EST · MMXXVI
Home/Insights/Guides/How to Prepare for a Regulator AML Audit
Compliance, AML & Travel Rule

How to Prepare for a Regulator AML Audit

How to Prepare for a Regulator AML Audit. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business without a well-documented AML program is not merely a compliance gap. It is an invitation for enforcement action, frozen correspondent-banking rails and, in the worst case, licence revocation. Regulators across the major hubs – from the FCA under the UK Money Laundering Regulations to MAS under Singapore's Payment Services Act to VARA in Dubai – are deepening their supervisory cycles for virtual asset service providers. An audit visit can arrive with limited notice. How you have prepared in the preceding months determines whether the outcome is a clean bill of health or a remediation order.

This guide sets out the concrete steps a VASP (virtual asset service provider) should take before a regulator arrives. Each step identifies the regulated basis, the cross-border complication, and the most common mistake at that stage. Read sequentially for a preparation project plan, or jump to the section that matches your most urgent gap.

Step 1: Understand What Regulators Examine in a VASP AML Audit

Regulators conduct a VASP AML audit by testing four interlocking elements: the written policy framework, its live implementation, the competence of the people responsible, and the documented evidence that the first three actually connect. A firm that has excellent policies but cannot produce evidence of their operation will fare poorly. Auditors at the FCA, MAS, and VARA each follow a variant of the FATF Recommendations – in particular, FATF Recommendation 15, which brings virtual asset activities within the core AML/CFT perimeter – meaning the substantive questions are consistent across jurisdictions even when the procedural formalities differ.

The examination typically spans: the business-wide risk assessment, customer due-diligence records, transaction monitoring logs and escalation trails, Travel Rule data flows, sanctions screening evidence, MLRO reports to senior management, and training records. Gaps in any one of these feeds into the overall supervisory rating. In our cross-border practice, we have seen firms arrive at an audit with strong onboarding procedures but near-absent documentation of their ongoing monitoring decisions – and that imbalance shapes the entire supervisory conversation that follows.

Cross-border note: if your entity holds licences in multiple jurisdictions, each regulator will assess compliance against its own standards. A clean MAS audit does not insulate you from FCA findings on the same underlying program. Structure your evidence accordingly.

Step 2: Complete and Update Your Business-Wide Risk Assessment

The business-wide risk assessment (BWRA) is the document from which every other AML control is expected to flow, and it is typically the first item a regulator requests. An outdated or generic BWRA signals to an examiner that the downstream controls were not risk-based either. Under the applicable provisions of every major regime – MiCA's CASP obligations, the VARA rulebooks, the FCA's MLR expectations – the BWRA must reflect the actual products, customer segments, channels and geographies the firm operates.

In practical terms, the BWRA should identify the specific risks associated with pseudonymous on-chain transactions, cross-border fund flows, DeFi product interfaces where applicable, and any higher-risk customer categories (politically exposed persons, correspondent relationships with unregulated entities, jurisdictions on FATF's enhanced-scrutiny lists). The document must be dated, version-controlled, and signed off at board level.

Common mistake: firms treat the BWRA as a one-time exercise completed at licence application and never revisit it. A regulator who sees a BWRA dated two or three years prior – with no annotation for product changes, new geographies, or updated FATF guidance – will treat the entire risk program as stale. Build a calendar review into your governance cycle, at minimum annually or after any material change to the business model.

Cross-border note: if your firm serves customers across multiple jurisdictions, the BWRA must capture jurisdiction-specific risk factors. A Lithuanian CASP passporting into other EU member states under MiCA will face questions about how it has calibrated risk for the full distribution footprint, not just the home-state customer base.

Step 3: Audit Your KYC and CDD Records Before the Regulator Does

Running an internal audit of your customer due-diligence files before the regulatory examination is the single most effective preparation step you can take. A regulator conducting a CDD file review will pull a sample – often stratified by risk tier – and test whether the KYC framework (the set of policies, procedures and controls governing know-your-customer checks) produces records that match the risk rating assigned to each customer. Discrepancies between the stated policy and the actual file content are treated as systemic failures, not individual errors.

The internal review should confirm: that identity verification documents are present and unexpired; that the source of funds or wealth documentation matches the risk tier; that enhanced due diligence has been conducted and documented for every customer in the higher-risk category; and that periodic reviews have been completed on schedule. Where records are missing or incomplete, remediate before the examination – and document the remediation itself.

Common mistake: firms conflate onboarding approval with an open-ended licence to transact. A customer who passed onboarding three years ago but whose risk profile has materially changed – through adverse media, sanctions designations or changes in transaction pattern – and whose file shows no refresh, represents exactly the gap a skilled examiner will identify first.

Prepare a remediation log: when internal review surfaces a file deficiency, record the date of discovery, the gap, the action taken and the person responsible. That log itself demonstrates a functioning control environment.

Step 4: Test Your Transaction Monitoring Coverage and Alert Escalation

Transaction monitoring (the automated and manual process of identifying unusual or suspicious patterns in customer activity) is the operational core of any VASP AML program, and it receives close attention in every supervisory examination. The question regulators ask is not simply whether a monitoring system is in place, but whether its rules and thresholds are calibrated to the firm's actual risk profile and whether the alert-to-escalation pipeline produces documented, defensible decisions.

Before an audit, run a retrospective review of your alert history: How many alerts fired over the preceding period? What proportion were reviewed within your stated SLA? How many escalated to a suspicious activity report (SAR) or similar report to the financial intelligence unit? Where alerts were closed without escalation, is there a documented rationale? Regulators in Singapore (MAS), the UK (FCA) and under the VARA regime in Dubai have all indicated publicly that inadequate SAR filing rates – relative to the volume and risk profile of a business – are a supervisory concern.

Cross-border note: SAR filing obligations, thresholds and the identity of the receiving financial intelligence unit differ by jurisdiction. A firm operating in both the UK and a MENA hub must maintain parallel reporting pipelines. Merging or confusing them is a common operational failure.

Common mistake: treating transaction monitoring as a technology problem rather than a governance problem. A well-configured system with no documented human review of alert disposals – or with rules that have never been back-tested against actual typologies – will not satisfy an examiner asking for evidence of effective oversight.

For a scoped assessment of your transaction monitoring posture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard review path. Your entity type, product mix, and jurisdictional footprint change the analysis – and a gap identified before the regulator arrives is a gap you control.

Step 5: Verify Your Travel Rule Compliance and Data Architecture

The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual asset transfer, derived from FATF Recommendation 16) is now an active supervisory flashpoint across the leading licensing hubs. Under MiCA, the applicable EU Transfer of Funds Regulation applies to CASPs. Under the VARA rulebooks, Travel Rule obligations are explicit. FCA and MAS-regulated VASPs must demonstrate compliant data collection and transmission.

Audit preparation in this area requires three things. First, map every transfer flow: which transfers are in scope, what data is collected at origination, and what mechanism transmits that data to the beneficiary VASP. Second, test your counterparty VASP screening: do you have a process to verify that the counterparty is itself a regulated VASP before transmission? Third, document your handling of unhosted-wallet transfers. Each regime has a distinct approach to transfers from self-hosted addresses; the evidentiary standard you apply to those flows needs to be documented and defensible.

Common mistake: firms implement a Travel Rule solution at the technical level but never test whether the data actually reaches the counterparty in the format required, or whether their policy document describes what the system actually does. The gap between the written procedure and the live data flow is the gap an auditor will find.

Cross-border note: if your firm transacts with counterparty VASPs in jurisdictions that have not yet implemented the Travel Rule, you need a documented policy for those relationships. Blanket application of your highest-standard protocol to all transfers is the most defensible posture; any deviation requires a rationale on file.

Step 6: Confirm MLRO Competence and Senior Management Governance

Every licensed VASP must designate a Money Laundering Reporting Officer (MLRO) – the individual with personal responsibility for oversight of the AML/CFT program and for filing suspicious activity reports. The MLRO role is a regulated position under every major regime, and regulators will scrutinize both the competence of the individual and the structural authority they hold within the organization.

Before an audit, confirm: that the MLRO has completed regime-specific AML training recently (and that the training record can be produced); that the MLRO has direct access to senior management and the board; that MLRO reports to governance bodies are documented, dated and show evidence of board engagement; and that the MLRO has sufficient resource – time, budget, staffing – to discharge the role. A nominal MLRO who is simultaneously carrying three other operational roles, and whose reports show no board response, will be treated as a governance failure.

In our practice, we regularly advise on the structural positioning of the MLRO function, including where the role sits in a cross-border group with entities in multiple licensing jurisdictions. A shared-service MLRO arrangement across jurisdictions can create ambiguity about accountability that regulators in each hub will independently scrutinize.

Common mistake: appointing the MLRO and then treating the role as administrative. Regulators expect the MLRO to demonstrate substantive expertise in virtual-asset typologies, jurisdiction-specific AML requirements, and the firm's specific product and customer risks. Generic AML certification without crypto-specific competence will be visible in the interview the examiner conducts with the MLRO.

Step 7: Assemble the Evidence Pack and Pre-Audit Rehearsal

Assembling a complete, organized evidence pack before the regulator arrives converts the examination from a reactive document search into a structured presentation of a functioning compliance program. This step is procedural but operationally decisive: firms that can produce organized evidence on day one of an examination set a different tone than firms that spend the first two days locating documents.

The evidence pack should contain, at minimum: the current BWRA with version history; the AML/CFT policy and all subsidiary procedures; a sample of CDD files across risk tiers (pre-reviewed and remediated as above); transaction monitoring configuration documentation and a sample of alert decisions with rationale; Travel Rule configuration evidence and a sample of compliant transfers; MLRO annual report and board sign-off; training records for all relevant staff; and any prior regulatory correspondence, including responses to any previous findings.

Run a pre-audit rehearsal. Designate who will answer which categories of examiner question. The MLRO answers questions about program design and SAR filing. The compliance officer answers questions about day-to-day procedure execution. Senior management answers questions about governance and resource allocation. Crossed or inconsistent answers on the same factual question – even if each is individually accurate – can generate an adverse impression of organizational control.

Cross-border note: if the regulator has requested a joint examination with a home-state and host-state supervisor, the evidence pack must be organized to address each regime's requirements in parallel. We have advised on multi-jurisdictional examination preparation where the sequencing of disclosures to different regulators became itself a legal question.

Common mistake: over-preparing on documentation and under-preparing on personnel. An examiner who interviews the MLRO and finds that the individual cannot describe the transaction monitoring rule set, cannot explain why a particular SAR was or was not filed, or cannot articulate the firm's approach to high-risk jurisdictions, will discount the documentation entirely.

If a prior regulatory finding is still open – or if a new examination has been announced – reach the OBOLUS compliance desk now at info@oboluslaw.com. A second read of an open finding frequently surfaces the structural cause and the fastest route to closure.

A Cross-Border Remediation: How Preparation Reversed a Supervisory Trajectory

In a recent compliance engagement, a payments company holding licences in two EU jurisdictions discovered – shortly before a scheduled supervisory examination – that its Travel Rule data architecture was not transmitting beneficiary information in the format required by one of its home regulators. The firm's internal records showed technical implementation had been completed, but no end-to-end testing had been conducted. We were instructed to lead the pre-examination preparation. Working with the firm's compliance team and allied technical counsel, we identified the precise transmission gap, produced a remediation record demonstrating correction prior to the examination date, and prepared an explanatory memo addressed to the examiner presenting the gap as identified, remediated, and closed. The examination concluded without a formal finding on the Travel Rule issue. The firm's proactive documentation of the self-identified gap – and its speed in correcting it – was treated by the regulator as evidence of a functioning control environment rather than a systemic failure.

A Common Assumption Worth Examining: Is One Licence Enough?

A common assumption among operators entering the digital-asset space is that a single offshore registration satisfies AML obligations globally. It does not. The FATF framework, and the domestic legislation that implements it in each licensing jurisdiction, applies where services are provided to customers – not merely where the entity is incorporated. Serving customers in the EU without a MiCA CASP authorisation, or customers in Singapore without a MAS Payment Services Act licence, exposes the entity to enforcement in those customer-facing jurisdictions regardless of the licence held elsewhere.

This is the structural gap that produces the most consequential audit failures: a firm that believes it is operating compliantly under one regime but is in fact unregistered – and therefore unmonitored and non-compliant – in the jurisdictions where most of its customers live. We map the licence stack across operating, custody and payment layers before a business commits to a structure, precisely because the cost of remediation after a regulatory finding is multiples of the cost of getting the structure right at inception.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect and transmit originator and beneficiary information alongside a virtual asset transfer. This obligation derives from FATF Recommendation 16 and is now embedded in the applicable provisions of MiCA's transfer-of-funds regime, the VARA rulebooks, MAS's Payment Services Act requirements, and equivalent frameworks in the major licensing hubs. The specific data fields required, and the threshold below which the rule does not apply, vary by jurisdiction and should be confirmed against current legislation in each operating market.

Who must act as MLRO for a crypto firm?

A licensed VASP must designate a named individual as Money Laundering Reporting Officer. That individual holds personal responsibility for the firm's AML/CFT program and for filing suspicious activity reports with the relevant financial intelligence unit. Regulators assess the MLRO's competence, seniority, structural authority within the firm, and direct access to the board. Shared or nominal MLRO arrangements across multi-jurisdictional groups attract heightened supervisory scrutiny. Most regimes also require the MLRO appointment to be approved or notified to the relevant regulator.

How do regulators audit crypto AML programs?

Regulators typically examine four areas: the written policy framework and business-wide risk assessment; evidence of live implementation through CDD files and transaction monitoring records; the competence and governance of the MLRO and senior management; and documentation of Travel Rule and sanctions screening compliance. Examinations combine document review with staff interviews. The gap between what a policy states and what the operational record shows is the most common trigger for adverse findings. Pre-examination preparation – including internal file review, evidence organization, and staff rehearsal – materially affects outcomes.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programs that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams, and we map the licence stack across operating, custody and payment layers before a business commits. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, Travel Rule implementation, and regulatory examination preparation for VASPs across the EU, UK, UAE and APAC hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours