Crypto businesses operating across borders face a sanctions and AML compliance (anti-money laundering compliance) environment that has tightened sharply in recent years. A virtual asset service provider (VASP) processing transactions without a defensible sanctions screening architecture risks regulatory action, enforced banking closure, and personal liability for its compliance officers. That is the practical reality, not a theoretical concern. This analysis maps the sanctions screening obligations that apply across the major licensing hubs, contrasts the regulatory approaches, and identifies the structural decisions that determine whether a VASP's program will survive a supervisory review.
Why Sanctions Screening Is Not Optional for Crypto Businesses
Sanctions screening in the digital-asset context is a hard legal obligation in every major financial hub – not a best-practice aspiration. The FATF Recommendations, and specifically FATF Recommendation 15 on virtual assets, require jurisdictions to bring VASPs within their AML and counter-terrorist financing (CTF) regimes. That inclusion extends explicitly to sanctions compliance: VASPs must screen customers and counterparties against applicable sanctions lists, freeze assets or transactions as required, and report. Regulators across the leading hubs – VARA in Dubai, the FCA in the United Kingdom, MAS in Singapore, the SFC in Hong Kong, and ESMA's network of national competent authorities under MiCA – have each operationalized this baseline into binding conduct expectations.
The cross-border dimension compounds the obligation. A VASP licensed in one jurisdiction but serving users in others must consider which sanctions regimes apply. A platform with a European user base is exposed to EU sanctions. A platform banking in the United States, even through a correspondent, is in scope for OFAC. Operators we advise regularly underestimate this layering effect. The entity's incorporation address does not determine the sanctions universe; the location of the customer, the currency rail, and the banking counterparty all create independent vectors of exposure.
Operating without a structured screening program exposes the business to enforcement, frozen banking rails, and revocation of the licence that underpins the whole operation. That is the loss-aversion case for building the program correctly at the outset.
The process above describes the standard obligation. Your facts – the entity structure, the user base, the banking stack – change the analysis significantly. For a scoped assessment of your sanctions exposure, contact OBOLUS at info@oboluslaw.com.
How Does Sanctions Screening Differ Across the Major Licensing Hubs?
The core obligation is consistent; the implementation requirements differ in ways that matter for a multi-jurisdiction operator. Understanding where the regimes diverge is essential before selecting an operating structure.
Under MiCA and the EU AML framework, CASPs (crypto-asset service providers) are subject to EU sanctions regulations as a matter of directly applicable law across all member states. There is no opt-out at the national level. The EU sanctions list – maintained by the Council – applies uniformly, and national competent authorities supervise compliance. The forthcoming EU AML Authority (AMLA) is expected to assume direct supervisory responsibility for the largest cross-border VASPs. For a business licensed through an EU member state and passporting across the bloc, the sanctions screening architecture must cover the EU consolidated list and, in practice, must be capable of real-time or near-real-time matching at onboarding and at the point of transaction.
VARA in Dubai operates a different model. The VARA rulebooks impose sanctions screening obligations as part of the compliance and risk management requirements that attach to each licensed activity. The relevant list is the UAE consolidated sanctions list, maintained by the UAE Executive Office of the Committee for Goods and Materials Subject to Import and Export Control. Operators with VARA licences who also bank internationally – as most do – face concurrent OFAC exposure. In our cross-border practice, we have seen businesses build a VARA-compliant program and discover only later that their correspondent banking relationship brought them within OFAC jurisdiction without a separate OFAC compliance layer.
MAS in Singapore requires digital payment token (DPT) service providers to comply with the Singapore sanctions regime administered by MAS itself, which mirrors UN Security Council designations and autonomous Singaporean designations. The MAS regime is notable for its expectation of documented risk assessments: the screening program must be proportionate to the operator's customer and geographic risk profile, and that proportionality analysis must be written down and auditable.
The SFC in Hong Kong, through its VASP licensing regime for virtual-asset trading platforms (VATPs), requires adherence to Hong Kong sanctions law under the United Nations Sanctions Ordinance and related instruments. The SFC's conduct expectations draw heavily on the Securities and Futures Commission's existing intermediary standards, meaning a VATP is expected to maintain controls comparable to a licensed securities firm.
The FCA in the United Kingdom requires cryptoasset businesses registered under the Money Laundering Regulations to maintain sanctions screening as part of their AML framework. The applicable sanctions list is the UK consolidated sanctions list, maintained by OFSI (the Office of Financial Sanctions Implementation) within HM Treasury. Post-Brexit, this list diverges from the EU list in important respects, which means a business operating across both the UK and EU must screen against both and manage the differences.
What Does the Travel Rule Require in Practice – and How Does It Interact with Screening?
The Travel Rule (the obligation, derived from FATF Recommendation 16 as applied to virtual assets, to pass originator and beneficiary data with a crypto transfer) is operationally linked to sanctions screening but is a distinct requirement. They interact at a critical point: if a VASP cannot identify the counterparty VASP on the other side of a transaction, it cannot complete the Travel Rule data exchange – and if it cannot complete that exchange, it also cannot screen the counterparty against sanctions lists. The two programs must be designed together.
MiCA's Transfer of Funds Regulation, which applies to CASPs across the EU, sets out the Travel Rule data requirements for crypto transfers. The practical challenge is the so-called "sunrise problem": where the sending VASP is in a jurisdiction that has implemented the Travel Rule but the receiving VASP is not, the data cannot be transmitted in a compliant format. Different regulators have taken different positions on how a VASP should handle unresponsive or non-Travel-Rule jurisdictions. The EU approach, MAS guidance, and FCA expectations all require the VASP to make a risk-based decision – which means the risk framework must document the decision logic and the outcome for each category of counterparty.
The sanctions dimension of the Travel Rule is this: originator and beneficiary data, when received, must be screened. A VASP receiving a transfer with Travel Rule data attached cannot simply accept it; it must run the names against the applicable sanctions lists before completing the transaction. For high-volume platforms, this creates a real-time data pipeline requirement that manual processes cannot satisfy.
FATF has been explicit that Travel Rule compliance and sanctions screening are complementary obligations under Recommendation 15 and Recommendation 16 respectively – a business that complies with one but not the other is not compliant.
How Does Sanctions Screening Work for Self-Hosted Wallets and DeFi Interactions?
Self-hosted wallets – wallets not held at a regulated VASP – present the most operationally complex screening scenario. The regulatory starting position across the major hubs is consistent: a VASP transacting with a self-hosted wallet must apply enhanced due diligence to satisfy itself that the wallet is not controlled by a sanctioned person. That is easily stated and genuinely difficult to execute.
The MiCA Transfer of Funds Regulation requires CASPs transacting with self-hosted wallets above defined thresholds to collect and verify originator or beneficiary information. The FCA's expectations for the UK market similarly require that cryptoasset businesses apply a risk-based approach to unhosted wallet transfers. MAS has been among the more prescriptive regulators in the Asia-Pacific region, requiring DPT licensees to have documented policies for unhosted-wallet transactions that address both Travel Rule and sanctions risk.
On-chain analytics tools – which interrogate blockchain transaction history and flag addresses linked to known sanctioned parties, darknet markets, ransomware clusters, or stolen-asset flows – are now effectively required infrastructure in any defensible program. In our cross-border practice, we have seen supervisory reviews in multiple jurisdictions where the absence of an on-chain analytics integration was treated as a material control gap, regardless of whether any sanctioned counterparty had actually transacted. The regulator's view is that the gap itself is the breach, irrespective of outcome.
DeFi interactions compound this further. Where a VASP provides a front-end or facilitates interaction with decentralized protocols, regulators are increasingly taking the position that the VASP must screen the wallet interacting with its interface even if the protocol itself is non-custodial. This is an unsettled area, but the direction of regulatory travel is toward treating customer-facing interaction as the locus of control.
What Are the Key Differences Between OFAC and Other Sanctions Regimes That Crypto Firms Must Understand?
OFAC (the Office of Foreign Assets Control, the US Treasury's primary sanctions enforcement body) operates with extraterritorial reach that sets it apart from most other sanctions regimes. A non-US VASP with no US licence, no US employees, and no US customers may still be in scope for OFAC if it uses US dollar settlement, routes transactions through US correspondent banks, or – more recently – has US investors.
OFAC has published specific guidance on virtual currency and sanctions compliance. It designates not only individuals and entities but specific wallet addresses: the Specially Designated Nationals (SDN) list includes crypto wallet addresses, which means a VASP must screen wallet addresses, not just names. This is technically distinct from traditional name screening and requires a different tooling architecture. A KYC (know your customer) framework that verifies only identity documents, without screening the associated wallet addresses, is insufficient for OFAC compliance.
The EU sanctions regime, by contrast, is entity and individual-focused and does not yet operate a systematic wallet-address designation list comparable to OFAC's SDN wallet address appending practice. However, EU regulations do prohibit the making available of funds or economic resources to designated parties – which means that if a VASP can establish that a wallet is controlled by a designated individual, transacting with it is prohibited regardless of whether the specific address appears on a list.
The UK OFSI regime operates similarly to the EU model in its legal structure but diverges in list content following Brexit. Japan's FSA and JVCEA framework, Singapore's MAS regime, and Hong Kong's SFC regime each require adherence to UN-derived designations and domestic autonomous lists, with varying degrees of alignment with OFAC and EU lists.
The practical implication for a VASP with a global user base is that it must screen against multiple lists concurrently – and manage the workflow when a hit on one list does not appear on another. In our practice, we regularly advise on how to structure the governance around multi-list hits: who decides, on what timeframe, with what documentation.
What Does a Defensible Sanctions Screening Program Look Like for a Regulated VASP?
A defensible sanctions screening program for a regulated VASP has several identifiable components that regulators across the major hubs consistently expect to find during a supervisory review. The program is not defined by any single tool; it is defined by the governance, documentation, and decision-making processes that surround the tools.
First, the scope of screening must be defined and documented. That means identifying which sanctions lists apply, based on a formal analysis of the VASP's entity structure, banking relationships, customer geography, and product offering. The list universe is not a static determination: it must be reviewed when the business model changes, when new banking correspondents are added, or when the user base expands into a new region.
Second, the program must address customer screening at onboarding, ongoing rescreening of the existing customer base against updated sanctions lists, and transaction-time screening. The frequency of rescreening is a recurring point of supervisory focus. A VASP that screens at onboarding but rescreens the full customer book only quarterly may have a defensible position for lower-risk customers; it will struggle to defend that cadence for high-risk or politically exposed persons.
Third, the program must address the unhosted-wallet and counterparty-VASP dimensions described above. That means a documented policy for how the VASP handles transactions involving unhosted wallets, how it identifies and screens counterparty VASPs, and how it manages Travel Rule non-compliance by the counterparty VASP.
Fourth, governance must be clear. The MLRO (money laundering reporting officer) or compliance officer must have a defined escalation path for sanctions hits, documented decision authority, and access to senior management and the board where required. Regulators in every major hub expect to see the MLRO function embedded in the governance structure, not outsourced entirely or treated as a formality.
Fifth – and this is the element most frequently absent when we review programs in our cross-border practice – the program must be tested. That means regular internal audits, periodic independent reviews, and documented responses to the findings. A regulator conducting a supervisory review looks for evidence that the program was tested, that findings were escalated, and that remediation was completed. A program that has never been tested is, in regulatory terms, a program of unknown effectiveness.
Micro-Matter: Managing a Sanctions Alert Across Two Jurisdictions
In a recent compliance matter, a payments company holding licences in two jurisdictions received a positive sanctions alert on an existing business customer during a periodic rescreening cycle. The customer appeared on the list of one sanctions regime but not the other, and the company's banking relationships were split across both jurisdictions. We advised on the legal obligations under each applicable regime, the interaction with the customer's contractual rights, and the reporting obligations to the relevant regulators. The matter was resolved by a structured exit from the relationship with contemporaneous documentation of the decision rationale, preserved for future regulatory inquiry. The outcome avoided enforcement exposure in both jurisdictions. The lesson: multi-list divergence is not a technical anomaly – it is a governance scenario that requires pre-built decision authority and documented protocols before the alert arrives.
Decision Matrix: Which Operator Profile Needs What Sanctions Program Architecture?
The appropriate sanctions screening architecture depends on the VASP's profile. Across the businesses we advise, three broad profiles emerge.
Profile A – Single-jurisdiction retail exchange: A VASP licensed in one EU member state under MiCA, serving retail customers exclusively within the EU, banking through a single EU credit institution. The relevant list universe is the EU consolidated list. The primary tools are a name-screening system at onboarding and rescreening, on-chain analytics for wallet screening, and a Travel Rule solution for transfers with counterparty VASPs. The MLRO function must be resident in the licensed entity. This is the baseline architecture. The key risk is that the business expands its banking relationships or user base into the UK or US without revisiting the list universe.
Profile B – Multi-hub institutional platform: A VASP with licences in Dubai under VARA and in Singapore under the MAS Payment Services Act, serving institutional clients globally, with banking in the US and Europe. The list universe is the UAE consolidated list, MAS-mandated UN-derived and Singaporean designations, OFAC (by reason of the US banking relationship), and EU sanctions (by reason of the European banking relationship). This profile requires a multi-list screening system, a Travel Rule solution operable across both VARA and MAS jurisdictions, and a governance framework that resolves which MLRO has authority over a cross-jurisdiction alert. The key risk is the OFAC extraterritorial dimension: institutional clients who are not US persons may still transact in US dollars, pulling the VASP within OFAC scope without either party appreciating it.
Profile C – DeFi front-end with regulated wrapper: A technology company that provides a user interface to decentralized protocols but holds a limited regulatory permission in one jurisdiction. The sanctions exposure is determined by the regulators taking the position that wallet-screening obligations attach to the customer-facing interface. The list universe at minimum follows the licensed jurisdiction's requirements, but the OFAC extraterritorial question remains live if any US person can access the interface. The key risk is that the regulatory position on DeFi front-ends is evolving rapidly, and a program built to today's expectations may need rapid revision.
What Do Regulators Look for When They Audit a Crypto AML Program?
Regulators auditing a VASP's AML and sanctions compliance program across the major hubs follow broadly comparable methodologies, even where the specific legal requirements differ. In our cross-border practice, we have assisted businesses preparing for supervisory reviews across multiple jurisdictions, and the pattern is consistent.
The review typically begins with the governance documentation: the AML policy, the sanctions policy, and the risk assessment. Regulators expect these documents to reflect the actual business model, not a generic template. A policy that describes a product suite the VASP no longer offers, or omits a product it does offer, signals to the reviewer that the program is not embedded in operations.
Transaction monitoring is scrutinized closely. Regulators expect to see the tuning rationale for the alert thresholds: why was a specific threshold set, who approved it, and when was it last reviewed? A program that has run at the same alert thresholds for two years without review will attract questions about whether the thresholds are still calibrated to the current customer and transaction profile.
Training records are frequently examined. The MLRO and compliance team must be able to demonstrate that they understand both the general AML/CFT obligations and the specific sanctions rules applicable to the business. Regulators in jurisdictions including the FCA and MAS expect training to be documented, role-specific, and updated when regulatory requirements change.
Finally, regulators look at the suspicious activity reporting (SAR) record. The number, timing, and quality of SARs filed are read as indicators of whether the program is functioning. A VASP that has processed substantial transaction volume over several years and filed no SARs, or a very small number, faces a credibility challenge in explaining why no suspicious activity was identified.
If a prior application stalled, a supervisory review identified gaps, or banking was withdrawn after a compliance failure, a structural review can identify the root cause and the path to remediation. Write to OBOLUS at info@oboluslaw.com.
A Common Assumption: Offshore Registration Satisfies Global Screening Obligations
A common assumption among early-stage crypto businesses is that a single offshore registration – in the BVI under the VASP Act, in the Cayman Islands under CIMA's regime, or in a similarly positioned jurisdiction – is sufficient to serve customers globally with a defensible sanctions screening posture. That assumption is incorrect, and acting on it is a source of material enforcement risk.
An offshore registration satisfies the regulatory requirement of the jurisdiction that granted it. It does not substitute for the requirements of the jurisdiction where the customer is located, the jurisdiction where the banking relationship is held, or the jurisdiction whose sanctions regime applies by reason of the currency used or the correspondent bank involved. OFAC, in particular, applies on the basis of US nexus – dollar transactions, US correspondent banks, US investors – regardless of where the VASP is incorporated or licensed.
Operators we advise who have relied on this assumption typically discover the gap when their banking correspondent conducts an enhanced due diligence review, or when a customer in a major jurisdiction triggers a regulatory inquiry. At that point, building a compliant program under pressure is far more costly and disruptive than building it correctly from the start. We map the licence, banking, and sanctions obligation stack as a single analysis – not three disconnected workstreams.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – the full practice overview, from FATF obligations to programme design across major hubs.
- MLRO and compliance officer function for established operators – how to structure the MLRO role, responsibilities and governance within a regulated VASP.
- Sanctions screening for regulated crypto entities – a dedicated service page for VASPs building or remediating their screening architecture.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP, when initiating a crypto transfer, to collect and transmit originator and beneficiary information – name, account identifier, and additional data – to the receiving VASP. The obligation derives from FATF Recommendation 16 as applied to virtual assets. Jurisdictions including the EU under MiCA's Transfer of Funds Regulation, Singapore under MAS guidance, and the UK under FCA rules have each implemented binding Travel Rule requirements. The precise data fields and threshold amounts vary by jurisdiction and should be verified against current applicable rules.
Who must act as MLRO for a crypto firm?
Most major licensing regimes require a regulated VASP to designate a natural person as the money laundering reporting officer (MLRO) or equivalent compliance officer. That individual must meet the regulator's fit-and-proper requirements, have sufficient seniority and resource to carry out the function, and be resident or accessible in the jurisdiction as the regulator requires. Some regimes permit the function to be shared or outsourced subject to conditions; others require it to be held in-house. The MLRO carries personal responsibility for the adequacy of the AML and sanctions program.
How do regulators audit crypto AML programs?
Regulators auditing a VASP's AML program typically review governance documentation, the written risk assessment, transaction monitoring thresholds and alert records, suspicious activity reporting history, customer due diligence files, and staff training records. They expect documents to reflect the actual current business model. A program that has not been independently reviewed, or whose alert thresholds have not been updated since launch, will attract scrutiny. Proactive testing, documented remediation of findings, and evidence of board-level engagement with the AML framework are the markers regulators look for in a mature program.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the sanctions, AML and compliance programs that sit around them. We structure licensing, banking and compliance as one mandate rather than three disconnected workstreams – so the gaps that create enforcement exposure are identified before they are found by a regulator. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Lydia Brennan, Tax & Structuring Analyst – specialising in the cross-border compliance and structural tax considerations that attend sanctions and AML program design for regulated digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.