EST · MMXXVI
Home/Jurisdictions/Switzerland/Regulator aml audit defence in Switzerland
Compliance, AML & Travel Rule

Regulator aml audit defence in Switzerland

Regulator aml audit defence in Switzerland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Defending a Regulatory AML Audit in Switzerland: What a VASP Must Know Now

A regulatory AML audit (a supervisory examination of a virtual asset service provider's anti-money laundering program by FINMA or a delegated self-regulatory organization) is one of the most consequential compliance events a Switzerland-based crypto business will face. The Swiss regime – built on FINMA's token taxonomy, the Anti-Money Laundering Act, and the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer) – is rigorous, well-staffed and has real enforcement teeth. A firm that cannot demonstrate a defensible, documented AML program on the day of examination risks remediation orders, licence suspension or, in serious cases, referral for criminal investigation. The sections below map exactly what auditors examine, how to prepare, and where cross-border structure creates unexpected exposure.

The answer in three sentences. Swiss VASP AML audits are conducted against the Anti-Money Laundering Act and FINMA's guidance on virtual assets (payment, utility and asset tokens, per the FINMA token taxonomy), supplemented by the FATF Recommendations – in particular Recommendation 15 on virtual assets and the Travel Rule. A defensible defence requires documented policies, an appointed Money Laundering Reporting Officer (MLRO), calibrated transaction monitoring, and a Travel Rule compliance stack that covers counterparty VASP due diligence. Cross-border operators face a compounded risk: the regulatory posture of the jurisdiction where users sit, where liquidity runs, and where banking is held can each generate independent obligations that surface during a Swiss examination.

What Is the Regulatory Basis for AML Supervision of Crypto Firms in Switzerland?

Switzerland regulates digital-asset businesses through FINMA, which applies the Anti-Money Laundering Act to VASPs alongside its published guidance on token classification. A firm offering exchange, custody, transfer or similar services over virtual assets is a financial intermediary under Swiss law – and is therefore subject to AML supervision either directly by FINMA or through an affiliated self-regulatory organization (SRO), which FINMA delegates to conduct front-line audits.

FINMA has published substantive guidance on its expectations for virtual-asset businesses. That guidance draws expressly on FATF Recommendation 15, which requires that VASPs implement the same core AML/CFT controls as traditional financial institutions. The Travel Rule, incorporated into FATF standards, requires that originator and beneficiary data accompany qualifying virtual-asset transfers. Switzerland implemented the Travel Rule requirement, meaning Swiss VASPs must pass and receive that data – and must manage the situation where the counterparty VASP cannot or does not comply.

SRO affiliation is the most common path for smaller crypto intermediaries in Switzerland. The SRO conducts periodic audits itself and escalates findings to FINMA. Larger or higher-risk intermediaries are supervised directly. Either way, the substance of what is examined is materially the same.

One distinction matters for cross-border operators: the FINMA fintech licence, the banking licence and the SRO-affiliated VASP path each carry different balance-sheet and operational expectations. An operator whose Swiss entity is merely one layer in a multi-jurisdiction structure should confirm that its chosen licence route is correctly calibrated to the activities actually conducted from Swiss soil – because an audit will examine economic substance, not just legal form.

To map the licence, banking and compliance stack for your Swiss entity, write to OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the liquidity arrangements and the banking – change the analysis materially.

What Do Auditors Actually Examine in a Swiss Crypto AML Audit?

A Swiss AML audit of a crypto business is a structured examination across five principal domains, each of which an experienced examiner will probe with specific documentation requests. Understanding these domains is the starting point of any audit defence.

First, governance and the MLRO. Every Swiss financial intermediary must designate a qualified MLRO responsible for the AML function. Auditors will assess the MLRO's seniority, independence from business lines, access to senior management and the documented scope of their authority. An MLRO who cannot demonstrate active oversight – through board reporting, escalation records and periodic training – is a significant finding.

Second, the written AML/CFT program. Examiners will request the firm's AML policy, risk appetite statement, KYC procedures, customer due diligence standards and enhanced due diligence protocols for high-risk clients. Policies must be current, approved at the right level and demonstrably implemented – not aspirational documents that diverge from actual practice.

Third, the KYC framework and customer onboarding records. Auditors sample customer files. They check whether identification was obtained and verified, whether beneficial ownership was established, whether the risk classification assigned to each client is defensible, and whether periodic review was conducted. In the virtual asset context, they will also assess whether on-chain activity was considered as part of the KYC file.

Fourth, transaction monitoring. Switzerland expects VASPs to monitor transactions for suspicious patterns using a calibrated, documented methodology. "Calibrated" means the thresholds and typologies were set by reference to the firm's specific risk profile – not copied verbatim from a generic template. Auditors ask to see alert logs, disposition records and the escalation path from analyst to MLRO to Suspicious Activity Report.

Fifth, Travel Rule compliance. This is a frequent area of examiner focus. For each qualifying transfer, the firm must pass originator and beneficiary data to the receiving VASP and receive it from the sending VASP. Where the counterparty VASP is unresponsive or unknown, the firm must apply its documented VASP due diligence and counterparty risk procedure. Auditors will test a sample of transactions and check both the data transmission record and the handling of exceptions.

How Does Cross-Border Structure Affect a Swiss AML Audit?

Operating a Swiss entity within a multi-jurisdiction structure creates compounded audit risk that is frequently underestimated until an examination begins. The auditor's scope covers the Swiss entity – but the Swiss entity's AML program must address risks generated across the entire operating chain.

Consider a common architecture: a Swiss holding or operating entity settles trades through liquidity providers in a third country, holds client assets through a custody vehicle in another jurisdiction, and banks through an account in a fourth. Each leg generates transaction flows that pass through the Swiss AML perimeter. If the firm's Swiss transaction monitoring does not cover correspondent-style flows from related entities, the examiner will note a gap.

The MiCA framework, now in force across the European Union, imposes its own AML expectations on CASP (crypto-asset service provider) authorisations – including Travel Rule obligations aligned with the same FATF baseline. A Swiss VASP that also serves EU clients through a sister entity should expect that FINMA or its SRO will ask how the Travel Rule data pipeline between the two entities operates and whether AML policies are consistent or deliberately differentiated. Regulators in the leading hubs increasingly expect group-level AML governance, not siloed entity-level compliance.

Banking is a related pressure point. Swiss bank accounts for crypto businesses are commercially restricted. Where a firm banks offshore – through a bank in Singapore under the MAS Payment Services Act regime, for example, or through an institution in the UAE operating under VARA supervision – that bank will have its own transaction monitoring. Inconsistencies between what the bank sees and what the FINMA-supervised entity reports are a known audit vulnerability.

In our cross-border practice, we regularly advise clients on aligning their group AML architecture before a supervisory examination rather than after. The cost of a pre-audit gap analysis is a fraction of the cost of a remediation order with a fixed deadline.

What Travel Rule Obligations Apply to a Swiss VASP Specifically?

The Travel Rule requirement for Swiss VASPs follows the FATF standard: originator and beneficiary data must accompany transfers at or above the applicable threshold, and VASPs must implement a process for handling transfers from entities that cannot or will not supply that data. The specific data-transfer threshold applicable in Switzerland is set by regulation – operators should confirm the current figure with reference to applicable Swiss law, as thresholds are subject to revision.

Three practical compliance points arise consistently in our work with Swiss crypto businesses.

First, VASP counterparty identification. Before transacting with a counterparty VASP, a Swiss firm should conduct VASP due diligence: confirming the counterparty is registered or licensed in its own jurisdiction, has a functioning AML program and is not on a sanctions list. Documented VASP due diligence, updated on a defined schedule, is an audit deliverable.

Second, technical implementation. The Travel Rule requires data to travel with the transaction. A number of technical messaging protocols exist for this purpose. Auditors will ask which protocol the firm uses, whether it is interoperable with the firm's major counterparties, and how failures are logged and resolved. Firms that handle Travel Rule compliance by email or spreadsheet typically fail this part of the examination.

Third, the unhosted wallet question. Swiss and international guidance has evolved on when VASPs must apply enhanced due diligence to transfers involving unhosted (self-custodied) wallets. FINMA's position is materially stricter than some other jurisdictions. A Swiss VASP must document its policy on unhosted wallet interactions and apply it consistently.

A Recent Defence Engagement: How Preparation Changed the Outcome

In a recent AML audit defence matter, we were engaged by a payments-focused VASP incorporated in Switzerland shortly after it received an audit notification from its SRO. The firm had a functioning AML policy on paper, but transaction monitoring thresholds had not been reviewed since the firm's initial SRO affiliation and no VASP counterparty due diligence register existed. We conducted a structured gap analysis across all five audit domains, rewrote the MLRO authority matrix, rebuilt the transaction monitoring calibration documentation with a defensible risk-rationale, and implemented a Travel Rule counterparty register in the weeks before the examination. The SRO audit proceeded without a material finding. The firm's compliance posture today is materially stronger than what it had the day the notification arrived – and it retains its banking relationships.

How Should a VASP Prepare Its Audit Defence Before the Examination Date?

Effective audit defence in Switzerland begins when the notification arrives – or, preferably, before it does. The preparation sequence follows a defined path, and the margin for error is narrow once a date is set.

The first step is a gap analysis against the five audit domains described above. This is not a self-certification exercise. It requires a structured review of every policy document, every system configuration and a sample of live transaction records. The gap analysis should identify not just missing documents but substantive control failures – because examiners are experienced at distinguishing paper compliance from operational compliance.

The second step is remediation sequencing. Not all gaps can be closed before the examination. The firm's counsel and MLRO should prioritise in three tiers: issues that can be fully resolved before the audit date; issues where a credible remediation plan with a timeline can be presented; and issues that represent systemic weaknesses requiring a longer-term fix with management commitment. Presenting a structured remediation roadmap to examiners is materially better than presenting undisclosed problems that the examiner discovers independently.

The third step is document production management. Auditors in Switzerland, whether SRO or FINMA staff, will issue a request list. The firm's response should be complete, ordered and accompanied by an index. Incomplete or disorganised production is read as a governance signal. We routinely advise clients to treat document production as an advocacy act, not a filing exercise.

The fourth step is preparing the MLRO and senior management for interview. Swiss examiners will speak directly to the MLRO and may meet the CEO or board. These conversations are substantive. The MLRO should be able to explain, without referring to documents, how the firm's risk appetite was set, how suspicious activity reports are handled and how Travel Rule exceptions are managed.

If an audit notification has arrived or is expected, reach OBOLUS now at info@oboluslaw.com. If a prior application stalled or a compliance program was questioned, a second read can surface the structural reason and the route back to good standing.

Which Firms Are Most Exposed – and What Should They Do First?

Not all Swiss VASPs carry the same audit risk profile. The following decision guidance reflects what we see across the range of businesses operating under Swiss supervision.

Profile A – recently SRO-affiliated startup. The firm built its AML program rapidly at the time of affiliation and has not revisited it since the business scaled. Transaction volumes, customer types and product lines have changed; the documented risk appetite has not. This profile should prioritise a full policy refresh, a re-calibration of transaction monitoring thresholds and documentation of its Travel Rule technical stack. Timeline to prepare a defensible program: typically a matter of weeks with focused counsel support.

Profile B – multi-jurisdiction operator with a Swiss entity. The firm is licensed or registered in two or more jurisdictions. Its Swiss entity relies partly on group-level AML infrastructure built for a different regulatory baseline. Cross-border data flows and group-level governance create specific gaps. This profile should prioritise a jurisdictional mapping exercise to identify which obligations apply specifically to the Swiss entity, and then align the group AML architecture accordingly. Timeline: longer, depending on group complexity, but the analysis must be complete before any examination date.

Profile C – established VASP with a prior finding. The firm received a finding or informal comment in a previous SRO review and implemented partial remediation. A follow-up examination will specifically test whether the prior finding was addressed. This profile's immediate priority is a documented implementation record for every prior finding, plus a proactive assessment of whether the remediation was effective in practice. The follow-up examination is a higher-stakes event than the initial one.

Across all three profiles, the common failure point we observe is the same: the gap between what the compliance policy says and what the operation actually does. Examiners are trained to find that gap quickly.

A Common Assumption That Costs Swiss VASPs

A common assumption among operators is that a single offshore licence – or an SRO affiliation obtained for a minimal-footprint entity – is sufficient to cover a genuinely global client base without further regulatory engagement. This assumption is incorrect and, in the Swiss context, can be directly damaging in an AML audit.

FINMA and Swiss SROs examine the substance of the business conducted through the Swiss entity. If a Swiss-registered VASP is, in practice, serving clients in EU member states, in the United States or in Asia without the appropriate licence or registration in those jurisdictions, the examiner will note the mismatch. More specifically, the AML risk profile generated by serving high-risk or unrestricted client populations will not be adequately addressed by a compliance program designed around a narrower, lower-risk client base. The result is a systemic AML control gap – exactly the kind of finding that triggers escalation from an SRO to FINMA.

We map the licence stack across operating, custody and payment layers before a firm commits to a structure. That mapping prevents the audit vulnerability from being built into the business architecture in the first place.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, drawn from FATF Recommendation 15, requires that a virtual asset service provider transmit originator and beneficiary identification data alongside qualifying virtual-asset transfers and receive equivalent data on incoming transfers. Where a counterparty VASP cannot supply the required data, the receiving VASP must apply documented procedures to manage the exception – including, in some cases, declining the transaction. Switzerland applies this requirement to VASPs supervised under FINMA or affiliated with an SRO.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) must be a sufficiently senior individual with operational independence from business-line functions, direct access to senior management and the authority to file Suspicious Activity Reports. In Switzerland, the MLRO role is a formal compliance appointment reviewed by FINMA and SROs during examination. The MLRO must be demonstrably active – not a nominal title assigned to a director who performs no day-to-day compliance function. Staffing and seniority expectations vary with the size and risk profile of the firm.

How do regulators audit crypto AML programs?

Swiss AML audits of crypto businesses – whether conducted by an SRO or directly by FINMA – typically follow a structured document review and interview process. Examiners request AML policies, KYC files, transaction monitoring logs and Travel Rule records. They sample customer onboarding documentation and disposition records for flagged alerts. Senior management and the MLRO are interviewed. The examination tests whether documented controls are operationally implemented, not merely written down. Findings are graded by severity, and material findings require a remediation response within a defined period.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance structures that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – because an AML audit in Switzerland rarely travels alone. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP AML programme architecture and supervisory examination defence across Swiss and multi-jurisdiction digital-asset structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours