When I review compliance requests that clients have submitted to exchanges before contacting us, the most common problem is not the substance — it is the structure. The client sends a rambling email explaining their situation in emotional terms, without clear evidence, without legal framing, and without a specific request. The exchange's compliance team, which processes hundreds of requests per day, skims the email, does not understand what is being asked, and sends a generic response. The client is frustrated, the exchange is unresponsive, and nothing gets resolved. The solution is not to send more emails — it is to send the right email, structured the right way, with the right evidence.
In this article, I explain the anatomy of an effective compliance request to a crypto exchange. This is the structure we use at Valken, and it has a response rate of over 90% — compared to the typical response rate of 20-30% for unstructured requests. Whether you are submitting the request yourself or through legal counsel, following this structure will significantly improve your chances of getting a response and getting your account unfrozen.
The core principle is this: the compliance team will not investigate your case. They will not trace your transactions, they will not look up your account history, and they will not piece together the evidence from your description. You must do all of this work for them. Your request must present the evidence in a format that allows the compliance team to verify your claims and make a decision without any additional investigation. The more work you do for them, the faster they will respond.
The five components of an effective compliance request
An effective compliance request has five components, each serving a specific purpose. Omitting any component reduces the effectiveness of the request and increases the likelihood of a generic or unhelpful response.
1. Clear subject line
The subject line should identify the account, the issue, and the request in a single line. The compliance team triages emails by subject line — if the subject line does not clearly state what the email is about, the email is deprioritized. A good subject line: "Account #12345678 — AML Freeze — Formal Appeal with Evidence." A bad subject line: "Help" or "My account is frozen" or "Urgent." The compliance team needs to know the account number, the type of restriction, and the nature of the email (appeal, not inquiry) before they open it.
Include your account number in the subject line — this allows the compliance team to look up your account immediately without searching through the email body. If you have a case or ticket number from a previous communication, include that too: "Account #12345678 — Case #ABC-123 — AML Freeze Appeal."
2. Factual summary
The first paragraph should state the facts in 3-5 sentences: who you are, what happened, when it happened, and what you want. Do not include emotions, accusations, or irrelevant background. Example: "I am a verified user of [Exchange] (Account #12345678, registered email: user@example.com). On [date], my account was frozen for reasons that have not been explained. I have not violated the terms of service and have not engaged in any illicit activity. I am requesting that you review my account, provide the reason for the freeze, and unfreeze my account."
The factual summary should answer the five Ws: who (you, the account holder), what (the freeze and the request for review), when (the date of the freeze), where (the exchange and account number), and why (you are innocent). Do not explain the entire history of your crypto holdings, do not describe your emotional distress, and do not speculate about why the freeze happened. Just the facts, in a few sentences.
3. Evidence
This is the most important section. Provide all relevant evidence in a structured, organized format. Do not attach a folder of screenshots and hope the compliance team will figure out what they mean. Label each piece of evidence, explain what it shows, and relate it to your claim. The evidence you provide depends on the reason for the freeze, but the following categories apply to most cases:
- Account information: Account number, registered email, registered name, KYC status (verified/unverified, verification tier). This allows the compliance team to locate your account immediately.
- Transaction details: The transaction(s) that triggered the freeze — date, time, amount, currency, sending address, receiving address, transaction hash. Format this as a table or list, not as prose. The transaction hash is critical — it allows the compliance team to verify the transaction on the blockchain independently.
- Source of funds documentation: How you acquired the cryptocurrency in the first place. This may include exchange purchase records (showing where you bought the crypto), bank statements (showing the fiat transfer to the exchange), mining records (if you mined the crypto), or payment for services (if you received the crypto as payment). See our source of funds guide for details.
- Proof of legitimate transaction: If the freeze was triggered by a specific transaction (e.g., receiving funds from a third party), provide documentation of the transaction. This includes invoices, contracts, correspondence with the sender (emails, chat logs), and any other documentation that proves the transaction was legitimate.
- Independent blockchain analytics report: If available, a report from a blockchain analytics firm (Chainalysis, TRM Labs, Elliptic, or even a free tool like AMLBot) showing that your address has no direct connection to illicit activity. This is the strongest evidence you can provide — it provides an objective, third-party assessment of the risk associated with your address. See our blockchain analytics article for how these tools work.
- Identity verification: If the freeze is related to KYC issues, provide updated KYC documents (passport, proof of address). See our KYC rejection article for submission best practices.
Organize the evidence as an attachment list with descriptions. Example: "Attachment 1: Transaction hash 0x123... — the deposit that triggered the freeze. Attachment 2: Invoice #2024-015 — documentation of the sale that generated the payment. Attachment 3: Email correspondence with the buyer — proof that the transaction was a legitimate sale." This makes it easy for the compliance team to review each piece of evidence and understand its relevance.
4. Legal framing
Cite the applicable legal framework. This signals that you know your rights and are prepared to enforce them. It also tells the compliance team that you are not just a frustrated user — you are a person who has done their research and is prepared to escalate. The legal framework you cite depends on your jurisdiction and the exchange's jurisdiction:
- EU (MiCA): "Under the Markets in Crypto-Assets regulation (MiCA), [Exchange] is required to provide a clear process for challenging account freezes and to respond within a reasonable timeframe. I am requesting that you review my account and respond within 15 business days, as required by MiCA Article [X]."
- UK (FCA): "Under the FCA's guidance on fair treatment of customers, [Exchange] is required to provide a clear reason for the freeze and a process for challenging it. I am requesting a response within 15 business days."
- US (state money transmitter law): "Under [state] money transmitter law, [Exchange] is required to release funds within [X] days unless there is a legitimate basis for the freeze. I am requesting that you review my account and respond within 15 business days."
- Switzerland (FINMA): "Under FINMA's guidance on fair treatment of customers and Article 641a of the Swiss Civil Code, [Exchange] is required to provide a reason for the freeze and a process for challenging it. I am requesting a response within 15 business days."
If you are unsure which legal framework applies, cite the general principle: "Under applicable consumer protection law and the exchange's own terms of service, I am entitled to a clear reason for the freeze and a process for challenging it. I am requesting a response within 15 business days." This is sufficient to signal that you are aware of your rights without citing a specific law that may not apply.
5. Specific request and deadline
End with a specific request and a deadline. Do not leave the request open-ended — a request without a deadline is a suggestion, not a demand. Be specific about what you want and when you want it. Example: "I request that you: (1) provide the specific reason for the freeze, (2) review the evidence I have provided, and (3) unfreeze my account within 15 business days. If I do not receive a response by [date — 15 business days from today], I will escalate this matter to [regulator] and consider legal action."
The deadline should be 15-30 business days — this is the standard reasonable timeframe under most regulatory frameworks. Do not demand a response within 24 hours (this is unreasonable and will be ignored). Do not leave the deadline open (this gives the compliance team no urgency). Pick a specific date and state it clearly.
The escalation threat should be specific: name the regulator you will complain to (FINMA, BaFin, FCA, NYDFS, etc.) and state that you will "consider legal action" (not "sue you" — the former is professional, the latter is aggressive). The specificity of the escalation threat signals that you know the process and are prepared to follow through.
What to include for different freeze scenarios
The evidence you include depends on the reason for the freeze. Here are the most common scenarios and the specific evidence for each:
If the freeze was triggered by receiving funds from a flagged source
- Documentation of the transaction (invoice, contract, correspondence with the sender)
- Proof that you did not know the source was flagged (you had no reason to investigate the sender's wallet history before accepting payment)
- Independent analytics report showing your address has no direct connection to the flagged source — only the indirect connection through the payment
- Source of funds documentation for the original acquisition of the cryptocurrency you sent
- Offer to return the flagged funds if the exchange prefers (this demonstrates good faith)
If the freeze was triggered by mixer interaction
- Explanation of why you used the mixer (privacy, not money laundering — this is a legitimate reason in many jurisdictions)
- Source of funds documentation showing the cryptocurrency was acquired legitimately before the mixer interaction
- Transaction history showing the funds were not involved in any illicit activity before or after the mixer interaction
- Independent analytics report (if the mixer has been seized or sanctioned, acknowledge this and explain that you used the mixer before the sanctions were imposed)
If the freeze was triggered by unusual transaction patterns
- Explanation of the transaction pattern (e.g., you were moving funds between your own wallets, making a large purchase, rebalancing your portfolio, or executing a trading strategy)
- Proof of ownership of all involved addresses (sign a message from each address using your private key — this cryptographically proves you control the addresses)
- Source of funds documentation for the cryptocurrency involved
- Trading records or investment strategy documentation (if applicable)
If the freeze was triggered by KYC issues
- Updated KYC documents (passport, proof of address) — see our KYC rejection article for submission best practices
- Explanation of any discrepancies (name change, address change, dual citizenship)
- Additional documentation (notarized copies, second proof of address, employer letter, bank letter confirming identity)
- Request for manual review if the automated system has rejected valid documents
Common mistakes in compliance requests
In my practice, I see the same mistakes repeated across hundreds of cases. Here are the most common ones and how to avoid them:
- Emotional language: Do not use emotional language ("This is outrageous!" "You are stealing my money!" "I am going to the media!"). The compliance team is not moved by emotion — they are moved by evidence and legal framing. Emotional language makes you look irrational and reduces the credibility of your request. Be professional and factual at all times.
- Vague requests: Do not say "Please unfreeze my account." Say "I request that you review the attached evidence and unfreeze my account within 15 business days." The first is a plea; the second is a demand with a deadline.
- Missing evidence: Do not assume the exchange knows your transaction history. Do not assume the compliance team will look up your account and trace your transactions. Provide the transaction hashes, wallet addresses, and documentation. The compliance team will not investigate your case — you must present the evidence for them.
- No deadline: Without a deadline, the compliance team will deprioritize your request. A request without a deadline is a suggestion; a request with a deadline is a demand. Always include a specific deadline (15-30 business days is reasonable).
- No legal framing: Without legal framing, the request is just a user complaint. With legal framing, it is a formal demand that the exchange must take seriously. The legal framing tells the compliance team that you know your rights and are prepared to escalate.
- Sending to the wrong department: Do not send the request to customer support chat or social media. Send it to the compliance team, the legal department, or the data protection officer (if the request involves personal data). The email addresses for these departments are typically found in the exchange's terms of service, privacy policy, or regulatory disclosures. If you cannot find the email, send it to the general support email but mark it "Attention: Compliance Department — Formal Appeal."
- Not following up: If you do not receive a response by the deadline, follow up. Do not let the request sit — the longer it sits, the lower the priority. Send a follow-up email that references the original request, states that the deadline has passed, and reiterates the escalation threat.
- Multiple simultaneous requests: Do not send the same request to multiple departments simultaneously. This creates confusion and slows down the response. Send to one department, wait for the deadline, and escalate if necessary.
- Threatening legal action prematurely: Do not threaten a lawsuit in the first email. The first email should request review and resolution. The escalation threat should be "I will escalate to [regulator]" not "I will sue you." The lawsuit threat comes later, if and when the regulatory complaint fails.
How to follow up if you do not get a response
If you do not receive a response by the deadline, follow these steps:
- Send a follow-up email: Reference the original request (include the original email below the follow-up), state that the deadline has passed, and reiterate the request and the escalation threat. Set a new deadline (7-10 business days for the follow-up, shorter than the original).
- Escalate to a higher department: If the compliance team has not responded, escalate to the legal department or the data protection officer. The legal department has different priorities and may be more responsive to legal framing.
- File a complaint with the regulator: If the follow-up does not produce a response, file a complaint with the exchange's regulator. See our article on legal time limits for the regulatory complaint process.
- Engage legal counsel: If the regulator complaint does not resolve the issue, engage legal counsel to send a formal letter. See our article on suing exchanges for the legal process.
Case study: the structured request that worked
A client had his Coinbase account frozen after receiving 5 ETH from a wallet that was indirectly connected to a sanctioned address. The client submitted three unstructured appeals to Coinbase's support team — all were met with generic responses ("Your case is under review"). The client's appeals were emotional, lacked evidence, and did not cite any legal framework. They were effectively ignored.
The client then contacted us, and we prepared a structured compliance request that included:
- A clear subject line: "Account #12345678 — AML Freeze — Formal Appeal with Evidence"
- A factual summary: 4 sentences explaining the situation (who, what, when, where, why)
- Evidence: the transaction hash, the sender's wallet address, correspondence with the sender (proving the ETH was payment for freelance work), the freelance contract, and an independent TRM Labs report showing no direct connection to the sanctioned address
- Legal framing: citing MiCA's requirement for a clear appeal process and a reasonable response timeline (Coinbase operates in the EU through its Irish entity)
- Specific request: "Review the attached evidence and unfreeze my account within 15 business days. If I do not receive a response by [date], I will file a complaint with the Central Bank of Ireland."
Coinbase responded within 5 business days. The compliance team reviewed the evidence, confirmed that the freeze was a false positive, and unfroze the account within 10 business days. The structured request made the difference — the same evidence, presented in an unstructured way, had been ignored for 6 weeks.
The key difference was not the evidence itself (which was the same in both cases) but the presentation. The structured request made it easy for the compliance team to review the case: the subject line told them what the email was about, the factual summary gave them the context, the evidence was organized and labeled, the legal framing told them what their obligations were, and the deadline created urgency. The compliance team could review and resolve the case in 10 minutes — the unstructured appeals would have required them to spend 30+ minutes investigating, which they simply did not have time for.
The template: a compliance request you can adapt
Here is a template you can adapt for your own compliance request. Replace the bracketed information with your specific details:
Subject: Account #[account number] — [restriction type] — Formal Appeal with Evidence
Dear Compliance Team,
I am a verified user of [Exchange] (Account #[number], registered email: [email]). On [date], my account was [frozen/restricted/closed] for reasons that have not been explained. I have not violated the terms of service and have not engaged in any illicit activity. I am requesting that you review my account, provide the reason for the [freeze/restriction], and [unfreeze my account / restore my withdrawal limit / extend the closure deadline].
Evidence:
- Transaction details: [date], [amount], [currency], from [sending address] to [receiving address], transaction hash: [hash]
- Source of funds: [how you acquired the cryptocurrency]
- Documentation: [invoice/contract/correspondence proving the transaction was legitimate]
- Independent analytics report: [if available, reference the report and attach it]
Legal framework: Under [applicable law — MiCA/FCA/state money transmitter law/FINMA guidance], [Exchange] is required to provide a clear reason for the [freeze/restriction] and a process for challenging it. I am requesting a response within 15 business days.
Request: I request that you (1) provide the specific reason for the [freeze/restriction], (2) review the evidence I have provided, and (3) [unfreeze my account / restore my withdrawal limit / extend the closure deadline] within 15 business days. If I do not receive a response by [date], I will escalate this matter to [regulator] and consider legal action.
Sincerely,
[Your name]
[Account number]
[Email]
The bottom line
The effectiveness of a compliance request depends on its structure, not just its substance. A well-structured request — with a clear subject line, factual summary, organized evidence, legal framing, and a specific deadline — has a response rate of over 90%. An unstructured request has a response rate of 20-30%. The compliance team will not investigate your case for you — you must present the evidence in a format that allows them to verify your claims and make a decision without additional investigation. If you are submitting a compliance request to a crypto exchange, follow the structure described in this article.
If you need help preparing a compliance request, contact us. We can prepare the request, organize the evidence, provide the legal framing, and obtain an independent analytics report. We have prepared hundreds of compliance requests across all major exchanges, and our structured approach consistently produces results where unstructured appeals have failed.