A virtual asset service provider (VASP) that treats its AML/CFT policy as a compliance checkbox – rather than as a legal instrument that will be read by a regulator, a forensic examiner or an opposing party's counsel – is building a liability that surfaces at the worst possible moment: during enforcement, during a freezing-order application or during civil recovery proceedings. The documents a VASP drafts today become the evidence standard against which its conduct is measured tomorrow. That reality reshapes how every clause in an AML/CFT policy should be written, structured and version-controlled.
This analysis examines AML/CFT policy drafting through the disputes lens – the angle that most compliance consultants leave out. It maps the contrasting positions regulators and courts take when they read the same document, identifies the structural drafting failures that convert a minor gap into an enforcement finding, and sets out a decision matrix for operators choosing between a minimum-viable-policy approach and a litigation-ready one. The cross-border dimension is deliberate: a VASP licensed in one hub but serving users, holding assets and banking in others faces a multi-forum exposure that a single-jurisdiction policy cannot address.
Why AML/CFT Policy Drafting Is a Disputes Issue
An AML/CFT policy is simultaneously a regulatory compliance document and a forensic artifact. Regulators – the Financial Action Task Force (FATF), national supervisors operating under FATF Recommendation 15, and VASPs' own competent authorities such as VARA, the FCA, MAS and ESMA's national counterparts under MiCA – read a policy to assess whether a firm has understood its legal obligations and built systems proportionate to its risk. Courts, forensic accountants and opposing counsel read the same document to reconstruct what the operator knew, when it knew it, and whether it departed from its own stated procedures. Those are structurally different readings of the same text, and a policy drafted to satisfy one audience only will often fail the other.
In our cross-border practice, we regularly review AML/CFT policies produced by operators at the point when a dispute or enforcement inquiry has already begun. The pattern is consistent: the policy states a procedure that the operator never actually ran; the operator ran a procedure that the policy never mentions; or the policy exists in a single version that pre-dates three rounds of product changes without a single amendment. Each of those gaps, in the hands of a skilled examiner, becomes a narrative about systemic failure rather than an isolated oversight.
The commercial stakes are not abstract. Operators we advise routinely report that a banking correspondent's AML review, a VASP licence renewal, or a counterparty due diligence process has surfaced a policy weakness that then delayed operations by weeks or months. The disputes angle is therefore also a business-continuity angle: the policy that would fail in court will often fail in a banking review first.
The Regulatory Baseline: What FATF and National Regimes Require
FATF Recommendation 15 requires that VASPs be regulated, licensed or registered and supervised for AML/CFT purposes, and that they implement the full suite of customer due diligence, transaction monitoring, suspicious activity reporting and record-keeping obligations. That baseline is then translated – with material variation – into each national regime: the applicable provisions under MiCA and its attendant delegated acts for EU-licensed entities; the VARA rulebooks for Dubai-mainland operators; the Payment Services Act framework administered by MAS in Singapore; the FCA's money-laundering registration requirements in the UK; and the VASP Act regimes in the BVI and Cayman Islands, among others.
The point at which drafting error most reliably surfaces in disputes is the gap between what the international baseline requires and what the operator's policy actually says. A policy drafted to FATF's standard recommendations without being calibrated to the specific regime under which the operator holds its licence will almost certainly miss jurisdiction-specific requirements. ESMA and national competent authorities under MiCA have authority to require policies that address crypto-specific risk factors the older FATF guidance did not anticipate in detail. VARA's rulebooks impose layered obligations around high-risk customer categories that an operator with a legacy FATF-template policy will not have addressed.
For a multi-jurisdictional operator – one entity licensed in Lithuania under a MiCA CASP authorisation, a subsidiary registered with the FCA, and a custody vehicle in the Cayman Islands under the applicable CIMA regime – there is no single policy template that satisfies all three regulators simultaneously. The choice is between a master policy with jurisdiction-specific addenda (the approach we generally recommend) and separate standalone policies for each entity (administratively heavier but sometimes cleaner for regulators who want to see the full document without conditional language). Either approach requires deliberate drafting; neither happens by accident.
How Courts Read an AML/CFT Policy: The Litigation Standard
When a VASP's AML/CFT policy enters a courtroom – in England and Wales, the DIFC Courts, Singapore, Hong Kong or New York – it enters as a document that the firm voluntarily adopted as its own standard of conduct. The question a court will ask is not whether the policy was sophisticated; it is whether the firm followed what it promised to do. Departure from a stated procedure is the most common mechanism by which an operator converts a regulatory issue into a civil-liability issue or a criminal-exposure issue.
England and Wales is the most active jurisdiction globally for crypto asset tracing and recovery proceedings. Courts there have examined VASP records – including policy documents, transaction-monitoring alerts and KYC decision logs – in the context of Norwich Pharmacal and Bankers Trust disclosure applications, and in proceedings following worldwide freezing orders. The disclosure framework that English courts apply is broad: a VASP served with a disclosure order must produce the documents it holds, including its AML/CFT policy, its alert logs and any internal escalation records. If those records show that the VASP's policy required enhanced due diligence for a category of customer and no enhanced due diligence was performed, the firm's exposure extends beyond the regulatory to the tortious.
The DIFC Courts have shown comparable willingness to examine VASP conduct records in asset-recovery proceedings. In matters we have monitored, the forensic examination of a VASP's transaction monitoring records – against the policy that was supposed to govern those records – has been a decisive factor in establishing whether a respondent VASP was itself complicit or merely negligent. That distinction carries significant consequences for injunctive relief and for damages.
The practical drafting implication is this: every procedural commitment in an AML/CFT policy should be capable of being discharged as written. If enhanced due diligence is triggered at a specific threshold, the threshold must be operationally embedded in the transaction-monitoring system. If a policy states that the Money Laundering Reporting Officer reviews all alerts above a certain risk score within a stated period, that workflow must exist and be documentable. A policy that outpaces the firm's actual operational capacity is not a conservative document – it is a liability.
To discuss the litigation exposure embedded in your current AML/CFT documents, contact OBOLUS at info@oboluslaw.com. The gap between what your policy says and what your systems do is often the first thing an opposing party's counsel will look for.
The Travel Rule: Drafting Failures That Migrate into Disputes
The Travel Rule – the obligation, derived from FATF Recommendation 16, to collect, verify and transmit originator and beneficiary information with virtual asset transfers – is the single most technically complex AML obligation a VASP must operationalize, and therefore the most fertile ground for drafting failures that later become dispute exhibits.
The Travel Rule requires a VASP to identify the originating and receiving parties to a transfer above the applicable threshold, transmit that information to the receiving VASP and verify it against its own customer records. The applicable threshold varies by jurisdiction – a point that a single-jurisdiction policy will miss entirely. An operator moving value between a Singapore-licensed entity and a UK-registered entity, with the end recipient using a Cayman-registered custody vehicle, is simultaneously subject to the threshold rules applicable under MAS's Payment Services Act regime, the FCA's MLR provisions and the VASP Act framework administered by CIMA. Those thresholds are not identical. A policy that states a single global threshold – without identifying which threshold applies to which entity and which leg of a transfer – will misfire in at least one jurisdiction on a routine basis.
In litigation, Travel Rule failures typically surface in one of two ways. First, a claimant seeking to trace misappropriated assets will subpoena Travel Rule transmission records to establish the flow of funds across exchanges – and if the respondent VASP failed to collect or transmit the required data, that failure can be used to challenge the admissibility or completeness of its own transaction records. Second, a regulator examining a suspicious activity report will look at whether the reporting VASP's Travel Rule policy was operational at the time of the flagged transaction. If the policy was adopted but not implemented, the supervisor's finding will be failure to maintain an effective AML program rather than a mere administrative gap – a materially heavier charge.
The cross-border angle here is particularly acute for operators who use third-party Travel Rule technology solutions. The technology platform may be compliant with its own jurisdictions; it may not automatically address the transmission format, encryption standard or counter-party VASP verification protocol required by the operator's own licensing jurisdiction. The policy must specify how the technology integrates with the operator's legal obligations – not simply adopt the technology vendor's standard terms by reference.
KYC Framework Design and the Evidentiary Gap
A KYC framework (know-your-customer program) that cannot produce a coherent audit trail for a single customer relationship – from initial identification through ongoing monitoring to exit or SAR filing – is a framework in name only. In our practice, the evidentiary gap between a VASP's stated KYC policy and its actual records is the finding that most often determines the outcome of both regulatory examinations and third-party recovery actions.
The structural issue is version control. A KYC policy is a living document. Customer risk classifications, identity verification standards and beneficial ownership requirements change as the operator's product evolves, as it enters new markets and as its regulator issues updated guidance. Operators who maintain a single undated policy document – or who overwrite previous versions without a change log – are unable to demonstrate to a court or a regulator what procedures applied at any specific point in time. That inability is itself an evidentiary problem: it allows an examiner to apply the current, stricter standard to historical conduct, even if the historical standard was actually more permissive.
Version control is therefore not a document-management nicety; it is a legal protection. Every material amendment to a KYC framework should be dated, attributed to the approving officer and retained in a form that allows the operator to reconstruct the standard that applied on any given date. The same principle applies to risk appetite statements, PEP screening lists and the criteria used to trigger enhanced due diligence.
Regulators in the leading hubs – MAS, VARA and the national competent authorities operating under MiCA – increasingly expect a VASP's KYC framework to demonstrate proportionality between the operator's assessed risk profile and the controls it has deployed. A policy that is identical in its customer risk-scoring methodology for a peer-to-peer derivatives platform and for a retail exchange serving mainstream consumers is unlikely to survive regulatory scrutiny in any of those hubs. It is also unlikely to assist a court that is trying to determine whether the operator exercised reasonable care in relation to a specific customer category.
Transaction Monitoring: The Gap Between Policy and System
Transaction monitoring policy provisions are the highest-frequency source of disputes-relevant AML documentation failure, because they create the most verifiable commitments. A policy that states specific alert-trigger conditions, review timelines and escalation hierarchies is making operational promises that the firm's technology stack either keeps or breaks – and that record of keeping or breaking is fully recoverable in disclosure proceedings.
In our cross-border practice, we have seen transaction-monitoring policies that specified alert logic for one blockchain network but were silent on others that the operator's platform subsequently added. We have seen policies that required a second-line compliance review of all high-risk alerts within a defined period, where the firm's actual workflow had no second-line function at all. In each case, the document gap was not the root problem; it was the symptom of a policy that was drafted at launch and never maintained as the business grew.
The disputes-angle lesson is structural. Transaction monitoring policies should be drafted in modules: the rule-set governing alert generation (which lives closer to the technology team and changes frequently), the escalation and documentation procedure (which lives in compliance and changes less often), and the SAR filing threshold and timing (which is set by the applicable legal regime and should be stated by reference to that regime, not as a free-standing internal rule). Modularizing the policy allows the operator to update each component on its own cycle without producing a version-control tangle that an examiner can exploit.
For operators using on-chain forensic tools – Chainalysis, TRM Labs, Elliptic or comparable platforms – the policy must specify how the tool's output is weighted in the alert review process. A risk score generated by a blockchain analytics provider is an input to a human judgment, not a substitute for it. A policy that delegates the compliance decision to the tool's output – without specifying the human review layer – will not satisfy the applicable VASP provisions in any major licensing jurisdiction, and will be scrutinized closely in any proceeding where the tool's scoring methodology is itself in dispute.
Micro-Matter: Policy Gap Exposed in Recovery Proceedings
In a recent matter, a payments company sought our assistance after a forensic examination in connection with civil recovery proceedings revealed that its transaction monitoring policy had not been updated to cover a specific class of automated transfers introduced to its platform the prior year. The policy required enhanced review for transfers above a stated risk score, but the risk-scoring logic had never been configured for the new transfer type – meaning the category generated no alerts by design, even when individual transfers carried characteristics that would have triggered review under any rational risk model. The gap had persisted across multiple quarterly compliance reviews without detection because the reviews were conducted against the policy document, not against the system's alert coverage. Working in coordination with allied counsel in the relevant forum, we assisted in preparing the disclosure materials that explained the gap to the court and in restructuring the monitoring policy and system configuration on an expedited basis. The proceedings resolved without a finding of systemic evasion, a distinction that materially affected the operator's subsequent regulatory posture.
The MLRO Function: Drafting Accountability into the Policy
The Money Laundering Reporting Officer (MLRO) role must be defined in the policy with sufficient precision that the responsibilities of the office are clearly assigned, documented and capable of being transferred. A policy that states only that "the MLRO is responsible for AML compliance" is not a policy; it is a title. In disputes, the MLRO's documented decisions – and equally the decisions the MLRO was never asked to make – are among the most probative records available to an examiner.
The applicable provisions under MiCA, the VARA regime, the FCA's MLR framework and MAS's Payment Services Act regime all contemplate a senior management function with named accountability for AML/CFT program oversight. The policy should specify, at minimum: the MLRO's decision-making authority in the SAR escalation chain; the circumstances under which the MLRO must escalate to the board or to the applicable regulator; the process by which a temporary or acting MLRO assumes responsibilities in the event of absence or departure; and the record-keeping requirements that attach to the MLRO's decisions.
Board-level accountability is a distinct but related issue. Regulators in the major hubs increasingly assess whether senior management has received adequate AML/CFT training and whether board minutes reflect active oversight of the compliance function. A policy that assigns all accountability to the MLRO without establishing a board-level escalation mechanism may satisfy the letter of the applicable regime while failing its spirit – and that failure will be apparent to an examiner who reads the governance documents in sequence.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To map the AML policy and governance structure that your licensing jurisdiction requires, write to OBOLUS at info@oboluslaw.com.
Decision Matrix: Minimum-Viable Policy vs. Litigation-Ready Policy
The choice between a minimum-viable AML/CFT policy and a litigation-ready one is not primarily a question of sophistication; it is a question of how the operator's risk profile maps against its operational capacity and its exposure to cross-border proceedings.
Profile A – Early-stage VASP, single-jurisdiction licence, no institutional counterparties. The appropriate policy is a lean, carefully maintained document that tracks the applicable regime's requirements precisely, avoids commitments the operator cannot operationally discharge, and is versioned from day one. The primary risk is regulatory examination at licence renewal; the secondary risk is being named in a third-party disclosure application where the firm holds records relevant to a dispute between other parties. A minimum-viable policy is defensible here if it is operationally accurate.
The indicative timeline for building this policy from a regulatory baseline is a matter of weeks for a firm with clean product architecture and a clear customer risk profile.
Profile B – Multi-jurisdiction operator, institutional rails, Travel Rule obligations across multiple entity pairs. A litigation-ready policy is required. The document must address each licensing jurisdiction's specific requirements, the Travel Rule threshold applicable to each entity, the KYC risk classifications appropriate to the operator's customer base, and the transaction monitoring logic governing each product line. Version control and MLRO accountability provisions must be explicit. The primary risk is regulatory examination in multiple jurisdictions simultaneously; the secondary risk is being drawn into recovery or enforcement proceedings where the operator's own records are the subject of disclosure.
The indicative drafting and implementation timeline for this profile extends to several months for a firm without existing policy infrastructure. The cost of that investment is materially lower than the cost of a policy-gap finding during an active enforcement inquiry.
Profile C – Operator seeking a new licence in a jurisdiction where AML/CFT policy quality is a material criterion in the application review. VARA, MAS and the national competent authorities under MiCA all treat the quality of the applicant's proposed AML/CFT documentation as a substantive criterion, not a formality. A policy submitted with a licence application that is generic, unversioned or mis-calibrated to the jurisdiction's specific risk categories will generate a deficiency notice that delays the application. The policy for this profile must be drafted to the anticipated regulator's standard before submission.
A Common Assumption About Offshore Policies
A common assumption among operators establishing a VASP in an offshore jurisdiction is that a simple AML/CFT policy calibrated to that jurisdiction's requirements is sufficient for the entirety of their business – including users, banking relationships and institutional counterparties located elsewhere. That assumption is incorrect, and the disputes angle makes the error especially costly.
An operator licensed in the BVI under the VASP Act, banking in a European correspondent and serving users across multiple continents is exposed to the regulatory and legal standards of each jurisdiction where it conducts a material part of its business. Its banking correspondent will apply its own AML/CFT standard – which may exceed the BVI's – as a condition of maintaining the account. Its institutional counterparties will conduct due diligence against their own jurisdictions' expectations. And if assets traced through the operator are frozen in a common-law proceeding, the court examining its records will apply the standard of what a reasonably competent VASP would have done – informed by the international FATF baseline, not only by the offshore regime.
We map the compliance exposure across the operating, custody and payment layers before operators commit to a structure. The licence stack and the AML policy stack must be designed together.
Self-Assessment Checklist for AML/CFT Policy Fitness
Operators who want to pressure-test their current AML/CFT policy against the disputes standard should work through the following diagnostic sequence before the next regulatory examination or the next counterparty due-diligence request.
- Does the policy identify, by name, each licensing jurisdiction in which the operator or a group entity is regulated, and does it specify the applicable regime for each?
- Does the Travel Rule section state the applicable threshold for each entity pair, and does it describe the transmission mechanism and the counterparty-VASP verification procedure?
- Is every version of the policy dated and retained, with a change log that identifies who approved each amendment and when?
- Does the transaction monitoring section describe the alert-trigger logic in a way that can be verified against the actual system configuration?
- Is the MLRO role defined with specific decision-making authority, escalation triggers and succession provisions?
- Does the policy address on-chain forensic tool output, and does it specify the human review layer that sits above the tool's risk score?
- Has the policy been reviewed, and has that review been documented, within the past twelve months or following any material product change?
A negative answer to any of these questions is a gap that warrants attention before rather than during a regulatory or legal proceeding.
Related at OBOLUS
- AML/CFT and Travel Rule for Digital Asset Businesses – our full practice area coverage across licensing hubs and compliance regimes
- VASP Business Risk Assessment for Early-Stage Founders – a scoped risk assessment for operators building their first compliance program
- Token Sale Agreement Drafting in Poland – structuring and documentation for token issuances under applicable Polish and EU frameworks
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect, verify and transmit originator and beneficiary information – including names, account identifiers and, in some regimes, address data – alongside virtual asset transfers above the applicable threshold. The threshold varies by jurisdiction; multi-entity operators must track each entity's applicable standard separately. The receiving VASP must verify the transmitted information against its own customer records before processing the transfer.
Who must act as MLRO for a crypto firm?
Most major licensing regimes – including those administered by VARA, MAS, the FCA and the national competent authorities under MiCA – require the MLRO to be a named individual of sufficient seniority to exercise genuine oversight of the AML/CFT program. The MLRO must have clear decision-making authority for SAR filings and escalation, access to transaction monitoring outputs, and a documented line of accountability to the board. Acting or temporary arrangements must be pre-planned and documented in the policy itself.
How do regulators audit crypto AML programs?
Regulators conducting AML examinations typically review the VASP's policy documentation, its customer risk assessment methodology, a sample of customer due diligence files, transaction monitoring alert logs and SAR filing records. They assess whether the written policy matches the operational systems and whether the overall program is proportionate to the operator's specific risk profile. A policy that was never operationalized – or that has not been updated to reflect the operator's current products and customer base – is among the most common findings at examination.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML/CFT and Travel Rule obligations that sit at the intersection of those activities. Digital assets are the entirety of our practice. We map the compliance stack across the operating, custody and payment layers before our clients commit to a structure – because the policy that fails in litigation usually failed in design. To discuss your AML/CFT program, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – advising digital-asset operators on the technology-law interface, including AML/CFT policy architecture, on-chain compliance tooling and the disputes exposure embedded in compliance documentation.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.