For virtual asset services

Wallet screening and chain analytics for Australian VASPs

Wallet screening and blockchain analytics are the tools that make virtual-asset monitoring visible: they attribute addresses, flag exposure to illicit activity and help a VASP see where value has been. They are not decision engines. A provider score is input; the VASP's assessment, evidence and decision are the compliance record. This guide explains how Australian VASPs should select, configure and evidence wallet screening without overstating what the tool proves.

See the virtual asset services AML/CTF workspace

What the tools actually do

A screening result combines the provider's data, algorithms and thresholds. Coverage varies by asset, chain and geography. The VASP should document which tools cover which assets and what the score means, so a red score is not silently treated as proof or a green score as absolution.

  • Address attribution to services, mixers, exchanges and known actors
  • Exposure scoring for direct and indirect contact with illicit activity
  • Sanctions and watchlist matching for addresses and counterparties
  • Transaction graph analysis for investigation
  • Rescreening when new intelligence changes an address's risk

Integrate screening into the workflow

Screening works only when it is connected to the decision: the wallet, the customer, the transaction and the outcome. A VASP that screens in one system and decides in another loses the evidence chain.

  • Screen wallets at onboarding and before transfers
  • Screen counterparty addresses on the same basis as customer wallets
  • Apply rescreening on the program's defined events and cycles
  • Escalate confirmed exposure to the compliance officer
  • Block or refuse where the assessment and the program require it

Assess before you act

A provider score is a starting point. Confirm the address, the exposure path, the amount and the customer context. An address with indirect exposure from a long chain may warrant enhanced review; a direct match to a sanctioned address warrants immediate action under the applicable law. Record the disposition: cleared, enhanced, refused or reported, with reasons.

Do not let a vendor's risk band override the VASP's legal obligations. Sanctions matches are legal red lines; suspicious activity requires an SMR assessment. The tool can flag, but the VASP decides.

Evidence and vendor management

AUSTRAC's VASP risk insights emphasise the importance of knowing your customer and your counterparties. A wallet-screening record that shows the provider result and the VASP's own assessment is the difference between a tool log and a compliance file.

  • Retain the provider, request reference, result and date for each screen
  • Store the assessment and decision, not just the score
  • Review provider coverage, data sources and changes regularly
  • Test the integration with controlled scenarios
  • Document outages and the manual fallback

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Does AUSTRAC require a specific chain-analytics provider?

No. AUSTRAC does not mandate a provider. The VASP must assess and monitor risk using controls proportionate to its services, and evidence its decisions.

Is a green wallet screen proof of a clean address?

No. A screen reflects the provider's current data and coverage. Record the result, the assessment and the next review, and treat material changes with rescreening.

What should we do with a direct sanctions match?

Treat it as a legal red line: stop dealing with the address or person, follow the applicable sanctions law and any reporting requirements, and record the evidence.

Can we rely on the provider's risk band for SMR decisions?

No. The provider result is input. The statutory suspicion test is assessed by the VASP, and the SMR decision and reasoning must be documented.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.