The Money Laundering Reporting Officer (MLRO) and the compliance officer function sit at the legal core of any digital-asset business operating inside the Astana International Financial Centre (AIFC). For an inbound operator, getting the personnel structure right is not a procedural afterthought – it is the difference between a live licence and a stalled one. The Astana Financial Services Authority (AFSA), which supervises regulated firms within the AIFC, treats adequate AML/CFT governance as a threshold condition for authorisation, not a post-licence formality.
As digital-asset regulation converges on the FATF model across Central Asia and the Gulf, the AIFC sits in an unusual position: a common-law jurisdiction inside Kazakhstan, governed by English-law-derived rules, with direct supervisory authority held by AFSA. Firms that treat the MLRO role as a box to tick – appointing a nominal officer with no real authority – expose the entity to enforcement action, supervisory escalation and loss of banking relationships. We have seen this pattern in practice across multiple hubs, and Kazakhstan is no exception.
This page sets out the MLRO and compliance officer obligations under the AIFC regime, explains how AFSA examines these functions during application review and ongoing supervision, and addresses the cross-border dimension that almost every inbound operator faces.
What is the legal basis for the MLRO function in the AIFC?
The AIFC imposes an explicit statutory obligation on regulated digital-asset firms to appoint a designated officer responsible for AML/CFT oversight, aligning with the FATF Recommendations – specifically FATF Recommendation 15, which requires virtual-asset service providers to implement risk-based AML/CFT controls. Under the AFSA regulatory framework, this obligation is not optional for any firm holding a digital-asset trading facility, custody or related licence. AFSA's AML/CFT rules sit within the broader AIFC regulatory rulebooks, which are binding on all authorised persons.
The MLRO must be a natural person. The role cannot be outsourced to a corporate entity or absorbed into a generic "director of risk" title with no defined authority. AFSA expects the MLRO to have direct access to the board, sufficient seniority to reject a suspicious transaction, and the operational independence to file a Suspicious Activity Report without interference from commercial management.
The compliance officer function is conceptually adjacent but legally distinct. The compliance officer is responsible for ensuring the firm operates within the conditions of its authorisation – monitoring regulatory change, managing licence conditions and owning the internal control framework. In smaller AIFC-regulated entities, one person may hold both designations, subject to AFSA satisfaction that there is no material conflict and that the individual has sufficient capacity.
Who qualifies as MLRO or compliance officer under AFSA rules?
AFSA applies a fitness-and-propriety standard to both the MLRO and the compliance officer, assessing competence, experience and integrity before and after authorisation. A candidate must demonstrate practical AML/CFT experience relevant to the firm's business model. A nominee with a background solely in general legal or corporate governance, without documented experience in financial crime compliance, is unlikely to satisfy AFSA's standard.
Residency requirements for the MLRO in the AIFC context are a live question. AFSA has, in practice, accepted non-resident MLROs where the firm demonstrates robust escalation procedures and the officer is genuinely reachable and engaged. That said, AFSA increasingly scrutinises nominee arrangements – situations where the named officer has no real role in day-to-day compliance. The trend across leading crypto hubs is clear: regulators want substance, not signatures.
Key qualifications AFSA expects to see include:
- A demonstrable track record in AML/CFT compliance within financial services or digital assets specifically.
- Familiarity with the FATF Recommendations and their application to virtual-asset service providers.
- Practical knowledge of transaction monitoring, KYC (know-your-customer) onboarding, and the escalation and reporting chain.
- No adverse regulatory history in any jurisdiction.
In our practice, candidates who combine a financial-crime compliance background with direct experience of a crypto-native business model – exchange operations, custody, or stablecoin management – perform significantly better during AFSA's fit-and-proper review than candidates drawn solely from traditional banking compliance.
What are the core duties of an MLRO at an AIFC-regulated digital-asset firm?
The MLRO's primary statutory duty is to receive, evaluate and escalate internal suspicious-activity reports, and where warranted to file an external Suspicious Activity Report with the relevant Kazakhstani financial-intelligence authority. That obligation is non-negotiable and continues throughout the life of the authorisation.
Beyond the SAR function, an AIFC-regulated MLRO is expected to own the following operational responsibilities:
- AML/CFT programme ownership – drafting, maintaining and annually reviewing the firm's written AML/CFT policies and procedures, calibrated to the firm's specific risk exposure (customer types, geographies, product lines, transaction volumes).
- Transaction monitoring oversight – supervising the rules engine or manual review process that flags unusual transaction patterns; adjusting parameters as typologies evolve.
- KYC programme governance – ensuring customer due-diligence processes meet AFSA's standards, including enhanced due diligence for higher-risk clients and politically-exposed persons.
- Travel Rule compliance – overseeing the firm's data-collection and transmission obligations for virtual-asset transfers under the applicable AFSA provisions implementing FATF Recommendation 16.
- Staff training – designing and delivering periodic AML/CFT training to all relevant staff, with records maintained for AFSA inspection.
- Regulatory liaison – acting as the point of contact for AFSA on AML/CFT matters, including examination responses, and managing information requests from law enforcement.
The compliance officer's remit overlaps on training and policy governance but extends into broader licence-condition management: tracking regulatory change, coordinating responses to AFSA consultations, and owning the internal compliance calendar.
How does the Travel Rule apply to AIFC-regulated VASPs?
The Travel Rule – the obligation to collect and transmit originator and beneficiary data alongside a virtual-asset transfer – applies to AIFC-regulated virtual-asset service providers under AFSA's implementation of FATF Recommendation 16. The MLRO is operationally responsible for ensuring the firm has a compliant Travel Rule solution in place before processing transfers above the applicable threshold.
In practice, this means the firm must be able to:
- Identify the originator (name, account identifier, and jurisdiction of the sending VASP).
- Identify the beneficiary (name and account identifier at minimum).
- Transmit that data securely to the receiving VASP at or before the point of transfer.
- Receive and validate incoming Travel Rule data from counterpart VASPs.
The cross-border dimension here is acute. Most inbound operators to the AIFC have users or liquidity partners across multiple jurisdictions – the European Union (now under MiCA and its ESMA-supervised Travel Rule framework), Singapore (under MAS), Hong Kong (under the SFC VASP regime) and beyond. The Travel Rule data format and threshold vary by jurisdiction. A firm that processes transfers to EU counterparties must comply with the MiCA-aligned Travel Rule standard; transfers to Singapore counterparties must meet the MAS standard; and so on.
We regularly advise AIFC-licensed firms on building a Travel Rule programme that works across these overlapping regimes rather than one optimised for the AIFC alone. A single-jurisdiction Travel Rule implementation routinely breaks down at the first cross-border transfer.
For a scoped review of your Travel Rule programme across the AIFC and your operating jurisdictions, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
What does AFSA review during the authorisation application?
AFSA's authorisation process for a digital-asset trading facility or custody licence includes a direct assessment of the AML/CFT governance structure – not merely a paper check of whether a policy document exists. The review typically covers three layers: the written programme, the nominated individuals, and the operational infrastructure.
At the programme level, AFSA expects to see a business-risk assessment (a document mapping the firm's inherent AML/CFT risks by customer type, product, geography and delivery channel, with mitigating controls). The MLRO must be able to demonstrate ownership of that document – not merely file it.
At the individual level, the MLRO and compliance officer candidates are assessed on the fitness-and-propriety criteria described above. AFSA may request CV documentation, regulatory reference letters, and – in some cases – a direct interview or Q&A with the regulator.
At the infrastructure level, AFSA will examine whether the firm has an operational transaction-monitoring system appropriate to its volume and risk profile, a functional KYC onboarding process, and a Travel Rule solution. A firm that describes a compliant process in its policies but cannot demonstrate that the technology stack is in place will face follow-up questions that delay authorisation.
The timeline from a complete application to an authorisation decision varies under AFSA's current process. The registry does not carry a precise day count, and AFSA's published timelines are indicative. In our experience, the AML/CFT governance review is consistently one of the elongating factors – firms that submit with a well-documented, operationally ready compliance function move through this phase materially faster than those that plan to "build out" compliance after approval.
How do tax and banking interact with the MLRO function for an AIFC operator?
The MLRO function does not operate in isolation from the firm's tax and banking structure, and inbound operators frequently underestimate this interdependency. Banking is the most immediate pressure point.
Kazakhstani banks servicing AIFC-licensed digital-asset firms conduct their own AML/CFT due diligence on the licence holder. A bank's compliance team will review the firm's AML/CFT policies, ask for the MLRO's CV, and may request evidence of transaction-monitoring capacity. A firm with a nominal or inadequately documented MLRO structure may be declined banking even after receiving its AFSA authorisation. This is not hypothetical – we have seen it in both the AIFC context and across comparable hub jurisdictions.
The cross-border banking dimension adds further complexity. Many AIFC-licensed firms route operational and custody accounts through correspondent-banking chains that touch EU, UK or US-regulated institutions. Those institutions impose their own enhanced due diligence (EDD) requirements on digital-asset counterparties. The MLRO must be prepared to respond to EDD questionnaires from correspondent banks, often on short notice and with significant technical depth.
On the tax side, the AIFC offers a defined tax regime with certain exemptions for qualifying entities. The interaction between that regime and the compliance function arises principally through the substance requirements: a firm claiming tax benefits in the AIFC must demonstrate genuine economic substance, and the compliance function – headcount, documented processes, and active MLRO engagement – contributes directly to the substance profile.
In a recent matter, an exchange operator seeking AIFC authorisation had structured its entity with a remote MLRO in a different time zone and no local compliance support. The banking application was declined at the due-diligence stage before the AFSA licence was even issued. We restructured the governance model, appointed a locally-engaged MLRO with documented authority and operational access, and supported the resubmission to both the bank and AFSA. The entity received its banking relationship and proceeded to authorisation without further material delay.
What are the most common AML/compliance mistakes AIFC applicants make?
In our cross-border practice, the compliance failures we see most consistently in AIFC applications fall into recognisable patterns. Identifying them early saves months.
The first is the nominal MLRO: a director or external consultant named in the application with no real authority, no access to transaction data, and no documented involvement in the firm's day-to-day operations. AFSA's assessment process is designed to surface this.
The second is a policy/process disconnect: the AML/CFT written programme describes controls that the technology stack does not actually implement. Transaction-monitoring rules are described as "calibrated to the firm's risk profile" but have never been tested against live data. AFSA expects demonstrated operational readiness, not aspirational documentation.
The third is Travel Rule under-preparation. Firms frequently treat Travel Rule compliance as a future problem – "we will implement a solution once we are live." This approach fails on two levels: AFSA expects a compliant solution before processing transfers, and the cross-border complexity means implementation takes longer than anticipated.
A common assumption among inbound operators is that a single offshore licence – an existing registration in, say, a Caribbean or Eastern European jurisdiction – is sufficient to cover their AIFC operations or to satisfy AIFC banking partners. It is not. Each jurisdiction operates its own AML/CFT regime, and an AIFC-licensed entity is assessed against AIFC and AFSA standards, regardless of what other registrations the group holds. The compliance function must be built for the AIFC entity specifically.
If a prior AFSA application stalled or a banking relationship was declined, a structured review can identify the compliance gap and map the route forward. Write to info@oboluslaw.com or message us at t.me/oboluslaw. A second read of the AML/CFT programme and the MLRO governance structure routinely surfaces structural issues that are fixable before resubmission. Map your options.
Self-assessment: is your AIFC compliance function ready for AFSA?
Before submitting an application or engaging with AFSA on a compliance review, an operator should be able to answer yes to each of the following:
- Is a named natural person formally designated as MLRO, with documented authority, board access, and operational independence from commercial management?
- Does the MLRO have documented AML/CFT experience relevant to the firm's digital-asset business model?
- Is the firm's AML/CFT programme current, complete and calibrated to a documented business-risk assessment?
- Is a transaction-monitoring system live and producing test results the MLRO can demonstrate?
- Does the KYC onboarding process meet AFSA's customer due-diligence standards, including EDD triggers for higher-risk customers?
- Is a Travel Rule solution in place, configured for cross-border transfers to counterparty VASPs in the firm's primary operating jurisdictions?
- Are staff AML/CFT training records current and accessible for AFSA inspection?
- Has the compliance function been mapped against the firm's banking and tax-substance requirements, not just the licence conditions?
A "no" on any of the above is a material gap. In our experience, a firm that goes to AFSA with unresolved gaps will receive a request for further information that adds weeks – sometimes months – to the timeline. Resolving the gaps before application is consistently more efficient.
Related at OBOLUS
- AML, Travel Rule and KYC compliance for digital-asset businesses – end-to-end programme design and regulatory engagement across major hubs.
- How to run a VASP business risk assessment – a structured guide to building the foundational AML document AFSA will review.
- Utility token legal opinion in Luxembourg – token classification and legal-opinion practice across EU jurisdictions.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 – requires a virtual asset service provider (VASP) to collect, verify and transmit the name and account identifier of the originator and beneficiary with each virtual-asset transfer above the applicable threshold. The rule applies to both the sending and the receiving VASP. Compliance requires a technical solution capable of exchanging that data with counterpart institutions, including where those counterparties operate under different jurisdictional regimes such as MiCA, the MAS Payment Services Act or the AFSA rulebook.
Who must act as MLRO for a crypto firm?
The MLRO must be a natural person with demonstrated AML/CFT expertise and sufficient seniority to act independently of commercial management. Under AFSA's regime, the nominee is assessed for fitness and propriety before authorisation is granted. Corporate nominees, nominal appointments, and individuals without documented compliance experience in financial services or digital assets are unlikely to satisfy the regulator's standard. In smaller entities, the MLRO and compliance officer roles may be held by a single individual, subject to the regulator's satisfaction on capacity and conflict.
How do regulators audit crypto AML programs?
Regulators including AFSA typically conduct AML/CFT audits through a combination of document review, system demonstrations, and staff interviews. They examine the written AML/CFT programme for completeness and calibration to the firm's specific risk profile, test whether transaction-monitoring rules are live and producing actionable outputs, review SAR filing records, assess KYC onboarding documentation for a sample of customer files, and verify that Travel Rule procedures are operational. An MLRO who cannot demonstrate direct involvement in each of these functions during an examination creates a material supervisory risk for the firm.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML/CFT, Travel Rule and compliance architecture that sits around them. We map the licence, compliance and banking stack across operating, custody and payment layers before a client commits – across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your AIFC compliance structure, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML/CFT programme design, MLRO function governance and AFSA regulatory engagement for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.