Reusable KYC for exchanges and banks, governed by the institutions that rely on it
Follow a group of exchanges - and the bank that joins them - as they found the Crypto Exchange Association (demo) on Verana: one governed KYC credential checked once and reused everywhere with the original issuer paid on every reuse, one free counterparty proof for the Travel Rule, and every payment building a public, slashable trust score.
Exchanges compete on markets, liquidity and product. Banks compete on rates, service and trust. Neither competes on document checks - yet every one of them pays an IDV provider to re-run the same passport scan, the same liveness check, the same AML screening on the same customer the market already checked last month. The check is a commodity, regulated identically for both sectors. The friction is not: it costs real money, it costs sign-ups, and between banks and exchanges it costs entire business relationships. And the retail queue is only half of it - the Travel Rule makes the institutions re-verify each other, transfer after transfer.
A large exchange. Pays for a full KYC on every new customer - then watches those customers get re-checked everywhere else.
A growing exchange. Loses a share of its sign-ups at the KYC wall - people abandon rather than upload a passport again.
A retail bank. Holds the best-audited KYC files in the market - and re-runs the checks anyway, on customers the exchanges just verified.
An IDV provider. Good at its job, paid per check - by everyone, for the same person, again and again.
Five problems, one cause
The Travel Rule requires exchanges and banks to verify the counterparty institution behind a transfer. The FATF standard sets a 1,000 USD/EUR baseline - but the EU went further: under Regulation (EU) 2023/1113, applied since 30 December 2024, originator and beneficiary data must travel with EVERY crypto transfer, whatever the amount (the 1,000 EUR line survives only for self-hosted wallet ownership checks). Each travel rule network - Sumsub, TRP, Notabene, VerifyVASP, Sygna - keeps its own directory, so each institution joins several or all of them to reach enough counterparties, resubmits its license and controls to each, and pays each a subscription plus per-message fees.
Because none of the networks can see the others' verifications, the same institution is due-diligenced multiple times per year, by multiple institutions, on the same license.
The vendor fee (about 1.85 USD per check with AML screening, list price) is only the floor: all-in, with ops time and manual review, onboarding a funded customer costs a multiple of that. Multiply by every exchange and every bank the same customer joins, and the industry pays many times for one fact: this person is who they say they are.
Industry onboarding studies put abandonment during KYC above half. Every re-check is a funded account lost to whichever competitor has one step less.
Every customer moving between a bank and an exchange is re-checked in both directions. And because a bank cannot see how an exchange verified its customers, the safe answer is too often not to serve them at all.
A phishing site that looks like an exchange - or a bank - asks for exactly what a real one asks for: documents and a selfie. Nothing lets a customer tell them apart before uploading.
KYC is a compliance tax every institution pays separately - and the people paying the highest price are the users, in queues, re-uploads, stolen documents and closed accounts.

“We spend a fortune verifying people the whole market has already verified. Our KYC file is an asset we can never use twice - and every re-check we force on a customer is a gift to whoever onboards them faster.”

“We do not de-bank crypto customers because they are crypto customers. We de-bank them because we cannot see how they were verified. Give me the provenance of the check - who ran it, on what evidence, with what at stake if it was faked - and the risk conversation changes completely.”