Financial Integrity Monitor

United States — Ohio US-OH

Domains (D1–D6)
3
Sources
8
Role actions
8
Horizon <90d
1
Jurisdiction profile
Largely CompliantTier BRisk: IncreasingMixed

Ohio has no state-level AML/BO regime distinct from federal BSA/CTA framework; state financial institutions and MSBs are supervised by the Ohio Division of Financial Institutions alongside federal regulators (FinCEN, OCC, Fed, FDIC).

MoreFederal 2025 CTA rollback exempted Ohio-formed LLCs from BOI reporting, widening opacity around the state's large small-business/shell-formation base. Active federal prosecutorial engagement (USAO-NDOH/SDOH) on crypto fraud forfeitures partly offsets state-level regulatory gaps, especially around unregulated crypto ATM kiosks.

Key deficiencies
  • No Ohio state-level beneficial ownership registry; reliant on now-narrowed federal CTA regime exempting domestic reporting companies
  • No Ohio-specific crypto ATM/kiosk consumer-protection statute (transaction caps, fraud warnings, ID verification) despite documented elder-fraud exploitation via Ohio-linked kiosk operators
  • Regional bank HQ concentration (Fifth Third, KeyCorp, Huntington) creates correspondent-banking and BSA/AML supervisory complexity requiring sustained OCC/Fed/FinCEN coordination
Recent developments (18m)
  • March 2025: FinCEN interim final rule exempted all US-formed entities (including Ohio LLCs) and their beneficial owners from CTA BOI reporting, narrowing the federal transparency backstop for Ohio-registered shell entities
  • February 2025: USAO for the Northern District of Ohio filed an $8.2M USDT civil forfeiture complaint against a cross-border pig-butchering laundering network that victimized Cleveland-area residents
  • August 2025: FinCEN issued a first-of-its-kind Notice (FIN-2025-NTC1) on CVC kiosk-enabled scam and laundering typologies, directly responsive to patterns previously documented in Ohio-linked crypto ATM cases
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Ohio House Bill 648 has emerged as this cycle's material financial-integrity development in Ohio, and it is best read as architecture rather than incident. The bill, introduced on January 20, 2026 and currently before the House Financial Institutions Committee, would require any person who owns, operates, or facilitates a digital-asset kiosk in Ohio to register as a money transmitter under the state's existing Money Transmitters Act, bringing the kiosk channel inside the same BSA/AML licensing perimeter that already governs conventional money-services businesses in the state. The proposal is assessed, not confirmed, since it has not advanced past committee, but the underlying policy rationale is well evidenced: it is understood to respond to the bankruptcy and cessation of operations of a nationwide crypto-ATM kiosk operator, a failure that exposed the absence of a distinct licensed category for kiosk operators under Ohio's money-transmitter framework. Structurally, HB648 would close that gap by extending registration, and by extension AML program and OFAC-screening obligations administered by the Division of Financial Institutions, to a channel used disproportionately to target elderly victims. This is the kind of structural gap-closure this monitor treats as more analytically significant than any single enforcement action, because it changes what the regulatory perimeter covers going forward rather than sanctioning a single past violation.

The jurisdiction's broader financial-integrity posture, as tracked this cycle, is assessed as structural rather than episodic, and mixed between enforcement and enablement postures: Ohio's designated regulator, the Division of Financial Institutions, already requires money-transmitter licensees to maintain a BSA/AML program and screen against the OFAC Specially Designated Nationals list, and HB648 would simply extend that same designated-regulator architecture to a channel not currently captured by it, rather than creating a new regulatory body or standard.

Other Developments

No additional Ohio-specific development met this cycle's materiality threshold beyond the kiosk-registration signal detailed above. This cycle's dispatch scope was limited to Ohio, and the standing federal-baseline posture across the balance of this monitor's typology domains for the jurisdiction is unchanged from the prior cycle.

Cross-Monitor Connections

HB648's kiosk-registration requirement sits directly on the boundary between this monitor's financial-integrity lens and the payments-infrastructure lens that the World Payments Monitor applies to the same bill and the same kiosk-operator failure: where this monitor reads HB648 as an AML/CTF perimeter-closure measure, the payments monitor reads the identical instrument as a licensing and market-access development. The crypto-specific consumer-protection and product dimensions of the same bill and the same kiosk-operator failure are likewise tracked independently by the crypto monitor, which assesses the elder-focused disclosure and transaction-hold provisions as consumer-protection architecture rather than AML architecture. Readers following the full picture around Ohio's digital-asset kiosk channel should treat these three monitor lenses as complementary rather than duplicative: the same instrument, the same failure, and the same regulator, viewed through three distinct analytical frames.

Outlook

HB648 remains in committee, and its path to enactment is not yet determinable from current sourcing; the regulatory horizon places its expected resolution in 2026 Q4 with a half-year uncertainty band. If enacted, the practical effect would be to require kiosk operators to obtain money-transmitter licensure, implement KYC and AML disclosures, and apply elder-protection transaction holds, closing a gap this monitor assesses as structurally significant regardless of the bill's ultimate legislative fate, since its introduction alone confirms that Ohio's regulator and legislature have identified the kiosk channel as an AML/CTF perimeter gap worth closing. The next cycle should watch for committee action and any parallel movement by the Division of Financial Institutions to address the same gap through guidance rather than statute.

weekly_brief_draft · JID US-OH
Domain intelligence (D1–D6)

D1 Sanctions

Huione Group (Cambodia) severed from US financial system via FinCEN Section 311 special measure (14 Oct 2025); Ohio-headquartered banks (Fifth Third, KeyCorp, Huntington) must apply enhanced correspondent-banking restrictions; EU/UK pursue divergent parallel designations.

D2 Beneficial Ownership

Ohio has no state-level BO registry; the March 26, 2025 FinCEN interim final rule exempted ALL US-formed entities nationwide (not Ohio-specific) and their beneficial owners from CTA BOI reporting, leaving only foreign entities registering in Ohio subject to federal disclosure.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto / Digital Assets / Financial Innovation

Continue reading

Ohio House Bill 648 is this cycle's defining development in the crypto and digital-assets domain for Ohio. Introduced on January 20, 2026 and currently pending before the House Financial Institutions Committee, the bill would require any person who owns, operates, or facilitates a digital-asset kiosk in the state to register as a money transmitter under the Ohio Money Transmitters Act. This is architecture, not incident: rather than sanctioning a specific bad actor, HB648 would extend the state's existing BSA/AML licensing perimeter, administered by the Division of Financial Institutions, to a channel — physical crypto kiosks — that currently sits outside a distinct licensed category. The bill's introduction follows the bankruptcy and cessation of operations of a nationwide crypto-ATM kiosk operator, a failure this monitor assesses as having crystallised the regulatory gap the bill now targets. Kiosk-based crypto transactions are a channel disproportionately used to target elderly victims, and closing the licensing gap would bring kiosk operators within the same registration, AML-program, and OFAC-screening obligations that already apply to conventional money-services businesses in Ohio. The bill's practical significance should not be overstated at this stage: it remains a proposal, assessed rather than confirmed in status, and its path through committee is not yet determinable from current sourcing.

Outlook

The regulatory horizon places HB648's expected resolution in 2026 Q4, with a half-year uncertainty band reflecting genuine legislative uncertainty. If enacted, kiosk operators would need money-transmitter licensure, KYC and AML disclosures, and elder-protection transaction holds — a direct expansion of Ohio's designated AML/CTF regulatory perimeter. Watch for committee movement on HB648 and for any parallel guidance from the Division of Financial Institutions addressing the same kiosk-channel gap administratively ahead of, or independent of, the statute's passage.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
Proposed2026-Q4 · ±half_year

HB648 Digital Asset Kiosk regulation

Kiosk operators would need money-transmitter licensure, KYC/AML disclosures, and elder-protection transaction holds.
1 dated · 3 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROAssessed

Ohio HB648 would extend BSA/AML registration, program, and OFAC-screening obligations to digital-asset kiosk operators.

If enacted, kiosk operators become subject to the same designated-regulator AML/CTF architecture already governing Ohio money transmitters, meaning new SAR/CTR-adjacent monitoring obligations attach to a previously uncaptured channel.

2 evidence refs
ComplianceAssessed

A digital-asset kiosk licensing gap in Ohio is being closed through pending legislation rather than through enforcement action.

Compliance functions with kiosk-adjacent exposure in Ohio should track HB648's committee status, since its enactment would newly obligate kiosk operators to register as money transmitters and adopt the DFI's existing licensee compliance framework.

2 evidence refs
LegalPossible

No material change for this persona this cycle.

No material change for this persona this cycle

BoardAssessed

Ohio is closing a licensing gap for digital-asset kiosks following an operator bankruptcy, a structural rather than episodic regulatory signal.

The development is assessed, not enacted, but reflects a broader pattern of state-level scrutiny of kiosk-based crypto access points that may be relevant to enterprise risk appetite in adjacent markets.

1 evidence refs
CTOAssessed

Digital-asset kiosk infrastructure in Ohio would face new licensure and KYC technical-integration requirements under pending legislation.

Kiosk hardware and software providers operating in Ohio should anticipate a KYC-disclosure and elder-protection transaction-hold requirement if HB648 is enacted, with implications for kiosk-side identity-verification architecture.

1 evidence refs
RiskAssessed

The kiosk-channel failure that prompted HB648 illustrates an emerging risk typology around unlicensed physical crypto access points.

Risk functions should note that Ohio's designated regulator is treating kiosk-channel exposure as a structural gap rather than an isolated incident, which may inform exposure assessments for kiosk-adjacent counterparties.

1 evidence refs
OperationsAssessed

Pending Ohio legislation would add kiosk operators to the population requiring FinCEN MSB registration and OFAC screening.

Transaction-monitoring and screening operations supporting Ohio money-services activity should anticipate a possible expansion of the in-scope registrant population if HB648 is enacted.

2 evidence refs
AuditPossible

Ohio's designated-regulator AML/CTF architecture is stable, but a new registrant population may be added under HB648.

Audit scope for Ohio money-transmitter compliance testing may need to expand to a new kiosk-operator population if the bill advances, requiring updated control-testing procedures once resolved.

1 evidence refs
Decision lens
MLRO

Ohio HB648 would extend BSA/AML registration, program, and OFAC-screening obligations to digital-asset kiosk operators.

Compliance

A digital-asset kiosk licensing gap in Ohio is being closed through pending legislation rather than through enforcement action.

Legal

No material change for this persona this cycle.

Board

Ohio is closing a licensing gap for digital-asset kiosks following an operator bankruptcy, a structural rather than episodic regulatory signal.

CTO

Digital-asset kiosk infrastructure in Ohio would face new licensure and KYC technical-integration requirements under pending legislation.

Risk

The kiosk-channel failure that prompted HB648 illustrates an emerging risk typology around unlicensed physical crypto access points.

Operations

Pending Ohio legislation would add kiosk operators to the population requiring FinCEN MSB registration and OFAC screening.

Audit

Ohio's designated-regulator AML/CTF architecture is stable, but a new registrant population may be added under HB648.

Shared evidence: 2 refs
Scenario sketches

AMLA Direct-Supervision Transition and Cross-Border Obliged-Entity Perimeter

Illustrative orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves toward direct and indirect supervision of cross-border obliged entities, alongside the directly-applicable AMLR (Reg (EU) 2024/1624) and per-Member-State transposition of the sixth AML Directive, the supervisory landscape could shift from a purely national model toward a hybrid EU-level regime. Such a shift could, illustratively, alter incentives for evasion structuring that currently exploits divergent national supervisory intensity, though this is a structural possibility for analytical orientation, not an observed development in any jurisdiction covered this cycle, including Ohio.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architectureno_changeNo material Russia dark-fleet/tech-procurement or Houthi/Yemen channel development this cycle within the pooled budget.
T2 · EU AML Package / AMLAno_changeNo fresh AMLR/6AMLD/AMLA development researched this cycle; budget concentrated on US-OH-bound and Tier D jurisdictions.
T3 · FATF Grey Listno_changeNo new plenary outcome identified this cycle.
T4 · Beneficial-Ownership Register Statusno_changeNo fresh BO-registry development identified this cycle.
T5 · Crypto & Digital-Asset IntegritymixedUS-OH fragmentation continues: HB648 kiosk registration tightens while HB18 crypto-reserve authority and a Bitcoin-payment vendor authorization loosen the state's digital-asset posture.
T6 · Sanctions Regime Divergenceno_changeNo fresh EU/US/UK autonomous-listing divergence identified this cycle.
Registers

Enforcement actions

  • Civil forfeiture complaint filed against over $8.2 million in USDT tied to a cross-border pig-butchering scheme that victimized at least 30 identified individuals, including a Cleveland-area retiree who liquidated a $650,000 retirement account into the scheme. 27 Feb 2025
  • FinCEN issued Notice FIN-2025-NTC1 on the use of convertible virtual currency kiosks for scam payments and other illicit activity, reminding financial institutions of BSA reporting obligations and detailing typologies including tech-support, bank-imposter, and elder-targeted scams. 4 Aug 2025
  • FinCEN issued an interim final rule removing BOI reporting requirements under the Corporate Transparency Act for all US-formed entities and US-person beneficial owners, narrowing the rule to apply only to foreign entities registering to do business in US states including Ohio. 26 Mar 2025
  • Coordinated multi-agency action targeting the lifecycle of transnational scam-compound operations — compounds, digital infrastructure, and laundering networks — of the type shown to have victimized Ohio residents in the NDOH USDT forfeiture case. 23 Apr 2026

Sanctions changes

  • FinCEN imposed a Section 311 special measure severing Huione Group (Cambodia) from the U.S. financial system as a foreign financial institution of primary money laundering concern, requiring Ohio-headquartered banks and MSBs to apply enhanced due diligence/correspondent restrictions against the designated network. 14 Oct 2025
  • Presidential National Security Presidential Memorandum (NSPM)-2 (Feb. 4, 2025) reimposed a 'maximum pressure' campaign on Iran, reaffirming blocked-property status for Iranian financial institutions under Executive Order 13599 and reiterating correspondent-account prohibitions applicable to all U.S. financial institutions, including Ohio-headquartered regional banks. 4 Feb 2025

Regulatory horizon (register)

  • GENIUS Act final stablecoin AML/sanctions implementing regulations
  • Potential Ohio state crypto-ATM consumer-protection legislation
  • CLARITY Act market-structure legislation Senate passage window

Active schemes

  • [HIGH] Ohio-linked crypto ATM kiosk elder-fraud and cash-in pipeline
  • [HIGH] Pig-butchering DeFi/stablecoin laundering targeting Ohio victims
  • Ohio LLC shell-formation opacity post-CTA domestic exemption
Sources
  1. TRM Labs
  2. FinCEN / U.S. Department of the Treasury
  3. FinCEN / U.S. Department of the Treasury
  4. OCCRP
  5. ICIJ
  6. FinCEN / U.S. Department of the Treasury
  7. U.S. Department of the Treasury
  8. Elliptic
Coverage gaps
Ohio has no state-level beneficial ownership registry, and t…
Ohio has no state-level beneficial ownership registry, and the March 2025 federal CTA rollback exempted domestic (Ohio-formed) reporting companies from BOI disclosure entirely, leaving only foreign entities registering in Ohio subject to federal transparency requirements.
Ohio has not enacted a crypto ATM/kiosk consumer-protection …
Ohio has not enacted a crypto ATM/kiosk consumer-protection statute (transaction limits, enhanced ID verification, mandatory fraud warnings) despite the state having hosted a documented kiosk-licensing violation network (Bitcoin of America/Meraban) and continuing elder-fraud exploitation nationally, while at least 18 other states have passed such laws.
Public, systematically searchable records of Ohio Division o…
Public, systematically searchable records of Ohio Division of Financial Institutions supervisory/enforcement actions (as distinct from federal FinCEN/DOJ actions) are limited, constraining independent verification of state-level MSB licensing enforcement density for this baseline.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.