When a regulator places a virtual-asset business under heightened scrutiny, the compliance function stops being administrative and becomes the firm's primary legal exposure. The Money Laundering Reporting Officer (MLRO) – the individual accountable for the AML/CFT program – and the broader compliance officer structure are stress-tested in ways that routine supervision never triggers. Gaps that survive a standard examination rarely survive an enhanced review. This page sets out the regulated basis for the MLRO and compliance officer function, the expectations regulators now apply under heightened scrutiny, and the structural steps that keep a digital-asset business defensible.
Operating without the right compliance architecture risks enforcement, frozen banking rails and – in the worst outcomes – personal liability for the officer who signed the program. Across the major virtual-asset hubs, from VARA in Dubai to the FCA in the United Kingdom to MAS in Singapore, the direction of travel is identical: regulators are raising the bar on AML governance, and the MLRO sits at the center of that expectation.
What Does Heightened Scrutiny Mean for a Digital-Asset Compliance Function?
Heightened scrutiny is a formal or informal supervisory posture in which a regulator subjects a licensed or registered entity to closer, more frequent and more granular oversight of its AML/CFT controls. It is triggered by a range of events: a suspicious-activity report pattern, a whistleblower referral, an adverse FATF mutual evaluation of the home jurisdiction, an enforcement action against a peer firm, or an applicant's prior compliance failures surfacing during the licensing process. Under FATF Recommendation 15 – the international standard governing virtual assets – competent authorities are expected to apply risk-proportionate supervision, and heightened scrutiny is the operational expression of that duty at the firm level.
The practical effect is immediate. Examination cycles shorten. Regulators request transaction monitoring logs, risk-appetite statements, KYC documentation and Travel Rule records on compressed timelines. The MLRO is often called to attend a supervisory interview in person. A program that looked adequate on paper is now evaluated against actual transaction data, not just policy documents.
In our practice, we see compliance teams discover – only after the enhanced review is triggered – that their policies were never operationalized. The written AML manual described a three-tier customer risk rating; the onboarding system only ran two. That gap, minor in a routine audit, becomes the opening line of an enforcement notice under heightened scrutiny.
The MLRO Function: Regulatory Basis and Personal Accountability
The MLRO is the named individual responsible for receiving internal suspicious-activity disclosures, evaluating them against applicable thresholds, and deciding whether to file a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) with the relevant financial intelligence unit. Every major virtual-asset regime mandates the role, though its precise designation varies.
Under the FCA's Money Laundering Regulations, the MLRO must be a senior manager with sufficient authority and resources to carry out the function independently. Under VARA's compliance rulebook, the compliance officer holding the AML mandate must be approved by the authority and must not have material conflicts with the business lines they oversee. MAS under the Payment Services Act expects the designated compliance officer to have direct reporting lines to the board, not only to executive management. The AIFC/AFSA framework in Kazakhstan similarly requires an identified individual with documented accountability.
Personal accountability is not theoretical. Where an AML program fails and an enforcement action follows, regulators in most flagship jurisdictions may impose sanctions on the officer directly – license revocation, financial penalties, or a prohibition from holding approved-person status. Under heightened scrutiny, the regulator will examine whether the MLRO had the independence, seniority, technical competence and resource base to execute the function. A de-facto MLRO who held the title but lacked authority is a finding, not a defense.
For a scoped review of your MLRO structure and whether it meets current supervisory expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, operating jurisdictions and customer base all change the analysis.
How Does a KYC Framework Hold Up Under Enhanced Review?
A KYC framework (Know Your Customer: the policies, procedures and controls a firm uses to identify, verify and risk-rate its customers) is the foundation on which every other AML control rests. Under heightened scrutiny, regulators do not read the KYC policy – they sample the underlying customer files. The question shifts from "does your policy require enhanced due diligence for high-risk customers?" to "show us the EDD records for these twelve accounts."
Across the digital-asset sector, we regularly advise firms that run defensible KYC policies against inadequate implementation. The most frequent failure modes are three: inconsistent application of the customer risk-rating matrix (automated screening flags a PEP but the onboarding team overrides the flag without documenting a reason); static risk scores that are never refreshed after onboarding; and shallow beneficial-ownership verification for corporate accounts that stops at the first-tier nominee.
FATF guidance on virtual assets specifically flags the risk posed by nested accounts – exchanges using other exchanges as customers – and by peer-to-peer transfer volumes that bypass institutional onboarding. Regulators under heightened scrutiny will trace a sample of high-value transactions back to the originating KYC file. If the file is missing, incomplete or internally inconsistent, that is a material finding.
Building a KYC framework that survives enhanced examination requires more than documentation. It requires a technology architecture in which the risk score is the output of the onboarding system, not a field an analyst fills in. It requires an escalation path that is actually used. And it requires periodic testing – a live walkthrough of the policy against real files – rather than an annual policy review that no one tests against actual data.
Travel Rule Obligations: The Gap That Triggers the Most Findings
The Travel Rule – the obligation, drawn from FATF Recommendation 16 and implemented at the national level by most major virtual-asset regimes, to pass originator and beneficiary information alongside a virtual-asset transfer – is the single most examined AML control in a heightened-scrutiny review of a VASP (virtual asset service provider).
Under MiCA and the EU Transfer of Funds Regulation as extended to crypto-assets, every transfer above the applicable threshold must carry the full identifying data of the originator and beneficiary. VARA and MAS have each issued guidance requiring VASPs to implement compliant Travel Rule solutions before operating. The FCA's expectation under the UK Money Laundering Regulations is substantially aligned, though the de-minimis threshold and the treatment of unhosted wallets vary from the EU position.
The implementation gap is well-documented in practice. A VASP may have a Travel Rule solution in place and still fail examination because: the solution does not interoperate with the counterparty VASP's protocol; the firm has no documented procedure for what to do when counterparty data is unavailable; or the firm's Travel Rule records are held in a system that is not accessible to compliance at transaction speed.
In a recent heightened-scrutiny examination, a payments firm we advised had a Travel Rule solution that covered outbound transfers but had no systematic process for validating inbound counterparty data. The examiner found that Travel Rule records for a material percentage of inbound transactions were empty. That finding – not a substantive money-laundering event, but a process gap – required a remediation plan with board-level sign-off and a follow-up examination within a defined period. The reputational and operational cost exceeded what a front-end compliance build would have cost by a significant margin.
Transaction Monitoring: What Examiners Actually Look For
Transaction monitoring – the continuous, automated review of customer activity against behavioral baselines to detect suspicious patterns – is evaluated differently under heightened scrutiny than in a routine review. The question is not whether the firm has a transaction monitoring system. It is whether that system is calibrated to the firm's actual risk profile, whether the alert thresholds are defensible, and whether the disposition of alerts is documented and consistent.
Regulators in the major digital-asset hubs increasingly expect firms to demonstrate that their monitoring rules were tuned to the firm's specific product set and customer base – not imported unchanged from a generic rulebook. A rule designed to flag structuring in a fiat payments context may be entirely blind to structuring patterns in on-chain activity: rapid cycling across multiple addresses, use of privacy-enhancing protocols, layering through DeFi liquidity pools. An examiner who understands on-chain mechanics – and VARA, MAS and the FCA all now have dedicated crypto-specialist supervision staff – will test for on-chain-specific alert logic.
Alert disposition is equally scrutinized. The examiner will ask for the SAR filing log and the closed-alert log for the review period. Where alerts were closed without a SAR, there must be a documented rationale that a trained analyst would recognize as adequate. Regulators have taken enforcement action against firms where the alert log showed a high rate of rapid, undocumented closures – a pattern that suggests the system was generating alerts that compliance treated as noise rather than potential cases.
If a prior examination identified transaction monitoring gaps, a structured remediation program is the route to close the supervisory file. Write to us at info@oboluslaw.com to scope the remediation work. If your application stalled or an account was closed, a second read of the structural issues can surface the route back.
The Cross-Border Reality: One Entity, Multiple Regulatory Expectations
Most digital-asset businesses operate across more than one jurisdiction, and the compliance officer's difficulty is that heightened scrutiny from one regulator often arrives simultaneously with an ordinary supervision cycle from a second. The MLRO who is managing an enhanced examination in one jurisdiction must maintain the standard program in another – often with the same team.
The cross-border dimension compounds the Travel Rule problem. A VASP licensed in the EU under MiCA serving users in Singapore, with banking in Lithuania, faces three distinct regulatory bodies, each with its own Travel Rule implementation timeline, de-minimis threshold and treatment of unhosted wallets. The program must satisfy the most demanding requirement in each category, not an average.
We have seen firms that structured their compliance function on a single-licence model – a legal opinion that one jurisdiction's license was sufficient for global operations – discover that their banking counterparties, correspondent banks and payments processors apply their own AML due-diligence criteria. A bank may freeze an account not because a regulator ordered it but because the bank's own AML team assessed the VASP as high risk and could not satisfy its own customer-due-diligence obligations. The myth that a single offshore license suffices for global operation collapses at the banking relationship, not at the regulatory inquiry.
A defensible cross-border compliance architecture maps each regulatory obligation to the entity that carries it, documents the interplay between jurisdictions and maintains a matrix of applicable thresholds. We map the licence, compliance and banking stack across operating, custody and payment layers before a client commits to a structure – because the cost of rebuilding it under supervisory pressure is categorically higher than building it correctly at the outset.
Decision Matrix: Which Compliance Posture Fits Which Operator Profile?
Not every digital-asset firm faces the same compliance risk profile, and the MLRO and compliance officer function should be sized and structured accordingly.
Profile A – Early-stage exchange or broker, single jurisdiction, limited product set. The compliance function at this stage is typically an in-house MLRO supported by an outsourced compliance program. The immediate priority is a defensible KYC framework, a functioning Travel Rule solution and an alert-disposition log that an examiner could follow. The risk of heightened scrutiny at this stage comes from licensing – regulators examine the program before authorization is granted, and a thin application is increasingly met with requests for live testing of the monitoring system before approval. The timeline to build a defensible program from scratch is measured in weeks for a focused team, not months.
Profile B – Licensed VASP expanding to a second or third jurisdiction, multiple product lines. This firm already has a working AML program but must now reconcile divergent requirements. The MLRO role may need to be supported by a network of local compliance officers, each accountable to the primary MLRO and to the relevant local regulator. The Travel Rule solution must interoperate across jurisdictions. The transaction monitoring system must be tuned for each product's specific risk profile. External counsel serves here as a senior reviewer of the program architecture and the gap between local requirements and the existing baseline.
Profile C – Firm under active heightened scrutiny or remediation order. The compliance function has been found wanting. The immediate priority is a documented remediation plan with board-level endorsement, a named remediation owner and a timeline that the regulator has approved. External counsel in this context works alongside internal compliance to draft the plan, represent the firm in supervisory dialogue and ensure that each remediation step is documented in a way that closes the finding. The risk is not simply the current finding but the pattern it creates for future supervision cycles.
The Most Common Structural Mistakes – and How Regulators Find Them
In our practice, the same structural failures recur across digital-asset businesses of different sizes and across different regulatory environments. Identifying them before an examiner does is the practical purpose of a compliance gap assessment.
The first is the policy-implementation gap described earlier: written procedures that are more rigorous than the system can actually execute. The second is an MLRO who lacks real independence – who reports to the CEO rather than the board, or who has a commercial incentive not to apply the risk framework in a way that declines customers. Regulators in the EU under MiCA and under VARA's rulebook both require documented evidence of the MLRO's independence, including the right to raise concerns directly to the board without executive interference.
The third structural failure is inadequate resourcing. An AML program that was adequate for a firm processing a certain transaction volume becomes inadequate when volumes grow. The monitoring system generates more alerts; the SAR assessment queue lengthens; the MLRO cannot review all escalations in the required timeframe. Under heightened scrutiny, the examiner will ask about MLRO capacity in relation to transaction volume. A ratio that would trouble a bank examiner troubles a VASP examiner equally.
The fourth failure is poor record-keeping. The Travel Rule records are incomplete. The alert-disposition log has gaps. The KYC files for a sampled cohort of high-risk customers are missing the EDD documentation that the policy requires. Record-keeping failures are among the easiest findings for an examiner to document and among the most difficult for a firm to rebut, because the absence of a record is itself the finding.
Related at OBOLUS
Related at OBOLUS
- Compliance, AML and Travel Rule for Digital-Asset Businesses – full-service AML/CFT counsel across licensing, program design and regulatory dialogue
- The Compliance Burden in Practice: MLRO and Compliance Officer Function – a practitioner analysis of the daily operational weight of the MLRO role
- Exchange Listing Legal Counsel for Regulated Entities – legal support for exchanges navigating securities and listing requirements across jurisdictions
FAQ
What does the Travel Rule require from a VASP?
Under FATF Recommendation 16, implemented across the major digital-asset regimes including MiCA, the VARA rulebook and the MAS Payment Services Act framework, a VASP must pass originator and beneficiary identifying information alongside a virtual-asset transfer above the applicable threshold. This applies to both outbound and inbound transfers. Where the counterparty VASP cannot provide compliant data, the receiving VASP must have a documented procedure for handling the gap – typically a risk-based hold, enhanced due diligence or, in some regimes, refusal of the transaction. The specific de-minimis threshold varies by jurisdiction and should be verified against current legislation.
Who must act as MLRO for a crypto firm?
The MLRO must be a named senior individual with sufficient authority, independence and competence to run the AML/CFT disclosure function. Most major regimes – including the FCA, VARA and MAS frameworks – require the MLRO to be approved or notified to the regulator and to have a direct reporting line to the board. The role cannot be held by someone with a material commercial conflict of interest in the firm's customer-acceptance decisions. For cross-border operators, each licensed entity typically requires its own locally accountable MLRO, even where a group-level compliance officer exists.
How do regulators audit crypto AML programs?
Regulators examine the AML program against both documented policies and actual transaction data. In a heightened-scrutiny review, examiners typically request a sample of KYC files for high-risk customers, the transaction monitoring alert log and SAR filing record for the review period, Travel Rule records for a sample of transfers, and evidence of the MLRO's independence and board-level reporting. On-chain forensics are increasingly used to verify that reported transaction volumes match monitoring records. Gaps between the written policy and the operational record are the most common findings and the most difficult to remediate after the fact.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule obligations that sit across all of them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when it matters most. To discuss your compliance architecture or a live supervisory matter, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program architecture, MLRO accountability frameworks and cross-border VASP compliance under heightened supervisory review.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.