Enforcement against virtual asset service providers (VASPs – firms that exchange, transfer, safeguard or arrange dealing in virtual assets) has shifted from isolated penalty notices to coordinated, multi-jurisdictional action. The pattern is now clear: regulators are targeting the gap between a firm's stated compliance posture and its actual transaction-monitoring performance. For any operator assessing its own exposure, the enforcement record offers the most honest benchmark available.
This analysis draws on what regulators across the major hubs have communicated through enforcement decisions, supervisory letters and published guidance. It contrasts the positions taken in different regimes, maps the risk factors that consistently attract scrutiny and presents a practical decision matrix for operators working across borders. One anonymized matter from our practice illustrates how the risk crystallizes in real time. A full VASP business risk assessment – covering AML compliance, the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual asset transfer), KYC framework adequacy and transaction monitoring – is the starting point for any defensible compliance posture today.
What Enforcement Patterns Reveal About Regulatory Expectations
Recent enforcement tells a consistent story: the highest-risk profile is not the firm that lacks a policy document but the firm whose documented policies are not reflected in its live transaction flows. Regulators in leading hubs – the FCA in the United Kingdom, MAS in Singapore, FinCEN in the United States and ESMA's network of national competent authorities under the MiCA regime – have each signaled the same expectation. A VASP must demonstrate that its AML program is operational, not merely written.
The specific failure modes repeat across jurisdictions. First, customer due-diligence records that are incomplete at account opening. Second, transaction monitoring thresholds set so high that structuring activity passes through undetected. Third, Travel Rule data that is collected but never verified. Fourth, a compliance officer who is formally appointed but operationally bypassed when commercial pressure builds.
In our cross-border practice, we see the same four failure modes in almost every pre-enforcement review we conduct. The pattern is durable because it reflects a structural tension: the compliance function is a cost center, and the commercial function sets the pace.
FATF Recommendation 15 on virtual assets, and the FATF guidance on the Travel Rule, have given national regulators a common benchmark against which to measure VASPs. Where a firm cannot demonstrate alignment with that benchmark, the regulatory response has moved from guidance letters to formal enforcement with meaningful financial consequences.
Why the Travel Rule Gap Is the Highest-Probability Enforcement Trigger
The Travel Rule is currently the single most frequently cited deficiency in VASP enforcement actions across the major hubs, because full compliance requires simultaneous action by both the originating and beneficiary VASP – a bilateral dependency that breaks down the moment one counterparty is unregulated or uncooperative.
Under FATF standards, a VASP transferring virtual assets must collect and transmit originator and beneficiary information alongside the transaction. The threshold at which this obligation activates varies by jurisdiction – firms should verify the applicable de-minimis in each market they serve – but in practice, regulators expect controls to function across the transfer book, not only above a threshold.
The cross-border dimension is acute. A VASP licensed in the European Union under the MiCA regime and receiving transfers from a counterparty in a jurisdiction with no Travel Rule implementation faces an immediate compliance asymmetry. Regulators have been explicit: the obligation falls on the regulated firm regardless of what the counterparty does. The regulated VASP cannot receive funds and proceed as if the incoming data is sufficient. It must have a policy for what happens when it is not.
In a recent compliance review, a payments company serving both EU and Asian corridors discovered that its Travel Rule vendor was capturing originator data but not verifying it against the customer's KYC record. The mismatch went undetected for several months. We identified the gap during a pre-licensing review and redesigned the firm's counterparty onboarding protocol before the supervisory examination that followed. The outcome was a clean examination finding rather than a remediation order.
To map your Travel Rule obligations across every corridor your business operates, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the transfer corridors, the technology stack – change the analysis materially.
How Regulators Assess KYC Framework Adequacy
A KYC framework is adequate when it matches the actual risk profile of the customer base – not the theoretical risk profile assumed during system design. Regulators have made this distinction explicit in supervisory communications across multiple hubs, and it is the distinction that separates defensible programs from those that attract remediation.
The practical test regulators apply is whether enhanced due diligence is being triggered at the right volume and depth. A VASP serving institutional counterparties in a small number of regulated jurisdictions should be running lighter automated screening and heavier relationship-level due diligence. A VASP with a large retail customer base across emerging markets should be doing the opposite. When the controls are miscalibrated – too light for the actual risk, or so heavy on low-risk accounts that the compliance team is swamped and genuine alerts are missed – regulators treat this as a systemic failure, not an isolated gap.
Under the MiCA regime, national competent authorities are expected to assess whether a CASP's customer risk assessment methodology is dynamic – updating when customer behavior changes, not just at onboarding. The FCA has communicated the same expectation through its supervisory engagement with registered cryptoasset businesses. MAS in Singapore has been explicit that periodic customer reviews must be risk-triggered, not just calendar-driven.
The cross-border complexity here is significant. Operators serving customers in multiple jurisdictions must layer jurisdictional risk onto customer risk. A customer resident in a jurisdiction with weaker AML/CFT controls is not equivalent in risk terms to an otherwise identical customer in a jurisdiction with a well-developed supervisory regime, even if the transaction values are the same.
What Transaction Monitoring Failures Look Like in Practice
Transaction monitoring failures in VASP enforcement cases almost always fall into one of three categories: rules that are set but never tuned, alerts that are generated but never resolved and outputs that are reviewed but never escalated to SARs (suspicious activity reports) at an appropriate rate.
The first category – rules set but never tuned – is the most common. A VASP launches its monitoring system at go-live and sets thresholds based on early transaction data. As volumes grow and the customer base diversifies, the thresholds become obsolete. What was a meaningful alert at launch becomes noise. Regulators have specifically called out the failure to conduct periodic rule-effectiveness reviews as a standalone compliance deficiency, separate from the failure to file SARs.
The second category – alerts generated but not resolved – typically reflects a resource mismatch. A compliance team sized for fifty thousand monthly transactions cannot work effectively at five hundred thousand. When alert queues back up, the realistic choices are to close alerts without investigation, to raise thresholds and suppress the volume or to hire. Regulators have seen all three responses and treated the first two as evidence of an inadequate compliance program.
The third category – reviews without escalation – is the most legally hazardous for individuals within the firm. A compliance officer who sees a pattern, documents it and does not file a SAR (or its jurisdictional equivalent) has created a written record of awareness without action. In enforcement proceedings, that record is extraordinarily difficult to explain.
In our practice, we regularly advise compliance teams on how to structure their escalation governance so that the decision not to file is as well-documented as the decision to file. Regulators do not expect every suspicious transaction to generate a report. They do expect a documented, consistent rationale.
Cross-Border Risk: How Jurisdiction-Stacking Multiplies Exposure
For a VASP sitting between two regulatory hubs – licensed in one jurisdiction but serving customers or operating infrastructure in another – the compliance obligation is not the average of the two regimes but the highest applicable standard of each, applied simultaneously. This is the reality that the single-offshore-licence assumption ignores, and it is the assumption most frequently falsified by enforcement action.
Consider a VASP holding a registration in the BVI under the VASP Act and serving retail customers in the European Union. The BVI registration satisfies the BVI FSC's requirements for that entity. It does not satisfy MiCA's CASP authorisation requirement for providing crypto-asset services to EU customers. Nor does it satisfy the FCA's financial promotion rules for any UK-resident customer who sees the firm's marketing. The operator has three separate compliance obligations running in parallel, and the weakest link determines the enforcement outcome.
The same dynamic applies to banking. A VASP that obtains banking with a European payment institution and routes transactions through a US correspondent bank is simultaneously subject to FinCEN's BSA/AML expectations, the European institution's own AML program and the correspondent bank's de-risking criteria. In our practice, we have seen firms lose banking access not because of their own compliance failures but because their transaction profile was inconsistent with the risk appetite of the correspondent bank two layers removed.
If a banking relationship has been terminated or a licence application has stalled, a structural review can identify the underlying cause and the route back. Write to OBOLUS at info@oboluslaw.com for a second assessment of your structure.
Decision Matrix: Which Risk Profile Should Prioritize What
A VASP business risk assessment does not produce the same action list for every operator. The priority depends on the firm's activity type, geographic scope and regulatory status.
Profile A – Early-stage operator, single jurisdiction, registration pending. The primary risk is that the compliance program is designed for an idealized customer base rather than the actual one. The priority action is a gap analysis against the specific supervisory expectations of the target regulator, conducted before submission. A rejected application extends the timeline by months and creates a supervisory record. Travel Rule vendor selection and KYC workflow design should be complete before first filing.
Profile B – Operating VASP, licensed in one jurisdiction, serving cross-border users. The highest probability risk is jurisdictional overreach – serving customers in markets where the existing licence does not confer permission. The priority action is a customer-jurisdiction audit: mapping where customers are actually located against the firm's regulatory permissions. Secondary priority is Transaction Rule coverage for every corridor the firm actively services.
Profile C – Multi-licensed operator, established compliance program, scaling volumes. The primary risk is program obsolescence: controls designed for lower volumes and a narrower customer base that have not been updated as the business grew. The priority action is a rule-effectiveness review and a governance audit to confirm that the compliance officer's authority has kept pace with the commercial team's growth. In our practice, we have seen compliance functions at this stage that were adequately resourced two years ago and are materially under-resourced today.
Profile D – VASP facing regulatory correspondence or supervisory inquiry. Time is the binding constraint. The priority action is an immediate gap analysis against the specific issues raised, a response strategy and – if enforcement proceedings are a real possibility – engagement of legal counsel before any further submission to the regulator. In this profile, what is not said in the initial response is often as consequential as what is said.
How Do Regulators Audit Crypto AML Programs?
Regulators audit VASP AML programs through a combination of documentation review, transaction-file sampling and interviews with the compliance officer and senior management – and the weighting between those three methods varies significantly by jurisdiction and by the reason for the examination.
A scheduled supervisory examination under the MiCA regime will typically begin with a request for the firm's AML/CFT policy documentation, its risk assessment, its customer risk-classification methodology and a sample of customer files at different risk tiers. The regulator will then pull a transaction sample and test whether the monitoring outputs match the documented policies. The gap between what the policy says should happen and what the transaction file shows actually happened is the primary finding mechanism.
An FCA cryptoasset supervisory visit in the UK proceeds similarly, with particular attention to the decision-making record for individual SAR filings and non-filings. MAS in Singapore has supplemented scheduled examination with data-driven monitoring of VASP transaction flows, allowing the regulator to identify outlier patterns before an examination is scheduled. SFC in Hong Kong has communicated an expectation that VASP compliance officers will be individually accountable – not merely institutionally responsible – for program performance.
The AIFC/AFSA in Kazakhstan and the VARA regime in Dubai each conduct examinations aligned to FATF standards, with VARA having published detailed rulebook requirements that effectively create an examination checklist for operators willing to read the rulebook as a supervisory script.
The common thread across all major regulators is the expectation that the compliance officer can walk an examiner through a specific transaction, explain why it did or did not generate an alert, and explain what happened next. Firms that can do this consistently, in real time, pass examinations. Firms that cannot are assigned remediation timelines and revisited.
What Mistakes Do VASP Operators Consistently Make?
The most costly mistake is treating compliance as a point-in-time exercise rather than a continuous operational discipline. A compliance program that was adequate at the point of licensing and has not been updated since is a program that will fail the next examination – particularly as transaction volumes have grown and the regulatory baseline has tightened.
The second most common mistake is under-investing in the compliance officer function. Regulators across every major hub have moved toward personal accountability for compliance officers. Appointing a compliance officer who lacks the authority, the resources or the seniority to override commercial decisions exposes both the individual and the firm.
A third consistent mistake is failing to document decisions that are not taken. When the compliance team reviews a transaction and decides not to escalate, that decision should be recorded with the reasoning. When the firm receives a Travel Rule data request from a counterparty and responds with a partial data set, the basis for that response should be in the file. Regulators treat undocumented decisions as absent decisions.
A fourth mistake – one we observe regularly in multi-licensed operators – is running the compliance program as a single global program rather than as a modular structure that can satisfy each jurisdiction's specific requirements independently. The requirements under MiCA, the FCA's MLR registration and the MAS Payment Services Act are not identical. A global policy that is calibrated to the most demanding of those standards will be over-inclusive in some markets and under-inclusive in others. The better structure is a core global policy with jurisdiction-specific annexes that are reviewed whenever the local regulatory baseline changes.
A common assumption among operators is that a single offshore licence is sufficient to serve customers globally. This assumption is consistently falsified by enforcement: the applicable compliance obligation follows the customer, not the licence. An entity licensed in a permissive jurisdiction but serving EU customers is subject to MiCA obligations for those customers. An entity serving US persons is subject to FinCEN's BSA/AML expectations regardless of where the entity is incorporated. The licence determines the home regulator's jurisdiction; the customer determines every other regulator's interest.
Related Practices
Related at OBOLUS
- AML, Travel Rule and compliance for digital-asset businesses – end-to-end compliance program design and ongoing counsel for VASPs across multiple regimes.
- MLRO and compliance officer function in Hong Kong – individual accountability, appointment requirements and SFC expectations for VASP compliance officers.
- Corporate bank account opening from a cross-border perspective – how banking access interacts with licence status and compliance posture across leading jurisdictions.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect and transmit identifying information about the originator and beneficiary of a virtual asset transfer – name, account identifier and, in most jurisdictions, address or other identifying data – alongside the transfer itself. The obligation applies at each side of the transfer: the originating VASP must send the data, and the beneficiary VASP must receive and screen it. The applicable threshold varies by jurisdiction and should be verified against current local legislation. Where a counterparty is unregulated or uncooperative, the regulated VASP still carries the obligation and must have a documented policy for managing that gap.
Who must act as MLRO for a crypto firm?
A money laundering reporting officer (MLRO) for a VASP must be a sufficiently senior individual with genuine authority over the firm's AML/CFT program. Most major regulators – including the FCA, MAS and SFC – require the MLRO to be individually named, approved or notified, and to be reachable by the regulator. The role cannot be nominal: regulators now assess whether the MLRO has the resources, the seniority and the operational independence to override commercial decisions when compliance requires it. In smaller firms, the MLRO may also serve as compliance officer; in larger firms, the roles are typically separated.
How do regulators audit crypto AML programs?
Regulators typically audit VASP AML programs through three methods: documentation review (policies, risk assessments, customer risk classifications), transaction-file sampling (testing whether monitoring outputs match documented policies) and interviews with the compliance officer and senior management. The primary finding mechanism is the gap between what the policy states should happen and what the transaction record shows actually happened. Regulators in leading hubs – including the FCA, MAS, SFC and the VARA regime – have increasingly supplemented scheduled examinations with data-led monitoring of live transaction flows.
To pressure-test your VASP's compliance posture before the next supervisory examination, message OBOLUS at t.me/oboluslaw.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and KYC compliance obligations that sit around them. We map the licence, banking and compliance stack across every operating, custody and payment layer before you commit. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in cross-border VASP compliance program design, AML/Travel Rule obligations and supervisory risk assessment across the MiCA, FCA, MAS and VARA regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.