EST · MMXXVI
Home/Services/Compliance Aml Travel Rule/AML/cft policy drafting for Regulated Entities
Compliance, AML & Travel Rule

AML/cft policy drafting for Regulated Entities

Aml/cft policy drafting for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Regulated digital-asset businesses face a hard truth: a weak AML/CFT policy (a documented anti-money-laundering and counter-terrorist-financing program) is not merely a compliance gap – it is the single most common trigger for supervisory action, banking termination and licence revocation across every major hub. As VASP supervision tightens under MiCA, VARA, the MAS Payment Services Act and equivalent regimes, regulators no longer accept generic templates; they expect policies that map directly to the firm's product, user base, risk appetite and cross-border footprint. Operating without a defensible AML/CFT framework exposes the business to enforcement, frozen payment rails and the loss of correspondent banking that most digital-asset firms already find difficult to secure. This page explains what the drafting process involves, where businesses most often go wrong, and how OBOLUS structures the work for regulated entities operating across multiple jurisdictions.

Why AML/CFT Policies Fail Regulatory Inspection

Most policy failures share a structural cause: the document was built for registration, not for operation. A regulator reviewing a VASP (virtual asset service provider) at examination will cross-reference the written policy against transaction monitoring logs, escalation records and staff training certificates. A policy that describes a risk appetite in the abstract but cannot be traced to a live customer-risk scoring model, a suspicious-activity referral trail or a defined MLRO (money-laundering reporting officer) escalation path will fail that cross-reference instantly.

Under MiCA and the national regimes transitioning into it, the expectation is explicit: policies must be proportionate to the business model. An exchange processing large-volume institutional flows is held to a materially higher standard than a custody wallet with retail users, even if both hold a CASP (crypto-asset service provider) authorisation from the same national competent authority. Regulators across the EU increasingly coordinate through ESMA's supervisory convergence tools, meaning a weak policy in one member state can generate adverse commentary that travels.

In our practice, the most common inspection failure points are: a KYC framework that sets verification tiers on paper but applies them inconsistently in the onboarding system; transaction monitoring thresholds that were set at launch and never recalibrated; and a Travel Rule implementation that covers outbound transfers but misses inbound-counterparty due diligence. Each of these is fixable during drafting. None is fixable once a supervisory review is already open.

For a scoped assessment of your current AML/CFT program before the next examination cycle, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk profile. Your entity structure, user geography and product mix change the analysis materially.

What Regulators Require from an AML/CFT Policy

Every major regime grounds its AML/CFT requirements in the FATF Recommendations, including Recommendation 15 on virtual assets, which demands that VASPs apply the full suite of customer due diligence, record-keeping, suspicious activity reporting and Travel Rule obligations. How those recommendations translate into enforceable obligations differs by jurisdiction, but the structural building blocks are consistent.

A compliant AML/CFT policy for a regulated entity must address, at minimum: the firm's risk-based approach methodology, specifying how it rates jurisdictional risk, customer risk and product/channel risk; the KYC framework (know-your-customer procedures covering identity verification, beneficial ownership and enhanced due diligence triggers); the transaction monitoring program and its escalation logic; the Travel Rule (the FATF obligation to pass originator and beneficiary data with every qualifying virtual-asset transfer) implementation across both outbound and inbound flows; politically exposed person screening; sanctions screening against relevant lists; and the MLRO role, authority and reporting lines.

Under VARA in Dubai, the rulebooks introduce additional layering: each activity licence carries its own compliance schedule, and the policy must map to the specific licensed activity, not to a generic VASP description. Similarly, ADGM's FSRA expects a policy that is calibrated to the recognised virtual assets the firm handles and the client classification model in use. In Singapore, the MAS Payment Services Act supervision expects documented periodic reviews and a compliance testing calendar that the policy itself should mandate.

How Does the Travel Rule Affect Policy Drafting?

The Travel Rule adds a layer of inter-institutional due diligence that most AML policies still handle inadequately. The obligation requires that a VASP transmitting a virtual-asset transfer above the applicable threshold passes originator name, account number and address – and beneficiary name and account number – to the receiving institution. The receiving VASP must then screen that data before crediting the funds.

In practice, drafting a Travel Rule section requires the policy to resolve several operational questions that have no single global answer. What threshold triggers the obligation? That varies by jurisdiction: the FATF standard sets a baseline, but national regulators have discretion, and a firm serving users across the EU, the UAE and Singapore must reconcile three different applicable regimes in a single workflow. Which Travel Rule messaging protocol does the firm use? The policy must name it and describe the fallback procedure when the counterparty VASP is unhosted or does not respond.

We regularly advise clients who have adopted a Travel Rule technology solution – whether a TRISA-compatible system, the OpenVASP protocol or a proprietary integration – but whose written policy does not reflect the actual operational workflow. That gap, between what the document says and what the system does, is what the examination surfaces. The fix is to draft the policy after the operational architecture is mapped, not before.

Cross-border complexity compounds quickly. A firm licensed under MiCA in an EU member state, operating a custody layer in ADGM and processing payments through a Singapore entity under the MAS regime, carries Travel Rule obligations across all three frameworks simultaneously. The policy must specify which entity bears primary Travel Rule responsibility for which flow, and how the group AML function coordinates escalation across those three regulatory perimeters.

The Drafting Process: What OBOLUS Does

Effective AML/CFT policy drafting begins with a gap analysis, not a template. The gap analysis maps the firm's current state – its entity structure, licensed activities, product architecture, user geography and existing compliance documents – against the requirements of each applicable regime. That mapping produces a scoped list of documents that need to be drafted, revised or consolidated.

The typical engagement for a regulated entity covers the following stages. First, a pre-drafting diagnostic: we review existing policies, examine the operational architecture and interview the compliance function to identify the gaps. Second, the principal policy document: we draft the group AML/CFT policy incorporating the risk-based approach, customer risk methodology, KYC framework, transaction monitoring parameters, Travel Rule implementation, sanctions and PEP screening, and the MLRO mandate. Third, the supporting schedule set: we draft the entity-level schedules that translate the group policy into jurisdiction-specific obligations – each schedule addresses the local regulator's specific requirements by name, without invention.

Fourth, the operational procedures layer: the policy is only as strong as the procedures that implement it. We draft or review the customer onboarding procedure, the enhanced due diligence trigger checklist, the suspicious activity report escalation pathway and the Travel Rule operational runbook. Fifth, the training and testing framework: the policy must mandate a training calendar and a periodic compliance testing program; we draft those governance documents as part of the engagement.

A recent engagement illustrates the scope. A regulated exchange holding licences in two Gulf jurisdictions and an EU member state had a group AML policy drafted at the time of its first licence application. By the time it applied for its third licence, the policy had not been updated to reflect a new retail product or the Travel Rule obligations that accompanied it. We conducted the gap analysis, identified the structural inconsistencies across the three regulatory regimes, and rebuilt the policy and schedule set in a matter of weeks. The firm entered its next supervisory review with a defensible, current document set.

Common Mistakes Regulated Entities Make

Generic templates, copied from public sources or repurposed from a previous licence application, are the single most dangerous starting point. Regulators have seen them. A policy that describes "enhanced due diligence for high-risk customers" without specifying the triggers, the additional data points required and the approval authority needed to onboard such a customer is not a policy; it is a placeholder.

A common assumption is that a single policy document covering the group is sufficient for every entity within it. In our practice, that assumption does not survive examination in any major hub. Each regulated entity – whether the exchange, the custodian or the payment processor – holds its own licence, bears its own supervisory relationship, and must be able to produce its own compliant policy. The group policy sets the framework; the entity-level schedule implements it for the specific regulated activity and jurisdiction. Conflating the two is a structural error that no amount of revision to the group document can fix.

A second common error is the static risk appetite statement. The risk appetite must be reviewed and recalibrated on a documented schedule; many policies specify an annual review but provide no mechanism for triggering an out-of-cycle review when the product changes or when a new jurisdiction is added to the firm's footprint. Regulators under the VARA rulebooks and the MAS regime both assess whether the firm's risk management kept pace with its commercial expansion.

Third: the Travel Rule section that covers outbound flows only. The receiving-VASP obligation – screening inbound originator data, handling non-compliant or missing data, and refusing credits where the counterparty cannot be identified – is as legally mandatory as the transmitting obligation and is more frequently examined because it is more often incomplete.

If a prior application stalled, a supervisory review opened, or a banking relationship was terminated citing AML concerns, reach OBOLUS at info@oboluslaw.com for a second-read assessment. A structural review can surface the specific deficiency and the route to remediation before the issue escalates.

Cross-Border AML/CFT Policy Considerations

For a business operating across multiple jurisdictions, the AML/CFT policy question is fundamentally a group-architecture question. The choice of where the group compliance function sits, which entity acts as the primary MLRO for cross-border escalations, and how the policy reconciles divergent local requirements is a legal and structural decision, not purely an operational one.

Consider a firm with an exchange licensed under MiCA in an EU member state, a custody function licensed by the FSRA in ADGM, and a transfer service registered with the FCA in the United Kingdom. Each of those entities carries its own AML/CFT obligations. The EU regime mandates ESMA-aligned supervision through the national competent authority. ADGM operates on a common-law financial services framework with its own recognised-asset list. The FCA's cryptoasset registration under the Money Laundering Regulations carries its own specific program requirements. None of these frameworks is identical. A single group policy that ignores those differences will fail in all three examinations simultaneously.

The cross-border dimension also affects the Travel Rule in a way that most policy documents do not address adequately. When a transfer crosses from an EU-licensed VASP to an ADGM-licensed custodian within the same group, the Travel Rule obligation still applies as a matter of regulatory form in most frameworks, even though both entities are under common ownership. The policy must confirm whether the group has obtained a regulatory determination on intra-group flows and, if not, treat those flows as third-party transfers for Travel Rule purposes.

We have seen this issue arise repeatedly in practice. The group assumes that intra-entity flows are exempt. A supervisory examination finds no intra-group data-sharing agreement, no Travel Rule records and no documented rationale for the exemption claim. The result is a material AML finding that was entirely avoidable at the drafting stage.

Decision Matrix: Which Policy Structure Fits Your Entity?

Not every regulated entity needs the same policy architecture. The right structure depends on the firm's size, the number of licensed entities, the range of regulated activities and the geographic spread of its user base.

A single-entity VASP holding one licence in one jurisdiction – say, a CASP authorisation under MiCA in Lithuania – needs a standalone AML/CFT policy calibrated to the Bank of Lithuania's supervisory expectations and the FATF baseline. The document set is narrower: group policy and local schedule collapse into a single document; the Travel Rule section addresses EU-specific obligations; the risk methodology reflects a single product and a defined user geography. The typical drafting timeline in straightforward cases is a matter of weeks.

A multi-entity regulated group operating across two or more jurisdictions needs a layered architecture: a group policy that sets the risk framework and governance model, plus entity-level schedules that implement local requirements by name for each licensed entity. Each schedule references the applicable local regulator – whether VARA, MAS, the FCA or another – and maps to that regulator's specific expectations. This structure is more intensive to draft but is the only architecture that survives simultaneous examination in multiple jurisdictions.

A group that also holds a fintech licence, a payment institution authorisation or a banking licence in addition to its VASP activities carries a more complex intersection of obligations. The AML/CFT policy must address each regulated perimeter and specify which obligation set applies to which product flow. In these structures, we work alongside allied counsel in the relevant jurisdiction to ensure the entity-level schedule meets local form and supervisory expectation.

In each profile, the decision axis is the same: how many regulated entities, how many jurisdictions, how many distinct regulated activities. The answer to those three questions determines whether the firm needs one document, a layered set or a full group compliance manual.

Self-Assessment Checklist for AML/CFT Readiness

Before engaging counsel, a general counsel or compliance officer can use the following markers to identify where the policy is most likely to be deficient. A "no" or "uncertain" answer to any item below is a drafting gap that a regulator will find.

Does the policy specify the firm's risk appetite in measurable terms – high, medium and low risk criteria for customer, jurisdiction and product – rather than in generic language? Does the KYC framework define the verification data points required at each tier and the conditions under which enhanced due diligence is triggered automatically? Does the transaction monitoring section specify the model type, the alert-review SLA and the escalation path to the MLRO? Does the Travel Rule section address both outbound and inbound flows, and does it name the protocol in use and the handling procedure for non-responsive counterparties?

Is the MLRO role defined by reference to a named individual or a designated function, with explicit authority to refuse a transaction and escalate to senior management without prior approval? Does the policy mandate a documented training calendar and a compliance testing cycle? Is the policy reviewed on a defined schedule, with a documented trigger for out-of-cycle review when the business model or regulatory environment changes? Is each licensed entity covered by its own policy or schedule that references its applicable local regulator by name?

If any of those questions returns an uncertain answer, the policy is not examination-ready. OBOLUS maps and closes those gaps systematically.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16 as applied to virtual assets, requires a transmitting VASP to pass originator name, account number and address – plus beneficiary name and account number – to the receiving institution with every qualifying transfer. The receiving VASP must screen that data before processing the credit. The specific transfer threshold that triggers the obligation varies by jurisdiction; a VASP operating across multiple regimes must reconcile each applicable threshold in its written policy and operational procedure.

Who must act as MLRO for a crypto firm?

Every regulated VASP must designate a Money Laundering Reporting Officer – an individual with sufficient seniority, independence and authority to receive internal suspicious-activity disclosures, decide on external reporting and refuse transactions without prior board approval. Most major regulators, including the FCA, MAS and VARA, assess the MLRO appointment as part of their licensing and examination process. In a multi-entity group, each licensed entity typically requires its own designated MLRO, though the function may be shared under a documented group compliance mandate where local rules permit.

How do regulators audit crypto AML programs?

Supervisory examinations for digital-asset AML programs follow a consistent pattern across the major hubs: regulators request the written policy and supporting procedures, cross-reference them against live transaction monitoring records, escalation logs and suspicious activity reports, then interview the MLRO and compliance staff. Examiners under MiCA and the ESMA supervisory-convergence framework, as well as those acting under VARA and the MAS Payment Services Act, increasingly use risk-based sampling of specific transaction categories – stablecoin flows, large-value transfers and high-risk-jurisdiction onboardings – to test whether the policy reflects actual operations. A policy that cannot be traced to live records is treated as non-compliant regardless of its written quality.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule programs that regulators in every major hub now examine rigorously. We map the licence stack across operating, custody and payment layers before you commit, and we build AML/CFT frameworks that survive examination – not just application. Digital assets are the whole of our practice. To discuss your AML/CFT policy needs, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program architecture, Travel Rule implementation and multi-jurisdictional regulatory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours