Preventive and Continuous Compliance

ACE enforces compliance in two ways: it can block a transaction while it executes, and it can keep watching addresses and act after their risk changes. This page explains the two modes, so you can choose the one that fits your token, or use both.

Two modes

Preventive enforcement runs inside the transaction. A protected function asks a PolicyEngine to evaluate your policies, and the transaction reverts if a policy rejects it. It is provided by Policy Management and, for identity checks, Cross-Chain Identity. Your contract must integrate with ACE: it inherits PolicyProtected or is upgraded to do so.

Continuous monitoring runs outside the transaction. Active Monitoring screens a watchlist of addresses against TRM on a schedule, applies a rule you define when an address's risk level changes, and calls an existing function on your token, such as a freeze or a blocklist entry. Your contract does not change.

Preventive (Policy Manager, Identity Manager)Continuous (Active Monitoring)
When it actsWhile the transaction executesAfter a screening run detects a risk change
What it doesReverts a transaction that breaks a policyCalls an admin function on your token, flags a decision for review, or records it
Contract changesYes: PolicyProtected or an upgradeNone: you provide the ABI and grant an onchain role
Works on tokens already deployedOnly if you can upgrade them or place a contract in frontYes, if the token has admin functions you can grant a role for
Data it usesTransaction data, onchain state, credentials, and optionally a permit from an offchain checkTRM risk levels of the addresses on your watchlist, and balances
TimingImmediate: no violating transaction gets throughBounded by your screening interval: a change is seen at the next run
EvidencePolicyRunComplete events and the Reporting APIThe Decisions log, the TRM result, and the operation history

What each mode cannot do

A preventive policy cannot act on a token whose contract you cannot change, and it cannot react to something that happens outside a transaction, such as an address that is added to a sanctions list after it received tokens.

Continuous monitoring cannot stop a transaction. Between a risk change at TRM and the next screening run, an address can still transact. You reduce the window with a shorter screening interval.

Choose a mode

Your situationUse
You build a contract, or can upgrade it, and must block non-compliant transactionsPolicy Manager
You must check who can hold or transfer a token, based on KYC or accreditationIdentity Manager with Policy Manager
Your token is already deployed and cannot be changed, and you want to react when a holder becomes high riskActive Monitoring
You need both blocking at transaction time and a reaction to holders whose risk changes laterBoth

The two modes complement each other. Preventive policies stop a violating transaction at the moment it happens. Active Monitoring covers the holders who were compliant when they received the token and changed risk level afterward.

TRM in each mode

ACE uses TRM Wallet Screening in two separate features. They use separate credentials and separate guides:

Managed offchain risk policy (preventive)Active Monitoring (continuous)
When TRM is calledOnce per transaction request, before the user submits itOn a schedule, for every address on the watchlist
ResultA permit that the transaction consumes onchainA decision that follows your rule
Where the key livesIn the Vault DON, uploaded with the CRE CLIIn the Platform, under General settings > API access
GuideManaging Offchain Policies (MVP)Configure the TRM API Key and Screening Schedule

What both modes share

Both modes use your organization's onboarding, your CRE Connect Wallet on each network, the same signing models, the Coordinator API, and the ACE Platform. You can adopt Active Monitoring without using Policy Manager or Identity Manager.

Next steps

Get the latest Chainlink content straight to your inbox.