A virtual asset service provider (VASP) that operates without a documented, regulator-ready AML/CFT policy – an anti-money-laundering and counter-financing-of-terrorism program – is not merely exposed to a fine. It risks losing its banking relationships, triggering supervisory action across every jurisdiction where its users reside, and, in the worst case, criminal liability for its officers. With supervisors under the FATF Recommendations (the global AML/CFT standards issued by the Financial Action Task Force) tightening expectations for VASPs specifically, the gap between a paper policy and a genuinely operational one is narrowing fast. This guide walks through each step of drafting that policy – what each element must contain, the cross-border considerations that most internal teams miss, and the mistakes that reliably surface at examination.
Why VASP AML Policies Fail Examinations
Most AML/CFT policy failures at supervised VASPs share a common root: the policy describes a program that exists on paper but does not match the firm's actual activity, user base or technology stack. A regulator conducting a supervisory review – whether the FCA in the UK, MAS in Singapore, VARA in Dubai or a national competent authority under the MiCA regime in the EU – will cross-reference your written policy against your transaction records, your staffing, your vendor contracts and your onboarding flows. Inconsistency is treated as evidence of systemic weakness, not clerical error.
The second most common failure is jurisdictional tunnel vision. A VASP licensed in one hub routinely serves users, processes transactions or settles funds in others. Each additional jurisdiction layered onto the operating model may trigger separate AML/CFT obligations – sometimes under regimes with materially different thresholds, monitoring rules and reporting obligations. A policy drafted as if the business exists only in one country will not survive that scrutiny.
In our practice, we see this pattern particularly often when a VASP has scaled quickly: the compliance documentation was drafted at launch for a simpler model and was never updated to reflect new products, new jurisdictions or new counterparties.
Step 1: Map the Regulated Perimeter Before You Write a Single Clause
The first step in drafting an effective AML/CFT policy is establishing exactly which regulated activities your business conducts and in which jurisdictions – because those facts determine which legal obligations apply. This is not a compliance exercise. It is a legal analysis. A VASP offering exchange services, custody and fiat off-ramping across three jurisdictions may be subject to three separate AML supervisors, three sets of suspicious activity reporting obligations and three different thresholds for customer due diligence.
Begin by cataloguing every product or service the business offers. Map each product against the FATF Recommendation 15 definition of virtual asset activities: exchange, transfer, safekeeping, administration, participation in token offerings, financial services related to an issuer's offer. Then identify every jurisdiction where users are resident, where transactions settle, and where the legal entities sit. The intersection of those two maps is your regulated perimeter.
Cross-border note: a VASP passporting under MiCA from one EU member state to serve users across the EEA still must satisfy the AML/CFT rules of the host-state supervisor for local users. The passport covers the service authorisation; it does not collapse all AML obligations into one regime.
Common mistake at this step: listing only the jurisdiction of incorporation. If your servers are in one country, your banking is in a second and your largest user segment is in a third, your AML/CFT obligations extend across all three.
The analysis at Step 1 often reveals structural gaps that cannot be fixed by a better-written policy. If you are unsure which regimes apply to your model before you commit to a jurisdiction or product launch, map your options with OBOLUS at info@oboluslaw.com.
Step 2: Appoint an MLRO and Define Governance
Every supervised VASP must designate a Money Laundering Reporting Officer (MLRO) – a named individual with the authority, resources and seniority to execute the AML/CFT program and to make suspicious activity reporting decisions independently of business pressure. Most flagship regimes impose this as a baseline: the FCA requires it under the UK Money Laundering Regulations, MAS requires an equivalent compliance officer function, and VARA's rulebooks mandate a defined compliance framework with named responsibility.
The MLRO must be named, must have a documented mandate, and must have a direct reporting line to the board or a senior governing body. The policy should describe the governance structure explicitly: how the MLRO escalates to the board, how the board reviews AML/CFT performance, and how the firm documents those reviews.
The policy should also address deputy coverage. A solo MLRO with no deputy creates a continuity risk that some supervisors treat as a structural deficiency.
Cross-border note: some regimes require the MLRO to be locally resident or locally licensed. A group compliance officer sitting in a different jurisdiction may not satisfy that requirement. Operators we advise in multi-entity structures often need a locally qualified MLRO in each licensed entity, with the group function serving a coordination role.
Common mistake at this step: naming the MLRO in the policy but failing to document their authority in the corporate governance documents. A regulator can and will ask to see the board resolution or governance manual that formalises the appointment.
Step 3: Build a Risk-Based KYC Framework
A risk-based KYC framework (know-your-customer program) is the backbone of any VASP AML/CFT policy – it determines who the business onboards, what it collects to verify their identity, and how it calibrates the intensity of due diligence to the risk the customer presents. FATF Recommendation 10 and the FATF Virtual Assets guidance both require a risk-based approach: enhanced due diligence for higher-risk customers, simplified measures where the risk evidence supports them.
The policy should define the firm's customer risk methodology at a level of specificity a compliance analyst can apply without discretionary judgment. This means documented risk factors – geography, customer type, product used, source of funds, transaction size and pattern – and a scoring or tiering system that assigns each customer to a risk band.
For each risk band, the policy must specify: the minimum identity documentation required, the source-of-funds or source-of-wealth threshold, the frequency of periodic review, and the circumstances that trigger an escalation to enhanced due diligence.
Cross-border note: customer risk scoring must account for FATF-listed jurisdictions and EU high-risk third countries. A customer resident or transacting through a jurisdiction on either list triggers mandatory enhanced due diligence under most leading regimes – regardless of the customer's own apparent risk profile.
Common mistake at this step: using a generic KYC policy template that sets one threshold for all customers. A VASP serving institutional counterparties and retail users on the same platform faces materially different risk profiles for each segment. A single-tier approach will not satisfy an examiner – and it will not protect the business.
Step 4: Embed Travel Rule Compliance
The Travel Rule – the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data with every qualifying virtual asset transfer – is now an enforceable requirement in the major VASP hubs, and its absence from an AML/CFT policy is an immediate supervisory red flag. The policy must address how the firm collects, screens and transmits the required data, what it does when it receives a transfer from a counterparty VASP that cannot provide compliant data, and how it handles transfers to or from unhosted wallets.
The Travel Rule data set includes, at minimum: the originator's name, account number or wallet address, and – for transactions above the applicable threshold – address and identification number. Beneficiary data requirements mirror these. The policy should specify the firm's chosen Travel Rule solution and the technical protocol it uses to exchange data with counterparty VASPs.
Unhosted wallet policy is a discrete sub-section. Several regimes – including the FCA's current posture and the approach under MiCA – require enhanced due diligence or transaction monitoring when a customer transfers to or from a self-custodied wallet. The policy should describe how the firm verifies ownership of an unhosted wallet where required, and what risk controls apply when it cannot.
Cross-border note: Travel Rule thresholds differ by jurisdiction. The policy should map the firm's obligations jurisdiction by jurisdiction, because a transfer that falls below the threshold in one regime may exceed it in another leg of the same transaction. Operating under the lower threshold globally is the conservative and defensible approach.
Common mistake at this step: drafting the Travel Rule section in abstract terms without naming the firm's actual technical solution, the protocol it operates on, or the process for handling counterparty VASPs that are not yet Travel Rule-capable.
If your Travel Rule implementation does not yet match your written policy, that gap will surface at examination. For a scoped review of your compliance posture across the Travel Rule and KYC framework, contact OBOLUS at info@oboluslaw.com.
Step 5: Design the Transaction Monitoring Program
Transaction monitoring – the automated and manual review of customer activity against expected behavior and known typologies – is the operational core of an AML/CFT policy that regulators can actually test. The policy must specify the monitoring methodology, the rule sets or machine-learning parameters in use, the alert-review process, the escalation path and the documentation standard for closed alerts.
A credible transaction monitoring section includes: the categories of behavior that generate alerts (velocity, jurisdiction, counterparty type, mixing or obfuscation indicators, large round-number transactions, structuring patterns); the timeline for alert review; who reviews alerts and who can close them; and what happens when an alert cannot be resolved. On-chain forensic tools – using blockchain analytics platforms to assess counterparty wallet risk – are now a standard expectation in most leading regimes. The policy should describe how that tooling integrates with the alert workflow.
Cross-border note: some regulators in the EU and the Gulf require that transaction monitoring rules be reviewed and updated at defined intervals, with the review documented. A monitoring system calibrated at launch and never revisited is a liability in any supervisory examination.
Common mistake at this step: treating transaction monitoring as purely a technology question. The policy is the written evidence that the firm makes human decisions about the alerts the technology generates. If your alert-review process is not documented, the monitoring system provides no AML/CFT credit at examination.
A Compliance Gap – Identified Before the Examination
In a recent advisory matter, a payments-focused VASP with licensing across two EU member states approached us ahead of a scheduled supervisory review. Its written AML/CFT policy included a Travel Rule section, but the section described a counterparty-data exchange process that the firm's technical team had modified during a platform rebuild. The actual process in production differed materially from the policy in three respects: the threshold used, the unhosted-wallet verification step and the alert-closure timeline. We worked with the firm to conduct a policy-to-practice gap analysis, update the operative document and produce a board-level summary that evidenced supervisory engagement. The examination proceeded without a formal finding on the Travel Rule provisions.
Step 6: Establish Suspicious Activity Reporting and Record-Keeping
A complete AML/CFT policy closes with the internal and external reporting obligations – what the firm reports, to whom, on what timeline, and how it maintains the records that support those reports. The MLRO is the decision-maker for all suspicious activity reports (SARs). The policy should describe the internal escalation process: how a compliance analyst surfaces a concern, how the MLRO reviews it, and the standard for the decision to file or not file.
Record-keeping requirements vary by jurisdiction, but most leading regimes require retention of identity verification records, transaction records and internal AML/CFT decision files for a defined period after the end of a customer relationship. The policy should state the firm's retention standard and the storage format. Records that cannot be retrieved within a reasonable window during an examination are treated as records that do not exist.
Cross-border note: a multi-jurisdictional VASP must address reporting obligations in each jurisdiction where it is supervised. An SAR filed with the FCA does not satisfy an obligation to the FIU of another jurisdiction where the transaction has a nexus. The policy should identify each relevant financial intelligence unit and the applicable reporting threshold or trigger.
Common mistake at this step: omitting a tipping-off prohibition clause. Once an SAR is filed or under consideration, alerting the subject – or allowing staff to do so inadvertently – is a criminal offense in most jurisdictions. The policy must address how staff are instructed to handle customer inquiries that relate to a transaction under review.
A Common Assumption Challenged
A persistent belief among early-stage VASPs is that a single offshore licence is sufficient to serve clients globally, and that a policy compliant in that jurisdiction satisfies all AML/CFT obligations everywhere. It does not. Every jurisdiction in which a VASP has users, processes transactions or holds banking may impose its own AML/CFT obligations, reporting duties and supervisory jurisdiction. A policy that is internally consistent but silent on the regimes of other operating jurisdictions may pass examination in one country and trigger enforcement in another. The cross-border reality of digital asset business means that AML/CFT compliance is inherently multi-jurisdictional – and a policy written as if it were not is a structural liability.
Related at OBOLUS
- AML, Travel Rule and Compliance for Digital Asset Businesses – our full practice overview for VASPs navigating multi-jurisdictional AML obligations
- Custody Rules After Recent Exchange Failures – what current safeguarding and segregation expectations mean for your compliance posture
- Lithuania vs. United Kingdom – Where to License a Crypto Business – a comparative analysis for operators choosing between two leading EU-adjacent hubs
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect, verify and transmit originator and beneficiary identifying information alongside every qualifying virtual asset transfer. At minimum, this covers the originator's name, account or wallet identifier, and – above the applicable threshold, which varies by jurisdiction – address and national identification. The receiving VASP must be able to screen and retain this data. Transfers to or from unhosted wallets attract separate policy requirements in most leading regimes.
Who must act as MLRO for a crypto firm?
Most supervised regimes require the MLRO to be a named individual with seniority sufficient to make suspicious activity reporting decisions independently of commercial pressure. Under the FCA, MAS, VARA and comparable regimes, the MLRO must be formally appointed, must have a documented mandate and must report to the board or a senior governance body. Some jurisdictions require the MLRO to be locally resident. A group compliance officer in another country may not satisfy that local requirement for each licensed entity.
How do regulators audit crypto AML programs?
Supervisors typically audit VASP AML programs by cross-referencing the written policy against transaction records, staffing levels, vendor contracts and onboarding flows. They will test alert-review timelines, sample closed SAR decisions, review Travel Rule data exchange records and examine board-level AML/CFT governance minutes. A policy that describes controls the firm does not operationally run – or that was accurate at launch but not updated since – is the most common source of examination findings. Regulators in the EU, UK, Singapore and the UAE have all signaled increased examination intensity for VASPs.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule obligations that surround all of them. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit. To discuss your AML/CFT compliance posture, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in multi-jurisdictional AML/CFT policy design and supervisory engagement for VASPs across the EU, UAE, UK and Singapore.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.