Share via:
- Updated on: August 10, 2026
Key takeaways:
KYT compliance, short for Know Your Transaction, is the ongoing monitoring of what a customer does after onboarding, not a one-time check at account opening.
KYC answers who your customer is. KYT answers what they are doing, who they are transacting with, and whether that activity matches their stated profile.
Most KYT gaps are not tooling gaps. They are missing risk scoring on counterparties, alerts nobody dispositions, and no audit trail a reviewer can follow.
FATF Recommendations 15 and 16 set the expectation for transaction-level monitoring at virtual asset businesses, though national implementation varies by jurisdiction.
When you compare KYT tools, test six things: chain coverage, attribution depth, screening latency, counterparty risk scoring, case management, and the quality of the evidence produced.
Your supervisor asks how you monitor customer activity after onboarding. Your banking partner asks the same question in different words, usually before a review of the relationship. If the honest answer is a screening tool that runs once at account opening, you have a KYT compliance gap, and it is the kind that surfaces during an examination rather than quietly. If you are further along and comparing KYT tools rather than defining the term, the six criteria that separate real capability from a dashboard are chain coverage, attribution depth, screening latency, counterparty risk scoring, case management, and exportable evidence quality. Each one is covered below, along with how to test it.
This guide covers what KYT compliance means, how it sits alongside KYC and KYB, where programs fall short under scrutiny, and what to have ready when you are asked to prove yours works.
What is KYT compliance?
KYT compliance is the practice of monitoring, risk scoring, and documenting blockchain transactions on an ongoing basis to detect and act on financial crime risk. It applies to deposits, withdrawals, and internal transfers, and it assesses the counterparties on the other side of each transaction rather than only the customer in front of you. A working KYT program screens transactions in real time, assigns a risk score based on the exposure it finds, generates alerts, records how each alert was resolved, and retains that record for review.
The distinction that matters operationally is timing. KYC happens at a point in time and gets refreshed periodically. KYT runs continuously, because risk arrives with the transaction.
How is KYT different from KYC and KYB?
The three controls answer different questions and produce different evidence. Teams get into difficulty when they assume strong performance on one covers the others.
Control | Question it answers | When it runs | Typical evidence |
|---|---|---|---|
KYC (Know Your Customer) | Who is this individual, and are they who they claim to be? | At onboarding, refreshed periodically | Identity documents, verification records, screening results |
KYB (Know Your Business) | Who owns and controls this corporate customer? | At onboarding, refreshed on material change | Ownership structure, beneficial owner checks, corporate filings |
KYT (Know Your Transaction) | What is this customer doing, and who are they transacting with? | Continuously, on every transaction | Risk scores, alert records, disposition notes, tracing output |
Where do KYT programs fall short?
Four gaps come up repeatedly, and none of them are solved by buying a tool.
Screening stops at onboarding. Address screening runs when a customer first deposits, then never again. Counterparty risk changes over time, and a wallet that was clean in March may be attributed to a scam cluster by August.
Counterparties are not risk scored. A deposit that arrived from an exchange tells you very little on its own. What matters is whether that exchange has weak controls, and whether the funds reached it through a mixer two hops earlier. Without exposure analysis across hops, you are recording addresses and calling it risk assessment.
Alerts are generated but not dispositioned. A queue of open alerts with no resolution notes reads worse to a reviewer than a smaller queue that is fully worked. Reviewers examine the decisions you recorded, and an alert with no disposition records no decision at all.
There is no audit trail. If your analyst cannot reconstruct why a transaction was cleared six months ago, the control cannot be evidenced, and an unevidenced control gets treated as an absent one.
What is the regulatory basis for KYT?
The international baseline comes from the Financial Action Task Force. Recommendation 15 covers new technologies and sets the expectation that virtual asset service providers identify and assess money laundering and terrorist financing risk on an ongoing basis. Recommendation 16, the Travel Rule, requires originator and beneficiary information to accompany transfers above applicable thresholds, which in practice means you need to know who sits on both sides of a transaction. FATF’s Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs sets out how both are meant to apply.
FATF sets standards rather than law. How those standards reach you depends on your jurisdiction, your license, and your supervisor’s current focus, and the thresholds and timelines differ across markets. Treat the recommendations as the framing your supervisor is likely working from, then confirm the specific obligation with your own counsel.
For informational purposes only. Not legal or compliance advice.
What should you look for in KYT capability?
If you are assessing tooling, these are the criteria that matter. Ask for each one to be demonstrated on live data rather than described in a feature list.
Chain coverage. Which blockchains and assets are supported, and are the chains your customers actually use included? Coverage gaps become blind spots.
Attribution depth. How many entities are attributed, how is attribution verified, and can you see the reasoning behind a label? An unexplained risk flag is difficult to defend.
Screening latency. Does screening return a result before you release funds, or after? Real-time matters when the control is meant to prevent rather than report.
Counterparty risk scoring. Does the system trace exposure across multiple hops and cross-chain movement, or does it only look at the direct sending address?
Case management. Can an analyst work an alert, record a decision, and attach reasoning inside the same system, or does that happen in a spreadsheet?
Evidence quality. Can you export something that holds up in front of an examiner, a banking partner, or a court?
Crystal Expert was built around this set. It runs real-time KYT across 330+ blockchains, scores counterparty exposure using verified entity attribution, and produces audit-ready reports with a full trail behind each decision, so the answer to “show me how you resolved this alert” is a document rather than an explanation.
How do you evidence KYT to a supervisor or banking partner?
Have four things ready before you are asked for them.
A written monitoring scope. Which transactions are screened, against what lists and risk categories, at what point in the flow, and what falls outside scope by design. Stating the exclusions deliberately is stronger than leaving them undefined.
Your risk scoring methodology. The thresholds you set, why you set them there, and what changes when a score crosses each one. Include the date of your last threshold review, since a methodology nobody has revisited in two years invites a follow-up question.
A sample of worked alerts. Pick a range rather than your best cases: one cleared, one escalated, one that resulted in a filing or an account restriction. Each should show the analyst decision and the reasoning behind it, with the tracing output attached.
A retention record. Proof you can reconstruct any decision inside your retention period, including which system holds what and how long. This is the item teams most often assume is covered and most often is not.
If you can produce that set quickly, the conversation with your bank is usually short. If assembling it takes three weeks, you will find your own gaps in the process, which is useful, if uncomfortable.
KYT is a control you operate, not a product you own. Get to the point where you can describe yours in two sentences and evidence it in four documents, and you have removed the question from the table.
Frequently asked questions
What does KYT stand for?
KYT stands for Know Your Transaction. It refers to the ongoing monitoring, risk scoring, and documentation of blockchain transactions to detect financial crime risk. The term sits alongside KYC and KYB, and covers customer activity after onboarding rather than customer identity at onboarding.
What is the difference between KYT and KYC?
KYC verifies who your customer is using identity documents and screening, at onboarding and on periodic refresh. KYT monitors what that customer does afterward, assessing every transaction and the counterparties involved. A customer can pass KYC cleanly and still send funds to a high-risk address the same week.
Is KYT a regulatory requirement?
Transaction monitoring for virtual asset businesses is set out in FATF Recommendations 15 and 16, which most jurisdictions implement through national law and licensing conditions. The specific obligation, thresholds, and timing depend on where you operate and what license you hold, so confirm the detail with your counsel.
Who needs KYT compliance?
Crypto exchanges, wallet providers, OTC desks, and payment processors that handle digital assets need KYT as a licensing and banking requirement. Financial institutions with crypto-exposed customers need it to assess inbound risk. Law enforcement and regulators use the same transaction analysis for investigations and oversight.
How do you compare KYT tools?
Compare on-chain coverage, attribution depth and how labels are verified, screening latency against your release process, whether counterparty exposure is traced across multiple hops and chains, case management inside the platform and the quality of exportable evidence. Test each on live data rather than accepting a feature list.
What is the difference between KYT and transaction monitoring?
Transaction monitoring is the broader term used across banking for reviewing customer activity against expected behavior. KYT is transaction monitoring applied to blockchain activity, where the counterparty is an address rather than an account, so it depends on attribution and on-chain tracing that traditional systems do not perform.
Want to see KYT working on live data? Crystal Expert scores counterparty risk for every transfer and provides the audit trail that supervisors ask for. Request a walkthrough.
