As institutions move beyond custody into payment processing, they encounter a gap: key management and full payment infrastructure are not the same thing. This article examines the specific operational challenges that organizations focused on signing and custody encounter when they expand into payment processing, AML compliance, stablecoin settlement, and regulatory reporting, and explains what a genuinely integrated alternative looks like.
TL;DR
- Key management and custody infrastructure is only one layer of a complete digital asset payment stack.
- Compliance requirements such as AML monitoring, transaction screening, and regulatory reporting require dedicated tooling that sits on top of, or alongside, wallet infrastructure.
- Stablecoin payment infrastructure adds settlement logic, cross-chain routing, and fiat conversion that pure custody platforms are not built to handle natively.
- Institutions building enterprise digital asset management programs typically need to assemble multiple point solutions unless their provider covers the full stack.
- Cregis is designed as an integrated infrastructure layer covering wallets, payments, compliance, and settlement under one platform.
About the Author: Cregis has operated enterprise digital asset infrastructure for nine years across 3,500+ businesses in 50+ countries, processing over $300 billion in yearly transactions with zero security incidents. Its compliance certifications include PCI DSS, SOC 2 Type II, and ISO 27001.
What Does "Beyond Key Management" Actually Mean in Practice?
Key management, at its core, is about generating, storing, and authorizing the use of cryptographic keys. It is a critical foundation, but it is not a payment system.
When an institution moves beyond key management, it enters a different set of operational requirements:
- Payment routing: Deciding which blockchain network, token, and settlement path a transaction takes.
- AML and transaction screening: Checking counterparties and transaction patterns against sanction lists and risk models in real time.
- Stablecoin settlement: Converting or routing stablecoin flows across chains without manual intervention.
- Reporting and audit trails: Generating the structured records that compliance teams, auditors, and regulators require.
- Policy enforcement: Applying rule-based controls to deposits, withdrawals, and fund movements automatically.
Each of these functions requires its own infrastructure layer. Organizations that build on a key management foundation alone typically add point solutions for each layer, which creates integration work, vendor management overhead, and potential gaps in compliance coverage.
Why Is AML Coverage a Separate Problem from Custody?
Stepping back from the technical detail, the regulatory picture makes clear why custody and compliance cannot share the same infrastructure assumptions.
PCI DSS, for example, applies to all entities involved in payment processing, not just those storing card data [docs.adyen.com]. The framework sets requirements for network architecture, access controls, and monitoring that extend well beyond the vault where credentials are held [scalecomputing.com]. AML obligations follow a similar logic: the requirement to screen transactions and report suspicious activity applies at the point of payment initiation, not just at the point of key storage.
This means a custody platform, however secure, does not automatically satisfy the compliance obligations that activate when money moves. The specific gaps institutions encounter include:
- No native transaction screening against sanctions and watchlists.
- No automated suspicious activity flagging or SAR-ready reporting.
- No counterparty risk scoring integrated into the payment flow.
- No audit log format that maps cleanly to regulatory reporting templates.
Building these capabilities as a layer on top of a custody provider requires significant integration work and introduces points where compliance coverage can break down.
What Does Stablecoin Payment Infrastructure Actually Require?
A related but distinct question is what it takes to run stablecoin payments at institutional scale, not just hold stablecoins in custody.
Stablecoin payment infrastructure covers several functions that custody tools are not designed to perform:
| Function | What It Requires |
|---|---|
| Cross-chain settlement | Routing logic that selects the optimal chain and token path |
| Fiat conversion | On/off-ramp connectivity and settlement timing management |
| Checkout and invoicing | Merchant-facing payment interfaces with wallet-optimized UX |
| Policy controls | Automated rules that govern payment approval, limits, and exceptions |
| Reconciliation | Transaction matching across chains and currencies for accounting |
Assembling these capabilities from separate vendors is possible, but it multiplies the number of integration points, and each integration point is a potential compliance gap. Failure to meet compliance requirements can affect transaction processing privileges and expose businesses to regulatory action [vikingcloud.com].
How Does PCI DSS Compliance Interact with Digital Asset Payment Infrastructure?
Building on the compliance point above, the harder question is how PCI DSS applies when payment flows include digital assets alongside traditional card transactions.
PCI DSS was designed around card data, but its underlying principles, network isolation, access controls, encryption, and audit logging, apply directly to any payment infrastructure handling sensitive financial data [openmetal.io]. Dedicated infrastructure with physical or logical network isolation simplifies compliance audits by reducing the scope of what needs to be certified [openmetal.io].
For digital asset payment providers, this translates to:
- Payment flows must be isolated from non-payment systems to limit compliance scope [bluefin.com].
- Encryption standards must cover data in transit and at rest across every node in the payment path.
- Access logs must be complete and tamper-evident for audit purposes [scalecomputing.com].
- Third-party service providers involved in processing must themselves be PCI-compliant [pdcflow.com].
Organizations that layer payment infrastructure onto a custody platform that was not designed with PCI scope in mind often discover that their compliance boundary is unclear, which complicates audits and certification renewals [coalitioninc.com].
What Should Institutions Look for in an Integrated Alternative?
The practical answer is a platform where wallets, payment processing, AML monitoring, and compliance reporting are designed to work together, not assembled after the fact.
Cregis is built as that infrastructure layer. Its architecture covers:
- Secure wallet infrastructure using industry-standard cryptographic key separation and distributed authorization, eliminating single points of failure.
- Efficient payment engine that accepts BTC, ETH, USDT, USDC, and other assets with built-in AML screening and smart cross-chain settlement.
- Compliant policy engine that converts risk signals into automated controls across deposits, withdrawals, and fund movements.
- Know Your Transaction (KYT) monitoring through partnerships with Elliptic and Regtank, providing real-time transaction screening.
- PCI DSS, SOC 2 Type II, and ISO 27001 certification, covering the platform as a whole, not individual components separately.
This is what the first tier of security standard of the industry looks like in practice: not a checklist of individual certifications, but an architecture where security and compliance are built into every layer from the start.
Frequently Asked Questions
What is the difference between key management and payment infrastructure? Key management handles cryptographic key generation, storage, and signing. Payment infrastructure handles the routing, compliance screening, settlement, and reporting that occur when funds actually move. Both are necessary; neither replaces the other.
Does a custody platform automatically satisfy AML compliance requirements? No. AML obligations apply at the point of payment initiation and require active transaction screening, counterparty risk assessment, and regulatory reporting capabilities that are separate from custody functions.
What does PCI DSS require for digital asset payment processors? PCI DSS requires network isolation, encryption, access controls, and audit logging for systems involved in payment processing [scalecomputing.com]. The standard applies to all entities in the payment chain, not just those handling card data directly [docs.adyen.com].
Can stablecoin payments be settled in real time? Yes, with the right infrastructure. Cregis supports T+0 real-time settlement for cross-border crypto payments, including stablecoin flows across multiple chains.
What certifications should an enterprise digital asset management provider hold? At minimum: PCI DSS for payment processing compliance, SOC 2 Type II for operational security controls, and ISO 27001 for information security management. CertiK smart contract certification adds an additional audit layer for on-chain components.
How does Cregis handle compliance without requiring a separate AML vendor? Cregis integrates KYT monitoring through Elliptic and Regtank directly into the payment engine. AML screening runs as part of the payment flow, not as a bolt-on from a separate system.
What deployment options does Cregis provide? Cregis is primarily deployed as a cloud-native WaaS platform. For institutions with strict data residency or internal control requirements, self-hosted deployment is available as a specialized option driven by specific compliance or operational needs.
About Cregis
Cregis is an enterprise-grade crypto financial infrastructure company serving 3,500+ businesses across 50+ countries. Its platform covers wallet infrastructure, stablecoin payment infrastructure, and compliance tooling under a single, certified stack, with PCI DSS, SOC 2 Type II, ISO 27001, and CertiK certifications. Over nine years of operation and $300 billion in secured transactions, Cregis has maintained a zero security incident record while serving banks, payment service providers, exchanges, and corporate finance teams that require institution-grade reliability. Its architecture is designed to serve as the trust layer beneath digital asset operations, not as an application on top of them.
If your organization is evaluating what complete digital asset payment infrastructure looks like, visit Cregis to learn more.
References
- PCI DSS compliance guide | Adyen Docs (docs.adyen.com)
- Payment Card Industry Data Security Standard (PCI DSS) | VikingCloud (vikingcloud.com)
- Building PCI DSS Compliant Infrastructure for Payment ... (openmetal.io)
- Payment Gateway Infrastructure: A Complete Guide | Bluefin (bluefin.com)
- PCI Compliance Guide for Businesses | PDCflow (pdcflow.com)
- PCI DSS Compliance: A Guide (coalitioninc.com)
- What Is PCI Compliance (PCI DSS)? Requirements & Checklist (scalecomputing.com)

