Comparison

Building Crypto SAR and STR Filings on Defensible On-Chain Evidence

At a glance

A defensible crypto SAR (Suspicious Activity Report) or STR (Suspicious Transaction Report) rests on three things a filing officer must be able to reproduce months later: the transaction path itself, the attribution data that links pseudonymous addresses to a controlling real-world entity, and a written narrative that explains why the pattern is suspicious. Most compliance teams already own a Tier-1 blockchain analytics platform for exactly this job — Chainalysis, TRM Labs or Elliptic are typically bought for broad chain coverage, sanctions list screening, and the entrenched dataset that regulators and law-enforcement counterparts recognise. That purchase is sound, and this article does not argue otherwise. What it examines is the narrower question that decides filing quality: when a flagged wallet sits behind nested services, a no-KYC exchange, or a stablecoin layering chain, does your evidence pack answer "who controls this address and how do you know?" — or does it stop at a score?

That gap is where NOMINIS positions itself. NOMINIS is an intelligence layer for fighting crypto crime that brings wallet screening, KYT (Know Your Transaction — the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding) and crypto investigations into one platform. It is built to catch terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents miss — complementary depth rather than blanket superiority, since each platform sees data the others do not. NOMINIS provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, and layers external intelligence — dark web, OSINT, SOCMINT and HUMINT — to attribute wallets to entities. Throughout 2026, that kind of pre-designation attribution is what turns a suspicion into a filing a regulator can follow.

What makes on-chain evidence defensible in a crypto SAR or STR filing?

What makes on-chain evidence defensible is narrower than what makes it interesting: this section covers only the evidence package attached to a filed suspicious activity report or suspicious transaction report, not open investigative work. A reviewer at a financial intelligence unit reads the narrative once, so each blockchain assertion must be independently reproducible from the ledger and clearly separated from inference.

The attributes below are the ones examiners and FIU analysts typically test:

How do SAR and STR obligations compare across FinCEN, FINTRAC, the UK NCA, and AUSTRAC?

Suspicious activity reporting obligations differ far more in narrative expectation than in name: the United States and the United Kingdom file a SAR (Suspicious Activity Report), Canada files an STR (Suspicious Transaction Report), and Australia files a suspicious matter report. Before comparing regimes, agree on the four criteria that actually change how a filing is built:

Regime Report name Trigger basis Narrative emphasis Retention posture
FinCEN (US) SAR Suspicion-based, with prescribed dollar thresholds for some institution types Detailed who/what/when/where/why narrative expected Supporting documentation held for a defined statutory period
FINTRAC (Canada) Suspicious Transaction Report Reasonable grounds to suspect; no minimum amount Structured fields plus a narrative explaining the grounds Records must be retrievable on request
UK NCA Suspicious Activity Report Knowledge or suspicion; includes consent (DAML) requests Glossary codes plus concise reasons for suspicion Records kept for the prescribed period after relationship end
AUSTRAC (Australia) Suspicious matter report Suspicion on reasonable grounds Grounds-for-suspicion narrative, plus travel-rule data where applicable Statutory retention of transaction and identification records

The verdict: the trigger and the deadline shift by jurisdiction, but the evidentiary core does not. Because NOMINIS combines wallet screening, KYT and investigations in one platform, the wallet context assembled for a Canadian filing supports a FinCEN or AUSTRAC narrative without a second manual trace.

Which on-chain evidence types carry the most weight in a suspicious activity narrative?

Not all on-chain evidence carries equal weight in a suspicious activity narrative, so the practical question is which types a reviewer — an FIU analyst, an auditor, or a court — can independently verify. Before comparing categories, fix the evaluation criteria: verifiability (can a third party reproduce the finding from public ledger data?), attribution strength (does it link a pseudonymous address to a controlling real-world entity?), typology fit (does it evidence a recognised laundering pattern such as layering — rapid movement through multiple wallets or chains to obscure origin?), and durability (does it survive re-checking months later?). Weight verifiability highest; an unreproducible assertion weakens the whole filing.

Evidence type What it establishes Verifiability Main limitation
Transaction hashes Immutable record of value transfer, timestamp, amount Highest — anyone can re-check on a block explorer Proves movement, not intent or ownership
Address clusters Multiple addresses under common control High, if the heuristic is documented Clustering logic must be disclosed and defensible
Mixer / tumbler exposure Deliberate obfuscation of fund origin High for direct exposure; weaker at distance Indirect hops need proportionate weighting
Cross-chain bridge hops Continuity of the money trail across networks Moderate — depends on tracing depth Manual reconstruction is slow and error-prone
Sanctions screening hits Direct nexus to a designated party under OFAC or equivalent High, list-anchored List timing lags real-world activity

Attribution data — information that de-pseudonymizes an address by linking it to the controlling real-world entity — is what converts the middle categories from suggestive into narrative-grade. NOMINIS layers external intelligence, including dark web, OSINT, SOCMINT and HUMINT sourcing, onto ledger analysis precisely so that a cluster or bridge hop arrives with a named counterparty attached rather than as an unexplained pattern for the reviewer to interpret alone.

How does blockchain analytics attribution compare with raw ledger data as evidence?

Blockchain analytics attribution and raw ledger data serve two different evidentiary roles in a suspicious activity report, and confusing them is what makes filings fragile. Raw ledger records — transaction hashes, input and output addresses, amounts, block timestamps — are verifiable facts any reviewer can reproduce from a public node. Attribution data, meaning data that de-pseudonymizes addresses by linking them to the controlling real-world entity, is an analytical conclusion drawn from clustering heuristics, exchange deposit patterns and external intelligence. It carries a confidence level, not a certainty.

Before comparing the two, fix the criteria that matter to a reviewing regulator or prosecutor: reproducibility (can a third party re-derive it?), provenance (what source or method produced it?), stability over time (does the claim change when the vendor updates its dataset?), and investigative value (does it identify a counterparty or only a string?). Weight reproducibility highest for facts you assert, and investigative value highest for context you offer as analysis.

Criterion Raw ledger records Vendor cluster attribution
Reproducibility Full — verifiable on any node Partial — depends on vendor methodology
Provenance The chain itself Heuristics plus intelligence sources
Stability Immutable Can be revised as labels improve
Investigative value Low without context High — names the counterparty

The practical rule: state ledger facts as facts, and label attributed entities as assessments with their basis. NOMINIS supports that separation by pairing on-chain tracing with external intelligence — dark web, OSINT, SOCMINT and HUMINT — so the attribution behind a flagged wallet has a stated source rather than an unexplained score.

What steps turn a blockchain alert into a filed SAR or STR narrative?

The steps that turn a blockchain alert into a filed suspicious activity or transaction report are sequential, and each one has to leave an audit trail a regulator or law-enforcement partner can follow. Teams at the decision stage — already obligated to monitor, now choosing how to operationalise it — need a workflow that survives review, not just a dashboard.

  1. Triage the alert. Confirm what fired: sanctions exposure, structuring (breaking large sums into many small transfers to stay under reporting thresholds), or layering across services. Record the rule, threshold and timestamp.
  2. Trace the funds. Follow value backwards to source and forwards to destination across chains. NOMINIS performs cross-chain tracing inside a single investigation view, so the money trail does not break where funds hop through a bridge, a nested service, or a stablecoin swap before cash-out.
  3. Attribute the counterparties. Attach attribution data — information linking a pseudonymous address to the controlling real-world entity — so the narrative names services and clusters, not just hashes.
  4. Preserve the evidence. Capture transaction hashes, cluster identifiers, exports of the graph, and the version of the risk data used at the time of the decision. Immutability of the ledger is not the same as immutability of your analysis.
  5. Draft the narrative. State who, what, when, where and why suspicious, in plain language, with each assertion tied to a preserved artefact.
  6. File and retain. Submit to the relevant financial intelligence unit within the deadline, then archive the full case file — alerts, analyst notes, disposition rationale — for the retention period your licence requires.

Which evidence errors make a crypto SAR narrative indefensible on review?

Evidence errors in crypto suspicious activity filings cluster in three places, and the severity depends on what you mean by "indefensible." To an examiner, a filing is weak when the narrative cannot be reconstructed from the record; to law enforcement, it is weak when the on-chain trail breaks before it reaches an identifiable entity; to your own second line, it is weak when nobody can say who observed what, and when.

The recurring failure modes are documentation gaps (screenshots without block heights or timestamps), attribution overreach (labelling an address as an exchange or a sanctioned party without stating the basis for that identification), and chain-of-custody drift (exported data re-keyed by hand between the analytics tool and the finished narrative).

Do this But watch out for
Trace funds across chains to the destination service Truncating the trail before it reaches an identifiable counterparty, leaving the report unresolved
Attach entity attribution — data linking an address to the controlling real-world party Presenting inferred attribution as fact; NOMINIS distinguishes on-chain heuristics from external intelligence signals
Preserve raw exports alongside the written narrative Version drift when cluster labels are updated upstream after filing

Across published designation cases, the pattern points less to missing data than to analyst inference recorded in the same register as ledger fact — a distinction reviewers can test, and one that quietly decides whether a report survives scrutiny. The highest-impact mitigation is a single evidence field per assertion naming its origin: NOMINIS records dark web, OSINT and other external intelligence sources beside the on-chain path, so reviewers see the provenance of every identification.

Frequently Asked Questions

What makes on-chain evidence defensible in a crypto SAR or STR filing?

A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) is defensible when every assertion in the narrative can be reproduced by a reviewer from primary blockchain data. That means recording transaction hashes, addresses, timestamps, asset and amount, the direction of flow, and the risk logic that triggered the alert — plus the version and date of the screening result, since risk scores change as new intelligence lands. NOMINIS builds wallet screening, KYT and investigations in one platform so the alert, the trace and the exported evidence come from a single audited record rather than three disconnected tools.

Which artifacts should an MLRO attach to a filing?

Investigators generally attach a compact, reviewable package rather than a raw data dump:

How do you keep a cross-chain money trail auditable?

Layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — breaks audit trails when each bridge hop is reconstructed by hand in a spreadsheet. The fix is to trace and export in one continuous record so hop ordering, bridge contracts and destination addresses survive into the filing. By NOMINIS's own account, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which keeps the chain of reasoning intact across bridges instead of ending at the first chain boundary.

Why do some terror-financing and sanctions cases never become filings?

Because the counterparty looks unremarkable until external context is added. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — so jurisdictional risk alone can point the wrong way. NOMINIS is positioned on exactly these cases: when OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it before the names reached OFAC's SDN List.

When should a compliance team stay on its current incumbent platform?

Staying put is the right call in several common situations. If your enterprise contract with Chainalysis, TRM Labs or Elliptic is mid-term, your case management and API integrations are deeply wired in, and your filings are dominated by mainstream fraud and market-abuse typologies, a migration adds cost without adding detection. Those platforms bring broad enterprise coverage and incumbency, and each platform sees some data the others do not. Many teams therefore run NOMINIS alongside an incumbent as a second, complementary intelligence layer for terror-financing and sanctions-evasion exposure.

How should a smaller VASP or CASP start without a long procurement cycle?

Smaller regulated digital-asset businesses — exchanges, custodians, stablecoin issuers, payment providers, OTC desks and wallet providers — often stall because enterprise crypto AML compliance procurement runs longer than their regulatory clock. NOMINIS is fully self-serve with published pricing, so a team can sign up and begin screening immediately, then extend into API-based KYT (continuous analysis of blockchain transactions, as distinct from KYC identity checks at onboarding). For assurance review in 2026, Nominis states it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II.

Ready to make the switch?

See why teams choose Nominis.

Book a demo