Financial Integrity Monitor

United States — Iowa US-IA

Domains (D1–D6)
6
Sources
8
Role actions
8
Jurisdiction profile
Largely CompliantTier BRisk: IncreasingMixed

Iowa AML/CTF oversight is federally anchored: money transmitters/MSBs register with FinCEN and license under Iowa Code ch.

More533C via the Iowa Division of Banking; beneficial ownership transparency runs through the federal Corporate Transparency Act (now largely inoperative for domestic entities). Iowa layered a 2025 crypto-ATM consumer-protection statute atop this framework after aggressive Attorney General litigation against kiosk operators.

Key deficiencies
  • No independent Iowa beneficial-ownership registry; state relies entirely on the now-narrowed federal CTA/BOI regime
  • No dedicated state AML examination cadre for MSBs beyond licensing; supervisory depth depends on federal delegation
  • Crypto-ATM transaction caps enacted 2025 have not stopped elder-fraud volumes rising nationally
  • Limited independent Iowa-specific investigative/NGO coverage outside national outlets referencing Iowa AG actions
Recent developments (18m)
  • Iowa Attorney General sued Bitcoin Depot and CoinFlip (Feb. 26, 2025) alleging the majority of Iowa transactions on their kiosks were scam-related
  • Iowa enacted crypto-ATM consumer protection law (transaction/fee caps) effective summer 2025
  • FinCEN issued national CVC Kiosk Notice FIN-2025-NTC1 (Aug. 4, 2025) citing the Iowa enforcement action as a model
  • Federal CTA/BOI interim final rule (March 26, 2025) exempted domestic reporting companies — including Iowa-formed LLCs/corporations — from beneficial ownership reporting
  • Bitcoin Depot, defendant in the Iowa suit, filed for bankruptcy (May 2026) after multi-state regulatory pressure
  • FinCEN proposed sweeping AML/CFT program reform NPRM (April 2026) affecting all federally regulated Iowa financial institutions
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Iowa this cycle presents a structural paradox that the financial-integrity architecture-over-incident principle is built to surface: the same jurisdiction that produced a nationally cited enforcement model against crypto-ATM operators is simultaneously absorbing a federal beneficial-ownership rollback that widens corporate opacity for every Iowa-formed entity. The Iowa Attorney General announced consumer-fraud actions against Bitcoin Depot and CoinFlip on 26 February 2025, alleging that the majority of examined Iowa kiosk transactions were scam-related, and FinCEN cited these actions in its August 2025 national CVC Kiosk Notice as a template for red-flag supervisory expectations. Yet the enforcement architecture that made Iowa a reference point is already narrowing: Bitcoin Depot, the largest named defendant and formerly the largest North American kiosk operator, filed for Chapter 11 bankruptcy on 18 May 2026 and took its network of more than 9,000 kiosks offline, contracting Iowa-specific exposure even as the underlying elder-fraud typology persists nationally through remaining operators such as CoinFlip.

Running in parallel, and analytically the more consequential of the two developments, is the 26 March 2025 interim final rule that exempted all United States-formed entities, including Iowa LLCs and corporations, from FinCEN beneficial-ownership information reporting. Only foreign entities registering to do business in Iowa remain in scope. This is a structural reversal of gains credited to the 2021 Corporate Transparency Act, compounding gaps in timely beneficial-ownership access that the Financial Action Task Force had already flagged in its seventh Enhanced Follow-up Report of March 2024. A parallel and newly documented exposure vector, the DPRK IT-worker fraudulent-employment scheme, generated nearly 800 million dollars in 2024 through remote employment obtained under stolen identities, with nationwide targeting that plausibly reaches Iowa-based employers of contracted remote information-technology labour.

Other Developments

Federal beneficial-ownership retreat compounds a standing FATF finding. The exemption of domestic reporting companies from FinCEN reporting obligations directly undercuts the remediation the Financial Action Task Force had credited toward closing serious gaps in timely beneficial-ownership access under Recommendations 24 and 25, a trajectory the eighth Enhanced Follow-up Report, anticipated around 2027, will re-examine.

Farmland ownership opacity draws USDA and CFIUS attention. The United States Department of Agriculture is partnering with the Committee on Foreign Investment in the United States and state lawmakers to close gaps that allow entities linked to countries of concern to acquire American farmland through layered corporate ownership, an exposure amplified in Iowa dense agricultural land market by the same beneficial-ownership rollback described above.

AML program reform proposed even as an adviser rule is delayed. FinCEN issued an April 2026 Notice of Proposed Rulemaking that would require board approval, a risk-based four-pillar program framework, and a United States-based AML/CFT Officer for all federally regulated institutions, including those operating in Iowa, with the comment period closed 9 June 2026 and a final rule pending. At the same time, FinCEN postponed the effective date of the Investment Adviser AML Rule from 1 January 2026 to 1 January 2028, delaying a planned control uplift for registered investment advisers operating in or from Iowa.

A transaction cap addresses symptom, not architecture. Iowa own crypto-ATM consumer-protection statute, effective summer 2025 and cited by FinCEN as a national model, caps kiosk transaction and fee amounts, yet national fraud-complaint and loss data continued rising sharply afterward, indicating that point-of-transaction caps alone do not substitute for upstream AML and know-your-customer controls at kiosk operators and their liquidity providers.

State examination capacity remains structurally thin. Iowa money-services businesses register with FinCEN and license under Iowa Code chapter 533C through the Iowa Division of Banking, but the state maintains no dedicated AML examination cadre beyond registration and licensing, leaving supervisory depth dependent on federal delegation relative to the scale of money-services-business and crypto-ATM activity in the state.

Sanctions architecture shows both divergence and convergence. United States courts forced OFAC to delist the Tornado Cash mixing protocol in March 2025 after ruling that OFAC lacked authority to sanction an immutable smart contract, a judicial constraint not mirrored in European Union or United Kingdom frameworks. By contrast, the October 2025 designation of the Prince Group Transnational Criminal Organization and 146 associated targets, including Chen Zhi, was coordinated jointly by OFAC, FinCEN, and the United Kingdom Foreign, Commonwealth and Development Office, with OFSI concurrently sanctioning the related Byex Exchange, an unusually convergent instance against the more typical pattern of transatlantic sanctions-regime divergence.

A standing coordination channel persists. A Memorandum of Understanding between OFAC and the State of Iowa, likely operating through the Iowa Insurance Division, establishes a formal state-federal sanctions-coordination instrument, though no Iowa-specific dark-fleet, shadow-banking, or export-diversion enforcement action was identified in the eighteen-month research window.

Cross-Monitor Connections

The DPRK IT-worker fraudulent-employment scheme carries direct routing relevance beyond this monitor. Its state-directed character, in which North Korean operatives use stolen identities and United States-based laptop-farm facilitators to obtain remote employment before funnelling wages through overseas crypto over-the-counter facilitators back to weapons programs, is a proliferation-financing data point relevant to macro-level sanctions-effectiveness tracking, and separately constitutes a state-directed illicit-finance network relevant to monitoring of state-capture architecture. Both connections are logged this cycle at medium confidence pending fuller corroboration of the Iowa-specific employer nexus.

Outlook

Three forward-looking instruments will shape the next several cycles of Iowa exposure. The FinCEN AML/CFT Program Reform Notice of Proposed Rulemaking, with an estimated 2027 impact date, would reorganise program governance around board approval and a four-pillar risk-based structure for all federally regulated institutions operating in Iowa. The Investment Adviser AML Rule, now pushed to a 1 January 2028 effective date, leaves a two-year gap in dedicated federal AML program obligations for registered investment advisers. And the outcome of the Iowa Attorney General litigation against CoinFlip and Bitcoin Depot, expected around 2027, will help settle whether state Attorney General authority over crypto-ATM operator liability becomes a durable precedent, notwithstanding that the Bitcoin Depot bankruptcy has already partially mooted claims against that specific defendant. None of these are certainties; each remains at consultation, in-force-pending, or litigation stage respectively, and the underlying elder-fraud and beneficial-ownership-opacity typologies are structural enough that they are likely to persist regardless of how any single instrument resolves.

weekly_brief_draft · JID US-IA
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

Iowa entry into the sanctions-architecture domain this cycle is defined less by direct enforcement action than by exposure inference. OFAC designated six individuals and two entities, including a DPRK IT-management company, along with 21 crypto addresses, for facilitating a fraudulent remote-employment scheme that generated nearly 800 million dollars in 2024 for weapons programs. The scheme relies on stolen identities and United States-based laptop-farm facilitators to obtain remote information-technology employment with American companies nationwide. Iowa exposure is inferred from this nationwide targeting pattern rather than confirmed through an Iowa-specific case, and the finding should be read as a plausible but unconfirmed proliferation-financing vector for Iowa-based employers of contracted remote labour, consistent with the Possible-confidence framing applied to the jurisdiction-specific dimension of this scheme.

Structurally, this is a proliferation-financing exposure vector layered onto an ordinary corporate-employment relationship: an Iowa firm engaging remote IT contractors has no obvious reason to suspect a sanctions nexus, which is precisely the architecture-over-incident lesson. The wages obtained through this fraudulent employment are converted through overseas crypto over-the-counter facilitators based in China, Vietnam, Laos, and the United Arab Emirates before returning to fund DPRK weapons programs, evading sanctions while exposing host companies to malware and intellectual-property theft as a secondary harm. Multiple independent sources, including the OFAC primary designation together with commercial blockchain-forensics and financial-press corroboration, support this finding at High confidence for the scheme itself, even where the Iowa-specific employer nexus remains only assessed as plausible.

Standing alongside this newly documented exposure is the Memorandum of Understanding between OFAC and the State of Iowa, a formal state-federal sanctions-coordination instrument likely administered through the Iowa Insurance Division. This is a structural rather than episodic finding: it establishes an institutional channel for coordination but has not, in the eighteen-month research window, produced any Iowa-specific dark-fleet, shadow-banking, or export-diversion enforcement action. The absence of enforcement activity through an existing coordination channel is itself an analytically relevant data point under the enablement-as-signal principle, indicating either a genuine absence of qualifying activity in Iowa or a capacity gap in translating the coordination instrument into active casework, a distinction the current evidence base cannot resolve.

Seen together, these two findings describe a sanctions-architecture posture for Iowa that is more passive-exposure than active-enforcement in character. Iowa participates in the national sanctions-compliance infrastructure through the OFAC coordination channel and inherits the same federal sanctions obligations as any other United States jurisdiction, but the substantive development this cycle, the DPRK IT-worker designation, arrived through a national OFAC action rather than an Iowa-originated case. This positions Iowa as a target jurisdiction in the sanctions-evasion architecture rather than an enabler or an active enforcer, a role classification that should inform how remote-employment screening obligations are prioritised for Iowa-domiciled employers going forward.

Outlook

The near-term trajectory for this domain depends substantially on whether further OFAC designations or Treasury guidance specify Iowa-based employer instances within the DPRK IT-worker scheme, which would upgrade the current Possible-confidence jurisdictional inference to a confirmed exposure. Absent that, the domain is likely to remain structurally stable: the OFAC-Iowa coordination channel persists as an institutional fact, but no near-term regulatory horizon item specific to Iowa sanctions enforcement was identified this cycle. The broader federal sanctions-architecture picture, including the judicial constraint on DeFi-protocol designations and the coordinated Prince Group action logged under the crypto-assets domain, will continue to shape the environment in which any future Iowa-specific sanctions exposure would be assessed.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

This is the first interpretation cycle in which Iowa sanctions-architecture exposure has been documented in this record, and the baseline established here centres on two structurally distinct findings that together describe a jurisdiction positioned as a jurisdiction of exposure rather than a jurisdiction of active enforcement or enablement. The first and more consequential finding is the OFAC designation of six individuals and two entities, including a DPRK IT-management company, for facilitating a fraudulent remote-employment scheme that generated nearly 800 million dollars in 2024 for DPRK weapons programs. North Korean operatives, using stolen identities and United States-based laptop-farm facilitators, obtained remote information-technology employment with American companies nationwide, a targeting pattern broad enough to plausibly reach Iowa-based employers of contracted remote labour, though no Iowa-specific case has yet been confirmed. Wages obtained through this scheme are converted through overseas crypto over-the-counter facilitators in China, Vietnam, Laos, and the United Arab Emirates, evading sanctions while exposing host companies to malware and intellectual-property theft as a secondary harm.

The second finding, structural rather than episodic, is the standing Memorandum of Understanding between OFAC and the State of Iowa, likely administered through the Iowa Insurance Division, which establishes a formal state-federal sanctions-coordination channel. Notably, across the eighteen-month research window underlying this baseline, no Iowa-specific dark-fleet, shadow-banking, or export-diversion enforcement action has been identified despite this coordination instrument being in place. Read together, this describes a jurisdiction that inherits full federal sanctions obligations and participates in institutional coordination infrastructure, but whose substantive sanctions-relevant development this cycle arrived through a national OFAC action rather than Iowa-originated casework.

The analytical significance of this baseline lies in what it establishes about the limits of current evidence rather than in any confirmed Iowa-specific enforcement pattern. The DPRK IT-worker exposure is carried at Possible confidence specifically because the Iowa employer nexus is inferential, extrapolated from nationwide targeting rather than direct evidence, and this caveat should persist across future cycles until either a confirmed Iowa case emerges or the inference is formally downgraded. Similarly, the absence of enforcement activity through the OFAC-Iowa coordination channel should be tracked as a standing enablement-as-signal data point: either a genuine absence of qualifying Iowa-specific sanctions-evasion activity, or an unresolved capacity question about how effectively the coordination instrument translates into active investigative work at the state level.

Going forward, this domain baseline should be read alongside the crypto-assets domain finding on Prince Group and Tornado Cash, since both illustrate the same underlying federal sanctions-architecture within which any future Iowa-specific development would sit; the coordinated OFAC-FinCEN-OFSI action against Prince Group demonstrates that transatlantic convergence is achievable in specific cases, even against the backdrop of the judicial constraint that forced the Tornado Cash delisting. As subsequent cycles accumulate, the priority tracking items for this domain are: whether the DPRK IT-worker scheme produces a confirmed Iowa employer case; whether the OFAC-Iowa MOU produces any documented casework; and whether any Iowa-specific export-control or shadow-banking enforcement action emerges that would shift the domain trajectory from its current worsening-on-exposure, stable-on-enforcement mixed posture.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

For Iowa, a United States state rather than a European Union or European Economic Area jurisdiction, the directly relevant beneficial-ownership development this cycle is domestic and federal in origin: the 26 March 2025 interim final rule that exempted all United States-formed entities, including Iowa LLCs and corporations, from FinCEN beneficial-ownership information reporting obligations under the Corporate Transparency Act framework. Only foreign entities registering to do business in Iowa remain within scope. This is a structural rather than episodic finding under the architecture-over-incident principle: it restores a beneficial-ownership opacity gap in Iowa-formed vehicles that can be layered into shell or nominee ownership chains, reversing gains the 2021 Corporate Transparency Act had been credited with delivering.

A second, related exposure compounds this gap in an Iowa-specific sector. The United States Department of Agriculture is partnering with the Committee on Foreign Investment in the United States and state lawmakers to close gaps allowing entities linked to countries of concern to acquire United States farmland through layered corporate ownership. Iowa dense agricultural land market and limited state-level foreign-ownership disclosure regime create an exposure that the federal beneficial-ownership rollback directly amplifies, since the domestic entities used to structure such acquisitions are now themselves outside FinCEN reporting scope. This second finding is carried at Assessed rather than High confidence, reflecting single-source Bloomberg reporting without independent corroboration in the current evidence base.

Globally, the European Union AML Package sets the structural direction against which beneficial-ownership regimes elsewhere are increasingly measured, and it is worth stating as durable backdrop even though Iowa sits outside its direct perimeter. The package comprises three distinct instruments: the AML Regulation, or AMLR (Regulation (EU) 2024/1624), which is directly applicable across Member States without national transposition; the sixth AML Directive, or 6AMLD, which each Member State transposes into domestic law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority. AMLA supervision shifts the European architecture from a purely national model toward a hybrid regime in which AMLA will directly supervise a defined population of high-risk cross-border obliged entities while indirectly overseeing the remainder through coordination with national supervisors. Iowa is a United States state, not an EEA Member State, so 6AMLD transposition tracking and AMLA direct-supervision selection do not apply to this jurisdiction; the comparison is offered as backdrop against which the divergent trajectory of the United States beneficial-ownership regime, contracting even as the EU regime consolidates supervisory reach, can be read.

The Financial Action Task Force seventh Enhanced Follow-up Report, published in March 2024, had already identified serious gaps in timely beneficial-ownership access for the United States under Recommendations 24 and 25. The March 2025 rollback removes a remediation step FATF had credited toward closing those gaps, meaning the eighth Enhanced Follow-up Report, anticipated around 2027, will need to assess a beneficial-ownership environment that has moved backward rather than forward since the last review, specifically for Iowa-formed entities among all United States-formed entities nationwide.

Outlook

The defining question for this domain over coming cycles is whether Iowa, or any United States state, moves to establish an independent state-level beneficial-ownership disclosure mechanism to partially offset the federal rollback, a development not indicated in any regulatory horizon item identified this cycle. Absent such a state-level response, the structural opacity gap for Iowa-formed entities is likely to persist until the federal rule is revisited, and the farmland-ownership exposure compounding it will remain dependent on USDA-CFIUS coordination outcomes not yet resolved. The FATF eighth Enhanced Follow-up Report, expected around 2027, is the most concrete forward marker against which this trajectory will next be formally assessed.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

This baseline establishes Iowa position in the beneficial-ownership and corporate-transparency domain as one of the more clearly worsening structural trajectories in the current record, anchored in a federal rule change with direct and immediate effect on every Iowa-formed entity. The 26 March 2025 interim final rule exempted all United States-formed domestic reporting companies, including Iowa LLCs and corporations, from FinCEN beneficial-ownership information reporting requirements under the Corporate Transparency Act, leaving only foreign entities registering to do business in Iowa within scope. This reverses transparency gains the 2021 Corporate Transparency Act had been credited with delivering and restores a structural opacity gap into which shell or nominee ownership chains can be layered without federal visibility.

A second and Iowa-specific exposure compounds this federal gap: USDA, working with CFIUS and state lawmakers, is attempting to close routes by which entities linked to countries of concern acquire United States farmland through layered corporate ownership, an exposure this baseline treats as Assessed confidence given single-source reporting, but one made structurally more difficult to close precisely because the domestic corporate vehicles used in such transactions are now outside FinCEN beneficial-ownership reporting scope. Iowa dense agricultural land market makes this a jurisdiction of particular relevance for any future farmland-ownership transparency initiative.

As standing context against which this Iowa-specific trajectory should be read, the European Union AML Package continues to establish the global direction of beneficial-ownership regulatory travel, even though it has no direct jurisdictional bearing on Iowa. The package rests on three distinct instruments: the directly applicable AML Regulation (Regulation (EU) 2024/1624); the sixth AML Directive requiring Member State transposition; and the AMLA Regulation (Regulation (EU) 2024/1620) establishing the Anti-Money Laundering Authority, which is progressively shifting European supervision from a purely national model toward a hybrid regime combining direct AMLA supervision of high-risk cross-border obliged entities with indirect oversight of the remainder. The contrast between a European architecture consolidating supervisory reach and a United States architecture contracting beneficial-ownership visibility for domestic entities is the central structural juxtaposition this domain baseline establishes, and it is a contrast likely to persist across future cycles absent a reversal of either trajectory.

The Financial Action Task Force seventh Enhanced Follow-up Report of March 2024 had flagged serious gaps in timely beneficial-ownership access for the United States under Recommendations 24 and 25; the March 2025 rollback removes a remediation step credited toward closing those gaps. This means the anticipated eighth Enhanced Follow-up Report, expected around 2027, becomes the key forward marker for this domain: it will need to assess a United States beneficial-ownership environment, and by extension an Iowa beneficial-ownership environment, that has moved backward since the prior review rather than forward. Future cycles should track whether any state-level beneficial-ownership disclosure mechanism emerges to partially offset the federal contraction, whether the USDA-CFIUS farmland initiative produces concrete Iowa-relevant outcomes, and whether the eighth FATF Enhanced Follow-up Report formally documents the regression this baseline has identified.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The defining finding for Iowa in this domain is a capacity deficit rather than an active facilitation pattern. Iowa money-services businesses register with FinCEN and license under Iowa Code chapter 533C through the Iowa Division of Banking, but the state maintains no dedicated AML examination cadre beyond this registration and licensing function. Supervisory depth for Bank Secrecy Act compliance depends structurally on federal delegation rather than independent state capacity, a finding supported by a strong primary FinCEN source, the national MSB state-contact directory, at High confidence.

This capacity deficit is analytically significant precisely because of its interaction with the scale of relevant activity in Iowa. The crypto-ATM elder-fraud typology documented under the digital-assets domain this cycle, and the Iowa Attorney General enforcement response to it, both occurred against a backdrop in which the state itself has no independent proactive-detection mechanism for the money-services-business sector in which crypto-ATM operators are licensed. The Iowa Attorney General enforcement actions against Bitcoin Depot and CoinFlip were consumer-fraud actions brought under general state legal authority, not products of a dedicated AML examination function, which is a meaningful distinction for assessing whether the Iowa enforcement model is replicable elsewhere or contingent on unusually motivated prosecutorial attention rather than durable supervisory infrastructure.

The enablement-as-signal principle is directly relevant here: the absence of independent state AML examination capacity is not itself an enforcement failure, since federal delegation is a legitimate and common supervisory model across United States states, but it does mean that any facilitation occurring through Iowa-licensed money-services businesses that falls below the threshold of federal examination attention would likely go undetected at the state level. No evidence collected this cycle indicates that this gap has been actively exploited by professional facilitators operating through Iowa, but the structural precondition for such exploitation, thin independent supervisory capacity relative to sector scale, is documented and should be tracked.

This finding should also be read against the national FinCEN CVC Kiosk Notice, which cited Iowa enforcement action as a model despite Iowa lacking dedicated AML examination infrastructure specifically for the crypto-ATM sector that generated the underlying fraud pattern. This juxtaposition, a state praised nationally for consumer-protection-driven enforcement outcomes while lacking the supervisory architecture that would make such enforcement systematic rather than episodic, is itself an architecture-over-incident observation worth preserving in the standing record for this jurisdiction.

Outlook

No regulatory horizon item identified this cycle proposes to establish a dedicated Iowa state-level AML examination function, so this capacity gap is likely to persist as a structural feature of the jurisdiction absent a state legislative initiative not currently indicated in the evidence base. The relevant forward marker to track is whether any future multi-state or federal examination coordination effort, potentially connected to the FinCEN AML/CFT Program Reform Notice of Proposed Rulemaking logged under the compliance-technology domain, extends more systematic supervisory attention to Iowa-licensed money-services businesses, including crypto-ATM operators, without requiring the state itself to build independent examination capacity.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

This baseline establishes the enabler-jurisdiction posture of Iowa around a single, durable structural finding: the absence of dedicated state-level AML examination capacity for money-services businesses beyond registration and licensing functions administered through Iowa Code chapter 533C and the Iowa Division of Banking. Supervisory depth for Bank Secrecy Act compliance in Iowa depends on federal delegation rather than independent state examination infrastructure, a High-confidence finding supported by a strong primary FinCEN source. This is not, on its own, evidence of active facilitation of illicit finance through Iowa; federal delegation is a common and legitimate supervisory model across United States states. It is, however, a structural precondition worth tracking, because it means that any facilitation activity occurring below the threshold that triggers federal examination attention would likely go undetected at the state level.

The analytical value of this baseline lies in its interaction with the crypto-assets domain finding this same cycle. Iowa was cited nationally by FinCEN as a model jurisdiction for crypto-ATM enforcement following Attorney General actions against Bitcoin Depot and CoinFlip, yet those actions were brought under general consumer-fraud legal authority rather than a dedicated AML examination function. This juxtaposition, a jurisdiction praised for enforcement outcomes while lacking the supervisory architecture that would make such outcomes systematic rather contingent on prosecutorial initiative, is the central enabler-jurisdiction observation this baseline preserves. It raises an open and currently unresolved question: whether the Iowa enforcement model is replicable in other states lacking similarly motivated prosecutorial attention, or whether it depended on circumstances not tied to durable supervisory capacity.

No evidence collected across this baseline period indicates that professional facilitators have actively exploited the Iowa examination-capacity gap, and the domain trajectory is accordingly assessed as stable rather than worsening, in contrast to the clearly worsening trajectories documented in the beneficial-ownership and crypto-assets domains this same cycle. This distinction matters: Iowa is not documented this cycle as an active enabler jurisdiction in the sense of demonstrated facilitation, but as a jurisdiction whose supervisory architecture creates latent capacity for undetected facilitation, a distinction the enablement-as-signal principle requires this record to state explicitly rather than to elide.

Going forward, the priority tracking items for this domain are whether any future multi-state or federal examination coordination initiative, potentially connected to the FinCEN AML/CFT Program Reform Notice of Proposed Rulemaking currently at consultation stage, extends more systematic supervisory attention to Iowa-licensed money-services businesses without requiring independent state-level examination capacity; and whether any evidence emerges in future cycles of the capacity gap having been actively exploited, which would require reclassifying this jurisdiction trajectory from stable to worsening.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

No material Iowa-specific conflict-finance or extractive-industry finding was identified in this cycle evidence base. The standing conflict-finance coverage areas tracked more broadly by this monitor, including Russian war-economy financing, Sahel minerals, and DRC governance, are not directly implicated by the Iowa-specific sub-national evidence assembled this cycle. The only tangential connection is the farmland-ownership national-security exposure logged under the Beneficial Ownership and Corporate Transparency domain this cycle, in which entities linked to countries of concern may acquire Iowa agricultural land through layered corporate structures; this finding is properly a beneficial-ownership and national-security issue rather than a conflict-finance one, and it is cross-referenced here for completeness rather than treated as an independent D4 development. In accordance with the honesty-over-coverage principle, this domain sub-brief is intentionally thin: no invented findings are substituted for the absence of Iowa-specific conflict-finance material this cycle.

Outlook

This domain trajectory is assessed as stable, reflecting an absence of material Iowa-specific signal rather than a confirmed finding of no risk. Future cycles should continue to monitor for any Iowa-specific nexus to conflict-affected commodity supply chains or armed-group financing, including through the agricultural or extractive sectors, and should upgrade this domain sub-brief from limited-signal status only if such a nexus is directly evidenced.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity — Cumulative Analysis

Across the research window synthesised into this first baseline, no material Iowa-specific conflict-finance or extractive-industry integrity finding has been identified. This domain sits structurally apart from the other five domains in the current Iowa record: the standing conflict-finance coverage areas this monitor tracks at a broader level, including Russian war-economy financing, Sahel minerals, and DRC governance, have no direct Iowa-specific nexus documented in the evidence assembled to date. The single tangential connection identified, the farmland-ownership exposure in which entities linked to countries of concern may acquire Iowa agricultural land through layered corporate structures, is properly classified as a beneficial-ownership and national-security finding rather than an independent conflict-finance development, and is cross-referenced here rather than treated as substantive D4 signal.

Consistent with the honesty-over-coverage principle governing this record, this cumulative entry remains intentionally limited rather than padded with speculative content. The absence of signal is itself the finding: Iowa, as a sub-national United States jurisdiction with a large agricultural economy but no documented extractive-industry or conflict-adjacent commodity exposure in the current evidence base, does not present a conflict-finance profile comparable to jurisdictions more directly implicated in this monitor standing coverage. This should not be read as an assurance of zero risk, only as an accurate reflection of the evidence collected to date.

Future cycles should test this limited-signal status against any emerging evidence of Iowa-specific supply-chain exposure to conflict-affected commodities, any agricultural-sector nexus to sanctioned or conflict-adjacent entities beyond the farmland-ownership finding already logged under the beneficial-ownership domain, and any extractive-industry integrity question that may arise from Iowa role in broader United States agricultural or mineral supply chains. Absent such evidence, this domain trajectory should remain assessed as stable with limited signal.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

Iowa own regulatory and enforcement environment for digital assets is the lead story in this domain, not the global crypto-asset regulatory backdrop. The Iowa Attorney General announced consumer-fraud lawsuits against Bitcoin Depot and CoinFlip on 26 February 2025, alleging that a majority of examined Iowa kiosk transactions involving Bitcoin Depot, and roughly ninety percent involving CoinFlip, were scam-related, with all of the top twenty Iowa CoinFlip users identified as scam victims. CoinFlip disputed these allegations in an April 2026 court filing, and the exact court-filing date for both actions, as distinct from the public announcement date, remains an open item in the current evidence base. These Iowa-originated actions were cited by FinCEN in its August 2025 national CVC Kiosk Notice as evidence of the scale of kiosk-enabled fraud, making Iowa a genuine national reference point for crypto-ATM AML red-flag expectations rather than a passive recipient of federal guidance.

The most significant structural development since that enforcement wave is the narrowing of Iowa-specific kiosk exposure: Bitcoin Depot, the largest named defendant, filed for Chapter 11 bankruptcy on 18 May 2026 and took its national network of more than 9,000 kiosks offline. This is a market-structure outcome traceable in part to sustained multi-state regulatory pressure in which Iowa was an early mover, and it materially contracts the Iowa-specific footprint of the underlying scheme even as the elder-fraud typology persists nationally through remaining operators such as CoinFlip. Iowa own 2025 consumer-protection statute, which caps crypto-ATM kiosk transaction and fee amounts and was cited by FinCEN as a national model, represents a proactive state-level regulatory layer, though national fraud-complaint and loss data continued rising sharply after its enactment, indicating that transaction-cap regulation addresses symptom rather than the underlying AML and know-your-customer architecture at kiosk operators and their upstream liquidity providers.

A separate but connected Iowa-relevant digital-asset exposure is the DPRK IT-worker wage-conversion channel: wages obtained by DPRK IT operatives through fraudulent remote employment, potentially including Iowa-based employers, are converted through overseas crypto over-the-counter facilitators in China, Vietnam, Laos, and the United Arab Emirates, evading sanctions while exposing host companies to malware and intellectual-property theft. As global backdrop rather than the Iowa-specific lead, two federal developments illustrate the broader United States digital-asset sanctions environment within which Iowa exposure sits: the March 2025 judicial delisting of the Tornado Cash mixing protocol, after a United States court ruled OFAC lacked authority to sanction an immutable smart contract, a constraint not mirrored in European Union or United Kingdom frameworks; and the October 2025 coordinated OFAC-FinCEN-OFSI designation of the Prince Group Transnational Criminal Organization and the related Byex Exchange, illustrating that United States-United Kingdom sanctions convergence on crypto-enabled fraud networks is achievable in specific cases.

Outlook

The litigation outcome for the ongoing CoinFlip suit, expected around 2027, will be the most concrete near-term marker for this domain, given that the Bitcoin Depot claims have already been partially mooted by that operator bankruptcy. The broader question this domain must continue to track is whether the underlying elder-fraud typology migrates cleanly to remaining and future kiosk operators as Bitcoin Depot exits the market, and whether Iowa transaction-cap model is adopted or superseded by more AML-architecture-focused state or federal measures, including the FinCEN AML/CFT Program Reform Notice of Proposed Rulemaking logged under the compliance-technology domain this cycle.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

This first baseline for Iowa in the digital-assets domain centres on a genuinely Iowa-originated enforcement story rather than a passive application of national or global crypto-asset regulatory developments. The Iowa Attorney General lawsuits against Bitcoin Depot and CoinFlip, announced 26 February 2025, alleged that a majority of examined Iowa kiosk transactions involving Bitcoin Depot, and roughly ninety percent involving CoinFlip, were scam-related, with every one of the top twenty Iowa CoinFlip users identified as a scam victim. CoinFlip disputed these allegations in an April 2026 court filing. FinCEN subsequently cited these Iowa-originated actions in its August 2025 national CVC Kiosk Notice as evidence of the scale of kiosk-enabled elder fraud, establishing Iowa as a genuine national reference point for crypto-ATM AML red-flag expectations, a rare instance of a sub-national enforcement record shaping federal supervisory guidance.

The most consequential development to have unfolded since that initial enforcement wave is structural rather than episodic: Bitcoin Depot, the largest named defendant and formerly the largest crypto-ATM operator in North America, filed for Chapter 11 bankruptcy on 18 May 2026 and took its network of over 9,000 kiosks offline nationally. This narrows Iowa-specific kiosk exposure materially, even though the underlying elder-fraud typology persists nationally through remaining operators such as CoinFlip, whose litigation with the Iowa Attorney General continues. Iowa own 2025 crypto-ATM transaction and fee-cap statute, cited nationally by FinCEN as a model, illustrates the limits of point-of-transaction regulation: national fraud-complaint and loss data continued rising sharply after its enactment, a pattern this baseline reads as evidence that transactional caps address symptom rather than the upstream AML and know-your-customer architecture at kiosk operators and their liquidity providers.

A second and structurally distinct Iowa-relevant exposure in this domain is the DPRK IT-worker wage-conversion channel, in which wages obtained through fraudulent remote employment, potentially including at Iowa-based employers, are laundered through overseas crypto over-the-counter facilitators in China, Vietnam, Laos, and the United Arab Emirates. This channel connects the digital-assets domain directly to the sanctions-architecture domain baseline established this same cycle. As global backdrop against which Iowa exposure should be read, two federal developments illustrate the wider United States digital-asset sanctions environment: the March 2025 judicial delisting of Tornado Cash, reflecting a United States-specific judicial constraint on DeFi-protocol sanctions not mirrored in European Union or United Kingdom frameworks, and the October 2025 coordinated OFAC-FinCEN-OFSI designation of the Prince Group Transnational Criminal Organization, an unusually convergent transatlantic sanctions action against crypto-enabled fraud infrastructure.

Going forward, the CoinFlip litigation outcome, expected around 2027, is the clearest forward marker for this domain, since the parallel Bitcoin Depot claims are already partially mooted by that operator market exit. Future cycles should track whether the elder-fraud typology migrates cleanly to remaining or new kiosk operators following Bitcoin Depot departure, whether Iowa transaction-cap model is adopted elsewhere or superseded by AML-architecture-focused reform, and whether the DPRK IT-worker wage-conversion channel produces any confirmed Iowa-specific employer case.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

Iowa federally regulated institutions face a genuinely mixed near-term compliance-technology posture this cycle, defined by one forward-moving and one backward-moving federal instrument arriving nearly simultaneously. FinCEN issued an April 2026 Notice of Proposed Rulemaking that would require board approval, a risk-based four-pillar program framework, and a United States-based AML/CFT Officer for all federally regulated financial institutions, including those operating in Iowa, with the comment period closed 9 June 2026 and a final rule pending. This is a structural reform proposal that would meaningfully change program-governance requirements away from the existing five-pillar framework, and Iowa-domiciled banks and payment companies would need to begin planning for board-level AML governance ahead of finalisation, even though the instrument remains at consultation stage and its final form is not yet settled.

Simultaneously, and moving in the opposite risk direction, FinCEN postponed the effective date of the Investment Adviser AML Rule from its originally planned 1 January 2026 date to 1 January 2028, a two-year extension of the period during which registered investment advisers and exempt reporting advisers operating in or from Iowa have no dedicated federal AML program requirement. This is a worsening risk-direction data point precisely because it delays a planned control uplift rather than merely maintaining an existing baseline, extending a known gap in adviser-sector AML program coverage for a further two years.

At the state level, Iowa own 2025 crypto-ATM consumer-protection statute, which caps kiosk transaction and fee amounts, represents an early proactive compliance-technology layer that most states have not adopted, and FinCEN cited it as a national model. However, the fact that national fraud-complaint and loss data continued rising sharply after this statute enactment is itself a compliance-technology finding: it demonstrates that transaction-level controls, however proactive, cannot substitute for upstream AML and know-your-customer architecture at the kiosk-operator and liquidity-provider level. This is a useful corrective for compliance functions considering point-of-transaction controls as a primary rather than supplementary defence layer.

Taken together, these three developments describe an Iowa compliance-technology environment in genuine tension: a sweeping federal program-governance reform moving toward finalisation, a federal adviser-sector control uplift being delayed, and a state-level consumer-protection measure demonstrating the limits of transactional controls alone. This mixed picture should inform how Iowa-domiciled institutions of different types, banks and payment companies facing the AML/CFT Program Reform NPRM, investment advisers facing a further two-year gap, and crypto-asset operators facing state transaction caps, each calibrate their compliance-technology investment priorities differently rather than treating this as a single uniform regulatory trajectory.

Outlook

The AML/CFT Program Reform NPRM final rule, with an estimated 2027 impact date, is the most consequential near-term compliance-technology development to track, given its board-approval and four-pillar governance requirements would apply across all federally regulated Iowa institutions. The Investment Adviser AML Rule 1 January 2028 effective date is a second, lower-uncertainty marker, given its quarter-level uncertainty band reflects an already-finalised postponement rather than a pending proposal. Whether Iowa or other states move to strengthen crypto-ATM AML architecture beyond transaction caps, in response to continued national fraud-loss growth despite existing caps, remains an open question not resolved by any regulatory horizon item identified this cycle.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

This first baseline for Iowa compliance-technology posture is defined by a genuine tension between advancing and receding federal control requirements, arriving within the same research window. FinCEN April 2026 Notice of Proposed Rulemaking proposes to fundamentally reform AML/CFT program requirements for all federally regulated financial institutions, including those operating in Iowa, introducing board approval, a risk-based four-pillar structure, and a mandatory United States-based AML/CFT Officer in place of the existing five-pillar framework. The comment period closed 9 June 2026 with a final rule pending, meaning Iowa-domiciled banks and payment companies now face a known but not yet finalised structural governance change to plan against.

Moving in the opposite direction, FinCEN postponement of the Investment Adviser AML Rule effective date from 1 January 2026 to 1 January 2028 extends by two full years the period during which registered investment advisers and exempt reporting advisers operating in or from Iowa carry no dedicated federal AML program obligation. This baseline treats this postponement as a worsening risk-direction data point rather than a neutral extension, since it delays a control uplift that had already been finalised and scheduled, rather than simply preserving a pre-existing gap.

At the state level, Iowa 2025 crypto-ATM transaction and fee-cap statute stands as an early example of proactive state compliance-technology innovation, cited nationally by FinCEN as a model. The persistence and continued sharp rise of national fraud-complaint and loss data after this statute enactment is a durable finding this baseline preserves: transaction-level caps, however well-intentioned and proactively adopted, do not substitute for upstream AML and know-your-customer architecture at the kiosk-operator and liquidity-provider level. This finding should inform how any future evaluation of Iowa consumer-protection model, including in the pending CoinFlip and Bitcoin Depot litigation, weighs the model effectiveness.

The cumulative picture this baseline establishes is one of genuine directional tension rather than uniform improvement or uniform decline: a sweeping governance reform advancing toward finalisation for banks and payment companies, an adviser-sector control uplift being pushed back by two years, and a state-level consumer-protection measure whose limits are becoming empirically clearer even as it is held up as a national model. Future cycles should track the AML/CFT Program Reform NPRM final-rule outcome, expected around 2027, as the single most consequential compliance-technology development for Iowa institutions, alongside the lower-uncertainty 1 January 2028 Investment Adviser AML Rule effective date, and should continue to monitor whether Iowa or other states move beyond transaction caps toward upstream AML-architecture reform for crypto-ATM operators.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
No dated horizon items this cycle. 4 items tracked without a confirmed date.
4 pending date · baseline fim-2026-07-05
Role action cards
MLROHigh

Iowa crypto-ATM enforcement and a newly documented DPRK IT-worker remote-employment scheme both surface AML and CPF screening exposure for institutions operating in or from Iowa this cycle.

The Iowa Attorney General crypto-ATM actions and the resulting FinCEN national kiosk guidance establish a documented red-flag reference set for suspicious-activity reporting triggers at crypto-asset operators. Separately, the OFAC DPRK IT-worker designation documents a proliferation-financing revenue channel that plausibly reaches remote-employment relationships involving Iowa-based employers, a screening exposure not confined to obviously high-risk sectors.

8 evidence refs
ComplianceHigh

A federal beneficial-ownership rollback and a pending AML program-governance reform, moving in opposite directions, both bear directly on Iowa-domiciled obliged entities.

The March 2025 CTA/BOI exemption removes a reporting obligation Iowa-formed entities previously carried, while the April 2026 AML/CFT Program Reform NPRM would add board-approval and four-pillar governance obligations still pending finalisation. The Investment Adviser AML Rule delay to 2028 and the persistent gap in independent Iowa state AML examination capacity both extend windows during which control-framework adequacy for certain Iowa-domiciled firm types remains untested.

8 evidence refs
LegalHigh

Sanctions-nexus and enforcement-trajectory questions concentrate around the Iowa crypto-ATM litigation, the DPRK IT-worker designation, and the Tornado Cash judicial ruling.

The Iowa Attorney General suits against Bitcoin Depot and CoinFlip, the Bitcoin Depot bankruptcy partially mooting those claims, the OFAC DPRK IT-worker and Prince Group designations, and the judicial constraint underlying the Tornado Cash delisting together define the current liability and enforcement-authority landscape for crypto-asset and sanctions-adjacent client instructions touching Iowa.

7 evidence refs
BoardHigh

Strategic-level regulatory change this cycle is defined by the tension between a federal transparency rollback and a proposed federal governance-reform requiring board-level AML approval.

The CTA/BOI rollback and the FATF beneficial-ownership gap it compounds represent a material reputational and regulatory-trajectory question, while the AML/CFT Program Reform NPRM would directly require board approval of AML/CFT programs if finalised. The Investment Adviser AML Rule delay to 2028 and the Bitcoin Depot market exit are both material to institutional risk appetite and sector-exposure planning at the governance level.

5 evidence refs
CTOHigh

Crypto-ATM kiosk infrastructure exposure and DPRK wage-conversion crypto laundering channels are the primary technical evasion vectors documented this cycle.

The Iowa kiosk enforcement wave, the Bitcoin Depot bankruptcy taking a 9,000-kiosk network offline, the DPRK IT-worker wage-conversion channel through overseas crypto OTC facilitators, and the Tornado Cash judicial delisting all bear on how crypto-asset infrastructure and platform architecture intersect with AML control design and sanctions-screening technology.

7 evidence refs
RiskHigh

Emerging exposure concentration this cycle spans beneficial-ownership opacity, proliferation-financing employment channels, and crypto-ATM operator market contraction.

The CTA/BOI rollback, the compounding FATF beneficial-ownership finding, the farmland-ownership exposure, the DPRK IT-worker scheme, and the Prince Group designation together represent a cross-typology risk concentration meriting escalation-level attention, with the Bitcoin Depot bankruptcy also a relevant model-risk data point for exposure concentrated in a single dominant operator.

6 evidence refs
OperationsHigh

Transaction-monitoring and screening-update implications concentrate around the FinCEN kiosk red-flag guidance and the DPRK IT-worker designation.

The FinCEN CVC Kiosk Notice establishes red-flag expectations directly relevant to transaction-monitoring rule updates for crypto-asset operators, the OFAC DPRK designation requires screening-list updates, the Investment Adviser AML Rule delay affects onboarding-workflow timing for adviser-sector clients, and Iowa transaction-cap statute demonstrates that operational caps alone have not reduced observed fraud-loss volume.

4 evidence refs
AuditHigh

Control-testing scope questions arise from the Iowa state examination-capacity gap and from two federal rule changes altering the AML program baseline against which controls are tested.

The absence of independent Iowa AML examination capacity for money-services businesses is a documented audit-trail and control-testing gap, the pending AML/CFT Program Reform NPRM would change the governance baseline controls are tested against, the Investment Adviser AML Rule delay extends a period during which no dedicated federal program exists to test, and Iowa transaction-cap statute effectiveness itself warrants control-adequacy testing given continued fraud-loss growth.

4 evidence refs
Decision lens
MLRO

Iowa crypto-ATM enforcement and a newly documented DPRK IT-worker remote-employment scheme both surface AML and CPF screening exposure for institutions operating in or from Iowa this cycle.

Compliance

A federal beneficial-ownership rollback and a pending AML program-governance reform, moving in opposite directions, both bear directly on Iowa-domiciled obliged entities.

Legal

Sanctions-nexus and enforcement-trajectory questions concentrate around the Iowa crypto-ATM litigation, the DPRK IT-worker designation, and the Tornado Cash judicial ruling.

Board

Strategic-level regulatory change this cycle is defined by the tension between a federal transparency rollback and a proposed federal governance-reform requiring board-level AML approval.

CTO

Crypto-ATM kiosk infrastructure exposure and DPRK wage-conversion crypto laundering channels are the primary technical evasion vectors documented this cycle.

Risk

Emerging exposure concentration this cycle spans beneficial-ownership opacity, proliferation-financing employment channels, and crypto-ATM operator market contraction.

Operations

Transaction-monitoring and screening-update implications concentrate around the FinCEN kiosk red-flag guidance and the DPRK IT-worker designation.

Audit

Control-testing scope questions arise from the Iowa state examination-capacity gap and from two federal rule changes altering the AML program baseline against which controls are tested.

Shared evidence: 15 refs
Scenario sketches

Illustrative AMLA direct-supervision transition and cross-border evasion adaptation

Illustrative orientation only: as the Anti-Money Laundering Authority builds out its direct-supervision perimeter for a defined population of high-risk cross-border obliged entities under the AMLA Regulation, alongside the directly applicable AML Regulation and per-Member-State sixth AML Directive transposition, evasion architecture could plausibly adapt by shifting activity toward obliged entities positioned just below the direct-supervision threshold, or toward jurisdictions and entity types where indirect national supervision remains the primary control layer. This is an illustrative structural sketch of how a hybrid EU-level and national supervisory regime might reshape the evasion landscape, not a description of any observed adaptation.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative post-bankruptcy consolidation of crypto-ATM elder-fraud typology

Illustrative orientation only: following the market exit of a dominant kiosk operator through bankruptcy, the underlying elder-fraud cash-to-crypto typology could plausibly consolidate around a smaller number of remaining operators, potentially with liquidity or franchise arrangements filling gaps left by the exited operator network. This is a structural illustration of how operator-level market exit interacts with a persistent typology, not an observed or predicted outcome for any named operator.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative expansion of remote-employment sanctions-evasion screening exposure

Illustrative orientation only: as remote-employment fraudulent-identity schemes tied to sanctioned state actors persist, exposure could plausibly extend beyond information-technology contracting into other remote-service sectors that similarly rely on limited in-person verification, broadening the population of employers, potentially including in agricultural and other Iowa-relevant sectors, who face latent sanctions-screening exposure without an obvious basis for suspicion. This is a structural illustration of exposure-vector expansion, not an observed development.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturematerial_changeUK 27-vessel shadow-fleet designation vs OFAC temporary oil-cargo GL amid Iran conflict.
T2 · EU AML Package / AMLAmaterial_changeAMLA direct-supervision data collection due 15 Aug 2026; provisional 40-entity list by end-Sept 2026; AMLR/AMLD6 apply from 10 July 2027.
T3 · FATF Grey Listmaterial_changeBosnia and Herzegovina and Iraq added; Algeria and Namibia removed at June 2026 Plenary; 22 jurisdictions remain under monitoring; blacklist unchanged (DPRK, Iran, Myanmar).
T4 · Beneficial-Ownership Register Statusmaterial_changeCTA domestic-entity BOI exemption remains in force, widening the shell-company opacity gap relative to the EU trajectory.
T5 · Crypto & Digital-Asset Integritymaterial_changeHuione Section 311 finding extended to H-Pay; MiCA full CASP enforcement approaches; sanctioned Russia-linked exchange Grinex suspends operations.
T6 · Sanctions Regime Divergencematerial_changeOFAC covers roughly a third of Russia's shadow fleet versus the EU's more comprehensive tanker list; UK's autonomous vessel-designation powers add a third divergent track.
Registers

Enforcement actions

  • Iowa AG filed suit alleging Bitcoin Depot's kiosks in the state were instruments of massive fraud, with an analysis of Iowa transactions between October 2021 and July 2024 suggesting more than half involved scams, costing Iowans over $20 million. 26 Feb 2025
  • Iowa AG sued CoinFlip alleging roughly 90% of transactions examined on its Iowa ATM network were scam-related and that all of its top 20 Iowa users were scam victims, calling the firm a 'willfully blind participant' in victimizing Iowans. 26 Feb 2025
  • FinCEN issued Notice FIN-2025-NTC1, a national advisory on illicit finance risks at crypto ATMs, explicitly citing the Iowa Attorney General's February 2025 lawsuits as evidence of the scale of kiosk-enabled fraud and setting AML/CFT red-flag expectations for financial institutions. 4 Aug 2025
  • OFAC designated facilitators of DPRK government-orchestrated IT worker fraud schemes that generated nearly $800 million in 2024 for DPRK weapons programs, including 21 cryptocurrency addresses; the scheme systematically targets US businesses nationwide, creating exposure for Iowa-based employers of contracted remote IT labor. 12 Mar 2026

Sanctions changes

  • OFAC designated six individuals and two entities, including Vietnam- and China-based currency converters and a DPRK IT-management company (Amnokgang Technology Development Company), for facilitating DPRK IT-worker fraud schemes funding WMD/ballistic missile programs, with 21 crypto addresses listed. 12 Mar 2026
  • US Treasury delisted the Tornado Cash mixer in March 2025, following a US court ruling that OFAC lacked authority to sanction the immutable smart-contract protocol, reversing the original 2022 designation. 1 Mar 2025
  • OFAC, jointly with FinCEN and in coordination with the UK's FCDO, designated the Prince Group Transnational Criminal Organization and 146 associated targets (including Chen Zhi) for operating massive 'pig butchering' scam and money-laundering operations — the same laundering-network typology into which US crypto-ATM (including Iowa) scam proceeds are shown to flow. 14 Oct 2025

Regulatory horizon (register)

  • Resolution of Iowa AG litigation vs. CoinFlip/Bitcoin Depot
  • FinCEN AML/CFT Program reform NPRM comment deadline
  • Investment Adviser AML Rule new effective date
  • US FATF 8th Enhanced Follow-up Report (BO access gaps)

Active schemes

  • [HIGH] Crypto-ATM elder-fraud cash-to-crypto laundering pipeline
  • [CRITICAL] DPRK IT-worker fraudulent-employment revenue scheme
  • [HIGH] Post-CTA-rollback shell-entity beneficial-ownership opacity
  • Foreign farmland-ownership opacity in Iowa's agricultural sector
Sources
  1. Financial Crimes Enforcement Network (FinCEN)
  2. Office of Foreign Assets Control (OFAC) / State of Iowa
  3. International Consortium of Investigative Journalists (ICIJ)
  4. Financial Action Task Force (FATF)
  5. Financial Crimes Enforcement Network (FinCEN)
  6. Chainalysis
  7. Bloomberg
  8. Bloomberg
Coverage gaps
Iowa has no independent state AML examination cadre for lice…
Iowa has no independent state AML examination cadre for licensed money-services businesses beyond registration/licensing under Iowa Code ch. 533C; supervisory depth for BSA compliance depends on federal delegation (FinCEN/federal banking agencies), leaving state-level supervisory capacity thin relative to the scale of MSB/crypto-ATM activity within the state.
The March 2025 federal CTA/BOI interim final rule exempted a…
The March 2025 federal CTA/BOI interim final rule exempted all US-formed entities, including Iowa LLCs and corporations, from beneficial ownership reporting to FinCEN, restoring a beneficial-ownership opacity gap that Iowa has no independent state-level registry to fill.
Despite Iowa's 2025 crypto-ATM transaction-cap and fee-cap s…
Despite Iowa's 2025 crypto-ATM transaction-cap and fee-cap statute, national FBI IC3 data show crypto-ATM fraud complaints and losses continuing to rise sharply (99% complaint increase in 2024, losses projected to exceed $380 million in 2025), indicating state-level transactional caps alone have not closed the underlying enforcement/detection gap.
Independent Iowa-specific investigative/NGO reporting (OCCRP…
Independent Iowa-specific investigative/NGO reporting (OCCRP, Global Witness, ICIJ standalone Iowa-focused pieces) is sparse; available Iowa-specific findings largely surface as secondary references within national crypto-ATM and CTA coverage rather than dedicated Iowa-focused investigations, and no direct Iowa.gov primary URL for the AG's press release was independently verified in this research pass.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.