Anti-Money Laundering (AML) and Know Your Transaction (KYT) screening evaluates an address or transaction against blockchain risk data, checking for connections to activity like sanctions, darknet markets, stolen funds, or ransomware. It is the primary way to screen counterparties for risk that is not captured by simply knowing who controls an address.
How it works
AML/KYT fits into your compliance policy the same way any other check does: a Trigger decides which transactions get sent to your provider, and an Outcome decides what happens based on the result. See Building a Compliance Policy for how Trigger and Outcome work in general.
What differs is how each provider expresses risk. Chainalysis and TRM Labs return a categorical risk level (Unknown, Low, Medium, High, Severe); Elliptic returns a numeric score. Some providers also flag specific risk categories, like sanctions exposure or a connection to a mixer. See each provider's own article for exact fields and values.
Providers
You can connect one or more of:
You can use different providers for different workspaces.
Limitations
Blockchain and asset coverage varies by provider: which chains and assets a provider can screen depends on that provider's own data coverage, not on Fireblocks. See each provider's own article for what it currently supports.
Some routes never reach your Trigger at all: vault-to-vault, vault-to-exchange, Gas Station-to-vault, and non-custodial-wallet-to-non-custodial-wallet within the same workspace. Those transactions are still registered with your provider and count toward your usage quota, unless you explicitly set a Pass rule for them.
Best practices
- Keep policies simple. Overly complex rules make it harder to understand what is being screened, and harder to audit later.
- Risk ratings are not comparable across providers. A score that one provider treats as high risk, another might treat as moderate. Calibrate your Outcome rules to how your specific provider scores risk, rather than assuming a rating is universal.
- Consider screening by category instead of score. Some providers let you build rules around specific risk categories rather than a risk score, if that maps better to your compliance strategy.
FAQ
The questions below are the ones readers ask most often.
How is this different from Address Registry Screening?
Address Registry Screening checks whether an address belongs to a verified, opted-in entity on the Fireblocks network. AML/KYT checks any address against your provider's risk data, regardless of whether the counterparty is a Fireblocks customer. You can use both in the same policy.
Developer portal
See AML policies for how screening works through the API.