A crypto exchange operating across three continents, a custodian onboarding institutional clients in four regulatory zones, a token issuer distributing through a European platform – each of these businesses faces the same structural problem: a single AML/CFT policy (anti-money laundering and countering the financing of terrorism compliance program) drafted to satisfy one regulator will almost certainly fail the next. With supervisory convergence accelerating under the FATF Recommendation 15 standard for virtual assets, the gap between a compliant policy and a merely filed one is widening. This page explains what a defensible, cross-border AML/CFT policy contains, how it is built, where operators consistently go wrong, and how OBOLUS approaches the work.
An AML/CFT policy for a digital-asset business is not a generic compliance template. It is a jurisdiction-specific, operationally calibrated document that maps your regulated activities against the applicable legal regime in each market, assigns duties to named roles, and encodes transaction-monitoring rules and escalation procedures that a regulator can follow. Getting it right at the outset avoids the enforcement exposure and debanking risk that follows a supervisory finding.
Why the Cross-border Dimension Changes Everything
The most common mistake in crypto AML compliance is treating the policy as a single-jurisdiction document. In our practice, operators who draft to satisfy one regulator routinely discover that a second supervisor – or a correspondent bank conducting its own due diligence – finds the policy silent on requirements that are routine elsewhere.
The FATF framework is global, but its implementation is not uniform. FATF Recommendation 15 requires countries to regulate VASPs and apply AML/CFT measures proportionate to the risks they present. The transposition of that obligation into domestic law varies meaningfully. Under MiCA, an EU-licensed CASP (crypto-asset service provider) operates under ESMA guidance coordinated across the European Economic Area, with national competent authorities retaining enforcement authority. A business also registered under Singapore's Payment Services Act faces the Monetary Authority of Singapore's own VASP-specific requirements, which differ in structure and reporting cadence. A Dubai-licensed operator under VARA must satisfy VARA's AML rulebooks, which carry their own transaction-monitoring obligations separate from the DIFC financial free zone framework.
These are not cosmetic differences. The risk-appetite statement, the customer risk-rating methodology, the enhanced-due-diligence triggers and the suspicious-activity reporting thresholds all shift depending on which regime governs which part of the business. A policy that conflates them – or, worse, defaults to the most permissive – creates regulatory exposure at the point a supervisor in the more demanding jurisdiction conducts a review.
We regularly advise businesses that have reached Series B or moved into new markets only to discover that their AML documentation was written for the jurisdiction of incorporation, not the jurisdiction of activity. Rebuilding a policy under supervisory scrutiny is significantly more expensive – and more adversarial – than building it correctly before launch.
The process described below applies whether your business is a single-jurisdiction exchange or a multi-entity group spanning the EU, the Gulf and Southeast Asia. The cross-border angle is not optional; it is the lens through which every section of the policy must be drafted.
To discuss the scope of your AML/CFT policy requirements across your active jurisdictions, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements – change the analysis materially.
The Regulated Basis: What the Law Actually Requires
Every AML/CFT policy must trace its contents to a legal obligation. Generic language ("we conduct KYC on customers") does not satisfy a regulator looking for a documented framework that maps to the applicable rules. Three layers of obligation are relevant to most digital-asset businesses.
The first is the FATF standard and its domestic implementation. Countries that are FATF members or that model their rules on the FATF Recommendations require VASPs to maintain written AML/CFT programs covering customer due diligence, record-keeping, transaction monitoring, reporting of suspicious activity and, where applicable, the Travel Rule. The policy must name the legal instrument that imposes each obligation.
The second is the specific regime of each licensed entity. An EU CASP under MiCA operates under the anti-money laundering directives as augmented by MiCA's own VASP-specific provisions, with ESMA providing coordinating guidance. A Singapore DPT (digital payment token) service licensee under the Payment Services Act operates under MAS's notices and guidelines on AML/CFT for digital-payment-token service providers. A business licensed by VARA in Dubai follows VARA's AML/CFT rulebook. None of these is interchangeable; each requires separate treatment within the policy architecture.
The third layer is the de-facto expectation of correspondent banks and payment processors. Banking partners routinely require sight of an AML/CFT policy as part of their own due-diligence process. A policy that satisfies the regulator but uses terminology or risk categories unfamiliar to a compliance team at a tier-one bank creates friction at the account-opening or account-maintenance stage. We draft with both audiences in mind.
One point that operators regularly underestimate: the Travel Rule (the obligation under FATF Recommendation 16 to pass originator and beneficiary information with virtual-asset transfers above the applicable threshold) must be operationally embedded in the policy, not appended as a footnote. Under MiCA's AML framework and under the specific Travel Rule regimes in Singapore, the UK and Hong Kong, the VASP's policy must document its counterparty-VASP verification procedure, its handling of transfers to and from unhosted wallets, and its controls for jurisdictions that have not implemented the Travel Rule. These are live examination points in supervisory reviews we monitor.
What a Compliant Cross-border AML/CFT Policy Contains
A compliant policy is not a single document. It is a structured set of instruments, each serving a distinct function within the overall program. The architecture we build for clients typically includes the following components.
The core AML/CFT policy sets out the legal basis, the scope of activities covered, the governance structure (board ownership, MLRO designation, reporting lines) and the firm's overall risk appetite. It is the document that a regulator or a bank will read first. It must be precise about which entities and which activities it covers, and it must be dated and version-controlled.
The customer risk-rating methodology documents how the business classifies customers by risk level and what enhanced due diligence applies to high-risk categories. For digital-asset businesses this includes criteria specific to the sector: wallet-address screening, transaction-pattern analysis, exposure to high-risk counterparty jurisdictions and politically exposed person status.
The transaction monitoring procedures translate the risk-rating framework into operational rules. They identify the alert scenarios, the escalation path from automated alert to human review, the decision criteria for filing a suspicious-activity report, and the record-keeping obligations that attach to each step.
The Travel Rule compliance annex addresses counterparty VASP verification, the technical protocol used for originator and beneficiary data exchange, the handling of transfers below the applicable threshold, and the firm's policy for transfers involving unhosted wallets. This annex must be calibrated to each jurisdiction's Travel Rule implementation, since thresholds and technical requirements differ.
The training and awareness program is not a discretionary addition. Regulators in the leading hubs – including VARA, the FCA and MAS – expect documented evidence that staff training has occurred, that it is role-specific and that it is updated when the regulatory position changes.
Finally, the MLRO annual report template and the independent audit scope document round out the suite. These exist to support the ongoing governance cycle rather than the initial authorisation, but regulators increasingly expect to see them in place at launch.
What Goes Wrong: Common Mistakes in Cross-border Drafting
In our cross-border practice, four failure patterns appear repeatedly. Each is avoidable if the drafting process is properly scoped at the outset.
The first is jurisdiction mismatch. The policy names one regulatory regime but the business is active – or intends to be active – under two or three. A CASP authorised in an EU member state that also onboards users through an entity registered in the BVI faces two distinct supervisory expectations. The policy must address both, either in a unified document with jurisdiction-specific annexes or in a master-plus-local structure. A single document written only to the EU standard will not satisfy the BVI FSC under the VASP Act 2022, and vice versa.
The second failure is operational disconnect. The policy states that certain enhanced due diligence steps will be performed, but the firm's onboarding system does not support them. Regulators conducting supervisory visits or desk-based reviews compare the documented procedure with the actual transaction records. A gap between the two is, in many supervisory frameworks, treated as a more serious finding than a gap in the policy text itself, because it indicates the policy is not implemented.
The third is Travel Rule non-compliance by omission. Many operators document their obligations under the Travel Rule but fail to address what happens when a counterparty VASP cannot be verified, or when a transfer arrives from a jurisdiction that has not yet implemented the Travel Rule. The policy must answer those questions. Under MiCA's AML component, ESMA guidance and the FCA's own Travel Rule rules, the firm's handling of these edge cases is a standard examination point.
The fourth failure – and the one most damaging to banking relationships – is vague risk-appetite language. Statements like "we do not accept high-risk customers" without defining what constitutes high risk give a correspondent bank's compliance team no basis for relying on the policy. A well-drafted policy articulates specific categories, specific screening tools, specific escalation triggers and specific documentation requirements. That level of specificity is what converts a compliance document into a banking-grade assurance instrument.
Cross-border Interaction: Banking and Tax Considerations
An AML/CFT policy does not sit in isolation. For a digital-asset business operating across borders, it intersects with two further dimensions that must be addressed in the drafting process.
The first is the banking layer. Correspondent banks and e-money institution partners conduct their own AML risk assessments of crypto business clients. The policy must speak their language: risk categorisation aligned to the Financial Action Task Force typologies, documented screening against OFAC, UN and EU sanctions lists, and clear procedures for handling politically exposed persons and adverse media. Operators we advise regularly present their policy to banking partners as part of account-opening due diligence. A policy that reads as a regulator-directed template, with no acknowledgment of the broader financial-crime environment, rarely satisfies a de-risking-sensitive bank.
The second is the tax-information-exchange layer. While not formally part of AML/CFT, regulators in the leading digital-asset hubs increasingly expect the compliance function to interact with the reporting obligations under DAC8 in the EU (the directive extending crypto-asset reporting to tax authorities) and the OECD Crypto-Asset Reporting Framework. A policy drafted without awareness of these obligations may create disclosure inconsistencies that surface in a combined regulatory and tax audit. We draft with both frameworks in view.
The cross-border reality for most of the businesses we advise is this: the entity that holds the licence, the entity that holds the customer assets, the entity through which banking flows, and the entity that employs the MLRO may all sit in different jurisdictions. The AML/CFT policy architecture must reflect that structure, not assume a single-entity, single-jurisdiction model.
If a prior policy was rejected by a regulator or flagged by a banking partner, OBOLUS can conduct a structured gap analysis and rebuild the documentation to the required standard. Write to us at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
How This Works in Practice: A Cross-border Policy Rebuild
In a recent compliance engagement, a payments and custody business operating under two licences – one in an EU member state and one in a Gulf free zone – approached us after its primary banking partner flagged the AML/CFT policy as inadequate during a periodic account review. The policy had been drafted to satisfy the EU licence at incorporation; the Gulf entity had been added later, and its regulatory requirements had not been incorporated into the documentation.
We conducted a comparative gap analysis across both regimes, mapped the Travel Rule obligations under each supervisory framework, and redrafted the policy as a master document with jurisdiction-specific annexes covering each entity's distinct obligations. The transaction-monitoring procedures were rebuilt to reflect the firm's actual system configuration, and the counterparty-VASP verification procedure was documented to the standard expected by both regulators and the banking partner. The revised policy was accepted by the bank at the next review cycle, and the corresponding regulator confirmed its adequacy in writing at the firm's next supervisory engagement.
Self-Assessment: Is Your AML/CFT Policy Defensible?
Before engaging external counsel, operators can use the following markers to assess the current state of their AML/CFT documentation. These are the questions a regulator or a bank will ask first.
- Does the policy name every legal regime under which each entity operates, with a specific reference to the applicable AML/CFT rules in each jurisdiction?
- Does the customer risk-rating methodology use criteria specific to digital-asset business, including wallet screening, exchange-risk classification and counterparty-VASP verification?
- Does the Travel Rule annex address transfers to unhosted wallets, transfers from non-Travel-Rule jurisdictions, and the technical protocol used for data transmission?
- Is the MLRO designation current, with documented authority, reporting lines and a formal escalation path to the board?
- Are training records maintained, role-specific and updated to reflect regulatory developments in each active jurisdiction?
- Has the policy been reviewed by the board within the past twelve months, with a board minute confirming approval?
- Is the policy consistent with what the firm's onboarding and monitoring systems actually do – and is that consistency documented?
A "no" answer to any of these questions is a finding waiting to happen. In our experience, the businesses that face the most disruptive supervisory outcomes are those where the gap between the documented policy and the operational reality is largest. Closing that gap is the core of the work.
Decision Matrix: Which Policy Architecture Fits Your Profile
The right policy structure depends on the business model, the entity structure and the regulatory footprint. The following decision branches reflect the situations we encounter most frequently.
Single-entity, single-jurisdiction operator – a CASP licensed in one EU member state with a homogeneous user base – requires a unified policy document covering the MiCA AML/CFT obligations, the national transposition measures and the ESMA guidance on Travel Rule. Timeline to a defensible policy: typically a matter of weeks. Primary risk: Travel Rule edge cases and the gap between the policy text and onboarding-system functionality.
Multi-entity, multi-jurisdiction group – a holding structure with operating entities in the EU, the UAE and Singapore, or in a combination of a flagship hub and an offshore vehicle – requires a master policy plus jurisdiction-specific annexes. Each annex addresses the local regime (MiCA and its national transposition; VARA's AML rulebook; MAS's DPT-service AML notices). The MLRO structure must be documented across entities, and the Travel Rule obligations must be mapped jurisdiction by jurisdiction. Timeline: longer, reflecting the comparative analysis and internal consultation required. Primary risk: inconsistency between the master document and the annexes, and failure to update the annexes when a local regulatory position changes.
Early-stage operator pre-licensing – a business preparing its first licence application, typically under MiCA or the MAS Payment Services Act – should treat the AML/CFT policy as part of the application package, not as a post-authorisation task. Regulators in the leading hubs assess the quality of the policy as an indicator of the firm's governance maturity. A well-drafted policy at application stage reduces the number of information requests from the regulator and can meaningfully shorten the authorisation timeline. Primary risk: under-specifying the policy to avoid committing to procedures the business has not yet built.
Related at OBOLUS
Related at OBOLUS
- AML/CFT and Travel Rule Compliance Practice – the full scope of our AML and Travel Rule advisory services for digital-asset businesses
- Regulator AML Audit Defence: Practical Lessons for Boards – how boards and MLROs prepare for and respond to supervisory AML reviews
- NFT Project Legal Structuring in the Czech Republic – jurisdiction-specific structuring guidance for digital-asset projects in an EU member state
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 – requires a VASP to collect, verify and transmit originator and beneficiary information with every virtual-asset transfer above the applicable threshold. The specific threshold and the technical transmission standard vary by jurisdiction. Under MiCA's AML component and under the rules of MAS, the FCA and VARA, the obligation covers both the sending and receiving VASP. A VASP must also document its procedures for transfers involving unhosted wallets and for counterparties in jurisdictions that have not yet implemented the Travel Rule.
Who must act as MLRO for a crypto firm?
Most licensing regimes – including the MiCA framework, the MAS Payment Services Act regime, and the VARA rulebooks – require an authorised or registered firm to designate a named money laundering reporting officer (MLRO) with sufficient seniority, authority and resources to discharge the function. The MLRO must have direct access to the board and a documented escalation path. Regulators assess the MLRO's qualifications and the adequacy of their mandate; a nominal designation without operational authority is a common supervisory finding.
How do regulators audit crypto AML programs?
Supervisory reviews of AML/CFT programs in the leading digital-asset hubs typically combine a desk-based review of the policy documentation with a transaction-file sample review. Regulators compare the documented procedures against the actual onboarding records, transaction-monitoring alerts and suspicious-activity reports filed. They assess whether the MLRO function is operational, whether staff training is evidenced and whether the policy has been subject to board-level approval. ESMA, VARA, the FCA and MAS have all published supervisory expectations that describe the examination methodology in varying levels of detail.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance architecture that sits around them. We map the compliance stack – across operating, custody and payment layers – before you commit. Digital assets are the whole of our practice. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your AML/CFT policy requirements, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and cross-border compliance architecture for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.