Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do ISIS-linked money services businesses create higher…
Cyber Security

Why do ISIS-linked money services businesses create higher sanctions risk for exchanges and VASPs?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Money services businesses can bridge fiat and crypto across multiple countries, making them effective conduits for layered transfers and obscured origin points. When those firms are controlled by designated facilitators, the risk extends beyond a single wallet or account to counterparties, settlement paths, and beneficiary exposure. That creates both direct sanctions liability and broader operational risk for global compliance teams.

Why This Matters for Security Teams

Money services businesses sit at a high-risk junction between fiat movement, correspondent relationships, and crypto settlement. When an MSB is linked to a designated or otherwise sanctioned facilitator, exchanges and VASPs cannot treat the exposure as a single-counterparty problem. The risk extends into onboarding, chain-of-custody review, beneficiary screening, transaction monitoring, and offboarding decisions. That is why sanctions screening must be paired with deeper counterparty due diligence and ongoing risk scoring, not handled as a one-time name match exercise.

Current guidance suggests that teams should evaluate both direct exposure and indirect facilitation risk, because a clean wallet label does not prove clean origin. This is especially important where the MSB operates across jurisdictions, uses nested accounts, or relies on third-party settlement agents that obscure control. The compliance failure mode is usually not the obvious flagged transfer. It is the accumulation of weak signals that never get connected into a sanctions narrative. For control design, the NIST Cybersecurity Framework 2.0 remains useful for linking governance, risk assessment, and monitoring into one operating model. In practice, many security teams encounter this only after a counterparties review exposes hidden dependency chains rather than through intentional sanctions-focused mapping.

How It Works in Practice

For exchanges and VASPs, the operational question is not simply whether an MSB appears on a list. It is whether the MSB can introduce sanctioned value, sanctioned persons, or sanctioned jurisdictions into the transaction path through layered routing, omnibus accounts, or affiliated cash-out points. That requires risk-based controls that combine customer due diligence, transaction monitoring, wallet intelligence, and escalation workflows. Sanctions controls should not sit only in the compliance team if the platform also uses automated onboarding, API-based settlement, or high-speed trading flows.

A practical program usually includes:

  • Enhanced due diligence for MSBs, including ownership, control, licensing, and cross-border settlement relationships.
  • Screening against sanctions lists, adverse media, and known facilitation patterns before activation and on an ongoing basis.
  • Blockchain analytics and off-chain intelligence to identify clustered exposure, nested services, and rapid hop patterns.
  • Alert triage rules that distinguish simple routing complexity from indicators of sanctioned facilitation.
  • Documented escalation paths for freezing, rejecting, or exiting relationships when risk cannot be reasonably remediated.

Controls should be implemented under a broader governance model, not as isolated technical filters. The most effective programs align sanctions monitoring to NIST SP 800-53 Rev 5 Security and Privacy Controls, especially access control, audit logging, continuous monitoring, and incident response. That helps teams prove they can detect exposure, preserve evidence, and act consistently across jurisdictions. These controls tend to break down when the exchange relies on manual review for high-volume flows, because analysts cannot reliably connect account structure, chain data, and beneficiary context fast enough.

Common Variations and Edge Cases

Tighter sanctions screening often increases onboarding friction and investigation volume, requiring organisations to balance speed against defensibility. That tradeoff becomes sharper when the MSB operates in a country with weak licensing oversight, fragmented beneficial ownership records, or heavy use of correspondent intermediaries. In those cases, there is no universal standard for how much indirect exposure is acceptable, so firms need documented risk tolerance and consistent escalation criteria.

Another edge case is where the MSB itself is not designated, but its owners, senior operators, or habitual counterparties are linked to prohibited networks. Best practice is evolving here: some firms treat repeated association patterns as sufficient to deny service, while others require stronger evidence before exiting a relationship. The key is to avoid false precision. A wallet that is technically unlabelled may still be operationally contaminated through settlement pathways or shared control structures.

Identity and control intersections matter too. Where an MSB uses delegated operators, sub-accounts, or shared administrative access, the exchange should treat account governance as part of sanctions risk, not just cybersecurity hygiene. That is especially true when access to funding, treasury, or payout systems is controlled by multiple parties across borders. In those environments, sanctions exposure often persists because ownership, access, and money movement are reviewed separately instead of as one operational control problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.1Sanctions risk needs governance, risk appetite, and accountability across the exchange.
NIST SP 800-53 Rev 5AC-2Account and access governance helps control shared or delegated MSB administration.

Set clear ownership, risk thresholds, and escalation for sanctioned counterparty exposure.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org