At a glance
- Exchange jurisdiction risk is a legitimate input to wallet scoring, weighted alongside on-chain behaviour, attribution data and direct counterparty exposure.
- FATF-derived jurisdiction labels describe where an exchange is registered, not how its customers behave or where funds ultimately settle.
- NOMINIS combines wallet screening, KYT and crypto investigations in one platform, with real-time monitoring across 70+ blockchains, per NOMINIS.
- Jurisdiction signals speed up triage but cannot replace tracing; pair them with cross-chain hop analysis before escalating or filing.
Nominis
Published:
Yes — the jurisdiction in which a counterparty exchange is registered belongs in a wallet risk score, as one weighted signal sitting beside on-chain behaviour, attribution data (data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity) and direct exposure to sanctioned clusters. The signal also carries a documented failure mode. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions — FATF being the Financial Action Task Force, the global standard-setter whose mutual-evaluation ratings most jurisdiction models inherit — with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions. A favourable country rating can therefore sit on precisely the flows an MLRO needs surfaced. For teams recalibrating models in 2026, the practical question is how much weight the geography field should carry, and what evidence has to accompany it before a transaction is held. Nominis was built for that combination: wallet screening, KYT (continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing) and investigations in one platform, with real-time monitoring across 70+ blockchains and cross-chain tracing up to 50+ hops, according to Nominis.
Should exchange jurisdiction risk feed your wallet scoring, and how heavily?
Yes — the licensing jurisdiction of a counterparty exchange is a legitimate input to a blockchain wallet risk score, provided it enters the model as a contextual modifier applied on top of behavioural evidence. This section narrows to one sub-case: how to treat the regulatory domicile of a centralized exchange appearing as a counterparty in a screened address's transaction graph. Jurisdiction risk here means the AML/CTF standing of the venue's licensing regime — its FATF listing status, whether it operates under a framework such as MiCA, and whether it has implemented the FATF Travel Rule, the obligation to pass originator and beneficiary information alongside a transfer.
Registration in a well-supervised jurisdiction is not evidence that a venue's flows are clean. As published on nominis.io/insights, Nominis contributed on-chain analysis that independently corroborated a Washington Post investigation into IRGC laundering nearly $150 million through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025. Nested services compound the problem: brokers that route customer funds through another platform's custody and liquidity can park illicit flow behind the deposit addresses of a separately licensed venue.
Which jurisdiction attributes are worth modelling?
| Attribute | Allowed values / range | Why it matters to the score |
|---|---|---|
| FATF listing status | Compliant / increased monitoring / call for action | Sets the baseline supervisory expectation for enhanced due diligence |
| Licensing regime | Licensed under a named framework such as MiCA / registered only / unlicensed | Determines whether records and escalation paths exist at all |
| Travel Rule implementation | Full / partial / none | Governs whether originator data can be obtained for the counterparty leg |
| KYC posture | Full / tiered / no-KYC | No-KYC venues break the identity link behind the address |
| Custody structure | Independent custody / nested | Nested routing obscures who actually controls the funds |
Apply these attributes as weightings on direct evidence — hop distance from a sanctioned or illicit cluster, structuring patterns, mixer exposure — and record each weighting and its rationale in your risk policy, so an examiner can reconstruct how any single score was reached.
What exactly does exchange jurisdiction risk measure in a wallet score?
Exactly what "exchange jurisdiction risk" measures depends on which reading of jurisdiction you apply to a counterparty venue, and the two readings in common use can produce different scores from the same blockchain data.
Regulatory-regime risk treats jurisdiction as a licensing fact: where the exchange is registered, which supervisor oversees it, and whether it operates under a regime such as MiCA or a FATF-aligned framework. A venue incorporated in a well-supervised market scores low on this reading, whatever its customers do.
Observed-behaviour risk treats jurisdiction as an empirical variable: how often wallets tied to venues in a given country actually appear in illicit flows. On this reading, a venue in a well-regulated market can still carry elevated exposure when attribution data shows sanctioned or terror-linked counterparties transacting through it. This article uses the observed-behaviour reading throughout.
The four terms sitting underneath the score:
| Term | What it means | Underlying data |
|---|---|---|
| Jurisdiction risk | Risk weighting attached to the country or regime governing a counterparty venue | Registration and supervisory records, FATF listings |
| VASP attribution | Linking a pseudonymous address to the virtual asset service provider controlling it | Attribution data — clustering, deposit-address mapping, off-chain signals |
| Exchange counterparty exposure | Share of a wallet's traced volume reaching or leaving a named venue | Cross-chain transaction tracing across hops |
| Wallet risk score | Composite output driving alerting and escalation thresholds | All of the above, plus sanctions and typology datasets |
Each input ages differently. Registration records are stable and cheap to obtain, but they describe status rather than flows. Attribution data — the layer that de-pseudonymizes addresses by tying them to the controlling real-world entity — has to be refreshed as services rotate deposit addresses and nested brokers appear. Counterparty exposure depends on how many hops the tracing engine follows before the trail is abandoned. Nominis combines these inputs in one platform, so attribution, cross-chain tracing and sanctions data resolve into the single score a compliance team acts on.
How do jurisdiction signals compare with direct exposure signals inside a risk model?
To compare jurisdiction signals with direct on-chain exposure signals, three criteria carry most of the weight inside a wallet risk model, and each is worth defining before any scoring decision is made:
- Accuracy — how closely the signal tracks the specific wallet in front of you rather than the population it belongs to. This becomes decisive when alert volume is already straining the review queue.
- Evidentiary strength — whether the signal produces a traceable artefact (a transaction path, a cluster, an attribution record linking an address to the controlling real-world entity) that an investigator can reconstruct. This matters most when a case may become a suspicious activity report or a law-enforcement referral.
- Defensibility — whether the rationale survives examiner scrutiny under regimes such as MiCA, the FATF Travel Rule and OFAC sanctions obligations, without reading as blanket geographic exclusion.
| Criterion | Jurisdiction / licensing signal | Direct on-chain exposure signal |
|---|---|---|
| Accuracy | Population-level; a legitimate counterparty in a higher-risk venue scores the same as an illicit one | Wallet-level; keyed to sanctioned addresses, mixers, darknet markets and terror-financing clusters |
| Evidentiary strength | Contextual — supports a risk rating, rarely supports a narrative on its own | Produces a reconstructible fund path and counterparty attribution |
| Defensibility | Defensible as a tiering input; weak as a sole basis for de-risking a customer | Defensible as a stated, evidenced reason tied to an identified counterparty |
| Refresh behaviour | Changes slowly, with licensing and mutual-evaluation cycles | Changes continuously as funds move across chains and hops |
Geography-derived inputs fit portfolio tiering, review scoping and counterparty onboarding, where population-level context is what the decision needs. Direct exposure inputs fit per-transaction decisions, freeze rationales and investigative escalation, where an examiner will ask which address, which path, which hop.
The registration status of a venue also says little about where its flows terminate. Nominis published a forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market, finding that 45 route funds through nested services — exchanges or brokers that push user funds through another platform's custody rather than holding them independently. That same Nominis study identified nearly 6,000 wallets facilitating over $100 million in transaction volume annually.
Where does jurisdiction-weighted scoring produce false positives or miss real illicit activity?
Jurisdiction-weighted scoring — assigning wallet risk partly by the regulatory standing of the country where a counterparty exchange or service is registered — can produce two opposite failures at once: unnecessary friction for legitimate users, and quiet blind spots where illicit funds move through venues in well-regulated markets. Both failures share a cause: a registration flag describes the venue's paperwork, not the behaviour of the funds passing through it.
Does a high-risk country flag mean the customer is high-risk?
No. A registration address is a property of the venue, not evidence about the individual wallet. Risk models that treat the two as equivalent drive de-risking — closing or refusing accounts for category membership alone — which removes customers without removing exposure and inflates alert queues analysts cannot clear within review deadlines.
Can a well-regulated venue still carry illicit flow?
Yes. Nested services — brokers or exchanges that route user funds through another platform's custody and liquidity rather than holding funds independently — inherit the host's jurisdictional standing while masking the real counterparty. Nominis forensic research into no-KYC exchanges has documented how widely this pattern is used to keep operating under sanctions pressure. Attribution data, which links an address to the controlling real-world entity, identifies the nested operator sitting behind the host venue's registration.
| Do this | But watch out for — and how to manage it |
|---|---|
| Use registration jurisdiction as one input among several | Blanket offboarding of legitimate users; require corroborating on-chain behaviour before any exit decision |
| Escalate on concentrated exposure to higher-risk venues | Alert inflation; pair the geographic signal with entity attribution and hop distance before it reaches an analyst |
| Apply lighter handling to low-risk-jurisdiction counterparties | Nested infrastructure hiding behind a compliant front; Nominis addresses this with cross-chain tracing that follows funds past the first counterparty |
How should a compliance team calibrate jurisdiction weighting step by step?
Compliance teams can calibrate jurisdiction weighting through a short, documented cycle rather than a one-off parameter change — and at the decision stage, what matters is that each adjustment is defensible to a regulator and testable against alerts you have already worked.
- Set the baseline. Record how your risk model treats counterparty jurisdiction today: which registries or lists it draws on, whether it scores the exchange's licensing domicile or its operating reality, and what weight the factor carries relative to behavioural signals.
- Separate jurisdiction from typology. Score the venue's domicile as one input and the transaction pattern — structuring, layering, nested routing — as another, so a single factor cannot silently dominate the composite score.
- Define escalation thresholds explicitly. Decide which combined scores trigger enhanced due diligence, which trigger a hold, and which are logged for periodic review. Write the bands into policy, not into a configuration file alone.
- Document the rationale per weight. One paragraph per factor naming the source, the assumption, and the review date is usually enough to satisfy an examiner asking why a given jurisdiction scores as it does.
- Back-test against closed alerts. Replay a sample of resolved cases through the revised weighting and compare outcomes: which true positives survive, which noise disappears, which escalations now arrive later.
- Re-run on a fixed cadence and after any sanctions designation touching your counterparty set.
The constraint worth naming is structural: back-testing can only measure alerts a model already produces, so weighting tuned purely on internal history tends to confirm existing coverage rather than expose gaps. No-KYC venues that route funds through nested services — brokers pushing user money through another platform's custody — surface mainly through attribution data, which links blockchain addresses to the real-world entity controlling them, not through internal replay.
Frequently Asked Questions
What does exchange jurisdiction risk mean in wallet scoring?
Exchange jurisdiction risk is the weighting a compliance team assigns to a counterparty wallet based on where the exchange or service behind it is registered and supervised — typically mapped against FATF jurisdiction categories. It is a legitimate input, but it is a weak proxy on its own: Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions.
How does attribution data change a jurisdiction-weighted score?
Attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — tells you what a counterparty actually is, while a registration country only tells you where its paperwork sits. That distinction matters because of nested services: exchanges or brokers that route user funds through another platform's custody and liquidity to obscure ownership. A Nominis forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services, identifying nearly 6,000 wallets that facilitate over $100 million in transaction volume annually.
Which signals should sit alongside jurisdiction in a risk model?
Where a 2026 risk assessment already weights counterparty jurisdiction, these entity- and flow-level signals belong beside it:
- Entity attribution for the service controlling the address, including nested and no-KYC infrastructure.
- Cross-chain path depth — per Nominis, the platform delivers real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops.
- Hosted versus unhosted wallet status, since self-custody addresses create visibility gaps that custodial counterparties do not.
- Typology markers such as layering and structuring, where funds are split or moved rapidly through multiple wallets, chains or services.
Does jurisdiction scoring help with sanctions-evasion cases?
Jurisdiction scoring rarely catches sanctions evasion by itself, because designated actors deliberately transact through venues that look well-regulated. Nominis addresses that gap through KYT — Know Your Transaction, the continuous analysis of blockchain transactions for laundering, sanctions evasion, fraud and terror financing, distinct from KYC identity checks at onboarding. Nominis CEO Snir Levi appeared on i24 News (The Rundown) to break down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions.
Can Nominis run alongside an existing Tier-1 provider?
Yes. Nominis is built to operate as an additional intelligence layer next to platforms such as Chainalysis, TRM Labs and Elliptic. Every provider carries coverage gaps, and the depth Nominis contributes concentrates on terror-financing, sanctions-evasion and broader illicit-activity cases documented across its published insights, including IRGC- and Hezbollah-linked and ISIS-linked networks.
How quickly can a smaller VASP or CASP start screening?
Nominis is the only fully self-serve, transparently-priced platform in the category: pricing is published, and a regulated exchange, custodian, OTC desk or crypto payment provider can sign up and begin screening immediately, with automated monitoring reducing the manual effort of assembling wallet context by hand. For procurement diligence, Nominis won 1st place at Mastercard's Fintech Forum, and per its own company information it is backed by Mastercard and leading venture-capital firms and holds SOC 2 Type II.
About this article
Nominis publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Nominis before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24