Guide

What a complete check takes

Two books sit beside a screen: the indicators live chain data can answer, and the clocks the institution still runs. This page is that walk. The product landing stays the brief.

Three examiners

What a complete check takes

The half the identity stack cannot see

Regulated virtual asset firms build their monitoring on the FATF Virtual Assets Red Flag Indicators of ML/TF (September 2020). Of the 17 indicators below, the examiners answer 10 outright from live chain data and contribute to 5 more. The remaining 2 belong to an identity stack, and this page says so rather than counting them twice.

Half one

Who the customer is

Document and liveness verification, sanctions and PEP name matching, adverse media, source of wealth, and beneficial ownership down to natural persons.

Not chainscore.net Identity and KYC vendors

chainscore.net does not do this half and does not claim to. It has no view of a passport, a PEP list or a customer file.

Half two

What the wallet has touched

Counterparty attribution, direct and indirect exposure across hops, sanctioned address designation, bridge and cluster context, and named behavioural scenarios.

chainscore.net ScoreGuard, ChainTrace and Holistix

A verified identity says nothing about whether the wallet behind it sits two hops from a mixer. That is the half a name-matching stack structurally cannot see.

10 chain data 5 in part 2 identity stack

Indirect exposure, not just the first counterparty

The obligation says direct and indirect. A single-address lookup answers only the first half, because indirect exposure is a property of the graph rather than of the address. Hops are traced outward with the value share decayed by distance.

Sanctions screened as addresses, not as names

995 designated addresses on supported chains, from the US Treasury OFAC — Specially Designated Nationals list, published 09/18/2026. A name match can be defeated by a spelling; a designated address is the account itself.

The report says how much it actually knows

Every screen carries an attribution coverage figure and a plain statement of what the score covers. Below 70% identified value the report cannot auto-clear — a clean number over unidentified counterparties is sent to review, not presented as a pass.

Unknown stays unknown

Counterparties the label book does not document are left unlabelled. Nothing is inferred from an address's shape to fill a gap in a report someone will file.

Findings arrive shaped like a filing

Scenarios are named, exhibits are attached, and ScoreGuard assembles a SAR narrative pack with filing categories. The decision to file stays with the institution.

Three books, deliberately not merged

Compliance, forensic and cross-chain scores keep their own scales, databases and label books. A cross-chain trace cannot silently rewrite a compliance filing.

Indicator · who answers it

Red flag indicatorAnswered byHow
Direct and indirect exposure to darknet markets, mixers, ransomware and reported theft Chain data ChainTrace hop tracing · ScoreGuard exposure Exposure is traced out over multiple hops with the share decayed by distance, so a counterparty that is clean at hop 1 and dirty at hop 3 still reaches the report.
Mixing and tumbling services used to obscure flow between known wallets and darknet marketplaces Chain data Category exposure Mixer contact is a named category with its own value share, not a footnote.
Transfers to high-risk wallet addresses or service clusters Chain data Attribution and cluster labels Counterparties resolve to a labelled entity where one is documented. Where none is, they stay unknown rather than being guessed from the hash.
Dealings with designated individuals, entities and their addresses Chain data OFAC SDN address designation Screened as an address designation, not a name match, so it does not depend on the customer having given a matching name.
Accumulation from many unrelated wallets in small amounts, then a single transfer out or full exchange to fiat Chain data Graph and flow analysis A fan-in followed by a single exit is a shape, and the graph is where a shape is visible.
Structuring under reporting thresholds, round amounts, round trips and transactions with no commercial basis Chain data Named behavioural scenarios Each scenario is named in the report, so a reviewer can see which one fired and why.
Multiple high-value transfers in short succession, or a staggered pattern followed by long silence Chain data Velocity and pass-through scenarios Includes the rapid in-then-out signature of layering, timed across the transfer set.
Dormant accounts that become active after a full year Chain data Dormancy detection Measured from the observed transfer history rather than from an account-opening date.
Rising or sustained activity with higher-risk geographies and entities Chain data Jurisdiction exposure Exposure is attributed by jurisdiction where the label book records one.
Sending to or receiving from a service with weak or non-existent CDD Chain data ScoreGuard KYV VASP due diligence covers licensing, jurisdiction and the provider's own cluster behaviour.
Moving value across chains, or into an exchange and straight out into a privacy coin Chain, in part Out-of-sight legs Hosted venues (exchanges, custodians, merchants) and mixers are marked out of sight: the deposit is attributed, but onward hops — including a privacy-coin withdrawal inside the venue — are not in this score. Bridge far-sides stay modelled. An unindexed or unavailable chain is named as opaque, not scored empty-and-clean. Permissioned ledgers (GS DAP, Citi Token Services) are disclosed even when no address matched. The internal hop itself is still not observable.
Funds suspected stolen, or received from addresses linked to holders of stolen funds Chain, in part Label book categories Answerable for published incidents in the cited overlay (FBI/IC3 Bybit theft cluster, Chainalysis Euler and Wormhole exploiter addresses). An unreported hack is still not in any label set, including this one.
Activity that deviates from the customer's normal transactional behaviour Chain, in part Stated customer profile When the institution supplies a stated customer profile (expected volume, transfer size, counterparties, jurisdictions, direction), deviation from that profile is scored. Without one, this flag cannot fire — the wallet's own history is still in the report. Opening-deposit versus declared income is a separate stated-identity indicator.
A large opening deposit inconsistent with the customer's stated profile, or a new user withdrawing the full balance Chain, in part Stated identity (account age, income) When the institution supplies account opening date, a new-customer flag, or declared income, a large first inbound or a new-user full withdrawal is scored. Without those CDD facts the flag cannot fire — first-seen on chain is not account age. PEP and source-of-wealth remain an identity stack. An institution can attest PEP or SoW status on the report; that is disclosure, not a name-list or document screen.
Repeated transfers to one account by several people, or from a single IP address Chain, in part Many-to-one wallet shape Many distinct inbound wallets in a short window are named as a many-to-one shape. That they are several people, or that they share an IP, remains an identity check.
Politically exposed persons, their family members and close associates Identity stack PEP screening vendor A name-list obligation. Nothing on chain marks an address as belonging to a PEP. An institution can attest a PEP or RCA status on the report; that is recorded as disclosure, not a screen.
Source of funds and source of wealth, verified against documentary evidence Identity stack Enhanced due diligence file Where funds came from on chain is traceable. Whether the documents explaining them are truthful is not a chain question. An institution can attest that SoW documents are on file; that is recorded as disclosure, not a review of those documents.

Named directly in the published AML/CFT policies of VARA-regulated virtual asset firms as the indicator set their monitoring is built on. A screen that covers only the identity half leaves the on-chain obligations asserted but unevidenced — and a screen that covers only the chain half is not a substitute for knowing the customer.

Why the second half has to be carried separately

The score has nowhere to put a wallet finding

The same policies publish their risk models weight for weight. Both are fully specified, and each totals 100. Across all 18 factors, the weight assigned to anything observable on chain is 0 — while 15 of the 17 indicators the same policy monitors are answerable from chain data. The model is not wrong. It simply has no field for what a wallet screen finds, which is why the evidence has to travel beside the customer score rather than inside it.

Customer risk rating matrix

Country of Residence 15.0 Customer file
Nationality 15.0 Customer file
Employment Status 15.0 Customer file
Product 15.0 Institution's own product
PEP Risk 15.0 PEP screening vendor
Business Risk Assessment 8.0 Firm-wide assessment
Reputational Risk 7.0 Adverse media vendor
Customer Introduction 5.0 Onboarding channel
Tax Crime Risk 5.0 Customer file
Total 100 None of it on chain

Jurisdiction risk sub-indicators

FATF Uncooperative / AML Deficient 20.0
FATF Compliance with 40+9 Recommendations 15.0
International sanctions 15.0
US Secretary of State terrorism 10.0
Global Initiative Criminality Index 10.0
Offshore Finance Centre 10.0
US State ML Assessment 7.5
Corruption risk 7.5
Global Initiative Resilience Index 5.0
Total 100

Country indices. They grade the place, not the wallet, and chainscore.net does not supply them.

Obligation · clock · what the screen hands over

ObligationClockWhat chainscore.net contributes
Freeze on a confirmed designated-party match Within 24 hours An address designation is the account itself, so a hit is unambiguous and carries no partial-name uncertainty to resolve first. The institution freezes and notifies its supervisor.
Fund Freeze Report or Partial Name Match Report Within 5 business days The screen supplies the exhibit pack behind the match: counterparties, traced value, hop distance and the designation reference, exportable as JSON or CSV. The institution files on the regulator's platform.
Respond to an FIU request for further information Within 48 hours Stored reports re-open with their full counterparty and transfer detail intact, so the answer does not depend on re-running a screen against a chain that has moved on. The institution answers the request.
Periodic review, by risk band High annually · medium 2 years · low 3 years A re-screen returns the same scales and the same label book, so this year's result is comparable with last year's rather than merely newer. The institution sets and runs the cadence.
Retain records supporting a filing Minimum 8 years Every screen is stored with its provenance — data source, label book size and coverage — and exports as a self-contained file. The institution owns the retention schedule.

Deadline arithmetic is built in for FinCEN SAR and STR/EU AMLD filings. The UAE GoAML clocks above are stated as the obligation they are; the product does not run a countdown against them.