Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do permissionless layer 2 networks create new…
Governance, Ownership & Risk

Why do permissionless layer 2 networks create new compliance and investigation challenges for financial services teams?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

Permissionless layer 2 networks can increase speed and scale, but they also multiply the number of transactions, assets, and counterparties that teams must assess. That raises the burden on screening and tracing controls. When token standards expand quickly, compliance teams need broader visibility into entity relationships, fund flows, and alerting so risk review does not become fragmented.

Why This Matters for Security Teams

Permissionless layer 2 networks change the compliance problem from monitoring a relatively bounded set of transfers to tracking activity across fast-moving, composable, and often pseudonymous transaction paths. Financial services teams still need to know who touched an asset, whether counterparties are sanctioned, and how value moved across bridges, rollups, and token wrappers. That is difficult when the control point is no longer a single ledger and when assets can be split, routed, and reassembled across many hops.

This also creates an investigation gap. Traditional casework often assumes a clear origin, a stable asset type, and a narrow chain of custody. In layer 2 environments, those assumptions break down because the same exposure can appear in multiple forms and on multiple venues. Current guidance suggests aligning monitoring to the broader control objectives in the NIST Cybersecurity Framework 2.0 and then layering digital-asset specific tracing on top. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is useful here because many of the same audit issues arise when control ownership is fragmented across tooling and teams.

In practice, many security teams encounter the scope of the problem only after an alert must be defended to auditors or law enforcement, rather than through intentional design of the monitoring model.

How It Works in Practice

The practical challenge is not simply volume. It is the combination of throughput, interoperability, and weakly bounded identity. A compliance team may need to trace funds from a deposit address into a rollup, through a bridge, into a wrapped token, and then back out through a separate venue. Each step can alter the on-chain representation while preserving economic exposure, which complicates screening, sanctions review, and suspicious activity narratives.

Teams usually need a workflow that combines transaction monitoring, entity resolution, wallet clustering, and case management. That workflow should be documented in terms that map to the FATF Recommendations, because AML obligations do not disappear just because settlement moved to a permissionless layer 2. For control design, the OWASP Non-Human Identity Top 10 is also relevant when internal bots, indexers, or automated investigators use API keys and service accounts to ingest blockchain data, since those identities often become the weakest part of the evidence pipeline.

  • Maintain asset and wallet lineage across layer 1, layer 2, bridges, and custodial endpoints.
  • Normalize token metadata so wrappers, derivatives, and migrated assets are not treated as separate risk silos.
  • Use alert triage rules that consider counterparty exposure, typology, and hop count, not just a single transaction hash.
  • Preserve chain-of-custody logs for investigative defensibility, including timestamps, screening outputs, and analyst actions.

NHIMG’s Top 10 NHI Issues reinforces a broader lesson: when identity and access controls are opaque, downstream monitoring becomes unreliable even if the data itself is available. These controls tend to break down when teams rely on a single analytics vendor or a single chain view because cross-domain tracing becomes incomplete as soon as value leaves the visible perimeter.

Common Variations and Edge Cases

Tighter monitoring often increases operational cost, alert fatigue, and false positives, so organisations have to balance deeper traceability against settlement speed and user experience.

Permissionless layer 2 networks are not uniform. Some use optimistic rollups, others use validity proofs, and some assets are native on the layer 2 while others are bridged representations. Best practice is evolving on how much tracing granularity is sufficient for compliance, and there is no universal standard for this yet. Teams should therefore define thresholds for when a transfer is treated as low risk, escalated, or frozen, rather than assuming one policy fits every network.

Edge cases matter most when an investigation touches privacy-preserving tools, cross-chain bridges, or self-custody wallets used by third parties. In those cases, the evidence trail may be technically complete but operationally hard to interpret. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks is a reminder that visibility gaps are often governance gaps as well. Financial services teams should also align exception handling to the NIST Cybersecurity Framework 2.0 and the NIST SP 800-207 Zero Trust Architecture principle of continuous verification, especially where automated systems make routing decisions on behalf of humans.

The hardest cases usually involve a legitimate business flow that later intersects with suspicious counterparties, because the review then depends on reconstructing intent from a highly fragmented transaction history.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Automated wallet analytics and API keys are non-human identities that must be governed.
NIST CSF 2.0DE.CM-1Continuous monitoring is central to tracing flows across permissionless layer 2 networks.
NIST Zero Trust (SP 800-207)PR.AC-4Zero trust helps with continuous verification of automated evidence and access paths.
NIST AI RMFAI-assisted investigation and screening need governance for reliability and accountability.
OWASP Agentic AI Top 10A2Autonomous analysis agents can chain tools and alter investigation outcomes without oversight.

Set governance, oversight, and escalation rules for AI used in blockchain compliance workflows.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org