Elliptic Holistic Screening: What Cross-Chain AML Means for Accounting Firms and CFOs
Blockchain analytics just moved. Elliptic has launched Holistic Screening, a capability that automatically traces proceeds of crime across every major blockchain and crypto asset at the same time, replacing what were previously slow, manual cross-chain investigations with API-driven risk scores delivered in milliseconds. For accounting firms, auditors, and CFOs who sign off on digital asset AML controls, this development changes the benchmark for what a defensible screening programme looks like.
Why Cross-Chain Crime Created a Compliance Gap
Ten years ago, most illicit crypto activity stayed on a single chain. Bitcoin moved to Bitcoin addresses; investigators traced Bitcoin transactions. That world no longer exists.
The Rise of Cross-Chain Infrastructure
Decentralised exchanges, cross-chain bridges, and coinswap services have removed the barriers that once separated individual blockchains and assets. Capital now moves freely between chains, which is genuinely useful for legitimate market participants. It is equally useful for those trying to obscure the origin of funds. According to Elliptic's own research, hundreds of millions of dollars linked to ransomware and North Korean state-sponsored cyber activity have been routed through cross-chain bridges. Decentralised exchanges have been used to frustrate asset seizures worth billions of dollars, and coinswap services operating in Russia and elsewhere have facilitated money laundering and sanctions evasion at scale.
Where First-Generation Tools Fall Short
The generation of blockchain analytics tools built between 2015 and the early 2020s treats each blockchain as a separate silo. A Bitcoin wallet is analysed against Bitcoin data; an Ethereum wallet against Ethereum data. When funds cross a bridge or flow through a decentralised exchange swap, the trail breaks. Investigators then have to stitch the picture together manually, which is time-consuming, error-prone, and not scalable across a large client book. This is the gap that Elliptic's new capability is designed to close.
What Holistic Screening Actually Does
Holistic Screening is built on Nexus, an analytics engine that Elliptic states took three years to develop. Nexus merges blockchain-by-blockchain data into a single unified financial network representing the entire crypto asset ecosystem, drawing on hundreds of billions of data points collected over the past decade. The result is that fund flows can be traced continuously, even when they change asset type or hop between chains.
Three Core Capabilities
Elliptic describes three specific functions that sit beneath the Holistic Screening umbrella:
Multi-asset screening analyses all transactions associated with a wallet regardless of which crypto asset was used, rather than screening each asset in isolation. A wallet that received Bitcoin, swapped to Ether, and then moved to a stablecoin is assessed as a single risk profile, not three separate ones.
Cross-asset tracing follows fund flows even when an asset swap occurs within the same blockchain, for example when a user converts one token to another via a decentralised exchange. Previously, this type of on-chain swap could break an automated trace, requiring manual continuation.
Cross-chain tracing extends that logic to movements between blockchains entirely, such as a bridge transfer from Ethereum to a layer-2 network or a completely different chain. The trace continues automatically rather than stopping at the bridge.
All three functions operate through API calls, meaning they can be embedded into existing compliance workflows and executed at scale, rather than being reserved for high-priority manual investigations.
Implications for Accounting Firms and Their Digital Asset Clients
The launch of a more capable screening tool is not merely a vendor announcement. It has practical consequences for how compliance obligations are understood and documented.
Raising the Bar on What Is Adequate AML Screening
Regulators and standard-setters in jurisdictions ranging from the EU under MiCA to the Financial Action Task Force at the global level have consistently stated that Virtual Asset Service Providers and entities handling digital assets must apply risk-based controls commensurate with the actual risks they face. Cross-chain crime is now a documented, quantified risk category, not a theoretical one. When a tool exists that can automatically address that risk at scale, the argument that manual or siloed screening is sufficient becomes harder to sustain in a regulatory examination or an audit.
Accounting firms advising crypto exchanges, custodians, DeFi protocols, or any other virtual asset business should be asking their clients whether their current screening stack can trace funds across chains and assets. If it cannot, that gap needs to be documented, risk-assessed, and either remediated or explicitly accepted by senior management with a clear rationale. That rationale will need to hold up under scrutiny.
Firms that provide crypto accounting software evaluations or technology due diligence as part of their advisory offering should also be updating their assessment frameworks to include cross-chain and multi-asset tracing as evaluation criteria, not optional extras.
Audit Trail and Documentation Requirements
From an audit standpoint, the shift toward automated cross-chain risk scores has documentation implications in both directions. On the positive side, API-driven scoring creates a timestamped, reproducible audit trail that is far easier to present to an examiner than a collection of manual investigation notes. The risk score is generated automatically and can be logged against the relevant transaction or customer record without human transcription errors.
The counterpoint is that automated tools embed assumptions about which blockchains and assets are covered, how risk categories are weighted, and how often the underlying data is refreshed. Firms signing off on AML controls need to understand those assumptions, not simply accept the output as a black box. Auditors should be requesting documentation of tool coverage, scoring methodology, and data update frequency as standard procedure when reviewing a client's digital asset compliance programme. The emergence of a more capable generation of tooling makes this documentation more important, not less, because regulators will increasingly expect firms to be aware of what best-in-class looks like.
Sanctions Screening and the Cross-Chain Problem
Sanctions compliance is a specific area where cross-chain capability matters. If a sanctioned actor uses a bridge or a decentralised exchange to layer funds before they reach a wallet that an exchange is about to credit, a single-chain screen may return a clean result. A cross-chain trace starting from the same endpoint could surface the sanctioned origin. Accounting firms advising clients on sanctions risk should treat this as a live concern, particularly given the documented use of cross-chain infrastructure by actors linked to North Korea and Russian-based laundering services, as cited in Elliptic's research.
For more context on how AI-enabled threats are evolving in parallel with laundering techniques, see our earlier analysis on AI in crypto crime and what it means for AML compliance teams. The cross-chain problem and the AI-assisted evasion problem are converging, and compliance programmes need to account for both.
What CFOs Need to Assess Now
CFOs at businesses that hold, trade, or custody digital assets face a more immediate operational question: does the current compliance technology stack reflect the actual risk environment?
Technology Stack Review
The practical starting point is a gap analysis. Map the blockchains and assets your business touches against the coverage of your current screening tool. Identify any assets or chains that fall outside automated coverage and assess how those gaps are currently managed. If the answer is manual investigation, quantify the resource cost and the time lag, and consider whether that is proportionate given the volumes involved.
When evaluating whether to adopt more capable digital asset accounting software or compliance tooling, cross-chain and multi-asset screening coverage should now sit alongside standard criteria such as chain coverage breadth, integration with existing ERP or accounting systems, and regulatory reporting outputs. The underlying analytics engine matters, not just the interface.
Policy and Governance Updates
If a gap analysis reveals that current tooling cannot trace cross-chain flows, that finding should be escalated to the board or audit committee with a proposed remediation timeline. It should also be reflected in the firm's AML risk assessment. Leaving a known capability gap unaddressed without a documented acceptance decision creates regulatory and reputational exposure.
Policies governing customer due diligence and transaction monitoring should be reviewed to confirm they explicitly account for cross-chain activity, particularly where clients are active in DeFi or use cross-chain bridges as part of their normal operations. For broader context on how FATF's evolving DeFi guidance intersects with these controls, see our coverage of how the FATF DeFi report reshapes VASP obligations.
The Bigger Picture for Crypto Compliance Standards
Elliptic's launch is a signal about where the compliance technology market is heading, not a one-off product update. The industry has spent a decade building first-generation tools designed for a single-chain world. The infrastructure underpinning crypto has moved well beyond that, and the compliance tooling is now catching up. Firms that set their AML benchmarks based on what was available in 2020 need to revisit those benchmarks now.
Regulators globally are watching cross-chain crime closely. FATF has flagged cross-chain bridges and decentralised exchanges as high-risk typologies. The EU's MiCA framework and associated transfer of funds rules create obligations that assume screening can keep pace with the assets being moved. As automated cross-chain tracing becomes the industry standard rather than the cutting edge, the expectation that regulated entities will use it will harden accordingly.
For accounting firms, the practical upshot is that client AML reviews, annual compliance audits, and technology due diligence engagements all need a cross-chain lens applied going forward. The tools exist. The documented risks exist. The regulatory expectation is forming. Waiting for explicit regulatory mandates before updating controls is the less defensible position.
Frequently Asked Questions
What is cross-chain crime and why does it matter for AML compliance?
Cross-chain crime refers to the use of cross-chain bridges, decentralised exchanges, and similar infrastructure to move illicit funds between different blockchains and asset types, deliberately breaking the transaction trail. It matters for AML compliance because first-generation screening tools typically analyse each blockchain in isolation, meaning a fund flow that hops chains may not be flagged. Regulators including FATF have identified this as a documented high-risk typology.
How does automated cross-chain tracing change what a defensible AML programme looks like?
Once automated cross-chain tracing is available at scale, regulators and auditors can reasonably expect regulated entities to use it or to document explicitly why they have not. A programme that relies on manual investigation to bridge cross-chain gaps may still be defensible in some contexts, but it needs to be risk-assessed and signed off at a senior level with a clear rationale, rather than simply left unaddressed.
What documentation should auditors request when reviewing a client's blockchain analytics tools?
Auditors should request coverage documentation covering which blockchains and asset types the tool screens, the methodology used to generate risk scores, how often the underlying data is refreshed, and whether cross-chain and multi-asset tracing is included. For automated tools, it is also worth confirming how scoring outputs are logged and retained for audit trail purposes.
Does cross-chain screening affect sanctions compliance specifically?
Yes. A sanctioned actor who layers funds through a bridge or a DEX swap before depositing to an exchange may pass a single-chain screen while failing a cross-chain trace. This makes cross-chain capability particularly relevant for sanctions screening, not just general AML transaction monitoring.
What should a CFO do first if their current screening tool does not support cross-chain tracing?
The immediate step is a gap analysis: map the assets and blockchains your business touches against your current tool's coverage, quantify how cross-chain gaps are currently managed, and document the finding. That finding should be escalated to the board or audit committee with a proposed remediation timeline and reflected in the firm's AML risk assessment. Leaving a known gap undocumented is the highest-risk approach.
Source: Elliptic
