Licensed crypto firms — exchanges, custodians, stablecoin issuers and payment processors — are permitted, even expected, to outsource functions and run infrastructure in the cloud. The question is not whether regulators allow it. The question is how tightly they police the conditions under which it happens. Across MiCA, VARA, the FCA's money-laundering registration, MAS under the Payment Services Act, and parallel regimes in Singapore, Hong Kong and the AIFC, regulators share a single non-negotiable premise: a CASP (crypto-asset service provider) or VASP (virtual asset service provider) may delegate a task, but it may never delegate accountability.
The stakes are concrete. A firm whose cloud vendor fails an audit, whose KYC provider is not mapped in a compliant sub-processor agreement, or whose transaction-monitoring feed goes dark for 72 hours, faces regulatory censure, suspended licences and – because AML deficiencies are borderless – coordinated action from multiple supervisors at once. This analysis sets out the operative rules, the cross-border interaction points, and the structural choices that separate durable outsourcing arrangements from liability exposure.
Why Outsourcing Rules Are Tightening Across Every Major Regime
Regulators tightened outsourcing expectations for crypto firms because the prior silence was exploited. Early VASP regimes said little about where data could sit or who could run AML checks. Firms placed core compliance functions with unvetted vendors, pointed regulators to SaaS dashboards as evidence of monitoring, and characterised cloud infrastructure as an ordinary IT procurement decision. Supervisors have since closed each of those gaps in turn.
Under MiCA, ESMA and the relevant national competent authorities apply the same material-outsourcing standard to CASPs that applies across the broader financial sector. That means a written outsourcing policy, a register of all outsourced functions, risk-based due diligence on each service provider, and ongoing monitoring documented at a frequency the regulator can inspect. The regime draws a sharp line between a function that is outsourced – retaining accountability at the CASP – and one that is effectively abandoned to a third party, which may constitute a breach of the authorisation conditions.
VARA in Dubai operates on an activity-based rulebook structure. The Virtual Assets Regulatory Authority expects each regulated entity to identify which activities are covered by its own systems and which rely on third-party infrastructure, to document the dependency chain, and to demonstrate that concentration risk in any single vendor does not threaten operational resilience. In practice, that requirement is live from the point of licensing, not deferred to a later supervisory review.
In Singapore, the Monetary Authority of Singapore published detailed outsourcing guidelines that apply to institutions it supervises, and the Payment Services Act regime extends those obligations to licensed digital payment token service providers. Firms in our cross-border practice that hold MAS licences alongside EU or UAE authorisations describe the documentation burden as additive: each supervisor wants its own outsourcing register, its own incident-notification template and its own right-to-audit clause in vendor contracts.
The cross-border reality: a CASP authorised under MiCA passporting to other EU member states faces consolidated supervision of its outsourcing arrangements from the home NCA – but the host regulator retains the right to raise concerns about local data handling. That layering of home and host expectations is the operational trap firms walk into when they expand without updating their vendor contracts.
What Regulators Mean by "Material Outsourcing" – and Why the Label Changes Everything
Whether an arrangement qualifies as "material outsourcing" is the threshold question that determines how much governance a firm must build around it. Regulators across MiCA, MAS and the FCA regime converge on the same functional definition: an arrangement is material if its failure or degradation would impair the firm's ability to perform a regulated function, meet its AML/CFT obligations, or satisfy its clients.
For a crypto exchange, the list of material functions typically includes transaction monitoring, KYC and onboarding infrastructure, blockchain analytics, order-matching engine hosting, custody key-management systems, and the Travel Rule data-transmission layer. Non-material functions – HR software, office productivity tools, finance administration – attract lighter oversight expectations, though the distinction must be documented and defensible.
The FCA, under its money-laundering registration requirements, is explicit that a firm relying on a third-party AML provider remains the regulated entity for the purposes of any enforcement action. Regulators at every level apply that logic: the vendor may be sanctioned in parallel if it contributed to a systemic failure, but the VASP faces primary accountability. We regularly advise clients that the single most common structural error is treating an AML-as-a-service contract as a compliance solution rather than as a compliance tool that the firm must actively supervise.
The practical consequence is a governance layer that most outsourcing contracts were not originally designed to carry. A SaaS agreement for a transaction-monitoring platform, written for a FinTech client in a lightly regulated context, will almost certainly lack: a right-to-audit clause the regulator can step into, a business-continuity obligation expressed in recovery-time objectives the supervisor has approved, provisions for regulator-directed suspension of the vendor relationship, and data-portability rights that allow the firm to migrate to a replacement provider within a defined window. Each of those gaps must be filled contractually before an inspection occurs – not during one.
Cloud-Specific Rules: Concentration Risk and Data Sovereignty
Cloud infrastructure triggers two distinct regulatory concerns: concentration risk and data sovereignty. They are related but they require different contractual and structural responses.
Concentration risk arises when a significant proportion of the crypto sector's operational capacity sits on a small number of hyperscale cloud providers. Regulators – including ESMA under MiCA's operational resilience provisions and MAS under its outsourcing guidelines – flag this as a systemic concern. For an individual CASP, the obligation translates into demonstrating that it has identified its own concentration exposure and has a credible exit plan if a primary cloud region or provider becomes unavailable. That exit plan must be documented, tested, and proportionate to the firm's scale.
Data sovereignty concerns arise because regulators increasingly specify where certain categories of data must be stored and processed. Under MiCA, the European Data Protection Board and national data-protection authorities apply GDPR to personal data processed by CASPs, which means that routing KYC records through a cloud region outside the EU requires a documented legal transfer mechanism. VARA's rulebooks impose jurisdiction-specific data-residency expectations for regulated activities conducted within Dubai. The FSRA in Abu Dhabi's ADGM applies its own data-handling standards to regulated entities in that perimeter.
The cross-border implication is acute. A firm with a MiCA passport, a VARA licence and a MAS licence simultaneously will find that those three regimes have different, and partly inconsistent, data-residency expectations. The operational answer is not to pick the most permissive rule and apply it everywhere. Regulators in each jurisdiction will assess compliance against their own standard. The legal answer is an architecture document that maps each data category to the applicable regime and shows the firm has designed its cloud topology around those constraints, not around cloud-provider defaults.
In a recent engagement, a firm with dual authorisations in an EU member state and a Gulf jurisdiction discovered that its transaction-monitoring vendor was routing all data – including personal information from EU-resident clients – through a processing region that satisfied the Gulf regime but not GDPR. The remediation involved renegotiating the vendor's multi-tenancy model, implementing data-residency controls at the application layer, and preparing documentation for the EU NCA. The work was completed before the scheduled supervisory inspection, but the timeline was tight. Early-stage vendor selection with a cross-jurisdiction data map would have avoided the exercise entirely.
For a scoped assessment of your outsourcing and cloud architecture across your active regulatory perimeters, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, the jurisdictions where your users sit, and your existing vendor contracts change the analysis materially.
AML and Travel Rule Compliance in Outsourced Infrastructure
AML/CFT compliance is the most scrutinised area of outsourcing for VASPs, and the Travel Rule creates a specific problem: the obligation to transmit originator and beneficiary data alongside a transfer cannot be discharged by pointing to a third-party platform. The Travel Rule – the obligation under FATF Recommendation 15 and its implementing legislation across MiCA, MAS, the FCA regime and VARA – requires the originating VASP to send accurate counterparty data to the beneficiary VASP before or at the time of the transfer. If the Travel Rule solution is a vendor platform, the VASP must have contractual control over the data fields transmitted, must be able to demonstrate message integrity, and must have an incident-response procedure for the event that the platform goes offline mid-transaction.
Transaction monitoring presents the same structural challenge. A blockchain analytics tool, a KYC provider and an identity-verification platform are all components of the AML programme; none of them is the programme itself. The firm's MLRO – the money-laundering reporting officer, the designated individual accountable to the regulator for the AML regime – must be able to demonstrate that the outputs of outsourced tools are subject to human review, that the firm has tuned the tool's alert thresholds to its own risk profile, and that suspicious-activity reporting is triggered by internal decision, not vendor automation alone.
Regulators in the major hubs increasingly expect the MLRO to be a substantive position, not a nominal appointment. Under the FCA's registration framework, the MLRO must be a natural person of appropriate seniority within the firm. Under VARA's rulebooks, the compliance function has mandatory staffing and reporting expectations. Under MiCA, the "fit and proper" standard applies to the key function-holders who oversee AML. In a heavily outsourced operating model, the regulator's first question at examination is whether the MLRO actually controls the compliance function or merely relays vendor reports.
We have seen firms present transaction-monitoring outputs with impressive statistical dashboards and receive an adverse finding in the same inspection because the MLRO could not explain the alert parameters or demonstrate that rules had been reviewed in the prior twelve months. The dashboard was outsourced. The judgment was not.
Decision Matrix: Which Outsourcing Model Fits Which Operator Profile
Not every crypto firm faces the same outsourcing decision. The right structure depends on the firm's licence category, its cross-border footprint, and its internal technical capacity. The following profiles reflect patterns we see across our advisory engagements.
Profile A – Single-jurisdiction CASP, limited product set. A newly authorised CASP in a single EU member state operating a spot exchange with retail and institutional clients. This firm can rely heavily on third-party infrastructure for KYC, transaction monitoring and cloud hosting, provided the vendor contracts are brought up to the material-outsourcing standard required by its NCA. The governance overhead is manageable; the primary risk is inadequate contractual documentation. Timeline from licensing to a compliant outsourcing register: typically a matter of weeks if addressed systematically. Key risk: the NCA discovering during the first supervisory review that vendor contracts predate the CASP authorisation and lack right-to-audit clauses.
Profile B – Multi-licensed VASP, cross-border user base. A firm holding licences under VARA and MAS, serving users across the Gulf and Southeast Asia. This firm faces the additive documentation burden described above. Neither regulator will accept the other's outsourcing standard as a proxy. The firm needs a master outsourcing policy with jurisdiction-specific annexes, data-residency controls tailored to each regime, and separate incident-notification procedures for each supervisor. The MLRO function – or its equivalent under each regime – must be staffed to a level that can respond to two simultaneous supervisory inquiries without diverting the same person. Key risk: a vendor incident that triggers notification obligations in both jurisdictions within different reporting windows, creating a coordination failure that each regulator interprets as a disclosure delay.
Profile C – Token issuer under MiCA, custody and transfer outsourced. An entity issuing an asset-referenced token or e-money token under MiCA, relying on third-party custody of reserve assets and a third-party payment rail for redemptions. This profile faces the strictest outsourcing rules in the EU regime, because the integrity of the reserve and the redemption mechanism are the core obligations of ART and EMT authorisation. ESMA and the relevant NCA will expect that each component of the custody and settlement chain is covered by written agreements that give the regulator direct information rights. Outsourcing the custody function does not reduce the issuer's reserve-management obligation. Key risk: the custodian's terms of service not meeting the MiCA standard, and the issuer discovering this during the whitepaper approval process rather than at structuring.
Profile D – Exchange operating under an offshore licence with inbound EU or UK users. This is the profile the AUDIENCE_MYTH targets. A firm with a single registration in a light-touch offshore perimeter, providing services to EU or UK residents, faces the extraterritorial reach of MiCA and the FCA's financial-promotion rules regardless of its place of incorporation. The outsourcing regime of the offshore jurisdiction may be minimal – but the moment the firm's users are EU or UK persons, the firm is within scope of those supervisors' expectations for AML, Travel Rule compliance and, where relevant, marketing controls. Firms in our practice that have learned this from an enforcement letter rather than a legal opinion face a compressed remediation timeline with limited negotiating room. Key risk: assuming that the licensing question and the user-access question are the same question. They are not.
If a prior application stalled, a licence was restricted, or account rails were closed, a second review of your outsourcing structure often surfaces the structural cause. Write to info@oboluslaw.com or message t.me/oboluslaw to start that conversation.
Contrasting Positions: Light-Touch vs. Prescriptive Outsourcing Regimes
Not every jurisdiction applies the same degree of prescription to outsourcing arrangements. The contrast matters for firms choosing where to anchor their primary authorisation and where to rely on passporting or equivalence.
The BVI's VASP Act creates a registration and conduct framework that focuses on AML/CFT baseline compliance and beneficial ownership transparency, but does not yet impose the same granular outsourcing governance that MiCA or MAS require. A BVI-registered VASP with a cloud-hosted platform and a third-party KYC provider can satisfy the BVI FSC's expectations with lighter contractual documentation than an EU CASP. That is a feature for certain fund-administration and institutional-service models. It is not a substitute for a MiCA authorisation where EU clients are served.
Cayman Islands, similarly, imposes through CIMA a conduct and AML framework that is calibrated to the fund and capital-markets sector it historically regulated. The VASP track under the Virtual Asset (Service Providers) Act adds a registration layer but does not replicate the operational-resilience and outsourcing-governance depth of the EU or Singapore regimes. Firms using a Cayman vehicle as the issuer or general partner of a digital-asset fund, while operating a trading or custody function under a MiCA authorisation, face a documentation architecture that satisfies both – and must ensure the two governance frameworks are reconciled in writing.
Switzerland offers a different model. FINMA's token taxonomy and the fintech-licence route provide a path to regulated activity in a jurisdiction with deep financial infrastructure and a well-developed supervisory culture. FINMA's outsourcing expectations follow the Swiss Financial Market Infrastructure Act and the associated circulars, which are detailed and procedural. Firms that selected Switzerland for its reputation and infrastructure must budget for the documentation and governance overhead that matches.
The practical conclusion from the comparison is that light-touch offshore regimes reduce the compliance overhead for certain business models, but they do not reduce the compliance obligation where users in heavily regulated perimeters are being served. The relevant question for an operator is not which jurisdiction has the simplest outsourcing rules, but which combination of licences maps onto the jurisdictions where the users, the assets and the banking relationships actually sit.
How Regulators Audit Outsourcing – and What They Consistently Find
Supervisory inspections of outsourcing arrangements in crypto firms follow a pattern that has become predictable across the major hubs. Understanding the inspection methodology is useful for structuring the governance programme, because the gaps regulators find most often are not exotic – they are the same gaps appearing in each examination cycle.
The inspection typically begins with a request for the firm's outsourcing register. Regulators expect a document that lists every material outsourced function, identifies the vendor, the jurisdiction of the vendor's data processing, the contractual basis of the arrangement, the most recent due-diligence review date, and the recovery-time objective in the event of vendor failure. A register that was assembled for the licence application and not updated since is a red flag. A register that does not exist at all triggers an immediate escalation.
The second focus is vendor contracts. Regulators pull two or three material contracts and examine them against a checklist that the firm should already be using internally: right-to-audit clauses, business-continuity and disaster-recovery obligations, data-handling and data-residency terms, incident-notification procedures with defined timescales, and provisions for an orderly exit if the relationship is terminated. Missing items in vendor contracts, discovered during a supervisory inspection rather than a pre-inspection internal review, leave the firm in the uncomfortable position of negotiating with a vendor under regulatory time pressure.
The third focus is the MLRO's evidenced oversight of outsourced compliance functions. Regulators ask for board minutes, MLRO reports, and internal audit findings that demonstrate the firm's senior management engaged with the outsourcing risk – not just at the point of onboarding the vendor, but on an ongoing basis. Firms that cannot produce that evidence are treated as having transferred accountability to the vendor, which is not legally possible and triggers formal findings.
In our cross-border practice, we assist firms in preparing for these inspections through structured pre-examination reviews. The work typically surfaces three or four contractual gaps and one governance gap. Each is remediable, but the remediation window after a supervisory letter is shorter and more adversarial than the window before one.
The Common Assumption – One Offshore Licence Solves the Problem
A common assumption among operators entering the digital-asset market is that an offshore licence – BVI, Cayman, or a similar low-overhead perimeter – is sufficient to serve clients globally, provided the entity and its servers sit outside the EU, UK and US jurisdictional perimeters. That assumption is legally incorrect and is increasingly enforced against.
MiCA applies to any person offering crypto-asset services to EU clients or residents, regardless of where the offeror is established. The FCA's financial-promotion rules extend to communications directed at UK persons. FinCEN's money-services business rules reach any entity providing money-transmission services to US persons, wherever the entity is incorporated. None of those regimes is satisfied by an offshore registration that was not designed to meet their requirements.
The outsourcing dimension compounds the exposure. A firm operating under a light-touch offshore registration, using a cloud platform that processes EU-resident personal data, is simultaneously outside the EU licencing perimeter and inside the GDPR's processing obligations. Those are not the same question, and the answer to one does not resolve the other. We regularly advise operators who have discovered, sometimes after a regulatory inquiry, that their geographic arbitrage strategy was based on a misreading of which law applies to which activity.
The more durable structure identifies the jurisdictions where users and assets are concentrated, maps the licences required by those perimeters, and builds the outsourcing and cloud architecture around the union of those requirements – not the lowest common denominator. That is a more expensive initial build. It is considerably less expensive than an enforcement response, a banking relationship terminated for compliance reasons, or a licence suspension.
Operators we advise routinely discover that the cost of building the compliant structure from the outset is a fraction of the cost of rebuilding it after a supervisory finding. The decision matrix is not a choice between cost and compliance. It is a choice between the timing of the spend.
Related at OBOLUS
- AML, Travel Rule and compliance practice – how OBOLUS structures the full compliance and AML stack for licensed VASPs and CASPs
- KYC and onboarding framework: cross-jurisdiction comparison – how onboarding obligations differ across MiCA, MAS, VARA and the FCA regime
- Creditor claims in crypto insolvency – what recent enforcement tells operators about recovery risk and creditor priority
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15 and implemented across MiCA, the Payment Services Act in Singapore, VARA and the FCA regime, requires a VASP to collect and transmit accurate originator and beneficiary information alongside a virtual-asset transfer to the receiving VASP. The obligation applies at or before the time of the transfer. VASPs must have a compliant transmission mechanism, and the VASP – not a third-party platform – remains accountable for the accuracy and completeness of the data sent.
Who must act as MLRO for a crypto firm?
The money-laundering reporting officer – the designated individual accountable for the firm's AML regime – must be a natural person of appropriate seniority, typically approved or notified to the relevant regulator. Under the FCA's registration framework, the VARA rulebooks and MiCA's fit-and-proper standard, the MLRO must exercise substantive oversight of the compliance function, including outsourced AML tools, and must be capable of demonstrating that oversight through documented reviews, board reports and alert-management records.
How do regulators audit crypto AML programs?
Supervisory inspections of AML programmes typically cover the outsourcing register, vendor contracts, alert-management records, suspicious-activity reporting logs, transaction-monitoring tuning history, MLRO reports to senior management, and training records. Regulators in the major hubs – including ESMA-aligned NCAs under MiCA, the FCA, MAS and VARA – increasingly conduct thematic reviews of specific AML components rather than waiting for the scheduled authorisation review cycle, so firms should maintain inspection-ready documentation continuously.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule obligations that sit around every regulated activity. We map the licence, outsourcing and AML stack across operating, custody and payment layers before you commit to a structure. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when compliance failures become disputes. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border VASP and CASP outsourcing governance, AML programme structure and supervisory examination readiness.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.