Skip to content
Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Audit & Advisory Investigation Crypto OSINT Investigation Training & Advisory Seqlense Immo Pricing Academy Blog Partners Supported Chains Contact My Seqlense Get Started
Back to blog

KYT vs KYC: why transaction monitoring is now non-negotiable

Where identity checks stop and continuous behaviour monitoring has to start.

Identity is a snapshot. Behaviour is a film. For years, compliance teams treated onboarding checks as the main line of defence against financial crime: verify who the customer is, confirm the documents, screen the sanctions lists, and move on. That model no longer holds, especially in crypto. A wallet that passed every identity check on Monday can be receiving funds from a sanctioned mixer on Friday. This is the gap that Know Your Transaction (KYT) is built to close, and EU rules now make continuous monitoring an obligation rather than a nice-to-have.


What KYC actually verifies (and what it misses)

Know Your Customer answers a single question: is this person or entity who they claim to be, and are they allowed to be your customer? It covers identity verification, beneficial ownership, sanctions and PEP screening, and a risk rating at onboarding. Done well, it stops obvious bad actors at the door.

But KYC has three structural blind spots:

  • It is a point in time. A clean check at onboarding says nothing about what happens six months later.
  • It verifies identity, not intent. A legitimate user can be knowingly or unknowingly moving illicit funds.
  • It stops at your customer. In crypto, the counterparties matter as much as the account holder, and KYC never looked at them.

What KYT adds: the behaviour layer

Know Your Transaction shifts the focus from who to what they do over time. In practice it means scoring and screening activity continuously against risk signals. For a bank that looks like velocity checks, structuring detection and unusual-pattern alerts. For a crypto business it goes further, because the blockchain itself is a public ledger of counterparties.

On-chain, KYT typically covers:

  • Source and destination of funds, tracing whether value came from or is heading to a mixer, a sanctioned address, a darknet market or a known theft.
  • Exposure scoring, measuring how many hops separate a wallet from illicit activity and how much of its history is tainted.
  • Behavioural baselines, flagging when an account suddenly transacts in ways that do not fit its own profile.
  • Real-time alerting, so a risky inbound transfer can be held or reviewed before funds are credited.

The two disciplines are complementary, not competing. KYC tells you the account belongs to Alice. KYT tells you Alice's account just received funds two hops from a wallet on a sanctions list. You need both.

KYC KYT
Question Who is the customer? What is the customer doing?
Timing At onboarding, periodic refresh Continuous
Scope Your customer Customer plus counterparties
Signal Identity, documents, screening Flows, patterns, on-chain exposure

Why this is now non-negotiable in the EU

The regulatory direction of travel has removed most of the room to treat monitoring as optional.

The EU Transfer of Funds Regulation (the recast TFR) extended the "travel rule" to crypto-asset transfers and began applying from 30 December 2024, alongside the main provisions of MiCA. Crucially, unlike the 1,000 EUR threshold that applies to some traditional transfers, the crypto travel rule applies with no de minimis threshold: information on originator and beneficiary must accompany transfers of any size (Jones Day).

At the same time, the EU's Anti-Money-Laundering Regulation (AMLR), adopted in 2024, folds crypto-asset service providers squarely into the obliged-entity regime: ongoing customer due diligence, suspicious-transaction reporting to Financial Intelligence Units, and multi-year record keeping. These are continuous duties, not onboarding events.

Both build on the Financial Action Task Force (FATF) standards, whose Recommendation 16 travel rule for virtual assets is the global baseline that EU law now enforces (FATF, Elliptic).

The practical takeaway: to comply with the travel rule and to file meaningful suspicious-activity reports, a provider must be watching transactions as they happen. Identity data alone cannot generate a travel-rule payload or spot a laundering pattern.


Building monitoring that regulators respect

Effective transaction monitoring is less about buying an alert engine and more about wiring it into a defensible process. A workable programme usually has:

  1. A risk-based rule set tuned to your products, geographies and customer types, not a generic template.
  2. On-chain exposure screening for every relevant address, with clear thresholds for when exposure triggers review.
  3. Alert triage and case management that records who reviewed what, when, and why a decision was made.
  4. A feedback loop so confirmed cases sharpen the rules and cut false positives over time.
  5. An audit trail that lets a supervisor reconstruct any decision months later.

The last point matters more than teams expect. When a regulator asks why a transfer was cleared, "the system did not alert" is not an answer. Documented reasoning is.


Where Seqlense fits

Continuous on-chain surveillance is exactly the behaviour layer KYC cannot provide. Seqlense Monitoring watches blockchain addresses, scores risk and raises alerts as activity develops, so a wallet that turns risky after onboarding does not slip through. When an alert needs to become a case, Seqlense Investigation and OSINT services help trace flows and counterparties to the level of detail a suspicious-transaction report requires. And because obligations keep shifting, Seqlense Doc tracks guidance and rule changes across European regulators, so your monitoring thresholds stay aligned with what supervisors actually expect.

KYC gets the customer through the door. KYT is what keeps you safe once they are inside.


Sources

Related articles

Why compliance is a monitoring problem, not a paperwork problem

The thesis behind treating regulatory and on-chain watch as one live signal.

The real cost of a missed regulatory deadline

Fines, remediation and reputational drag, made concrete.