Compliance is transaction architecture. The decisive question is whether a gate runs before credit and before signing, with enough versioned evidence to reproduce the decision months later.
Most compliance failures are not missing policies. They are gates placed at the wrong point in the call graph, where they can observe a problem but no longer stop it. This sheet is about placement.
Where does sanctions screening belong?
Before signing, never after broadcast. Screening a transaction you have already sent is not a control, it is a report, because the only action left is a filing.
What is the Travel Rule in one paragraph?
It is the requirement that identifying information about the sender and the recipient travels alongside a transfer between regulated firms, above a threshold. IVMS101 is the shared data format that information is carried in.
If the format is standard, why is it hard?
The payload is standardised and the network is not. The competing Travel Rule networks all carry IVMS101 but discover and authenticate counterparties differently, so you either join several of them or route through a broker.
Why rescreen addresses you already cleared?
Sanctions lists move in both directions. An address that is clean today can be designated tomorrow, and the exposure applies to what you already did, so screening only at onboarding leaves a gap that grows every day.
If you remember one lineCompliance controls are pipeline placement decisions, not a checklist. Screen before irreversibility.
Gate before irreversibility
Gate placement is the whole design. A control that runs after signing is forensics, not compliance.
Gates6observe → sign
BoundarySIGNthe irreversible step
PayloadIVMS101.2023 structured fields
Deposit gates4before credit
Withdrawal gates4before the signer
On alertDO NOT SIGNhold, never broadcast
01 · OBSERVE
Parse chain, contract, transfer identity and finality.
Minimum IVMS101 data to authenticated counterparty.
05 · AUTHORIZE
Ledger intent, policy, velocity, approvals.
06 · SIGN
Only the exact cleared payload.
Signing is the boundary. “Screen before broadcast” is too late if valid signed bytes already exist.
Gate before irreversibility
Five gates run before the sixth. Once valid signed bytes exist, every remaining control is after the fact.
Signing is the boundary. Screening before broadcast is too late if a valid signature already exists.
Gate placement rules
Deposit observation
Parse chain, contract, amount, source, destination, tag, and finality before any customer posting.
Concrete use: Open a compliance case on a new USDC transfer while the balance remains pending.
Failure mode: Screening after credit lets tainted value fund internal trades or withdrawals.
Pre-credit KYT
Screen the actual transfer and counterparty exposure before making funds available.
Concrete use: Persist provider, model/list version, score, categories, hop depth, and raw response hash.
Failure mode: A naked score cannot be reproduced after the vendor model changes.
Pre-sign withdrawal gate
All identity, Travel Rule, sanctions, destination, and business-policy checks must pass before irreversible signing.
Concrete use: The signer callback verifies compliance case case_20418=cleared and exact destination bytes.
Failure mode: Screening between signing and broadcast leaves a valid signed payload that can escape.
Rescreen on list update
Addresses and persons previously clean can become blocked property when lists change.
Concrete use: Subscribe to list changes, rescreen held positions and pending transfers, and open retroactive cases.
Failure mode: A once-at-onboarding result silently expires.
Fail closed
Provider outage blocks automated value movement while an explicit, dual-controlled manual route handles exceptions.
Concrete use: After 60 seconds of KYT timeout, queue rather than sign; page operations before SLA breach.
Failure mode: Fail-open turns the outage into an ideal attacker window.
Compliance gate map
The control boundary is signing. A signed blockchain transaction is a bearer-like capability even if your broadcaster has not submitted it yet.
Path
Gate
Input
On hit
If placed later
Deposit
Asset validation
chain + contract + decimals
Quarantine
Fake token may be credited
Deposit
KYT exposure
source + transfer graph
Pending/manual review
Funds become internally spendable
Deposit
Sanctions
person + address + live list
Block/segregate
Blocked property may move
Deposit
Finality
chain-native status
Wait
Reorg creates unbacked credit
Withdrawal
Customer/KYC state
identity + account risk
Reject/review
Value enters signer path
Withdrawal
Travel Rule
counterparty + threshold + IVMS payload
Hold/send data
Transfer may breach obligation
Withdrawal
Destination KYT
address + asset + amount
Reject/review
Signed transaction exists
Withdrawal
Policy callback
ledger intent + decoded payload
Do not sign
Broadcast control is too late
Travel Rule implementation register
This is a routing register, not a legal threshold table. Thresholds and scope depend on entity, activity, corridor, and current local implementation; resolve them in maintained policy data before launch.
IVMS101 standardizes identity data; it does not standardize discovery, transport, certificate trust, or corridor policy.
Object / field
Cardinality / type
Constraint
Common rejection
originator / beneficiary
1 object
Person arrays + account number
Flattening all persons into one name
naturalPerson.name
1..n
Structured nameIdentifier
Single free-text full name
legalPerson.name
1..n
Legal-person identifier structure
Using natural-person fields
nameIdentifierType
code
Controlled vocabulary such as LEGL
Unrecognized local code
geographicAddress
0..n
Typed address + ISO country
Country name instead of alpha-2 code
addressType
code
Controlled vocabulary
Billing/home/business semantics mixed
nationalIdentification
0..1
Identifier + type; authority where required
Sending raw document without type
dateAndPlaceOfBirth
0..1
ISO date + place
Locale-formatted date
customerIdentification
0..1
VASP customer identifier
Reusing government ID
accountNumber
0..n strings
Chain/account or internal account
Dropping memo/tag
originatingVASP / beneficiaryVASP
0..1
Legal-person identity
Trusting a domain name as identity
transferPath
0..1
Ordered intermediaries
Losing sequence
payloadMetadata
0..1
Encoding/transliteration metadata
No Latin/local script strategy
IVMS101.2023 worked payload
Illustrative transport envelope: validate against the counterparty network's current IVMS101.2023 schema and required jurisdictional fields. Names use structured identifiers; dates use ISO 8601.
Do not copy identity values into production. Store consent/lawful-basis, schema version, counterparty identity, transport receipt, policy decision, and the minimum data actually required.
KYT, sanctions & data protection
Hop depth
Indirect exposure is a policy parameter; at enough hops almost every liquid address becomes connected.
Concrete use: Store direct and 1-hop exposure separately and require a documented threshold by category.
Failure mode: Treating graph distance as moral certainty creates unbounded false positives.
Vendor disagreement
Attribution and clustering are models, not shared facts.
Concrete use: Route a high-value disagreement to evidence review; retain each vendor's label version.
Failure mode: Averaging opaque scores does not create truth.
Dynamic sanctions data
Lists add and remove identifiers; application code must consume versioned authoritative data.
Concrete use: Treat the OFAC SDN feed as an external signed/versioned input and rescreen on update.
Failure mode: Hard-coded addresses become wrong in both directions.
Blocked-property response
Freeze and segregate; route reporting, recordkeeping, and legal decisions to the applicable program.
Concrete use: Open one case linking asset, list version, timestamps, owners, decisions, and reports.
Failure mode: Automatically returning funds may itself be prohibited.
Data minimization
Transmit required identity data only to an authenticated counterparty under a recorded lawful mechanism.
Concrete use: Encrypt in transit and at rest, separate compliance payload from chain transaction, and expire unnecessary copies.
Failure mode: The blockchain is not a place for Travel Rule personal data.
Blocked-property and alert runbook
Deadlines are jurisdiction- and program-specific. The runbook must link to maintained legal policy, never freeze a number in application code.
Atomically freeze availability and prevent signing; preserve the exact screening response.
Identify governing entity, program, list entry, ownership/control basis, and transaction state.
Segregate or label the position so routine sweeps and reconciler repairs cannot move it.
Do not return, consolidate, or test-transfer value without authorized legal determination.
Open a privileged case with timestamps, list version, assets, chain evidence, and decision owners.
Evaluate required blocking/rejection reports and deadlines under the applicable program.
Evaluate separate suspicious-activity reporting and anti-tipping-off constraints.
Notify internal legal/compliance/security through the documented channel, not ordinary support notes.
Rescreen related customers, addresses, counterparties, and pending transfers.
Retain records and schedule ongoing/annual reporting where the applicable rule requires it.
Test release/delisting path with dual control and complete audit evidence.
After closure, repair the placement or data defect that allowed exposure.
Common mistakes & anti-patterns
Failures that pass a vendor demo. Expand each for the control and the reason it fails.
Screen after broadcast
The irreversible action already happened.
Concrete use: Gate before signing.
Failure mode: A broadcaster hold does not neutralize signed bytes.
Hard-coded lists
Sanctions state changes without software releases.
Failure mode: Delisting is as important as designation.
Score as fact
A vendor's risk score encodes taxonomy and model choices.
Concrete use: Store evidence, category, distance, model and appeal path.
Failure mode: Threshold tuning without false-positive measurement is guesswork.
Unauthenticated counterparty
Correct IVMS data sent to the wrong VASP is a breach.
Concrete use: Verify certificate/entity before payload transmission.
Failure mode: Protocol membership is not universal identity assurance.
KYT integration surfaces
Recheck each vendor's public documentation before procurement. This compares integration shape, not quality, experience, or rank.
Provider
Documented surface
Retain
Do not infer
Chainalysis
APIs and platform workflows
category, exposure, score, evidence/version
Cross-vendor score equivalence
TRM Labs
APIs and case workflows
risk indicators, attribution, graph context
Attribution immutability
Elliptic
Wallet/transaction screening APIs
risk rule, category, path, timestamp
Identical taxonomy
Merkle Science
Transaction-monitoring APIs
rule hit, exposure, model state
Score as legal conclusion
Crystal
Blockchain-analytics APIs
entity/category and transaction evidence
Universal chain/token coverage
Travel Rule protocol interoperability
The payload is standardized more broadly than transport and discovery. Multi-network routing, receipts, retries, and counterparty identity are first-class state.
Operational and volatile claims were checked against these first-party documents on 2026-08-31. Examples are illustrative controls, not legal, investment, or vendor-selection advice.
IVMS101.2023Maintainer page and current data model download.