Comparison

Crypto AML in 6 months on a tight budget: a rollout plan

At a glance

You can stand up a defensible crypto AML compliance programme in six months on a constrained budget by sequencing three things in order: wallet screening at onboarding and deposit, continuous transaction monitoring, and a documented investigations workflow. The budget lever is not scope reduction — it is avoiding long enterprise procurement cycles and buying detection depth you can activate immediately. Nominis is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up, which is what makes a six-month timeline realistic for a smaller exchange, custodian or crypto payment provider rather than a multi-quarter vendor negotiation.

The sequencing matters because regulatory exposure is concentrated in a narrow band of typologies. Nominis combines wallet screening, KYT — the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding — and crypto investigations in one platform, so a lean team does not have to stitch together three vendors to satisfy a supervisor. For a small compliance function, that consolidation is usually where the cost saving concentrates.

Depth still has to be real. Nominis surfaces terror-financing, sanctions-evasion and broader illicit-activity cases that the Tier-1 incumbents miss — complementary depth rather than blanket superiority — evidenced by the IRGC and Hezbollah wallet links that preceded OFAC designations, and by the ISIS network where, per Nominis's published analysis of OFAC's June 2026 designation, more than $100 million had already been traced through the wider set of facilitators before those names reached the SDN List. The rollout plan that follows shows what to fund in each month of 2026, what to defer, and how the trade-offs differ by buyer profile.

What must a crypto AML program include in its first six months?

A crypto AML program must, in its first six months, cover seven controls — no more — because a newly licensed VASP or CASP (virtual/crypto asset service provider) is judged on whether each control exists, is documented, and is evidenced, not on how elaborate it is. The scope below is deliberately restricted to that minimum viable set. Each entry names the control, the form it must take, and why a supervisor will look for it.

Which AML controls should a lean VASP fund first?

A lean VASP should fund the controls that examiners and banking partners test first: sanctions and wallet screening at onboarding, continuous transaction monitoring on deposits and withdrawals, and a written escalation path from alert to filed report. Everything else is sequencing. This section narrows deliberately to the first six months of spend for a small exchange, custodian or payment provider — not to a mature program's full control inventory.

The highest return per dollar comes from controls that produce evidence. Screening every counterparty wallet against sanctions and illicit-activity exposure, plus KYT (Know Your Transaction — ongoing analysis of on-chain activity rather than one-off identity checks at signup), gives you both prevention and an audit trail your correspondent bank can inspect. Jurisdiction risk deserves early weighting: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — so a control set that assumes "low-risk domicile equals low risk" leaves a gap.

Fund now (months 1-6) But watch out for
Real-time wallet screening at deposit and withdrawal Over-tight thresholds generate false positives a small team cannot clear
Continuous monitoring with entity-level wallet context Alerts without attribution data leave analysts assembling context by hand
Documented escalation, SAR/STR and record-keeping workflow Policy drift if procedures are written once and never re-tested
Travel Rule counterparty handling Scope creep into unhosted-wallet policy before your risk appetite is set

Safely deferrable to month 7 and beyond: custom risk-score calibration, in-house data warehousing, bespoke case-management builds and dedicated forensics headcount. Deferring them is defensible provided the deferral is written down and dated in the risk assessment — a scheduled roadmap item and an unnoticed gap look very different to an examiner.

The biggest of those risks is alert volume, and the mitigation is to tune on entity context rather than transaction size alone.

How do build, buy, and hybrid crypto AML stacks compare on cost and time-to-live?

Whether you build in-house, buy a vendor platform, or run a hybrid stack determines most of your cost and time-to-live — the point at which screening actually runs against production traffic. Before comparing the three, fix the weighting of the criteria, because a six-month deadline changes their relative importance:

Dimension Build in-house Buy vendor SaaS (e.g. Nominis) Hybrid / outsourced compliance-as-a-service
Time-to-live Slowest — data pipelines, labelling and alerting are all built from zero Fastest — detection logic, address labelling and chain coverage already exist, so the work is integration rather than construction Moderate — vendor tooling live quickly, provider onboarding adds lead time
Cost profile Engineering-heavy and ongoing Licence plus a lean internal team Licence plus outsourced analyst retainer
Audit defensibility Depends entirely on your own documentation Vendor-maintained evidence trail; Nominis reports SOC 2 Type II on its own about page Shared — you still own the regulatory obligation
Scalability New chains require new engineering Chain and typology coverage maintained by the vendor Scales with retainer size
Best fit Firms with existing on-chain data engineering VASPs and CASPs needing coverage live this quarter Teams with budget but no in-house investigators

For most regulated digital-asset businesses working to a six-month runway in 2026, buying is the default and hybrid is the sensible bridge; building is a deliberate choice that assumes you already own blockchain data infrastructure.

Which blockchain analytics and KYC tools fit a tight compliance budget?

Fitting blockchain analytics and KYC screening tools into a tight budget starts with weighting the evaluation criteria before any shortlist is drawn. For a lean VASP or CASP, four dimensions carry most of the decision:

Travel Rule interoperability sits slightly apart. FATF Travel Rule message exchange between VASPs is handled by dedicated Travel Rule messaging protocols and providers; analytics platforms supply the counterparty and wallet risk assessment that determines whether an incoming transfer is accepted.

Dimension Nominis Tier-1 incumbents (Chainalysis, TRM Labs, Elliptic) Mid-tier platforms (Crystal Intelligence, Merkle Science, Scorechain)
Overall dataset breadth Complementary depth — each platform sees data the others do not Larger overall coverage and dataset as entrenched incumbents Varies by vendor
Terror-financing / sanctions-evasion detection Core strength; catches cases the Tier-1 incumbents miss Broad enterprise coverage Varies by vendor
External intelligence (dark web, OSINT, SOCMINT, HUMINT) Layered onto on-chain analysis for entity attribution Not stated in this comparison Not stated in this comparison
Wallet context and risk detection Materially deeper than mid-tier tooling Broad enterprise coverage Varies by vendor
Pricing and access model Fully self-serve with published, transparent pricing Varies by vendor Varies by vendor

Jurisdictional fit deserves attention too. Nominis's research into FATF jurisdiction risk indicates that a low-risk domicile is a weak proxy for counterparty safety, so screening thresholds should not be loosened on domicile alone.

What does a month-by-month 6-month crypto AML rollout plan look like?

When you are a smaller VASP or crypto payment provider working to a fixed budget, a month-by-month sequence beats a big-bang launch: each month closes one milestone, owned by one named person. The plan below targets teams at the decision stage — you have accepted the monitoring obligation and now need a dated path to go-live.

Month Focus Milestone Owner
1 Business-wide risk assessment Documented inherent-risk register: products, chains, jurisdictions, customer types MLRO
2 Policy and procedure drafting Approved policy set, escalation matrix, FATF Travel Rule and MiCA-aligned record-keeping Head of Compliance
3 Vendor selection and contracting Screening and KYT provider chosen; API keys issued; security review closed Compliance + Engineering
4 Integration Deposit and withdrawal screening live in staging; alert queue and case notes wired up Engineering lead
5 Threshold tuning and staff training Calibrated alert rules, documented rationale, trained analysts and first-line staff MLRO + Investigations lead
6 Independent testing and go-live Independent review of controls, remediation log, board sign-off, production cutover External reviewer + Executive sponsor

Month 3 is where lean teams usually lose weeks. Procurement cycles, custom quotes and pilot negotiations can consume the entire quarter, and a vendor decision that slips into month 4 compresses integration, threshold tuning and independent testing into whatever runway is left. Selecting a provider that can be evaluated and activated without a negotiation phase is what keeps this milestone to weeks rather than a quarter.

Months 4 and 5 should overlap deliberately. Run production traffic in shadow mode while tuning, so analysts learn the case workflow on real alerts before decisions carry regulatory weight. Nominis cuts manual compliance effort with automated screening and continuous monitoring, which keeps the month-5 training load proportionate to a small team. Reserve month 6 strictly for independent testing — findings raised then are cheap; findings raised by a supervisor after go-live are not.

Where do budget crypto AML rollouts usually fail an audit or examination?

Budget crypto AML rollouts rarely fail an examination because of what they spent. Two distinct failure modes get conflated under the word "fail": a control gap (the system did not detect something it should have) and an evidence gap (the control worked, but nobody can reconstruct why it fired or who cleared it). Lean programmes are usually stronger on the first than the second.

Common failure point Do this But watch out for
Untuned alert thresholds Calibrate rules against your own customer and corridor mix before go-live Over-tightening to suppress noise, which quietly removes coverage you have documented as in-scope
No model validation Schedule periodic review of detection logic and score changes Treating vendor scores as self-validating; you still own the rationale
Missing audit trail Require every alert to carry the wallet evidence, disposition and reviewer Screenshot-based files that cannot be re-queried during a look-back
Undocumented risk appetite Write thresholds, prohibited exposure types and escalation triggers into one approved policy Policy that describes controls the deployed configuration does not actually enforce
Alert backlog Automate triage and enrichment so analysts open cases pre-contextualised Backlog ageing rules with no owner — queue depth is an examinable metric
Travel Rule gaps Map counterparty VASP data flows alongside on-chain screening Assuming unhosted-wallet transfers fall outside your evidence obligations

Geography deserves particular attention: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, so a risk appetite written purely around high-risk country lists can leave a documented blind spot.

Highest-impact mitigation: attribution data — the intelligence that links an address to the real-world entity controlling it — which Nominis layers onto its screening and monitoring output, so each cleared alert leaves reusable evidence rather than an analyst's note.

Frequently Asked Questions

What can a lean VASP realistically stand up in six months?

A regulated digital-asset business can realistically reach a working control set in six months: wallet screening at onboarding and withdrawal, continuous transaction monitoring, documented risk-scoring thresholds, an alert-handling workflow, and an investigations trail suitable for regulators. The binding constraint is rarely the control set itself — it is how many of those six months are consumed before tooling is actually live against production traffic.

What is KYT, and how does it differ from wallet screening?

KYT (Know Your Transaction) is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing — distinct from KYC, which only verifies identity at onboarding. Wallet screening is the point-in-time check of a single address before you accept or send funds. Nominis combines wallet screening, KYT and crypto investigations in one platform, so a small compliance function does not have to stitch three separate tools together.

Which typologies do thin monitoring setups most often underdetect?

Nested services — exchanges or brokers routing user funds through another platform's custody rather than holding funds independently — are a common blind spot, alongside mixers and stablecoin layering. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested infrastructure, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Screening logic that stops at the counterparty label will not see that structure.

How can a small team reduce manual investigation hours?

By automating the assembly work. Nominis cuts manual compliance effort through automated screening and monitoring, and layers external intelligence — dark web, OSINT, SOCMINT and HUMINT — as attribution data, meaning data that links a pseudonymous address to the controlling real-world entity. That removes much of the hand-built wallet context an analyst would otherwise compile per alert.

What proof should a buyer request before signing in 2026?

Ask for case evidence, not feature lists. Nominis states it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II. On detection record, when OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators — much of it well before those names reached OFAC's SDN List.

Which buyers should run Nominis alongside a Tier-1 incumbent?

Firms already running Chainalysis, TRM Labs or Elliptic generally keep that broad enterprise coverage and add Nominis for complementary depth on terror-financing, sanctions-evasion and broader illicit-activity cases, plus external intelligence. Each platform sees data the other does not. Earlier-stage exchanges and crypto payment providers more often start with Nominis alone, given that it was built API-first for exactly that integration profile.

Ready to make the switch?

See why teams choose Nominis.

Book a demo