KYT is one of those compliance-conversation abbreviations that’s almost always mistaken for either a legal requirement or a phrase from the FATF Recommendations. Neither is true: behind the term is an industry practice that both the law and the regulator are familiar with — just under different names.
What KYT Is, in Simple Terms
KYT is the monitoring of a customer’s transactions and the assessment of their risk throughout the relationship: a system or a specialist checks each transaction against the customer’s profile, their behavioral history, and a set of rules, in order to spot a deviation and flag it in time. The term arose by analogy with KYC (Know Your Customer) and took hold primarily in the crypto industry, where it came to mean monitoring virtual asset transfers.
The phrase “KYT is continuous transaction control” comes up often, but no source actually requires the word “continuous” — it’s more accurate to speak of ongoing monitoring: it runs throughout the customer relationship, not only at onboarding.
Why KYT Isn’t a Statutory Term
This can be checked directly. The word “KYT” doesn’t appear even once in the Russian translation of the FATF Recommendations (an unofficial translation by MUMCFM, hosted on the EAG website; 192 pages, updated in June 2026) — nor does it appear in Articles 6 and 7 of 115-FZ, read in full. Russian legislation itself uses the word “operation” (операция), not “transaction” (транзакция), at all.
The closest regulatory equivalent in Russia isn’t “KYT” — it’s the wording in Bank of Russia Regulation No. 860-P of 18 June 2025: a credit institution’s internal control rules must include “a program for identifying, in customer activity, transactions subject to mandatory control, digital ruble transactions subject to mandatory control, suspicious transactions, suspicious digital ruble transactions, suspicious activity, and suspicious digital ruble activity” — one of the programs making up the internal control rules. In other words, what the industry calls KYT, the regulator calls a program for identifying transactions and suspicious activity.
KYT, KYC, and AML: What’s the Difference
The three terms are often lined up in a scheme like “KYC is who, KYT is what, AML is risk,” but that simplification is misleading in two places at once: KYT doesn’t “come after” KYC — they feed each other — and AML doesn’t “include” KYT as a sub-item in a scheme; it’s the legal framework within which both practices exist.
| What it is | Object | When it happens | Status of the term | |
|---|---|---|---|---|
| KYC | establishing and verifying information about the customer, their representative, the beneficiary, and the beneficial owner | a person | at onboarding and when information is updated | industry term; called “identification” in 115-FZ |
| KYT | monitoring a customer’s transactions and assessing their risk | a transaction and customer behavior | ongoing, throughout the relationship | industry term; no statutory definition |
| AML / AML-CFT | the full set of measures against money laundering and terrorist financing | the organization as a whole | throughout the entire customer relationship | AML-CFT is the statutory framework (115-FZ) |
The line between KYC and KYT is blurry: the results of transaction monitoring can become grounds for updating customer information, and the customer profile built during KYC verification sets the expected behavior that new transactions are compared against. Under 115-FZ, information is updated at least once every three years for low-risk customers, at least once a year for the rest, and within seven business days if doubts arise about the accuracy of the data — these timeframes belong to KYC, not KYT, but they’re exactly what shapes the profile that monitoring relies on. For how these requirements are met in practice, see the NeuroVision AML solutions page.
How Transaction Monitoring Works
The logic of monitoring is a chain, not a single mechanism; each step in it solves its own task:
The system receives information about the amount, the parties, the purpose, and other parameters of the transaction.
The transaction is checked against a set of rules: some are set by law (mandatory control thresholds), and some the organization sets itself in its internal control rules.
The transaction is compared against the customer’s history and typical behavior, to distinguish what’s normal from what isn’t.
When a deviation is detected, an alert is generated: an indication that the transaction needs human attention.
A designated compliance officer analyzes the alert in the context of the customer’s history and other data.
Based on the review, a decision is made: close the alert as a false positive, record the information, or report it to the authorized body.
Rules, Thresholds, and the Customer Profile
Rules and thresholds are the basic mechanism of monitoring. Some are set by law — for example, the mandatory control thresholds under 115-FZ. Some the organization sets itself, in its internal control rules, based on its own risk assessment. The rules come first; everything else — the customer profile, behavioral history, models — is built on top of them. Without a customer profile, a rule turns into a crude filter on amount alone: the profile and transaction history are needed to tell a specific customer’s normal behavior apart from what’s atypical for them.
From Alert to Specialist Decision
An alert isn’t an accusation or a ready-made conclusion — it’s an indication that a transaction or a set of a customer’s transactions needs human attention. Reviewing it is the job of a designated compliance officer, who weighs the alert against the customer’s history, other transactions, and the data available — and the final decision depends on that context.
Where Machine Learning Helps, and Where Rules Are Enough
Machine learning is not a mandatory element of monitoring — no regulatory source reviewed requires it. Some systems apply machine learning to find anomalies and reduce the share of false positives, but rules and thresholds remain the basic mechanism. A separate add-on is link analysis (the industry calls it graph analysis): it helps reveal chains of transfers and connected accounts, but it too isn’t a mandatory requirement — it’s a decision an organization makes on its own.
Why False Positives Are Unavoidable
The broader and cruder a rule is, the more transactions it flags without real grounds — this is a manageable quantity, not a system defect. The topic of false positives, and how they’re reduced without losing the quality of the check, is covered in detail in the article “False Positives in AML Screening”.
It’s worth separately noting: real-time monitoring is not a mandatory requirement of the standard. For example, the Interpretive Note to Recommendation 16 (INR.16, paragraph 28), as rendered in the unofficial Russian translation prepared by MUMCFM, explicitly allows that a receiving financial institution’s measures for detecting transfers lacking the required information may include post-event monitoring or, where feasible, real-time monitoring — meaning both options are named on equal footing.
What Signs Raise a Transaction’s Risk
Some signs are direct statutory grounds for documenting information under Article 7(2) of 115-FZ:
- a confusing or unusual nature of the deal, with no obvious economic sense or obvious lawful purpose
- a deal inconsistent with the purposes of the organization’s activity as set out in its founding documents
- repeated transactions or deals whose nature gives grounds to believe their purpose is evading mandatory control procedures (the industry calls this structuring)
- a transaction by a customer about whom the authorized body has sent an inquiry
- a customer’s refusal to carry out a one-off transaction that raises suspicion
- a customer’s decision to refuse to establish a relationship or to terminate one, where there are reasonable grounds to suspect this is connected with the conduct of internal controls
In addition, as industry indicators not tied to any specific provision: rapid transit of funds, a sharp change in transaction volume, atypical geography, a departure from the customer’s usual behavior, and unusual transfer chains.
None of the signs listed on its own means a crime has occurred, and none automatically makes a transaction suspicious. Under the law, it’s grounds for documenting the information and further assessment: suspicion arises among the organization’s staff as a result of applying the internal control rules — it doesn’t trigger on its own.
A separate note on source freshness: the signs of unusual deals used to be tied to Bank of Russia Regulation No. 375-P, but that regulation has been superseded — replaced by Regulation No. 860-P of 18 June 2025. The specific indicator codes from the annex to 860-P aren’t given here: that level of detail requires a separate check.
The Travel Rule: What It Is and Who It Affects
The Travel Rule is a rule requiring a transfer to be accompanied by information about the sender and the recipient. The term “Travel Rule” doesn’t appear in the Russian translation of the FATF Recommendations at all — not once across 192 pages; it’s an industry name that took hold in the crypto industry.
In June 2025, FATF revised Recommendation 16 — exactly what changed, and how virtual assets fit into it, is covered below, in the section on implementation. The Russian translation of the FATF Recommendations, prepared by MUMCFM and hosted on the EAG website, was updated in June 2026 and contains the revised Recommendation 16, “Payment Transparency.” The translation is unofficial: FATF publishes the original text of the standard. The verbatim data requirements and thresholds below are given according to the translation of the FATF Recommendations updated in June 2026.
How Recommendation 15 and Recommendation 16 Are Connected
The precise structure has three layers, and collapsing them into the single phrase “the Travel Rule is Recommendation 16” is a mistake:
- Recommendation 15, “New Technologies,” requires countries to ensure virtual asset service providers (VASPs) are regulated for AML-CFT purposes, licensed or registered, and subject to effective monitoring systems
- the Interpretive Note to Recommendation 15 (INR.15), paragraph 7(b), extends the requirements of Recommendation 16 to virtual asset transfers
- Recommendation 16, “Payment Transparency,” sets out the substance of the requirement itself: a transfer must be accompanied by information about the sender and the recipient
FATF itself frames this link in its July 2026 report: “The Travel Rule applies the FATF’s payment transparency requirements (FATF Recommendation 16) to the VA context.”
What Data Is Transmitted, and Who’s Responsible
The obligations are spelled out in the Interpretive Note to Recommendation 15 (INR.15), paragraph 7(b):
- The ordering VASP obtains and holds required and accurate originator information and required beneficiary information on virtual asset transfers, submits it to the beneficiary VASP or financial institution immediately and securely, and makes it available to appropriate authorities upon request
- The beneficiary VASP obtains and holds required originator information and required and accurate beneficiary information, and makes it available to authorities upon request
Notice the asymmetry in the word “accurate”: for the ordering VASP, accuracy is required for the originator’s data; for the beneficiary VASP, for the beneficiary’s data. A feature specific to virtual assets: the information can be transmitted directly or indirectly, and it doesn’t have to accompany the transfer itself — for bank transfers, the data travels with the payment message, while for virtual assets a separate channel is more often used.
The data set for a cross-border payment or transfer of value above the minimum threshold (INR.16, paragraph 9):
- the name of the sender and the recipient
- the account number of the sender and the recipient, if an account is used; if there’s no account, a unique transaction reference number (paragraph 9(b))
- the sender’s address, as well as the recipient’s country and city
- the sender’s date of birth, if the sender is a natural person
- if the sender and/or the recipient is a legal entity, where available: an associated BIC (Business Identifier Code), an LEI (Legal Entity Identifier), or a unique official identifier
Is There a Threshold Below Which the Rule Doesn’t Apply
This is the most common distortion on the topic: there are two different thresholds of USD or EUR 1,000, and they’re constantly confused.
| Threshold | What it means | Provision |
|---|---|---|
| The customer due diligence threshold | the threshold amount for one-off transactions above which a VASP is required to carry out customer due diligence | INR.15, paragraph 7(a), referencing Recommendation 10 |
| The transfer data-set threshold | countries may adopt a threshold of no more than USD/EUR 1,000, below which it’s sufficient to have the sender’s name, the recipient’s name, and each party’s account number or a unique transaction reference number, with no requirement to verify the accuracy of this data absent suspicion | INR.16, paragraph 8 |
Two conclusions here are unavoidable. First, below the data-set threshold, the requirement doesn’t disappear — only the volume of information transmitted changes: the ordering financial institution still has to ensure that a transfer below the minimum threshold contains the sender’s name, the recipient’s name, and each party’s account number or a unique transaction reference number (INR.16, paragraph 21). Second, this threshold is optional for a country: FATF explicitly states that countries should minimize thresholds given the risk of transactions moving underground, and that national requirements may be stricter. The claim “the Travel Rule applies starting at $1,000” is wrong for both reasons at once.
What’s Happening With Implementation: FATF Data for 2026
According to FATF, on 18 June 2025 it published amendments to Recommendation 16, agreed at its June 2025 plenary meeting, and renamed it — it’s now called “Payment Transparency.” Countries are expected to be ready to implement the updated requirements by the end of 2030 — a deadline for countries, not for individual companies. The revision responds to a changing payment landscape: the diversity of payment products and market participants, new technologies and messaging standards, and the evolution of risks.
The revision also extends to virtual asset transfers: the Interpretive Note to Recommendation 15 points to the updated data set — name, account number or a unique transaction reference number, the sender’s address, the recipient’s country and city, the sender’s date of birth if a natural person, and for legal entities a BIC, an LEI, or a unique official identifier — or to equivalent information as applied to virtual assets. The minimum threshold is retained: countries may adopt a threshold of no more than USD/EUR 1,000 for cross-border payments and transfers of value, excluding cash withdrawals, and, under the new provision, separately for domestic transfers. As of publication, FATF’s guidance on applying the revised Recommendation 16 hadn’t yet been finalized: the draft was out for public consultation from 24 June to 21 August 2026 and, according to FATF, doesn’t change the obligations of the updated recommendation but clarifies how they apply.
How far the Travel Rule has actually been implemented in practice is shown by the FATF report “Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs” from July 2026: 83% of respondents (91 of 109 jurisdictions) had passed legislation implementing the Travel Rule, with another 11 of 109 reporting that they were in the process of doing so. A more telling figure: 60% (55 of 91) of the jurisdictions that had already passed such legislation had not yet issued findings or guidance, or taken supervisory or enforcement action against VASPs over Travel Rule compliance. The gap between passing a law and actually applying it is the thing worth remembering from this data.
KYT in Crypto Services vs. Banks: What’s Different
The general logic of monitoring is the same: a stream of transactions, rules and thresholds, risk assessment, detecting deviations, an alert, human review. But the implementation differs markedly.
| Crypto services | Banks and fintech | |
|---|---|---|
| What’s monitored | virtual asset transfers, links between addresses, behavior across platforms | account transactions, payments, transfers, customer behavior within the bank |
| Counterparty data | the other party may have no servicing provider at all | the other party is almost always served by a financial institution |
| Data exchange | Travel Rule information is transmitted separately from the transfer itself on the network — directly or indirectly; the standard doesn’t prescribe a specific channel, and in practice a separate channel is more often used for virtual asset transfers | the data travels together with the payment message |
| Regulatory framework | Recommendation 15 and its Interpretive Note, plus national virtual asset regulation | Recommendation 16 directly, national banking regulation, and in Russia, 115-FZ and Bank of Russia acts |
A Russian detail almost nobody writes about: Federal Law No. 283-FZ of 4 August 2026 added new types of mandatory-control transactions to Article 6 of 115-FZ — the purchase and sale of digital currencies, the acquisition and redemption of digital rights, and also crediting digital currencies or digital rights to an identifier address administered by a digital depositary from an identifier address not administered by a digital depositary, and the reverse transfer. This is the closest Russian equivalent to the topic of non-custodial wallets, and the threshold for these transactions is the common one — ₽1 million. Law No. 283-FZ took effect on 1 September 2026, and it sets no separate deadline for these provisions — meaning they’ve been in effect since that date.
KYT and 115-FZ: The Russian Framework
Mandatory Control: There’s No Single Threshold
The claim “mandatory control starts at ₽600,000” is contradicted by the text of the current version of the law — thresholds vary by type of transaction:
| Type of transaction | Threshold | Provision |
|---|---|---|
| General list: cash; transactions involving persons from listed jurisdictions; transactions on accounts and deposits; other transactions with movable property; precious metals; purchase and sale of digital currencies; acquisition and redemption of digital rights; transactions between administered and non-administered identifier addresses | ₽1,000,000 | paragraph 1 |
| Real estate transactions | the amount is set by the authorized body, not less than ₽5,000,000 | paragraph 1.1 |
| Receipt and disbursement of funds by a non-profit organization | no threshold | paragraph 1.2 |
| Accounts and letters of credit of strategic defense-industry and security organizations (business entities, federal state unitary enterprises, state corporations, state companies, public-law companies) | ₽10,000,000 | paragraph 1.3 |
| Receiving a transfer from the territory of a foreign state on the authorized body’s list | no threshold | paragraph 1.3-1 |
| Separate state defense order accounts | ₽600,000 — crediting from and debiting to any other accounts; ₽10,000,000 — the second and subsequent credits from, and debits to, other separate state defense order accounts | paragraph 1.4 |
| Receiving cash on a card issued by a foreign bank on the list | no threshold | paragraph 1.5 |
| Payments under a leasing agreement | ₽1,000,000 | paragraph 1.6 |
| Postal money order | ₽100,000 | paragraph 1.7 |
| Refund of an unused advance payment for communication services | ₽100,000 | paragraph 1.8 |
| Transactions on the instructions of a customer — a foreign citizen or foreign legal entity — identified under the simplified procedure (Article 7(1)(5-11)) | ₽50,000 for a foreign citizen; ₽500,000 for a foreign legal entity | paragraph 1.8-1 |
| Transactions whose types are determined by Rosfinmonitoring (the Federal Financial Monitoring Service) in agreement with the Bank of Russia | the threshold is set by the corresponding act | paragraph 1.9 |
| Transfer to a digital ruble account and back | ₽1,000,000 | paragraph 1.11 |
| Digital currencies and rights as consideration under foreign trade contracts | ₽10,000,000 | paragraph 1.12 |
| Transactions involving persons on the list of those connected to extremism and terrorism | no threshold | paragraph 2 |
There’s no single mandatory-control threshold: the law sets different thresholds for different types of transactions. The baseline threshold under Article 6(1) is ₽1 million, and “₽600,000” is the threshold only for transactions between a separate state defense order account and any other accounts (paragraph 1.4); movement between separate state defense order accounts, starting from the second credit, is controlled from ₽10,000,000.
Suspicious Transactions and Reporting Deadlines
Mandatory control and detecting suspicious transactions are different procedures, with different timeframes and different starting points. Information on mandatory-control transactions is submitted to the authorized body no later than three business days following the day the transaction is carried out (Article 7(1)(4)). Information on suspicious transactions is sent no later than three business days following the day such transactions are detected — regardless of whether the transaction itself is on the Article 6 list (Article 7(3)).
Bank of Russia Regulation No. 860-P separately distinguishes between “suspicious transactions” and “suspicious activity”: a single transaction can be normal even when a customer’s overall pattern of conduct isn’t.
The obligation to maintain internal control rules and appoint a designated compliance officer responsible for implementing them doesn’t fall on every company — only on the organizations listed in Article 5 (banks, professional securities market participants, insurance organizations, pawnshops, payment acceptance operators, and others) and the persons specified in Article 7.1 (attorneys, notaries, persons providing legal and accounting services) — and only when carrying out certain transactions on a customer’s behalf or by their instruction. For more on exactly who 115-FZ applies to and how financial monitoring works, see the article “AML/CFT in Simple Terms”; the requirements of 115-FZ as they apply to fintech companies are covered in the article “Fintech Compliance Under Federal Law 115-FZ”.
Why Mandatory Control Isn’t KYT
Equating “KYT = mandatory control” is wrong. Mandatory control is a list of transaction types set by law (including transactions Rosfinmonitoring is entitled to define under Article 6(1.9)): if a transaction is on the list and exceeds the threshold, the information is sent regardless of whether it raises suspicion or not. A KYT system works not only off formal mandatory-control thresholds, but also off risk assessment and deviations. The internal control rules are an organization’s internal document, including, among other things, a program for identifying such transactions; a KYT system is a tool that helps implement that program. The two concepts partly overlap, but they aren’t the same.
Checking transactions and their parties against the lists of persons connected to extremism and terrorism, as well as against sanctions lists, is a separate task, applied to both the customer and the parties to the transaction. For more on how list screening and politically exposed person (PEP) risk assessment work, see the article “How Sanctions Screening, PEP Checks, and Risk Profiling Work”.
How KYT Differs From Anti-Fraud
| KYT | Anti-fraud | |
|---|---|---|
| What it looks for | signs of money laundering and terrorist financing, transaction behavior atypical for the customer | fraud: unauthorized access, social engineering, altered payment details, abuse |
| In whose interest | meeting AML-CFT requirements and reducing regulatory risk | protecting the customer and the organization from direct loss |
| Who receives the result | the designated compliance officer, the authorized body | the security team, the product, the customer themselves |
| Time horizon | behavior over time, a body of transactions | more often a single transaction, here and now |
Overlaps are possible, and that’s normal: both systems look at the flow of transactions and build rules on top of it. But the roles differ — the task, who receives the result, and the time horizon are all different. For more on the architecture of a system that hunts for fraud in real time, see the article “Anti-Fraud System: Architecture and Real-Time Fraud Monitoring”.
How to Build Transaction Monitoring: Where to Start
For an organization implementing or revising transaction monitoring, the usual sequence looks like this:
- determine whether the organization is subject to Article 5 or Article 7.1 of 115-FZ, and exactly which transactions fall under mandatory control
- set out, in the internal control rules, a program for identifying transactions subject to mandatory control and suspicious transactions, and appoint a designated compliance officer
- set thresholds and rules — both the statutory ones and the organization’s own, based on its customer risk assessment
- build a customer profile and typical behavior pattern, to distinguish normal transactions from atypical ones
- build in screening against the lists of persons connected to extremism and terrorism and against sanctions lists
- set up a route for specialist review of alerts and a procedure for recording decisions
- as the transaction flow grows — consider automating data collection, rule application, and initial risk assessment, while leaving the decision on disputed alerts to a specialist
According to its product page, the NeuroVision KYT platform supports configuring custom scenarios and triggers — amount limits, transaction types, geography, frequency, links between accounts — connecting to sanctions lists, KYC databases, core banking systems, and payment gateways, and support for STR/SAR reporting formats (suspicious transaction reports). Some systems also apply machine learning to find anomalies in customer behavior.
The NeuroVision KYT platform helps configure verification rules and scenarios, connect sanctions lists, and generate reports, leaving the decision on disputed alerts to a specialist
KYT is the industry name for the practice of ongoing transaction monitoring and risk assessment — not a statutory term: in Russia, the closest regulatory equivalent is the program for identifying mandatory-control transactions and suspicious transactions within the internal control rules. What sets this practice apart from KYC is its object of attention (a transaction, not just the customer) and the fact that it isn’t tied to onboarding or scheduled-review checkpoints. AML, meanwhile, isn’t an alternative to KYT — it’s the broader legal framework. The path from a transaction to a decision is a chain of data, rules, risk assessment, and specialist review, not an automated system that renders its own verdict. Real-time monitoring and machine learning are common, but not mandatory under the standard; rules and thresholds remain the basic mechanism. The Travel Rule requires a virtual asset transfer to be accompanied by information about the sender and the recipient, and that requirement doesn’t disappear even for small amounts — only the volume of data changes. And within the Russian 115-FZ framework, it’s worth remembering: there’s no single mandatory-control threshold, and mandatory control and the KYT approach are different things, even though they partly overlap.