EST · MMXXVI
Home/Jurisdictions/Liechtenstein/MLRO and compliance officer function in Liechtenstein
Compliance, AML & Travel Rule

MLRO and compliance officer function in Liechtenstein

Mlro and compliance officer function in Liechtenstein. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

Liechtenstein has built one of the most precisely drafted virtual asset regulatory regimes in Europe. Under the Token and Trusted Technology Service Provider Act (known as the TVTG, or colloquially as the Blockchain Act), any business that offers token-related services in or from Liechtenstein must register with the Financial Market Authority Liechtenstein (FMA). That registration triggers a full set of AML/CFT obligations – and at the centre of every compliant operation sit two roles: the Money Laundering Reporting Officer (MLRO) and the compliance officer. Get those functions wrong and the FMA can suspend operations, revoke registration and refer the matter to the Liechtenstein public prosecutor. The consequences travel beyond the principality. A compliance failure in Liechtenstein can destabilise banking relationships across the EEA, impair a MiCA passporting strategy and expose the group to correspondent-bank scrutiny internationally. This page sets out what the law requires, how the roles must be structured, and what cross-border operators need to plan before they go live.

Why Liechtenstein Matters for Digital-Asset Compliance

Liechtenstein enacted the TVTG ahead of most European peers, giving token-based businesses a clear statutory basis to operate. The regime recognises a wide range of token service providers – from token issuers and exchange platforms to custody agents and payment-token services – and aligns their obligations with the FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer). Because Liechtenstein is part of the European Economic Area, FMA-registered businesses benefit from a degree of regulatory equivalence that a purely offshore structure cannot replicate. That EEA status also means that when MiCA's CASP passporting regime applies in full, the principality is positioned to become an even more significant entry point for businesses seeking EU-wide reach from a compact, well-regulated base.

Operators we advise regularly underestimate how quickly the FMA moves from registration review to supervisory examination. Unlike some larger jurisdictions where the first post-registration audit is measured in years, the FMA is a small regulator with a focused mandate. It knows its registered population and it follows up. A firm that appoints a nominal MLRO without genuine operational authority will find that gap exposed rapidly.

The FMA supervises registered token service providers under both the TVTG and the Liechtenstein Due Diligence Act (Sorgfaltspflichtgesetz, or SPG), which implements the relevant EU AML directives into domestic law. The interaction between those two instruments is where most compliance programmes go wrong.

Who Needs an MLRO and Compliance Officer Under Liechtenstein Law?

Any entity registered as a token service provider under the TVTG and subject to AML obligations under the SPG must designate at least one person responsible for AML/CFT compliance – the MLRO – and, in practice, a separate compliance officer responsible for the broader regulatory programme. The FMA expects these functions to be distinct in firms of any meaningful size. A sole-trader or micro-entity may consolidate the roles, but that consolidation must be documented and justified to the regulator; it is not assumed.

The MLRO obligation is not unique to Liechtenstein, but the principality's approach carries specific local nuances. The MLRO must be:

  • A natural person who is resident or otherwise sufficiently accessible to the FMA for supervisory contact.
  • Sufficiently senior to receive and act on suspicious-transaction reports without referral to a line manager – a structural independence requirement that cannot be satisfied by a junior operations hire.
  • Knowledgeable about the firm's specific token services, not merely generic AML process.

For inbound operators – businesses headquartered outside Liechtenstein that register a subsidiary or branch in the principality – the FMA will scrutinise whether the nominated MLRO actually controls the compliance function or is merely a figurehead for a team operating elsewhere. In our cross-border practice, we have seen applications stall precisely because the proposed MLRO was based in a different time zone with no delegated authority to file reports or suspend transactions locally. That structure will not pass the FMA's substance test.

What Does the MLRO Function Require in Practice?

The MLRO in a Liechtenstein token service provider is the primary point of contact between the firm and the FMA's Financial Intelligence Unit (FIU) for suspicious transaction reporting, and the person accountable for the firm's compliance with the SPG on a day-to-day basis. The role encompasses four core functions:

  1. Suspicious Activity Reporting (SAR): Receiving internal reports from staff, assessing them and filing disclosures with the FIU as required under the SPG. The MLRO must have genuine authority to suspend a transaction pending review – that authority must be documented in the firm's governance framework.
  2. KYC/CDD oversight: Ensuring that the firm's know-your-customer (KYC) and customer due diligence (CDD) processes meet the risk-based requirements set by the FMA. For token service providers, this includes enhanced due diligence for high-risk counterparties and politically exposed persons (PEPs).
  3. Travel Rule implementation: Under the applicable provisions implementing FATF Recommendation 15 and the EU Funds Transfer Regulation as applied to crypto assets, the MLRO is accountable for ensuring that originator and beneficiary information travels with every qualifying virtual-asset transfer. The de-minimis threshold and the technical solution for data transmission both require active governance, not a set-and-forget technical implementation.
  4. Staff training and culture: The SPG requires periodic AML training for all relevant staff. The MLRO is typically responsible for designing and evidencing that programme.

In our practice, we regularly advise firms that have deployed sophisticated transaction-monitoring software but have not documented who reviews the alerts, at what frequency and by what escalation path. The FMA is not satisfied by the existence of a tool; it wants to see the governance around it.

CTA #1

If you are registering a token service provider with the FMA and need to structure the MLRO and compliance function correctly from day one, the process above describes the standard path. Your facts – the entity structure, the user base, the jurisdictions from which customers are onboarded – change the analysis materially. Map your options with our team at info@oboluslaw.com.

Compliance Officer vs. MLRO: How the Roles Interact

The compliance officer carries broader accountability than the MLRO, though the two roles overlap significantly in a small firm. Where they differ most is scope: the MLRO owns the AML/CFT programme specifically, while the compliance officer is responsible for the firm's adherence to the full TVTG and FMA regulatory perimeter – licence conditions, conduct rules, reporting obligations and governance standards.

A workable division in a mid-sized token service provider typically looks as follows. The MLRO manages the FIU relationship, owns the SAR process and chairs the AML governance committee. The compliance officer owns the regulatory calendar (FMA reporting deadlines, licence renewals, changes of control notifications), monitors regulatory development – particularly the MiCA transition and any FATF guidance updates – and manages the compliance testing programme that feeds back into MLRO-owned policies.

Neither role can be purely administrative. The FMA expects both to have genuine decision-making authority. If either individual requires sign-off from a commercial line manager to suspend onboarding or file a suspicious-activity report, the independence requirement has not been met.

Cross-Border Complexity: Where Liechtenstein Sits in a Multi-Jurisdiction Stack

Operating a token service provider from Liechtenstein rarely means operating only in Liechtenstein. Most firms using the TVTG regime serve customers across the EEA, hold assets through custodians in Switzerland or Luxembourg, and bank through correspondent relationships in Austria, Germany or beyond. Each of those connections adds a compliance layer.

The Swiss banking corridor is particularly important. Many FMA-registered firms maintain their principal banking relationships with Swiss-regulated banks. Those banks apply FINMA's expectations on VASP due diligence – expectations that may differ from the FMA's in emphasis and in the level of documentation required. The MLRO must understand both regimes. A Travel Rule compliance programme built purely to satisfy the FMA may not satisfy the Swiss bank's correspondent-bank onboarding requirements, and vice versa.

Similarly, where the group holds a parallel MiCA CASP authorisation in another EEA member state, the group MLRO structure must reconcile potentially differing national implementations of the EU AML Directive. In our cross-border practice, we have seen groups nominate a single "group MLRO" without appointing a local Liechtenstein MLRO with genuine authority. That structure works only if the FMA is satisfied that the group MLRO is sufficiently accessible and operationally in control of the Liechtenstein entity's compliance programme. Absent that satisfaction, the FMA will require a separate local appointment.

For firms with a US nexus – whether through dollar-denominated stablecoins, US-domiciled investors or FinCEN reporting obligations – the compliance officer must also map the interaction between the SPG's requirements and the applicable FinCEN rules. Those two regimes share FATF ancestry but diverge in their treatment of certain DeFi activities and in their approach to de-risking.

How Does the FMA Assess MLRO and Compliance Officer Appointments?

The FMA reviews MLRO and compliance officer appointments as part of the initial TVTG registration and again whenever either role changes. The assessment focuses on three axes: fitness, properness and operational capacity.

Fitness requires demonstrable knowledge of AML/CFT law and of the specific token services the firm provides. A CV listing generic banking compliance experience will attract follow-up questions if it does not evidence familiarity with virtual-asset specific risks – unhosted wallets, cross-chain bridge exposure, mixing-service red flags and the like.

Properness is a conduct history check. Prior regulatory sanctions, criminal convictions or directorial disqualifications in any jurisdiction will be reviewed. For inbound operators, the FMA will expect documentation from the home jurisdiction as well as from Liechtenstein.

Operational capacity is the element most frequently underweighted. The FMA will ask how many firms the proposed MLRO serves in that capacity. An individual acting as MLRO for a large number of registered entities will face scepticism about whether the role can be discharged properly at any of them. The FMA has publicly signalled concern about compliance-officer outsourcing arrangements that dilute effective oversight.

The timeline from a complete application to FMA approval varies by complexity. Where the MLRO profile is strong, the firm's AML policies are well-drafted and the governance documentation is complete, approval can be measured in weeks. Gaps in any of those areas extend the process, sometimes materially.

A Recent Cross-Border Compliance Matter

In a recent Liechtenstein registration matter, a payment-token service provider expanding from a non-EEA base had appointed a group compliance officer resident outside the principality. The FMA raised concerns about the individual's accessibility and about whether the firm's Travel Rule solution – which had been designed for a different jurisdiction's de-minimis threshold – satisfied the SPG. We advised on restructuring the MLRO appointment to a Liechtenstein-based individual with explicit delegated authority over transaction suspension, rewrote the AML policy suite to reflect FMA expectations, and calibrated the Travel Rule programme to the applicable EEA threshold. Registration completed within a quarter of the original projected timeline after those adjustments were in place.

CTA #2

If a prior FMA application stalled or your MLRO appointment was queried, a structured review can identify the specific gap and the path to resolution. A second read often surfaces the structural issue quickly. Write to us at info@oboluslaw.com or message t.me/oboluslaw to discuss.

What Are the Most Common Compliance Failures the FMA Identifies?

The FMA's supervisory priorities in the virtual-asset sector cluster around five recurring failures. Each has a structural cause and a structural remedy.

  • Nominal MLRO appointments. The individual on paper has no operational authority and no dedicated time. The remedy is a written delegation of authority, a defined time commitment and direct access to the board.
  • Travel Rule gaps. The firm has a Travel Rule solution but has not tested it against the counterparties it actually transacts with. Unhosted-wallet transactions in particular require a documented policy, not just a software switch. The Travel Rule obligation under the applicable EEA regime applies regardless of whether the counterparty VASP is cooperative.
  • Inadequate transaction-monitoring calibration. Alert thresholds set to default values at deployment, never adjusted for the firm's specific transaction profile and risk appetite.
  • Outsourced compliance without retained oversight. Third-party compliance providers are not prohibited, but the MLRO cannot outsource the judgment function. The FMA expects the appointed MLRO to be able to explain every material compliance decision.
  • KYC refresh failures. Periodic reviews of existing customer files are required. Many firms complete strong onboarding KYC but do not run periodic refresh reviews on long-standing customers whose risk profile may have changed.

A common assumption in the market is that technology solves compliance. It does not. Technology supports the compliance function; the MLRO and compliance officer provide the judgment, the governance and the accountability that no software product can substitute.

Which Operator Profile Needs What Compliance Structure?

The right structure depends on firm size, service scope and group architecture. Three profiles illustrate the decision points.

Profile A – Single-entity startup, Liechtenstein-only registration, narrow token service. A combined MLRO/compliance officer role may be acceptable to the FMA if the individual is sufficiently senior and has genuine authority. The risk is concentration: illness or departure of one person suspends effective compliance. For this profile, a documented deputisation arrangement and a clear succession plan are essential from day one. Timeline to satisfactory FMA appointment: measured in weeks, assuming a strong individual candidate.

Profile B – EEA-facing operator using Liechtenstein as the group's primary registration point, with a parallel MiCA CASP application pending. A dedicated local MLRO with operational authority in Liechtenstein, supported by a group compliance function, is the minimum viable structure. The group compliance officer can coordinate across jurisdictions, but the local MLRO must be identifiable, accessible and genuinely in control of the Liechtenstein programme. Timeline and capital commitments will reflect the MiCA CASP requirements alongside the TVTG registration.

Profile C – Non-EEA group using a Liechtenstein subsidiary as a regulated EEA gateway, with significant transaction volume and cross-border customer bases. A full compliance team – including a dedicated MLRO, a compliance officer, a deputy MLRO and a technology-and-monitoring specialist – is both commercially prudent and likely expected by the FMA given the operational scale. Outsourced compliance support is appropriate for specialist tasks (forensic investigation, Travel Rule technical implementation), but core governance must remain in-house. The cross-border interaction with Swiss banking and the US FinCEN perimeter requires the compliance officer to carry multi-jurisdictional expertise, not merely Liechtenstein-specific knowledge. Indicative build-out: a matter of several months to recruit, document, test and evidence the programme to FMA standards.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule obliges a virtual asset service provider (VASP) to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual-asset transfer. In the EEA, the obligation is implemented through the applicable Funds Transfer Regulation provisions and FATF Recommendation 15. In practice, this means the originating VASP must pass the sender's and recipient's identifying data to the receiving VASP before or at the point of transfer. The applicable de-minimis threshold varies by jurisdiction; above it, no exemption applies simply because the counterparty is uncooperative or unhosted.

Who must act as MLRO for a crypto firm?

The MLRO must be a sufficiently senior natural person with genuine authority to receive internal suspicious-activity reports, assess them independently and file disclosures with the relevant financial intelligence unit. In Liechtenstein, the FMA expects the MLRO to be accessible for supervisory contact, knowledgeable about the specific token services the firm provides and structurally independent of commercial line management. An individual serving as MLRO across a large number of entities simultaneously will attract scrutiny about capacity. The role cannot be effectively discharged on a purely nominal basis.

How do regulators audit crypto AML programs?

Regulators – including the FMA in Liechtenstein – typically audit AML programmes through a combination of document review, transaction testing and interviews with the MLRO and compliance officer. They examine whether policies match actual operational practice, whether transaction-monitoring alerts are reviewed on a documented schedule and whether suspicious-activity reports are filed promptly and correctly. Staff training records, KYC file quality and Travel Rule compliance logs are all within scope. The audit may be triggered by the annual supervisory cycle, by a change in the firm's registration, or by a specific concern raised by an FIU referral or a banking counterparty query.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programmes that sit around them. Digital assets are the whole of our practice. We map the licence and compliance stack – including the MLRO and compliance officer structure – across operating, custody and payment layers before you commit, so your registration is built to survive its first FMA audit. To discuss your Liechtenstein or cross-border compliance situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme design, MLRO function structuring and VASP regulatory compliance across the EEA and beyond.

Want a scoped assessment of your MLRO structure and AML programme before the FMA reviews it? Write to us at info@oboluslaw.com or message us via t.me/oboluslaw.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours