At a glance
- Low-risk FATF jurisdiction status describes a country's regime, not the counterparty exchange routing funds through it.
- Nominis research found illicit actors are 12x more likely to use exchanges in low-risk FATF countries.
- Counterparty screening should test the venue's own controls, nested-service exposure and attribution data — not its registration address.
- NOMINIS combines wallet screening, KYT and investigations, adding dark web, OSINT, SOCMINT and HUMINT attribution to on-chain flows.
Nominis
Published:
Screening counterparty exchanges in low-risk FATF jurisdictions means treating the venue itself — not the country stamped on its registration — as the unit of risk. A jurisdiction rated low-risk by the Financial Action Task Force (FATF), the intergovernmental body that sets global anti-money-laundering and counter-terrorist-financing standards, tells you that the national regime meets a standard; it says nothing about whether a specific exchange operating there enforces know-your-customer checks, routes flows through nested services, or holds wallets with exposure to sanctioned entities. Nominis research found that illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — a finding that makes geography a weak proxy for counterparty risk and puts the burden back on entity-level evidence.
That evidence is what most compliance teams assemble by hand. If your venue already runs transaction monitoring through Chainalysis, TRM Labs or Elliptic — the Tier-1 incumbents known for broad enterprise coverage and incumbency — you have the on-chain half of the picture. What typically stays manual is the other half: identifying who actually controls a counterparty's deposit addresses, whether a "regulated" venue is fronting another platform's custody, and whether its wallet clusters connect to terror-financing or proliferation-financing infrastructure that has not yet reached OFAC's Specially Designated Nationals list. This article looks at how to build that counterparty file in 2026 — the attribution data, nested-service tests and jurisdictional signals worth weighting — and where NOMINIS, which combines wallet screening, Know Your Transaction monitoring and crypto investigations in one platform, fits alongside or in place of an incumbent stack.
Why can a counterparty exchange domiciled in a low-risk FATF jurisdiction still carry terror-financing or sanctions exposure?
Narrowing the question to a single case: a counterparty exchange domiciled in a jurisdiction that FATF has neither grey-listed nor black-listed still carries residual exposure, because domicile records which supervisory regime the entity registered under, and registration does not observe the transaction paths by which illicit funds actually arrive. The attributes below describe what a screening decision depends on once domicile is known.
- Jurisdiction of domicile — values: FATF-compliant, increased-monitoring, or call-for-action. Sets baseline supervisory expectations, licensing scrutiny and FATF Travel Rule enforcement, but says nothing about which customers the venue onboards or which chains it settles on.
- Custody architecture — values: independent custody, or nested. Nested services are exchanges or brokers that route user funds through another platform's custody and liquidity rather than holding funds themselves, a structure used to obscure ownership under sanctions pressure. On-chain, deposits can resolve to the host platform's addresses, so the visible counterparty is not the controlling operator.
- Onboarding controls — values: full KYC, tiered, or no-KYC. Determines whether an information request can ever recover a real-world identity behind a deposit.
- Withdrawal surface — values: hosted or unhosted. Hosted (custodial) wallets are managed by a third party and ease compliance; unhosted (self-custody) wallets give users full control and create visibility gaps at the point of screening.
- Attribution depth — values: address-level only, or entity-level. Attribution data de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity, so entity-level coverage can identify an otherwise unremarkable deposit address as belonging to a known facilitator.
Layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin — means exposure often sits several hops upstream of the depositing address, inside a venue whose own registration looks orderly. NOMINIS layers external intelligence from dark-web sources, OSINT, SOCMINT and HUMINT onto its screening to attribute those upstream addresses to controlling entities.
What is the difference between a low-risk domicile and a low-risk counterparty in exchange screening?
The difference between a low-risk domicile and a low-risk counterparty is that one describes where an exchange is registered and supervised, while the other describes what a specific entity and its addresses actually do. This depends on what you mean by "low-risk," because the phrase carries two separate meanings in counterparty exchange screening, each measured with different evidence.
Jurisdiction-level risk (the domicile). This is assessed from FATF mutual evaluation outcomes, grey-list status, and the strength of the local VASP licensing regime — for example, an exchange authorised under the EU's MiCA framework and subject to supervised Travel Rule obligations. It tells you how the venue is regulated, not how it behaves.
Entity- and address-level risk (the counterparty itself). This is assessed from on-chain evidence and attribution: which deposit addresses the venue controls, what those addresses receive, and whether flows are routed through nested services — brokers or exchanges that run user funds through another platform's custody rather than holding them independently. A fully licensed venue in a well-rated country can still sit in front of nested infrastructure.
Precise definitions for the terms this distinction rests on:
- VASP / CASP — a virtual asset service provider (called a crypto-asset service provider under MiCA): a business that exchanges, transfers, custodies or issues virtual assets for others.
- Counterparty exchange — the venue on the other side of a customer deposit or withdrawal.
- Attribution data — data that de-pseudonymises blockchain addresses by linking them to the controlling real-world entity and its activity.
- Exposure — the value or share of a customer's flows connected, directly or through intermediate hops, to a given entity or risk category.
- Travel Rule — the FATF requirement to transmit originator and beneficiary information alongside qualifying transfers between VASPs.
NOMINIS screens at both the address and entity level, using attribution data to link an address to the real-world entity controlling it.
How do jurisdiction-list screening, attribution-depth screening, and behavioural screening approaches compare?
Jurisdiction-list screening, attribution-depth screening and behavioural screening test three different things about the same counterparty exchange, which is why their results diverge on exactly the venues that look clean on paper. Each becomes decisive in a different operational situation:
- Coverage — how much of a counterparty's real exposure the method can observe. Decisive when funds cross several chains and intermediaries before reaching your deposit address.
- False-positive load — the volume of alerts an analyst must clear by hand. Decisive for small AML functions where review capacity, not detection, is the constraint.
- Evidentiary strength — whether the output holds up in a suspicious-activity report or regulator's file. Decisive when a finding must be defended, not merely recorded.
- Sensitivity to concealed exposure — whether the method surfaces sanctions- or terror-financing-linked flows routed through a venue with an unremarkable risk profile. Decisive where nested services sit between you and the true counterparty.
| Screening method | What it actually tests | Coverage | False-positive load | Evidentiary strength |
|---|---|---|---|---|
| Jurisdiction-list filtering | Registration country and licence status of the counterparty venue | Broad but shallow — every venue gets a score, none gets a trace | Low volume, but misses exposure a licensed venue carries | Weak alone; establishes context, not a money trail |
| Attribution-depth analysis | Which real-world entity controls the addresses and clusters behind the venue | Deep on traced flows; bounded by attribution data quality | Moderate; ambiguity concentrates at unhosted wallets | Strong — produces a named, reconstructable path |
| Behavioural / typology detection | Patterns such as layering, structuring and mixer use across transactions | Wide across transaction volume; weaker on entity identity | Higher; benign patterns can mimic typologies | Moderate; supports intent, needs attribution to name a party |
These methods are layered because each covers another's gap: a list tells you where a venue is registered, cluster tracing tells you whose addresses sit behind it, and typology detection tells you how funds are moved through it. NOMINIS pairs on-chain attribution with external intelligence — dark web, OSINT, SOCMINT and HUMINT — so flagged deposit addresses can be tied to the controlling entity rather than left as unresolved risk scores.
Which data layers should a counterparty exchange screening workflow actually cover?
This workflow narrows to screening exchange counterparties your platform sends value to and receives from. Each data layer answers a different question about that counterparty; jurisdictional filtering—sorting counterparties by FATF risk classification of their registration country—operates only as a coarse first pass.
On-chain attribution data. Attribution data de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and activity. Typical values: entity name, service type (exchange, mixer, OTC desk, nested service), and confidence indicator. A deposit address at a licensed venue may belong to a nested service—a broker routing user funds through another platform's custody and liquidity rather than holding them independently—which registration records do not reveal.
Hop depth. Tracing distance, measured in transaction hops and extended across chains, between the counterparty address and an attributed source or destination. Layering—rapid movement through multiple wallets, chains or services to obscure origin—pushes illicit origin beyond a one-hop view.
Sanctions and designated-entity identifiers. Wallet addresses, entity names, aliases and corporate identifiers from OFAC's SDN List and equivalent regimes. Exact-match and fuzzy-match handling both matter, since designations name entities after flows have moved.
Off-chain and open-source intelligence. Dark web listings, OSINT, SOCMINT and HUMINT signals binding an address to an operator, marketplace or facilitation network no ledger records.
Regional-language sources. Forums, marketplaces and messaging channels in local languages, where counterparty infrastructure is advertised before appearing in English-language reporting.
Typology libraries. Named patterns—structuring, mixer use, nested exchange routing, stablecoin laundering, proliferation financing—giving an analyst a testable hypothesis rather than an unlabelled anomaly.
NOMINIS brings on-chain attribution, cross-chain tracing and external intelligence together in one platform, so an analyst can move from a flagged counterparty deposit to its attribution and external-intelligence context inside the same investigation.
How should a compliance team escalate when a low-risk-jurisdiction counterparty triggers an alert?
When a counterparty exchange in a low-risk jurisdiction triggers an alert, the compliance team should escalate along a graded, documented path — the jurisdiction rating shifts the starting assumption, but the procedure stays the same.
What does the escalation path look like step by step?
- Triage the hit inside the alerting platform. Confirm whether exposure is direct or indirect, record hop distance, and capture the attribution data — evidence linking an address to the controlling real-world entity — that drove the score. NOMINIS combines address screening, KYT (Know Your Transaction: continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing) and investigation tooling in one platform.
- Run enhanced due diligence on the counterparty itself, not only the transaction: licensing status, ownership, and whether the venue routes flows through nested services — brokers operating inside another platform's custody rather than holding funds independently.
- Issue an RFI (request for information) to the counterparty VASP, using Travel Rule channels where they exist, with a defined response deadline.
- Apply interim exposure limits — holds, withdrawal caps or counterparty caps — proportionate to the finding.
- Document the SAR/STR decision either way. A reasoned decision not to file is itself a record examiners expect to see.
Where do over- and under-escalation actually hurt?
| Do this | But watch out for | Mitigation |
|---|---|---|
| Freeze funds on a first indirect hit | Customer attrition and unjustified restriction claims | Tie freezes to a written severity threshold, not analyst discretion |
| Escalate every low-risk-jurisdiction alert to EDD | Queue backlog; genuine cases age out | Automate evidence collection so analyst time goes to adjudication |
| Close alerts quickly because the venue is licensed | Missed sanctions-evasion and terror-financing exposure | Require attribution evidence, not registration status, to close |
| Rely solely on the counterparty's RFI response | Self-reported answers can be unverifiable | Corroborate against on-chain tracing and external intelligence before closing |
What should teams monitor as FATF listings, sanctions designations, and typologies change?
Teams should monitor FATF plenary outcomes, grey- and black-list movements, and new sanctions designations as live inputs to counterparty risk rather than an annual paperwork exercise. A counterparty exchange's jurisdiction, licensing posture and correspondent relationships can shift between plenary cycles, so a venue that screened clean at onboarding can inherit exposure without changing its own conduct.
A defensible programme in 2026 rests on three mechanics:
- Scheduled review cadence. Periodic re-assessment of every counterparty exchange, timed to the plenary calendar and risk appetite, with rationale recorded rather than inferred.
- Event-driven re-screening triggers. A new OFAC SDN designation, list movement affecting the counterparty's jurisdiction, licence withdrawal, or newly observed typology—mixer usage, nested services routing funds through another platform's custody, or stablecoin layering—should force an unscheduled re-screen of historical and open exposure.
- Governance evidence. Retained screening outputs, version-stamped risk ratings, escalation notes and analyst reasoning behind each disposition make a decision reviewable by regulators months later.
Designation dates are poor proxies for risk dates. Sanctions listings tend to be lagging markers on both sides: exposure can accumulate against an address long before the controlling entity is named, and designated addresses are not always dormant once the listing lands. That makes a point-in-time screen at onboarding an incomplete control for counterparty exchanges whose wallets keep moving value between review cycles. Continuous KYT—ongoing transaction analysis rather than identity checks at onboarding—closes both gaps, and NOMINIS applies automated screening and monitoring so list changes do not become a manual reconciliation project.
Frequently Asked Questions
What does a "low-risk" FATF jurisdiction rating actually tell you about a counterparty exchange?
It tells you how the Financial Action Task Force assessed that country's anti-money-laundering and counter-terrorist-financing framework through its mutual evaluation process. It is a country-level judgment. The individual exchanges, brokers and payment firms licensed in that country still apply their own onboarding and monitoring controls, and those vary widely. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. Counterparty due diligence therefore operates at the entity and wallet level alongside the jurisdictional view.
How do you screen a counterparty exchange in practice?
A workable sequence for a VASP or CASP looks like this:
- Resolve the counterparty's deposit and withdrawal addresses to the controlling entity using attribution data — data that de-pseudonymizes blockchain addresses by linking them to the real-world entity behind them and its activity.
- Establish whether the counterparty holds customer funds itself or routes them through another platform's custody and liquidity.
- Apply continuous KYT, or Know Your Transaction: ongoing analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which verifies identity only at onboarding.
- Trace indirect exposure across chains rather than stopping at direct counterparties. Per NOMINIS, the platform provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
- Retain the FATF Travel Rule counterparty record and the screening rationale so the decision is reconstructible at audit.
Why do nested services complicate screening in well-regulated jurisdictions?
Nested services are exchanges or brokers that route user funds through another platform's custody or liquidity instead of holding funds independently, which obscures who actually controls an address. A registered, jurisdictionally clean counterparty can carry that traffic without it appearing in a direct-exposure view. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.
Which cases do the Tier-1 incumbents tend to miss, and where does NOMINIS add depth?
Chainalysis, TRM Labs and Elliptic bring broad enterprise coverage and large datasets as entrenched incumbents, and each platform sees some data the others do not. NOMINIS catches terror-financing, sanctions-evasion and broader illicit-activity cases those Tier-1 incumbents miss — complementary depth rather than blanket superiority, not wider coverage across the board. Much of that depth comes from external intelligence — dark web, OSINT, SOCMINT and HUMINT — layered onto on-chain analysis, which can surface facilitation infrastructure that address-level ledger data alone leaves unattributed.
How quickly can a smaller VASP start screening counterparties?
NOMINIS is fully self-serve with published pricing: a compliance team can sign up and begin wallet screening immediately, without an enterprise procurement cycle. That matters where monitoring obligations arrive before a dedicated procurement function exists. Screening, KYT and investigation tooling sit in the same platform, so a smaller exchange or payment provider can start with address screening and extend into continuous monitoring and money-trail tracing without re-tooling or a second vendor onboarding.
When does staying on your current monitoring platform make sense?
If your existing Tier-1 deployment is embedded in case management, alerting and regulatory reporting workflows, and your risk appetite centres on general laundering typologies already well covered, a migration in 2026 may create more operational disruption than it resolves. An alternative in this position is to run a second layer for specific exposures — sanctions, terror financing, nested counterparties — rather than replacing the incumbent. Contract timing, API rework, historical case continuity and retraining of analysts all belong in that calculation.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24