Crypto, Digital Assets, and AML: The Investigation Gap That Keeps Getting Wider

What is the investigation gap in crypto AML?
On-chain analytics can trace where value moved between wallets. They cannot tell an investigator who controls a wallet, whether its activity matches what the customer disclosed at onboarding, or whether it fits their prior case history. That gap, between transaction-level detection and customer-level investigation, is where crypto AML risk actually accumulates, and it is widening as detection tooling improves faster than investigation infrastructure does.

The crypto AML problem has been framed, almost universally, as a detection problem: trace the transactions, map the wallets, flag exposure to high-risk addresses, build better blockchain analytics. That framing is not wrong. It is incomplete, and the incompleteness is where the real risk accumulates.

On-chain analytics can tell you that a wallet interacted with a mixer, a sanctioned address, or a known darknet market. What it cannot tell you is whether the person behind that wallet is a customer you understand, a risk you can explain, or a filing you need to make. The jump from on-chain detection to customer-level investigation is the gap in crypto AML investigation, in any jurisdiction that regulates virtual asset service providers.

Can on-chain analytics alone tell you whether a crypto customer is a risk?

No. On-chain data is pseudonymous by design. A blockchain record shows that wallet A sent value to wallet B at a specific time. It does not show who controls wallet A, what the commercial purpose was, or how the activity relates to that customer’s traditional payment flows. Answering the real investigation question, whether this activity makes sense given everything else known about the customer, requires bringing on-chain data into the same view as KYC, transaction history, and case history.

What On-Chain Analytics Can and Cannot Do

Blockchain analytics platforms have become genuinely sophisticated. They cluster wallet addresses by entity, trace transaction flows across multiple hops, flag exposure percentages to risk-categorised address types, and increasingly handle cross-chain activity. For transaction-level detection, they deliver real capability.

The limitation is fundamental, not technical. Most VASP and crypto-enabled firm investigations are not built around a unified view. Investigators switch between on-chain analytics platforms and customer account systems, manually attempting to assemble a coherent picture that the tooling was not designed to provide in integrated form.

Three Investigation Challenges Beyond Pseudonymity

ChallengeWhy on-chain data alone falls shortWhat investigation infrastructure needs to add
Cross-chain activityBridged, multi-chain transfers appear as disconnected or low-confidence clustersLinked view across chains, tied to the same customer profile
DeFi complexityA flagged DeFi interaction says nothing about business-model fitContextualised against the customer’s disclosed activity
Peer-to-peer flowsWallet-to-wallet transfers bypass exchange infrastructure entirelyCustomer context to apply risk-based due diligence meaningfully

Peer-to-peer flows are a persistent investigation challenge at VASPs everywhere. Direct wallet-to-wallet transfers that bypass exchange infrastructure are harder to attribute and harder to contextualise. The JMLSG VASP guidance is explicit that firms should apply risk-based customer due diligence to peer-to-peer transfers, but that due diligence depends on the investigator having meaningful customer context to work with, not just a flagged transaction.

The Regulatory Architecture and Where It Points

The FCA’s cryptoasset registration regime has established a baseline expectation: firms operating as VASPs in the UK must meet AML/CTF standards commensurate with the risks of their activity. Registration is a compliance floor, not a ceiling, and registered firms are subject to the same supervisory scrutiny as other regulated firms.

The Travel Rule, implemented in the UK through the Money Laundering Regulations and set out in JMLSG VASP guidance, requires VASPs to collect, verify, and transmit originator and beneficiary information for crypto asset transfers above a threshold. It is fundamentally an investigation quality requirement dressed as a data transmission requirement: it creates a structured expectation that firms know who their customers are and can provide that information in usable form. This is not a UK-only construct. The US applies its own Travel Rule obligations through FinCEN, the EU has built the same requirement into its Transfer of Funds Regulation, and the UAE’s VARA and DFSA frameworks impose comparable originator and beneficiary information standards on licensed VASPs. Firms with weak customer context infrastructure will struggle to meet any version of that expectation consistently.

FATF Recommendation 15 on virtual assets requires that countries ensure VASPs are subject to adequate AML/CTF regulation and supervised for compliance, and FATF’s subsequent guidance on the Travel Rule and DeFi risk reinforces the same direction internationally: the expectation is not just detection, but investigation-quality AML controls that can demonstrate why decisions were made.

The uncomfortable truth: A VASP can have a fully integrated on-chain analytics platform, hold a clean registration with its regulator, and still be producing investigations that are shallow, contextually incomplete, and unable to hold up under supervisory scrutiny, because the analytics tell you what happened on-chain and the investigation infrastructure cannot connect that to what the customer actually is.

The Customer-First Investigation View

The fix is architectural, not additive. Adding more on-chain analytics capability to an investigation workflow that is not built around the customer does not close the gap. It adds a richer data source to a fragmented investigation process.

What does a customer-first investigation view actually add for a crypto alert?

It means that when an on-chain flag triggers a review, the investigator opens a unified environment that already presents the customer’s KYC profile and risk history, their traditional transaction activity, all prior case records and their reasoning, the on-chain data relevant to the current alert, and the contextual questions the firm’s internal AML procedures require for this customer type. Nothing about that requires new data collection, only integration.

A concrete picture: A VASP investigator receives an alert that a customer’s wallet shows exposure to a flagged counterparty address. Without an integrated investigation view, the investigator logs into the on-chain analytics platform, retrieves the exposure detail, then opens the customer account system to check onboarding documents, then searches case management for prior reviews. Fifteen minutes of retrieval work before analysis begins. With a customer-first investigation view, everything needed to reason about this customer’s on-chain activity is assembled before the alert is opened, and the investigator reaches a decision faster, with a traceable rationale reflecting the full picture.

The gap between on-chain detection and customer-level investigation is not a feature of crypto AML complexity. It is a feature of investigation infrastructure that has not kept pace with the detection tooling it is supposed to support. As crypto activity grows across regulated firms everywhere, VASPs, EMIs with crypto functionality, payment institutions handling crypto-to-fiat flows, that infrastructure gap becomes a proportionately larger compliance risk.

Industry compliance cost research has found that the cost burden in crypto-adjacent compliance is disproportionately driven not by detection failures but by investigation overhead: the manual effort required to contextualise flagged activity against a customer picture that no single tool currently provides in integrated form.

The investigation gap in digital asset AML compliance will not be closed by better blockchain analytics. It will be closed by investigation intelligence that treats on-chain data as one input into a customer-level investigation, not the investigation itself.

At TechnoXander, our AML Investigation Intelligence Platform integrates on-chain activity with traditional customer data and case history in a unified investigation view, so investigators reach crypto AML decisions with the full customer picture assembled, not assembled by them. Speak to our team to see what that looks like for your VASP or crypto-enabled firm.

About Author:

Sonal Bomb, CEO of TechnoXander, professional portrait highlighting leadership, innovation, and company vision.

Sonal Bomb

Sonal Bomb specialises in payments regulation, fraud prevention, and compliance frameworks across the UK and EU. She works closely with banks and PSPs on implementing Verification of Payee (VoP), Confirmation of Payee (CoP), and Open Banking requirements, translating evolving regulatory mandates into practical payment infrastructure.

VoP • CoP • Open Banking • PSD2/PSD3 • Payment Fraud Prevention • FiDA

LinkedIn Profile
Tags :
Social Share with Tooltip

Related Post

The Next Phase of AML Is Not Better Detection. It Is Better Decisions.

The Next Phase of AML Is Not Better Detection. It Is Better Decisions.

What is the next phase of AML maturity? It is the…

The AML Vendor Landscape Is Crowded. The Investigation Quality Gap Is Not Being Filled.

The AML Vendor Landscape Is Crowded. The Investigation Quality Gap Is Not Being Filled.

What is the investigation quality gap in the AML vendor market?…

Crypto, Digital Assets, and AML: The Investigation Gap That Keeps Getting Wider

Crypto, Digital Assets, and AML: The Investigation Gap That Keeps Getting Wider

What is the investigation gap in crypto AML? On-chain analytics can…