A risk score is only useful if it drives a decision. The challenge for crypto compliance teams is not producing scores. It is building a decision framework that maps scores to consistent, defensible actions. This article covers how score tiers translate to business decisions, what a high-risk score means in financial terms, and why scores must reflect current intelligence rather than historical snapshots.
Address Risk Scoring: Outputs and Decision Triggers
Address risk scoring takes the output of a crypto address risk assessment (sanctions exposure, transaction graph signals, behavioral anomalies) and converts it into a numeric score. The score serves one purpose: enabling consistent, policy-driven decisions at scale. This scoring layer sits within a full crypto AML compliance program; for the underlying concept, see Crypto Address Risk Scoring explained.
Without a score, every address requires individual analyst judgment. That approach does not scale to thousands of transactions per day, and it produces inconsistent outcomes, with different analysts making different decisions on comparable addresses. Regulators do not accept inconsistency as a compliance posture.
With a score, compliance programs can define explicit policies: addresses above threshold X are blocked automatically, while addresses in range Y are held for review. Addresses below threshold Z are passed through with a logged screening record. The policy is consistent, documented, and defensible.
FATF's 2025 targeted update on virtual assets reinforces the expectation that crypto platforms operate risk-based compliance programs, meaning risk assessment drives decision-making, not just identity verification. (FATF Virtual Assets Targeted Update 2025) A score-based decision framework puts that principle into practice.
Risk Score Tiers and the Business Decisions They Drive

The decision framework must map each risk level to a specific action. Phalcon Compliance assigns every screened address one of five risk levels. The following tier structure reflects both the product's classification logic and established regulatory expectations across OFAC, FATF, and standard AML program design. (Compliance Handbook V3, Ch.4.5)
| Risk Level | What It Means | Recommended Action | Regulatory Basis |
|---|---|---|---|
| Critical | Highest severity. The address is blacklisted, or directly tied to an illicit entity: a sanctions (SDN) match, or a Tether freeze on the address itself. | Freeze or reject the transaction immediately | OFAC SDN match / AML law |
| High | Significant risk exposure. Indirect sanctions links, confirmed proximity to illicit activity, or strong behavioral signals. | Block pending senior review, or escalate to manual investigation with hold | FATF Recommendation 10 (PDF) |
| Medium | Moderate risk exposure. Some elevated signals, but no direct or confirmed illicit link. | Isolate and request supporting documentation (source of funds, business purpose, counterparty identity) | Risk-based AML program baseline |
| Low | Limited risk exposure. Minor or isolated signals that do not, on their own, justify blocking. | Allow the transaction with passive monitoring and a logged screening record | Standard address-screening baseline |
| No Risk | Clean address. Whitelisted, or no risk triggers of any kind. | Process normally with a logged screening record | Standard address-screening baseline |
Critical-risk addresses have direct sanctions exposure, an active USDT freeze, or a confirmed link to criminal activity. Automatic rejection or freezing is the only defensible response. Processing a transaction from a Critical address, even with a manual review note, creates regulatory liability that documentation does not mitigate.
High-risk addresses carry significant exposure that stops short of an automatic blacklist hit. The defensible response is to block the transaction pending senior review or escalate it to a documented manual investigation with a hold, rather than letting it through on an analyst note alone.
Medium-risk addresses have indirect exposure or elevated behavioral signals that do not meet the threshold for blocking. The appropriate response is to isolate the transaction and request supporting documentation from the counterparty: source of funds, business purpose, counterparty identity. This creates a documented review record while allowing legitimate transactions to proceed with additional scrutiny.
Low- and No-Risk addresses pass through with a logged screening record. The log entry is not optional. It is the evidence that screening occurred on that specific transaction. Regulators examining a compliance program want to see that every transaction was screened, not just the flagged ones.
The action mappings are configurable. Platforms operating in higher-risk jurisdictions or processing higher-risk transaction categories may apply more conservative actions to High and Medium tiers. The key requirement is that the policy is explicit, documented, and consistently applied.
This page is part of the AML Compliance Hub, which covers the full compliance stack from address screening to SAR filing.
The Real Cost of High-Risk Scores: The USDT Case
Understanding what a high-risk score means in financial outcome terms clarifies why the reject/freeze decision is not conservative. It is necessary.
What does a high-risk score ultimately mean for a USDT address? In 2025, Tether froze $1.26 billion across 4,163 addresses, and only 3.6% of those funds were ever unfrozen. A high-risk score is not a warning. It is a near-permanent financial outcome. (BlockSec USDT Blacklisting Analysis)
The 96.4% permanent freeze rate has direct implications for platforms that process transactions from high-risk USDT addresses. Any funds sent to a subsequently frozen address become inaccessible. User disputes, chargebacks, and legal claims follow. The compliance cost of processing one high-risk transaction can exceed the cost of a year of screening operations.

OFAC FAQ 561 notes that publicly listed sanctioned addresses are not intended to be exhaustive. (OFAC FAQ 561) Platforms cannot rely solely on checking the SDN list. They must screen for addresses with exposure to listed entities, which requires the graph-based assessment that risk scoring reflects.
The USDT freeze data also illustrates asymmetric regulatory risk. Platforms that process transactions from addresses that are subsequently frozen face retroactive scrutiny of why those addresses were not flagged at transaction time. Risk scoring creates the documented evidence that screening occurred and what result it produced.
The 30-Day Window: Why Scores Must Be Current
A risk score is accurate as of the moment of assessment. Its accuracy degrades as time passes, because on-chain activity continues and threat intelligence is updated continuously.

Between March 9 and April 8, 2026, Tether froze 962 addresses holding $228 million, an average of 32 new addresses per day. During the same period, 69 addresses totaling $29 million were unfrozen. These figures demonstrate that risk scores are dynamic: an address that passed screening yesterday may fail today. (Stablecoin Freeze Risk Whitepaper, Ch.1.2)
32 new high-risk addresses identified per day means that a compliance system relying on weekly batch updates misses approximately 224 newly flagged addresses between update cycles. For a platform processing high volumes of USDT transactions, each of those missed addresses represents a potential compliance exposure.
| Scoring Approach | Static (Point-in-Time) | Dynamic (Continuous) |
|---|---|---|
| Update frequency | Weekly or daily batch | Real-time or near real-time |
| Coverage of newly flagged addresses | Misses addresses flagged since last update | Captures newly flagged addresses immediately |
| Portfolio review capability | Manual re-run required | Automatic alert on address status change |
| Regulatory defensibility | Gap between screening date and freeze date | Contemporaneous record of risk status |
| Operational cost | Lower initial, higher remediation | Higher initial, lower remediation |
The operational implication is that a compliance program relying on static scoring needs to account for the addresses that will be flagged in the interval between updates. A dynamic scoring system, one that reflects current threat intelligence at the moment of each transaction, eliminates this interval risk.
Portfolio review is the complement to real-time transaction screening. An address assessed as low-risk six months ago may now carry high-risk signals due to subsequent on-chain activity or new sanctions designations. Periodic re-screening of the existing address inventory catches these changes before they create undocumented exposure—the discipline of continuous crypto address risk monitoring covers this in depth.
See how Interlace applies risk scoring in a live payment environment → see the AML Check Case Study.
Building a Decision Framework for Your Platform
A defensible risk scoring decision framework requires four components:
-
Defined risk levels with explicit action mappings for each level.
-
A documented policy that is consistently applied across every transaction.
-
A logged screening record for every transaction, including those that pass.
-
A re-screening cadence for the existing address inventory.
The first three components address the transactional compliance requirement: screening addresses before processing transactions and documenting the result. The fourth component addresses the portfolio risk that accumulates as threat intelligence updates and previously screened addresses change status.
Phalcon Compliance provides the API infrastructure for all four components. The risk score API returns a score and signal breakdown in milliseconds. The compliance dashboard provides logging and audit trail access. Alert capabilities notify compliance teams when previously screened addresses receive updated risk designations.
The decision framework is configurable to your platform's risk appetite and regulatory context. Platforms operating in higher-risk jurisdictions, or processing higher-risk transaction categories, can set more conservative thresholds. The policy is yours. The infrastructure, and the intelligence behind it, is Phalcon Compliance's.