Medium AML Risk in Crypto: What It Means and What to Do

What does a medium AML risk score for a wallet or transaction mean? Learn which factors to review, when to request supporting documents, and when to move to blockchain graph analysis.
Get advice from AML Crypto experts
A medium AML risk score is probably the most uncomfortable result you can get. Low risk seems straightforward. High risk at least tells you to be cautious. Medium risk leaves you with the harder question: should you proceed with the transaction or not?

There is no universal answer. Medium risk is neither a prohibition nor confirmation that a transaction is safe. It is a signal that the automated report has identified factors that need to be examined before a decision is made.

The biggest mistake in this situation is choosing whichever interpretation feels more convenient. The recipient may want to treat medium risk as almost low risk, while a compliance officer may instinctively treat it as almost high risk. But AML analysis does not work well with a “glass half clean” approach. What matters is what is actually in the glass.

What Does Medium AML Risk Mean?

Medium risk usually means that the AML service has identified certain risk indicators, but taken together they are not sufficient to classify the wallet or transaction as clearly low or high risk.
The reasons can vary significantly:
  • a small share of funds linked to a serious risk source;
  • a substantial indirect connection to a less critical category;
  • unusual wallet behavior or insufficient data for confident attribution.
This is why two reports with the same risk score may describe completely different situations. One wallet may have a small direct exposure to stolen funds. Another may have received a significant share of its funds from a licensed gambling platform. The score may look similar, but the appropriate response may be very different.

Why the Risk Score Alone Is Not Enough

A final score is useful for quickly sorting transactions, but by itself it explains very little. To understand the actual risk, several factors need to be reviewed.
The general principle is simple: the closer, more recent, and more material the connection, the less justification there is for dismissing it as background noise. In such cases, deeper review is warranted before proceeding with the transaction.

Not All Risk Factors Are Equally Serious

Exposure to a sanctioned address, stolen assets, known fraud, or terrorist financing requires a much stronger response than most indirect or contextual risk factors. Even a relatively small percentage of funds associated with such categories may be significant.

Gambling, high-risk exchanges, and certain P2P sources require a more nuanced assessment. The category label alone is not enough. You need to understand who controls the address, whether the service operates legally, whether it is licensed, and how the platforms you intend to use treat funds originating from such sources.

In other words, seeing  Gambling  in an AML report does not automatically make the transaction criminal. But dismissing the report simply because it is “only a casino” would be equally premature.

How Jurisdiction Affects Risk Assessment

When reviewing a medium-risk result, you should consider more than just the user's country of residence. Relevant factors may include the sender's jurisdiction, the country in which the exchange or exchanger is registered, and, for businesses, the jurisdictions of banking and payment partners.
The same source can be treated differently depending on the jurisdiction. A licensed gambling operator may be a perfectly legal business in one country, while interactions with it may trigger additional scrutiny or directly conflict with a platform's internal policies in another.

VASP and exchange services operating from jurisdictions with strategic deficiencies in their AML/CFT frameworks also deserve additional attention, as do entities subject to sanctions unrelated specifically to their blockchain activities.

FATF publishes a list of jurisdictions under increased monitoring, commonly referred to as the grey list. A country's inclusion on this list does not mean that every local company is involved in money laundering. It means that the jurisdiction has committed to addressing identified deficiencies and is subject to increased monitoring.

For a specific transaction, however, this may justify enhanced due diligence. FATF and similar organizations update their assessments regularly, so relying on old lists or outdated information can lead to incorrect conclusions.

A similar principle applies to offshore VASPs operating without a clearly identifiable license, transparent legal entity, or mature AML controls. The risk does not come from the word “offshore” itself. It comes from a combination of opacity, weak regulatory oversight, and the inability to verify who actually operates the service.

FATF also highlights the risks associated with offshore VASPs and the importance of considering the quality of their registration, licensing, and regulatory supervision.

What Else Can Cause a Medium Risk Score?

Sometimes the reason is not a specific high-risk label but the behavior of the wallet itself. For example, transaction volumes may suddenly increase without an obvious explanation, funds may begin to be split across numerous transfers, or the customer may unexpectedly start interacting with a new group of counterparties.

This activity does not in itself prove money laundering. However, it may differ sufficiently from the user's normal profile to trigger a higher risk assessment.

FATF considers unusual transaction patterns, economically illogical activity, and inaccurate explanations regarding the source of funds or relationships with counterparties to be indicators that should be analyzed together with other available information.
Another common scenario is an indirect connection to a risky entity two or three hops away.
A hop is one transactional step. If funds move from a risky address to an intermediary and then to the wallet being screened, the two wallets are two hops apart. This relationship is weaker than a direct connection, but it does not magically disappear after the second transfer. Its significance depends on the risk category, the share of funds involved, the timing, and the nature of the intermediary addresses.
Chains involving major exchanges and other custodial services require particular caution. Once assets enter a pooled hot wallet, confidently linking a specific withdrawal to a specific earlier deposit may no longer be possible without obtaining additional information directly from the service.

First Step: Save the AML Report

Every AML screening result should be recorded and preserved, even when the conclusion appears obvious.
The report documents which wallet or transaction was screened, on which blockchain, at what time, and which labels were available to the service.

This matters because the risk profile can change later. New transactions may appear, attribution data may be updated, or previously unidentified historical connections may be retrospectively labeled.

As a result, the risk score of a wallet can change significantly over time, potentially affecting counterparties that previously interacted with it.

A saved AML report does not make a questionable transaction safe, but it records the information available at the time the decision was made.

For businesses, the report should ideally be accompanied by a short decision rationale: which factors were reviewed, what information was requested from the customer, and why the transaction was approved, suspended, or rejected.

A screenshot without the wallet address, blockchain, and date is about as useful as a receipt without the amount or the name of the store. Technically, you have a document, but proving anything with it becomes difficult.

For example, our AML screening service Btrace allows users to save screening results, including in PDF format.

What Should You Do After Receiving a Medium-Risk Result?

You should not immediately accept, transfer, or deposit the funds to an exchange. First, save the AML report and identify what caused the score: whether the category is serious, what percentage of funds is affected, whether the exposure is direct or indirect, and when the connection occurred.

The next step is to ask the counterparty for an explanation. Depending on the transaction, this may include:
  • information about the source of funds;
  • the purpose of the payment;
  • details of the previous transaction;
  • information about the exchange or exchanger that was used.
For larger transactions, supporting documents confirming the underlying transaction and the source of the assets may also be appropriate.

The explanation should then be compared with the blockchain data. If someone claims that the funds were withdrawn from their own account at a well-known exchange, the route, amount, and timing should at least be consistent with that explanation.

A statement such as “these are all my wallets” is not, by itself, on-chain evidence of ownership.
Businesses should make the depth of their review proportionate to the risk. Requesting a large folder of documents because of a small and understandable indirect exposure is just as unreasonable as ignoring a large transfer with obvious links to stolen funds.

A risk-based approach means that control measures should reflect the nature and level of the identified risk rather than being applied mechanically to every transaction.

When Is Blockchain Graph Analysis Needed?

An automated AML report answers the question: where was the risk detected?

A graph helps answer another question: how exactly did the connection arise?

Graph analysis allows you to examine the flow of funds, intermediary wallets, counterparties, associated addresses, and clusters.

For example, it may show that an indirect fraud exposure passes through a major centralized exchange. Alternatively, it may reveal a persistent chain of transfers between closely related wallets.

Bholder is one example of such a tool. It allows analysts to visually investigate fund flows and move from an aggregated overview to individual transactions.

The specific interface, however, is less important than the analytical method itself. A graph does not produce the truth at the click of a button. What it provides is additional context for the analyst.

Example of visual analysis of relationships between cryptocurrency addresses in Bholder.

There is no reason to perform graph analysis for every medium-risk result.
It becomes appropriate when:
  • the transaction amount is significant;
  • the origin of funds is unclear;
  • the customer's explanation contradicts the blockchain data;
  • a disputed connection materially affects the decision.
If you do not have sufficient experience, the case is better referred to a specialist. Attractive lines connecting circles do not automatically make a blockchain investigation accurate.

How to Make the Final Decision

After reviewing the case, you should end up with something more specific than “well, the risk seems medium.”

There are essentially three possible decisions.
Proceed with the transaction if the reasons behind the score are understood, the explanation is supported by available evidence, the relevant risk category is acceptable under your jurisdiction and internal policies, and the decision has been documented.
Pause the transaction and request additional information if the available data is insufficient, contradictions remain, or the flow of funds requires manual analysis.
Decline the transaction if critical connections are identified, the counterparty's explanation cannot be substantiated, or the risk is unacceptable to you, your platform, or your company.
Medium risk should not automatically result in either rejection or approval. Its purpose is to trigger additional questions before the transaction becomes irreversible.

Conclusion

A medium AML risk score means that the factors identified by the screening service require further analysis.

You should save the report and review the risk category, the share of affected funds, direct and indirect exposure, the age of the relationship, and the relevant jurisdictional context.

The next step is to request an explanation, compare it with blockchain data, and make a clear decision: proceed, pause the transaction, or decline it.

Btrace helps identify the factors behind the risk score. When an automated report does not provide enough context, the transaction flow can be examined using a blockchain graph or referred to a specialist.

The key is not to make a decision based on the color of a single indicator. Traffic lights are useful on the road, but in AML, green, yellow, and red require a little more analysis.

FAQ

  • Can I Accept Cryptocurrency With a Medium AML Risk Score?
    Sometimes, yes, but only after reviewing the reasons behind the score. You should consider the risk category, the share of funds affected, the nature of the exposure, the transaction context, and the requirements of the relevant jurisdictions.
  • What Should I Do First?
    Do not automatically move the funds. Save the complete AML report and determine which factors contributed to the risk score.
  • Is a Connection Two or Three Hops Away Dangerous?
    Not necessarily. It is weaker than a direct connection, but it cannot be assessed properly without considering the risk category, the share of funds involved, the timing, and the intermediary services.
  • Is Blockchain Graph Analysis Always Necessary?
    No. It is generally warranted when the amount is significant, the transaction route is complex, there are contradictions in the available information, or the cost of making the wrong decision is high.
  • Why Should I Save the AML Report?
    It records the information available at the time the decision was made and can help justify your actions during an audit, a request from a platform, or a later retrospective review.
Want to learn more and get expert advice? Leave your email and we will contact you promptly!
We also recommend