Know Your Address (KYA): The Address-Layer Risk Screen Beneath Identity Verification

AMLComplianceKYA
July 27, 2026
4 min read

A sanctioned actor can transact through a freshly generated address that has no identity attached. Identity verification screens the person; the address keeps moving. Know Your Address (KYA) screens the blockchain address itself against risk intelligence before a transaction is processed. It is the only control that catches wallet-level risk when no customer identity is in the loop. This page is part of the AML Compliance Hub and defines what KYA is and where it sits; for the deployment framework and the cost side, see the linked pages below.

Know Your Address, Definition and Core Function

KYA evaluates a blockchain address on its own merits. An address is a public key with no inherent identity, but it has a transaction history, counterparty relationships, and behavioral patterns, all observable on-chain, all carrying compliance-relevant information.

In practice, KYA answers three questions before a transaction clears. Has this address transacted with sanctioned entities? Has it received funds from known scam wallets, darknet markets, or ransomware operators? Does its behavior (frequency, velocity, counterparty mix) resemble known laundering activity? This address-layer screen is one control within a full crypto AML compliance program, and it catches four categories of risk that an identity check has no signal for:

  1. Illicit fund origin: addresses that received funds from known criminal operations, regardless of who controls the address now.

  2. Mixer / obfuscation exposure: addresses that interacted with mixing services, suggesting deliberate origin-hiding.

  3. Counterparty risk: addresses with high-risk counterparties in their transaction graph, even when the address itself is unflagged.

  4. Behavioral anomaly: addresses whose velocity, cross-chain activity, or layering signatures match known laundering methodologies.

KYA does not replace identity verification where that is legally required; it operates at a different layer and catches what identity processes cannot see.

KYA vs Traditional Identity Verification, Why Address Screening Fills the Gap

Infographic comparing KYA address screening and identity checks

Traditional identity verification establishes who a person is: it matches a presented document to a person, verifies liveness, and records the result. It does not evaluate the blockchain addresses that person will use. KYA evaluates what an address has done, not who controls it. The two are complementary, but they catch different risks.

Dimension Identity verification KYA (address screening)
Object of check Person / legal entity Blockchain address
Trigger timing Account opening (one-time or periodic) Every transaction (real-time)
Data sources Government ID, biometrics, sanctions lists On-chain history, counterparty graph, behavior models
Detectable threats Sanctioned individuals, PEPs Illicit fund flows, mixer exposure, scam-wallet links
Regulatory mapping FATF Recommendation 10 (CDD) FATF Recommendation 16 (Travel Rule)

The critical gap: a user who passes identity checks at onboarding can then move funds through addresses with significant illicit exposure. The identity check never flags this; the address check does. That gap is widest in high-velocity environments (payment platforms, DeFi protocols, high-withdrawal exchanges), where the risk is not who is on the platform but what funds move through it. Pig-butchering and human-trafficking proceeds, for instance, flow through wallet clusters that are identifiable on-chain even when the controlling identity is fabricated.

Phalcon Compliance KYA address screening interface

KYA Screening Workflow, From Address Input to Risk Decision

At the concept level, a KYA screen runs a short pipeline: address input → label and sanctions matching → counterparty-graph and behavioral analysis → risk decision (clear / enhanced review / block). The result typically returns in seconds. The output is not a binary pass/fail but a tiered signal a compliance analyst can act on and document.

KYA workflow from wallet input to risk decision

Where to run that screen across the transaction lifecycle (pre-deposit, pre-sweep, pre-withdrawal, and portfolio review) is a deployment question with its own framework. This page keeps to the concept; for the four-control-point deployment model and how each point maps to a specific exposure, see Crypto AML Address Screening. Partners such as Cobo, a digital-asset custody platform that co-built cross-border payment security with BlockSec, have wired KYA into that lifecycle to screen high-risk transfers before they settle.

Regulatory Foundations for KYA in VASP Compliance

Regulators increasingly treat transaction monitoring (not just onboarding identity checks) as a required element of a crypto compliance program. FATF's risk-based approach expects controls proportionate to on-chain risk across the transaction lifecycle (FATF Recommendations), and FinCEN's suspicious-activity framework requires money services businesses to detect and report illicit activity. KYA is the address-level mechanism for meeting both. It produces timestamped, address-level screening records tied to specific transactions, exactly the audit trail examinations expect, and it maps to the common requirements across FATF-aligned regimes, which matters for platforms operating across multiple jurisdictions.

Phalcon Compliance KYA, Real-Time Address Risk Screening

Manual address review does not scale: a platform clearing thousands of transactions a day cannot hand-check each address against current sanctions lists and behavioral signals. Automated KYA at millisecond response times is the only architecture that keeps coverage while scaling with volume.

Frequently Asked Questions

Upgrade Your Crypto Compliance Architecture

Transition from traditional identity verification to proactive address-based risk management; master the core strategies and technologies for crypto AML.