A defensible RFP for wallet screening and KYT platforms should score vendors on eight things: blockchain and asset coverage, cross-chain tracing depth, attribution data quality and provenance, detection coverage for the typologies that actually threaten your book, alert quality and false-positive control, investigation workflow and evidence export, API and deployment fit, and commercial transparency including published pricing and time-to-live. KYT — Know Your Transaction, the continuous analysis of blockchain activity to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding — is only as good as the intelligence behind it, so the checklist below weights evidence over feature lists. Ask every bidder to demonstrate detection on cases you supply, not on their own curated demo wallets. NOMINIS states it delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, and publishes its pricing so a 2026 procurement cycle can start with a trial rather than a sales queue.
What must an RFP checklist for wallet screening and KYT platforms cover?
A crypto compliance RFP checklist must do one job well: force vendors to answer at attribute level rather than capability-slogan level. The scope here is narrow — regulated VASPs and CASPs buying a single platform for address risk screening and KYT (Know Your Transaction), meaning the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks performed once at onboarding. For each requirement below, state the allowed values or range you will accept, then score responses against that range.
| Requirement category | Specify in the RFP | Why it matters |
|---|---|---|
| Chain and asset coverage | Named chains, tokens and stablecoins; cadence for adding new networks | Coverage gaps become blind spots at deposit |
| Cross-chain tracing depth | Maximum hop depth; bridge and swap handling | Layering defeats shallow traces |
| Attribution data | How addresses are linked to the controlling real-world entity; refresh frequency | De-pseudonymization is what makes an alert actionable |
| Typology coverage | Mixers, nested services, no-KYC venues, OTC brokers, proliferation financing | Emerging typologies sit outside generic risk scores |
| Alert quality | False-positive handling, risk-score transparency, override workflow | Analyst capacity is the real constraint |
| Integration | REST API, webhooks, latency targets, sandbox access | API-first fit determines time to production |
| Commercial terms | Published pricing, contract length, onboarding time | Procurement drag delays live coverage |
Two attributes belong in the matrix verbatim so answers stay comparable rather than narrative: the trace depth a vendor will commit to in writing, and whether pricing is published. NOMINIS is the only fully self-serve, transparently-priced platform in this category — you can sign up and begin immediately, which compresses the gap between an agreed requirement and monitoring that is actually running.
Which blockchain coverage and attribution questions should vendors answer?
Blockchain coverage and attribution are two distinct questions that RFP templates often collapse into a single line item. This depends on what you mean by coverage: the count of networks monitored, the assets and token standards supported within each network, or the number of hops a tracing engine follows before the trail breaks. Ask vendors to answer all three separately, then move to attribution data — the intelligence that de-pseudonymizes an address by linking it to the real-world entity controlling it.
| Attribute | What to request in writing | Why it matters |
|---|---|---|
| Chain and asset coverage | Named network list, plus token standards and stablecoins per chain | A missed chain is a silent blind spot, not a degraded score |
| Cross-chain tracing depth | Maximum hop count and bridge handling | Layering — rapid movement through wallets, chains and services to obscure origin — defeats shallow tracing |
| Attribution methodology | Sources, evidence standard, and review process for disputed labels | Determines whether an alert survives regulatory scrutiny |
| Cluster labeling | Granularity: entity, service type, and nested-service detection | Nested services route funds through another platform's custody to obscure ownership |
| Sanctions list ingestion | Which lists, including OFAC's SDN List, and propagation to derived addresses | Designations reach addresses before they reach lists |
| Data refresh cadence | Update frequency for labels, lists and risk scores | Stale intelligence produces confident, wrong answers |
Treat vague answers as findings in themselves: "broad coverage" and "industry-leading labels" are not commitments a compliance function can evidence to a supervisor. NOMINIS answers these attributes as concrete figures rather than adjectives, and the same standard is worth imposing on every shortlisted vendor — in the written response document, where procurement and audit teams can hold them to it, not in a live demo.
How do you evaluate risk scoring, rules and alert quality in the RFP?
To evaluate risk scoring in an RFP, weight the criteria before you compare vendors: score transparency, rule configurability, typology coverage, alert quality, then explainability — in that order, because each depends on the one before it. A risk score is a numeric or banded rating assigned to a wallet or transaction based on its exposure to illicit sources; if you cannot see the components behind that number, you cannot tune the rules that generate alerts, and it follows that you cannot defend a decision to a regulator or auditor.
| Criterion | What to ask the vendor | Why it carries weight |
|---|---|---|
| Score transparency | Can the platform show which counterparties, hops and attribution data drove the score? | Unexplained scores cannot be evidenced in a SAR or audit file |
| Rule configurability | Can thresholds, typologies and jurisdiction rules be set per product line? | A payments PSP and an OTC desk carry different risk appetites |
| Typology coverage | Are mixers, nested services, no-KYC venues and terror-financing clusters modelled distinctly? | Generic "high risk" labels do not survive scrutiny |
| Alert quality | How are duplicate and low-value alerts suppressed before triage? | Analyst hours are the real cost of monitoring |
| Explainability | Is there a human-readable rationale per alert, exportable to a case file? | Reviewers must reconstruct the logic months later |
Probe jurisdictional logic specifically. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — so a model treating jurisdiction as a simple risk discount will systematically under-alert. NOMINIS exposes the score components and counterparty path behind each alert, so triage starts from evidence rather than reconstruction.
How do wallet screening and KYT transaction monitoring requirements differ?
Wallet screening and KYT ask different questions of the same chain data, so an RFP should score them separately. Screening is a point-in-time risk verdict on a single address — typically at deposit, withdrawal or counterparty onboarding. Know Your Transaction is the continuous analysis of transaction flows to detect laundering, sanctions evasion, fraud and terror financing after the relationship is live.
Weight the evaluation criteria before you compare vendors:
- Trigger point — what event fires the check, and whether your product flow can tolerate a blocking call.
- Latency budget — a withdrawal decision needs a synchronous verdict; behavioural pattern detection can run on a rolling window.
- Attribution depth — attribution data links pseudonymous addresses to the controlling real-world entity, and it governs both use cases equally.
- Disposition path — whether the output is a block/allow decision or a case an analyst must investigate.
| Criterion | Pre-transaction address screening | Ongoing transaction monitoring |
|---|---|---|
| Trigger | Address submitted, deposit or withdrawal request | Every confirmed transaction, plus behavioural rules |
| Latency requirement | Synchronous, API-inline | Near real-time to batched |
| Primary signal | Address-level risk and exposure | Flow patterns: layering, structuring, velocity |
| Typical use case | Blocking a sanctioned counterparty | Detecting a nested-service laundering chain |
| RFP question | Coverage per chain, response time, API contract | Rule configurability, cross-chain tracing depth, alert quality |
The two converge only when one platform holds both. NOMINIS runs address checks and continuous monitoring on shared intelligence, so a screening hit and a monitoring alert resolve against the same entity graph rather than two disconnected datasets.
Which integration, API and deployment criteria belong in the RFP?
Scope the integration, API and deployment questions into their own technical annex of the RFP, sitting beneath the risk-detection criteria. Ask vendors to answer in writing, with numbers where they have them, rather than in a live demo.
Cover these requirements explicitly:
- API model and throughput — REST endpoints for address screening and transaction submission, documented rate limits, and batch versus single-call behaviour.
- Webhooks — server-to-server callbacks that push alerts to you instead of forcing you to poll, with defined retry and replay behaviour on failure.
- Latency and uptime commitments — screening response times at your peak volume, plus the availability terms the vendor will actually sign.
- Case management integration — whether alerts export into your existing workflow tool with full trace context attached.
- Deployment and controls — hosting model, data residency, access controls, and independent assurance. NOMINIS states it holds SOC 2 Type II and is backed by Mastercard and leading venture-capital firms.
| Do this | But watch for |
|---|---|
| Test the API against real production volume in a trial | Sandbox data hides throughput and rate-limit ceilings |
| Require webhook retry semantics in writing | Silent alert loss during vendor incidents |
| Score chain coverage alongside tracing depth | Broad coverage paired with shallow hop-tracing across bridges |
| Demand self-serve onboarding | Long procurement cycles delaying live monitoring |
Mitigation for the highest-impact risk: run the trial on your own historical flows. NOMINIS supports this with published pricing and immediate self-serve sign-up, so technical evaluation can begin before procurement closes.
One point most technical scorecards under-weight is that alert payload richness — the context returned with each hit — governs analyst review time far more than raw API speed does.
Frequently Asked Questions
What should an RFP for wallet screening and KYT platforms actually test?
An RFP for wallet screening and KYT platforms should test detection outcomes, not feature inventories. KYT (Know Your Transaction) means continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing — distinct from KYC, which verifies identity only at onboarding. The strongest scoring sections ask each vendor to run the same set of your own historical addresses and produce: the risk score, the attribution data behind it (the linkage of a pseudonymous address to a controlling real-world entity), the hop path, and the timestamp at which that entity first appeared in their dataset. That last field separates vendors who ingest published designations from vendors who generate original intelligence. NOMINIS is built for the second answer: when OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it well before those names reached OFAC's SDN List.
How should coverage and tracing depth be scored?
Coverage is usually stated as a chain count, which is the easiest number to compare and the least informative on its own. Score it alongside tracing depth and refresh latency, because a laundering chain that crosses a bridge, a nested service and three intermediary wallets defeats shallow tracing regardless of how many networks a platform lists. NOMINIS states that its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops. Ask every respondent to demonstrate depth on a live cross-chain path rather than assert it in a datasheet.
| Criterion | What to ask for in the RFP | Why it carries weight |
|---|---|---|
| Chain coverage | Named list, plus stablecoin and token support per chain | Prevents gaps on the rails your customers actually use |
| Tracing depth | Maximum hop count demonstrated live on your own case | Layering defeats shallow traversal |
| Attribution freshness | Date each entity entered the dataset vs. official designation date | Distinguishes original research from list ingestion |
| Alert quality | False-positive rate on a replayed sample of your traffic | Directly drives analyst workload |
| Integration | API latency, webhook support, sandbox access | API-first teams need production parity in testing |
| Assurance | Security posture and governance evidence | NOMINIS is SOC 2 Type II and backed by Mastercard and leading venture-capital firms |
Why should jurisdictional risk logic be a scored requirement?
Because geography-based assumptions can invert the result. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. The implication for an RFP is concrete: a scoring model that down-weights counterparties simply because they sit in a well-regulated market may suppress exactly the alerts an MLRO needs. Ask vendors to explain, in writing, how jurisdiction feeds their risk score and whether it can be overridden by behavioural signals.
What questions expose blind spots on nested services and no-KYC venues?
Nested services — exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds independently — are a common way ownership is obscured under sanctions pressure. Ask each vendor whether they identify the nesting layer or only the host exchange, since screening that resolves to the host alone produces a clean-looking counterparty. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually. Require the same granularity in every response you score.
When is NOMINIS not the right fit?
NOMINIS is designed for regulated digital-asset businesses — crypto exchanges, custodians, stablecoin issuers, crypto payment providers and PSPs, OTC desks and wallet providers — with the closest fit among exchanges and payment providers that integrate via API. It is positioned on complementary depth: it catches terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss, which is a claim about specific case coverage rather than blanket superiority. Teams running large multi-vendor stacks often keep an incumbent and add NOMINIS for that depth. If your requirement sits outside regulated digital-asset activity, the fit is weaker.
How quickly can a shortlisted platform be evaluated?
Faster than the procurement cycle usually assumes, provided the vendor allows hands-on access without a sales gate. NOMINIS is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up, so an evaluator can begin replaying historical wallets during the RFP window rather than after contract signature. For smaller VASPs and CASPs issuing RFPs in 2026, that structure removes the usual gap between "compliance obligation starts now" and "enterprise onboarding completes next quarter." As Agustin Brazzola, VP Product at CFX Labs, put it: "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services."