For a virtual asset service provider (VASP) registered under the British Virgin Islands VASP Act 2022, the single most consequential compliance decision after incorporation is not the AML policy document – it is who sits in the chair. The Money Laundering Reporting Officer (MLRO) and the compliance officer function are the two roles on which the BVI Financial Services Commission (FSC) judges whether an operator's AML/CFT regime is real or cosmetic. Getting those roles wrong – structurally or in terms of individual fitness – is how BVI-registered VASPs attract supervisory scrutiny, lose correspondent banking and, in the harder cases, see their registration revoked.
Under the BVI VASP Act 2022 and the broader anti-money laundering framework administered by the FSC, a VASP must maintain an MLRO and a compliance officer as named, accountable persons. The two functions can sit with a single qualified individual in smaller operations, but they carry distinct legal obligations. This page sets out the regulated basis, the practical requirements, the cross-border complications that arise for digitally active BVI entities, and the decision points that determine whether your structure will withstand FSC scrutiny.
The regulatory basis: BVI VASP Act and the FSC
The BVI Financial Services Commission administers VASP registration and ongoing supervision under the BVI VASP Act 2022, which brought virtual asset service providers formally within the FSC's AML/CFT supervisory mandate. The Act works in conjunction with the BVI's Anti-Money Laundering and Terrorist Financing Code – the primary instrument that sets out the MLRO's statutory duties, the compliance officer's reporting obligations, and the minimum program that a VASP must maintain.
The FSC's approach draws on FATF Recommendation 15, which requires that virtual asset service providers be subject to AML/CFT regulation proportionate to the risks they present. BVI, as a FATF-aligned jurisdiction, has built its VASP framework around that baseline. The consequence for operators is that the MLRO and compliance officer functions are not administrative box-ticking. They are the primary accountability mechanism through which the FSC assesses whether the operator is meeting its obligations under the applicable regime.
In our practice, VASPs that enter BVI without understanding the difference between the two roles frequently structure them incorrectly from day one. The FSC has made clear through its supervisory communications that it expects each named officer to be genuinely active. A dormant title on a registration document satisfies neither the letter nor the spirit of the applicable provisions.
What is the difference between an MLRO and a compliance officer?
The MLRO and the compliance officer carry distinct mandates, and conflating them is one of the structural errors the FSC regularly identifies on examination.
The MLRO's core function is reactive and intelligence-facing. This officer receives internal suspicious activity reports from staff, assesses them, and decides whether to file a suspicious activity report (SAR) with the BVI Financial Investigation Agency (FIA). The MLRO must have direct access to the board and must be able to act independently of commercial pressure. Where a transaction generates a concern, it is the MLRO – not the CEO, not the chief revenue officer – who determines whether a disclosure goes to the FIA.
The compliance officer's function is proactive and systemic. This role owns the design, implementation and ongoing review of the AML/CFT program: the know your customer (KYC) framework, transaction monitoring rules, sanctions screening, staff training and the periodic risk assessment. Where the MLRO looks at individual transactions and reports, the compliance officer looks at the program as a whole and ensures it reflects the current risk environment.
In smaller VASPs, a single senior individual may hold both designations, provided that person has the genuine capacity, qualifications and independence to discharge both functions. Operators we advise routinely underestimate the time commitment. A dual MLRO/compliance officer at a growing exchange is a full-time position, not an ancillary title. The FSC's supervisory expectation reflects that reality.
Under the BVI AML framework, both the MLRO and the compliance officer must be natural persons – not legal entities or nominee services. They must be sufficiently senior to influence the business and must have a direct reporting line to the board.
What fitness and propriety criteria apply in BVI?
Fitness and propriety for the MLRO and compliance officer function in the BVI context turns on three practical axes: relevant experience, integrity and operational independence.
On experience, the FSC expects the designated officer to have demonstrable knowledge of AML/CFT obligations – either through a background in financial services compliance, legal practice in the field, or through formal AML certification from a recognised body. Pure crypto-native experience without AML grounding is not, in the FSC's view, an adequate substitute. Operators we advise who have attempted to appoint technically strong but compliance-light candidates have encountered FSC queries that delay registration.
On integrity, the standard background screening applies: criminal record checks, adverse regulatory history across all prior jurisdictions, and disclosure of related-party relationships that could compromise independence. The FSC conducts its own checks. It does not rely solely on applicant disclosures.
Operational independence is the axis most frequently underweighted by founders. The compliance officer and MLRO must be able to escalate concerns and, where necessary, override commercial decisions that generate AML risk. That independence is structural: it requires a reporting line that bypasses the revenue-generating part of the business and reaches the board directly. A compliance officer who reports to the chief commercial officer, rather than to the board or a dedicated risk committee, will draw FSC attention.
The FSC's fitness assessment covers the named individuals personally and is re-triggered whenever a new person is appointed to either role. Operators must notify the FSC promptly of any change in the persons holding these positions.
To map your MLRO structure before you submit to the FSC, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your specific entity structure, your user base geography and your banking arrangements all affect the analysis before a single document is filed.
KYC framework and transaction monitoring obligations
The compliance officer owns the KYC framework – the system for identifying and verifying customers, understanding the purpose of business relationships, and assessing the risk each customer presents.
Under the BVI AML/CFT framework, VASPs are required to conduct customer due diligence (CDD) at account opening, on an ongoing basis, and upon any material change in the risk profile of a customer. Enhanced due diligence (EDD) is required for higher-risk relationships: politically exposed persons (PEPs), customers in high-risk jurisdictions, and large or unusual transaction patterns. The compliance officer must ensure the business's CDD procedures are documented, applied consistently and reviewed at regular intervals.
Transaction monitoring is the operational heart of the program. A BVI-registered VASP must maintain a system – whether automated, manual or hybrid – that flags transactions falling outside the expected pattern for a given customer profile. The compliance officer sets the rules. The MLRO receives the output. The system must be calibrated to the operator's actual business model: a custody operation monitoring weekly rebalancing trades has different rule requirements than a retail exchange processing thousands of daily transactions.
Sanctions screening runs parallel to transaction monitoring. Every customer and counterparty must be screened against applicable sanctions lists – including those maintained by OFAC, the UN and the UK OFSI – before and during a business relationship. Given that many BVI-registered VASPs serve customers across multiple regions, the applicable sanctions perimeter is typically wider than the BVI domestic regime alone would require. This is a point operators frequently underestimate. A BVI-registered entity whose customers include US persons, or whose banking infrastructure runs through US correspondent banks, is exposed to OFAC jurisdiction regardless of its own place of registration.
How does the Travel Rule apply to BVI VASPs?
The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary information alongside a virtual asset transfer – applies to BVI-registered VASPs in proportion to their transfer activity and the thresholds the FSC has adopted under the applicable provisions.
In practice, a BVI VASP sending or receiving virtual assets on behalf of customers must collect, hold and transmit specific data about the originator and beneficiary of each transfer. That data must travel with the transfer to the receiving VASP. Where the receiving VASP is in a different jurisdiction, compliance depends on both parties' systems being capable of exchanging the required data fields. This is the sunrise problem – the asymmetry between jurisdictions that have implemented the Travel Rule and those that have not.
For operators we advise, the Travel Rule creates a practical pre-launch decision: which Travel Rule messaging protocol will the business adopt, and how will it handle transfers to VASPs that have not yet adopted any protocol? The compliance officer must have a documented policy for each scenario, including a procedure for suspending transfers where Travel Rule compliance cannot be achieved. That policy is reviewed by the FSC on examination.
The cross-border dimension is particularly acute for BVI entities. A BVI-registered exchange whose primary market is in Asia, whose banking is in Europe, and whose token reserves are custodied in a US entity faces Travel Rule obligations that flow from each of those relationships, not only from the BVI registration. The compliance officer's program must address all of them.
Cross-border interaction: tax, banking and the multi-layer reality
A BVI VASP does not operate in isolation. Its AML compliance program sits inside a wider structure that typically involves entities in multiple jurisdictions – an operating company, a custody vehicle, a payment gateway and sometimes a holding company in a different tax-efficient location. Each layer generates its own compliance obligations, and the MLRO and compliance officer in the BVI entity must understand how those layers interact.
Banking is the most immediate pressure point. Correspondent banks serving the BVI market conduct their own AML due diligence on prospective customers. A VASP that cannot demonstrate a credible, properly staffed AML program – with named, qualified MLRO and compliance officer – will not open a meaningful banking relationship. Regulators in the leading hubs increasingly expect operators to present a complete program, not a policy document signed by a dormant nominee. A common assumption is that offshore registration alone resolves the banking access question. It does not. Banking access depends on demonstrating genuine compliance infrastructure, and that demonstration starts with the quality of the individuals in these two roles.
Tax interaction is a secondary but real consideration. Where the beneficial owner of the BVI VASP is a natural person or entity in a jurisdiction with controlled foreign corporation rules or economic substance requirements, the question of where the MLRO and compliance officer are physically located can affect the substance analysis for tax purposes. Operators with multiple layers should ensure that the compliance function's physical location is consistent with the substance position of the relevant entity.
In a recent matter, a mid-market exchange had structured its BVI VASP with an offshore nominee holding both the MLRO and compliance officer titles while its actual compliance operations were managed from a jurisdiction that required its own local licensing. When a prospective banking partner conducted due diligence, the disconnect surfaced immediately. We worked with the operator to restructure the compliance function, appoint a substantive MLRO with genuine authority, and align the program documentation with what the business actually did. The banking relationship opened within weeks of the restructure completing.
How does the FSC audit a VASP's AML compliance program?
FSC examination of a BVI VASP's AML compliance program typically follows a structured cycle: document review, staff interviews and, in more intensive examinations, transaction file sampling. The MLRO and compliance officer are the FSC's primary contact points throughout.
At the document review stage, the FSC will assess whether the AML/CFT policy is current, whether it reflects the business's actual risk profile, and whether it has been approved at board level within a reasonable period. Out-of-date policies – those that pre-date the adoption of the VASP Act or that fail to address the Travel Rule – are a standard finding in FSC examinations. The compliance officer is accountable for keeping the program current.
Staff interviews test whether the policy is understood and applied. The FSC may speak directly with the MLRO to assess whether that person understands their statutory reporting obligations. It may also speak with front-line staff to assess whether the training program has been delivered. A sophisticated policy document that no one in the operation has read is not, in the FSC's view, a compliant program.
Transaction file sampling – reviewing specific customer files and transaction records against the CDD and monitoring rules in the policy – is the most granular form of examination. It tests whether the program that exists on paper operates in practice. Gaps between policy and practice are the most common source of formal regulatory findings. The compliance officer's internal audit function is the primary defence against those gaps appearing on examination.
If your AML program has not been reviewed since the VASP Act came into force, that gap is visible to the FSC on examination. To conduct a pre-examination review or restructure the compliance function before an FSC inquiry, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship closed following a compliance query, a second read of the program structure can surface the reason and the route back.
Decision matrix: which compliance structure fits your BVI operation?
Operators approach the MLRO and compliance officer question from different starting positions. The right structure depends on the operator's scale, its cross-border footprint and the sophistication of its transaction flows.
A newly registered BVI VASP with limited transaction volume – a custody vehicle or a fund-facing trading entity – can typically operate with a dual MLRO/compliance officer appointed from the founding team, provided that individual has demonstrable AML experience and genuine independence. The risk at this profile is that growth outpaces the structure: as volumes increase and counterparty diversity grows, the dual role becomes a bottleneck. Operators at this profile should build a transition plan into their compliance governance from the outset.
A mid-market BVI exchange with retail-facing activity – processing transactions across multiple jurisdictions, with a broad customer base – requires separated roles. The transaction volume and the diversity of customer risk profiles mean that a single dual officer cannot, in practice, discharge both functions to the standard the FSC expects. The compliance officer should be a full-time position. The MLRO may be a senior compliance officer by another title, but the reporting line to the board must be clear and documented.
A BVI VASP that is part of a multi-entity group – holding company in one jurisdiction, operations in another, custody in a third – faces the most complex compliance architecture. Group-level and entity-level compliance functions need clear delineation. The BVI FSC's expectations apply to the BVI entity specifically; a group compliance officer based elsewhere does not satisfy the entity-level obligation unless there is a clear sub-delegation, local accountability and genuine authority to act on behalf of the BVI entity.
In each profile, the common mistake is the same: treating the MLRO and compliance officer appointments as administrative steps in the registration process rather than as the foundation of the business's ongoing supervisory relationship with the FSC.
Related at OBOLUS
- AML, Travel Rule and compliance advisory for digital-asset businesses – how we structure and audit AML programs across jurisdictions
- AML and Travel Rule regime in Lithuania – comparative EU VASP AML requirements under MiCA transition
- VASP licence application in Ireland – how the Irish AML registration compares for inbound operators
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, drawn from FATF Recommendation 16, requires a VASP initiating a virtual asset transfer to collect and transmit specific identifying information about the originator and beneficiary to the receiving VASP. The data travels with the transfer. Receiving VASPs must verify and retain that information. The precise data fields and de-minimis threshold vary by jurisdiction. BVI-registered VASPs must have a documented policy covering transfers to counterpart VASPs that have not yet implemented a compatible Travel Rule messaging solution.
Who must act as MLRO for a crypto firm?
The MLRO must be a named natural person with sufficient seniority, AML expertise and independence to receive internal suspicious activity reports and decide whether to file a report with the relevant financial intelligence unit – in the BVI context, the Financial Investigation Agency. The role cannot be held by a nominee service or a dormant legal entity. The individual must have a direct reporting line to the board, unmediated by commercial management. The FSC assesses both the structural independence and the individual fitness of the appointed MLRO.
How do regulators audit crypto AML programs?
FSC examinations of BVI-registered VASPs typically combine document review, interviews with the MLRO and compliance officer, and transaction file sampling. Examiners assess whether the written policy reflects current risks and legislation, whether staff understand and apply it, and whether actual transaction files match the documented procedures. The most common findings involve outdated policies, gaps between policy and practice, and MLRO or compliance officer appointments that lack genuine independence or the required expertise. A pre-examination internal review can surface those gaps before the FSC does.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the AML, compliance and Travel Rule frameworks that sit around those activities. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, MLRO function requirements and VASP compliance frameworks across common-law jurisdictions including the British Virgin Islands.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.