D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Mississippi operates entirely within the federal BSA/AML framework administered by FinCEN and OFAC; state adds licensing via the Dept.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Mississippi has closed a structural gap in its treatment of cash-to-crypto conversion points. Under the Virtual Currency Kiosk Consumer Protection Act (HB1625), any operator of a virtual-currency kiosk in the state must now hold a money-transmitter licence, bringing kiosk operators inside the licensing perimeter of the Money Transmission Modernization Act rather than leaving them to operate as an unlicensed adjunct to the money-services sector. This is a narrow but concrete instrument: it targets a single physical touchpoint — the unattended kiosk — rather than establishing a general digital-asset licensing framework, and it is paired with the Data Security for Money Transmitters Act (HB1596), which requires the same licensees, including kiosk operators, to designate a qualified individual and maintain a written information-security program with a 72-hour breach-notification duty to the Commissioner of Banking and Consumer Finance.
Read as a financial-innovation development, the law is best understood as regulatory catch-up: virtual-currency kiosks have proliferated as a retail on-ramp with historically light licensing scrutiny relative to online exchanges, and Mississippi's approach — folding kiosk operators into the existing money-transmitter category rather than legislating a bespoke crypto licence — is consistent with a broader wave of US state-level kiosk regulation moving in the same direction. Assessed at High confidence on enrolled-bill text corroborated independently, this is a genuine tightening rather than a proposal.
The evidentiary base for this cycle is limited to the statutory text and its immediate secondary commentary; confirmation of implementing guidance or first-enforcement activity under the new kiosk-licensing requirement has not been located this cycle and remains a gap. What would sharpen this picture is evidence of the Department of Banking and Consumer Finance issuing kiosk-specific rulemaking, or evidence of an early licensing action against an operator that continued to run unlicensed kiosks past the July 1, 2026 effective date.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Mississippi's AML/CTF-adjacent regime for money transmitters materially expanded this cycle. The Data Security for Money Transmitters Act (HB1596) amends the Money Transmission Modernization Act (Miss. Code Ann. Section 75-16-1 et seq.) to require every MTMA licensee to designate a qualified individual and maintain a comprehensive written information-security program calibrated to the licensee's size and complexity, with a 72-hour breach-notification obligation running to the Commissioner. This sits alongside, rather than replaces, the state's existing money-transmitter licensing architecture, and it is paired with the Virtual Currency Kiosk Consumer Protection Act (HB1625), which extends the licensing perimeter itself to virtual-currency-kiosk operators. Assessed at High confidence on enrolled-bill text corroborated by independent legal-industry summaries, the combined effect is a governance-and-licensing tightening across the money-transmission sector generally, with the crypto-kiosk vector specifically brought inside a regime that previously reached it only incompletely.
This is not a comprehensive AML/CTF regime in the federal BSA sense — it does not itself create new suspicious-activity-reporting or customer-due-diligence obligations — but it does raise the governance and breach-response baseline against which a Mississippi money-transmitter licensee, including a crypto-kiosk operator, will now be assessed by its state regulator. The pairing of HB1596 and HB1625 also signals that Mississippi's Department of Banking and Consumer Finance is treating data-security governance as inseparable from licensing scope: a licensee that fails to maintain the required program risks its money-transmitter licence itself, not merely a separate data-security penalty.
Confirmation of whether the Department of Banking and Consumer Finance has issued implementing rules elaborating the 'comprehensive written information-security program' standard beyond the bare statutory text has not been located this cycle. Future cycles should watch for enforcement activity testing the 72-hour breach-notification timeline, and for whether Mississippi's approach is echoed or diverged from by neighbouring states responding to the same crypto-kiosk fraud vector.
The new governance and 72-hour breach-notification duty under HB1596 raises the compliance baseline against which a Mississippi-licensed money transmitter, including a crypto-kiosk operator, will be assessed. This is a governance obligation, not a new SAR or CTR trigger, but it materially expands the documented compliance-programme standard.
Compliance functions supervising Mississippi money-transmitter licensees should confirm the qualified-individual designation and written information-security program are in place as of the July 1, 2026 effective date, and that kiosk-operating counterparties hold the required licence.
Because the obligations are written into amended primary legislation rather than a freestanding or easily-reversed instrument, legal risk assessment should treat them as a settled feature of the licensing regime rather than a contingent or likely-to-be-challenged rule.
No material change for this persona this cycle
Technology functions supporting a Mississippi money-transmitter or kiosk operation should confirm the risk-based written information-security program and breach-detection/notification workflow can meet the 72-hour notification timeline now in force.
This narrows a previously under-regulated exposure concentration point; risk functions tracking cash-to-crypto typologies should register Mississippi as tightening rather than static.
Operational workflows for onboarding or continuing relationships with Mississippi money-services-business customers should reflect the expanded licensing population.
No material change for this persona this cycle
Mississippi now imposes qualified-individual and written information-security-program duties on all money-transmitter licensees, including virtual-currency-kiosk operators.
A licensing gap for virtual-currency kiosks in Mississippi has closed, and a new information-security-program standard applies sector-wide.
Mississippi's HB1596/HB1625 package amends the Money Transmission Modernization Act directly, giving the new obligations durable statutory standing.
No material change for this persona this cycle.
Mississippi's kiosk-licensing extension and information-security-program mandate create a defined technical-governance standard for crypto-kiosk infrastructure.
The cash-to-crypto kiosk vector in Mississippi is now inside licensing-based AML/CTF architecture rather than sitting outside it.
Onboarding a Mississippi-licensed virtual-currency-kiosk operator as a customer now requires confirming money-transmitter licensure obtained under HB1625.
No material change for this persona this cycle.
Illustrative scenario for analytical orientation: as the AMLA Regulation (Reg (EU) 2024/1620) moves the EU toward direct and indirect supervision of cross-border obliged entities, alongside the directly-applicable AMLR (Reg 2024/1624) and per-state 6AMLD transposition, the supervisory perimeter for large cross-border groups could shift from a purely national model toward a hybrid EU-level regime. This could, illustratively, alter where evasion typologies concentrate, as entities test the boundary between AMLA-supervised and nationally-supervised populations. This is architecture-over-incident framing under the intelligence register; it is illustrative orientation, not a prediction or observed fact for this cycle.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | No material change found this cycle; awaiting_primary_source given US-MS-bound sweep. |
| T2 · EU AML Package / AMLA | no_change | Out of scope for the US-MS-bound sweep; not independently re-searched. |
| T3 · FATF Grey List | no_change | No plenary outcome surfaced this cycle for this jurisdiction sweep. |
| T4 · Beneficial-Ownership Register Status | no_change | No US-MS-specific BO registry development; no state-level BO registry exists in Mississippi. |
| T5 · Crypto & Digital-Asset Integrity | improving | Mississippi enacted the Virtual Currency Kiosk Consumer Protection Act (HB1625), bringing crypto-ATM operators within the MTL licensing perimeter for the first time, effective July 1, 2026. |
| T6 · Sanctions Regime Divergence | no_change | No EU/US/UK autonomous-listing divergence development surfaced for this jurisdiction sweep. |