Purpose

Monitor fiat and virtual asset activity using risk-based rules, blockchain analytics and FATF red-flag indicators, and ensure alerts receive documented disposition.

Scope

This procedure applies to transaction monitoring across fiat and virtual asset activity, including pre-transaction, post-transaction, automated and manual reviews where applicable.

Steps

#ActionDetailsEvidence
1Identify transaction contextIdentify the transaction, direction, asset, network, value, customer, counterparty and wallet exposureMonitoring alert
2Monitor fiat and virtual-asset activityMonitor on-ramp and off-ramp activity across both fiat and virtual assets. Includes large/high-value transactions, repeated smaller transactions, structuring, velocity anomalies, unusual routing, and activity inconsistent with client profileMonitoring alert
3Assess high-risk exposureAssess exposure to high-risk wallets, mixers, darknet markets, stolen funds, scams, ransomware, terrorism financing, child-exploitation services, high-risk exchanges, P2P platforms, obfuscation services, sanctions and other typologies. Provider scans 20+ risk sources and assigns a proprietary crypto risk score: 0–25% (minimal), 25–75% (moderate, caution), >75% (strongly advised to reject)Blockchain analytics report
4Apply monitoring scenariosInclude structuring/smurfing, sudden spikes, transactions inconsistent with client profile/source of funds/wealth, unusual use of multiple wallets/chains/counterparties, high-risk typology exposure, and unusual on/off-ramping behavior. Apply risk-calibrated limits, thresholds, scenarios and heightened-review steps by risk categoryRule/configuration version
5Apply wallet-risk score bandsApply the approved production interpretation of wallet-risk score bands and alert boundaries; do not infer whether a score of exactly 25% or 75% belongs in a higher band while ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration remains openAlert disposition
6Review alerts by cadenceAll alerts reviewed by trained personnel. Review high-risk alert populations at least daily and low/medium-risk at least weekly, without delaying resolution of time-critical alerts. Document escalation decisions, investigation steps, outcomes, and reporting actionsAlert disposition
7Trace blockchain hopsFor targeted blockchain investigations, normally trace up to three (3) hops; for high-risk or escalated cases, consider deeper tracing, often up to six (6) hops. Actual depth depends on blockchain, tool capability, and case usefulnessTransaction graph and hop-depth rationale
8Determine tracing depthDetermine actual tracing depth from blockchain, tool capability, exposure path and usefulness of further tracing; document why the selected depth is sufficient. Six hops is not a limit on broader automated monitoringTransaction graph and hop-depth rationale
9Preserve investigation evidencePreserve the relevant path, intermediary wallets, transaction hashes, amounts, exposure percentages, timestamps, tool result and configuration or rule version usedInvestigation notes
10Auto-clear only where approvedAuto-clear only where an approved rule permits it and the retained evidence supports the disposition; failed, processing, incomplete or unresolved results are not clearanceAlert disposition
11Escalate high-risk alertsEscalate high-risk, suspicious, sanctions-related or unresolved alerts to Compliance and apply limits, holds or other risk-commensurate measures where appropriateReporting or restriction decision
12Document investigationDocument the investigation, rationale, disposition, reporting assessment and restriction decisionInvestigation notes
13Feed calibration loopFeed false positives, potential misses, workload, emerging risks and investigation outcomes into controlled rule calibrationCalibration record

Evidence

  • monitoring alert
  • blockchain analytics report
  • investigation notes
  • alert disposition
  • calibration record
  • transaction graph and hop-depth rationale
  • rule or configuration version
  • reporting or restriction decision

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added fiat and on-chain scenarios, queue-review cadence, three-hop/six-hop investigation rules and case substantiation requirements after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.