EST · MMXXVI
Home/Services/Compliance Aml Travel Rule/MLRO and compliance officer function for Institutional Clients
Compliance, AML & Travel Rule

MLRO and compliance officer function for Institutional Clients

Mlro and compliance officer function for Institutional Clients. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Tal

Institutional digital-asset businesses operate inside an expanding web of anti-money laundering obligations. A Money Laundering Reporting Officer (MLRO) – the named individual legally responsible for a firm's AML program – is a mandatory appointment under every major VASP regime, from MiCA across the EU to VARA in Dubai to the Payment Services Act regime supervised by MAS in Singapore. Without a qualified, continuously available MLRO, a firm cannot obtain or retain its licence, cannot satisfy banking counterparties, and becomes the primary target when regulators open an AML examination. This page sets out how the MLRO and compliance officer function works in practice, what institutional operators get wrong, and how OBOLUS structures the engagement.

Why the MLRO Function Is a Regulated Seat, Not a Job Title

Most licensing regimes treat the MLRO as a controlled function, not simply a managerial role. Under MiCA and the national AML transpositions that sit alongside it, the MLRO must satisfy a fit-and-proper test, be approved by the competent authority, and be reachable at all times for suspicious transaction escalations. The same logic applies under the VARA rulebooks in Dubai: the compliance function is not delegable to a junior employee or a part-time contractor who also handles marketing. Regulators scrutinize the MLRO's qualifications, independence from the business line, and access to the board.

The cross-border dimension is where institutional operators feel the most pressure. A firm licensed in one EU member state but serving institutional counterparties in the UAE, Hong Kong, and Singapore faces AML obligations in each operating layer. The MLRO must understand the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with every qualifying virtual-asset transfer – across each relevant jurisdiction, because the threshold and technical standard can differ. Handling that from a single compliance seat requires deliberate scoping of what law applies at each node.

In our regulatory practice, the most common structural failure we see is a firm that appointed an MLRO at licence application, then failed to resource that officer adequately once the business scaled. The officer holds the regulated seat. The infrastructure around the seat – escalation procedures, the KYC framework (the documented rules governing how the firm identifies and verifies clients), the transaction monitoring system, the suspicious activity reporting chain – had not kept pace. Regulators notice the gap within the first supervisory cycle.

For institutional clients who are mapping this for the first time: the process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis significantly. Map your options with an OBOLUS specialist before the next supervisory filing.

What Does a Functional MLRO Program Require at the Institutional Level?

A functional MLRO program for an institutional VASP is built on five inter-locking components, each of which a regulator or a banking counterparty will test independently. The absence of any one of them is enough to trigger a remediation demand or, in severe cases, licence suspension.

The first component is a written, board-approved AML/CFT policy that maps the firm's specific risk exposure – by product, by client segment, by geography. Generic templates fail here. An institutional custodian holding assets for funds domiciled in the Cayman Islands, whose ultimate investors span multiple jurisdictions, carries a different risk profile than a spot exchange serving retail EU clients.

The second is a KYC framework calibrated to the institutional client base. For institutional counterparties, that means entity due diligence: ownership chains, beneficial ownership to the applicable threshold, source of funds at the fund level, and ongoing review triggered by material changes. The MLRO owns this framework and is accountable when it fails.

The third is transaction monitoring – automated or rule-based systems that flag unusual patterns and feed a review queue the MLRO manages. For VASPs, this layer intersects directly with the Travel Rule. Every transfer above the applicable threshold must carry originator and beneficiary data. Where a counterparty VASP cannot or will not provide that data, the MLRO must have a documented policy for how the firm responds: hold, reject, or apply enhanced scrutiny. Under the FATF framework and the MiCA-aligned AML obligations, passivity is not a permissible option.

The fourth component is the suspicious activity reporting chain: internal SARs escalated to the MLRO, external reports filed with the financial intelligence unit of the relevant jurisdiction, and a tipping-off prohibition regime the entire firm understands. Institutional clients frequently underestimate how quickly a regulator can identify that SAR filings are disproportionately low relative to the volume and risk profile of the business.

The fifth is training. The MLRO's obligation does not end with a once-annual e-learning module. In our practice, regulators across the major hubs increasingly require evidence of tailored, documented, role-specific training refreshed as the regulatory regime evolves.

How Does the Travel Rule Interact With the MLRO Function?

The Travel Rule, as applied to virtual assets under FATF Recommendation 15 and the jurisdiction-specific transpositions of it, sits directly inside the MLRO's remit. It is not a technology problem that the compliance team can park with engineering. The MLRO is responsible for ensuring the firm's Travel Rule solution is operationally compliant, that the data fields required are actually collected and transmitted, and that the firm has a documented procedure for handling transfers where the counterparty VASP is unhosted, unregistered, or non-cooperative.

For institutional operators, the Travel Rule creates a specific tension. Institutional transfers are often large, structured, and involve counterparties who are themselves regulated. But "regulated" does not mean "Travel Rule compliant." We regularly advise clients whose institutional counterparties in jurisdictions that have not yet aligned their Travel Rule threshold or technical standard to the FATF baseline. The MLRO must resolve that gap in real time – not after the transfer has settled.

The MAS regime in Singapore and the SFC regime in Hong Kong both impose Travel Rule obligations on their licensed VASPs. Under VARA in Dubai, the applicable rulebooks require transfer information to accompany outgoing transactions in a form the receiving institution can process. The practical consequence is that an institutional VASP operating across these hubs needs Travel Rule procedures that are jurisdiction-aware, not a single global policy that ignores local thresholds. The MLRO owns that architecture.

A technical note worth flagging: Travel Rule compliance solutions – the messaging standards and protocols that VASPs use to exchange data – are not interoperable across all counterparties. The MLRO must understand which standard the firm's counterparties use and maintain a documented escalation path when the counterparty cannot receive data in the required format.

Cross-Border MLRO Structure: One Officer or Several?

An institutional VASP operating across multiple regulated jurisdictions faces a structural question the MLRO function alone cannot resolve: which jurisdiction's AML law governs which part of the business, and does each regulated entity need its own approved MLRO? The answer is almost always yes, at least for entities that hold a licence creating a formal approved-person requirement.

Under MiCA, a CASP (crypto-asset service provider) passporting across the EU holds one CASP authorisation but may operate branches in other member states. The AML obligations attach to the entity level. If the firm also holds a VARA licence for its Dubai operations and a Payment Services Act licence in Singapore, each of those entities has its own supervised compliance obligation. A single MLRO based in one jurisdiction may serve as the group compliance head, but each regulated entity typically requires a locally available compliance officer who can engage with the relevant regulator directly.

Banking adds another layer. Banks that provide fiat rails to institutional VASPs conduct their own AML due diligence on the VASP. That due diligence includes reviewing the MLRO's qualifications, the firm's SAR filing history where accessible, the Travel Rule solution, and the transaction monitoring infrastructure. We have seen institutional clients lose banking relationships not because their AML program was structurally deficient, but because they could not produce the documentation a correspondent bank required within the review window.

The decision matrix here runs roughly as follows. A single-entity institutional VASP with one regulatory licence and a focused product set needs one approved MLRO, a written AML policy, a Travel Rule solution, and a transaction monitoring system calibrated to its risk profile. The timeline for getting that to a regulatorily defensible standard depends heavily on where the firm is starting from and which regime applies, but from a standing start it is not a matter of days. A multi-entity group with licences across three or more jurisdictions needs a group compliance architecture, potentially multiple local MLRO appointments, and a programme office capable of running parallel submissions to different regulators on different annual cycles. The risk in both cases is underestimating what "functional" means to a regulator conducting an on-site examination.

What Do Regulators Examine in an AML Audit of an Institutional VASP?

Regulators auditing an institutional VASP's AML program focus on the gap between documented policy and operational reality. The written policy is a starting point, not a conclusion. An examiner from ESMA's national competent authorities, VARA, the FCA, or MAS will typically ask for evidence that the policy is actually applied: completed KYC files, transaction monitoring alert logs and their disposition, SAR records, training completion data, and board-level AML reporting minutes.

Three examination themes recur across the major hubs. The first is customer risk categorisation. Regulators check whether the firm's risk ratings for institutional clients are documented, consistent, and re-evaluated periodically. An institutional counterparty flagged as low-risk at onboarding but whose transaction patterns have since changed materially is a red flag the MLRO should have caught. The second theme is Travel Rule completeness. Examiners pull a sample of outgoing transfers and verify that the required data was transmitted and that gaps were handled according to a documented procedure. The third is the internal SAR process: how quickly escalations reach the MLRO, how the MLRO documents their decision to file or not file, and whether that decision record exists.

In a recent AML advisory matter, an institutional exchange had documentation that satisfied its home-state regulator at the licence stage, but had not updated its KYC framework to reflect an expansion into institutional lending products. When a secondary regulator in another jurisdiction conducted its own review, the gaps in the lending-product onboarding procedures triggered a formal remediation request. We assisted the firm in mapping the exact scope of the deficiency, drafting the remediation plan, and presenting it to both regulators on a coordinated timeline. The exchange resolved the matter without enforcement action, though the remediation window was tight.

If a prior regulatory review surfaced gaps you have not yet closed, early external engagement can make the difference between a remediation letter and an enforcement notice. Map your options with us before the next examination cycle.

Common Structural Mistakes Institutional Operators Make

Institutional operators make a small number of recurrent structural mistakes in their AML and MLRO programs. Each one is avoidable, and each one regularly appears in regulatory enforcement actions and supervisory letters across the major hubs.

The first is the nominal MLRO. The officer is named on the licence, satisfies the fit-and-proper criteria at the time of approval, but has no real authority in the business. The business line makes product decisions. Compliance is asked to ratify them afterward. This structure fails on its first serious examination because the regulator can quickly establish, through document review and interview, that the MLRO's sign-off was a formality rather than a gate.

The second is a KYC framework that was designed for a retail client base and applied without modification to institutional counterparties. Institutional onboarding requires entity-level documentation that retail processes do not contemplate: constitutional documents, regulated-fund status, ultimate beneficial ownership, and – where the counterparty is itself a VASP – evidence of that VASP's own AML program. Applying a retail template to an institutional prime brokerage client is a structural mismatch a regulator will identify.

The third is treating the Travel Rule as a back-office matter. The MLRO who does not understand the technical standard their firm uses, does not know which counterparty VASPs they cannot exchange data with, and has not documented a policy for unhosted-wallet transfers is exposed. VARA and MiCA both treat Travel Rule compliance as part of the core AML program, not a separate technical workstream.

A common assumption in the market is that once a licence is granted and an MLRO is named, the compliance obligation is substantially met. It is not. The licence creates the ongoing obligation. The MLRO function is the mechanism by which that obligation is met on a continuous basis. We have seen firms treat the post-licence period as maintenance mode and discover, at the next supervisory cycle, that the regulator views it as a live and escalating requirement.

How OBOLUS Structures the MLRO and Compliance Officer Engagement

OBOLUS approaches the MLRO and compliance officer function for institutional clients as a matter of legal architecture, not HR. The question is not simply who will sit in the seat. It is what legal regime governs the seat, what the seat requires procedurally, how the obligation interacts with every other licensed entity in the group, and how to build a program the firm can actually sustain operationally.

We map the licence stack before we touch the compliance program. An institutional client that holds licences under VARA, MiCA, and the Payment Services Act needs its AML obligations characterised correctly for each entity. The Travel Rule threshold, the SAR filing jurisdiction, the transaction monitoring parameters – all of these differ. A single global AML policy that does not distinguish between them is not a program; it is a document.

We regularly advise on the drafting or revision of AML/CFT policies calibrated to the institutional risk profile, the scoping of the KYC framework for both entity types the firm serves, the Travel Rule solution assessment and gap analysis, and the MLRO training program. Where a client needs an interim compliance officer during a transition – a change of MLRO, a new licence in a new jurisdiction, a remediation period – we can place an experienced compliance professional and transfer the function to an in-house appointment on a documented timeline.

We map the licence, banking, and AML stack across the operating, custody, and payment layers before you commit. That is not a due-diligence checkbox; it is the foundation on which the compliance program is built. To scope that work for your institutional structure, write to info@oboluslaw.com.

Decision Matrix: Which Institutional Profile Needs What

Different institutional operator profiles require materially different MLRO and compliance program structures. The matrix below is indicative. It is not a substitute for jurisdiction-specific legal advice, but it illustrates how the analysis branches.

Profile A – Single-entity institutional exchange, one regulatory licence. This firm needs one approved MLRO with demonstrable AML expertise, a written policy, a Travel Rule solution covering its primary counterparty set, and transaction monitoring calibrated to its product risk. The timeline to a regulatorily defensible program from a standing start is weeks to a few months, depending on how current the documentation is and whether the regulator requires pre-approval of the MLRO. The primary risk is failing to keep the program updated as the product offering evolves.

Profile B – Multi-entity group, licences in two or three jurisdictions. This structure requires a group compliance architecture: a group compliance head (often the MLRO of the primary entity), local compliance officers in each regulated jurisdiction, and a programme office that coordinates policy updates across entities. Travel Rule procedures must be jurisdiction-aware. The timeline is longer because multiple regulated entities have different approval processes, and the risk is inconsistency – a gap in one entity's program that creates regulatory exposure in that jurisdiction while the group believes it is compliant.

Profile C – Institutional custodian holding assets for third-party funds. Custody creates specific AML obligations around safeguarding, segregation, and the due diligence owed to the funds whose assets are held. The MLRO must understand the fund layer as well as the underlying asset layer. If the custodian is also in the transfer chain – processing withdrawals on fund instruction – the Travel Rule applies to those transfers. The KYC framework must address the fund as the counterparty and, in many jurisdictions, look through to the fund's investors to the applicable beneficial ownership threshold.

Self-Assessment Checklist for Institutional MLRO Programs

Before engaging counsel or preparing for a supervisory cycle, institutional operators should work through the following diagnostic. These are the questions a regulator will ask first.

  • Does the MLRO hold an approved-person status in every jurisdiction where the group holds a regulated licence?
  • Has the AML/CFT policy been reviewed and updated within the last twelve months, and is it specific to the current product set and client base?
  • Is the KYC framework differentiated for institutional counterparties, covering entity due diligence, beneficial ownership, and source of funds at the fund level?
  • Does the Travel Rule solution cover every jurisdiction from which the firm sends or receives transfers above the applicable threshold?
  • Is there a documented procedure for transfers where the counterparty VASP cannot provide Travel Rule data?
  • Are SAR filings proportionate to the volume and risk profile of the business, and is the MLRO's decision record maintained for each escalation?
  • Has the board received a formal AML report from the MLRO in the current reporting period?
  • Is the training program role-specific and documented, with completion records available for examination?

If any of these questions produces a qualified answer, that qualification is the starting point for the remediation programme. Regulators do not expect perfection at the first supervisory cycle. They do expect an institution that has identified its gaps and has a documented, time-bound plan to close them.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15 and transposed into local law by each major VASP regime, requires a virtual-asset service provider to collect and transmit originator and beneficiary information with every qualifying transfer. The applicable threshold and the required data fields vary by jurisdiction. Where the receiving institution cannot process the data – for example, because it is unhosted or operates in a jurisdiction that has not yet implemented the rule – the sending VASP must have a documented procedure for how it handles that transfer. The MLRO owns that procedure and is accountable for its consistent application.

Who must act as MLRO for a crypto firm?

Under most major VASP regimes – including MiCA across the EU, VARA in Dubai, and the Payment Services Act regime in Singapore – the MLRO must be a named individual who satisfies the regulator's fit-and-proper criteria, holds an approved-person status where required, and has genuine authority and independence within the firm. The role cannot be filled by a nominee or a part-time contractor without substantive AML expertise. For multi-entity groups, each regulated entity typically requires its own locally available compliance officer, even if a group MLRO sits above them at the holding level.

How do regulators audit crypto AML programs?

Regulators auditing a VASP's AML program examine the gap between documented policy and operational practice. They review completed KYC files, transaction monitoring alert logs and their disposition records, SAR filing history proportionate to the firm's risk profile, Travel Rule completeness across a sample of transfers, board-level AML reporting, and staff training records. The examination is evidence-based: a policy document without supporting operational records does not satisfy the audit. The MLRO should be able to walk an examiner through each layer of the program with reference to live records, not retrospective reconstruction.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance obligations that run alongside them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit – because the compliance program is only as sound as the structure it sits inside. To discuss your MLRO and compliance officer requirements, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program architecture, MLRO function design and Travel Rule compliance for multi-jurisdictional institutional VASPs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours