cyberx_
back to indexCompliance & Regulation4 min read

Counterparty Due Diligence in Virtual Assets

Screening answers a question about the address. What supervisors ask about is who stands behind it — two different questions, with answers that rarely line up.

Robert F.
In this article

Almost every compliance program with virtual-asset exposure is built around a single risk-scoring tool: an address goes in, a label comes out. That is necessary, it is cheap, and it handles the volume.

The trouble starts when the label becomes the whole answer. Because it answers one question — and not the one that gets asked later.

Two questions that look like one

"Does this address have a problematic history?" is a question about the address. The tool answers it well: it knows that identifier's history and scores it accordingly.

"Who is behind this operation, and is the asset what it claims to be?" is a question about structure. No address score answers it, because the answer isn't on the blockchain — it lives in the relationships among people, companies, and behavior over time.

The two coexist without contradiction: a clean address paired with a problematic counterparty is a common combination, not an anomaly. A freshly created intermediary starts out with a spotless history by definition — it has no history at all.

What scoring can't reach

  • Actual ownership structure, including who shows up once you look two layers past the declared cap table
  • Trajectory, not just current status — the company that looks clean today may have changed hands three times in eighteen months
  • Recurrence across cases — the entity dismissed in one alert may be central to another months later, and without institutional memory that stays invisible
  • Consistency between narrative and behavior — declared activity that matches volume, public footprint that matches size, counterparties that match the stated business

None of this is a failure of the tool. It's scope. The mistake is treating the floor as the ceiling.

Signals that warrant a deeper look

None of these is a conclusion. All of them are reason to look harder:

  • Volume inconsistent with declared activity or with the history of the relationship
  • A newly incorporated structure moving amounts typical of a mature operation
  • A chain of intermediaries with no apparent economic rationale
  • A destination address that changes with every transaction, unexplained
  • A counterparty that resists clarifying source of funds — the refusal is itself data
  • A public footprint that is either nonexistent or built all at once, on clustered dates

Taken alone, each item has an innocent explanation. Three together rarely do.

The bottleneck is analysis, not alerting

This is the point that costs the most in practice.

Virtual-asset transaction volume is not compatible with manual review. A poorly calibrated threshold produces alerts in excess — and alerts nobody can work create the worst possible scenario: the institution knew, documented that it knew, and did nothing. From a liability standpoint, that is worse than never having generated the alert.

Which is why the threshold matters more than the tool. Three decisions that have to be written down before the first alert arrives:

  1. What escalates to enhanced review, and on what basis
  2. Who decides, and within what deadline
  3. Where it goes when the tool can't resolve it — internal capacity or external support. An alert with no destination becomes an ignored alert, and an ignored alert shows up in the audit

The question nobody asks and should

The most revealing question about a program isn't which tool it runs. It's this: take an alert from six months ago and reconstruct the decision using only what was recorded.

If it can be reconstructed — what was seen, what was concluded, why the call went that way — the program stands up. If the answer depends on somebody's memory, the problem already exists today; it will simply surface the day an outsider asks the same question.

A control without a trail is, for supervisory purposes, a control that never happened.

In one line

The tool answers for the address; the question is about the counterparty. Having both answers costs more — and it is the difference between having followed the process and being able to prove it.


CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about ongoing cases, matters under judicial secrecy, clients, or operational detail that would compromise an investigation in progress.

Tags

[AML/CFT][Virtual assets][KYC][Due diligence]

Share