EST · MMXXVI
Home/Insights/Tax/MLRO and compliance officer function: The Compliance Burden in Practice
Compliance, AML & Travel Rule

MLRO and compliance officer function: The Compliance Burden in Practice

Mlro and compliance officer function: The Compliance Burden in Practice. Cross-border digital-asset legal counsel for business – licensing, disputes and structu

The question a new digital-asset compliance officer faces on day one is deceptively simple: what exactly does this role require, and who is legally accountable when something goes wrong? Under every major AML compliance regime – from the FATF framework to MiCA, the VARA rulebooks and Singapore's Payment Services Act – a regulated virtual asset service provider must appoint a designated individual responsible for the firm's anti-money laundering program. That individual, the MLRO (Money Laundering Reporting Officer), carries personal accountability that sits alongside – and often above – the corporate obligation. This analysis maps the function in practice: what the role demands, where it generates the most friction, and how the cross-border reality of digital-asset business reshapes a burden that was already substantial in a single-jurisdiction firm.

Why the MLRO Function Has Never Carried Greater Risk

The MLRO function matters more today than at any prior point in the digital-asset cycle because regulators have moved from registration-only regimes toward full supervisory engagement. Regulators across the leading hubs – including the FCA in the United Kingdom, VARA in Dubai and MAS in Singapore – now conduct thematic reviews, desk-based assessments and on-site examinations that are explicitly focused on the competence and independence of the compliance function, not just the adequacy of written policies.

Operating without a properly appointed, genuinely empowered MLRO exposes the business to enforcement action, supervisory restriction and – in serious cases – criminal referral of the individual officer. We have seen compliance officers across multiple jurisdictions face personal investigations where the firm's written policy was adequate but the implementation record was thin. The gap between a well-drafted AML compliance manual and a demonstrably functioning program is precisely where regulators focus their attention.

The cross-border dimension sharpens this risk considerably. A firm licensed in one jurisdiction but serving users in several others may face concurrent supervisory attention from the home regulator and informal inquiries from the regulators of user-facing markets. The MLRO must be able to account for the program as a whole – not just the home-jurisdiction slice of it.

Operating without the right licence risks enforcement, frozen banking rails and the loss of the correspondent relationships that keep a digital-asset business alive. The MLRO is the individual a regulator expects to explain, defend and – if necessary – rebuild the firm's compliance posture. That is a significant personal and institutional burden.

The first mid-page CTA: The analysis below describes the standard path. Your facts – the entity structure, the user base, the jurisdictions served and the banking relationships – change the analysis materially. For a scoped assessment of your compliance function, contact OBOLUS at info@oboluslaw.com.

What Does the MLRO Role Actually Require?

The MLRO role requires a combination of legal knowledge, operational authority and documented independence that most new crypto firms underestimate when they first structure their compliance function. The core obligation under the FATF Recommendations – and in particular Recommendation 15 on virtual assets and virtual asset service providers – is that a VASP must implement a risk-based AML/CFT program and designate a senior individual to oversee it.

In practice, that program has five operational layers. First, a written KYC framework (know-your-customer framework) governing onboarding: the documentary standards, the source-of-funds checks and the enhanced due-diligence triggers for higher-risk counterparties. Second, a transaction monitoring system capable of identifying patterns associated with layering, structuring and sanctions evasion. Third, a Travel Rule compliance program – the obligation, under FATF Recommendation 16, to pass originator and beneficiary data alongside a virtual-asset transfer. Fourth, a suspicious-activity reporting function with clear escalation lines to the MLRO and, from the MLRO, to the relevant financial intelligence unit. Fifth, a training and awareness program that reaches every client-facing and operations employee.

The MLRO must own all five layers. The individual must have sufficient seniority to override business decisions that create compliance risk. Where a firm structures the MLRO as a junior function reporting to the chief revenue officer, regulators treat that as a structural deficiency – regardless of what the policy document says about independence.

In the businesses we advise, the most common structural weakness is not the policy – it is the reporting line. An MLRO who cannot escalate a SAR filing decision to the board without going through a revenue-generating line manager is not genuinely independent, and regulators who examine the org chart will say so.

How Does the Travel Rule Reshape the MLRO's Daily Compliance Burden?

The Travel Rule is the single largest operational addition to the MLRO's compliance burden over the past three years, and its full weight is still being absorbed by most mid-size VASPs. Under the Travel Rule obligation – now embedded in MiCA, the VARA regime and the MAS Payment Services Act framework – a VASP transferring virtual assets must collect, verify and transmit counterparty data to the receiving VASP before or simultaneously with the transfer.

The operational challenge is three-dimensional. The first dimension is technical: VASPs must use an interoperable messaging protocol (commonly referred to as IVMS 101) and must integrate with a Travel Rule solution capable of matching incoming transfers to known VASPs, managing unhosted-wallet transfers separately and storing the data in a retrievable format for regulatory inspection.

The second dimension is jurisdictional. The data threshold above which the Travel Rule applies varies by regime. The home regulator may apply a threshold that differs from the threshold applied by the VASP on the other end of a cross-border transfer. The MLRO must understand the higher standard and apply it, because the regime that imposes the more demanding obligation controls for compliance purposes in that jurisdiction.

The third dimension is counterparty risk. Sending Travel Rule data to an unvetted offshore VASP that lacks adequate AML controls creates its own exposure. Leading regulators increasingly expect VASPs to conduct due diligence on counterpart VASPs before establishing operational relationships – treating correspondent-VASP onboarding as a risk event comparable to a high-value customer onboarding.

A micro-matter illustrates the stakes. In a recent matter, a payments company operating across two regulated jurisdictions had implemented a Travel Rule solution technically but had not built the counterparty-VASP due-diligence layer into its onboarding workflow. During a thematic review, the home regulator identified a pattern of outgoing transfers to jurisdictions with materially weaker AML supervision. We assisted the company in rebuilding its counterparty risk matrix, drafting the revised onboarding standard and preparing the regulatory response. The review concluded without formal action, but the remediation timeline ran to several months of intensive compliance work.

Contrasting Positions: MLRO as Individual Officer Versus Institutional Function

The core conceptual tension in MLRO governance is whether the role should be understood as a personal accountability function – one individual carrying named legal responsibility – or as an institutional compliance function distributed across a team. Both positions are defensible, and regulators in different hubs take different default views.

Under the FCA's approach, the nominated officer for suspicious activity reports is a named individual with a specific regulatory registration. The MLRO in that sense is always a person. Under the VARA framework, the compliance officer requirement is framed in terms of the entity's obligation to maintain a functioning program, with less explicit personal-liability language in the primary rules – though enforcement practice can and does reach individuals. MAS in Singapore sits closer to the FCA model, expecting a named AML compliance officer whose fitness and propriety can be assessed on application and re-assessed on renewal.

The practical consequence for a cross-border VASP is that a single MLRO servicing multiple licensed entities in different jurisdictions must satisfy each regulator's competence and availability standard independently. Regulators do not automatically accept a remote, group-level MLRO as satisfying a local requirement for a resident or accessible compliance officer. This creates a real staffing and cost challenge for firms trying to operate efficiently across jurisdictions.

The decision matrix at this fork looks like this. A firm operating from a single regulated hub with a clearly defined user base can generally structure a single MLRO with a deputy covering absence. A firm licensed in two or more jurisdictions with distinct regulatory obligations – say, a VARA-licensed exchange with an MAS-regulated payments subsidiary – should anticipate that each regulator will expect a locally accountable compliance function, even if strategy and policy are set centrally. A group-level compliance function is appropriate for policy and escalation; it does not substitute for local accountability.

What Are the Most Common Governance Mistakes in MLRO Appointments?

The most common governance mistake is appointing the MLRO on paper without investing the role with genuine operational authority. This pattern appears repeatedly in supervisory findings across the leading hubs: the written policy is well-structured, the MLRO is named and the training records exist, but the individual has no real capacity to halt a client relationship, delay a product launch or escalate a SAR to the board without management approval at every step.

The second common mistake is failing to document the MLRO's decisions. Regulators examining a compliance program look for a decision trail. When did the MLRO last review a high-risk customer? What was the rationale for retaining a relationship after a suspicious transaction alert? When was the risk appetite last formally assessed? Absent documentation, a regulator assumes the decision was not made – or worse, was made informally in ways the firm would not want recorded.

The third common mistake is conflating the MLRO function with the KYC operations function. KYC operations – the day-to-day onboarding, document collection and screening work – is a compliance-adjacent function. It reports to the MLRO in a well-structured firm. It is not the same as the MLRO function, and treating a senior KYC analyst as the MLRO without the associated authority, independence and board access is a structural error that regulators flag consistently.

A fourth mistake, specific to the digital-asset sector, is underinvesting in transaction monitoring calibration. An automated monitoring system generates alerts. Those alerts require a human review decision. Where the MLRO has not documented the calibration logic, reviewed and updated threshold settings, and recorded the rationale for alert dispositions, the system creates a paper trail of unreviewed risks rather than evidence of a functioning program. This is particularly acute in firms that have grown rapidly and allowed alert volumes to outpace review capacity.

How Do Cross-Border Operations Stack MLRO Obligations?

Cross-border digital-asset operations create a layered set of AML compliance obligations that a single-jurisdiction MLRO framework cannot fully address. When a VASP is licensed in one jurisdiction but its users transact from others, the firm may attract regulatory attention from multiple directions simultaneously.

The first layer is the home-jurisdiction obligation: the MLRO must satisfy the regulator that licensed the firm. The second layer is the customer-jurisdiction exposure: if the firm serves retail or institutional users in a jurisdiction that applies its own AML rules to VASPs operating cross-border, the local regime may apply even without a formal local licence. Several major markets take this extraterritorial view of their AML rules, particularly for exchanges with a material customer base in the jurisdiction.

The third layer is the banking relationship. Correspondent banks that provide fiat on-ramps and off-ramps to crypto firms conduct their own AML due diligence on the VASP. That due diligence looks closely at the MLRO function – its governance, its independence, its documented outputs. Banks that are uncomfortable with the quality of the compliance function will withdraw the relationship. In our cross-border practice, we have seen firms lose banking access not because of a specific compliance failure but because the bank's own AML team assessed the MLRO function as inadequate during a periodic review.

The Travel Rule adds a fourth cross-border layer. Transferring assets between a home-jurisdiction VASP and a counterpart in a different regime requires the MLRO to have mapped both sets of Travel Rule obligations and to have built workflows that satisfy the more demanding standard. Regulators in both jurisdictions may request evidence of that mapping. Operators we advise routinely find that their Travel Rule solution handles the technical protocol but that the counterparty-VASP due-diligence workflow and the jurisdictional-threshold mapping have not been built out.

If your compliance program has hit a wall – a supervisory inquiry, a banking review or a stalled licence application with a compliance-related condition – a second read can surface the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

Decision Matrix: Which Compliance Structure Fits Which Operator?

No single compliance structure fits every digital-asset operator, and the risk of deploying a generic model is that it satisfies no regulator fully while imposing costs that are disproportionate to the business's actual risk profile.

Profile A – a single-jurisdiction exchange or broker with a defined user base: This profile can operate a single MLRO with a documented deputy arrangement for continuity. The program should be built to the home regulator's standards with a clear view of whether any material user population sits in a jurisdiction with extraterritorial reach. The key risk is underinvestment in transaction monitoring calibration as volumes grow. Indicative build timeline for a competent program from scratch is measured in months, not weeks.

Profile B – a multi-licensed group (for example, VARA exchange plus MAS-regulated payments subsidiary): This profile requires a group compliance function for policy and escalation, and locally accountable compliance officers in each regulated entity. The MLRO in each entity must be able to satisfy the local regulator independently. The key risk is a structural gap between group policy and local implementation – particularly where the local compliance officer is part-time or shared across entities. Regulators in this profile are most likely to require evidence that the local officer has genuine authority.

Profile C – a token issuer without an exchange business: This profile has a more defined compliance perimeter (primarily issuer-level AML obligations and, under MiCA, the whitepaper and ART/EMT obligations). The MLRO function may sit alongside a legal and finance team rather than requiring a standalone compliance department. The key risk is underestimating the secondary-market distribution channels: if the token trades on third-party exchanges, the issuer still has obligations with respect to investor-facing information and, in some regimes, ongoing transaction-level obligations.

Profile D – a DeFi protocol with governance-token holders: This profile sits at the frontier of regulatory classification. Where the protocol has no identifiable VASP function – no custody, no fiat conversion – the MLRO obligation may not formally apply. Where it does have such functions, or where the development company is treated as a VASP by a regulator, the obligation bites fully and the absence of a compliance function is treated as a heightened risk by enforcement agencies.

Objection: "A Single Offshore Licence Is Enough to Serve Clients Globally"

A common assumption among early-stage digital-asset businesses is that a licence in a flexible offshore jurisdiction resolves the global compliance question. It does not. The offshore licence satisfies the home jurisdiction; it does not satisfy the AML obligations of the jurisdictions where the firm's users actually sit.

This matters most in the context of the MLRO function because the AML obligation follows the customer, not the licence. A VASP licensed in a jurisdiction with light-touch supervision that serves customers in a jurisdiction with robust AML enforcement is exposed to enforcement action in the customer jurisdiction regardless of where the legal entity sits. Several major markets have brought enforcement actions against offshore VASPs that were technically licensed elsewhere on the basis that the VASP conducted regulated activities in the enforcement jurisdiction through its user base and marketing.

The Travel Rule compounds this. If a VASP operating on a single offshore licence transfers assets to or from a VASP subject to a more demanding Travel Rule standard, the transaction chain creates a record that is visible to the demanding-regime regulator. The absence of a compliant compliance program on the sending side becomes visible at the receiving end.

In our practice, we map the licence, banking and compliance stack across all the jurisdictions where a business has material customer exposure – not only where it is legally domiciled. That mapping exercise regularly surfaces obligations that a single offshore licence does not address and that require either additional licensing, enhanced compliance posture or a restructuring of the customer-acquisition approach.

How Do Regulators Examine and Audit Crypto AML Programs?

Regulatory examination of a crypto AML program follows a consistent pattern across the major supervisory authorities, even though the specific methodology varies by jurisdiction. The examination typically begins with a desk-based review of the firm's AML policy documentation, governance structure and the MLRO's written reports to the board.

From that base, the examiner looks for operational evidence. Transaction monitoring alert volumes, disposition rates and escalation records are standard requests. Regulators consistently focus on the ratio of alerts generated to alerts reviewed, and on the documentation quality of alert-closure decisions. A firm that generates a large alert volume and disposes of most alerts without a documented rationale raises immediate supervisory concern regardless of whether any underlying SAR was filed.

The second examination focus is the KYC framework. Examiners pull a sample of customer files and assess whether the onboarding documentation meets the stated policy standard. Common findings include expired documentation, missing source-of-funds evidence for high-value customers and inconsistent application of enhanced due diligence triggers across the customer base.

The Travel Rule is an increasingly standard element of examinations across all major hubs. Examiners ask for a sample of outgoing and incoming transfers and assess whether Travel Rule data was collected, transmitted and stored in accordance with the applicable regime. Where a firm relies on a third-party Travel Rule solution, the examiner will assess whether the firm's own staff understand the solution's limitations and have built manual workflows to address them.

Regulators in the leading hubs increasingly expect the MLRO to present at examination, to speak to the program and to demonstrate personal knowledge of the firm's risk profile. Where the MLRO defers entirely to written documentation and cannot explain the rationale for key risk decisions, examiners treat that as evidence of a nominal rather than a genuine compliance function.

A second micro-matter: in a recent licensing matter, a custodian seeking authorisation under a leading framework was asked by the regulator to demonstrate that its MLRO had personally reviewed and signed off on the transaction monitoring calibration during the preceding period. The calibration had been performed by the operations team, and the MLRO had received a summary rather than conducting a direct review. We worked with the firm to reconstruct the review process, establish a formal MLRO sign-off protocol and prepare a written response to the regulator's concern. The application proceeded to approval following remediation.

To map the compliance and licence stack for your operating model, contact OBOLUS at info@oboluslaw.com.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

Under the FATF Travel Rule – reflected in MiCA, the VARA regime and the MAS Payment Services Act framework – a VASP must collect and transmit originator and beneficiary information alongside a virtual-asset transfer. The precise data fields and the threshold above which the obligation applies vary by jurisdiction. The VASP must also conduct due diligence on the receiving VASP before establishing an operational relationship, ensuring counterparty AML standards are adequate.

Who must act as MLRO for a crypto firm?

Every regulated VASP must designate a named senior individual as MLRO – the person accountable for the firm's AML compliance program and for filing suspicious-activity reports with the relevant financial intelligence unit. The individual must be genuinely senior, genuinely independent from revenue-generating functions and capable of escalating directly to the board. In multi-licensed groups, each regulated entity typically requires its own locally accountable compliance officer rather than relying solely on a group MLRO.

How do regulators audit crypto AML programs?

Regulators typically begin with a desk-based review of the firm's AML policy, governance structure and MLRO reports. They then examine operational evidence: transaction monitoring alert volumes and disposition records, KYC file samples for documentation quality, and Travel Rule compliance records for a sample of transfers. The MLRO is increasingly expected to present personally and to demonstrate direct knowledge of the program's risk decisions. Alert-closure documentation quality and counterparty-VASP due-diligence records are consistent examination focus areas across all leading hubs.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML compliance, Travel Rule and KYC framework design that sit around every regulated digital-asset operation. Digital assets are the whole of our practice. We map the licence and compliance stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when it matters most. To discuss your compliance function or your MLRO governance structure, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – cross-border AML compliance program design, MLRO governance and the tax and structural implications of multi-jurisdiction VASP operations.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours