On-Chain Analytics and AML Risk - How deep do you go?
Hey everyone, still relatively new to the compliance side of things, especially with crypto. I've been spending a fair bit of time trying to wrap my head around effective AML/CFT measures for businesses dealing with digital assets. We're obviously checking source of funds, doing KYC, the usual stuff. But when it comes to on-chain analytics, it feels like a rabbit hole. We've got tools that can trace transactions, identify mixers, darknet market exposure, etc.
My question is, where do you draw the line? I understand the need for due diligence, but there's a point where you could just keep digging endlessly into every single UTXO or transaction hop. How do you guys manage the scope of your on-chain analysis without drowning in data or incurring astronomical costs from third-party tools for every minor transaction? Is it risk-based, transaction size, jurisdiction, or something else entirely? Looking for practical insights on setting reasonable boundaries.