For a virtual asset service provider (VASP) operating under heightened regulatory scrutiny, the quality of its AML/CFT policy documentation is the difference between a clean supervisory visit and an enforcement referral. Regulators across the major licensing hubs – VARA in Dubai, ESMA coordinating under MiCA, the FCA in the United Kingdom, the MAS in Singapore and the SFC in Hong Kong – have aligned on one expectation: a policy framework that is specific to the business, defensible under examination and current. Generic templates do not pass that test. As supervisory intensity increases across every major crypto hub, businesses that delayed investing in compliant documentation are now discovering the cost.
This page sets out how OBOLUS approaches AML/CFT policy drafting for digital-asset businesses operating under heightened scrutiny, what the process involves, where cross-border operations complicate the picture and what operators most often get wrong.
What does heightened scrutiny mean for a digital-asset business?
Heightened scrutiny is not a single formal status. It is a condition that arises when a regulator, a correspondent bank or a payments partner treats your business as requiring additional review before granting or maintaining access. The trigger varies. It may be the nature of your licensed activities – custody and exchange attract more attention than advisory. It may be the jurisdictions you serve, the categories of customer you onboard or a prior adverse finding in your supervisory history. It may simply be that your regulatory environment has raised its expectations and your documentation has not kept pace.
Under the FATF Recommendations – specifically Recommendation 15, which applies to virtual assets and VASPs – regulators are expected to assess whether a VASP's AML/CFT controls are commensurate with its risk profile. When they conclude they are not, heightened scrutiny follows. At that point, the burden shifts to the operator to demonstrate adequacy. A well-drafted policy framework is the primary vehicle for that demonstration.
In our practice, we see heightened scrutiny arrive in several forms: a targeted supervisory questionnaire, a formal remediation notice, a correspondent bank's enhanced due diligence request or a pre-licensing review that surfaces documentation gaps. Each requires the same underlying response – a policy suite that maps to the actual business, the actual risks and the current regulatory expectations of the relevant jurisdiction.
The process above describes the standard supervisory interaction. Your facts – the entity structure, the user base, the product set, the banking relationships – change the analysis materially. For a scoped assessment of your current AML/CFT documentation, contact OBOLUS at info@oboluslaw.com or map your options here.
What is the regulatory basis for AML/CFT policy obligations?
Every major digital-asset regime derives its AML/CFT obligations from the same international baseline: the FATF Recommendations, which set out the risk-based approach to money laundering and terrorist financing prevention. How those obligations are implemented varies significantly by jurisdiction, and for a multi-jurisdiction operator, the policy suite must address each applicable regime without contradiction.
Under MiCA and the EU's broader AML regime, CASPs (crypto-asset service providers) are subject to the Fourth and Fifth Anti-Money Laundering Directives as they apply to the crypto sector, with further harmonisation on the horizon under the EU AML Authority. The obligations include customer due diligence, ongoing monitoring, suspicious transaction reporting and record-keeping – all of which must be reflected in documented policies. ESMA guidance and the relevant national competent authorities add supervisory expectations on top of the legislative floor.
VARA in Dubai, ADGM/FSRA in Abu Dhabi and AFSA within the AIFC in Kazakhstan each publish their own AML/CFT rulebooks. The structural requirements – a designated compliance officer, documented risk appetite, customer due diligence procedures, a transaction monitoring framework – are consistent across them. The detail, the reporting thresholds and the supervisory expectations for documentation differ, sometimes materially.
The FCA's cryptoasset AML registration regime and the MAS regime under the Payment Services Act both require registered or licensed entities to maintain and demonstrate policies that meet the applicable money laundering regulations. In each case, a regulator's assessment of adequacy turns heavily on the written documentation – not just what controls exist in practice, but whether they are described with sufficient precision and specificity to be auditable.
For operators with a cross-border footprint, the policy suite must navigate the interaction between home-jurisdiction requirements and host-jurisdiction expectations. A business licensed in one EU member state that passports into others under MiCA must satisfy the home-state NCA on its documentation while remaining responsive to host-state supervisory enquiries. A VARA-licensed entity serving clients with a nexus to Singapore or Hong Kong must be aware that each of those regulators may form a view about the adequacy of its AML/CFT posture.
What does a defensible AML/CFT policy suite contain?
A defensible AML/CFT policy suite for a digital-asset business under heightened scrutiny is not a single document. It is a structured set of interconnected policies, procedures and supporting materials that together demonstrate a functioning, risk-based compliance programme. The architecture matters as much as the content of any individual document.
At the foundation is a business risk assessment (BRA): a documented analysis of the money laundering and terrorist financing risks inherent in the business model, the product set, the customer base and the geographies served. The BRA drives everything downstream. A regulator reviewing your documentation will check whether your policies are calibrated to the risks you identified, and whether your identified risks reflect an honest assessment of your business. Generic, low-risk assessments for exchange businesses serving high-volume anonymous wallets do not survive scrutiny.
Built on the BRA, the core policy suite typically covers: customer due diligence and enhanced due diligence procedures; the Travel Rule (the obligation, established under FATF Recommendation 16 and implemented across major hubs, to pass originator and beneficiary data with virtual asset transfers above applicable thresholds); transaction monitoring and alert management; suspicious activity and suspicious transaction reporting; record-keeping; sanctions screening; and staff training. Each document must be specific to the business – its actual products, its actual customer segments, its actual technical environment.
The Travel Rule policy is a particular focus of supervisory attention. Regulators expect to see documented procedures for identifying counterparty VASPs, for the technical means of transmitting the required data (whether through a TRISA, TRP or bilateral arrangement) and for handling unhosted wallet transactions. A policy that describes Travel Rule compliance in abstract terms without specifying the operational mechanics will not satisfy a regulator operating at heightened attention.
Supporting the core suite is a KYC framework – documented customer identification and verification procedures, risk-based customer segmentation, periodic review triggers and enhanced due diligence criteria for higher-risk customers. The KYC framework must be consistent with the BRA: if the BRA identifies certain customer categories as higher risk, the KYC framework must treat them accordingly.
In our practice, we regularly advise on the governance layer that sits above the policy documentation: the board-level AML/CFT risk appetite statement, the MLRO reporting line, the internal audit or independent review cycle and the escalation procedure from compliance to senior management. Regulators under heightened scrutiny regimes do not assess the policies in isolation. They assess the governance structure that gives them force.
What are the most common drafting mistakes under heightened scrutiny?
The mistakes we encounter most frequently are structural, not cosmetic. They are the kind that survive a first-pass internal review but fail under a regulator's targeted examination.
The first is policy-practice divergence: the written procedure describes a process that the compliance team does not actually follow. This arises when policies are drafted quickly to meet a licensing deadline and the operational reality evolves without corresponding policy updates. A regulator interviewing your compliance staff will ask them to describe what they actually do. If the answer does not match the policy, the divergence is noted as a finding of its own – separate from any underlying control gap.
The second is insufficient risk differentiation. Policies that treat all customers, all products and all transaction types as presenting the same risk level signal to a regulator that the risk assessment was not genuine. A business operating in multiple jurisdictions, with both retail and institutional customers, with products ranging from exchange to custody to staking, must reflect that complexity in its risk framework.
The third is Travel Rule documentation that is incomplete. Many operators can describe their Travel Rule obligations at a high level. Fewer have documented the specific technical solution they use, the procedures for counterparty VASP verification, the handling of unhosted wallets above applicable thresholds and the escalation path for non-compliant transfers. Regulators operating at heightened scrutiny level will ask for each of these in detail.
A fourth, and increasingly common, mistake is failing to update documentation after a product launch, a new jurisdiction entry or a change in customer mix. Policies that were accurate on the date of authorisation but no longer reflect the business as it operates are a systemic risk. They expose the business to findings not just on the new activity, but on the adequacy of its governance processes for keeping policies current.
How does cross-border operation affect the AML/CFT policy stack?
Cross-border digital-asset businesses face a structural challenge: a single set of internal policies must simultaneously satisfy multiple regulatory regimes, each with its own drafting expectations, reporting formats and supervisory culture.
The most acute tension is between home-jurisdiction authorisation requirements and host-jurisdiction supervisory expectations. A CASP passporting under MiCA from a smaller member state into larger markets will find that the host-state NCA has formed its own view about documentation standards. The home-state authorisation may have been granted on a policy suite that the host-state regulator would regard as insufficiently detailed.
For operators with a UAE and European footprint, the VARA rulebook and the EU AML regime operate on different architectures. VARA's activity-based licensing means that each licensed activity may have its own supervisory expectations on documentation. A business holding both an exchange licence and a custody licence from VARA must ensure its policy suite addresses the distinct risk profiles of each activity, not just the business as a whole.
Banking is the practical forcing function for many of the businesses we advise. A correspondent bank conducting enhanced due diligence will request the AML/CFT policy suite as part of its own review. The policy must satisfy not just the licensing regulator but also the bank's compliance standards – which may be more demanding in some respects than the formal regulatory requirement. We have seen well-run businesses lose banking relationships because their policy documentation, while technically compliant with the licensing regime, was insufficiently granular for a major correspondent bank's financial crime team.
Allied counsel in the relevant jurisdiction can assist where local-law nuance requires adaptation of the policy suite beyond what a central document can address. For businesses with entities in Singapore, Hong Kong or a BVI/Cayman holding structure, the policy architecture must account for how AML obligations at the entity level interact with group-level policies.
If a prior application stalled or an account was closed following a documentation review, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or map your options here.
Which profile needs what level of policy work?
Not every business needs a full policy rebuild. The right scope depends on the business profile, the regulatory exposure and the specific trigger for the heightened scrutiny engagement.
Profile A – Pre-authorisation or licence renewal: A business preparing for its first CASP authorisation under MiCA, a VARA licence application or MAS registration under the Payment Services Act needs a complete policy suite built from the ground up. The BRA, the KYC framework, the Travel Rule policy, the transaction monitoring procedures and the governance documents must all be in place before submission. The indicative timeline for a full suite build, assuming a cooperative client with documented business model detail, is typically a matter of weeks rather than days. The key risk at this stage is underestimating the specificity that the regulator will require.
Profile B – Post-authorisation remediation: A business that has received a supervisory finding or a formal notice identifying documentation gaps needs a targeted remediation programme. This is often faster than a full build because the existing suite provides a baseline. The task is gap-analysis, re-drafting the deficient sections and producing a remediation log that demonstrates the regulator's concerns have been addressed. The key risk here is addressing the letter of the finding without resolving the underlying structural issue – which leaves the business exposed to a follow-up finding at the next review cycle.
Profile C – Banking or correspondent-bank onboarding: A business that has received an enhanced due diligence request from a bank may need its policies reviewed and, where necessary, upgraded to meet the bank's financial crime standards. This is a distinct exercise from regulatory compliance drafting. Banks assess policy documentation with a focus on the granularity of the procedures, the quality of the risk assessment and the governance oversight. The key risk is treating a bank's EDD request as a regulatory compliance matter and producing documentation that satisfies the regulator but not the bank.
Profile D – Group restructuring or new-jurisdiction entry: A business expanding into a new hub or restructuring its entity architecture needs its policy suite reviewed for cross-jurisdictional consistency. The policies must satisfy each new regulator without creating inconsistencies that would undermine the position in existing jurisdictions. This is a coordination exercise as much as a drafting one.
How does OBOLUS approach AML/CFT policy drafting?
Our approach is built around specificity. Generic policies are not what regulators operating at heightened scrutiny level accept. Every engagement begins with a structured fact-gathering exercise that maps the business model, the customer base, the product set, the jurisdictions of operation and the existing documentation baseline.
From that foundation, we produce a gap analysis that identifies what is missing, what requires update and what is adequate. For a business preparing a full policy suite, the gap analysis becomes the drafting roadmap. For a business responding to a supervisory finding, it frames the remediation programme.
We draft each policy document to the standard of the most demanding regulator in the business's licensing footprint. A policy suite built to VARA and MiCA standards will generally satisfy the FCA and MAS as well. The reverse is not always true. This approach reduces the risk of having to maintain different policy versions for different regulators – a governance burden that creates inconsistency over time.
In a recent engagement, a mid-sized exchange operator with licences in two jurisdictions came to us after a supervisory review identified gaps in its Travel Rule documentation and transaction monitoring procedures. We conducted a full policy audit, identified the divergence between the written procedures and the operational practice, and produced a revised suite aligned to both regulatory regimes. The operator was able to respond to the regulator within the remediation window with a documented programme that addressed both the specific findings and the underlying governance gap. The business retained its licences.
We map the compliance stack across the operating, custody and payment layers of the business before any document is drafted. This prevents the common outcome of a policy suite that is internally inconsistent – where the transaction monitoring procedure refers to risk categories that the BRA does not define, or the Travel Rule policy assumes a technical capability that the business has not yet implemented.
A common assumption worth examining
A common assumption among operators new to heightened scrutiny is that a single offshore licence, or a policy suite drafted to the minimum requirements of a lighter-touch regime, is sufficient to operate across multiple markets. It is not. The regulatory reality of digital-asset business is that the regime in which you are licensed is not the only regime that matters. The regime of your customers, of your banking relationships and of any regulated activity you conduct in a given jurisdiction all form a view about your compliance adequacy. A policy suite calibrated only to a registration-level requirement in a jurisdiction with limited supervisory capacity will not satisfy a major European NCA, a Singapore correspondent bank or a VARA supervisory review.
A related assumption is that AML/CFT policies, once drafted, are stable. They are not. Policies require update each time the business changes materially: a new product, a new jurisdiction, a change in customer risk profile, a regulatory update. The governance process for maintaining policies is itself a supervisory expectation. Businesses that treat policy drafting as a one-time task rather than an ongoing programme consistently find themselves in remediation cycles.
Related at OBOLUS
- Compliance, AML and Travel Rule for Digital-Asset Businesses – the full practice overview covering KYC, Travel Rule and ongoing compliance programme design
- MLRO and Compliance Officer Function in Jersey – the governance and personal liability dimensions of the senior compliance role in a leading offshore centre
- Tax Regime for Digital Assets in the UAE under VARA (Dubai) – the interaction between VARA licensing, tax positioning and banking access for UAE-domiciled operators
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 16 and implemented across the major licensing hubs, requires a VASP to collect and transmit originator and beneficiary information with virtual asset transfers that meet or exceed the applicable threshold in the relevant jurisdiction. The obligation applies both to outgoing transfers and to the receipt and verification of information on incoming transfers. The specific data fields, thresholds and technical transmission standards vary by jurisdiction. Documented procedures for counterparty VASP identification and for handling unhosted wallet transactions are a standard supervisory expectation.
Who must act as MLRO for a crypto firm?
Most regulated digital-asset regimes require a named Money Laundering Reporting Officer (MLRO) who holds personal regulatory responsibility for the firm's AML/CFT programme. The MLRO must be sufficiently senior, sufficiently resourced and sufficiently independent to discharge those responsibilities effectively. Regulators assess the MLRO's fitness as part of licensing and ongoing supervision. In some jurisdictions the MLRO must be resident in the regulated jurisdiction; in others a qualified individual based elsewhere may be accepted. The specific requirements vary by regime and are a critical component of the policy governance structure.
How do regulators audit crypto AML programs?
Regulators audit crypto AML programmes through a combination of document review, staff interviews and, where available, transaction-level analysis. A supervisory visit will typically include a request for the full policy suite, the business risk assessment, recent suspicious activity reports, transaction monitoring alert logs and evidence of staff training. The regulator will test whether the written policies reflect actual operational practice and whether the governance structure – board oversight, MLRO reporting line, internal audit cycle – is functioning. A well-documented programme that demonstrates live operation, not just paper compliance, is the standard the examination is designed to test.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML/CFT, Travel Rule and compliance programmes that sit around them. Digital assets are the whole of our practice. Operators we advise regularly face heightened scrutiny from regulators and banking partners; we map the compliance stack before any engagement begins. To discuss your AML/CFT documentation needs, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT programme design and regulatory documentation for digital-asset businesses under multi-jurisdictional scrutiny.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.