Yes, when the article’s risk comes from exchange connectivity rather than a single onboarding event. User screening is necessary, but it is not sufficient if funds can move through local exchanges into regulated venues or higher-risk networks. Counterparty tracing gives compliance teams the context they need to decide whether the exposure is acceptable or escalates to sanctions concern.
Why counterparty tracing changes the compliance decision
Simple user screening answers one question, is the person or entity on a list at onboarding or review time. Counterparty tracing answers a different question, where did value actually move, which venues touched it, and whether the exposure later crossed into a higher-risk environment. That distinction matters when the risk is not the first user, but the transaction path.
For compliance teams, tracing is most valuable when the same customer can interact with multiple exchanges, brokers, wallets, or chains. A clean-screened user can still generate exposure if funds are routed through a risky counterparty, because the compliance decision depends on the full path, not just the original account record.
That is why tracing is a context tool, not a replacement for screening. It helps teams decide whether a relationship is merely noisy, whether it warrants enhanced review, or whether it should be treated as sanctions-relevant because the receiving or intermediary counterparty changes the risk profile.
When screening is necessary but not enough
Screening remains the baseline because it supports onboarding, periodic review, and alert triage. But screening alone is limited to the identity or counterparty directly in front of you, while modern exposure often arrives through indirect relationships, nested transfers, or exchange-to-exchange movement. If the operational question is “can this flow reach a prohibited or higher-risk venue?”, screening by itself will miss that answer.
Counterparty tracing becomes more important as soon as the business model includes indirect settlement, liquidity routing, or multi-hop transfers. In those environments, the meaningful control is not simply knowing who passed a screen, it is understanding whether the counterparty graph creates a path to unacceptable exposure.
For that reason, compliance teams should treat tracing as the mechanism that tests whether screening results still hold after funds move. The right decision is often not “screen harder” but “trace far enough to know what the screen does not reveal.”
What practitioners should look for in an effective tracing program
Good tracing does not need to solve every attribution problem to be useful. It needs to produce enough lineage to show which counterparty relationships matter, where regulated or higher-risk venues appear, and whether the exposure is isolated or repeated. The practical test is whether the output can support a defensible escalation decision.
Teams should also define what counts as a meaningful counterparty signal. Common examples include repeated interaction with the same venue cluster, flows through jurisdictions or platforms with weak visibility, or movement patterns that create a plausible sanctions or AML concern even when the originating user looked ordinary.
Where possible, tracing should be tied to case management so reviewers can distinguish one-off noise from persistent exposure. Without that workflow, the analysis becomes interesting but not operationally useful.
Risk and Threat Considerations
Simple screening can fail when adversaries or risky actors use intermediate venues to dilute visibility. The main exposure is false comfort: a clean initial record can hide downstream connectivity to a regulated exchange, mixing service, or other higher-risk network that changes the compliance outcome.
Failure mechanism: The control checks the direct subject of the screening event, but not the transaction path, so the compliance team loses sight of the relationship that actually drives exposure.
Impact: Funds can be approved, delayed, or escalated on incomplete context, increasing sanctions, AML, and counterpart-risk exposure while reducing defensibility of the decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | Tracing depends on knowing the assets and venues in the transaction path. |
| GV.RM-01 — Risk management strategy is established, managed, and agreed to by organizational stakeholders | Prioritizing tracing over screening is a risk decision based on exposure pathways. | |
| PR.AA-05 — Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties | Counterparty tracing supports decisions about whether exposure should be accepted or escalated. | |
| Recommendation — Inventory the systems and venues used in transaction flows so tracing can cover the full exposure path. Set a risk strategy that weights downstream exposure and counterpart connectivity in compliance decisions. Restrict approval paths when traced exposure reaches higher-risk counterparties or venues. | ||
| CIS Controls v8 | CIS-5 — Account Management | Compliance screening and tracing both depend on managed, attributable counterpart relationships. |
| Recommendation — Maintain accountable counterparty records so transaction paths can be reviewed and escalated. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question turns on whether a relationship should be allowed after downstream exposure is understood. |
| Recommendation — Use access-control decisions that reflect traced exposure, not only initial screening results. | ||
Practitioner Guidance
What to prioritise: Use screening as the baseline filter, then apply tracing whenever the transaction can cross venues, jurisdictions, or counterparties before final settlement. The more indirect the flow, the more tracing should influence the decision.
What to verify: Confirm whether the tracing result explains the exposure in a way a reviewer can act on, not just whether it labels a wallet or address. If the output cannot show the relevant hop, counterparty cluster, or venue relationship, it is not strong enough for a final compliance call.
Decision rule: If the customer is clean-screened but the traced path reaches a higher-risk venue or network, escalate the case rather than treating screening as dispositive. If tracing shows no meaningful downstream exposure, screening may remain sufficient for that case.
Practitioner takeaway: The right control is the one that reveals the exposure that actually matters, and in multi-hop financial flows that is usually tracing, with screening as the starting point rather than the endpoint.
Related resources from NHI Mgmt Group
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- When should teams prioritise contextual classification over simple field detection?