Financial Integrity Monitor

United States — Massachusetts US-MA

Domains (D1–D6)
5
Sources
9
Role actions
8
Horizon <90d
3
Jurisdiction profile
Largely Compliant (As Part Of Usa Federal Aml/Cft Framework; Not Fatf Grey/Black-Listed)Tier ARisk: StableMixed

Massachusetts operates under the federal BSA/AML framework (FinCEN, OFAC) with no independent state AML statute; state-level enforcement runs through the Attorney General's Office (consumer-protection/unfair-deceptive-practices statutes), the Securities Division of the Secretary of the Commonwealth, and the Division of Banks (money transmitter licensing).

MoreBoston is a major asset-management, trust, and private-banking hub, elevating professional-gatekeeper exposure.

Key deficiencies
  • No state-level beneficial ownership registry; Massachusetts LLC/corporate filings via the Secretary of the Commonwealth remain low-transparency, compounded by the federal CTA rollback
  • Crypto ATM/kiosk sector operated for years in Massachusetts with weak AML/KYC controls before state enforcement caught up
  • State money-transmitter/crypto oversight is exposed to federal preemption via OCC national trust-bank charters, mirroring the pattern documented in neighboring Maine
  • Limited direct public evidence of state banking regulator (Division of Banks) enforcement actions in the 18-month window, indicating a possible supervisory visibility gap
Recent developments (18m)
  • Massachusetts Attorney General Andrea Joy Campbell sued crypto ATM operator Bitcoin Depot in February 2026 alleging knowing facilitation of scams
  • Massachusetts AG's office secured restitution for cryptocurrency fraud victims (SpireBit case) using commercial blockchain tracing tools
  • FinCEN renewed Residential Real Estate Geographic Targeting Orders covering Massachusetts (Boston-area) counties through February 2026
  • Federal Corporate Transparency Act domestic beneficial-ownership reporting requirement was rescinded (March 2025), affecting Massachusetts-formed entities
  • Bitcoin Depot, subject of the Massachusetts suit, filed for bankruptcy and ceased ATM operations in May 2026
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The most consequential development this cycle sits at the intersection of sanctions architecture and digital-asset innovation: Iranian Revolutionary Guard Corps-linked facilitators have been assessed to be minting a proprietary stablecoin, USDZ, through OFAC-designated issuer Zedxion, to fund proxy operations, a mechanism reported to have moved billions of dollars in transactions since 2020 through layered financial structures. This sits alongside continuing conventional sanctions-architecture activity: OFAC published Russia-related designations on July 20, 2026 under Executive Order 14024 Section 11, naming entities including A T S Heavy Equipment and Pitersnab LLC, even as the GL 131H/132/134-series general-license amendments continue their rolling cadence around the temporary reopening of segments of the oil market. Architecture over incident: the designation cadence itself is a known, recurring compliance surface, but the emergence of state-adjacent proprietary stablecoin rails as a sanctions-evasion mechanism is the structural shift obliged institutions should register this cycle, since it moves value outside the correspondent-banking channels that existing sanctions screening architecture is built around.

Other Developments

The EU AML Package's three instruments continue divergent progression. The AMLR's beneficial-ownership provisions (Articles 11-13 and 15) and a package of AMLA technical standards fall due July 10, 2026, ahead of the AMLR's full direct-applicability date of July 10, 2027. Running in parallel, and less smoothly, the sixth Anti-Money Laundering Directive's register-access transposition provisions missed their July 10, 2025 deadline in roughly a third of Member States, prompting the European Commission to open infringement proceedings against eleven Member States; the Directive's general transposition deadline remains July 10, 2027. The Anti-Money Laundering Authority itself, operational since July 1, 2025, is required to publish twenty-three technical standards by July 10, 2026, ahead of assuming direct supervision of approximately forty high-risk cross-border institutions from January 2028 — a structural shift of the EU's AML supervisory perimeter from a purely national model toward a hybrid EU-level regime.

Cambodia's own regulator is signalling enabler-jurisdiction risk before any fresh FATF action. The National Bank of Cambodia's governor publicly warned that the country must avoid a third FATF grey-list placement tied to scam-centre and casino-linked laundering, and the central bank has launched a second national risk assessment. No fresh 2026 FATF primary statement on Cambodia specifically was identified this cycle, so this reads as a pre-designation warning phase rather than a confirmed listing event.

A separate enabler-jurisdiction risk remains standing rather than fresh. The Golden Triangle Special Economic Zone in Laos remains associated with cyber-enabled fraud and online gambling under the territorial control of Zhao Wei's transnational criminal organization; Zhao faced UK sanctions in 2023 for links to human trafficking and forced criminality in scam operations. This is assessed at low confidence and treated as continuing background structural risk rather than a new development this cycle.

Compliance technology supervision is shifting from tick-box to outcomes. SR 26-2, issued April 17, 2026 by the Federal Reserve, OCC, and FDIC, replaces the SR 11-7 model-risk-management framework, and FinCEN has proposed a two-pronged AML supervisory framework that judges programme design separately from implementation, reserves serious enforcement for material or systemic failures, and explicitly encourages the use of artificial intelligence in compliance programmes.

Cross-Monitor Connections

The IRGC's use of a proprietary, OFAC-designated stablecoin issuer to fund proxy operations is a direct node connecting this cycle's sanctions-architecture and crypto/digital-asset findings; it is also a conflict-finance-adjacent signal to the extent proxy-operation funding intersects with regional conflict financing, though this cycle's evidence base does not extend to a dedicated, independently-sourced conflict-finance development beyond that Iran nexus. Cambodia's casino-and-scam-centre laundering exposure and Laos's Golden Triangle SEZ risk both connect enabler-jurisdiction findings to the gambling and online-scam ecosystems that other monitors in this fleet track from different angles.

Outlook

Watch for the AMLA's publication of its twenty-three technical standards against the July 10, 2026 deadline, and for whether the Commission's infringement proceedings against the eleven Member States lagging on 6AMLD register-access transposition produce further enforcement movement ahead of the July 2027 general transposition deadline. On sanctions-evasion infrastructure, the trajectory to monitor is whether designation activity against stablecoin-based evasion mechanisms such as USDZ/Zedxion accelerates to match the pace at which such rails are reportedly moving value. Cambodia's self-identified grey-list risk is also one to watch for a possible FATF plenary decision in a coming cycle.

weekly_brief_draft · JID US-MA
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

Sanctions architecture targeting Russia continued its established rolling-amendment cadence this cycle, while a parallel and structurally more significant development emerged in Iran: sanctions-evasion infrastructure is beginning to route around, rather than through, the correspondent-banking rails that existing sanctions screening architecture is built to monitor. OFAC published Russia-related Designations Updates on July 20, 2026, naming entities including A T S Heavy Equipment and Pitersnab LLC under Executive Order 14024 Section 11, while the GL 131H/132/134-series of general licenses continues its rolling amendment cycle, including provisions addressing a temporary reopening of segments of the oil market. This is architecture functioning as designed: a layered general-license regime that permits calibrated market access alongside continuing designation activity, assessed at high confidence on the strength of a Tier-1 OFAC primary source.

The more consequential architectural signal is Iranian Revolutionary Guard Corps-linked facilitators reportedly minting a proprietary stablecoin, USDZ, through OFAC-designated issuer Zedxion, to fund proxy operations, with reported transaction volumes in the billions of dollars since 2020 routed through layered financial structures. This is assessed rather than confirmed, resting on a single Tier-4 secondary source with the primary FinCEN alert not retrieved this cycle, and the sanctions-evasion theory here is one of infrastructure substitution: rather than laundering funds through designated correspondent banks where screening architecture would eventually flag the activity, the proxy network mints its own settlement asset, sidestepping that monitoring layer entirely.

For obliged institutions, the compliance obligation attached to the Russia sanctions architecture this cycle remains squarely a screening obligation under Executive Order 14024, applicable across banks and cross-sector correspondent-banking relationships; the claim underlying this cycle's designation update explicitly flags correspondent-bank counterparties as the relevant customer typology. The Iran-linked stablecoin thread carries a different, though related, compliance texture: its customer typology is VASP-counterparty risk, meaning the relevant control point sits with crypto-asset operators and any bank maintaining a relationship with them, rather than with traditional correspondent banking alone. A bank whose sanctions screening architecture is built entirely around correspondent-banking rails and SDN-list matching may have no natural detection point for a proxy network settling in a proprietary stablecoin it does not already monitor.

Architecture-over-incident framing is warranted here rather than incident-specific alarm: neither the July 20 SDN designations nor the USDZ/Zedxion reporting is, on its own, an isolated enforcement event of primary significance. The more durable finding is that the layered general-license and designation machinery around Russia continues to operate as an evolving but recognisable architecture, while the Iran-linked stablecoin reporting, even at Assessed confidence on a single Tier-4 source, is an early signal of a structurally different evasion architecture that conventional correspondent-banking-centric screening was not designed to see.

Outlook

Watch for whether OFAC or FinCEN issue a dedicated primary-source advisory on proprietary-stablecoin sanctions-evasion mechanisms of the USDZ/Zedxion type, which would materially upgrade this cycle's Tier-4-sourced assessment to a corroborated finding. On the conventional side, the GL 134-series oil-market provisions and the pace of new EO 14024 Section 11 designations remain the baseline indicators of whether the layered general-license architecture is tightening or loosening around Russia in the coming cycle.

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

The EU AML Package's three constituent instruments continued their distinct, standing-architecture progression this cycle. The package comprises three legally separate instruments: the AML Regulation (AMLR, Regulation (EU) 2024/1624), which is directly applicable across Member States without national transposition; the sixth Anti-Money Laundering Directive (6AMLD), which each Member State must transpose into its own national law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts a defined slice of AML/CFT supervision from purely national authorities toward a hybrid EU-level regime. This tripartite architecture is durable structural backdrop, not a single-cycle development, and this cycle's beneficial-ownership signal is best read against it.

Within that backdrop, this cycle's concrete development is a milestone-and-friction pairing. On the AMLR side, the beneficial-ownership provisions at Articles 11 to 13 and 15, together with a package of AMLA technical standards, fall due July 10, 2026, ahead of the AMLR's full direct-applicability date of July 10, 2027, a Regulation-track timeline that, being directly applicable, does not depend on Member State transposition quality. On the 6AMLD side, by contrast, the Directive's register-access transposition provisions missed their July 10, 2025 deadline in roughly a third of Member States, prompting the European Commission to open infringement proceedings against eleven Member States; the Directive's general transposition deadline remains July 10, 2027. This is assessed rather than confirmed, resting on Tier-3 and Tier-4 secondary legal commentary without a direct eur-lex or Commission infringement-notice primary citation retrieved this cycle.

The AMLA itself, operational since July 1, 2025, must publish twenty-three technical standards by July 10, 2026, covering matters from risk-based supervision to CDD requirements for newly covered sectors, ahead of assuming direct supervision of approximately forty high-risk cross-border obliged entities beginning January 2028. The structural read is that the EU's beneficial-ownership and corporate-transparency regime is bifurcating in practice even as it unifies on paper: the AMLR's directly-applicable rules and AMLA's build-out are proceeding on schedule, while national 6AMLD transposition maturity is visibly uneven, evidenced by the Commission's infringement action against roughly a third of Member States.

The AMLR's beneficial-ownership articles specifically target fund-structure and corporate customer typologies, meaning asset managers, fund administrators, and corporate-service providers operating cross-border in the EEA are the obliged-entity population most directly affected by the Articles 11-13 and 15 timeline, independent of the separate AMLA technical-standards workstream that applies more broadly across the cross-sector obliged-entity population. The jurisdiction-level read corroborates this bifurcation: EEA-wide risk direction is assessed as stable overall, with enforcement-versus-enablement characterised as mixed and the underlying dynamic characterised as structural rather than episodic; per-Member-State transposition status was not fully established this cycle, which is itself a coverage gap worth flagging rather than a resolved uniform picture.

Outlook

Watch for whether AMLA meets its July 10, 2026 deadline to publish the full slate of twenty-three technical standards, and for whether the Commission's infringement proceedings against the eleven lagging Member States produce further escalation, a referral to the Court of Justice would be the next structural marker, ahead of the 2027 general transposition and full-application dates. The gap between the AMLR's uniform, directly-applicable rulebook and 6AMLD's uneven national transposition is the structural fault line most likely to generate next-cycle developments in this domain.

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

Two enabler-jurisdiction signals surfaced this cycle, one fresh and one standing. Cambodia's own central bank governor publicly warned that the country must avoid a third FATF grey-list placement, citing persistent reports linking Cambodia to online scam hubs and illegal gambling operations tied to laundering, undeclared cash movements, and cross-border payment abuse; the National Bank of Cambodia has launched a second national risk assessment in response. This is assessed rather than confirmed, and notably no fresh 2026 FATF primary statement on Cambodia specifically was identified this cycle; the signal is a jurisdiction acknowledging its own exposure ahead of any FATF action, which reads as a pre-designation warning phase rather than a confirmed listing event.

The second signal is standing background risk rather than a new development: the Golden Triangle Special Economic Zone in Laos remains associated with cyber-enabled fraud and online gambling under the control of Zhao Wei's transnational criminal organisation, who faced UK sanctions in 2023 for links to human trafficking and forced criminality in scam operations. This is assessed at low confidence on a single secondary source with no fresh 2026-cycle primary designation, and is treated here as continuing structural risk rather than an active development.

Outlook

Cambodia's self-identified risk is the item to watch most closely: a second national risk assessment plus public central-bank acknowledgment of scam-centre and casino-linked laundering exposure typically precedes, rather than follows, FATF plenary action, so a listing decision in a coming cycle would not be a surprise. The Golden Triangle SEZ risk in Laos remains unresolved background exposure absent a fresh triggering event.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto / Digital Assets / Financial Innovation

Continue reading

Two developments this cycle define the compliance perimeter for stablecoins and other digital-asset innovation. First, Treasury advanced formal rulemaking: FinCEN and OFAC issued a joint Notice of Proposed Rulemaking on April 8, 2026 to implement AML/CFT and sanctions provisions for GENIUS Act Permitted Payment Stablecoin Issuers, with final regulations required by July 18, 2026 and full enforcement beginning no later than January 18, 2027. This formally integrates PPSIs into the Bank Secrecy Act and OFAC compliance framework, treating them as financial institutions for AML/CFT purposes and creating a defined customer-due-diligence obligation with a VASP-counterparty typology lens. This is assessed rather than confirmed, corroborated by Federal Register primary docket references cited within Tier-3 law-firm analysis, but without a direct Federal Register primary citation independently retrieved this cycle.

Second, and at a materially larger scale, the ruble-backed stablecoin A7A5 facilitated $93.3 billion in transactions in ten months, reflecting a scale of digital-asset use to circumvent sanctions and facilitate cross-border trade that is assessed at high confidence on Tier-2 analytics-vendor data corroborated by EU Council sanctions-package context. Read together with the Iran-linked USDZ/Zedxion reporting surfaced elsewhere this cycle, the pattern is that state-adjacent stablecoin rails are now processing sanctions-evasion volume at a scale that exceeds prior typologies for this vector, arriving at the same moment the United States is building out its first dedicated AML/CFT and sanctions compliance perimeter for regulated payment stablecoin issuers. The asymmetry is notable: the GENIUS Act rulemaking targets permitted, US-regulated issuers, while the largest reported sanctions-circumvention volume this cycle runs through a ruble-backed stablecoin operating entirely outside that perimeter.

For affected firm types, the compliance burden falls primarily on crypto-asset operators and banks maintaining stablecoin-issuer relationships. The GENIUS Act's BSA-based CDD obligation for PPSIs means these issuers will need to stand up customer due diligence, sanctions screening, and reporting programmes on a timeline compressed to roughly nine months between the April NPRM and the July final-rule deadline, with full enforcement following six months later in January 2027, a rapid build-out schedule relative to the scale of the new obliged-entity population being brought inside the regulatory perimeter for the first time.

Outlook

Watch for the GENIUS Act PPSI final rule, due no later than July 18, 2026, and whether its AML/CFT and sanctions provisions extend any meaningful reach toward non-US-regulated stablecoins such as A7A5, or whether the compliance perimeter remains confined to permitted domestic issuers while the largest sanctions-evasion volume continues to run outside it. Full enforcement begins no later than January 18, 2027, giving obliged institutions a defined runway to build PPSI-specific compliance programmes.

D6 Compliance Technology & Active Defence

Compliance Technology & Active Defence

Continue reading

United States banking supervisors executed a structural pivot in AML supervisory philosophy this cycle. SR 26-2, issued April 17, 2026 by the Federal Reserve, OCC, and FDIC, replaces the SR 11-7 model-risk-management framework, and FinCEN has separately proposed a two-pronged AML supervisory framework that judges programme design separately from implementation, reserving serious enforcement action for material or systemic failures rather than for every technical gap, and explicitly encouraging institutions to adopt artificial intelligence within their compliance programmes. This is assessed rather than confirmed, corroborated across multiple Tier-4 secondary analyses of the underlying April 2026 Federal Register proposal, without a direct primary Federal Register citation independently retrieved this cycle.

The structural significance of this shift is that it moves US AML supervision away from a tick-box compliance-programme-adequacy standard and toward an effectiveness-and-outcomes standard, a change that directly enables rather than merely permits the use of AI-driven transaction-monitoring and screening tools that a stricter tick-box regime would have treated with more supervisory suspicion. Practitioner commentary corroborating this shift also flags a persisting enforcement-expectation gap: institutions and examiners do not yet share a common, tested understanding of what a material or systemic failure means in practice under the new two-pronged framework, which is itself a compliance-technology risk in the transition period even as the direction of travel is toward lighter-touch, effectiveness-based supervision.

The obligation reshaping here is classified as a governance obligation rather than a reporting or screening one, and it applies across banks and the broader cross-sector obliged-entity population that falls under Federal Reserve, OCC, and FDIC supervision, distinguishing it from the customer-due-diligence and screening obligations driving this cycle's sanctions and beneficial-ownership developments. For compliance-technology vendors and internal build teams alike, the practical effect of a governance-standard shift of this kind is to lower the supervisory friction associated with adopting new detection technology, provided the institution can demonstrate sound programme design; the harder question, per the persisting enforcement-expectation gap noted above, is what evidentiary standard will satisfy examiners that a design is in fact sound.

Outlook

Watch for the first enforcement actions or examination findings issued under the SR 26-2 / effectiveness-based framework, which would begin to clarify where supervisors draw the line between a tolerated design gap and a material or systemic failure warranting serious enforcement. The explicit regulatory encouragement of AI adoption in compliance is also worth tracking for whether it is followed by supervisory guidance on model-risk expectations specific to AI-driven AML tools, given that SR 26-2 itself is a model-risk-management framework replacement.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
In Force Pending10 Jul 2026 · ±half_year

AMLA Work Programme / build-out (RTS/ITS package)

AMLA stands up in Frankfurt and publishes its first work programme and supervisory methodology; by 10 July 2026 AMLA must publish 23 technical standards covering risk-based supervision to CDD requirements for newly covered sectors.
Adopted10 Jul 2027 · ±year

AMLR / 6AMLD application date

The single AML rulebook (AMLR) becomes directly applicable and 6AMLD transposition deadlines bite across Member States.
source not collected
Adopted1 Jan 2028 · ±multi_year

AMLA direct supervision of selected obliged entities

AMLA begins direct supervision of a first cohort of approximately 40 high-risk cross-border obliged entities, shifting supervisory perimeter from purely national authorities to a hybrid EU-level regime.
source not collected
3 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

GENIUS Act stablecoin AML/CFT rulemaking and a CJNG fuel-smuggling TBML alert both create new SAR-relevant exposure this cycle.

The GENIUS Act PPSI NPRM brings a new class of stablecoin issuers into BSA-based CDD and reporting obligations ahead of a July 18, 2026 final rule, while FinCEN's supplemental alert on CJNG fuel-smuggling schemes flags a specific TBML typology relevant to SAR-filing decisions for banks and payment companies with trade-finance or fuel-sector exposure.

2 evidence refs
ComplianceAssessed

The EU AML Package and the US SR 26-2 supervisory shift both change the control-framework baseline obliged entities must meet.

AMLR beneficial-ownership provisions and AMLA technical standards fall due July 10, 2026, while 6AMLD transposition lags in roughly a third of Member States; separately, SR 26-2 replaces SR 11-7 and signals a US shift toward effectiveness-based AML supervision. Both are structural control-framework developments rather than single incidents.

4 evidence refs
LegalAssessed

Sanctions-nexus exposure widened this cycle via new OFAC designations, IRGC stablecoin evasion, and the scale of A7A5 sanctions circumvention.

New EO 14024 Section 11 designations, IRGC-linked use of the OFAC-designated Zedxion stablecoin issuer, and the $93.3 billion in ten-month A7A5 transaction volume all raise sanctions-nexus liability considerations for counterparties with Russia- or Iran-adjacent exposure, including through digital-asset rails rather than only traditional correspondent banking.

3 evidence refs
BoardAssessed

FATF grey-list movement and Cambodia's self-identified laundering risk are the strategic-level items this cycle.

The FATF grey list added Iraq and Bosnia and Herzegovina and removed Algeria and Namibia at its June 2026 plenary, holding at 22 jurisdictions under increased monitoring, while Cambodia's central bank has itself warned of a possible third grey-listing tied to scam-centre and casino-linked laundering, a reputational and market-access consideration for any institution with Cambodia-linked exposure.

2 evidence refs
CTOHigh

State-adjacent stablecoins (USDZ, A7A5) and the GENIUS Act PPSI rulemaking define this cycle's digital-asset architecture risk.

IRGC-linked minting of the proprietary USDZ stablecoin and the ruble-backed A7A5 stablecoin's $93.3 billion in ten-month transaction volume both illustrate sanctions-evasion rails operating outside correspondent-banking-centric screening architecture, while the GENIUS Act NPRM builds a formal BSA/OFAC compliance perimeter specifically for permitted, US-regulated stablecoin issuers.

3 evidence refs
RiskAssessed

Enabler-jurisdiction and state-adjacent stablecoin exposure both point to concentration risk building outside conventional monitoring.

Cambodia's self-identified scam-centre and casino-linked laundering risk, standing Golden Triangle SEZ exposure in Laos, and the scale of A7A5 sanctions-circumvention volume together indicate exposure concentration in enabler-jurisdiction and digital-asset vectors that sit outside traditional correspondent-banking risk models.

3 evidence refs
OperationsAssessed

New OFAC designations and the SR 26-2 supervisory shift both touch day-to-day screening and monitoring workflow.

The July 20, 2026 EO 14024 Section 11 designations require immediate screening-list updates, while SR 26-2's replacement of SR 11-7 and its encouragement of AI adoption signal a coming change in how transaction-monitoring model validation is expected to be documented.

2 evidence refs
AuditPossible

SR 26-2 and the AMLA/6AMLD governance build-out both create new control-testing scope.

The replacement of SR 11-7 by SR 26-2 changes the model-risk-management standard against which internal audit tests AML transaction-monitoring models, while the AMLA governance build-out and uneven 6AMLD transposition create a documentation gap worth flagging for cross-border obliged entities' audit programmes.

3 evidence refs
Decision lens
MLRO

GENIUS Act stablecoin AML/CFT rulemaking and a CJNG fuel-smuggling TBML alert both create new SAR-relevant exposure this cycle.

Compliance

The EU AML Package and the US SR 26-2 supervisory shift both change the control-framework baseline obliged entities must meet.

Legal

Sanctions-nexus exposure widened this cycle via new OFAC designations, IRGC stablecoin evasion, and the scale of A7A5 sanctions circumvention.

Board

FATF grey-list movement and Cambodia's self-identified laundering risk are the strategic-level items this cycle.

CTO

State-adjacent stablecoins (USDZ, A7A5) and the GENIUS Act PPSI rulemaking define this cycle's digital-asset architecture risk.

Risk

Enabler-jurisdiction and state-adjacent stablecoin exposure both point to concentration risk building outside conventional monitoring.

Operations

New OFAC designations and the SR 26-2 supervisory shift both touch day-to-day screening and monitoring workflow.

Audit

SR 26-2 and the AMLA/6AMLD governance build-out both create new control-testing scope.

Shared evidence: 6 refs
Scenario sketches

AMLA Direct-Supervision Transition and Cross-Border Evasion Adaptation

Illustrative scenario: as AMLA moves from a purely national-supervision backdrop toward direct supervision of roughly forty high-risk cross-border obliged entities from 2028, under the AMLA Regulation (Reg (EU) 2024/1620), alongside the directly-applicable AMLR (Reg (EU) 2024/1624) and per-state 6AMLD transposition, obliged entities and their counterparties could adapt by concentrating higher-risk cross-border activity in Member States where national transposition of 6AMLD register-access provisions remains slower, temporarily exploiting the timing gap between harmonised Level-1 rules and uneven national implementation before AMLA's direct-supervision perimeter widens. This is architecture-over-incident illustrative orientation, not a prediction or a description of observed behaviour.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitecturestableNo material change identified this cycle; OFAC EO 14024 Russia framework remains fully in force per secondary reporting.
T2 · EU AML Package / AMLAwatchAMLD6 BO-register transposition deadline (10 July 2026) and AMLA technical-standards obligations are the near-term milestone; full AMLR application remains 10 July 2027.
T3 · FATF Grey Listmaterial_changeJune 2026 Plenary: Iraq and Bosnia and Herzegovina added, Algeria and Namibia removed; grey list stands at 22 jurisdictions.
T4 · Beneficial-Ownership Register StatuswatchEU BO-register provisions (AMLD6 Art 11-13, 15) carry a 10 July 2026 transposition deadline; a third of member states reportedly missed the earlier 10 July 2025 register-access deadline, triggering Commission infringement proceedings.
T5 · Crypto / VASP Regulatory FrameworkstableNo material crypto-sanctions-evasion or DeFi-enforcement development surfaced this cycle beyond the standing GENIUS Act implementation track.
T6 · Sanctions Regime DivergencestableNo material EU/US/UK autonomous-listing divergence identified this cycle in the sources searched.
Registers

Enforcement actions

  • Massachusetts Attorney General Andrea Joy Campbell filed suit against Bitcoin Depot alleging the company knowingly facilitated crypto scams and used misleading sales tactics to overcharge Massachusetts consumers. 3 Feb 2026
  • The Massachusetts AG's office filed a civil lawsuit under the state's unfair and deceptive practices law against the SpireBit scam network, using commercial blockchain-tracing tools to identify over 700 addresses tied to the scheme and secure asset freezes. 5 Jul 2025
  • FinCEN renewed its Residential Real Estate Geographic Targeting Orders, requiring title insurers to report and maintain records on non-financed residential real estate purchases by legal entities and trusts above a purchase-price threshold across covered counties, including Massachusetts metropolitan areas. 9 Oct 2025
  • The Massachusetts AG's office institutionalized use of a commercial blockchain intelligence platform to trace and recover stolen crypto-fraud proceeds, coordinating with exchanges to freeze scammer-controlled wallets pending court judgment. 5 Jul 2025

Sanctions changes

  • OFAC designated UK-registered Iranian-linked cryptocurrency exchanges Zedcex and Zedxion on January 30, 2026 for processing transactions for the IRGC, marking the first sanctioning of exchanges specifically for activity within Iran's financial system — a listing that triggers immediate compliance/screening obligations for any Massachusetts-based or -exposed financial institution or crypto-exposed firm. 30 Jan 2026
  • OFAC settled with a US-person attorney/fiduciary for $1,092,000 for apparent Ukraine-/Russia-related sanctions violations arising from serving as trustee of a sanctioned Russian oligarch's family trust between 2018 and 2022, underscoring OFAC's broad definition of 'property interest' as applied to trust and corporate-services structures nationally, including Massachusetts' substantial trust-and-estate bar. 9 Dec 2025

Regulatory horizon (register)

  • FinCEN AML/CFT program reform rule comment period closes
  • Nationwide Residential Real Estate AML rule supersedes Boston-area GTOs
  • GENIUS Act stablecoin implementing regulations deadline
  • CLARITY Act market-structure legislation outcome

Active schemes

  • [HIGH] Crypto ATM cash-to-crypto scam laundering pipeline
  • Trust/fiduciary gatekeeper concealment of sanctioned persons' assets
  • [HIGH] Anonymous LLC/corporate-shell formation post-CTA rollback
Sources
  1. FinCEN (US Department of the Treasury)
  2. FATF
  3. OFAC (US Department of the Treasury)
  4. ICIJ
  5. TRM Labs
  6. FinCEN / OFAC (US Department of the Treasury)
  7. ICIJ
  8. Chainalysis
  9. Massachusetts Attorney General's Office
Coverage gaps
The federal rescission of Corporate Transparency Act domesti…
The federal rescission of Corporate Transparency Act domestic beneficial-ownership reporting (March 2025) removed the principal national transparency backstop for Massachusetts-formed LLCs and corporations, with no state-level substitute beneficial ownership registry in place.
A federal reinterpretation of banking rules is allowing cryp…
A federal reinterpretation of banking rules is allowing crypto firms to obtain slimmed-down national trust-bank charters that grant immunity from state regulator enforcement, a pattern documented in Maine and structurally applicable to Massachusetts' Division of Banks oversight of money transmitters and crypto firms.
Crypto ATM operators allegedly knew as early as 2021 that th…
Crypto ATM operators allegedly knew as early as 2021 that their Massachusetts kiosks facilitated money laundering 'at an extreme volume,' yet effective state enforcement action did not arrive until the AG's February 2026 lawsuit — a multi-year enforcement lag during which scam losses accumulated.
This baseline could not locate direct primary-source enforce…
This baseline could not locate direct primary-source enforcement orders or examination findings from the Massachusetts Division of Banks or Securities Division (Secretary of the Commonwealth) for the 18-month window, despite Massachusetts' significant asset-management/trust-sector footprint; coverage of state banking-regulator activity relies on secondary/investigative sourcing only.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.