Join our Newsletter — 33% off our NHI Course

Over-The-Counter Exchange Office

An over the counter exchange office is a privately operated venue that facilitates asset conversion outside a traditional exchange order book. In crypto investigations, these desks can obscure counterparties, aggregate customer flows, and move value across jurisdictions, which makes them important nodes for tracing, sanctions screening, and illicit finance monitoring.

Expanded Definition

An over-the-counter exchange office is a privately run venue where buyers and sellers convert assets without using a public order book. In practice, that can mean cash-for-crypto desks, brokered asset swaps, or facilitated transfers that settle through negotiated quotes rather than transparent market matching. The term is most often used in financial crime investigations and sanctions work, where the lack of public price discovery can make counterparties harder to identify and transaction chains harder to reconstruct.

Definitions vary across jurisdictions and vendors, because some desks operate as licensed money services businesses while others function as informal brokers or high-touch conversion services. In a cybersecurity and identity context, the term matters because customer due diligence, recordkeeping, and transaction monitoring determine whether a desk can be used to move value while obscuring beneficial ownership. Authoritative anti-money laundering guidance often treats these entities as higher-risk intermediaries, especially when they handle cross-border flows or convert between fiat and digital assets. For investigators, the key distinction is not whether a desk is “crypto” or “traditional,” but whether it creates a controlled conversion point outside a transparent exchange. The most common misapplication is treating every private broker as equivalent to a regulated exchange, which occurs when analysts ignore licensing status, settlement method, and counterparty visibility.

Examples and Use Cases

Implementing controls around over-the-counter exchange offices rigorously often introduces friction in onboarding and transaction handling, requiring organisations to weigh investigative visibility against customer convenience and execution speed.

  • A cash-intensive desk accepts fiat deposits and later disburses digital assets, creating a conversion point that investigators may need to trace through bank records, wallet analytics, and customer files.
  • A broker arranges a large cross-border asset swap for a corporate client, where negotiated pricing and private settlement reduce market transparency but increase the need for sanctions screening and source-of-funds checks.
  • An investigative team reviews a cluster of transactions routed through several desks to determine whether funds were layered to hide origin before reaching a regulated venue.
  • A compliance program flags a desk for enhanced due diligence because it appears in a flow pattern associated with mule activity, rapid value movement, or counterparties linked to high-risk jurisdictions.
  • Security analysts correlate activity with public advisories such as CISA cyber threat advisories when the desk is used as a cash-out point after compromise, fraud, or account takeover.

Why It Matters for Security Teams

For security, compliance, and investigations teams, the risk is not the desk itself but the opacity it can introduce into value movement. Over-the-counter exchange offices can break the audit trail that defenders rely on for sanctions enforcement, anti-money-laundering monitoring, and incident reconstruction. When a desk aggregates many smaller transactions into fewer settlement events, attribution becomes harder and suspicious patterns can be missed if monitoring only looks at public exchange activity. This also intersects with identity security: if customer verification is weak, the desk can become a convenient conversion layer for stolen credentials, fraudulent accounts, or synthetic identities. The broader threat landscape is evolving as adversaries blend financial abuse with cybercrime, and reporting such as the Anthropic first AI-orchestrated cyber espionage campaign report shows how automation can accelerate abuse across adjacent domains. Organisations typically encounter the operational impact only after funds have already moved through a private desk, at which point tracing, freezing, and evidentiary reconstruction become operationally unavoidable.

Where AI-assisted detection is used to review these flows, teams should align threat models with the MITRE ATLAS adversarial AI threat matrix so automation does not become a blind spot.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 Risk management framing fits private conversion venues that increase transaction opacity.
NIST SP 800-63 IAL2 Identity proofing levels are relevant where OTC desks onboard customers and beneficial owners.
NIST AI RMF AI RMF applies when analytics are used to detect suspicious OTC activity and manage model risk.
NIST AI 600-1 GenAI profiles matter when AI helps summarize, triage, or investigate OTC transaction patterns.
OWASP Non-Human Identity Top 10 NHI controls matter when OTC workflows rely on service accounts, API keys, or automation.

Inventory non-human identities in monitoring pipelines and rotate secrets used for wallet or case systems.