The short answer is yes. Under the FATF risk-based approach, a virtual asset service provider must monitor transactions on an ongoing basis. It must also identify suspicious activity and keep auditable records of how it did both. KYT, or Know Your Transaction, is the on-chain control that satisfies the monitoring and identification side of that duty. This page sets out what FATF actually requires of a VASP. It also explains where the line between KYT and the Travel Rule sits, and how a KYT capability maps onto the obligation. This page is part of the KYT Resource Center.
The Short Answer: Yes, Under the FATF Risk-Based Approach
The FATF risk-based approach is the framework that pulls VASPs into the same AML discipline as traditional financial institutions. Under Recommendation 1, countries require financial institutions, including VASPs, to identify, assess, and understand their money laundering and terrorist financing risks. They must then apply measures proportionate to those risks. The duty is not a fixed checklist. It is an ongoing obligation to calibrate controls against the risk a specific VASP actually faces. For a crypto business, that means controls able to see on-chain exposure in real time.
KYT is required because FATF Recommendation 10 obliges VASPs to perform ongoing monitoring of transactions, and on-chain transaction monitoring is what KYT does. A VASP that screens wallet addresses and transaction flows against known risk is doing the work that Recommendation 10 asks for. So is a VASP that scores those flows and reviews the ones that surface. A VASP that onboards a customer and then never looks at the chain again is not, regardless of what its policy document says. The requirement attaches to the behavior, not to the label, and KYT is the label the industry uses for the behavior FATF is asking for.
What FATF Actually Requires of VASPs
FATF does not publish a paragraph that says a VASP must buy a product called KYT. It publishes recommendations that, taken together, make on-chain transaction monitoring effectively unavoidable for any VASP that takes its obligations seriously.
Recommendation 10 requires ongoing monitoring. A VASP has to keep watching transactions across the business relationship, not only at onboarding. For a crypto business, exposure can change between the moment a wallet is first screened and the moment a withdrawal lands. Ongoing monitoring therefore means a control that re-checks risk as transactions happen, not once at account opening.
Recommendation 10 sets out customer due diligence, including ongoing scrutiny of transactions to keep the understanding of the customer up to date. KYT feeds that ongoing scrutiny by surfacing the transaction-side risk that should trigger a closer look at the relationship.
Recommendation 15 requires countries to license or register VASPs and supervise them for AML compliance. In practice, that means a regulator can ask a VASP to demonstrate that its monitoring actually runs and produces records.
Recommendation 20 requires financial institutions to report suspicious transactions to the financial intelligence unit. A VASP cannot file on a transaction it never examined. The suspicious transaction reporting obligation therefore sits downstream of a monitoring control that surfaces the transaction in the first place. KYT is that upstream control.

KYT vs Travel Rule: Where the Line Is
A common source of confusion is whether the Travel Rule is part of KYT. It is not. KYT and the Travel Rule are two distinct VASP obligations that sit side by side, and conflating them distorts both.
KYT maps to FATF Recommendation 10 for ongoing monitoring and to Recommendation 11 for recordkeeping. It is about monitoring, identifying suspicious activity, and keeping auditable records of what was monitored and what was found. The output of KYT is a risk score, a disposition, and an audit trail that a regulator can read.
The Travel Rule maps to FATF Recommendation 16. It is about the transmission of originator and beneficiary information between VASPs when a virtual asset transfer takes place. The output of a Travel Rule control is a message, sent and received between institutions, carrying identifying information about the parties to a transfer.
Travel Rule is a separate VASP obligation that addresses information transmission, not transaction monitoring. KYT does not perform the Travel Rule, and the Travel Rule does not perform KYT. A VASP subject to both needs two controls, one for each obligation. Treating them as the same thing leads to one of two gaps. The first is a monitoring gap, where a VASP assumes its Travel Rule messages cover its monitoring duty. The second is a transmission gap, where a VASP assumes its monitoring covers its information-sharing duty. Neither assumption holds.
How KYT Satisfies the Obligation
A KYT capability that is going to satisfy FATF Recommendation 10 has to do four things, and each maps onto a part of the obligation.
First, ongoing monitoring. The control has to screen wallet addresses and transactions as they happen, not only at onboarding. A deposit that arrives clean at first screening can transact with a risky counterparty an hour later. A control that does not re-check on a continuous basis misses exactly the kind of risk drift that ongoing monitoring is meant to catch.
Second, explainable scoring. FATF expects a VASP to be able to explain why a transaction was treated the way it was. A risk score that arrives as a bare number is not auditable. A score is auditable when it arrives with the risk indicators behind it, the exposure figures, and the data sources those indicators draw on. A reviewer or a regulator can then follow the reasoning from score to disposition.
Third, an audit trail. Every screening, every score, and every disposition has to be recorded with enough context to reconstruct what happened and why. The same applies to every human decision on top of an alert. This is the evidence a supervisor asks for under Recommendation 15. It is also what closes the loop between a control that runs and a control that can be demonstrated to have run.
Fourth, suspicious transaction reporting readiness. The alerts a KYT control produces are the input to the suspicious transaction report obligation under Recommendation 20. Turning those alerts into a filing-ready narrative is its own discipline; see how to write a crypto SAR or STR. KYT does not file the report. The structured evidence it produces, the risk indicators, the exposure, and the timeline, is what a compliance team works from. That team uses it to decide whether a transaction rises to the level of a report.
Phalcon Compliance brings these together in one platform. It performs KYT transaction monitoring and KYA address screening. It produces explainable risk scores with the indicators behind them, and keeps the audit trail of every screening and disposition. It also supports suspicious transaction report generation on its Essential tier and above. The result is a control that maps onto the FATF obligation rather than sitting parallel to it.


What to Do Next
If you are a compliance officer asking whether your VASP needs KYT, the regulatory answer is clear. FATF Recommendation 10 obliges you to monitor transactions on an ongoing basis and identify suspicious activity, and Recommendation 11 obliges you to keep auditable records. KYT is the control that does that work on-chain. Evaluate Phalcon Compliance against the four requirements above. Those are ongoing monitoring, explainable scoring, audit trail, and STR readiness. Together they show how the platform fits the FATF risk-based approach your business is operating under.