EST · MMXXVI
Home/Jurisdictions/Kazakhstan Aifc/Sanctions screening for crypto in Kazakhstan (AIFC)
Compliance, AML & Travel Rule

Sanctions screening for crypto in Kazakhstan (AIFC)

Sanctions screening for crypto in Kazakhstan (AIFC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

For a digital-asset business operating inside the Astana International Financial Centre (AIFC), sanctions screening is not a back-office checkbox. It is the core compliance obligation that determines whether your banking relationships hold, your licence remains live and your counterparties will transact with you at all. The Astana Financial Services Authority (AFSA) – the AIFC's independent regulator – applies a common-law supervisory model that explicitly incorporates FATF Recommendation 15 (the obligation to apply AML/CFT controls to virtual assets and virtual asset service providers) into its supervisory expectations. Failure to operationalize those expectations exposes a firm to licence suspension, mandatory remediation and the loss of correspondent banking – a sequence we have seen move from warning letter to account closure in a matter of weeks.

This page sets out the sanctions-screening regime applicable to crypto firms authorised or seeking authorisation in the AIFC, the cross-border interaction with tax, banking and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer), and the decision points that an operator must resolve before committing to a structure.

What is the AFSA sanctions and AML framework for virtual assets?

The AFSA supervises digital-asset activity in the AIFC under its dedicated virtual-asset framework, which covers digital-asset trading facilities, custody services and related intermediary functions. The framework is built on a common-law base – the AIFC operates under English-law principles separate from the Kazakhstani legal system – and incorporates FATF standards as a supervisory floor. The AFSA framework explicitly requires licensed firms to maintain a sanctions-screening programme that checks counterparties, beneficial owners and transaction flows against applicable sanctions lists before onboarding and on a continuous basis thereafter. The primary lists in scope are those issued by the United Nations Security Council, the United States (OFAC), the European Union and the United Kingdom. Firms with a cross-border user base – which describes almost every exchange or custody service operating through the AIFC – must also monitor for jurisdictions and persons subject to enhanced restrictions under Kazakhstani national law.

The AFSA's supervisory approach draws on its common-law heritage. Regulators here expect written policies, documented risk assessments, senior management accountability and evidence that controls actually function – not merely that they exist on paper. In our practice, the most common gap we identify at the point of AFSA supervisory review is the absence of a documented rationale for list selection. A firm that screens only against one sovereign list, without written justification for omitting others, is presenting a controls weakness even if no sanctioned person has ever attempted to transact.

Operating without a properly calibrated sanctions programme risks enforcement, frozen correspondent-banking rails and the loss of the AIFC licence itself.

Which crypto firms are required to conduct sanctions screening in the AIFC?

Every firm conducting regulated digital-asset activities inside the AIFC perimeter – including digital-asset trading facility operators, custodians, brokers and transfer agents – is subject to AFSA AML and sanctions obligations from the date of registration or authorisation. The obligation is not limited to firms with Kazakhstani users. An AIFC-registered entity that transacts exclusively with counterparties in third countries still operates under AFSA supervision and must satisfy its screening requirements with respect to those counterparties.

Two categories of operator regularly underestimate their exposure. First, firms that structure the AIFC entity as a holding or treasury vehicle – on the assumption that it holds assets rather than conducts regulated activity – may find that custody arrangements or intra-group transfers bring them within the AFSA's activity perimeter. Second, token issuers who distribute through an AIFC-registered placement agent may inherit compliance obligations through the agency relationship, depending on how that relationship is characterised under the AFSA framework.

The AIFC's status as a free-zone enclave within Kazakhstan also means that certain Kazakhstani national financial-intelligence-unit (FIU) reporting requirements apply in parallel. The interface between AIFC regulatory obligations and the broader Kazakhstani AML regime is a point of genuine legal complexity, particularly for firms that operate both inside and outside the AIFC perimeter. Allied counsel in the relevant local jurisdiction is typically required to map this dual exposure correctly.

A common assumption in this market is that a single offshore licence is sufficient to serve clients globally. That assumption does not survive contact with AFSA supervisory reality or with the correspondent banks that gate the firm's access to fiat rails. Screening obligations follow the activity, not the marketing intent.

How does the Travel Rule apply to AIFC-registered VASPs?

The Travel Rule – the FATF obligation requiring a VASP (virtual asset service provider) to collect, retain and transmit originator and beneficiary information with each virtual-asset transfer above the applicable threshold – is incorporated into the AFSA supervisory framework as a direct consequence of AFSA's FATF-aligned posture. In our cross-border practice, the Travel Rule is consistently the compliance gap that creates the most acute risk for AIFC-registered firms dealing with counterparties in MiCA-regulated jurisdictions or in Singapore, where the Monetary Authority of Singapore applies the Travel Rule under the Payment Services Act.

Practical Travel Rule compliance for an AIFC VASP requires three operational elements. First, the firm must select and deploy a Travel Rule solution capable of exchanging structured data with counterparty VASPs across the major interoperability protocols. Second, the firm must implement a sunrise-clause policy – a documented procedure for handling transfers from or to jurisdictions where the counterparty VASP is not yet Travel Rule-compliant – that the AFSA and correspondent banks will accept as prudent. Third, the firm's onboarding workflow must capture the beneficial-ownership data needed to populate Travel Rule messages before a transfer is processed, not after.

The cross-border dimension is acute here. A transfer from an AIFC-registered exchange to a European counterparty VASP implicates both the AFSA framework and the MiCA regime as it is applied by ESMA and relevant EU national competent authorities. Where the receiving VASP sits in Singapore, the MAS Payment Services Act Travel Rule requirements apply at the receiving end. The compliance standard the AIFC firm must meet is, in practice, the highest standard demanded by any jurisdiction in the chain.

To map Travel Rule obligations across your operating corridors before onboarding begins, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base and banking corridors change the analysis materially.

What does a compliant sanctions-screening programme look like under AFSA supervision?

An AFSA-compliant sanctions-screening programme consists of five documented elements that the regulator expects to find in place at any supervisory review, whether routine or triggered by an incident. Each element has a cross-border dimension that an operator with international flows must address explicitly.

The first element is list governance: a written policy identifying each sanctions list screened, the rationale for inclusion or exclusion, the update frequency and the owner responsible for adding new lists when a relevant sovereign authority imposes new restrictions. Firms that rely on a vendor-managed screening tool without an internal list-governance policy are delegating a supervisory obligation without retaining the supervisory accountability.

The second element is counterparty and beneficial-owner screening at onboarding. The AFSA framework applies a risk-based KYC standard consistent with FATF Recommendation 10, requiring identification and verification of the beneficial owner behind a legal entity, not merely the registered name. For institutional counterparties – funds, family offices, other VASPs – this means obtaining and screening UBO data to the level that satisfies the firm's own documented risk appetite.

The third element is ongoing transaction monitoring. Screening at onboarding is not sufficient. The AFSA expects firms to monitor transaction flows on an ongoing basis, with automated alerts for transactions involving listed entities, high-risk corridors or patterns consistent with sanctions evasion (including structuring and layering through intermediary wallets).

The fourth element is blockchain analytics integration. Given the pseudonymous nature of on-chain transfers, AFSA-supervised firms are expected to use blockchain analytics tools to assess the provenance and destination of funds at the wallet and transaction level. A firm relying solely on name-matching without on-chain forensics is operating a programme that will not withstand a post-incident review.

The fifth element is documented escalation and reporting. When a match is identified – whether a true positive or a potential match requiring further review – the firm's documented procedure must specify the escalation path, the timeline for resolution and the conditions under which a suspicious-activity report is filed with the AIFC's designated financial-intelligence channel. The MLRO (Money Laundering Reporting Officer) carries personal accountability for the completeness of this escalation record.

How does sanctions screening interact with banking and tax for an AIFC crypto firm?

The banking interaction is direct and consequential. Correspondent banks that provide USD and EUR clearing to AIFC-registered digital-asset firms conduct their own due diligence on the firm's AML and sanctions programme as a condition of maintaining the relationship. In practice, a firm that cannot produce a current risk assessment, a list of screened sanctions regimes and evidence of a functioning escalation process will not retain correspondent access – regardless of its AIFC regulatory status. We have advised on situations where a firm's AFSA licence was fully in order but its banking relationship collapsed because the correspondent's compliance team identified a gap in the firm's OFAC screening posture.

The tax dimension adds a second layer. An AIFC-registered digital-asset firm benefits from the AIFC's dedicated tax regime, which provides for a defined period of relief from certain Kazakhstani corporate taxes. However, the firm's tax position in its ultimate ownership jurisdiction – whether a UAE holding company, a BVI structure or a family-office vehicle – is determined by the rules applicable there. Where the AIFC entity passes funds through to a parent or related-party entity in another jurisdiction, transfer-pricing documentation and substance requirements apply. A sanctions hold on a transaction can create an unanticipated tax event if the delayed or blocked settlement crosses a period end.

For a business sitting between the AIFC and a European or Asian operating entity, the legal question turns on which jurisdiction's requirements govern each leg of the structure. The answer is rarely one jurisdiction's rules alone. In our practice, operators who structure the AIFC entity in isolation – without mapping the banking, tax and sanctions obligations of the related entities above and below it – regularly encounter compliance friction that was avoidable at the design stage.

How AFSA sanctions exposure surfaced in a recent cross-border matter

In a recent matter, a digital-asset custody firm operating under AIFC authorisation onboarded a fund vehicle structured through a third jurisdiction. The firm's sanctions-screening programme matched against the registered name of the fund and its primary GP entity, returning no alerts. A blockchain analytics review of wallet history – conducted as part of our compliance mapping work – identified that one of the fund's underlying LPs had transacted through a wallet cluster associated with a designated party. The firm had no obligation-triggering event under its existing procedure because the LP-level beneficial owner was not captured in its onboarding KYC chain. We restructured the onboarding procedure to require LP-level UBO disclosure for fund vehicles above a defined AUM threshold, updated the screening policy to incorporate the relevant designation list, and prepared the documented rationale required for the AFSA compliance file. The firm retained its banking relationship and avoided the enforcement referral that a post-incident review would otherwise have generated.

What are the decision points before committing to an AIFC digital-asset structure?

An operator considering the AIFC as a base for digital-asset activity faces three sequential decision points on the sanctions and AML side before authorisation is sought.

The first decision point is activity perimeter mapping. The firm must determine which of its proposed activities fall within the AFSA's regulated perimeter and which do not. This determines the scope of the AML and sanctions programme required, the MLRO appointment obligations and the reporting channels that must be established before the firm is live.

The second decision point is list and corridor selection. A firm with a genuinely global user base – clients in the EU, Southeast Asia, the Gulf and the CIS region – will face a more complex list-governance challenge than a firm serving a defined corridor. The UN, OFAC, EU and UK lists are the baseline. Secondary lists – the AIFC's own high-risk country designations, national FIU lists and counterpart lists applied by the firm's correspondent banks – must be identified, assessed and incorporated or excluded with written justification. This exercise cannot be delegated entirely to a vendor; it requires legal input.

The third decision point is the MLRO and escalation architecture. The AFSA requires that a responsible person be appointed with clear authority and documented procedures for sanctions hits, suspicious-activity reports and Travel Rule exception handling. For a startup or a firm moving from a lighter-touch offshore jurisdiction, the gap between what the AFSA expects of an MLRO and what the firm currently has in place can be significant.

A profile-based summary of the decision logic:

An exchange or trading facility moving from a lighter regime into the AIFC should build its compliance programme from scratch against AFSA expectations rather than porting an existing policy. The legacy policy will almost certainly not address on-chain analytics integration or AIFC-specific reporting channels.

A custody service with institutional counterparties should weight its programme toward UBO capture at the fund-vehicle level and toward blockchain-forensics integration, given that the most frequent sanctions breach in the custody context involves LP-level exposure rather than counterparty-level exposure.

A token issuer using an AIFC placement agent should obtain a legal opinion on the scope of its own obligations before assuming that the agent's compliance programme covers its exposure entirely.

If a prior compliance assessment stalled or a banking relationship was closed, a structural review can identify the root cause and the route back. Contact OBOLUS at info@oboluslaw.com. A second read of the compliance architecture regularly surfaces the specific gap that a first review missed.

Is a single AIFC licence sufficient for global digital-asset operations?

A common assumption in the market is that AIFC authorisation, once obtained, provides a stable compliance base for serving clients in any jurisdiction. That assumption is incorrect in three respects. First, the AIFC licence governs the firm's regulated activities within the AIFC perimeter. It does not create a passporting right into the EU, Singapore, Hong Kong or any other major regulated market. An AIFC firm accepting clients in MiCA-regulated jurisdictions must assess its obligations under the applicable MiCA provisions; an AIFC firm accepting clients in Singapore must assess its obligations under the MAS Payment Services Act. Second, the firm's correspondent banking relationships are governed by the banks' own compliance standards, which may be more demanding than the AIFC's minimum requirements on specific lists or corridors. Third, the Kazakhstani national AML regime applies in parallel for certain activities and counterparties, creating a dual-layer obligation that the AIFC regime alone does not resolve.

We map the licence stack across operating, custody and payment layers before a client commits to a structure, specifically to avoid the compliance friction that flows from treating the AIFC licence as a standalone solution. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – and the sanctions-screening architecture sits at the intersection of all three.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – derived from FATF Recommendation 16 as applied to virtual assets – requires a VASP to collect, verify and transmit originator and beneficiary information alongside each virtual-asset transfer above the applicable threshold. The data typically includes the sender's name, account reference and address information, and the equivalent data for the recipient. Under the AFSA framework and aligned regimes such as MiCA and the MAS Payment Services Act, a VASP must also have a procedure for handling transfers where the counterparty VASP cannot yet exchange structured Travel Rule data.

Who must act as MLRO for a crypto firm?

Under the AFSA framework, a licensed digital-asset firm is required to appoint a Money Laundering Reporting Officer with sufficient seniority, independence and documented authority to receive internal suspicious-activity reports, make external reports to the designated channel and oversee the firm's AML and sanctions programme. The MLRO carries personal accountability for the adequacy of escalation records. The role may be held by an employee or, in certain circumstances and with AFSA consent, by an outsourced function – but the accountability cannot be outsourced with it.

How do regulators audit crypto AML programs?

AFSA supervisory reviews of crypto AML programmes typically involve a request for the firm's current risk assessment, its AML and sanctions policies, its KYC and onboarding procedures, a sample of client files demonstrating that procedures were followed, transaction-monitoring alert records and escalation logs. Regulators assess whether controls are documented, whether they are actually applied and whether the documented rationale for list selection and risk appetite is coherent. Blockchain analytics usage and Travel Rule implementation are increasingly standard review items in leading hubs, including the AIFC.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, sanctions screening and compliance architecture that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack as a single mandate, not three disconnected workstreams – and we engage allied counsel in every relevant jurisdiction where local overlay is required. To discuss your AIFC compliance structure, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme design, sanctions architecture and AFSA supervisory readiness for AIFC-registered digital-asset firms.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours