TL;DR:
- Responding to crypto regulatory inquiries involves immediate asset controls, thorough documentation, and clear communication with authorities. Firms that build detailed, defensible compliance programs and escalate uncertainties proactively are better protected against enforcement actions. Speed and quality of responses are crucial, with disciplined record-keeping serving as the best defense.
Responding to a crypto regulatory inquiry is a structured legal process requiring immediate compliance actions, documented due diligence, and clear communication with the SEC, CFTC, or OFAC. Crypto businesses that treat an inquiry as a routine administrative task routinely face escalated enforcement. The standard industry term for this process is “regulatory examination response,” and it covers everything from sanctions screening to audit trail preparation. This guide walks you through each stage, from the moment you receive notice to the point where your compliance program withstands regulator scrutiny.
What are the initial steps to respond to a crypto regulatory inquiry?

The first 48 hours after receiving a regulatory inquiry define how the rest of the examination unfolds. Three actions must happen immediately: block new transactions with any designated entities, freeze all related crypto and fiat assets, and report frozen funds to the relevant regulator such as OFAC or OFSI. Delay on any of these steps signals poor governance and invites deeper scrutiny.
Once assets are frozen, your compliance team must conduct a look-back exercise. OFAC guidance treats documented look-back procedures as a baseline compliance expectation, not an optional best practice. This means grouping customers by risk tier and applying consistent investigative frameworks to identify any prior transactions that may constitute sanctions evasion.
After completing the look-back, file Suspicious Activity Reports (SARs) where required. You can find detailed guidance on SAR obligations and reporting to the FBI through Murphyslawcrypto’s published resources. Communicate your findings to internal leadership and outside counsel before responding to the regulator in writing.
Here is the sequence to follow:
- Block all new transactions with designated or flagged entities.
- Freeze associated crypto wallets and fiat accounts.
- Notify the relevant regulator of frozen assets.
- Launch a documented look-back exercise covering the relevant time period.
- File SARs for any suspicious activity identified.
- Brief internal compliance leadership and retain outside legal counsel.
- Prepare a written response that addresses the inquiry directly and completely.
Pro Tip: Never send a written response to a regulator without legal review. A single poorly worded sentence can expand the scope of an inquiry into a full enforcement action.
How to conduct thorough due diligence beyond automated alerts

Weak governance and poor investigation quality cause most sanctions violations, not the absence of screening software. Regulators focus on how your firm investigates beneficial ownership and indirect counterparty risks, not simply whether your system generated an alert. Automated list-hits are the starting point, not the conclusion.
Understanding beneficial ownership is central to this process. A customer may not appear on a sanctions list directly, but a controlling owner or affiliated entity might. Your investigation must trace ownership structures at least two levels deep, document what you found, and explain why you reached the conclusion you did.
Static address screening is insufficient for modern sanctions compliance. Entity intelligence and network analysis are required to detect circumvention through intermediaries, shell companies, and cross-chain swaps. These are the mechanisms that most sanctions enforcement actions target today.
The following elements define a defensible due diligence process:
- Beneficial ownership mapping: Document the full ownership chain for every high-risk customer, including indirect controllers.
- Network and transaction pattern analysis: Review counterparty ecosystems, not just individual wallet addresses.
- Risk tiering: Group customers into consistent cohorts and apply the same investigative framework to each tier.
- Documented rationale: Record the logic behind every risk decision, not just the outcome.
- Escalation protocols: Define clear thresholds for when a relationship requires enhanced due diligence or exit.
Pro Tip: Apply the “regulator test” to every risk decision: ask whether you could explain this relationship to an SEC or CFTC examiner tomorrow with confidence. If the answer is no, escalate before the inquiry forces your hand.
The table below shows the difference between surface-level and defensible due diligence:
| Due diligence level | What it covers | Regulator assessment |
|---|---|---|
| Automated screening only | Sanctions list matches on wallet addresses | Insufficient; flags governance weakness |
| Entity-level investigation | Beneficial ownership, indirect counterparties | Meets baseline expectation |
| Network and pattern analysis | Transaction flows, shell structures, cross-chain activity | Demonstrates governance quality |
| Fully documented with rationale | All of the above plus written decision logic | Strongest defense in examination |
What are best practices for organizing compliance documentation during examinations?
Speed and quality of response heavily influence examination outcomes. Firms with clear remediation plans that directly address regulator feedback achieve significantly better results than firms that respond reactively. Preparation before an inquiry arrives is what separates a manageable examination from an enforcement action.
Your AML and sanctions program documentation must tell a coherent story. Regulators assess the quality of decision-making, not just the presence of screening tools. Every decision on a customer relationship, risk rating, or SAR filing must have a written explanation that a regulator can follow without asking follow-up questions.
The role of a compliance officer in this process is to own the audit trail from end to end. That means maintaining records of who made each decision, when, and on what basis. Gaps in this record create the impression of a compliance program that exists on paper but not in practice.
Key documentation practices to maintain:
- Audit trails for every risk decision: Date, decision-maker, rationale, and outcome must all be recorded.
- SAR filing logs: Document when SARs were filed, what triggered them, and what follow-up occurred.
- Remediation plans: When a regulator raises a concern, respond with a written plan that includes timelines and responsible parties.
- Governance records: Board and senior management oversight of the compliance program must be documented, not assumed.
- Training records: Regulators verify that staff received current AML and sanctions training.
Voluntary self-disclosure to OFAC or relevant bodies typically results in lower penalties than enforcement-driven cases. Proactive disclosure, paired with a well-documented remediation plan, signals to regulators that your firm takes compliance seriously and is not attempting to conceal violations.
Common mistakes to avoid when handling crypto regulatory inquiries
Relying solely on automated screening tools is the most common and costly mistake in crypto compliance. Compliance programs must move beyond technology reliance to thoughtful, well-documented decision frameworks. A firm that can show only that its software ran a check will not satisfy a regulator who wants to understand the human judgment behind each risk decision.
Ignoring indirect or nested ownership structures is equally dangerous. Most sanctions enforcement today targets circumvention through intermediaries and shell companies. A customer who passes automated screening may still present serious sanctions exposure through a parent entity or affiliated wallet.
“The simple test is whether you could explain a relationship decision to a regulator tomorrow with confidence. If you cannot, escalate the relationship for enhanced due diligence or consider exiting it entirely. Discomfort explaining a decision is itself a compliance signal.”
Slow or incomplete communication with regulators compounds every other mistake. Regulators interpret delayed responses as evidence of disorganization or concealment. A firm that responds promptly, even with a partial answer and a clear timeline for the full response, demonstrates good faith. A firm that goes silent signals the opposite.
Additional pitfalls to avoid:
- Failing to escalate: If your team cannot justify a relationship decision, escalate it immediately rather than leaving it unresolved.
- Inconsistent risk tiering: Applying different standards to similar customers creates the appearance of selective enforcement within your own program.
- Undocumented remediation: Fixing a problem without recording what changed and why leaves regulators with no evidence of improvement.
- Ignoring personal liability: Crypto executives face personal liability for compliance failures, not just the firm itself.
Key Takeaways
Responding effectively to a crypto regulatory inquiry requires immediate asset controls, documented due diligence, and a compliance program that can explain every decision to a regulator on demand.
| Point | Details |
|---|---|
| Act within 48 hours | Block transactions, freeze assets, and notify regulators immediately upon receiving an inquiry. |
| Go beyond automated screening | Investigate beneficial ownership and indirect counterparty risks with documented rationale. |
| Build a defensible audit trail | Record every risk decision with the date, decision-maker, and written justification. |
| Disclose proactively | Voluntary self-disclosure to OFAC typically results in lower penalties than reactive enforcement. |
| Escalate when uncertain | If you cannot explain a relationship to a regulator confidently, escalate or exit it before the inquiry forces the issue. |
What I’ve learned about crypto regulatory examinations
The firms that fare best in regulatory examinations are not the ones with the most sophisticated software. They are the ones that built a culture where compliance decisions get written down, reviewed, and defended before a regulator ever asks. That discipline is harder to build than any technology stack, and it is the only thing that actually protects you when the SEC or CFTC comes calling.
Speed matters, but quality matters more. I have seen firms rush out responses that created more questions than they answered. A well-organized, complete response delivered in five business days beats a hasty, incomplete one delivered in two. Regulators are experienced readers. They notice when a response is designed to satisfy the letter of an inquiry rather than the spirit of it.
The deeper lesson is that a crypto compliance program is not a document you file and forget. It is a living record of how your firm makes decisions under uncertainty. The firms that treat it that way rarely face enforcement actions. The ones that treat it as a checkbox exercise are the ones that end up in the news.
— Mark
Murphyslawcrypto can help you respond with confidence
Receiving a regulatory inquiry from the SEC or CFTC is not the moment to figure out your compliance program. It is the moment to call a lawyer who has been inside these cases.

Murphyslawcrypto, founded by Liam Murphy, Esq. (Penn Law, formerly Paul Hastings and McKool Smith), provides crypto compliance consulting and regulatory defense for businesses facing SEC and CFTC scrutiny. Liam has litigated landmark matters involving Celsius, Terraform Labs, and BitMEX. The firm builds defensible compliance programs, prepares examination responses, and represents clients when enforcement escalates. If your business needs to address a regulatory inquiry now, Murphyslawcrypto offers the legal depth to protect your interests. Review your legal options for crypto compliance and contact the firm directly.
FAQ
What does it mean to respond to a crypto regulatory inquiry?
Responding to a crypto regulatory inquiry means providing a documented, legally defensible reply to a formal request from the SEC, CFTC, or OFAC. It includes freezing assets, conducting look-back exercises, filing SARs where required, and submitting written responses with supporting compliance records.
How quickly must a crypto business respond to an SEC or CFTC inquiry?
The SEC and CFTC set specific deadlines in their inquiry letters, typically ranging from 10 to 30 days. Firms should act within 48 hours on asset controls and begin preparing documentation immediately, regardless of the formal deadline.
What is a look-back exercise in crypto compliance?
A look-back exercise is a documented review of historical transactions to identify activity that may constitute sanctions evasion or suspicious behavior. OFAC treats this as a baseline compliance expectation when a sanctions designation affects a firm’s customer base.
Does voluntary self-disclosure reduce penalties in crypto enforcement cases?
Yes. Voluntary self-disclosure to OFAC typically results in lower penalties than cases where violations are discovered through enforcement. Proactive disclosure paired with a remediation plan demonstrates good faith and improves regulator relations.
What is the biggest compliance mistake crypto firms make during regulatory inquiries?
The most common mistake is relying solely on automated screening tools without conducting entity-level investigations. Regulators assess the quality of human judgment and documented decision-making, not just whether a software system ran a check.