Name-only screening misses the operational layer where many illicit transactions actually occur. Bad actors can reuse addresses, move funds through intermediaries, and interact without obvious identity matches. Without address screening, organisations lose the ability to detect exposure, stop prohibited activity, and build evidence for escalation, reporting, and enforcement response.
Why This Matters for Security Teams
Name screening alone creates a false sense of coverage because sanctions exposure often sits at the transaction and wallet layer, not just the identity layer. For compliance, fraud, and security teams, that means the control gap is operational, not theoretical. A sanctioned party can appear through reused blockchain addresses, intermediary wallets, or service accounts that never match a watchlist name. That weakens investigation quality and delays escalation.
For organisations handling virtual asset activity, the issue maps to broader control expectations in the NIST Cybersecurity Framework 2.0, especially around governance, detection, and response. It also aligns with the recordkeeping and control discipline implied by sanctions and AML programmes. Current guidance suggests that screening should be risk-based and layered, because sanctions compliance is not just about identity matching but about recognising exposure across addresses, counterparties, and transaction paths.
In practice, many security teams encounter sanctions exposure only after funds have already moved through a chain of addresses, rather than through intentional pre-transaction controls.
How It Works in Practice
Effective sanctions control in blockchain environments usually combines name screening, address screening, transaction monitoring, and escalation workflows. The practical question is not whether an address belongs to a known bad actor, but whether the organisation can identify risk when the address is linked to a sanctioned entity, a mixer, a high-risk service, or a previously flagged cluster. That is why blockchain analytics is often used alongside onboarding and continuous monitoring.
At a minimum, teams should define where screening occurs in the lifecycle, who owns alerts, and what evidence is preserved for investigation. Good practice is evolving, but the control model generally includes:
- screening wallet addresses at onboarding and before transactions are approved;
- watching for indirect exposure through hops, clusters, and counterparty relationships;
- correlating alert data with customer due diligence and case management records;
- documenting decisioning so that holds, rejects, and escalations are explainable.
This aligns with the control intent of NIST SP 800-53 Rev 5 Security and Privacy Controls, particularly around access, auditability, incident handling, and system integrity. It also fits the management-system approach in ISO/IEC 27001:2022 Information Security Management, where risk treatment and monitoring must be demonstrable. For sanctions and AML programmes, the FATF Recommendations — AML and KYC Framework reinforce the need for ongoing risk-based controls rather than one-time checks.
These controls tend to break down when organisations rely on static watchlists without transaction telemetry, because blockchain exposure changes faster than manual review queues can keep up.
Common Variations and Edge Cases
Tighter address-level screening often increases operational friction, requiring organisations to balance compliance coverage against false positives, customer delays, and investigation workload. That tradeoff is especially visible in DeFi, custody, and payment flows where a single user action can touch multiple addresses in seconds.
There is no universal standard for this yet on exactly how deep address correlation should go. Best practice is evolving, and the right threshold depends on the use case, risk appetite, and legal jurisdiction. Some organisations screen only direct wallet matches. Others include cluster intelligence, sanctions adjacency, and behavioral indicators. The more indirect the exposure model, the more important it becomes to define how much evidence is needed before a case is escalated.
Edge cases also matter. Shared infrastructure, hosted wallets, bridges, and chain-hopping can complicate attribution. In those environments, name-only screening may still catch some onboarding risk, but it will not reliably identify prohibited activity already in motion. The most mature programmes therefore treat address screening as a detection and enforcement control, not just a compliance checkbox, and they document how exceptions are handled when identity is uncertain or attribution is disputed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Sanctions screening needs risk treatment and governance, not just identity checks. |
| NIST SP 800-53 Rev 5 | AU-2 | Address screening depends on auditable logs and decision trails for investigations. |
| OWASP Non-Human Identity Top 10 | Blockchain addresses function like machine identities and need lifecycle governance. | |
| NIST SP 800-63 | Identity assurance principles help distinguish person checks from address-level exposure. | |
| DORA | Operational resilience requires sanctions controls that continue during stress and outages. |
Test that screening, escalation, and evidence capture still work under degraded operating conditions.
Related resources from NHI Mgmt Group
- What breaks when organisations treat audit logs as compliance evidence only?
- Why do crypto addresses create a compliance problem for sanctions teams?
- What breaks when attribution depends on blockchain addresses alone?
- What breaks when organisations rely on compliance reviews instead of continuous monitoring?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org