Loading market data...

UK's IRGC Terror Designation Still a Crypto Compliance Headache Three Years On

UK's IRGC Terror Designation Still a Crypto Compliance Headache Three Years On

The UK's designation of Iran's Islamic Revolutionary Guard Corps (IRGC) as a terrorist organization took effect three years ago this week, but the law's broad language covering crypto assets remains a live concern for exchanges and wallet providers. Under Section 17C(1) of the National Security Act 2023, obtaining, accepting, or retaining a qualifying material benefit from a designated body like the IRGC carries a maximum sentence of 14 years in prison. The offense applies when a person knows, or ought reasonably to know, that the benefit came from a designated body.

What the law covers

The law's wording is broad enough to cover crypto assets, including stablecoins and on-chain transfers, as it covers money or anything of value supplied directly or indirectly. A Schedule 6A designation does not automatically trigger asset freezes or dealing restrictions — those require separate action under UK sanctions. Section 17C(2) covers agreeing to obtain, accept, or retain a benefit, carrying up to 10 years in prison. Section 17B covers conduct intended or likely to materially assist a designated body in UK-related activities, with separate elements from Section 17C.

On-chain timing problems

On-chain settlement creates timing challenges that traditional finance doesn't face. A deposit can settle before the recipient has reliable identity of the sending wallet, and attribution may occur later. The Office of Financial Sanctions Implementation's cryptoassets threat assessment notes that crypto firms cannot reject incoming blockchain transactions and that addresses may be attributed later. That means a firm could unknowingly hold funds from an IRGC-linked wallet for hours or days before realizing it — and by then, the offense of retaining a benefit may already have been committed.

Exclusions and gray areas

Exclusions exist for reasonable consideration for goods or services, reasonable excuses, legal obligations, public functions, and humanitarian activities consistent with international principles. But the burden falls on the recipient to prove they fall into one of those categories. For a crypto exchange processing thousands of transactions a day, proving that every incoming deposit came from a legitimate source is a tall order.

What firms are up against

The law doesn't require intent — it's enough that the recipient ought reasonably to have known the benefit came from a designated body. That's a negligence standard. Combined with the inability to reject incoming blockchain transactions, firms face a compliance gap that no amount of KYC checks can fully close. Three years in, the technical and legal questions around how OFSI will enforce this provision remain unanswered.