AML screening methodology

How CryptoAML.ai scores a crypto address: sources, rules and limits

CryptoAML.ai runs its own sanctions and blacklist checks before it asks any external provider. After that it adds blockchain intelligence from MistTrack and Merkle Science (through Didit), and then applies a verdict step written in our code. OnChainRisk sits connected as a reserve provider and contributes nothing to current reports. The output is a screening signal about an address. It is not legal advice and not a compliance guarantee.

Where the data comes from

These names appear as data sources only. CryptoAML.ai is a customer of these providers, and none of them endorses or certifies us.

LayerSourceWhat we takeWhat we leave out
Address sanctionsOFAC SDN list (US Treasury)Crypto addresses from the SDN file, refreshed dailyA clean result never proves the owner is unsanctioned
Name sanctionsUN, UK OFSI, Australian DFAT, Swiss SECOEntity names and aliases, matched against labels returned for an addressDirect address lookup, because these lists carry names
Public blacklistsRansomwhere (BTC). 0xB10C curated OFAC address files (BTC/ETH/TRX). MyEtherWallet darklist (ETH).Known ransomware and sanctioned and scam addressesOther chains: these lists cover BTC/ETH/TRX only
Issuer freezesTether contract on Ethereum and TRONA read-only check of whether USDT is frozen for the addressRecovery or unfreezing of funds
Blockchain intelligenceMerkle Science, reached through DiditRisk grade, exposure shares, labels on the address itselfResale of raw provider data: reports carry our analysis
Blockchain intelligenceMistTrackRisk score plus risk level plus labels on its supported chainsResale of raw provider data
Gateway and fallbackDiditXRP and Lightning, plus any request MistTrack cannot answer normally
ReserveOnChainRiskIntegration stays in our code; the subscription has not been active since 2 October 2026Any use in current reports

What our own code does before a provider is asked

Before we ask an external provider, our own code runs the address through sanctions and blacklists. A direct OFAC hit adds 95 points on a 100-point scale, and a confirmed label match from the UN, UK, Australian or Swiss lists pushes the score to at least 95. Known blacklist hits set fixed floors. The sum never goes above 100.

The four grades are fixed: below 20 is LOW, 20 to 49 is MEDIUM, 50 to 79 is HIGH, and 80 and above is CRITICAL. The rule is deterministic. The same address with the same inputs gets the same grade. It is not a machine-learning model and not a rating issued by a regulator.

Why a provider grade does not go straight into the report

Provider grades are filtered before they reach the report. Some providers mark any sanctions or mixer or darknet exposure as top risk, and a big exchange hot wallet then looks like a criminal wallet.

Our verdict step addresses that behavior. If the address itself carries a sanctions or mixer or darknet label, the grade stays CRITICAL. If the only finding is exposure, the share of the address's volume sets the grade. At 10% or more the grade stays CRITICAL. At 1% or more it becomes HIGH. Below that it becomes MEDIUM. The grade never drops to LOW. The exposure share stays visible in the report. Anything we cannot explain stays CRITICAL. This step applies to Merkle Science results only.

One October 2026 comparison on 11 live addresses showed the split. On a large exchange wallet and a well-known personal wallet, one provider returned CRITICAL and the other returned Low. Eleven addresses is a small sample, so we treat it as the reason for our rule rather than a benchmark of either provider.

What happens when a provider is down

Provider failure has a fixed order. MistTrack receives the request first on the chains it supports. Any reply that is not a normal answer goes to Didit.

If the deep layer is unavailable, the report says "unavailable, basic result only". We never fill that gap with a guess. If the chain data provider fails outright for a supported chain, we refuse to score the address.

The anonymous free check does not include the deep layer. The report says so. The check still runs OFAC and chain data and the BTC/ETH/TRX blacklists.

Whose name is on the report

The report carries the CryptoAML name, and its deep-layer line reads "Deep: CryptoAML". We set the scoring rules. The thresholds and the verdict step are also ours, so the report is our analysis. The providers above supply the underlying data, and this page is where we name them.

What this page does not claim

A LOW grade has one meaning only: the layers we ran found nothing. It does not mean the address is safe or the owner is clean. Sanctions lists change. We refresh OFAC daily. Nothing here is legal or financial advice.

Questions people ask

People ask the same questions about coverage and limits. The answers below state the current rules.

Which data providers does CryptoAML.ai use?

Our own layer covers OFAC sanctions and UN, UK, Australian and Swiss name matching and public blacklists. We then add data from Merkle Science (through Didit) and MistTrack. The verdict rules run after that.

Is OnChainRisk still used?

No. The OnChainRisk integration stays in our code as a reserve. Its subscription has not been active since 2 October 2026. We will list it as an active source on the day it is switched back on.

Does a LOW result mean an address is safe?

No. LOW means the layers we ran found no sanctions match or blacklist hit, and no high-risk exposure, at the time of the check.

Why can two providers grade the same address differently?

Each provider uses its own labels, its own coverage and its own rule for exposure, and some mark even a tiny indirect contact with a mixer as top risk. That gap is why we grade exposure by share of volume ourselves.

Does the free check use the same sources?

The free check runs OFAC and chain data and the BTC/ETH/TRX blacklists. It leaves out the deep provider layer and states that in the result.

Run a check

Run a check through the web or through Telegram. The URL is https://cryptoaml.ai/check/ and the bot handle is @cryptoamlscan_bot.