EST · MMXXVI
Home/Services/Compliance Aml Travel Rule/AML/cft policy drafting for Institutional Clients
Compliance, AML & Travel Rule

AML/cft policy drafting for Institutional Clients

Aml/cft policy drafting for Institutional Clients. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

An institutional digital-asset business operating without a properly drafted AML/CFT policy (an anti-money laundering and counter-terrorist financing governance document) does not merely face a compliance gap. It faces the real prospect of enforcement action, account closures, and the abrupt loss of correspondent banking – the precise risks that a single missed framework obligation can trigger. Regulators across every leading hub now expect institutional-grade documentation: policies calibrated to the firm's actual risk exposure, not borrowed templates from a different business model. This page explains what a compliant AML/CFT policy requires, how the drafting process works at OBOLUS, and where cross-border operators most commonly go wrong.

Why Institutional AML/CFT Policy Drafting Is Different

Institutional clients – exchanges, custodians, token issuers and funds – face a materially higher standard of scrutiny than retail operators. The relevant regulatory regimes, including MiCA and the ESMA supervisory framework across the EU, VARA in Dubai, the MAS Payment Services Act regime in Singapore, and the FCA's Money Laundering Regulations regime in the UK, all require documented, risk-proportionate AML/CFT programs. The word "risk-proportionate" is where institutional drafting diverges sharply from generic VASP boilerplate.

An institutional custodian settling for a fund manager has a different transaction-monitoring profile than a retail exchange. A cross-border payments infrastructure operator is not the same as a token issuer. Each business line generates distinct typologies, distinct counterparty risks, and distinct obligations under the applicable Travel Rule provisions. A policy that does not map to the actual business model will fail a regulatory audit – and increasingly, it will fail the due-diligence review of a correspondent bank before it ever reaches a regulator.

In our cross-border practice, we regularly advise institutional operators who arrived with policies drafted for a different jurisdiction, a different product scope, or an earlier version of the applicable regime. The cost of redrafting after an enforcement referral is many times higher than getting it right at the outset.

Operating without the right policy structure risks enforcement, frozen banking rails and lost institutional relationships. The loss-aversion case is straightforward: a deficient AML/CFT program is one of the top triggers for de-banking in the digital-asset sector.

For a scoped assessment of your current AML/CFT documentation, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking jurisdictions – change the analysis materially. Map your options.

What Is the Regulatory Basis for AML/CFT Policy Obligations?

The baseline for any institutional AML/CFT policy is the FATF Recommendations, specifically Recommendation 15 on virtual assets and the requirement that virtual asset service providers (VASPs) implement risk-based AML/CFT programs. FATF's Recommendation 15 and the accompanying guidance on virtual assets form the architecture that national regulators translate into binding obligations. No flagship jurisdiction departs from that architecture – the variance is in how strictly it is applied and how the Travel Rule data threshold is calibrated.

Under MiCA, authorised CASPs (crypto-asset service providers) operating in the EU or passporting across member states must maintain documented risk assessments, customer due diligence procedures, transaction monitoring systems, and suspicious transaction reporting channels. The ESMA supervisory convergence work means that national competent authorities are progressively aligning their audit expectations across the bloc.

In Dubai, VARA's rulebooks impose equivalent obligations on all licensed activity types – advisory, broker-dealer, custody, exchange, and transfer/settlement. Each activity-based licence carries its own AML/CFT annexe requirements, meaning a multi-product operator must reconcile obligations across several sub-frameworks within the VARA regime.

The MAS Payment Services Act regime in Singapore, the SFC's VASP licensing regime in Hong Kong, FINMA's guidance in Switzerland, and the FCA's MLR registration framework in the UK each layer additional jurisdiction-specific requirements. An institutional operator active across several of these jurisdictions cannot rely on a single-regime policy and assume equivalence. Equivalence must be demonstrated, not assumed.

What Must an Institutional AML/CFT Policy Actually Contain?

A compliant institutional AML/CFT policy is not a single document. It is a suite of interlocking documents – a master policy, supporting procedures, risk appetite statements, and role-specific annexes – that together demonstrate a functioning governance framework to a regulator or a correspondent bank.

The core components regulators expect to see include:

  • A business-risk assessment that maps the firm's products, counterparty types, geographies and transaction volumes against the risk typologies identified in applicable guidance. This is the foundation. Everything else flows from it.
  • A customer due diligence (CDD) and enhanced due diligence (EDD) framework calibrated to the institutional context. For a custodian serving funds, EDD for a Cayman-domiciled fund structure looks different from EDD for a domestic retail customer. The policy must reflect that difference.
  • A transaction monitoring policy that specifies the rule-sets, alert thresholds, escalation procedures and review timelines applied to on-chain and off-chain activity. Regulators increasingly expect documented rationale for rule-set configuration, not just a reference to a vendor's out-of-the-box settings.
  • Travel Rule compliance procedures – the obligation to pass originator and beneficiary data with each covered transfer – specifying how the firm collects, validates, transmits and receives that data, and how it handles transfers from non-compliant counterparty VASPs.
  • A sanctions screening policy covering OFAC, EU consolidated lists, UN designations and any jurisdiction-specific lists the firm is exposed to through its user base or banking arrangements.
  • A suspicious transaction / suspicious activity reporting procedure with clear MLRO escalation paths and documented timelines.
  • An AML/CFT training program with records of delivery and completion – one of the first items a regulatory examiner will request.
  • A policy review and update schedule tied to the firm's risk assessment review cycle and to regulatory change triggers.

Each component must be internally consistent. A policy that lists high-risk jurisdictions in the risk assessment but then applies standard CDD to counterparties from those jurisdictions will fail on its face.

How Does the OBOLUS Drafting Process Work?

We approach institutional AML/CFT policy drafting as a structured legal engagement, not a document-production exercise. The process has four phases, each with a defined deliverable.

The first phase is a regulatory scoping analysis. Before a word of policy is drafted, we map the jurisdictions in which the client is authorised or seeking authorisation, the activity types involved, and the banking relationships that need to be satisfied. A custodian licensed under VARA in Dubai but banking through a Singapore correspondent and serving EU-domiciled funds must satisfy three supervisory expectations simultaneously. The scoping analysis surfaces conflicts and gaps before drafting begins.

The second phase is a business-risk assessment. We work with the client's compliance and operations teams to document the actual risk profile – products, customer segments, geographies, transaction flows, technology stack. This is not a template exercise. The risk assessment drives every downstream policy choice: CDD risk ratings, monitoring thresholds, EDD triggers, and sanction-screening scope.

The third phase is policy and procedure drafting. We draft the master policy and each supporting procedure against the regulatory obligations identified in the scoping analysis and the risk profile identified in the assessment. Where two jurisdictions impose conflicting requirements, we draft to the more demanding standard and document the rationale for correspondent-bank review.

The fourth phase is governance integration. A policy that sits in a folder and is never operationalised will not satisfy a regulator. We assist the client in embedding the policy framework into its MLRO function, its technology vendor configuration, and its board-level reporting cadence. We also prepare the training materials and the review-trigger schedule.

In our practice, the entire engagement from scoping to delivered governance package typically runs over a matter of weeks, depending on the complexity of the client's jurisdictional footprint and product mix. We do not offer off-the-shelf templates.

How Does the Travel Rule Apply to Institutional Digital-Asset Operators?

The Travel Rule – the obligation to pass originator and beneficiary identification data with each covered virtual-asset transfer – is, for institutional operators, one of the most operationally demanding AML/CFT requirements. FATF's Travel Rule guidance has been adopted, with varying data thresholds and de-minimis treatments, across the MiCA regime, VARA, MAS, the SFC's framework and most other flagship regimes.

For a retail exchange, Travel Rule compliance is primarily a technology procurement and counterparty-VASP onboarding question. For an institutional operator, it is a governance and risk-management question of a different order. An OTC desk handling large-value transfers between institutional counterparties must document how it validates the identity of the originating and beneficiary VASPs, how it handles transfers from jurisdictions that have not yet implemented the Travel Rule, and how it manages the "sunrise problem" – the compliance asymmetry that arises when one side of a transfer is operating under a regime that does not yet require Travel Rule data.

Our AML/CFT policy drafting for institutional clients covers Travel Rule compliance as a distinct module: the data collection and validation procedure, the counterparty-VASP due diligence framework, the treatment of unhosted wallets (which regulators in multiple jurisdictions are progressively restricting for institutional accounts), and the escalation procedure when Travel Rule data is unavailable or inconsistent.

The data threshold above which the Travel Rule obligation is triggered varies by jurisdiction and is marked as a verify-before-use figure in our analysis. We advise clients qualitatively on the applicable threshold in each relevant regime and build the policy to comply with the most demanding standard where conflicts arise.

What Are the Most Common AML/CFT Policy Mistakes in Cross-Border Operations?

Cross-border institutional operators make the same category of mistakes with enough frequency that we see recognizable patterns across engagements. Understanding them is the fastest way to self-assess the adequacy of an existing policy.

The most persistent mistake is jurisdiction transposition: taking a policy drafted for one regulatory regime and filing it with a second regulator without updating the substantive obligations. An FCA-facing AML policy does not automatically satisfy VARA's rulebook requirements. Each regime has its own defined terms, its own CDD standard, and its own reporting channel. A regulator reading a policy written for another jurisdiction will identify the mismatch quickly.

A close second is risk-assessment abstraction. Many institutional operators have a risk assessment that reads as a generic description of virtual-asset risks rather than a document specific to the firm's own products and counterparties. A regulator examining a policy for a derivatives desk that contains no reference to the specific counterparty types or settlement mechanics of that desk will treat the risk assessment as incomplete.

Third is Travel Rule implementation lag. The policy commits to Travel Rule compliance; the technology vendor has not been configured; the counterparty-VASP onboarding process has no Travel Rule data request embedded. The gap between documented obligation and operational reality is a regulatory finding waiting to happen.

Fourth – and directly relevant to the institutional context – is failure to document the MLRO's authority and escalation path. A policy that names an MLRO but does not define the decision rights, the reporting line to the board, and the conflict-resolution mechanism for cases where the MLRO and management disagree will not satisfy the governance expectations of leading regulators.

A common assumption among first-time institutional applicants is that a single offshore registration is sufficient to cover global institutional client activity. It is not. The regulatory obligation follows the user, the transaction, and the banking relationship – not just the place of entity incorporation. We address this directly in every policy drafting engagement.

Which Institutional Profile Requires Which AML/CFT Policy Structure?

Institutional operators are not a homogeneous group. The appropriate policy structure depends on the firm's activity mix, jurisdictional footprint, and counterparty profile. The following decision framework illustrates the principal variants.

Profile A – Multi-jurisdiction exchange with retail and institutional segments. This operator requires a bifurcated CDD framework: one track for retail customers (standard risk-rating, automated monitoring) and a separate institutional-counterparty track with documented EDD, Travel Rule compliance at the entity level, and a correspondent-bank-facing summary of the institutional KYC program. The policy must address the VARA or MAS or SFC regime in the primary licensing jurisdiction and, where passporting is not available, identify the regime applicable in each additional operating jurisdiction. Timeline to complete drafting: typically a matter of weeks from scoping completion, depending on the number of active jurisdictions. Key risk: failure to reconcile conflicting CDD standards across the jurisdictions without a documented rationale.

Profile B – Institutional custodian serving regulated funds. The EDD requirements for a fund as a customer are distinct. The policy must address the look-through obligation (identifying the underlying beneficial owners of the fund, not merely the fund vehicle), the treatment of funds domiciled in offshore jurisdictions, and the sanctions-screening obligations at the underlying investor level where required by applicable law. The Travel Rule obligation in this context is limited to transfer instructions, but the custodian's policy must be explicit about what data is collected, retained, and transmitted. Key risk: inadequate beneficial ownership documentation for complex fund structures.

Profile C – Token issuer at the primary-offering stage. The AML/CFT policy for a token issuer must address the KYC framework applied at subscription, the sanctions-screening obligations for purchasers, and the secondary-market transfer controls where the issuer retains any role in the transfer mechanism. Where the token is classified as an ART or EMT under MiCA, the issuer's obligations under the applicable MiCA authorisation requirements apply directly. Key risk: treating the primary offering as outside the AML/CFT perimeter because it is structured as a placement rather than a financial service.

Profile D – OTC desk or liquidity provider. Large-value institutional transactions generate a heightened obligation to document the source of funds and the business purpose of each transaction. The policy must specify the EDD trigger for transaction size, the source-of-funds documentation standard, and the escalation path for transactions that cannot be fully documented before execution. The Travel Rule is directly engaged. Key risk: treating counterparty-VASP relationships as a VASP-level CDD exercise rather than applying transaction-level EDD to individual transfers above the applicable threshold.

A Recent AML/CFT Policy Engagement

Earlier this year, a licensed exchange operating across two major regulatory hubs engaged OBOLUS after its banking partner notified it that the existing AML/CFT policy was inadequate for correspondent-banking due diligence. The exchange's policy had been drafted for an earlier, simpler product scope and did not address the institutional segment the firm had since added. We conducted a full regulatory scoping analysis, identified the gaps against both applicable regimes, and redrafted the master policy, the CDD and EDD procedures, and the Travel Rule compliance module. We also prepared a policy summary document for the correspondent bank's compliance team. The banking relationship was maintained, and the exchange subsequently passed a regulatory examination without a finding against its AML/CFT governance. The engagement ran over approximately six weeks.

If a prior application stalled or a banking relationship is under review, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options.

AML/CFT Policy Self-Assessment: Five Questions to Ask Now

Before engaging counsel or beginning a redraft, an institutional operator can quickly gauge policy adequacy against five diagnostic questions.

  • Is the business-risk assessment jurisdiction-specific and product-specific? A risk assessment that does not name the firm's actual product lines, actual customer segments, and actual operating jurisdictions is not adequate. Generic language about virtual-asset risks is not a substitute for documented analysis of the firm's own risk profile.
  • Does the Travel Rule procedure document what happens when counterparty data is unavailable? Most policies document the affirmative obligation. Few document the escalation and decision procedure for the case where a counterparty VASP does not provide Travel Rule data. Regulators ask about this directly.
  • Is the MLRO's authority documented, including the conflict-resolution path? A policy that names an MLRO without defining decision rights, reporting lines, and the mechanism for escalating a disagreement with management does not satisfy the governance expectations of ESMA-aligned regulators, VARA, or the MAS regime.
  • Was the policy last reviewed after the most recent regulatory change in each applicable jurisdiction? MiCA's CASP provisions, VARA's rulebook updates, and the SFC's VASP regime all impose ongoing policy-review obligations tied to material change. A policy that has not been updated since a regime change is non-compliant on its face.
  • Has the policy been tested against a correspondent bank's due-diligence request? Banking due diligence is often more demanding than regulatory examination. If the policy has never been stress-tested against an actual correspondent-bank questionnaire, it may satisfy the regulator but fail the bank – with operational consequences that arrive faster.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect, verify, and transmit originator and beneficiary identification data with each covered virtual-asset transfer. The specific data fields required and the transfer-value threshold above which the obligation is triggered vary by jurisdiction. Most leading regimes have adopted the FATF standard, which includes the originator's name, account identifier, and address or other identifying information, alongside equivalent beneficiary data. A VASP must also document how it handles transfers where the counterparty VASP fails to provide the required data.

Who must act as MLRO for a crypto firm?

Most licensed jurisdictions require a designated Money Laundering Reporting Officer (MLRO) who carries personal accountability for the firm's AML/CFT compliance. The MLRO must be sufficiently senior to have authority over compliance decisions, must have a documented reporting line to the board, and must not hold a role that creates a structural conflict of interest with the compliance function. Regulators including VARA, the FCA, and ESMA-aligned national competent authorities increasingly scrutinize the MLRO appointment as part of licensing and ongoing supervision. The MLRO's qualifications, authority and escalation path must be documented in the firm's AML/CFT policy.

How do regulators audit crypto AML programs?

Regulators auditing a digital-asset firm's AML/CFT program typically request the firm's written policies, its business-risk assessment, a sample of customer due diligence files (including EDD files for higher-risk customers), transaction monitoring alert logs and disposition records, training records, and suspicious transaction reports filed over the review period. They also examine the MLRO's governance documentation. The audit may be triggered by a licensing review, a periodic supervisory examination, or an event-driven inquiry. Firms that cannot produce complete, current documentation across all of these areas are at heightened risk of a regulatory finding.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the AML/CFT compliance, Travel Rule implementation and KYC framework design that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – so the structure works in every jurisdiction it needs to. To discuss your AML/CFT policy requirements, contact info@oboluslaw.com or reach us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML/CFT governance frameworks, Travel Rule implementation, and VASP/CASP regulatory compliance across multi-jurisdiction digital-asset operations.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours