Any virtual asset service provider (VASP) operating in or from the Bahamas must build a transaction monitoring program that satisfies the Digital Assets and Registered Exchanges Act (the DARE Act regime) and the broader anti-money-laundering obligations set by the Securities Commission of the Bahamas (SCB). The SCB supervises digital-asset businesses directly, and its expectations on suspicious-activity detection, Travel Rule compliance (the obligation to pass originator and beneficiary data with each transfer), and KYC (know-your-customer) controls are increasingly aligned with FATF Recommendation 15 standards. Getting the monitoring architecture right before the SCB asks for it is not optional – it is the difference between a licence that stands and one that stalls.
The Regulatory Basis for Transaction Monitoring in the Bahamas
Transaction monitoring in the Bahamas sits at the intersection of two complementary regimes: the DARE Act regime, which the Securities Commission of the Bahamas administers for digital-asset businesses, and the overarching anti-money-laundering and counter-terrorist financing (AML/CFT) obligations that flow from the Bahamas' Financial Transactions Reporting Act and related legislation. Together, they require registered and licensed digital-asset businesses to maintain systems capable of detecting unusual activity, generating suspicious transaction reports (STRs), and preserving records that regulators can audit.
The SCB has made clear that compliance with FATF Recommendation 15 is a baseline expectation. That recommendation treats VASPs on par with traditional financial institutions for AML/CFT purposes. A firm that has a DARE Act registration but lacks documented monitoring thresholds, automated screening tools, and a functioning escalation chain is exposed – regardless of how clean its underlying business is.
The cross-border dimension matters from day one. A Bahamas-registered exchange serving users in the EU, the UK, or Singapore cannot rely solely on local standards. The SCB examines the global reach of the business. Regulators in those users' home jurisdictions may separately apply MiCA, FCA, or MAS expectations to activity touching their markets. The monitoring program must be designed to satisfy the most demanding applicable standard, not the minimum local floor.
The SCB is the designated supervisory authority for digital-asset businesses under the DARE Act regime. Its guidance documents and examination procedures set the operational standard against which monitoring programs are measured.
What Does a Compliant Transaction Monitoring Program Actually Look Like?
A compliant monitoring program for a Bahamas-registered VASP combines four operational layers: real-time screening against sanctions lists, rules-based detection of suspicious transaction patterns, a case-management workflow for escalation and STR filing, and an audit trail that the SCB can inspect without advance preparation. Each layer must be documented and tested.
Real-time sanctions screening means checking every counterparty and every wallet address against lists maintained by the Office of Foreign Assets Control (OFAC) in the US, the UN Security Council, and the SCB's own designated-persons list. In practice, most firms use a combination of on-chain analytics tools and commercial screening databases. The SCB expects firms to show which lists they screen, how frequently those lists are refreshed, and what the false-positive handling procedure is.
Rules-based detection covers the transaction patterns the compliance team has decided to flag: structuring below a reporting threshold, rapid movement of large stablecoin balances across wallets, high-velocity trading inconsistent with the client's stated business, and peer-to-peer transfers to addresses associated with known illicit activity. The ruleset must be documented, regularly reviewed, and adjusted as the firm's product mix changes.
Case management is where most programs fail examination. A rule fires, a case opens – and then the record shows no analyst action, no documented outcome, and no STR filed or a documented decision not to file. The SCB looks at closure rates, escalation timelines, and whether the MLRO (Money Laundering Reporting Officer) is genuinely reviewing cases or rubber-stamping them.
The Travel Rule obligation, under FATF Recommendation 15, requires that originator and beneficiary information travel with every qualifying virtual-asset transfer – and the Bahamas, as a FATF-member jurisdiction, has implemented this at the VASP level. The practical consequence is that the monitoring program must include a Travel Rule data-collection and transmission capability, not just a post-hoc screening function.
How Does the SCB Supervise AML Compliance for Digital-Asset Businesses?
The SCB supervises registered digital-asset businesses through a combination of desk-based review and on-site (or remote) examination. The supervisory cycle begins at registration: the SCB reviews the applicant's AML/CFT policies and procedures as part of the DARE Act registration process, and a deficient compliance manual is grounds for refusal or conditions on the registration.
Once registered, firms are subject to ongoing reporting obligations. Suspicious transaction reports go to the Bahamas Financial Intelligence Unit (FIU), with a copy of the reporting log available to the SCB on request. Threshold-based currency transaction reports apply where Bahamian dollar or US dollar amounts cross the relevant statutory threshold. The SCB may also request ad hoc data – a transaction sample, a list of high-risk customers, evidence of Travel Rule messaging – on short notice.
Examination outcomes range from a management letter noting deficiencies to formal remediation requirements, licence conditions, and in serious cases, referral to enforcement. In our cross-border practice, we regularly see businesses that received a deficiency letter and treated it as low-stakes correspondence. The SCB does not forget an unanswered letter. A second examination that finds the same gaps tends to escalate directly to conditions or suspension.
For businesses operating across jurisdictions – a Bahamas-registered exchange with a Singapore payment subsidiary, for example – the SCB increasingly coordinates with peer regulators. MAS and the SCB share FATF membership. An adverse finding in one jurisdiction travels. The monitoring program must be defensible in every forum where the business has a regulatory footprint.
Firms should maintain a self-assessment log that maps each SCB AML requirement to the policy, the system control, the staff role responsible, and the last test date. That document is the first thing an examiner reads.
The KYC Framework and the Risk-Based Approach Under the DARE Act Regime
Transaction monitoring does not operate in isolation. It depends on the quality of the underlying KYC data. A monitoring rule that flags a transfer as high-risk is only useful if the analyst can pull up a complete customer file and make an informed judgment about whether the flag is genuine.
The DARE Act regime requires a risk-based approach (RBA) to customer due diligence (CDD). That means categorizing customers by risk level – applying simplified due diligence to low-risk relationships and enhanced due diligence (EDD) to high-risk ones. High-risk categories include politically exposed persons (PEPs), customers in FATF-listed jurisdictions, and businesses whose source of funds cannot be readily verified.
In practice, the KYC framework and the monitoring program must be integrated at the system level. The customer's risk rating should trigger monitoring rule adjustments automatically: a high-risk customer rated at onboarding should face lower transaction thresholds before an alert fires. Most firms we advise build this integration as a second-phase project, after they have the basic monitoring infrastructure in place. That sequencing is understandable but leaves a gap that the SCB will identify.
There is a common assumption among founders entering the Bahamas market that a single offshore registration is enough to serve a global customer base at a uniform compliance standard. That is not accurate. The KYC requirements for a UK-resident customer are shaped by FCA expectations; for an EU customer, by MiCA. A Bahamas-registered firm serving those customers must apply the highest applicable standard to each customer. The monitoring program must be built to accommodate that variability, not to apply a single flat ruleset regardless of where the customer sits.
Travel Rule Implementation: What Bahamas-Registered VASPs Must Do
Travel Rule compliance is operationally the most complex element of a Bahamas VASP's monitoring program, and it is the area where the SCB and FATF convergence is most visible. The Travel Rule requires that, for qualifying virtual-asset transfers, the originating VASP collects and transmits to the beneficiary VASP: the originator's name, account number (or wallet address), the originator's physical address or national identity number or date and place of birth, and the beneficiary's name and account number.
The threshold at which the Travel Rule applies and the exact data fields required are set by the implementing jurisdiction's rules; in the Bahamas, the SCB applies FATF guidance as the interpretive baseline. Firms should confirm the current de-minimis threshold with the SCB or with counsel, as it is subject to regulatory update and should not be treated as a fixed number taken from third-party summaries.
Two operational challenges dominate Travel Rule implementation for Bahamas VASPs. First, counterparty identification: the originating VASP must identify the beneficiary VASP before transmitting the data. For transfers to unhosted wallets (wallets not held at a VASP), different rules apply and the SCB expects documented procedures for handling those. Second, data security: Travel Rule data contains personal information and is subject to the Bahamas Data Protection Act requirements in addition to AML rules.
Several technical messaging protocols exist for Travel Rule compliance – TRISA, OpenVASP, and others. The SCB does not mandate a specific protocol, but it expects the firm to demonstrate that its chosen solution actually delivers compliant data to the counterparty VASP and that the firm can evidence successful transmissions on request.
In a recent engagement, a payments company registered in the Bahamas discovered that its Travel Rule messaging solution was transmitting to counterparties but not storing confirmation receipts. The data was leaving the firm, but there was no audit trail proving receipt. We worked with the firm to implement a confirmation-logging module and back-populate records for the prior operating period, allowing it to satisfy an SCB request for evidence without an adverse finding. Acting quickly – within weeks of identifying the gap – was decisive.
Cross-Border Banking and Correspondent Risk for Bahamas-Registered VASPs
For a Bahamas-registered digital-asset business, the AML/CFT compliance program is not only a regulatory requirement – it is a banking prerequisite. Correspondent banks that provide USD clearing to Bahamian institutions apply their own AML due-diligence standards to the businesses they serve. A firm that cannot produce a clean, documented monitoring program with low STR closure times and evidence of Travel Rule transmission will find its banking options narrow quickly.
This dynamic is particularly acute for crypto businesses. Correspondent banks in major clearing jurisdictions – New York, London, Singapore – have elevated scrutiny for VASPs relative to traditional financial institutions. The Bahamas' status as a FATF-member jurisdiction with an active SCB supervision regime works in the firm's favor, but it does not substitute for robust internal controls. In our practice, we regularly advise clients that the banking stack and the compliance program must be designed together, not sequentially.
Operating without the right AML architecture risks not just enforcement from the SCB but frozen correspondent rails and lost banking relationships. Those outcomes are harder to recover from than a regulatory deficiency letter. A bank that exits a relationship rarely returns, and the reputational signal travels to other potential banking partners.
For a scoped assessment of your transaction monitoring program and how it maps to SCB expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base, and banking relationships all change the analysis.
Decision Point: Which Businesses Need a Full Program Now?
Not every digital-asset business with a Bahamas connection faces the same monitoring obligation at the same time – but the threshold for triggering the full DARE Act regime is lower than most founders expect.
Profile A – The registered VASP: a business registered under the DARE Act regime as an exchange, custodian, or token-services business. This firm needs a complete monitoring program before the SCB grants or renews its registration. The program must cover: a documented risk-based approach, CDD and EDD procedures, Travel Rule capability, STR filing procedures, and an MLRO appointed at an appropriate seniority level. Timeline to build from scratch is typically several months; firms that engage counsel early in the registration process avoid last-minute remediation.
Profile B – The exempt or transitional business: a firm that started under an earlier exemption or transitional arrangement and has not yet migrated to the full DARE Act registration. These firms face a compliance cliff. The SCB does not grandfather pre-existing gaps. The monitoring program must be brought to current standard as part of the migration.
Profile C – The inbound foreign business: a firm licensed in another jurisdiction – say, under MiCA in the EU or under MAS in Singapore – that onboards Bahamas-resident customers or routes Bahamian dollar flows. This business may not need a Bahamas DARE Act registration, but its AML program must account for the Bahamas-specific risk factors in its geographic risk assessment. Failure to do so creates a gap that home-jurisdiction supervisors can and do identify.
If a prior application stalled or a compliance gap has already been identified, a second read of the program can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com to map the compliance architecture before the next SCB touchpoint.
Common Mistakes in Bahamas AML Programs for Digital-Asset Businesses
A common assumption is that a generic AML policy template, adapted from a template sold by a compliance consultant, satisfies the SCB's expectations. It does not. The SCB looks for evidence that the policy reflects the firm's actual business: the specific asset classes traded, the customer risk profile, the jurisdictions where counterparty VASPs are located, and the monitoring rules calibrated to those factors. A policy that describes a generic exchange without any reference to the firm's product suite is a red flag on examination.
The second common error is treating the MLRO appointment as an administrative formality. The MLRO must have genuine authority to file STRs without board approval, access to all compliance data, and sufficient seniority to influence business decisions on high-risk customer acceptance. In our experience, firms that appoint a junior operations employee as nominal MLRO consistently fail the SCB's governance assessment.
Third: ignoring the intersection of AML obligations and data-protection law. Travel Rule data, STR content, and CDD records are simultaneously subject to AML retention requirements and the Bahamas Data Protection Act. The compliance program must address both. Firms that build their monitoring architecture for AML compliance without a data-protection review often find themselves with a conflict between retention obligations and deletion rights – a conflict that regulators in multiple jurisdictions can exploit.
Finally, the monitoring ruleset is never set-and-forget. As the SCB's supervisory expectations evolve, as the firm's product mix changes, and as FATF guidance is updated, the rules must be reviewed and adjusted. An annual review documented in the board minutes is the minimum. Firms operating in rapidly evolving product areas – DeFi interfaces, stablecoin issuance, tokenized assets – should review quarterly.
Related at OBOLUS
- AML, Travel Rule and compliance for digital-asset businesses – our full-scope compliance practice covering KYC, monitoring and CFT across 70+ jurisdictions.
- VASP business risk assessment in France under AMF/PSAN – how the French supervisory regime assesses AML programs for registered crypto businesses.
- Enforcement of foreign judgments from a cross-border perspective – when compliance failures lead to enforcement action and asset recovery becomes necessary.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – rooted in FATF Recommendation 15 – requires that a VASP transmit specified originator and beneficiary information to the receiving VASP alongside each qualifying virtual-asset transfer. Required data typically includes the originator's name, account or wallet identifier, and identifying details, plus the beneficiary's name and account. The precise threshold and data fields depend on the implementing jurisdiction's rules. Bahamas-registered VASPs should confirm current requirements with the SCB or qualified counsel, as regulatory updates occur without published advance notice.
Who must act as MLRO for a crypto firm?
The Money Laundering Reporting Officer (MLRO) must be a sufficiently senior individual with genuine authority to file suspicious transaction reports independently, access all compliance records, and challenge business decisions on high-risk customer relationships. Under the DARE Act regime and the SCB's AML expectations, the MLRO cannot be a nominal appointee. The role requires documented delegation of authority, a clear reporting line to the board, and demonstrated subject-matter competence in AML and digital-asset compliance. Regulators assess the MLRO's actual function, not just the organizational chart.
How do regulators audit crypto AML programs?
The SCB examines AML programs through desk-based review of policies and reports, and through targeted examination of transaction samples, case-management logs, and Travel Rule transmission records. Examiners look for documented risk assessments, calibrated monitoring rules, evidence of MLRO action on alerts, and timely STR filings with the Bahamas FIU. A self-assessment log that maps each requirement to a control, a responsible person, and a test date significantly reduces examination friction and demonstrates the kind of governance the SCB expects from a licensed digital-asset business.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance architecture that surrounds them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and when disputes arise, our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specializing in AML program design, Travel Rule implementation and SCB supervisory engagement for digital-asset businesses across FATF-member jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.