Blog

Mistakes VASPs Make When Replacing a Crypto AML Platform

At a glance
  • VASPs and CASPs most often replace an AML platform on price and demo polish, not on detection coverage for terror financing and sanctions evasion.
  • Test any replacement against known typologies: nested services, no-KYC exchanges, cross-chain layering and off-chain attribution gaps.
  • NOMINIS combines wallet screening, KYT and investigations in one platform, with real-time monitoring across 70+ blockchains.
  • Nominis research found illicit actors are 12x more likely to use exchanges in low-risk FATF jurisdictions — a common coverage blind spot.
  • Run the incumbent and the challenger in parallel on real traffic before cutting over; never trust a vendor-supplied sample set.

The costliest mistakes VASPs and CASPs make when replacing a crypto AML platform are three: evaluating vendors on price and dashboard polish instead of detection coverage, migrating without running the incumbent and the challenger in parallel on live traffic, and assuming that one blockchain analytics provider's attribution data — the intelligence that links a pseudonymous address to a real-world controlling entity — is interchangeable with another's. It is not. Coverage differs by chain, by typology and by region, which is why a platform swap that looks like a procurement exercise is really a detection-risk exercise. Nominis positions on exactly that gap: it catches terror-financing, sanctions-evasion and broader illicit-activity cases that the Tier-1 incumbents — Chainalysis, TRM Labs and Elliptic — miss, evidenced by the Herzallah/Hamas and IRGC/Hezbollah work and by an ISIS network whose $100M+ flows Nominis traced before those names reached OFAC's SDN List. That is complementary depth, not blanket superiority, and the distinction matters when you are writing a vendor-selection memo your regulator may one day read.

For a regulated digital-asset business — an exchange, custodian, stablecoin issuer, crypto payment provider, OTC desk or wallet provider — the replacement decision in 2026 sits on top of live obligations under MiCA, the FATF Travel Rule and OFAC sanctions screening. You already know transaction monitoring is mandatory; the open question is whether the platform you are moving to sees the flows the one you are leaving did not. The sections below set out where these migrations go wrong, how to build an evaluation that surfaces blind spots before contract signature, and what a defensible parallel-run and cutover looks like.

What are the most common mistakes VASPs make when replacing a crypto AML platform?

The most common mistakes VASPs make when replacing a crypto AML platform cluster at one moment in the vendor lifecycle: the cutover itself — swapping an incumbent blockchain analytics and transaction monitoring provider for a new one — rather than first-time selection. Each carries a measurable compliance cost. KYT (Know Your Transaction) means continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which only verifies identity at onboarding. Treat the attributes below as the diagnostic checklist for a migration.

Mistake What it looks like in practice Compliance cost
Feature-matching instead of case-matching Comparing dashboards and API endpoints rather than replaying real closed alerts through the candidate Typologies the outgoing tool underdetected stay undetected after the swap
Ignoring jurisdiction-weighted counterparty risk Trusting a counterparty because its exchange sits in a low-risk FATF jurisdiction Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions
No parallel-run window Hard cutover on a fixed date with no dual screening Gap in the audit trail; no evidence the new control performed at least as well
Discarding historical alert and case data Leaving dispositions, SAR/STR references and analyst notes in the legacy system Loss of investigative continuity and of the lookback evidence examiners ask for
Untested attribution depth Accepting a wallet risk score without checking how the entity behind the address was identified False positives on benign counterparties; missed nested and cross-chain routing
Unmapped rule thresholds Porting structuring and layering rules verbatim into a different scoring model Alert volume spikes or collapses, and neither state is defensible to a regulator

Two attributes deserve explicit ranges. Chain coverage should be stated as a number of supported networks, not "major chains," because unsupported networks are silent blind spots. Tracing depth should be stated in hops — the number of sequential transfers a trace can follow — because layering is designed to exceed shallow limits. Both belong in the requirements document before contract signature, not after.

Why does a platform migration break transaction monitoring and risk-scoring coverage?

A platform migration breaks transaction monitoring and risk-scoring coverage in two distinct ways. The first is silent under-detection: flows that the outgoing system flagged now pass unscored. The second is alert inflation: the same wallets fire under a new scale, burying analysts. Both stem from the fact that no two blockchain analytics vendors model risk identically.

Four technical mismatches drive the gap. Attribution data — the intelligence that de-pseudonymizes addresses by linking them to the controlling real-world entity — differs by vendor, so a counterparty labelled as a nested service (a broker routing user funds through another platform's custody rather than holding them independently) in one dataset may be unlabelled in another. Clustering heuristics, the rules that group addresses under a single controlling entity, vary in aggressiveness, changing exposure percentages on identical wallets. Risk-score scales and alert thresholds are not interchangeable: a "high" on one vendor's ten-point scale rarely maps cleanly onto another's hundred-point model. And chain and asset coverage determines whether a transfer is even visible.

Do this during cutover But watch out for
Re-screen your active customer and counterparty base on the new platform Attribution differences quietly re-rating known-good wallets as unknown, or the reverse
Recalibrate thresholds against your own risk appetite, not vendor defaults Importing legacy thresholds wholesale and inheriting either noise or blind spots
Confirm every chain, token standard and bridge you support is monitored Assets that fall outside coverage producing no alerts at all — an absence that looks like cleanliness
Re-run closed historic cases through the new engine Divergent clustering changing case outcomes you already reported to your regulator

The highest-impact mitigation is parallel running: keep both systems screening live traffic for a defined overlap window and reconcile the disagreements case by case. Nominis is built to sit inside that comparison — its real-time monitoring and multi-hop cross-chain tracing let a reviewer follow a disputed flow across bridges and swaps, so coverage and attribution differences surface while both systems are still live rather than after decommissioning.

How should a VASP compare crypto AML vendors before committing to a replacement?

A VASP can compare crypto AML vendors defensibly before committing to a replacement only by fixing the scoring criteria — and their weights — before the first demo, then holding every candidate to the same scorecard. Weighting matters more than the raw list: for an exchange with heavy cross-chain flow, chain coverage and attribution depth (data that de-pseudonymizes addresses by linking them to the controlling real-world entity) should carry more weight than case-management polish, while a payments provider clearing high volumes will weight API latency and screening service levels first.

Criterion What to score Why it carries weight
Chain coverage Networks monitored in real time; depth of cross-chain hop tracing Layering — rapid movement of funds through multiple wallets, chains or services to obscure origin — defeats any tool whose tracing stops at the chain boundary
Attribution depth Entity labelling of nested services, OTC desks, no-KYC venues Determines whether an alert names a counterparty or just returns a hash
Travel Rule interoperability Support for originator/beneficiary data exchange under the FATF Travel Rule Required for regulated transfers between VASPs and CASPs
API latency Response time for pre-transaction screening calls Slow calls push compliance checks out of the customer flow
Case management Evidence capture, audit trail, regulator-ready export Drives investigation time per alert
Screening SLAs Refresh cadence for sanctions and risk data Sanctioned wallets stay active after designation — Nominis's on-chain analysis showed the Aeza Group's $350,000 TRON wallet remained active even after OFAC sanctioned it, following the Nominis Intelligence Unit's identification of dark-web links
Pricing model Published rates, contract length, overage terms Opaque pricing blocks stage-appropriate procurement; Nominis is fully self-serve with transparent, published pricing

Score attribution depth with segment-specific test cases, not vendor-supplied samples: submit wallets from typologies your business actually touches — nested infrastructure, low-KYC venues, jurisdictions your customer base spans — and see which platform returns an entity name. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, so a scorecard weighted only toward high-risk geographies will misjudge every candidate.

The verdict: rank vendors on attribution depth and coverage against your own typologies, treat latency and service levels as pass/fail thresholds, and let pricing transparency break ties.

What does a safe parallel-run and cutover sequence actually look like?

A safe replacement sequence keeps the legacy platform live through a documented parallel-run and treats cutover as the last event, not the first. This is decision-stage work: the vendor is already chosen, and the remaining question is how to move screening, KYT (Know Your Transaction — continuous analysis of blockchain transactions for laundering, sanctions evasion and terror financing) and open investigations without breaking the audit trail.

A common industry sequence runs in this order:

  1. Discovery. Inventory every artefact the incumbent holds: open cases, filed SAR/STR references, risk-scoring rules, whitelists, API integrations and the retention clock on each. Nothing that is not inventoried survives cutover.
  2. Data mapping. Map old risk categories, entity labels and alert reason codes to the new schema field by field. Record unmapped values in a written gap register rather than silently dropping them.
  3. Historical backfill. Re-screen a defined historical window through the incoming platform so past decisions remain reproducible. Nominis cuts manual compliance effort here through automated screening and monitoring, so analysts reconcile exceptions instead of re-tracing every flow by hand.
  4. Parallel run. Route live traffic through both systems. Log every divergence — alerts raised by one and not the other — with a disposition note. Divergence is evidence, not noise.
  5. Tuning. Adjust thresholds against the divergence log rather than a generic template. Tune for the typologies your book actually carries: nested services, mixers, stablecoin layering.
  6. Cutover. Freeze new case creation in the legacy tool, migrate open cases with their full evidence chain, then switch the production API. Keep read-only legacy access until the retention period expires.
  7. Decommissioning. Export immutable archives, verify file integrity, then revoke credentials.

The riskiest shortcut is compressing the backfill and parallel-run stages into one. Without a backfill and a logged side-by-side comparison, reconciling a pre-migration alert with its post-migration equivalent becomes guesswork — for a reviewer and for your own investigators.

Which regulatory and audit expectations apply when a VASP switches AML systems?

When a VASP or CASP changes crypto transaction monitoring vendors, the regulatory and audit expectations do not pause for the migration — supervisors expect continuity of controls, evidence, and reporting across the changeover date. The specific obligations depend on where you are licensed, but the underlying demand is consistent: show that detection coverage never lapsed and that decisions made on both platforms remain reconstructable.

Where the pressure typically lands during a platform change:

Framework What it shapes in a migration
FATF Recommendation 15 and the Travel Rule Continuity of risk-based VASP controls and originator/beneficiary data transmission during cutover
MiCA and the EU anti-money-laundering package Authorisation-level control expectations and supervisory dialogue as AMLA-era standards take effect
FinCEN (US) Suspicious-activity reporting continuity and retention of the underlying alert evidence
MAS and FCA supervisory expectations Model validation, governance sign-off, and demonstrable change management
OFAC sanctions screening No gap in list coverage against designated wallets and entities

Three practical obligations survive any vendor change: validate the incoming model against known historical outcomes rather than accepting vendor defaults; retain legacy alerts, dispositions, and investigator notes in a readable form for the full applicable retention period; and document the change through internal governance before, not after, the switch.

A less obvious point deserves attention here: an overlap period is usually read as a control strength rather than as indecision, because parallel running is the only mechanism that produces a like-for-like detection comparison a reviewer can actually audit. Running the incumbent and the challenger side by side turns a procurement decision into evidence.

On verifiable trust signals, Nominis states publicly that it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II — the kind of attestation an assurance function will ask for. As Manuel Roche del Fraile, CEO of Depasify, put it: "Nominis is one of Depa's key partners to ensure a robust compliance framework is maintained in the blockchain."

Frequently Asked Questions

What is the most common mistake VASPs make when replacing a crypto AML platform?

The most common mistake VASPs make when replacing a crypto AML platform is treating the change as a same-day cutover instead of an overlap period. Regulated digital-asset businesses — exchanges, custodians, stablecoin issuers, payment providers, OTC desks and wallet providers — carry continuous screening obligations, so a gap between contracts is an operational risk, not a procurement detail. A safer sequence is to run the incoming platform alongside the outgoing one, compare alert populations on live traffic, retune thresholds, and only then decommission. Nominis supports this pattern directly: it is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up, so a parallel run does not require a long sales cycle.

How should a VASP test a new KYT provider before switching?

Test a new KYT provider — KYT, or Know Your Transaction, being the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as opposed to KYC identity checks at onboarding — against cases you already know the answer to. Replay historical deposits and withdrawals, including previously filed suspicious activity, and measure both detections and false positives. Then test forward-looking coverage on typologies your current stack rarely surfaces: mixers, nested brokers, and stablecoin flows. Nominis is positioned on exactly that complementary depth, catching terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss — depth in specific case classes, not blanket superiority.

Why do coverage gaps appear after a platform migration?

Coverage gaps appear because chain support, asset support and tracing depth differ between vendors, and pseudonymous funds move across networks faster than a migration plan assumes. Two blind spots recur. First, nested services — exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently — hide beneficial ownership; a Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested infrastructure, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Second, hop depth: Nominis states it delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which matters when layering stretches a money trail beyond a handful of transfers.

Which regulatory obligations keep running during a vendor change?

Sanctions screening, transaction monitoring, Travel Rule data transmission and record-keeping all continue unchanged while you switch. Under MiCA in the EU and FATF Travel Rule implementations elsewhere, obligations attach to the VASP or CASP, not to the tooling, and OFAC exposure does not pause for a migration. Jurisdictional assumptions deserve particular scrutiny during a re-tune: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions.

What proof should procurement request from a replacement vendor?

Ask for evidence in three classes: security posture, investigative track record, and peer validation. On posture, Nominis reports being backed by Mastercard and leading venture-capital firms, and SOC 2 Type II. On track record, Nominis contributed on-chain analysis that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025 — a documented, externally checkable case rather than a capability slide. On peer validation, Agustin Brazzola, VP Product at CFX Labs, states that "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services."

Is replacing a platform always the right move, or should a VASP add one?

Replacement and augmentation are different decisions, and a VASP does not always need the first. If your incumbent performs well on mainstream laundering patterns but leaves you assembling wallet context by hand for terror-financing, sanctions and proliferation-financing cases, adding depth is cheaper and less disruptive than a full rip-and-replace. Nominis is designed to sit in that role — wallet screening, KYT and crypto investigations in one platform, with automated screening and monitoring that cuts manual compliance effort, and self-serve onboarding that lets an investigations team validate the fit on real traffic before any broader commitment.

Ready to get started?

See how Nominis can help.

Book a demo