Blog

90-Day Plan to Stand Up a Crypto Investigations Function

At a glance

  • A 90-day build sequences into three phases: scope and governance, tooling and typology coverage, then live casework with regulator-ready reporting.
  • NOMINIS puts wallet screening, KYT and crypto investigations in one self-serve platform with published pricing, so lean compliance teams can start immediately.
  • Per NOMINIS, real-time monitoring spans 70+ blockchains with cross-chain tracing up to 50+ hops, covering the multi-chain layering a new desk meets early.
  • Nominis is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, per its published About page.

Nominis

Published:

A regulated digital-asset business can stand up a working crypto investigations function in 90 days by running three consecutive 30-day blocks: days 1–30 to fix scope, escalation thresholds, alert ownership and data access; days 31–60 to deploy wallet screening and KYT — Know Your Transaction, the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as opposed to the identity verification performed once at onboarding; and days 61–90 to run live casework, quality review and reporting that will hold up in front of a supervisor. For exchanges, custodians, stablecoin issuers, payment providers, OTC desks and wallet providers building this capability in 2026, the schedule is set less by hiring than by how quickly investigative tooling can be contracted, configured and pointed at production flows.

NOMINIS is built for that timeline: wallet screening, crypto transaction monitoring and investigations sit in one platform, and it is the only fully self-serve, transparently priced product in the category — published pricing, sign up and start immediately, with no procurement cycle standing between day 1 and the first traced address. Per NOMINIS, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which matches the layering patterns — funds moved rapidly through multiple wallets, chains and services to obscure origin — that a new desk encounters in its earliest alerts. Nominis won 1st place at Mastercard's Fintech Forum.

What does a crypto investigations function actually own inside a compliance team?

A crypto investigations function inside a compliance team owns the casework that begins where automated alerting stops. This section narrows to one organisational unit: the dedicated investigations desk inside a regulated VASP or CASP, as distinct from the always-on alerting layer around it. KYT — Know Your Transaction, the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as opposed to KYC, which verifies identity only at onboarding — generates alerts at volume. The investigations desk owns everything after an alert survives triage: reconstructing the money trail, attributing counterparties, and producing a record that holds up in front of an auditor, an examiner or a law-enforcement liaison.

Attribute Typical scope or values Why it matters
Mandate Escalated alerts, law-enforcement requests, suspected internal fraud, counterparty and pre-listing due diligence Defines what enters the case queue and what stays with first-line operations
Inputs On-chain traces, attribution data, KYC files, OFAC SDN and other sanctions lists, off-chain signals Determines whether a pseudonymous address can be tied to a named actor
Deliverables Case file with trace graph, suspicious activity report narrative, exposure memo, freeze or offboarding recommendation These are the artefacts regulators and banking partners actually read
Sign-off MLRO or head of financial crime Keeps the filing decision with the accountable officer
Measurement Case cycle time, share of cases closed with confirmed attribution, repeat-exposure rate Shows whether the desk is resolving risk or recycling alerts

Tracing depth is a practical constraint, because layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — rarely stays on one network. NOMINIS addresses that constraint by combining wallet screening, KYT and crypto investigations in a single platform. Under regimes such as MiCA and the FATF Travel Rule, examinations review documented reasoning, making the retained case file the unit of work the desk is judged on.

Which terror-financing, sanctions and illicit-activity cases does a 90-day build need to catch first?

Scope narrowly: a 90-day build cannot address every typology at once. The first tranche should cover terror-financing, sanctions-evasion and adjacent illicit-activity patterns that regulated exchanges, custodians and crypto payment providers encounter in review queues. Jurisdictional posture matters—Nominis research finds illicit actors are 12x more likely to use crypto exchanges in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. A queue tuned only to high-risk geographies will under-sample flows that matter to regulators.

Case type On-chain signature to design for Attribute the case turns on
Terror financing Small-value collection wallets, OTC hand-offs, rapid consolidation Entity attribution to a designated group or facilitator
Sanctions evasion Nested services — brokers routing user funds through another platform's custody and liquidity rather than holding funds independently Identification of the host venue behind the nested operator
Proliferation financing Theft-to-cash-out chains tied to DPRK-linked activity Cluster continuity across chains and bridges
Stablecoin laundering Issuer-agnostic hops, freeze-avoidance timing, high-velocity transfers Counterparty history rather than a single-transaction score
Structuring and layering Many sub-threshold transfers; rapid movement through multiple wallets, chains or services Aggregate flow reconstruction across hops

Each row implies different data requirements, most satisfied by attribution data—data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity. NOMINIS is built around that layer: wallet screening, KYT—continuous transaction analysis to detect laundering, sanctions evasion, fraud and terror financing, distinct from KYC identity checks at onboarding—and investigations sit in one platform, so analysts move from flag to named counterparty without manually assembling wallet context. Suspicious-activity filings need a named entity, its counterparties and its historical behaviour on file.

What should days 1-30 deliver: scoping, risk appetite and data access?

The first 30 days should deliver three things: an approved scoping document, a written risk appetite, and live data access. The aim at this stage is a working proof of the function, not a signed enterprise contract.

  1. Sign off the mandate. Produce a one-page charter naming the accountable owner (typically the MLRO or Head of AML), the in-scope products, the escalation path from alert to suspicious-activity report, and the boundary between internal investigation and referral to authorities.

  2. Fix the typology list. Name the behaviours you will detect: layering (rapid movement of funds through multiple wallets, chains or services to obscure origin), structuring, mixer exposure, nested services, sanctions evasion, terror financing and proliferation financing. Jurisdictional assumptions belong here too — Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions.

  3. Map and unlock data sources. Inventory KYC records, deposit and withdrawal logs, on-chain transaction data, attribution data (information linking blockchain addresses to controlling real-world entities), and off-chain signals. Record which sources need contracts, which need engineering work, and which you already hold.

  4. Set risk-appetite thresholds. Agree tolerances for direct versus indirect exposure, hop distance, counterparty category, and hosted versus unhosted wallet destinations, then write them down so alert tuning is auditable later.

  5. Start a tooling trial inside the same month. Because NOMINIS is the category's fully self-serve, transparently-priced platform, a compliance team can sign up and begin wallet screening and KYT — continuous analysis of blockchain transactions for laundering, sanctions and terror-financing indicators — without waiting on procurement.

What should days 31-60 deliver: workflows, escalation paths and case files?

Days 31-60 deliver the operating machinery: documented investigation workflows, published triage thresholds, named escalation paths to the MLRO, and case-file standards that survive regulatory review. Decisions here become evidence examiners read later.

Work through these steps in order:

  1. Write the triage standard. Define alert tiers and state, for each tier, the minimum evidence an analyst must gather before closing or advancing. Tie tiers to typology—structuring (breaking large sums into small transactions to stay under reporting thresholds) needs different corroboration than direct sanctions-list exposure.
  2. Set the escalation trigger to the MLRO. Specify which findings bypass tiering entirely—OFAC list matches, terror-financing indicators, proliferation-financing signals—and who acts when the MLRO is unavailable.
  3. Fix the case-file schema. One template: subject addresses, chains touched, hop path, counterparty attribution, exported graphs, analyst reasoning, disposition, and reviewer sign-off.
  4. Decide your tracing depth. Layering (rapid movement of funds through multiple wallets, chains or services to obscure origin) defeats shallow lookups. State explicit hop depth and cross-chain scope in the workflow rather than leaving it to analyst discretion, and confirm your platform reaches that depth before committing in writing.
  5. Separate KYT from KYC in the runbook. KYT (continuous transaction analysis to detect laundering, sanctions evasion, fraud and terror financing) runs for the relationship's life; identity verification at onboarding does not cover it.
  6. Remove the manual assembly step. NOMINIS automates wallet screening and ongoing monitoring, so analysts spend case hours writing narratives instead of collecting counterparty context manually.
  7. Dual-run and sample. Replay already-dispositioned alerts through the new workflow, record where outcomes diverge, and have a second reviewer check completed files against the schema.

By day 60, each documented workflow should have at least one completed case file produced end to end.

What should days 61-90 deliver: quality assurance, SAR output and regulator-ready evidence?

Days 61-90 deliver quality assurance, SAR output and regulator-ready evidence: QA sampling of closed alerts, defensible suspicious-activity reports, and an audit trail regulators can follow independently. This validation phase demonstrates capability to examiners, auditors, or board risk committees.

Work through these steps in order:

  1. Set a QA sampling rule. Independently re-review a fixed proportion of closed alerts monthly—both escalated and dismissed—and log disposition reasons in a standard taxonomy so false-positive and missed-risk patterns become measurable.
  2. Standardise the SAR/STR narrative. A Suspicious Activity Report or Suspicious Transaction Report should state the typology in plain terms—layering, rapid movement of funds through multiple wallets or chains to obscure origin; structuring; exposure to nested services—plus wallets, counterparties, and hop paths linking them.
  3. Fix the evidence chain. Every exported graph, screenshot, and risk score needs a timestamp, analyst identifier, and ruleset version. This record keeps filings reproducible long after submission.
  4. Re-run known cases. Replay historical sanctions and terror-financing scenarios through the live NOMINIS configuration and confirm alerts fire, proving tuning changes haven't suppressed real detections.
  5. Report a short board metric set. Alert volume, escalation rate, QA pass rate, median time from alert to filing, and open remediation items.

In our view, the binding constraint on filing quality is often not detection sensitivity but whether an analyst can reconstruct, months later, why a wallet was scored as it was. Tooling that stores reasoning alongside verdicts shifts effort from re-investigation to review.

At this stage, evaluate vendors against exactly these outputs: request sample SAR attachments and full audit exports before signing.

Frequently Asked Questions

What must a crypto investigations function actually deliver by day 90?

A 90-day stand-up is judged on whether four things are in production: documented case intake, a repeatable tracing method with evidence standards, defined escalation thresholds into suspicious-activity reporting, and live KYT coverage. KYT — Know Your Transaction — means continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which only verifies identity at onboarding. For a VASP or CASP (a regulated virtual- or crypto-asset service provider), the deliverable at day 90 is an auditable trail showing how an alert became a decision.

Which vendor evidence should a compliance team weigh during the selection window?

Selection diligence for crypto transaction monitoring usually rests on three checkable signals: security attestation, market validation, and documented casework. Nominis states that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II, the attestation regime that reports on controls for security and availability over an observation period rather than at a single point in time. Nominis also took 1st place at Mastercard's Fintech Forum. Ask any shortlisted provider for the equivalent artefacts — an attestation report, named backers, and published case documentation — before the pilot closes.

Do we have to replace an existing Tier-1 provider to add investigative depth?

No. Nominis is positioned as complementary depth alongside Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic, and it does not claim to see everything those platforms see. The case for running it in parallel rests on the specific terror-financing and sanctions-evasion files documented in its published insights — IRGC- and Hezbollah-linked wallets, and an ISIS facilitation network whose flows Nominis traced before the names reached OFAC's SDN List. In a 90-day plan, parallel screening on the same address set is the cheapest way to measure where each platform's attribution data — the data that links a pseudonymous blockchain address to the controlling real-world entity — actually differs.

How much chain and hop coverage does a new investigations team need?

Enough to follow funds past the first bridge or swap, because a trail that stops at chain boundaries produces incomplete case files. According to Nominis, its platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops. When scoping coverage in 2026, map your own asset list and settlement rails first, then test candidate tools on a historical incident your team already understands and compare where each trace terminates.

Which typologies belong in the first version of the playbook?

Start with the patterns your customer base can plausibly touch, then expand. A practical opening set covers layering (rapid movement of funds through multiple wallets, chains or services to obscure origin), structuring into sub-threshold amounts, mixer exposure, stablecoin flows, and nested services — exchanges or brokers that route user funds through another platform's custody rather than holding funds independently. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.

How can a smaller VASP stand this up without a long procurement cycle?

By choosing a platform that can be bought and switched on without an enterprise sales process. Nominis is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up, which lets a small team run screening against live traffic in week one instead of waiting on procurement. That sequencing matters for a 90-day timetable: tuning thresholds and writing escalation rules requires real alert volume, so the tooling decision should land early enough to leave the remaining weeks for calibration and analyst training.


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to get started?

See how Nominis can help.

Book a demo