For an established virtual asset service provider, the MLRO (Money Laundering Reporting Officer) and compliance officer function is not a back-office formality. It is the structural layer that keeps a licence live, banking relationships intact and regulators satisfied. When that function is under-resourced or badly designed, the consequences arrive fast: a correspondent bank exits, a supervisory review opens, or a regulator suspends the authorisation. The question operators must answer is not whether to build this function, but how to build it correctly across multiple jurisdictions and expanding product lines.
Under FATF Recommendation 15 – the global standard for virtual assets – and under the domestic regimes that implement it (including MiCA and its national competent authorities, VARA, the FCA's registration regime, and the MAS Payment Services Act framework), a licensed VASP must designate a qualified individual as MLRO, maintain a documented AML/CFT programme, and apply the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer). This page sets out what that means in practice for an operator already in the market.
The Regulated Basis for the MLRO and Compliance Officer Function
Every leading VASP regime imposes a mandatory senior-management compliance appointment. The MLRO function exists because regulators treat AML risk as a board-level accountability, not a technical task. Under FATF Recommendation 15, jurisdictions are expected to require VASPs to implement AML/CFT measures at least equivalent to those applied to financial institutions, including the appointment of a competent officer responsible for the programme. MiCA and its accompanying ESMA guidance reinforce this at the EU level; VARA's rulebooks apply comparable requirements in Dubai; the FCA's Money Laundering Regulations regime does the same for UK-registered cryptoasset businesses; and MAS imposes equivalent obligations on holders of a Digital Payment Token service licence under the Payment Services Act.
In practice, this means the designated individual must be named to the regulator, must possess demonstrable AML expertise, and must have sufficient seniority and authority to act on their own findings – including filing suspicious transaction reports without seeking board approval. Many established operators discover, during a supervisory review, that their named compliance officer lacks the documented authority the regime actually demands. That gap is not theoretical: it is the single most common deficiency cited in VASP supervisory reports across the EU member states, the UK and the Gulf jurisdictions we follow in our practice.
What Does an Adequate AML Programme Look Like for a Scaled Operator?
An adequate AML programme for an established operator is a living system, not a set of policies filed on incorporation day. It has four core components: a documented risk assessment updated to reflect the current product and customer profile; a KYC framework (know-your-customer procedures calibrated to risk tier); a transaction monitoring system with documented alert thresholds and disposition records; and a Travel Rule compliance mechanism for cross-border transfers.
The risk assessment must be genuinely reflective of the business. An operator that has added staking products, a custody layer and a fiat off-ramp since its initial licence was granted faces a materially different risk profile than the one described in its original AML policy. Regulators expect the assessment – and the controls built from it – to track those changes. In our cross-border practice, we regularly see operators whose policies describe a product set that no longer matches what the business actually runs. The delta between the documented programme and operational reality is where enforcement exposure accumulates.
Transaction monitoring for an established exchange or custodian operates at scale. Alert logic must be proportionate to the volume and typology of transactions the platform processes. Thresholds set for a startup with light volume frequently generate either alert fatigue or blind spots when transaction numbers grow. The compliance officer's role includes ensuring the monitoring calibration keeps pace with the business – and that the review records are sufficient to demonstrate to an examiner that alerts were genuinely assessed, not auto-cleared.
For an established operator, the contextual bridge from programme to practice is the compliance officer's operational authority. That means documented escalation paths, a clear suspicious activity reporting process, training records for front-line staff, and a governance structure that places the compliance function outside the business line it supervises.
Map the compliance structure across your operating, custody and payment layers before a supervisory review surfaces the gaps. To discuss a scoped assessment, contact OBOLUS at info@oboluslaw.com or map your options.
How Does the Travel Rule Apply to an Established VASP?
The Travel Rule – the obligation to originate, transmit and retain originator and beneficiary data alongside a virtual asset transfer – is the most operationally demanding AML obligation for a scaled exchange or custodian. FATF has applied this standard to VASPs since its 2019 guidance update, and implementation is now codified across the major licensing regimes: MiCA in the EU, the VASP regime under VARA in Dubai, the FCA regime in the UK, and MAS in Singapore, among others.
For an established operator, Travel Rule compliance requires a technical solution capable of identifying the counterparty VASP on the receiving end of a transaction, transmitting the required data through a recognised messaging protocol, and handling transfers to unhosted (self-custodied) wallets in accordance with the jurisdiction's applicable rules. The FATF-recommended de-minimis threshold and the precise data fields required vary by jurisdiction – operators running a multi-jurisdiction stack must map each regime's requirements separately, not assume uniformity.
The operational failure mode we see most often is not refusal to implement: it is partial implementation. An operator builds Travel Rule capability for transfers originating from its platform, then discovers that inbound transfers from counterparty VASPs are not being handled correctly, or that its unhosted-wallet policy lacks the enhanced due-diligence triggers the relevant regime requires. Supervisory examinations in the EU and the UK have begun focusing precisely on this gap – the completeness of inbound Travel Rule handling, not just outbound.
What Happens When the Compliance Structure Spans Multiple Jurisdictions?
Operating across licensing jurisdictions compounds every compliance obligation. An operator holding a CASP authorisation under MiCA, a VARA licence in Dubai, and an FCA registration in the UK does not run one AML programme: it runs three overlapping frameworks, each with its own regulatory reporting lines, its own MLRO designation requirements, and its own Travel Rule implementation standard.
The cross-border reality for established operators is that local regulators do not accept the parent entity's compliance programme as a substitute for a local-facing one. Each licensed entity typically requires its own named MLRO (or an approved shared function, where the regulator permits it), its own board-approved risk assessment, and its own documentation trail. Where a shared compliance model is used – one team serving multiple licensed entities – the governance records must demonstrate that the function is operationally independent in each jurisdiction. Regulators examine this closely.
There is also the question of where the compliance officer actually sits. Several of the Gulf jurisdictions require the MLRO to be physically present or at minimum domiciled in the relevant jurisdiction. Others accept remote functions with appropriate oversight. The FCA regime has historically scrutinised the substance of the UK compliance function in firms that manage their primary operations from offshore. The BVI FSC and CIMA apply their own standards to registered VASPs. For a business operating across these jurisdictions simultaneously, the question of who holds the MLRO role – and where – becomes a structural legal question, not an HR one.
In our practice, we work with operators to map each jurisdiction's applicable requirements against the entity structure, then design a compliance governance model that satisfies all of them without requiring unnecessary duplication of cost or personnel.
What Are the Most Common Compliance Failures for Established Operators?
The five mistakes we see repeatedly in established VASP compliance programmes follow a recognisable pattern. First, the risk assessment is not updated after product expansion – a business that added DeFi aggregation or tokenised-asset trading is running a materially higher risk profile than its founding-era AML policy describes. Second, the MLRO's authority is nominal: the individual is named to the regulator but has no documented escalation rights and no independent reporting line to the board. Third, transaction monitoring thresholds are never recalibrated after volume growth, creating systematic blind spots.
Fourth, and critically for multi-jurisdiction operators: the Travel Rule solution covers outbound transfers but not inbound ones, leaving the operator exposed on the receiving side of transactions from other VASPs. Fifth, training records are inadequate. Regulators across MiCA's national competent authorities and the FCA's supervisory function have made clear that staff AML training is examined as evidence of programme substance, not merely as a box-check.
A common assumption in the market is that a well-resourced compliance team is sufficient on its own. In our experience, the team must be combined with documented governance – authority structures, escalation matrices and board engagement records – or it fails the supervisory test even where the individuals involved are genuinely expert. Programme substance and programme documentation are both required. One without the other does not satisfy the standard.
Which Compliance Governance Model Fits Your Operator Profile?
The right compliance governance model depends on the operator's entity structure, jurisdictional footprint and stage of growth. Three profiles recur in our practice.
Profile A is the single-jurisdiction licensed operator with a growing product line. This entity needs a dedicated internal MLRO with documented authority, a risk assessment that tracks the expanded product scope, and a Travel Rule solution calibrated for both outbound and inbound transfers. The primary risk is that the compliance function was designed for the business at launch and has not kept pace. The remediation path is typically a structured review, a programme gap analysis, and an authority framework that meets the current regulatory standard.
Profile B is the multi-jurisdiction group with licensed entities in two or more regimes. This operator needs a shared compliance model with clear local accountability in each entity. The MLRO designation, local board reporting and jurisdiction-specific risk assessment must all be documented at the entity level, even where resources are centralised. The key risk is that regulators in one jurisdiction conclude the local compliance function is a shell. The design priority is demonstrable local substance: named individuals, local records, and governance that can withstand examination.
Profile C is the operator whose compliance programme was built for a prior licence category and has since obtained an additional authorisation (for example, adding a custody licence to an exchange licence, or expanding from a standard payment institution to a major payment institution under MAS). This operator must re-baseline the risk assessment, re-examine the MLRO's authority scope, and extend the monitoring and KYC framework to the new regulated activity. The risk is assuming the existing programme extends to the new activity without modification – it rarely does.
A Compliance Function Under Examination
In a recent matter, an established exchange operator holding licences in two EU member states entered a supervisory review cycle under the applicable MiCA transition arrangements. The regulator's examination identified that the MLRO designation in one entity was held by an individual who lacked documented authority to file suspicious activity reports independently of the CEO. The compliance team was experienced; the gap was governance, not expertise. We assisted the operator in restructuring the authority framework, updating the board-level AML governance records, and producing a revised risk assessment that accurately reflected the dual-jurisdiction product scope. The operator completed the review cycle with no material findings. Timing was critical: the examination had opened in early autumn and the revised documentation was required within a defined window.
Self-Assessment: Is Your Compliance Function Examination-Ready?
Before a regulator or correspondent bank asks these questions, your compliance officer should be able to answer them affirmatively.
- Is the MLRO named to the relevant regulator, with a documented authority to act independently on AML findings?
- Has the AML risk assessment been updated within the past twelve months to reflect the current product set and customer profile?
- Does the transaction monitoring system have documented calibration records showing alert thresholds were set and reviewed for the current transaction volume?
- Is the Travel Rule solution handling both outbound and inbound transfers in compliance with each jurisdiction's applicable requirements?
- Are staff AML training records current, with completion records at the individual level?
- For multi-jurisdiction operators: does each licensed entity have its own board-approved risk assessment and named compliance governance, or is the group relying on a parent-level document?
If one or more of these questions draws a qualified answer, the gap between the current programme and the examination standard is a concrete legal risk. Banking correspondents and acquiring banks increasingly run their own AML programme audits of VASP clients – the compliance function is therefore customer-facing as well as regulatory-facing.
If your compliance programme has not been pressure-tested against the current supervisory standard in each jurisdiction you operate, the next examination will do it for you. To commission a scoped compliance review, write to info@oboluslaw.com or map your options.
Addressing the Offshore Licence Assumption
A common assumption among operators expanding internationally is that a single offshore licence – a BVI FSC VASP registration, a Cayman CIMA registration, or similar – is sufficient to serve clients across multiple target markets. This assumption does not withstand regulatory scrutiny. Most major jurisdictions apply their VASP or AML obligations on the basis of where clients are located, not only where the entity is incorporated. An operator serving EU retail clients from a BVI entity may nonetheless fall within the MiCA CASP perimeter. A business with UK-facing marketing and a VARA licence in Dubai still requires FCA registration for UK-regulated activities.
The compliance function must be designed around the actual regulatory perimeter of the business – which includes where services are marketed, where users are onboarded, and where fiat conversion occurs – not only the jurisdiction of the licensed entity. In our cross-border practice, we regularly advise operators who have built a compliance programme around their licence jurisdiction without mapping the regulatory reach of the jurisdictions where their customers actually sit. The MLRO and compliance officer function must address all of those layers.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – the full practice overview covering FATF, MiCA and cross-border obligations
- The compliance burden in practice – an analysis of how the MLRO function operates under operational pressure
- MLRO and compliance officer function for early-stage founders – how compliance governance is structured at the pre-licence stage
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, transmit and retain originator and beneficiary information alongside every qualifying virtual asset transfer. The precise data fields and the applicable de-minimis threshold vary by jurisdiction. FATF Recommendation 15 sets the international standard; MiCA, the FCA regime, MAS and VARA each implement it with jurisdiction-specific requirements. An established operator must ensure its Travel Rule solution handles both outbound and inbound transfers and addresses unhosted-wallet transactions in line with the relevant regime.
Who must act as MLRO for a crypto firm?
The MLRO must be a named individual with demonstrable AML expertise, sufficient seniority to act independently of the business line, and documented authority to file suspicious transaction reports without seeking board approval. Most leading VASP regimes – including those under MiCA, VARA, the FCA and MAS – require the MLRO to be approved or notified to the regulator. Multi-jurisdiction groups must assess whether each licensed entity requires its own MLRO or whether a shared function is permissible under the applicable rules.
How do regulators audit crypto AML programs?
Regulators examine the AML programme as a system: the current risk assessment, the MLRO's authority framework, transaction monitoring calibration records, Travel Rule implementation for both inbound and outbound transfers, staff training records and board governance documents. The examination tests whether the programme reflects the business as it currently operates – not as it was designed at inception. Supervisory reviews across the EU's national competent authorities and the FCA have focused particularly on programme completeness and governance documentation, not merely the existence of written policies.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers as one mandate, and we structure licensing, banking and tax as a single integrated workstream rather than three disconnected engagements. To discuss your compliance function, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML programme design, MLRO governance and Travel Rule compliance for licensed VASPs across multi-jurisdiction structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.