Skip to main content
Should Your Firm Accept Cryptocurrency Payments?Ethics and Conduct
5 min readFor Compliance Officers

Should Your Firm Accept Cryptocurrency Payments?

The decision isn't whether cryptocurrencies are the future of commerce. That question has been settled. The question is whether your organization can accept, hold, or transact in digital currencies without creating unmanageable compliance exposure under the Foreign Corrupt Practices Act (FCPA) and related anti-corruption frameworks.

This decision carries consequences beyond payment processing. When you authorize cryptocurrency transactions, you're creating new channels through which value can move across borders with varying degrees of traceability. Your choice affects your FCPA risk profile, your internal control architecture, and your ability to detect misconduct before regulators do.

Key Factors Affecting Your Decision

Three factors determine whether your organization can safely operate in the cryptocurrency space:

Transaction transparency requirements. Your industry and regulatory obligations dictate how thoroughly you must document payment chains. If you're subject to enhanced due diligence requirements under FinCEN guidance or operate in high-risk jurisdictions, you need complete visibility into who receives payments and for what purpose. Some cryptocurrency platforms allow users to operate with minimal identity verification, which conflicts with know-your-customer obligations that financial institutions must meet.

Control environment maturity. Your existing compliance program must be capable of detecting anomalies in digital currency flows. Traditional red flags, such as round-dollar amounts and payments to shell companies, don't always translate to blockchain transactions. If your monitoring systems can't flag unusual cryptocurrency activity, you're operating blind.

Cross-border exposure. Companies conducting business in jurisdictions with weak governance structures face elevated corruption risk. The Financial Crimes and Enforcement Network stated in 2013 that digital currency firms need to comply with the same anti-money laundering rules as other financial institutions. If your commercial relationships span multiple regulatory regimes, you must assess whether each jurisdiction's cryptocurrency framework aligns with your compliance obligations.

Path A: Prohibit Cryptocurrency Transactions

Choose this path if your organization lacks the control infrastructure to monitor digital currency flows or operates in sectors where payment transparency is non-negotiable.

When this applies:

You're subject to stringent anti-money laundering requirements that demand verified counterparty identity. Many cryptocurrency exchanges don't require verifiable personal information to purchase digital currencies, creating gaps in your due diligence chain. If you can't confirm who received value, you can't demonstrate FCPA compliance.

Your compliance program relies on traditional transaction monitoring. If your controls flag suspicious activity by scanning bank statements for unusual patterns, cryptocurrency transactions occurring outside your banking relationships will evade detection. The August 2016 theft of $65 million in Bitcoins from the Hong Kong-based Bitfinex exchange platform demonstrates that digital currency networks face security vulnerabilities your organization may not be equipped to manage.

Your business model doesn't require cryptocurrency functionality. If you can accomplish commercial objectives through conventional payment rails, the compliance cost of supporting digital currencies outweighs any operational benefit.

Implementation requirements:

Establish explicit policy language prohibiting employees from conducting business transactions in any cryptocurrency. Include this restriction in your Code of Conduct and third-party contracting standards.

Configure bank account monitoring to detect transfers to known cryptocurrency exchanges. Flag these transactions for compliance review even if they fall below your standard materiality thresholds.

Train procurement and sales teams to recognize and decline requests for cryptocurrency payment. Emphasize that such requests may indicate corruption risk, particularly in jurisdictions where public officials have influence over contract awards.

Path B: Permit Limited Cryptocurrency Use With Enhanced Controls

Choose this path if your business model benefits from digital currency capabilities and you can build control mechanisms that maintain transaction visibility.

When this applies:

You operate in industries where cryptocurrency adoption provides a competitive advantage or meets customer demand. Your compliance function has the capacity to design, implement, and monitor specialized controls for digital currency transactions.

Your organization maintains sophisticated transaction monitoring systems capable of tracking blockchain activity. You can identify which Bitcoin addresses send payments, trace cryptocurrency flows through mixing services that obscure transaction origins, and flag patterns inconsistent with legitimate business purposes.

You're prepared to restrict cryptocurrency authority to specific roles and require dual authorization for digital currency transactions above defined thresholds.

Implementation requirements:

Designate authorized cryptocurrency users by role and maintain a registry of approved Bitcoin addresses that can initiate payments. Prohibit employees from creating wallets or addresses outside this controlled framework.

Establish enhanced due diligence protocols for counterparties requesting cryptocurrency payment. Verify that the recipient's jurisdiction permits digital currency transactions and that your payment doesn't violate local law.

Implement real-time monitoring of cryptocurrency wallets your organization controls. Configure alerts for transactions to addresses not pre-approved through your vendor management process.

Require documented business justification for every cryptocurrency transaction. Your audit trail must demonstrate that the payment serves a legitimate commercial purpose and that conventional payment methods were considered and rejected for specific reasons.

Conduct quarterly reviews of cryptocurrency activity with your Audit Committee. Report transaction volumes, counterparty jurisdictions, and any red flags identified through monitoring.

Path C: Engage Cryptocurrencies Through Regulated Intermediaries Only

Choose this path if you need cryptocurrency functionality but want to minimize direct exposure to blockchain transaction risks.

When this applies:

Your business requires the ability to accept cryptocurrency payments from customers but you don't need to hold or transact in digital currencies yourself. You can immediately convert cryptocurrency receipts to fiat currency through regulated exchanges that perform identity verification.

You're willing to accept the transaction costs and conversion timing associated with intermediary services in exchange for enhanced compliance controls.

Implementation requirements:

Contract with cryptocurrency payment processors that comply with FinCEN anti-money laundering rules and perform customer identification. Verify that your processor maintains know-your-customer protocols equivalent to traditional financial institutions.

Configure automatic conversion of cryptocurrency receipts to your operating currency. Don't maintain cryptocurrency balances that require ongoing monitoring and security management.

Treat the payment processor as a high-risk third party subject to enhanced due diligence. Assess their compliance program, financial stability, and regulatory standing before engagement and annually thereafter.

Decision Matrix

Factor Path A: Prohibit Path B: Limited Use Path C: Intermediary Only
Control environment Basic transaction monitoring Advanced blockchain analytics Delegated to processor
Compliance cost Low High Moderate
FCPA risk Minimal Manageable with controls Reduced through intermediary
Business flexibility Constrained Maximum Moderate
Audit complexity Standard Significant Moderate
Regulatory alignment Clear Requires ongoing assessment Processor-dependent

Your cryptocurrency decision isn't permanent. As regulatory frameworks mature and control technologies improve, you may move from Path A to Path C or from Path C to Path B. What matters is that your current choice aligns with your compliance capabilities, not your competitors' announcements or your sales team's preferences.

The sales vice president eager to close a deal doesn't determine your cryptocurrency policy. Your Chief Compliance Officer does, based on whether you can detect and prevent the misconduct that digital currencies can enable.

You Might Also Like