Building a financial technology company means accepting responsibility before you possess perfect information. Customers arrive before every workflow is elegant. Banks ask questions before you have a polished answer for every edge case. Fraud changes faster than any written manual. Vendors promise capabilities that look complete in a sales presentation and turn out to require months of integration, tuning, and human review.
I learned this by building Crypto Dispensers in the real world. The work was not a classroom exercise where every requirement appeared on one page and every solution came with a checklist. It was a sequence of practical problems: how to identify the person using the service, how to confirm the source and destination of a wire, how to recognize identity theft, how to screen a wallet, how to monitor transactions, how to document a decision, when to ask for more information, when to delay activity, and when to refuse it.
Each answer led to another question. Each new partner introduced a different set of capabilities and limitations. Each year brought more guidance, more experienced professionals, better tools, and a deeper understanding of the risks. That is what responsible building often looks like. You do not wake up with the final system. You take the next obligation seriously, implement it, test it, learn where it is weak, and improve it.
None of this means standards should disappear for startups. A company that moves value has duties to its customers, its partners, and the integrity of the financial system. Mistakes matter. Weak controls can cause real harm. A founder should be judged by whether he confronted those duties honestly, sought help, responded to warning signs, and kept building a stronger program.
But judgment must preserve distinctions. A control that should have been stronger is not the same fact as a decision to assist crime. A customer who lies to a company is not the same person as a company that joins the lie. A service that is misused is not automatically a criminal partner in that misuse. If those differences are erased, ordinary imperfection can be rewritten as intent after the fact, and the story of building can be turned into the story of concealment simply because the finished system did not exist on the first day.
Building under change
The rules do not arrive all at once.
People outside an emerging industry often imagine compliance as a completed instruction manual. They picture a founder opening the book on day one, reading every rule, purchasing a finished system, and then choosing whether to follow it. That picture is comforting because it makes every later problem look like a simple act of disobedience. It is also far removed from how new financial technology is actually built.
The legal obligations may begin with statutes and regulations, but operating them requires interpretation. A company has to translate broad duties into customer questions, software logic, escalation paths, transaction limits, recordkeeping, training, vendor relationships, and human judgment. A rule that sounds clear at a distance can create dozens of implementation decisions when it meets a new product and a real customer.
Virtual currency made that challenge more intense. The technology evolved, business models changed, federal guidance developed, state expectations differed, banks adjusted their risk tolerance, and vendors created tools that did not exist when early companies first entered the market. A founder had to understand not only what the business did, but how regulators might classify it, what a banking partner required, what a compliance professional recommended, and what the available technology could reliably enforce.
That does not excuse ignoring the law. It explains why serious compliance is a process of translation, implementation, testing, and revision. FinCEN itself describes anti-money-laundering programs in risk-based terms. The appropriate controls depend on the size, structure, risks, products, customers, and complexity of the business. A small company should not pretend to be a global bank, but it must understand its own risks and take reasonable steps to manage them.
The honest question is not whether every control existed in its final form from the beginning. No growing system meets that fantasy. The honest questions are what the company understood at the time, what information it had, what risks it identified, what actions it took, and how it responded as its knowledge and capabilities increased.
The work behind the policy
Compliance is built one control at a time.
A mature compliance program can look like one machine from the outside. Inside a startup, it is a collection of systems that must be chosen, connected, staffed, documented, and improved. Identity verification is one layer. Sanctions screening is another. Fraud detection, wallet screening, transaction monitoring, recordkeeping, escalation, reporting, training, and independent review each solve a different part of the problem.
Even identity verification is not one decision. What documents will the system accept? How will it detect a synthetic identity, a stolen identity, an expired credential, or a customer using someone else's phone? What happens when automated verification fails but the person appears legitimate? Which cases require manual review? How are records stored, protected, and retrieved? A founder does not solve those questions by writing the letters KYC in a policy.
Wallet monitoring brings its own judgment. Blockchain analytics can identify exposure patterns, but the output is not self-interpreting. Direct exposure is different from distant exposure. A risk score is not a verdict. Tools need thresholds, review procedures, trained people, and documented outcomes. Transaction monitoring has the same problem. If the rules are too loose, risks are missed. If they are too broad, ordinary customers are buried in false positives and the review team loses the ability to see what matters.
Then there are partners. Startups depend on banks, identity vendors, blockchain analytics providers, payment processors, compliance consultants, lawyers, and software platforms. Each partner sees only part of the system. Each integration takes time. A contract does not install a control, and an API does not create a sound decision process by itself. Someone has to design the workflow, train the team, measure the results, and correct what fails.
Responsible founders build that architecture in stages because that is the only way complex operational systems are built. The sequence matters. So does the direction of travel. A record of adding controls, hiring expertise, responding to problems, and improving procedures can be evidence of responsibility. It should not be casually inverted into evidence that the founder knew the earlier system was criminal.
Movement of funds
Wire transfers teach risk in real time.
Wire transfers look simple to a customer. Money leaves one account and arrives in another. For the company receiving the wire, the operational reality is much more demanding. The sender's name may not match the customer profile. The bank memo may be incomplete. A business account may be used for a personal transaction. A third party may claim to be helping a relative. A transfer may be recalled after the corresponding asset has already moved.
Those facts can indicate different problems. A mismatch may reflect innocent confusion, identity theft, account takeover, fraud against the sender, an undisclosed intermediary, or an attempt to hide beneficial ownership. The company has to decide what information to request, what evidence is reliable, whether activity should be delayed, and whether the relationship should continue. Making those decisions consistently requires policies, but policies become useful only when people encounter real cases and learn how the patterns appear.
A startup also learns the boundaries of its partners. One bank may provide detailed originator information while another provides only a limited description. One institution may contact the company immediately about a concern while another may send a notice after the relevant events. A fraud victim may sound exactly like a willing customer until a family member calls. A convincing identity document may survive one vendor's checks and fail another's.
That is why wire controls mature through experience. The company may strengthen name matching, require proof of account ownership, add secondary verification, create cooling-off periods, lower limits, separate business and personal cases, document exceptions, or require additional review for high-risk patterns. Each improvement should be evaluated on its own facts and in the time when it was made.
The existence of a later safeguard does not automatically prove that an earlier transaction was knowingly improper. Often it proves that the business learned something and acted. If every correction is treated as a confession, institutions create a perverse incentive to hide improvement. A system committed to safety should encourage companies to recognize risk and become better.
Precision in risk
Different threats require different answers.
Fraud, identity theft, account takeover, sanctions exposure, and money laundering can overlap, but they are not interchangeable labels. Fraud usually involves deception for gain. Identity theft involves the misuse of another person's identifying information. Account takeover involves gaining control of someone else's account. Money laundering concerns transactions involving criminal proceeds under legal elements that include specific knowledge or intent.
The same transaction can raise more than one concern, but the response depends on what the company knows. A customer may be the criminal. A customer may be the victim. A customer may be acting under manipulation without understanding what is happening. A third party may have compromised the account. Treating every unusual transaction as proof of one theory can make the company less accurate and the customer less safe.
Identity controls ask whether the person is who they claim to be. Fraud controls ask whether the transaction reflects deception or unauthorized use. Wallet screening asks about the risk associated with a destination or source address. Transaction monitoring asks whether activity is inconsistent with the customer's profile or resembles known patterns. Escalation and reporting ask what should happen when the facts remain concerning after review.
A responsible program connects these systems without pretending they answer the same question. It records why a case was cleared, restricted, rejected, or reported. It recognizes that a flag is the beginning of analysis, not the end. It also recognizes that false positives have consequences. Freezing an innocent person's activity, exposing private information, or wrongly branding someone suspicious is not a neutral act.
Precision protects both enforcement and the public. When every risk becomes money laundering, the phrase loses its legal meaning and operational usefulness. When investigators collapse every control gap, fraud incident, or unusual transaction into a single criminal narrative, they can miss the actual story. Serious work requires the patience to distinguish categories before assigning blame.
The legal distinction
Imperfection is not criminal intent.
The federal money-laundering statute does not define the offense as operating an imperfect company. Section 1956 addresses transactions involving proceeds of unlawful activity and includes mental-state requirements such as knowledge and intent. The precise elements depend on the charged theory, but the principle is fundamental: criminal liability cannot be replaced by a general feeling that a system should have been better.
There is a moral distinction too. A person who learns that funds are criminal proceeds and chooses to help promote the crime, conceal the source, disguise ownership, or avoid reporting requirements has made a deliberate choice. A founder whose company is deceived, who misunderstands a risk, or whose controls fail has a different state of mind. The failure may still require correction. It may create civil or regulatory questions. It may expose weaknesses that deserve hard scrutiny. But it is not automatically the same human act.
Intent should be evaluated through contemporaneous evidence. What did the founder actually know? What was represented to him? What records did he have? Did he conceal information, or did he document it? Did he resist compliance, or did he hire professionals and add controls? Did he encourage suspicious conduct, or did he create limits, reviews, and reporting processes? What did he do after a problem became visible?
Those questions are harder than pointing to an imperfect outcome, but justice depends on them. Hindsight makes every missed signal look obvious. A completed investigation can arrange scattered facts into a clean narrative that no participant possessed in real time. The danger is that reconstruction begins supplying the very knowledge and intent the evidence is supposed to prove.
Accountability does not require pretending every mistake is innocent. It requires refusing to pretend every mistake is criminal. The line between negligence, regulatory deficiency, recklessness, knowledge, and specific intent matters because the law assigns different consequences to different conduct. Erasing that line may make a theory simpler. It does not make the theory true.
Misuse and participation
Being misused is not the same as helping.
Every useful financial system can be misused. Banks process transactions later tied to fraud. Payment applications are used by scammers. Gift cards are demanded by extortionists. Telephones carry criminal conversations. The fact that a tool appears in wrongdoing does not, by itself, establish that the provider joined the wrongdoing.
The distinction is not a loophole. It is the difference between a service relationship and a criminal agreement. A company may believe a customer is using a product for a lawful purpose while the customer hides the truth. The customer may pass identity checks, provide plausible explanations, and structure conduct to avoid attention. Criminals study controls precisely because they want legitimate systems to misunderstand them.
Deliberate facilitation looks different. It involves evidence that the provider knew the relevant facts and chose to help anyway, or acted with the intent required by law. That evidence might involve concealment, instructions, coordination, false records, evasive conduct, or other proof tied to the person accused. It should not be inferred merely from the fact that a transaction occurred through the service.
This distinction protects honest enforcement. If investigators begin with the assumption that misuse proves partnership, they stop asking whether the company was also deceived. They may treat every operational record as incriminating while ignoring records that show review, concern, limitation, or improvement. The same evidence can be made to tell opposite stories depending on whether intent is investigated or presumed.
A founder should answer for his own choices. A customer should answer for the customer's choices. Where the evidence proves coordination, the law can address coordination. Where it proves deception of the company, justice should recognize the company as a target of that deception, not automatically convert it into an accomplice.
Inside the arena
The man in the arena sees the whole field.
There is a famous distinction between the critic and the person in the arena. The phrase endures because building exposes a person to uncertainty that observation cannot reproduce. The founder has to decide while the information is incomplete, the team is small, the customer is waiting, the bank has its own deadline, and the available tool solves only part of the problem.
The spectator can freeze one moment and ask why the company did not already possess everything it learned later. The builder remembers the sequence. First came the problem. Then came the search for expertise. Then the vendor review, the contract, the integration, the exceptions, the training, the false positives, the escalation process, and the next version. What looks like one control in a report may represent months of work and thousands of decisions.
Founders do not deserve immunity because the work is hard. Difficulty is not a defense to dishonesty. But the difficulty is relevant to understanding conduct. The person who is actually building has to balance security, privacy, access, cost, speed, and reliability. A control that stops all transactions may eliminate one risk by eliminating the business. A control that collects everything may reduce one uncertainty while creating a serious privacy and security burden.
Real leadership lives in those tradeoffs. You make the best decision you can, measure what happens, listen to people who know more than you, and change the system when the evidence demands it. Sometimes the first answer is wrong. Sometimes the vendor fails. Sometimes a customer defeats a process that looked strong. The test of character is not whether uncertainty disappeared. It is whether the founder faced it honestly.
An investigation that wants the truth should reconstruct the arena, not merely judge the final photograph. It should understand what tools existed, what advice was received, what constraints applied, and what alternatives were realistically available at the time. Context does not erase responsibility. It makes responsibility accurate.
Maturity and scale
Responsible systems mature as companies grow.
A company with ten customers and a company with ten million customers do not operate the same way. The risks change with volume, geography, products, transaction size, staffing, and adversarial attention. Controls that were reasonable for an early stage may need to become more automated, specialized, documented, and independently tested as the company grows.
Regulatory guidance recognizes this reality through the language of risk. FinCEN has explained that the sophistication of internal controls should be appropriate to an MSB's size, structure, risks, and complexity. That does not mean small firms receive permission to ignore obligations. It means the law expects judgment rather than theater. A program should address the actual business instead of imitating the organizational chart of an institution with a thousand-person compliance department.
Growth should trigger questions. Are transaction limits still appropriate? Is manual review becoming inconsistent? Do investigators need better case-management tools? Is wallet screening calibrated to the current product? Are fraud and AML teams sharing information? Are wire procedures capturing account ownership and third-party risk? Is the independent review testing the controls that matter most?
A founder who asks and answers those questions is not admitting that the earlier company was a criminal enterprise. He is doing the work of maturation. Every serious institution has a history of revised policies, stronger systems, new vendors, expanded training, and corrected weaknesses. Improvement is how responsibility becomes operational.
The fair measure is whether the program grew with the risks and whether identified problems produced real action. A static program can become inadequate. A developing program can become stronger. The timeline must be read as a timeline, not compressed into a single accusation that assumes the final standard existed unchanged from the beginning.
Judging the record
Hindsight is not a fair standard of proof.
Hindsight has a clean desk. It receives the emails, transactions, interviews, alerts, and later discoveries in one organized file. It can place two events side by side even when the people involved saw them months apart and had no reason to connect them. It knows which warning was meaningful because it already knows the outcome.
The person making the original decision did not have that advantage. He had incomplete information mixed with noise. He had customers who looked ordinary, explanations that appeared plausible, vendors that returned imperfect results, and a business that still had to operate. Fair review requires asking what a reasonable person could see then, not what an investigator can assemble now.
This is especially important when evaluating a founder's words. Entrepreneurs speak in shorthand. Teams debate unfinished ideas. A single sentence can sound decisive after context is removed, even though the surrounding conversation shows uncertainty, disagreement, or an attempt to solve a compliance problem. Messages should be read in sequence, with the operational facts they addressed, not treated as isolated admissions because a phrase fits a later theory.
The same discipline applies to omissions. A missing control may be important, but it does not explain why it was missing. The reason could be cost, vendor availability, integration delay, incorrect advice, a mistaken risk assessment, competing priorities, or deliberate avoidance. Those possibilities are not morally or legally equivalent. Evidence has to distinguish them.
Government has the power to investigate that distinction fully. It can examine records, interview witnesses, compare versions of policies, review vendor contracts, and test whether conduct changed after warnings. With that power comes a duty not to substitute hindsight for proof. A founder's imperfect path can be criticized. It should not be rewritten as criminal intent unless the evidence actually establishes criminal intent.
Primary authorities
Sources for editorial review.
18 U.S.C. § 1956, Laundering of monetary instruments.
U.S. House Office of the Law Revision Counsel
Money Laundering Overview.
U.S. Department of Justice
Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies.
Financial Crimes Enforcement Network
Frequently Asked Questions: Conducting Independent Reviews of Money Services Business Anti-Money Laundering Programs.
Financial Crimes Enforcement Network
Interagency Interpretive Guidance on Providing Banking Services to Money Services Businesses Operating in the United States.
Financial Crimes Enforcement Network
Author's note: This essay presents my perspective as a founder and is intended as general public commentary. It does not offer legal advice, decide the facts of any case, identify any official, or ask any witness, court, or agency to act outside lawful process.