Sanctions screening for crypto businesses registered in Seychelles is a live compliance obligation, not a box-checking exercise. The Securities Act and the Virtual Asset Service Providers Act (VASPA) create a regulated perimeter within which every licensed entity must maintain a real-time sanctions-screening program, a documented AML/CFT policy and a transaction-monitoring architecture that survives regulatory scrutiny. With VASP supervision tightening across the major licensing hubs, a Seychelles-domiciled platform that also serves European, Gulf or Asian users faces not one compliance baseline but several running concurrently.
This page maps the sanctions-screening obligations that apply under the Seychelles VASPA regime, the cross-border layers that activate when users or counterparties sit in other jurisdictions, and the practical steps operators take to build a program that holds under audit. One anonymized engagement is included to illustrate how the issues arise in practice.
The regulatory basis for sanctions screening in Seychelles
Seychelles-licensed VASPs must screen every customer, counterparty and transaction against applicable sanctions lists as a condition of holding their authorisation. The Financial Intelligence Unit (FIU) of Seychelles is the primary supervisory body for AML/CFT compliance, operating alongside the Financial Services Authority (FSA), which maintains the VASPA licensing register. Both bodies align their expectations to the FATF Recommendations, including FATF Recommendation 15, which extends the AML/CFT obligations applicable to financial institutions to virtual asset service providers.
The relevant sanctions lists a Seychelles VASP must screen against include the UN Security Council consolidated list, the OFAC Specially Designated Nationals list, and the EU consolidated sanctions list – depending on the currency rails, correspondent banking relationships and user base of the business. Operating on USD payment rails without OFAC screening is not a compliance option. It is an enforcement path.
In our cross-border practice, we see a consistent pattern: an operator structures in Seychelles for its favourable corporate and licensing environment, then discovers mid-build that its banking partner, payment processor or institutional counterparty imposes compliance standards drawn from a different regime entirely. Getting the sanctions-screening architecture right at the outset – before the banking relationship is in place – avoids a costly rebuild later.
What does a compliant sanctions-screening program require?
A compliant sanctions-screening program for a Seychelles VASP requires four interlocking elements: a current and complete list of applicable screening targets, an automated screening tool calibrated for crypto-specific identifiers, a documented escalation procedure, and periodic testing by an independent function.
Screening targets for a digital-asset business go beyond names and entities. They include blockchain wallet addresses published by OFAC and other designating authorities. OFAC has added cryptocurrency addresses directly to the SDN list; failing to screen against those addresses in real time is a strict-liability issue under US sanctions law regardless of where the VASP is incorporated. A Seychelles registration does not create a safe harbour from secondary sanctions exposure.
The screening tool itself must match the nature of the business. A spot exchange with high transaction volume needs a tool capable of matching addresses in real time at the point of transaction. A custody platform with lower frequency but higher average balance needs a tool that re-screens the wallet population periodically – because new designations are issued continuously. Both tools must cover name-based screening against natural persons, legal entities and vessels, not only blockchain addresses.
Escalation procedure means a written, board-approved process for what happens when a match is found. That process must identify who makes the determination (typically the MLRO), what the holding period is while the determination is made, how the regulator is notified, and how the firm documents its decision to proceed or to freeze. Seychelles law requires suspicious activity reports to be filed with the FIU where reasonable grounds exist. The threshold for filing is not a conviction – it is reasonable grounds.
For a scoped assessment of your Seychelles AML program, write to OBOLUS at info@oboluslaw.com. The process above describes the standard architecture. Your facts – the user base, the custody structure, the payment rails and the counterparty profile – change which elements need the most development. Map your options.
How does the FATF Travel Rule apply to a Seychelles VASP?
The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary identifying information alongside a virtual asset transfer – applies to Seychelles-licensed VASPs as part of the VASPA compliance framework. A Seychelles VASP transferring virtual assets to or receiving them from another VASP must collect, verify and transmit the required data for transfers above the applicable de-minimis threshold. The precise threshold is set by the Seychelles FIU and aligns broadly with the FATF guidance figure, but operators should verify the current applicable level directly with current legislation rather than rely on a fixed number that may have been updated.
Operationally, Travel Rule compliance requires the VASP to implement a VASP-to-VASP messaging protocol – a technical layer that transfers customer data securely between originating and beneficiary VASPs. The leading solutions in practice include TRISA, OpenVASP and proprietary implementations built on those standards. The choice of protocol depends on which counterparty VASPs the business transacts with most; interoperability is the practical constraint.
A complication specific to the Seychelles environment is the sunrise issue: when a Seychelles VASP sends a transfer to a VASP domiciled in a jurisdiction that has not yet implemented the Travel Rule, the receiving VASP may lack the technical infrastructure to accept the required data packet. FATF guidance and most competent authorities direct the sending VASP to collect and store the information regardless, and to exercise enhanced due diligence on the counterparty relationship. In our practice, we advise clients to maintain a counterparty VASP register that records each counterparty's Travel Rule status and the steps taken to transmit data, so that the compliance record is audit-ready.
KYC framework and transaction monitoring for Seychelles crypto firms
KYC obligations under the Seychelles VASPA regime require identity verification at onboarding, ongoing monitoring and enhanced due diligence for higher-risk customers and relationships. The KYC framework must be risk-based: a retail customer transacting in modest volumes and a corporate counterparty processing large institutional flows require different verification depth, different source-of-funds documentation and different refresh cycles.
For digital-asset businesses, KYC also has a blockchain dimension. A customer who deposits from an unhosted wallet – one not held at a regulated VASP – triggers enhanced due diligence obligations in most leading regimes. Seychelles-licensed VASPs should have a documented policy on unhosted wallet interactions: what blockchain analytics the firm runs, how it assesses the risk profile of the wallet's transaction history, and when it requires the customer to prove control of the address before accepting the deposit.
Transaction monitoring must be calibrated to the specific typologies relevant to the product. A peer-to-peer exchange faces different typology risks from a yield-bearing custody platform. The FIU and FATF have both published virtual-asset-specific typology guidance that informs how monitoring rules should be written. A generic rule set ported from a traditional financial institution is unlikely to catch crypto-specific patterns: structuring through multiple wallet hops, use of mixing services, rapid conversion between asset classes, or concentration of large transfers just below a threshold.
In practice, we regularly advise Seychelles VASPs to conduct a gap analysis of their monitoring rules against the latest FATF virtual-asset typology reports before a regulatory inspection cycle. The analysis surfaces rules that are miscalibrated, thresholds that have drifted from the risk profile of the current user base, and governance weaknesses in the alert review process.
Cross-border interaction: banking, tax and multi-regime compliance
A Seychelles VASP operating across borders faces multiple compliance baselines running in parallel, and the most demanding baseline is the one that governs whichever regulated relationship is most operationally critical. That is almost always the banking relationship.
Correspondent banks servicing Seychelles entities routinely apply their own sanctions-screening and AML standards – typically drawn from their home jurisdiction, which may be the UK, the EU or the US. In our cross-border practice, we have seen situations where a Seychelles VASP's internal AML program was technically compliant with local requirements but fell short of the correspondent bank's proprietary enhanced due diligence standards. The result was a frozen account and a demand for enhanced documentation, not a local regulatory action. The distinction matters: the timeline for resolution, and the entity that resolves it, is the bank – not the FIU.
For operators with European user bases, MiCA and the EU's Transfer of Funds Regulation create additional Travel Rule obligations that apply to the EU leg of the business even if the licensed entity is in Seychelles. A Seychelles VASP serving EU retail users without a MiCA authorisation is operating in a grey area that ESMA and national competent authorities have indicated they will address. The practical answer for many operators is a dual structure: the Seychelles entity for certain activity types, and a separate MiCA-authorised entity for EU-facing activity.
Tax interaction is a second cross-border layer. Seychelles does not impose corporate income tax on offshore profits, but a VASP with staff, servers or customers in other jurisdictions may create taxable presence in those jurisdictions under their own rules. Transfer pricing documentation, permanent establishment analysis and the classification of token receipts as income or capital are questions that belong in the structure design phase, before transactions begin.
If your Seychelles structure has encountered banking or multi-regime compliance friction, contact OBOLUS at info@oboluslaw.com. A second read on the structure can surface the reason and the route back. Map your options.
How sanctions and AML issues present in practice
In a recent compliance engagement, a digital-asset trading platform licensed in a mid-shore jurisdiction – structurally similar to Seychelles – faced an unexpected account suspension by its correspondent bank. The bank had flagged a batch of outgoing transfers that matched wallet addresses on a private blockchain intelligence watchlist not derived from any public sanctions list. The firm's internal AML program screened against the UN, OFAC and EU lists; it did not screen against the bank's proprietary list, the existence of which had not been disclosed at onboarding.
We were engaged to assess the program gap, negotiate a disclosure package with the bank, and implement an enhanced screening layer that included the additional address-level data sources the bank required. The account was reinstated within several weeks. The more durable outcome was a revised counterparty onboarding process that surfaces each banking partner's specific screening requirements before the relationship begins – avoiding the discovery of the gap at the point of a transaction freeze. The engagement illustrated a point we raise regularly with clients: the compliance baseline that matters most is not always the regulatory minimum. It is the standard set by the most demanding commercial counterparty.
What does a Seychelles VASP compliance program need to cover?
A baseline-compliant sanctions and AML program for a Seychelles-licensed VASP covers the following elements. Each is a commitment that the regulator may inspect and the bank may independently verify.
First, a documented AML/CFT policy, board-approved and reviewed at least annually, that sets out the risk appetite, the customer risk classification methodology, the screening architecture and the escalation matrix. The policy must reflect the actual product and user base of the firm – not a generic template.
Second, a designated MLRO with the seniority, authority and independence to make filing decisions without board interference. The MLRO must have documented access to all transaction and customer data, a clear reporting line to the board, and a training record that demonstrates current knowledge of virtual-asset-specific typologies.
Third, an automated sanctions-screening tool covering name-based and address-based targets, updated in real time as new designations are issued. Manual screening is not viable at any meaningful transaction volume.
Fourth, a transaction-monitoring system with rules calibrated to the product typology, an alert review process with documented disposition timelines, and a management information report presented to the board on a regular basis.
Fifth, a Travel Rule solution implemented and tested with the key counterparty VASPs the firm transacts with, a counterparty VASP register documenting each counterparty's verification status under the applicable VASP verification standards, and a policy for unhosted wallet interactions.
Sixth, an independent audit or review of the AML program on a cycle appropriate to the risk profile of the business – typically annual for a high-volume exchange and at least biennial for a lower-frequency custody platform.
The decision point: what an operator should assess before going live
Before a Seychelles-licensed VASP goes live, the compliance architecture needs to be stress-tested against three variables: the user base, the product and the banking stack.
A VASP serving retail users in multiple jurisdictions has a higher inherent risk profile than one serving a closed set of institutional counterparties. The risk profile determines the depth of the KYC program, the sensitivity of the transaction-monitoring rules and the frequency of the MLRO review cycle. Calibrating those elements to a risk profile that has not been formally assessed is one of the most common structural weaknesses we identify in incoming compliance audits.
The product matters because different products attract different typologies. A spot exchange attracts smurfing and structuring patterns. A lending or yield platform attracts layering through recurring deposit-withdrawal cycles. A custody service for institutional clients attracts due-diligence questions about the source and beneficial ownership of the assets custodied. The monitoring rules must match the product.
The banking stack matters because, as noted above, the most demanding compliance standard the firm faces may be the one imposed by its bank rather than its regulator. We map the licence, banking and compliance requirements across all three layers – operating entity, custody layer and payment rail – before a client commits to a structure. That mapping identifies the compliance ceiling early, when it can still be designed into the architecture rather than retrofitted under pressure.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – end-to-end compliance program design across jurisdictions and product types
- AML and Travel Rule regime in Malta – comparative EU baseline under MiCA and the MFSA framework
- Redemption and liquidity terms in Liechtenstein – structuring considerations for token issuers in an EEA-passportable regime
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, verify and transmit identifying information about the originator and beneficiary of a virtual asset transfer to the receiving VASP at the time of the transaction. The obligation applies to transfers above the applicable de-minimis threshold set by the relevant jurisdiction. Both the sending and receiving VASP must have a technical solution capable of exchanging the required data. Where the counterparty VASP lacks that capability, the sending VASP must document its attempts to transmit and apply enhanced due diligence.
Who must act as MLRO for a crypto firm?
A crypto firm must designate a Money Laundering Reporting Officer with sufficient seniority to make independent filing decisions, direct access to all customer and transaction data, and documented authority to act without board interference in time-sensitive situations. The MLRO must maintain current knowledge of virtual-asset typologies through ongoing training. Seychelles and most FATF-aligned regimes require the MLRO designation to be notified to the relevant supervisory authority. A nominee or non-executive MLRO with no operational access is unlikely to satisfy a regulatory inspection.
How do regulators audit crypto AML programs?
Regulators typically audit crypto AML programs through a combination of document review, transaction sample testing and interviews with the MLRO and compliance team. Document review covers the AML/CFT policy, risk assessment, customer files and alert disposition records. Transaction testing checks whether monitoring rules flag the activity they are designed to catch and whether escalations were handled within the documented timelines. Interview questions probe whether the MLRO understands the firm's specific risk typologies. Significant gaps between the written policy and operational practice are the most common finding in enforcement actions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that compliance gaps are identified in the design phase, not under regulatory pressure. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when matters escalate. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and sanctions-screening architecture for digital-asset businesses across mid-shore and offshore licensing jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.