TRM Labs screening evaluates transactions for blockchain risk, using Fireblocks' Anti-Money Laundering (AML) Transaction Screening Policy (Trigger) and AML Post-Screening Policy (Outcome) to decide which transactions get sent for screening and what happens based on the result. See Building a Compliance Policy for how Trigger and Outcome work in general.
This integration is currently in Early Access. Contact your Customer Success Manager to join. It is also a premium feature that requires an additional purchase, separate from Early Access enrollment.
How it works
Fireblocks sends transaction details, including the output address, transaction hash, and Customer Reference ID, to TRM Labs for Know Your Transaction (KYT) screening. TRM Labs returns a categorical risk level (Unknown, Low, Medium, High, Severe), along with the specific risk categories matched, if any.
Screening works somewhat differently depending on direction: incoming transactions are evaluated through TRM's transaction monitoring, and outgoing transactions through TRM's wallet screening. Outgoing transactions are not currently registered with TRM's transaction monitoring, in this Early Access release.
Because TRM Labs' screening is asynchronous, a result is not always immediate. The Post-Screening Policy includes a Wait action, specific to TRM Labs, that holds a transaction until a new result arrives or a time window you define elapses.
You can view screened transactions on the Transaction History page, the Audit Log, or via the API. Transaction rejection information is available only from Fireblocks, not from TRM Labs directly. TRM Labs can also send you alerts for indirect risk exposure through its own UI.
Setup
Before you begin, complete the general setup of your compliance integrations.
- Create an API key in TRM Labs. TRM Labs documents API access in the TRM Labs documentation. You need Know Your Transaction (KYT) API access in TRM Labs to create the key. If you are later removed from the TRM Labs account, create a new key.
-
Activate the integration in the Fireblocks Console:
- Go to Policies > Compliance > AML > Policy > Connect.
- Select TRM Labs.
- Enter your API key.
Default Screening and Post-Screening policies apply automatically until you create your own. The default rules are greyed out in the Console and cannot be edited or removed; any custom rules you add above them take precedence, and rules are evaluated top to bottom.
To switch to a new API key later, submit a ticket to Fireblocks Support with the new key.
Processing
The subsections below describe how processing works.
Timing parameters
Because results can arrive asynchronously, TRM Labs' Post-Screening Policy includes two timing fields alongside the usual ones: Valid After (the minimum time that must pass before a rule applies), and Valid Before (the maximum time within which it applies). These work together with the Wait action to hold a transaction only as long as it makes sense for your policy.
Testing transaction rejection
You can test that rejection rules work before relying on them in production:
- Incoming: add a rule that accepts transactions above a small threshold (for example, $0.0568) and a final rule that rejects everything else, then send test transactions above and below that threshold.
- Outgoing: add a rule that rejects transactions TRM Labs identifies as high-risk, then mark one of your own destination addresses as high-risk in TRM Labs to trigger it.
Transactions that receive an "Unknown" result are not affected by these test rules, and both only apply within your configured blocking-timeout window.
Supported assets
TRM Labs supports a broad range of blockchains, including Bitcoin, Ethereum, Solana, and TRON. Testnet assets are not currently supported.
Limitations
Only one AML provider can be connected to a workspace at a time. To switch providers, contact Fireblocks Support.
FAQ
The questions below are the ones readers ask most often.
What does the Wait action do?
It holds a transaction in a pending state until TRM Labs returns a new result, or until the Valid Before time window you have set elapses, whichever comes first.
Can I see why a transaction was rejected?
Yes, through Fireblocks. TRM Labs provides the risk result; Fireblocks provides the rejection details.