Gibraltar's AML/CFT Regime: The Regulated Basis for Crypto Firms
Gibraltar was among the first common-law jurisdictions to introduce a dedicated licensing regime for distributed ledger technology businesses, and its Proceeds of Crime Act 2015 – together with the subordinate regulations that implement FATF standards – forms the statutory backbone for every AML/CFT obligation a DLT Provider (a firm authorised under Gibraltar's technology-driven financial services framework) must meet. The Gibraltar Financial Services Commission (GFSC) supervises compliance and expects policies that are tailored to the firm's specific activity profile, not adapted from generic templates. Operators we advise are routinely surprised by the granularity the GFSC expects at authorisation stage: a policy document that reads as boilerplate will draw a formal deficiency notice and extend the licensing timeline accordingly.
The AML/CFT obligation in Gibraltar sits on three pillars. First, a risk-based approach to customer due diligence (CDD), calibrated to the firm's product mix and customer geography. Second, a transaction monitoring programme aligned to the firm's risk appetite statement. Third, a governance structure that places a qualified Money Laundering Reporting Officer (MLRO) at its centre, with direct access to senior management and the board. The GFSC has made clear in its supervisory guidance that the MLRO role is substantive, not ceremonial – the officer must have genuine authority to pause onboarding and to file a Suspicious Activity Report (SAR) without prior management sign-off.
For inbound operators – a Singapore-headquartered exchange opening a Gibraltar DLT entity, for example – the cross-border dimension immediately complicates policy drafting. The firm's home jurisdiction may already impose its own AML/CFT standards. Where those standards diverge from Gibraltar's, the firm must either adopt the more demanding of the two or prepare a gap analysis that the GFSC can review. In our practice, we have seen operators underestimate this reconciliation exercise, particularly where the parent entity operates under a framework that relies on simplified due diligence thresholds that Gibraltar does not recognise.
The FATF Travel Rule – the obligation to collect and transmit originator and beneficiary data with every qualifying virtual asset transfer – applies to Gibraltar DLT Providers under the applicable anti-money laundering provisions. The precise threshold above which Travel Rule obligations are triggered varies; operators should confirm the current de minimis with the GFSC or qualified counsel rather than assume equivalence with other jurisdictions. The practical consequence is that a firm's policy documentation must specify the technical solution it will use to exchange Travel Rule data and must address what happens when a counterparty VASP cannot receive structured data – a scenario that arises frequently in cross-border transfers to exchanges in jurisdictions where no Travel Rule solution has been deployed.
For a scoped assessment of your Gibraltar DLT policy obligations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis materially. Map your options.
What Must an AML/CFT Policy Cover for a Gibraltar DLT Provider?
An AML/CFT policy for a Gibraltar DLT Provider must address, at minimum: a firm-wide risk assessment, customer risk classification, CDD and enhanced due diligence (EDD) procedures, ongoing monitoring, record-keeping obligations, internal reporting lines, the MLRO function, staff training, and the Travel Rule data-transmission framework. The GFSC does not publish a prescriptive template, which means the policy must be derived from the firm's own risk assessment rather than imported wholesale from another jurisdiction's model.
The firm-wide risk assessment is the foundation. It identifies the specific money-laundering and terrorist-financing risks that the firm's products, delivery channels, customer types and geographic footprint create. A custody-only provider and a retail exchange face different risk profiles. The policy language must reflect that difference. A custody provider, for instance, carries elevated risks around beneficial ownership verification and large-block withdrawals; a retail exchange faces higher exposure to structuring and sanctions-list evasion at the onboarding stage.
Customer risk classification drives the CDD programme. At a minimum, the policy must define low-, medium- and high-risk customer categories and set out the evidence required at each tier. For high-risk customers – politically exposed persons (PEPs), customers from higher-risk jurisdictions, legal entities with complex ownership structures – EDD procedures must be specified in detail. The GFSC has signalled, through published supervisory findings, that generic EDD provisions ("additional information will be obtained as appropriate") are insufficient. The policy must describe the specific additional steps: source-of-funds documentation, senior management sign-off, periodic review intervals.
Ongoing monitoring requirements are equally specific. The policy must describe the transaction monitoring system, the rules or typologies it applies, the thresholds that trigger an alert, the escalation path from alert to investigation to SAR filing, and the timeframes at each stage. Regulators in the leading hubs increasingly expect the monitoring programme to be calibrated against the firm's actual transaction data, not set at generic industry thresholds. A firm processing only institutional-size transfers will have a very different monitoring calibration than one serving retail customers with frequent small transactions.
Record-keeping obligations under Gibraltar law require that CDD records and transaction records be retained for a defined period following the end of the business relationship. Operators should confirm the current statutory retention period with qualified counsel. The policy must specify where records are held, in what format, and how they can be retrieved for a GFSC inspection at short notice.
The MLRO Function: Governance and Substance
The MLRO must be a natural person, resident and available to the GFSC, with sufficient seniority and independence to perform the role without commercial pressure overriding compliance judgments. Gibraltar's regime does not prescribe a formal qualification for the MLRO position, but the GFSC expects evidence of relevant AML/CFT training and experience in the sector. In practice, a newly licensed DLT Provider that appoints an MLRO with no prior virtual-asset exposure is likely to receive scrutiny during supervisory review.
For cross-border groups, the MLRO question carries additional weight. A parent entity in another jurisdiction may already have a group MLRO or compliance officer. Gibraltar requires a local MLRO who has actual authority over the Gibraltar entity's compliance programme. A group officer who provides oversight from a remote location without genuine decision-making authority over the local book does not satisfy the regime. In our practice, we have seen applications delayed because the proposed MLRO was a group compliance officer with a dozen other concurrent responsibilities and no documented allocation of time to the Gibraltar entity.
The MLRO must receive internal suspicious activity reports from staff, assess them, and decide whether to file a SAR with the Gibraltar Financial Intelligence Unit (GFIU). The policy must document the internal reporting pathway – how staff raise a concern, within what timeframe, and what happens if the MLRO is unavailable. A deputy MLRO or documented cover arrangement should be part of the governance framework, particularly for smaller teams where key-person risk is acute.
How Does an Inbound Operator Build a Compliant AML/CFT Programme?
An inbound operator – whether a new market entrant or an established business relocating part of its structure to Gibraltar – should approach AML/CFT policy drafting as a sequential, evidence-based exercise rather than a documentation exercise. The sequence matters: risk assessment first, policy second, procedures third, training last. Reversing that order produces policies that are internally inconsistent and fail GFSC review.
Step one is a Gibraltar-specific risk assessment. Even where a parent entity already holds a risk assessment for its home jurisdiction, Gibraltar's supervisory expectations and the specific activities to be conducted from the Gibraltar entity will require a dedicated assessment. The assessment should identify the top three to five risk scenarios specific to the firm's product and customer profile and map them to the controls that will mitigate each.
Step two is drafting the policy suite: the overarching AML/CFT policy, the CDD procedure, the EDD procedure, the transaction monitoring procedure, the SAR filing procedure, and the Travel Rule compliance procedure. Each document should be self-consistent and cross-referencing. The GFSC will read them as a suite, not as isolated documents.
Step three is the technical implementation layer. The policy must describe the systems the firm uses for identity verification, sanctions screening, PEP screening, and transaction monitoring. If the firm is using third-party providers for any of these functions, the policy must address how the firm retains oversight of outsourced functions and what contractual protections are in place. The GFSC does not permit full delegation of AML/CFT responsibility to a third-party provider; the firm remains accountable.
Step four is staff training. The policy must specify training content, frequency, and the method by which completion is recorded. New joiners must be trained before they handle customer files. Refresher training must be documented annually at minimum. A firm that cannot produce training records at a supervisory visit is exposed to enforcement findings regardless of the quality of its policy documentation.
Indicatively, a well-resourced inbound operator with a single-activity licence profile can complete the policy drafting and internal sign-off process within a matter of weeks. Firms with multiple activity types, complex group structures or cross-border policy reconciliation requirements should expect the process to take longer. These timelines assume that the firm-wide risk assessment is conducted in parallel with policy drafting, not sequentially.
Travel Rule and Cross-Border Interaction: Banking and Tax Considerations
The Travel Rule creates a direct cross-border interaction between a Gibraltar DLT Provider's AML/CFT programme and its banking and payments relationships. Banks that provide settlement accounts to crypto firms – already a constrained set in most jurisdictions – will review a firm's Travel Rule compliance posture as part of their own correspondent banking due diligence. A firm that cannot demonstrate a credible Travel Rule solution is at material risk of losing banking access, regardless of the strength of its underlying licence.
In Gibraltar, as in other FATF-member jurisdictions, the Travel Rule requires that qualifying transfers be accompanied by originator and beneficiary data: name, account number or equivalent identifier, and – for originators – an address or other identifying information. The firm's policy must specify how it collects this data at origination, how it transmits it to receiving VASPs, and how it handles incoming transfers where the required data is missing or incomplete. The "sunrise problem" – the risk that a receiving VASP in a jurisdiction that has not yet implemented the Travel Rule cannot accept structured data – must be addressed in the procedure, not left as a gap.
The cross-border tax dimension is a separate but related consideration. A Gibraltar-licensed DLT Provider that serves customers across multiple jurisdictions may create taxable presence in those jurisdictions depending on the nature of its activities, the location of its staff, and the substance of its local operations. Tax authorities in the major markets have become more attentive to the question of whether a crypto business with a small offshore licence and a large onshore customer base has correctly characterised its permanent establishment exposure. This is not an AML/CFT issue in itself, but it interacts with AML/CFT policy because the firm's customer geography – which the AML/CFT risk assessment must document – is also the basis on which tax authorities assess nexus.
Banking relationships for Gibraltar-licensed DLT Providers are typically structured with a primary settlement bank and one or more backup providers. The AML/CFT policy is a document that banks routinely request as part of their own due diligence. A policy that reads as internally consistent, operationally specific, and GFSC-aligned materially reduces the time and friction involved in opening and maintaining those relationships. Operating without the right documentation risks enforcement, frozen rails and lost banking – the three outcomes that most rapidly disable a digital-asset business regardless of its underlying licence status.
If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Write to info@oboluslaw.com or Map your options.
What Are the Most Common Mistakes in Gibraltar AML Policy Drafting?
The most common mistake in Gibraltar AML/CFT policy drafting is treating the policy as a submission document rather than an operational one. A policy drafted solely to satisfy the GFSC at authorisation will fail its first real test – a supervisory visit, a SAR filing, or a correspondent bank review. The GFSC, and the banks that read these documents, assess operational credibility. A policy that describes procedures in passive voice with no ownership assigned, no timeframes specified, and no escalation paths defined will not satisfy either audience.
A second common mistake is failing to align the Gibraltar policy with group-level policies where they exist. Groups that operate a Gibraltar entity alongside entities in Singapore, the EU or the UK will have AML/CFT policies at the group level. Where those group policies set lower standards than Gibraltar requires – for example, where the group policy permits simplified CDD for categories of customer that Gibraltar treats as standard or high risk – the Gibraltar entity must maintain a local policy that meets the higher standard. Simply appending a Gibraltar addendum to a group policy does not satisfy this requirement if the addendum conflicts with the main document.
A third mistake is the Travel Rule gap. Firms regularly submit AML/CFT policy suites that address CDD and transaction monitoring competently but that contain only a single paragraph on Travel Rule compliance, typically a statement that the firm will comply with applicable requirements. The GFSC expects a Travel Rule procedure that names the technical solution, addresses the sunrise-problem scenario, specifies what the firm does when a counterparty cannot receive data, and assigns responsibility to a named role within the firm.
A common assumption in the market is that a single offshore licence is sufficient to serve customers globally. It is not. Each jurisdiction in which a DLT Provider actively markets to, onboards, or serves customers may apply its own AML/CFT obligations independently of the licence the firm holds. A Gibraltar-licensed firm serving EU retail customers is within the scope of the MiCA regime's customer-facing obligations as well as Gibraltar's domestic requirements. The policy must reflect the full perimeter of the firm's regulatory exposure, not just the jurisdiction of its primary licence.
In a recent compliance matter, a payments company authorised in a common-law offshore jurisdiction had operated for several months before expanding its marketing into a second jurisdiction. When it sought a banking relationship in that second jurisdiction, the bank's compliance team identified that the firm's AML/CFT policy addressed only the home-jurisdiction requirements and contained no provisions for the Travel Rule obligations applicable in the target market. We revised the policy suite, conducted a gap analysis against both regimes, and drafted a Travel Rule procedure that satisfied both the banking partner and the secondary jurisdiction's supervisory expectations. The banking relationship was established within a matter of weeks of the revised documentation being submitted.
Which Operator Profile Applies to Your Structure?
AML/CFT policy complexity in Gibraltar scales with the firm's activity profile, customer geography, and group structure. Three broad profiles emerge from our practice.
A single-activity Gibraltar DLT Provider – a custody-only or exchange-only entity serving professional or institutional customers in a limited number of jurisdictions – faces the most tractable policy drafting exercise. The customer base is relatively homogeneous, the risk assessment is straightforward, and the Travel Rule obligations are manageable because the counterparty VASP universe is limited. For this profile, a well-scoped engagement with qualified counsel can produce a GFSC-ready policy suite within a realistic timeframe, and the principal risk is under-specification of EDD procedures for high-net-worth institutional customers. The key risk at the compliance stage is that the policy is drafted too narrowly and does not anticipate the firm's growth into new customer categories.
A multi-activity provider – a firm holding DLT authorisation for exchange and custody activities, or exchange and lending – faces a materially more complex exercise. The risk assessment must address the interaction between the activity types: a customer who uses both exchange and lending services presents a different risk profile from a customer using only one. The transaction monitoring programme must be calibrated to detect risk patterns that span both activity types. The key risk here is siloed policy drafting, where exchange and custody procedures are written independently without a unifying risk framework.
A Gibraltar entity within a multi-jurisdictional group – particularly a group that includes entities in jurisdictions with divergent AML/CFT standards – faces the highest policy drafting complexity. The Gibraltar policy must satisfy the GFSC, must be reconcilable with the group policy, and must address the cross-border data-sharing and Travel Rule obligations that arise from serving customers and interacting with counterparty VASPs across multiple regulatory perimeters. For this profile, the engagement should begin with a group-level gap analysis before any Gibraltar-specific drafting commences. The timeline for a GFSC-ready suite is longer, and the ongoing maintenance obligation – keeping the policy current as the group's activity profile and the regulatory environment evolve – is the primary long-term cost.
How Does the GFSC Audit a Crypto Firm's AML Programme?
The GFSC's supervisory approach to DLT Providers draws on the same risk-based methodology it applies to conventional financial services licensees, adapted for the specific features of virtual asset activity. Supervisory engagement typically proceeds through a combination of annual return filings, desk-based review, and on-site inspection. The GFSC has the power to request documentation, interview the MLRO and senior management, and conduct a full transaction-level review of the firm's monitoring records.
In practice, regulators in the leading hubs increasingly focus their AML supervision on three pressure points: the quality of the risk assessment (is it genuinely firm-specific or generic?), the effectiveness of the transaction monitoring programme (are alerts being investigated and resolved, or accumulating unreviewed?), and the MLRO's actual decision-making authority (can the GFSC speak to a qualified, engaged MLRO or to a nominal figurehead?).
Firms that have maintained contemporaneous records of their risk assessment reviews, their monitoring programme calibrations, and their SAR filing decisions are substantially better positioned in a supervisory review than firms that reconstruct those records in response to an inspection request. The GFSC looks for a culture of compliance, not a compliance archive assembled on demand.
Cross-border groups should also be aware that the GFSC may share supervisory findings with counterpart regulators under mutual assistance arrangements. A finding in Gibraltar can surface in a licensing or supervisory review in another jurisdiction. The AML/CFT policy and its governance therefore carry consequences beyond the Gibraltar entity itself.
Related at OBOLUS
- AML/CFT and Travel Rule compliance for digital-asset businesses – our practice overview covering the full compliance lifecycle across jurisdictions.
- KYC and onboarding framework design for established operators – scoped service for firms revisiting or rebuilding their customer due diligence architecture.
- Security token offering structuring in Japan under the FSA/JVCEA regime – jurisdiction-specific analysis for operators considering the Japanese market.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 15 – requires a virtual asset service provider to collect and transmit specified originator and beneficiary information alongside qualifying virtual asset transfers. At minimum, this covers the originator's name, account identifier, and an address or other identifying information, together with the beneficiary's name and account identifier. The precise data fields and de minimis threshold vary by jurisdiction; Gibraltar-licensed DLT Providers should confirm the current requirements with the GFSC or qualified counsel. The firm's AML/CFT policy must specify the technical solution used to transmit and receive this data.
Who must act as MLRO for a crypto firm?
A Gibraltar DLT Provider must appoint a natural person as its Money Laundering Reporting Officer (MLRO). That person must have genuine authority to make suspicious activity report (SAR) filing decisions independently of commercial management, must be available to the GFSC, and must demonstrate relevant AML/CFT experience and training. For cross-border groups, a group compliance officer based outside Gibraltar does not satisfy the local MLRO requirement unless that person has documented, substantive authority over the Gibraltar entity's compliance programme and an allocated time commitment to that role.
How do regulators audit crypto AML programs?
The GFSC audits DLT Provider AML programmes through a combination of annual returns, desk-based document review, and on-site inspection. Supervisors assess whether the firm-wide risk assessment is genuinely specific to the firm's activity and customer profile, whether the transaction monitoring programme is calibrated and actively managed, and whether the MLRO has real decision-making authority. Firms that maintain contemporaneous records of risk assessment reviews, monitoring calibrations, and SAR decisions are substantially better placed in a supervisory review than those that reconstruct documentation on request.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML/CFT regime analysis and policy architecture for digital-asset businesses across common-law and civil-law licensing jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.