SOC 2 Type II tells you that an independent auditor tested a vendor's security, availability and confidentiality controls across an observation window — typically several months — and formed an opinion on whether those controls operated effectively throughout, rather than simply existing on the day of inspection. For a crypto AML vendor, that matters concretely: you are handing over customer wallet addresses, transaction histories and alert dispositions, and a Type II report is the closest thing to evidence that this data is handled under governed access, change management and incident response. What SOC 2 Type II does not tell you is anything about detection quality. It is an assurance report about how a company runs its systems, not a benchmark of whether the platform catches sanctions evasion, terror financing or proliferation financing — financial support for the proliferation of weapons of mass destruction, including missile programmes — that other tools miss.
That gap is the practical problem for an MLRO or Head of Compliance running a procurement cycle in 2026. Two vendors can both present a clean Type II report and still differ enormously in what their attribution data — the intelligence that links a pseudonymous blockchain address to a controlling real-world entity — actually surfaces. NOMINIS holds SOC 2 Type II and is backed by Mastercard and leading venture-capital firms, per its own published company information; separately, and on a different axis of evidence, NOMINIS publicly warned of new North Korean proliferation-financing tactics months before OFAC's 4 November 2025 sanctions against DPRK-linked networks, and its monitoring detected the wallet connections behind the February 2025 Bybit attack. The first fact answers "can I trust them with my data." The second answers "will they find what I am obligated to find." A rigorous vendor assessment needs both questions asked, scored and documented — and this article walks through how to read the attestation, where its scope ends, and what evidence fills the remainder.
What does a SOC 2 Type II report actually prove about a crypto AML vendor?
A SOC 2 Type II report proves that a crypto compliance vendor's stated controls actually operated effectively across a defined observation period — not merely that they were designed on paper. SOC 2 is an attestation standard maintained by the AICPA (American Institute of Certified Public Accountants), under which an independent auditor tests a service organization's controls against the Trust Services Criteria. The distinction that matters for a compliance buyer is simple: a Type I report opines on control design at a single point in time, while a Type II report opines on operating effectiveness over a window of time.
Applied narrowly to blockchain analytics and transaction monitoring vendors, the attributes worth reading in the report are these:
| Attribute | What it can contain | Why it matters to an MLRO |
|---|---|---|
| Report type | Type I (design) or Type II (operating effectiveness) | Only Type II evidences that controls held up in live operation |
| Trust Services Criteria in scope | Security (mandatory), plus optionally Availability, Confidentiality, Processing Integrity, Privacy | Confidentiality and Availability speak directly to customer wallet data and monitoring uptime |
| Observation period | A stated date range, not a single date | A short or stale window weakens the assurance you can rely on |
| Auditor opinion | Unqualified, qualified, adverse, or disclaimer | A qualified opinion signals exceptions the auditor could not clear |
| Exceptions and management response | Listed control deviations with remediation notes | Shows how the vendor handles failure, not just success |
| Complementary user entity controls | Obligations pushed back to you | Defines what your own team must operate for the assurance to hold |
For NOMINIS, as for any provider in this category, the attestation speaks to the control environment surrounding the platform — how customer and wallet data is governed, accessed and protected — rather than to the investigative depth of what the platform actually detects on-chain. Those are two separate questions, and only one of them is answered by an auditor's opinion.
Which Trust Services Criteria matter most for transaction monitoring and blockchain analytics?
Of the five Trust Services Criteria a SOC 2 report can cover — security, availability, processing integrity, confidentiality and privacy — only security is mandatory; the other four are elected by the vendor, and which ones a blockchain analytics provider elects tells you where it has accepted independent scrutiny. Narrowing to the digital-asset compliance use case, the criteria below carry the most weight for KYT (know your transaction), the continuous analysis of blockchain transactions used to detect laundering, sanctions evasion and terror financing.
| Criterion | Elected status | Controls to look for | Why it matters for screening and monitoring |
|---|---|---|---|
| Security (Common Criteria) | Always in scope | Access control, change management, encryption in transit and at rest, incident response, vendor management | Wallet screening queries reveal your customers and your investigative leads; a breach exposes both |
| Availability | Optional | Monitoring, capacity planning, backup and recovery, documented uptime commitments | Real-time screening sits in the deposit and withdrawal path — outages become blocked payments or unscreened flows |
| Processing integrity | Optional | Input validation, pipeline reconciliation, error handling, completeness checks | Risk scores and tracing results must be complete and accurate, or alerts and Travel Rule decisions rest on partial data |
| Confidentiality | Optional | Data classification, retention and disposal, segregation of tenant data | Case files, subject names and report-relevant material must not leak between customers |
| Privacy | Optional | Notice, consent, data-subject rights, minimisation aligned to GDPR-style regimes | Transaction analysis enriches on-chain data with personal identifiers captured at onboarding |
NOMINIS states that it runs real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops — the kind of always-on, multi-chain pipeline that makes availability and processing integrity worth reading as closely as security. Beyond the criteria list, examine three things in the report itself: the system description's boundary, the subservice organisations carved out, and the exceptions recorded in the auditor's testing tables. Those pages, not the badge, show what was actually examined.
How do you read the scope, observation window, and exceptions inside the report?
This depends on what you mean by scope — and reading a SOC 2 Type II report well starts with separating scope from the observation window the auditor actually tested. Two distinct meanings travel under the same word.
Criteria scope is which Trust Services Criteria the audit covered. Security (the common criteria) is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional additions. A report covering Security alone is a valid SOC 2 Type II, but it says nothing about uptime commitments for a screening API.
System scope is which services, environments and entities the system description covers. A vendor may operate several components — for a platform like NOMINIS, that means wallet screening, KYT (Know Your Transaction — continuous analysis of blockchain transactions for laundering, sanctions evasion and terror financing) and investigations tooling. Confirm the description names the components you will actually consume, not a narrower corporate subset.
Then work through four remaining elements:
| Element | What to check | Why it matters |
|---|---|---|
| Observation window | Start and end dates of the tested period | A Type II tests operating effectiveness over time; a short window shows less operating history |
| Subservice organizations | Carve-out (excluded, with expectations listed) vs inclusive (tested) | Cloud and data infrastructure risk may sit outside the report |
| Complementary user entity controls | Controls the report assumes you operate | Unimplemented CUECs shift residual risk back to your firm |
| Exceptions | Deviations noted in the testing results | Frequency, criticality and management response matter more than raw count |
Exceptions are not automatic disqualifiers. A qualified opinion with a documented, remediated control failure is often more informative than a clean report over a brief window. Read the auditor's opinion paragraph first, then the testing tables — that sequence answers most vendor-risk questions in one pass.
What does SOC 2 Type II not tell you about sanctions screening and detection quality?
SOC 2 Type II tells you that a vendor's controls operated effectively over a review period; it does not tell you whether that vendor's screening actually catches the right wallets. The attestation examines security, availability, confidentiality and processing integrity — not detection quality. It follows that an audit-clean vendor can still miss a sanctioned counterparty, because nothing in the audit scope tests attribution data (the linkage of a pseudonymous address to the real-world entity controlling it), sanctions and PEP list refresh latency, false-positive rates, or model governance — the documented process for how risk-scoring logic is changed, tested and approved.
The gap is concrete. After the Nominis Intelligence Unit identified dark-web (Blacksprut) links, OFAC sanctioned the Aeza Group's TRON wallet, and Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning. List-matching alone would not have surfaced that continued activity; behavioural monitoring did.
| Do this | But watch out for |
|---|---|
| Request the SOC 2 Type II report and read the exceptions, not just the logo | It attests to control operation, not detection accuracy or coverage |
| Test attribution depth on known cases before signing | Vendors may demo curated wallets; insist on your own address set |
| Ask how sanctions and PEP lists are ingested and how fast | Fresh lists still miss unlisted facilitators and successor wallets |
| Ask for model-governance documentation on scoring changes | Undocumented tuning shifts your alert volume without an audit trail |
| Confirm licensing and registration obligations sit with you, the regulated VASP or CASP | Vendor certification never transfers your regulatory accountability |
The highest-impact mitigation: pair the attestation with a live detection test. NOMINIS supports this directly — its published pricing and self-serve sign-up let a compliance team screen real wallets against real-time monitoring across 70+ blockchains before committing to a contract.
How does SOC 2 Type II compare with SOC 2 Type I, SOC 1, ISO 27001, and ISO 27701?
Before comparing the reports, fix the criteria — a SOC 2 Type II attestation earns its weight only against a defined yardstick. Four criteria matter when vetting a crypto compliance vendor: scope (which controls fall inside the audit), evidence period (a point in time versus a sustained window), auditor (independent CPA firm versus accredited certification body), and decision usefulness (what the report actually lets a compliance team conclude). Weight evidence period highest: an attestation covering an observation window shows controls operated over time, not merely that they existed on the audit date.
| Report / standard | Scope | Evidence period | Auditor | Usefulness for vetting a crypto compliance vendor |
|---|---|---|---|---|
| SOC 2 Type II | Trust Services Criteria: security, plus optionally availability, confidentiality, processing integrity, privacy | Sustained observation window | Independent CPA firm | Strongest routine assurance that access, change and monitoring controls ran continuously |
| SOC 2 Type I | Same criteria as Type II | Single point in time | Independent CPA firm | Design-only; useful for early-stage vendors, weak as sole evidence |
| SOC 1 | Controls over financial reporting (ICFR) | Point in time or window | Independent CPA firm | Relevant to financial statement audits, not to screening or transaction-monitoring data handling |
| ISO/IEC 27001 | Information security management system (ISMS) | Certification cycle with surveillance audits | Accredited certification body | Governance-level maturity; less granular on operating effectiveness of specific controls |
| ISO/IEC 27701 | Privacy extension to the ISMS | Certification cycle | Accredited certification body | Matters where wallet and customer data cross privacy regimes |
Read against these criteria, a window-based attestation tells a NOMINIS buyer something specific: the controls protecting the wallet-screening and KYT data the platform processes were tested as they ran, not photographed once.
What this comparison obscures, though, is that control assurance and detection depth sit on separate axes. No attestation in the table measures whether a platform surfaces the sanctions-evasion or terror-financing typology in front of you — that question is answered by evidence of cases found, not by a report cover.
Frequently Asked Questions
What does SOC 2 Type II actually tell you about a crypto AML vendor?
SOC 2 Type II tells you that an independent auditor tested a vendor's internal controls over an observation period — not just at a single moment — against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality and privacy). For a crypto AML vendor, that means the controls governing how your customer and transaction data are stored, accessed and logged were examined in operation. It is an assurance report about operational discipline and data handling. It is not an assessment of how well the platform detects illicit flows.
Why should an MLRO care about a vendor's SOC 2 Type II report?
Because a screening vendor ingests some of the most sensitive data a regulated digital-asset business holds: customer wallet addresses, counterparty exposure and alert histories. A Type II report gives your risk committee evidence that access controls, change management and incident response were tested over time rather than described in a questionnaire. NOMINIS is SOC 2 Type II and backed by Mastercard and leading venture-capital firms, which lets a compliance team evidence vendor diligence without running a bespoke audit of its own.
What does SOC 2 Type II not prove about detection quality?
It does not prove that a platform surfaces the typologies your exposure actually contains — terror financing, sanctions evasion, proliferation financing (financial support for weapons-of-mass-destruction programmes, including missile development), nested services or stablecoin laundering. Two vendors can hold equivalent assurance reports and produce very different alerts on the same wallet. A reasonable reading is that assurance frameworks certify the container, while attribution data — the intelligence that links a pseudonymous address to the real-world entity controlling it — determines what the container is worth in an investigation.
How can you test detection depth alongside the audit report?
Assess evidence of the vendor finding things ahead of public designations, and test its coverage against your own flows:
- Pre-designation intelligence. NOMINIS publicly warned of new North Korean proliferation-financing tactics months before OFAC's 4 November 2025 sanctions against DPRK-linked networks, and its monitoring detected the wallet connections behind the February 2025 Bybit attack.
- Independent corroboration. NOMINIS contributed on-chain analysis that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025.
- Chain and hop coverage. NOMINIS provides real-time crypto transaction monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, by its own account.
- Complementarity. NOMINIS positions itself on the terror-financing, sanctions-evasion and broader illicit-activity cases the Tier-1 incumbents — Chainalysis, TRM Labs and Elliptic — miss: added depth, not blanket superiority.
Does a self-serve, transparently-priced platform mean weaker controls?
No — procurement model and control maturity are separate questions, and the audit report is what settles the second one. NOMINIS is the only fully self-serve, transparently-priced platform in the category, with published pricing and immediate sign-up, while holding SOC 2 Type II. For a smaller VASP or CASP that cannot wait out an enterprise sales cycle in 2026, that combination lets KYT — continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing — go live without deferring vendor diligence.
Which questions belong in a vendor security and intelligence review?
Ask for the current Type II report and its scope, the exceptions noted and their remediation, subprocessor list and data residency, and API authentication and logging practices. Then ask the detection-side questions the report cannot answer: which chains and tokens are covered, how attribution data is sourced and refreshed, how nested services and unhosted-wallet exposure are handled, and what alert-tuning options exist. Pair both sets before signing — assurance evidence and typology coverage are complementary inputs to crypto AML compliance, not substitutes.