A digital-asset business that processes user transactions across borders without a coherent KYC (know-your-customer) programme is not merely taking a compliance risk. It is operating on borrowed time. Regulators in every leading hub – from the ESMA-supervised EU under MiCA to the VARA regime in Dubai and the MAS Payment Services Act in Singapore – have made onboarding controls the first line of examination. A failure there cascades: banking rails freeze, licence applications stall, and enforcement proceedings open.
This analysis compares how KYC and onboarding obligations are structured across the flagship jurisdictions for digital-asset businesses. It covers the legal basis in each regime, the practical divergences that trip up cross-border operators, and the decision points that a general counsel or compliance officer must resolve before going live. The cross-border angle is not incidental – it is the central problem, because the entity, the users, the banking and the relevant regulator rarely sit in the same place.
Why KYC Divergence Matters Now
KYC divergence across jurisdictions is no longer a theoretical compliance problem – it is an operational constraint that determines which corridors a digital-asset business can realistically serve. As major regimes converge on the FATF Recommendations framework, including Recommendation 15 (the extension of AML/CFT obligations to virtual assets and virtual asset service providers), the surface-level rules look similar. The execution detail does not.
The FATF standard requires countries to ensure that VASPs (virtual asset service providers) are licensed or registered, subject to customer due diligence, and monitored for suspicious activity. But each jurisdiction interprets "customer due diligence" differently. The threshold for enhanced due diligence, the acceptable forms of identity verification, the treatment of corporate customers and the definition of a PEP (politically exposed person) vary in ways that create real operational friction.
In our cross-border practice, we regularly advise businesses that have built a single KYC process and assumed it will satisfy regulators in every market they serve. It rarely does. The mismatch surfaces earliest in banking – a correspondent bank in one jurisdiction rejects onboarding data collected under the looser standards of another. By then, the business has already acquired customers it cannot properly document under the stricter regime.
Operators we advise routinely underestimate the cost of retrofitting a KYC programme. It is significantly cheaper to map the requirements before onboarding the first user than to remediate thousands of customer files under regulatory pressure.
The EU MiCA CASP Standard for Onboarding
Under the MiCA regime, a CASP (crypto-asset service provider) must satisfy the customer due diligence requirements of the applicable EU AML framework – not as a separate KYC exercise but as an integrated component of its authorisation conditions. ESMA and the national competent authorities expect the onboarding programme to be documented, tested and reviewed, not merely described in a policy manual.
The EU framework imposes a risk-based approach to customer due diligence. This means that a CASP must assess the risk profile of each customer before determining the intensity of the due diligence applied. For retail users transacting at low volumes, simplified due diligence may be available where the jurisdiction's law permits it. For customers transacting at higher volumes, presenting unusual patterns, or sitting in higher-risk jurisdictions, enhanced due diligence is mandatory – and the standard for what constitutes "enhanced" is increasingly set by supervisory practice, not just the text of the regime.
Passporting is one of MiCA's most commercially significant features. A CASP authorised in one EU member state may passport its services across the EU/EEA without re-authorising in each market. But passporting does not flatten the KYC obligation. The CASP must apply its programme consistently to users across all passported territories, and the host-state regulator retains supervisory interest in conduct directed at its residents. A business passporting from Lithuania into Germany cannot apply the onboarding standards of its home state in a way that falls below the minimum expected in the host market.
Corporate onboarding under MiCA is particularly demanding. The beneficial ownership verification requirement – identifying the natural persons who ultimately own or control a legal entity customer – aligns with the EU's broader AML framework. For complex structures involving multiple layers of holding companies or trusts, the documentation burden is substantial.
For a scoped assessment of your EU onboarding programme and its fit with MiCA authorisation requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis significantly.
How Does VARA Dubai Approach KYC for VASPs?
VARA in Dubai applies an activity-based licensing model, and the KYC obligations attached to each licence reflect the risk profile of that activity. An exchange licence carries different onboarding expectations than a custody licence or a transfer and settlement licence – even though all three are regulated under the same VARA rulebooks.
The VARA regime requires licensed entities to maintain a written AML/CFT programme that addresses customer identification, verification, ongoing monitoring and suspicious transaction reporting. The programme must be approved by a responsible officer, and VARA expects that officer to have genuine seniority within the organisation – not a nominal title. In our practice, we have seen applications delayed because the designated compliance function lacked the authority and resources to operate the programme credibly.
Dubai's position as a cross-border hub creates a specific challenge. Many VARA-licensed businesses serve customers who are physically present in the UAE but who have financial connections to other jurisdictions. The onboarding programme must satisfy VARA's expectations while also managing the risk that a customer's activity in Dubai is connected to conduct that would attract scrutiny from regulators in their home country. That layered risk assessment is not something a single-jurisdiction KYC policy handles well.
VARA has indicated a clear supervisory interest in how licensees apply the Travel Rule (the obligation under FATF Recommendation 16 to pass originator and beneficiary information alongside a virtual asset transfer). The interaction between the Travel Rule and the onboarding programme is direct: a business cannot comply with the Travel Rule for outgoing transfers unless its onboarding process captured the data in the correct format at the point of customer admission.
Singapore and Hong Kong: Contrasting Risk-Based Approaches
Singapore and Hong Kong represent two mature Asian regulatory regimes that have both moved toward mandatory VASP licensing, but they apply different supervisory philosophies to KYC that produce divergent compliance programmes in practice.
Under the MAS Payment Services Act, a DPT (digital payment token) service provider must conduct customer due diligence in accordance with MAS's AML/CFT notices. MAS takes a strongly risk-based posture: the MAS supervisory framework expects licensees to calibrate the intensity of their due diligence to a genuine assessment of risk, not to apply uniform procedures across all customers regardless of profile. In practice, MAS-supervised firms typically invest heavily in technology-assisted risk scoring at the point of onboarding, using transaction monitoring data to feed back into the ongoing customer risk assessment.
Hong Kong's SFC regime for VATP (virtual-asset trading platform) licensing imposes detailed onboarding requirements that sit alongside the general AML obligations under Hong Kong's Anti-Money Laundering and Counter-Terrorist Financing Ordinance. The SFC expects a VATP to apply rigorous know-your-customer procedures, including for corporate customers, with documentation standards that reflect the sophistication of the professional-investor market that Hong Kong has historically served.
The contrast between the two regimes is sharpest on the question of retail access. Singapore's DPT licensing regime permits retail customer services subject to appropriate risk controls and disclosures. Hong Kong's VATP regime has historically restricted access to professional investors in certain contexts, though the regulatory posture has evolved. A business deciding between Singapore and Hong Kong as its principal Asian hub must resolve this structural difference before designing its onboarding architecture – because building a retail-facing programme for a jurisdiction that restricts retail access is an expensive mistake to reverse.
What Does the Travel Rule Add to Onboarding Obligations?
The Travel Rule is not a separate compliance exercise bolted onto the side of a KYC programme – it is an extension of the customer due diligence obligation into the transfer layer, and designing it as an afterthought creates structural gaps. Under FATF Recommendation 16, a VASP must collect, verify and transmit originator and beneficiary information with each virtual asset transfer above the applicable threshold. That threshold varies by jurisdiction; the data elements required are broadly consistent but differ in detail.
The operational consequence is significant. To comply with the Travel Rule on outgoing transfers, the VASP must have captured the originator's data at onboarding in the correct format and to the correct standard of verification. If the onboarding programme collected incomplete data – or collected the right data in the wrong format – the VASP cannot generate a compliant Travel Rule message without going back to the customer. At scale, that remediation is costly. In a transfer corridor with tight settlement windows, it may be impossible.
For incoming transfers from counterparty VASPs, the Travel Rule obligation runs in reverse: the receiving VASP must assess whether the originator data transmitted by the sending VASP is adequate and whether the transfer is consistent with its own customer's profile. This requires a VASP due diligence programme – an onboarding process for counterparty VASPs as distinct from end customers – that most smaller operators have not built.
In a recent cross-border matter, a payments company operating across three jurisdictions discovered that its outgoing Travel Rule messages were consistently rejected by counterparty VASPs because its onboarding process had captured customer addresses in a free-text format rather than the structured schema required by the IVMS101 standard. The remediation required re-engaging a material proportion of its customer base. We were engaged to structure a revised onboarding template and to advise on the supervisory disclosure obligations that arose from the gap. The underlying issue was a KYC architecture decision made before the Travel Rule obligation was properly understood.
How Do AML Onboarding Standards Differ for Corporate Versus Retail Customers?
Corporate customer onboarding is consistently the most demanding element of a digital-asset AML programme, and it is the area where divergence between jurisdictions is most practically significant for a business operating across borders.
Every major AML regime requires a VASP to identify and verify the beneficial owners of a corporate customer – typically defined as the natural persons who ultimately own or control the entity above a specified ownership threshold. The ownership threshold, the depth of the verification required, and the treatment of regulated entities as lower-risk counterparties all vary. What counts as sufficient documentary evidence of a complex ownership structure in a Cayman Islands fund may not satisfy the evidentiary standard expected by the Bank of Lithuania or the FCA.
Under the UK FCA regime, which operates through the Money Laundering Regulations framework, a VASP registered for AML purposes must apply enhanced due diligence to higher-risk customers. The FCA has been explicit in its supervisory communications that it considers the digital-asset sector to be higher risk across the board, which means that practices acceptable for simplified due diligence in other sectors do not automatically apply here.
FINMA in Switzerland applies a token taxonomy that influences onboarding intensity. A firm dealing in payment tokens is subject to a different supervisory posture than one dealing in asset tokens or hybrid instruments. The classification of the instrument affects not just the licence category but the depth of due diligence expected of both the firm and its customers.
The AIFC/AFSA regime in Kazakhstan applies a common-law framework within the financial centre, and the onboarding obligations for its licensed digital-asset entities reflect FATF standards adapted to a developing-market context. Operators using the AIFC as a gateway to Central Asian markets must apply due diligence that accounts for the higher prevalence of cash-based economies and the documentation challenges that creates for corporate customers with complex regional ownership structures.
If a prior application stalled or a banking relationship was withdrawn because of documented AML gaps, a structural review can identify the root cause and the route back. Write to us at info@oboluslaw.com to discuss a scoped remediation engagement.
Common Mistakes in Cross-Border KYC Programme Design
The most expensive KYC errors in cross-border digital-asset businesses are structural – they are built into the programme at inception and compound across every subsequent customer interaction. The following patterns appear regularly in our practice.
The first is treating the home-jurisdiction standard as a universal floor. A business licensed in one jurisdiction builds its onboarding process to satisfy that regulator, then passports or expands into additional markets assuming the same programme will hold. It will not. Each jurisdiction in which the business has customers or conducts regulated activity has its own supervisory expectations, and "we comply with [home jurisdiction] AML rules" is not a defence in an enforcement action brought by a host-state regulator.
The second is separating the KYC data collection process from the systems that need to consume it. A business that collects identity documents in a proprietary format and then tries to feed that data into a Travel Rule messaging system, a sanctions screening engine and a transaction monitoring platform will encounter integration failures. The onboarding architecture must be designed with all downstream data consumers in mind from the outset.
The third is underbuilding the corporate onboarding process. Retail onboarding is relatively well understood, and the market for automated identity verification solutions is mature. Corporate onboarding – particularly for fund structures, trusts and entities with nominee arrangements – still requires significant manual judgment. Businesses that automate retail onboarding efficiently sometimes neglect to build the legal-review capacity needed for complex corporate structures, creating a queue of high-value customers who cannot be admitted because the verification process has not been designed for them.
The fourth is treating onboarding as a one-time event. Every major AML regime requires ongoing customer due diligence – periodic refresh of customer data, trigger-based review when a customer's risk profile changes, and exit procedures when the relationship cannot be maintained to the required standard. A business that has strong onboarding but weak ongoing monitoring will fail a regulatory review of its AML programme, regardless of how clean its new customer files look.
Decision Matrix: Which KYC Architecture for Which Operator Profile?
The right KYC architecture depends on the operator's licence structure, customer mix and transfer volume. The following profiles illustrate the principal decision branches.
Profile A – EU-licensed exchange with retail users across multiple member states. The operator holds a CASP authorisation in a single member state and passports EU-wide. The appropriate architecture centres on a risk-tiered due diligence engine that applies enhanced checks automatically above defined risk scores, a Travel Rule module built to the IVMS101 standard from day one, and a documented process for host-state regulatory interaction. The key risk is cross-border enforcement if the passporting programme is seen as regulatory arbitrage – applying a lenient home-state standard to users in stricter host markets.
Profile B – VARA-licensed operator in Dubai serving MENA and Asian corridors. The operator is licensed under VARA for exchange and transfer activities. The appropriate architecture addresses VARA's activity-specific rulebook requirements, integrates sanctions screening against OFAC, UN and domestic UAE lists, and builds a VASP due diligence programme for counterparty corridors into Asia. The key risk is the corridor mismatch: a VARA licence does not authorise the operator to conduct regulated activity in Singapore or Hong Kong, so the onboarding programme must include a clear geo-blocking or restriction framework for users in markets where the operator is not locally licensed.
Profile C – BVI or Cayman fund with digital-asset exposure, using a third-party custodian. The fund itself is not a VASP, but its custodian is. The appropriate architecture includes a clear contractual allocation of AML responsibility between the fund and the custodian, investor-level due diligence at the fund that satisfies the CIMA or BVI FSC requirements for the fund's own registration, and a data-sharing protocol that allows the custodian to satisfy its own ongoing due diligence obligations without re-burdening investors. The key risk is the assumption that the custodian's AML programme covers the fund – it does not.
Profile D – Multi-jurisdictional stablecoin issuer. The issuer faces AML obligations both as a CASP/VASP and, under MiCA's EMT (e-money token) or ART (asset-referenced token) regime, potentially as an e-money or regulated-token issuer. The appropriate architecture builds in issuer-level KYC for all holders above a defined balance, integrates with the contract-level freeze capability that Tether and Circle demonstrate for their own instruments, and maintains a legal-hold protocol that allows rapid response to law-enforcement or court-order freeze requests. The key risk is the assumption that issuing on a public blockchain eliminates the onboarding obligation – it does not, and regulators are increasingly clear on this point.
A Common Assumption That Creates Regulatory Exposure
A common assumption in this market is that a single offshore licence is sufficient to serve customers globally, provided the KYC programme is "international standard." This is incorrect, and it is increasingly dangerous as regimes mature.
The principle of territorial scope means that a digital-asset business conducts regulated activity in any jurisdiction where it has customers, where transactions are executed, or where its marketing is directed – regardless of where its entity is incorporated or licensed. A business licensed in the BVI that markets actively to EU residents is not outside the scope of MiCA. A Singapore-licensed operator with a substantial UAE customer base is not beyond VARA's supervisory reach if it is conducting VARA-regulated activities directed at Dubai residents.
In our practice, we have seen enforcement risk crystallise not from active violations but from the passive assumption that a single licence provides a global safe harbour. Regulators in the major hubs have refined their jurisdictional reach analysis significantly over the past several years. The test is not where you are – it is where your customers are and what you are doing with them.
The practical consequence for KYC design is that an operator serving a genuinely multi-jurisdictional customer base needs a programme that is modular: capable of applying the standards of the most demanding applicable regime to the relevant sub-set of customers, while maintaining a coherent and auditable structure overall. That is more expensive to build than a single-standard programme. It is significantly less expensive than a regulatory enforcement action or a banking exit.
Related at OBOLUS
- Compliance, AML and Travel Rule for Digital-Asset Businesses – our core practice covering AML programme design, Travel Rule implementation and ongoing compliance advisory across jurisdictions.
- AML and Travel Rule Regime in the UAE Under VARA – a detailed analysis of VARA's AML and Travel Rule requirements for licensed virtual-asset businesses in Dubai.
- EMI Onboarding for VASPs in Malta – how the MFSA's onboarding expectations interact with the MiCA transition for Malta-licensed digital-asset entities.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 – requires a VASP to collect, verify and transmit originator and beneficiary information alongside each virtual asset transfer above the applicable threshold. The precise threshold varies by jurisdiction, but the data elements required are broadly consistent with the IVMS101 international messaging standard. Critically, the sending VASP must have captured this data at onboarding to generate a compliant message at the point of transfer. A VASP that cannot produce compliant Travel Rule data on outgoing transfers is, in effect, operating with an incomplete KYC programme.
Who must act as MLRO for a crypto firm?
Most regulated digital-asset regimes require a designated MLRO (money laundering reporting officer) – a senior individual with responsibility for the firm's AML programme, suspicious activity reporting and regulatory liaison on AML/CFT matters. The seniority, qualification and residency requirements for the MLRO vary by jurisdiction. VARA, ESMA under MiCA, MAS and the FCA each set expectations that go beyond a nominal appointment. The MLRO must have genuine authority, adequate resources and direct board access. Regulators scrutinise the MLRO's practical capacity during licence applications and supervisory reviews.
How do regulators audit crypto AML programs?
Regulators audit crypto AML programmes through a combination of document review, on-site inspection, transaction sampling and supervisory interviews with key personnel including the MLRO. The focus areas typically include the quality of the firm's risk assessment, the completeness of customer due diligence files, the effectiveness of transaction monitoring, the timeliness and accuracy of suspicious activity reporting, and the training records of relevant staff. In the leading hubs, supervisors increasingly use data analytics to identify outlier transaction patterns before or during the inspection, making it essential that the firm's own monitoring systems are calibrated to detect the same signals.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and onboarding compliance programmes that regulators in every major hub now examine as a condition of authorisation. We map the licence, banking and compliance stack across the operating, custody and payment layers before you commit to a structure. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-jurisdiction AML programme design, VASP licensing and Travel Rule implementation for digital-asset businesses operating across multiple regulatory regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.