Blog

Why Illicit Actors Prefer Exchanges in Low-Risk FATF Jurisdictions

At a glance
  • Illicit actors gravitate to exchanges in low-risk FATF jurisdictions because lighter scrutiny, weaker enforcement, and reputational cover let dirty funds blend into legitimate flows.
  • Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions than higher-risk ones.
  • Roughly 91.5% of terror-linked transactions target exchanges in low-risk and increased-risk jurisdictions, inverting the assumption that risk concentrates in blacklisted countries.
  • MLROs should re-weight geographic risk models, monitor counterparty exchanges continuously, and treat jurisdictional reputation as a signal — not a safeguard.

Why Illicit Actors Prefer Exchanges in Low-Risk FATF Jurisdictions

Illicit actors prefer exchanges in low-risk FATF jurisdictions because those venues offer the operational advantages of a compliant environment — banking access, fiat on-ramps, credible counterparties — without the intense enforcement scrutiny applied to blacklisted countries. In short, low-risk status is treated as camouflage, not as a deterrent. Nominis research found that illicit actors are 12x more likely to route funds through crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions — a finding that inverts the intuitive assumption that geographic risk concentrates where the Financial Action Task Force's grey and black lists sit. For MLROs and financial-crime leaders reading this in 2026, the practical implication is direct: a counterparty exchange's home jurisdiction says far less about its exposure than the on-chain behaviour flowing through it, and geographic-risk scoring models built on FATF list status alone will systematically underweight where illicit funds actually move.

Why do illicit actors prefer exchanges in low-risk FATF jurisdictions?

Illicit actors prefer exchanges domiciled in low-risk FATF jurisdictions because the "low-risk" label itself lowers the friction on every leg of a laundering flow — onboarding, movement, and cash-out. As the opening figures show, Nominis's research documents a pronounced skew of illicit flows toward these venues rather than toward the obviously blacklisted ones. The perverse logic: the cleaner the flag, the less scrutiny the counterparty receives from correspondent banks, payment rails, and receiving VASPs downstream.

If a jurisdiction is FATF-rated as low-risk, it follows that transactions routed through its licensed exchanges inherit a presumption of legitimacy — and that presumption is exactly what layering (moving funds through multiple wallets, chains, or services to obscure origin) is designed to exploit. A wallet that touches a "clean" exchange picks up a reputational halo that survives several downstream hops, especially when cross-chain bridges and nested services (brokers that route funds through another platform's custody rather than holding independently) further fragment the trail.

What tactics does this enable, and what should you watch for?

Do this But watch out for
Flag counterparties operating from low-risk jurisdictions when behavior diverges from the jurisdiction's risk profile Rule-based screening that trusts the jurisdiction label and suppresses the alert
Trace beneficial ownership through nested-service layers, not just the immediate exchange Nested infrastructure that presents a clean front-end while routing through no-KYC venues
Monitor structuring patterns (many small transfers under reporting thresholds) even from "reputable" origins Threshold-based logic that only trips on large single transactions
Correlate on-chain flows with sanctions and terror-financing attribution data Attribution gaps that make a low-risk-origin wallet look pristine on the surface

The highest-impact mitigation: treat jurisdiction as one signal among many, never a pass.

What does 'low-risk FATF jurisdiction' actually mean?

This depends on what you mean by "low-risk FATF jurisdiction" — the phrase actually blends two distinct classifications that are often conflated in compliance conversations. The Financial Action Task Force (FATF) is the intergovernmental body that sets global anti-money-laundering (AML) and counter-terrorist-financing (CTF) standards, and its published lists shape how regulated firms weight geographic risk in their screening logic.

Which FATF lists actually exist?

FATF itself maintains only two formal public lists, and neither is called "low-risk":

  • Black list (High-Risk Jurisdictions Subject to a Call for Action): currently a very small set, including the DPRK and Iran, where counter-measures are expected.
  • Grey list (Jurisdictions Under Increased Monitoring): countries with identified strategic deficiencies that have committed to a remediation action plan.

Everything else — the vast majority of countries — sits outside these lists. In industry shorthand, those unlisted jurisdictions get labelled "low-risk," but FATF has never certified them as such.

How does "low-risk" actually get assigned?

The label is a derived rating, not an official designation. It typically reflects a combination of:

  • Mutual Evaluation Reports (MERs) from FATF-Style Regional Bodies, scoring technical compliance and effectiveness across the FATF Recommendations.
  • Basel AML Index and similar third-party country-risk indices.
  • Domestic supervisor maturity — whether a jurisdiction licenses VASPs (Virtual Asset Service Providers), enforces the FATF Travel Rule, and aligns with frameworks like the EU's MiCA regulation.
  • Sanctions posture — participation in OFAC, UN, and EU sanctions regimes.

Which interpretation should compliance teams use?

For practical AML programme design, the most useful reading treats "low-risk" as unlisted-but-not-cleared. A jurisdiction can sit off both FATF lists and still host weakly-supervised exchanges, permissive VASP licensing regimes, or nested-service infrastructure. That gap between the formal FATF classification and on-chain reality is exactly where illicit flows concentrate — and why geographic risk ratings alone cannot substitute for transaction-level intelligence.

How do illicit actors exploit compliance gaps in low-risk jurisdictions?

Illicit actors exploit compliance gaps in low-risk FATF jurisdictions by chaining together a small set of predictable tactics — nested accounts, shell entities, and KYC arbitrage — that individually look benign but combine into effective laundering pipelines. The specification here is narrow: not why they choose these jurisdictions, but exactly how they operate once inside them, and which attributes of each tactic a monitoring team should encode into detection logic.

Which tactical attributes matter most?

Tactic How it works Detection attribute Why it matters
Nested services A broker or informal exchange runs customer flows through another platform's custody rather than holding funds independently, hiding the true originator. Cluster of deposit addresses funneling to a single upstream VASP account with disproportionate outbound volume. Nominis's forensic study of 57 no-KYC exchanges serving the Russian and Ukrainian market found 45 route funds through nested services — nearly 6,000 wallets facilitating over $100 million in annual volume.
Shell entities Corporate wrappers registered in permissive company registries hold accounts at a compliant exchange elsewhere. Mismatch between beneficial-owner geography, funding-source geography, and counterparty geography. Layers legal opacity onto on-chain opacity, defeating name-based sanctions screening.
KYC arbitrage The same beneficial owner opens accounts at multiple VASPs, choosing the weakest identity checks for high-risk flows and the strongest for cash-out. Behavioural fingerprints (device, timing, counterparty overlap) recurring across ostensibly unrelated accounts. Bypasses jurisdictional controls without triggering any single platform's thresholds.
Structuring across venues Large sums split into sub-threshold transactions spread across exchanges in the same low-risk corridor. Coordinated timing and amount patterns across counterparties, not within one account. Single-venue KYT (Know Your Transaction — continuous on-chain analysis for financial crime) misses it entirely.

What does this look like in practice?

The Washington Post's IRGC investigation, which Nominis's on-chain analysis independently corroborated, described nearly $150 million laundered through the London-registered exchanges ZedCex and ZedXion between 2023 and 2025 — a textbook combination of shell-entity registration in a low-risk jurisdiction and nested routing to hide the ultimate originator. The exploit sits in the seams between venues, registries, and reporting regimes — which is precisely where single-platform monitoring goes blind.

Which jurisdictions and exchange profiles are most commonly abused?

The jurisdictions and exchange profiles most frequently abused share a common signature: light-touch supervision paired with high liquidity and permissive onboarding. Illicit actors gravitate toward venues where the regulatory ceiling sits below their operational needs — not always tax havens, but often FATF-assessed "low-risk" or "increased-risk" countries whose reputational cover exceeds their enforcement teeth.

What criteria should you weight when profiling a venue?

Before comparing venues, MLROs should agree on the criteria that actually predict illicit exposure. In our view, these five carry the most weight:

  • Supervisory intensity — is the licensing regime enforced, or nominal? MiCA-aligned regimes in the EU raise the bar materially; several offshore regimes do not.
  • KYC depth — full identity verification, tiered limits, or no-KYC at all.
  • Nested-service posture — does the venue custody funds directly, or route through third-party liquidity that obscures counterparty attribution?
  • Travel Rule adherence — implementation of the FATF Travel Rule for VASP-to-VASP transfers.
  • On-chain footprint — measurable exposure to sanctioned addresses, mixers, and darknet markets under continuous KYT (Know Your Transaction, the ongoing analysis of blockchain flows for financial-crime signals).

How do the exchange profiles compare?

Exchange profile Typical jurisdiction posture KYC depth Nested-service risk Illicit-exposure signal
Licensed Tier-1 CEX MiCA / major-market regulated Full, tiered Low Low, but layering-transit risk remains
Regional licensed CEX in "low-risk" FATF country Formal license, thin supervision Variable Moderate Disproportionate — see below
No-KYC exchange Offshore or unclear None High Very high
P2P / OTC desk Often unlicensed Minimal High Very high, especially in conflict zones

Both Nominis findings cited earlier converge on this profile: the pronounced skew of terror-linked flows toward low-risk and increased-risk jurisdictions, and the prevalence of nested routing among no-KYC exchanges, point to the same conclusion — the "clean-jurisdiction" cover is itself the attraction.

Verdict: the highest-abuse combination in 2026 is a nominally-licensed venue in a low-risk FATF country running nested liquidity — a profile that reads clean on paper but resolves dirty on-chain.

What typologies signal jurisdictional arbitrage in crypto flows?

Several recurring typologies signal jurisdictional arbitrage in crypto flows, and compliance teams can learn to spot them before funds disappear into layered infrastructure. The common thread: illicit actors deliberately route value through venues whose supervisory posture creates a gap between what regulators expect and what exchanges actually enforce.

Which patterns should analysts watch for?

  • Nested-service routing. Funds land at a licensed exchange but ultimately clear through a broker or sub-exchange riding on that platform's liquidity — the nested pattern Nominis found across most of the no-KYC exchanges it studied (see above).
  • Low-friction venue hopping. As covered earlier, Nominis research quantifies the pronounced skew of terror-linked flows toward exchanges in low-risk and increased-risk FATF jurisdictions — a pattern MLROs should treat as a persistent baseline rather than a periodic anomaly.
  • Stablecoin layering across chains. Rapid movement of USDT or USDC across Tron, Ethereum, and BNB Chain — sometimes across many sequential hops — to break analytical continuity between origin and cash-out.
  • Structuring under Travel Rule thresholds. Splitting withdrawals just beneath the FATF Travel Rule's originator/beneficiary reporting trigger, a classic smurfing adaptation for the on-chain era.
  • Mismatched geography. Onboarding IP, KYC documentation, and counterparty exposure clustering in a different region than the exchange's licensing jurisdiction.

Action and risk: how should MLROs respond?

Do this But watch out for
Screen counterparty VASPs by both license jurisdiction and beneficial-owner geography A "clean" license can mask nested operators — verify the actual custody layer
Flag cross-chain hops beyond a defined depth as elevated risk Legitimate DeFi users also hop chains; tune thresholds to your risk appetite
Escalate structured withdrawals near reporting thresholds Structuring alerts generate noise — pair with wallet attribution data before filing
Monitor stablecoin corridors into low-supervision venues Blanket bans on stablecoin counterparties will block legitimate PSP flows

Highest-impact mitigation: invest in attribution depth — linking pseudonymous addresses to controlling entities and their off-chain footprint. Without it, jurisdictional red flags remain circumstantial; with it, the money trail becomes evidentiary.

Frequently Asked Questions

What defines a "low-risk" FATF jurisdiction?

The Financial Action Task Force (FATF) is the intergovernmental body that sets global anti-money-laundering standards. A "low-risk" jurisdiction is one not appearing on FATF's grey list (increased monitoring) or black list (call for action) — typically countries with mature AML regimes, active supervisors, and demonstrated technical compliance with the FATF Recommendations.

Why do illicit actors target exchanges in low-risk jurisdictions rather than obviously permissive ones?

Counterintuitively, low-risk jurisdictions offer laundering advantages precisely because their reputational cleanliness reduces downstream scrutiny. As the data cited above shows, Nominis's research finds illicit actors strongly favour exchanges in low-risk FATF jurisdictions — with the overwhelming majority of terror-linked transactions flowing to low-risk and increased-risk venues — because funds cleared through a well-regulated venue face fewer questions at the next hop.

Does using a licensed VASP protect my firm from exposure to illicit funds?

Licensing establishes a compliance baseline but does not immunize you against counterparty risk. Illicit flows routinely traverse licensed Virtual Asset Service Providers, which is why continuous Know Your Transaction (KYT) monitoring — ongoing analysis of blockchain activity, distinct from onboarding KYC — is essential alongside jurisdictional due diligence.

How does the FATF Travel Rule change the calculus for cross-border crypto transfers?

The Travel Rule requires VASPs to share originator and beneficiary information on transfers above defined thresholds, mirroring correspondent-banking obligations. It closes some cross-jurisdictional information gaps but is unevenly implemented worldwide, so illicit actors continue routing through corridors where Travel Rule enforcement lags.

What role do nested services play in jurisdictional arbitrage?

Nested services — brokers or exchanges operating on top of another platform's custody and liquidity — let bad actors piggyback on a reputable venue's infrastructure while hiding true ownership. In the Nominis forensic study referenced earlier, most of the no-KYC exchanges examined were found to route funds through nested services, spanning thousands of facilitating wallets and substantial annual volume.

How should an MLRO adjust risk scoring for counterparties in low-risk jurisdictions?

Treat jurisdiction as one input, not a conclusion. Weight on-chain behavioural signals — cross-chain hop patterns, exposure to mixers, nested-service indicators, and proximity to sanctioned wallets — alongside the counterparty's licensing status. In 2026, sophisticated laundering typologies increasingly cluster around clean-jurisdiction venues, so static geographic scoring alone will leave blind spots.

Ready to get started?

See how Nominis can help.

Book a demo