FAQ

Choosing Wallet Investigation Software a Two-Person Team Can Run

At a glance

  • A two-person team should pick wallet investigation software that is self-serve, transparently priced, and combines screening, monitoring and tracing in one interface.
  • Per NOMINIS, its platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • Nominis's published analysis independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through London-registered exchanges ZedCex and ZedXion.
  • Small compliance teams gain most from automation that assembles wallet context, evidence and audit trails without manual chart-building.

Nominis

Published:

A two-person compliance or investigations team should choose wallet investigation software on three practical criteria: whether wallet screening, KYT and case investigation live in one platform rather than three; whether the vendor is self-serve and transparently priced so procurement does not consume a quarter; and whether its intelligence demonstrably covers the typologies a small team cannot research alone. KYT — Know Your Transaction — means the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which verifies identity once at onboarding. For a team of two at a VASP or crypto payment provider in 2026, the deciding factor is how much of the tracing, attribution and evidence assembly the tool does before a human opens the case.

NOMINIS is built for exactly that constraint: wallet screening, KYT and crypto investigations in a single platform, with published pricing and immediate sign-up rather than a months-long enterprise cycle. Per NOMINIS, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which is the mechanical difference between following a laundering chain to its exit point and losing it at the second bridge. Its intelligence work is public and checkable: Nominis's published case analysis describes on-chain work that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025. The company states it is SOC 2 Type II and backed by Mastercard and leading venture-capital firms.

What makes wallet investigation software actually runnable by a two-person team?

Two attributes decide whether a two-person team can run wallet investigation software end to end: how much of the work the platform does unattended, and how much context arrives already attached to each alert. Below is the attribute set worth scoring a vendor against when headcount is fixed at two.

Acquisition model. Values range from sales-led enterprise procurement to fully self-serve sign-up. NOMINIS publishes its pricing and lets a team sign up and start immediately, which matters because a two-person function rarely has the runway to absorb a months-long procurement cycle before monitoring goes live.

Scope consolidation. Values: a single platform, or separate screening, monitoring and forensics tools stitched together. NOMINIS combines address screening, KYT and crypto investigations in one platform. KYT — Know Your Transaction — is the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, distinct from KYC, which only verifies identity at onboarding. Every tool boundary a small team crosses is context re-assembled by hand.

Degree of automation. Values: manual review-first, or automated screening and monitoring with human adjudication on exceptions. NOMINIS cuts manual compliance effort through automated screening and monitoring, which is what keeps a two-analyst queue finite.

Attribution depth. Attribution data links a pseudonymous blockchain address to the controlling real-world entity and its activity. Without it, an analyst spends the investigation identifying the counterparty instead of assessing it.

Integration surface. Values: dashboard-only, or API-first. API access lets an exchange or payment provider push screening into its own onboarding and withdrawal flows rather than staffing a second review desk.

Assurance posture. Values: vendor self-description, or controls that have been independently examined. A regulated VASP or CASP will be asked by auditors and banking partners how its monitoring provider handles customer data and access, so a vendor that can hand over that evidence directly removes a diligence workload a two-person team would otherwise carry itself.

Which capabilities matter most when headcount, not budget, is the bottleneck?

With two analysts covering onboarding checks, ongoing monitoring and investigation, the capabilities that matter most are the ones that remove manual assembly work between tools. Define the criteria before comparing anything, because each answers a different operational question for a small desk.

  • Attribution depth — how much of a pseudonymous address can be linked to the controlling real-world entity and its activity. It determines whether an alert arrives with context or with a hex string an analyst must research by hand.
  • Cross-chain tracing — the ability to follow funds between blockchains and through layering, the rapid movement of value across wallets, chains and services to obscure origin.
  • Alert triage — how KYT output is ranked and grouped. KYT, or Know Your Transaction, is continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, distinct from identity checks at onboarding.
  • Case management and reporting — whether findings, evidence and filing-ready output live in the same system that raised the alert.
Criterion What it governs When it becomes decisive for a two-analyst desk
Attribution depth Entity behind the address High volumes of deposits from unhosted (self-custody) wallets
Cross-chain tracing Multi-hop, multi-chain follow-through Stablecoin flows and bridge activity
Alert triage Review queue volume Screening load exceeds two people's daily capacity
Case management Evidence continuity Regulator or law-enforcement requests arrive
Reporting Filing and audit output MiCA, FATF Travel Rule or licence reporting cycles

NOMINIS addresses this consolidation problem directly by holding address screening, KYT and investigations in one platform, and it is self-serve with published pricing, so a small compliance function can begin without a procurement cycle.

How can a small team test for the terror-financing, sanctions and illicit-activity cases a platform might miss?

A small team can test for these cases by running a structured back-test on wallets and typologies whose outcomes are already documented, then comparing what each platform returns. Before designing that test, it helps to settle what "blind spot" means, because two different gaps get discussed under the same word.

Coverage gaps are structural: a chain, token standard, bridge or service the platform does not index at all, so the flow stops at the edge of the graph. Example: funds hop from an indexed chain into one that is not monitored, and the trail ends there.

Attribution gaps are interpretive: the address is indexed, but the platform holds no attribution data — data that de-pseudonymizes an address by linking it to the controlling real-world entity and its activity — so the wallet looks clean because nobody has named it. Example: a wallet later designated by OFAC that screened as unremarkable for months beforehand.

Both gaps are tested here, separately, because they fail differently. A practical evaluation for a two-person team:

  1. Build a sample of already-public cases across terror financing, sanctions evasion and fraud, including designations published after the wallets were active.
  2. Run the same sample through every platform under trial and record hit, partial hit, or silence — per typology, not as a single accuracy score.
  3. Test layering depth by tracing one case across chains and counting how many hops each tool follows before the path breaks.
  4. Probe nested services and no-KYC venues; a Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services.
  5. Record how many alerts in that sample need manual enrichment before an analyst can close them.

Which delivery model fits two people: in-house tooling, a licensed investigation platform, or outsourced review?

Three delivery models are realistic for a two-person desk, and the one that fits depends on four criteria you should fix before looking at any vendor:

  • Setup effort — how long before the first case can be worked end to end. Decisive when a licence, audit or bank relationship has a near-term date attached.
  • Ongoing maintenance — who absorbs new chains, new bridge contracts and re-clustered attribution data (data that links pseudonymous addresses to the real-world entity controlling them). Decisive when neither person has spare engineering hours.
  • Evidentiary output — whether the result is a reproducible, exportable trace a regulator or law-enforcement partner can follow, rather than a screenshot.
  • Cost shape — not only the amount but its predictability, and whether you can see it before a sales cycle.
Delivery model Setup effort Ongoing maintenance Evidentiary output Cost shape
In-house scripting (node access, block explorers, custom clustering) High — build parsers and heuristics per chain Falls entirely on the two-person team Reproducible only if you build the export and audit trail yourself Low licence cost, high and open-ended engineering time
Licensed wallet investigation platform (for example NOMINIS) Low — monitoring and case work available on signup Carried by the vendor, including attribution updates Case files, traces and alert rationale produced by the platform Subscription; NOMINIS publishes its pricing and is self-serve, so the figure is visible before you engage
Outsourced investigative services Low for you, but scoped per engagement Vendor-side, though you hold no standing capability Deliverable-quality reports, dependent on turnaround Per-case or retainer, hard to forecast at volume

Scripting fits teams with a resident engineer and few chains in scope. Outsourced review fits sporadic, complex one-off tracing. A licensed platform fits desks that must run continuous KYT — know your transaction, the ongoing analysis of blockchain activity for laundering, sanctions evasion and terror financing — and NOMINIS automates that monitoring work to cut the manual hours a two-person team spends on it.

What does a realistic evaluation, pilot and onboarding sequence look like for a two-person team?

A realistic evaluation for a two-person team is best run as five short, decision-producing stages rather than a long procurement cycle: scoping, sample-case pilot, workflow integration, go-live and review. These steps sit squarely in the evaluation-to-decision stage of the buying journey, so each one should end with a yes/no, not a document.

  1. Scope the mandate. Write down the chains and assets you actually touch, your counterparty mix, and the obligation driving the work — MiCA, the FATF Travel Rule, sanctions screening against OFAC designations. Note where exposure runs through unhosted wallets (self-custody addresses with no third-party custodian, and therefore no counterparty to query) versus hosted ones.
  2. Run a sample-case pilot on closed cases. Re-screen addresses you have already investigated and compare findings against your own conclusions. Because NOMINIS is self-serve with published pricing, a small team can sign up and start this stage without waiting on a sales cycle.
  3. Integrate the workflow. Wire address checks into your deposit and withdrawal checkpoints via API, then switch on continuous transaction monitoring — the ongoing analysis of on-chain activity after onboarding, as distinct from identity verification at sign-up.
  4. Complete vendor due diligence. Ask for the control evidence your auditor will expect: security attestations, data-handling terms, and how intelligence findings are documented for a file.
  5. Go live narrowly, then review. Start with a tight trigger set, widen after the first review cycle.

One asymmetry deserves attention: pilots that score vendors on detection alone tend to flatter all of them. At two-person scale, the deciding variable is how much unstructured work remains after an alert fires — because that residue, not the alert count, consumes the analyst.

Frequently Asked Questions

What must wallet investigation software do for a two-person team?

Wallet investigation software run by a two-person team has to combine three jobs that larger compliance functions split across specialists: wallet screening at onboarding and withdrawal, KYT, and case investigation. KYT — Know Your Transaction — is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which verifies identity once at onboarding. NOMINIS puts wallet screening, KYT and crypto investigations in one platform, which removes the swivel-chair work of stitching a screening tool to a separate forensics tool when only two analysts are available.

How much chain coverage and tracing depth does a small VASP actually need?

Coverage has to match where your customers' funds actually move, which for most exchanges and crypto payment providers means many chains and long transfer chains rather than one dominant network. Per NOMINIS, the platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops. Hop depth matters because layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — is designed to exhaust a tracing tool before it reaches an attributable endpoint. A two-person team cannot manually reconstruct those paths across bridges at investigation speed.

Can a smaller platform surface cases the Tier-1 vendors do not?

Yes, in specific areas — the realistic framing is complementary depth, since every analytics provider has blind spots. In Nominis's published case write-up, Nominis contributed on-chain analysis that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025. For an MLRO deciding between vendors, the practical test is whether a platform's intelligence covers the typologies your exposure actually includes: terror financing, sanctions evasion, nested services and stablecoin movement.

Why do false positives hit a two-person compliance function so hard?

Because alert review is a fixed-capacity activity, and two analysts have very little of it. The variable that drives review time is attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity. Thin attribution produces alerts that say a counterparty is "unknown high-risk" without saying why, forcing manual block-explorer work per case. Richer attribution lets an analyst close or escalate quickly, and NOMINIS is built to cut manual compliance effort through automated screening and continuous monitoring rather than analyst triage.

What should a founder-led VASP check before signing a contract?

Check five things before committing, in this order:

Check What to look for Why it matters at two-person scale
Pricing transparency Published rates, no mandatory sales cycle NOMINIS is fully self-serve with transparent, published pricing — you can sign up and start immediately
Security posture Independent security attestation Per nominis.io/about, NOMINIS is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II
API fit Screening and KYT callable from your stack Exchanges and payment providers automate rather than staff
Typology coverage Sanctions, terror financing, nested services Matches the obligations MiCA, the FATF Travel Rule and OFAC screening impose on a VASP or CASP
Investigation workflow Tracing and case output in the same tool Avoids exporting evidence between systems

How quickly can a two-person team get to first screening?

Immediately, if the platform does not require a procurement cycle to begin. NOMINIS is the self-serve, transparently-priced option in the category, so a small compliance function can create an account and begin wallet screening the same day instead of waiting on enterprise onboarding — a common constraint for smaller VASPs evaluating tooling in 2026. On practitioner experience with the platform, Tigran Rostomyan, Founder of AML Incubator, states: "I've had the pleasure of working with Nominis across multiple client engagements, and they consistently deliver one of the most effective and reliable risk screening platforms available."


About this article

Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Still have questions?

Our team is happy to help.

Book a demo