KYCC: Knowing Your Customer's Customer in Stablecoins
KYCC is the obligation to look one layer past your direct customer. For a stablecoin issuer whose direct customer is an exchange, that gap is where risk hides.
KYCC stands for Know Your Customer's Customer, the practice of identifying and risk-rating the people or entities your direct customer serves, not just the customer themselves. It exists because in many financial arrangements, especially stablecoin issuance, your direct customer is an intermediary who onboards their own users, and the money laundering or sanctions risk lives with those downstream users you never signed up.
Key takeaways
- KYCC extends standard Know Your Customer diligence one layer down: you assess your customer's customers, not only your customer.
- It matters most when your direct customer is an intermediary (an exchange, a payment processor, a corresponding institution) that onboards end users on their own.
- For stablecoin issuers, the direct customer is frequently a distributor or exchange, so the issuer has little native visibility into who ultimately holds or moves the token.
- Onchain, the wallet-to-wallet trail is public, but mapping wallets to real-world identity across intermediaries is where visibility actually breaks.
- KYCC obligations trace to correspondent-banking and third-party rules from FATF, FinCEN and banking regulators, later inherited by crypto intermediaries and issuers.
The chain that creates the problem
A stablecoin issuer rarely mints tokens directly into the hands of retail holders. The typical flow runs through several parties, and each hop is a place where the issuer's line of sight can drop.
| Step | Party | Who they onboard | Issuer visibility |
|---|---|---|---|
| 1. Mint | Issuer | Its direct institutional client | Full: the issuer runs KYC on this client |
| 2. Distribution | Exchange or distributor (the issuer's customer) | Its own trading users | Partial: issuer sees the exchange, not the exchange's users |
| 3. Withdrawal | End user | Themselves | None natively: the user was never the issuer's customer |
| 4. Secondary transfer | End user to another wallet | Anyone | None: value now moves peer-to-peer |
The issuer performed proper diligence at step 1. By step 3 the token is held by someone the issuer never assessed. KYCC is the requirement to reach into step 2 and gain reasonable assurance that the exchange in the middle is itself running competent identification on the users it onboards. The issuer cannot always name every end user, but it is expected to understand and monitor the intermediary well enough to trust the diligence happening one layer down.
A worked example
Suppose an issuer mints a large tranche to Exchange A after full KYC on Exchange A as a corporate client. Exchange A credits that liquidity across many of its own accounts, including one belonging to a user later flagged as sanctioned. The issuer never onboarded that user and has no direct record of them. Under a pure KYC regime, the issuer's obligation ended at Exchange A. Under a KYCC regime, the issuer is expected to have assessed whether Exchange A's own customer identification, transaction monitoring and sanctions screening are adequate, because Exchange A's failures flow back to the token the issuer put into circulation. If Exchange A cannot demonstrate that program, the intermediary itself becomes the risk the issuer has to price, restrict, or exit.
Where the regulatory obligation comes from
KYCC is not a crypto invention. It grew out of correspondent-banking supervision, where one bank holds accounts for another bank and inherits exposure to that second bank's clients. The Financial Action Task Force sets the baseline: its Recommendations require enhanced due diligence for correspondent relationships, including gathering enough information to understand the respondent institution's business and the quality of its own anti-money-laundering controls. That is KYCC in substance: diligence on an intermediary that stands between you and the ultimate customer.
In the United States, the same logic appears in the Bank Secrecy Act framework. FinCEN's 2013 guidance on virtual currency classified administrators and exchangers of convertible virtual currency as money services businesses subject to those AML obligations. FATF later extended its standards explicitly to virtual asset service providers through its updated guidance on virtual assets and VASPs, which is why exchanges and issuers now carry the same correspondent-style expectations that banks have long faced.
These are the primary sources for the obligation itself. How a specific issuer implements KYCC (contractual attestations, periodic audits, wallet screening) varies by firm and jurisdiction, so treat any single implementation as a business choice rather than a settled legal requirement.
Why the onchain trail helps and where it stops
Public blockchains change one part of this problem. Every transfer in the chain above is recorded: the mint to Exchange A, the withdrawal to a user wallet, and every secondary hop after that are all visible as onchain records. In principle an issuer can watch the token's full circulation without asking the intermediary for anything.
What the chain does not give you is identity. A wallet address is a pseudonym. The mint transaction shows tokens leaving the issuer and entering an address the issuer knows belongs to Exchange A, but the withdrawal shows tokens arriving at an address with no name attached. Linking that address back to a real person still depends on the intermediary's off-chain records, which is exactly the boundary KYCC is designed to police. The public ledger tells you the shape of the flow; it does not tell you who is on the other end.
To use the onchain trail for KYCC at all, an issuer has to resolve every one of those transfers into consistent fields: which asset moved, who issued it, the sending and receiving address, the amount, its USD value at the time, and whether the counterparty address is a known exchange deposit wallet, a distributor, or an unlabeled endpoint. Raw node data does not arrive in that shape, and a single stablecoin lives across many chains at once, each with its own transaction format. Allium ingests raw data from 150+ blockchains and standardizes it into those fields, with entity labeling that attaches known exchange and institution wallets to addresses. That is the input a monitoring or market oversight function needs to see where a token sits relative to the intermediaries in the chain. As a SOC 2 certified data provider, Allium aims for records reliable enough to sit under a compliance workflow.
KYC versus KYCC in one line
KYC answers "who is my customer." KYCC answers "can I trust who my customer serves." For most direct-to-consumer businesses the two collapse into the same question, because the customer is the end user. For a stablecoin issuer whose customer is an exchange, they are two different questions, and the gap between them is precisely the risk KYCC was built to close.
Frequently asked questions
What does KYCC stand for?
KYCC stands for Know Your Customer's Customer. It is the practice of assessing the customers of your direct customer, typically an intermediary, rather than stopping your due diligence at the customer you onboarded directly.
How is KYCC different from KYC?
KYC identifies and risk-rates your direct customer. KYCC extends that one layer further to the people or entities your customer serves. The difference only bites when your direct customer is an intermediary who onboards their own users, such as an exchange that a stablecoin issuer sells to.
Why do stablecoin issuers need KYCC?
A stablecoin issuer usually mints tokens to institutional distributors and exchanges rather than to end holders. Those intermediaries onboard the actual users, so the issuer has no native record of who ultimately holds the token. KYCC requires the issuer to gain reasonable assurance that the intermediary in the middle runs competent identification and monitoring on its own users.
Does KYCC come from a specific regulation?
KYCC grew out of correspondent-banking supervision. The FATF Recommendations require enhanced due diligence on respondent institutions in correspondent relationships, and FinCEN's Bank Secrecy Act framework applies similar AML obligations to money services businesses. FATF later extended these standards to virtual asset service providers, which is how issuers and exchanges inherited correspondent-style expectations.
Can blockchain data replace KYCC?
No. Onchain records show the full path a token takes between wallets, including mints, withdrawals and secondary transfers. They do not reveal who controls each wallet. Linking an address to a real identity still depends on the intermediary's off-chain records, which is the boundary KYCC is designed to police.
What happens if an intermediary fails its own KYC?
The intermediary itself becomes the risk. If an exchange in the middle cannot demonstrate adequate customer identification and sanctions screening, its failures flow back to the token the issuer put into circulation. Under a KYCC framework the issuer is expected to restrict, remediate, or exit that relationship rather than rely on it.