THE WORKING PRINCIPLE

A useful counterparty review documents the evidence for a decision and the limits of that evidence.

Start with the operational question

Describe why the counterparty is being reviewed. A new settlement address, an internal escalation, and a changed relationship can call for different evidence. The brief should make the business context understandable to someone outside the originating team.

Record how the address was obtained and the network on which it should be examined. Similar-looking identifiers on different networks do not provide the same review context.

Establish the public record

Capture the network snapshot and the relevant indexed activity. Note whether the address is a wallet or contract, which counterparties appear in the returned activity, and which source references support those observations.

Keep the activity window visible. A small set of recent transactions is a starting point for inquiry, not a comprehensive profile of a counterparty.

KEEP IN THE RECORD
  • Complete address and network
  • Snapshot block and retrieval time
  • Relevant direct activity
  • Source coverage and gaps

Add intelligence for a defined purpose

Before consulting a provider, state the question it should help answer. That might concern attributed exposure, a reported campaign, or the significance of an infrastructure relationship.

Preserve provider attribution and distinguish the provider’s assessment from your team’s own conclusion. If sources disagree, keep the disagreement visible and identify what further evidence would resolve it.

Write a reviewable rationale

Summarize the strongest relevant observations, the material unknowns, and the next review step. Avoid turning an unexplained score or an isolated association into a conclusion.

A good handoff allows operations, security, or another reviewer to inspect the basis of the assessment without rebuilding the entire investigation. Apply the appropriate review process for your organization.

GroundTruth field notes describe an investigation method. Apply the review scope, source licensing, and information-handling requirements appropriate to your organization.