EST · MMXXVI
Home/Insights/Regulatory/Regulator aml audit defence: What Recent Enforcement Tells Operators
Compliance, AML & Travel Rule

Regulator aml audit defence: What Recent Enforcement Tells Operators

Regulator aml audit defence: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

With AML enforcement against digital-asset businesses intensifying across every major licensing hub, the gap between a compliant program and a defensible one has never mattered more. Regulators are no longer satisfied by a policy document and a checkbox KYC flow. They are auditing transaction monitoring calibration, probing the Travel Rule data chain, and testing whether a firm's Money Laundering Reporting Officer (MLRO) has real authority or is simply a name on a form. This analysis draws on what recent enforcement patterns reveal – from VARA and MiCA-era national competent authority reviews to FCA and MAS supervisory visits – to show operators exactly where the defensibility gap opens.

The core lesson from a wave of supervisory actions across leading hubs is this: documented intent is not the same as operational effectiveness. Regulators assess whether controls actually work at the transaction level, not whether the compliance manual is well-written. The following sections map the enforcement anatomy, contrast the positions regulators take against what operators typically present, and set out a decision matrix for building a program that survives scrutiny.

What the enforcement pattern actually looks like

Regulators across the major hubs are structuring AML audits around the same three fault lines: program adequacy, control effectiveness and senior management accountability. Understanding that anatomy is the first step in building a defence. The audit does not begin with a fine; it begins with an information request that maps exactly those three dimensions.

In our cross-border practice, we see a consistent pattern. The supervisory letter arrives requesting six to eighteen months of transaction monitoring data, escalated alerts, MLRO reports to the board, and records of Suspicious Activity Report (SAR) filings. The subtext of every request is the same: show us the gap between what your policy says and what your operations do.

Under MiCA, national competent authorities have explicit supervisory powers to demand access to AML systems, require explanations of control failures and issue binding remediation timelines. The EU framework does not treat AML as a bolt-on; it treats it as a condition of authorisation. Operators who received CASP authorisation expecting a one-time compliance review quickly discover that ongoing supervisory engagement is the baseline expectation. VARA in Dubai operates a similar model: activity-based rulebooks specify AML obligations at the transactional level, and supervisory visits are calibrated to test live system behaviour, not just documentation.

The FCA's approach under the UK Money Laundering Regulations adds a further dimension. Cryptoasset businesses registered under the MLR face the same supervisory depth as authorised payment firms. In our practice, we have seen post-registration reviews where the regulator's technical team submitted test transactions to a firm's KYC onboarding flow specifically to measure friction, flag rates and data-collection completeness. The lesson is direct: assume your controls are the specimen, not your policies.

Why the Travel Rule is the most common audit flashpoint

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data alongside a virtual asset transfer – is now the single most contested area in AML supervisory reviews of virtual asset service providers (VASPs). Regulators consistently find that firms have a Travel Rule policy but lack operational infrastructure to execute it at scale.

The structural challenge is well-known. A VASP must identify the counterparty VASP on the receiving side of a transfer, exchange identifying data before or simultaneously with the transfer, and retain records. Where the counterparty is unhosted – a self-custodied wallet – the obligation shifts to enhanced due diligence and risk-based controls. Each of those steps requires technical integration, not just a policy commitment.

Regulators in MiCA member states have been particularly focused on Travel Rule data completeness. The framework's transfer-of-funds provisions extend the obligation to crypto-asset transfers in a way that aligns with FATF guidance, and national competent authorities are actively testing whether firms can produce originator and beneficiary data on demand for any given transaction in their window. MAS in Singapore has published supervisory expectations that make clear Travel Rule compliance is assessed on a live-system basis, not on the presence of a policy alone.

Two failure modes appear most frequently in our cross-border advisory work. The first is a technology gap: the firm has a Travel Rule solution for transfers to other registered VASPs but no defined protocol for unhosted-wallet transfers, which in practice constitute a significant proportion of total volume for certain exchange types. The second is a data-quality gap: the system captures originator data but with insufficient granularity – a wallet address without a legal name, or a legal name without an account identifier. Neither meets the regulatory standard, and both are visible in audit data.

For a scoped review of your Travel Rule infrastructure before the next supervisory cycle begins, contact OBOLUS at info@oboluslaw.com. The process above describes the standard enforcement anatomy. Your facts – the entity structure, the wallet types you serve, the jurisdictions your users sit in – change the analysis materially.

How regulators test transaction monitoring calibration

Transaction monitoring calibration – the process of setting alert thresholds, velocity rules and risk-scoring parameters to generate alerts at the right rate – is now a primary supervisory focus because it is objectively testable from a regulator's vantage point. A system generating very few alerts is not a sign of a clean book; it is a red flag that thresholds are set to suppress investigation.

The audit methodology regulators use is instructive. They request alert data over the review period and cross-reference it against on-chain transaction characteristics: mixers, high-risk jurisdictional exposure, structuring patterns just below reporting thresholds, and rapid layering. If the firm's alert rate is implausibly low relative to its transaction profile, the regulator can infer miscalibration without needing to prove it through a specific failure.

In a recent advisory engagement, we reviewed a mid-size exchange's transaction monitoring output ahead of a scheduled supervisory visit. The system was generating alerts at roughly half the rate of comparable firms in the same asset class. The cause was a lookback window that was too short – the system was not catching multi-leg layering spread across several days. Recalibrating the lookback period and adding cross-account velocity rules brought the alert rate into a defensible range before the visit. The outcome illustrated a broader principle: the defensibility of a monitoring programme is measured by whether it would catch the transactions regulators expect it to catch, not by whether it generates few false positives.

Operators that rely on out-of-the-box monitoring configurations without tuning them to their specific user base, asset types and transaction patterns are routinely exposed in audit. Regulators under VARA, under the MiCA regime and under the FCA's MLR supervisory framework increasingly expect documented evidence of ongoing calibration – not a set-and-forget implementation. That means model validation logs, threshold-change records and periodic reviews by a qualified compliance function.

What MLRO accountability means under current supervisory expectations

The MLRO is the individual accountable to the regulator for the firm's AML program. Supervisory pressure has moved that role from administrative to genuinely senior – and the consequences of a nominal appointment are now significant. Regulators are asking whether the MLRO has budget authority, access to board reporting and operational independence from commercial leadership.

Under every major regime – MiCA, VARA, MAS's Payment Services Act framework, the FCA MLR regime – the MLRO must be a natural person, typically resident or at least accessible to the relevant regulator, with demonstrable competence in AML and the specific asset types the firm handles. A compliance officer who doubles as the Chief Operating Officer and has no dedicated resource is structurally incapable of meeting the independence standard, regardless of what the organisational chart says.

The accountability question sharpens in cross-border structures. A firm with a MiCA CASP authorisation in one EU member state, a VARA licence in Dubai, and user acquisition operations in a third jurisdiction needs to resolve clearly which MLRO is responsible for which activities, whether group-level policies flow down effectively, and whether the relevant regulators can reach the right individual within the timeframes their rules require.

We regularly advise multi-jurisdictional groups on MLRO structuring. The consistent finding is that regulators in the leading hubs increasingly expect the MLRO to have a documented mandate – a written terms of reference or equivalent – that is approved by the board and reviewed at least annually. The absence of that document is itself an audit finding, independent of whether the underlying AML program is sound.

Contrasting positions: what operators present versus what regulators expect

The central tension in AML audit defence is a framing mismatch. Operators tend to present their compliance program as a set of policies and procedures. Regulators assess it as a set of operational controls with measurable performance.

This contrast plays out across four specific dimensions in supervisory reviews we have observed.

First, on KYC framework depth: operators frequently present customer due diligence procedures that describe what should be collected at onboarding. Regulators want to see what was actually collected, how many accounts passed enhanced due diligence with incomplete data, and what triggered a step-up review. The defensible position requires operational data, not policy text.

Second, on SAR quality: the number of SARs filed is less important than the quality of the underlying analysis. A regulator reviewing a batch of disclosures that consist of transaction hashes and a one-line description will find that more concerning than a lower volume of well-reasoned, analytically complete reports. Quality signals that the firm understands its own risk exposure. Quantity without quality signals that the monitoring system is generating alerts that the compliance team cannot actually evaluate.

Third, on risk appetite documentation: operators often state a risk appetite in general terms – "we do not serve high-risk jurisdictions" – without mapping that statement to a defined list, a product-level control and a monitoring rule. Regulators, particularly under VARA and MiCA, expect the risk appetite to be operationalised at the transaction level. The statement alone is not the control.

Fourth, on vendor reliance: a significant number of firms delegate substantial compliance function to a single KYC or transaction monitoring vendor and present the vendor's capabilities as their own. Regulators consistently treat vendor dependency as a risk factor, not a mitigant. The expectation is that the firm understands its own data, can override vendor decisions and has a documented oversight process for vendor performance.

Why cross-border structures create specific AML audit risk

A business operating across multiple regulatory perimeters – say, a MiCA-licensed CASP in an EU member state serving users whose assets are custodied through a BVI entity and whose transfers flow through a payment rail in Singapore – faces a compounding risk that each regulator will assess the program as if it owns the whole of the obligation.

That expectation is not unreasonable. FATF standards and the regimes built on them – including MiCA, the MAS Payment Services Act framework and the VARA rulebooks – do not recognise a "home regulator handles it" exemption for group-level compliance. Each licensed entity is expected to have controls adequate for its own activities. Group-level policies that are written for the parent and applied to subsidiaries without local adaptation routinely fail supervisory review in the subsidiary's home jurisdiction.

The Travel Rule amplifies this risk. A transfer that originates with a VARA-licensed entity and terminates with a MiCA-licensed CASP needs to satisfy the data requirements of both regimes. If the sending firm collects data to FATF minimum standards but the receiving jurisdiction's transposition imposes additional fields, the data chain breaks at the border. That break is auditable by either regulator.

In our cross-border practice, we work with allied counsel in the relevant jurisdiction to map the specific data requirements at each step of the transfer chain before the firm goes live. The alternative – discovering the gap during a supervisory review – is materially more costly in both time and regulatory goodwill.

If a prior application stalled or a compliance gap was identified in an audit, a second read can surface the structural reason and a route forward. Write to our team at info@oboluslaw.com to scope the review.

An anonymised matter: pre-audit programme remediation

In a recent engagement, a payments company holding a digital-asset registration in a major European jurisdiction engaged us ahead of a scheduled supervisory review. The firm had operated under the prior national VASP regime and was transitioning to MiCA-aligned authorisation. Its transaction monitoring system was a legacy configuration calibrated for fiat payments, not crypto-asset transfers. Alert rules did not account for multi-hop on-chain layering, and the MLRO had no formal mandate document. We conducted a gap analysis across the monitoring infrastructure, the Travel Rule data chain and the MLRO governance structure, engaged allied counsel in the local jurisdiction to align the remediation to the national competent authority's specific supervisory style, and delivered a documented remediation report with an implementation timeline. When the supervisory review proceeded, the firm was able to present operational evidence – calibration logs, Travel Rule test runs and a board-approved MLRO mandate – rather than policies alone. The supervisory visit concluded without a remediation direction.

Decision matrix: matching your profile to the right remediation priority

Not every operator faces the same audit risk profile. The right remediation priority depends on the firm's licence type, transaction volume and jurisdictional footprint. The following matrix describes three common profiles.

Profile A – Early-stage CASP with MiCA authorisation, primarily retail on-ramp: The primary risk is KYC framework depth. At lower transaction volumes, monitoring calibration matters less than ensuring that customer due diligence is complete and that enhanced due diligence triggers are operationalised. The Travel Rule exposure is moderate, mainly affecting transfers above the applicable threshold to other VASPs. Remediation priority: KYC operational audit, enhanced due diligence documentation, Travel Rule vendor selection. Timeline to defensible position: typically a matter of weeks for the documentation layer, longer if vendor integration is required.

Profile B – Mid-size exchange with multi-jurisdictional user base and custody services: The primary risk is transaction monitoring calibration and cross-border Travel Rule data quality. The firm likely has monitoring in place but with insufficient tuning for its specific asset mix and user behaviour. MLRO accountability is also a live risk if the function sits below senior management in practice. Remediation priority: monitoring model validation, Travel Rule chain audit, MLRO mandate formalisation. Timeline: varies by the complexity of the technology stack, but a structured programme can be completed before a supervisory cycle in most cases.

Profile C – Offshore-structured group with onshore licensing in two or more hubs: The primary risk is group-policy cascade failure – the situation where the parent's AML program does not translate into operationally effective controls at the licensed-entity level. Regulators in each hub assess the entity in their jurisdiction, and a gap at any node is a finding. Remediation priority: entity-level policy localisation, data-sharing agreements between group entities, and a documented MLRO structure that allocates accountability clearly across the group. Timeline: a group-level remediation of this type is a sustained programme; prioritise the entities facing the nearest supervisory cycle.

A common assumption that creates audit risk

A common assumption among operators is that an offshore or single-hub licence provides a compliance umbrella for the entire group's activities. It does not. Each regulator supervises the entities and activities within its perimeter. A firm that is fully compliant with its primary regulator but has an unlicensed entity processing transfers in a second jurisdiction, or a licensed entity applying a group AML policy that does not meet the second regulator's specific requirements, is exposed in both places simultaneously.

The related assumption is that AML compliance is primarily a documentation exercise. Supervisory practice across VARA, MiCA national competent authorities, MAS and the FCA now consistently tests operational effectiveness. Documentation is the starting point of the audit, not the end of it. Operators who invest in policy without investing in system calibration, data quality and MLRO governance are systematically under-prepared for the supervisory environment that exists today.

The practical corrective is straightforward: treat every audit as if it were a live operational test, not a document review. That means maintaining calibration logs, Travel Rule test records, MLRO reporting chains and vendor oversight documentation as standing operational records, not artefacts produced for a supervisory visit.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP to collect and transmit originator and beneficiary identifying information alongside a virtual asset transfer. The specific data fields, the de minimis threshold below which the obligation does not apply, and the treatment of transfers to unhosted wallets vary by jurisdiction. Operationally, compliance requires both a technical solution capable of exchanging data with counterparty VASPs and a risk-based protocol for transfers where the counterparty is unhosted or unresponsive.

Who must act as MLRO for a crypto firm?

The MLRO must be a natural person with demonstrable AML competence and, in most major licensing regimes, a degree of operational independence from commercial functions. Under MiCA, VARA, MAS and FCA requirements, the role carries personal accountability for the firm's AML program. Multi-jurisdictional groups must resolve clearly which individual is accountable to which regulator, and that allocation should be documented in a board-approved mandate. A nominal appointment – a name on a form without real authority or resource – creates significant supervisory risk.

How do regulators audit crypto AML programs?

Regulators typically begin with an information request covering transaction monitoring data, alert and escalation records, SAR filings, customer due diligence samples and MLRO reports to senior management over a defined review period. The analysis tests whether documented controls are operationally effective – whether alert thresholds are calibrated correctly, whether Travel Rule data is complete, and whether the MLRO function has real authority. Some regulators also conduct live testing of onboarding flows and submit test transactions to assess friction and data collection in practice.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. Operators we advise routinely tell us that the gap between a compliant programme and a defensible one only becomes visible under supervisory pressure. We map that gap before the regulator does. To discuss your AML programme or a forthcoming supervisory review, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML programme design and supervisory defence for digital-asset businesses across EU, UAE and Asia-Pacific regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours