Financial Integrity Monitor

United States — Ohio US-OH

Domains (D1–D6)
5
Sources
8
Role actions
8
Horizon <90d
3
Jurisdiction profile
Largely CompliantTier BRisk: IncreasingMixed

Ohio has no state-level AML/BO regime distinct from federal BSA/CTA framework; state financial institutions and MSBs are supervised by the Ohio Division of Financial Institutions alongside federal regulators (FinCEN, OCC, Fed, FDIC).

MoreFederal 2025 CTA rollback exempted Ohio-formed LLCs from BOI reporting, widening opacity around the state's large small-business/shell-formation base. Active federal prosecutorial engagement (USAO-NDOH/SDOH) on crypto fraud forfeitures partly offsets state-level regulatory gaps, especially around unregulated crypto ATM kiosks.

Key deficiencies
  • No Ohio state-level beneficial ownership registry; reliant on now-narrowed federal CTA regime exempting domestic reporting companies
  • No Ohio-specific crypto ATM/kiosk consumer-protection statute (transaction caps, fraud warnings, ID verification) despite documented elder-fraud exploitation via Ohio-linked kiosk operators
  • Regional bank HQ concentration (Fifth Third, KeyCorp, Huntington) creates correspondent-banking and BSA/AML supervisory complexity requiring sustained OCC/Fed/FinCEN coordination
Recent developments (18m)
  • March 2025: FinCEN interim final rule exempted all US-formed entities (including Ohio LLCs) and their beneficial owners from CTA BOI reporting, narrowing the federal transparency backstop for Ohio-registered shell entities
  • February 2025: USAO for the Northern District of Ohio filed an $8.2M USDT civil forfeiture complaint against a cross-border pig-butchering laundering network that victimized Cleveland-area residents
  • August 2025: FinCEN issued a first-of-its-kind Notice (FIN-2025-NTC1) on CVC kiosk-enabled scam and laundering typologies, directly responsive to patterns previously documented in Ohio-linked crypto ATM cases
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The defining development of this baseline cycle is a scope correction with structural consequences for Ohio beneficial-ownership transparency. An interim final rule issued by FinCEN, effective March 26, 2025, exempted all United States-formed entities nationwide, together with their US-person beneficial owners, from Corporate Transparency Act beneficial-ownership-information reporting obligations; only foreign entities registering to do business in US states now remain subject to federal disclosure (fim-2026-07-05-001). This is a national policy choice rather than an Ohio-specific carve-out, and an earlier characterization of this exemption as state-limited is corrected in this cycle. The correction matters because Ohio, unlike a majority of peer states, maintains no state-level beneficial-ownership registry; Ohio relies entirely on the now-narrowed federal backstop for beneficial-ownership visibility into entities formed within its borders (fim-2026-07-05-002).

Set against this, Ohio also carries above-average exposure in the crypto-asset channel: a crypto-ATM kiosk network associated with elder-targeted and romance-investment fraud operated in the state until its 2023 cessation, and no Ohio statute currently imposes the transaction limits or identity-verification requirements that eighteen or more peer states have adopted for kiosk operators (fim-2026-07-05-003, fim-2026-07-05-004). Layered onto both threads is the Section 311 special measure severing Huione Group, the Cambodia-based conglomerate at the center of a documented pig-butchering laundering architecture, from the US financial system, with direct correspondent-banking consequences for the super-regional banks headquartered in Ohio (fim-2026-07-05-009). A parallel federal rulemaking track, the joint FinCEN and OFAC implementing rule for GENIUS Act stablecoin AML and sanctions obligations, is expected to finalize ahead of the January 2027 statutory deadline and directly affects Ohio-headquartered banks exploring stablecoin issuance or custody (fim-2026-07-05-012).

Other Developments

Iran sanctions posture reaffirmed. National Security Presidential Memorandum-2, issued February 4, 2025, reaffirmed blocked-property status for Iranian financial institutions designated under Executive Order 13599 and reiterated correspondent-account prohibitions binding on all US financial institutions, a continuing architecture rather than a new designation (fim-2026-07-05-010).

Sanctions-list divergence creates correspondent friction. EU and UK sanctions regimes have pursued parallel but non-identical designation timing and scope relative to OFAC and FinCEN action against the Prince Group and Huione-linked network, a divergence functioning as friction for Ohio-headquartered multinational banks reconciling three lists rather than merely an administrative inconvenience (fim-2026-07-05-011).

FinCEN sharpens kiosk-scam supervisory expectations. Notice FIN-2025-NTC1, issued August 4, 2025, details tech-support, bank-imposter, and elder-targeted kiosk scam typologies and raises Bank Secrecy Act reporting and red-flag expectations for institutions banking kiosk operators nationwide, including deployments in Ohio (fim-2026-07-05-007).

Interagency strike force targets scam-compound infrastructure. A coordinated DOJ Scam Center Strike Force action with OFAC and the State Department, announced April 23, 2026, targeted Southeast Asian scam-compound financial infrastructure matching the typology identified in the Northern District of Ohio pig-butchering case, though this data point rests on a single lower-tier source this cycle and has not been independently corroborated by a stronger source (fim-2026-07-05-008).

Civil forfeiture evidences the laundering architecture. The Office of the United States Attorney for the Northern District of Ohio and the FBI filed a civil forfeiture complaint on February 27, 2025 against 8.2 million dollars in USDT traced through DeFi platforms, cross-chain swaps, and unhosted wallets to Southeast Asian scam-compound operators; the individual forfeiture is the data point, the layering pathway is the structural finding (fim-2026-07-05-005, fim-2026-07-05-006).

Ohio bank concentration compounds supervisory complexity. Fifth Third, KeyCorp, and Huntington, all headquartered in Ohio, concentrate correspondent-banking and Bank Secrecy Act supervisory exposure requiring sustained coordination among the OCC, the Federal Reserve, and FinCEN not present in most other states (fim-2026-07-05-017).

State-level enforcement visibility remains thin. Public, systematically searchable records of Ohio Division of Financial Institutions money-services-business enforcement activity, distinct from federal FinCEN and DOJ action, remain limited, constraining independent assessment of whether the state supervisory layer meaningfully supplements federal oversight (fim-2026-07-05-015).

United States retains clean FATF standing. The February 13, 2026 FATF plenary added Kuwait and Papua New Guinea to increased monitoring while leaving Iran, North Korea, and Burma unchanged on the call-for-action list; the United States, and by extension Ohio, remains outside both lists, though a possible subsequent mid-2026 plenary update has not been independently verified this cycle (fim-2026-07-05-016).

Cross-Monitor Connections

Two cross-monitor routings apply this cycle. The pig-butchering laundering architecture identified in the Northern District of Ohio forfeiture action routes proceeds to Southeast Asian scam-compound operators reported to be intertwined with forced-labor trafficking infrastructure in Cambodia and Myanmar, a medium-strength flag to the conflict-finance monitor given the human-exploitation dimension underlying the financial layering (fim-2026-07-05-005, fim-2026-07-05-008). Separately, the continued Iran maximum-pressure sanctions posture under NSPM-2 and the Section 311 special measure against Huione Group both register as low-strength but relevant data points for macro-variable sanctions tracking, with the documented EU/UK divergence on Prince Group and Huione designations adding a regime-friction dimension to that read (fim-2026-07-05-009, fim-2026-07-05-010, fim-2026-07-05-011). Neither flag rises to a state-capture reading for Ohio itself; Ohio functions in this cycle as an enabler and target jurisdiction for these architectures rather than as a locus of state-directed capture.

Outlook

The near-term trajectory for Ohio financial-integrity exposure is best read as mixed-to-deteriorating. On the compliance-technology axis, the joint FinCEN and OFAC GENIUS Act stablecoin rule is expected to finalize within roughly six months and would tighten AML and sanctions-compliance obligations for Ohio-headquartered banks exploring stablecoin issuance (fim-2026-07-05-012). On the market-structure axis, the CLARITY Act digital-asset legislation, advanced by the Senate Banking Committee in May 2026 after contentious markup, faces uncertain passage before the November 2026 midterms; failure would risk a multi-year regulatory delay for the market-structure rules bearing on Ohio-based exchanges and crypto-ATM operators (fim-2026-07-05-013). At the state level, the absence of any filed Ohio crypto-kiosk consumer-protection bill, despite the trend among eighteen or more peer states, remains a live but unconfirmed legislative-pressure signal rather than a scheduled development (fim-2026-07-05-014). The state-level beneficial-ownership gap and the thin visibility into Ohio Division of Financial Institutions enforcement activity are structural rather than episodic conditions and are unlikely to resolve absent new state legislation.

weekly_brief_draft · JID US-OH
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

Ohio carries no independent sanctions-designation authority of its own, but the correspondent-banking exposure of its super-regional banking sector places the state squarely inside the current cycle of federal sanctions-architecture activity. The Section 311 special measure against Huione Group, effective October 14, 2025, severed the Cambodia-based conglomerate from the US financial system as a foreign financial institution of primary money-laundering concern (fim-2026-07-05-009). The designation is best read architecturally rather than as an isolated action: Huione Group has been documented as a crypto-scam-linked laundering network operating at a scale that required a systemic financial-system response, and the special measure requires Ohio-headquartered banks, including Fifth Third, KeyCorp, and Huntington, to apply enhanced correspondent-banking restrictions as a direct downstream consequence of the designation.

Running in parallel, National Security Presidential Memorandum-2, issued February 4, 2025, reaffirmed the blocked-property status of Iranian financial institutions designated under Executive Order 13599 and reiterated the correspondent-account prohibitions binding on all US financial institutions (fim-2026-07-05-010). This is a continuing maximum-pressure posture rather than a new designation event, and its significance for Ohio lies in the sustained compliance burden it places on the correspondent-banking desks of the same regional banks implicated in the Huione response.

The architectural picture is complicated by documented divergence between the OFAC and FinCEN designation track and the parallel EU and UK sanctions regimes, which have pursued designations against the Prince Group and Huione-linked network on different timing and with different scope (fim-2026-07-05-011). For a multinational bank headquartered in Ohio, this divergence is not a mere administrative inconvenience; it is itself an architectural friction point, since reconciling three non-identical lists against a single correspondent-banking relationship creates both compliance cost and, potentially, a residual gap that a sophisticated evasion network could exploit in the interval before all three regimes converge on the same designated entities.

Applying a three-level sanctions-architecture reading, the scheme level is the Huione Group crypto-scam laundering conglomerate itself; the architecture level is the guarantee-marketplace and cyber-enabled fraud infrastructure of which Huione formed a node, an infrastructure documented elsewhere as resilient to the removal of any single participant; and the strategic-consequence level is the correspondent-banking chokepoint through which the United States projects the Section 311 special measure into the global financial system, a chokepoint that Ohio-headquartered banks sit directly inside by virtue of their correspondent relationships (fim-2026-07-05-009). Analytically, this cluster of developments illustrates an architecture-over-incident principle: the special measure and the NSPM-2 reaffirmation are each significant less for the specific entities named than for what they reveal about the enforcement machinery available to the sanctions regime and the correspondent-banking chokepoints through which that machinery is transmitted into the domestic financial system. Ohio does not host any sanctioned entity directly; its exposure runs entirely through the correspondent-banking relationships of its three federally chartered super-regional banks, meaning any assessment of severity for Ohio specifically must be read through that transmission channel rather than through any Ohio-specific designation, of which none exists this cycle.

Set against this active designation picture, the United States retains a clean standing at the Financial Action Task Force. The February 13, 2026 plenary added Kuwait and Papua New Guinea to increased monitoring and left Iran, North Korea, and Burma unchanged on the call-for-action list, with the United States appearing on neither list (fim-2026-07-05-016). This clean status is a structural baseline fact for Ohio rather than a cycle development in itself, though it should be read alongside the acknowledged gap that a possible subsequent mid-2026 plenary outcome has not been independently verified this cycle.

Outlook

The sanctions-architecture picture bearing on Ohio is likely to remain active rather than resolve in the near term. The Section 311 special measure against Huione Group establishes a durable correspondent-banking restriction rather than a one-time action, meaning Ohio-headquartered banks face a sustained enhanced-due-diligence burden for the foreseeable future (fim-2026-07-05-009). The EU/UK divergence on Prince Group and Huione-linked designations is a structural condition of parallel-but-non-identical sanctions regimes rather than a transient gap expected to close quickly, and it should be tracked as a persistent friction point for correspondent-banking compliance rather than a one-off reconciliation task (fim-2026-07-05-011). The Iran maximum-pressure posture under NSPM-2 shows no signal of near-term relaxation (fim-2026-07-05-010). The clean FATF status is a favorable baseline condition, but the acknowledged gap around a possible subsequent mid-2026 plenary means this status should be re-verified in a subsequent cycle rather than assumed stable by default (fim-2026-07-05-016).

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

As of this first baseline cycle for Ohio, the sanctions-architecture picture is anchored by two active federal postures and one structural friction point. The Section 311 special measure severing Huione Group, the Cambodia-based conglomerate at the center of a documented pig-butchering laundering architecture, from the US financial system, effective October 14, 2025, is the dominant data point (fim-2026-07-05-009). It requires Ohio-headquartered super-regional banks, Fifth Third, KeyCorp, and Huntington, to apply enhanced correspondent-banking restrictions, a durable rather than transient compliance burden. Running alongside it, the continuing maximum-pressure posture toward Iran under National Security Presidential Memorandum-2 reaffirms blocked-property status for Iranian financial institutions designated under Executive Order 13599 and the correspondent-account prohibitions binding on all US financial institutions, a posture with no baseline signal of relaxation (fim-2026-07-05-010).

The structural friction point running through both threads is documented divergence between OFAC and FinCEN designation timing and the parallel EU and UK sanctions regimes on the Prince Group and Huione-linked network (fim-2026-07-05-011). For Ohio-headquartered multinational banks, reconciling three non-identical designation lists against a single correspondent-banking relationship is a persistent compliance cost and a potential residual gap exploitable by sophisticated evasion intermediaries in the window before convergence. None of Ohio exposure in this domain runs through direct in-state designation; it is entirely a function of the correspondent-banking relationships of the three super-regional banks headquartered in the state, and that transmission channel is the correct lens for assessing severity going forward.

Against this active-designation backdrop, the United States retains a clean standing at the Financial Action Task Force, with the February 13, 2026 plenary adding Kuwait and Papua New Guinea to increased monitoring while leaving Iran, North Korea, and Burma unchanged on the call-for-action list (fim-2026-07-05-016). This is a favorable structural baseline rather than a cycle-specific development, though a possible subsequent mid-2026 plenary outcome remains unverified and should be revisited.

Outlook

Going forward, this domain should be tracked along three lines established in this baseline: the durability of the Huione Group correspondent-banking restriction and its effect on Ohio bank enhanced-due-diligence programs; the persistence or narrowing of EU/UK/US designation-list divergence on the Prince Group and Huione network; and confirmation of continued clean FATF standing for the United States against any subsequent 2026 plenary outcome. None of these three lines shows signal of near-term resolution as of this baseline cycle.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

For Ohio specifically, the corporate-transparency picture this cycle turns on a single but consequential federal scope correction rather than any state-level reform. An interim final rule issued by FinCEN, effective March 26, 2025, exempted all United States-formed entities nationwide, and their US-person beneficial owners, from Corporate Transparency Act beneficial-ownership-information reporting; only foreign entities registering to do business in US states, Ohio included, remain subject to federal disclosure (fim-2026-07-05-001). This corrects an earlier mischaracterization of the exemption as Ohio-specific: the policy choice is national in scope, and its consequence for Ohio derives from the size of Ohio relative shell-formation base rather than from any distinct Ohio carve-out. Ohio permits rapid, low-friction LLC and corporation formation through the Secretary of State with no state-level beneficial-ownership disclosure requirement, leaving Ohio reliant entirely on the now-narrowed federal backstop for any visibility into who beneficially owns entities formed within its borders (fim-2026-07-05-002). This is a structural gap rather than an episodic one: it does not depend on any single enforcement failure but on the durable absence of a state-level registry layered onto a federal regime that has itself just narrowed.

Applying the enabler-jurisdiction filter, the relevant question for Ohio is not one of enforcement capacity being absent by incapacity, but of political choice: Ohio has for decades marketed itself as a low-friction formation state, and no bill is currently before the Ohio General Assembly to impose beneficial-ownership disclosure at company formation. The severity of this gap should be read as elevated precisely because it compounds with the newly narrowed federal backstop rather than existing against a still-broad federal disclosure baseline; the interaction of the two conditions, not either alone, constitutes the structural finding for this cycle (fim-2026-07-05-001, fim-2026-07-05-002). For Ohio-based and Ohio-facing financial institutions, the practical consequence of this scope narrowing falls most heavily on customer due-diligence programs built around an assumption of federal registry corroboration. Where compliance functions previously could cross-reference a beneficial-ownership filing against a customer declared ownership structure for domestic entities, that cross-reference is now unavailable for the large majority of US-formed corporate and fund-structure customers, leaving institutions more dependent on their own onboarding-stage verification for entities carrying corporate or politically-exposed-person risk typologies (fim-2026-07-05-001, fim-2026-07-05-002).

Globally, the European Union AML Package sets the structural direction for beneficial-ownership transparency architecture, though Ohio sits entirely outside its direct perimeter. The package comprises three distinct instruments: the directly applicable AML Regulation, known as the AMLR, under Regulation (EU) 2024/1624; the sixth AML Directive, transposed at the discretion of each EU member state; and the AMLA Regulation, Regulation (EU) 2024/1620, which establishes the Anti-Money Laundering Authority and shifts supervision of high-risk cross-border obliged entities from purely national authorities toward a hybrid direct-and-indirect EU-level supervisory regime. None of these instruments reaches Ohio directly, and no AMLA-related development altering Ohio domestic standing was identified this cycle; the architecture is noted here as durable global backdrop against which the narrower, US-specific beneficial-ownership picture for Ohio should be read, not as a development bearing directly on this jurisdiction.

Outlook

The beneficial-ownership trajectory for Ohio is best read as deteriorating rather than stable. The narrowed federal CTA regime removes the principal existing mechanism for domestic beneficial-ownership visibility, and no legislative signal currently indicates that Ohio intends to establish a state-level registry to backstop that narrowing. Absent new state legislation, the corporate-formation channel in Ohio is likely to remain structurally opaque to beneficial-ownership scrutiny beyond the residual federal disclosure obligation applicable only to foreign entities registering in the state (fim-2026-07-05-001, fim-2026-07-05-002). The EU AML Package trajectory, while not directly applicable to Ohio, continues to move toward operational AMLA supervision and should be monitored for any future US-EU reciprocal-recognition or correspondent-transparency implications relevant to Ohio-headquartered banks with EU-facing subsidiaries.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

The baseline state of beneficial-ownership transparency for Ohio, established in this first cycle, rests on the interaction of two conditions rather than either alone. First, an interim final rule issued by FinCEN, effective March 26, 2025, exempted all United States-formed entities nationwide, together with their US-person beneficial owners, from Corporate Transparency Act reporting obligations, leaving only foreign entities registering to do business in US states subject to federal disclosure (fim-2026-07-05-001). This is a national policy choice, not an Ohio-specific carve-out, correcting an earlier mischaracterization. Second, and independent of the federal scope change, Ohio has never maintained a state-level beneficial-ownership registry: rapid, low-friction LLC and corporation formation through the Secretary of State carries no disclosure requirement of its own (fim-2026-07-05-002). The compounding of these two conditions, rather than either in isolation, constitutes the structural finding for Ohio in this domain, and it is assessed as an elevated-severity, structural rather than episodic gap.

The practical consequence for financial institutions operating in or with exposure to Ohio is a weakened basis for customer due-diligence cross-referencing: compliance functions can no longer rely on federal registry corroboration for the large majority of US-formed corporate and fund-structure customers, and must depend more heavily on onboarding-stage verification for entities carrying corporate or politically-exposed-person typologies.

As standing global backdrop against which this US-specific picture should be read, the European Union AML Package establishes a three-instrument architecture: the directly applicable AML Regulation (Regulation (EU) 2024/1624), the sixth AML Directive transposed at member-state discretion, and the AMLA Regulation (Regulation (EU) 2024/1620) establishing the Anti-Money Laundering Authority and a hybrid direct-and-indirect EU-level supervisory perimeter. This architecture does not reach Ohio directly and no AMLA development altering Ohio domestic standing has been identified through this baseline cycle; it is carried here purely as durable comparative context.

Outlook

Absent new Ohio state legislation establishing a beneficial-ownership registry, this domain is expected to remain on a deteriorating trajectory in subsequent cycles, with the corporate-formation channel in Ohio structurally opaque beyond the narrow federal disclosure obligation applicable to foreign entities. Future cycles should track any Ohio legislative activity on this front, alongside continued monitoring of AMLA operational build-out as comparative global context.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

Ohio functions this cycle as a structural rather than incidental enabler jurisdiction along two distinct but related lines. First, the concentration of super-regional bank headquarters within the state, Fifth Third, KeyCorp, and Huntington, creates correspondent-banking and Bank Secrecy Act supervisory exposure requiring sustained coordination among the Office of the Comptroller of the Currency, the Federal Reserve, and FinCEN that is not present in most other states (fim-2026-07-05-017). This concentration risk exists independent of any single enforcement action; it is a standing feature of Ohio banking geography that raises the systemic stakes of any correspondent-banking compliance failure at one of the three institutions.

Second, public and systematically searchable records of Ohio Division of Financial Institutions enforcement activity against money-services businesses, distinct from federal FinCEN and DOJ action, remain limited (fim-2026-07-05-015). This is best characterized as a sourcing-thinness gap rather than a confirmed regulatory-capacity deficit: it is genuinely uncertain, on the evidence available this cycle, whether the state supervisory layer meaningfully supplements federal oversight or largely defers to it. The distinction matters for the enabler-jurisdiction filter, which asks whether a gap reflects capacity limitation or deliberate policy choice; here, the honest answer is that the evidence base itself is too thin to resolve the question, and that thinness is itself recorded as the finding for this cycle.

Outlook

Neither line of this domain is likely to resolve quickly. The bank-headquarters concentration is a fixed feature of Ohio corporate geography and will persist as a standing supervisory-complexity condition regardless of any single-cycle development (fim-2026-07-05-017). The visibility gap into state-level enforcement is a research and transparency question rather than a scheduled regulatory event, and closing it would require either expanded state publication practices or a future research pass with access to non-public supervisory data; absent either, this domain is likely to remain thinly evidenced in subsequent cycles (fim-2026-07-05-015).

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

The baseline for Ohio in this domain establishes two standing conditions. Ohio hosts the headquarters of three super-regional banks, Fifth Third, KeyCorp, and Huntington, concentrating correspondent-banking and Bank Secrecy Act supervisory exposure that requires sustained coordination among the Office of the Comptroller of the Currency, the Federal Reserve, and FinCEN not present in most other states (fim-2026-07-05-017). This concentration is a fixed structural feature rather than an episodic condition and will remain the primary driver of systemic stakes in this domain for Ohio regardless of any single-cycle development.

Separately, and evidenced only thinly this cycle, public records of Ohio Division of Financial Institutions enforcement activity against money-services businesses remain limited relative to federal FinCEN and DOJ action (fim-2026-07-05-015). This is recorded honestly as a sourcing-thinness gap rather than a confirmed capacity deficit, since the evidence base available this cycle cannot resolve whether the state supervisory layer meaningfully supplements or largely defers to federal oversight.

Outlook

Subsequent cycles should continue to track whether expanded state publication practices or deeper research access narrows the visibility gap into Ohio state-level MSB supervision, and should monitor the bank-concentration condition for any material change, such as a merger altering the super-regional footprint, that would shift the systemic-stakes calculus established in this baseline.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

Ohio carries above-average salience in this domain relative to a typical Midwestern state, driven by a documented crypto-ATM kiosk elder-fraud pipeline and a discrete but architecturally significant pig-butchering laundering case. The Bitcoin of America and Sonny Meraban kiosk network generated at least 250 million dollars in nationwide 2022 volume before the company ceased operations in March 2023; the operator pleaded guilty in November 2024 to licensing-requirement violations and related charges, receiving five years probation with asset forfeiture (fim-2026-07-05-003). The underlying kiosk-scam typology, distinct from this specific now-defunct operator, remains active industry-wide, and Ohio has not enacted the transaction-limit or identity-verification statutes that eighteen or more peer states have adopted for kiosk operators, leaving the roughly 37,000-machine national kiosk footprint without the state-level guardrails available elsewhere (fim-2026-07-05-004). The scale of this exposure should be read structurally rather than as a single-operator problem: even with the Bitcoin of America network dormant, the industry continues to present the same underlying vulnerability documented in Ohio, rapid conversion of victim cash into cryptocurrency at unattended machines followed by transfer to third-party or offshore wallets within minutes, a sequence that defeats reversal once initiated and that state-level transaction caps or identity-verification rules are specifically designed to interrupt (fim-2026-07-05-004).

Separately, a transnational pig-butchering network with reported Cambodia and Myanmar links laundered proceeds from Ohio-victim romance and investment fraud through decentralized-finance platforms, cross-chain swaps, and unhosted wallets before consolidating in TRON-based USDT addresses linked to Southeast Asian scam-compound operators (fim-2026-07-05-005). The architecture-over-incident reading holds that the DeFi and stablecoin layering pathway itself is the structural finding; the resulting 8.2 million dollar civil forfeiture complaint filed by the Office of the United States Attorney for the Northern District of Ohio and the FBI on February 27, 2025 is the individual data point evidencing that architecture (fim-2026-07-05-006). A further, lower-confidence data point corroborates this reading: a coordinated DOJ Scam Center Strike Force action with OFAC and the State Department, announced April 23, 2026, targeted Southeast Asian scam-compound financial infrastructure matching the typology of the Northern District of Ohio case, though this action rests on a single tier-three source this cycle and has not been independently corroborated by a stronger source (fim-2026-07-05-008).

At the federal level, two legislative and regulatory tracks bear directly on Ohio-headquartered financial institutions operating in or adjacent to digital assets. The joint FinCEN and OFAC proposed rule implementing GENIUS Act AML and sanctions-compliance obligations for payment stablecoin issuers is expected to finalize ahead of the January 2027 statutory deadline, directly affecting Ohio-headquartered banks exploring stablecoin issuance or custody (fim-2026-07-05-012). For Ohio-headquartered banks weighing stablecoin issuance or custody services, the practical significance of the pending rule is that it would convert what is currently a voluntary or precautionary AML posture into an explicit statutory and regulatory obligation, with a compliance-program requirement modeled on existing Bank Secrecy Act expectations but tailored to payment-stablecoin issuance and redemption flows (fim-2026-07-05-012). The CLARITY Act digital-asset market-structure bill, advanced by the Senate Banking Committee in May 2026 after a contentious markup, faces uncertain passage before the November 2026 midterms; its outcome would set, or fail to set, nationwide market-structure rules affecting Ohio-based crypto-ATM operators, exchanges, and banks alike (fim-2026-07-05-013). Absent CLARITY Act passage, Ohio-based digital-asset exchanges and crypto-ATM operators would continue to operate under the current fragmented state-and-federal jurisdictional patchwork, a condition that itself constitutes a standing enabler-jurisdiction gap rather than a resolved regulatory perimeter (fim-2026-07-05-013).

Outlook

The trajectory across this domain is deteriorating on the state-guardrail axis even as the federal compliance perimeter tightens. No bill has been filed in the Ohio legislature to impose kiosk transaction limits, identity verification, or fraud warnings, despite the documented history as a kiosk-licensing-violation base and continued exploitation of the elder-fraud typology industry-wide; this remains a speculative but plausible legislative-pressure signal rather than a scheduled development (fim-2026-07-05-014). At the federal level, GENIUS Act finalization within the coming half-year would tighten the AML and sanctions perimeter for Ohio-headquartered stablecoin-adjacent banks, while CLARITY Act failure would extend market-structure uncertainty for Ohio-based digital-asset participants by a further multi-year period (fim-2026-07-05-012, fim-2026-07-05-013). Taken together with the DeFi-laundering architecture evidenced by the Northern District of Ohio forfeiture, Ohio financial-integrity risk in the digital-asset channel is assessed as increasing overall for this baseline cycle (fim-2026-07-05-018).

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

The baseline picture for Ohio in this domain is one of above-average salience across three converging pathways. The first is a retail cash-in pipeline: the Bitcoin of America and Sonny Meraban kiosk network generated at least 250 million dollars in nationwide 2022 volume before ceasing operations in March 2023, with the operator pleading guilty in November 2024 to licensing-requirement violations (fim-2026-07-05-003). The underlying kiosk-scam typology remains active industry-wide notwithstanding this operator dormancy, and Ohio has not enacted the transaction-limit or identity-verification statutes adopted by eighteen or more peer states, leaving the state exposed within a national kiosk footprint of roughly 37,000 machines (fim-2026-07-05-004).

The second pathway is a digital layering channel: a transnational pig-butchering network with reported Cambodia and Myanmar links has laundered proceeds from Ohio-victim fraud through DeFi platforms, cross-chain swaps, and unhosted wallets, consolidating in TRON-based USDT addresses linked to scam-compound operators, with an 8.2 million dollar civil forfeiture filed by the Office of the United States Attorney for the Northern District of Ohio and the FBI evidencing the architecture (fim-2026-07-05-005, fim-2026-07-05-006). A lower-confidence interagency strike-force action corroborates but does not independently confirm this reading (fim-2026-07-05-008).

The third pathway is the federal regulatory perimeter itself, which is in active flux. The joint FinCEN and OFAC GENIUS Act stablecoin implementing rule is expected to finalize ahead of the January 2027 statutory deadline, converting a currently voluntary AML posture for stablecoin-adjacent Ohio banks into an explicit statutory obligation (fim-2026-07-05-012). The CLARITY Act market-structure bill, meanwhile, faces genuinely uncertain passage before the November 2026 midterms, with failure risking a multi-year extension of the current fragmented jurisdictional patchwork for Ohio-based digital-asset participants (fim-2026-07-05-013).

Read together, these three pathways, retail kiosk cash-in, digital layering, and a tightening but incomplete federal perimeter, support an overall assessment of increasing financial-integrity risk for Ohio in the digital-asset channel across this baseline cycle (fim-2026-07-05-018).

Outlook

Future cycles should track whether any Ohio kiosk consumer-protection bill is filed, whether the GENIUS Act rule finalizes on the expected half-year horizon, and whether the CLARITY Act clears the Senate before the November 2026 midterms; each represents a distinct axis along which this baseline assessment could shift materially in either direction.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

Two developments this cycle illustrate a compliance-technology and active-defence posture that is improving even as the underlying threat surface, discussed in the crypto domain, continues to expand. FinCEN issued Notice FIN-2025-NTC1 on August 4, 2025, a first-of-its-kind notice detailing convertible-virtual-currency kiosk scam and laundering typologies, including tech-support, bank-imposter, and elder-targeted schemes, which raises Bank Secrecy Act reporting and red-flag expectations for financial institutions banking kiosk operators nationwide, including deployments in Ohio (fim-2026-07-05-007). The notice functions as supervisory and regulatory-technology guidance development: it raises supervisory expectations across the sector without itself imposing a direct penalty, and it is best read as sharpening the detection and reporting apparatus available to institutions rather than as an enforcement action in its own right.

Separately, blockchain-analytics support was directly embedded in the DOJ and FBI enforcement workflow against the pig-butchering scam-network proceeds discussed in the crypto domain, underpinning both the 8.2 million dollar Northern District of Ohio forfeiture and the broader interagency Scam Center Strike Force action. This illustrates the operational integration of commercial blockchain analytics into active federal enforcement against transnational laundering infrastructure, a genuine active-defence development distinct from the underlying scam typology itself (fim-2026-07-05-006, fim-2026-07-05-008).

Outlook

The compliance-technology trajectory for institutions with Ohio exposure is one of rising supervisory expectations layered onto a threat surface that is itself still expanding. The FIN-2025-NTC1 typology notice is likely to be followed, in the ordinary course of FinCEN practice, by increased examiner attention to whether institutions banking kiosk operators have adjusted red-flag monitoring and Suspicious Activity Report filing practices to reflect the newly documented typologies; institutions that have not done so face a widening gap between supervisory expectation and demonstrated control (fim-2026-07-05-007). The embedding of blockchain-analytics tooling into DOJ and FBI enforcement workflows is likely to continue and expand to further cases sharing the DeFi and stablecoin layering profile documented in the Northern District of Ohio matter, reinforcing the case for institutions to adopt comparable analytics capability defensively rather than relying solely on ex-post law-enforcement recovery (fim-2026-07-05-006, fim-2026-07-05-008).

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

The baseline for this domain rests on two developments read together as a single active-defence trend. FinCEN issued Notice FIN-2025-NTC1 on August 4, 2025, a first-of-its-kind notice detailing convertible-virtual-currency kiosk scam and laundering typologies, raising Bank Secrecy Act reporting and red-flag expectations for institutions banking kiosk operators nationwide, including Ohio deployments (fim-2026-07-05-007). This is supervisory guidance development rather than enforcement in itself, sharpening the detection apparatus available to institutions ahead of any specific penalty action.

Alongside it, blockchain-analytics support was directly embedded in the DOJ and FBI enforcement workflow underpinning both the 8.2 million dollar Northern District of Ohio pig-butchering forfeiture and the broader interagency Scam Center Strike Force action, evidencing operational integration of commercial analytics tooling into active federal enforcement against transnational laundering infrastructure (fim-2026-07-05-006, fim-2026-07-05-008).

Outlook

Subsequent cycles should track whether examiner attention following the FIN-2025-NTC1 notice produces observable changes in institution red-flag monitoring and Suspicious Activity Report practices, and whether blockchain-analytics integration extends to further cases sharing the DeFi and stablecoin layering profile established in this baseline.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
Proposed1 Jul 2026 · ±year

Potential Ohio state crypto-ATM consumer-protection legislation

Growing multi-state trend toward crypto-kiosk transaction limits and fraud warnings may prompt an Ohio-specific statute; no bill has been filed as of baseline.
Consultation1 Jul 2026 · ±half_year

GENIUS Act final stablecoin AML/sanctions implementing regulations

FinCEN and OFAC joint proposed rule would establish AML and sanctions-compliance program obligations for payment stablecoin issuers under the GENIUS Act, ahead of the January 2027 statutory deadline.
Proposed1 Oct 2026 · ±year

CLARITY Act digital-asset market-structure legislation Senate passage window

Senate Banking Committee advanced the CLARITY Act in May 2026 after contentious markup; passage before November 2026 midterms would set nationwide digital-asset market-structure rules; failure risks multi-year delay.
3 dated · 3 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

Correction to Corporate Transparency Act scope, an active Section 311 special measure, and a Bank Secrecy Act typology notice together reshape the AML picture for Ohio-exposed institutions this cycle.

The nationwide, not Ohio-specific, exemption of US-formed entities from Corporate Transparency Act reporting removes a customer due-diligence cross-reference for domestic corporate and fund-structure customers, while the Section 311 special measure against Huione Group requires enhanced correspondent-banking due diligence at Ohio-headquartered banks. FinCEN Notice FIN-2025-NTC1 separately raises reporting and red-flag expectations for institutions banking crypto-ATM kiosk operators.

9 evidence refs
ComplianceHigh

Federal beneficial-ownership scope narrowing, absent Ohio kiosk statute, and pending GENIUS/CLARITY Act rulemaking together define this cycle policy-gap picture.

The narrowed Corporate Transparency Act regime and the absence of an Ohio state-level beneficial-ownership registry compound into a structural control-framework gap for onboarding corporate customers. The absence of Ohio kiosk consumer-protection legislation, against the FinCEN kiosk typology notice, means control-framework adequacy for kiosk-adjacent exposure should be reassessed. Pending GENIUS Act and CLARITY Act rulemaking will materially change the compliance perimeter for stablecoin and digital-asset activity.

8 evidence refs
LegalHigh

A guilty-plea record in an Ohio kiosk case, an active civil forfeiture action, an interagency strike force, and the Section 311 special measure together define this cycle enforcement-trajectory picture.

The Meraban guilty plea and five-year probation outcome, the Northern District of Ohio civil forfeiture complaint, and the lower-confidence interagency strike force action collectively evidence an active enforcement trajectory around Ohio-linked crypto laundering. The Section 311 special measure against Huione Group and continuing Iran maximum-pressure sanctions, together with EU/UK designation divergence, bear on sanctions-nexus and correspondent-banking liability exposure for Ohio-headquartered institutions.

6 evidence refs
BoardHigh

Concentration of super-regional bank headquarters in Ohio, combined with the Section 311 special measure and EU/UK sanctions divergence, elevates institution-level financial-crime risk this cycle.

The presence of three super-regional bank headquarters in Ohio concentrates systemic correspondent-banking and Bank Secrecy Act supervisory exposure, and the active Huione Group special measure, layered onto documented EU/UK sanctions-list divergence, raises reputational and strategic-level regulatory-change considerations. The overall Ohio financial-integrity risk trajectory is assessed as increasing this cycle.

4 evidence refs
CTOAssessed

A dormant kiosk-scam architecture, an active DeFi/stablecoin laundering pathway, and pending GENIUS/CLARITY Act rulemaking together define this cycle digital-asset infrastructure picture.

The Bitcoin of America kiosk network and the DeFi/cross-chain/unhosted-wallet layering pathway evidenced in the pig-butchering case illustrate technical evasion vectors relevant to platform and data architecture. Pending GENIUS Act stablecoin rulemaking and the uncertain CLARITY Act market-structure legislation will materially affect the technical compliance architecture required of stablecoin-adjacent and digital-asset platforms.

5 evidence refs
RiskHigh

DeFi/stablecoin laundering exposure, an interagency strike force, the Huione special measure, and Ohio bank-concentration together mark an increasing risk trajectory this cycle.

The DeFi/stablecoin layering architecture and the corroborating interagency strike-force action represent an emerging risk typology with cross-monitor escalation relevance to conflict-finance tracking. The Huione Group special measure and Ohio super-regional bank concentration together raise exposure-concentration considerations for correspondent-banking risk models, consistent with the overall increasing risk-direction assessment for Ohio this cycle.

5 evidence refs
OperationsHigh

New FinCEN kiosk-typology guidance and the absence of Ohio transaction-limit legislation have direct transaction-monitoring and screening implications this cycle.

FinCEN Notice FIN-2025-NTC1 details specific kiosk scam typologies that should inform transaction-monitoring rule updates for institutions banking kiosk operators. The absence of Ohio-level transaction caps or identity-verification requirements for kiosk operators means no state-mandated operational threshold currently supplements institution-level controls, and the Section 311 special measure requires updated correspondent-banking screening lists.

3 evidence refs
AuditHigh

The narrowed federal beneficial-ownership regime, the absent Ohio state registry, thin visibility into state-level enforcement records, and bank-concentration risk together raise control-testing scope questions this cycle.

The scope narrowing of Corporate Transparency Act reporting and the absence of any Ohio state-level beneficial-ownership registry mean documented evidence of beneficial-ownership verification for domestic entities is now thinner than in prior periods, a gap that control testing should specifically probe. Limited public visibility into Ohio Division of Financial Institutions enforcement records constrains independent verification of whether state-layer oversight remains fit for purpose, and the concentration of super-regional bank headquarters in Ohio raises the audit-scope stakes of any single institution control failure.

4 evidence refs
Decision lens
MLRO

Correction to Corporate Transparency Act scope, an active Section 311 special measure, and a Bank Secrecy Act typology notice together reshape the AML picture for Ohio-exposed institutions this cycle.

Compliance

Federal beneficial-ownership scope narrowing, absent Ohio kiosk statute, and pending GENIUS/CLARITY Act rulemaking together define this cycle policy-gap picture.

Legal

A guilty-plea record in an Ohio kiosk case, an active civil forfeiture action, an interagency strike force, and the Section 311 special measure together define this cycle enforcement-trajectory picture.

Board

Concentration of super-regional bank headquarters in Ohio, combined with the Section 311 special measure and EU/UK sanctions divergence, elevates institution-level financial-crime risk this cycle.

CTO

A dormant kiosk-scam architecture, an active DeFi/stablecoin laundering pathway, and pending GENIUS/CLARITY Act rulemaking together define this cycle digital-asset infrastructure picture.

Risk

DeFi/stablecoin laundering exposure, an interagency strike force, the Huione special measure, and Ohio bank-concentration together mark an increasing risk trajectory this cycle.

Operations

New FinCEN kiosk-typology guidance and the absence of Ohio transaction-limit legislation have direct transaction-monitoring and screening implications this cycle.

Audit

The narrowed federal beneficial-ownership regime, the absent Ohio state registry, thin visibility into state-level enforcement records, and bank-concentration risk together raise control-testing scope questions this cycle.

Shared evidence: 15 refs
Scenario sketches

Illustrative AMLA direct-supervision transition and its effect on cross-border obliged-entity evasion pathways

As an illustrative orientation only, one could sketch how the ongoing shift from purely national AML supervision within the European Union toward AMLA direct and indirect supervision of high-risk cross-border obliged entities, under the AMLA Regulation (Regulation (EU) 2024/1620), alongside the directly applicable AML Regulation (Regulation (EU) 2024/1624) and per-state transposition of the sixth AML Directive, could reshape the evasion landscape over time. A hybrid EU-level supervisory perimeter could, in principle, close gaps previously created by inconsistent national transposition, while simultaneously creating a transitional window in which entities reclassified between national and AMLA-direct supervision face uncertain examination cadence. This is architecture-over-incident illustration of a structural mechanism, not a description of any observed event or a prediction of how the transition will unfold.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitecturestableNo material new development this cycle beyond continuing enforcement of pre-existing advisories.
T2 · EU AML Package / AMLAstableNo AMLR/6AMLD/AMLA developments surfaced this cycle; logged as coverage gap.
T3 · FATF Grey ListworseningJune 2026 Plenary added Bosnia and Herzegovina and Iraq; removed Algeria and Namibia; net 22 jurisdictions.
T4 · Beneficial-Ownership Register StatusworseningUS CTA/BOI regime remains narrowed to foreign reporting companies; GAO flags unaddressed gap; codification bills advancing.
T5 · Crypto & Digital-Asset IntegrityworseningFinCEN proposed rule extends Huione Group special measure to successor entities.
T6 · Sanctions Regime DivergencestableNo new EU/US/UK autonomous-listing drift signal surfaced this cycle.
Registers

Enforcement actions

  • Civil forfeiture complaint filed against over $8.2 million in USDT tied to a cross-border pig-butchering scheme that victimized at least 30 identified individuals, including a Cleveland-area retiree who liquidated a $650,000 retirement account into the scheme. 27 Feb 2025
  • FinCEN issued Notice FIN-2025-NTC1 on the use of convertible virtual currency kiosks for scam payments and other illicit activity, reminding financial institutions of BSA reporting obligations and detailing typologies including tech-support, bank-imposter, and elder-targeted scams. 4 Aug 2025
  • FinCEN issued an interim final rule removing BOI reporting requirements under the Corporate Transparency Act for all US-formed entities and US-person beneficial owners, narrowing the rule to apply only to foreign entities registering to do business in US states including Ohio. 26 Mar 2025
  • Coordinated multi-agency action targeting the lifecycle of transnational scam-compound operations — compounds, digital infrastructure, and laundering networks — of the type shown to have victimized Ohio residents in the NDOH USDT forfeiture case. 23 Apr 2026

Sanctions changes

  • FinCEN imposed a Section 311 special measure severing Huione Group (Cambodia) from the U.S. financial system as a foreign financial institution of primary money laundering concern, requiring Ohio-headquartered banks and MSBs to apply enhanced due diligence/correspondent restrictions against the designated network. 14 Oct 2025
  • Presidential National Security Presidential Memorandum (NSPM)-2 (Feb. 4, 2025) reimposed a 'maximum pressure' campaign on Iran, reaffirming blocked-property status for Iranian financial institutions under Executive Order 13599 and reiterating correspondent-account prohibitions applicable to all U.S. financial institutions, including Ohio-headquartered regional banks. 4 Feb 2025

Regulatory horizon (register)

  • GENIUS Act final stablecoin AML/sanctions implementing regulations
  • Potential Ohio state crypto-ATM consumer-protection legislation
  • CLARITY Act market-structure legislation Senate passage window

Active schemes

  • [HIGH] Ohio-linked crypto ATM kiosk elder-fraud and cash-in pipeline
  • [HIGH] Pig-butchering DeFi/stablecoin laundering targeting Ohio victims
  • Ohio LLC shell-formation opacity post-CTA domestic exemption
Sources
  1. TRM Labs
  2. FinCEN / U.S. Department of the Treasury
  3. FinCEN / U.S. Department of the Treasury
  4. OCCRP
  5. ICIJ
  6. FinCEN / U.S. Department of the Treasury
  7. U.S. Department of the Treasury
  8. Elliptic
Coverage gaps
Ohio has no state-level beneficial ownership registry, and t…
Ohio has no state-level beneficial ownership registry, and the March 2025 federal CTA rollback exempted domestic (Ohio-formed) reporting companies from BOI disclosure entirely, leaving only foreign entities registering in Ohio subject to federal transparency requirements.
Ohio has not enacted a crypto ATM/kiosk consumer-protection …
Ohio has not enacted a crypto ATM/kiosk consumer-protection statute (transaction limits, enhanced ID verification, mandatory fraud warnings) despite the state having hosted a documented kiosk-licensing violation network (Bitcoin of America/Meraban) and continuing elder-fraud exploitation nationally, while at least 18 other states have passed such laws.
Public, systematically searchable records of Ohio Division o…
Public, systematically searchable records of Ohio Division of Financial Institutions supervisory/enforcement actions (as distinct from federal FinCEN/DOJ actions) are limited, constraining independent verification of state-level MSB licensing enforcement density for this baseline.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.