Regulators should combine continuous transaction monitoring with risk-based supervision, so they can review large volumes of activity without treating every transaction the same. The practical goal is to spot unusual patterns, verify compliance with AML, KYC, and sanctions rules, and reserve deeper review for the highest-risk activity. That approach supports enforcement while still allowing banks to develop digital asset services responsibly.
How regulators can monitor digital asset activity without choking off innovation
Effective oversight works best when it is calibrated to the activity, not forced into a one-size-fits-all review model. Regulators need visibility into flows, counterparties, and control quality, but they also need to avoid turning routine, low-risk activity into a licensing bottleneck. The right balance is continuous monitoring, targeted intervention, and clear expectations for banks building digital asset services.
Why risk-based monitoring is the practical answer
Digital asset activity can move quickly, span multiple venues, and create more alerts than a manual review process can absorb. A risk-based approach lets supervisors focus on material exposure, such as sanctions screening, customer due diligence, suspicious activity, and concentration in higher-risk products, instead of treating every transfer as equally suspicious. That keeps the supervisory model usable at scale.
For regulators, the key judgement is not whether to monitor, but how to separate ordinary activity from patterns that deserve escalation. Banks should be able to demonstrate that their controls are calibrated to product type, customer profile, geography, and transaction behaviour, rather than to vague concern about digital assets in general.
What good supervision looks like in practice
Good supervision combines automated surveillance with human review thresholds. Regulators should expect banks to maintain alert logic that can detect anomalies, but also to document why certain rule sets are more sensitive for higher-risk digital asset flows. In practice, that means reviewing the quality of the bank’s FATF Recommendations, AML and KYC Framework implementation, not just the volume of alerts it generates.
They should also look for evidence that banks can defend their screening and escalation logic under regulatory examination. If a bank cannot explain how it segments low-risk from high-risk activity, or cannot show that sanctions and customer verification checks are operating consistently, then the monitoring model is too blunt to support innovation responsibly.
A second useful lens is whether institutions are applying existing banking control disciplines to digital asset operations, rather than building a parallel control universe. Core practices such as account governance, logging, access review, and exception handling should still be visible, and the CIS Controls v8 remain a useful reference point for those operational basics.
How to preserve innovation while tightening oversight
The fastest way to slow legitimate innovation is to make every new product await bespoke approval. A better model is supervisory pre-clarity: define what must be monitored, what must be reported, and what can proceed under existing banking controls. That gives firms room to launch digital asset services while keeping the regulator focused on risk signals that matter.
Regulators can also reduce friction by demanding control evidence instead of requiring constant case-by-case approval. If banks can produce audit trails, exception reports, and periodic control attestations, supervisors can reserve deeper review for outlier activity. That approach is consistent with the control emphasis in the EBA AML/CFT Guidance, which supports a risk-based posture in banking supervision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-8 — Audit Log Management | Monitoring digital asset activity depends on reliable logs, alerts, and traceable review evidence. |
| Recommendation — Centralize audit logging so digital asset alerts and investigations remain traceable. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Risk-based supervision requires explicit appetite and escalation rules for different digital asset risks. |
| DE.CM-01 — Continuous Monitoring | Continuous observation is central to spotting unusual digital asset patterns without blocking normal flows. | |
| Recommendation — Define risk thresholds that let routine activity proceed while escalating true exceptions. Use continuous monitoring to detect anomalous digital asset activity at scale. | ||
Practitioner Guidance
What to prioritise: Start with monitoring that is calibrated to risk factors the bank can actually evidence, especially customer risk, product risk, and sanctions exposure. If the control team cannot explain why a rule exists or what risk it detects, it will usually create noise rather than insight.
What to verify: Check that automated alerts feed into a documented human escalation path, and that higher-risk digital asset activity receives faster review without forcing all activity through the same queue. The practical test is whether the bank can prove proportionality, not merely volume.
Common mistake: Treating innovation and supervision as opposing goals. In practice, well-designed monitoring can speed approval of legitimate activity by giving regulators confidence that unusual behaviour will surface quickly and consistently.
Practitioner takeaway: The objective is not to inspect every digital asset transaction equally, but to build a monitoring model that is selective enough to support scale and strict enough to surface genuine abuse.
Related resources from NHI Mgmt Group
- How can teams monitor digital asset activity without overrelying on narrative analysis?
- How should regulators and compliance teams build controls for fast-growing crypto markets without slowing legitimate innovation?
- How should NFT platforms monitor transaction risk without slowing legitimate customer activity?
- How should regulators design digital asset rules that protect consumers without stifling innovation?