AML Judgment Gap Report · Full findings
Crypto and Digital Assets
This is a specimen. The cases, the weights, the methods and the sources are real, and are what your team would sit and what your own report would cite. The scores are invented, for a hypothetical cohort of 14 people. A real report carries your own results and nothing else.
Your team detects 6 of the 20 money laundering methods that apply to this sector. 6 need action, and 4 of those are rarely covered by standard training.
5 of these are urgent. Your team was tested on them and missed them.
Your assessment is 7 cases, not one. Each covers a different part of your exposure, and the appendix shows how many of your 20 methods each one carries. Measured against the methods that apply to this sector, not against other firms.
Since the last sitting
September cohort against March cohort. Your team detected 5 methods then and 6 now. 5 went backwards.
What to do
For each one, ask a single question. Does the team not know the method, or do they know it and have no rule that would surface it? The first needs a briefing. The second is a control gap, and it is the more serious answer.
- High
- Tested and missed, on a case covering a large part of your exposure.
- Medium
- Tested and missed on a smaller case, or never tested on one that matters.
- Low
- Never tested, and a small part of your exposure.
Ordered by priority. The reason for each is printed with it, so you can disagree with the ranking.
- 01
Chain-Hopping Across Bridges and Swaps
HighYour team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.
- Result
- Caught 46% of the laundering customer's alerts.
- Tested by
- The Exchange Desk — covers 6 of your 20 methods
- Training
- Rarely covered by standard annual refreshers
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
For a VASP: deposits whose immediate provenance is a bridge or DEX contract rather than an identifiable counterparty, and short holding times between receipt and onward swap. For a bank: fiat settlement from an exchange whose own inbound provenance cannot be evidenced.
90 days · Re-testSit The Exchange Desk again, on the version the team has not seen.
OwnerTarget date - 02
Mixers, Tumblers and Privacy Coins
HighYour team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you.
- Result
- Caught 46% of the laundering customer's alerts.
- Tested by
- The Exchange Desk — covers 6 of your 20 methods
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
For a VASP: deposits with mixer-adjacent provenance, or swap history through privacy assets. For a bank: exposure arrives already laundered, at the off-ramp.
90 days · Re-testSit The Exchange Desk again, on the version the team has not seen.
OwnerTarget date - 03
Nested Exchange Access and Sub-Accounts
HighYour team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.
- Result
- Caught 46% of the laundering customer's alerts.
- Tested by
- The Exchange Desk — covers 6 of your 20 methods
- Training
- Rarely covered by standard annual refreshers
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
A single institutional customer whose deposit and withdrawal counterparties number in the thousands, activity patterns inconsistent with a single beneficial owner, and onward flows to jurisdictions the customer does not operate in.
90 days · Re-testSit The Exchange Desk again, on the version the team has not seen.
OwnerTarget date - 04
State-Actor Cyber Theft and Laundering
HighYour team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you. Training rarely covers this, so a refresher will not fix it.
- Result
- Caught 46% of the laundering customer's alerts.
- Tested by
- The Exchange Desk — covers 6 of your 20 methods
- Training
- Rarely covered by standard annual refreshers
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
For VASPs: deposits traceable to designated addresses, and institutional counterparties who cannot evidence their own inbound provenance. For banks: correspondent exposure to intermediaries in the cash-out chain.
90 days · Re-testSit The Exchange Desk again, on the version the team has not seen.
OwnerTarget date - 05
Unhosted Wallets and Fragmented Off-Ramping
HighYour team was tested on this and missed it. It sits in The Exchange Desk, which covers 6 of the 20 methods that apply to you.
- Result
- Caught 46% of the laundering customer's alerts.
- Tested by
- The Exchange Desk — covers 6 of your 20 methods
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
Numerous customers each receiving modest, regular exchange settlements with no other economic profile, sharing device, address or beneficiary characteristics.
90 days · Re-testSit The Exchange Desk again, on the version the team has not seen.
OwnerTarget date - 06
Child Sexual Exploitation Payment Patterns
MediumYour team was tested on this and missed it. Training rarely covers this, so a refresher will not fix it.
- Result
- Caught 36% of the laundering customer's alerts.
- Tested by
- The Payment Trail — covers 1 of your 20 methods
- Training
- Rarely covered by standard annual refreshers
Now · BriefSend the team the register entry. It has the mechanism, the signal and the sources.
30 days · ControlWhich rule, report or alert would surface this?
Small repeated payments, often at unusual hours, to money transfer beneficiaries in a small number of jurisdictions with no family or trade connection to the customer; use of prepaid instruments or virtual assets by a customer with no other digital activity; and payment values clustered in narrow bands.
90 days · Re-testSit The Payment Trail again, on the version the team has not seen.
OwnerTarget date
On your own report
Each line carries your team’s result, an owner and a date. The re-test at 90 days shows what has moved.
Appendix
Evidence
Everything the finding above rests on, for anyone who wants to check it.
By case
The 7 cases that make up your assessment. Detection rate is the share of the laundering customer’s alerts the team caught. The last column counts people who escalated everything, which catches the laundering customer without deciding anything and scores badly for that reason.
| Case | Your methods | Share of assessment | Runs | Median mark | Detection rate | Escalated everything |
|---|---|---|---|---|---|---|
| The Exchange Desk | 6 | 24% | 14 | 49 | 46% | 3 of 14 |
| The Verification Desk | 6 | 24% | 14 | 87 | 84% | 3 of 14 |
| The Victim Ledger | 5 | 20% | 14 | 79 | 76% | 2 of 14 |
| The Betting Account | 4 | 16% | 14 | 67 | 63% | 2 of 14 |
| The Incoming Payment | 2 | 8% | 14 | 69 | 65% | 3 of 14 |
| The Fundraising Appeal | 1 | 4% | 14 | 65 | 63% | 3 of 14 |
| The Payment Trail | 1 | 4% | 14 | 39 | 36% | 2 of 14 |
Every method
All 20 methods that apply to this sector, and where each one is documented. Full citations are at amlbenchmark.com/coverage.
| Method | Case | Rate | Result |
|---|---|---|---|
| Chain-Hopping Across Bridges and Swapsrarely trainedElliptic, The State of Cross-Chain Crime 2025 | The Exchange Desk | 46% | Missed |
| Child Sexual Exploitation Payment Patternsrarely trainedFinCEN Notice FIN-2021-NTC3 (16 September 2021) on identifying and reporting suspicious activity related to online child sexual… | The Payment Trail | 36% | Missed |
| Nested Exchange Access and Sub-Accountsrarely trainedFATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs (October 2021) | The Exchange Desk | 46% | Missed |
| State-Actor Cyber Theft and Launderingrarely trainedBybit, 21 February 2025: approximately US$1.5bn in Ethereum stolen, attributed by the FBI to North Korean actors under the… | The Exchange Desk | 46% | Missed |
| Mixers, Tumblers and Privacy CoinsOFAC designation of Blender.io (May 2022) and of Tornado Cash (8 August 2022), the latter cited as having been used to launder… | The Exchange Desk | 46% | Missed |
| Unhosted Wallets and Fragmented Off-RampingFATF, Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions (3 March 2026) | The Exchange Desk | 46% | Missed |
| Guarantee Marketplaces and Criminal Service Platformsrarely trainedFinCEN finding that Cambodia-based Huione Group is a foreign financial institution of primary money laundering concern under… | The Victim Ledger | 76% | Partial |
| Stablecoin Settlement Infrastructurerarely trainedFATF, Targeted Report on Stablecoins and Unhosted Wallets (3 March 2026), attributing 84 per cent of illicit virtual asset… | The Victim Ledger | 76% | Partial |
| State-Sponsored IT Worker Payroll Infiltrationrarely trainedOFAC designations targeting DPRK IT worker facilitation, including Sim Hyon Sop of Korea Kwangson Banking Corporation (April… | The Incoming Payment | 65% | Partial |
| Terrorist Financing: small-value and fundraisingrarely trainedFATF, Comprehensive Update on Terrorist Financing Risks (July 2025) | The Fundraising Appeal | 63% | Partial |
| Crypto ATMs and OTC BrokersR v Osunkoya: the FCA's first criminal prosecution for unregistered cryptoasset activity under the Money Laundering Regulations… | The Victim Ledger | 76% | Partial |
| Investment and Romance Scam Proceeds InfrastructureUS and UK joint action of 15 October 2025 against the Cambodia-based Prince Group transnational criminal organisation: OFAC… | The Victim Ledger | 76% | Partial |
| NFT and In-Game Asset Wash TradingFATF and national FIU material on virtual asset market abuse | The Betting Account | 63% | Partial |
| Ransomware Proceeds ConversionOFAC designation of 2 June 2026 of Nobitex, Iran's largest virtual currency exchange, together with Wallex, Bitpin and Ramzinex… | The Victim Ledger | 76% | Partial |
| Agentic Laundering and Automated Smurfingrarely trainedTRM Labs, Autonomous AI Agents and Financial Crime (2026), identifying layering as the stage most susceptible to automation… | The Verification Desk | 84% | Detected |
| Biometric Injection and Liveness Bypassrarely trainedGroup-IB, Weaponized AI (January 2026), documenting 8,065 biometric injection attempts against the digital loan onboarding of a… | The Verification Desk | 84% | Detected |
| Laundering and Fraud as a Servicerarely trainedFATF, Professional Money Laundering (26 July 2018), describing professional launderers, organisations and networks that launder… | The Verification Desk | 84% | Detected |
| Synthetic and AI-Generated Onboarding Documentsrarely trainedFinCEN Alert FIN-2024-Alert004 (13 November 2024) on fraud schemes using generative AI to circumvent identity verification… | The Verification Desk | 84% | Detected |
| Synthetic Identities at Scalerarely trainedUS Federal Reserve payments-improvement material on the transformation of synthetic identity fraud by generative AI; industry… | The Verification Desk | 84% | Detected |
| Control Probing and Detection-Threshold DiscoveryAnalytic pattern rather than a single reported case | The Verification Desk | 84% | Detected |
How this was measured
Each case is built around one customer who is laundering money. The rate is the share of that customer’s alerts the team caught.
- Detected
- Four fifths of them or more.
- Partial
- Between a half and four fifths.
- Missed
- Half or fewer.
- Untested
- No one has sat a case covering it.
Nothing is reported as detected on the strength of a good overall mark. Findings are suppressed below 3 runs on a case, because a smaller number describes one analyst rather than a team. Methods are declared on the case, not the individual alert, so this reports whether the team detected the method a case is built around rather than scoring each method separately.
