Watchlist and Screening

Screening is how Active Monitoring detects risk: it checks the addresses on your watchlist against TRM Wallet Screening on a schedule you choose. TRM Labs is the blockchain analytics provider that scores the risk of each address, and you use your own TRM account. This page explains what is screened, how a result becomes a risk event, and what limits apply.

The watchlist

The watchlist is the list of wallet addresses that Active Monitoring screens. You build it from a CSV file or from an ACE identity registry. See Manage the Watchlist.

The watchlist belongs to your organization, not to one token. Active Monitoring evaluates every watchlist address against the monitoring rule of every monitored token, on each network of that token.

Active Monitoring screens only these addresses. It does not read your token's holder list and does not screen the counterparties of transfers.

TRM risk levels

TRM returns one risk level for each screened address: Severe (score 15), High (10), Medium (5), Low (1), or Unknown (0). Active Monitoring asks TRM about the address across all the networks that TRM covers, so the level applies to the address as a whole, not to one network.

Your monitoring rule maps each level to a response. See Limits, Statuses, and Values for the scores and API values.

TRM also returns the categories behind the level, for example sanctions exposure or mixer activity. Active Monitoring keeps the full TRM result with each decision. You can read it in the TRM raw data tab of the decision.

Schedule

You choose how often Active Monitoring screens, in whole hours, when you add your TRM API key. The Platform UI offers 6, 12, and 24 hours. The API accepts 1 to 168 hours.

Screening starts when you click Start screening, or call POST /active-monitoring/screening-interval/start. The first run starts immediately, and later runs repeat at the interval. Each run screens the whole watchlist.

The Decisions log header shows when the least recently screened address was screened, and the interval: for example, "Last screened 2:15 hrs ago | Updates every 6 hrs".

If TRM cannot screen some addresses in a run, for example because the API key is invalid or TRM is unavailable, those addresses keep their previous result and are tried again at the next run.

When a result becomes a risk event

A screening result does not always lead to a decision. Active Monitoring raises a risk event only when:

  • an address is screened for the first time, or
  • the highest risk level of an address differs from the level of the previous run.

An address that stays at the same level raises no new event, so it produces no new decision. For example, an address that is Severe at the first run, and Severe at every later run, produces one decision for each matching rule, at the first run only.

This has three consequences:

  • A monitoring rule reacts to new events. When you create or replace a rule, addresses whose level does not change are not evaluated again.
  • A decision reflects the balance at the moment of the event, not later. An address that gets a balance after its decision does not trigger a new decision until its level changes.
  • To see Active Monitoring act on an address again, its risk level must change.

Limits

ItemLimit
Watchlist sizeNo fixed limit
Screening providerTRM only
Screening interval6, 12, or 24 hours in the Platform UI; 1 to 168 hours in the API
TRM API keysOne per organization

You need a TRM API key for TRM Wallet Screening. Active Monitoring does not provide TRM credentials. See the TRM website for how to get access.

Next steps

Get the latest Chainlink content straight to your inbox.