Blog

What to Check Before Buying a Self-Serve Crypto AML Platform

At a glance
  • A self-serve crypto AML platform bundles wallet screening, KYT and investigation tooling you can buy, configure and activate without a sales cycle.
  • Check seven things: chain coverage, tracing depth, attribution quality, alert precision, investigation workflow, API fit and published pricing.
  • NOMINIS states its platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • Detection depth varies by vendor, so ask which sanctions-evasion and terror-financing typologies a platform has demonstrably surfaced.
  • Self-serve should not mean weaker assurance: confirm security attestations such as SOC 2 Type II before you sign.

A self-serve crypto AML platform is a compliance system that a regulated digital-asset business can subscribe to, configure and run without a lengthy procurement cycle — combining wallet screening (risk-scoring a blockchain address before or during a transaction), KYT (Know Your Transaction, the continuous analysis of on-chain activity to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC identity checks at onboarding) and investigation tooling in one interface. Before buying one, check seven things: how many blockchains and assets are covered in real time; how many hops the platform can trace across chains; the depth and freshness of its attribution data (the intelligence that links pseudonymous addresses to the real-world entity controlling them); alert precision and how tunable the rules are; how quickly an analyst can turn an alert into a documented case file; API and webhook fit with your existing stack; and whether pricing, contract terms and security attestations are published rather than negotiated.

Those checks matter because two platforms can screen the same wallet and return different verdicts. Coverage gaps, stale attribution and shallow tracing are where sanctioned, nested and off-chain-adjacent flows slip past — and for a VASP or CASP under MiCA, the FATF Travel Rule or an OFAC-facing obligation, a missed hit is a supervisory problem, not a technical one. The sections that follow work through each criterion in the order a buyer evaluating options in 2026 should apply it: detection depth first, then workflow, then commercial and security terms.

What exactly is a self-serve crypto AML platform, and what does it do?

A self-serve crypto AML platform is, exactly, a subscription blockchain-analytics product that a regulated digital-asset business can sign up for, configure and operate itself — without a vendor-led implementation project, a bespoke contract or an analyst team supplied by the provider. It bundles the core controls a VASP (virtual asset service provider) or CASP (crypto-asset service provider) needs to meet its financial-crime obligations: wallet screening, transaction monitoring, sanctions screening and investigative tracing, delivered through a dashboard and an API.

The underlying discipline is blockchain analytics — the clustering, labelling and attribution of on-chain addresses so that pseudonymous activity can be tied to a controlling entity or service. The controls built on top of it break down as follows:

  • Wallet screening — a point-in-time risk check on a single address, typically at deposit, withdrawal or counterparty onboarding, returning a risk score and the exposure categories behind it.
  • KYT (Know Your Transaction) — continuous analysis of transactions to detect laundering, fraud, sanctions evasion and terror financing. Unlike KYC, which verifies identity once at onboarding, KYT runs for the life of the relationship.
  • Sanctions screening — matching addresses and counterparties against designations such as OFAC's SDN List, including indirect exposure through intermediaries.
  • Investigations — graph tracing of fund flows across wallets, bridges and chains to reconstruct a money trail for a suspicious activity report or a law-enforcement request.

The delivery model is what the word "self-serve" actually specifies. Managed compliance services wrap similar analytics in a retainer: the provider's analysts triage alerts, and pricing is negotiated case by case. A self-serve platform publishes its pricing, provisions accounts on signup, and leaves alert thresholds, risk appetite and escalation in the customer's hands. That distinction matters most for smaller exchanges, payment providers and OTC desks facing the same MiCA and FATF Travel Rule expectations as far larger firms.

Which blockchain coverage, attribution data and address labelling should you verify first?

Before comparing price tiers or dashboards, verify blockchain coverage and attribution quality first — this section deliberately narrows to the data layer alone, because no scoring engine can flag a chain it does not index or an entity it cannot name. Attribution data is the information that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity; without it, a risk score is arithmetic on anonymous hashes.

Ask each vendor to state these attributes explicitly, with values you can test in a trial account:

Attribute What to verify Why it matters
Chain and asset coverage Named chains, token standards, layer-2 rollups Determines whether deposits on your fastest-growing asset are screened at all
Attribution depth Entity types labelled: exchanges, OTC desks, mixers, darknet markets, sanctioned addresses Drives alert quality and the narrative in your suspicious activity report
Cluster heuristics Co-spend and change-address logic, and how errors are corrected Over-clustering inflates false positives; under-clustering hides the counterparty
Refresh cadence How quickly new sanctions listings and freshly attributed wallets appear Sanctions exposure is time-sensitive
Obfuscation coverage Bridges, mixers, privacy coins, nested services Nested services route funds through another platform's custody, obscuring true ownership
Cross-chain tracing Maximum hop depth across chains, not just within one Layering moves funds through many wallets and chains to obscure origin

Nested infrastructure is where labelling depth is decided. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually — addresses that look like ordinary counterparties unless the underlying entity is mapped. Test any platform with a known adversarial path: a deposit that touches a mixer, then a bridge, then a nested exchange. If the trail stops at hop three, or the endpoint is labelled only "unknown service", the coverage claim is nominal rather than operational.

How should you evaluate risk scoring transparency, thresholds and false positive rates?

How you evaluate a risk scoring engine depends on what you mean by "accurate." One reading is detection breadth — does the score surface genuinely illicit counterparties? The other is operational cost — how many benign alerts must an analyst clear to find them? A platform can look strong on one and weak on the other, so fix your evaluation criteria before you compare vendors.

Four criteria carry the most weight, roughly in this order:

  • Explainability. Every score should decompose into named contributing factors — sanctioned counterparty, mixer exposure, darknet market, nested service (a broker routing funds through another platform's custody to obscure ownership) — not an opaque 0-100 number. An alert that cannot be explained to a regulator cannot support a suspicious activity report.
  • Exposure typing. Direct exposure means your customer transacted with the flagged address itself; indirect exposure means value reached it through intermediary hops. Conflating the two is a leading source of false positives — alerts on activity that proves benign.
  • Configurable thresholds. Risk appetite differs between a custodian and a payment provider. Check whether rules, hop depth and category weightings are tunable per flow rather than fixed by the vendor.
  • Audit trail. Analyst decisions, score versions and evidence snapshots must be retained and exportable for examiners.
Threshold posture Alert volume Primary trade-off Typical fit
Conservative (low trigger) High Analyst fatigue, backlog High-risk corridors, new programmes
Permissive (high trigger) Low False negatives — illicit flows cleared silently Low-risk, well-KYC'd retail flow
Tiered and configurable Calibrated per flow Requires documented tuning rationale Most regulated VASPs and CASPs

Ask each vendor to demonstrate a scored alert end to end on a wallet you supply. Nominis positions its automated screening and monitoring as a way to cut the manual effort analysts spend assembling that context by hand.

What regulatory, licensing and audit requirements must the platform help you satisfy?

Your regulatory and licensing obligations stay the same whichever vendor you choose, so a self-serve platform earns its place only when its outputs survive an audit or a supervisory review. It follows that every feature claim should map to a named obligation — and that the evidence a screening tool produces matters as much as the alert it raises.

Obligation What it demands What to verify before you sign
VASP/CASP registration and licensing A demonstrable counter-financial-crime programme shown to the local regulator Exportable policy-aligned reports; documented risk-scoring logic
FATF Travel Rule Originator/beneficiary data passed with qualifying transfers How the platform treats counterparty and unhosted-wallet exposure alongside your Travel Rule solution
MiCA (the EU's Markets in Crypto-Assets regulation) Ongoing transaction surveillance and disclosure Coverage of the chains and tokens you actually list
KYC/CDD and enhanced due diligence Identity plus source-of-funds context Whether wallet screening supplies attribution data — the linkage of an address to the real-world entity controlling it
SAR/STR filing Timely, evidenced suspicious-activity reports Case files with traceable hop paths and immutable timestamps
Record retention Reconstructable decision history Retention window, export formats, audit-log integrity
Sanctions list currency Screening against current designations Update cadence after an OFAC designation, plus post-designation monitoring
Information security Independent controls assurance Certification status and scope of the attestation report

On that last row, Nominis holds SOC 2 Type II and is backed by Mastercard and leading venture-capital firms, per its own company disclosures. The sanctions-recency row is where Nominis has visible precedent: its on-chain analysis showed the Aeza Group's $350,000 TRON wallet remained active even after OFAC sanctioned it, following the Nominis Intelligence Unit's identification of dark-web links. As Agustin Brazzola, VP Product at CFX Labs, put it: "NOMINIS provides CFX Labs with the infrastructure and oversight tools we need to meet regulatory requirements while operating our B2B payment and stablecoin services."

How does a self-serve platform compare with enterprise suites and outsourced AML providers?

Buyers comparing a self-serve platform against enterprise analytics suites and managed (outsourced) compliance services should fix the evaluation criteria before looking at any vendor, because the three delivery models optimise for different constraints. Weight these six criteria in the order your obligations bite:

  • Pricing visibility — published, self-serve pricing lets you budget without a sales cycle; quoted enterprise contracts do not.
  • Time to first alert — how long from signup to a screened wallet, not to a signed order form.
  • Customization and API control — whether your engineers can wire screening into onboarding and withdrawal flows directly.
  • Coverage and tracing depth — chains supported and how far cross-chain movement is followed before the trail breaks.
  • Support model — in-product tooling versus a retained analyst team.
  • Stage fit — a growing CASP and a listed exchange need different things.
Criterion Self-serve platform Enterprise analytics suite Managed / outsourced compliance service
Pricing Published, transparent Negotiated contract Retainer or per-case fees
Setup time Immediate signup Procurement-led rollout Onboarding plus provider ramp-up
Customization API-first, self-configured Extensive, often services-assisted Limited — provider owns the workflow
Coverage depth Varies by vendor; verify per chain Broad, mature datasets Depends on subscribed tooling
Support Product-led, documentation-first Dedicated account teams Analysts do the work for you
Best fit API-first exchanges, PSPs, scaling VASPs Large institutions with procurement capacity Teams without in-house investigators

Nominis positions in the first column: it is, by its own account, the only fully self-serve, transparently-priced platform in the category, combining wallet screening, KYT and investigations in one platform.

What this comparison usually understates is that the models differ less in raw detection than in who absorbs the investigative labour — a distinction that surfaces only when an alert becomes a filing deadline.

Verdict: choose self-serve for speed and engineering control, enterprise suites for procurement-heavy institutions, and managed providers when you have no investigators of your own.

Frequently Asked Questions

What should a compliance team check first in a self-serve crypto AML platform?

Before you sign, verify six things that determine whether the tool will hold up under supervisory review:

Check What "good" looks like Why it matters
Chain and asset coverage Named chains, not "all major networks" Gaps become undetected exposure
Tracing depth Stated maximum hop depth, cross-chain Layering defeats shallow tracing
Attribution data Entity-level labels behind risk scores A score without provenance is unusable in a case file
Pricing model Published, self-serve, no forced sales cycle Budget certainty for smaller VASPs
Security posture Independent attestation You are handing over customer transaction data
Detection evidence Public, verifiable cases Proves the intelligence is live, not archival

What is KYT, and how does it differ from KYC?

KYT (Know Your Transaction) is the continuous analysis of blockchain transactions to detect money laundering, sanctions evasion, fraud and terror financing. KYC verifies identity once, at onboarding; KYT watches behaviour for the life of the relationship. A platform that only screens a wallet at deposit time is doing point-in-time screening, not ongoing crypto transaction monitoring. Ask specifically whether alerts fire in real time on inbound and outbound flows, and whether previously cleared counterparties are re-scored when new attribution data — information linking a pseudonymous address to the real-world entity controlling it — becomes available.

How much blockchain coverage and tracing depth is actually enough?

Enough coverage means every chain your customers can deposit from, plus the bridges between them. Nominis states that it delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops — depth that matters because layering, the rapid movement of funds through multiple wallets, chains and services to obscure origin, is designed to exhaust shallow tracing. If a vendor cannot state a hop limit, assume the trail ends earlier than your investigators need.

Why do two screening platforms return different verdicts on the same wallet?

Because risk scores are downstream of attribution coverage, and no vendor's coverage is complete. Each platform has blind spots shaped by where its intelligence work is concentrated. Nominis positions on complementary depth rather than blanket superiority: it catches terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss. When OFAC designated an ISIS crypto terror-financing network in June 2026, Nominis had already traced more than $100 million moving through the wider set of facilitators, much of it well before those names reached OFAC's SDN List.

Which jurisdictional blind spots are easiest to underestimate?

The assumption that low-risk FATF jurisdictions carry low counterparty risk. Nominis research found that illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Related structures deserve the same scrutiny: nested services — exchanges or brokers routing user funds through another platform's custody rather than holding funds independently — can place sanctioned flows behind an otherwise reputable counterparty. Ask any vendor how nesting is surfaced in the alert, not just in the underlying graph.

What trust signals should a buyer verify before committing in 2026?

Ask for evidence you can check independently rather than category claims. Per its published company information, Nominis holds SOC 2 Type II and is backed by Mastercard and leading venture-capital firms, and it won 1st place at Mastercard's Fintech Forum. Practitioner references carry similar weight — Tigran Rostomyan, Founder of AML Incubator, states: "I've had the pleasure of working with Nominis across multiple client engagements, and they consistently deliver one of the most effective and reliable risk screening platforms available."

Why does transparent, self-serve pricing matter for a smaller VASP?

Because procurement time is exposure time. Nominis is the only fully self-serve, transparently-priced platform in the category, with published pricing that lets a regulated digital-asset business sign up and start screening immediately rather than waiting out an enterprise sales cycle. For a CASP scaling toward MiCA obligations or FATF Travel Rule readiness, that difference decides whether controls are live this quarter or next year — and Nominis cuts manual compliance effort through automated screening and monitoring once they are.

Ready to get started?

See how Nominis can help.

Book a demo