Purpose
Monitor fiat and virtual asset activity using risk-based rules, blockchain analytics and FATF red-flag indicators, and ensure alerts receive documented disposition.
Scope
This procedure applies to transaction monitoring across fiat and virtual asset activity, including pre-transaction, post-transaction, automated and manual reviews where applicable.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify transaction context | Identify the transaction, direction, asset, network, value, customer, counterparty and wallet exposure | Monitoring alert |
| 2 | Monitor fiat and virtual-asset activity | Monitor on-ramp and off-ramp activity across both fiat and virtual assets. Includes large/high-value transactions, repeated smaller transactions, structuring, velocity anomalies, unusual routing, and activity inconsistent with client profile | Monitoring alert |
| 3 | Assess high-risk exposure | Assess exposure to high-risk wallets, mixers, darknet markets, stolen funds, scams, ransomware, terrorism financing, child-exploitation services, high-risk exchanges, P2P platforms, obfuscation services, sanctions and other typologies. Provider scans 20+ risk sources and assigns a proprietary crypto risk score: 0–25% (minimal), 25–75% (moderate, caution), >75% (strongly advised to reject) | Blockchain analytics report |
| 4 | Apply monitoring scenarios | Include structuring/smurfing, sudden spikes, transactions inconsistent with client profile/source of funds/wealth, unusual use of multiple wallets/chains/counterparties, high-risk typology exposure, and unusual on/off-ramping behavior. Apply risk-calibrated limits, thresholds, scenarios and heightened-review steps by risk category | Rule/configuration version |
| 5 | Apply wallet-risk score bands | Apply the approved production interpretation of wallet-risk score bands and alert boundaries; do not infer whether a score of exactly 25% or 75% belongs in a higher band while ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration remains open | Alert disposition |
| 6 | Review alerts by cadence | All alerts reviewed by trained personnel. Review high-risk alert populations at least daily and low/medium-risk at least weekly, without delaying resolution of time-critical alerts. Document escalation decisions, investigation steps, outcomes, and reporting actions | Alert disposition |
| 7 | Trace blockchain hops | For targeted blockchain investigations, normally trace up to three (3) hops; for high-risk or escalated cases, consider deeper tracing, often up to six (6) hops. Actual depth depends on blockchain, tool capability, and case usefulness | Transaction graph and hop-depth rationale |
| 8 | Determine tracing depth | Determine actual tracing depth from blockchain, tool capability, exposure path and usefulness of further tracing; document why the selected depth is sufficient. Six hops is not a limit on broader automated monitoring | Transaction graph and hop-depth rationale |
| 9 | Preserve investigation evidence | Preserve the relevant path, intermediary wallets, transaction hashes, amounts, exposure percentages, timestamps, tool result and configuration or rule version used | Investigation notes |
| 10 | Auto-clear only where approved | Auto-clear only where an approved rule permits it and the retained evidence supports the disposition; failed, processing, incomplete or unresolved results are not clearance | Alert disposition |
| 11 | Escalate high-risk alerts | Escalate high-risk, suspicious, sanctions-related or unresolved alerts to Compliance and apply limits, holds or other risk-commensurate measures where appropriate | Reporting or restriction decision |
| 12 | Document investigation | Document the investigation, rationale, disposition, reporting assessment and restriction decision | Investigation notes |
| 13 | Feed calibration loop | Feed false positives, potential misses, workload, emerging risks and investigation outcomes into controlled rule calibration | Calibration record |
Evidence
- monitoring alert
- blockchain analytics report
- investigation notes
- alert disposition
- calibration record
- transaction graph and hop-depth rationale
- rule or configuration version
- reporting or restriction decision
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Controls: CTRL-AML-004 Ensure Transaction Monitoring Alerts Are Reviewed
- Operating SOP: PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP
- Blockchain analytics system: SYS-KYT-001 Crystal Intelligence Blockchain Analytics
- Calibration and change record: PUB-KYT-002 Crystal Intelligence Calibration and Change Record
- Calibration validation issue: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration
- Manual coverage: sections 4.2, 4.4-4.5, 5.5 and 14.4.1.3.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Added fiat and on-chain scenarios, queue-review cadence, three-hop/six-hop investigation rules and case substantiation requirements after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.