EST · MMXXVI
Home/Insights/Tax/Regulator aml audit defence: The Compliance Burden in Practice
Compliance, AML & Travel Rule

Regulator aml audit defence: The Compliance Burden in Practice

Regulator aml audit defence: The Compliance Burden in Practice. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Tal

When a regulator requests an AML audit file, the clock starts immediately. Digital-asset firms operating across borders face a compliance burden that is structurally different from traditional finance: multiple regimes apply simultaneously, the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) adds a layer most legacy compliance programs were never built to carry, and a single gap in KYC (know-your-customer) documentation can ground an otherwise functional exchange. The analysis below maps the compliance burden in practice – what regulators examine, where firms routinely fail, and how to position a defence before the audit letter arrives.

What Do Regulators Actually Examine in a Crypto AML Audit?

A regulator conducting an AML audit of a digital-asset business is looking for a live program, not a policy document. The audit tests whether the firm's controls operate as described, whether transaction monitoring is calibrated to the actual risk of its customer base, and whether the MLRO (Money Laundering Reporting Officer) has meaningful authority and resources. Under FATF Recommendation 15, virtual asset service providers are held to the same AML/CFT standards as traditional financial institutions, and supervisors in the leading hubs – VARA in Dubai, the FCA in the United Kingdom, MAS in Singapore, and the national competent authorities operating under MiCA in the EU – have made clear they will test controls against that standard, not against what firms self-report.

In our cross-border practice, we consistently see audits structured around three lines of inquiry. First, does the firm know who its customers are, and can it evidence that? Second, does it monitor transactions in a way that is proportionate to the products it offers? Third, when suspicious activity is identified, does the escalation chain work? Each line generates document requests that reach back through onboarding records, monitoring logs, MLRO decision files and board-level risk committee minutes.

Regulators increasingly compare what the policy says against what the data shows. If a policy states that high-risk customers are reviewed every twelve months, the auditor will pull a sample and check the dates. A mismatch between the policy and the log is, in most jurisdictions, treated as an AML failure regardless of whether the underlying customer posed any actual risk. That asymmetry – between document compliance and substantive risk management – is the first practical burden a firm carries into an audit.

CTA #1 – The process above describes the standard path a regulator follows. Your facts – the entity structure, the user base geography, the product mix – change the analysis materially. For a scoped assessment of your current AML posture, contact OBOLUS at Map your options.

The Travel Rule: Why It Creates Disproportionate Audit Exposure

The Travel Rule is the single compliance obligation most likely to generate an immediate audit finding for a crypto firm that has not built for it deliberately. Under the FATF standard, a VASP (virtual asset service provider) must transmit originator and beneficiary data when it transfers virtual assets on behalf of a customer – and must verify that data before sending. Under MiCA and the EU's Transfer of Funds Regulation, that obligation applies to transfers of any value above the applicable threshold; regulators under the MiCA regime expect a CASP (crypto-asset service provider) to have a functioning Travel Rule solution in place from authorisation. The FCA, MAS, VARA and AFSA in Kazakhstan's AIFC all apply analogous standards.

The operational burden is significant. A VASP must identify whether the counterparty is another regulated VASP or an unhosted wallet (a wallet address not associated with a regulated institution). For transfers to unhosted wallets above a defined threshold, enhanced due diligence is expected. For VASP-to-VASP transfers, the originating firm must transmit data that the receiving firm will in turn verify – which requires both firms to have compatible messaging infrastructure. In practice, many smaller operators either lack the infrastructure or have implemented it inconsistently, and regulators have started to find that gap.

In a recent matter, a payments business we advised in the early stages of an FCA review had implemented Travel Rule messaging for its largest institutional counterparties but had not addressed the unhosted wallet population. The regulator's information request exposed the gap within the first exchange of correspondence. We worked with the client to document the risk-based rationale it had applied, supplement the transaction-monitoring logs with enhanced source-of-funds records, and prepare a remediation timeline that gave the FCA a credible forward plan. The outcome was a supervisory letter rather than a formal enforcement referral – but the margin was narrow and the lesson is clear: partial implementation is visible and will be tested.

Does the MLRO Have Real Authority? The Resourcing Test

Regulators treat an under-resourced or structurally marginalised MLRO as a control failure, not a staffing matter. A well-functioning MLRO must have direct access to the board, independence from the business lines that generate revenue, and the ability to file a Suspicious Activity Report (SAR) without seeking commercial approval. Under the MiCA regime and equivalent frameworks administered by the FCA and MAS, the designated compliance officer carries individual accountability – and an audit that finds the MLRO is overruled by commercial teams, or is handling compliance as a secondary role, will typically recommend a remediation order.

In our practice, we regularly advise founders who have appointed a technical compliance officer but have not built the governance structure around that appointment. The MLRO needs a documented mandate, a budget line, a risk-appetite statement from the board, and a reporting channel to the audit committee or equivalent. Without those structural anchors, the role is nominal. Regulators – particularly VARA and the Bank of Lithuania – have in recent cycles focused on governance architecture as much as on the technical content of AML programs.

The cross-border dimension adds complexity. A firm licensed in one jurisdiction but serving customers across multiple territories may need to satisfy the MLRO resourcing expectations of each relevant regulator. A CASP passporting under MiCA remains subject to the supervisory expectations of its home-state NCA, but host-state regulators may still examine whether the firm's AML program covers local risk typologies. For a business between Singapore and the EU, for instance, the MAS Payment Services Act and the MiCA CASP regime impose overlapping but not identical expectations on the compliance function.

How Should Transaction Monitoring Be Calibrated for a Crypto Audit?

Transaction monitoring is the technical centre of a crypto AML audit, and it is the area where firms most often present an inadequate defence. A monitoring program calibrated for fiat payment flows will not catch the risk typologies that regulators expect a VASP to address: chain-hopping through multiple protocols, rapid cycling through unhosted wallets, the use of privacy-enhancing techniques, and exposure to sanctioned addresses. Under FATF guidance and the applicable provisions of MiCA, a firm is expected to apply a risk-based approach – but "risk-based" does not mean "light." It means calibrated to the actual risks of the products and customers involved.

The practical test an auditor applies is whether the firm's monitoring rules would have detected the risk scenarios documented in its own business risk assessment. If the risk assessment identifies chain-hopping as a high-risk pattern but the monitoring system has no rule addressing it, the firm has demonstrated internal inconsistency – which is, in most supervisory frameworks, treated as a systemic failure rather than an isolated gap. ESMA and the relevant national competent authorities under MiCA have signalled that they will apply exactly this internal-consistency test during CASP authorisation reviews and subsequent supervisory examinations.

Firms we advise that have invested in on-chain analytics tools – integrating wallet screening, clustering analysis and exposure scoring into their monitoring workflow – are materially better positioned in an audit. The tool itself is not the defence; the defence is the governance layer around the tool: documented alert-review procedures, escalation logs, disposition records and periodic calibration reviews signed off by the MLRO. Without that governance layer, even a technically strong monitoring suite will not satisfy an auditor who is looking for a live program.

CTA #2 – If a prior application stalled or a regulator has issued an information request, a second read can surface the structural reason and the route forward. Write to OBOLUS at Map your options to discuss the remediation path.

Contrasting Positions: Where Cross-Border AML Obligations Conflict

One of the most under-examined aspects of the compliance burden is the conflict that arises when two regulators impose differing AML obligations on the same firm. This is not a theoretical risk. A VASP licensed in the BVI under the VASP Act 2022 and serving EU retail customers via a white-label arrangement may simultaneously attract MiCA CASP obligations in the EU – with materially different KYC depth requirements, Travel Rule thresholds and monitoring expectations than the BVI FSC requires. The firm must satisfy both, and the gap between the two regimes is a live audit risk in both jurisdictions.

The AIFC regime administered by AFSA in Kazakhstan is a further illustration. AFSA has developed a common-law digital-asset framework that is broadly FATF-aligned but carries its own calibration on enhanced due diligence triggers and record-keeping periods. A firm operating under AFSA supervision while routing transactions through EU-facing infrastructure must map the obligations of each regime and document where its controls satisfy the higher standard. Regulators in the leading hubs increasingly expect a firm to have done that mapping exercise and to be able to produce it on request.

Switzerland presents a specific variant. FINMA supervises financial intermediaries through the SRO (self-regulatory organisation) model alongside direct licensing. A firm with a Swiss nexus – whether through a fintech licence or an SRO affiliation – must satisfy FINMA's anti-money laundering provisions while managing the interaction with any EU passporting obligations that apply to its cross-border activities. The regulatory expectations on transaction monitoring in Switzerland are detailed and have been enforced: FINMA has issued public enforcement decisions against financial intermediaries for inadequate AML programs in the digital-asset space, and those decisions set a practical benchmark for what the regulator considers insufficient.

Decision Matrix: Which AML Defence Posture Fits Your Operator Profile

The appropriate compliance posture depends on the business model, the regulatory regime, and the stage of the firm's relationship with its supervisor. The following analysis sets out three operator profiles and the corresponding defence architecture each should build.

Profile A – Early-stage CASP under MiCA: A firm seeking or recently holding CASP authorisation in an EU member state faces a home-state NCA that will examine the AML program as part of the authorisation dossier. The priority is to build a documented AML policy, a risk appetite statement, an MLRO mandate, and a transaction-monitoring framework before submission – because a deficient program at authorisation is harder to remediate than one built correctly at the outset. The timeline for NCA review varies by jurisdiction; the quality of the compliance documentation directly affects the length and depth of that review.

Profile B – Established exchange under active supervision: A firm already licensed and operating – whether under VARA in Dubai, the FCA in the UK, or MAS in Singapore – faces periodic supervisory review and must demonstrate that its AML program evolves as its product set and customer base evolve. The defence posture here is continuous: regular calibration of monitoring rules, documented MLRO reviews, and a board-level risk committee that generates a paper trail showing senior engagement with AML risk. An audit finding against a firm at this profile carries enforcement risk and reputational exposure that an early-stage firm has not yet accumulated.

Profile C – Cross-border operator with fragmented compliance: A firm running separate entities in multiple jurisdictions – a BVI holding company, an operating entity in Lithuania under MiCA transition, and a UAE entity under VARA – must coordinate AML programs across three frameworks. The risk is inconsistency: a gap in one jurisdiction's program becomes an audit finding in that jurisdiction but may also signal to other regulators that the group-level compliance culture is weak. Allied counsel in each relevant jurisdiction should be coordinating the compliance architecture, not operating independently. We have seen this structure fail audits not because any single entity had a critical gap, but because the three programs were visibly uncoordinated and the group had no documented rationale for the differences.

A Common Assumption That Creates Audit Risk

A common assumption among operators is that the compliance work done for a prior licence application is sufficient for ongoing supervisory review. It is not. An AML program that was adequate at the point of authorisation will drift out of calibration as the product evolves, the customer base grows and FATF guidance is updated. Regulators examine not just whether a program exists but whether it has been maintained – and a program with no documented review history since the authorisation date is, in supervisory terms, a static document, not a live control.

A second assumption that generates risk is that deploying an off-the-shelf compliance product satisfies the regulatory obligation. Technology is a tool; the obligation is on the firm. A monitoring system that flags alerts that are never reviewed, or that has not been re-calibrated since deployment, will produce an audit finding regardless of the vendor's reputation. The FCA and VARA have both, in public guidance, made clear that the governance layer – the human decisions, the escalation records, the MLRO sign-off – is the substance of the program, and the technology is the mechanism. Firms that conflate the two will be exposed.

A third, specifically cross-border assumption is that a single offshore licence is sufficient to serve clients globally without additional regulatory engagement. In practice, the obligation follows the customer. A firm with CIMA registration in Cayman serving EU retail clients at scale is likely to attract MiCA CASP scrutiny regardless of where the entity sits. Allied counsel in the relevant jurisdiction should assess the customer-facing obligations before a service is launched, not after a regulator issues an information request.

Self-Assessment Checklist: AML Audit Readiness

The following checklist identifies the core evidence a regulator will request in the first wave of an AML audit. A firm that can produce each item promptly – without internal reconstruction – is in a materially stronger position than one that cannot.

  • A current AML policy, dated and signed at board level, with a documented review history.
  • A business risk assessment that addresses the firm's specific products, customer segments and geographic reach.
  • MLRO mandate documentation, including reporting lines, budget allocation and board access rights.
  • Transaction monitoring rule set, with documented rationale for each rule threshold and the date of last calibration review.
  • Alert review log for the preceding twelve months, showing disposition decisions and escalation records.
  • Travel Rule implementation documentation: the solution deployed, the scope of coverage (VASP-to-VASP and unhosted wallet population), and any documented risk-based exclusions with their rationale.
  • KYC file samples demonstrating the onboarding standard applied to high-risk, standard and low-risk customer categories.
  • SAR filing records for the review period (aggregate count; content is privileged).
  • Training records for all customer-facing and compliance staff, dated within the preceding twelve months.
  • Board or risk committee minutes evidencing senior engagement with AML risk during the review period.

In our practice, we regularly advise clients to run an internal audit against this list six months ahead of any anticipated supervisory review. The gap between what the firm believes it can produce and what it can actually produce on short notice is almost always wider than expected – and the window to remediate gaps before a regulator requests the file is narrow.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, rooted in FATF Recommendation 15 and implemented through regimes including MiCA's Transfer of Funds Regulation, the FCA's UK framework and the MAS Payment Services Act, requires a VASP to transmit originator and beneficiary information when transferring virtual assets on behalf of a customer. The data must be transmitted to the counterparty institution and, where the counterparty is not a regulated VASP, enhanced due diligence on the unhosted wallet is generally expected above the applicable threshold. The exact data fields and thresholds vary by jurisdiction and should be confirmed against current legislation.

Who must act as MLRO for a crypto firm?

Most leading regimes – including those administered by the FCA, MAS, VARA and national competent authorities under MiCA – require a licensed VASP or CASP to designate a named individual as the MLRO (Money Laundering Reporting Officer) or equivalent. That individual must have sufficient seniority, independence from commercial functions, and direct board access to exercise the role effectively. Where the firm operates across multiple jurisdictions, each licensed entity may be required to carry its own MLRO appointment, though group coordination of the compliance function is generally expected.

How do regulators audit crypto AML programs?

Regulators typically conduct AML audits of crypto firms through a combination of document review, data analysis and interviews. The document review covers the AML policy, business risk assessment, transaction monitoring configuration, KYC file samples and MLRO decision records. Data analysis tests whether the monitoring rules would detect the risk scenarios the firm has itself identified. Interviews examine whether staff understand the controls and whether escalation procedures are applied in practice. VARA, the FCA and ESMA's national competent authorities have all signalled that live testing of controls – rather than reliance on self-certification – is the direction of supervisory practice.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance architecture that sits around them. We map the licence and compliance stack across operating, custody and payment layers before you commit – and when a regulatory review is live, we work with you on the substantive response, not just the paperwork. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – cross-border compliance architecture and AML program design for digital-asset businesses operating across multiple regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours