Crypto and Digital Assets

AML Judgment Gap Report · Full findings

Crypto and Digital Assets

17 September 2026 · 14 participants · 7 cases each · 98 runs · September cohort

This is a specimen. The cases, the weights, the methods and the sources are real, and are what your team would sit and what your own report would cite. The scores are invented, for a hypothetical cohort of 14 people. A real report carries your own results and nothing else.

6/20Material gapsHalf or fewer detected

Your team detects 6 of the 20 money laundering methods that apply to this sector. 6 need action, and 4 of those are rarely covered by standard training.

5 of these are urgent. Your team was tested on them and missed them.

Detected 6Partial 8Missed 6

Your assessment is 7 cases, not one. Each covers a different part of your exposure, and the appendix shows how many of your 20 methods each one carries. Measured against the methods that apply to this sector, not against other firms.

Since the last sitting

September cohort against March cohort. Your team detected 5 methods then and 6 now. 5 went backwards.

6 closed2 improved5 declined7 unchanged
MethodMarch cohort to September cohortMovement
Crypto ATMs and OTC Brokers
94%Detected76%Partial
Declined
Guarantee Marketplaces and Criminal Service PlatformsRarely trained
94%Detected76%Partial
Declined
Investment and Romance Scam Proceeds Infrastructure
94%Detected76%Partial
Declined
Ransomware Proceeds Conversion
94%Detected76%Partial
Declined
Stablecoin Settlement InfrastructureRarely trained
94%Detected76%Partial
Declined
State-Sponsored IT Worker Payroll InfiltrationRarely trained
50%Missed65%Partial
Improved
Terrorist Financing: small-value and fundraisingRarely trained
46%Missed63%Partial
Improved
Agentic Laundering and Automated SmurfingRarely trained
67%Partial84%Detected
Closed
Biometric Injection and Liveness BypassRarely trained
67%Partial84%Detected
Closed
Control Probing and Detection-Threshold Discovery
67%Partial84%Detected
Closed
Laundering and Fraud as a ServiceRarely trained
67%Partial84%Detected
Closed
Synthetic and AI-Generated Onboarding DocumentsRarely trained
67%Partial84%Detected
Closed
Synthetic Identities at ScaleRarely trained
67%Partial84%Detected
Closed

What to do

For each one, ask a single question. Does the team not know the method, or do they know it and have no rule that would surface it? The first needs a briefing. The second is a control gap, and it is the more serious answer.

High
Tested and missed, on a case covering a large part of your exposure.
Medium
Tested and missed on a smaller case, or never tested on one that matters.
Low
Never tested, and a small part of your exposure.

Ordered by priority. The reason for each is printed with it, so you can disagree with the ranking.

  1. 01

    Chain-Hopping Across Bridges and Swaps

    High

    Your team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.

    Result
    Caught 46% of the laundering customer's alerts.
    Tested by
    The Exchange Desk — covers 6 of your 20 methods
    Training
    Rarely covered by standard annual refreshers
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    For a VASP: deposits whose immediate provenance is a bridge or DEX contract rather than an identifiable counterparty, and short holding times between receipt and onward swap. For a bank: fiat settlement from an exchange whose own inbound provenance cannot be evidenced.

    90 days · Re-test

    Sit The Exchange Desk again, on the version the team has not seen.

    OwnerTarget date
  2. 02

    Mixers, Tumblers and Privacy Coins

    High

    Your team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you.

    Result
    Caught 46% of the laundering customer's alerts.
    Tested by
    The Exchange Desk — covers 6 of your 20 methods
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    For a VASP: deposits with mixer-adjacent provenance, or swap history through privacy assets. For a bank: exposure arrives already laundered, at the off-ramp.

    90 days · Re-test

    Sit The Exchange Desk again, on the version the team has not seen.

    OwnerTarget date
  3. 03

    Nested Exchange Access and Sub-Accounts

    High

    Your team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.

    Result
    Caught 46% of the laundering customer's alerts.
    Tested by
    The Exchange Desk — covers 6 of your 20 methods
    Training
    Rarely covered by standard annual refreshers
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    A single institutional customer whose deposit and withdrawal counterparties number in the thousands, activity patterns inconsistent with a single beneficial owner, and onward flows to jurisdictions the customer does not operate in.

    90 days · Re-test

    Sit The Exchange Desk again, on the version the team has not seen.

    OwnerTarget date
  4. 04

    State-Actor Cyber Theft and Laundering

    High

    Your team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.

    Result
    Caught 46% of the laundering customer's alerts.
    Tested by
    The Exchange Desk — covers 6 of your 20 methods
    Training
    Rarely covered by standard annual refreshers
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    For VASPs: deposits traceable to designated addresses, and institutional counterparties who cannot evidence their own inbound provenance. For banks: correspondent exposure to intermediaries in the cash-out chain.

    90 days · Re-test

    Sit The Exchange Desk again, on the version the team has not seen.

    OwnerTarget date
  5. 05

    Unhosted Wallets and Fragmented Off-Ramping

    High

    Your team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you.

    Result
    Caught 46% of the laundering customer's alerts.
    Tested by
    The Exchange Desk — covers 6 of your 20 methods
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    Numerous customers each receiving modest, regular exchange settlements with no other economic profile, sharing device, address or beneficiary characteristics.

    90 days · Re-test

    Sit The Exchange Desk again, on the version the team has not seen.

    OwnerTarget date
  6. 06

    Child Sexual Exploitation Payment Patterns

    Medium

    Your team was tested on this and missed it. Training rarely covers this, so a refresher will not fix it.

    Result
    Caught 36% of the laundering customer's alerts.
    Tested by
    The Payment Trail — covers 1 of your 20 methods
    Training
    Rarely covered by standard annual refreshers
    Now · Brief

    Send the team the register entry. It has the mechanism, the signal and the sources.

    30 days · Control

    Which rule, report or alert would surface this?

    Small repeated payments, often at unusual hours, to money transfer beneficiaries in a small number of jurisdictions with no family or trade connection to the customer; use of prepaid instruments or virtual assets by a customer with no other digital activity; and payment values clustered in narrow bands.

    90 days · Re-test

    Sit The Payment Trail again, on the version the team has not seen.

    OwnerTarget date

On your own report

Each line carries your team’s result, an owner and a date. The re-test at 90 days shows what has moved.

Appendix

Evidence

Everything the finding above rests on, for anyone who wants to check it.

By case

The 7 cases that make up your assessment. Detection rate is the share of the laundering customer’s alerts the team caught. The last column counts people who escalated everything, which catches the laundering customer without deciding anything and scores badly for that reason.

CaseYour methodsShare of assessmentRunsMedian markDetection rateEscalated everything
The Exchange Desk624%144946%3 of 14
The Verification Desk624%148784%3 of 14
The Victim Ledger520%147976%2 of 14
The Betting Account416%146763%2 of 14
The Incoming Payment28%146965%3 of 14
The Fundraising Appeal14%146563%3 of 14
The Payment Trail14%143936%2 of 14

Every method

All 20 methods that apply to this sector, and where each one is documented. Full citations are at amlbenchmark.com/coverage.

MethodCaseRateResult
Chain-Hopping Across Bridges and Swapsrarely trainedElliptic, The State of Cross-Chain Crime 2025The Exchange Desk46%Missed
Child Sexual Exploitation Payment Patternsrarely trainedFinCEN Notice FIN-2021-NTC3 (16 September 2021) on identifying and reporting suspicious activity related to online child sexual…The Payment Trail36%Missed
Nested Exchange Access and Sub-Accountsrarely trainedFATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs (October 2021)The Exchange Desk46%Missed
State-Actor Cyber Theft and Launderingrarely trainedBybit, 21 February 2025: approximately US$1.5bn in Ethereum stolen, attributed by the FBI to North Korean actors under the…The Exchange Desk46%Missed
Mixers, Tumblers and Privacy CoinsOFAC designation of Blender.io (May 2022) and of Tornado Cash (8 August 2022), the latter cited as having been used to launder…The Exchange Desk46%Missed
Unhosted Wallets and Fragmented Off-RampingFATF, Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions (3 March 2026)The Exchange Desk46%Missed
Guarantee Marketplaces and Criminal Service Platformsrarely trainedFinCEN finding that Cambodia-based Huione Group is a foreign financial institution of primary money laundering concern under…The Victim Ledger76%Partial
Stablecoin Settlement Infrastructurerarely trainedFATF, Targeted Report on Stablecoins and Unhosted Wallets (3 March 2026), attributing 84 per cent of illicit virtual asset…The Victim Ledger76%Partial
State-Sponsored IT Worker Payroll Infiltrationrarely trainedOFAC designations targeting DPRK IT worker facilitation, including Sim Hyon Sop of Korea Kwangson Banking Corporation (April…The Incoming Payment65%Partial
Terrorist Financing: small-value and fundraisingrarely trainedFATF, Comprehensive Update on Terrorist Financing Risks (July 2025)The Fundraising Appeal63%Partial
Crypto ATMs and OTC BrokersR v Osunkoya: the FCA's first criminal prosecution for unregistered cryptoasset activity under the Money Laundering Regulations…The Victim Ledger76%Partial
Investment and Romance Scam Proceeds InfrastructureUS and UK joint action of 15 October 2025 against the Cambodia-based Prince Group transnational criminal organisation: OFAC…The Victim Ledger76%Partial
NFT and In-Game Asset Wash TradingFATF and national FIU material on virtual asset market abuseThe Betting Account63%Partial
Ransomware Proceeds ConversionOFAC designation of 2 June 2026 of Nobitex, Iran's largest virtual currency exchange, together with Wallex, Bitpin and Ramzinex…The Victim Ledger76%Partial
Agentic Laundering and Automated Smurfingrarely trainedTRM Labs, Autonomous AI Agents and Financial Crime (2026), identifying layering as the stage most susceptible to automation…The Verification Desk84%Detected
Biometric Injection and Liveness Bypassrarely trainedGroup-IB, Weaponized AI (January 2026), documenting 8,065 biometric injection attempts against the digital loan onboarding of a…The Verification Desk84%Detected
Laundering and Fraud as a Servicerarely trainedFATF, Professional Money Laundering (26 July 2018), describing professional launderers, organisations and networks that launder…The Verification Desk84%Detected
Synthetic and AI-Generated Onboarding Documentsrarely trainedFinCEN Alert FIN-2024-Alert004 (13 November 2024) on fraud schemes using generative AI to circumvent identity verification…The Verification Desk84%Detected
Synthetic Identities at Scalerarely trainedUS Federal Reserve payments-improvement material on the transformation of synthetic identity fraud by generative AI; industry…The Verification Desk84%Detected
Control Probing and Detection-Threshold DiscoveryAnalytic pattern rather than a single reported caseThe Verification Desk84%Detected

How this was measured

Each case is built around one customer who is laundering money. The rate is the share of that customer’s alerts the team caught.

Detected
Four fifths of them or more.
Partial
Between a half and four fifths.
Missed
Half or fewer.
Untested
No one has sat a case covering it.

Nothing is reported as detected on the strength of a good overall mark. Findings are suppressed below 3 runs on a case, because a smaller number describes one analyst rather than a team. Methods are declared on the case, not the individual alert, so this reports whether the team detected the method a case is built around rather than scoring each method separately.

Results are a diagnostic and carry no regulatory standing. They are not a professional qualification. The customers and transactions in each case are fictional; the methods they are based on are taken from the published sources cited above. AML Benchmark is a trading name of Net Werth Ltd, company number 12718042.

Produce this on your own team

£750 for one cohort of up to 25 people sitting the whole Crypto and VASPs Assessment, invoiced, with no licence and no notice period. Deducted from a licence if you take one within 90 days.

Arrange a pilot