D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Illinois AML/CTF oversight sits atop the federal BSA/OFAC framework: the Illinois Department of Financial and Professional Regulation (IDFPR) licenses currency exchanges and money transmitters under the Transmitters of Money Act and Currency Exchange Act, and shares OFAC-compliance findings with Treasury under a standing MOU.
United States federal law that applies in United States – Illinois is covered once, on the United States page. This page covers United States – Illinois’s own layer: its own law, regulators and enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Illinois enacted the Digital Assets and Consumer Protection Act (205 ILCS 731), effective 18 August 2025, which gives the Illinois Department of Financial and Professional Regulation authority to register, supervise, and take enforcement action against digital-asset exchanges and administrators serving Illinois residents, with civil penalties of up to $100,000 per day for violations. The instrument is framed by IDFPR as a consumer-protection measure, and no AML-specific provision within DACPA itself was independently confirmed this cycle. That absence is itself worth naming precisely: the state has built a substantial registration and supervisory perimeter around digital-asset business activity without, so far as this cycle's research established, attaching an explicit anti-money-laundering clause to that perimeter. This is the enablement-as-signal pattern this monitor's register is built to surface: a state creating meaningful regulatory infrastructure for a sector without yet layering financial-crime controls onto it is analytically significant in its own right, independent of any enforcement action.
The architecture-over-incident reading here is that DACPA's registration requirement, its civil-penalty regime, and IDFPR's supervisory authority together constitute compliance-technology-adjacent infrastructure. A registry of who is transacting digital-asset business with Illinois residents, backed by enforcement powers, is the kind of structural precondition that an AML overlay could be built on top of later, whether via IDFPR rulemaking or a subsequent legislative amendment. It is not, on the evidence gathered this cycle, itself an AML instrument.
The question to track is whether IDFPR's forthcoming DACPA implementing rules, expected around the first quarter of 2027 within a half-year uncertainty band, add any Illinois-specific AML or KYC conditions beyond the federal Bank Secrecy Act baseline. As of this cycle, no such condition has been confirmed, and the July 2027 full-licensing compliance deadline for digital-asset businesses serving Illinois residents remains the operative near-term milestone. Whether Illinois follows the fantasy-contest precedent, discussed elsewhere in this brief, of attaching an explicit federal-standards AML clause to a state licensing instrument is the pattern to watch for DACPA specifically.
This cycle's signal for compliance technology in Illinois is indirect and infrastructural rather than a discrete tooling development. The Illinois Department of Financial and Professional Regulation's registration and supervisory architecture under the Digital Assets and Consumer Protection Act, established by P.A. 104-0428 effective 18 August 2025, creates a registry of digital-asset businesses serving Illinois residents backed by enforcement powers of up to $100,000 per day in civil penalties. No AML-specific guidance has been issued under this architecture as of this cycle, but the registration requirement itself is the kind of structural precondition that compliance-technology tooling, transaction monitoring, screening, and reporting systems, would eventually need to plug into once, and if, an AML overlay is added.
This is worth flagging in the compliance-technology domain specifically because the three-pillar balance principle this monitor applies means AML enforcement volume should not crowd out attention to the compliance infrastructure being built ahead of enforcement activity. A registration perimeter without an AML overlay is not evidence of an active-defence gap on its own; it is evidence that the state has sequenced registration ahead of financial-crime-specific rulemaking, which is a common and often deliberate regulatory sequencing choice.
Watch for whether IDFPR's implementing rules, expected around the first quarter of 2027, include any requirement for registered digital-asset businesses to deploy specific transaction-monitoring or screening technology as a condition of registration. No such requirement has been confirmed this cycle. Absent that, the compliance-technology signal for Illinois remains a watch-only item rather than an active development.
Illinois has no independent state anti-money-laundering statute and no state Financial Intelligence Unit; AML supervision in the state remains a function of the federal Bank Secrecy Act and FinCEN architecture. This cycle's material development is not a change to that federal-state division of authority, but a state-level licensing condition that extends the existing federal obliged-entity model into a newly regulated gaming vertical. The Sports Wagering Act amendment creating Illinois Gaming Board licensure for fantasy-contest operators, at Section 25-120.5(a), requires those licensees to comply with anti-money-laundering standards as defined by the federal Bank Secrecy Act of 1970 and the Anti-Money Laundering Act of 2020.
The architecture-over-incident reading is that this is a structural finding, not an incident: Illinois has not created new AML law, it has conditioned a new category of state gaming licensure on compliance with the existing federal standard. This is a template worth watching for reuse: other states building adjacent licensing regimes for previously ambiguous or newly legalized activity classes, prediction markets, digital-asset kiosks, fantasy-contest variants, may follow the same pattern of layering a federal-standards AML compliance clause onto a new state licence rather than legislating independent AML requirements. Separately, IDFPR's DACPA/DAKA registration architecture for digital-asset businesses is compliance-technology-adjacent infrastructure that a future AML overlay could build on, but no AML-specific clause within DACPA itself has been confirmed this cycle; that is treated in this brief's D5 and D6 sub-briefs rather than here.
Watch whether Illinois or other US states extend the Section 25-120.5(a) style federal-standards AML compliance clause to further newly licensed gaming or gaming-adjacent verticals over the coming cycles, and whether IDFPR's forthcoming DACPA implementing rules add any Illinois-specific AML or KYC condition beyond the federal BSA baseline. Neither has been confirmed as of this cycle.
Commercial Activity is not yet covered for this jurisdiction in this report.
Fantasy-contest operators newly licensed under the Sports Wagering Act must comply with anti-money-laundering standards as a condition of that licence. Where your institution operates or partners with Illinois-licensed fantasy-contest platforms, confirm that BSA/AMLA-2020 obliged-entity treatment is understood to apply to this newly regulated activity class.
IDFPR can register, supervise, and penalize digital-asset exchanges and administrators serving Illinois residents up to $100,000 per day, but no AML-specific provision within DACPA itself was confirmed this cycle. Compliance functions supporting digital-asset business in Illinois should track IDFPR's forthcoming implementing rules for any AML/KYC addition.
No material change for this persona this cycle
This is a structural pattern, not an isolated event, and signals how state-level licensing regimes in the US may increasingly piggyback on the federal BSA baseline rather than legislate independent state AML law. Board-level financial-crime risk exposure from Illinois-licensed gaming or digital-asset subsidiaries should be assessed against this evolving pattern.
Technology teams supporting digital-asset compliance in Illinois should note that DACPA/DAKA registration infrastructure exists but no AML-specific technical standard or reporting integration has been confirmed this cycle; build flexibility into any registration-integration work pending IDFPR's implementing rules.
Risk functions should incorporate Illinois fantasy-contest licensees into obliged-entity risk-scoring models where relevant, given the newly imposed Section 25-120.5(a) compliance duty referencing BSA 1970 and AMLA 2020 standards.
No material change for this persona this cycle
Internal audit scope for Illinois-licensed fantasy-contest operations should confirm how compliance with the Section 25-120.5(a) AML condition is documented and evidenced, given that this is a state licensing condition referencing federal standards rather than a distinct state-level audit regime.
A new Illinois state gaming licence now carries an explicit federal BSA/AMLA-2020 compliance condition.
Illinois built a digital-asset registration and enforcement perimeter (DACPA) without a confirmed AML-specific clause.
No material change this cycle.
Illinois is extending federal AML obliged-entity architecture into new state-licensed gaming and digital-asset verticals.
IDFPR's digital-asset registration architecture is compliance-technology-adjacent infrastructure with no confirmed AML overlay yet.
A new obliged-entity class (fantasy-contest licensees) has been created in Illinois with a federal-standards AML condition.
No material change this cycle.
A new state licensing condition references federal AML standards without a confirmed independent audit or reporting mechanism at the state level.
Illustrative orientation only: as the EU's Anti-Money Laundering Authority moves from purely national AML supervision toward direct and indirect supervision of cross-border obliged entities under the AMLA Regulation (Reg (EU) 2024/1620), alongside the directly-applicable AMLR (Reg (EU) 2024/1624) and per-Member-State transposition of the sixth AML Directive, one illustrative structural question is whether entities operating across multiple supervisory perimeters could exploit transition-period gaps between national and AMLA-level oversight. This is not observed in Illinois or any US jurisdiction this cycle; it is offered as architecture-over-incident orientation for how a hybrid supervisory regime could reshape evasion incentives generally, independent of any specific US-IL finding.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | Out of scope for this US-IL-bound dispatch. |
| T2 · EU AML Package / AMLA | no_change | Not applicable to US-IL (non-EEA jurisdiction). |
| T3 · FATF Grey List | no_change | Not applicable at the US-IL subnational level. |
| T4 · Beneficial-Ownership Register Status | no_change | No US-IL-specific development located; out of scope for this pass. |
| T5 · Crypto & Digital-Asset Integrity | watch | Illinois enacted DACPA (205 ILCS 731) and the Digital Asset Kiosk Act (205 ILCS 732), giving IDFPR registration/enforcement authority over digital-asset businesses and kiosks, plus a new Digital Asset Tax Act (0.2% privilege tax, effective 2027-01-01). No AML-specific provision independently confirmed this cycle. |
| T6 · Sanctions Regime Divergence | no_change | Not applicable at the US-IL subnational level. |