Digital-asset businesses face a tightening enforcement environment. Anti-money laundering obligations, Travel Rule compliance (the requirement to pass originator and beneficiary data with every qualifying transfer), and KYC (know-your-customer) screening have moved from aspirational best practice to hard regulatory expectation across every major hub. A business that gets this wrong faces more than a fine: it faces frozen banking relationships, suspended licences and, in the worst cases, criminal referral of its responsible officers. This page maps the full compliance perimeter for digital-asset businesses, explains the cross-border obligations that most operators underestimate, and sets out how OBOLUS structures engagements in this practice.
What Is the Regulated Compliance Perimeter for a Digital-Asset Business?
Every firm that qualifies as a VASP (virtual asset service provider) under FATF Recommendation 15 – and its national implementations – is inside the AML/CFT perimeter from the moment it onboards its first customer. That perimeter covers customer due diligence, ongoing transaction monitoring, suspicious activity reporting, sanctions screening, record-keeping and, critically, Travel Rule compliance on transfers above the applicable threshold. FATF Recommendation 15 extended the full AML/CFT framework to VASPs and obligated member jurisdictions to regulate them accordingly. In practice, the perimeter is wider than most operators expect.
The regulated perimeter is not defined by where your servers sit. It follows the activity. An exchange incorporated in a low-supervision jurisdiction but serving EU residents is within the reach of MiCA and the national transpositions of the EU's AML directives. A custody platform registered in Singapore under the Payment Services Act (the MAS licensing regime for digital payment token services) that accepts US clients risks triggering FinCEN obligations simultaneously. Regulators do not respect corporate convenience structures.
In our practice, we see the same pattern repeatedly: a business launches under one regime, grows its user base across multiple regions, and discovers – usually during a banking review or a regulatory enquiry – that it is operating outside its licensed perimeter in two or three jurisdictions. The exposure is not theoretical. Enforcement actions by the FCA, VARA and MAS have all proceeded on exactly this factual basis.
The obligation map has three layers. First, the home-jurisdiction AML regime: the rules set by the regulator that granted the licence. Second, the host-jurisdiction obligations: the AML rules of every country where the business actively provides services or markets itself. Third, the global standards: FATF's framework, OFAC sanctions and, increasingly, the Travel Rule data standards that are converging across the major hubs. Failing any one layer can destabilize all three.
For a scoped assessment of your compliance perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis materially. Map your options
How Does the FATF Travel Rule Apply to VASPs?
The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual-asset transfer – and to hold that data available for competent authorities. FATF's guidance on virtual assets (updated most recently in 2021) treated the Travel Rule as a direct analogue of the wire-transfer rule applied to banks. The threshold above which data must travel with the transaction varies by jurisdiction, but the principle is now embedded in the licensing conditions of every major hub.
Implementation differs significantly across regimes. Under MiCA and the EU's Transfer of Funds Regulation (as extended to crypto-assets), the obligation applies from the first euro. Singapore's MAS imposes Travel Rule obligations under the Payment Services Act from a stated transfer threshold. The FCA's UK regime, VARA in Dubai, and ADGM's FSRA in Abu Dhabi each have their own thresholds and technical standards for the data fields that must accompany a transfer. An operator active in three jurisdictions may be running three slightly different compliance workflows on the same underlying transfer.
The technical challenge compounds the legal one. Sending and receiving VASPs must exchange data before or simultaneously with the transfer – using a protocol that both counterparties support. Where the counterparty VASP is in a jurisdiction that has not yet implemented the Travel Rule, the sending VASP often faces an obligation it cannot practically fulfil. This is the "sunrise problem," and regulators have addressed it inconsistently. Some permit a documented best-efforts approach; others hold the sending VASP strictly liable regardless of the counterparty's capabilities.
In a recent compliance-restructuring matter, an exchange had been applying Travel Rule obligations only to inter-VASP transfers above a single threshold – the figure it understood to apply in its home jurisdiction. An expansion into the EU exposed it to the more stringent Transfer of Funds Regulation standard. We mapped the full obligation set, built a jurisdiction-by-jurisdiction threshold schedule and helped the firm select a compliant messaging protocol. The project ran over a single quarter.
What KYC and Customer Due Diligence Standards Apply to Crypto Firms?
A compliant KYC program for a digital-asset business has three mandatory elements: customer identification and verification, beneficial ownership determination (for corporate customers) and ongoing due diligence calibrated to risk. The risk calibration piece is where most crypto-firm programs fall short. A regime that treats a retail DeFi user identically to an institutional OTC counterparty is not risk-based – and regulators know it.
Under MiCA's AML expectations, VARA's rulebooks and MAS's notices under the Payment Services Act, a VASP must maintain a written risk assessment, segment its customer base by risk tier and apply enhanced due diligence to high-risk categories: politically exposed persons, customers from high-risk jurisdictions on the FATF grey list, and transactions with unhosted wallets above applicable thresholds. FATF's mutual evaluation process reviews whether national supervisors are effectively enforcing these standards on VASPs in their jurisdiction.
The cross-border angle is acute. A firm licensed under VARA in Dubai that accepts corporate clients incorporated in BVI, Cayman or other offshore centres must satisfy the beneficial ownership look-through obligations of the VARA rulebooks – not merely the standards of the client's home jurisdiction. Where the client's UBO sits in a jurisdiction on a relevant grey list, enhanced due diligence is mandatory, not optional. We regularly advise on the layering of these obligations for multi-entity client structures.
One persistent mistake is treating KYC as a one-time onboarding event. Ongoing monitoring requires periodic refresh of customer data, event-triggered re-verification (a change of UBO, a new jurisdiction of operations, a spike in transaction volumes) and documented closure of accounts where refresh is refused. An auditor or regulator examining a two-year-old customer file with no activity record will treat the absence of refresh as a control failure, regardless of how thorough the original onboarding was.
How Should a VASP Structure Its Transaction Monitoring Program?
Effective transaction monitoring for a digital-asset business requires a combination of on-chain analytics, rule-based alerts and human review – and the three must be integrated in a way that the firm can demonstrate to a regulator. Buying a blockchain analytics subscription and treating it as a monitoring program is not enough. Regulators including the FCA and MAS have issued guidance making clear that monitoring must be calibrated to the firm's specific risk profile and customer base.
On-chain analytics tools – the category includes products from Chainalysis, TRM Labs and Elliptic, among others – produce risk signals and exposure scores for individual wallet addresses and transactions. Those signals must flow into a documented alert workflow: who reviews flagged transactions, within what timeframe, against what escalation criteria, and with what record-keeping. Where a transaction triggers a suspicious activity report obligation, the firm must file promptly and must not tip off the customer.
The monitoring architecture for a multi-jurisdiction operator is more complex. Different regulators set different thresholds for structuring alerts, cash-equivalent exposure limits and high-risk counterparty flags. A single global monitoring ruleset calibrated to the most stringent jurisdiction is conservative but defensible. A jurisdiction-specific ruleset that applies weaker monitoring in lower-regulation markets is a vulnerability – regulators compare notes, and a gap identified in one market will be interrogated in others.
Operators we advise routinely underestimate the documentation burden. A monitoring program that generates alerts but cannot demonstrate what happened to each alert – who reviewed it, what they concluded and what action followed – will fail an audit even if the underlying controls are sound. The audit trail is not an administrative formality. It is the evidence that the program functions.
If a prior compliance review flagged weaknesses in your monitoring architecture, a second read can surface the structural reason and the route to remediation. Contact OBOLUS at info@oboluslaw.com or reach us via t.me/oboluslaw. Map your options
Who Must Serve as MLRO and What Governance Does a Crypto Firm Need?
A Money Laundering Reporting Officer (MLRO) is a mandatory appointment under the AML frameworks of every major licensing jurisdiction – from the FCA's MLR regime in the UK to the VARA rulebooks in Dubai to the Payment Services Act notices in Singapore. The MLRO receives internal suspicious activity reports, decides whether to file externally, owns the AML policy suite and is the primary point of contact for the regulator on AML matters. This is a senior, accountable role – not an administrative function.
The fit-and-proper standard for an MLRO varies by jurisdiction but consistently requires relevant financial crime experience, no disqualifying regulatory history and the seniority to escalate concerns to the board without interference. In our practice, we have seen regulators reject MLRO nominations where the candidate had no experience specific to virtual assets, or where the reporting line ran through the commercial team rather than directly to the board or audit committee. Both are red flags under the governance standards that VARA, the FCA and MAS each apply.
Beyond the MLRO appointment, a compliant governance structure requires a written AML/CFT policy approved at board level, a risk assessment reviewed at least annually, a training program with documented completion records and an independent audit function that reviews the AML program on a schedule proportionate to the firm's risk profile. The independence of the audit function is non-negotiable: a self-review by the compliance team satisfies no regulator's standard.
For businesses structured across multiple entities – a common structure for an exchange that separates the technology company, the licensed entity and the custody vehicle – the governance question becomes which entity employs the MLRO and whether each regulated entity has its own designated officer or whether a group MLRO structure is permissible under each applicable regime. The answer varies. AIFC's AFSA, for instance, has specific expectations about the local presence and authority of a compliance officer within the AIFC perimeter.
What Are the Cross-Border AML Obligations That Most Operators Miss?
The single most common compliance failure we see in cross-border digital-asset businesses is the assumption that a home-jurisdiction licence and a single AML program covers the full exposure. It does not. Each jurisdiction where a VASP actively markets or provides services imposes its own AML obligations – and those obligations apply whether or not the VASP has a local licence.
The EU's Transfer of Funds Regulation (as extended to crypto-assets under MiCA) applies to transfers involving EU-resident counterparties regardless of where the sending VASP is incorporated. FinCEN's Bank Secrecy Act obligations apply to any money services business – including a VASP – that operates in or does business touching the United States. AUSTRAC registration requirements in Australia apply to businesses that provide digital currency exchange services to Australian residents. None of these obligations are triggered by the location of a server. They are triggered by the customer.
Sanctions compliance adds another layer. OFAC's SDN list obligations apply extraterritorially to any transaction that has a US nexus – which, for a dollar-denominated stablecoin transfer clearing through US-correspondent banking, is nearly every transaction. The UK's HMT financial sanctions regime and the EU's sanctions regime apply similarly broad reach. Tether and Circle, as issuers of the two largest stablecoins by market capitalization, hold the technical ability to freeze tokens on-chain and act on OFAC designations and court orders. A sanctions screening failure is not merely a regulatory issue – it can result in the issuer freezing the firm's own operating balances.
For businesses with a presence in multiple GCC jurisdictions, the interaction of VARA's Dubai perimeter with ADGM's FSRA regime in Abu Dhabi and the forthcoming federal UAE framework requires careful mapping. These are three distinct regulatory perimeters operating in the same national territory – a fact that surprises operators who assume a single UAE-wide licence is achievable or sufficient.
What Happens in a Regulatory AML Audit or Enforcement Action?
A regulatory AML audit of a digital-asset business typically proceeds in three phases: a document review (policies, procedures, training records, monitoring logs, SAR filing history), a systems review (a walk-through of the technical monitoring and KYC infrastructure) and, increasingly, a transaction review in which the regulator samples a cohort of customer onboarding files and monitored transactions to test whether the documented controls actually operated. The third phase is where most deficiencies surface.
Regulators across the major hubs have sharpened their crypto-specific audit capabilities. The FCA has issued multi-firm reviews identifying systemic weaknesses in crypto-firm AML programs. MAS has published thematic observations on DPT service providers. VARA's supervisory team in Dubai includes staff with exchange-specific compliance backgrounds. An audit by these bodies is not a tick-box review of paper policies – it is a substantive interrogation of whether the firm's controls function in practice.
Enforcement outcomes range from a direction to remediate identified weaknesses to suspension of the licence pending remediation, a public censure, a financial penalty and, at the most serious end, referral to law enforcement. The severity of the outcome correlates directly with two factors: the nature of the underlying failure (a documentation gap is less serious than a failure to file SARs on known suspicious activity) and the firm's response to the audit (a cooperative, evidence-based response mitigates significantly; a defensive or incomplete one aggravates).
In a recent audit-defence engagement, a payments firm regulated under an EU national competent authority received a supervisory letter citing weaknesses in its Travel Rule implementation and its beneficial ownership verification for corporate clients. We mapped the specific gaps against the regulatory expectations, built a remediation plan with sequenced deliverables and managed the written correspondence with the regulator. The matter closed without formal enforcement action in less than one business quarter.
How Do AML Obligations Apply to Unhosted Wallets and DeFi?
Unhosted wallet interactions and DeFi protocol engagement represent the frontier of AML compliance – the area where regulatory expectations are evolving fastest and where the gap between the written rule and enforcement practice is widest. The answer varies materially by jurisdiction and by the specific nature of the interaction.
Under the EU's Transfer of Funds Regulation, a VASP making a transfer to or from an unhosted wallet above the applicable threshold must collect and verify the identity of the wallet's controller before processing. The technical mechanism for that verification – a small test transaction, a cryptographic proof of address control, a self-declaration – is not mandated in the regulation itself and varies by implementing guidance. ESMA and the European Banking Authority have issued joint guidance, but national competent authorities have retained significant interpretive discretion.
VARA's Dubai rulebooks impose unhosted wallet due diligence obligations on licensed VASPs, requiring risk-based screening of wallet addresses and enhanced measures for high-risk exposures. The FSRA in ADGM takes a similarly risk-based approach. In both cases, the expectation is that the VASP's on-chain analytics tool flags the unhosted wallet for risk scoring and that the firm documents its response to material risk signals.
DeFi raises a harder question: where no identifiable entity is providing the service, who carries the VASP obligation? FATF's guidance acknowledges the category but stops short of a definitive answer for fully decentralized protocols. In our practice, we see the regulatory pressure directed not at the protocol itself but at the identifiable points of centralization – the frontend operator, the foundation, the team that controls upgrade keys. Firms operating at those points of centralization should treat themselves as within the VASP perimeter until the regulatory analysis in their jurisdiction clearly establishes otherwise.
Which Compliance Instruments Fit Which Operator Profile?
The right compliance architecture depends on the firm's activity type, user base geography and stage of development. There is no single configuration that fits all digital-asset businesses, and an architecture that works for a spot exchange will be materially deficient for a custody provider or a token issuer. The following decision matrix sets out the principal profiles we encounter and the primary compliance instruments each requires.
Profile A – A centralized exchange licensed in one MiCA jurisdiction, passporting into the EU/EEA. The primary instruments are a CASP-grade AML policy suite, a full Travel Rule implementation covering the Transfer of Funds Regulation zero-threshold standard, a risk-based KYC framework with enhanced due diligence tiers and a monitoring program calibrated to the exchange's transaction volumes and risk typologies. The MLRO must be a senior, experienced hire with board-level reporting authority. The timeline to reach audit-ready status from a standing start is typically measured in months, not weeks.
Profile B – A multi-jurisdiction operator with a VARA licence in Dubai and a US-facing business through a separately licensed entity. This profile requires parallel compliance programs that meet both VARA's rulebooks and FinCEN's Bank Secrecy Act expectations. The Travel Rule obligations differ: VARA applies its own threshold and data standards; FinCEN's CVC (convertible virtual currency) guidance applies separately. Sanctions screening must satisfy OFAC requirements across the US entity and any transaction with a US nexus touching the Dubai entity. The risk of cross-contamination between the two programs – where a control failure in one is treated as evidence of systemic failure in the other – requires an explicit governance separation.
Profile C – An early-stage token issuer preparing for a regulated public offer under MiCA. The compliance obligation at the issuance stage is primarily the ART or EMT whitepaper and disclosure regime administered by ESMA and the relevant NCA. Post-issuance, if the issuer's token circulates on CASP platforms, it is those CASPs that carry the primary AML obligation for transfers – but the issuer retains responsibility for its own AML program in respect of the initial distribution and any ongoing services it provides directly. An early engagement with the NCA on the whitepaper and the AML framework is the most efficient path.
Profile D – A custody provider operating across multiple common-law offshore centres (BVI, Cayman) with clients in the EU and Asia-Pacific. The BVI FSC's VASP Act 2022 and CIMA's VASP Act each impose registration and AML obligations. Those obligations run in parallel with the MiCA obligations triggered by EU-resident clients and the MAS obligations triggered by Singapore-resident clients if the custody firm is providing services in that market. The compliance architecture must address each home-jurisdiction regime and each host-jurisdiction trigger – a matrix that requires explicit jurisdictional mapping before any compliance program can be written.
A Common Assumption: One Offshore Structure Covers Global Operations
A common assumption among early-stage digital-asset businesses is that a single offshore registration – or even a single well-regarded licence – provides sufficient AML cover for a global user base. This assumption is incorrect, and acting on it is one of the most reliable routes to enforcement exposure.
An offshore registration addresses only the home-jurisdiction obligation. It says nothing about the AML obligations imposed by the jurisdictions where the firm's users are located, where its banking relationships are maintained or where its tokens trade on secondary markets. A CIMA registration for a Cayman-incorporated exchange does not satisfy the FCA's MLR registration requirement for UK users. It does not satisfy MAS's DPT licensing requirement for Singapore users. It does not satisfy the Transfer of Funds Regulation for EU-resident counterparties. Each of those obligations exists independently and is enforced independently.
The banking relationship amplifies the risk. Correspondent banks and payments processors conduct their own AML due diligence on the businesses they serve. A business that holds only an offshore registration and serves a global user base will find it progressively harder to maintain banking relationships as its scale increases and its banking counterparties' compliance scrutiny intensifies. We have seen businesses lose their entire banking stack – not through regulatory enforcement, but through voluntary de-risking by their banking counterparties – because the compliance architecture did not match the geographic footprint.
The practical answer is a jurisdiction-by-jurisdiction obligation mapping conducted before launch, with a compliance architecture designed to address every triggered obligation from day one. Retrofitting a compliance program to a live business is significantly more expensive and disruptive than building it correctly at the outset. We map the licence and compliance stack across the operating, custody and payment layers before our clients commit to a structure.
Related at OBOLUS
- AML Audit Defence in Brazil – Navigating regulator-led AML reviews for digital-asset firms in Brazil
- DeFi Protocol Legal Structuring in Czech Republic – Structuring decentralized-protocol operations within the EU MiCA perimeter
- Crypto Exchange Setup in the Isle of Man – Licensing and compliance requirements for exchange operations in the Isle of Man
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary information – including name, account number or wallet address, and identifying data – alongside every qualifying virtual-asset transfer. The obligation applies above thresholds that vary by jurisdiction: the EU's Transfer of Funds Regulation applies from the first euro; other regimes set a stated minimum threshold. Both the sending and receiving VASP must retain the data and make it available to competent authorities on request. Failure to comply is an AML control deficiency that regulators treat seriously.
Who must act as MLRO for a crypto firm?
Every VASP licensed under the AML frameworks of the major hubs – including those administered by the FCA, VARA, MAS and AFSA – must appoint a named Money Laundering Reporting Officer. The MLRO must be a senior individual with relevant financial crime experience, a clean regulatory history and direct reporting authority to the board or audit committee. The role carries personal accountability: the MLRO makes the final decision on suspicious activity report filings and is the firm's primary contact for the regulator on AML matters. Most regimes require regulatory pre-approval of the appointment.
How do regulators audit crypto AML programs?
A regulatory AML audit of a crypto firm typically covers three areas: policy and procedure documentation, technical systems (KYC platform, transaction monitoring, on-chain analytics integration) and a transaction sample review in which the regulator tests whether documented controls actually operated on live cases. Regulators including the FCA, MAS and VARA have developed crypto-specific audit methodologies and staff with exchange-sector experience. Firms that can demonstrate an end-to-end audit trail – from alert generation through human review to disposition – are materially better positioned than those whose documentation stops at the policy level.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence and compliance stack across the operating, custody and payment layers before clients commit to a structure – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where enforcement or recovery action follows. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Elena Frost, Partner – Compliance, AML/KYC, Travel Rule — specialising in cross-border AML program design, Travel Rule implementation and regulatory audit defence for digital-asset businesses across the major licensing hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.