Sanctions screening in the digital-asset context means checking every wallet address, counterparty identifier and transaction against government-published sanctions lists before allowing a transfer to proceed – and blocking or reporting any match. For a virtual asset service provider (VASP), the obligation is not optional. It sits at the intersection of anti-money laundering law, financial-crime compliance and, in most flagship jurisdictions, the specific licensing conditions under which a VASP operates. Failure to screen – or screening badly – exposes the business to regulatory enforcement, account closure by correspondent banks and, in the most serious cases, secondary sanctions liability.
This guide explains what the obligation requires, how it arises across major regimes, and where it intersects with licensing, the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) and AML compliance more broadly.
What Is Sanctions Screening and Why Does It Apply to Crypto?
Sanctions screening is the systematic comparison of a business's customers, wallet addresses and counterparty institutions against lists maintained by government authorities – including OFAC (the US Office of Foreign Assets Control), the EU Consolidated List, the UK Financial Sanctions Implementation Office (FSOI) list and the UN Security Council list. A match, or a close match, triggers a mandatory hold and a reporting obligation.
The application to digital assets is direct. When a VASP onboards a user, it collects identity information; that information must be screened. When a deposit or withdrawal is requested, the sending or receiving address must also be checked. The pseudonymous nature of blockchain transactions does not remove the obligation – it complicates the execution. A sanctioned person can control a wallet that has never been publicly linked to their identity. This is why address screening, using on-chain forensic tools, has become a distinct compliance function separate from standard know-your-customer (KYC) checks on identity documents.
As VASP supervision tightens across the major hubs, regulators no longer accept manual spot-checks. They expect automated, real-time screening against updated lists, with a documented escalation procedure for matches and a qualified officer accountable for the outcome.
What Is the Regulated Basis Across Major Regimes?
The obligation to screen derives from multiple overlapping legal sources depending on where a VASP is licensed or where it does business – and the cross-border reach of some regimes, particularly the US, means a firm does not need a US licence to face US sanctions exposure.
Under MiCA (the EU's Markets in Crypto-Assets Regulation), a CASP (crypto-asset service provider) authorised by a national competent authority, overseen at the level of ESMA, must comply with the AML directives and with EU financial-sanctions regulations. The CASP authorisation does not itself create a self-contained sanctions regime; it layers on top of the EU's existing AML and sanctions architecture. Passporting a MiCA authorisation across the EU/EEA brings the compliance programme into scope in every member state where users are served.
Under the VARA (Virtual Assets Regulatory Authority) regime in Dubai, VARA's rulebooks require VASPs to maintain sanctions-screening procedures that align with UAE sanctions law and with the CBUAE (Central Bank of the UAE) AML guidelines. The mainland Dubai scope of VARA is distinct from the DIFC financial free zone, which has its own regulatory environment – a structural point that catches operators who assume a single Dubai presence covers both.
In Singapore, the MAS (Monetary Authority of Singapore) expects Payment Services Act licensees carrying out digital payment token services to screen in line with MAS's guidelines on AML/CFT and with Singapore's sanctions framework. Singapore actively enforces both directions: it monitors whether VASPs are screening and whether they are acting on hits.
In the United Kingdom, the FCA's registration regime under the Money Laundering Regulations applies to cryptoasset businesses; the UK sanctions regime is administered separately by OFSI, but the practical obligation lands on the same compliance programme. UK-registered VASPs must screen against both.
Critically, US OFAC sanctions have extraterritorial reach. A VASP with no US operations, no US clients and no US licence can still face OFAC enforcement if it processes a transaction that touches US dollars, a US correspondent bank or a US person anywhere in the chain. This is the single most common misconception in our cross-border practice: operators assume territorial registration limits their exposure. It does not.
How Does Address Screening Actually Work in Practice?
Address screening in a VASP context goes beyond name-matching. It involves three distinct checks that must work in parallel.
The first is entity screening: comparing customer names and beneficial-owner information against sanctions lists at onboarding and at periodic re-screening. This is the closest analogy to traditional AML name-screening in banking. A VASP processes it through automated watchlist-matching software with a defined fuzzy-match threshold.
The second is wallet address screening: checking the specific blockchain address a customer is sending to or receiving from against published sanctions designations. OFAC has directly designated specific wallet addresses, making this a hard legal obligation for any business with potential US nexus, not a best-practice suggestion. Forensic platforms maintain address databases and update them continuously.
The third is transaction-path screening: assessing whether funds flowing through a transaction have passed through a sanctioned address at any point in their history. This is the most technically demanding check. It uses clustering analysis and risk-scoring to assign a risk profile to a transaction based on its on-chain provenance. The depth of this analysis – how many hops back in the chain the firm investigates – is a judgment call that varies by regulator and by the firm's own risk appetite.
In our cross-border practice, we regularly advise VASPs that are uncertain how deep their transaction-path analysis needs to go. The short answer is that the regulator's expectation is not uniform across jurisdictions, and the internal threshold a firm sets must be documented and defensible. A threshold that is systematically too low is, in a regulatory examination, evidence of a weak programme.
For a scoped assessment of your screening programme's defensibility across the jurisdictions where you operate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard model. Your entity structure, user geography and banking stack change the specific obligations and the examination risk.
Where Does the Travel Rule Intersect with Sanctions Screening?
The Travel Rule and sanctions screening are distinct obligations that operate on the same data. Understanding the intersection is essential for a VASP designing its compliance architecture.
The Travel Rule, rooted in FATF Recommendation 15 (virtual assets), requires a VASP to transmit originator and beneficiary information with a virtual asset transfer above the applicable threshold. That threshold varies by jurisdiction and is a [VERIFY] figure in each regime – write it qualitatively until cleared. What is clear is the principle: a VASP must know who is sending and who is receiving before it processes the transfer.
That same identity data – originator name, account number, geographic identifier, beneficiary name – is exactly the data a sanctions-screening check requires. A VASP that implements the Travel Rule correctly is, in theory, also generating the inputs for a real-time sanctions check on both ends of every transfer. In practice, the two systems are often built and managed separately, creating gaps: Travel Rule data arrives in one workflow, sanctions checks run in another, and a match generated in one system does not automatically halt the other.
Regulators, particularly VARA and MAS, increasingly treat the Travel Rule and sanctions screening as a single integrated obligation for cross-border transfers. A VASP that can demonstrate seamless data flow between its Travel Rule messaging protocol and its screening stack is in a materially stronger position in an examination than one that runs them independently.
The cross-border dimension here is pointed. A transfer from a MiCA-authorised CASP in Lithuania to a VARA-regulated VASP in Dubai crosses two Travel Rule regimes with different technical messaging standards and different sanctions list primaries (EU Consolidated and UAE sanctions). The receiving VASP must screen on its applicable list; the sending VASP must screen on its own before release. A gap in either direction creates exposure.
How Does KYC Relate to Sanctions Screening – and Why the Distinction Matters?
KYC and sanctions screening are complementary, not synonymous. Conflating them produces compliance programmes that satisfy neither obligation properly.
KYC (know your customer) refers to the identity-verification and customer-due-diligence process a VASP runs at onboarding and on a risk-adjusted ongoing basis. Its purpose is to establish who the customer is, assess their risk profile and determine whether the business relationship is appropriate. Under the FATF framework and under MiCA, VARA, MAS and other VASP regimes, KYC is a prerequisite to operating, but it is principally an AML tool.
Sanctions screening is a separate legal obligation with a binary outcome: a customer or counterparty is either on a list or they are not, and if they are, the firm has no legal discretion to proceed. KYC feeds sanctions screening – you cannot screen a name you have not collected – but passing KYC does not satisfy the sanctions obligation. A customer can complete full identity verification without appearing on any watchlist at the time of onboarding, then be designated by OFAC six months later. Continuous re-screening is what closes that gap.
We have seen firms in examination situations argue that their KYC programme functionally covered their sanctions obligation. Regulators treat this as a fundamental programme weakness, not a minor gap. The MLRO – the money laundering reporting officer, the named individual accountable for the firm's AML and sanctions programme – is expected to be able to explain, precisely and separately, how each obligation is met.
Who Is Accountable – and What Does That Mean for a Crypto Business?
Every VASP operating under a supervised AML regime must appoint an MLRO (money laundering reporting officer) with sufficient seniority, authority and resource to manage both the AML and the sanctions programme. The MLRO is personally accountable to the regulator and must be able to demonstrate that the programme is designed, implemented and tested.
For a digital-asset business, this creates specific challenges that do not arise in the same way for a traditional financial institution. The volume of transactions at even a mid-sized exchange can be orders of magnitude higher than at a comparable traditional payment firm. The technical complexity of on-chain screening – clustering, heuristics, multi-hop analysis – requires the MLRO to understand the forensic methodology well enough to brief the board and defend it to a regulator.
Across the jurisdictions we advise in, regulators have been explicit that appointing an MLRO without the technical resource to support them is not a compliant arrangement. VARA's rulebooks require the VASP to ensure the MLRO has adequate staff and systems. MAS takes a similar position. An MLRO managing sanctions screening manually across a live exchange is, by definition, a regulatory risk.
The MLRO's accountability also extends to the transaction-monitoring system. Where a firm uses automated rules to flag transactions for review, the MLRO must be able to explain why the rules are set at the thresholds they are, what the false-positive rate is and how alerts are investigated. In our practice, we regularly see firms that have bought a compliance platform but have not properly documented the calibration decisions. That documentation gap becomes the finding in a regulatory examination.
If your sanctions or AML programme has been flagged by a regulator, or if a banking partner has raised concerns about your programme, contact OBOLUS at info@oboluslaw.com. A second read of the programme often surfaces the structural reason and the route to resolution.
What Makes the Cross-Border Dimension Uniquely Complex for Crypto VASPs?
For a business sitting between two licensing regimes – say, a MiCA-authorised CASP serving EU users from an entity also licensed under VARA in Dubai – the sanctions obligation is not additive in a simple sense. It is jurisdictionally layered in ways that can produce operational contradictions.
Consider the scenario: EU sanctions law designates a counterparty that is not on the UAE sanctions list. The EU entity must block a transfer; the UAE entity has no independent obligation to do so, and may in fact have a contractual obligation to its customer to process it. This is not an edge case. The EU and UAE sanctions regimes are maintained independently, and divergences exist.
The practical answer is that the group-level compliance programme should apply the most restrictive applicable standard – in our practice, this is the architecture we advise for any multi-entity VASP group. The commercial cost of over-screening is lower than the legal cost of under-screening against a stricter regime's list. But documenting that policy decision, and building the operational workflow to implement it, requires deliberate design.
US OFAC exposure adds a further layer. Because OFAC's sanctions have secondary effects that reach transactions touching the US financial system, a VASP group that holds USD accounts, settles in USDT or USDC (where US-regulated issuers Tether and Circle hold freeze authority over their tokens and generally act on OFAC designations), or processes transactions through US correspondent banking, carries a US sanctions exposure regardless of where it is licensed. The OFAC list must be part of every VASP's screening stack if any of those conditions apply – which, for any significant exchange, they almost certainly do.
In a recent cross-border compliance matter, a custodian operating across two jurisdictions had built separate screening stacks for each entity that did not share a common sanctions-hit escalation procedure. When a counterparty was designated mid-settlement, the two entities handled the hit differently, creating a reporting inconsistency that complicated the subsequent regulatory notification. We assisted in harmonising the group's escalation architecture and drafting the notification to both regulators. The outcome was a corrective action plan rather than an enforcement referral – in part because the gap was identified and addressed proactively.
Does a Sanctions Screening Failure Trigger a Licensing Problem?
A sanctions screening failure can become a licensing problem, a banking problem and a disputes problem simultaneously. These are not separate legal questions; they escalate in sequence, and each stage closes options available at the prior stage.
At the licensing level: a VASP's licence conditions, in virtually every major regime, require the firm to maintain an adequate AML and sanctions programme. A material failure – one that resulted in transactions with a sanctioned party, or that demonstrates systematic weakness in the programme – gives the regulator grounds to impose conditions, suspend the licence or, in serious cases, revoke it. VARA, MAS and the FCA have all used their enforcement powers in this direction across the broader financial-services sector. The crypto-specific enforcement record is building.
At the banking level: correspondent banks and banking partners conduct their own AML due diligence on VASPs. They review the quality of the VASP's sanctions programme as part of that process. A programme that cannot demonstrate real-time address screening, documented escalation and a qualified MLRO will not pass a tier-one bank's counterparty review. For VASPs operating in markets where correspondent banking for crypto is already scarce, a programme deficiency that closes the remaining banking relationship is a near-existential risk.
At the disputes level: if a sanctions failure results in funds being frozen by an issuer or by a correspondent bank, the VASP may face customer claims for wrongful blocking, and may simultaneously face regulatory demands for records and explanations. The firm sits between two sets of obligations that can pull in opposite directions. Resolving that position requires counsel who can work across the regulatory, contractual and disputes dimensions at the same time.
A common assumption in the market is that a single offshore licence is sufficient to manage global compliance exposure. It is not. Offshore registration in a jurisdiction with a lighter-touch AML regime does not insulate a VASP from OFAC secondary sanctions, from MiCA obligations if EU users are served, or from the expectations of US or European banking partners who apply their own AML standards to the VASP's programme. Licensing strategy and compliance programme design must be built together, not sequentially.
What Does a Defensible Sanctions Screening Programme Look Like?
A defensible programme has five recognisable components, each of which a regulator will probe in examination.
First, a policy document that states the firm's sanctions obligations by jurisdiction, the lists screened, the frequency of re-screening, and the escalation procedure for matches. This document must be board-approved and reviewed at least annually.
Second, a screening system that operates in real time for transactions, updates list data continuously, and applies a documented match-sensitivity threshold. The sensitivity setting is a compliance decision, not a vendor default – and it must be documented as such.
Third, an alert-management workflow with defined investigation steps, documented outcomes and a retention policy for records. Regulators want to see that alerts were investigated, not merely closed.
Fourth, a transaction-monitoring system calibrated to the firm's specific risk profile – product mix, user geography, transaction volumes – with documented tuning decisions and regular effectiveness testing.
Fifth, an MLRO who understands all of the above and can explain each component to a regulator at examination without referring to a vendor's marketing materials. Technical competence in the MLRO role is increasingly what separates firms that resolve examinations smoothly from those that receive enforcement referrals.
We map this programme architecture against the specific requirements of each jurisdiction where a client operates. The cross-border layer – which list is primary, how Travel Rule data feeds screening, how group escalation is structured – is where programme design becomes genuinely complex, and where generic compliance tooling is insufficient.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – our practice overview covering the full AML and Travel Rule compliance lifecycle
- Regulator AML audit defence for digital-asset firms – legal counsel when a regulator reviews or challenges your AML programme
- VARA licence application under heightened scrutiny – the specific licensing and compliance requirements under the VARA regime in Dubai
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, rooted in FATF Recommendation 15 on virtual assets, requires a VASP to collect and transmit originator and beneficiary identifying information with a virtual asset transfer above the applicable threshold. The threshold varies by jurisdiction and should be confirmed against current local legislation. Receiving VASPs must verify the data received. The obligation applies to both the sending and the receiving side of a transfer, and non-compliance is an AML regulatory breach in every major licensed regime.
Who must act as MLRO for a crypto firm?
A crypto firm operating under a supervised AML regime must appoint a money laundering reporting officer (MLRO) who is sufficiently senior, has direct board access and commands adequate staff and technical resource to manage both the AML and the sanctions programme. The MLRO is personally accountable to the regulator. In most licensed jurisdictions – including under MiCA, the VARA regime and the MAS Payment Services Act framework – the MLRO appointment is a licence condition, and regulators vet the candidate's competence during the authorisation process.
How do regulators audit crypto AML programs?
Regulators typically audit a VASP's AML programme through a combination of documentation requests, management interviews and transaction sample reviews. They examine the policy framework, the screening-system configuration, alert-management records, MLRO reports and board minutes. On-chain forensic capacity – the firm's ability to explain the provenance of flagged transactions – has become a specific examination focus across VARA, MAS and FCA reviews. A programme that relies on a vendor platform but cannot explain the platform's methodology in its own terms is a recurring examination weakness.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, sanctions and Travel Rule compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack and the compliance programme architecture across operating, custody and payment layers before you commit. For clients who have encountered regulatory friction, we provide AML audit defence and programme remediation across the major hubs. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in sanctions screening programme design, AML regime compliance and Travel Rule implementation for digital-asset businesses across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.