, and financial/non-financial risk.

How PwC can help

 

  • Digital Asset AML Risk Assessment: Update the enterprise BSA/AML risk assessment for digital asset products, customer segments, geographies, and blockchain networks/protocols.
  • AML Transaction Monitoring & Case Investigations Operating Model: Design AML-specific alerting, triage, investigations, and SAR/STR decisioning workflows that leverage blockchain analytics to identify laundering typologies (e.g., layering, mixers, chain-hopping) and support defensible documentation.
  • Wallet Screening & Sanctions Controls: Implement sanctions screening for wallet addresses and relevant smart contract interactions, with documented decisioning, blocking, and regulatory reporting procedures.
  • KYC/KYB & Wallet Provenance Standards: Define onboarding, beneficial ownership, and wallet-risk requirements (hosted vs. unhosted), including enhanced due diligence triggers and documentation standards.
  • Travel Rule & Digital Asset Recordkeeping Readiness: Establish data capture, counterparty information exchange (where applicable), and retention/audit trail controls to support compliance and exams.
  • Ecosystem Financial Crime Due Diligence: Build due diligence and ongoing monitoring standards for exchanges, custodians, payment partners, analytics providers, and other critical third parties.
  • Digital Asset Fraud Risk Framework & Typology Library: Define priority digital asset fraud typology scenarios (ATO, social engineering, insider threats, protocol exploits) and map them to preventive and detective controls, escalation triggers, and loss event tracking
  • Onchain Monitoring and Investigations Operating Model: Implement blockchain monitoring and investigations workflows (alert triage, case management, evidence capture) alongside preventive transaction controls and transaction suspension procedures for high-risk transfers and treasury movements.
  • Identity, Account, and Device Security Uplift: Strengthen authentication and step-up verification for high-risk actions (new wallet, withdrawals), supported by device and behavioral signals.
  • Integrated Fraud Analytics (Onchain + Offchain): Combine blockchain indicators with traditional fraud tooling to help improve detection, reduce false positives, and accelerate triage.
  • Customer Harm, Recovery, and Remediation Playbooks: Define operational procedures for trace/freeze/escalate (where feasible), law enforcement engagement, customer communications, and remediation governance.
  • Regulatory applicability & activity classification: Map digital asset offerings to banking, payments, money transmission, securities/commodities, and stablecoin-specific requirements (e.g., Genius Act, money-transmitter rules, BitLicense, etc.) across jurisdictions.
  • Licensing / Charter Strategy & Roadmap: Define the target licenses/charters and a phased plan to launch, scale, and expand into new markets that cares for supervisory expectations.
  • Regulatory Obligations & Change Management Enablement: Translate newly applicable digital asset regulations into obligations that can be incorporated into the inventory of laws, rules, and regulations stand up ongoing regulatory change management routines to keep the inventory and compliance mapping current as rules evolve.
  • Exam, Audit & Assurance Readiness: Prepare defensible supervisory narratives and evidence binders, design regulator-ready recordkeeping and reporting (including onchain evidence and audit trails), and support regulatory exams, audits/attestations, and ongoing supervisory requests.
  • Cross-Jurisdiction Control Framework Alignment: Build a single, coherent compliance and controls baseline that satisfies multiple regimes while minimizing duplicated processes and inconsistent obligations.
  • Consumer Protection & Product Governance Controls: Establish disclosures, marketing review, complaint handling, redemption terms (where relevant), and customer support expectations aligned to regulatory scrutiny.
  • Digital Asset ERM Integration & Governance: Embed digital assets into risk appetite, policy standards, three lines of defense, issue management, board reporting, and audit coverage.
  • Liquidity & Redemption/Run Risk Stress Testing: Model redemption dynamics and liquidity needs, define liquidity buffers and monetization paths, and operationalize contingency funding playbooks.
  • Market, Credit, and Counterparty Risk Framework: Establish limits, eligibility standards, and monitoring for volatility, concentration, settlement exposures, and counterparties (exchanges, market makers, issuers).
  • Operational Resilience for 24/7 Markets: Design controls for uptime, reconciliations, incident response, change management, and always-on monitoring aligned to critical digital asset processes.
  • Digital Asset Third-Party & Supplier Risk Framework: Establish enhanced due diligence and ongoing oversight for critical providers (custodians, wallet/KMS, node/RPC, analytics, tokenization platforms, settlement partners), including subcontractor mapping, concentration risk, SLAs, and exit/portability plans.
  • Capital / Prudential and Balance Sheet Impact Assessment: Evaluate capital and liquidity implications, operational risk considerations, and accounting/treasury impacts—translated into management actions and governance.

Questions business leaders are asking

What does “regulator-ready” look like for a digital asset launch, and what evidence will supervisors expect?

Regulator-ready typically means you can demonstrate a clear regulatory perimeter, sound governance, and effective controls before launch. Supervisors generally expect evidence such as a board-approved business and risk strategy, defined decision rights and accountable owners, documented policies and procedures (AML/sanctions, fraud, custody/key management, third-party risk, incident response), end-to-end process maps and control points, risk assessments specific to the product and blockchain activity, testing results (UAT/control testing, tabletop exercises, resiliency tests), third-party due diligence packages, and a complete audit trail/recordkeeping approach (including how onchain evidence is captured and retained). They also look for credible staffing and training, clear customer disclosures, and a plan for ongoing monitoring, issue management, and independent assurance.

How do AML and sanctions programs need to change for wallets, smart contracts, and onchain transactions?

AML and sanctions programs need to incorporate onchain risk signals and controls that do not exist in traditional payments. In practice, this means updating your AML risk assessment to cover blockchain networks and protocols, wallet types like hosted and unhosted, and transaction typologies like mixers, chain-hopping, and rapid layering. These enhanced programs typically:

  • Add blockchain analytics to support wallet attribution, exposure tracing, and alert enrichment;

  • Implement wallet and sanctions screening, including relevant smart contract interactions where exposure is plausible; 

  • Enhance KYC and KYB and wallet provenance standards covering ownership, control, beneficial owner, and high-risk indicators;  

  • Operationalize AML investigations with defensible documentation and SAR or STR decisioning using onchain evidence; and

  • Where applicable, operationalize Travel Rule data capture and exchange and strengthen recordkeeping so the program is exam-ready.

What are the most effective fraud controls to help reduce customer harm in irreversible payment rails?

Because transactions are often final and difficult to reverse, the most effective controls emphasize prevention, friction for high-risk activity, and rapid detection. Common leading practices include strong identity and account security using MFA, device binding, behavioral signals, and step-up authentication. They also include transaction guardrails like limits, allowlists, velocity checks, beneficiary change controls, and time delays for large or unusual withdrawals. Many firms deploy real-time monitoring that combines traditional signals with onchain indicators. They implement targeted controls against customer harm patterns, especially scams and social engineering. An effective program also includes incident and recovery playbooks that cover trace, escalate, and freeze where feasible, coordination with custodians and exchanges, law enforcement workflows, and clear customer communication and remediation governance.

What licenses/registrations apply to our planned activities, and what is the fastest compliant path to market?

Applicable licenses and registrations depend on what you do, where you do it, and for whom, such as custody, trading, brokerage, payments, stablecoin issuance, and tokenization platform services. Common regulatory touchpoints can include money transmission and MSB obligations, state licensing regimes, bank or trust authorities for custody, and depending on product features, securities or commodities related requirements. The fastest compliant path is usually achieved by confirming the regulatory perimeter for the specific product and jurisdictions, choosing a launch scope that minimizes licensing complexity like limited geography, narrow features, or institutional-only, and using a phased strategy. Many firms partner with appropriately licensed entities for initial launch while building their own licensing footprint and controls for scale. This approach helps reduce time-to-market while keeping the long-term target state clear and defensible.

How do stablecoin redemption and liquidity dynamics affect our funding, liquidity buffers, and stress testing?

Stablecoin models introduce redemption timing commitments and potential run dynamics, so liquidity planning typically needs to be more explicit and operational than in many traditional products. Firms generally need a clearly defined redemption policy covering timing, fees, limits, and exceptions, a reserve strategy aligned to required liquidity, and multiple tested monetization paths to convert to cash under normal and stressed conditions. Stress testing usually focuses on severity and speed, large redemptions over short windows, concentration risk among large holders, market liquidity haircuts, and operational or settlement outages. Funding and liquidity buffers are then calibrated to the modeled scenarios and supported by contingency funding plans, clear escalation triggers, and pre-defined operational playbooks that include communications, execution steps, and decision documentation during stress.

How should we structure ownership and decision rights for digital asset risk across the enterprise and product teams?

A common effective model is central standards with embedded execution. Centralized enterprise risk functions typically set the firmwide risk appetite, define minimum control standards, and own key decision rights like approving new digital asset activities, interpreting regulatory obligations, and establishing escalation and incident governance. Product and operations teams then embed those standards into day-to-day workflows and own control execution, including onboarding procedures, transaction operations, monitoring and escalation, reconciliations, and issue remediation. This structure creates consistent governance and supervisory clarity while keeping accountability close to where the product is built and operated.

Contact us

John Sabatini

John Sabatini

Risk & Regulatory Platform Leader, PwC US

Matt Blumenfeld

Matt Blumenfeld

Global and US Digital Assets Lead, PwC US

Jacob Sciandra

Jacob Sciandra

Principal, PwC US

Vasilios Chrisos

Vasilios Chrisos

Financial Crimes Unit Regulatory and AML Leader, PwC US

Follow us