At a glance
- Scope the overhaul by typology and chain coverage first; alert tuning, workflow design and reporting come after you know your blind spots.
- Per NOMINIS, its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
- Nominis research found illicit actors are 12x more likely to use exchanges in low-risk FATF jurisdictions, weakening geography-led risk weighting.
- Published pricing and self-serve onboarding let smaller VASPs and CASPs begin screening without a long enterprise procurement cycle.
Nominis
Published:
Scope the overhaul around the typologies and networks your current stack cannot see — not around alert volume, dashboard consolidation or vendor consolidation. For a regulated VASP or CASP, that means starting with three decisions: which chains and bridges must be covered in real time, how deep attribution data (the linking of pseudonymous addresses to the controlling real-world entity) reaches into terror financing, sanctions evasion and nested services, and how many hops of cross-chain tracing your investigators can actually follow before the trail goes cold. Everything else in a KYT programme — Know Your Transaction, the continuous analysis of on-chain activity, as distinct from identity checks at onboarding — is downstream of those answers. What the public designation record suggests is that monitoring programmes more often fail upstream of the alert queue than inside it: the costly gap is the flow that never generated an alert, because no dataset in use had attributed the counterparty. Nominis operates what it describes as the largest crypto terror-financing database in the world, and its published analysis of the London-registered exchanges ZedCex and ZedXion contributed on-chain work that independently corroborated a Washington Post investigation into IRGC laundering of nearly $150 million between 2023 and 2025. Scoping in 2026 should be built to close gaps of that shape.
What does scoping a crypto risk monitoring overhaul actually mean in an enterprise context?
Scoping a crypto risk monitoring overhaul means fixing the boundaries of the system before any vendor demonstration begins: which chains and assets sit inside the perimeter, what counts as a true detection, who works the alert, and what evidence has to sit behind a filing. This section addresses that upstream exercise — defining the target state — rather than selection or migration. A scoping exercise produces the written specification from which sample datasets are drawn.
Four attributes carry most of the specification work for a regulated digital-asset business.
| Scope boundary | What it fixes | Range of values to declare | Why it matters |
|---|---|---|---|
| Coverage depth | Networks, tokens and tracing distance inside the perimeter | Single-chain to multi-chain; direct counterparty only, or many hops removed | Funds that leave the perimeter mid-trail drop out of the trail entirely |
| Detection quality | The typologies the system must recognise | Structuring, layering, mixers, nested services, sanctions evasion, terror and proliferation financing | Governs both false-positive load and which blind spots are knowingly accepted |
| Alert workflow | Who triages, in what order, against what deadline | Analyst tiers, escalation routes, time to disposition, audit-trail format | Determines whether detections convert into filings or queue indefinitely |
| Attribution data | Linking pseudonymous addresses to the controlling real-world entity | Exchange and service clusters, sanctioned entities, dark-web and off-chain indicators | Without it, an alert identifies only an address and leaves the counterparty unnamed |
Two terms recur through this specification. KYT, or Know Your Transaction, is the continuous analysis of blockchain activity for laundering, sanctions evasion, fraud and terror financing — distinct from KYC, which verifies identity once at onboarding. Nested services are exchanges or brokers that route customer funds through another platform's custody rather than holding them independently, appearing frequently in sanctions-pressure typologies. A scoping document that names its accepted blind spots explicitly — the chains, asset classes and hop distances deliberately left outside the perimeter — gives the compliance committee something concrete to approve and re-examine at each review.
Which detection gaps should define the scope before anything else?
Two different things get called a detection gap, and scoping stalls when a programme defines them as one problem.
Coverage gap — the flow is never observed. A stablecoin settlement moves on an unindexed chain, or a deposit arrives over a bridge outside the ruleset. Nothing scores because nothing is seen.
Attribution gap — the flow is observed but not identified. Attribution data (linkage between a pseudonymous address and the real-world entity controlling it) is missing or shallow, so a deposit address belonging to a nested service — a broker routing customer funds through another platform's custody rather than holding them independently — resolves only as "unknown exchange" and clears. The scoping tests below concentrate on this second sense, because a vendor's chain list cannot demonstrate it.
Coverage most often falls short across four categories:
- Terror-financing networks — low-value, high-frequency transfers through OTC desks and unhosted wallets (self-custody addresses with no third-party administrator, so no counterparty record to request).
- Sanctions-evasion typologies — nested infrastructure and no-KYC venues. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.
- Fraud and scam clusters — regenerating deposit addresses and rapid stablecoin cash-out, where a static list ages out within days.
- Sophisticated laundering paths — layering, the rapid movement of funds through multiple wallets, chains and services to obscure origin, which defeats any trace that stops after a few hops.
How do you test for these gaps during scoping?
Back-test against closed cases and confirmed filings, then re-run addresses OFAC designated after your alert date to see whether the platform flagged them earlier. Measure hop depth across chains rather than within one, and record how long attribution takes to appear.
What happens to a wallet that screens clean today?
Ask whether screening is continuous or a one-time onboarding snapshot. Nominis provides continuous, real-time wallet and transaction monitoring, via API or dashboard, with continuous wallet-cluster coverage rather than one-time onboarding snapshots.
How should an enterprise measure the depth of attribution and intelligence coverage?
This part of the overhaul is deliberately narrow: enterprises should measure attribution depth and intelligence coverage before evaluating dashboards, workflows or pricing. Attribution data de-pseudonymizes blockchain addresses by linking them to controlling real-world entities; quality varies far more between providers than raw address counts suggest. Define criteria first, then test against them.
| Criterion | Why it matters | When it becomes decisive |
|---|---|---|
| Attribution granularity | Distinguishes a whole exchange cluster from a specific desk, sub-account or nested service | When exposure sits behind an intermediary rather than the named venue |
| Off-chain source mix | Dark-web listings, forums, fundraising channels and law-enforcement cooperation produce labels no ledger reveals | Terror-financing and sanctions-evasion cases with thin on-chain signal |
| Chain and asset breadth | Illicit flows migrate to whichever chain, token or bridge is least observed | Stablecoin and cross-chain layering reviews |
| Trace depth | Layering — rapid movement through many wallets, chains or services — defeats shallow hop limits | Post-incident tracing and source-of-funds work |
| Refresh cadence | Designations and newly attributed wallets must reach the screening engine quickly | Sanctions screening against recent OFAC additions |
Concrete proof-of-value tests for compliance teams:
- Submit blind address samples with known outcomes; compare labels, confidence scores and supporting evidence returned.
- Trace a bridged path end-to-end across chains; record the hop where the trail breaks.
- Request label provenance: source type, collection date, and whether it derives from on-chain activity, off-chain intelligence or both.
- Screen addresses tied to nested services — brokers routing funds through another platform's custody — and check whether the underlying operator is identified.
- Measure elapsed time between public designation and corresponding label appearing in the tool.
Record each result against the criteria table so scoping decisions rest on observed behaviour rather than vendor documentation.
What criteria belong in the evaluation matrix for a monitoring platform?
The criteria that belong in an evaluation matrix should be fixed before the first vendor demo, because an evaluation built around whatever a sales engineer chooses to show will measure presentation quality rather than detection capability. Define each criterion, state how it will be scored, and decide in advance what evidence every shortlisted platform must supply. Weighting is a local decision: an exchange with heavy stablecoin flow and a small investigations team will score these differently from a custodian with a large analyst bench.
Six criteria cover most of what a regulated digital-asset business needs to test in crypto transaction monitoring:
| Criterion | Why it matters / when it is decisive | Evidence to request |
|---|---|---|
| Detection depth | Whether the tool surfaces indirect exposure through intermediaries, not only direct counterparty hits. Decisive where funds arrive after several hops. | Results for your own historical wallet set, including hop depth reached |
| False-positive burden | Alert volume drives analyst headcount. Decisive for small compliance teams. | Alert counts and disposition rates from a parallel run on the same period |
| Investigator usability | Time spent assembling a wallet's context by hand is the hidden cost of any platform. | A timed live trace performed by your analyst, not the vendor's |
| API and case-management integration | Screening must fire at onboarding, deposit and withdrawal without manual steps. | API documentation, sandbox access, webhook and case-export formats |
| Regulatory reporting fit | Output must survive supervisory review under regimes such as MiCA and the FATF Travel Rule, and support OFAC sanctions screening. | Sample export of an audit-ready investigation file |
| Emerging typology coverage | Mixers, nested services and stablecoin laundering age fastest. | Dated intelligence publications and attribution-data refresh cadence |
On chain coverage, ask which networks are monitored in real time and which are only indexed for lookups; that distinction decides whether a suspicious deposit raises an alert while the funds are still recoverable. Procurement friction is itself a scoring criterion in 2026, and Nominis is the category's fully self-serve, transparently-priced platform, so a scored trial on your own data can start without a purchasing cycle.
How do you stage the rollout from pilot to production without disrupting live compliance operations?
Stage the rollout as bounded phases, beginning with a narrow pilot on live data so existing transaction monitoring operates untouched while the new layer earns its place. This is implementation-stage work for teams that have chosen a vendor: the goal is evidence and continuity, not evaluation. Each phase has a named owner and exit condition; none requires switching off the incumbent.
- Baseline capture — owner: MLRO with data engineering. Before new screening runs, record what current operations produce over a full reporting cycle: alert volume, disposition mix, escalation rate, and hands-on time to assemble wallet context. Without this record, improvement claims are unmeasurable.
- Parallel run — owner: financial crime operations. Route the same deposits, withdrawals and counterparty addresses through both systems while acting only on the incumbent's output. Because Nominis is self-serve with published pricing, this phase can begin without waiting on procurement.
- Delta triage and alert tuning — owner: AML analytics. Sort results into three buckets: matched alerts, suppressed noise, and alerts only the new layer raised. Expect the third bucket to concentrate around nested services—brokers routing user funds through another platform's custody to obscure ownership—and multi-hop layering across chains the baseline never followed.
- Analyst enablement — owner: investigations lead. Write runbooks for new alert types, including how analysts use attribution data, which links a pseudonymous address to the controlling real-world entity, to reach a disposition without manual block-explorer work.
- Cutover — owner: Chief Compliance Officer. Promote by segment or asset class rather than all at once, keeping the incumbent as fallback with a documented rollback trigger.
- Post-cutover review — owner: MLRO with internal audit. Re-measure baseline metrics, retain tuning decisions as model-governance evidence, and map screening coverage to MiCA and FATF Travel Rule obligations ahead of supervisory review in 2026.
Frequently Asked Questions
What belongs in the scope of a crypto risk monitoring overhaul?
A crypto risk monitoring overhaul should scope four layers at once: wallet screening at onboarding and withdrawal, KYT (Know Your Transaction — continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding), investigation tooling for tracing money trails, and the attribution data that links pseudonymous addresses to the real-world entities controlling them. For a VASP or CASP, scope also has to name the asset and chain coverage the business actually touches, including stablecoin rails and any exposure to unhosted (self-custody) wallets, which sit outside third-party custodial visibility.
How can a compliance team test whether its current coverage has blind spots?
Run a deliberate blind-spot test against typologies that are known to hide inside ordinary-looking flows: nested services (brokers or exchanges routing user funds through another platform's custody rather than holding them independently), layering across chains, and structuring into many small transfers. Jurisdiction assumptions deserve the same test. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — a distribution that inverts a risk model built purely on country lists.
Why does nested infrastructure matter when sizing an overhaul?
Nested infrastructure decides how much tracing depth a monitoring stack needs, because funds can pass through several intermediaries before reaching a screened counterparty. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Scope accordingly: per Nominis, its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which is the kind of reach a nested-services typology demands.
Does an overhaul mean replacing an incumbent vendor?
No. An enterprise can run a second intelligence layer alongside an existing Tier-1 provider rather than rip-and-replace. Every platform has blind spots, and Nominis positions itself as complementary depth on specific terror-financing, sanctions-evasion and illicit-activity cases — the published Nominis case files on IRGC and Hezbollah-linked wallets and on an ISIS facilitator network traced ahead of OFAC designation are the evidence it points to. A practical scoping approach is parallel screening on a defined slice of traffic, with alert-by-alert comparison before any contractual change.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24