All notes
    AEOOctober 5, 202615 min read

    SEO and AEO Audit for Crypto and Fintech: How to Assess Organic and LLM Visibility on a YMYL Site

    SEO and AEO Audit for Crypto and Fintech: How to Assess Organic and LLM Visibility on a YMYL Site

    Use the same five-layer framework to assess technical access, YMYL trust, AI citations, and conversion.

    Share

    AI summary

    Short on time? Generate a TL;DR with key takeaways.

    Five-layer crypto SEO and AEO audit framework

    An SEO and AEO audit for a crypto or fintech site is a structured assessment of four things: whether search engines and AI crawlers can access and understand your site, whether your content and entity signals meet the trust standard Google applies to financial pages, whether AI assistants cite your brand accurately when buyers ask about your category, and whether the organic and AI-referred traffic you already get actually converts. For exchanges, stablecoin issuers and wallets the trust layer carries the most weight, because Google classifies these pages as YMYL (Your Money or Your Life) and holds them to a higher bar than almost any other kind of content.

    This guide walks through how I approach that audit, layer by layer, and what I look for at each stage. It is written for in-house marketing leads and heads of growth who want to know what a proper audit should cover before they commission one or try to run one internally.

    Why financial sites get audited differently

    Most SEO audit templates were built for ecommerce and publishing sites. They check crawlability, page speed, duplicate content, title tags and backlinks, and then hand you a spreadsheet sorted by severity. That is a reasonable starting point, but it misses the thing that decides outcomes in finance: whether Google and the AI assistants have enough evidence to trust you with a topic that can affect someone's money.

    Google's search quality rater guidelines define YMYL topics as those that could significantly affect a person's health, financial stability, safety or wellbeing. Financial advice, investing, and pages where people transact or store value sit squarely inside that definition. A crypto exchange, a stablecoin issuer and a self-custody wallet all ask users to move or hold funds. That is about as direct a financial consequence as a web page can have.

    Two things follow from that. First, the quality bar for the content is higher, so thin pages, anonymous authorship and unsourced claims cost you more than they would on a travel blog. Second, the audit has to look outside your own domain, because trust in this space is judged partly on what independent sources say about you.

    What the quality rater guidelines actually say, and what they do not

    It is worth being precise here, because this topic attracts a lot of loose talk.

    Quality raters are contractors who evaluate search results against Google's guidelines. Their ratings do not change the ranking of any individual page. Google uses the feedback to measure how well its ranking systems are performing and to refine them. So the guidelines are best read as a description of what Google's systems are trying to reward, not as a checklist that moves rankings directly.

    Google's own documentation says E-E-A-T (experience, expertise, authoritativeness and trustworthiness) is not a single ranking factor. Its systems use a mix of signals to surface helpful and reliable content, and for YMYL topics Google says it places even greater emphasis on those signals. The guidelines also describe trust as the most important element of the four, with the other three feeding into it.

    For a financial site, the practical reading is this. Raters are told to work out who is responsible for the site and the content, what the purpose of the page is, and what the reputation of the site and its creators looks like based on independent sources. They are told to look for accurate, well-sourced content that reflects genuine expertise, clear information about who runs the business, and for transactional sites, clear customer service and contact information. They are told to rate pages low when a YMYL page lacks adequate evidence of expertise or trust, contains inaccurate or misleading information, or appears designed to mislead.

    None of that is exotic. But when I audit exchange and wallet sites, I regularly find that the About page names no one, the licence information is buried in a footer PDF, the educational content has no author, and the pricing and fee pages have no last-updated date. Each of those is a small trust gap on its own. Together they describe a site that a careful rater, or a careful language model, has little reason to rely on.

    Layer one: technical foundations

    A site that cannot be crawled, rendered and indexed reliably cannot be trusted by anyone, human or machine. The technical layer comes first because every later finding depends on it.

    For crypto and fintech sites, the problems I see most often are these.

    Rendering is the first. Many exchange and dApp front ends are single page applications that depend on client-side JavaScript. If critical content such as fee tables, supported assets, jurisdiction information or product descriptions only appears after scripts run, search crawlers may see a partial page, and AI crawlers, many of which do not execute JavaScript at all, may see almost nothing. I test this by comparing the raw HTML response with the rendered DOM for each template type, and by checking what the major crawlers actually receive in server logs.

    Indexation control is the second. Exchanges tend to generate enormous numbers of URLs: trading pairs, token pages, price pages, language and region variants, filtered and sorted views. Without a deliberate canonical and indexation strategy, you end up with crawl budget spent on near-duplicate pages while the pages that matter are crawled infrequently. Programmatic pages need a quality threshold. A price page that shows a ticker and nothing else is the kind of thin content that drags down how a whole directory is perceived.

    International and jurisdictional setup is the third. Crypto businesses operate under different licences in different markets, and the site structure usually has to reflect that. I check hreflang implementation, whether region selectors and geo-redirects block crawlers from seeing content, and whether the right entity and licence information appears on the right regional version. A site that shows a user in the EU the wrong regulatory status is a compliance problem and a trust problem at the same time.

    Performance and stability make up the fourth. Core Web Vitals (LCP, CLS and INP, which replaced FID in 2024) matter most on mobile, where a large share of retail crypto traffic arrives. Heavy charting libraries, third-party widgets and wallet connection scripts are the usual culprits.

    Structured data is the fifth. Organization markup with sameAs links to your official profiles and regulator register entries helps machines resolve who you are. Article markup with named authors and dates supports the editorial layer. FAQ markup no longer produces rich results for most sites, since Google restricted them in 2023, but I still use it where the content is genuinely question and answer, because it gives answer engines a clean structure to parse. I treat schema as a way to state facts clearly, not as a lever to pull for visual SERP features.

    Finally, AI crawler access. I check robots.txt and any bot management layer for the user agents that matter, including GPTBot, OAI-SearchBot, PerplexityBot and ClaudeBot, and I check CDN and WAF rules, because security tools often block these by default without anyone deciding to. Whether to allow training crawlers is a business decision. Whether to allow retrieval and search crawlers is usually an easier one, because blocking them removes you from the answers entirely. It is worth knowing which choice you have made rather than discovering it later.

    Layer two: authority and trust signals

    This is where YMYL changes the audit most. I split it into on-site and off-site.

    On the site, I look for the following. A clear legal entity, with the registered company name, registration number, jurisdiction and address easy to find. Licence and registration information stated plainly, with links to the relevant regulator register entry so a reader can verify it. For an EU business that might be a MiCA authorisation, for a UK business an FCA registration, and so on. A real About page naming leadership, with credentials and verifiable profiles. Authors on educational and market content, with bios that explain why they are qualified to write about the topic. An editorial policy that explains how content is researched, reviewed and updated. Visible published and last-updated dates, and a habit of actually updating the page when facts change. Primary sources cited for factual claims, such as regulator documents, reserve attestations, audit reports and protocol documentation rather than other blogs. Risk disclosures written for humans. And accessible contact and support information, including how to report a problem.

    Off the site, I look at how the entity is described elsewhere. That includes regulator registers, review platforms, news coverage, community discussion, Wikipedia and Wikidata where an entry exists, and the sources that rank for your brand name plus words like review, scam, legit and complaints. This matters for two reasons. The guidelines tell raters to research reputation from independent sources, and the large language models draw heavily on exactly these third-party sources when they form an answer about a company. If the independent record is thin, outdated or negative, no amount of on-site polish fully compensates.

    I also look at brand SERP defence. In this industry, impersonation and phishing sites are common, and a user who searches for your wallet or exchange by name may be shown a convincing fake. Monitoring your brand results, claiming your official profiles and making your canonical URLs unambiguous is part of being authoritative, not a separate security exercise.

    Layer three: what changes by business type

    The framework above applies everywhere, but the details differ across exchanges, stablecoin issuers and wallets.

    Exchanges

    For exchanges the central question is licensing and jurisdiction, and whether your site says clearly where you are permitted to operate. Users and AI assistants both ask questions like whether a platform is regulated in a given country, what its fees are, and which assets it supports. If your answers to those questions are scattered, out of date or contradicted by third-party sites, you lose control of the narrative. I check that fee schedules, supported jurisdictions and product availability each live on a dedicated, dated, crawlable page, that comparison and alternative pages are handled honestly, and that programmatic pairs and token pages meet a real quality bar. I also review financial promotion compliance, since the wording on landing pages is regulated in many markets and the audit should flag anything that creates risk.

    Stablecoin issuers

    A stablecoin page is a page about whether a person can rely on something to hold its value. That makes accuracy and transparency the whole game. I look for a clear statement of the issuing entity, the reserve composition and where it is held, the frequency and source of attestations or audits, redemption terms and who is eligible to redeem, supported chains and contract addresses, and a plain account of the risks. Data that changes, such as reserve breakdowns and circulating supply, should be dated and sourced, ideally with links to the primary documents. AI assistants frequently summarise stablecoins by pulling from comparison articles, so I also check what those third-party summaries say about the issuer and whether they are accurate.

    Wallets

    Wallets are judged on security claims. I check whether statements about custody model, key management, audits and open source status are specific and verifiable: a link to the repository, a link to the audit report, a named security contact and a bug bounty programme where one exists. Educational content about seed phrases, recovery and transaction safety needs accurate, expert-reviewed guidance, because errors here lead directly to lost funds. Wallets also face the heaviest impersonation risk, so download page integrity and official link consistency across the site, app stores and social profiles deserve a careful review.

    LLM citation and accuracy mapping for a regulated crypto brand

    Layer four: LLM visibility

    The AEO half of the audit asks what the AI assistants say when your buyers ask them about your category, and whether what they say is true.

    I build a prompt set that reflects how people actually research. It covers category discovery prompts such as which exchanges are regulated in a given region or which stablecoins are considered most transparent, comparison prompts that pit you against named competitors, brand prompts that ask directly about you, and trust and safety prompts such as whether you are legitimate. I vary the prompts by jurisdiction and by funnel stage, then run each one repeatedly across ChatGPT, Perplexity, Gemini, Claude and Google AI Overviews, because responses vary between runs and a single answer proves very little.

    From the results I measure several things. Mention share is how often your brand appears in answers. Citation share is how often your own domain is cited as a source, which is a different and often lower number. Position and framing look at whether you are recommended, listed neutrally or mentioned as a caution. Sentiment and accuracy capture whether the model states your fees, licence status and jurisdictions correctly. And source mapping identifies which third-party domains the models rely on when they talk about you, which tells you where to focus your off-site effort.

    In YMYL categories, accuracy is the finding that matters most. In our MiCA research, one major exchange appeared in roughly three quarters of AI-generated answers about EU crypto exchanges despite not holding a valid MiCA licence. The point is not about that exchange. It is that visibility in AI answers and regulatory accuracy are separate things, and an audit has to test both. A brand can be highly visible and consistently misdescribed, and for a regulated business that is a risk, not a win.

    I also classify each topic as owned, contested or unsettled, depending on whether one brand or a small group clearly dominates the answers. Unsettled topics are the opportunity, because no one has locked in the citation habit yet.

    Layer five: conversion assessment

    Traffic that does not convert is a vanity metric, and finance sites have conversion problems that generic CRO advice does not cover. So the audit includes a conversion assessment of the pages that bring in organic and AI-referred visitors.

    I start by defining what conversion means for each business type. For an exchange it might be account registration, KYC completion, first deposit and first trade. For a wallet it could be an install or a first transaction. For a stablecoin issuer it may be an integration enquiry or a developer signup. I then check that analytics captures those events, and where relevant that on-chain actions such as wallet connections and deposits can be tied back to the landing page and channel that started the journey.

    Then I review the pages themselves. Does the page match the intent of the query that brought the visitor? Is the primary action obvious? How many steps stand between a visitor and registration, and where do people drop out? Are trust elements such as licences, security information and regulator links placed near the point of decision rather than only in the footer? How does the page perform on mobile connections? Does a wallet connect flow fail gracefully?

    Compliance shapes what is testable. Risk warnings and mandatory disclosures cannot simply be removed to lift conversion, but their placement, wording clarity and design can be tested within the rules of each market. I treat that as a design constraint, and I flag where compliance copy is doing more damage than it needs to.

    For AI-referred traffic, I look at visits from sources such as chatgpt.com and perplexity.ai, compare their behaviour with organic search visitors, and note that a share of AI-driven visits arrive without a referrer and show up as direct. That makes the numbers an undercount, so I treat them as directional.

    Turning findings into a roadmap

    The output of an audit is only useful if it tells a team what to do first. I score each finding on three dimensions: how much it affects trust or visibility, how much revenue or pipeline it touches, and how hard it is to fix. Broken access for crawlers and incorrect regulatory information sit at the top. A long tail of minor template issues goes at the bottom. The result is a 30, 60 and 90 day plan that separates quick fixes, structural work and ongoing programmes such as digital PR and content refreshes.

    I also include a baseline for the LLM visibility numbers, so progress can be measured on the same prompt set later. Without a baseline, AEO work is impossible to evaluate.

    Common mistakes I see

    Treating the audit as a one-off document. These sites change constantly, licences get granted, products launch and regulators issue new rules, so the trust and accuracy checks need a regular rhythm.

    Optimising pages for keywords while leaving authorship and sourcing untouched. On a YMYL site, the writing and the evidence behind it are the product.

    Ignoring the off-site record. If the independent sources describing you are out of date, an on-site rewrite will not fix the answers people get.

    Assuming that strong rankings mean strong AI visibility. The two overlap, but they are not the same, and the gap between them is where most of the missed opportunity sits.

    Getting started

    If you want to do a first pass internally, start with five checks. Fetch your key templates as raw HTML and see what a crawler sees. Confirm your licence and entity details are findable in two clicks from the homepage. Check that every educational article has a named, qualified author and a last-updated date. Ask the major AI assistants ten questions a buyer would ask and note what is wrong. And look at the first page of results for your brand name plus the word review.

    If you would like an outside view, I run audits that cover all five layers for exchanges, stablecoin issuers, wallets and other regulated crypto and fintech businesses. The best next step is a growth plan conversation, where we look at your current visibility and decide what is worth doing first.

    FAQ

    What is the difference between an SEO audit and an AEO audit?

    An SEO audit assesses how well a site can be crawled, indexed and ranked in traditional search results. An AEO audit assesses how often and how accurately AI assistants mention and cite your brand when answering questions about your category. For financial businesses the two share a foundation of technical health and trust signals, so they are best run together.

    What does YMYL mean for a crypto site?

    YMYL stands for Your Money or Your Life. It is the category Google uses for topics that could significantly affect a person's financial stability, health, safety or wellbeing. Exchanges, wallets, stablecoins and financial advice content fall into it, which means Google expects stronger evidence of expertise, accuracy and trust.

    Do quality raters affect my rankings?

    No. Raters evaluate search results to help Google measure and improve its systems, but their ratings do not directly change the ranking of individual pages. The guidelines are still useful because they describe what Google is trying to reward.

    How often should I run an LLM visibility audit?

    Quarterly is a sensible rhythm for most businesses, with more frequent checks on high-stakes prompts such as licence status and fee questions. AI answers shift as models and sources update, so a single snapshot goes stale quickly.

    Can I fix AI answers that describe my business incorrectly?

    You cannot edit the models directly, but you can influence the sources they draw from. That means publishing clear, dated, well-sourced pages on the topic, correcting inaccurate third-party coverage, and strengthening the independent sources that describe you accurately.

    Free · 5 business days

    Want this for your team?

    Start with twenty prompts against your brand. Free Growth Plan, no slide deck.

    Request a Growth Plan