A compliance officer onboards a customer with a verified government ID. Three weeks later, that customer's wallet receives funds from an address freshly added to a sanctions list. The onboarding file is clean. The wallet is not. This is the gap that customer address due diligence in crypto is built to close.
Traditional customer due diligence (CDD) verifies who the customer is at onboarding. Address due diligence verifies what the wallet has done and what it gets exposed to over time. In crypto, the wallet's behavior is the risk surface, because the blockchain records it permanently. This article explains how address-level CDD works, what it covers, why ongoing monitoring is required, and what regulators expect.
Traditional CDD vs. Address Due Diligence: What Changes On-Chain
Customer due diligence (CDD) confirms identity; address due diligence assesses wallet behavior. The two are complementary, not interchangeable, and crypto compliance requires both.

Traditional CDD collects documents at onboarding: a passport, a selfie, a proof of address. Once approved, the customer is presumed compliant until a trigger forces a refresh. The unit of analysis is the person.
Address due diligence inverts the unit of analysis. The object under review is the wallet address, and the evidence is its full on-chain transaction history. Where a customer can present documents selectively, the wallet cannot hide its transfers. Every deposit, counterparty, and smart-contract interaction is recorded.
| Dimension | Traditional CDD (Identity) | Address Due Diligence (On-Chain) |
|---|---|---|
| Object reviewed | Natural person or business | Wallet address |
| Evidence source | Submitted documents, registries | Public blockchain transaction history |
| Risk signal | Identity verification, PEP/sanctions name match | Counterparty exposure, fund source path, entity clustering |
| Refresh model | Periodic or event-triggered | Continuous, label updates in near real time |
| Key compliance gap | Cannot see post-onboarding wallet behavior | Cannot verify the human behind the wallet |
The two methods are complementary. Identity verification handles who the customer claims to be; address due diligence handles what their funds actually do. A platform running only traditional CDD is blind to wallet-level exposure, where the majority of illicit crypto transaction volume surfaces. For how this fits the broader AML stack exchanges run, see Crypto AML Compliance.
Risk Categories and Signals Address Due Diligence Covers
Address-level CDD evaluates a wallet against structured risk categories and produces evidence an analyst can defend. It is not a single pass-or-fail lookup; it is a multi-signal assessment that combines exposure, behavior, and provenance into one wallet risk profile. The object of the assessment is the wallet, not the human behind it.
The OFAC SDN list is the baseline U.S. reference for direct exposure. OFAC has clarified that digital currency addresses can be added directly to SDN designations (OFAC FAQ 561). A wallet does not need to be sanctioned itself to carry risk; sitting one or two hops from a designated cluster changes its profile, and the funding source path carries its own weight.
The full seventeen-indicator taxonomy that feeds this assessment, from Sanctioned to Mixing to FATF jurisdiction risk, is detailed in our address risk screening guide. Here we focus on how CDD assembles those signals into a defensible wallet risk profile.
Why One-Time Address Checks Fail
A wallet that was clean at onboarding can become high-risk overnight. Sanctions designations land at any hour, hack proceeds move through the chain in minutes, and a single new transaction can reclassify a previously benign address. A point-in-time check captures status at that moment and nothing more.

This is the structural weakness of one-time screening: it treats risk as static when it is dynamic. An address that cleared onboarding in January may, by March, have received funds from a mixer only designated in February. The original approval file still reads "clean," but the live exposure has changed.
FATF's Recommendations require ongoing due diligence on the business relationship, not only at onboarding. The FATF Virtual Assets 2025 Update reinforces that VASPs must screen transactions continuously and re-screen existing customer addresses as new information emerges. A one-time check does not satisfy this obligation.
Continuous address monitoring runs on two cadences. The first is event-triggered: when a new sanctions designation, hack incident, or illicit-fund movement touches a monitored wallet, the system re-scores immediately. The second is periodic re-review: a scheduled re-screen of the entire address book so that slow-building exposure (a counterparty drifting into a risk cluster over months) is still caught. Phalcon Compliance supports both modes, rather than treating screening as a single pass-fail event.
In one deployment, Interlace, a Hong Kong-licensed payment institution, reduced review time by 70% and blocked 99.9% of high-risk withdrawals after integrating Phalcon Compliance for continuous address-level screening (Interlace case study, BlockSec).
Regulatory Expectations for Address Due Diligence
Regulators increasingly expect address-level risk management, even when the governing rules predate crypto. The expectation spans jurisdictions.

FATF Recommendation 10 (customer due diligence) and Recommendation 15 (new technologies) jointly require VASPs to apply a risk-based approach covering both the customer and the transaction flow. In practice this means understanding not only who is onboarded but the risk profile of the wallets that customer uses. The 2025 targeted update found that of 163 jurisdictions surveyed, only a small minority were fully compliant with VASP supervision.
In the European Union, MiCA requires CASPs (crypto-asset service providers) to implement effective AML controls, which in practice includes screening customer wallets for illicit exposure. In the United States, FinCEN's BSA framework requires money services businesses to run a risk-based AML program that addresses their specific product risks. For crypto platforms, wallet-level screening is part of that program, not optional.
A common thread is that screening results must be documented, retained, and exam-ready. Address due diligence is not only a detection function; it is an audit-readiness function. Phalcon Compliance supports STR/SAR-ready reports aligned with multiple key regulatory jurisdictions and exports address-screening results in formats usable for compliance record-keeping.
| Framework | Address-Level Expectation | Practical Requirement |
|---|---|---|
| FATF Rec 10 + 15 | Risk-based CDD covering customer and transaction flow | Screen customer wallets for illicit exposure; document risk decisions |
| EU MiCA | CASP AML controls for crypto-asset transactions | Pre-transaction wallet screening; ongoing monitoring |
| U.S. FinCEN BSA | Risk-based AML program for MSBs | Wallet-level screening integrated into the AML program; SAR on detected activity |
| OFAC SDN | No transactions with designated parties, including addresses | Screen against SDN list including digital currency identifiers; block and report matches |
For compliance teams operationalizing these obligations, Phalcon Compliance's address-level (KYA) and transaction-level (KYT) modules provide the two screening layers. The full platform is at Phalcon Compliance.
ā Book a Phalcon Compliance demo and run address due diligence across your customer wallet flows: Book a demo
Frequently Asked Questions
Is customer address due diligence the same as KYC?
No. KYC verifies the identity of the person behind the account at onboarding using government-issued documents. Address due diligence assesses the risk profile of the wallet itself, based on on-chain transaction history and counterparty exposure. They are complementary: KYC answers "who is this person," address due diligence answers "what does this wallet do." BlockSec's products cover the address and transaction layers (KYA and KYT), not identity verification.
What signals make a crypto address high-risk?
Direct exposure to sanctioned entities or SDN-listed addresses, transaction history with documented illicit clusters (phishing, pig-butchering, hacker-attack-linked wallets, drainer contracts, mixers), and proximity to terrorist-financing clusters. Behavioral patterns also count, such as rapid hop-through layering or peel-chain structuring. Phalcon Compliance's risk taxonomy spans more than 200 signal types (Phalcon Compliance Docs).
How often should existing customer addresses be re-screened?
Continuously, not on a fixed schedule alone. Sanctions designations and hack incidents land at any time and can reclassify a previously clean address. Best practice combines event-triggered re-scoring with periodic full re-screening of the address book. FATF's ongoing-due-diligence requirement is not satisfied by a one-time onboarding check.
Does address due diligence apply to self-custody wallets?
Yes, where a regulated platform interacts with them. When a customer withdraws to or deposits from a self-custody wallet, the platform still needs the risk profile of that address. On-chain history is independent of who controls the keys. MiCA and FATF guidance both contemplate screening counterparty wallets, even when the counterparty is the customer's own self-custody address.



