Assessment of a digital-asset address against sanctions lists and risk indicators before a transaction is accepted. The check sits with the regulated provider that receives the transfer, not with the seller of the underlying goods, and it resolves three separate questions: whether the address itself is designated, whether the assets reaching it carry exposure to listed or illicit sources, and whether the person presenting the address controls it. It runs before acceptance because the alternative — establishing the answer afterwards — leaves the provider holding property it may be prohibited from returning. A payment that fails screening is either sent back or frozen, and those two outcomes leave the payer in very different positions.
The market also calls it address screening or crypto wallet screening. All three name the same control.
What the screen actually examines
Ordinary use collapses three checks into one word. They run on different objects, answer different questions, and fail in different ways.
| Check | What it answers | What it cannot answer |
|---|---|---|
| List matching — the address string against designated addresses | Whether this exact address appears on a sanctions list at the moment of the query | Whether the controller is designated. Published addresses are not an exhaustive inventory of what a designated person controls |
| Exposure and provenance — the transaction history reaching the address | Which categories of counterparty the funds passed through, at what distance, and in what proportion of value | Whether the payer knew, intended or benefited. Exposure is a measurement, not a finding of conduct |
| Control verification — the person against the address | Whether the party presenting a self-hosted address can demonstrate disposal over it | Anything about the funds. A verified controller can still present tainted assets |
The gap in the first row governs the other two. A sanctions designation attaches to the person and to that person’s property; enumerated addresses are identifiers assisting detection, not the boundary of the prohibition. An address absent from every list can therefore still be blocked property. US Treasury guidance for the virtual-currency sector reflects this directly, recommending a historic lookback across past activity once an address is designated, precisely to surface unlisted addresses that transacted with it. Screening built only on string matching is under-inclusive by design, which is why exposure analysis exists alongside it rather than as an enhancement of it.
Who runs it, and at which point
In a bullion purchase funded from digital assets the sequence is fixed, and screening occupies one position in it.
- The counterparty requests a quote and receives an order reference. Every later document and every incoming payment carries that reference.
- Payment is made through a payment gateway operated by a licensed digital-asset platform.
- The platform screens the address, the transaction and the chain history under its own licence, applying its own program. It converts and settles in national currency.
- Golden Ark Reserve is settled in fiat against the order reference. It holds no digital assets, receives no token, and issues no claim on metal.
- Golden Ark Reserve runs its own counterparty gating — AML/KYC, source-of-funds review and sanctions screening — independently of anything the platform did. Passing one is not passing the other.
- Allocation follows settlement: whole bars, identified by serial number, segregated from the seller’s own stock, with the counterparty named in the vault register of a dedicated client sub-account at Brink’s.
Two consequences follow from the ordering. Screening happens on the payment leg, before the seller sees a settled figure, which is why an address problem surfaces as a payment that does not arrive rather than as an allocation that unwinds. And because the platform’s decision rules are its own, no seller can promise a screening outcome in advance — the gate belongs to the licensed operator, and a quote is not a pre-clearance.
What the screen produces
A screening record: the query, the data sources consulted, the categories returned, the disposition, and the date. It is an internal compliance artefact and it stays internal. The counterparty-facing output is a verification status with a date and an internal reference, not the report.
That record does work later. When a receiving bank asks how funds originating in digital assets were assessed before they entered the banking system, the answer is not a narrative; it is a document produced by a licensed provider at the time of conversion, joined by an order reference to the pro forma invoice, the settlement, the allocation record and the commercial invoice. The screening record is the first link in that chain, and it is the one a compliance reviewer reads first because it is the only one produced before the money moved.
Where it fails
Indirect exposure returns a hit on clean funds. Exposure is measured across intermediaries, so assets that passed through a service with mixed activity carry a proportion of that service’s profile. The result is a flag on a payer who did nothing, resolvable only by explanation and documentation, and resolved on the provider’s timetable rather than the payer’s.
Self-declaration does not establish control. Where a self-hosted address is involved, an assertion of ownership is not evidence of it. Under the EU framework the verification must use suitable technical means — a signed message, a controlled test transfer, or equivalent — and a customer’s statement is explicitly insufficient. A payer holding no technical proof of control arrives at conversion with a transfer that cannot be completed.
Payment from an address the payer does not control breaks the chain regardless of the screen. Funds arriving from a third party, or from an account held in another name, produce a settled amount whose origin the payer cannot evidence. The screen may return nothing adverse and the payment still fails the file.
Designation is effective on publication. Lists change without a fixed schedule, and a transfer initiated against a clean result can complete after the position has changed. Screening is a statement about a moment, not a certificate.
Rejected and blocked are not variants of the same outcome. A rejected transfer is refused and returned. Blocked property is not: the holder must deny all parties access to it and report it to the authority, with periodic reporting while the block persists. The distinction is the one that matters commercially, because only one of the two ends with the payer still holding the funds.
A payment without its reference is an unattributed credit. It arrives, and nothing connects it to an instruction. Screening cleared the funds; the file cannot place them.
How the obligation differs across regimes
Screening obligations are set by the regime the provider is licensed in, and those regimes have diverged.
The FATF standard is the baseline. Its seventh targeted update, published 16 July 2026, records 83% of surveyed jurisdictions with Travel Rule legislation in force, up from 73% a year earlier, with a further eleven implementing. The same report finds that many jurisdictions have not converted those frameworks into supervision and enforcement in practice. For a counterparty this is the operative fact about the payment leg: legislation is close to universal, examination is not, and the difference between a provider that screens to the standard and one that merely falls under it is visible in the record it produces, not in the law it cites.
The EU has gone further than the baseline in two respects that bear directly on a payer. Information on the originator and the beneficiary must accompany crypto-asset transfers with no de-minimis amount, unlike conventional wire transfers — a rule applying since 30 December 2024 under Regulation (EU) 2023/1113. And for transfers to or from a self-hosted address above EUR 1 000, the provider must assess whether its customer owns or controls that address — a check the EBA’s travel-rule guidelines say a customer’s self-declaration does not satisfy. That framework is expressly provisional: the same regulation required the Commission to assess, by 30 June 2026, whether further restrictions on self-hosted address transfers are warranted, and allows those restrictions to be introduced by delegated act rather than by fresh legislation.
Two further changes are already dated. From 10 July 2027 the EU anti-money-laundering regulation prohibits regulated providers from keeping anonymous accounts or handling anonymity-enhancing assets, and brings persons trading in precious metals and stones into the obliged-entity perimeter. A bullion counterparty funded from digital assets therefore sits, from that date, between two obliged entities rather than one.
The asset mix has shifted underneath all of this. The FATF’s targeted report of 3 March 2026 records more than 250 stablecoins in circulation by mid-2025 against a market capitalisation above USD 300 billion, and cites industry analysis putting stablecoins at 84% of illicit virtual-asset transaction volume in 2025. Its recommended mitigations are issuer-side: the capacity to freeze, burn or withdraw tokens in the secondary market, due diligence at redemption, and smart-contract controls that deny-list or allow-list addresses. Stablecoins are consequently the asset class where control does not end when the transfer confirms: the issuer keeps a lever the sender does not.
Terms it is confused with
Transaction screening reviews a single transaction against sanctions, PEP and adverse-media data; wallet screening is the address-level component of it. Blockchain analytics is the technique that produces the exposure measurement, not the control itself. KYC identifies the counterparty; wallet screening assesses an address, and an identified counterparty can present a flagged one. Source of funds documents where the money came from; screening tests what the chain says about it. Proof of funds shows the money exists. The Travel Rule governs what information accompanies a transfer between providers; screening governs whether the transfer is accepted at all.
What the screen does not carry forward
Every screening result has an expiry, and both directions are live. Designations take effect on publication. Delistings do the same: OFAC removed Tornado Cash and its associated addresses from the SDN List on 21 March 2025, and assets prohibited to US persons on one day were not on the next. For stablecoins, the issuer retains the ability to freeze or burn tokens at an address after a transfer confirms. A digital-asset position therefore stays exposed to reassessment for as long as it is held at an address — the screen clears the moment, not the holding.
This is the structural reason the payment leg and the metal leg stay separate. At settlement the screened object stops existing. What the counterparty holds afterwards is title to identified bars, recorded by serial number, weight, fineness, producer and location, in a register naming the counterparty. It has no address, no issuer and no smart contract. There is nothing to re-screen when a list is updated, no deny-list that can reach it, and no third party with a technical capacity to immobilise it. The screening record does not travel with the metal; it stays on the payment leg as the document explaining where the money came from, which is the question a receiving bank asks.
The boundary matters as much as the point. This changes the form of the record, not the gate. Counterparty eligibility is screened by the seller independently and continuously — sanctions, supplier restrictions and supply-chain standards apply to the person, not to the payment instrument — and a counterparty outside those limits at the payment leg is outside them at the metal leg.
Screening obligations, the evidence they produce and the counterparty gating applied alongside them are set out in full at AML & KYC physical gold controls; the funding route in which the check occurs is described at Buy Physical Gold with Crypto.
