AML Transaction Monitoring for Digital Assets: What Institutional-Grade Controls Actually Look Like
A EUR 21.5 million fine (roughly USD 24.6 million). That is what the Central Bank of Ireland issued to Coinbase Europe in 2025 for deficiencies in AML transaction monitoring, specifically for failures between 2021 and 2025. The fine covered one of the largest regulated exchanges in Europe. The compliance failures were not exotic: insufficient monitoring controls, inadequate transaction screening, and documentation gaps that should have been caught years earlier.
This matters because it signals what regulators are looking for when they audit VASPs (Virtual Asset Service Providers) in 2025 and 2026. They are not just checking whether an AML programme exists. They are testing whether transaction monitoring controls are functioning in practice, producing defensible alerts, and generating audit trails that hold up to scrutiny.
For compliance teams at exchanges, custodians, and digital asset payment firms, this raises a practical question: what does institutional-grade AML transaction monitoring actually look like in a crypto environment?
This article addresses that question from the operational layer.
Why Crypto AML Monitoring Is Not the Same as Traditional Finance AML
Traditional AML transaction monitoring was built for fiat. It assumes centralised accounts, counterparty relationships that clear through correspondent banks, and transaction data that flows through known institutional channels.
Digital assets break each of those assumptions:
- Transactions settle in seconds or minutes. There is no correspondent bank window in which to intercept a flagged transfer. By the time a rule fires after settlement, the funds have moved.
- Pseudonymity means a wallet address does not inherently identify its controller. Blockchain data is fully transparent, but attributing addresses to real-world entities requires external intelligence.
- A single customer may interact with hundreds of external wallet addresses, across multiple blockchains, within a short window. The transaction graph is non-linear in ways that legacy monitoring rules cannot handle.
- Cross-chain movement: funds can hop from Bitcoin to Ethereum to Tron within minutes using bridges or exchanges, making end-to-end tracing difficult without multi-chain analytics.
These differences are not theoretical. The EBA’s (European Banking Authority) July 2025 Opinion on ML/TF risks identified transaction monitoring as one of the most common areas of inadequate AML control among assessed institutions, with crypto-specific gaps called out explicitly.
What is AML Transaction Monitoring for Crypto?
These typologies are what the three monitoring layers above are actually trying to catch. Effective AML transaction monitoring for digital assets is the continuous, systematic review of blockchain transactions and customer activity to detect patterns associated with money laundering, terrorist financing, sanctions evasion, and other financial crime.
It combines three integrated layers:
- On-chain monitoring: screening blockchain transactions in real time against known risk indicators, high-risk address clusters, sanctioned wallets, and behavioural typologies.
- Off-chain transaction monitoring: applying rules and anomaly detection to customer account activity, deposit and withdrawal patterns, and risk profile changes over time.
- Counterparty intelligence: using blockchain analytics to attribute external addresses to known entities, exchanges, darknet markets, mixers, or other VASPs.
In a well-designed system, these three layers work together. A customer’s on-chain transaction connects to a wallet cluster associated with a high-risk exchange. That signal feeds into the off-chain monitoring rule, which has already flagged unusual withdrawal velocity for that account. Together they generate an alert that warrants investigation. Separately, neither would necessarily have triggered a review.
Learn More – Understanding the Travel Rule in Digital Asset Transactions
Key Money Laundering Typologies in Crypto
Effective AML monitoring requires rules and models calibrated to the typologies that are actually used to launder funds through virtual assets. These differ meaningfully from traditional wire fraud patterns.
Layering through multiple wallet hops. Funds move through a chain of wallets, sometimes dozens, to obscure the trail between the source and the final destination. Each hop may involve a different blockchain or protocol.
Chain-hopping. Rapid conversion of funds from one blockchain to another using bridges or decentralised exchanges. This exploits gaps in multi-chain monitoring that focus on a single chain.
Structuring (smurfing). Splitting large amounts into multiple smaller transactions that individually fall below reporting thresholds. In crypto, this can happen across multiple wallets simultaneously and at high speed.
Mixer and tumbler use. Services that pool funds from multiple inputs to obscure the link between senders and recipients. FATF (the Financial Action Task Force, the global AML standard-setter) has identified mixer use as a high-risk typology requiring enhanced scrutiny.
Rapid exchange and cash-out. Funds move to an exchange immediately after reaching a wallet, converted to fiat, and withdrawn. The entire cycle can be completed within hours.
Use of peer-to-peer exchanges or OTC desks. Unregulated or lightly regulated P2P platforms and OTC desks can be used to convert funds without the KYC controls of licensed exchanges.
Monitoring systems that use only rules designed for traditional wire transfer fraud will miss most of these patterns. This is one of the core findings from recent regulatory reviews: the typologies matter, and crypto-specific rules have to be built deliberately.
The Risk-Based Approach: Why Not Every Transaction Gets the Same Scrutiny
FATF Recommendation 1 establishes that AML controls must be proportionate to risk. This applies to transaction monitoring: not every transaction should receive the same level of scrutiny.
A risk-based approach means:
- High-risk customer segments (PEPs or politically exposed persons, customers with prior suspicious activity flags, customers transacting with high-risk jurisdictions) receive more intensive monitoring rules and lower alert thresholds.
- Lower-risk segments (onboarded institutional clients with established transaction history and clean screening) receive proportionate controls that do not generate excessive false positives.
- Product and channel risk drives rule design: on-chain transfers to unhosted wallets, deposits from P2P exchanges, and large OTC transactions warrant different rules than standard exchange trading activity.
This is not just regulatory theory. A monitoring system that generates 500 alerts per analyst per day is not functional. Calibration toward the risk-based model, so analysts work through a manageable, meaningful caseload rather than noise, is what makes the system operationally sustainable and regulatorily defensible.
The customer risk rating framework is the input. If risk ratings are stale or inaccurate, monitoring rules will misfire. The two systems are not independent.
What is Know Your Transaction (KYT)?
Know Your Transaction is the crypto-specific application of ongoing transaction monitoring. Where KYC establishes who the customer is at onboarding, KYT applies continuous intelligence to what they are doing at the transaction level.
KYT uses blockchain analytics to assign risk scores to individual transactions and wallet interactions based on:
- Direct exposure to sanctioned addresses, known mixer outputs, or darknet market wallets.
- Indirect exposure through two or three hops: funds that passed through a high-risk entity before reaching the customer’s wallet, even if not directly connected.
- Transaction pattern analysis: velocity, timing, counterparty diversity, and chain-hopping behaviour.
The distinction between direct and indirect exposure matters for risk calibration. A transaction with direct exposure to a sanctioned address is a categorical compliance issue. Indirect exposure through multiple hops requires risk-based assessment, not automatic blocking.
Leading blockchain analytics providers used for KYT include Chainalysis, Elliptic, and TRM Labs. The choice of provider affects coverage (which blockchains and asset types are supported), the intelligence model (how risk scores are calculated), and integration depth with existing compliance workflows.
Real-Time vs Batch Monitoring: Why the Distinction Matters in Crypto
Traditional AML monitoring often runs in batch: transactions from the day are reviewed overnight, alerts generated for morning review. This model does not work for crypto.
Crypto transactions are irreversible. In many cases, they settle within seconds. A monitoring system that identifies a suspicious transaction 12 hours after settlement cannot intervene. It can only report after the fact.
This is why regulators expect real-time or near-real-time monitoring for high-risk crypto channels. The operational requirement is:
- Pre-transaction screening against sanctions lists and known high-risk wallets, before the transaction is signed.
- Real-time alert generation for transactions that breach risk thresholds, while the transaction can still be held or investigated.
- Post-settlement monitoring for pattern detection and typology-based alerts that require broader account-level analysis.
Many exchanges run both: real-time for on-chain activity, batch for behavioural account-level analysis. The pre-transaction screening layer is the one most often missing from early-stage compliance implementations, and the one regulators focus on first.
Sanctions Screening: The Parallel Obligation
Sanctions screening is distinct from AML monitoring but runs in parallel, and the integration matters.
Every outbound transfer above a risk threshold should be screened against OFAC (US), EU consolidated sanctions, UN sanctions lists, and relevant regional lists (MAS Targeted Financial Sanctions, VARA sanctions requirements) before execution, not after.
The 2025-2026 enforcement environment makes post-execution discovery a serious liability. A transfer to a sanctioned address that cleared pre-execution screening may still be defensible. A transfer that was never screened is not.
Wallet-level sanctions screening, rather than just customer-level OFAC checks at onboarding, is the operational standard expected in regulated markets in APAC and MENA.
Learn More – Pre-Trade vs Post-Trade Screening for Crypto Exchanges
Suspicious Activity Reporting: What Gets Filed and When
When monitoring controls identify activity that warrants further assessment and cannot be otherwise resolved, regulated VASPs have an obligation to file a Suspicious Activity Report (SAR) with the relevant financial intelligence unit.
The SAR filing obligation applies when:
- A transaction or pattern is inconsistent with the customer’s known profile and no adequate explanation has been obtained.
- A transaction involves a counterparty or wallet with a known or suspected connection to financial crime.
- A customer’s behaviour, taken in aggregate, suggests structuring or layering activity.
In practice, SAR quality is a common supervisory finding. Regulators are not only assessing whether SARs were filed, but whether they contain sufficient detail to be actionable, whether they were filed promptly, and whether the underlying monitoring system generated the alert in a reasonable time frame.
Filing a SAR after the fact, following a regulator inquiry, does not substitute for a monitoring system that should have caught the activity earlier.
What Regulators Find When They Audit Crypto AML
Based on publicly available enforcement actions and supervisory guidance from FATF, EBA, MAS, and VARA, the most consistent findings in crypto AML audits are:
- Monitoring rules not calibrated to crypto typologies. Rules designed for traditional wire transfers do not flag crypto-specific layering and chain-hopping patterns.
- Stale customer risk ratings. Risk ratings set at onboarding and never updated. A customer’s transaction profile evolves; monitoring rules that do not reflect that evolution produce both false positives and false negatives.
- Unhosted wallet exposure not risk-scored. Transactions to and from self-hosted wallets treated as a category, rather than individually risk-scored based on on-chain intelligence.
- No pre-transaction sanctions screening. Screening happens post-settlement, or only at the customer level at onboarding.
- Audit trail gaps. Alert generation, investigation steps, and closure decisions not documented in a way that is retrievable and defensible.
These are not novel findings. They appear in enforcement actions and supervisory guidance consistently across jurisdictions. The gap between what exchanges document in their AML policies and what their systems actually do in practice is where regulatory risk concentrates.
Building Toward Institutional-Grade AML Controls
The institutions building effective digital asset AML monitoring in 2026 share a few consistent characteristics:
They treat transaction monitoring as infrastructure, not a compliance add-on. The monitoring system is integrated with the wallet layer, the customer risk rating engine, and the sanctions screening tool, not operated as a separate manual process.
They calibrate rules to digital asset typologies, not just generic financial crime patterns. This requires dedicated crypto compliance expertise, not a generic AML team asked to also cover digital assets.
They run pre-transaction controls for high-risk flows. Not every transaction requires pre-execution screening, but those involving high-risk counterparty addresses, unhosted wallets above a threshold, or customers with elevated risk ratings should not go out without a real-time check.
They maintain defensible audit trails. Every alert, every investigation step, every closure decision is documented and retrievable. This is not expensive to implement, but it requires deliberate system design from the outset.
Shilpa Sharma
Global Compliance Manager
Shilpa is a Global Compliance Manager at Liminal, with over seven years of experience across fintech compliance, financial crime, and AML. Before Liminal, she managed surveillance and compliance functions at Groww and worked as a Senior AML Consultant at Protiviti. She holds a Certified Anti-Money Laundering Expert (CAME) credential and specializes in global regulatory strategy, risk assessment, and compliance process automation.