EST · MMXXVI
Home/Insights/Regulatory/Regulator aml audit defence: The Structuring Angle
Compliance, AML & Travel Rule

Regulator aml audit defence: The Structuring Angle

Regulator aml audit defence: The Structuring Angle. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Why structural choices define AML audit outcomes

When a regulator opens an AML audit against a digital-asset business, the first question is almost never about a single suspicious transaction. It is about whether the firm's compliance architecture – the entity that holds the licence, the entities that touch customer funds, and the entities that sit between them – creates observable, auditable controls or a set of gaps that a regulator will characterise as systemic. The structuring angle in AML audit defence is the recognition that legal entity design, jurisdictional layering and the placement of compliance functions are as important to audit outcomes as the transaction monitoring logs. Businesses that conflate structural risk with operational risk routinely arrive at a regulatory hearing poorly positioned, not because their KYC processes were weak but because the compliance map presented to the auditor does not match the corporate map. This analysis unpacks both dimensions.

The core proposition is this: a VASP (virtual asset service provider) operating across multiple jurisdictions that holds one licence and routes activity through several affiliates must demonstrate, at audit, that the AML/CFT obligations that attach to the licensed entity are not diluted by that structure. Where they are – or where the auditor perceives that they are – the result is a deficiency finding that carries the weight of a structural failure, not a procedural one. The difference in regulatory consequence is material.

What follows addresses the mechanics of that exposure, the legal frameworks that create it, and the structural decisions that either amplify or reduce it across the leading digital-asset hubs.

What triggers AML obligations across jurisdictions?

The threshold question – which entity, doing what activity, in which jurisdiction, carries the AML obligation – is answered differently in each regime, and the gap between those answers is where structural risk lives. Under the FATF Recommendation 15 framework, a VASP conducting exchange, transfer, custody or administration of virtual assets must apply AML/CFT controls equivalent to those applied to traditional financial intermediaries. Every major hub has transposed this standard, but the scope definitions diverge in ways that matter to group structures.

Under MiCA (the EU's Markets in Crypto-Assets Regulation), the supervised entity is the CASP (crypto-asset service provider) authorised by an NCA (national competent authority) and supervised in coordination with ESMA. The CASP bears the AML obligation directly. But a group that runs a holding company in one EU member state, an operational entity in a second, and a technology-service entity in a third has a structural question: which entity is the CASP for the purpose of which activities? The authorisation follows the activity, not the label. If the technology entity controls customer onboarding data, the regulator will ask whether AML obligations that attach to onboarding have been correctly allocated.

In Dubai, VARA's activity-based licence regime means that each regulated activity – custody, exchange, transfer/settlement – carries its own licence and, with it, its own AML compliance perimeter. A firm that holds a single VARA exchange licence but routes transfers through an affiliated entity that is unlicensed for transfer services has created a structural gap that VARA examinations are specifically designed to expose.

In Singapore, the MAS regime under the Payment Services Act – which applies to DPT (digital payment token) service providers – places AML/CFT obligations on the licensed major payment institution. An affiliated entity providing "technology services" to that institution is not automatically outside MAS scrutiny if its activities amount to conducting the regulated service in substance.

The cross-cutting principle is one of substance over form. Regulators in the leading hubs increasingly assess the economic and operational reality of the group, not merely the formal allocation of licences. A structural defence that depends on a label – "this entity is a technology company, not a VASP" – must be grounded in an honest assessment of what that entity actually does.

For a scoped review of your entity structure against the regulated perimeter in your key jurisdictions, contact OBOLUS at Map your options. The process above describes the standard analysis. Your facts – the entities that touch clients, the flow of funds, the location of controls – change the assessment materially.

How group structures create audit surface

Every intercompany relationship in a digital-asset group is a potential audit finding. That is not an overstatement. It is the direct implication of how regulators approach consolidated AML supervision.

Three structural patterns generate the largest volume of audit risk in the firms we advise.

The first is the technology-services affiliate. A parent company provides a white-label trading engine, KYC data infrastructure or transaction monitoring tooling to a licensed operating entity. The affiliate holds no licence. But it processes the data that the licensed entity's AML program depends on. At audit, the regulator will test whether the licensed entity has adequate oversight and contractual control over that affiliate's outputs. If the data-sharing agreement is thin or the affiliate sits in a jurisdiction with different data-access rules, the auditor has a line of questioning that the compliance team is often not prepared for.

The second pattern is the payment-relay entity. Fiat flows in and out of the group through a payment entity that may hold a money services licence or an e-money institution authorisation in a jurisdiction separate from the primary operating licence. If the KYC records held by the operating entity and the transaction records held by the payment entity are not reconciled in a way the auditor can verify, the Travel Rule chain – the obligation to pass originator and beneficiary data with each transfer – is demonstrably broken at the intercompany seam.

The third is the custodial affiliate. Digital-asset custody is a regulated activity in most flagship regimes. A firm that custodies client assets in an entity that is a sister company of the licensed VASP, rather than the VASP itself, needs a clear legal basis for that arrangement that the auditor can follow. Where the custody arrangement is undocumented or governed by a generic intercompany services agreement that was drafted before the custody regime came into force, the finding is predictable.

In our practice, we see all three patterns produce audit risk not because the firm intended a compliance gap but because the structure was built for operational efficiency and the compliance layer was added afterwards. Retrofitting is harder than building correctly. Auditors are experienced at distinguishing the two.

Does the Travel Rule create structural obligations beyond transaction-level compliance?

The Travel Rule (the obligation to pass originator and beneficiary information with each virtual asset transfer above the applicable threshold) is frequently treated as an operational compliance item – a matter of selecting a Travel Rule protocol and configuring the transaction-monitoring system. That is a correct but incomplete view. The structural dimension of Travel Rule compliance is the question of which entity in the group is legally obligated to collect, transmit and receive the required information, and whether the group's corporate structure allows that entity to do so in practice.

Where a group routes transfers through a payment-relay affiliate in a different jurisdiction, the Travel Rule obligation may sit with the affiliate rather than the licensed exchange. If that affiliate is registered but not fully licensed, or if it is in a jurisdiction where the Travel Rule threshold is set differently, the group faces a compliance gap at the seam between entities. Regulators in the EU operating under ESMA's coordinated MiCA supervision are increasingly attentive to exactly this seam.

The practical implication is that Travel Rule compliance architecture must be group-wide, not entity-specific. The policies, the data-sharing protocols and the counterparty VASP due-diligence framework must run across the entities that collectively handle a transfer, from origination to settlement. Where those entities sit in different jurisdictions – as they frequently do – the group needs a documented legal basis for cross-entity data sharing that is consistent with the data-protection rules in each jurisdiction.

This is not a theoretical concern. In cross-border groups operating between the EU and the UAE, the GDPR-equivalent data rules and the VARA Travel Rule requirements are not automatically aligned. The legal work is in the mapping, not the assumption.

Where you place the MLRO determines more than you expect

The MLRO (Money Laundering Reporting Officer) placement decision – which entity holds the MLRO, and whether that individual has visibility across the group – is a structural one with direct audit consequences. Most jurisdictions require that each licensed entity have a designated MLRO with appropriate seniority, independence and access to the information needed to discharge the role. The question for a multi-entity group is whether a single MLRO, or a matrix of MLROs, satisfies those requirements across the group's jurisdictions.

VARA's rulebooks and the MAS regime under the Payment Services Act both set expectations about the MLRO's seniority, their operational independence from business lines and their ability to escalate directly to the board. Placing the MLRO in a holding company entity that does not itself hold the regulated licence, without a clear delegation and oversight mechanism documented in the compliance framework, creates an audit finding of the kind that regulators characterise as a governance failure.

The FCA's approach in the UK – where cryptoasset businesses must register under the Money Laundering Regulations and satisfy the FCA that their AML controls are effective – places particular emphasis on whether senior management responsibility for AML is genuinely owned at the regulated entity, not assigned notionally from a parent. Deficiency notices in this area tend to escalate quickly to supervisory engagement.

A correctly structured MLRO framework for a multi-entity digital-asset group typically includes a primary MLRO at each licensed entity with genuine authority; a group-level compliance function with information rights across entities but not a substitute for entity-level ownership; and a governance document that maps which compliance decisions are made at entity level and which are escalated. That document is one of the first things an experienced regulator asks for.

Decision matrix: which structural profile faces which audit risk?

Not all digital-asset businesses face identical audit risk. The risk profile tracks the structural choices made at formation and at each subsequent expansion. The following matrix describes four common profiles, each with its dominant risk vector and the structural fix that addresses it.

Profile A – Single licensed entity, direct client relationships, no affiliates. This is the lowest-complexity audit profile. The AML obligation, the MLRO function and the transaction monitoring are all housed in one place. The audit surface is limited to the operational quality of those controls. The dominant risk is operational, not structural: gaps in KYC procedures, inadequate transaction monitoring thresholds, or failure to file suspicious activity reports in the required window. The structural fix is not needed – the fix is operational hygiene.

Profile B – Licensed operating entity with a technology-services affiliate in a different jurisdiction. The dominant risk is the supervised entity's ability to demonstrate oversight and contractual control of the affiliate's outputs. The structural fix is a robust intercompany agreement that grants the licensed entity audit rights, data access and the ability to enforce AML-relevant obligations against the affiliate. The compliance program must explicitly address data flows from the affiliate, including their use in the KYC and transaction monitoring processes.

Profile C – Group with licensed entities in multiple jurisdictions, each serving different user geographies. The dominant risk is fragmented Travel Rule compliance and inconsistent KYC standards across entities. The structural fix is a group-wide AML policy that sets minimum standards, with entity-level policies that meet or exceed those standards and are reconciled at group level. The MLRO matrix must be documented and tested at audit. Travel Rule data flows must be mapped across all intercompany transfer seams.

Profile D – Group with a licensed operating entity and an unlicensed or lightly regulated payment or custody affiliate. This is the highest-risk profile. The structural fix, in most cases, is to bring the affiliate within the regulatory perimeter – either by licensing it or by restructuring the function into the licensed entity. Where that is not commercially feasible in the short term, the group needs a legal opinion that supports the current structure, ideally from counsel in each relevant jurisdiction, and a compliance overlay that treats the affiliate as a regulated third party for due-diligence purposes.

If you recognise your structure in Profile C or D, the time for a structural review is before the next examination cycle begins – not after. Contact OBOLUS at Map your options. If a prior assessment flagged structural gaps, a second read can surface the route back to a defensible position.

Micro-matter: cross-border group restructuring ahead of a regulatory examination

In a recent matter, a digital-asset exchange group with licensed entities in an EU member state and an offshore financial centre had built its compliance architecture over several years of rapid growth. The group's Travel Rule implementation ran through a payment affiliate incorporated in a third jurisdiction. That affiliate's intercompany agreement with the licensed EU entity predated the MiCA transition period and did not address the CASP's specific Travel Rule data obligations under the updated regime. When the EU regulator's examination schedule was announced, the group had a window of several months to respond.

We worked with the group to map every intercompany data flow that touched AML-relevant information, identified the three seams at which the Travel Rule chain was not documented to the standard the examination would test, and drafted updated intercompany agreements and a group-wide AML policy that brought the affiliate's obligations into line with the CASP's requirements. The MLRO structure was also revised: the group's existing arrangement placed the MLRO at the holding company level only, and we worked with the group to establish entity-level MLRO appointments with documented delegation from the group function. The examination proceeded with no structural deficiency findings. Operational findings in transaction monitoring were addressed separately and resulted in a standard remediation plan.

The outcome turned on the pre-examination window. Groups that discover structural gaps during an examination, rather than before it, have far less room to address them without regulatory intervention.

Contrasting positions: substance over form in AML audit defence

There are two defensible positions a group can take at the outset of a regulatory examination. The first is the formalist position: the group presents the licences held, the compliance policies adopted and the technical controls deployed, and argues that it has met the legal requirements as written. The second is the substantive position: the group presents the same materials but frames them within an honest account of how the group actually operates – which entities touch clients, where decisions are made, how data flows – and demonstrates that the compliance architecture maps to the operational reality.

In our cross-border practice, the formalist position fails more often than it succeeds. Experienced AML examiners in the leading hubs are skilled at reconstructing the economic reality of a group from corporate structure charts, system logs and intercompany agreements. A presentation that leads with the formal structure invites the examiner to test it. A presentation that leads with the operational reality and then shows how the compliance framework addresses it gives the examiner less investigative room.

The legal implication of this is not that firms should disclose weaknesses they are not required to disclose. It is that the audit defence strategy should be built on a compliance map that the group can honestly defend, not on a compliance map that looks correct in isolation but collapses when tested against operational data. Building that map is the first step in any structuring engagement we undertake for a group facing an examination.

A common assumption in this area is that once licences are in place across the operating jurisdictions, the AML audit defence work is complete. It is not. Licences define the perimeter of regulatory supervision. They do not automatically produce the compliance architecture that passes examination. The architecture must be built, documented and tested.

How does banking interact with the AML audit picture?

Digital-asset businesses operate without stable banking access at significant competitive and legal disadvantage. The connection to AML audit defence is direct. A group whose banking arrangements are fragile – meaning that the bank holds a contractual right to exit on AML-related grounds, or that the group relies on multiple payment intermediaries with varying levels of due diligence – faces two simultaneous risks when an AML examination begins.

The first is the examination itself. The second is the risk that the bank, on becoming aware of the examination, exercises its exit right. Both risks are amplified by a compliance architecture that is not prepared for scrutiny. Conversely, a group that enters an examination with a well-documented AML program, an honest structural map and a clear MLRO function is a more defensible banking client. Banks conduct their own AML due diligence on business customers; the materials a firm prepares for a regulatory examination overlap significantly with the materials a bank will request.

Operating without the right licence and the right compliance architecture risks enforcement action, frozen payment rails and lost banking relationships simultaneously. Those three consequences tend to arrive together, not sequentially. The structural work that addresses examination risk also addresses banking risk, which is why we approach AML structuring as a combined licence, compliance and banking exercise, not a siloed regulatory matter.

For groups with entities in the EU and the Gulf – a common configuration in the firms we advise – the banking interaction is particularly acute. VARA-licensed entities in Dubai operate in a banking environment that is attentive to AML posture. EU-licensed CASPs must satisfy their NCA on AML and also maintain banking relationships under GDPR-compliant data-sharing arrangements. Aligning those two requirements across a group requires legal input at the structural level, not just at the operational level.

Self-assessment: is your AML structure examination-ready?

The following questions test the examination readiness of a group's AML compliance structure. They are not a substitute for a professional assessment, but they are the questions an experienced examiner will ask.

First: can you draw a corporate structure chart that accurately reflects which entity holds each licence, which entity holds client assets, which entity holds client data and which entity processes payments – and does that chart match the one in your compliance documentation?

Second: for each intercompany relationship that touches AML-relevant data or processes, is there a written agreement that specifies the AML obligations of each party, grants audit rights to the licensed entity and is governed by law that allows the licensed entity to enforce those obligations?

Third: does each licensed entity have a designated MLRO with seniority, independence and information access adequate to discharge the role under the requirements of that jurisdiction's AML regime?

Fourth: does the group's Travel Rule compliance framework identify every intercompany transfer seam at which originator or beneficiary data must be passed, and is each seam covered by a documented protocol that specifies the data standard and the counterparty VASP due-diligence process?

Fifth: is the group's KYC framework documented at group level with entity-level policies that address jurisdiction-specific requirements, and have those policies been tested against a sample of actual customer files within the last review cycle?

A "no" answer to any of these questions is a finding that a competent examiner will reach. The time to address it is before the examination schedule is announced.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – derived from FATF Recommendation 16 as applied to virtual assets – requires a VASP to collect, verify and transmit originator and beneficiary information with each virtual asset transfer above the applicable threshold. The specific data fields, the threshold amount and the technical standard for transmission vary by jurisdiction. In practice, compliance requires a Travel Rule protocol, counterparty VASP due-diligence procedures, and intercompany agreements where the transfer chain crosses group entities. Threshold figures are jurisdiction-specific and should be verified against current legislation in each relevant regime.

Who must act as MLRO for a crypto firm?

Each licensed entity in a digital-asset group must typically designate a Money Laundering Reporting Officer (MLRO) who meets the seniority, independence and competency requirements set by the relevant regulator. Under regimes including VARA, the MAS Payment Services Act and the FCA's MLR registration, the MLRO must have genuine authority to escalate concerns to the board and direct access to the compliance data necessary to perform the role. Placing MLRO responsibility at a holding-company level without documented delegation to the licensed entity is a common structural deficiency finding at examination.

How do regulators audit crypto AML programs?

Regulators in the leading digital-asset hubs – including ESMA-coordinated NCAs under MiCA, VARA in Dubai and MAS in Singapore – typically examine both the documented AML framework and its operational reality. An examination will test whether corporate structure, compliance documentation and actual data flows are consistent; whether the KYC and transaction monitoring controls are calibrated to the firm's risk profile; whether the Travel Rule chain is unbroken across entities; and whether the MLRO function is genuinely independent. A mismatch between the documented structure and the operational one is among the most common triggers for an escalated supervisory response.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and structural work that sits around them. Digital assets are the entirety of our practice, and we act only for businesses – never retail. We map the licence, compliance and banking stack across operating, custody and payment layers before clients commit to a structure, because the structural choices made at formation are the ones that determine audit outcomes. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML compliance architecture, regulatory examination strategy and cross-border VASP structural analysis for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours