Transaction Monitoring
Transaction monitoring is the automated surveillance of wallet activity to detect anti-money laundering, counter-terrorism financing, and sanctions red flags under FATF Recommendation 20 and FinCEN's Bank Secrecy Act framework. For a Virtual Asset Service Provider, it is the operational mechanism that turns AML policy into actual filed Suspicious Activity Reports.
Unlike traditional banking, where transactions move through a known intermediary, crypto transaction monitoring works on pseudonymous on-chain data — wallet addresses, transaction graphs, and counterparty risk scores derived from clustering and attribution.
What Transaction Monitoring Detects
A modern crypto transaction monitoring system scores every inbound and outbound transaction against multiple risk dimensions:
- Direct sanctions exposure — Wallet interacts with an OFAC SDN-listed address (Tornado Cash, Garantex, Lazarus Group attributions).
- Indirect exposure — Wallet is N hops away from a sanctioned or illicit cluster, where N is configurable (typically 1-5 hops).
- High-risk counterparty types — Mixers, privacy wallets, darknet markets, ransomware payment processors, gambling sites, or unhosted wallets from FATF grey-list jurisdictions.
- Behavioural anomalies — Activity inconsistent with the customer's declared profile (a retail customer suddenly moving institutional volumes).
- Structuring — Multiple sub-threshold transactions designed to evade reporting limits (the crypto equivalent of "smurfing").
Common Red Flags Under FATF Guidance
FATF's 2025 Targeted Update on Implementation of VA Standards lists the typologies that supervisors expect transaction monitoring to catch:
| Red flag | What it looks like on-chain | |----------|----------------------------| | Mixer usage | Deposits to Tornado Cash, Sinbad, or similar pre-2022-OFAC-listed services | | Peel chain | Long sequence of small outbound transactions from a large initial deposit | | Chain-hopping | Rapid conversion between BTC, ETH, USDT across chains to break attribution | | DPRK IT worker pattern | Mid-size payments from US tech firms to wallets clustered with Lazarus addresses | | Pig-butchering | Customer deposits steadily, then makes a large outbound transfer to a known scam cluster | | Sanctions evasion | Counterparty wallet linked to Russian, Iranian, or Cambodian scam-network entities |
How the Tools Work
The crypto transaction monitoring market is dominated by three blockchain analytics providers:
- Chainalysis KYT — Real-time scoring API used by Coinbase, Kraken, and most US-licensed exchanges. Integrates with the Travel Rule protocols.
- Elliptic Lens — Strong on European compliance and cross-chain attribution.
- TRM Labs — Strong on law enforcement and sanctions screening; embedded in many bank crypto onboarding workflows.
These tools combine attribution data (clustering heuristics, exchange deposit-address tagging, off-chain intelligence) with rule engines and machine-learning models. The output is a numeric risk score that the regulated entity then triages via human analysts.
Enforcement Failures
Inadequate transaction monitoring has been the central allegation in nearly every major crypto AML enforcement action of the last five years:
- Binance (DOJ/FinCEN, November 2023) — $4.3 billion in penalties; failure to report suspicious transactions including from Hamas-linked wallets and DPRK actors.
- Bittrex (FinCEN/OFAC, October 2022) — $29 million for failing to monitor transactions with users in sanctioned jurisdictions.
- BitMEX (FinCEN, August 2021) — $100 million for failing to implement an AML/KYC programme.
- Robinhood Crypto (NYDFS, August 2022) — $30 million for AML and transaction monitoring deficiencies.
- Justin Sun / Tron (SEC + multilateral, March 2026) — $4.68 billion combined penalty referencing systemic monitoring failures.
The pattern in every case: the regulator either showed the firm had no functioning monitoring, or had monitoring that flagged risks the firm ignored.
Calibration: The Hard Part
A working transaction monitoring programme is not just buying Chainalysis. Supervisors expect:
- Risk-based thresholds — Tuned to the institution's customer base, products, geographies. Calibrated as the business changes.
- Periodic model validation — Independent testing of detection effectiveness vs false positive volumes (the cost trade-off that decides programme economics).
- Documented escalation procedures — When an alert fires, what happens next, who decides, how long until a SAR is filed.
- Audit trail — Every alert disposition logged, with reasoning, retained per BSA record-keeping rules (5 years in the US).
- Periodic typology refresh — New FATF guidance, new sanctions designations, new attack patterns translated into new rules within a defined SLA.
Regulatory Framework
| Jurisdiction | Source | Key requirement | |--------------|--------|-----------------| | Global | FATF Recommendation 20 + Targeted Update on VAs (2025) | Risk-based monitoring of VA/VASP transactions | | US | BSA + FinCEN guidance + 31 CFR 1022 | SAR filing within 30 days of detection | | EU | AMLD6 + MiCA + AMLA (operational 2027) | Continuous monitoring; STR filing to national FIU | | UK | MLR 2017 (as amended) + FCA SYSC 6 | Transaction monitoring proportionate to AML risk | | Singapore | MAS Notice PSN02 | Real-time and post-event monitoring | | Hong Kong | SFC AMLO + HKMA AML Guideline | Ongoing customer due diligence + monitoring |
Related Terms
- AML — Anti-money laundering — the policy framework transaction monitoring serves
- KYC — Know your customer — the onboarding control that transaction monitoring complements
- KYT — Know your transaction — the on-chain layer specific to digital assets
- Travel Rule — Counterparty information requirement that feeds monitoring data
- OFAC — US sanctions authority whose SDN list every monitoring system screens against
- FATF — Sets the global standards transaction monitoring implements
- SAR — Suspicious Activity Report — the regulatory output transaction monitoring produces
- Sanctions Screening — The narrower screening function focused on listed entities
- Enhanced Due Diligence — The deeper investigation triggered when monitoring flags risk
- Risk-Based Approach — The FATF principle that drives how monitoring is calibrated
Browse all Regulation terms
Related Terms
Found this definition useful? Share it.