Continuous Monitoring Closes the Post-Screening Risk Gap in Crypto AML
A crypto AML screening gives you a risk score at a single point in time. That score can be accurate, defensible, and completely useless six months later if the wallet you cleared has since moved funds through a darknet marketplace. Elliptic's newly launched Continuous Monitoring capability is designed to close exactly that gap: it watches enrolled wallets and transactions for events that can shift a screening outcome, reruns a full assessment against a firm's own configured risk rules, and delivers targeted alerts without burying analysts in noise. For compliance teams, auditors, and CFOs who rely on crypto accounting software to maintain an auditable record of counterparty risk, the implications are significant.
The Problem With Point-in-Time Crypto Screening
Point-in-time screening is the industry default for a practical reason: it is fast, it produces a result, and it satisfies a checkbox at onboarding. The difficulty is that crypto risk does not stay still.
How Stale Scores Accumulate Silently
Consider the scenario Elliptic uses to illustrate the problem. A wallet is screened at onboarding and returns a score of 0.5 out of 10. No meaningful exposure, cleared to transact. Months later, those funds move forward to a darknet marketplace. Nothing was wrong with the original screening; the wallet simply changed. It is now a 10 out of 10. But unless a member of the compliance team happens to rescreen it manually, the only number visible in the system is still 0.5. The team continues treating a high-risk counterparty as a clean one.
This is not an edge case. It is a structural gap in any workflow that relies solely on onboarding-stage checks. Closing it manually would require rescreening every enrolled entity repeatedly, which is unscalable for any firm handling significant transaction volumes. The gap grows with the size of the portfolio.
Why Existing Monitoring Approaches Fall Short
Prior solutions to this problem have tended to fail in one of two directions. Label-based monitoring watches for changes to the designations attached to known addresses and triggers an alert when a label changes. The limitation is that risk can arrive without any label changing at all: a new transaction or a fresh connection to a previously unlinked illicit actor will not alter the label on an address, so the monitoring stays silent while fresh exposure builds.
The opposite failure mode is over-alerting: firing a notification on every label change, material or not, with no mechanism to filter by what actually matters to a specific business. Compliance analysts already stretched thin report being overwhelmed by notifications that carry no genuine signal. When every alert looks the same, the important ones get buried.
How Continuous Monitoring Works
Elliptic's approach is structured around three sequential steps, layered over a scheduled rescreening baseline.
Step One: Broad Event Detection
The system watches enrolled screenings for the specific events capable of changing a screening outcome. These include a new or changed label on a screened address or counterparty, and changes in the clusters an address belongs to. Each qualifying event triggers a rescreen. Elliptic describes this as the broadest event detection set currently available in the market, drawing on attribution data the firm has been refining since 2013.
Step Two: Full Rescreen Against Configured Risk Rules
When an event is detected, the system does not apply a generic risk template. It runs a full screening against the firm's own configured risk rules. Because those rules can be updated without raising a support ticket, the monitoring capability evolves alongside the organisation's risk appetite. A firm that tightens its exposure thresholds for mixers, for example, will see that tightening reflected automatically in the next rescreen.
Step Three: Targeted Notification
Alerts are delivered by webhook or Slack, and only when a risk change crosses criteria the firm has set. Configurable triggers include a score threshold breach, a change in the absolute risk score, a triggered risk rule, or a specific screening source. The result is that analysts receive notifications calibrated to their own definitions of a material change, rather than a raw feed of every event the system detects.
The Scheduled Rescreen Layer
Alongside event-driven detection, Continuous Monitoring also rescreens every enrolled wallet and transaction on a regular schedule, with each check being a full recalculation rather than an incremental update. The two layers are complementary: event detection catches change as it happens, while the scheduled cycle ensures that nothing drifts unnoticed over a longer period. Elliptic frames this dual-layer design as the most comprehensive risk monitoring currently available across its solutions.
Who This Affects and How
Elliptic identifies several distinct use cases, each with a different compliance pressure that Continuous Monitoring addresses differently.
High-Volume Transaction Processors
Firms processing large numbers of time-sensitive screenings need to react the moment a cleared entity becomes risky. Manual rescreening at that volume is not operationally viable. Continuous Monitoring keeps risk current without manual review, and configurable webhooks route only the changes that meet the firm's own thresholds into its case management workflow, reducing the triage burden on analysts.
Smaller Compliance Teams With Audit Obligations
Teams with limited analyst capacity face a specific tension: they are expected to maintain ongoing, auditable monitoring but do not have the headcount to run manual rechecks at regular intervals. Continuous Monitoring covers the window between scheduled reviews while keeping alert volume low enough to be manageable. The auditable evidence trail it produces is directly relevant for regulatory examinations, since regulators increasingly expect firms to demonstrate not just that a screening was run at onboarding but that the risk assessment remained current throughout the relationship.
Payment and Settlement Operations
For operations that need to keep payment approvals fast without missing risk on pay-ins and pay-outs, configurable risk thresholds can support quicker approval decisions while generating auditable records for hold or reject outcomes. This matters for CFOs overseeing treasury operations that involve digital assets: the ability to show a regulator the precise risk score and the rule that triggered a decision is a material compliance asset.
Ecosystem and Counterparty Monitoring
Firms that need to monitor a broad set of ecosystem addresses and counterparties, such as exchanges tracking the behaviour of large liquidity providers, can do so without rescreening known entities by hand. Continuous Monitoring keeps the risk exposure picture accurate as the network around a counterparty changes.
Accounting and Audit Implications
From an accounting and audit perspective, the shift from periodic to continuous monitoring has practical consequences that go beyond the compliance function. Firms that use crypto compliance reporting as part of their broader financial controls framework need to consider how stale AML screening data interacts with their books.
Audit Trail Integrity
An auditor reviewing a firm's AML procedures will ask whether the risk assessment on a counterparty was current at the time a transaction was approved. A point-in-time score that was accurate at onboarding but was never refreshed is not a satisfactory answer if the counterparty's risk profile changed materially between the two dates. Continuous Monitoring generates a timestamped, rule-referenced record of every rescreen, which is exactly the evidence an auditor or regulator needs to assess whether a decision was made on sound information.
Provisioning and Exposure Calculations
For firms that hold digital assets on their balance sheet and use risk classifications to inform provisioning decisions, a monitoring gap can mean that high-risk exposures remain classified at lower risk levels longer than they should. This has implications for any firm using crypto accounting software to maintain accurate digital asset ledgers: the risk data feeding the classification needs to be as current as the price data. A stale score is as problematic as a stale valuation.
Regulatory Expectations and the Travel Rule
Regulators across multiple jurisdictions, including FATF member states and those implementing MiCA in the EU, increasingly expect virtual asset service providers to demonstrate ongoing monitoring, not just onboarding checks. The Travel Rule compounds this: firms must screen originator and beneficiary information at the point of transfer, but the counterparty's risk profile between transfers also matters. Continuous Monitoring addresses the between-transfer window directly. For context on the broader regulatory environment shaping these expectations, see our coverage of the global crypto policy shifts that shaped compliance priorities in Q2 2026.
It is also worth placing this development alongside the capabilities that distinguish effective AML programmes from checkbox exercises. Our earlier analysis of the eight capabilities that actually detect money laundering in crypto AML software identified real-time rescreening and configurable risk rules as two of the most operationally significant features. Continuous Monitoring delivers both within a single workflow.
What Compliance Teams Should Do Now
Regardless of whether a firm adopts this specific tool, the launch of Continuous Monitoring raises a question that every compliance team should be able to answer: what happens to a cleared screening between now and the next time it is manually reviewed?
Assessing the Current Gap
Compliance officers should map the lifecycle of a typical screening within their current workflow. When is a wallet or counterparty first screened? What triggers a manual rescreen? What is the realistic interval between rescreens for the bulk of the portfolio? If the honest answer is that most entities are only rescreened when they appear in a transaction, the gap is real and growing.
Reviewing Regulatory Expectations
Firms operating under licences in jurisdictions with active supervisory programmes, including the UAE's VARA framework, the EU under MiCA, and FATF-compliant regimes elsewhere, should check whether their current monitoring frequency meets the regulator's stated expectations. Where guidance references ongoing monitoring, a purely periodic approach may be insufficient, particularly if the firm handles high-risk asset types or counterparty categories.
Evaluating Tool Configuration
For firms already using automated screening tools, the question is whether those tools can distinguish between material and immaterial risk changes. An alert feed that cannot be filtered to the firm's own risk rules creates its own compliance problem: analysts who learn to ignore high-volume alerts may miss the ones that matter. Any evaluation of monitoring capability should include a review of how alert thresholds are configured and who has authority to adjust them.
Frequently Asked Questions
What is the difference between point-in-time screening and continuous monitoring?
Point-in-time screening assesses the risk of a wallet or transaction at the moment the check is run. Continuous monitoring watches enrolled entities after the initial check and rescreens them automatically when events occur that could change the outcome, such as new transaction links or changed cluster associations. The first gives you a snapshot; the second keeps that snapshot current.
Why does crypto risk change after an initial screening?
Blockchain activity is ongoing. A wallet that had no exposure to illicit actors at onboarding may receive or send funds connected to darknet markets, sanctioned entities, or fraud schemes days or months later. Because the blockchain is public and every transaction is permanent, the risk profile of an address is a moving target, not a fixed attribute.
What evidence does automated continuous monitoring produce for auditors and regulators?
A well-designed continuous monitoring system generates a timestamped record of every rescreen, the risk score produced, the specific rule or threshold that triggered an alert, and the action taken. This chain of evidence allows auditors and regulators to assess whether a firm's decisions were based on current risk data rather than stale onboarding results. It is materially stronger evidence than a single onboarding screening record.
How does this relate to digital asset accounting software and financial reporting?
Digital asset accounting software records balances, valuations, and transaction histories. AML monitoring data feeds the risk classification that underpins provisioning and counterparty exposure decisions. If the risk classification is based on a stale screening, the financial reporting built on top of it may not reflect the firm's true risk exposure. Continuous monitoring keeps the risk data that informs accounting classifications as current as the valuation data.
Which regulatory frameworks require ongoing AML monitoring rather than just onboarding checks?
FATF Recommendation 10 on customer due diligence explicitly requires ongoing monitoring of the business relationship, including scrutiny of transactions to ensure they are consistent with the institution's knowledge of the customer and their risk profile. MiCA's AML provisions, the EU's Transfer of Funds Regulation, and national implementations across FATF member states carry the same expectation. Jurisdiction-specific guidance on frequency and depth varies, so firms should check the rules applicable to their licence type and the asset categories they handle.
Source: Elliptic
