EST · MMXXVI
Home/Jurisdictions/Seychelles/MLRO and compliance officer function in Seychelles
Compliance, AML & Travel Rule

MLRO and compliance officer function in Seychelles

Mlro and compliance officer function in Seychelles. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a virtual asset service provider in Seychelles without a properly staffed MLRO function (Money Laundering Reporting Officer, the designated individual accountable for a firm's anti-money-laundering program) exposes a business to regulatory suspension, banking termination and personal liability for the officer who signs off on a deficient compliance architecture. Seychelles has built its VASP (virtual asset service provider) regulatory regime on the foundation of the Anti-Money Laundering Act and the accompanying VASP-specific legislation administered by the Financial Intelligence Unit (FIU) and the Financial Services Authority (FSA). As FATF pressure on offshore digital-asset jurisdictions intensifies, the FSA is tightening its supervisory posture – and every VASP must now demonstrate that its MLRO and compliance officer function is operationally real, not a paper appointment.

This page sets out the regulated basis for the MLRO and compliance officer requirement in Seychelles, the practical steps to structure that function correctly, the cross-border complications that arise when a Seychelles-registered VASP serves clients in multiple jurisdictions, and the decision points an operator must resolve before going live.

What is the regulatory basis for the MLRO requirement in Seychelles?

The MLRO obligation in Seychelles derives from the country's AML/CFT legislative architecture, which implements FATF Recommendation 15 on virtual assets and virtual asset service providers. The Financial Services Authority oversees the licensing and prudential supervision of VASPs, while the Financial Intelligence Unit holds jurisdiction over AML/CFT reporting obligations. A licensed VASP must appoint a natural person as MLRO; that appointment is a condition of licence, not an administrative formality. The FSA reviews the individual's fitness and propriety as part of the authorisation process, and subsequent changes to the MLRO must be notified and approved promptly.

The compliance officer function may, in larger organisations, be separated from the MLRO role. In practice, many Seychelles-incorporated VASPs combine both functions in a single individual, particularly at incorporation and in the early operating phase. Regulators have accepted this structure when the individual has demonstrable AML/CFT experience and when the firm's risk profile does not demand a segregated function. As transaction volumes grow, the FSA increasingly expects a cleaner separation.

Seychelles has ratified the relevant FATF commitments and has undergone mutual evaluation processes that scrutinise the effective implementation of those commitments at the individual obligated-entity level. The consequence for a VASP is direct: a licence that passes the paperwork stage but fails a supervisory examination because the MLRO is nominal generates enforcement outcomes that are difficult and expensive to reverse.

Who qualifies to serve as MLRO for a Seychelles VASP?

The FSA applies a fitness-and-propriety standard that assesses competence, experience and personal integrity, with the expectation that the appointee has a working knowledge of AML/CFT obligations as applied to virtual-asset businesses specifically. A compliance professional with a background in traditional financial services can satisfy this test, but the FSA expects evidence of familiarity with crypto-specific risk typologies – transaction monitoring of on-chain activity, Travel Rule compliance (the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data with a virtual-asset transfer above a defined threshold), and the KYC challenges posed by pseudonymous counterparties.

The MLRO does not have to be physically present in Seychelles. The FSA has permitted remote-based MLROs operating from other jurisdictions, provided they are genuinely available and accountable and that a local contact point is maintained for regulatory correspondence. However, an MLRO who is also performing this function for half a dozen other entities – a common offshore arrangement – is more likely to attract supervisory scepticism about actual availability and the depth of engagement with the firm's day-to-day risk profile.

In our cross-border practice, we have seen fitness-and-propriety queries delayed substantially where an MLRO's CV was not tailored to demonstrate virtual-asset-specific competence. A well-prepared submission maps the candidate's prior roles to each element of the FSA's stated criteria and includes evidence of relevant training or professional development in the digital-asset AML space.

For a scoped assessment of your MLRO appointment and compliance architecture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard regulatory path. Your entity structure, user base and existing personnel change the analysis materially. Map your options.

What must the MLRO's compliance program cover?

A Seychelles VASP's AML/CFT compliance program must address, at minimum, a written risk assessment of the business, a documented KYC framework, transaction monitoring procedures, a suspicious-transaction reporting mechanism to the FIU, and staff training. The MLRO owns and is accountable for each of these components. The FSA expects the program to be calibrated to the VASP's actual risk profile – product type, client geography, transaction volumes and delivery channels – not imported verbatim from a generic template.

The KYC framework for a virtual-asset business must address enhanced due diligence for higher-risk clients, including politically exposed persons and clients from FATF grey-listed or blacklisted jurisdictions. The framework also has to account for the on-chain dimension: wallet screening, counterparty-exchange risk and, where applicable, the provenance of incoming assets. Regulators in the leading hubs increasingly expect VASPs to integrate blockchain analytics tooling into their KYC and transaction monitoring processes – and the FSA's supervisory expectations are moving in the same direction.

Travel Rule compliance presents a distinct operational challenge for a Seychelles VASP serving counterparties across multiple jurisdictions. The Travel Rule requires the transfer of structured originator and beneficiary data with each qualifying virtual-asset transfer, both outbound and inbound. Where the counterparty VASP is in a jurisdiction that has implemented the Travel Rule under its own local legislation, the data exchange must conform to both regimes. Where the counterparty is an unhosted wallet or an entity that has not implemented Travel Rule procedures, the VASP must have a documented policy for managing that gap – including the option of declining the transaction.

The MLRO is also expected to maintain an internal suspicious-activity report (SAR) log and to file external reports with the Seychelles FIU when the reporting threshold is reached. Timeliness of reporting is a direct supervisory indicator: late or absent SARs are among the most common findings in FSA and FIU examinations of VASPs.

How does the cross-border reality affect the Seychelles MLRO function?

A Seychelles VASP licence does not create a regulatory passport to serve clients in the European Union, the United Kingdom, Singapore or any other jurisdiction with its own VASP or cryptoasset regime. This is the single most consequential misconception we address in inbound instructions: the offshore licence permits the Seychelles-regulated activity; it does not authorise the activity in the jurisdiction where the client sits, where the marketing reaches, or where the payment rails operate.

The MLRO must therefore understand and document the jurisdictional footprint of the firm's actual operations. A Seychelles VASP with EU-resident clients faces potential exposure under MiCA (the Markets in Crypto-Assets Regulation administered by ESMA and national competent authorities), which imposes its own VASP authorisation requirement – as a CASP (crypto-asset service provider) under that regime – on firms actively soliciting or servicing EU clients at scale. The MLRO who certifies the compliance program as adequate without accounting for this extra-territorial exposure is signing off on an incomplete picture.

Banking is the point at which this cross-border gap becomes most visible. Seychelles-incorporated VASPs routinely bank through correspondent networks that route through EU, UK or US-regulated institutions. Those institutions conduct their own due diligence on the VASP as a respondent customer, and they will ask for evidence of a functional AML program – including the identity, qualifications and availability of the MLRO. A nominee MLRO who cannot speak to the firm's risk assessment or monitoring procedures in a bank call creates a material de-banking risk.

In a recent matter, a payments-focused VASP incorporated in an offshore jurisdiction had operated for over a year with a shared compliance officer whose primary engagement with the firm was quarterly. When the firm's correspondent bank initiated a periodic review, the compliance officer was unable to respond substantively to questions about transaction monitoring logic or the firm's exposure to grey-listed jurisdictions. The bank exited the relationship. We were engaged to restructure the compliance function, appoint a dedicated MLRO, and support the firm through a new banking due-diligence process. The relationship was re-established within a matter of months, after the compliance program had been rebuilt from the risk assessment outward.

If a banking relationship has been exited or is under review, reach our compliance desk now at info@oboluslaw.com. A second read of the compliance architecture can surface the structural reason and the route back. Map your options.

How does the MLRO appointment work in the FSA application process?

The FSA application process for a VASP licence in Seychelles requires the submission of detailed personal questionnaires and supporting evidence for all proposed controllers, directors and senior officers, including the MLRO. The MLRO submission typically includes a full CV, a professional reference, evidence of AML/CFT training and, in practice, a written statement setting out how the individual intends to discharge the function within the specific business model being licensed.

The FSA conducts its review of key individuals in parallel with its review of the business application. Deficiencies in the MLRO's documentation are a common cause of licence application delays. The most frequent shortcomings are a CV that is not mapped to virtual-asset-specific competencies, the absence of any articulation of how the MLRO will interact with the VASP's systems and controls in practice, and a lack of documented training in on-chain compliance tools.

Post-licensing, the MLRO function is subject to ongoing supervisory oversight. The FSA may require the MLRO to attend supervisory meetings or to produce the firm's AML/CFT program documentation on request. An annual compliance review, submitted to the board and retained for supervisory inspection, is standard practice across the leading offshore regimes and is increasingly expected by the FSA as well.

Which operator profiles need a dedicated versus a combined MLRO and compliance officer?

The choice between a combined MLRO/compliance officer function and a separated structure turns on the firm's size, risk profile and the intensity of its supervisory relationship with the FSA. The following prose matrix covers the three most common profiles in our practice.

A startup VASP with a narrow product line – for instance, a spot exchange serving a limited client geography with moderate transaction volumes – can generally satisfy the FSA with a combined function in a single, experienced individual. The key risk at this profile is overload: if the MLRO is also running operations, the compliance function degrades under business pressure. The mitigation is documented time allocation and a clear escalation path that does not route through the MLRO's competing responsibilities.

A mid-size VASP with multiple product lines, clients across several higher-risk jurisdictions, and an active treasury function needs a separated compliance officer and MLRO. The compliance officer manages the day-to-day program – KYC, transaction monitoring, staff training and policy maintenance. The MLRO focuses on the reporting function and the supervisory relationship. Both individuals need direct board access. The FSA expects this structure at this scale, and a combined function at the mid-size level is increasingly a supervisory concern.

An exchange or custodian operating at institutional scale, with clients in the EU or other heavily regulated markets, requires a compliance function that is genuinely equivalent to the programs those market participants would expect from a regulated counterparty in their own jurisdiction. That means a dedicated compliance team, a standing compliance committee at board level, and an MLRO with the authority and resources to escalate without business-unit interference. The Seychelles licence is the foundation; the compliance architecture above it must be built to the expectations of the most demanding regulator the business touches.

What are the MLRO's ongoing obligations after licensing?

Once licensed, the MLRO's obligations run continuously and are not discharged by the initial FSA approval of the compliance program. The program must be reviewed and updated when the firm's risk profile changes materially – a new product line, a new client geography, a significant increase in transaction volumes, or a change in the firm's banking or custody arrangements. Each such change should trigger a documented review, not merely an administrative update.

The Travel Rule obligation is live from the date of licensing. The MLRO is responsible for ensuring that the firm's technical infrastructure can actually generate, transmit and receive the required data fields for qualifying transfers. Many Seychelles VASPs have discovered – at the point of a bank or counterparty due-diligence review – that their systems were not producing compliant Travel Rule messages. Remediation is costly and disruptive. Pre-launch testing of the Travel Rule implementation against the firm's actual counterparty network is the standard we recommend in our practice.

The MLRO is also responsible for the firm's response to a supervisory examination or a law-enforcement inquiry. In the digital-asset environment, those inquiries increasingly arrive with technical specificity: regulators ask for transaction hashes, wallet address records and the analytical methodology behind a suspicious-activity determination. An MLRO who cannot engage with that technical specificity is not equipped for the role in a virtual-asset context.

Operators we advise regularly invest in the MLRO function at the outset – in the quality of the appointment, the documentation of the program and the testing of the Travel Rule implementation – because the cost of a remedial exercise after a supervisory finding or a banking exit is a multiple of the upfront investment.

What are the most common MLRO compliance failures for Seychelles VASPs?

A common assumption is that an offshore licence with a named MLRO on the application satisfies the compliance obligation. It does not. The FSA, and more importantly the correspondent banks and counterparty VASPs that the business will interact with, look for evidence of an MLRO who is operationally engaged, not merely named. The most consistent compliance failures we see in inbound instructions fall into a small number of recurring patterns.

The first is the shared MLRO: a single individual appointed as MLRO across multiple Seychelles VASPs, with insufficient time to engage substantively with any of them. Banks and counterparties have become adept at identifying this pattern through due-diligence questionnaire responses, and they treat it as a risk indicator. The second is the unrevised program: a compliance manual prepared at licensing and not updated since, regardless of how the business has evolved. The third is the absent Travel Rule implementation: a VASP that has a policy document describing Travel Rule compliance but no operational mechanism for actually transmitting or receiving the required data.

Each of these failures is correctable. None of them is correctable quickly when a bank has already issued a de-risking notice or the FSA has opened a supervisory inquiry. The decision point is before the problem surfaces.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect and transmit structured originator and beneficiary information with every qualifying virtual-asset transfer. The data travels with the transaction to the receiving VASP, which must verify and retain it. The applicable threshold and data fields vary by jurisdiction, but the obligation applies to both outbound and inbound transfers. A Seychelles VASP must have an operational mechanism – not just a policy – for meeting this requirement before going live.

Who must act as MLRO for a crypto firm?

The MLRO must be a named natural person with demonstrable AML/CFT competence, approved by the relevant regulator as part of the licence authorisation. In Seychelles, the FSA applies a fitness-and-propriety test that covers experience, integrity and availability. The MLRO may be based outside Seychelles in many structures, but must be genuinely accessible and operationally engaged with the firm – not a nominal appointment serving multiple entities with minimal time commitment to any of them.

How do regulators audit crypto AML programs?

Regulators typically examine the written compliance program, the risk assessment, KYC files for a sample of clients, transaction monitoring logs, SAR records and evidence of staff training. In digital-asset firms, they increasingly ask for technical records: wallet screening reports, Travel Rule message logs and the analytical methodology behind suspicious-activity determinations. An audit-ready MLRO maintains documented evidence of each program element and can produce it promptly on supervisory request.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule architecture that sits around every regulated digital-asset operation. We map the licence stack – operating, custody and payment layers – before you commit, and we act only for businesses. Digital assets are the entirety of our practice. To discuss your compliance program or MLRO appointment, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and VASP supervisory compliance across offshore and onshore digital-asset regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours