The Crypto Paper Trail for AML: What to Save Before an Exchange or Bank Asks
Imagine: 3 years ago you bought ETH on an exchange using a bank transfer. You withdrew it to a hardware wallet. Later you swapped half for USDC on a DEX, bridged it to another chain, received freelance payments in the same wallet, sold some through a P2P trade, and now you are depositing the remainder on a regulated exchange to convert to fiat. The exchange compliance team sends a message: please explain the Source of Funds for this deposit.
The blockchain history still exists. Every transaction is recorded. But the blockchain does not contain the bank statement that funded the original purchase, the trade confirmation from the exchange you no longer use, the invoice for the freelance work, the P2P order details, a record of which wallets were yours, or an explanation of why you bridged to another chain. The transactions remain. The context that explains them may not.
This is the problem that AML recordkeeping solves — not after a compliance review begins, but before one is ever needed. An AML-ready paper trail connects three things: where the crypto came from, how it moved, and why each material step happened. Blockchain preserves transactions. It does not automatically preserve the AML explanation behind them.
This article explains what records to save at each stage of a crypto lifecycle — purchase, income, self-custody, swaps, bridges, P2P trades, and cash-out — so that when an exchange or bank asks a Source of Funds question months or years later, the answer is already documented.
A practical note on proportionality: not every $10 transfer needs a dedicated evidence folder. More attention should go to large transactions, income, purchases, P2P trades, cross-chain movements, significant self-transfers, transactions likely to be cashed out later, and counterparties that may later be questioned.
What an AML Reviewer Needs to Reconstruct
When an exchange asks "where did this 100,000 USDC come from?", they are not asking only for the last TxID. A coherent explanation may need to connect an entire chain: income or savings → purchase → exchange → self-custody → swap → bridge → current wallet → exchange deposit.
For each material stage, useful evidence answers four questions.
- What happened on-chain? Keep the blockchain and network, TxID, addresses involved, asset, amount, date, and token contract where relevant. The TxID is the durable blockchain reference — it links a specific movement to a specific block and timestamp that anyone can independently verify. For more on how to find and save a crypto transaction ID, see our TxID guide.
- What was the economic event? Was it a crypto purchase, salary, freelance payment, asset sale, loan repayment, staking reward, P2P trade, gift, inheritance, swap, or cash-out? Supporting records explain the economic origin — the "why" that the blockchain cannot provide.
- Whose wallet or account was involved? An AML reviewer may need to distinguish your own exchange account from your own self-custody wallet, from a payment to another person, from an employer, from a customer, from a P2P counterparty, from a merchant, or from a service. Keep a private mapping of your important wallet addresses — labeled clearly enough to distinguish self-transfers from third-party activity. Do not store seed phrases, private keys, or wallet backups inside your AML records.
- Why did the transaction happen? A simple explanation may be enough: moved to cold storage, received freelance income, portfolio rebalance, bridged ETH to Base, paid supplier, sold crypto and withdrew fiat. Without this context, a chain of TxIDs may still be difficult to interpret. For more on how Source of Funds reviews match documents with blockchain history, see our SoF matching guide.
Build the AML Paper Trail While the Crypto Moves
The strongest AML documentation is created at the time each event occurs — not reconstructed years later from fragments. The following covers the main lifecycle stages.
- When you buy crypto. Save the exchange or platform name, account ownership confirmation, trade confirmation, asset, amount, date, fiat value, the relevant bank or card payment record, and fees where material. When withdrawing from the exchange, also save the withdrawal confirmation, network, destination wallet address, and TxID. The AML chain reads: Bank or Card → Exchange → Crypto Purchase → Withdrawal → Personal Wallet. Do not assume that exchange history will always remain accessible — platforms close, change ownership, or archive old account data.
- When crypto comes from income. For freelance income, save the invoice or contract, client or counterparty name, amount, payment wallet address, TxID, and date. For salary received in crypto, save the employment record, payslip, and payment transaction. For staking or mining rewards, save the platform or protocol name, reward history, wallet, and distribution TxIDs where applicable. The transaction can show that USDC arrived. The invoice explains why it arrived.
- When you move funds to self-custody. This is where AML histories often become difficult later. Record which exchange withdrawal went to which wallet, the receiving address, which personal wallet application or device it belongs to, the purpose of the wallet, and the period of use. Keep simple labels: "Ledger ETH Main," "BTC Cold Storage," "MetaMask DeFi Wallet 2025–2026," "USDC Freelance Wallet." This allows later distinction between self-transfers, payments to third parties, and incoming payments from others. Never store seed phrases, private keys, wallet backups, or keystore files inside AML transaction records.
- When you swap assets. Save the input asset, output asset, wallet, transaction ID, DEX or exchange used, relevant contract address, amount in, amount out, and date. The AML purpose is to preserve continuity. Without this record, BTC purchased years ago may eventually appear as USDC with no obvious explanation of how the asset changed. Keep enough to reconstruct: ETH → DEX Swap → USDC.
- When you bridge crypto. Save the source chain, source TxID, bridge used, asset sent, amount, destination chain, destination transaction, output asset, destination wallet, and fees where useful. Cross-chain movement can make Source of Funds harder to explain because the same economic position is now represented across different blockchain histories. Do not rely only on a "Bridge Complete" screenshot — preserve the transaction references on both sides.
- When you use P2P or OTC. Where available, save the platform, order ID, asset, amount, the fiat leg and payment confirmation, wallet addresses, TxID, and any agreement or order context. The purpose is not to investigate the counterparty — it is to preserve enough context to explain why funds entered or left your wallet.
- When you sell or cash out. Connect the chain: Personal Wallet → Exchange Deposit → Sale → Fiat Withdrawal → Bank. Save the exchange deposit record, TxID, trade or sale confirmation, fiat proceeds, withdrawal confirmation, and the relevant bank record.
Some Records Matter More Because They Disappear
On-chain data may remain accessible indefinitely. Off-chain evidence is often what becomes unavailable — and it is usually the off-chain layer that an AML reviewer needs most.
- Exchange History. Save material purchases, sales, withdrawals, deposits, and account statements while access exists. Exchanges can close, shut down, change ownership, enforce data-retention limits, change export formats, or lock account access. Do not assume that a trade confirmation from 2024 will still be downloadable in 2028.
- Bank and Fiat Payment Records. For material crypto acquisitions or cash-outs, retain the bank or card records that connect fiat to crypto. This is particularly important for the first link in the chain — the original purchase that explains how fiat became crypto.
- Contracts and Invoices. Especially important for freelancers, consultants, merchants, contractors, and private sales. The blockchain shows that 5,000 USDC arrived. The invoice explains why 5,000 USDC arrived. Both together create a stronger AML explanation than either alone.
- P2P Order History. The blockchain may show funds arriving from an unfamiliar address. P2P order records can explain which platform, which trade, which fiat payment, and what the transaction purpose was. This data may be difficult or impossible to recover years later.
- Your Own Wallet Map. Memory degrades faster than blockchain. Five years later, address 0xAB...39 may mean nothing. A simple contemporaneous label — "My cold-storage wallet," "USDC Freelance Wallet" — preserves critical context. Do not present self-created labels as independently verified ownership proof.
- AML Screening Reports. If a user performs AML screening before or after a material transaction, preserving the report documents what the screening showed at that time. Address attribution can change, sanctions data can update, and a later screening may show a different result. A historical report preserves the point-in-time assessment.
Turn Years of Transactions into One Coherent AML History
A paper trail is only useful if a future reviewer can follow the thread from acquisition to current funds. That requires organization, not just accumulation. For each material event, retain a simple record: date, transaction type, asset, amount, chain, wallet or account, counterparty or service where relevant, TxID, purpose, supporting documents, and AML screening where relevant.
For example: "2026-04-18 | Freelance income | 4,500 USDC | Base | Client → USDC Freelance Wallet | Invoice 024 | TxID." Or: "2024-11-03 | Purchase + withdrawal | 0.18 BTC | Exchange X → BTC Cold Storage | Bank payment + trade record + withdrawal TxID."
- Focus on Continuity. The archive should allow a future reviewer to follow: Acquisition → Ownership → Movement → Transformation → Current Funds. Avoid collecting files without relationships between them. A folder of random screenshots is not a paper trail — it is a pile.
- Keep Original Records Where Possible. Prefer official PDFs, CSV exports, exchange statements, bank statements, original invoices, and order confirmations. Screenshots can support context but should not automatically replace original files.
- Keep Wallet Secrets Separate. Never include seed phrases, private keys, wallet passwords, or recovery backups in AML documentation. AML records need wallet identification, not wallet credentials.
- Use Secure Backups. A paper trail stored only on one old computer can disappear before the AML review ever begins. Use reasonable secure backup — without overcomplicating the storage infrastructure.
For material transactions — particularly before a large deposit, P2P deal, cross-chain transfer, or significant payment — saving a dated AML screening report adds a layer of documented risk context. The report records what a blockchain analytics tool identified about the wallet or transaction at that specific point in time.
An AML screening report is most useful when it is preserved alongside the TxID, purpose, counterparty context, and other transaction records — as part of the broader paper trail rather than as a standalone document. It can support a future Source of Funds explanation by showing that the user checked the risk profile before acting. It does not prove legal ownership, permanent low risk, or guarantee that an exchange or bank will accept the funds.
Using the Paper Trail When an Exchange or Bank Actually Asks
When a compliance review arrives, the paper trail converts a stressful reconstruction into a structured response.
Example. An exchange asks: please explain the Source of Funds for this 80,000 USDC deposit. Do not respond with 500 random screenshots. Use the paper trail to build a specific route: Salary Savings → Exchange ETH Purchase → Self-Custody → DEX Swap to USDC → Bridge to Base → Current Wallet → Exchange Deposit. Then provide evidence for the material stages: bank purchase record, exchange purchase confirmation, withdrawal TxID, wallet mapping and context, swap transaction, bridge transactions, current deposit, and AML report where relevant.
Good AML documentation is selective but connected. Do not automatically disclose unrelated wallets, bank accounts, transactions, or private financial records. Answer the actual review request.
If there are gaps. Do not fabricate missing records. Instead, identify the missing stage, export whatever historical data still exists, obtain duplicate bank or exchange records where possible, reconstruct blockchain movement, distinguish known facts from remembered context, and explain limitations clearly. If the original exchange closed, possible remaining evidence may include the bank transfer, a confirmation email, the withdrawal TxID, the receiving self-custody wallet, and subsequent blockchain history. Incomplete but honest is better than invented.
What tracing can and cannot fix. Blockchain tracing can help reconstruct complex movements across wallets, chains, and protocols. It cannot recreate invoices, contracts, employment relationships, bank payments, reasons for transactions, or missing exchange account records. Recordkeeping and tracing solve different problems — one preserves the why, the other reconstructs the where.
Know What Each AML Record Actually Proves
Not every document proves the same thing. Understanding the limits prevents over-reliance on any single piece of evidence.
- Purchase Confirmation can support acquisition, date, amount, and platform. It does not alone prove that the current crypto is unchanged from that purchase — swaps, bridges, and movements may have transformed the asset since.
- Bank Statement can support fiat funding or fiat cash-out. It does not alone prove which specific on-chain funds correspond to it — the connection requires matching with exchange records and TxIDs.
- TxID can support transaction existence, sender and recipient addresses, asset, amount, and blockchain timing. It does not automatically prove legal ownership, transaction purpose, or real-world identity.
- Wallet Label can preserve your own contemporaneous context — which wallet you called "Cold Storage" or "Freelance Wallet." It does not independently prove legal ownership of the address to a third party.
- Invoice or Contract can support why funds were paid. It does not alone prove that the crypto actually came from that payer — without a matching blockchain transaction connecting the payment address, the invoice, and the wallet.
- AML Screening Report can document the risk assessment at a particular time. It does not prove legal ownership, Source of Funds, permanent low risk, or future exchange acceptance.
The strongest ordinary AML explanation rarely relies on one perfect document. It links economic source → financial record → blockchain transaction → wallet context → later movement. That makes Source of Funds easier to reconstruct and easier for another person to understand.
Formal evidence is different. If a transaction becomes part of a criminal investigation, lawsuit, asset-recovery claim, or regulatory proceeding, formal preservation standards may be significantly stricter. For more on how blockchain evidence is preserved for formal legal review, see our evidence-preservation guide. Personal AML recordkeeping and formal forensic evidence are related but not the same.
Prepare for the AML Question Before Anyone Asks It
Crypto users often assume that because the blockchain is permanent, they can explain everything later. The transactions may remain. The AML context may not. What disappears: the purchase confirmation, the invoice, the exchange account, the P2P order, the bank evidence, the wallet ownership context, the reason for the transfer, the bridge history, and the historical AML screening result. A strong crypto paper trail lets the user connect how the crypto was acquired, which wallets were theirs, how assets changed form, why funds moved, and how the current balance relates to the original Source of Funds.
The blockchain preserves where the crypto moved. An AML-ready paper trail preserves where it came from, why it moved, and how those funds remained connected to you.
FAQ
What Crypto Records Should I Keep for AML Checks?
For material crypto activity, useful AML records can include exchange trade confirmations, bank statements, transaction IDs, wallet addresses, invoices, contracts, P2P order records, staking or mining statements, swap and bridge transactions, sale records, and dated AML screening reports where relevant.
Why Do Exchanges Ask for Crypto Source of Funds?
An exchange may need to understand how the crypto was originally acquired and whether the transaction is consistent with the customer's profile and risk controls. A blockchain deposit alone may show where the funds arrived from without explaining their economic origin.
What Documents Can Prove Crypto Source of Funds?
The right evidence depends on how the crypto was obtained. Common examples include exchange purchase records, bank statements, invoices, salary or freelance records, sale agreements, P2P records, mining or staking history, transaction IDs, and wallet history that connects those records to the current funds.
Why Is Blockchain History Not Enough for an AML Review?
Blockchain data records movements between addresses, but it usually does not explain why a transaction happened, who legally owned each wallet, what off-chain payment funded the purchase, or which invoice or contract was connected to the transfer.
What Should I Save When Moving Crypto to My Own Wallet?
Save the exchange withdrawal record, network, destination address, TxID, and a private record showing that the receiving address belongs to your self-custody wallet. This can later help distinguish self-transfers from payments to third parties.
What Should I Save After a Crypto Swap or Bridge?
For swaps, retain the input asset, output asset, transaction ID, wallet, protocol, and amounts. For bridges, preserve the source and destination chains, transaction references on both sides, bridge used, assets, amounts, and receiving wallet.
Should I Keep AML Reports with My Crypto Records?
For material transactions, a dated AML report can document what a wallet or transaction screening showed at that time. It can support a future AML explanation, but it does not replace Source of Funds documentation and does not guarantee acceptance by an exchange or bank.
What If My Old Exchange Account Is Closed?
Preserve whatever remains: bank transfers, confirmation emails, transaction IDs, wallet history, earlier exports, tax or accounting records, and other contemporaneous evidence. Try to obtain duplicate records where possible and clearly identify gaps rather than fabricating missing documents.
How Should I Organize Crypto Records for a Future AML Review?
For significant transactions, keep the date, asset, amount, blockchain, wallet or account, transaction ID, purpose, counterparty or service where relevant, and supporting documents together. The goal is to preserve a clear sequence from acquisition or income through subsequent movements to the current funds.
What Should I Send When an Exchange Asks for Source of Funds?
Answer the specific transaction being reviewed. Explain how the assets were acquired and how they moved to the current deposit, then provide the records supporting that route. Avoid sending unrelated personal financial information unless it is requested or necessary to explain the funds.