EST · MMXXVI
Home/Jurisdictions/United Kingdom/AML/cft policy drafting in United Kingdom
Compliance, AML & Travel Rule

AML/cft policy drafting in United Kingdom

Aml/cft policy drafting in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

AML/CFT Policy Drafting in United Kingdom

Operating a digital-asset business in the United Kingdom without a documented, defensible AML/CFT (anti-money laundering and counter-financing of terrorism) policy is not merely a compliance gap – it is an enforcement target. The Financial Conduct Authority has made clear that cryptoasset firms registered under the Money Laundering Regulations face the same supervisory expectations as conventional financial institutions. A policy that was adequate at registration can become a liability within months as the FCA's risk-appetite and transaction-monitoring expectations tighten. For any business processing digital-asset flows touching UK clients, UK banking rails or a UK-registered entity, the policy framework is the first document the regulator reads – and the first place an enforcement team looks.

The regulated basis is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations – referred to here as the Money Laundering Regulations – which implement FATF Recommendation 15 for virtual assets. Firms must register with the FCA before conducting cryptoasset business in the UK; the AML/CFT policy is both a registration prerequisite and an ongoing supervisory obligation. This page maps the drafting process, the cross-border complications that most inbound operators underestimate, and the decision points that determine whether an existing policy is fit for a tightening supervisory environment.

What Is the Regulatory Baseline for AML/CFT in UK Crypto?

The FCA's authority over UK cryptoasset firms rests on the Money Laundering Regulations, which impose a broad set of obligations: risk assessment, customer due diligence, enhanced due diligence (EDD) for higher-risk relationships, transaction monitoring, suspicious-activity reporting and record-keeping. A firm's AML/CFT policy is the master document that translates these obligations into internal controls, procedures and governance structures. The FCA has consistently indicated that policy documents must be proportionate, risk-based and specifically calibrated to the firm's own product and customer mix – not copied from a generic template.

The FCA's cryptoasset supervisory work has identified systemic weaknesses in three areas: inadequate business-wide risk assessments, transaction-monitoring systems set to default thresholds without product-specific calibration, and governance structures where the Money Laundering Reporting Officer (MLRO) lacks genuine authority over business decisions. A policy addressing only the letter of the Regulations – without demonstrating that controls are proportionate to the firm's actual risk exposure – will not satisfy the FCA's current supervisory posture.

In our practice, we regularly advise firms that their risk assessment is the load-bearing document in the entire AML/CFT architecture. If the risk assessment misclassifies the customer base, understates geographic exposure or fails to account for the peer-to-peer or DeFi channels through which assets enter the firm, every downstream control is calibrated against a false baseline. The policy therefore starts with the risk assessment, not with a list of procedures.

Who Needs a UK AML/CFT Policy – and When Does the Obligation Arise?

Any firm carrying on cryptoasset activity that falls within the scope of the Money Laundering Regulations in the UK must maintain a compliant AML/CFT policy; this obligation attaches at registration, not at some later operational milestone. The scope covers exchange activity, custody, token issuance platforms and certain transfer and settlement functions. Critically, the territorial reach of the Regulations extends to firms established outside the UK if they carry on business from a UK establishment – and, in some circumstances, to firms targeting UK customers through remote means.

This cross-border dimension is where inbound operators most frequently misjudge their exposure. A business incorporated in the EU that passports a MiCA authorisation is not thereby exempt from the UK's parallel regime. The UK is no longer part of the EU's MiCA passporting architecture. A firm with EU authorisation that onboards UK clients, settles transactions through UK banking correspondents or maintains a UK-facing interface is, in most configurations, conducting business subject to FCA oversight. We have seen operators invest substantially in a MiCA-compliant policy only to discover they need a materially different UK-specific document to accompany an FCA registration application.

Firms subject to the Money Laundering Regulations must appoint an MLRO, conduct a business-wide risk assessment, establish written policies and procedures, and train staff – all before commencing regulated activity. The FCA will scrutinise the MLRO's fitness and propriety, the quality of the risk assessment and the operability of the procedures at the registration stage and in subsequent supervisory reviews.

For a scoped assessment of your UK registration obligations and whether your existing AML/CFT policy meets FCA expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

How Is a UK AML/CFT Policy Structured and Drafted?

A defensible AML/CFT policy for a UK-registered cryptoasset firm is a suite of interlinked documents, not a single narrative – and the drafting sequence matters as much as the content. The business-wide risk assessment comes first; it identifies the inherent risks arising from the firm's products, customers, geographic footprint and delivery channels. From that assessment, the policy translates risk scores into proportionate controls: customer due diligence thresholds, EDD triggers, transaction-monitoring rules, screening frequencies and escalation pathways.

The core documents in a complete UK AML/CFT policy suite typically include:

  • A business-wide risk assessment (reviewed and updated at least annually, and on material change).
  • A customer risk-rating methodology, including the criteria that trigger enhanced due diligence.
  • A KYC framework (know-your-customer procedures) covering onboarding, periodic review and off-boarding.
  • Transaction-monitoring rules, calibrated to the firm's specific asset classes and flow patterns.
  • A Travel Rule compliance procedure (originator and beneficiary information on qualifying transfers).
  • A suspicious-activity-reporting procedure, including internal SAR escalation and submission to the National Crime Agency.
  • Screening procedures for sanctions, politically exposed persons and adverse media.
  • An MLRO governance charter, setting out authority, reporting lines and annual reporting obligations.
  • A staff-training programme, with records of completion.

In drafting these documents, the Travel Rule procedure deserves particular attention. The UK's implementation of FATF's Travel Rule – the obligation to collect and transmit originator and beneficiary information with a qualifying virtual-asset transfer – imposes specific data requirements on both originating and beneficiary VASPs. Determining when a transfer crosses the threshold that triggers Travel Rule obligations, how to handle transfers to or from unhosted wallets, and what to do when the counterparty VASP cannot receive the required data are all questions that must be resolved in writing, not case by case. The FCA expects to see a documented procedure, not an ad hoc judgment call.

Who Must Act as MLRO – and What Does the Role Actually Require?

The MLRO role in a UK-registered cryptoasset firm is a regulated function; the individual appointed must be approved or notified to the FCA and must demonstrate the competence, seniority and independence to perform the role effectively. This is not a nominal compliance appointment. The FCA has taken action against firms where the MLRO lacked the authority to pause onboarding, the access to information needed to conduct meaningful oversight, or the reporting line to the board that the role requires.

In our practice, we see a recurring pattern with early-stage crypto firms: the MLRO is the founder, the CTO or an external consultant with no real authority over commercial decisions. The FCA's published expectations – and its supervisory findings in the cryptoasset sector – make clear that the MLRO must have genuine power to decline or exit a customer relationship, unobstructed access to transaction data, and a direct reporting line to the board or equivalent governance body.

The MLRO's annual report to the board is a required document, not a formality. It must cover the volume and quality of internal suspicious activity reports, the firm's exposure to the risks identified in the business-wide risk assessment, any material changes to the risk profile during the year, and the adequacy of training. The FCA may request this document in a supervisory review. A thin or formulaic annual report is itself a supervisory finding.

For firms operating across multiple jurisdictions – a UK entity with a Dubai subsidiary licensed by VARA, or a Singapore MAS-licensed parent with a UK-facing wallet product – the MLRO governance structure must address how AML obligations are allocated across the group. The UK entity's MLRO cannot simply defer to a group compliance function operating under a different regime. The FCA expects entity-level ownership of UK AML obligations.

How Should Transaction Monitoring Be Calibrated for Crypto?

Transaction monitoring for a cryptoasset firm is materially different from the equivalent function at a conventional payment institution, and the FCA is fully aware of that difference. The firm's transaction-monitoring system must be calibrated to the specific risk profile documented in the business-wide risk assessment – not to off-the-shelf thresholds inherited from a banking template.

The relevant variables include the asset classes the firm handles, the customer segments it serves, the average transaction size, the expected frequency of peer-to-peer interactions and the firm's exposure to privacy-enhanced protocols or high-risk geographic corridors. A firm that handles only a limited range of major-cap assets and serves institutional counterparties will have a materially different monitoring posture than one offering retail access to a broad asset catalogue, and the policy must reflect that.

Blockchain analytics is now a standard supervisory expectation, not an optional enhancement. The FCA expects that firms can trace the provenance of incoming funds, identify exposure to sanctioned addresses and assess the transaction history of counterparty wallets. A transaction-monitoring procedure that does not address on-chain analytics – alongside traditional payment-flow monitoring – is incomplete by current supervisory standards. This is an area where the policy and the operational tooling must be designed together; a procedure that cannot be executed with the firm's actual systems is not compliant, regardless of how well it is written.

A micro-matter from our practice: in a recent compliance review, a digital-asset exchange had implemented a transaction-monitoring system acquired from a third-party vendor but had not configured it to reflect the firm's actual customer risk tiers. The default thresholds flagged a fraction of the transactions that a properly calibrated system would have caught. We restructured the monitoring rules to align with the firm's documented risk assessment, drafted a revised policy procedure and prepared an updated board report. The firm subsequently passed a supervisory follow-up without material findings.

How Does UK AML/CFT Interact With Banking, Tax and Other Jurisdictions?

The cross-border dimension of UK AML/CFT compliance is where policy gaps create the most acute business risk – because the consequences are not only regulatory but operational. A UK-registered firm with deficient AML/CFT documentation is a de-banking target. UK clearing banks and their international correspondent networks have exited crypto clients for AML-documentation failures that were, in principle, curable; the exit itself, however, may be immediate and the reinstatement of banking rails is rarely quick.

For a business sitting between the UK and another licensing hub – a MiCA-authorised entity in an EU member state, an ADGM entity in Abu Dhabi or an AIFC-licensed operation in Kazakhstan – the legal question turns on whether each entity's AML/CFT policy satisfies the obligations of the jurisdiction in which it operates, and whether the group-level policy architecture allocates obligations clearly enough to satisfy each regulator independently. A group AML policy that is drafted at the holding company level, without entity-specific schedules, will generally not satisfy the FCA for the UK entity.

The Tax dimension adds a further layer. The UK's reporting obligations for cryptoasset transactions – including the domestic application of the OECD's Crypto-Asset Reporting Framework (CARF) – create data-collection obligations that must be anticipated in the KYC and transaction-monitoring architecture. A firm that collects AML-driven customer data without structuring it for potential tax-reporting purposes will face a system redesign when reporting obligations become live. Designing the KYC framework to serve both functions from the outset is materially more efficient and is the approach we recommend for any operator building or rebuilding its UK compliance architecture.

If your firm has had a banking relationship terminated or a prior application stalled, a structural review of your AML/CFT policy can identify the root cause and map the route back. Contact OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options.

What Are the Most Common AML/CFT Policy Failures in UK Crypto Firms?

Deficiencies in UK cryptoasset AML/CFT programmes follow recognisable patterns. Understanding them is the fastest route to a gap analysis that is genuinely useful rather than merely reassuring.

The most common failure is a business-wide risk assessment that describes the firm's products and customers in generic terms rather than assessing the actual risks they create. A policy that states "the firm serves retail and institutional clients" without stratifying those segments by risk, transaction profile or geographic exposure is not a risk assessment – it is a description. The FCA's supervisory findings in the sector reflect this distinction consistently.

The second pattern is a Travel Rule procedure that is either absent or silent on the most operationally complex scenarios: transfers to or from unhosted wallets, transactions with VASPs in non-Travel-Rule jurisdictions, and the firm's approach when the required data cannot be obtained. The FATF Travel Rule applies to virtual-asset transfers above the applicable threshold; the UK's implementation imposes data collection and transmission obligations on both sending and receiving VASPs. A procedure that covers only the sending side is incomplete.

The third pattern – particularly in firms that have grown quickly – is a training programme that was adequate at the point of registration but has not kept pace with changes in the firm's product set, customer base or the regulatory environment. Annual training is a minimum; training triggered by material changes to the risk profile is also required. Records of training completion must be maintained.

A common assumption among operators expanding into the UK is that strong AML documentation in another jurisdiction – a VARA-approved programme, an MAS-compliant framework, or a FINMA-registered SRO affiliation – is sufficient to demonstrate AML competence to the FCA. It is not. Each regime has its own supervisory expectations, and the FCA does not accept foreign-compliance satisfaction as a substitute for UK-specific documentation. The UK policy must be drafted for the UK regulatory environment.

Self-Assessment: Is Your UK AML/CFT Policy Fit for FCA Scrutiny?

A firm can conduct an initial self-assessment against the following indicators. These are not a substitute for legal review; they are a triage tool to identify whether an urgent gap analysis is warranted.

  • Has the business-wide risk assessment been updated within the past twelve months, or on the last material change to the product or customer mix?
  • Does the risk assessment specifically address the blockchain-specific risks relevant to the firm – including smart-contract exposure, mixer/tumbler risk and high-risk geographic corridors?
  • Is the Travel Rule procedure documented, operational and tested against the firm's actual transfer volumes and counterparty base?
  • Does the MLRO have a written governance charter, an independent reporting line to the board and documented authority to decline or exit customer relationships?
  • Has the transaction-monitoring system been configured to the firm's documented risk tiers – not to a vendor default?
  • Are training records current, complete and auditable?
  • Has the firm's AML/CFT programme been independently reviewed in the past two years?

If the answer to any of these questions is "no" or "we are not sure," the policy requires attention before the next supervisory interaction. The FCA's cryptoasset supervisory programme is active. Firms that identify and remediate gaps proactively are in a materially stronger position than those that respond to a supervisory finding.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – derived from FATF Recommendation 16 as applied to virtual assets – requires a VASP (virtual asset service provider) to collect and transmit originator and beneficiary information alongside a qualifying virtual-asset transfer. In the UK, this obligation applies to both sending and receiving VASPs above the applicable threshold. The required data includes the originator's name, account identifier and, in certain cases, address or identification number, as well as equivalent beneficiary information. Firms must have a documented procedure for handling transfers where the counterparty cannot receive or provide the required data.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) must be an individual of sufficient seniority and competence, approved or notified to the FCA as required under the firm's registration. The MLRO must have genuine authority to decline customer relationships, unobstructed access to transaction data and a direct reporting line to the board. The role cannot be performed effectively by a nominee or by a part-time consultant without real operational authority. The FCA scrutinises MLRO fitness and propriety at registration and in supervisory reviews; a weak MLRO appointment is a material compliance risk.

How do regulators audit crypto AML programs?

The FCA audits cryptoasset AML programmes through a combination of desk-based reviews, supervisory visits and data requests. Examiners typically request the business-wide risk assessment, the MLRO's most recent annual report, a sample of customer due diligence files, evidence of transaction-monitoring calibration and training records. The FCA may also test whether the firm's operational controls actually match the written policy. Firms that cannot demonstrate a live, functioning programme – not merely a well-drafted document – are at significant risk of a material supervisory finding or, in serious cases, registration cancellation.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence, banking and AML stack across operating, custody and payment layers before our clients commit to a structure – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT programme design and FCA supervisory engagement for UK-registered cryptoasset firms.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours