A crypto AML risk assessment is the written analysis that tells you where money laundering could actually enter your business, how likely each path is, and what controls you have standing in the way. Regulators in every serious jurisdiction now expect one before they expect anything else. When an examiner opens your file, the risk assessment is usually the first document they ask for, because everything else in your compliance program is supposed to flow from it. If your transaction monitoring rules, your customer due diligence tiers, and your sanctions screening settings do not trace back to a documented risk decision, the examiner treats them as decoration.
The problem is that most teams write their first risk assessment backwards. They buy tools, set thresholds, and then write a document that justifies what they already bought. This guide walks through the forward direction: measure your actual exposure first, score it honestly, and let the scores decide where your money and your alerts go. We compiled the numbers below from Chainalysis crime data spanning 2020 through 2025, so the likelihood side of your scoring is anchored to observed criminal behavior rather than guesswork.
Quick solution
If you need a defensible crypto AML risk assessment fast, do these six things in order. First, list every product, customer type, geography, and asset you touch — that list is your inventory of risk factors. Second, score each factor for inherent risk on a simple 1-to-5 scale using published crime data, not intuition. Third, map every existing control to the factor it mitigates and score how much it actually reduces the risk. Fourth, subtract to get residual risk and rank the results. Fifth, write down the decisions the ranking forces: which factors need new controls, which need tuned thresholds, and which you accept. Sixth, date the document, get it approved by someone senior enough to be accountable, and calendar a refresh every twelve months or after any material change. A spreadsheet plus this discipline beats an expensive platform with no discipline every time.
Image: Chainalysis — total value received by illicit cryptocurrency addresses, 2020 through 2025, from the 2026 Crypto Crime Report introduction
Strip away the jargon and a risk assessment is three lists joined together. The first list is everything about your business that could attract laundering: the products you offer, the customers you accept, the countries you serve, and the assets you support. The second list is the threats that apply to each item, weighted by how often they actually occur. The third list is your controls, weighted by how well they actually work. Inherent risk is lists one and two multiplied together. Residual risk is what remains after list three is applied. The document that records those lists, the scores, and the decisions they produced is your risk assessment.
The reason regulators care so much is that the assessment is the only place where you are forced to be honest about trade-offs. A transaction monitoring system can look impressive while watching the wrong things. A risk assessment that says "we serve customers in high-risk corridors and our monitoring does not cover peel chains" cannot hide anything. Examiners under the Bank Secrecy Act framework in the United States, MiCA-era supervisors in the European Union, and the Monetary Authority of Singapore all converge on the same expectation: show us the analysis that explains why your program looks the way it does.
Scale matters here. Chainalysis estimated that addresses tied to illicit activity received on the order of 154 billion dollars during 2025, the largest figure the firm has recorded, with sanctioned entities driving much of the growth. Your assessment does not need to cite every number, but it needs to demonstrate that your likelihood scores came from somewhere real. That is the difference between an assessment an examiner accepts and one that triggers a findings letter.
The four risk pillars you must score
Every credible methodology, from the FATF guidance down to state money-transmitter examinations, organizes crypto AML risk into the same four pillars. Score all four or your assessment has a hole an examiner will find.
Products and services. An exchange with fiat on-ramps carries different exposure than a custody-only business or a payments processor. Features are risk factors: margin trading, cross-chain swaps, privacy coin support, and peer-to-peer transfers each open a distinct laundering path. Score each feature separately rather than scoring "the platform" as one line.
Customer types. Retail individuals, corporate accounts, other virtual asset service providers, and institutional desks each launder differently when they launder at all. A counterparty VASP with weak controls is a pipe into your platform from every one of its customers, which is why vasp due diligence deserves its own line in the assessment rather than a footnote under customer risk.
Geography. Corridor risk is about where value moves, not just where customers sit. A customer base concentrated in strong-supervision jurisdictions can still route value through services in weak ones. Map your actual flow data — your top counterparty services and their jurisdictions — rather than relying on the address a customer typed at onboarding.
Assets and channels. Stablecoins now dominate illicit transaction volume by asset, which means an assessment written in 2021 that treats Bitcoin as the primary threat vector is measuring the wrong thing. Every asset you list needs its own likelihood score based on current crime data, and every channel — on-chain deposits, internal transfers, fiat rails — needs its own controls mapping.

Image: Chainalysis — illicit transaction volume by asset category, 2020 through 2025, showing the shift toward stablecoins
The likelihood column is where most assessments fall apart, because teams guess. You do not have to guess. Public blockchain intelligence gives you base rates that map directly onto your risk factors.
Start with the denominator. Illicit activity was roughly 0.14 percent of all on-chain transaction volume in 2024 by Chainalysis measurement. That sounds reassuring until you remember it is an average across the entire economy. Your job is to figure out where your business sits relative to that baseline. A platform supporting instant swaps into stablecoins with customers in Eastern Europe and MENA sits well above it; a custody business serving vetted institutions sits below it.
Then adjust by asset. If stablecoins are the majority of your volume, weight your stablecoin likelihood scores up, because that is where illicit volume has migrated. Adjust by victim exposure too: laundering behavior differs depending on whether stolen funds came from personal wallet compromises or service breaches, and the destinations those funds favor — DEXs, bridges, mixers, no-KYC exchanges — tell you which of your own features are attractive to launderers.
Finally, adjust by geography using flow data rather than headlines. Regional victimization and laundering patterns shift year to year, and your top ten counterparty services will tell you more about your real corridor exposure than any country list. Write the number you used and its source next to every score. An assessment with citations is auditable; an assessment with bare numbers is an opinion.

Image: Chainalysis — illicit activity as a share of total on-chain transaction volume, from the 2025 Crypto Crime Report
More in Guides
Mapping controls to risks honestly
A control only counts if it actually intercepts the risk on the same line of the assessment. This is where the honest-subtraction discipline earns its keep.
Take deposit-side laundering of stolen funds. The observed destinations for stolen value are centralized exchanges, DEXs, bridges, and mixing services, with the mix shifting by victim type and by year. If your platform is a centralized exchange, you are on that destination list whether you like it or not. The control that intercepts this risk is real-time deposit screening against stolen-funds attribution — not your annual training program, not your board reporting. If you have deposit screening, score the mitigation. If you only screen at withdrawal, your residual risk on that line stays high and the assessment should say so.
The same logic applies across the program. Sanctions exposure is mitigated by screening depth and list latency, which is why your crypto sanctions screening tools configuration belongs in the controls column with its actual settings documented. Layering through your platform is mitigated by monitoring rules tuned to the typologies you scored, which is the job your crypto aml compliance software was bought to do. Each control gets an effectiveness score backed by evidence: alert quality reviews, lookback results, testing outcomes. A control that generates thousands of alerts nobody clears is not a control; it is a liability with a subscription fee.

Image: Chainalysis — where stolen funds go after theft, split by victim type, from the 2025 Crypto Crime Mid-Year Update
Choosing tooling that matches your risk tier
Tool selection comes after scoring, not before. A five-person startup with residual risk concentrated in two corridors needs different tooling than a multi-jurisdiction exchange. Because no single public source compares risk-assessment capabilities across the major blockchain intelligence vendors, we compiled one from vendor documentation, published product pages, and regulatory filings current to mid-2026.
| Vendor | Risk assessment strength | Best fit | Data depth | Typical buyer |
|---|---|---|---|---|
| Chainalysis | Entity-level exposure scoring backed by the largest published attribution dataset | Exchanges and VASPs needing examiner-recognized data | Very deep, cross-chain | Mid-size to large exchange |
| Elliptic | Configurable risk rules with holistic wallet screening | Firms wanting granular per-rule tuning | Deep, broad asset coverage | Compliance teams with analysts |
| TRM Labs | Risk scoring integrated with investigations workflow | Teams that combine assessment with casework | Deep, strong on newer chains | Investigations-heavy programs |
| ComplyAdvantage | AML risk data joined to traditional watchlist screening | Fintechs bridging fiat and crypto exposure | Moderate on-chain, strong lists | Payments and neobanks |
| Merkle Science | Behavioral rule engine with predictive typology flags | Firms in APAC corridors | Moderate, growing | Regional exchanges |
| Scorechain | Straightforward scoring with EU-oriented reporting | Smaller EU VASPs on a budget | Moderate | Early-stage VASPs |
The right reading of this table is not "which vendor is best" but "which vendor covers the residual risks my assessment ranked highest." A program whose top residual risk is stolen-fund deposits should weight attribution depth. A program whose top risk is corridor concentration should weight geographic flow analytics. Let the document drive the purchase order.
A risk assessment is a cycle, not a deliverable. The document you approve is a snapshot; the process that keeps it true is the control.
Set a fixed refresh cadence of twelve months at most, and trigger off-cycle refreshes on material changes: a new asset listing, a new jurisdiction, a new product feature, an acquisition, or a shift in the external threat data. The external environment moves fast enough to matter. Total crypto losses across services and personal wallets have run in the billions of dollars every year since 2022, with the mix between service breaches and personal wallet compromises shifting annually — a monitoring program tuned to last year's mix drifts out of alignment without anyone making a bad decision.
Each cycle should also re-test control effectiveness rather than carrying scores forward. Laundering costs and behavior change on the criminal side too: the average fees launderers pay and the premium they accept for moving stolen funds have moved substantially year to year, which changes which of your friction points actually deter anyone. Document what you re-tested, what changed, and which scores moved. An assessment whose scores never move is not stable; it is stale.
Assign a single accountable owner. Committees review; one person owns. That person signs the document, presents it to the board or senior management, and owns the remediation list it produces. Examiners consistently read diffuse ownership as no ownership.

Image: Chainalysis — total crypto losses split between service breaches and personal wallet compromises, 2022 through 2025
Common situations and what to do
Real programs rarely start from a clean page. These three situations cover most of the teams we hear from.
"We are a startup exchange going for our first state money-transmitter licenses, and we have never written a risk assessment." Start with the six-step quick solution above and keep the first version under twenty pages. Examiners for a first license want to see sound method and honest scoring, not volume. Score your four pillars, cite public crime data for likelihood, map the controls you actually have, and be explicit about the gaps with dates for closing them. A short document that admits its gaps outperforms a long one that hides them.
"We are a mid-size VASP and our last assessment was outsourced to a consultancy two years ago." The consultancy document is now a liability twice over: it is stale, and nobody in-house can defend its scores in an exam. Rebuild it internally using the old document as a starting inventory. The rebuild forces your team to learn where the numbers came from, which is precisely what an examiner tests when they ask "why is this a three and not a four."
"We are a payments company adding stablecoin settlement to an existing fiat product." Do not bolt a crypto annex onto your fiat assessment. Stablecoin settlement changes your asset pillar, your geography pillar through new counterparty corridors, and your monitoring surface — flows through your transaction monitoring for crypto exchanges stack behave nothing like card rails. Run a full four-pillar scoring pass on the new product before launch and let it set your monitoring thresholds from day one.
Mistakes that sink assessments in exams
- Scoring inherent risk after choosing controls. If every inherent score conveniently lands just above the control you already bought, examiners recognize the pattern instantly. Score exposure first, blind to your tooling, then map controls.
- Treating the assessment as an annual document rather than a living one. A new asset listing or corridor that never triggers a re-score is the single most common finding. Wire material-change triggers into product launch checklists so the assessment cannot be bypassed.
- Copying a generic template without measuring your own flows. Templates list every theoretical risk equally. Your actual counterparty exposure data — which services, which jurisdictions, which assets — is what makes the document yours, and its absence is what makes a template obvious.
- Ignoring the laundering-cost side of deterrence. Controls work by raising the cost of moving illicit value through you. If you never ask which of your frictions launderers actually route around, you will keep investing in controls that inconvenience customers while leaving the cheap path open.

Image: Chainalysis — average laundering fees and stolen-fund premium over time, an indicator of how much friction criminals tolerate
Frequently asked questions
How often should a crypto AML risk assessment be updated?
At minimum once every twelve months, and immediately after any material change: a new asset, product feature, jurisdiction, customer segment, or a significant shift in external threat data. Most regulators treat an assessment older than a year as stale, and most findings letters cite an unassessed change rather than a missing document.
What is the difference between inherent risk and residual risk?
Inherent risk is your exposure before controls: the likelihood and impact of laundering given your products, customers, geographies, and assets with nothing standing in the way. Residual risk is what remains after your actual controls, scored at their actual effectiveness, are applied. Regulators expect to see both numbers and the subtraction between them, because the gap is what justifies your control spend.
Can a small VASP do a risk assessment without buying a platform?
Yes. The methodology is a structured spreadsheet: factors, likelihood scores with cited sources, impact scores, control mappings, residual scores, and decisions. Blockchain intelligence platforms make the likelihood data richer and the refresh cheaper, but the document and the discipline are what examiners grade. Buy tooling when your residual-risk ranking tells you which capability you lack.
Which risk factors matter most for a crypto exchange?
Deposit-side exposure to stolen and sanctioned funds, corridor concentration in weak-supervision jurisdictions, stablecoin flows given their majority share of illicit volume, and counterparty VASP quality. Rapid swap features and cross-chain bridges deserve explicit scoring because they are consistently observed destinations for stolen funds.
Who should sign off on the risk assessment?
A single accountable senior owner — typically the chief compliance officer or BSA officer — with formal approval from senior management or the board. Examiners read committee-only ownership as no ownership, and they routinely test whether the named owner can defend individual scores without the document in front of them.
Sources
- Chainalysis, "2026 Crypto Crime Report Introduction," January 2026 — total illicit value received estimated at 154 billion dollars for 2025, with asset-level breakdowns showing stablecoin dominance.
- Chainalysis, "2025 Crypto Crime Mid-Year Update," July 2025 — stolen fund laundering behavior by victim type and destination, total losses across services and personal wallets, and laundering fee trends.
- Chainalysis, "2025 Crypto Crime Report," February 2025 — illicit activity measured at 0.14 percent of total on-chain transaction volume for 2024.



