Regulator AML Audit Defence in Bahamas: Legal Requirements for Businesses
A crypto exchange or custodian operating under the Bahamas regulatory regime faces a distinctive audit risk: the Securities Commission of the Bahamas (SCB) runs AML examinations that probe governance, transaction monitoring, Travel Rule (the obligation to pass originator and beneficiary data with a transfer) compliance, and the fitness of the nominated Money Laundering Reporting Officer (MLRO). When an audit notice lands, the clock starts immediately. Preparation that should have taken months must compress into days. In our practice, the businesses that manage this well are those that built their AML program around the SCB's published expectations from the outset – not those that assembled a file in response to the examination letter.
This page sets out the legal basis for AML supervision in the Bahamas, explains what the SCB examines, and identifies the cross-border issues that most commonly surface when a digital-asset business must defend its program before a regulator.
What Is the Legal Basis for AML Supervision in the Bahamas?
The Securities Commission of the Bahamas is the primary regulator for digital-asset businesses operating under the Digital Assets and Registered Exchanges Act (DARE Act), and it applies AML/CFT requirements derived from the FATF Recommendations – including Recommendation 15 on virtual assets – through the Bahamas Financial Transactions Reporting Act and supporting guidelines. Any business registered as a Digital Asset Business (DAB) under the DARE Act falls within the SCB's supervisory perimeter for AML purposes. That perimeter is not limited to exchange activity: custody, brokerage, advisory and token-issuance functions each carry their own compliance obligations.
The Bahamas has been an active FATF member jurisdiction and aligns its AML expectations with the FATF mutual evaluation cycle. The SCB has signalled, through published guidance and examination practice, that it treats Travel Rule implementation and KYC framework (know-your-customer policies and procedures) design as first-priority review areas. Businesses that treat these as checkbox exercises – rather than operational realities – routinely find discrepancies during examination that the regulator characterises as systemic failures, not isolated gaps.
The cross-border dimension matters immediately. A Bahamas-registered DAB typically serves clients in multiple jurisdictions. The SCB does not limit its AML inquiry to Bahamian customers. It expects the firm's transaction monitoring and Travel Rule posture to cover the full client population, wherever those clients are domiciled.
What Does the SCB Examine in an AML Audit?
An SCB AML examination typically covers six substantive areas, and the depth of review in each reflects how the regulator perceives the firm's risk profile. Firms with higher transaction volumes, complex customer profiles, or cross-border exposure can expect more intensive scrutiny across all six.
First, governance and the MLRO function. The SCB will assess whether the MLRO is genuinely senior, operationally empowered, and adequately resourced. An MLRO who cannot demonstrate independent access to transaction data or who lacks the authority to file suspicious activity reports without board approval is a finding waiting to be written. The regulator also reviews board-level AML risk appetite statements and the minutes of compliance committee meetings.
Second, the KYC framework and customer due diligence records. The SCB tests whether enhanced due diligence is applied to higher-risk customers – politically exposed persons, correspondent relationships, customers in high-risk jurisdictions – and whether the documentation actually held matches the policies as written. In digital-asset businesses, the SCB increasingly reviews wallet attribution records alongside identity files.
Third, transaction monitoring systems and their calibration. A monitoring system that generates alerts but cannot demonstrate a documented review and disposition process is treated as non-functional. The regulator will pull sample alert files and test the chain from alert generation through investigation to escalation or clearance. Calibration logs – showing how thresholds were set and when they were last reviewed – form part of the expected record.
Fourth, Travel Rule compliance. The SCB expects DABs to collect and transmit originator and beneficiary information for virtual-asset transfers, consistent with the FATF Travel Rule. For outbound transfers, the firm must be able to demonstrate that counterparty VASPs are identified, that the required data has been transmitted, and that transfers to non-compliant counterparties are handled through a documented sunrise-gap procedure. For inbound transfers, the firm must show what it does when originator data is missing or inadequate.
Fifth, suspicious activity reporting. The SCB will review the volume of internal suspicion reports, the ratio of internal reports to external filings with the Financial Intelligence Unit, and the quality of documented reasoning on both outcomes. A firm with very few internal reports and no external filings is not regarded as having a clean compliance record – it is regarded as having a dysfunctional reporting culture.
Sixth, record-keeping. AML records must be retained for the period specified under the applicable Bahamian legislation. Gaps in record retention – particularly for high-risk or legacy transactions – create enforcement exposure even where the underlying conduct was compliant.
How Does Cross-Border Business Create AML Audit Risk in the Bahamas?
For most Bahamas-licensed digital-asset businesses, the most acute AML examination risk does not come from domestic activity – it comes from the firm's cross-border footprint. A DAB registered under the DARE Act that also holds clients in the EU, the UK, or the US carries layered obligations. The SCB applies its own AML framework; the EU's MiCA regime and ESMA guidance apply where the firm services EU clients; the FCA's financial-crime rules apply where UK clients are involved; and FinCEN's rules reach any dollar-denominated transaction.
In our cross-border practice, we regularly advise firms that have applied the strictest of these frameworks domestically – and still find themselves with an SCB examination finding because the Bahamian compliance documentation does not capture how those additional obligations were met. The issue is not the substantive compliance; it is the audit trail. The SCB examines what is in the file, not what was done.
Banking interaction adds a second cross-border complication. Bahamian correspondent banking for digital-asset businesses is limited. Most DABs manage payments through one or two banking relationships that run through US dollar correspondent accounts. A SAR filing in the Bahamas that relates to a transaction also visible to the firm's US correspondent bank can trigger a parallel inquiry. Audit defence counsel therefore needs to understand both the Bahamian supervisory process and the downstream risk to the banking relationship.
For a scoped assessment of your AML audit exposure in the Bahamas, contact OBOLUS at info@oboluslaw.com. The process above describes the standard examination path. Your entity structure, client base, and banking relationships change the analysis materially.
Who Must Act as MLRO, and What Does Fitness Mean in Practice?
Under the Bahamian AML regime, every DAB must appoint a named individual as MLRO, and that individual must satisfy the SCB's fit-and-proper criteria. The regulator's examination of the MLRO function goes beyond verifying that a name appears in the licence application. It assesses whether the designated officer is genuinely carrying out the role.
Fitness, in practice, means three things. First, seniority: the MLRO must have sufficient authority within the organisation to escalate concerns to the board and to refuse or terminate business relationships without needing secondary approval. An MLRO who is also the head of sales, or who reports to a commercial rather than a governance line, will attract examiner scrutiny. Second, competence: the SCB will ask whether the MLRO has received appropriate AML training and whether that training is current. Third, resource: the MLRO must have adequate support – in terms of staff, technology, and budget – to perform the function. A solo MLRO at a high-volume exchange is a structural finding.
Cross-border businesses face an additional complexity. Where a Bahamas DAB is part of a group, and AML functions are centralised in another jurisdiction, the SCB expects local oversight to be real rather than nominal. A group AML policy prepared under MiCA standards for the EU does not automatically satisfy the SCB's Bahamian-law requirements. The local MLRO must be able to account for Bahamian-specific obligations in their own terms.
What Is the Audit Defence Process When the SCB Issues an Examination Notice?
Audit defence in the Bahamas begins with a legal analysis of the examination scope, not with a rush to produce documents. When the SCB issues an examination notice, the notice typically identifies the subject areas and requests an initial document submission by a specified date. That submission is the first material the regulator reads. Its quality sets the tone for the entire examination.
The practical steps are sequential. First, conduct an internal gap assessment against the SCB's examination checklist – identifying, before the regulator does, where the AML program falls short of documented expectations. Second, prepare a disclosure strategy: what is produced in the initial submission, what is reserved, and how gaps are addressed. A regulator that discovers a gap the firm did not disclose is more likely to treat it as a systemic failure than a regulator that receives a candid account of a known gap and a remediation plan. Third, prepare the MLRO and other witnesses for examiner interviews. SCB examiners conduct interviews as part of the on-site process, and the responses of compliance staff shape the examiner's characterisation of the program.
In a recent matter, a digital-asset business operating across two offshore jurisdictions faced simultaneous AML examinations – one from the Bahamian SCB and one from a second regulator in its secondary licence jurisdiction. We coordinated a unified disclosure strategy that addressed both sets of expectations without producing inconsistent accounts. The firm resolved both examinations without enforcement action. Timing mattered: we were engaged before the initial document submission in each jurisdiction, not after a finding had already been issued.
Fourth, manage ongoing correspondence. Regulators in the leading hubs increasingly follow up initial submissions with targeted information requests. Each response should be reviewed by counsel before dispatch. A technically accurate but poorly framed response can inadvertently expand the scope of the examination.
What Are the Most Common AML Program Deficiencies the SCB Identifies?
Across examination practice in offshore digital-asset hubs, the AML deficiencies that appear most frequently fall into a consistent pattern. Identifying them in advance – and addressing them before an examination – is the most cost-effective form of audit defence available to a business.
The most common is a gap between policy and practice. A firm may hold a well-drafted AML policy, but the actual conduct of customer due diligence, transaction monitoring, or Travel Rule data transmission does not match what the policy says. The SCB tests practice, not paper. The second most common is inadequate Travel Rule infrastructure. Many Bahamas-licensed VASPs have adopted a Travel Rule solution but have not completed counterparty integration or documented their sunrise-gap procedure for transfers to and from non-integrated entities. The regulator will probe the firm's actual completion rate and the steps taken when data is unavailable.
A third recurring issue is the treatment of self-hosted wallets. The SCB's approach to transfers involving unhosted wallets aligns with the FATF's risk-based guidance: the firm must have a documented procedure for assessing and managing the risk these transfers present, and that procedure must be applied consistently. Firms that permit transfers to and from self-hosted wallets without any documented risk assessment are exposed.
Fourth: the quality of suspicious activity reports. Internal SARs that are formulaic – repeating transaction data without analysis of why the activity is suspicious – do not satisfy the regulator's expectation of a functioning reporting culture. The SCB will assess the quality of reasoning in internal reports, not just their existence.
Which Business Profiles Face the Highest AML Audit Risk in the Bahamas?
Not all digital-asset businesses carry the same AML examination risk. The profile that most consistently attracts intensive SCB scrutiny is one where rapid growth has outpaced compliance infrastructure. A firm that grew its customer base significantly in the year preceding the examination – without commensurate investment in transaction monitoring, MLRO resource, or Travel Rule tooling – presents examiners with an easy finding: the program is not proportionate to the risk it is supposed to manage.
Profile A: an exchange with retail clients across multiple jurisdictions, high transaction volumes, and a single MLRO who has not been supported by a compliance team. Risk: systemic transaction monitoring deficiency; MLRO fitness finding. Indicative path: programme remediation required before the regulator will close the examination; interim voluntary undertakings may be sought.
Profile B: a custody business with institutional clients and concentrated exposure to a small number of high-value counterparties. Risk: enhanced due diligence gaps on large-volume clients; inadequate board-level risk appetite documentation. Indicative path: documentation-led remediation; limited examiner interface required if records are well organised.
Profile C: a group structure where Bahamas is the operating entity but compliance functions are centralised offshore in a different group company. Risk: nominal local MLRO; Bahamian-specific obligations not separately documented. Indicative path: structural adjustment required; local MLRO must be given genuine authority and access.
In all three profiles, the cross-border reality – clients in the EU subject to MiCA-level standards, dollar flows through US correspondents, Travel Rule obligations applying to transfers across multiple hub jurisdictions – creates audit exposure that a purely domestic compliance review will not surface.
If a prior examination stalled or produced findings you are working to address, a second read can identify the structural cause and the route to resolution. Write to OBOLUS or message us at t.me/oboluslaw.
A Common Assumption: One Offshore Licence Means One Set of AML Rules
A common assumption among founders and CFOs building cross-border digital-asset businesses is that a Bahamas DARE Act registration addresses AML compliance for the whole operation. It does not. The Bahamian regime governs conduct within the SCB's supervisory perimeter. A firm serving EU clients is also within MiCA's AML expectations, enforced by national competent authorities; a firm with UK users is within the FCA's financial-crime regime; a firm processing dollar payments is within the FinCEN framework. Each layer has its own record-keeping, reporting, and Travel Rule requirements.
In our practice, we have seen firms that were fully compliant under Bahamian law receive findings from a second regulator precisely because they treated the Bahamas licence as the ceiling rather than the floor. Audit defence for a cross-border business requires counsel who can map all applicable regimes simultaneously – not just the jurisdiction where the licence sits.
We map the licence, compliance, and banking stack across operating, custody, and payment layers before you commit to a structure. That is the work that makes audit defence straightforward when the examination notice arrives.
Related at OBOLUS
- AML and Travel Rule Compliance for Digital-Asset Businesses – the full practice overview covering AML program design and cross-border obligations
- KYC and Onboarding Framework from a Cross-Border Perspective – structuring customer due diligence for multi-jurisdiction operations
- GPLP Structuring for Digital Assets in Turkey – jurisdiction-specific structuring analysis for an emerging digital-asset market
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, drawn from FATF Recommendation 15, requires a VASP (virtual asset service provider) to collect, verify, and transmit originator and beneficiary information alongside virtual-asset transfers above the applicable threshold. Originator data includes name, account identifier, and geographic information. Beneficiary data includes name and account identifier. The transmitting VASP must ensure receiving VASPs can receive the data, and must have a documented procedure for transfers where the counterparty cannot yet accept structured data.
Who must act as MLRO for a crypto firm?
Every regulated digital-asset business must designate a named Money Laundering Reporting Officer (MLRO) who is sufficiently senior, operationally independent, and adequately resourced to perform the function. The MLRO receives internal suspicion reports, determines whether to escalate to the Financial Intelligence Unit, and is the regulator's primary contact on AML matters. Under the Bahamian regime and most equivalent frameworks, the MLRO must meet fit-and-proper criteria assessed by the regulator. A nominal appointment without genuine authority is a supervisory finding.
How do regulators audit crypto AML programs?
A regulator conducting an AML audit of a digital-asset business typically combines document review, systems testing, and examiner interviews. It will assess governance documentation, KYC records, transaction monitoring calibration logs, Travel Rule transmission records, internal SAR files, and MLRO-board reporting lines. Examiners compare written policy against documented practice and test sample transactions end-to-end. Firms with gaps between policy and operational records – regardless of actual conduct – typically receive the most adverse characterisations in examination reports.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit to a structure, and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where disputes arise. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design and regulator examination defence for digital-asset businesses across offshore and EU-aligned jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.