Nine Engineering Decisions That Define On-Chain AML Screening
Most compliance teams evaluate an on-chain risk provider through demos and sales decks. The decisions that actually determine whether a system holds up under regulatory scrutiny or collapses under volume pressure are invisible in those settings. Elliptic's September 2026 technical paper, "Built for Compliance," sets out nine of those engineering choices, and the implications for any firm treating crypto accounting software as part of its compliance stack are significant.
Why Engineering Architecture Is a Compliance Question
On-chain risk screening is no longer a niche workflow. Tokenized financial services and stablecoin settlement are routing ordinary payment volumes through public ledgers. Agentic AI systems are originating and settling transactions without direct human instruction. Elliptic's own data, published in September 2026, records a 500% increase in agentic crypto transactions over a three-month window. That is not a projection; it has already happened.
When volumes move at that pace, the engineering underneath a screening system stops being a vendor detail and becomes a direct compliance liability. A provider that performs adequately at one million transactions a month may create missed alerts, delayed filings, or audit gaps at six million. Regulators, whether under MiCA in the EU, FinCEN rules in the US, or equivalent frameworks elsewhere, expect firms to demonstrate that their controls are fit for the volumes they actually process, not the volumes they processed at onboarding.
The Moment the Architecture Becomes Visible
Elliptic cites a concrete example from its client base: one customer's transaction volume rose from roughly 1.5 million per month to 6.7 million over two days. That kind of spike, whether caused by a market event, a product launch, or the uptake of an agentic settlement workflow, is precisely where engineering decisions surface. Latency increases, regional failover triggers, alert queues back up, and an analyst's working day becomes unmanageable. The nine decisions Elliptic documents are the ones that separate systems that absorb that shock from systems that fail quietly and visibly in the audit trail.
What the Nine Decisions Cover
The paper does not reduce to a simple checklist. Each of the nine areas reflects a genuine trade-off that every on-chain risk provider has resolved in one direction or another. Elliptic's position is that those resolutions should be legible to compliance officers and technical reviewers, not buried in proprietary black boxes.
Performance and Availability Under Real Conditions
Several of the nine decisions relate to how a system behaves when conditions are not normal. API uptime, regional redundancy, and the handling of volume spikes each represent a separate engineering choice. A provider that has not documented what actually happened during a major outage or a sudden volume surge cannot give a compliance team the evidence it needs to satisfy a regulator asking about a decision made under those conditions.
The paper frames this directly: the value of these engineering choices compounds with volume. A firm processing modest volumes today may be processing ten times that within eighteen months, particularly if stablecoin payment rails or tokenized asset settlement become part of its operating model.
Automation and Analyst Efficiency
A second cluster of decisions concerns how much work the system can route, triage, or resolve without requiring an analyst's direct attention. Elliptic's Lens product, described in the paper as a unified workspace combining wallet screening and transaction monitoring, is presented as its answer to the fragmentation problem: multiple tools, manual handoffs, and time lost moving between investigation steps.
The compliance relevance is not abstract. When alert volumes rise and analyst headcount stays flat, the ratio of unreviewed alerts to reviewed ones increases. That ratio matters in an enforcement context. A system that reduces the number of manual steps per alert, and creates a full audit trail in the process, directly affects the defensibility of a compliance programme.
Auditability and the Lookback Problem
One of the least discussed but most consequential engineering decisions concerns what happens when a regulator asks about a screening decision made three years ago. Can the system reproduce the risk data that was available at the time of the decision? Can it show the analyst's reasoning? Can it confirm which version of the risk model was running?
Elliptic treats full auditability as a design requirement, not a reporting feature. For accounting firms advising clients on AML compliance, and for CFOs signing off on internal control frameworks, this matters because the obligation to demonstrate compliance is retrospective. The question is not only whether alerts were generated today, but whether the firm can show, at any future point, that its screening was adequate at the time a transaction was processed.
Agentic Transactions and the New Volume Baseline
The paper draws a clear line between two companion documents. An earlier Elliptic publication sets out eight principles for agentic risk management in on-chain finance. "Built for Compliance" is described as the engineering layer underneath those principles: the decisions that determine whether a system can actually meet them in a live production environment.
The agentic context deserves attention from compliance leads and CFOs. When an AI agent originates a transaction, the traditional compliance model assumes a human decision-maker in the loop. Agentic workflows remove or compress that loop. Screening must therefore operate at machine speed, with the same accuracy and the same audit trail that a human-reviewed transaction would generate. That is an engineering problem before it is a policy problem, and it is one that firms relying on legacy screening tools are likely to encounter sooner than they expect.
Stablecoins as a Specific Risk Surface
Stablecoin settlement volumes are a recurring theme in the paper's framing. As major payment networks and financial institutions adopt stablecoin rails for cross-border and corporate settlement, the on-chain footprint of ordinary commercial activity expands rapidly. Each stablecoin transfer is a screenable event. Each counterparty wallet carries a risk profile. At scale, the number of screening calls per business day can exceed the capacity of systems built for cryptocurrency trading volumes rather than payment processing volumes.
For firms already tracking stablecoin accounting obligations, the operational link between settlement volume and screening capacity is direct. The accounting treatment of a stablecoin receipt may depend on whether the counterparty wallet passes sanctions screening at the time of settlement. A system that cannot return a result within the settlement window creates both an accounting problem and an AML control gap simultaneously.
Practical Implications for Accounting Firms and CFOs
The paper is structured partly as a procurement tool: nine questions to put to any screening provider, one for each engineering decision. For accounting firms advising clients on vendor selection, and for CFOs responsible for technology spend in compliance functions, that framing is useful.
For Accounting Firms and Auditors
When auditing a client's AML controls, the adequacy of the underlying screening technology is a relevant consideration. A system that cannot demonstrate its uptime history, its behaviour under volume pressure, or its auditability across multi-year lookback periods introduces audit risk. Firms should be asking clients not only what screening tools they use, but what evidence those tools can produce when a control is challenged. Crypto accounting software that integrates with or feeds data to screening systems also needs to be evaluated for consistency: if the transaction record in the accounting ledger does not match the transaction data submitted for screening, the audit trail is broken at the point that matters most.
For CFOs and Compliance Officers
Procurement decisions made when transaction volumes were low do not automatically remain adequate as volumes grow. The 500% increase in agentic transaction volumes cited by Elliptic is a leading indicator of where commercial volumes are heading, particularly for firms in financial services, payments, and treasury management that are adopting tokenized instruments. CFOs should treat screening capacity as a scalable resource requirement, subject to the same stress-testing logic applied to other operational infrastructure. The cost of a control failure in this area is not limited to a fine: it includes the reputational exposure, the cost of a retrospective review, and the potential for a regulator to require an independent audit of the firm's AML programme.
The Vendor Evaluation Framework
Elliptic's nine-question framework is designed to make provider comparisons substantive rather than superficial. The questions are not published in full in the available excerpt, but the paper signals they address each of the nine engineering decisions with specificity, including requests for evidence rather than assertions.
For firms that have not recently stress-tested their screening provider against these dimensions, the paper provides a useful prompt. Key areas to probe include: what the provider's documented uptime has been over the past twelve months; how the system performed during a volume event comparable to the 1.5-to-6.7 million transaction spike described; what the latency profile looks like at peak load; and how the system reconstructs a historical screening decision for audit purposes.
These are not unreasonable questions. Any provider that cannot answer them with evidence, rather than a roadmap or a promise, is telling you something important about where its engineering investment has gone.
Source: Elliptic
Frequently Asked Questions
Why does screening system architecture matter for regulatory compliance?
Regulators expect AML controls to be adequate for the volumes a firm actually processes. If a screening system degrades under load, produces delayed alerts, or cannot reconstruct historical decisions, a firm may be unable to demonstrate that its controls were effective at the time a transaction was processed. That is an audit and enforcement risk, not merely an operational inconvenience.
What are agentic crypto transactions and why do they create new screening challenges?
Agentic transactions are originated and settled by AI systems without direct human instruction at the moment of execution. They remove the human review step that traditional compliance models assume. Screening must therefore operate at machine speed and produce the same audit trail as a manually reviewed transaction. Legacy systems designed for human-paced workflows may not support this without re-engineering.
How does stablecoin volume affect AML screening capacity requirements?
Each stablecoin transfer is a discrete screenable event. As stablecoin rails are adopted for commercial payments and corporate settlement, the number of screening calls per day can grow rapidly, often faster than the compliance function's headcount. Systems built for cryptocurrency trading volumes may not be architected to handle payment-level throughput with the same latency and accuracy.
What does auditability mean in the context of on-chain screening?
Full auditability means the system can reproduce, at any future point, the risk data available at the time a screening decision was made, the version of the risk model that was running, and the analyst's recorded reasoning. This is essential when a regulator asks about a decision made months or years earlier. Systems that do not retain this information create a compliance gap that cannot be corrected retrospectively.
How should accounting firms use a framework like this when advising clients?
When reviewing a client's AML technology stack, accounting firms should ask for documented evidence of the screening system's performance history, its behaviour under volume spikes, and its auditability capabilities. If the client cannot produce this evidence, the adequacy of the control is difficult to assert in an audit context. The framework Elliptic describes provides a structured set of questions that can be adapted for due diligence or internal audit purposes.
