Background Base

Article

Agent Compliance Series I | From Alert to Investigation

Why next-generation AML infrastructure needs to move from detecting risk to understanding risk.

August 4, 202613 min read
Agent Compliance Series I | From Alert to Investigation

Why next-generation AML infrastructure needs to move from detecting risk to understanding risk.

Over the past few years, compliance systems in the crypto industry have become increasingly mature.

Address screening, transaction monitoring, sanctions list matching, and risk scoring have become baseline capabilities for exchanges, wallets, custodians, and payment service providers.

When a transaction occurs, the system can quickly tell a compliance team:

  • whether an address matches a high-risk label;
  • whether the transaction triggered a rule;
  • whether there is exposure to sanctions, scams, mixers, darknet markets, or other risk categories.

But what consumes most of a compliance team's time is often not whether the system raised an alert. It is what happens after the alert.

An alert can tell you:

There may be risk here.

What compliance teams actually need to answer is different:

  • Why did the risk appear?
  • Where did the funds come from, and where did they go?
  • Is there direct or indirect sanctions exposure?
  • Do these wallets belong to the same entity or network?
  • Should the case lead to freezing, enhanced due diligence, escalation, or suspicious activity reporting?

This is one of the most underestimated parts of crypto AML workflows:

moving from a risk alert to an explainable and actionable investigation outcome.

Alerts can be generated automatically. But moving from "seeing risk" to "explaining risk" still requires substantial human judgment. In many cases, the real work starts only after the alert appears.

1. The real challenge in AML is not detecting anomalies

Assume a trading platform receives an unusual USDT deposit:

  • Wallet A receives 500,000 USDT and then sends funds into a platform deposit address.
  • The monitoring system triggers a high-risk alert.

For a compliance analyst, this is only the beginning.

The next step is to open block explorers, review upstream sources of funds, determine whether intermediary wallets are merely pass-through addresses, check whether cross-chain bridges, DEXs, mixers, or high-risk OTC services are involved, and assess whether the wallet belongs to a broader cluster controlled by the same entity.

If the fund path is simple, the investigation may take tens of minutes.

If the path spans multiple chains, assets, and hops, the investigation can quickly become complex.

For example:

High-risk wallet -> intermediary wallet -> cross-chain bridge -> new-chain address -> DEX -> stablecoin -> exchange deposit address

With every additional hop, analysts need to reassess:

  • whether this step changes the nature of the risk;
  • whether funds were split or consolidated;
  • whether the behavior suggests an attempt to avoid monitoring;
  • whether the final recipient is still connected to the original risk source.

This is why, in many institutions, a risk alert may be generated in seconds, while a full investigation can take hours.

AML Workflow: From Alert to Investigation Outcome

2. Risk is moving from "address" to "network"

Early on-chain compliance was closer to an "address matching" problem.

Is address A on a blacklist? Has address B transacted with a scam address? Does address C match a high-risk label?

This capability remains important, but it is no longer enough.

Regulatory developments are also pushing the industry in this direction. In its 2025 update on virtual assets and VASPs, FATF noted that 99 jurisdictions had passed or were in the process of passing Travel Rule legislation. FATF also stated that the jurisdictions it prioritizes for material VASP activity cover approximately 98% of the global virtual asset market. In other words, on-chain compliance is no longer only an internal risk-control preference for a small group of institutions. It is becoming a foundational requirement within an increasingly global regulatory framework.

Today's risk actors rarely rely on a single address. Many high-risk networks move funds through multiple wallets, entities, service providers, and even jurisdictions.

Public enforcement actions illustrate this shift.

On July 24, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) expanded sanctions against a network related to Babak Zanjani, designating 4 individuals and 9 entities. According to Treasury, the network involved financial services, gold and precious metals, digital asset exchange activities, transportation, and infrastructure. Some related companies were also described as providing support to previously sanctioned digital asset exchange projects.

This was not merely an isolated address-level blocking action. OFAC had already acted against Zanjani and two digital asset exchange projects on January 30, 2026. The July follow-on action pointed further toward companies, managers, payment infrastructure, and cross-border settlement capabilities behind the network.

The key lesson is not simply that a specific address was sanctioned. It is that risk can be hidden across a group of companies, wallets, transaction paths, and business relationships.

From public sanctions materials, risk is often not a single point. It is a set of relationships: individuals, management teams, companies, payment services, digital asset trading platforms, wallet clusters, and cross-border settlement routes can all form one risk network.

Therefore, investigators are not only asking whether a transaction passed through a certain address. They are asking whether it entered the same risk network.

From Address Risk to Network Risk

For VASPs, trading platforms, and payment institutions, this changes the compliance question.

The old question was:

Does this address have risk?

The new question is:

What is the relationship between this address and the broader risk network?

The difference is not only the amount of data involved. It is the level of investigative capability required.

3. Stablecoins and unhosted wallets make investigations more complex

Another change comes from stablecoins.

In its 2026 targeted report on stablecoins and unhosted wallets, FATF noted that stablecoins, due to price stability, high liquidity, and cross-platform interoperability, support many legitimate use cases but can also be misused by criminals, terrorist financiers, and state-sponsored cybercriminal networks.

The report also provided important context: by mid-2025, there were more than 250 stablecoins in the market, with a total market capitalization of more than USD 300 billion. FATF also noted that P2P transfers and unhosted wallets can allow funds to move outside regulated intermediaries, creating additional challenges for tracing, freezing, and cross-border cooperation.

The significance of these numbers is not simply that the stablecoin market has grown. It is that stablecoins are becoming a settlement layer for on-chain funds. Once funds move across multiple chains, stablecoin assets, custodial platforms, and unhosted wallets, a single-address, single-chain, single-rule view can break down.

This aligns with what frontline compliance teams experience.

Stablecoins make fund movement faster and more global. They also introduce new investigative challenges:

  • funds can move across chains, causing a single-chain view to fragment;
  • P2P transfers between unhosted wallets may not pass through regulated intermediaries;
  • high-risk funds can reduce surface-level links through multiple hops;
  • risk can shift between on-chain activity, off-chain context, and different service providers.

FATF has also emphasized that supervisors and law enforcement agencies need technical capabilities to understand smart contract functions, cross-chain transaction mechanisms, blockchain analytics tools, and P2P transaction risks.

This shows that the core capability in crypto AML is moving from simple rule matching toward continuous and dynamic risk understanding.

4. Why manual investigations slow down

Many compliance teams do not lack data.

Their problem is the opposite: too much data, too many systems, and too much friction in turning fragmented evidence into a decision.

The external risk environment is also growing. In its 2024 Internet Crime Report, the FBI Internet Crime Complaint Center (IC3) reported more than 149,000 cryptocurrency-related complaints from the U.S. public, with reported losses exceeding USD 9.3 billion. This is a U.S. complaint-based metric, not a measure of global on-chain illicit finance. But it is enough to show that crypto-related risk has become a high-frequency, cross-platform, and multi-entity investigation challenge.

When an analyst faces a risk alert, they typically need to complete three types of work.

4.1 Reconstruct the fund path

Where did the funds come from? Which intermediary addresses did they pass through? Were they split? Were they consolidated again? Did they move across chains?

This may look like checking transaction records, but in practice it is closer to reconstructing a story.

4.2 Determine entity relationships

Are these addresses related? Do they belong to the same wallet cluster? Are they connected to a known service, organization, or risk event?

Without entity relationships, on-chain transactions are just points and lines. With entity relationships, analysts can begin to understand who may be transferring funds and why.

4.3 Document a reviewable judgment

The end product of an investigation is not a simple "high risk" label. It is a record that another person can review.

Analysts often need to explain which transactions matter most, whether the risk is a direct hit or indirect exposure, whether intermediary addresses are ordinary pass-through wallets, whether there are signs of splitting, consolidation, cross-chain movement, or rapid outbound transfers, and why the recommended action is to allow, apply enhanced due diligence, restrict activity, or escalate the case.

This work is often underestimated. It is not merely report writing. It is the process of turning scattered evidence into a clear investigative thread.

5. AI Agents are not chatbots. They are investigation collaboration layers.

In AML, an AI Agent should not be understood as a tool that simply writes a few summary paragraphs.

It is better understood as an investigation collaboration layer. It takes information scattered across on-chain transactions, address labels, entity relationships, risk rules, and external intelligence, and organizes it into leads that analysts can review and judge.

Why does this matter now? One direct reason is that stablecoins and P2P activity are widening the investigative surface of on-chain AML. As FATF noted in its 2026 report on stablecoins and unhosted wallets, by mid-2025 the market already included more than 250 stablecoins with a total market capitalization above USD 300 billion. At the same time, P2P transfers between unhosted wallets may bypass regulated intermediaries and make tracing, freezing, and cross-border cooperation more difficult.

In these scenarios, compliance teams are often not asking whether a single address matches a label. They are asking more specific questions:

  • Did the funds pass through a bridge or DEX?
  • Is the intermediary wallet merely a pass-through address?
  • Were stablecoins rapidly split or consolidated?
  • Is the relationship with a known risk network direct, indirect, or behavioral?

A valuable AI Agent should work around these questions instead of generating generic summaries.

AI Investigation Agent: From Alert to Investigative Leads

When an alert enters the investigation queue, the system should help analysts clarify several questions first: where funds came from, which addresses they passed through, whether there was splitting, consolidation, or cross-chain movement, whether the risk is a direct hit or indirect exposure, and which transactions, addresses, and timestamps support that judgment.

Whether to allow, restrict, apply enhanced due diligence, or escalate the case should still be decided by analysts based on customer context, business scenario, and institutional policy.

At minimum, this type of agent needs three capabilities.

5.1 Understand transaction context

A transfer is not only "Address A sent 500,000 USDT to Address B."

It also has time, amount, asset type, address history, transaction frequency, counterparty relationships, and business context.

The first step for an AI Agent is to place a transaction back into its full context instead of treating it as an isolated event.

5.2 Automatically trace fund paths

If funds pass through multiple intermediary addresses, cross-chain bridges, or DEXs, manual investigation can be time-consuming.

An AI Agent can help analysts quickly reconstruct fund flows, highlight key paths and high-risk nodes, and allow investigators to spend more time on judgment rather than repeated clicking and manual organization.

5.3 Generate explainable risk narratives

For a compliance team, a simple "High Risk" label is not enough.

What is more useful is an explanation such as:

Although this address does not directly match a sanctions list, its upstream funds are connected within three hops to a known high-risk network. After passing through multiple intermediary addresses, the funds entered an exchange deposit address, suggesting an attempt to reduce direct exposure. Enhanced due diligence and ongoing monitoring are recommended.

This type of explanation is the investigation outcome compliance teams actually need.

6. AI will not replace AML analysts

In many discussions, AI is framed as a replacement for people.

In a high-responsibility domain like AML, the more realistic direction is augmentation, not replacement.

AI can help with:

  • transaction path organization;
  • address relationship analysis;
  • risk signal aggregation;
  • preliminary investigation summaries.

But whether to freeze an account, reject a transaction, escalate a case, or submit a report still requires human analysts to make a final judgment based on business context and regulatory requirements.

The future of efficient compliance teams may not be larger teams. It may be teams equipped with better investigation tools.

7. ChainTrust is building AI-native crypto compliance intelligence

At ChainTrust, we believe the core of next-generation crypto compliance products is not simply adding another risk score for analysts. It is connecting screening, monitoring, assessment, and investigation into an executable workflow.

This is why ChainTrust continues to invest in on-chain risk data, entity relationship identification, and AI-driven investigation capabilities. For frontline compliance teams, the value of tooling should not stop at "flagging risk." It should help them answer, faster and with more evidence: where the risk came from, whether the evidence is sufficient, and what should be done next.

Different ChainTrust products support different stages of this workflow.

CT Check: the screening entry point before risk materializes

CT Check helps institutions screen address and entity risk, identify sanctions exposure, high-risk categories, and suspicious associations.

It answers:

Does this address have known risk?

CT Monitor: continuous monitoring as risk changes

CT Monitor helps institutions continuously monitor transaction behavior and changes in risk exposure. On-chain risk is not static. A wallet that appears low-risk today may change tomorrow due to new transactions, counterparties, or sources of funds.

It answers:

Is the risk of this address or transaction changing?

CT Assess: putting risk back into business context

CT Assess is closer to an institution's internal risk assessment process. It does not only ask whether an address matches a label. It helps teams evaluate addresses, transactions, customer context, and institutional policy together.

It answers:

What does this risk mean in our business context?

CT Probe: from alert to investigation outcome

CT Probe focuses on post-alert investigation.

With AI-driven investigation capabilities, it helps analysts trace fund paths, understand address relationships, identify key risk nodes, and form clearer investigative insights.

It answers:

Why does this transaction carry risk, and what should be reviewed next?

CT Data: the data foundation behind investigation capability

CT Data provides the underlying on-chain data support for screening, monitoring, assessment, and investigation. Without stable data coverage and risk labels, AI Agents cannot make reliable judgments. Without clear entity relationships and transaction semantics, investigations struggle to move from seeing transactions to understanding risk.

Taken together, CT Check is the pre-transaction risk entry point, CT Monitor tracks risk changes continuously, CT Assess places risk into customer and business context, CT Probe supports post-alert investigation, and CT Data provides the data foundation beneath these capabilities.

This is one of the key differences between ChainTrust and traditional tools. The goal is not only to answer whether an address is high-risk. It is to help teams answer why risk appeared, where the evidence is, and what should happen next.

Conclusion: next-generation AML is not only about detecting risk

Crypto compliance is entering a new stage.

In the past, the industry mainly needed to "see" on-chain risk.

Now, institutions need to "understand" risk.

As risk expands from single addresses into complex networks across chains, entities, and service providers, traditional alerting systems cannot complete the full job on their own.

Next-generation AML infrastructure needs to connect on-chain data, entity relationships, transaction paths, and investigative reasoning so compliance teams can move faster from risk signals to explainable action.

The value of AI Agents is not to replace compliance professionals. It is to help them make important judgments faster and more accurately.

From alert to investigation, this is the next upgrade in crypto AML workflows.

ChainTrust Labs

Learn more about ChainTrust KYT, on-chain risk monitoring, and investigation products:

https://chaintrustlabs.com/

References

[1] U.S. Department of the Treasury / OFAC | Treasury Further Dismantles Iranian Financier Zanjani's Network | 2026.07.24

[2] U.S. Department of the Treasury / OFAC | Treasury Sanctions Iranian Regime Officials for Violent Repression and Corruption | 2026.01.30

[3] FATF | Targeted Report on Stablecoins and Unhosted Wallets - Peer-to-Peer Transactions | 2026.03

[4] FATF | FATF urges stronger global action to address Illicit Finance Risks in Virtual Assets | 2025

[5] FATF | The FATF Recommendations | Recommendation 15: New Technologies and Virtual Assets

[6] FBI Internet Crime Complaint Center | Internet Crime Report 2024 | 2025

[7] ChainTrust official website