Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should regulators monitor digital asset activity without…
Governance, Ownership & Risk

How should regulators monitor digital asset activity without slowing legitimate banking innovation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Regulators should combine continuous transaction monitoring with risk-based supervision, so they can review large volumes of activity without treating every transaction the same. The practical goal is to spot unusual patterns, verify compliance with AML, KYC, and sanctions rules, and reserve deeper review for the highest-risk activity. That approach supports enforcement while still allowing banks to develop digital asset services responsibly.

How regulators can monitor digital asset activity without choking off innovation

Effective oversight works best when it is calibrated to the activity, not forced into a one-size-fits-all review model. Regulators need visibility into flows, counterparties, and control quality, but they also need to avoid turning routine, low-risk activity into a licensing bottleneck. The right balance is continuous monitoring, targeted intervention, and clear expectations for banks building digital asset services.

Why risk-based monitoring is the practical answer

Digital asset activity can move quickly, span multiple venues, and create more alerts than a manual review process can absorb. A risk-based approach lets supervisors focus on material exposure, such as sanctions screening, customer due diligence, suspicious activity, and concentration in higher-risk products, instead of treating every transfer as equally suspicious. That keeps the supervisory model usable at scale.

For regulators, the key judgement is not whether to monitor, but how to separate ordinary activity from patterns that deserve escalation. Banks should be able to demonstrate that their controls are calibrated to product type, customer profile, geography, and transaction behaviour, rather than to vague concern about digital assets in general.

What good supervision looks like in practice

Good supervision combines automated surveillance with human review thresholds. Regulators should expect banks to maintain alert logic that can detect anomalies, but also to document why certain rule sets are more sensitive for higher-risk digital asset flows. In practice, that means reviewing the quality of the bank’s FATF Recommendations, AML and KYC Framework implementation, not just the volume of alerts it generates.

They should also look for evidence that banks can defend their screening and escalation logic under regulatory examination. If a bank cannot explain how it segments low-risk from high-risk activity, or cannot show that sanctions and customer verification checks are operating consistently, then the monitoring model is too blunt to support innovation responsibly.

A second useful lens is whether institutions are applying existing banking control disciplines to digital asset operations, rather than building a parallel control universe. Core practices such as account governance, logging, access review, and exception handling should still be visible, and the CIS Controls v8 remain a useful reference point for those operational basics.

How to preserve innovation while tightening oversight

The fastest way to slow legitimate innovation is to make every new product await bespoke approval. A better model is supervisory pre-clarity: define what must be monitored, what must be reported, and what can proceed under existing banking controls. That gives firms room to launch digital asset services while keeping the regulator focused on risk signals that matter.

Regulators can also reduce friction by demanding control evidence instead of requiring constant case-by-case approval. If banks can produce audit trails, exception reports, and periodic control attestations, supervisors can reserve deeper review for outlier activity. That approach is consistent with the control emphasis in the EBA AML/CFT Guidance, which supports a risk-based posture in banking supervision.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-8 — Audit Log ManagementMonitoring digital asset activity depends on reliable logs, alerts, and traceable review evidence.
Recommendation — Centralize audit logging so digital asset alerts and investigations remain traceable.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyRisk-based supervision requires explicit appetite and escalation rules for different digital asset risks.
DE.CM-01 — Continuous MonitoringContinuous observation is central to spotting unusual digital asset patterns without blocking normal flows.
Recommendation — Define risk thresholds that let routine activity proceed while escalating true exceptions. Use continuous monitoring to detect anomalous digital asset activity at scale.

Practitioner Guidance

What to prioritise: Start with monitoring that is calibrated to risk factors the bank can actually evidence, especially customer risk, product risk, and sanctions exposure. If the control team cannot explain why a rule exists or what risk it detects, it will usually create noise rather than insight.

What to verify: Check that automated alerts feed into a documented human escalation path, and that higher-risk digital asset activity receives faster review without forcing all activity through the same queue. The practical test is whether the bank can prove proportionality, not merely volume.

Common mistake: Treating innovation and supervision as opposing goals. In practice, well-designed monitoring can speed approval of legitimate activity by giving regulators confidence that unusual behaviour will surface quickly and consistently.

Practitioner takeaway: The objective is not to inspect every digital asset transaction equally, but to build a monitoring model that is selective enough to support scale and strict enough to surface genuine abuse.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org