Tokenized Deposits · Part Three of Four

Monitoring Without a History: BSA/AML on Tokenized Deposit Networks

C. Erik Larson · October 2, 2026

Here is a problem I have not seen discussed much, and it is the one I would worry about first.

Start with what these networks get right. Access is controlled. Tokens are held only by wallets provisioned to customers who have completed KYC at a participating institution, and the contracts enforce it at the protocol level — a transfer without proper attestations cannot execute. That is a meaningfully higher floor than an open stablecoin.

But permissioned access is not a permissioned environment. Some of these run on private chains. Others do not: JPMorgan's deposit token is restricted to eligible institutional clients and settles on Base, a public L2. DTC-custodied securities are settling on Stellar. A whitelisted token moving through a public chain alongside other assets and composable contracts is a harder monitoring problem, not an easier one.

And in neither case is access control the same thing as monitoring.

Onboarding controls establish who is transacting. Monitoring asks whether the pattern of what they do looks like something. Every bank in the country does CIP on every accountholder and runs transaction monitoring anyway, because structuring, layering and trade-based laundering are all done by fully identified customers.

And monitoring systems are models. Thresholds, features, rules that fire and rules that do not, tuned against years of experience — productive alerts, typologies that became cases, feedback from investigations. That tuning is what makes them work and what makes them validatable. You can benchmark a model against history.

A new network has no history. New rails, new typologies, wallet-based rather than account-based, continuous rather than day-bounded. The monitoring system has to be calibrated from first principles, and then a second line has to form an independent opinion about whether the rules are the right rules, with no back-testing data worth the name.

I do not think this is intractable. Benchmark against synthetic typologies. Stress the thresholds. Document the judgment explicitly rather than burying it in a calibration. But it has to be done deliberately, and I have not seen a published framework for doing it.

There is a harder version. Layering across institutions is exactly what a single-participant view misses — it is why the BSA regime built information-sharing mechanisms. On a privacy-preserving network no participating bank sees the whole picture. The operator does. What the operator is obliged to do with that picture has not been settled.

Banks will be examined on this.

← Back to Thought Leadership