EST · MMXXVI
Home/Services/Compliance Aml Travel Rule/MLRO and compliance officer function for Regulated Entities
Compliance, AML & Travel Rule

MLRO and compliance officer function for Regulated Entities

Mlro and compliance officer function for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk t

Operating a regulated digital-asset business without a properly constituted Money Laundering Reporting Officer (MLRO) and compliance officer function is not merely a governance gap – it is an enforcement trigger. Regulators from the Financial Conduct Authority (FCA) in the United Kingdom to VARA in Dubai and ESMA's network of national competent authorities under MiCA treat the MLRO appointment as a baseline condition of authorisation, not an optional best practice. The question for a scaling crypto business is not whether to build the function, but how to structure it correctly across the jurisdictions in which the entity actually operates.

This page sets out the regulatory basis for the MLRO and compliance officer role, the practical steps required to build and maintain a compliant function, the cross-border complications that routinely catch operators off guard, and the common mistakes that lead to licence conditions, public censure or outright revocation.

What the regulated basis requires of a VASP's MLRO

Every regulated virtual asset service provider (VASP) – a firm providing exchange, transfer, custody, brokerage or related services in digital assets – must designate a natural person as its Money Laundering Reporting Officer. The MLRO function originates in the FATF Recommendations, specifically the obligations on financial institutions to appoint a compliance officer under Recommendation 18, and it is replicated with local variation in every flagship licensing regime. Under MiCA, the applicable CASP provisions require a senior management compliance function. The VARA rulebooks mandate an approved compliance officer with direct board access. The FCA's Money Laundering Regulations require a nominated officer whose identity is disclosed on registration.

The structural point most operators miss is this: the MLRO is not the compliance programme. The officer is the designated channel through which suspicious activity reports flow and the accountable person for the firm's AML/CFT (anti-money laundering and countering the financing of terrorism) framework. A firm can have a team of analysts and a sophisticated transaction monitoring system and still be non-compliant if the MLRO lacks genuine authority, independence from business lines, and direct access to the board or senior management.

In our practice, regulators in the leading hubs increasingly expect the MLRO to be resident in – or at minimum operationally connected to – the licensed jurisdiction. A nominee MLRO who plays no substantive role in the firm's day-to-day compliance decisions will not survive regulatory scrutiny. The FCA has been explicit on this point; VARA's supervisory approach reflects the same expectation.

What must a VASP's AML compliance programme contain?

A compliant AML programme for a regulated digital-asset entity must cover, at minimum: a written risk assessment, customer due diligence procedures, a KYC framework (the policies and controls by which the firm identifies and verifies customers and beneficial owners), transaction monitoring, the Travel Rule mechanism, suspicious activity reporting, record retention, and staff training.

Each element requires documentation that a regulator can audit. The risk assessment is the foundation: it must be entity-specific, address the particular risks of the firm's product set and customer base, and be reviewed at defined intervals. A generic risk assessment copied from a compliance template will be treated by most supervisors as evidence of a tick-box culture rather than genuine risk management.

Transaction monitoring is the operational core. The system must generate alerts calibrated to the firm's risk appetite and product mix. An exchange handling high-volume spot trading carries different typologies than a custody provider serving institutional clients. The monitoring ruleset must reflect that distinction, and the MLRO must be able to demonstrate to the regulator that alert thresholds were set deliberately and are reviewed regularly.

The Travel Rule – the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data with a virtual asset transfer – adds a data-transmission layer on top of the monitoring function. The MLRO is responsible for ensuring the firm has a compliant Travel Rule solution in place and that the solution interoperates with counterparty VASPs. This is rarely a purely technical matter; the MLRO must understand the rule's threshold triggers, the sunrise-problem implications when a counterparty is in a non-implementing jurisdiction, and the firm's policy for unhosted wallet transfers.

The FATF Travel Rule and the AML programme sit together operationally. Firms that treat them as separate work streams create gaps that regulators identify quickly.

How does the MLRO function operate across multiple licensed jurisdictions?

For a business licensed in more than one jurisdiction – say, a MiCA CASP authorised in an EU member state, a VARA-licensed entity in Dubai, and an FCA-registered entity in the United Kingdom – the MLRO question is genuinely complex. Each regime has its own nomination, approval and reporting-line requirements. In some cases, a single group MLRO can cover multiple entities if the supervisory authorities accept that structure; in others, each licensed entity requires its own designated officer.

The cross-border reality adds a second dimension: the firm's users, counterparties and banking relationships may span jurisdictions that do not yet have harmonised AML standards. Operators we advise routinely discover that their Travel Rule solution works well for transfers between two FATF-member VASP jurisdictions but breaks down when a transfer touches an unhosted wallet or a counterparty in a jurisdiction with a different de-minimis threshold. The MLRO must have a documented policy for each of those scenarios, not just for the clean cases.

Group-level compliance structures must be designed carefully. A parent entity in one jurisdiction cannot simply assume that its AML controls satisfy the requirements of a subsidiary's local regulator. The Bank of Lithuania, for example, applies FATF-aligned standards under its own supervisory guidance, and the transition to MiCA CASP authorisation requires entities to re-examine whether their existing compliance architecture meets the updated requirements. Similarly, MAS in Singapore applies its own Payment Services Act supervisory expectations, which are not identical to those of European NCAs even where the underlying FATF recommendations are the same.

A key risk in cross-border group structures is the assumption that a single offshore entity with one MLRO nomination covers all group activity. It does not. We have seen enforcement actions stem precisely from this assumption – a matter in which a group operated entities in three jurisdictions under a single MLRO who had no operational visibility into two of them.

For a scoped assessment of your MLRO and compliance officer structure across operating entities, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking jurisdictions – change the analysis. Map your options

What are the most common MLRO and AML compliance failures in crypto firms?

The most common failure is the nominal MLRO: a person named in a licence application who holds the title but exercises none of the function. Regulators have become sophisticated at identifying this pattern. They ask for SAR filing records, evidence of MLRO engagement in policy sign-off, training completion records, and board-level reporting logs. A nominee who cannot produce those records fails the test regardless of what the organisational chart says.

The second common failure is a KYC framework that was built at launch and never updated. A digital-asset firm's customer risk profile changes as the product evolves, as new markets open and as typologies shift. An MLRO who has not revised the KYC framework in several years is unlikely to satisfy a supervisory review, particularly as MiCA and the VARA rulebooks have introduced updated expectations on beneficial ownership verification and enhanced due diligence for higher-risk customers.

The third failure pattern is the gap between the AML policy document and operational reality. We regularly advise firms where the policy manual describes a rigorous monitoring and escalation process that, in practice, no one follows. The MLRO is personally accountable for that gap. In our cross-border practice, we have seen this gap surface most acutely in firms that scaled quickly: the compliance documentation did not keep pace with the growth of the team, the product set or the customer base.

A fourth – and increasingly common – failure is inadequate Travel Rule implementation. Firms deploy a technical solution but fail to operationalise it: the solution is connected but not configured for the firm's specific transaction flows, the MLRO does not understand its outputs, and there is no documented policy for what happens when a counterparty VASP cannot accept or supply the required data.

Which MLRO structure fits your entity profile?

The right MLRO structure depends on the entity profile, the jurisdictions of licensing and operation, and the scale of the compliance function required.

Profile A – Single-entity startup seeking first licence: A new VASP applying for its first licence in a single jurisdiction – for example, a MiCA CASP authorisation under an EU NCA – requires a designated MLRO who satisfies the personal approval criteria of that regulator. The MLRO may be an executive director or a standalone compliance hire. The indicative timeline to build a compliant programme from scratch, before the application, is a matter of months rather than weeks. The key risk is underdocumentation: the application file must evidence the MLRO's qualifications and the programme's scope.

Profile B – Multi-entity, multi-jurisdiction group: A group with licensed entities in two or more jurisdictions requires a clear group compliance governance model that documents how local MLRO obligations interact with group-level oversight. The indicative timeline to restructure a non-compliant group MLRO arrangement depends on the number of entities and supervisors involved. The key risk is the assumption that one approved officer's responsibilities can be stretched across regulated entities in jurisdictions where the supervisor requires a local nomination.

Profile C – Established operator under supervisory review: A firm that has received a supervisory letter, a regulatory visit, or a licence condition relating to its AML programme needs an experienced MLRO function review as a priority. The indicative timeline for a gap analysis and remediation roadmap is typically several weeks for a focused engagement. The key risk is delay: supervisors set remediation deadlines and they do not extend them automatically.

Profile D – Offshore entity expanding into a regulated hub: A business currently operating under a lighter-touch offshore registration that is seeking a flagship licence in a hub such as Dubai, Singapore or an EU member state must build a full MLRO function as part of the application process. Regulators in these jurisdictions will not approve an application from an entity that cannot demonstrate an operational compliance programme, not merely a documented one.

How a compliance gap was identified and addressed before regulatory escalation

In a recent cross-border compliance engagement, a custodian operating under registrations in two EU-adjacent jurisdictions approached our team after its banking counterparty raised questions about the adequacy of its AML controls. The firm had a documented AML policy and a named MLRO, but the MLRO had not filed a suspicious activity report in over a year and had not conducted a formal review of the firm's transaction monitoring alert thresholds. We conducted a gap analysis against the applicable FATF-aligned standards, identified four material weaknesses in the monitoring and reporting function, and produced a remediation roadmap with prioritised actions. The firm completed the remediation work before its next supervisory interaction; the banking relationship was preserved. The engagement was completed in a matter of weeks in the latter part of a recent calendar year.

A self-assessment: is your MLRO function audit-ready?

Before a regulator asks these questions, your MLRO function should have clear, documented answers to each of them.

  • Is the MLRO a named, approved natural person who is operationally active in the compliance function – not merely nominated on paper?
  • Does the MLRO have documented direct access to the board or senior management and a defined reporting line independent of the business?
  • Has the firm's AML risk assessment been reviewed and updated within the period specified in the firm's own policy?
  • Is the KYC framework calibrated to the current customer base, product set and jurisdictional scope – not to the original launch configuration?
  • Does the transaction monitoring system generate alerts against documented, rationale-supported thresholds?
  • Is the Travel Rule solution operational – not merely installed – and is there a documented policy for unhosted wallet transfers and non-responsive counterparty VASPs?
  • Can the MLRO produce SAR filing records, board reporting records and staff training completion logs on request?
  • For a multi-entity group: is there a written group compliance governance document that addresses each licensed entity's local MLRO obligation?

If the answer to any of these is "no" or "unclear," that is a gap that a regulator will find. In our practice, firms that address these gaps proactively almost always avoid the more serious regulatory consequences that arise when the gap is found by the supervisor first.

If a prior application stalled or a supervisory review raised questions about your AML programme, a structured second read can surface the underlying issue and the route to resolution. Contact OBOLUS at info@oboluslaw.com. To pressure-test your compliance structure before a regulator does, message us via t.me/oboluslaw. Map your options

A common assumption: one offshore licence is enough for global operations

A common assumption among early-stage operators is that a single offshore VASP registration – in the BVI, Cayman Islands or a comparable jurisdiction – is sufficient to serve clients across multiple markets while keeping the compliance burden light. This assumption is incorrect and, in an environment of converging AML standards, increasingly dangerous.

The BVI FSC under the VASP Act 2022 and CIMA under the Cayman VASP regime impose their own AML obligations. But more significantly, the jurisdictions where the firm's clients are located – and where its banking relationships sit – apply their own regulatory expectations to the firm's conduct. A crypto exchange incorporated in the BVI but serving EU-resident clients and holding correspondent banking in a MiCA-compliant jurisdiction will be scrutinised against EU AML standards regardless of its place of incorporation.

The cross-border reality is that the regulatory perimeter follows the activity, not just the entity. The MLRO function must be designed for the jurisdictions of operation, not merely the jurisdiction of incorporation. Firms that build a compliance programme calibrated only to their offshore registration routinely discover, at the moment of seeking a flagship licence or a banking relationship in a major hub, that their programme does not meet the applicable standard. By that point, the remediation cost is materially higher than if the programme had been built correctly at the outset.

We map the compliance architecture across the operating, custody and payment layers before an operator commits to a structure. That approach consistently surfaces conflicts and gaps that a narrower, single-jurisdiction review misses.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect, verify and transmit originator and beneficiary information with each virtual asset transfer that meets or exceeds the applicable threshold. The sending VASP must pass the data to the receiving VASP before or simultaneously with the transfer. Threshold levels vary by jurisdiction; no universal de-minimis figure applies across all regimes. The MLRO is responsible for ensuring the firm's Travel Rule solution is operational and that there is a documented policy for transfers where a counterparty cannot receive or supply the required data.

Who must act as MLRO for a crypto firm?

The MLRO must be a named natural person who holds genuine authority within the compliance function and is operationally active – not merely nominated on paper. Most flagship regimes require the regulator's prior approval of the MLRO appointment. The individual must have relevant knowledge of AML/CFT obligations, access to the firm's transaction data and the ability to file suspicious activity reports independently. A nominee who is not operationally involved in the compliance function will not satisfy supervisory scrutiny in any of the leading digital-asset licensing jurisdictions.

How do regulators audit crypto AML programs?

Supervisors typically audit a crypto firm's AML programme by requesting the written risk assessment, AML policy documentation, SAR filing records, transaction monitoring alert logs and staff training completion records. They will ask the MLRO to explain how alert thresholds were set and how the Travel Rule solution operates in practice. On-site visits may include interviews with compliance staff and a review of sample customer files. Regulators increasingly focus on whether the documented programme reflects operational reality – a gap between the two is itself treated as a compliance failure.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence and compliance stack across operating, custody and payment layers before clients commit to a structure. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your MLRO and AML compliance requirements, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT programme design, MLRO function review and cross-border VASP compliance across EU and international regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours