A compliance officer facing an examination gets one question first: show the continuous-monitoring evidence. A one-time screen at onboarding does not satisfy the FATF risk-based approach, because risk moves after the customer is onboarded. KYT compliance is the obligation to monitor on-chain transactions in real time, identify suspicious activity, apply risk-stratified disposition, and retain auditable records of every decision. This page expands the KYT compliance monitoring platform hub. It covers the obligation itself, the monitoring architecture that meets it, and the disposition model that survives examination.
What KYT Compliance Actually Means
The obligation layer sits above any single product. Under the FATF risk-based approach, a virtual asset service provider (VASP) must apply controls proportionate to on-chain risk across the transaction lifecycle, not only at onboarding. That means ongoing monitoring of counterparty risk, fund-path analysis, and suspicious-transaction identification, with records an examiner can trace. A screen run once at onboarding is customer due diligence, not ongoing monitoring, and examiners treat the gap as a finding.
Two boundaries matter. First, KYT compliance is a monitoring and recording obligation, not a definition of KYT as a product. Second, it is distinct from the FATF Travel Rule, a separate VASP obligation about transmitting originator and beneficiary information between institutions, not a monitoring function BlockSec provides. This page covers the monitoring side. For the authoritative framing, see the FATF risk-based approach guidance for virtual assets, and for the U.S. layer, money laundering obligations under U.S. law as published by FinCEN.
How Four-Layer Monitoring Meets the Obligation
Four monitoring layers translate the continuous-monitoring obligation into an operational control. Address risk flags the wallet itself, link risk traces counterparty fund sources across hops, behavior risk spots structuring anomalies, and fund-pool risk checks whether tainted value has reached the main balance. Each layer maps to a distinct question an examiner asks, and together they cover the exposure a single-point screen misses.

Address risk evaluates whether the address itself carries sanctions labels, scam tags, or mixer exposure. This is the baseline layer. Link risk goes further: it traces the counterparty's fund sources across multiple hops, not only the direct sender, so contamination two or three steps upstream still surfaces. Behavior risk looks past single addresses to related wallets and patterns such as fund splitting, rapid transit, or smurfing. Fund-pool risk then checks whether tainted value has entered the main balance, mixed with clean assets, or is about to leave through an outbound transfer.
These four layers correspond to where monitoring should run in the transaction lifecycle. The deployment points are pre-deposit, pre-sweep, pre-withdrawal, and periodic portfolio review. A screen at only one point is a one-time acceptance check, not continuous due diligence. The Phalcon Compliance capability operationalizes this: KYA screens the address, KYT screens the transaction, and Monitor enables continuous re-analysis. Once Monitor is enabled on an address, it re-runs on a dynamic schedule and notifies the team when risk changes, without consuming screening quota. Four event types drive those notifications: risk level increased, risk level decreased, alert triggered, and alert expired. That is the difference between a screen that was clean at onboarding and a control that catches the address flagged three weeks later.
| Layer | What It Evaluates | Examiner Question |
|---|---|---|
| Address risk | Wallet-level sanctions, scam, and mixer labels | Is the address itself flagged? |
| Link risk | Counterparty fund sources across multiple hops | Where did the funds originate upstream? |
| Behavior risk | Related-wallet patterns: splitting, rapid transit, smurfing | Does behavior match laundering typologies? |
| Fund-pool risk | Whether tainted value reached the main balance | Has contamination entered or is it leaving? |
Risk-Stratified Disposition and Audit Defensibility
Regulators do not expect a perfect block rate. They expect a defensible decision path: each transaction was assessed, assigned a risk level, routed to a proportionate action, and recorded with enough context to reconstruct the decision later. The disposition matrix gives compliance teams that path.

Risk levels run in six tiers, from Critical and High down to No Risk. Each organization defines the concrete meaning of each tier against its own policy and risk appetite. High risk triggers real-time interception. Medium risk routes to hold-and-review with a document request. Low risk is released with a retained record. The tiered structure is what makes the outcome explainable to an examiner, because it ties a numerical risk signal to a named action rather than an ad hoc judgment.
The alert lifecycle backs the disposition. Alerts default to Unresolved, move to Resolved when an analyst completes review, and auto-expire when the triggering rule or address state changes. Every alert carries an audit log of comments and system events, and each alert can be exported as PDF or CSV for external collaboration or archival. For suspicious activity, the platform generates a suspicious-transaction report per transfer, with a deposit or withdrawal direction specified at screening time as the prerequisite. This audit-ready alert workflow is the record examiners ask for: who reviewed what, when, against which rule, with which disposition.
| Risk Level | Default Disposition | Audit Artifact |
|---|---|---|
| Critical | Intercept | Alert + screening log |
| High | Real-time interception | Alert + screening log |
| Medium | Hold-and-review with document request | Alert + review record |
| Low | Release with retained record | Screening log |
| Informational | Release with retained record | Screening log |
| No Risk | Release | Screening log |
Default dispositions; each tier is configurable against internal policy (Phalcon Compliance Docs, Risk Levels).
Where KYT Compliance Fails, and the Fix
Most KYT compliance failures cluster in three modes. Stale intelligence misses risk changes after onboarding, cross-chain blind spots let contamination route around single-chain screening, and missing audit records leave examiners with no evidence that any review occurred. Each mode maps to a specific control gap, and each fix corresponds to a control in the monitoring architecture.

The first failure is data latency. An address cleared at onboarding can be linked to illicit activity days later. If the compliance program relies on manual re-screening, that change goes unnoticed until the next periodic review, by which point the funds may have moved on. The fix is continuous monitoring that re-runs on a dynamic schedule and pushes notifications through configured channels when risk changes. Monitor does this without consuming screening quota, billed at the monitored-address tier rather than per re-screen.
The second failure is the cross-chain blind spot. Contamination does not stay on one chain. It routes through bridges, mixers, and DeFi hops to break the trace. A single-chain screen reads the wallet as clean while the same funds are tainted three hops away on another chain. The fix is cross-chain tracing with unlimited hops, able to penetrate DeFi paths, mixers, and bridges rather than stopping at the first counterparty. For the detection-architecture side of this problem, including real-time versus batch processing and mixer modeling, see the real-time transaction risk scoring architecture page. For an operational view of how exchanges structure these controls end to end, see KYT compliance for crypto exchanges.
The third failure is the missing record. A risk decision made in a chat or a spreadsheet leaves no auditable trail. When the examiner asks for the basis of a release, there is nothing to show. The fix is an audit log that captures every team action with description, category, IP, and access time, exportable as CSV, paired with per-alert PDF exports and per-transfer STR reports. The record is the compliance artifact, not the block.
Assess Your KYT Compliance Posture
The obligation reduces to three things: monitor continuously, disposition by risk tier, and document every decision. Phalcon Compliance is built against that shape. KYA screens the address and KYT screens the transaction. The four-layer model covers address, link, behavior, and fund-pool exposure, and the six-tier disposition routes each result to an intercept, a hold-and-review, or a release with a retained record. Monitor handles the continuous re-analysis that closes the data-latency gap, and per-transfer STR export produces the audit artifact an examiner asks for.