A crypto exchange sits between its customers and the wider financial system, and that position carries an obligation: to know who its customers are and to keep illicit value from moving through its books. Anti-money-laundering screening is how an exchange meets that obligation in practice. It is not a single check run once at sign-up but a set of controls that examine both the people and companies an exchange deals with and the blockchain addresses their assets come from and go to.

For an exchange these two questions are distinct and equally necessary. One asks whether a customer or counterparty appears on a sanctions list, is a politically exposed person, or is the subject of credible adverse media. The other asks whether a wallet address is linked to theft, fraud, a sanctioned entity or a high-risk service before assets are credited or released.

This article sets out the two forms of screening an exchange needs, where they sit in onboarding, deposits, withdrawals and ongoing monitoring, and how the capability is built, bought and integrated — at the level of concept, process and high-level architecture, not a recipe for a screening engine or a set of scoring thresholds.

Two Screens Every Exchange Must Run

The word screening covers two different activities that an exchange must run side by side. Name and entity screening looks at identities: it checks a customer, and where relevant a counterparty, against sanctions lists, lists of politically exposed persons, and adverse-media sources, to establish whether dealing with that party carries heightened financial-crime risk. Wallet and on-chain screening looks at addresses: it assesses a blockchain wallet by its links, direct and indirect, to illicit activity or sanctioned actors, and returns a view of how risky a deposit or withdrawal to that address is.

Neither substitutes for the other. A customer can pass identity screening cleanly and still send funds to a wallet associated with a hacked exchange; a wallet can look unremarkable while the person behind the account is sanctioned. An exchange that runs only one of the two leaves an obvious gap. The design goal is a single financial-crime view in which identity risk and on-chain risk are assessed together and feed the same decisions, so that a withdrawal is judged on both who is sending it and where it is going. This capability is closely tied to KYC verification, which establishes identity in the first place, and to broader AML screening.

The two forms of screening an exchange runs, and how they differ in inputs, timing and output
DimensionName and entity screeningWallet and on-chain screening
What it examinesPeople and companies against sanctions, PEP and adverse-media data.Blockchain addresses and their exposure to illicit or sanctioned sources.
Typical inputsName, date of birth, nationality and other identity attributes.A wallet address and the network it belongs to.
When it runsAt onboarding and on a periodic, ongoing basis thereafter.At the moment of a deposit or a withdrawal, before funds move.
Primary outputMatches to review and a customer risk assessment.A risk score and the reasons behind it, to allow, hold or block.

Where Screening Fits in the Exchange Lifecycle

Screening is not a stage a customer passes through once; it is woven through the whole relationship. It begins at onboarding, alongside identity verification, when name and entity screening establishes a customer's initial risk profile before the account is opened. It continues at every deposit and withdrawal, when wallet screening examines the address on the other side of the movement. And it runs continuously in the background, because a customer who was clear at sign-up can later be added to a sanctions list or become the subject of adverse media.

Designing this well means treating screening as part of the flows customers already use rather than a separate gate bolted on beside them. When someone opens an account, requests a withdrawal or receives a deposit, the relevant checks should run inside that action, return a decision fast enough not to disrupt it, and escalate only the cases that genuinely need a human. The controls have to be native to onboarding, deposits and withdrawals, which is a matter of architecture as much as policy.

Wallet and Transaction Screening

Wallet screening answers a question unique to crypto: not just who a customer is, but where their money has been. Because activity on public blockchains is visible, an address can be assessed by its connections — whether it has received value from, or sent value to, wallets tied to theft, fraud, darknet markets, sanctioned entities or other high-risk services, whether directly or through intermediary hops. The output is a risk indication for a specific address, which the exchange uses to decide whether to credit an incoming deposit, allow an outgoing withdrawal, or hold the movement for review.

The practical demands are that the check runs at the moment it is needed, covers the blockchains the exchange actually supports, and returns a result the exchange can act on and later explain. Wallet screening sits close to the crypto exchange platform's deposit and withdrawal logic precisely because its decisions have to be made in line, while the transaction is still pending, rather than reconstructed afterwards.

Name, Sanctions, PEP and Adverse-Media Screening

The identity side of screening tests a person or company against three kinds of source. Sanctions screening checks whether the party appears on the lists maintained by the relevant authorities, because dealing with a sanctioned party is prohibited outright. PEP screening identifies politically exposed persons, whose position calls for enhanced scrutiny rather than refusal. Adverse-media screening looks for credible reporting that links the party to financial crime or related conduct. Company screening applies the same logic to corporate customers and, where needed, to the people associated with them.

The engineering challenge here is matching. Names are transliterated, abbreviated and shared, so screening produces candidate matches that a person then confirms or dismisses; the aim is to catch true matches without drowning reviewers in noise. Entity screening of a company is not the same as full business verification: confirming that an organisation is not sanctioned is a narrower question than establishing its ownership and structure, and the two should not be conflated. Identity screening depends on the attributes captured during onboarding, which is why it is designed together with the exchange's KYC flow rather than after it.

Alerts, Risk Scores and Ongoing Review

Screening does not deliver verdicts; it produces signals that inform decisions. A name match, a PEP flag or a high wallet-risk score is an indication to be assessed, not proof of wrongdoing, and a workable exchange applies a risk-based approach: most activity proceeds automatically, a defined set of cases is held for review, and clear criteria govern which is which. Consolidating identity and on-chain signals into a single customer risk view lets an exchange make those decisions consistently rather than one screen at a time.

Note: Screening generates alerts, and a proportion of them will be false positives — a legitimate customer who shares a name with a listed person, or an address flagged by a distant, indirect link. The aim is not to eliminate alerts but to manage them: to tune the balance between catching genuine risk and burdening customers and reviewers, and to record the basis of each decision.

Because risk is not fixed, screening has to be ongoing. Sanctions lists change, new adverse media appears, and a wallet's risk profile shifts as the chain around it evolves, so customers and, where relevant, their known addresses are re-screened periodically rather than only at sign-up. Every alert, decision and score should leave an audit trail: what was screened, what was found, and why the exchange allowed, held or blocked the activity. That record is what a supervisor or auditor asks to see, and it is what turns screening from an assertion into demonstrable control.

UK and EU Expectations

For an exchange serving UK and EU customers, screening is not optional good practice; it is how established anti-money-laundering obligations are met. In the United Kingdom, cryptoasset businesses operate under the money-laundering rules and are supervised by the FCA, which expects firms to screen customers and monitor activity for financial crime. Registration under that regime is a financial-crime gateway rather than authorisation for the wider activities an exchange may undertake, and the incoming UK cryptoasset regime is expected to build on these obligations rather than remove them — a design that meets UK regulatory readiness keeps screening at its centre.

In the European Union, anti-money-laundering requirements apply within the authorised-CASP environment set by the wider framework, and they are being consolidated: a single EU-wide rulebook and a dedicated EU-level anti-money-laundering authority are reshaping how these obligations are defined and supervised across member states. The engineering task does not change with the acronyms. We do not provide legal opinions or guarantee authorisation. We implement regulatory and audit requirements across technology, infrastructure and operations. Which customers and transfers fall in scope, and what must be screened and recorded, are questions for qualified advisers; the exchange's job is to make the controls run consistently, as part of EU regulatory readiness.

Building, Buying and Integrating the Capability

Few exchanges build screening data from scratch. Sanctions, PEP and adverse-media coverage, and the on-chain intelligence behind wallet risk scores, depend on maintained data that is bought in rather than assembled in-house; the realistic decisions are which capability to adopt and how to integrate it. Sensible criteria include the breadth of data behind name screening, the blockchains covered by wallet screening, how cleanly the checks fit existing onboarding, deposit and withdrawal flows, whether identity and on-chain results can be combined into one risk view, and where the personal data involved is processed and stored.

Legichain, Grumpio's product for financial-crime screening, is built around this combined need. It provides person and company screening against sanctions, PEP and adverse-media data, together with wallet risk screening across multiple blockchains, returning a risk score and a PDF evidence report; it is reached through an API and a web panel, supports periodic re-screening, and draws on a single credit pool, with on-premises or dedicated storage where an exchange requires it. Pricing and detail sit on the product site rather than in an exchange's design decision — Legichain sets these out in full. Whichever route an exchange takes, integration decides the result: screening has to become a native part of onboarding, deposits and withdrawals rather than a service queried on the side.

Summary and Next Steps

An exchange has to screen on two fronts at once: the identities of the people and companies it serves, against sanctions, PEP and adverse-media sources, and the blockchain addresses their assets move through, against links to illicit activity. Neither replaces the other, both belong inside onboarding, deposits, withdrawals and ongoing monitoring rather than beside them, and both produce signals to be assessed under a risk-based approach and recorded as audit evidence. For UK and EU markets this is settled obligation, not optional refinement.

Firms planning or operating an exchange can begin by mapping name and wallet screening onto their existing identity, deposit and withdrawal flows, deciding where automated decisions end and human review begins, and designing a single risk view that draws both signals together. Our work on crypto exchange software and AML screening sets out how these controls are engineered into the exchange rather than added at its edge.

Screen the customer and the wallet, in one flow. Grumpio builds crypto exchange platforms in which identity and on-chain screening are part of how onboarding, deposits and withdrawals work.