A suspicious deposit lands in a platform wallet at 03:14. The funds arrived through two hops from an address linked to a mixer. The compliance team has minutes before the value moves again, splits across sub-wallets, or leaves the chain. Identity checks at onboarding already passed. What was missing was a screen on the transaction itself. Know Your Transaction, or KYT, is that screen. It evaluates the AML and CFT risk of an on-chain transaction at the moment it enters or leaves a platform, so a compliance officer can act inside that narrow window.
What KYT Actually Means in Crypto
Know Your Transaction is the transaction-level AML and CFT risk screen. It evaluates each token movement inside a transaction, traces where funds came from and where they go, and assigns a risk level the team can act on. KYT does not verify who the customer is. It verifies what the transaction does.

The minimum screening unit is a single transfer. A transaction can carry several token transfers, and each one is assessed separately, so a multi-transfer transaction does not get one averaged score that hides a contaminated leg. Direction controls what the screen traces. A Deposit direction tracks the inflow and follows the money back to its source. A Withdrawal direction tracks the outflow and follows the money toward its destination. When no direction is set, both are screened by default.
Two risk types cover the threat surface. Exposure risk asks what the target is and who it interacts with. It checks whether an address or its counterparties carry risk labels such as Sanctioned, Scam, or Mixing, and whether funds connect directly or indirectly to known illicit entities. Behavioral risk asks how the money moves. It spots suspicious flow patterns such as large-value transfers, high-frequency small payments, rapid transit through intermediary addresses, and smurfing. These patterns are the standard signals of layering.
Every screened transfer lands in one of six risk levels, from Critical down through High, Medium, Low, and Informational to No Risk. Each organization defines what each tier means against its own policy. Seventeen risk indicators, from Sanctioned and Terrorist Financing to Mixing and FATF Grey List Jurisdiction, feed those levels. The output is a risk score a compliance team can route to an action, not just an alert.
KYT vs KYA vs KYC: Three Screens, Three Objects
Compliance officers new to crypto often conflate three screens that share a prefix but answer different questions. KYC verifies the person. KYA screens the address. KYT screens the transaction. Each runs at a different moment, reads different data, and catches a different threat.
| Dimension | KYC | KYA | KYT |
|---|---|---|---|
| Object | Natural person or entity | Wallet address | On-chain transaction (transfer level) |
| Trigger | Onboarding or periodic review | Before or after address interaction | When a transaction lands (deposit or withdrawal) |
| Data source | Identity documents and CDD files | Address labels and interaction graph | Transaction fund flow and behavior patterns |
| Threat detected | Identity fraud, impersonation | Sanctioned, scam, or mixer addresses | Layering, rapid transit, sanctions exposure |

KYC is a customer due diligence control. It confirms who the customer claims to be. It does not see the transaction. KYA is an address-level screen. It evaluates the risk of a wallet itself, using labels and the interaction graph around it. KYT goes one layer deeper. It evaluates the actual movement of value, transfer by transfer, and follows the fund path in the direction that matters for the control point.
The three are complements, not substitutes. A platform can verify every customer at onboarding and still process a deposit whose funds originated at a mixer three hops upstream, because KYC never looked at the transaction. Pairing an address screen with a transaction screen closes that gap. For a definitional walkthrough of the address side, see the Know Your Address (KYA) guide.
Why VASPs Need KYT
Under the FATF risk-based approach, a VASP must monitor transactions in real time, identify suspicious activity, apply risk-based disposition, and retain auditable records. KYT is the control that meets each of those four obligations at the transaction level, from the transfer screen through to the exported report.

The obligation is continuous, not one-time. A screen run at onboarding is customer due diligence. Examiners treat the absence of ongoing monitoring as a finding, because risk moves after the customer is onboarded. An address cleared on Monday can be linked to illicit activity by Thursday, and a Friday deposit can carry funds that were clean three hops back and contaminated at the source.
Phalcon Compliance's KYT maps to those obligations directly. Transfer-level screening evaluates each token movement, and Direction-based tracing follows the inflow to its source or the outflow to its destination. The Exposure Risk Engine works through Participant, Interaction, and Blacklist Interaction rules, using the seventeen risk indicators as its label set. On the transaction side, the Behavioral Risk Engine flags Large-Value Transfers and Rapid Transit templates—catching layering and rapid fund movement that an address-only screen misses.
Consider a deposit that lands at 03:14. KYT screens the transfer and traces the inflow. The Interaction Risk rule finds that funds two hops upstream passed through a mixer. The transfer is assigned a High risk level, an alert fires, and the team is notified through one of seven channels such as Telegram, email, or Slack. The analyst confirms the exposure and exports a suspicious transaction report for that transfer with the deposit direction specified at screening time. That STR is aligned with major regulatory jurisdictions and can be exported through a region-specific template for direct filing. The record is the compliance artifact, not the block.
This is where definition meets deployment. The transfer is the unit. Direction is the lens. The dual risk engines are the detection. The alert and the STR export are the evidence. For the regulatory source of the VASP monitoring obligation, see the FATF guidance on virtual assets.
Take KYT From Definition to Deployment
Definition is the entry point, not the destination. Once a compliance team can name what KYT screens and how it differs from KYA and KYC, the next question is deployment. How do those controls run across a real transaction lifecycle? That deeper read lives on the crypto compliance platform hub, where the KYT main line covers deployment points, cross-chain tracing, and platform selection.
→ Book a Phalcon Compliance demo and see KYT screen every transfer in your transaction lifecycle: Book a demo
Frequently Asked Questions
Does KYT replace KYC?
No. KYC verifies customer identity at onboarding. KYT screens transactions in real time. A platform needs both, at different layers and different triggers, because identity verification does not see the fund flow.
What is the minimum screening unit in KYT?
A single transfer. One transaction can contain several token transfers, and each is assessed separately, so a contaminated leg inside a multi-transfer transaction cannot hide behind an average score.
How does Direction affect KYT screening?
Direction decides what the screen traces. Deposit tracks the inflow and follows funds back to their source. Withdrawal tracks the outflow and follows funds toward their destination. Unspecified direction defaults to screening both.
Which risk types does KYT evaluate?
Two. Exposure risk checks what the target is and who it interacts with, using labels such as Sanctioned, Scam, and Mixing. Behavioral risk checks how the money moves, spotting layering patterns like large-value transfers, high-frequency payments, and rapid transit.
Can KYT catch a risk that appears after the deposit was processed?
KYT screens at the control point in real time. For risk that emerges later on an already-screened address, continuous monitoring re-runs on a dynamic schedule and notifies the team when the risk level changes or a new alert triggers.



