EST · MMXXVI
Home/Jurisdictions/Liechtenstein/AML/cft policy drafting in Liechtenstein
Compliance, AML & Travel Rule

AML/cft policy drafting in Liechtenstein

Aml/cft policy drafting in Liechtenstein. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Liechtenstein sits at the intersection of Swiss financial infrastructure and European regulatory law. Its Token and Trusted Technology Service Providers Act – commonly called the TVTG – made the principality one of the first jurisdictions anywhere to regulate the full lifecycle of token-based business. That legal clarity attracts serious operators. It also attracts scrutiny. The Financial Market Authority (FMA Liechtenstein), which supervises anti-money-laundering compliance for digital-asset firms, expects AML/CFT policy documentation that matches the sophistication of the business – not a template lifted from a bank's compliance manual.

Operating without adequate AML/CFT policies in Liechtenstein exposes a licensed firm to supervisory action, remediation orders and, in the worst case, suspension of the licence that took months to obtain. For a business whose banking rails run through Swiss correspondents – as most Liechtenstein-licensed crypto firms' do – a regulator's letter to the bank is often more damaging than a formal fine. The stakes are high from day one.

This page sets out the regulated basis for AML/CFT compliance in Liechtenstein, the practical content of a compliant policy suite, the cross-border interactions that shape those policies, and the decision points at which external counsel materially reduces risk.

The Regulated Basis: TVTG, the Due Diligence Act and FATF

Liechtenstein's AML/CFT regime for crypto firms rests on three interlocking instruments. The TVTG establishes the category of regulated token service provider and creates the licensing obligation. The Due Diligence Act (Sorgfaltspflichtgesetz, or SPG) imposes the substantive AML obligations – know-your-customer identification, beneficial ownership verification, transaction monitoring, record-keeping and suspicious activity reporting. The FMA Liechtenstein administers both.

Above those domestic instruments sits the FATF framework. Liechtenstein is a member of MONEYVAL, the Council of Europe's AML evaluation body, and its regime is calibrated to satisfy FATF Recommendation 15, which requires that virtual asset service providers – known as VASPs (entities that exchange, transfer or otherwise deal in virtual assets for clients) – be regulated and supervised for AML/CFT purposes. The consequence is that any gap between a firm's written policies and FATF's expectations for VASPs is not just a local compliance problem; it signals a systemic weakness that MONEYVAL evaluators will flag during the next mutual evaluation cycle.

In our cross-border practice, we consistently see operators underestimate how closely FMA Liechtenstein benchmarks its expectations against FATF guidance. A policy suite written to the minimum letter of the SPG without reference to FATF's VASP-specific risk factors will not pass a supervisory review.

What a Compliant AML/CFT Policy Suite Looks Like

A compliant policy suite for a Liechtenstein-licensed VASP is not a single document; it is a coordinated set of instruments that together cover every obligation the SPG and the FMA's supervisory expectations impose.

At minimum, the suite addresses the following areas. A risk assessment is the foundation: the firm must document the specific AML/CFT risks its business model generates, referencing product type, customer base, geographies served and delivery channels. A customer due diligence (CDD) policy specifies identification requirements for natural and legal persons, enhanced due diligence triggers for high-risk customers and business relationships, and simplified diligence where the regime permits. A beneficial ownership policy sets out how the firm looks through corporate structures to identify ultimate controlling persons – a particular point of FMA focus for firms serving institutional clients or structuring products.

A transaction monitoring policy defines the rule sets and behavioral thresholds the firm uses to detect suspicious activity, together with the escalation path from alert to investigation to suspicious activity report (SAR). A Travel Rule compliance policy – discussed separately below – governs the originator and beneficiary data the firm must collect and transmit with transfers. Finally, a record-keeping and training policy anchors the documentation and staff-competency obligations that the SPG requires and that FMA inspectors verify through file reviews.

Each policy document must be owned, dated, version-controlled and approved by a named member of senior management. FMA Liechtenstein has, in our experience, declined to accept policies that are undated, missing a named approver or drafted in a language the firm's compliance staff cannot demonstrate they understand.

To have your existing policy suite gap-assessed against FMA's current expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard architecture. Your business model, customer mix and cross-border footprint will change the analysis materially.

How Does the Travel Rule Apply to Liechtenstein VASPs?

The Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual asset transfer – is one of the most operationally demanding requirements a VASP faces, and Liechtenstein's implementation is strict.

Under the FATF framework as implemented in Liechtenstein, a VASP must collect and transmit identifying information about the sending customer and the intended recipient when a transfer meets the applicable threshold. Where the counterparty is another regulated VASP, the data must be transmitted securely and the receiving VASP must verify and hold it. Where the counterparty is an unhosted wallet (a wallet not held at a regulated institution), the firm must apply additional measures to establish that the wallet belongs to the customer or to a third party whose identity it has verified.

FMA Liechtenstein requires that a firm's Travel Rule policy specify the technical solution it uses – whether a VASP-to-VASP messaging protocol or another accepted method – the escalation procedure where counterparty data cannot be obtained, and the controls applied to unhosted wallets. A policy that states the obligation without specifying the operational procedure does not satisfy the expectation.

The cross-border complexity here is substantial. A Liechtenstein VASP serving customers across the EU, the UK and Asia is interacting with counterparty VASPs under at least three distinct Travel Rule regimes. The policy must acknowledge this reality and set out how the firm manages data exchange with VASPs operating under the MiCA regime, the FCA's UK rules and, for example, the MAS Payment Services Act in Singapore – each of which sets slightly different data-field and timing requirements. Operators we advise routinely discover that their Travel Rule policy was written for a single jurisdiction and does not map to the actual counterparty mix their transaction flow produces.

The MLRO Requirement and Governance Structure

Every VASP licensed under the TVTG must designate a Money Laundering Reporting Officer (MLRO) – a named individual responsible for receiving internal suspicious activity reports, filing external reports to the Financial Intelligence Unit (FIU), and acting as the point of contact for FMA Liechtenstein on AML matters.

The MLRO role carries personal exposure. An MLRO who approves a deficient policy, fails to file a SAR where the obligation is triggered, or cannot demonstrate active oversight of the transaction monitoring program is not protected by the corporate form. FMA Liechtenstein scrutinizes the MLRO's qualifications, the independence of the function from revenue-generating business lines, and the adequacy of the resources the firm has committed to the compliance function.

In practice, small and mid-size firms face a structural tension: the founders who best understand the business are often the same people the regulator requires to demonstrate independence from it. Where a firm lacks a suitably qualified in-house candidate for the MLRO role, the FMA has historically accepted an outsourced or contracted MLRO arrangement – but only if the individual is genuinely reachable, genuinely informed and genuinely empowered to escalate and report. A nominal appointment does not satisfy the expectation.

We have worked with founding teams in Liechtenstein who initially structured the MLRO role as a part-time addition to a development or operations role. In each case, the policy documentation reflected the governance the firm intended, not the governance it had actually built. Aligning the two – before the FMA's first supervisory review – is a material risk reduction step.

Cross-Border Interaction: Swiss Banking, EU Passporting and Tax

Liechtenstein's position creates a distinctive cross-border compliance architecture. The principality is part of the European Economic Area but uses the Swiss franc and is closely integrated with the Swiss banking system. A Liechtenstein VASP therefore often holds its operational and client accounts at Swiss banks, whose own AML compliance programs – supervised by FINMA – are demanding and closely watched.

Swiss correspondent banks apply their own due diligence to the Liechtenstein VASP as a customer. They will ask to review the firm's AML/CFT policies, its customer risk assessment methodology and, increasingly, its Travel Rule solution. A policy suite that satisfies FMA Liechtenstein on its face but cannot answer a Swiss bank's questionnaire will create banking difficulties that no amount of regulatory goodwill resolves. We map both the FMA expectation and the Swiss banking due diligence requirement in parallel when drafting for Liechtenstein-based clients.

On the EU side, a TVTG-licensed firm operating services into EU member states must consider whether its activities trigger the MiCA authorisation requirement for cross-border CASP services. The TVTG and MiCA are not identical regimes, and the equivalence question is not yet settled. The AML/CFT policy must be drafted with awareness of this ambiguity: if the firm takes on EU-resident clients at scale, the policy must be capable of satisfying MiCA-aligned supervisory review as well as FMA Liechtenstein's standard.

From a tax perspective, Liechtenstein's regime taxes resident entities on their worldwide income. The interaction between AML record-keeping obligations – which require the retention of transaction and customer data for an extended period – and tax reporting requirements for token transactions is a compliance design question that the firm's policies must address consistently. A transaction record kept for AML purposes but structured in a way that is inconsistent with the firm's tax reporting position creates an internal contradiction that both the FMA and the tax authority can exploit.

How the Process Works in Practice

In a recent engagement, a digital-asset exchange holding a TVTG authorisation approached us after the FMA issued a remediation notice following its first post-licensing supervisory review. The firm had a set of AML/CFT policies drafted at the time of the licence application, but those policies had not been updated to reflect the expansion of the firm's product line into token lending. The transaction monitoring rules were calibrated for exchange activity only; the lending product introduced a new risk typology – the extension and repayment of virtual-asset credit – that the existing rule set did not cover.

We conducted a gap analysis against the SPG, FMA supervisory guidance and FATF's VASP risk assessment methodology, then drafted a revised policy suite that addressed the lending product specifically, introduced enhanced due diligence triggers for large credit exposures and documented the MLRO's governance sign-off on the revised program. The firm submitted the updated documentation within the FMA's remediation window. The supervisory notice was closed. The lesson was clear: AML/CFT policies must be living documents, updated whenever the business model changes – not a one-time condition of the licence application.

What Goes Wrong: Common Drafting and Implementation Failures

Regulators in the leading hubs – including FMA Liechtenstein – have documented the failure modes they encounter most frequently. In our cross-border practice, the pattern is consistent.

The first and most common failure is the template policy: a document that describes a generic VASP business rather than the specific firm that signed it. Generic risk assessments, generic customer profiles and generic transaction monitoring thresholds signal to an examiner that the compliance function has not actually engaged with the firm's business. The FMA will ask questions that a generic policy cannot answer.

The second failure is policy drift: the business evolves – new products, new geographies, new customer segments – and the policies do not. In Liechtenstein, the FMA expects policies to be reviewed and, where necessary, updated at least annually and on each material change to the business. That review must be documented.

The third failure is governance without substance: a policy approves the MLRO's name and title but does not reflect a function that is actually resourced and active. The FMA assesses the MLRO's awareness of the firm's risk profile, the volume and quality of internal suspicious activity reports, and the timeliness of external reporting. A nominal governance structure that looks adequate on paper but is empty in practice is the failure mode that generates the most severe supervisory responses.

A fourth and increasingly prominent failure is the unhosted wallet gap: Travel Rule policies that address VASP-to-VASP transfers competently but say nothing coherent about the firm's obligations when a customer withdraws to a private wallet. With regulators across the EEA tightening expectations on this point, a policy that omits or vaguely addresses unhosted wallets is a predictable finding.

If a prior supervisory review raised findings, or if a banking partner has requested updated compliance documentation, OBOLUS can scope a policy revision rapidly. Write to info@oboluslaw.com with a brief description of the situation and we will propose a structured approach within one business day.

Decision Matrix: Which Profile Needs What Level of Policy Work

Not every Liechtenstein VASP faces the same policy drafting task. The scope and depth of the work turns on business model, customer profile and the firm's stage of regulatory engagement.

A firm at the TVTG licence-application stage – with a single-product model serving a defined customer segment – needs a policy suite that is complete, internally consistent and tailored to the application facts. The primary risk is underspecification: policies that satisfy the FMA's checklist but do not address the product's actual risk typology. The indicative output is a six-to-eight document suite, reviewed against FMA guidance before submission.

A firm that has obtained its licence and is now scaling – adding products, adding geographies, growing its customer count – needs a policy update cycle built into its governance calendar. The risk here is drift. The indicative approach is a structured annual review with interim updates triggered by product or business model changes, and a standing Travel Rule policy that maps each counterparty jurisdiction's requirements.

A firm that has received a supervisory finding or a banking-relationship questionnaire it cannot adequately answer is in a different situation. Speed matters. The approach is a gap analysis first – typically completed within a matter of days – followed by targeted policy revisions prioritized by the FMA's or the bank's stated concerns. A full policy rewrite on this timeline is achievable; the constraint is the quality of the firm's existing documentation and its willingness to make the governance changes the revised policies imply.

An inbound operator considering Liechtenstein as its EU-adjacent licensing hub – rather than an operator already in the jurisdiction – needs to understand from the outset that the AML/CFT policy suite is a pre-licensing deliverable, not an afterthought. Firms that treat it as one will face FMA queries that delay the application timeline materially.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect identifying information about the originator and beneficiary of a virtual asset transfer and to transmit that data to the receiving VASP alongside the transfer. In Liechtenstein, this obligation flows from the FATF framework as implemented through the SPG and FMA supervisory guidance. The specific data fields, thresholds and technical transmission standards vary by the counterparty's jurisdiction, which means a compliant Travel Rule policy must map each relevant corridor individually rather than adopting a single universal approach.

Who must act as MLRO for a crypto firm?

The MLRO must be a named individual with sufficient seniority, independence and AML expertise to receive internal suspicious activity reports, file external reports to the FIU, and engage with FMA Liechtenstein on supervisory matters. The role cannot be held by a person who is simultaneously responsible for business development or revenue targets, as the independence requirement would be compromised. Small firms sometimes engage a contracted MLRO; the FMA accepts this where the individual is genuinely active and demonstrably informed about the firm's risk profile.

How do regulators audit crypto AML programs?

FMA Liechtenstein typically reviews AML/CFT programs through a combination of document requests and examiner interviews. Inspectors will ask for the current version of each policy, evidence that the MLRO has reviewed and approved it, a sample of customer due diligence files and transaction monitoring alerts, records of SAR filings, and evidence of staff training. A program that looks complete on paper but cannot be demonstrated through the underlying records – alert logs, file notes, training registers – will not satisfy the review. Remediation timelines are set by the regulator and are not negotiable once issued.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, AML and banking stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is at issue. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML/CFT policy architecture and supervisory engagement for VASP-licensed digital-asset businesses across European and EEA jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours