The control gap we probe
Teams are strong on chain analysis and weak on documentary scepticism. An analyst who can trace a peel chain across four hops may still accept an onboarding pack that was generated rather than issued.
Sector assessment
20 laundering methods apply to this sector. 13 are rarely covered in standard AML training. The sector assessment uses 7 cases.
The ledger is permanent, so the exposure sits at the edges: on-ramp, off-ramp and identity.
Teams are strong on chain analysis and weak on documentary scepticism. An analyst who can trace a peel chain across four hops may still accept an onboarding pack that was generated rather than issued.
Sanctions designations of mixing services, FCA registration enforcement including action against unregistered ATM operators, and the Travel Rule have all moved the compliance burden onto the identity layer.
Cryptoasset exchange providers and custodian wallet providers must be registered with the FCA under the Money Laundering Regulations. Carrying on that activity without registration is a criminal offence in its own right, which the FCA has now prosecuted, so the scope question here has a custodial answer rather than a supervisory one.
Not one case. Every case that exercises a typology on your list is part of your mark, weighted by how much of your exposure it carries. The weights are derived from the register rather than chosen, so adding a case re-derives them instead of leaving the old ones wrong.
| Case | Your typologies | Share of your mark |
|---|---|---|
| The Exchange Deskwritten for your desk | 6 | 24% |
| The Verification Desk | 6 | 24% |
| The Victim Ledger | 5 | 20% |
| The Betting Account | 4 | 16% |
| The Incoming Payment | 2 | 8% |
| The Fundraising Appeal | 1 | 4% |
| The Payment Trail | 1 | 4% |
£99one payment, 12 months, nothing renews
£750pilot, up to 25 people, invoiced
Drawn from the full register and filtered to this sector. Each entry states what the typology looks like inside your own systems, and names the source it came from. 20 of the 20 are currently exercised by an assessment case; the rest are documented here and not yet built into one.
Small test transactions are run to establish where a firm's rules and thresholds sit, and activity is then shaped to stay just inside them. Automation makes the probing cheap and the adaptation continuous.
Sequences of small value-varying transactions preceding a step change in volume, activity that settles just below alerting thresholds across several distinct rules at once, and customers whose behaviour changes within days of a rule being retuned.
Access to abuse material or live-streamed abuse is bought through small, repeated payments, frequently to high-risk jurisdictions and increasingly through virtual assets and prepaid instruments.
Small repeated payments, often at unusual hours, to money transfer beneficiaries in a small number of jurisdictions with no family or trade connection to the customer; use of prepaid instruments or virtual assets by a customer with no other digital activity; and payment values clustered in narrow bands.
Statements, identity documents and supporting evidence are generated rather than obtained, and are internally consistent in ways genuine documents are not.
Statements with no fees or charges across months, running balances consistent to the penny, logos at incorrect aspect ratio, institution codes in the wrong format, identity photographs internally inconsistent or inconsistent with stated age, third-party webcam plugins during liveness checks.
Rather than holding a fake face up to the camera, the attacker bypasses the camera entirely: virtual-camera software injects a pre-rendered or real-time face-swapped video stream directly into the onboarding app, so the liveness check is validating a video file rather than a person.
Emulator and virtual-camera artefacts in the capture stream, device and app-integrity signals that contradict a genuine handset, repeated onboarding attempts from the same device fingerprint under different identities, and capture metadata inconsistent with the phone the customer claims to hold.
A person who does not exist is assembled from a mixture of real and fabricated data, passed through onboarding, allowed to build a credit and transaction history, and then used as durable laundering infrastructure rather than for a single fraud.
Thin-file customers who behave impeccably for months, clusters sharing partial attributes such as address, device or contact details, credit files that begin abruptly in adulthood, and accounts whose only real purpose emerges long after onboarding.
An autonomous agent executes the layering stage without a human in the loop: fragmenting funds into micro-transactions, selecting bridge and exchange routes on live liquidity, sizing transfers to stay inside observed thresholds, and adapting when a route stops working.
Transaction sequences with machine timing and sizing characteristics, activity that reshapes itself shortly after a control is changed, and volumes of small movements that exceed what any manual operation could sustain.
Assets are swapped rapidly across blockchains and between tokens using bridges and decentralised exchanges, so that following the trail requires a new tool, a new dataset and a new analyst judgment at every hop.
For a VASP: deposits whose immediate provenance is a bridge or DEX contract rather than an identifiable counterparty, and short holding times between receipt and onward swap. For a bank: fiat settlement from an exchange whose own inbound provenance cannot be evidenced.
Dollar-denominated stablecoins, predominantly on low-fee chains, have become the settlement layer between criminal enterprises, replacing correspondent banking for cross-border criminal value transfer.
Fiat on-ramp and off-ramp volumes at exchanges and OTC desks, and customers whose banked income disappears while spending continues. The settlement itself never touches the banking system.
Escrow-style online marketplaces broker laundering, stolen data, scam infrastructure and trafficking services between criminal counterparties, holding funds until both sides perform.
Exposure is indirect and sits at the fiat edges: payment institutions, exchanges and correspondent relationships with entities in the group's network. The prohibition itself is the compliance obligation.
Long-form investment and relationship frauds, frequently run from trafficked-labour compounds, collect victim funds through mule accounts and convert them into stablecoins for onward settlement.
Victim-side outbound payments escalating over weeks to newly added payees and exchange accounts, followed by indemnity claims and recall requests once the victim realises. The collection accounts show inbound from many unconnected individuals.
Funds are pooled and redistributed by a mixing service, or swapped into a privacy coin whose ledger does not expose amounts or counterparties, breaking deterministic tracing.
For a VASP: deposits with mixer-adjacent provenance, or swap history through privacy assets. For a bank: exposure arrives already laundered, at the off-ramp.
Extortion payments received in bitcoin are converted rapidly into stablecoins or swapped through decentralised protocols, often within hours, before distribution to affiliates.
Victim-side: an urgent, unexplained payment to an exchange or a specialist incident-response intermediary. Insurer and IR-firm accounts are a concentration point.
Cash is converted to crypto through machines or over-the-counter brokers who accept cash and settle on-chain, providing a placement route that bypasses bank deposit controls entirely.
ATM operator and OTC broker settlement accounts with cash deposit volumes inconsistent with a retail customer base, and customers whose card spending continues after banked income stops.
An unregistered or high-risk service obtains market access through an account at a compliant exchange, so the compliant firm's customer is in reality a downstream book of unknown customers.
A single institutional customer whose deposit and withdrawal counterparties number in the thousands, activity patterns inconsistent with a single beneficial owner, and onward flows to jurisdictions the customer does not operate in.
Value is held in self-custody between hops and cashed out in many small amounts across multiple venues and individuals, so no single off-ramp sees an amount worth investigating.
Numerous customers each receiving modest, regular exchange settlements with no other economic profile, sharing device, address or beneficiary characteristics.
A digital asset with no objective value is traded between wallets under common control at escalating prices, manufacturing a sale record that converts funds into apparent trading profit.
Marketplace settlement receipts where buyer and seller are ultimately the same interest, and gaming or marketplace platform accounts with volumes unrelated to any player base.
Capability is rented rather than built. Subscription platforms supply mule account provisioning, KYC-bypass tooling, synthetic identity generation, deepfake kits and end-to-end laundering, so an operator needs money rather than skill.
The same tooling signature across customers with no other connection: identical document templates, shared device or capture characteristics, and mule accounts appearing in coordinated batches rather than individually.
Funding is raised in small amounts through appeals, crowdfunding and sham charitable structures, and moved in values individually too low to trigger monitoring. The concern is destination and intent rather than the size or origin of the funds.
Small recurring outbound payments to campaigns, appeals or virtual asset addresses associated with proscribed causes; a charity whose disbursement pattern does not match its stated programme; and clusters of small transfers converging on a single beneficiary.
State-sponsored groups steal digital assets at scale from exchanges and protocols, then launder them through mixers, cross-chain bridges and complicit over-the-counter brokers to fund state programmes.
For VASPs: deposits traceable to designated addresses, and institutional counterparties who cannot evidence their own inbound provenance. For banks: correspondent exposure to intermediaries in the cash-out chain.
Operatives obtain remote technical roles using stolen or fabricated identities, often through intermediaries, and route salary payments onward to sanctioned regimes.
Payroll and contractor payments to accounts whose device and location signals contradict the stated worker location, several apparently unrelated contractors sharing payment infrastructure, and rapid onward transfer of net pay.
The Exchange Desk carries 6 of the 20 typologies above and 24 per cent of your mark. Full debrief, no account, no card.
Start The Exchange DeskRun the full Crypto and VASPs benchmark across up to 25 people for £750.
No integration · No customer data · Confidential cohort available
One documented case each week. One decision. The answer and the source afterwards.