With regulators across the EU, the Gulf and Asia tightening AML compliance (anti-money laundering compliance) expectations for digital-asset businesses, a weak institutional KYC and onboarding framework (the controls a firm uses to verify, screen and accept institutional counterparties) is no longer a documentation gap – it is an enforcement risk. A custodian or exchange that cannot demonstrate a defensible institutional onboarding standard faces frozen correspondent-banking rails, regulatory censure and, in the worst cases, licence suspension. This page sets out the legal basis, the practical process, the cross-border tensions and the common mistakes we see across our practice.
Why institutional KYC differs from retail onboarding
Institutional onboarding is materially more complex than consumer KYC because the counterparty is itself a regulated or structurally layered entity, not an individual. The first task is mapping who the client actually is: a fund managed by a GP entity, owned through a Cayman feeder, with ultimate beneficial owners spread across multiple jurisdictions. Under FATF Recommendation 10 – the global standard requiring customer due diligence – a VASP (virtual asset service provider) must identify not just the legal entity at the door but the natural persons who ultimately own or control it. For a crypto exchange, custodian or token-trading platform, this means constructing a UBO chain that satisfies both the home regulator and the regulatory expectations of the jurisdictions where the institutional client itself operates.
We regularly advise businesses that have built consumer-grade flows and attempted to push institutional clients through them. The result is almost always a combination of data gaps, re-documentation requests and, increasingly, regulator findings during a supervisory visit. The distinction matters not just as a compliance formality but as a genuine risk-management discipline: institutional counterparties move larger balances, operate across more jurisdictions and are more likely to trigger transaction monitoring alerts if their activity is not profiled correctly at onboarding.
The cross-border dimension compounds this. A digital-asset exchange licensed by VARA (the Virtual Assets Regulatory Authority, Dubai's VARA regime) that onboards a Singapore-domiciled fund managed by a Hong Kong GP entity must satisfy VARA's institutional due-diligence expectations while also accounting for the fact that the fund itself is regulated by the Monetary Authority of Singapore under the Payment Services Act and subject to MAS AML rules. The chain of regulatory expectations runs in both directions.
What is the regulated basis for institutional KYC?
The regulated basis for institutional KYC in digital assets flows from three converging sources: FATF's virtual-asset guidance, jurisdiction-specific VASP or CASP regimes, and – increasingly – direct supervision by financial regulators who previously focused only on traditional finance.
Under MiCA (the EU's Markets in Crypto-Assets Regulation), a CASP (crypto-asset service provider) authorised in any EU/EEA member state owes customer due-diligence obligations drawn from the bloc's anti-money laundering directive. The CASP passporting mechanism means that an operator authorised in, say, Lithuania by the Bank of Lithuania and passporting to other member states must maintain a single KYC standard consistent with the strictest national transposition in its user base. For institutional clients, this creates a baseline that is meaningfully higher than many operators expect.
In the UAE, VARA's rulebooks impose detailed institutional due-diligence obligations on every licensed activity category – advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement. Each activity carries its own operational trigger for enhanced due diligence. A firm with a VARA custody licence onboarding a regulated financial institution as a sub-custodian client must satisfy both the custody-specific rulebook and VARA's overarching AML/CFT framework. The Financial Services Regulatory Authority (FSRA) in Abu Dhabi's ADGM operates a parallel but distinct regime; operators with presence in both free zones must run two compliance postures unless they have mapped equivalence carefully.
In Singapore, the Payment Services Act requires Digital Payment Token service providers to implement a risk-based AML/CFT programme consistent with MAS Notice PSN02. Institutional onboarding under that notice demands entity verification, UBO identification, source-of-funds analysis and – for higher-risk entities – enhanced due diligence before the relationship is activated. The MAS framework is explicit that regulated entities are not automatically low-risk; a fund or broker that is itself subject to AML supervision still requires a documented risk assessment.
CTA #1 – The regulatory basis described above is the standard path. Your specific facts – the licence type, the client's domicile, the activity – change the analysis. Map your options with OBOLUS.
What does a strong institutional KYC framework include?
A defensible institutional KYC framework comprises six linked components, each of which must be documented at a level that survives regulatory examination.
The first component is entity identification and verification. This means obtaining and verifying constitutional documents (certificate of incorporation, charter or equivalent), confirming the registered address and obtaining confirmation of authorised signatories. For regulated entities, the framework should also capture licence or registration details from the home regulator's public register where one exists.
The second is beneficial ownership mapping. FATF-aligned regimes require identification of natural persons holding a defined ownership or control threshold. Where a fund or holding structure places UBOs below that threshold through layering, the framework must include a documented rationale for the risk-based determination of who ultimately controls the entity. This step is consistently the weakest point in frameworks we review during an onboarding audit.
Third is risk classification. Not every institutional client is the same risk. A regulated exchange in a FATF-compliant jurisdiction is a different risk profile from a lightly supervised fund in a jurisdiction without a VASP regime. The framework must assign a risk tier at onboarding – typically low, medium or high – and document the criteria. That classification drives the intensity of ongoing monitoring and the trigger for enhanced due diligence.
Fourth is source-of-wealth and source-of-funds analysis. For institutional clients, this is a business-level inquiry: how does the entity generate its assets, and what is the provenance of the specific funds being deposited or traded? For a crypto fund, this typically means reviewing the fund's investor base documentation and obtaining representations about the source of LP capital.
Fifth is sanctions and PEP screening. Every institutional client – and every UBO identified through the ownership map – must be screened against relevant sanctions lists (OFAC, EU, UN, domestic) and against politically exposed person databases. The screening must be documented and updated on a trigger-event basis, not just at onboarding.
Sixth is ongoing monitoring calibration. The onboarding profile must feed the transaction monitoring system directly. An institutional client onboarded as a market-maker should have a transaction profile that reflects market-making activity; alerts that would be red flags for a retail client may be entirely consistent with that profile. Failure to configure monitoring to the onboarded profile is a common source of false positives – and, more dangerously, false negatives.
How does the Travel Rule apply in the institutional context?
The Travel Rule (the obligation, drawn from FATF Recommendation 16 for virtual assets, to pass originator and beneficiary data with a transfer above the applicable threshold) creates a distinct set of institutional onboarding obligations that many frameworks still treat as a separate compliance module rather than an integrated part of the onboarding process.
The practical effect is this: every time a VASP sends or receives a transfer involving an institutional counterparty, it must collect, verify and transmit the originator and beneficiary data required by the applicable regime. For institutional relationships, this means the onboarding framework must establish – before the first transaction – both the counterparty's Travel Rule solution and the technical protocol for data exchange. The two principal interoperability solutions currently in wide use are TRISA and the OpenVASP protocol; the choice of protocol must be agreed bilaterally at the relationship-setup stage.
Under MiCA and the EU's Transfer of Funds Regulation (TFR) as applied to crypto-assets, VASPs handling transfers between institutional clients must maintain Travel Rule data for every transaction, regardless of amount, unless a specific de-minimis exemption applies – and those exemptions vary by member state transposition. VARA's AML/CFT framework imposes a similar standard with the added requirement that data be available to VARA inspectors on demand. The FCA (the UK Financial Conduct Authority) has published its own Travel Rule implementation guidance requiring that firms take a risk-based approach to unhosted wallet verification, but for institution-to-institution transfers the data standard is unambiguous.
In our cross-border practice, we have seen institutional clients decline to transact because a counterparty's onboarding documentation did not include a completed Travel Rule readiness attestation. The commercial cost of that gap – a failed settlement, a missed trade window – is typically far greater than the cost of building the framework correctly from the start.
What are the most common mistakes in institutional KYC?
The most frequent failure mode is treating institutional KYC as a document-collection exercise rather than a risk-assessment exercise. Forms are completed; documents are filed; the client is approved. But the documentation is never analysed against the risk profile, the transaction monitoring system is never configured to the approved activity type, and the periodic review cycle is never triggered. When a supervisory visit occurs – or when a suspicious transaction report is required – the firm has a filing cabinet, not a compliance programme.
The second common mistake is over-reliance on regulated-entity status as a proxy for low risk. A fund regulated by CIMA (the Cayman Islands Monetary Authority) is not automatically low-risk. CIMA registration indicates that the fund meets the Cayman VASP Act's requirements; it does not mean the fund's investors, its trading counterparties or its asset provenance have been independently assessed. Regulation and risk are different axes. Every major FATF-aligned regime is explicit on this point, and we have seen regulator findings that cite precisely this conflation.
The third mistake is geographic siloing. A firm with licences in Dubai and the EU maintains two separate onboarding teams and two separate frameworks. An institutional client onboarded under the VARA regime then attempts to access the EU-licensed entity and is treated as a new client. The duplicated effort is costly; more importantly, the risk intelligence gathered in the Dubai relationship – including adverse media hits and unusual transaction patterns – never reaches the EU compliance function. A consolidated institutional KYC framework, with jurisdiction-specific overlays, is the correct architecture.
Fourth is inadequate refreshment. An institutional counterparty's risk profile changes. A fund may change its strategy, its GP or its investor base. A regulated exchange may lose its licence in a home jurisdiction. A UBO may become a politically exposed person following a government appointment. Without a documented trigger-event and periodic-review programme, the onboarding KYC becomes stale and the firm's risk-based approach is, in substance, not risk-based at all.
How should a cross-border operator structure its institutional onboarding architecture?
A cross-border digital-asset operator – one that holds licences in more than one jurisdiction or serves institutional clients across multiple regulatory zones – needs an onboarding architecture that separates the global standard from the local overlay.
The global standard is the baseline: entity identification, UBO mapping, risk classification, sanctions screening, Travel Rule readiness. It applies to every institutional client, regardless of the jurisdiction through which they access the firm's services. It is documented in a master KYC policy that is board-approved and reviewed at least annually.
The local overlay sits on top. Where VARA requires a specific enhanced due-diligence step for certain activity types, that step is added for clients accessing the Dubai-licensed entity. Where the MAS requires a specific source-of-funds declaration for higher-risk DPT service relationships, that form is added to the Singapore onboarding flow. Where the FCA's financial-promotion rules require specific disclosures before a UK-accessible institutional client can receive marketing about the firm's services, those disclosures are captured in the UK overlay.
This architecture has three practical benefits. It avoids duplication. It ensures that local regulatory changes – a new VARA guidance note, a revised MAS notice – are addressed through the overlay without requiring a full rewrite of the global policy. And it gives regulators in any single jurisdiction a clean answer to the question: "Show me your KYC framework for this client type." The answer is the global policy plus the local overlay, presented as a coherent single document.
We map this architecture for clients during a structured onboarding-framework review, typically scoped across the specific jurisdictions where the business holds a licence or intends to obtain one. The output is a gap analysis against the applicable regimes and a prioritised remediation plan.
Which institutional KYC approach fits your profile?
The right framework design depends on the operator's profile. Below is a prose decision matrix covering the most common configurations we see in practice.
Profile A: Single-jurisdiction CASP under MiCA. An exchange or custodian authorised in one EU member state, passporting to others, serving institutional clients across the bloc. The primary instrument is a MiCA-aligned CDD programme consistent with the applicable anti-money laundering directive. The indicative design timeline for a well-resourced firm is a matter of weeks, not months. The key risk is member-state variation in AML transposition; the overlay model handles this without requiring separate policies per country.
Profile B: Multi-hub operator with VARA and a second offshore licence. A firm licensed by VARA in Dubai and by CIMA or the BVI FSC offshore, serving institutional clients from both entities. The design challenge is ensuring that Travel Rule data flows and risk intelligence are shared across the two compliance functions. The global/overlay architecture is the correct solution. The key risk is a supervisory finding in one jurisdiction that the firm's AML controls are inconsistent between entities.
Profile C: Singapore-licensed DPT provider with an EU institutional client base. The firm holds a Payment Services Act licence from MAS and is onboarding EU-regulated funds. The design must satisfy MAS Notice PSN02 in full while also accounting for the EU's Transfer of Funds Regulation requirements that apply to the counterparties. The Travel Rule overlay is the operative document. The key risk is a transaction rejected by the EU counterparty's VASP because the Travel Rule data package does not meet TFR standards – a commercial disruption with a legal compliance root cause.
Profile D: Pre-licence build. A firm preparing a VARA or MiCA application that wants its institutional KYC framework designed before the licence is granted, so that it can be submitted as part of the application. Most regulators in the leading hubs now expect to see a complete AML/KYC policy, including the institutional onboarding section, as a condition of authorisation. Building this framework after approval is granted creates a gap between the legal permission to operate and the operational readiness to onboard clients.
CTA #2 – If a prior application stalled or an institutional client raised due-diligence concerns about your onboarding process, a structured review can surface the gap and the route to resolution. Write to OBOLUS at info@oboluslaw.com.
A matter from our practice
In a recent engagement, a digital-asset custodian preparing for a VARA licence application had built an institutional KYC framework based on its prior experience in a different regulatory zone. During our review, we identified that the framework did not include a Travel Rule readiness attestation in the institutional onboarding pack, that the beneficial-ownership threshold used was misaligned with VARA's applicable AML standards, and that the transaction monitoring configuration for institutional accounts was identical to the retail configuration. We restructured the framework, introduced jurisdiction-specific overlays for the client's two operating entities, and embedded a periodic-review trigger programme. The revised framework was submitted as part of the VARA application documentation. The application proceeded to the next assessment stage without a request for clarification on the AML/KYC section.
Addressing a common assumption
A common assumption among operators entering the institutional digital-asset market is that a single offshore licence – typically Cayman or BVI registration – is sufficient to serve institutional clients globally without further regulatory engagement. This is incorrect in almost every scenario that matters commercially.
Offshore registration under the BVI VASP Act or the Cayman VASP Act satisfies the home-jurisdiction requirement for those entities. It does not satisfy the AML and licensing obligations of the jurisdictions where the institutional clients are located, where the funds originate, or where the firm's servers and banking relationships sit. An EU-regulated fund investing through an exchange that holds only an offshore registration is almost certainly receiving services from a firm that is not authorised to provide them in the EU under MiCA. The fund's own compliance officer will identify this; the relationship will not proceed.
The same logic applies to VARA, MAS and the FCA. Each of those regimes has explicit expectations about the licensing status of counterparties and service providers. Operating without the right licence stack does not just expose the operator to enforcement – it cuts off access to the institutional client base that makes the business viable. We map the licence stack across operating, custody and payment layers before operators commit to a structure, because the cost of discovering this problem after the structure is built is substantially higher than the cost of designing it correctly at the outset.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – the practice-area overview covering the full AML/CFT regime for VASPs and CASPs.
- AML/CFT policy drafting in Liechtenstein – jurisdiction-specific guidance on drafting AML policies under the Liechtenstein TVTG regime.
- VARA licence application under heightened scrutiny – how to manage a VARA application when the regulator has raised specific compliance concerns.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, drawn from FATF Recommendation 16 as applied to virtual assets, requires a VASP to collect, verify and transmit originator and beneficiary information alongside any virtual-asset transfer that meets or exceeds the applicable threshold. The precise threshold varies by jurisdiction – and some regimes, including the EU's Transfer of Funds Regulation as applied to crypto-assets, remove the de-minimis exemption for VASP-to-VASP transfers entirely. The data must be available to the receiving VASP before or at the time of the transfer and must be retained for the period required by the applicable AML regime.
Who must act as MLRO for a crypto firm?
A Money Laundering Reporting Officer (MLRO) is the designated individual responsible for a firm's AML/CFT programme, including receiving and assessing internal suspicious activity reports and making disclosures to the relevant financial intelligence unit. Most FATF-aligned VASP regimes – including MiCA, VARA, MAS and the FCA's MLR registration requirements – mandate a named, sufficiently senior MLRO. The individual must have the authority and the direct access to senior management and the board required to discharge that function independently. A nominee MLRO without operational authority does not satisfy these requirements and is a common source of supervisory findings.
How do regulators audit crypto AML programs?
Regulators in the leading hubs – VARA, ESMA's national competent authorities, MAS, the FCA, the SFC in Hong Kong – audit AML programmes through a combination of supervisory visits, document requests and, increasingly, transaction-level data analysis. An audit typically covers the AML policy, the risk assessment, customer due-diligence files (including institutional onboarding records), transaction monitoring alert logs and their resolution, and the MLRO's annual report. Firms that cannot produce a complete, coherent and up-to-date institutional KYC framework on short notice are at material risk of a finding, regardless of whether their underlying controls are actually sound.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions and on disputes and on-chain asset recovery across more than 25 forums. AML and KYC compliance – including institutional onboarding frameworks, Travel Rule implementation and MLRO support – is a core part of what we do. We have advised crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions; we map the licence, compliance and banking stack before you commit to a structure. To discuss your institutional onboarding programme, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT regime analysis and institutional KYC framework design for VASPs and CASPs across multi-hub operating structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.