Operating a digital-asset business without a properly documented KYC and onboarding framework (the suite of know-your-customer controls that sit at the front of every customer relationship) exposes the firm to enforcement, de-risking by banking partners and, increasingly, direct regulatory sanction. As supervisors across the major hubs tighten their expectations – from ESMA's CASP authorisation standards under MiCA to VARA's activity-based rulebooks in Dubai – the question for a general counsel is no longer whether KYC compliance is required, but whether the firm's current program can survive a regulatory audit, a correspondent-bank questionnaire or a contested onboarding dispute.
This analysis sets out the compliance burden in practice: the legal obligations that drive it, the cross-border frictions that multiply it, and the structural choices that determine whether it becomes a competitive asset or a liability. We examine contrasting regulatory positions, work through a decision matrix by operator profile, and surface the common mistakes we see in cross-border structures. The goal is a document a general counsel can use before the next board call.
What the KYC Burden Actually Requires of a Digital-Asset Business
Every major AML regime imposes a baseline obligation: identify your customer, verify that identity, understand the business relationship, and keep records. The AML compliance framework that applies to a VASP (virtual asset service provider) is materially more demanding than the generic financial-institution standard, because the on-chain environment introduces anonymity vectors – pseudonymous wallets, DeFi interactions, cross-chain bridges – that a traditional bank does not encounter. Regulators expect VASPs to account for those vectors explicitly.
Under MiCA, a CASP (crypto-asset service provider) must implement customer due diligence procedures that meet the standards set by the applicable EU Anti-Money Laundering directive. The Bank of Lithuania, the MFSA in Malta, and every other national competent authority applying MiCA is expected to scrutinize those procedures at the point of authorization and on an ongoing supervision basis. VARA in Dubai requires activity-specific AML/KYC manuals – a custody licensee faces different onboarding requirements from an exchange – and each rulebook specifies the minimum content of those manuals. The FCA in the UK applies its Money Laundering Regulations registration test partly on the adequacy of the applicant's AML controls, and an underdeveloped KYC policy is among the most common stated grounds for rejection.
The compliance burden, in practice, has three distinct layers. First, the customer identification program: collecting and verifying identity documents, beneficial ownership data and, for business customers, corporate structure evidence. Second, risk-based due diligence: mapping each customer to a risk tier (standard, enhanced, simplified where permitted) and calibrating monitoring intensity accordingly. Third, transaction monitoring: screening transactions in real time against sanctions lists, PEP databases and typology patterns, and filing suspicious activity reports where the threshold is met. Getting all three right, consistently, across multiple jurisdictions of both operation and customer residence, is the practical burden this analysis addresses.
How the Travel Rule Compounds the Cross-Border Obligation
The Travel Rule – the FATF Recommendation 15 obligation to pass originator and beneficiary data with every qualifying virtual-asset transfer – converts a domestic compliance program into a cross-border data-exchange infrastructure problem. A VASP that has built strong onboarding controls but has not solved its Travel Rule implementation is non-compliant in every jurisdiction that has enacted FATF-aligned rules, which now includes the EU under MiCA, Singapore under the Payment Services Act administered by MAS, the UK under FCA guidance, and a growing number of others.
The practical challenge is interoperability. A Singapore-based exchange sending funds to a counterpart VASP in Germany needs a Travel Rule messaging protocol both sides can read, a process for verifying that the receiving entity is indeed a regulated VASP (not an unhosted wallet or an unregistered entity), and a policy for what to do when the counterpart cannot or will not supply the required data. In our cross-border practice, we regularly advise clients on all three questions – and the unhosted-wallet problem remains the sharpest point of regulatory divergence between jurisdictions.
The data threshold that triggers the Travel Rule obligation varies by jurisdiction and is set by each competent authority; operators should consult current legislation for the precise figure in each market they serve. The legal consequence of non-compliance is not merely a fine: correspondent banks and stablecoin issuers increasingly treat Travel Rule non-compliance as a de-risking trigger, which means a VASP without a functioning Travel Rule program can find its banking rails and its USDT/USDC access cut simultaneously. That is an existential risk, not a technical one.
Contrasting Regulatory Positions on KYC Adequacy
Regulators in the leading hubs do not apply a single definition of KYC adequacy, and the divergence matters when a business operates across multiple jurisdictions. VARA in Dubai takes an activity-specific approach: each licensed activity category carries its own minimum KYC standard, and a firm holding both an exchange licence and a custody licence must maintain separate, compliant programs for each. The FSRA within ADGM applies a risk-proportionate framework that has historically given well-capitalized institutional operators more flexibility in their onboarding design, provided the underlying risk rationale is documented.
MiCA's approach is harmonized in principle but nationally variable in practice. ESMA sets the framework; the Bank of Lithuania, the MFSA and other NCAs set the supervisory intensity. A CASP passporting from Malta into Germany may find that the German BaFin, as host-state supervisor, expects additional disclosures or enhanced due diligence on German-resident customers that exceed what the Maltese home-state regime requires. That gap is a live compliance risk for any operator that treats passporting as a substitute for local analysis.
Singapore's MAS takes a tiered approach under the Payment Services Act. A Major Payment Institution conducting Digital Payment Token services faces stricter CDD requirements than a Standard Payment Institution, reflecting the different risk profiles of the volumes they handle. The SFC in Hong Kong applies detailed VASP licensing criteria that include KYC as a threshold condition: an applicant that cannot demonstrate a credible onboarding program will not receive a licence, regardless of its technology or capital position. FINMA in Switzerland expects VASP-equivalent AML controls aligned with its published guidance, and the Swiss SRO affiliation model means that a firm must satisfy not only the regulator but also its self-regulatory organization's compliance standards.
The practical takeaway is that a KYC framework designed for one jurisdiction will, in almost every case, need modification before it works in a second. We advise clients to build a modular framework – a documented core standard with jurisdiction-specific annexes – rather than attempting to design a single universal policy that ends up inadequate everywhere.
What Does a Compliant KYC Framework Need to Contain?
A compliant KYC framework for a VASP operating across jurisdictions must address at least seven substantive areas. Missing any one of them is the kind of gap that surfaces in a regulatory examination or a bank due-diligence questionnaire and is difficult to explain away.
The first is customer identification and verification: the documents, data sources and verification methods the firm uses to confirm who a customer is, including identity document checks, liveness testing for remote onboarding, and sanctions screening at admission. The second is beneficial ownership identification: for corporate customers, tracing the natural persons who ultimately own or control the entity, to the threshold set by the applicable AML regime. The third is risk classification: a documented methodology for assigning each customer to a risk tier and reviewing that classification on a defined cycle.
The fourth is enhanced due diligence triggers: politically exposed persons, high-risk jurisdictions on the FATF grey or black list, unusual transaction patterns and specific product risks (DeFi interactions, mixing services, privacy coins) that the firm's policy identifies as requiring elevated scrutiny. The fifth is transaction monitoring: automated systems calibrated to the firm's risk appetite and product set, with human review thresholds and a documented escalation path. The sixth is Travel Rule compliance: the technical and procedural solution for passing and receiving counterparty data on qualifying transfers. The seventh is record-keeping and SAR filing: the retention periods, the secure storage standard and the filing process for suspicious activity reports with the relevant financial intelligence unit.
In our practice, the areas that most frequently fall short are beneficial ownership (firms capture the direct shareholder but stop short of the ultimate natural person), transaction monitoring calibration (alert thresholds set so broadly that the compliance team is overwhelmed and genuine red flags are missed) and Travel Rule implementation (firms that have purchased a Travel Rule solution but have not integrated it into their onboarding workflow or trained staff on the unhosted-wallet decision tree).
The MLRO Role and Governance Structure in a Crypto Firm
Every regulated VASP in a major jurisdiction must designate a Money Laundering Reporting Officer (MLRO) – a named individual who is responsible for the firm's AML program, for receiving and assessing internal suspicious activity reports, and for making filings to the relevant financial intelligence unit. The MLRO role is a personal legal obligation, not merely a job title, and regulators scrutinize the fitness and seniority of the appointee.
Under the FCA's Money Laundering Regulations registration framework, the MLRO must be of sufficient seniority and have direct access to the board. VARA's AML rulebook sets similar expectations: the compliance function must be independent of business development, and the MLRO must have the authority to stop onboarding a customer or freeze a transaction without requiring business-line approval. The Bank of Lithuania and the MFSA, applying MiCA-aligned standards, expect the MLRO to be an approved person whose appointment is notified to the regulator.
For a cross-border operator, the governance question becomes more complex. A VASP holding licences in two jurisdictions may face a requirement to have a local MLRO in each. Some regulators will accept a group-level MLRO with a local deputy; others insist on a fully resourced local function. Getting this wrong at the licensing stage is expensive: a regulator that discovers a nominal MLRO appointment – someone whose day job is in a different department and who lacks genuine authority – will treat that as evidence of a systemic compliance failure, not an administrative error. The consequences range from remediation orders to licence suspension.
Decision Matrix: Which KYC Architecture Fits Which Operator Profile?
Not every VASP faces the same compliance burden, and the architecture of the KYC framework should reflect the firm's specific risk profile, customer base and regulatory footprint. The following matrix sets out four representative profiles and the framework design that best fits each.
Profile A – Retail exchange, multiple EU jurisdictions, high-volume, low-average-value transactions. The appropriate framework centers on automated, high-throughput identity verification at onboarding (biometric document checks, liveness detection), a risk-based tiering system that flags high-risk customers for enhanced due diligence without creating a manual backlog for standard customers, and a Travel Rule messaging solution integrated into the withdrawal and deposit flow. The MiCA CASP authorisation in the home member state, with passporting notifications to host NCAs, is the regulatory instrument. The key risk is alert fatigue in transaction monitoring: with high volumes, a poorly calibrated system generates more false positives than the compliance team can handle, and genuine red flags are missed.
Profile B – Institutional over-the-counter desk, global clients, large individual transactions, significant number of corporate and fund counterparts. The framework requires deeper beneficial ownership analysis at onboarding – full corporate structure mapping, UBO certification and, for fund clients, investor-level transparency where the applicable regime requires it. Automated verification is less relevant; a dedicated KYC analyst reviewing each file is appropriate. Transaction monitoring can tolerate longer review cycles because individual transaction values justify the human resource cost. The Travel Rule obligation is acute because each transfer is likely above any de-minimis threshold. FINMA, the FSRA or MAS are typical licensing counterparts for this profile. The key risk is stale KYC: corporate structures change, UBOs change, and a firm that runs a strong initial onboarding process but lacks a periodic review cycle will accumulate outdated files that fail examination.
Profile C – DeFi protocol with a regulated front-end, mixed user base, uncertain jurisdictional perimeter. The compliance architecture must first answer the threshold legal question: which activities, at which interface, constitute regulated VASP services? Once that boundary is drawn, the KYC framework applies to the regulated interface only. The risk here is that the boundary-drawing exercise is done carelessly: a protocol that assumes its on-chain activity is unregulated while maintaining a regulated front-end for fiat on-ramps may find that the on-chain activity itself crosses a supervisory threshold in certain jurisdictions. Roman Levitt, who leads our technology and DeFi counsel work, regularly advises on exactly this boundary question before clients commit to an architecture.
Profile D – Custody-only service, institutional clients, single jurisdiction. The framework can be leaner on the transaction monitoring side (custody involves holding, not transacting) but must be deeper on the source-of-funds and source-of-wealth side. Custodians in the leading hubs – under VARA, FSRA, MAS or the SFC – face specific safeguarding and segregation obligations that interact with the KYC framework: the firm must know not only who the customer is but where the assets came from and whether the custody arrangement itself is structured in a way that does not create a money-laundering exposure for the custodian.
CTA #1: The matrix above describes the standard analytical path. Your firm's facts – the entity structure, the user base, the banking counterparts, the products – change the analysis materially. For a scoped assessment of your KYC architecture, contact OBOLUS at info@oboluslaw.com. Map your options.
The Cross-Border Reality: Where KYC Programs Break Down
A KYC program that passes muster in its home jurisdiction regularly fails when the operator expands to a second market, and the failure is almost always structural rather than accidental. The three most common breakdowns we see in cross-border structures are jurisdictional scope misalignment, third-party reliance failures and technology integration gaps.
Jurisdictional scope misalignment occurs when the firm applies its home-jurisdiction KYC standard to customers in a second jurisdiction where a higher standard applies. A VASP licensed in a jurisdiction that permits simplified due diligence for low-risk retail customers may be processing transactions for customers in a jurisdiction where simplified due diligence is not permitted for that customer category. The home-jurisdiction programme is technically compliant; the cross-border application is not. Operators we advise routinely underestimate the extent to which host-state AML rules apply to their customers, even when the VASP itself is not licensed in the host state.
Third-party reliance failures arise when a VASP relies on another regulated entity – a payment processor, a fiat on-ramp provider or a banking partner – to perform some or all of the KYC. Reliance on a third party is permitted under most AML regimes, subject to strict conditions: the third party must itself be subject to equivalent AML obligations, the VASP must be able to obtain the customer data on demand, and the VASP remains legally responsible for the adequacy of the CDD. In practice, we see reliance arrangements that lack written agreements, that rely on entities in jurisdictions not recognized as equivalent, or that assume the banking partner's KYC is sufficient for VASP purposes when the regulatory standards differ.
Technology integration gaps are the most operationally disruptive. A firm may have purchased best-in-class identity verification software, a sanctions screening database and a Travel Rule messaging solution, but if those systems are not integrated into a single onboarding workflow – if a compliance officer must manually check three separate dashboards to clear a customer – the program will fail under volume pressure. Regulators examining a KYC program look at the workflow, not just the component tools. A stacked set of unintegrated systems does not constitute a program.
Micro-Matter: When an Onboarding Framework Fails at Scale
In a recent matter, an exchange operating across three EU jurisdictions approached us after its primary banking partner issued a de-risking notice. The bank's AML team had reviewed the exchange's onboarding files and found that beneficial ownership records for corporate accounts were consistently incomplete: the exchange had captured the registered shareholder but had not traced to the ultimate natural person in cases where an intermediate holding company was interposed. The exchange's KYC policy permitted reliance on the corporate customer's own certification for the UBO layer, without independent verification. Under the applicable MiCA-transitional AML standard, that approach fell short.
We conducted a gap analysis of the onboarding policy against the MiCA CASP standard and the specific requirements of each of the three host NCAs. We identified that two of the three jurisdictions required independent verification of UBO identity, not merely self-certification, above a stated ownership threshold. We then assisted in redesigning the remediation workflow: re-screening existing corporate accounts, updating the onboarding policy, retraining the KYC team and producing a remediation report for submission to the banking partner. Within a business quarter, the bank lifted the de-risking notice. No enforcement action was taken. The matter illustrates a point we return to repeatedly in our practice: a KYC policy that is adequate at a point in time becomes inadequate when the regulatory standard it was designed for is superseded – and MiCA's implementation is, for many operators, exactly that supersession event.
How Do Regulators Actually Audit a Crypto Firm's AML Program?
Regulatory audits of crypto AML programs follow a consistent pattern across the leading hubs, even though the specific frameworks differ. Understanding the examination methodology helps a firm prioritize its compliance investment.
The first phase is document review. The examiner requests the firm's AML policy, its KYC procedures, its risk assessment, its MLRO appointment documentation and a sample of onboarding files. The sample is typically risk-stratified: the examiner will want to see high-risk files, politically exposed person files and enhanced due diligence files, not just standard-tier accounts. A firm that has strong documentation for standard accounts but thin files for high-risk customers will be flagged immediately.
VARA, MAS and the FCA have all published examination findings in the VASP sector that identify inadequate enhanced due diligence on high-risk customers as a recurring deficiency. The second phase is transaction monitoring review: the examiner looks at the alert configuration, the alert disposition process, the quality of analyst notes and the SAR filing rate. A firm that generated a large number of alerts and filed very few SARs – or that filed a disproportionately high number – will face questions about calibration and analyst judgment.
The third phase, increasingly common, is a technology walkthrough. The examiner asks to see the live onboarding flow, the monitoring dashboard and the Travel Rule messaging system in operation. A gap between the written policy and the operational system is treated as evidence of a systemic failure, not a documentation oversight. In our practice, we have seen firms invest heavily in written policies that accurately describe a planned system but that were never fully implemented in the technology – a presentation risk that only becomes apparent when the examiner asks for a live demonstration.
Preparation for examination, in our experience, requires a pre-examination dry run: a structured internal audit that mirrors the examiner's methodology, identifies gaps before the regulator does, and produces a documented remediation plan. A firm that walks into an examination with a pre-prepared gap analysis and a remediation timeline demonstrates the kind of compliance culture that regulators in the leading hubs reward with lighter-touch ongoing supervision.
CTA #2: If a prior application stalled, a banking partner de-risked you or an examination identified deficiencies, a second read of your KYC architecture can identify the structural cause and the route back. Write to OBOLUS at info@oboluslaw.com to discuss a gap analysis. Map your options.
Objection Handler: "An Offshore Licence Is Enough to Serve Clients Globally"
A common assumption among early-stage operators is that a single offshore registration – in the BVI under the VASP Act 2022, in the Cayman Islands under CIMA's virtual-asset regime, or in a similarly permissive jurisdiction – provides a sufficient legal basis to serve customers anywhere in the world. It does not, and the consequences of proceeding on that assumption are serious.
The BVI FSC and CIMA provide genuine regulatory infrastructure for certain business models: funds domiciled in those jurisdictions, holding structures and, in some cases, the operating entity for a business whose customers are exclusively professional or institutional. But neither regime provides an exemption from the rules of the jurisdiction where the customer is located. A BVI-registered VASP offering exchange services to EU residents is subject to MiCA's CASP requirements as a matter of EU law, regardless of where the VASP is incorporated. A Cayman-registered entity accepting customers in Singapore must assess whether it triggers the licensing threshold under the Payment Services Act administered by MAS.
The offshore-first approach also creates a banking problem that compounds the compliance burden. Banks in the major financial centers increasingly require a local regulated entity or, at minimum, a regulated entity in a recognized equivalent jurisdiction, before they will provide correspondent banking or fiat-settlement services to a VASP. A BVI-registered exchange with no other regulated entity may find it cannot open a business bank account in any of the jurisdictions where it needs to settle fiat. We map the licence, banking and tax stack across operating, custody and payment layers before clients commit to a structure precisely to avoid this outcome.
The correct approach for most scaling operators is a layered structure: one or more operating licences in the jurisdictions that cover the majority of the customer base (an EU CASP for Europe, a MAS DPT licence for Southeast Asia, a VARA or ADGM licence for the Gulf), with a holding or treasury layer in an appropriate offshore jurisdiction where that is genuinely justified by the business model. Each layer requires its own KYC and AML program calibrated to its regulatory environment.
Related at OBOLUS
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – Full practice overview covering KYC program design, MLRO governance and Travel Rule implementation across jurisdictions.
- VASP business risk assessment: the disputes angle – How AML program deficiencies translate into enforcement exposure and litigation risk for operators.
- Token legal classification for institutional clients – Classification analysis that determines whether a token triggers securities, e-money or ART/EMT treatment and the compliance obligations that follow.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires a VASP that originates a virtual-asset transfer to pass identifying information about the originator and the beneficiary to the receiving VASP alongside the transfer. The receiving VASP must collect and verify that data. The precise data fields required and the monetary threshold that triggers the obligation vary by jurisdiction. Non-compliance exposes a VASP to regulatory sanction and to de-risking by banking and stablecoin-issuer counterparts.
Who must act as MLRO for a crypto firm?
Most major regulatory regimes – including the FCA's Money Laundering Regulations framework, VARA's AML rulebook and the MiCA-aligned standards applied by EU national competent authorities – require a VASP to designate a named Money Laundering Reporting Officer (MLRO). The appointee must be senior enough to have direct board access, independent of business development, and empowered to halt onboarding or transactions without business-line approval. Many regulators require the appointment to be formally notified and the individual to be an approved person.
How do regulators audit crypto AML programs?
Regulatory examinations of crypto AML programs typically proceed in three phases: document review (policies, procedures, onboarding file samples including high-risk and PEP files), transaction monitoring review (alert configuration, disposition quality, SAR filing rates) and, increasingly, a live technology walkthrough to verify that the written program reflects the operational system. VARA, MAS and the FCA have each identified enhanced due diligence gaps and monitoring calibration failures as recurring examination findings in the VASP sector.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, KYC and Travel Rule compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to a structure, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is required. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specializing in KYC program architecture, DeFi regulatory perimeter analysis and cross-border AML compliance for digital-asset businesses.
CTA #3: To pressure-test your KYC and AML structure before your next examination or banking review, message us via t.me/oboluslaw or write to info@oboluslaw.com. Map your options.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.