Background Base

Article

Agent Compliance Series III | Compliance Decisions

From risk leads to reviewable action: how AI agents can support AML case management.

August 24, 20269 min read
Agent Compliance Series III | Compliance Decisions

From risk leads to reviewable action: how AI agents can support AML case management.

The first two articles in this series moved the question from "is there an alert?" to "does this fund relationship actually transmit risk?"

But in day-to-day compliance operations, an investigative conclusion is not the end of the job. Even after an analyst determines that a customer address has meaningful indirect exposure, the team still has to decide what to do next: should the case jump the queue, should withdrawals be restricted, should enhanced due diligence be requested, should the case be escalated to the MLRO or compliance lead, and what needs to be monitored if the transaction is allowed?

This article focuses on that operational layer. The point is not to let an AI agent freeze, reject, or report on behalf of an institution. The point is to turn risk leads into an executable, reviewable, and auditable case workflow.

1. AML cases usually suffer from scattered information, not too little information

Consider a public enforcement example.

In April 2022, OFAC sanctioned the Russia-based darknet market Hydra and the virtual currency exchange Garantex. The U.S. Treasury stated that German law enforcement shut down Hydra servers and seized approximately $25 million in bitcoin. OFAC also identified multiple digital currency addresses linked to Hydra and Garantex. The U.S. Department of Justice stated that Hydra had received approximately $5.2 billion in cryptocurrency since 2015 and accounted for an estimated 80% of darknet market-related cryptocurrency transactions in 2021.

Once this kind of information enters an institution's monitoring environment, the real question is no longer just "is there a high-risk label?"

If a platform detects that a customer's deposit has upstream exposure to Hydra- or Garantex-related addresses, case intake cannot stop at "high-risk entity hit." It needs to put several facts into one view: which public identifier was matched, how many hops away it is from the customer transaction, whether the intermediate node is an exchange hot wallet or public infrastructure, whether the amount remains continuous through the path, whether the customer is trying to withdraw immediately, and whether the customer's historical behavior supports the stated transaction purpose.

Many compliance teams are not slowed down because they lack tools. They are slowed down because relevant facts are spread across KYT systems, customer records, trading back offices, risk platforms, case systems, block explorers, and internal policy documents. Analysts often spend more time assembling context than making the actual judgment.

At this stage, the most practical role of an agent is not to jump to a conclusion. It is to complete the case background.

Figure 1. AML case flow from lead to action

2. The first step is triage, not a full investigation

Not every alert deserves the same speed, depth, or level of human review. If every alert goes through a full fund-flow investigation, teams quickly get buried under low-quality work.

A better order of operations is triage: should this case be handled immediately, sent for enhanced review, placed in a normal queue, or logged for monitoring?

Tornado Cash is a useful example. In August 2022, OFAC sanctioned the virtual currency mixer and stated that it had been used to launder more than $7 billion worth of virtual currency since its creation in 2019, including funds associated with Lazarus Group, the Harmony Bridge exploit, and the Nomad heist.

If customer funds come directly from a sanctioned mixer address and the customer is trying to withdraw, the case should not sit in the same queue as a distant, weak exposure. It needs higher priority, immediate review, and potentially temporary transaction restriction. By contrast, if the apparent exposure only appears several hops away through a public DEX pool, an exchange hot wallet, or other infrastructure node, and there is no fast cash-out behavior, it should not be treated as equivalent to a direct sanctions hit.

That is the value of triage. It does not replace investigation. It makes sure limited human attention goes to the cases most likely to create real loss or regulatory risk.

Figure 2. AML case triage

3. A review pack matters more than an AI summary

Many discussions about AI agents focus on automatic summaries. In AML, a summary is only useful if it can be reviewed.

What reviewers need is an investigation package: a case record that organizes the evidence behind the judgment. It should not dump every transaction into the case. It should surface the facts that matter: case basics, trigger rules, key transactions, fund path, relationship assessment, customer context, evidence links, open uncertainties, and recommended action.

Using Hydra, Garantex, or Tornado Cash as reference cases, a usable review pack should answer several practical questions in one place. Is the customer exposure close to a known high-risk source, or only a weak distant link? Is the intermediate node a user wallet, an exchange-controlled address, public infrastructure, or a short-lived pass-through address? Did the amount remain continuous, or was it split, swapped, or mixed? Has the customer shown similar deposit-and-withdraw behavior before? If withdrawals are restricted, is the evidence strong enough to support that action? If EDD is requested, what documents or explanations are actually needed?

The most overlooked part is uncertainty. Many systems prefer to output a confident conclusion, but a reviewer needs to know which parts are evidenced, which parts are inferred, and which relationships may be noise.

If an agent only writes "recommend enhanced due diligence," the analyst still has to re-check the work. A useful agent prepares the case so that the reviewer can see the evidence, the reasoning, the gaps, and the next action without rebuilding the investigation from scratch.

Figure 3. Investigation review pack

4. Action is not binary. It is a decision matrix

AML decisions are rarely just "allow" or "block."

Institutions usually have a wider set of actions: allow with a recorded rationale, allow with ongoing monitoring, request enhanced due diligence, temporarily restrict withdrawal, escalate for human review, freeze or reject a transaction, or enter a SAR/STR-related process. Each action should correspond to a different level of risk, evidence, and business impact.

In a real case context, if the customer exposure is only a distant link through a public liquidity pool, the customer history is stable, and there is no outbound pressure, logging and monitoring may be appropriate. If funds have close exposure to Hydra, Tornado Cash, or an exchange that has been subject to enforcement action, and the customer is trying to withdraw quickly, the case may require enhanced investigation or temporary restriction. If there is a direct match to a sanctions identifier or a clearly designated high-risk actor, the case must enter a higher-level internal process.

The agent should not make the final decision for the institution. But it can make the reason for the recommended action clear.

A weak output says:

Recommend restricting withdrawal.

A better case record says:

The customer's deposit has close exposure to virtual asset services or mixer addresses publicly identified by OFAC. The path includes short-lived pass-through nodes, and the customer initiated a withdrawal shortly after deposit. Under internal policy, this case fits a "strong exposure + fast cash-out" scenario. Recommended action: temporarily restrict withdrawal and escalate for human review.

That is the kind of content that belongs in a case record. It leaves behind the evidence chain, the basis for judgment, and the proposed action.

Figure 4. Decision matrix

5. Human review is not a slogan. It defines accountability

In AML, human-in-the-loop should not be a decorative phrase in a product deck. It defines the accountability boundary.

An agent can prepare evidence, map policy, draft recommendations, and organize records. But actions such as freezing or restricting customer assets, rejecting transactions or terminating service, filing SAR/STR reports, changing customer risk ratings, initiating EDD, or escalating to legal and management teams should remain with authorized compliance personnel.

The reason is straightforward: these actions affect customer rights and create legal, regulatory, and institutional responsibility.

FinCEN's guidance on money services business suspicious activity reporting states that certain MSBs must report suspicious activity when the relevant conditions are met and that SARs are filed through the BSA E-Filing System. FinCEN also emphasizes that SAR supporting documentation must be retained and made available to appropriate authorities upon request. Requirements vary across jurisdictions, but the common point is the same: compliance decisions must be traceable.

An agent's output should therefore leave more than "the model rated this case high risk." It should record where the evidence came from, which rules were triggered, what remains uncertain, who made the final decision, when the action was taken, and what follow-up monitoring is required.

For compliance teams, reviewability matters more than automation.

6. The case is not over after the action

Many AML workflows treat the action as the end of the case. In crypto, risk often continues after the initial action.

Garantex provides a useful example. In 2025, OFAC took further action against a network involving Grinex and entities connected to the A7A5 stablecoin. Treasury stated that after enforcement action against Garantex in March 2025, related actors attempted to continue operations through Grinex and other arrangements, including moving customer deposits to new infrastructure.

That means a case does not naturally end just because an address is labeled, a platform is sanctioned, or a transaction is restricted. Risk actors may move to new domains, new platforms, new addresses, new assets, or new settlement routes.

For institutions, post-decision monitoring should continue to ask: do related addresses interact with new risk infrastructure, have linked entities changed operating patterns, is the customer moving through other assets or chains, and should historical cases be reviewed because of a new designation, announcement, or label?

An agent can support this work in very concrete ways: append newly discovered addresses, entities, and public notices to the original case; remind analysts to re-check historical exposure; feed repeated patterns back into monitoring rules; and record why a closed case was reopened.

This is the difference between a system that handles alerts one by one and a system that compounds institutional risk knowledge over time.

7. In product terms, agents should do less storytelling and more operational work

If Agent Compliance becomes a feature that only writes polished summaries, compliance teams will lose patience quickly. The real time savings come from the work analysts repeat every day but cannot skip.

When a case enters the workflow, the system should first bring address screening, transaction paths, entity labels, customer records, historical behavior, and triggered rules into one workspace. It should then separate obvious noise from relationships that need review. Finally, it should produce an editable review pack rather than an untraceable narrative.

In ChainTrust's product design, this breaks down into practical steps. CT Check screens addresses and entities. CT Monitor attaches new transactions and risk changes back to the case. CT Probe reconstructs paths and assesses relationship quality. CT Assess puts on-chain evidence back into the customer's risk profile, business context, and institutional policy. CT Data provides the underlying labels, entity relationships, and evidence sources.

The purpose is not to make analysts look at less evidence. It is to make them spend less time hunting for it.

Conclusion: from lead to action

Next-generation AML systems should not stop at finding risk, and they should not stop at drawing fund paths. They also need to help institutions answer a more operational question: what should we do now?

That question cannot be answered by a model alone. It requires on-chain evidence, customer context, institutional policy, regulatory requirements, and human review.

The real change brought by AI agents is not who makes the final decision. It is whether the institution can see the evidence more quickly, more clearly, and more consistently before a decision is made: which cases deserve priority, which evidence supports action, which actions require human confirmation, which risks need follow-up monitoring, and which records can stand up to review.

From risk leads to compliance decisions, the goal is not to make action look more automated. It is to make every action defensible.

ChainTrust Labs

Learn more about ChainTrust KYT, on-chain risk monitoring, and investigation products:

https://chaintrustlabs.com/

References

[1] U.S. Department of the Treasury / OFAC | Treasury Sanctions Russia-Based Hydra and Garantex | 2022

[2] U.S. Department of Justice | Justice Department Investigation Leads to Shutdown of Hydra Market | 2022

[3] U.S. Department of the Treasury / OFAC | U.S. Treasury Sanctions Tornado Cash | 2022

[4] U.S. Department of the Treasury / OFAC | Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals | 2025

[5] FATF | Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers | 2021

[6] FATF | Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing | 2020

[7] FinCEN | Money Services Business Suspicious Activity Reporting

[8] FinCEN | Suspicious Activity Report Supporting Documentation | 2007

[9] OFAC | A Framework for OFAC Compliance Commitments | 2019

[10] ChainTrust official website