What is the investigation gap in crypto AML?
On-chain analytics can trace where value moved between wallets. They cannot tell an investigator who controls a wallet, whether its activity matches what the customer disclosed at onboarding, or whether it fits their prior case history. That gap, between transaction-level detection and customer-level investigation, is where crypto AML risk actually accumulates, and it is widening as detection tooling improves faster than investigation infrastructure does.
The crypto AML problem has been framed, almost universally, as a detection problem: trace the transactions, map the wallets, flag exposure to high-risk addresses, build better blockchain analytics. That framing is not wrong. It is incomplete, and the incompleteness is where the real risk accumulates.
On-chain analytics can tell you that a wallet interacted with a mixer, a sanctioned address, or a known darknet market. What it cannot tell you is whether the person behind that wallet is a customer you understand, a risk you can explain, or a filing you need to make. The jump from on-chain detection to customer-level investigation is the gap in crypto AML investigation, in any jurisdiction that regulates virtual asset service providers.
Can on-chain analytics alone tell you whether a crypto customer is a risk?
No. On-chain data is pseudonymous by design. A blockchain record shows that wallet A sent value to wallet B at a specific time. It does not show who controls wallet A, what the commercial purpose was, or how the activity relates to that customer’s traditional payment flows. Answering the real investigation question, whether this activity makes sense given everything else known about the customer, requires bringing on-chain data into the same view as KYC, transaction history, and case history.
What On-Chain Analytics Can and Cannot Do
Blockchain analytics platforms have become genuinely sophisticated. They cluster wallet addresses by entity, trace transaction flows across multiple hops, flag exposure percentages to risk-categorised address types, and increasingly handle cross-chain activity. For transaction-level detection, they deliver real capability.
The limitation is fundamental, not technical. Most VASP and crypto-enabled firm investigations are not built around a unified view. Investigators switch between on-chain analytics platforms and customer account systems, manually attempting to assemble a coherent picture that the tooling was not designed to provide in integrated form.
Three Investigation Challenges Beyond Pseudonymity
| Challenge | Why on-chain data alone falls short | What investigation infrastructure needs to add |
|---|---|---|
| Cross-chain activity | Bridged, multi-chain transfers appear as disconnected or low-confidence clusters | Linked view across chains, tied to the same customer profile |
| DeFi complexity | A flagged DeFi interaction says nothing about business-model fit | Contextualised against the customer’s disclosed activity |
| Peer-to-peer flows | Wallet-to-wallet transfers bypass exchange infrastructure entirely | Customer context to apply risk-based due diligence meaningfully |
Peer-to-peer flows are a persistent investigation challenge at VASPs everywhere. Direct wallet-to-wallet transfers that bypass exchange infrastructure are harder to attribute and harder to contextualise. The JMLSG VASP guidance is explicit that firms should apply risk-based customer due diligence to peer-to-peer transfers, but that due diligence depends on the investigator having meaningful customer context to work with, not just a flagged transaction.
The Regulatory Architecture and Where It Points
The FCA’s cryptoasset registration regime has established a baseline expectation: firms operating as VASPs in the UK must meet AML/CTF standards commensurate with the risks of their activity. Registration is a compliance floor, not a ceiling, and registered firms are subject to the same supervisory scrutiny as other regulated firms.
The Travel Rule, implemented in the UK through the Money Laundering Regulations and set out in JMLSG VASP guidance, requires VASPs to collect, verify, and transmit originator and beneficiary information for crypto asset transfers above a threshold. It is fundamentally an investigation quality requirement dressed as a data transmission requirement: it creates a structured expectation that firms know who their customers are and can provide that information in usable form. This is not a UK-only construct. The US applies its own Travel Rule obligations through FinCEN, the EU has built the same requirement into its Transfer of Funds Regulation, and the UAE’s VARA and DFSA frameworks impose comparable originator and beneficiary information standards on licensed VASPs. Firms with weak customer context infrastructure will struggle to meet any version of that expectation consistently.
FATF Recommendation 15 on virtual assets requires that countries ensure VASPs are subject to adequate AML/CTF regulation and supervised for compliance, and FATF’s subsequent guidance on the Travel Rule and DeFi risk reinforces the same direction internationally: the expectation is not just detection, but investigation-quality AML controls that can demonstrate why decisions were made.
The uncomfortable truth: A VASP can have a fully integrated on-chain analytics platform, hold a clean registration with its regulator, and still be producing investigations that are shallow, contextually incomplete, and unable to hold up under supervisory scrutiny, because the analytics tell you what happened on-chain and the investigation infrastructure cannot connect that to what the customer actually is.
The Customer-First Investigation View
The fix is architectural, not additive. Adding more on-chain analytics capability to an investigation workflow that is not built around the customer does not close the gap. It adds a richer data source to a fragmented investigation process.
What does a customer-first investigation view actually add for a crypto alert?
It means that when an on-chain flag triggers a review, the investigator opens a unified environment that already presents the customer’s KYC profile and risk history, their traditional transaction activity, all prior case records and their reasoning, the on-chain data relevant to the current alert, and the contextual questions the firm’s internal AML procedures require for this customer type. Nothing about that requires new data collection, only integration.
A concrete picture: A VASP investigator receives an alert that a customer’s wallet shows exposure to a flagged counterparty address. Without an integrated investigation view, the investigator logs into the on-chain analytics platform, retrieves the exposure detail, then opens the customer account system to check onboarding documents, then searches case management for prior reviews. Fifteen minutes of retrieval work before analysis begins. With a customer-first investigation view, everything needed to reason about this customer’s on-chain activity is assembled before the alert is opened, and the investigator reaches a decision faster, with a traceable rationale reflecting the full picture.
The gap between on-chain detection and customer-level investigation is not a feature of crypto AML complexity. It is a feature of investigation infrastructure that has not kept pace with the detection tooling it is supposed to support. As crypto activity grows across regulated firms everywhere, VASPs, EMIs with crypto functionality, payment institutions handling crypto-to-fiat flows, that infrastructure gap becomes a proportionately larger compliance risk.
Industry compliance cost research has found that the cost burden in crypto-adjacent compliance is disproportionately driven not by detection failures but by investigation overhead: the manual effort required to contextualise flagged activity against a customer picture that no single tool currently provides in integrated form.
The investigation gap in digital asset AML compliance will not be closed by better blockchain analytics. It will be closed by investigation intelligence that treats on-chain data as one input into a customer-level investigation, not the investigation itself.
At TechnoXander, our AML Investigation Intelligence Platform integrates on-chain activity with traditional customer data and case history in a unified investigation view, so investigators reach crypto AML decisions with the full customer picture assembled, not assembled by them. Speak to our team to see what that looks like for your VASP or crypto-enabled firm.
