How to Read a Crypto AML Risk Score
A practical guide to crypto AML reports: identify the provider's scale, separate sanctions from exposure, and treat missing data as an open review.
Treat an AML risk score as a provider-specific summary of evidence, not as a universal pass or fail. Start with the report's scale and timestamp. Then read the underlying flags, coverage, and unknowns before deciding what your policy requires. A low number can support a review; it cannot guarantee that an exchange will accept the funds.
The number is only one field in a report. A provider might publish a 0–100 composite score, a band, category labels, or a different scale entirely. GetBlock's Crypto AML page shows a composite score and categorized exposure breakdown in its product preview, but that presentation is not a market standard and its sample values are not evidence about a wallet you are reviewing.
Read the report in order
Confirm what was actually screened
Check the network, asset, and input type first. A wallet address and a transaction hash answer different questions. If the report omits the chain or token variant, stop and resolve the input instead of interpreting the score.
Next, find the report's as of time, data refresh note, calculation or case identifier, and provider version. Record those fields in your case file. On-chain activity can continue after a check, and a list or attribution can change. The same address queried later may produce a different result without either report being malformed.
Read the scale and labels
Look for the provider's explanation of direction. Does a larger number mean greater risk, lower risk, or simply a percentile, and what does each band mean? If the document does not define the direction or threshold, preserve the value as unclassified and ask the provider. Never copy a threshold from another service.
A sanctions match is a list or identity question. A token blacklist can be an address restriction enforced by a token contract or issuer. Counterparty exposure describes links in the address's transaction history. These are different facts even when a dashboard places them beside the same score, so record the exact category and explanation rather than translating all of them into “high risk.”
Separate evidence from the decision
Use the report to answer evidence questions, and your policy owner to answer action questions. A review may need a human to consider the counterparty, purpose, amount, jurisdiction, and the relevant list or policy. OFAC's virtual currency guidance describes sanctions compliance practices tailored to the virtual currency industry and a risk-based approach. It does not prescribe one score threshold for all firms or transactions.
If a report returns no match, ask what sources and time range were covered. “No match found” is narrower than “the address is safe.” If attribution is unavailable, mark it unknown. If the provider times out, mark the screening status unknown and retry under a documented rule or send it for manual review. Do not treat absence of data as a clean result.
A reviewer’s scorecard
| Report element | Question to ask | Record in the case |
|---|---|---|
| Input | Which chain, asset, address, or transaction was queried? | Exact values, with no shortened address as the only copy |
| Scale | What does the number and each band mean? | Provider definition and threshold source |
| Signals | Is this sanctions, blacklist, exposure, or another category? | Category, direction, explanation, and match status |
| Coverage | Which lists, labels, hops, and dates were included? | Stated scope and gaps |
| Status | Did the provider complete the query? | Completed, unknown, timeout, or provider error |
| Decision | What does the applicable policy require next? | Action, reviewer, reason, and time |
The AML screening checklist CSV is a base worksheet with fields for network, subject type and subject, check time, source, sanctions signal, exposure, coverage, and review. It has no dedicated score or status columns, so add those as notes or extra columns when your review needs them. Fill it from the original report, include its source URL and retrieval time, and keep the raw report where your review process allows.
Compare two reports without forcing a ranking
Two services can disagree because they use different labels, attribution data, list versions, hop limits, or score directions. Normalize the evidence fields first: same chain, same asset, same input, comparable timestamps, and clearly named categories. If those conditions do not hold, preserve both outputs and write down the difference. A disagreement is a question for review, not proof that one service is wrong.
For a one-off USDT counterparty check, use Request check, choose the job, network, and expected volume, and add a Telegram username. Keep the address and report for follow-up; an operator confirms availability, scope, and price on Telegram before you share it. The initial Spawn path is manual, so this request does not promise an automated report or turnaround time. For recurring decisions, read How to check a USDT address and how to select a crypto AML API, which focuses on preserving these meanings when software receives a result.
Sources
- GetBlock Crypto AML (example of a provider-specific score and exposure presentation checked September 16, 2026)
- OFAC virtual currency sanctions guidance announcement (risk-based sanctions guidance, October 15, 2021)
- BestChange cryptocurrency address AML check (public address, asset, and analyzer inputs checked September 16, 2026)
