Operating a digital-asset business across borders means every jurisdiction your users touch can impose its own AML compliance (anti-money laundering compliance) obligations on the entity you operate. When regulators assess whether those obligations are met, the first question is almost always the same: who is responsible, and can they demonstrate personal competence and control? The Money Laundering Reporting Officer (MLRO) and the broader compliance officer function are the human architecture regulators inspect first. A gap there does not stay theoretical for long.
For a digital-asset business sitting across multiple licensing regimes, the MLRO function is not a box to tick on one application form. It is a live, cross-border accountability structure that must satisfy every regulator that supervises any part of your operations simultaneously. This page explains what that means in practice, where businesses most often go wrong, and what a well-constructed cross-border compliance function actually looks like.
What the MLRO Function Actually Does in a Regulated Crypto Business
The MLRO and compliance officer function serves as the central accountability point for a firm's entire KYC framework (know-your-customer framework), transaction monitoring infrastructure and suspicious activity reporting obligations. In every flagship licensing regime – whether VARA in Dubai, MAS in Singapore, the FCA in the United Kingdom, or ESMA-supervised authorities under MiCA – the regulations require a named, senior, fit-and-proper individual to own these obligations. The role is not ceremonial.
In practice, the MLRO receives internal suspicious activity reports, decides whether to file an external report with the relevant financial intelligence unit, and is personally accountable to the regulator for the quality of the firm's AML program. In many regimes, that personal accountability carries civil or criminal exposure. The compliance officer function, which often overlaps or sits alongside the MLRO role, is responsible for the governance layer: policies, controls, staff training, audit cycles and board-level reporting.
Under MiCA, CASPs (crypto-asset service providers) are required to maintain an independent compliance function with adequate seniority and resources. The FCA's Money Laundering Regulations impose equivalent expectations. VARA's rulebooks in Dubai and the Payment Services Act regime administered by MAS in Singapore both require demonstrably qualified individuals to hold these roles before a licence will issue.
In our practice, the most consistent observation is this: regulators do not merely check that a name is filled in. They assess whether the person named has real decision-making authority, sufficient seniority to escalate to the board, and the budget and tooling to do their job. A compliance officer who is also the chief executive, or who has no documented reporting line, is a red flag in any supervisory examination.
How Does the Cross-border Reality Reshape These Obligations?
A digital-asset business that holds a single licence but serves users or maintains banking relationships across multiple jurisdictions faces a compliance obligation that is materially more complex than the domestic picture. Each jurisdiction in the chain can impose its own regulatory expectations on the entity, and those expectations do not always align.
Consider a custodian authorised under the FSRA regime in Abu Dhabi's ADGM. If that custodian also processes transfers involving EU-resident counterparties, the Travel Rule (the obligation to pass originator and beneficiary identifying information with a virtual-asset transfer) applies in its MiCA formulation as well as in its FATF baseline formulation. The MLRO must manage a Travel Rule compliance architecture that satisfies both, not the more permissive of the two.
The FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule, form the baseline that most national regulators implement – but implementation details, de-minimis thresholds and enforcement posture vary by jurisdiction. An MLRO operating a business with users in Singapore, the EU and the UAE is, in effect, operating under three supervisory regimes simultaneously. In our cross-border practice, we advise clients to map the compliance obligation to the most stringent applicable regime and build the program to that standard, then document where local rules diverge.
Banking relationships add a further layer. Correspondent banks and payment infrastructure providers conduct their own AML due diligence on the digital-asset businesses they service. An MLRO who cannot produce a coherent, well-documented AML program on short notice will often find that the banking relationship is the first casualty of a supervisory query – before a regulator has even issued a formal finding.
For a scoped assessment of your cross-border compliance architecture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
What Do Regulators Actually Require from the Individual?
Fit-and-proper assessments for MLRO and compliance officer roles are applied rigorously across the leading digital-asset licensing regimes, and the criteria are substantively similar even where the formal tests differ. Regulators look at three dimensions: integrity, competence and time.
Integrity covers criminal record, regulatory history and any prior involvement with entities that were refused authorisation or had a licence revoked. Competence covers AML-specific qualifications, relevant professional experience and demonstrated understanding of the specific asset classes and transaction types the business handles. Time – often overlooked – means the person must genuinely have sufficient hours to perform the function. A nominee MLRO who is visibly a full-time employee of a different entity elsewhere will not pass scrutiny at VARA, MAS, the FCA or most other serious supervisors.
In our experience, regulators at the leading hubs are increasingly granular on the technology competence question. An MLRO who cannot explain how the firm's transaction monitoring system generates alerts, what the threshold logic is, or how blockchain analytics feeds into the review process will struggle in a supervisory examination. Digital-asset AML is not traditional financial-crime compliance with a crypto veneer. It requires genuine familiarity with on-chain data, wallet clustering, cross-chain bridge activity and exchange exposure.
One practical point that arises repeatedly: some jurisdictions permit the MLRO and compliance officer roles to be combined in a single individual, while others require separation. VARA's activity-based licensing regime, for example, distinguishes between compliance and MLRO functions at higher licence tiers. MAS expects clear delineation at the major payment institution level. Mapping those requirements to your specific structure before you file is not optional.
Program Design, Documentation and the Transaction Monitoring Stack
A defensible AML program in the digital-asset context requires five documented elements: a risk assessment calibrated to the firm's products and customer base; customer due diligence and KYC procedures that match the risk appetite; a transaction monitoring system with defined alert thresholds and review workflows; a suspicious activity reporting procedure that meets the local filing requirements; and a governance cycle covering training, independent audit and board reporting.
The transaction monitoring component is where most crypto-specific complexity arises. Traditional financial-crime systems are built for IBAN-to-IBAN logic. Digital-asset transaction monitoring requires integration of on-chain analytics – typically through tools that cluster addresses, assign risk scores and identify exposure to sanctioned wallets, darknet markets or mixers. The MLRO must understand this tooling well enough to explain its limitations, not just its outputs, to a regulator.
The Travel Rule adds a separate data-handling obligation on top of the monitoring function. Every qualifying transfer must carry originator and beneficiary data, and the MLRO is responsible for ensuring the firm has a technical solution in place for receiving and transmitting that data to and from counterparty VASPs. Where a counterparty VASP cannot or will not comply with Travel Rule data exchange, the MLRO must have a documented procedure for handling that scenario – including the conditions under which the transfer should not proceed.
Documentation discipline is a recurring differentiator in supervisory examinations. A firm that has a sophisticated monitoring stack but cannot produce the governance trail – the alert logs, the review decisions, the escalation records, the training attendance registers – will not fare well. Regulators do not inspect the system. They inspect the evidence that the system was being managed by a competent human being.
What Are the Most Common Mistakes in Cross-border Compliance Structures?
The most frequent and costly mistake we see is building a compliance function for the jurisdiction of incorporation and ignoring the jurisdictions of operation. A Cayman-incorporated entity with CIMA registration may have an MLRO who satisfies CIMA's requirements. But if that entity's exchange serves EU retail customers, the MiCA regime's CASP obligations apply to the activities directed at those customers – and the compliance program must address them. The MLRO cannot be unaware of this.
A second common failure is using a nominal MLRO who is not genuinely embedded in the business. Some operators appoint an external consultant to hold the MLRO title for a fee, without providing that person with access to systems, real-time transaction data or the authority to stop a relationship. This arrangement tends to collapse quickly under any supervisory scrutiny. Regulators expect the MLRO to be reachable, informed and empowered.
Third, compliance programs that were built at licence application stage and never updated become a liability over time. Regulatory guidance evolves. FATF updates its methodology. Domestic supervisors issue thematic reviews that effectively signal new expectations. In our cross-border practice, we have seen firms receive adverse examination findings not because they had no program but because their program reflected the regime as it existed two licensing cycles ago.
Finally, Travel Rule compliance is frequently treated as a technical implementation question rather than a legal and governance question. The MLRO must own the Travel Rule solution – not the technology team. The decision about which counterparty VASPs meet the data exchange standard, and what happens when one does not, is a compliance decision with regulatory consequences. Delegating it entirely to a vendor without senior oversight is a structural gap that examiners notice.
In a recent cross-border matter, a payments company that held licences in two jurisdictions approached us after an internal audit revealed that its transaction monitoring thresholds had never been calibrated to reflect the higher-risk customer segments it had onboarded in the second market. We worked through the documentation trail, recalibrated the risk assessment, restructured the escalation procedure and produced the governance record required to demonstrate remediation to both supervisors. The firm's banking relationship, which had been placed under review, was maintained.
If a prior examination raised findings or an account review is under way, OBOLUS can provide a second-read analysis. Contact us at info@oboluslaw.com. If a prior application stalled or a banking relationship came under pressure, a structured review can surface the underlying cause and the route back. Map your options.
Which Compliance Structure Fits Which Operator Profile?
Different operator profiles call for materially different compliance architectures, and the MLRO function must be matched to the actual complexity of the business.
A startup exchange seeking a single EU CASP authorisation under MiCA, with no operations outside the member state of registration and a straightforward retail customer base, can typically satisfy the compliance function requirement with a single qualified individual who serves as both MLRO and compliance officer. The program can be built around a defined customer risk matrix, a single analytics vendor integration and a straightforward reporting line to the board. The principal risk at this profile is underestimating the depth of documentation the national competent authority will expect at examination.
A mid-stage operator with a VARA licence in Dubai, a MAS-regulated Singapore entity and an ADGM-registered Abu Dhabi presence is operating three supervisory relationships simultaneously. Here, the MLRO function typically requires either a centrally located, sufficiently senior individual with clear authority across all three entities or a model in which each entity has a locally qualified MLRO and a group compliance officer provides the consolidating governance layer. The group-level function must document how conflicts between local requirements are resolved – and that document must be available to each supervisor on request.
A custody-and-transfer business that also provides lending services faces the most complex AML profile. Lending creates counterparty relationships that may not go through the standard onboarding flow, and cross-chain collateral arrangements can obscure beneficial ownership. The MLRO at this profile needs specialist expertise in structured-product AML, not just exchange-flow monitoring. The governance cycle must explicitly address the lending book as a distinct risk segment.
For all profiles, the common denominator is this: the MLRO must have a documented mandate, real access and genuine authority. The structure around that individual – whether one person or a group function – must be designed to survive a supervisory examination, not merely to satisfy an application checklist.
A Common Assumption: One Licence Covers Global Operations
A common assumption among early-stage digital-asset operators is that a single offshore licence – secured in a permissive jurisdiction and held by a well-structured entity – is sufficient to serve clients globally. It is not, and the MLRO function is where that gap becomes visible most quickly.
When a regulator in a jurisdiction where your customers are located determines that you are conducting regulated activities directed at persons in their territory, it does not typically contact your offshore regulator first. It contacts you. Its first request will often be for evidence of your AML program and the identity of your compliance officer. An MLRO whose mandate covers only the offshore entity cannot credibly respond to that enquiry.
This is not a hypothetical concern. MiCA applies to CASPs that target EU customers regardless of where the CASP is incorporated. The FCA's financial promotion rules in the United Kingdom operate on a similar logic. MAS has consistently signalled that operating without a licence in Singapore while directing services at Singapore residents is an enforcement priority. The VARA regime in Dubai applies to virtual asset activities conducted from or within the emirate, not merely to locally incorporated entities.
Operators we advise routinely discover, on a proper analysis of their user acquisition data and marketing footprint, that they have a material presence in two or three additional jurisdictions that they had not previously recognised as regulatory exposure. The MLRO is often the person who should have flagged this. Building the compliance function to see the full picture – not just the licensed perimeter – is the structural response to this risk.
Related at OBOLUS
- AML, KYC and Travel Rule compliance for digital-asset businesses – full practice overview covering the compliance regime from registration to examination.
- Governance expectations for boards of licensed VASPs – what board-level oversight of the MLRO function looks like under current supervisory standards.
- Crypto exchange licensing: the disputes angle – how licensing gaps and compliance failures feed into enforcement and commercial disputes.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, grounded in FATF Recommendation 15, requires a VASP (virtual asset service provider) to collect and transmit originator and beneficiary identifying information alongside virtual-asset transfers that meet or exceed the applicable threshold in each jurisdiction. The VASP must also have a procedure for handling transfers from counterparty VASPs that cannot or do not comply. The precise data fields, threshold amounts and technical transmission standards vary by jurisdiction and should be assessed against each applicable regime.
Who must act as MLRO for a crypto firm?
The MLRO must be a named, senior individual who is approved or deemed fit and proper by the relevant regulator. In most leading regimes – VARA, MAS, FCA and under MiCA – the person must have relevant AML qualifications or professional experience, genuine authority within the business and sufficient time to perform the function. A nominee with no real access to systems or decision-making authority will not satisfy supervisory scrutiny. Some jurisdictions allow the MLRO and compliance officer roles to be combined; others require separation at higher licence tiers.
How do regulators audit crypto AML programs?
Supervisory examinations of crypto AML programs typically focus on four areas: the adequacy and currency of the firm's risk assessment; the design and calibration of the transaction monitoring system; the quality of suspicious activity reporting decisions and their documentation; and the governance cycle, including board reporting, staff training records and independent audit findings. Examiners increasingly assess whether the compliance officer or MLRO can explain on-chain analytics and how blockchain forensic tools integrate into the firm's alert-review workflow.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, KYC and Travel Rule compliance programs that regulators and banking partners inspect most closely. We structure compliance, licensing and tax as one mandate rather than three disconnected workstreams, and we map the licence stack across operating, custody and payment layers before you commit. Digital assets are the whole of our practice. To discuss your compliance architecture or a pending examination, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border AML program design, MLRO function structuring and supervisory examination readiness for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.