EST · MMXXVI
Home/Insights/Regulatory/Governance Expectations for Boards of Licensed VASPs
Compliance, AML & Travel Rule

Governance Expectations for Boards of Licensed VASPs

Governance Expectations for Boards of Licensed VASPs. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLU

Regulators across every major digital-asset hub now treat board-level governance as a first-order licensing condition, not an administrative afterthought. When the Virtual Assets Regulatory Authority (VARA) in Dubai or the Monetary Authority of Singapore (MAS) reviews a new licence application – or investigates an existing licensee – the examination begins at the top of the corporate structure: who sits on the board, what authority they hold, and whether that authority is exercised with meaningful oversight of AML compliance, the Travel Rule, KYC frameworks, and transaction monitoring. Getting this wrong does not merely delay a licence. It ends one.

For licensed virtual asset service providers (VASPs), governance expectations have converged around a recognisable architecture: independent oversight at board level, a nominated Money Laundering Reporting Officer (MLRO) with direct board access, documented escalation paths, and periodic testing that regulators can inspect. This analysis unpacks that architecture across the leading licensing jurisdictions, identifies the fault lines where businesses most often fail, and provides a cross-border decision matrix for operators whose entity structure spans more than one regulatory perimeter.

We work through the regulatory foundation first, then the specific board-composition requirements, the MLRO mandate, the Travel Rule governance layer, the cross-border complications that a single-entity structure rarely resolves, the common structural mistakes, and finally the self-assessment lens that regulators increasingly use at examination time.

Why Governance Is Now a Primary Licensing Condition

Board governance is a substantive licensing condition because regulators have consistently found that AML failures at VASPs originate not in faulty software but in faulty accountability chains. Under MiCA, the EU's Markets in Crypto-Assets Regulation administered by ESMA and national competent authorities, a CASP authorisation requires the applicant to demonstrate that management-body members are of sufficient good repute and possess adequate knowledge, skills and experience. The obligation is structural: the board must be capable of overseeing the compliance function, not merely approving it.

VARA's rulebooks in Dubai follow the same logic. Each licensed activity – exchange services, custody, lending, transfer and settlement – carries distinct governance obligations that flow upward to the board. Regulators have been explicit: they expect the board to understand the AML risk profile of the business, to receive regular compliance reporting, and to act on material findings. Passive oversight is treated as a governance deficiency.

The FCA in the United Kingdom takes a comparable position under the Money Laundering Regulations framework. Cryptoasset registration requires firms to demonstrate that senior management is aware of the firm's AML/CFT exposure and bears personal accountability for remediation. In our practice, we see regulators in all three of these jurisdictions requesting board meeting minutes, escalation logs and documented risk-appetite statements as standard parts of the application dossier – before a licence decision is even issued.

The practical implication is that governance is not a post-licence compliance project. A firm that assembles a compliant board structure after approval has already told the regulator it did not understand the requirement. The structure must be in place – and evidence of its operation must be available – at the point of application.

What Does Adequate Board Composition Actually Require?

Adequate board composition for a licensed VASP requires a mix of independent oversight capacity, relevant financial-services or technology expertise, and the collective ability to challenge executive management on risk and compliance matters. No single licensing regime specifies an exact headcount across all activity types, but the structural expectation – drawn from ESMA guidance under MiCA, VARA's published rulebooks, and MAS's Payment Services Act regime – converges on several non-negotiable elements.

First, the board must include at least one member who is genuinely independent of executive management. Regulators in Singapore and Hong Kong under the SFC's VATP regime have been particularly attentive to nominee directors, shell-board arrangements, and situations where the founder controls all board seats. Those structures trigger enhanced scrutiny and frequently prompt requests for remediation as a pre-condition to licence issuance.

Second, the collective competence of the board must cover the regulated activities of the firm. A custody business whose board has no member with a background in safeguarding, settlement or financial-services risk will face questions. An exchange whose board cannot articulate a position on transaction monitoring thresholds will face more. The FSRA in Abu Dhabi's ADGM, which administers one of the more detailed virtual-asset governance frameworks, expects evidence of competence testing and ongoing training at board level – not merely at compliance officer level.

Third, fit-and-proper requirements apply individually and collectively. Each director must pass the relevant regulator's own screening. In our cross-border practice, we frequently advise founding teams that a director who is fully compliant in one jurisdiction may trigger additional disclosure requirements in a second – particularly where the second regulator runs criminal-record checks against a different standard or requires disclosure of involvement in prior regulated-entity failures.

For a CTA prompt: The process above describes the standard expectation. Your facts – the entity structure, the activity scope, the seat of the board – change the analysis materially.

Reach out to OBOLUS at info@oboluslaw.com for a scoped assessment of your board structure against the specific regime requirements of your target jurisdiction. The assessment can identify gaps before a regulator does.

The MLRO Mandate: Scope, Independence, and Board Access

Every licensed VASP must designate a Money Laundering Reporting Officer (MLRO) – the senior individual who holds personal accountability for the firm's AML/CFT framework, receives internal suspicious-activity reports, and serves as the primary interface with the financial intelligence unit and regulator. The MLRO is not merely a compliance function; under every major regime the role carries direct board-reporting rights and, in some regimes, the right to attend board meetings as a standing matter.

VARA's rulebooks make board access explicit. The MLRO must be able to report directly to the governing body without interference from the executive layer. FINMA in Switzerland applies a similar principle under its own supervised-entity regime. The MAS in Singapore, operating under the Payment Services Act, expects the firm's senior management to be demonstrably engaged with AML findings – which in practice means the MLRO's reports must reach a decision-making level capable of authorising remediation.

The residency and seniority of the MLRO is a recurring flashpoint. Regulators in the leading hubs increasingly require the MLRO to be resident – or at least substantially present – in the jurisdiction of licence. A VASP licensed in a common-law offshore centre that nominates a non-resident MLRO located in an unregulated jurisdiction will face direct questions. In our practice, we have seen applications stall specifically on this point, where the proposed MLRO lacked the jurisdictional presence the regulator expected.

There is also a resourcing question the board must own. An MLRO without budget authority, without access to forensic monitoring tools, and without a team sized to the firm's transaction volumes is a regulatory liability. The board is responsible for ensuring the MLRO has the resources to perform the role. Regulators test this at examination by asking whether the MLRO has ever escalated a resource request to the board and, if so, what the board's documented response was.

Travel Rule Governance: What the Board Must Own

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual asset transfer – is not solely a systems problem; it is a governance problem that the board must own in documented form. Under MiCA and under the VASP regimes in Singapore, Hong Kong, the BVI under the BVI FSC's VASP Act 2022, and the Cayman Islands under CIMA's Virtual Asset regime, the board is expected to have approved a written Travel Rule policy, to understand the firm's technical approach to compliance, and to receive periodic reporting on exception rates and remediation.

FATF's Recommendation 15 applies across all major hubs; the jurisdictional variables are the de-minimis threshold and the treatment of transfers to or from unhosted wallets. Both variables carry board-level significance because they determine where the firm draws the line on transaction execution. A board that has never discussed its unhosted-wallet policy has almost certainly not documented a risk-appetite decision on the point – which is precisely what a regulator will look for at examination.

The cross-border dimension is acute. A VASP licensed in Lithuania under the Bank of Lithuania's supervision and transacting with a counterpart VASP licensed under the SFC in Hong Kong must reconcile two Travel Rule implementation standards. The data fields required, the timing of transmission, and the treatment of failed delivery may differ. The board of the Lithuanian entity cannot delegate the resolution of those conflicts entirely to the compliance team; it must have approved the firm's inter-operability policy and must have evidence that the policy was reviewed and updated as the SFC's standards evolved.

In a recent matter, a digital-asset payments business operating under dual licences found that its Travel Rule compliance system was calibrated to the more permissive of the two applicable standards. The gap was identified during a supervisory review by the stricter regulator. We were engaged to map the policy against both regimes, draft a board-approved remediation plan, and coordinate the firm's communication with both supervisors simultaneously. The resolution required a board resolution, documented evidence of management escalation, and an updated compliance manual – not merely a software patch.

Cross-Border Governance: Why One Licence Is Rarely Enough

A common assumption in the VASP licensing market is that a single offshore licence – perhaps a BVI FSC registration or a Cayman CIMA authorisation – provides a sufficient governance foundation for global operations. It does not. The licence addresses activity within a defined regulatory perimeter; it does not resolve the governance obligations that arise in every jurisdiction where the firm's users are located, where its banking counterparties operate, or where its custody infrastructure is maintained.

The cross-border governance problem arises precisely because regulatory obligations follow activity and risk, not corporate domicile. A VASP whose users are predominantly in the EU faces MiCA obligations regardless of where the entity is registered. A VASP whose banking relationship runs through an FCA-regulated bank in London will face KYC and AML expectations that are set by the FCA's standards, not by the offshore regulator that issued the licence. The board must understand and document the full regulatory perimeter of the business, not only the domicile of the legal entity.

We regularly advise businesses that have structured their licensing around a single offshore entity and subsequently discovered that their banking counterparties, institutional partners, or exchange-listing due diligence processes require evidence of substantive regulation – meaning an MFSA-authorised CASP under MiCA, a VARA licence, or a MAS Payment Services Act licence. The gap between the offshore registration and the onshore expectation creates a governance deficit that the board must address through a structural upgrade, not a disclosure statement.

The decision matrix here follows the firm's activity profile. An operator conducting exchange services for EU-resident users requires MiCA CASP authorisation in an EU member state – a Lithuania or Malta domicile has historically been a common entry point, both now transitioning to full CASP status under MiCA. An operator focused on institutional clients in the Gulf requires a VARA licence (for Dubai mainland) or ADGM/FSRA authorisation (for Abu Dhabi). An operator building a cross-border payments corridor between Southeast Asia and Europe likely requires a MAS licence at the Singapore end and a CASP authorisation at the EU end – two boards, two MLROs, and two compliance programmes, each meeting the local standard.

If a prior licensing structure has left a governance gap that banking partners or institutional counterparties are now flagging, a structural review can surface the remedy. Write to OBOLUS at info@oboluslaw.com to map the full regulatory perimeter against your current entity structure. A second read of the facts frequently identifies a route that the initial structuring did not contemplate.

Transaction Monitoring: Where Board Accountability Becomes Operational

Transaction monitoring is the operational expression of the board's AML risk appetite, and regulators treat the calibration of the monitoring system as a direct reflection of board-level governance quality. Under the MiCA regime, under VARA's rulebooks, and under the SFC's VATP requirements in Hong Kong, the board is expected to have approved the firm's risk-based approach to monitoring – including the thresholds, the asset-class scope, and the escalation triggers – and to receive periodic reporting on alert volumes, false-positive rates, and the outcomes of investigated cases.

This creates a board-level accountability that many firms underestimate. A transaction monitoring system that generates a high false-positive rate reduces the compliance team's ability to investigate genuine alerts. If the board has not reviewed that rate and has not directed a calibration review, it has implicitly accepted a compliance posture that may not meet the regulator's standard. Regulators in the leading hubs have in recent years issued supervisory findings that name board-level governance failures as the root cause of monitoring deficiencies – not system failures.

The forensic tools available to regulators have advanced considerably. Services that provide on-chain transaction analysis – including the identification of high-risk counterparty addresses, mixer interactions, and chain-hop patterns – are now standard supervisory tools. A VASP whose monitoring system does not incorporate equivalent capability will face questions about the adequacy of its risk-based approach. The board's responsibility is to ensure the firm's monitoring infrastructure is calibrated to the risk profile of its user base, its transaction volumes, and the asset classes it supports.

What Are the Most Common Governance Mistakes by Licensed VASPs?

The most common board-level governance failures in licensed VASPs fall into a recognisable pattern: they are structural rather than incidental, and they persist because the founding team built the compliance architecture around the application rather than around the ongoing supervisory relationship.

The first and most frequent error is the paper MLRO. The individual nominated to the regulator as MLRO is qualified on paper but lacks the authority, the budget, or the seniority to function independently of the executive team. When the regulator tests board access – asking for evidence that the MLRO has reported adverse findings directly to the board – the file is thin. This is not a small gap; in several leading hubs it constitutes a material breach of the licence conditions.

The second error is governance that stops at the entity boundary. A group of entities – a licensed operating company, a custody subsidiary, and a payment processing entity – may each meet the governance requirements of its own regulator individually. But the group governance framework that binds them, resolves conflicts between compliance programmes, and provides consolidated AML reporting is missing. Regulators with group-supervision powers increasingly look across entity boundaries. The FSRA in Abu Dhabi's ADGM and the SFC in Hong Kong both apply group-level governance expectations to entities within a supervised structure.

The third error is static documentation. A board-approved AML policy from the year of licence issuance that has not been reviewed since is a governance failure waiting to be discovered. Regulatory standards move. FATF guidance is updated. The Bank of Lithuania's supervisory expectations under MiCA's transition regime differ from the prior VASP registration requirements. A board that has not directed a policy review in response to those changes has a documentation gap that no amount of procedural competence at the compliance-officer level will close.

A fourth, increasingly prominent error is the failure to document board decisions on novel risk categories. Unhosted wallets, DeFi protocol interactions, staking services and NFT trading each carry distinct AML risk profiles that evolving FATF guidance is addressing. A board that has never discussed, documented, or formally adopted a risk-appetite position on any of these categories is operating without a governance record that the regulator can examine. The compliance team's informal position on a novel risk category is not a board decision and does not satisfy the governance expectation.

Self-Assessment: The Six-Point Governance Test Regulators Apply

Supervisory examinations of licensed VASPs increasingly follow a structured governance assessment rather than a document checklist, and preparing for that assessment is a board-level responsibility. Based on the examination frameworks applied by VARA, ESMA's national competent authorities under MiCA, the MAS, and the FCA, the governance test resolves to six recurring questions.

First: does the board hold documented evidence that it has approved the firm's AML/CFT risk-appetite statement and that the statement has been reviewed within the preceding twelve months? Second: does the MLRO report directly and independently to the board, and is there a documented record of that reporting? Third: has the board reviewed and approved the firm's Travel Rule implementation approach, including its policy on transfers to or from unhosted wallets? Fourth: has the board received and acted upon a periodic report on transaction monitoring performance, including alert volumes and false-positive rates? Fifth: does each board member satisfy the applicable fit-and-proper standard in the jurisdiction of the licence – and has that standard been re-checked since the initial licence grant? Sixth: if the business operates across multiple jurisdictions, does the group governance framework ensure that the most demanding applicable standard is met across all entities?

Operators who can answer affirmatively to all six questions, with documentary evidence in a well-ordered compliance file, are in a strong position for a supervisory examination. Those who cannot answer affirmatively should treat the gap as a governance risk – because regulators increasingly do.

In our cross-border practice, we map this self-assessment against the specific requirements of each applicable regime before examination, not during it. The lead time between a supervisory notification and the first examination meeting is often measured in weeks, not months. By that point, the documentary record either supports the governance claim or it does not.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP to collect and transmit originator and beneficiary information alongside a virtual asset transfer. The data set typically includes names, account identifiers, and address information for both parties. The obligation applies above a jurisdiction-specific de-minimis threshold that varies across regimes; under MiCA, VARA, the MAS Payment Services Act, and the BVI FSC VASP Act, the requirement applies to transfers that meet or exceed the local threshold. VASPs must also screen the counterparty VASP before transmitting data and must have a documented policy for transfers where the counterpart is unhosted or unverified.

Who must act as MLRO for a crypto firm?

The MLRO must be a sufficiently senior individual – typically at management level – who is independent of the business-development function and who can report directly to the board without executive interference. Most major licensing regimes, including VARA, MAS, the FCA, and ESMA's national competent authorities under MiCA, require the MLRO to be formally notified to the regulator and to meet the applicable fit-and-proper standard. Many hubs additionally require the MLRO to be resident in, or substantially present in, the jurisdiction of the licence. Nominee or part-time MLROs with no genuine authority over the compliance programme consistently attract supervisory scrutiny.

How do regulators audit crypto AML programs?

Regulators audit VASP AML programmes through a combination of documentary review and direct examination. The documentary review typically covers the risk-appetite statement, the AML/CFT policy manual, board minutes referencing compliance reporting, MLRO report logs, transaction monitoring calibration records, and Travel Rule implementation documentation. Direct examination may include interviews with the MLRO, the compliance team, and – increasingly – board members. Regulators with on-chain analytical capability, including supervisory bodies in Dubai, Singapore and Hong Kong, may also run independent transaction analysis against publicly available blockchain data as part of the assessment.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. In our work on governance readiness, we map the compliance structure against the specific examination framework of each applicable regulator – before the supervisor makes the first request. We have coordinated cross-border compliance remediation for clients operating under dual licences simultaneously, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when enforcement action follows governance failure. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in VASP governance frameworks, AML programme design, and multi-jurisdictional supervisory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours