Section 6 · Lesson 6.6
Case: an exchanger checks a client on the way in
Up to now we've examined checks from a private person's standpoint. Now let's step into the shoes of an exchanger — a service through which dozens and hundreds of clients pass in a day. Here AML stops being one-off curiosity and becomes a conveyor: clear thresholds, automation on the way in, manual review of "grey" cases, and a properly drawn-up decline. We'll break down how an exchanger applies the checklist to an incoming address, where it sets the risk boundaries, and how it declines in a way that neither breaks the law nor loses its reputation.
The situation
- ServiceA USDT (TRC-20) → rubles exchanger. The client sends USDT to a deposit address issued to them and receives rubles to a card.
- TaskNot to accept dirty crypto that will later be frozen on deposit to an exchange, or that will lead a regulator to the exchanger.
- VolumeThe client flow makes checking each one by hand impossible — automation with manual review of borderline cases is needed.
Why an exchanger is obliged to check on the way in. An exchanger is a VASP (a virtual-asset service provider under the FATF classification). Having accepted dirty funds, it becomes a link in laundering and bears responsibility. A check on the way in is not a service for the client but a condition of the business's survival: without it, an exchanger sooner or later loses its bank accounts and falls under criminal risk.
How an exchanger applies the checklist to an incoming address
The logic is the same as in the basic checklist, but built into the flow and split into levels of automation. Let's trace the path of a single deal.
- The client submits a request. They specify the amount, network, and card details for payout. The exchanger issues a deposit address.
- The deposit arrives. The system records the incoming transaction and extracts the sender's address (and, in UTXO networks, the input sources).
- Auto-screening. The address goes to the AML API. Back come the score, categories and exposure shares.
- Sanctions filter. First of all — a
sanctions check: a link to OFAC/a wanted list at 1–2 hops = an instant stop, no arithmetic.
- Score and category assessment. Next — matching against the exchanger's thresholds and assessing the materiality of the categories (a mixer and theft are heavier than "gambling" or "p2p").
- Routing. The green zone — auto-payout; yellow — to an operator for manual review; red — hold and decline.
Where the exchanger sets its thresholds
A threshold is not a universal constant but a specific service's risk-appetite policy. Below is a typical, reasonable breakdown. A conservative exchanger shifts the boundaries down, an aggressive one up, but for everyone sanctions = zero tolerance.
0–39: green
auto-payout
→
40–74: yellow
manual review + source request
→
75–100: red
decline, hold
- Sanctions — off the scaleAny link to a sanctioned address = decline regardless of the number. The threshold here is zero.
- Category multipliersThe same score of 55 means different things: if it's built from
mixer/theft — closer to red; from gambling/exchange — it can go to yellow with a request for explanations.
- Amount thresholdA large deal undergoes enhanced due diligence (EDD) even at a moderate score.
- Hop depthA direct inflow from a mixer is heavier than 0.5% indirect exposure at 4 hops. Thresholds account for proximity.
The threshold must be written down. "We eyeball it" is not a policy but the absence of one. Thresholds, category weights and escalation rules must be fixed in the service's AML policy. Then decisions are reproducible, and an operator doesn't decline on a whim.
The yellow zone: how an exchanger handles a "grey" address
The most valuable skill is working with borderline cases, because green and red ones are obvious. In the yellow zone the exchanger doesn't decline at once but requests the source of funds (Source of Funds) from the client.
- Request for explanations. "Where did these funds come from?" — the answer and its confirmation (a screenshot of a withdrawal from an exchange, a contract, a history).
- Plausibility check. Does the client's story line up with the picture on the blockchain? "Salary in crypto" and an inflow straight from a mixer do not line up.
- The operator's decision. Plausible and confirmed — payout with a note in the file. No answer or a contradiction — decline.
How an exchanger draws up a decline
A decline is a legally sensitive moment. It has to be done correctly: not to "stiff" the client, but also not to pass the dirt further on.
- Do not carry out the exchange — the rubles are not paid, the deal is not executed.
- Return to the sender's address. The funds are returned to exactly where they came from (the same address), minus the network fee. A return to a "different" address at the client's request is forbidden — that would aid laundering.
- Recording the reason. In the log — the score, category, date, grounds for the decline. To the client — a neutral wording: "the deal cannot be carried out following the check."
- A sanctions case — specially. With sanctions exposure a return may be impossible/impermissible; the funds are held, and the case is escalated to compliance and, if necessary, to a lawyer.
- No "coaching" the client. Don't explain in detail exactly what triggered — otherwise you teach the launderer to bypass the filter next time.
Balancing two risks. An exchanger constantly balances between the risk of accepting dirt (regulatory/criminal) and the risk of declining a clean client (reputational/financial). Written thresholds, handling the yellow zone with a source request, and a careful decline are the instrument of that balance. Too strict — you lose clients; too lax — you lose the business.
The case conclusion
- An exchanger checks an incoming address on a conveyor: auto-screening + a sanctions filter + manual review of the yellow zone.
- Thresholds (e.g. 40 and 75) are a written risk-appetite policy, not "by eye"; sanctions are always = zero tolerance.
- The same score from different categories calls for a different response; the amount and hop proximity intensify the check.
- A "grey" address means a source-of-funds request and a plausibility check, not an automatic decline.
- A decline is drawn up correctly: a return to the sender's address, recording the reason, a neutral wording to the client.
The example is instructional. The specific thresholds are an illustration, not a recommendation; each service sets them in its own AML policy.