EST · MMXXVI
Home/Insights/Tech/MLRO and compliance officer function: A Cross-jurisdiction Comparison
Compliance, AML & Travel Rule

MLRO and compliance officer function: A Cross-jurisdiction Comparison

Mlro and compliance officer function: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structuri

As regulators across every major financial hub tighten supervision of virtual asset service providers (VASPs) – entities that exchange, transfer, safeguard or administer digital assets – the compliance officer and Money Laundering Reporting Officer (MLRO) functions have become the axis on which licensing decisions turn. A firm that structures its compliance architecture incorrectly before it applies risks delayed authorisation, conditional approval, or outright refusal. The consequences extend further still: operating without properly designated, empowered compliance personnel exposes the business to enforcement action, frozen payment rails and the loss of banking relationships that are already difficult to secure in this sector.

The MLRO and the compliance officer are not the same role, though many jurisdictions permit one individual to hold both. The MLRO carries a specific statutory duty to receive, evaluate and submit suspicious activity reports; the compliance officer carries the broader mandate of ensuring the business operates within the applicable regulatory regime. Where those two functions sit in the organisational hierarchy – and how much independence they command – determines whether a regulator will treat a firm's AML program as genuine or cosmetic. Across the jurisdictions we cover in our practice, that determination is made through documentary review, direct interviews with the nominated individuals, and ongoing supervisory engagement. This analysis maps the key differences across six leading regimes, identifies the structural questions operators must resolve before they apply, and provides a decision matrix for founders choosing where to domicile their compliance function.

Why the MLRO Function Is Not Uniform Across Jurisdictions

The MLRO function varies materially by jurisdiction in scope, seniority requirements and reporting obligations, making a one-size approach unworkable for any operator serving cross-border markets. FATF Recommendation 15 establishes the baseline: VASPs must apply AML and CFT measures equivalent to those for financial institutions, including the appointment of a compliance officer at the management level. But the way each jurisdiction translates that baseline into its own regime produces significant divergence.

In the United Kingdom, the Financial Conduct Authority requires a nominated officer – functionally the MLRO – who sits within the business and is approved as a Senior Manager under the applicable conduct regime. The FCA's money laundering registration process for cryptoasset businesses requires that individual to demonstrate genuine operational authority. The FCA has publicly refused or revoked registrations where the compliance function appeared to exist on paper only.

Under MiCA (the EU's Markets in Crypto-Assets Regulation), CASP authorisation is assessed by the relevant national competent authority. The requirement is not merely that a compliance officer exists, but that the role is held by someone with demonstrable relevant experience in financial services compliance, that the function is adequately resourced, and that governance arrangements give the compliance officer direct access to the management body. Across the EU, we have seen national regulators in Malta, Lithuania and elsewhere apply increasingly granular scrutiny to these arrangements as MiCA transition deadlines approach.

The VARA regime in Dubai takes a different structural approach: its activity-based licence framework requires each licensed entity to maintain a dedicated compliance function as a standing condition of authorisation. VARA's rulebooks impose specific obligations on the compliance officer by name across each activity category – from exchange services to custody – meaning the role specifications are effectively embedded in the licensing instrument itself.

For a cross-border operator, this divergence creates a genuine structural problem. A compliance officer appointed to satisfy the FCA may not meet VARA's requirements, and neither appointment may satisfy the MAS in Singapore without additional local expertise. The practical answer is rarely to appoint separate individuals in each jurisdiction. It is to design a compliance architecture – governance documents, reporting lines, resource allocation – that can be adapted to each regime's requirements from a single defensible core.

What Regulators Actually Examine When They Assess Your Compliance Function

When a regulator assesses a firm's compliance function, it looks beyond the compliance manual to the person and the power structure behind it. Four consistent themes emerge across the regimes we monitor: seniority, independence, resource adequacy and documented authority.

Seniority is the most frequently misunderstood. In our cross-border practice, we regularly encounter applications where the compliance officer holds the title but reports to the CFO or the Head of Operations. In most flagship jurisdictions, that structure is problematic. The FCA expects the nominated officer to have direct access to the board. VARA's governance requirements contemplate a compliance function that can escalate directly to senior management without obstruction. AFSA within the AIFC in Kazakhstan similarly requires the compliance officer to be a senior officer with board-level accountability.

Independence is related but distinct. The compliance officer must be able to decline or halt activities that create regulatory risk, without commercial pressure overriding that judgment. Regulators test this by examining escalation policies, board minutes, and whether compliance objections have ever been recorded and overridden. A business where the compliance function has never escalated anything is, in the regulator's experience, a business where escalation is not genuinely possible.

Resource adequacy covers headcount, systems access and budget. Transaction monitoring systems – the technical backbone of AML programs – require calibration, tuning and review. A single compliance officer managing thousands of transactions without automated screening tools will not satisfy the FSRA in Abu Dhabi, nor FINMA in Switzerland, nor the SFC in Hong Kong. Regulators in these jurisdictions expect documented evidence that the compliance function has the tools it needs. A reference to a named third-party system in the application is not enough; the regulator will ask how alerts are reviewed, by whom and how frequently.

Documented authority is the fourth element. The compliance officer must have a written mandate – typically a board resolution or terms of reference – that defines the scope of the role, the officer's right to access all business lines and data, and the escalation pathway. Without that document, a regulator cannot verify that the authority claimed in the application actually exists in the governance structure of the business.

How Does the Travel Rule Obligation Sit Within the Compliance Officer's Mandate?

The Travel Rule – the obligation under FATF guidance to pass originator and beneficiary data with a virtual asset transfer – is technically an AML/CFT obligation, but its operational weight falls on the compliance function more heavily than on any other part of the business. Compliance officers at crypto firms must own the Travel Rule implementation end to end: from counterparty VASP identification to data transmission protocol selection to the handling of transfers from unhosted wallets.

The Travel Rule applies in materially different ways across jurisdictions. FATF's guidance sets a threshold framework, but jurisdictions have implemented their own de-minimis levels. Some have set a lower threshold than the FATF baseline; others align precisely. A few have introduced sunrise provisions that phase in requirements based on whether a counterpart jurisdiction has implemented its own Travel Rule regime. The compliance officer of any firm operating cross-border cannot apply a single protocol. They must maintain a current map of which jurisdictions the firm's counterpart VASPs are licensed in, what each jurisdiction requires, and whether the firm's technical solution covers each case.

In our practice, operators we advise routinely underestimate the operational burden of Travel Rule compliance. The data-collection requirement is clear enough in the standard case: a transfer between two identified VASPs triggers the obligation to share originator name, account number and address alongside beneficiary name and account number. The complexity arises in edge cases: transfers from unhosted wallets (where the originator is not a VASP), transfers below the threshold where the jurisdiction applies a de-minimis, and transactions involving multiple legs through different jurisdictions.

The compliance officer must also manage VASP counterparty due diligence – verifying that the recipient VASP is genuinely licensed, that it has AML controls in place, and that the data transmitted meets the format requirements of the applicable protocol (TRISA, OpenVASP or a proprietary solution). Failure at any of these steps creates both a regulatory exposure and a transactional risk. Regulators in the leading hubs increasingly expect the compliance officer to produce evidence of counterparty due diligence as a matter of routine examination, not as a one-off request.

For a mid-page CTA anchor:

The compliance architecture you build before your first licence application sets the template for every market you enter after it. The process above describes the standard path. Your facts – the entity structure, the user base, the payment rails – change the analysis materially. Map your options with the OBOLUS compliance team at info@oboluslaw.com.

The KYC Architecture Differences by Regime

The KYC framework (know-your-customer framework) that sits beneath the MLRO function differs substantially in its technical and documentary requirements across jurisdictions, and those differences directly affect how the compliance officer's role is structured. Under MiCA and the EU's AML framework, customer due diligence requirements align with the EU's harmonised regime; enhanced due diligence applies to higher-risk categories, and the compliance officer is responsible for managing a risk-based system that can justify each categorisation in examination.

Singapore's MAS takes a risk-based approach under the Payment Services Act, but with detailed guidance on what "adequate" CDD looks like for digital payment token services. The MAS has made clear that a compliance officer who cannot articulate the firm's risk appetite, explain the calibration of its transaction monitoring rules, and demonstrate how adverse media screening is conducted will not satisfy a supervisory examination. In our cross-border practice, we have seen MAS examinations focus with particular intensity on the source-of-funds documentation for higher-value customers – a point that catches many operators by surprise.

Hong Kong's SFC regime for VASP licensing similarly requires a robust KYC architecture, with specific expectations around the documentation of beneficial ownership for corporate customers and the handling of politically exposed persons. The compliance officer in a Hong Kong-licensed entity must be able to produce, on request, the documented rationale for every enhanced due diligence decision taken in the prior examination period.

One structural tension emerges consistently across all these regimes: the tension between automated screening efficiency and the judgment-based review that regulators expect. No automated system correctly categorises every transaction. The compliance officer's mandate must include clear procedures for human review of alerts, documented override decisions and escalation pathways. A system that produces thousands of untriaged alerts is not a compliance function; it is a liability.

How Do the MLRO Function Requirements Compare in VARA Dubai Versus the EU CASP Regime?

VARA in Dubai and the EU's MiCA CASP regime share the same FATF baseline, but they differ in material ways that directly affect how a firm should design its compliance function depending on which market it prioritises. The VARA regime is activity-specific: each licensed activity category – exchange services, custody, transfer and settlement, lending – carries its own rulebook obligations for the compliance function. A firm licensed for multiple activities must ensure its compliance officer understands and can demonstrate compliance across all relevant rulebooks simultaneously.

Under MiCA, the compliance function is assessed primarily at the point of CASP authorisation, with ongoing supervisory engagement thereafter. The key distinction is passporting: a CASP authorised in one EU member state may passport its services across the EU and EEA, meaning the compliance function designed for the home-state licence effectively covers the entire single market. VARA provides no equivalent mechanism; a VARA licence covers mainland Dubai operations, and separate arrangements are required for other jurisdictions.

For an operator weighing these two regimes, the decision matrix runs as follows. A firm targeting the EU market should anchor its compliance function to MiCA CASP requirements in its chosen home member state, and design its KYC framework and Travel Rule solution to satisfy that regime. It can then passport from a single licence. A firm targeting the GCC and broader Middle East market, with EU access as secondary, may find VARA's activity-based approach more suited to its product profile – but must accept that it will need a separate compliance architecture for EU operations if it scales there.

A dual-hub structure – VARA for the GCC, a MiCA CASP in Lithuania or Malta for the EU – is a structure we have helped operators design in our practice. It requires two separate compliance functions that share a methodology but adapt to each regime's specific requirements. The compliance officer in each jurisdiction must be individually approved, individually resourced and individually accountable to the local regulator. A single person cannot hold both roles at once unless the regulators on both sides explicitly permit it, which most do not for active exchanges.

Transaction Monitoring: The Technical Core of Any AML Program

Transaction monitoring is the technical infrastructure that makes AML policy operational, and the compliance officer's credibility with regulators depends substantially on whether that infrastructure is fit for purpose. Across the regimes we cover, the standard expected of VASPs has risen steadily: on-chain analytics, blockchain forensics integration and real-time screening are now baseline expectations rather than advanced capabilities.

The FCA has been explicit in guidance that cryptoasset businesses must apply the same quality of transaction monitoring as other regulated financial services firms – and that the novel characteristics of blockchain transactions (pseudonymity, cross-chain bridges, mixer services) create additional monitoring obligations rather than lesser ones. The compliance officer must be able to articulate how the firm monitors for each of these risk indicators, what thresholds trigger enhanced review, and how the system is tuned and updated as new typologies emerge.

FINMA in Switzerland, AFSA in the AIFC and the FSRA in Abu Dhabi each take a similar position: the compliance officer must demonstrate active ownership of the monitoring function. This means documented tuning decisions, alert disposition records, and periodic reviews of whether the rule set still reflects the firm's actual risk exposure. A transaction monitoring system implemented at launch and never reviewed is not a compliance asset; regulators in these jurisdictions will treat it as evidence that the compliance function is not genuinely operational.

In a recent matter in our practice, a digital-asset exchange operating across three jurisdictions discovered during a regulatory examination that its transaction monitoring system had been generating alerts for a category of high-risk transactions that were then being automatically closed without human review due to a misconfigured rule. The compliance officer had not been informed of the misconfiguration. The regulator in one of the three jurisdictions treated this as a material control failure and required remediation before the firm's licence renewal proceeded. The remediation process took several months and required a full review of all affected transactions over the prior year. The operational and reputational cost significantly exceeded the cost of proper monitoring governance from the outset.

If your transaction monitoring governance has gaps – misconfigured rules, untriaged alerts, undocumented override decisions – the time to address them is before your next examination, not during it. If a prior application stalled or a supervisory finding was made, a structured review can surface the root cause and the route to remediation. Map your options or write to info@oboluslaw.com.

Decision Matrix: Which Compliance Structure Suits Which Operator Profile

The right compliance architecture for a VASP depends on the firm's activity profile, geographic footprint, ownership structure and the regulatory regime of its primary market – and there is no universal answer. Below is a structured view of four common operator profiles and the compliance architecture most suited to each.

Profile A: EU-focused exchange, single jurisdiction, straightforward product. This operator should build its compliance function around the MiCA CASP requirements in a chosen home member state. The compliance officer role and the MLRO role may be combined in one individual in most member states, provided the person has the relevant experience and the role is adequately resourced. The KYC framework and Travel Rule solution should be designed from day one to satisfy the home-state NCA. Timeline to authorisation varies by member state but is generally a matter of months under the MiCA regime. Key risk: underinvesting in the compliance officer's seniority and independence, which is the most common reason for delayed authorisation in the EU.

Profile B: Multi-product GCC operator seeking to expand into the EU. This operator should build its primary compliance function to VARA standards (if Dubai-based), recognising that it will need a separate, locally approved compliance officer for any EU CASP authorisation. The compliance methodology – risk appetite, KYC tiers, transaction monitoring calibration – can be shared across both structures, but the individuals must be distinct and the governance documents must reflect each jurisdiction's specific requirements. Key risk: assuming that a shared compliance function is permissible without confirming this with the relevant regulators.

Profile C: Offshore-registered fund or fund manager with digital-asset exposure. This operator often underestimates its VASP obligations. If the fund's strategy involves active trading or custody of digital assets on behalf of investors, it may trigger licensing requirements in the jurisdiction where the management entity operates, regardless of where the fund itself is domiciled. The compliance officer function must map the management entity's activities to the applicable regime – MAS in Singapore, FSRA in Abu Dhabi, or FINMA in Switzerland – and ensure the AML program covers both the fund management activity and any in-scope VASP activity. Key risk: treating compliance as a fund-administration function rather than a regulated-activity function, with materially different resourcing implications.

Profile D: Global exchange seeking licensing in multiple hubs simultaneously. This is the most complex case. The compliance function must be designed as a programme rather than a role: a global compliance framework, locally adapted governance documents, locally appointed and approved compliance officers in each jurisdiction, and a central oversight function that coordinates reporting and ensures consistency of methodology. Key risk: the central function overriding local compliance officers' judgments in ways that create regulatory exposure in individual jurisdictions. Each local compliance officer must have genuine independence; a system designed to satisfy the regulator that it does not actually have is a systemic governance failure.

A Common Assumption About Offshore Licences and Global Compliance

A common assumption among operators entering the digital-asset space is that a single offshore licence – in the BVI, Cayman Islands or a lightly regulated jurisdiction – is sufficient to serve a global customer base. This assumption is incorrect, and it carries material consequences for the MLRO and compliance officer function specifically.

The BVI FSC and CIMA each maintain VASP registration and licensing regimes under their respective VASP Acts. Both regimes require AML compliance programs meeting FATF standards. Neither regime provides any mechanism to passport services into the EU, the UK, Singapore, Hong Kong or the UAE. A firm licensed in the BVI but actively marketing to EU residents is, under MiCA, conducting CASP services without authorisation in the EU. The compliance officer of that firm – however well-designed their BVI compliance program – has no defence to the EU enforcement exposure.

The compliance implications compound the regulatory ones. A compliance officer who knows their firm is actively serving customers in jurisdictions where it is not licensed faces a direct personal exposure. In most jurisdictions, the MLRO has a legal obligation to escalate suspicious activity. A business model that is itself operating outside its licensed perimeter creates a systemic compliance risk that the MLRO cannot resolve through transaction monitoring alone. Regulators in the leading hubs increasingly expect compliance officers to demonstrate that they have assessed the jurisdictional scope of the firm's activities and confirmed that the firm is appropriately licensed in each market it serves.

The practical answer is not to avoid offshore structures – they have genuine utility as holding entities, fund vehicles and technology-operating entities in carefully designed cross-border structures. The answer is to be precise about what the offshore entity does and what it does not do, to ensure that the compliance function of the offshore entity matches its actual activity scope, and to overlay the operating entities in the regulated markets with fully compliant, locally authorised compliance functions. We map the licence stack across operating, custody and payment layers before you commit – because the cost of rebuilding a compliance architecture after a regulatory finding vastly exceeds the cost of building it correctly at the outset.

How Regulators Audit Crypto AML Programmes in Practice

Regulatory examination of a crypto AML program follows a consistent methodology across the leading hubs, and understanding that methodology is essential for any compliance officer managing ongoing supervisory relationships. Examinations are typically triggered by a scheduled supervisory review, a suspicious activity report, a third-party complaint or an adverse event such as a transaction freeze or media report. The compliance officer is the regulator's primary point of contact in all of these scenarios.

The FCA's examination approach for registered cryptoasset businesses typically begins with a documentary request: the compliance manual, the risk assessment, transaction monitoring rules and recent alert disposition records, board minutes where compliance matters were discussed, and the training records for compliance staff. A gap in any of these documents is treated as a potential governance failure, not an administrative oversight. The FCA has demonstrated willingness to de-register businesses where examination reveals that compliance policies exist on paper but are not implemented in practice.

VARA in Dubai conducts supervisory examinations that include interviews with the named compliance officer. The regulator is assessing not just whether the documents exist but whether the individual understands them, owns them and has the authority to enforce them. A compliance officer who cannot answer detailed questions about their firm's transaction monitoring calibration, escalation decisions or counterparty due diligence process will not satisfy a VARA examination. This is a point that operators often miss when they appoint a compliance officer primarily for licence application purposes without investing in ongoing operational engagement.

FINMA's approach in Switzerland is characterised by its emphasis on the substance of the compliance function over its form. FINMA examines whether the compliance officer has genuinely independent authority, whether that authority has been exercised in practice, and whether the board takes compliance reporting seriously. In our cross-border practice, we regularly advise compliance officers to maintain contemporaneous records of every material compliance decision – not because regulators always ask for them, but because they sometimes do, and a contemporaneous record is vastly more credible than a reconstructed one.

Across all regimes, one observation holds: regulators are less concerned with the elegance of compliance documentation than with evidence that the compliance function is operationally embedded in the business. The MLRO who can demonstrate a pattern of genuine escalation, genuine board engagement and genuine authority to act will satisfy an examination in almost any jurisdiction. The MLRO who can produce a well-formatted manual but cannot explain a single escalation decision in the past twelve months will not.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP to collect and transmit originator and beneficiary information alongside a virtual asset transfer above the applicable threshold. The originator's name, account identifier and address must pass to the recipient VASP. Jurisdictions implement de-minimis thresholds differently, so the obligation's precise scope depends on the jurisdiction of each transacting party. VASPs must maintain counterparty VASP due diligence records to satisfy examination.

Who must act as MLRO for a crypto firm?

Most leading jurisdictions require the MLRO to be a senior individual with genuine authority within the business – typically at management level or above. The individual must be approved by or notified to the relevant regulator in most flagship regimes (FCA, VARA, MAS, SFC). The role may be combined with a broader compliance officer function in some jurisdictions, subject to adequate resourcing. In a cross-border group, each regulated entity generally requires its own designated MLRO approved by the local regulator.

How do regulators audit crypto AML programs?

Regulators typically begin with a documentary request – compliance manuals, risk assessments, transaction monitoring rules, alert records and board minutes. They then interview the compliance officer directly, testing practical knowledge of the firm's controls. They examine whether compliance escalations have actually occurred and been recorded. Across the FCA, VARA, MAS and FINMA, the consistent finding that leads to adverse action is not deficient documentation but the absence of evidence that the compliance function operates independently and effectively in practice.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule obligations that sit across all of them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – because a compliance function built in isolation from the licence and banking stack invariably has gaps that regulators find. To discuss your compliance architecture or MLRO appointment, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – specialising in the regulatory and technical compliance obligations of digital-asset businesses across multi-jurisdiction licensing and AML programme design.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours