Operating a digital-asset business in Guernsey without a properly constituted Money Laundering Reporting Officer (MLRO) and compliance officer function is one of the fastest ways to attract enforcement attention from the Guernsey Financial Services Commission (GFSC). The GFSC supervises virtual asset service providers under its anti-money laundering and counter-terrorist financing regime, and it expects named, qualified individuals to hold these roles before a firm goes live – not as an afterthought once revenue arrives. For an operator expanding into the Channel Islands from a broader international structure, the question is not whether these roles are required; it is how to staff them, where accountability sits, and how the function connects to the rest of a cross-border compliance program.
This page answers those questions directly: who must hold the MLRO and compliance officer roles under the Guernsey regime, what those individuals must demonstrably do, how the function interacts with travel-rule obligations and transaction monitoring, and where the cross-border structure creates gaps that regulators routinely exploit.
Why Guernsey specifically requires designated compliance roles
The GFSC's supervision of virtual asset businesses rests on a statutory AML/CFT framework that mirrors the Financial Action Task Force (FATF) standards, including Recommendation 15 on virtual assets. Under the applicable provisions, every regulated entity must appoint an individual who carries personal accountability for the firm's anti-money laundering and counter-terrorist financing compliance. The MLRO is the pivot: that person receives internal suspicious activity reports, makes disclosure decisions to the Financial Intelligence Service (FIS), and is the primary contact for regulatory enquiries touching financial crime.
The compliance officer role is distinct, though in smaller firms the same person may hold both. The compliance officer owns the program: policies, controls, training calendars, testing cycles. The MLRO owns the disclosure function and the relationship with the FIS. Conflating the two without explicit governance documentation is a recurring finding in GFSC supervisory reviews. In our practice we have seen firms arrive at the GFSC with a single named officer wearing both hats but without a documented escalation matrix – a gap that stalls licence progression and, post-authorisation, creates supervisory risk.
Guernsey's regime also applies to businesses that are registered or licensed in the Bailiwick but whose customers, transactions or counterpart exchanges sit abroad. A Guernsey-domiciled entity processing transfers through exchanges in Singapore, the EU or the United States carries AML obligations under Guernsey law regardless of where the end client books. The MLRO must understand that cross-border dimension; a purely domestic compliance mindset does not meet the GFSC's expectations.
Contact OBOLUS to scope your compliance function before your GFSC application moves forward. The process above describes the standard path. Your facts – the entity structure, the user base, the correspondent banking – change the analysis. Map your options.
Who can serve as MLRO for a Guernsey digital-asset firm?
The MLRO must be a fit-and-proper individual approved by the GFSC – a natural person, resident or demonstrably accessible to Guernsey, with relevant AML/CFT experience and no disqualifying history. The Commission's fit-and-proper assessment covers honesty and integrity, competence and capability, and financial soundness. A curriculum vitae showing purely transactional crypto work, without documented AML decision-making experience, is unlikely to satisfy the assessors; the GFSC expects the candidate to have managed a suspicious activity report (SAR) cycle, overseen customer due diligence programs, or held a formally recognised AML role at a regulated entity.
For virtual asset businesses specifically, the GFSC will scrutinise whether the nominee understands the mechanics of on-chain transaction monitoring – blockchain analytics, clustering heuristics, cross-asset risk signals. A candidate who cannot speak to these tools at interview creates a credibility problem for the application. We regularly advise firms to document, before submission, the nominee's exposure to at least one recognised forensic or analytics platform, even where the firm plans to outsource day-to-day monitoring.
Outsourcing is a key issue in Guernsey. The MLRO role itself – specifically the SAR decision function – cannot be outsourced. The person named on the GFSC register carries that responsibility personally. Supporting functions (automated screening, adverse media, transaction alert triage) can be delegated to a third-party compliance technology provider or an external compliance support firm. But when an alert escalates to a potential disclosure, the named MLRO must make the call. That distinction is fundamental, and regulators test it.
What the compliance function must demonstrably do
A Guernsey VASP compliance program is not a binder of policies. The GFSC expects evidence that the program operates in practice: meeting minutes showing the compliance officer reported to the board, a training register current to the assessment date, documented control testing results, and a risk appetite statement that is actually used to calibrate customer onboarding decisions.
The specific components the GFSC expects include at minimum: a business-wide risk assessment updated at defined intervals; customer due diligence procedures calibrated to the risk classification of each customer segment; enhanced due diligence triggers for higher-risk counterparties; a transaction monitoring framework with documented alert-disposition logic; a sanctions screening process with version-controlled list management; and a SAR reporting log that the MLRO maintains and the board periodically reviews.
For digital-asset businesses, the transaction monitoring framework is the most technically demanding component. Operators we advise routinely underestimate the breadth of what the GFSC considers "monitoring": it is not only fiat on/off ramp scrutiny but on-chain activity analysis – tracing inbound assets for exposure to sanctioned addresses, darknet markets or mixing services. Where the firm uses a third-party analytics provider, the compliance officer must document how alerts are triaged, what disposition categories exist, and how escalation to the MLRO is triggered.
A practical example from our cross-border practice: a payments-adjacent virtual asset firm licensed in Guernsey processed stablecoin settlements for counterparties across three jurisdictions. The MLRO's monitoring procedures covered fiat flows but did not explicitly address on-chain risk scoring for the stablecoin legs. During a routine GFSC supervisory review, the gap was identified and the firm was required to enhance the program within a defined remediation window. The compliance officer had to rebuild the procedure, re-train staff and evidence the changes to the Commission's satisfaction before the matter was closed. The episode delayed a planned product expansion by a material period. Early structuring of the monitoring framework would have avoided that entirely.
How the Travel Rule applies to Guernsey VASPs
The Travel Rule – the FATF obligation requiring a virtual asset service provider to collect, verify and transmit originator and beneficiary information with every qualifying virtual asset transfer – applies to Guernsey-regulated VASPs under the applicable provisions of the Guernsey AML framework. The threshold above which the rule engages, and the precise data fields required, are set by the GFSC in line with FATF guidance; operators should consult the current regulatory notices rather than relying on any general summary, as these thresholds are subject to revision.
The operational challenge for a Guernsey VASP is counterparty identification. When the VASP on the other side of a transfer is itself regulated and Travel-Rule compliant, the data exchange is manageable through a recognized interoperability protocol. When the counterpart is an unhosted wallet or a VASP in a jurisdiction that has not yet implemented the Travel Rule, the Guernsey firm must apply enhanced scrutiny and, in many cases, will need a documented policy on whether it will process the transfer at all.
The MLRO carries direct accountability for the Travel Rule program. That is not a shared function with the technology team. The MLRO approves the policy, signs off on the counterparty risk framework, and is responsible if a disclosure gap arises from a failure to obtain originator data. The compliance officer implements the controls and evidences their operation. In a cross-border structure – Guernsey entity, operations hub in a second jurisdiction, banking in a third – the MLRO must confirm that the Travel Rule data obligations under Guernsey law are met regardless of which leg of the payment chain is processed where.
What cross-border gaps arise – and how banking amplifies the risk
The most acute risk for a Guernsey-licensed VASP operating cross-border is the gap between the compliance standard the GFSC requires and the standard actually applied at the point of customer interaction. A Guernsey entity whose customer onboarding and KYC verification are handled by an affiliated entity in a lower-scrutiny jurisdiction creates a structural compliance weakness. The GFSC holds the Guernsey entity responsible for the adequacy of the KYC gathered on its behalf, even where a group company performs the actual verification.
Banking amplifies this risk materially. Correspondent banks and Guernsey-based banking institutions increasingly apply their own AML overlays to digital-asset clients. A firm whose compliance program does not satisfy the bank's internal standards – even if it formally meets GFSC requirements – will find its banking rails restricted or closed. We have seen firms that passed initial GFSC supervision fail their bank's periodic review because the bank's AML questionnaire sought evidence of on-chain risk scoring that the firm had not yet operationalized. Operating without reliable banking is an existential constraint; it is also, from an enforcement standpoint, a signal that the firm's compliance posture is weak.
The interaction with tax is a second cross-border dimension. Guernsey's zero-rate corporate tax environment is attractive for structuring. But if the Guernsey entity is the licensed entity and the substance is thin – no real compliance officer presence, MLRO nominee with no genuine connection to the Guernsey operation – the risk is not merely regulatory. Substance requirements for tax purposes and the GFSC's expectations about genuine management and control are increasingly aligned. A nominee MLRO who cannot demonstrate active engagement with the compliance program fails both tests simultaneously.
If a prior application stalled or banking was closed, a second read of the compliance structure can surface the reason and the route back. Write to us at info@oboluslaw.com or map your options here.
Decision point: how should a Guernsey VASP staff this function?
The right staffing model depends on the firm's size, geographic scope and transaction volume – not on cost alone. Three profiles are common in our cross-border practice, and each carries distinct risks.
Profile A – Small or early-stage Guernsey VASP: A single qualified individual holding both the MLRO and compliance officer roles is permissible where volume and complexity are low. The risk is concentration: if that person leaves, is unavailable during a regulatory review, or is named in an adverse disclosure, the firm has no coverage. The GFSC expects a documented deputy or succession plan from day one.
Profile B – Mid-sized VASP with cross-border operations: Separate MLRO and compliance officer roles, with a deputy MLRO nominated and approved. The compliance officer may be supported by an external compliance technology provider for monitoring and screening. The MLRO retains the disclosure function. This model requires a documented escalation matrix and regular board reporting. Timeline to have this model operational, assuming nominees are identified and fit-and-proper documentation is prepared, is typically a matter of weeks for the documentation and several weeks for GFSC processing – though the actual timing varies by application complexity and GFSC workload.
Profile C – Group structure with a Guernsey licensed entity and an offshore parent: The group compliance function cannot substitute for the Guernsey-specific MLRO. Group policies can inform the Guernsey procedures, but a Guernsey-specific risk assessment, a Guernsey-law disclosure procedure and a named Guernsey-accountable MLRO are non-negotiable. Regulators in the leading hubs increasingly expect the locally licensed entity's compliance officer to be able to speak independently to its own program – not to refer every question to the group's London or Amsterdam office.
What do firms most often get wrong?
The most frequent mistake is treating the MLRO appointment as a formality – identifying a nominee, filing the name with the GFSC, and then not building the actual compliance infrastructure around that person. The MLRO's first year in role should produce a documented audit trail: board papers, risk assessment updates, training records, SAR log entries (even where no external disclosure was made) and test results from the transaction monitoring program. Without that trail, the first supervisory review will find an individual with a title but no program.
A common assumption in the market is that a strong group compliance function in a larger jurisdiction makes the Guernsey MLRO role largely administrative. That assumption is wrong. The GFSC assesses the Guernsey entity's compliance program on its own merits. A group-level policy that has not been localised to Guernsey law, with Guernsey-specific risk weightings, Guernsey entity decision trees and Guernsey-law disclosure procedures, will not pass. The compliance officer must own a live, localised program – not a photocopy of the parent's framework.
A second recurring mistake concerns the KYC framework: applying a single, undifferentiated due-diligence procedure to all customers regardless of risk classification. The Guernsey regime requires a risk-based approach. Higher-risk customers – those in high-risk jurisdictions, with complex ownership structures, or transacting in high-risk asset classes – require enhanced due diligence. The compliance officer must document why a customer was classified at a given risk level, what enhanced measures were applied, and when the classification was last reviewed. This is the most common gap identified in GFSC-led thematic reviews of the digital-asset sector.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – end-to-end compliance program design for VASPs across 70+ jurisdictions
- Regulator AML audit defence: the structuring angle – how to prepare for and manage a supervisory AML review
- Licence renewal and variation in South Africa – FSCA licensing cycle for digital-asset operators expanding into Africa
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires a virtual asset service provider to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual asset transfer. In Guernsey, the applicable AML provisions implement this obligation. The precise data fields and the threshold above which the rule applies are set by the GFSC and should be confirmed against current regulatory notices. Failure to obtain or transmit the required data is a reportable compliance breach.
Who must act as MLRO for a crypto firm?
The MLRO must be a named, fit-and-proper individual approved by the relevant regulator – in Guernsey, the GFSC. That person must be a natural human being with documented AML decision-making experience; the role cannot be held by a corporate entity or fulfilled entirely through outsourcing. The MLRO retains personal accountability for suspicious activity report decisions and for the firm's disclosure obligations to the Financial Intelligence Service, regardless of what compliance technology or external support the firm uses.
How do regulators audit crypto AML programs?
Regulators, including the GFSC, typically audit AML programs through a combination of desk-based document review and on-site (or remote) inspection. They request the business-wide risk assessment, customer risk classification records, transaction monitoring alert logs with disposition notes, training registers and board-level reporting. For digital-asset businesses, on-chain transaction monitoring documentation – showing how blockchain analytics alerts were triaged and escalated – receives particular scrutiny. A program that exists on paper but lacks an operational evidence trail will not satisfy the review.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where needed. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML/CFT program design, MLRO function structuring and VASP licensing compliance across Channel Islands and EU jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.