EST · MMXXVI
Home/Jurisdictions/Lithuania/AML and travel rule regime in Lithuania: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML and travel rule regime in Lithuania: Legal Requirements for Businesses

Aml and travel rule regime in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Lithuania established one of Europe's first dedicated virtual asset service provider (VASP) registration regimes, giving crypto businesses a fast-track entry point into the EU. Today, under the Bank of Lithuania's supervisory oversight and the transition toward full MiCA (Markets in Crypto-Assets Regulation) authorisation, that entry point carries real compliance weight. The Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer) and a structured AML/CFT (anti-money-laundering and countering the financing of terrorism) program are not optional extras – they are threshold conditions. Operating without them exposes the business to enforcement, frozen banking rails and regulatory deregistration.

This page sets out what the Lithuanian AML and Travel Rule regime requires, who it applies to, how an inbound business implements it, and where the cross-border complications arise. It is written for the compliance officer, general counsel or founder who needs the operational answer, not the academic overview.

Who Must Comply With Lithuania's AML Regime?

Every business registered as a VASP with the Bank of Lithuania is a reporting entity under the Lithuanian AML framework, which implements the EU's Anti-Money Laundering Directives (AMLD series) and the FATF Recommendations – specifically Recommendation 15, which brings virtual assets into the standard AML perimeter. The compliance obligation attaches to the entity at the moment of registration, not at the moment it processes its first transaction.

The category is broad. Exchanges converting fiat to crypto, custodians holding keys on behalf of clients, peer-to-peer platforms, and businesses providing transfer services all fall within scope. Businesses that merely hold tokens for their own account and do not provide services to third parties generally sit outside the definition – but the boundary is fact-specific and worth verifying before a structure is finalised.

Under the MiCA transition, entities that currently operate under the prior VASP regime will need to obtain a CASP (crypto-asset service provider) authorisation from a competent authority within the EU/EEA. Lithuania, as an EU member state, will require its existing VASPs to migrate to that authorisation standard. The AML obligations are continuous through that transition; there is no compliance gap.

In our practice, we regularly advise businesses that assumed the Lithuanian registration was a light-touch AML exercise. The Bank of Lithuania's supervisory posture has hardened considerably over recent years. Examiners now expect documented policies, tested systems and a functioning MLRO (money laundering reporting officer) before – not after – a business begins taking client funds.

For a scoped assessment of your compliance position under the Lithuanian regime, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the banking counterparties – change the analysis materially.

What Must an AML Program Contain?

A compliant AML program for a Lithuanian VASP must cover five operational pillars: a risk assessment, written policies and procedures, customer due diligence (CDD) and KYC (know-your-customer) frameworks, transaction monitoring, and an internal reporting structure headed by a designated MLRO.

The risk assessment is the foundation. It must be documented, business-specific and reviewed when the product or customer base changes. Generic template risk assessments that do not reflect the actual token types, geographies and channel mix of the business consistently fail supervisory scrutiny. The Bank of Lithuania has the authority to demand the underlying analysis, not just a summary conclusion.

CDD applies at onboarding and on a risk-rated ongoing basis. For higher-risk clients – those in higher-risk jurisdictions, politically exposed persons (PEPs), or clients exhibiting unusual transaction patterns – enhanced due diligence (EDD) applies. The threshold logic for triggering EDD mirrors the FATF standard: it is risk-based, not purely transactional-value-based.

Transaction monitoring must be calibrated to the specific risk profile of the business. Rules-based systems are common, but regulators across leading EU hubs increasingly expect a demonstrated rationale for the rules chosen and a periodic review of their effectiveness. Alerts must be investigated, decisions documented, and suspicious activity reported to the FCIS (Financial Crime Investigation Service), which is Lithuania's financial intelligence unit. The FCIS is the designated recipient of suspicious activity reports (SARs) under Lithuanian law.

The MLRO must be a natural person with genuine authority, competence and independence from the business line. This is not a title that can be held by the CEO as a formality. Examiners look for evidence that the MLRO has the access, resources and internal standing to escalate concerns and, where necessary, file a SAR without commercial interference.

How Does the Travel Rule Apply to Lithuanian VASPs?

The Travel Rule requires a VASP sending a virtual asset transfer to collect, verify and transmit originator and beneficiary data to the receiving VASP, and requires the receiving VASP to record that data. Lithuania implements the Travel Rule through its transposition of the EU's Transfer of Funds Regulation (TFR), which extends the Travel Rule to all virtual asset transfers regardless of transaction size – a stricter standard than the FATF baseline, which sets a de-minimis threshold. The practical effect is that Lithuanian VASPs must capture and transmit Travel Rule data on every transfer, with no de-minimis floor.

The data fields required include: the originator's name, account identifier or wallet address, and – for transfers above the relevant threshold – address and identification number. On the beneficiary side, the receiving VASP must capture name and account identifier at minimum. The standard is designed to mirror the wire-transfer data rules that apply in traditional finance.

Implementation raises two immediate operational questions. First, how does the VASP communicate Travel Rule data to a counterparty VASP that may be in a different jurisdiction with a different implementation standard? Second, what happens when the counterparty VASP is unhosted – that is, a self-custodied wallet? On the first question, several interoperability protocols have emerged in the industry (IVMS 101 is the messaging standard most commonly referenced). On the second, EU-level guidance and the Bank of Lithuania's own supervisory expectations require enhanced due diligence for transfers to or from unhosted wallets above the relevant threshold, including ownership verification steps.

We have seen businesses underestimate the operational lift here. Connecting to a Travel Rule messaging network, mapping counterparty VASPs, and building an exception-handling process for non-compliant or unhosted counterparties takes meaningful development and legal work. Starting that process after client onboarding begins is too late.

What Happens When the Business Operates Across Borders?

A Lithuanian VASP that serves clients in Germany, the Netherlands and the UK simultaneously does not operate in one AML environment – it operates in several, each with national-level implementation variations even within the EU's harmonised framework. The cross-border complexity is the part most frequently underestimated by businesses that obtained a Lithuanian registration primarily for speed.

Within the EU, MiCA passporting allows a CASP authorised in Lithuania to offer its services across all EU and EEA member states. The AML obligations, however, are not passported in the same way. Each member state may apply additional AML measures under the AMLD framework, and a business serving French or German clients may need to satisfy host-state supervisory expectations as well as those of the Bank of Lithuania as home-state supervisor.

The UK adds a separate layer. Post-Brexit, the UK's FCA (Financial Conduct Authority) operates its own cryptoasset registration under the Money Laundering Regulations, and its financial promotion rules apply to marketing directed at UK persons. A Lithuanian-registered VASP that markets to UK users without the appropriate FCA registration is exposed to UK enforcement risk regardless of its Lithuanian compliance status.

Banking is the practical chokepoint in all of this. Lithuanian banking for crypto businesses has tightened. Correspondent banking restrictions, IBAN discrimination concerns (flagged at the EU level) and the withdrawal of banking services from some categories of VASP have pushed many businesses toward alternative payments infrastructure or toward EU banking relationships in other jurisdictions. A business that does not account for banking resilience in its compliance and structure planning is solving half the problem.

Tax interaction is also real. The Lithuanian corporate tax environment is competitive within the EU, but the treatment of token issuance, staking income, and cross-border digital-asset transactions varies by activity type and treaty position. These are not purely compliance questions – they affect the entity structure and the licence stack.

If your prior application stalled or your banking relationship was closed, a structural review can surface the underlying reason and the route forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. A second read often identifies structural issues that were not visible the first time.

A Cross-Border AML Remediation: How Structural Gaps Surface

In a recent compliance remediation matter, a payments company registered in Lithuania as a VASP had built its AML program on a template policy it obtained from a service provider at incorporation. The Bank of Lithuania's supervisory review identified that the transaction monitoring rules had not been calibrated to the company's actual user base – which was concentrated in higher-risk jurisdictions – and that the MLRO lacked the authority to file SARs independently of senior management. We were instructed to rebuild the program: we rewrote the risk assessment, restructured the MLRO reporting line, and mapped the Travel Rule data flows against the company's technology stack. The business returned to full operational status within a matter of weeks of completing the remediation. The core lesson was not one of bad faith – the original policies were plausible on their face. The failure was one of calibration: a program built for a generic VASP, not for this specific business.

How Does an Inbound Business Get This Right?

An inbound business setting up AML and Travel Rule compliance for a Lithuanian VASP operation should work through six sequential steps, in this order.

The first step is entity and activity mapping. Before any policy is written, the business must be precise about what activities it will perform, in which jurisdictions, for which customer categories, and through which channels. The compliance architecture follows from that map – not the other way around.

The second step is risk assessment. A standalone, business-specific document. Not a generic one-pager. The Bank of Lithuania expects to see a risk assessment that reflects the specific risk factors of the business: product type, geography, customer profile, delivery channel and transaction volume range. Where a business cannot yet supply transaction volume data, it should present a modelled risk scenario based on its business plan.

The third step is policy development. Written AML, CDD, EDD, transaction monitoring and SAR policies that align with both Lithuanian law and the EU AMLD standards. Policies must also address the Travel Rule operationally – they should specify which messaging protocol the business uses, how counterparty VASP verification is handled, and what the exception process is for unhosted wallets.

The fourth step is technology implementation. This includes the transaction monitoring system, the Travel Rule messaging solution, and the CDD/KYC platform. The Bank of Lithuania does not prescribe a specific technology, but it expects demonstrably effective systems. Build choices made at this stage have long-term compliance implications.

The fifth step is MLRO appointment and training. The MLRO must be appointed before the business begins operating. Their mandate, authority, escalation paths and protected reporting rights should be documented in an internal charter. Training records for AML-relevant staff are also expected.

The sixth step is a pre-launch internal audit. An independent internal review of the full program before client onboarding begins. This is the point at which gaps are cheapest to fix.

What Are the Most Common AML Compliance Mistakes in Lithuania?

The most common mistake is treating the Lithuanian VASP registration as the end of the compliance exercise rather than the beginning. Registration is the permission to operate. The AML and Travel Rule obligations are the ongoing conditions of that permission.

A second frequent failure is the generic policy package. Many businesses arrive at their first Bank of Lithuania review with policies that were drafted for a different business model in a different jurisdiction and lightly adapted. Examiners identify these quickly. The substantive question they ask is whether the policies reflect what the business actually does.

A third error is MLRO under-resourcing. The MLRO role requires time, authority and competence. Assigning it as a collateral duty to a non-specialist – or to a director who also controls the commercial side of the business – creates structural independence problems that are difficult to remediate without organisational change.

A fourth issue is Travel Rule readiness being deferred. Businesses often plan to implement Travel Rule tooling after launch, once revenue is established. Under the EU's TFR implementation in Lithuania, that deferral is not legally available. The obligation applies from the first transfer. Deferral creates both a compliance exposure and a practical problem: retrofitting Travel Rule data flows into an existing technology stack is considerably harder than building them in from the outset.

A fifth pattern – one we observe regularly – is the assumption that a single offshore licence covers global operations. It does not. An offshore registration that is not recognised in the jurisdiction where the user sits, the bank operates or the exchange infrastructure is located creates gaps that enforcement agencies on both sides are increasingly willing to act on.

Which Profile of Business Should Consider Lithuania?

Lithuania remains a credible EU licensing and compliance base for the right operator profile. The Bank of Lithuania has well-established procedures, the local legal and compliance services market is developed, and the MiCA CASP authorisation pathway – when it crystallises – will carry EU passporting rights.

A business that is exchange-focused, has a predominantly EU user base and is prepared to invest in a properly resourced compliance function will find Lithuania a viable home. The CASP authorisation route, combined with a genuine AML and Travel Rule program, provides a defensible operating position across the EU/EEA.

A business that is primarily custody-oriented, has significant non-EU exposure, or operates at the intersection of DeFi protocols and regulated services should assess whether the Lithuanian regime's current regulatory interpretation of those activities is settled. In areas where supervisory guidance is still developing, the compliance build is harder to calibrate.

A business that wants to use a Lithuanian registration as a flag-of-convenience for global operations without a genuine compliance function will encounter enforcement risk not only in Lithuania but in every jurisdiction where its users sit. The cost of getting this wrong – enforcement, banking loss, reputational damage – materially exceeds the cost of getting it right at the outset.

In our cross-border practice, we map the licence stack across operating, custody and payment layers before a business commits to a jurisdiction. That mapping frequently reveals that Lithuania solves one part of the structure but requires allied counsel in adjacent jurisdictions to cover the full operating footprint.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP sending a virtual asset transfer to collect and transmit originator and beneficiary data – including names and account identifiers – to the receiving VASP. In Lithuania, the EU's Transfer of Funds Regulation applies this obligation to all transfers with no de-minimis floor. The receiving VASP must record and verify the data received. Failure to implement a functioning Travel Rule process is a direct compliance breach, not a procedural technicality.

Who must act as MLRO for a crypto firm?

The MLRO must be a natural person – typically a senior employee or officer – with genuine authority, appropriate AML competence and independence from the business line. In Lithuania, the MLRO is the designated point of contact for internal suspicious activity reports and for the FCIS. Regulators assess whether the MLRO has the practical standing to file a SAR without requiring commercial approval. Shared or purely nominal MLRO appointments consistently draw adverse supervisory findings.

How do regulators audit crypto AML programs?

The Bank of Lithuania audits AML programs by reviewing the underlying risk assessment, testing whether written policies reflect actual operations, and examining transaction monitoring alert-handling records and SAR filing histories. Examiners request evidence of MLRO independence and staff training. Remote and on-site reviews are both used. Under MiCA, supervisory coordination between national competent authorities and ESMA will add a cross-border audit dimension for CASPs passporting across the EU.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the full compliance stack before a business commits to a jurisdiction. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, Travel Rule implementation and supervisory engagement for digital-asset businesses in the EU and transitional VASP regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours