The AML and Travel Rule regime in Kazakhstan (AIFC) sits at the intersection of FATF-aligned anti-money laundering obligations and the common-law regulatory architecture of the Astana International Financial Centre – a purpose-built financial free zone governed by the Astana Financial Services Authority (AFSA). Digital-asset businesses operating within the AIFC framework must satisfy AML/CFT obligations derived from FATF Recommendation 15, implement a functioning Travel Rule (the obligation to pass originator and beneficiary data with every qualifying virtual-asset transfer), and maintain a compliance posture that withstands AFSA examination. For an inbound operator, the practical question is not whether these obligations apply – they do, from day one of authorisation – but how to structure the programme across entity, technology and banking layers before the licence is granted.
This page sets out the regulatory basis, the compliance programme elements AFSA expects, the cross-border friction points that most commonly create risk for inbound businesses, and the decision logic for operators choosing between the AIFC and parallel hub authorisations. One anonymized matter illustrates the practical stakes.
What is the regulatory basis for AML compliance in the AIFC?
The AIFC AML/CFT regime is grounded in the AFSA rulebook and Kazakhstan's national AML law, with the AIFC applying FATF standards – including FATF Recommendation 15 on virtual assets – to all digital-asset service providers it authorises. The AIFC operates as a common-law enclave with its own court and arbitration centre, legally distinct from the broader Kazakhstani regulatory perimeter, but AFSA-authorised firms remain subject to FATF-derived obligations as a condition of their licence. This means that a digital-asset trading facility or custody business licensed under the AIFC regime inherits AML/CFT obligations that are structurally similar to those applied by the FCA, MAS or FSRA – not a lighter-touch alternative to them.
AFSA supervises compliance through both the authorisation process and ongoing examination. The AML/CFT rulebook requires firms to appoint a qualified Money Laundering Reporting Officer (MLRO), maintain written policies and procedures, conduct customer due diligence at onboarding and on an ongoing basis, implement transaction monitoring, and file suspicious activity reports through the prescribed channel. These are not aspirational standards. AFSA expects to see documented, tested programme elements – not a compliance manual that has never been applied.
The cross-border dimension matters immediately. A firm authorised by AFSA but serving clients across multiple jurisdictions must assess whether the AML obligations of those client jurisdictions also apply to its activities. Where a business receives transfers from or sends transfers to counterparties in MiCA-supervised jurisdictions, FCA-registered firms or MAS-licensed entities, the Travel Rule obligations of those regimes interact with the AFSA rulebook. Operators we advise routinely underestimate this stack.
CTA #1 — The regime described above is the standard path. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis materially. Map your options with OBOLUS before the compliance architecture is locked in.
How does the Travel Rule operate for AIFC-licensed VASPs?
The Travel Rule, as applied within the AIFC framework, requires a VASP (virtual asset service provider) originating a transfer to collect and transmit originator and beneficiary identifying information to the receiving VASP – and for the receiving VASP to verify and retain that data. The obligation mirrors FATF's standard formulation: name, account identifier and, depending on the transaction value, additional verification data must travel with the transfer rather than being held only at the originating institution.
In our cross-border practice, the Travel Rule creates three distinct operational challenges for AIFC-licensed businesses. First, the counterparty VASP must also be Travel Rule-capable – and not every jurisdiction has implemented the rule at the same technical level. Second, the data-transmission protocol (whether TRISA, OpenVASP, Notabene or another solution) must be selected and integrated before the first institutional transfer is executed. Third, where the receiving address cannot be attributed to a Travel Rule-capable VASP – a common scenario involving self-hosted wallets – AFSA expects the firm to apply a risk-based assessment, which must be pre-documented in the firm's AML procedures.
The self-hosted wallet question is increasingly central to AFSA examinations. Regulators in the leading hubs, including AFSA, increasingly expect firms to articulate a written policy on unhosted wallet interactions: how the firm classifies the transaction risk, what enhanced due diligence is triggered, and at what threshold a transaction is declined. A policy that simply defers all decisions to the MLRO case-by-case is not, in our experience, treated as adequate.
Practically, a firm preparing for AIFC authorisation should treat Travel Rule readiness as a pre-authorisation deliverable, not a post-licence implementation task. AFSA's examination of a new applicant will include questions about technical solution selection and counterparty VASP screening methodology. Arriving at that stage without a documented answer delays the licence and signals programme immaturity.
What KYC framework does AFSA require for digital-asset businesses?
AFSA's KYC framework requires digital-asset firms to apply a risk-based approach to customer due diligence, stratified by customer type, product risk and jurisdictional exposure. At minimum, this means identity verification, beneficial ownership identification for legal entities, source-of-funds assessment for higher-risk relationships, and periodic review calibrated to the customer's risk classification.
The framework distinguishes between standard CDD, simplified CDD for lower-risk relationships, and enhanced due diligence for politically exposed persons (PEPs), high-risk jurisdictions flagged by FATF, and customers presenting atypical transaction patterns. A crypto exchange or custodian serving institutional clients must also apply correspondent-level due diligence to VASP counterparties – assessing the regulatory status, AML programme quality and ownership structure of VASPs with which it maintains an ongoing settlement relationship.
In our practice, the most common KYC gap at the point of AFSA examination is not identity verification – most firms have this configured – but beneficial ownership depth for corporate clients and the absence of a documented VASP counterparty due diligence policy. AFSA expects firms to know, at a programme level, how they assess the AML adequacy of every VASP counterparty before processing a transfer on their behalf. This is a meaningful programme investment for a new entrant.
The jurisdictional interaction with MiCA is also relevant here. A firm serving EU-based institutions must comply with both the AFSA KYC framework and the CDD expectations of the EU's AML regime as applied to the EU-side counterparty. The practical effect is that the AIFC-licensed firm operates to the higher of the two standards in practice – because the EU counterparty's compliance team will demand it.
How should an AIFC firm approach transaction monitoring?
Transaction monitoring in the AIFC context requires a combination of on-chain analytics and off-chain behavioural pattern detection, integrated into a documented alert management workflow with clear escalation paths to the MLRO. AFSA does not prescribe a specific technical solution, but it expects firms to demonstrate that the monitoring programme is proportionate to the business's risk profile and capable of detecting the typologies identified in the firm's own risk assessment.
On-chain analytics is a baseline expectation, not an optional enhancement. Firms operating digital-asset trading facilities or custody services are expected to screen wallet addresses against sanctions lists and to apply transaction tracing tools that can flag exposure to high-risk transaction histories – mixing services, sanctioned counterparties and dark-market flows. The principal analytics platforms used in the industry for this purpose are well-established; integration with AFSA compliance expectations requires that the output feeds a documented review and escalation process.
Regulators in the leading hubs increasingly expect the monitoring programme to be risk-stratified: different alert thresholds for retail versus institutional flows, different escalation timelines for sanctions-list hits versus structural pattern alerts. A single-threshold monitoring configuration applied uniformly across all transaction types is, in our experience, the single most common reason an AFSA examination generates a remediation finding.
The cross-border angle is acute for AIFC firms. A business routing transfers between the AIFC and counterparties in the UK, the EU or Singapore operates across multiple sanctions regimes simultaneously – OFAC, UK OFSI, EU sanctions and the AIFC's own AFSA sanctions posture. The monitoring solution must address all applicable sanctions lists, not just one.
Who must act as MLRO, and what does AFSA expect from compliance governance?
Every AFSA-authorised digital-asset firm must designate a Money Laundering Reporting Officer who is approved by AFSA as a controlled function holder, is sufficiently senior to have direct access to management and the board, and possesses demonstrable AML/CFT expertise relevant to the digital-asset sector. The MLRO cannot be a nominal appointment: AFSA's fitness and propriety assessment and its ongoing supervision process will engage with the MLRO directly.
The MLRO's core responsibilities include reviewing and approving the AML/CFT policies and procedures, making and receiving suspicious activity disclosures from staff, filing reports with the relevant financial intelligence unit, and providing periodic AML/CFT reporting to the board. The MLRO must also maintain the firm's risk assessment – a living document, updated when the business model, client base or product set changes materially – not a document filed at authorisation and reviewed only when an examiner asks for it.
For smaller inbound operators, the MLRO question is a practical constraint. A founder-led business with a team of fewer than ten may struggle to justify a full-time senior MLRO. AFSA has accommodated outsourced MLRO arrangements in certain contexts, subject to the firm demonstrating that the outsourced individual has genuine authority, adequate time commitment and no conflicts. We regularly advise clients on structuring this arrangement in a way that satisfies AFSA's expectations while remaining commercially viable for an early-stage operation.
Beyond the MLRO, AFSA expects a three-lines-of-defence model appropriate to the size of the firm. For a small digital-asset trading facility, this may be a condensed governance structure – but it must be documented. A firm that arrives at authorisation with a compliance function that exists only on paper will face a substantive remediation requirement before the licence is issued.
What are the banking and tax interactions for an AIFC-authorised digital-asset firm?
The AIFC's common-law architecture and FATF-aligned AML posture are specifically designed to reduce banking friction for authorised firms – but authorisation alone does not guarantee a banking relationship. In our cross-border practice, operators we advise routinely find that correspondent banking for digital-asset businesses requires demonstrating programme quality, not just regulatory status.
Banking access for AIFC-licensed digital-asset firms generally routes through Kazakhstani banks that have developed VASP-facing product lines and, in some cases, through regional financial institutions that treat AIFC authorisation as a baseline comfort level rather than a complete KYC substitute. The practical effect is that the AML programme – the risk assessment, the CDD procedures, the transaction monitoring configuration – doubles as the primary document set reviewed by the correspondent bank's own compliance function. A programme that is adequate for AFSA examination is also the firm's best argument to the bank's onboarding team.
Tax interaction is a distinct dimension. The AIFC offers a specific tax regime applicable to AIFC participants; the interaction between that regime and the beneficial ownership jurisdiction of the firm's ultimate shareholders, and the tax residency of its clients, requires careful mapping. Digital-asset income characterization varies by jurisdiction. A token issuance carried out by an AIFC entity with EU investors will attract MiCA token-regime analysis, potential VAT implications and withholding tax questions that are not resolved by the AIFC tax framework alone.
For inbound operators, the practical recommendation is to treat the licence application, the banking engagement and the tax structuring as simultaneous work streams. Completing the licence and then discovering that the banking stack requires restructuring, or that the tax position of the chosen holding jurisdiction creates friction at client onboarding, is a costly sequencing error that we have seen repeatedly.
CTA #2 — If a prior application stalled or a banking relationship was refused, a structured review can identify the specific programme gap and map the route back. Contact OBOLUS to scope that review.
What does an AML programme failure look like in practice?
In a recent compliance advisory matter, a digital-asset trading business had obtained AIFC authorisation and began onboarding institutional counterparties across Central Asia and the wider CIS region. Several months in, the firm's correspondent bank suspended outgoing transfers, citing concerns about the adequacy of the firm's VASP counterparty due diligence. The firm's AML policy addressed retail customer KYC in detail but contained only a generic paragraph on institutional counterparty assessment – with no documented process for evaluating the AML programme quality of incoming VASPs. We were instructed to review the compliance programme, identify the gap, and prepare a remediated policy and counterparty assessment matrix. The bank resumed transfers within weeks of receiving the remediated documentation package. The lesson: a programme adequate for authorisation is not always adequate for a correspondent bank's ongoing due diligence cycle.
Which operator profile is best placed to use the AIFC for AML-compliant digital-asset operations?
The AIFC suits a specific set of operator profiles. Understanding where the fit is strongest – and where a different hub may be more appropriate – is the decision logic that drives a sound structure.
Profile A: A regional digital-asset exchange targeting Central Asian and CIS institutional clients. The AIFC's common-law framework, FATF alignment and geographic position make it a natural first-choice authorisation for a business whose primary counterparty relationships run through the region. The AML programme must address the higher-risk jurisdictional profile of the client base with correspondingly strong CDD and enhanced due diligence procedures. The AIFC offers access to a well-developed arbitration framework for dispute resolution. Timeline to authorisation varies by application quality and AFSA workload, and should be treated as a matter of months rather than weeks.
Profile B: A European or global exchange seeking a secondary hub for Central Asian flows. A firm already holding a MiCA CASP authorisation or an FCA registration can use an AIFC licence to manage regional flows within a documented jurisdictional allocation. The AML architecture must address the interaction between AFSA obligations and the home-jurisdiction AML regime – effectively operating to the higher of the two standards. The cross-border legal analysis of what activity may be conducted from the AIFC entity without triggering licensing obligations in the primary jurisdictions is essential before the structure is committed.
Profile C: A custodian or token issuance platform seeking a common-law FATF-compliant base in Central Asia. The AIFC's custody and digital-asset trading facility concepts support this model. The AML programme must address the specific typologies associated with custody – custody transfer requests, wallet attribution, client asset segregation and, where applicable, staking or lending on custody balances. This profile also involves the most complex banking interaction, as custody firms hold client assets and correspondents will examine the safeguarding and client-money framework as well as the AML programme.
Where none of these profiles apply – where the business is primarily EU-facing, UK-retail or US-directed – the AIFC is unlikely to be the primary authorisation. The relevant regime will be MiCA, the FCA regime or US federal and state licensing, with the AIFC potentially relevant as a secondary structure. We map these decisions before the first application is filed.
What are the most common AML compliance mistakes for new AIFC entrants?
Operators we advise routinely encounter the same set of structural errors when entering the AIFC. The first is treating the AML/CFT policy as a one-time document rather than a programme. AFSA expects the policy to be a living instrument, reviewed at defined intervals and updated when the business model changes. A policy drafted at authorisation and never revisited will fail at the first supervisory examination.
The second error is underestimating the Travel Rule's technical requirements. Firms frequently draft a Travel Rule policy without selecting and integrating a compliant technical solution. AFSA – like the FCA, MAS and FSRA – expects the technical capability to be in place before the firm processes its first qualifying transfer. Documenting a policy that the technology cannot yet execute is not a compliant position.
The third error – one we see most frequently in inbound operators from jurisdictions with lighter AML traditions – is treating the MLRO as a compliance coordinator rather than a decision-maker. AFSA's expectations are clear: the MLRO has authority to override business decisions where AML/CFT risk requires it. A firm that structures the MLRO as a reporting function rather than a control function will face a remediation finding.
A common assumption in this space is that a single offshore licence is sufficient to serve clients globally. That assumption is incorrect. Every jurisdiction in which a firm has clients, operates infrastructure or holds assets will apply its own AML/CFT expectations to those activities, regardless of where the licence sits. The AIFC licence governs the AIFC-domiciled entity; it does not export the AFSA AML framework to counterparty jurisdictions.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – our core compliance practice across 70+ licensing jurisdictions
- AML/CFT policy drafting in Mauritius – VAITOS Act compliance programme structuring for VASP operators
- How to draft a token sale agreement – cross-border structuring considerations for token issuers
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires the originating VASP in a virtual-asset transfer to collect, verify and transmit identifying information about the originator and the beneficiary – name, account identifier and, above defined value thresholds, additional verification data – to the receiving VASP. The receiving VASP must in turn retain and verify that data. Under the AFSA framework, the obligation applies from the point of authorisation and requires a compliant technical solution integrated before the first qualifying transfer is processed. Non-compliance exposes the firm to regulatory remediation and potential suspension of its licence.
Who must act as MLRO for a crypto firm?
Under the AFSA regime, the MLRO must be an AFSA-approved controlled function holder who is senior enough to have direct board access, possesses demonstrable digital-asset AML expertise and holds genuine authority to escalate and override business decisions on AML grounds. The role may be held on an outsourced basis in limited circumstances – subject to AFSA being satisfied on time commitment, authority and absence of conflicts – but cannot be nominal. Founders or senior executives doubling as MLRO must demonstrate that the compliance function is genuinely independent of commercial pressure.
How do regulators audit crypto AML programs?
AFSA audits AML programmes through both document review and direct engagement with the MLRO and senior management. Examiners review the firm's written risk assessment, CDD and KYC procedures, transaction monitoring configuration, suspicious activity report logs, Travel Rule technical solution and VASP counterparty due diligence files. They test whether documented policies are actually implemented – asking for evidence of real transactions processed through the stated procedures. A programme that exists only on paper will not satisfy an AFSA examination. Programme gaps identified at examination typically generate a formal remediation requirement with a defined timeline for resolution.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programmes that sit around every licence. We map the licence stack across operating, custody and payment layers before you commit – because operating without the right programme in place risks enforcement, frozen banking rails and lost authorisation. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT programme structuring and Travel Rule implementation for digital-asset businesses across FATF-aligned jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.