Operating a digital-asset business without a properly documented anti-money-laundering and counter-terrorism-financing program is one of the clearest routes to regulatory enforcement. Regulators under MiCA, VARA, the FCA regime and the MAS Payment Services Act all require that a VASP (virtual asset service provider) maintain written AML/CFT policies that reflect the firm's specific risk profile, product set and customer base. A generic template lifted from a compliance vendor does not meet that standard. Legal counsel that understands both the regulatory text and the on-chain mechanics does. This page explains how OBOLUS constructs AML/CFT policy documentation for digital-asset firms, what the process looks like, where cross-border complexity arises, and how to assess whether your current program will survive a supervisory examination.
The Regulated Basis for AML/CFT Policy Obligations
Every major licensing regime imposes a mandatory obligation to maintain a written AML/CFT program, and the obligation follows the business regardless of where it is incorporated. The global baseline comes from the FATF Recommendations – specifically Recommendation 15, which extended the full FATF framework to virtual assets and their service providers. From that baseline, national and regional regimes impose their own layered requirements. Under MiCA and the coordinating role of ESMA, a CASP (crypto-asset service provider) must embed a risk-based approach into documented policies, procedures and controls. VARA in Dubai publishes conduct rulebooks that require VASPs to maintain a compliance manual addressing customer due diligence, transaction monitoring and suspicious activity reporting. The FCA's Money Laundering Regulations require registered cryptoasset businesses in the United Kingdom to implement documented risk assessments and controls. The pattern is consistent: a licence application without a credible policy suite will not proceed, and an existing licensee operating on a thin or undated policy invites supervisory action.
What regulators increasingly scrutinize is not the existence of a policy document but its operational specificity. A policy that names the firm, identifies the specific product risks – stablecoins, self-custodied wallets, high-velocity exchange activity – and maps each control to a named role holder is materially different from a generic document. In our practice, we have seen examination teams specifically request evidence that policies were reviewed following a product launch or a change in the customer base. Dated version histories and documented review cycles are not optional extras. They are evidence of a functioning program.
For a preliminary assessment of your current program's regulatory exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard regulated basis. Your entity structure, your product set and the jurisdictions your customers sit in change the specific obligations.
What AML/CFT Policy Drafting Covers for a Digital-Asset Firm
A complete AML/CFT policy suite for a digital-asset firm encompasses several interlocking documents, each addressing a distinct regulatory obligation. The core instrument is the firm-wide AML/CFT policy, setting out the risk-based approach, the compliance governance structure and the escalation framework. That policy is supported by a customer due diligence procedure (covering standard CDD, enhanced due diligence for higher-risk relationships, and simplified CDD where permitted), a transaction monitoring procedure, a suspicious activity reporting procedure, a Travel Rule compliance procedure (the obligation under the applicable VASP provisions to pass originator and beneficiary data with a qualifying transfer), a sanctions screening procedure and a record-keeping policy.
Beyond those core documents, firms with specific product profiles require additional instruments. A custody business needs a policy addressing the treatment of customer assets and the controls applied at the wallet level. A token issuer operating under MiCA's ART or EMT whitepaper regime needs a policy that addresses the redemption process and the reserve-monitoring controls. A platform offering DeFi access needs to address the specific risk of unhosted-wallet counterparties. We draft all of these as standalone instruments that can be reviewed independently and updated without requiring a root-and-branch revision of the entire suite.
The drafting process also produces two governance artifacts that regulators in the leading hubs increasingly expect to see: a firm-wide risk assessment that precedes the policies and provides their evidential foundation, and an annual review procedure that creates a documented audit trail going forward. Neither is the policy itself, but both are what an examination team will ask for first.
How Does the AML/CFT Policy Drafting Process Work?
The process at OBOLUS follows a staged model that keeps client involvement focused on business facts while we carry the regulatory-translation work. Stage one is an intake assessment – typically conducted by written questionnaire and a structured call – covering the firm's operating jurisdictions, licence status, product set, customer segments and existing documentation. That assessment takes a matter of days and produces a gap analysis document identifying what must be created, what must be revised and what is adequate.
Stage two is the drafting phase. We produce a first draft of the full policy suite, calibrated to the specific regulatory regimes that apply to the firm. For a business licensed under VARA in Dubai and passporting into the EU under MiCA, those two regulatory regimes generate overlapping but not identical requirements; the drafting must satisfy both without creating internal contradiction. Where the firm operates through multiple entities – a common structure in digital-asset groups – the policies must address which entity owns which obligation and how group-level controls interact with legal-entity-level responsibilities.
Stage three is review and iteration. We work through the draft with the client's compliance officer or designated MLRO (money laundering reporting officer), incorporating operational corrections and resolving any ambiguity about how a procedure maps to the firm's actual systems. Stage four is regulatory alignment: where an application is pending or an examination is anticipated, we review the final suite against the specific examination criteria or application checklist published by the relevant regulator. For a VARA application, that means the VARA compliance framework criteria. For a MAS DPT service licence, it means the MAS compliance guidelines for payment institutions. Final delivery is the complete policy suite in version-controlled form with implementation guidance.
From intake to delivery, the timeline depends on the complexity of the firm's structure and product set. A single-jurisdiction firm with a defined product scope can receive a first draft within a matter of weeks. A multi-entity, multi-jurisdiction group requires a longer intake phase and a longer drafting cycle. We provide a scoped timeline at engagement based on the intake findings.
Why Cross-Border Operations Complicate AML/CFT Policy
A digital-asset firm rarely sits cleanly within one regulatory perimeter. The entity may be licensed in the UAE under VARA, the banking relationship may sit in a European jurisdiction, the customers may span multiple continents, and the technical team may be in a third location entirely. Each of those facts carries regulatory consequences for the AML/CFT program. Regulators in the leading hubs do not accept the argument that obligations stop at the licence boundary.
The Travel Rule illustrates this particularly clearly. Under the applicable VASP provisions adopted by FATF-member jurisdictions, a VASP sending a qualifying transfer to another VASP must transmit originator and beneficiary data. The precise threshold at which that obligation activates varies by jurisdiction; the data fields required vary by jurisdiction; and the technical standards for transmitting the data – IVMS 101 formatting, the choice of Travel Rule protocol – vary by technical setup. A policy drafted for a single-jurisdiction firm will not address the outbound obligation when a customer sends to a VASP in a second jurisdiction operating under a different threshold. In our cross-border practice, we have seen firms pass an initial examination on their domestic policy and then face follow-up enquiries specifically about their cross-border Travel Rule posture. The two cannot be separated.
Sanctions screening adds a further layer. A firm licensed in Dubai must screen against UAE Central Bank designations, OFAC designations and UN consolidated list entries as a minimum. If that firm also serves customers in Europe, ESMA-aligned regulators will expect EU-sanctions screening as well. The policy must either address all applicable sanctions regimes explicitly or explain the jurisdictional logic for the scope chosen. Anything less creates an easily identifiable gap in an examination.
If your firm operates across more than one jurisdiction and has not reviewed its AML/CFT documentation since your last product launch or market expansion, write to us at info@oboluslaw.com. A prior application that stalled or an account that was closed often traces to a policy gap that a fresh review can identify and address.
What Are the Most Common Mistakes in Crypto AML/CFT Documentation?
The most frequent failure we see is a policy suite that was assembled at the time of a licence application and never updated. Regulators across the leading hubs treat an undated or un-reviewed policy as evidence of a non-functioning compliance program, regardless of how well the original documents were drafted. A policy that does not reflect a product that the firm has been operating for eighteen months is, in regulatory terms, not a policy for that product at all.
The second common failure is role misalignment. The policy names a compliance officer or MLRO who is not actually performing the functions described. In smaller firms this often happens when a founder or director is named as MLRO as a placeholder, with no practical authority to file suspicious activity reports or halt transactions. Regulators under the FCA regime, the MAS regime and VARA all expect the MLRO to be an appropriately qualified individual with genuine operational authority. A policy that names a placeholder MLRO fails on the substance, not just the form.
The third failure is technology disconnect. The transaction monitoring procedure names specific alert thresholds and typology rules, but the firm's actual monitoring system is configured differently. An examination team that requests both the written procedure and the system configuration logs will identify the discrepancy immediately. The policy and the technical implementation must be aligned, and that alignment must be documented.
A fourth, less visible failure involves group structures. A digital-asset group operating through multiple entities often produces a group-level policy and assumes that subsidiary compliance is satisfied by adherence to the group document. Where the subsidiary holds its own licence, the regulator of that subsidiary expects entity-level documentation that reflects the subsidiary's specific risk profile and customer base, not just a cross-reference to a group policy.
How Should a Firm Assess Its AML/CFT Policy Needs?
The appropriate scope of an AML/CFT policy engagement depends on three variables: the firm's regulatory status, the complexity of its product set, and the state of its existing documentation. The following profiles describe the most common situations we encounter.
A firm that is newly licensed – or is applying for a licence – under VARA, MAS or MiCA and has no existing documentation needs a full policy suite built from the ground up. The right instrument is a comprehensive drafting engagement covering all required documents, the firm-wide risk assessment, and implementation guidance. The timeline from intake to delivery is typically measured in weeks, with the exact duration depending on the number of entities and products in scope. The key risk at this stage is speed: firms often underestimate how long regulators take to review policy documentation as part of an application, and a late submission can reset a licence timeline materially.
A firm that holds an existing licence but has not reviewed its documentation for more than twelve months is a different profile. The right instrument here is a gap analysis followed by targeted redrafting of the documents that have fallen out of alignment. This is a faster and more focused engagement, though it can expand if the gap analysis reveals systemic issues. The key risk here is complacency: firms that have passed an initial examination sometimes treat that as ongoing validation, when in practice regulators expect progressive improvement.
A multi-entity group expanding into a new jurisdiction presents the most complex scenario. The policy suite must address entity-level obligations in the new jurisdiction while remaining consistent with group-level governance. Allied counsel in the relevant jurisdiction will often be required to confirm local regulatory expectations before the drafting phase begins. The timeline is longer, the coordination overhead is higher, and the risk of internal contradiction between entity-level and group-level documents is material.
In a recent compliance matter, a payments company with exchange licences in two jurisdictions approached us following a supervisory enquiry. The firm had comprehensive policies for its primary jurisdiction but had applied those documents unchanged to the second entity. We identified the divergent Travel Rule thresholds, the different suspicious-activity reporting channels and the inconsistent sanctions-screening scope. A revised policy suite for the second entity was delivered within weeks, and the firm was able to respond to the supervisory enquiry with updated documentation before the regulator's deadline.
Self-Assessment: Is Your AML/CFT Program Examination-Ready?
The following questions map to the areas most frequently examined by regulators in the leading VASP licensing hubs. A "no" or "unsure" answer to any of them is a signal that the program requires attention before the next examination cycle or product launch.
Does the firm's AML/CFT policy reflect every product and service currently operating, including products launched since the last policy update? Is the firm-wide risk assessment dated within the last twelve months? Does the MLRO named in the policy hold genuine operational authority – including the ability to file suspicious activity reports without board approval? Does the transaction monitoring procedure match the actual configuration of the monitoring system? Does the Travel Rule procedure address the firm's obligations as both an originating VASP and a beneficiary VASP? Does the sanctions screening procedure identify every sanctions regime applicable to the firm's customer base? Is there a version-controlled document history that can be produced to an examination team?
If the firm cannot answer "yes" to each of those questions with supporting documentation, the program has identifiable gaps. The time to close them is before a supervisory examination, not during one.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – the full practice overview covering FATF alignment, KYC frameworks and ongoing compliance counsel
- Travel Rule compliance program for regulated entities – building IVMS 101-aligned Travel Rule procedures and counterparty VASP due diligence
- Economic substance requirements for digital-asset businesses – how substance rules interact with your entity structure and AML obligations
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP sending a qualifying virtual asset transfer to transmit originator and beneficiary identifying information to the receiving VASP. The obligation derives from FATF Recommendation 15 and is implemented through national VASP regimes. The precise data fields, the threshold above which the obligation activates, and the technical standards for transmission vary by jurisdiction. A compliant Travel Rule procedure must address the firm's obligations both as an originating VASP and as a beneficiary VASP, and must account for transfers to or from unhosted wallets where the applicable regime requires it.
Who must act as MLRO for a crypto firm?
Most leading VASP licensing regimes require the firm to designate a named individual as MLRO or compliance officer with genuine operational authority. That individual must have the ability to file suspicious activity reports, halt transactions and escalate concerns without requiring prior approval from commercial leadership. Regulators under the FCA regime, MAS and VARA each expect the MLRO to be assessed as fit and proper. In smaller firms, a founder or director may hold the role if genuinely qualified, but a placeholder appointment that does not reflect operational reality creates a documentary inconsistency that examination teams identify quickly.
How do regulators audit crypto AML programs?
Regulators in the leading hubs typically examine AML/CFT programs through a combination of documentary review and operational testing. The documentary review covers the policy suite, the firm-wide risk assessment, version histories and training records. Operational testing involves requesting sample transaction files, alert dispositions and suspicious activity reports to verify that the written procedure matches actual practice. Regulators increasingly request the configuration logs of transaction monitoring systems alongside the written procedure. A program that presents well on paper but diverges from operational reality in documented ways will attract a finding regardless of the quality of the written documents.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML/CFT, Travel Rule and KYC compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the compliance stack across operating, custody and payment layers before you commit, so that policy documentation is built on the correct regulatory foundation. To discuss your AML/CFT program, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and regulatory examination readiness for VASP-licensed digital-asset businesses across the EU, UAE and Asia-Pacific hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.