How I would run discovery and the roadmap for CertiK's bank and regulator products, with a working requirements desk that maps digital asset rules in eight jurisdictions to product capabilities. It also covers the Compliance Engineer role.
CertiK already sells licensing advisory, audits, proof of reserves and on-chain AML. Central banks and regulators now ask for it as one relationship: the NBKR MoU, the Hub71 vendor role, the Brazil central bank session.
The bank and regulator line is spread across five names, three of them without a product page. A buyer cannot yet see one product, one scope, one evidence pack.
A requirements desk: 90 obligations checked against their primary sources, a Travel Rule threshold check, client requests ranked with the reason recorded, and multi-list sanctions screening with evidence records and a public API.
| Takeaway | What it means for the roadmap |
|---|---|
| Sell the bundle | Formal verification, licensing advisory, monitoring and PoR in one engagement is ground TRM, Elliptic and Chainalysis do not cover alone. The roadmap should make the bundle visible as a product. |
| Banks buy evidence | A compliance officer signs off on what a regulator will accept. Every feature needs the evidence artefact it produces, named up front. |
| Two known gaps | No Travel Rule capability, and narrower chain coverage than the bank-facing leaders. Both are partner or sequence decisions with clear owners. |
| Consultants are the sensor | The Solutions Consultants are in the field from day one. A shared discovery agenda turns their notes into ranked, sourced requests. |
CertiK's public job board shows an institutional compliance team forming in about ten weeks. The product line it will own already exists in parts.
| Posted | Role | Base |
|---|---|---|
| Jul 23 | Compliance Engineer (+ intern) | Europe / Asia |
| Aug 11 | Director of Product, AML & Digital Asset Compliance | Hong Kong |
| Sep 14 | Director of AML & Virtual Asset Compliance | Hong Kong |
| Oct 1 | Strategic Account Executive, Financial Institutions | Brazil |
| Oct 6 | Lead Product Manager, Digital Assets | US; APAC |
| Oct 6 | Solutions Consultant, Digital Assets | Europe; Dubai |
| Name in use | Where it appears |
|---|---|
| SkyInsights | Product page: address labels, risk scoring, KYT API |
| Compliance AML | The same product in its docs (docs.compliance.certik.com) |
| CertiK Compliance Tool | Licensing app named in the Hub71 deal; no product page |
| Supervision and Compliance solutions | Named in the NBKR MoU; no product page |
| Skynet Enterprise | January 2026 blog, for institutions and regulators; no product page |
Advisory lines on the product menu: VARA Compliance, DORA & MiCA Compliance, DLT Security Solutions, Proof of Reserves. Recent institutional moves: NBKR MoU on Digital Som security and oversight (September 2026), LF Decentralized Trust membership ahead of Sibos (September 2026), Central Bank of Brazil fireside (August 2026), Hub71 official vendor (July 2026).
The JD names three client types. Each answers to a different examiner, so each buys a different proof.
| Buyer | What they must show | Capability | Evidence artefact |
|---|---|---|---|
| Bank entering custody or stablecoins | Sanctions screening on every wallet it touches; transaction monitoring scaled to crypto; Travel Rule data on transfers; model governance | Wallet screening, KYT, counterparty VASP risk, Travel Rule partner | Screening logs, rule inventory with thresholds, model documentation, SOC 2 scope letter |
| Licensed or applying VASP | A licence file that maps each rule to a control, then ongoing compliance after approval | Licensing tool, readiness assessment, PoR, monitoring | Gap assessment, policy set, PoR report, incident log |
| Regulator or central bank | Oversight of licensees and of its own CBDC or stablecoin rails | Supervision dashboards, market surveillance, audit of DLT systems | Supervisory reports in the regulator's own format, audit trail |
| Consultant (internal) | That the field signal reaches the roadmap intact | Discovery agenda, request log | Ranked backlog with the reason per item |
The demo carries this logic row by row: obligation, capability, evidence, primary source. Its Travel Rule check turns the rows into a per-transfer answer (for example, the UK threshold fell to £800 on 30 June 2026). Try SG to UK, USD 2,000.
Bank and regulator buyers already know the blockchain-analytics leaders. CertiK's edge is the security and licensing work that comes before and around the monitoring.
| Company | Bank and regulator position | Strength | Opening for CertiK |
|---|---|---|---|
| TRM Labs | TRM Regulator product; Eurosystem framework via Banque de France; Stablecore channel to US banks | Packaged supervisor product; $2B valuation (Sep 2026) | Pair supervision tooling with CBDC and DLT security audits, which TRM does not sell |
| Elliptic | UOB, HSBC, Banking Circle, Sygnum; four global banks as investors | APAC bank distribution; 65+ chains | Licensing advisory and PoR for the same banks' digital asset units |
| Chainalysis | Lead Bank, Stablecore channel, deep government base | Data depth; bought Hexagate for security monitoring | Formal verification and audit lineage for issuers and CBDCs |
| Merkle Science | Mastercard Crypto Partner Program | APAC presence | Broader institutional bundle |
| MistTrack (SlowMist) | Hong Kong police; HK RegTech award | Home market in Hong Kong | Licensing plus monitoring for HK stablecoin issuers |
| Hacken, Halborn | Audit plus compliance readiness; Halborn cites large banks | Same security pitch | Own AML monitoring product to attach |
| Notabene, Sumsub, 21 Analytics | Travel Rule networks; Notabene serves AMINA Bank | Travel Rule messaging | Partners: fill the Travel Rule gap without building a network |
Read as a bank buyer would during vendor due diligence. Each is small and fixable; together they shape the first impression of the product line.
| Finding | What a reader sees | Fix |
|---|---|---|
| Dollar amounts render as math | On blog posts with two "$" amounts in a paragraph, the text between them renders as italic math and the dollar signs disappear. The bank-facing NBKR explainer is affected. | Escape "$" or restrict inline math delimiters in the blog renderer |
| Chain coverage differs | The product page says "9+15 chains"; the API docs list 20; six chains announced in May 2024 are absent from the docs table. | One coverage table, generated from the API, linked from both |
| Headline numbers differ | Clients: 5,500 and 5,000. Assets: $563B, $576B and $600B. Projects monitored: 21,000, 18,600 and 17,000. | One dated stats source for site, llms.txt and press |
| No landing page for regulators | "For Regulators & Compliance" appears in the Solutions menu with no page behind it. | A single page for the bank and regulator line, with scope and evidence pack |
| Certification scope | Footers state SOC 2 Type II and ISO 27001; the Trust page scopes them to the Skyharbor platform. | Name which products are in scope; plan the AML product into scope |
| Docs audience | The AML docs list exchanges, wallets, custodians and infra teams as users; banks and FIs are missing. Docs open in 简体 by default. | Add the bank persona; default docs language by locale |
| JD duty | How I would do it | Detailed in |
|---|---|---|
| Run discovery with clients and prospects; set the consultants' agenda | One interview guide per buyer type, with the five questions that decide scope. Consultants log every request against it in a shared format. | §06 |
| Build a practitioner panel for structured, paid interviews | Twelve seats: four bank compliance, four VASP MLROs, two former supervisors, two risk operations. Quarterly rounds, paid at an hourly rate, notes tagged to requirements. | §06 |
| Convert conversations into prioritized decisions, with the reason documented | Each request records the stated ask, the underlying need, the linked obligations and a score. The reason travels with the item into the roadmap. | §07, demo |
| Defend the ranking to leadership | A transparent formula plus a written override log. Leadership can move an item; the move and its reason are recorded. | §07 |
| Present to clients, prospects and regulators; tenders | A standard demo per buyer type, a tender response library mapped to capabilities, and a gap list shared with BD before any bid. | §08 |
| Join BD and consultants on client visits | Visit plans with named discovery goals; every visit ends with logged requests within 48 hours. | §06 |
| Own the roadmap conversation with CEO, BD and Engineering | Monthly roadmap review on one page: ranked items, evidence behind each, engineering estimates, what moved and why. | §07 |
For the Compliance Engineer role: how I would review AI-drafted regulatory output before it reaches a client.
Split the rule into obligations at article or paragraph level, each with its primary source link. This is the reference the AI is checked against.
Each claim in the draft must quote or point to a paragraph that supports it. Unsupported claims are marked in the draft for rework.
Keep a labelled set of known-answer questions per framework. Track wrong citation, missing obligation and overstated conclusion separately.
Every repeated error becomes a review rule or an evaluation case for Engineering, so the same defect is caught automatically next time.
Where readings conflict, lay out each reading with its source and pass it to senior review or Legal. Final conclusions stay with them.
A source that could not be read or a list that failed to load is reported as unavailable. A clean result requires every source to have answered.
Three input channels, one log, one format.
| Channel | Cadence and owner | What it captures | Guard against |
|---|---|---|---|
| Client and prospect sessions | Every visit; PM with BD | Stated ask, workflow today, examiner pressure, budget owner | Building for the loudest single client |
| Consultant field notes | Weekly; consultants log, PM triages | Requests seen in licensing and readiness work | Requests losing their context on the way in |
| Practitioner panel | Quarterly round of 12 paid interviews | Whether a need repeats across firms and markets | Mistaking one regulator's wording for a market need |
Which examiner or rule makes this urgent, and by when?
What do you do today, and what does it cost in hours?
What evidence would you hand the examiner?
Who signs off, and who pays?
What would make you switch from your current vendor?
A starting hypothesis from public information only, to be replaced by discovery. Score = reach × regulatory weight × confidence ÷ effort, the same formula as the demo.
| Candidate | Rank | Reason | First proof |
|---|---|---|---|
| One bank and regulator product: name, page, scope | 1 | Every sale and tender starts with the buyer understanding what they are buying. Low effort, touches every deal. | One page and one evidence pack, reviewed by three panel members |
| Travel Rule through a partner | 2 | Required in every mapped jurisdiction (FATF R.16; zero threshold under the EU TFR). Partnering avoids building a messaging network. | Partner shortlist; VASP counterparty risk shown beside each message |
| Bank tenant risk defaults | 3 | Bank policies usually treat mixer exposure as high risk; the docs default is low. A bank template keeps VASP defaults intact. | Configurable rule set, documented per tenant |
| Regulator reporting formats | 4 | Supervisors want output in their own format. Competitors already ship templates for FinCEN, FCA, MAS and MiCA. | One format end to end for the first regulator client |
| Certification scope extended to the AML product | 5 | Bank vendor risk teams ask for it before the first call. Long lead time, so start early. | Scope letter and timeline |
| Chain coverage published from the API | 6 | Removes a visible inconsistency; the coverage gap itself is sequenced by client demand. | Generated coverage table |
Built from the public job postings (2026), CertiK's own product, docs, blog and company pages (read 2026-10-06), regulators' primary texts, and competitors' own pages. The roadmap ranking uses public information only and is a hypothesis for discovery to test. The demo is my own prototype built for this application; it is unrelated to CertiK's production systems. Unsolicited interview homework; happy to walk through any section.
CertiK: about · SkyInsights · Compliance AML docs · supported chains
Institutional: NBKR · NBKR explainer · Hub71 · Brazil
Strategy: path to a public future · regulations report · trust and security
Advisory: VARA · DORA & MiCA · LF Decentralized Trust
Competitors: TRM · Elliptic · Chainalysis · Notabene
Regulators: SFC VATP list · MAS DTSP · HKMA stablecoins
Independent homework for the CertiK Lead Product Manager, Digital Assets and Compliance Engineer roles · 2026 · edwardtay.com