An AML (Anti-Money Laundering) review is a compliance check that may involve both automated risk-detection systems and manual analysis. A transaction can be flagged when a service detects risk indicators that require additional review, such as exposure to potentially illicit funds, sanctions-related risks, or unusual transaction patterns.
Being placed under review does not automatically mean you did anything wrong. It means the compliance team needs additional information or analysis before determining what should happen with the transaction.
What Triggers an AML/Compliance Review?
Transactions may be flagged because of risk indicators identified through blockchain analytics, transaction patterns, sanctions screening, or other compliance checks.
For security and compliance reasons, crypto services generally cannot disclose the exact rules, thresholds, or individual risk indicators that caused a specific transaction to be flagged. Revealing this level of detail could allow bad actors to reverse-engineer compliance systems and deliberately structure transactions to avoid detection.
Some factors that may contribute to additional review include:
Address risk exposure – funds may have interacted directly or indirectly with addresses associated with sanctions, ransomware, theft, fraud, or other illicit activity.
Transaction patterns – repeated or unusual transaction behavior may trigger additional analysis.
Sanctions-related exposure – a wallet, counterparty, individual, entity, or other element of the transaction may be subject to sanctions restrictions.
⚠️ A compliance flag is not, by itself, an accusation of wrongdoing. It means the transaction requires additional review before it can proceed.
“An AML review doesn't mean you are trying to swap stolen money. Our review serves the main purpose - to make sure that we can either proceed with the swap or return the funds of a scam or a hack with the help of law enforcement,” says Pauline Shangett, Chief Strategy Officer at ChangeNOW.
What Happens During the AML Review?
Once a transaction is flagged, the compliance team reviews the relevant risk indicators and decides what additional checks, if any, are required.
There is no single AML review flow that applies to every transaction. Each case is assessed individually, and the process may change depending on the nature of the detected risk.
One common flow may look like this:
Stage
What happens
1. Risk signal detected
Automated monitoring identifies a transaction that requires additional review
2. Compliance review
The compliance team assesses the flag and available transaction information
3. Information request
If necessary, the user is asked to provide source-of-funds, or other supporting information
4. Decision
The compliance team determines whether the transaction can proceed or whether additional action is required
“Every AML review is different. After a transaction is flagged, our compliance team reviews the case manually and determines the next steps based on the specific circumstances. There is no universal timeframe or identical review flow for every transaction. Providing the requested information promptly and following the compliance team’s instructions can help avoid unnecessary delays and move the review forward more efficiently,” shares the ChangeNOW Compliance team.
ChangeNOW's compliance team operates 24/7, which means standard cases can often be handled relatively quickly. More complex cases, however, may require additional information or further investigation.
What Documents or Information Might You Be Asked For?
If your transaction is under review, you may be asked to provide supporting information that allows the compliance team to verify your identity and the origin of the funds.
Common requests include:
Proof of identity – for example, a passport or government-issued ID.
Proof of address (POA) – documentation confirming your residential address.
Source of funds (SoF) – materials showing how you obtained the funds involved in the transaction.
Transaction details – information about where the funds were sent from and their transaction history.
Additional supporting materials – any other transaction-related documentation required to verify the source or legitimacy of the funds.
“The most common compliance request combines KYC and source-of-funds verification," says the ChangeNOW Compliance team. “This may include identification, proof of address, and materials demonstrating where the funds involved in the transaction originated.”
Providing complete and accurate information usually helps the compliance team resolve the case more efficiently.
Will I Get My Funds Back?
The outcome depends on the circumstances of the individual case.
If the compliance review is successfully completed and the necessary information is provided, the transaction may be allowed to proceed according to the service's compliance procedures.
However, there are situations in which funds cannot immediately be released or returned. These may include cases where:
insufficient source-of-funds information has been provided;
the required KYC process has not been completed;
funds are linked to illicit activity;
funds are subject to an ongoing investigation or other legal restrictions.
“Whether funds can be released or returned depends on the outcome of the compliance review. If required KYC or source-of-funds information is missing, or if the funds are linked to illicit activity or an ongoing investigation, the compliance team may be unable to process the transaction until the issue is resolved,” – ChangeNOW Compliance team warns.
ChangeNOW aims to be as transparent with users as possible, which also means being clear that compliance cases are not always simple or resolved immediately. The outcome depends on the specific circumstances, applicable legal requirements, and the information available to the compliance team.
At the same time, users who provide accurate information and complete any required KYC or source-of-funds checks should generally be able to move through the process without unnecessary complications.
How to Reduce the Risk of AML Review Delays
While you can't fully control an exchange's risk engine, a few habits reduce the odds of being flagged and speed up resolution if you are.
Be prepared to complete KYC if requested. Make sure you have valid identification and proof-of-address documents available.
Keep records showing where your crypto came from. Exchange statements, payroll records, invoices, purchase records, and transaction histories can all help demonstrate source of funds.
Use wallets and accounts whose transaction history you can explain. Sending funds through unrelated third-party wallets may make their origin harder to verify.
Avoid transaction patterns that may appear unusual. For example, repeatedly making many near-identical exchanges within a very short period may trigger additional review.
Respond promptly to compliance requests. Complete information can significantly shorten the review process.
The important distinction is that the goal should not be to “avoid AML checks,” but to make sure your transaction history and source of funds can be clearly verified if a review occurs.
Closing Thoughts
AML and compliance procedures are not designed to make crypto harder to use. Their purpose is to help protect users, prevent stolen funds from moving further through the ecosystem, and give victims a better chance of recovering their assets.
As Pauline Shangett shares:
“In our nine years in the market, we’ve managed to return more than $50 million to victims of various scams, hacks, and thefts.”
Every flagged transaction or request for information ultimately serves a broader goal: making the crypto ecosystem safer and helping ensure that illicit funds do not simply disappear without a trace.
ChangeNOW has worked on numerous cases involving stolen and fraud-related assets, often in cooperation with users, compliance teams, law enforcement, and industry partners.
You can explore more real-world recovery and AML cases here: ChangeNOW AML Cases.
AML Review FAQ
There is no fixed timeframe for an AML review. The duration depends on the complexity of the case, the risk indicators involved, and whether additional information or documents are required.
User cooperation can make a major difference: providing complete KYC and source-of-funds information promptly can significantly accelerate the process.
Usually, no. Once the funds have already been deposited and the transaction has entered compliance review, the user cannot simply cancel it while the review is ongoing.
The compliance team first needs to complete the necessary checks and determine what action can be taken.
“If we have frozen a swap for a review, the funds are sent into cold storage. We don't touch them until we're permitted to release them,” shares Pauline Shangett.
If the compliance team requires additional information and the user does not provide it, the case may remain unresolved, and the transaction may stay on hold.
The transaction cannot be fully reviewed until the necessary KYC, source-of-funds, or other requested information has been provided.
If you have already responded to the compliance team's requests and the case remains under review, updates are generally provided approximately once a week.
If additional documents or clarification are needed, the compliance team may contact you sooner.
Compliance systems rely on risk indicators, rules, and thresholds that are intentionally not fully disclosed. Publishing the exact trigger behind every review could allow bad actors to adapt their transaction behavior and bypass AML controls.
For this reason, a service may explain what information it needs from you without revealing the exact internal rule that generated the original flag.