EST · MMXXVI
Home/Insights/Disputes/MLRO and compliance officer function: Where the Legal Lines Are Drawn
Compliance, AML & Travel Rule

MLRO and compliance officer function: Where the Legal Lines Are Drawn

Mlro and compliance officer function: Where the Legal Lines Are Drawn. Cross-border digital-asset legal counsel for business – licensing, disputes and structuri

The Money Laundering Reporting Officer (MLRO) and compliance officer functions sit at the intersection of regulatory obligation, personal liability and operational design. For a digital-asset firm, misreading the boundary between the two roles is not a procedural inconvenience – it is a direct path to enforcement, deregistration and, in serious cases, personal criminal exposure for the individuals who hold those titles. As regulators across the major hubs tighten supervision of virtual asset service providers (VASPs), the question of who is accountable for what inside the compliance function has become one of the most consequential decisions a founding team or general counsel can make.

This analysis draws the legal lines clearly. It covers the regulatory basis for each function, the personal liability that attaches to each role, how the split plays out across the leading licensing regimes, and what a multi-jurisdiction operator must do when its compliance architecture spans more than one regulatory perimeter. A decision matrix and one anonymized micro-matter are included to ground the analysis in practice.

Two Functions, One Persistent Confusion

The MLRO and the compliance officer are legally distinct roles, even when a single individual is appointed to both. The MLRO is the statutory gatekeeper for suspicious activity: the function exists specifically because AML legislation in every FATF-aligned jurisdiction requires a named officer to receive internal suspicion reports, assess them and determine whether to make an external disclosure to the financial intelligence unit. The compliance officer function is broader – it covers the design, implementation and oversight of the entire regulatory compliance programme, of which AML is only one component.

Conflating the two creates structural risk. When a firm treats them as a single job description, the nuance of each accountability disappears. The MLRO's obligation is quasi-prosecutorial in character: a failure to file a suspicious activity report when the threshold is met is a criminal offence in most jurisdictions, and the personal liability is non-delegable. The compliance officer's accountability is managerial and regulatory: a failure of the compliance programme exposes the firm and, depending on the regime, the individual, to administrative sanctions. Both matter. The legal consequences of getting either wrong differ materially from each other.

In our cross-border practice, we consistently see firms in early licensing cycles treat the MLRO appointment as a checkbox and the compliance officer role as an extension of the legal team. Regulators – including the FCA, VARA and MAS – have made clear that both positions require substantive, demonstrable independence and competence. A name on a form is not enough.

What Is the Regulatory Basis Across the Leading Regimes?

Every major licensing regime for digital-asset businesses requires a named individual to own the AML function, though the title and the scope of that requirement vary across regulators. Under MiCA and the underlying national AML transpositions that continue to apply to CASPs (crypto-asset service providers), EU member states require a designated officer who holds personal responsibility for suspicious transaction reporting. The FCA's Money Laundering Regulations require every registered cryptoasset business to appoint a nominated officer – the functional equivalent of an MLRO – with clear reporting lines to senior management. VARA in Dubai mandates a dedicated MLRO as part of its governance requirements across its activity-based licence categories, and that officer must satisfy VARA's own fit-and-proper criteria independently of any compliance officer appointment.

MAS in Singapore, under the Payment Services Act, similarly requires that a Major Payment Institution licensee (the tier relevant to larger VASP operations) maintain a robust AML/CFT function with a named officer. The SFC in Hong Kong applies equivalent expectations under its VASP licensing regime. In the AIFC, the AFSA has adopted FATF Recommendation 15 as the baseline for its digital-asset framework, meaning any firm licensed there must maintain an AML compliance function that meets international standards, including a named officer with reporting authority.

The FINMA framework in Switzerland distinguishes between the compliance function within a licensed bank or fintech licence holder and the AML compliance obligations that arise from SRO membership. This dual structure – regulatory compliance plus self-regulatory body obligations – is a practical reason why Swiss-licensed digital-asset firms often carry two separate individuals in these roles even when the firm is small.

What is common across all of these regimes is a structural expectation: the AML reporting function must be sufficiently independent to escalate without being blocked by commercial pressure. That principle is the legal foundation on which the MLRO's personal accountability is built.

For a scoped assessment of how your compliance architecture maps to the regime you operate under, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base and the jurisdictions where your clients sit – change the analysis materially.

Personal Liability: Where Does It Attach?

The personal liability of an MLRO is narrower in scope but sharper in consequence than the personal liability of a compliance officer. An MLRO who receives an internal suspicion report, forms a reasonable ground to suspect money laundering or terrorist financing and then fails to make an external disclosure commits an offence under the applicable AML legislation in virtually every FATF-aligned jurisdiction. That obligation does not pass to the board, the CEO or the firm's legal team. It sits with the named individual. Authorised consent – the process by which the MLRO seeks clearance from the relevant financial intelligence unit before proceeding with a transaction – is similarly personal. Neither the firm's commercial interests nor a senior executive's instruction provides a defence.

The compliance officer's personal exposure is more diffuse but increasingly real. Regulators in the FCA perimeter have taken action against compliance officers personally where the compliance programme failed to meet minimum standards and the officer was found to have been either negligent or complicit in the failure. VARA's governance framework includes the concept of approved persons, meaning individuals in key compliance roles can be the direct subject of regulatory proceedings independent of any action taken against the firm. MAS has moved in the same direction – accountability for key compliance roles has shifted from the firm to the individual over successive rounds of Payment Services Act guidance.

The practical difference: the MLRO can be criminally liable for a single act of non-disclosure; the compliance officer is more typically exposed to administrative sanctions, removal and prohibition through regulatory proceedings. Both are serious. Neither exposure is absorbed by D&O insurance in its standard form – most policies exclude regulatory proceedings and deliberate acts, and the failure to file a suspicious activity report is exactly the kind of deliberate act that insurers will contest.

How Does the Travel Rule Interact With These Roles?

The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary data with every qualifying virtual asset transfer – sits squarely inside the compliance officer's programme design responsibility, but it generates MLRO-relevant events. When a VASP receives a transfer where the accompanying data is absent, incomplete or inconsistent with what transaction monitoring reveals about the counterparty, that discrepancy can itself constitute a red flag requiring the MLRO's assessment.

In our advisory work, the Travel Rule is the single most common source of friction between the compliance officer's system design decisions and the MLRO's day-to-day escalation load. A compliance programme that sets aggressive thresholds for flagging incomplete Travel Rule data will generate a high volume of internal suspicion reports. An MLRO who has not been involved in calibrating those thresholds will inherit a workload that may be unmanageable – and the risk that a genuine suspicion is buried in a volume of technical-compliance flags.

The cross-border dimension sharpens this tension. A VASP operating across the EU, the UAE and Singapore is subject to three distinct Travel Rule regimes with potentially different data requirements and different de-minimis thresholds. The compliance officer must design a system that satisfies all three simultaneously. The MLRO must be equipped to assess suspicion reports that arise from any one of those contexts. Where the firm has entities in multiple jurisdictions, each licensed entity may require its own MLRO appointment – meaning the firm could operate several named MLROs who need to communicate with each other without triggering tipping-off restrictions.

Operators we advise regularly underestimate this multi-MLRO coordination problem. It is not solved by a group compliance policy. It requires a documented escalation protocol that is reviewed by counsel in each relevant jurisdiction.

Decision Matrix: Which Profile Needs What Architecture?

Different operator profiles face different structural pressures on the MLRO and compliance officer functions. The right architecture depends on the regulatory perimeter, the transaction volume and the degree of cross-border exposure.

Profile A – Single-Jurisdiction Startup (EU CASP Applicant). A firm applying for CASP authorisation under MiCA in a single member state, serving users only within the EU, can operate with a single MLRO and a single compliance officer. The roles may be held by the same individual at early stage if the regulator in the home member state permits it – several NCAs do so for small entities on a transitional basis. The key risk is that the dual-role individual must have the independence and the bandwidth to perform both functions genuinely. Regulators are increasingly testing this through supervisory interviews. Timeline to demonstrate a functioning compliance framework: typically several months from initial appointment, with documented evidence of the programme being operational before authorisation is granted.

Profile B – Multi-Jurisdiction Exchange (VARA + MAS + FCA). A firm operating exchange services under VARA in Dubai, licensed under MAS in Singapore and registered with the FCA in the UK faces three distinct regulatory perimeters. Each will expect a named officer with accountability to that regulator. The firm needs a group compliance architecture – a group CCO who sets the programme – and named MLROs (or functional equivalents) for each regulated entity. The MLRO positions cannot be filled by a single individual sitting offshore relative to the regulated entity; regulators expect local accessibility. Key risk: the Travel Rule data exchange between the three entities triggers intra-group information sharing that must be structured to avoid tipping-off violations across jurisdictions.

Profile C – Institutional Custodian (ADGM + Cayman). A custodian licensed by the FSRA in ADGM and registered under the Cayman VASP framework operates in a different risk environment. Custody clients tend to be institutional; transaction volumes may be lower but individual transaction sizes are significant. The compliance officer function here needs to be heavily focused on counterparty due diligence and risk-appetite calibration rather than high-volume transaction monitoring. The MLRO's role is less about managing alert volume and more about exercising judgment on complex, high-value relationships. The risk of inadequate onboarding documentation in this profile is existential – a single large relationship that fails enhanced due diligence, discovered retrospectively, can trigger supervisory intervention by the FSRA with immediate consequences for the licence.

The MLRO in a DeFi-Adjacent Business: Does the Obligation Still Apply?

DeFi-adjacent structures do not automatically escape MLRO obligations, and regulators are actively closing the interpretive gap. The question turns on whether the business qualifies as a VASP under the applicable regime. A firm that maintains a front-end, controls smart contracts with administrative keys, operates a fee structure or performs token custody functions will typically be found to be conducting regulated virtual-asset activities regardless of the degree of on-chain automation in the underlying protocol.

ESMA and FATF guidance have both moved in the direction of substance over form: if a legal entity controls a material aspect of a service that delivers virtual-asset functions to users, that entity is likely a VASP and the MLRO obligation attaches. The fact that the settlement layer is decentralised does not relocate the AML accountability. Operators we advise in this space are increasingly told by their own boards that they need a clear regulatory opinion before launch, not after the first enforcement letter.

The compliance officer function in a DeFi-adjacent business faces a distinct design challenge. Traditional KYC (know-your-customer) frameworks assume an account relationship with a clearly identified user. Where users interact through non-custodial wallets, the compliance officer must design a system that can attribute on-chain activity to an identified person at the points where the business controls the interface. This is technically complex and, in several jurisdictions, the approach has not yet been finalised by the regulator. It is an area where the compliance officer needs to work closely with both the MLRO and technical counsel from the outset.

Micro-Matter: Cross-Border Escalation Failure

In a recent matter, a payments firm licensed in two jurisdictions discovered that its MLRO for the EU entity and the compliance officer for its MENA-region entity had each received separate intelligence about the same counterparty, through different channels, but had not shared that information. The EU MLRO had made an internal assessment and determined no disclosure was required based on the partial picture available. The MENA compliance officer had flagged the counterparty for enhanced due diligence but had not treated the matter as a suspicion event at all. When the counterparty was subsequently identified by a financial intelligence unit in a third country as linked to a sanctions evasion scheme, both entities faced supervisory enquiries. We were instructed to map the information flows, assess the tipping-off exposure and restructure the inter-entity escalation protocol. The matter resolved without enforcement, but the compliance programme required a full rebuild – a process that took several months and consumed significant management attention during a critical growth phase.

The lesson is structural, not personal: the failure was not the result of bad judgment by either individual. It was the predictable consequence of a multi-entity architecture where the MLRO and compliance officer functions had been designed independently for each entity without a documented group-level escalation protocol. The rebuild that followed should have been the design before the licences were granted.

What Do Regulators Actually Audit, and How?

Supervisory audits of AML and compliance programmes have become substantially more sophisticated across the leading digital-asset hubs. Regulators are no longer satisfied with reviewing policy documents. The FCA, VARA and MAS have all published supervisory expectations that make clear the audit will test whether the programme is operational, not just documented.

A typical audit examines the MLRO's suspicious activity report log: the volume of internal reports received, the MLRO's documented reasoning for each decision to file or not file, and the time elapsed between receipt of an internal report and the MLRO's decision. Where that log shows a pattern of blanket non-disclosure or excessively long decision times, the regulator will probe whether the MLRO is genuinely independent and adequately resourced. Regulators we have seen in action also test the MLRO's knowledge of the firm's actual transaction flows – not just the theoretical risk assessment in the programme documentation.

For the compliance officer, the audit typically reviews the transaction monitoring system: the calibration of rules and thresholds, the alert disposition process, the training records and the KYC framework's performance on high-risk categories. Under VARA's examination process, firms are expected to demonstrate that their transaction monitoring rules were designed by a qualified person and reviewed at least annually, with documented justification for any changes to thresholds. MAS has made similar expectations explicit in its AML/CFT guidelines for DPT service providers.

A common mistake we observe is the firm that passes its own internal audit but fails the regulatory one. Internal audits frequently test conformity with the written programme. Regulatory audits test whether the programme reflects reality. The gap between the two is where enforcement actions originate.

If a prior regulatory review identified gaps in your MLRO or compliance programme, a second structural analysis can often identify the root cause and the path forward. Contact OBOLUS at info@oboluslaw.com to discuss. If an application stalled or a supervisory letter arrived, the structural reason is usually findable – and fixable with the right approach.

Objection Handler: "One Licence Covers Our Compliance Needs"

A common assumption among operators entering the digital-asset space is that obtaining a licence in a single jurisdiction – often an offshore or lower-cost registry – discharges the compliance obligation for all the business the firm conducts globally. This is incorrect, and acting on it is one of the more reliable routes to enforcement.

The compliance and MLRO obligations attach where regulated activity occurs, not solely where the licence is held. A firm licensed in the BVI that actively markets to users in the EU, processes payments through a UK account and employs compliance staff in the UAE is, on any fair reading of the applicable regimes, conducting regulated activity in multiple perimeters. Each of those regulators applies its own AML standards to firms that operate within its perimeter. The BVI registration does not insulate the firm from FCA AML obligations if FCA-regulated activity is being conducted, nor from VARA obligations if a Dubai nexus exists.

The cross-border reality of digital-asset business means that the licence and the compliance programme are not the same thing. The licence determines who regulates the firm. The compliance programme must cover the totality of where the firm operates and where its users are. For a multi-jurisdictional operator, those two perimeters are rarely congruent. We map the full compliance perimeter for clients before they commit to an entity structure, because the cost of discovering the mismatch post-launch is multiples of the cost of designing it correctly at the outset.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect, verify and transmit originator and beneficiary information with each qualifying virtual-asset transfer. The data typically includes the full name, account identifier and, in some regimes, the address of both parties. The obligation applies to both the sending and receiving VASP. Where the receiving entity is unhosted or unregulated, enhanced due diligence and risk-based measures apply in most leading regimes. Thresholds and technical standards vary by jurisdiction and should be confirmed under current local legislation.

Who must act as MLRO for a crypto firm?

The MLRO must be a natural person with sufficient seniority, independence and expertise to assess internal suspicion reports and make disclosure decisions without commercial interference. Most major regulators – including the FCA, VARA and MAS – require the MLRO to meet a fit-and-proper standard and, in several regimes, to be individually approved by the regulator. The role cannot be held by an external consultant without the regulator's explicit acceptance of that arrangement. A firm operating multiple licensed entities typically needs a named MLRO for each regulated entity, not one group officer.

How do regulators audit crypto AML programs?

Regulatory audits examine both documentation and operational reality. Auditors typically review the MLRO's suspicious activity report log – the volume of internal reports, the documented reasoning for each disclosure decision, and the time from receipt to decision. For the compliance programme, they assess transaction monitoring calibration, KYC framework performance, training records and the audit trail of threshold reviews. Leading regulators including VARA and MAS have published explicit expectations: they test whether the programme reflects actual transaction flows, not just policy documents. Internal audit passes do not predict regulatory audit outcomes.

OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the compliance, AML and Travel Rule programmes that regulators increasingly test as closely as they test the licence itself. We map the licence stack, the compliance architecture and the banking and tax layer as a single mandate – not three disconnected workstreams. Operators we work with have found that integrating these analyses before commitment consistently produces a more defensible structure. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specialist in enforcement-facing compliance review, cross-border MLRO accountability analysis and AML programme restructuring for digital-asset businesses under supervisory pressure.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours