What a Regulatory AML Audit Means for a Digital-Asset Institution
A regulatory AML audit is a formal examination by a supervisory authority of an institution's anti-money-laundering controls, transaction-monitoring systems, KYC (know-your-customer) procedures and governance. For digital-asset businesses, these examinations now arrive with greater technical sophistication than they did even two years ago. Regulators across the major hubs – VARA in Dubai, the FCA in the United Kingdom, MAS in Singapore and ESMA's network of national competent authorities under MiCA – have each published enhanced supervisory expectations for VASPs (virtual asset service providers). The gap between a firm that manages an examination and one that receives a remediation order often comes down to preparation, not policy quality alone.
Operating without defensible AML documentation exposes the business to enforcement action, frozen banking rails and licence suspension. The loss is rarely limited to the fine itself; the reputational and operational cost of a public remediation order can be existential for an institutional digital-asset business.
This page sets out how OBOLUS supports institutional clients through the full arc of a regulatory AML examination – from early-stage preparation through to post-audit remediation – and explains the cross-border complications that arise when a firm is licensed in one jurisdiction but books business across several.
The Regulatory Basis for AML Examinations in Digital-Asset Markets
Every major VASP regime derives its AML examination authority from the same international baseline: FATF Recommendation 15, which requires jurisdictions to apply AML and counter-terrorist-financing obligations to virtual asset service providers. What differs is how each regime translates that standard into supervisory practice.
Under MiCA and the parallel AML framework being developed at the EU level, licensed CASPs face examination by their national competent authority, with ESMA providing convergence guidelines. The examination scope covers onboarding, transaction monitoring, the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), suspicious activity reporting and governance. In the UAE, VARA conducts both scheduled and ad hoc examinations across all activity categories it licenses, and its rulebooks specify documentary expectations with a granularity that rewards preparation. The FCA's AML supervisory model in the United Kingdom focuses heavily on systems-and-controls quality, with particular attention to whether a firm's transaction-monitoring thresholds are calibrated to the actual risk of its client base.
In our practice, we see a consistent pattern: firms that structured their AML programme to satisfy the application process but never stress-tested it against an actual examination. The application-ready programme and the examination-ready programme are materially different documents.
For a scoped assessment of your current AML programme against examination benchmarks, contact OBOLUS at info@oboluslaw.com. The process above describes the standard supervisory path. Your facts – the entity, the user base, the jurisdictions where clients are onboarded – change the analysis materially. Map your options.
What Regulators Actually Examine: The Five Core Pillars
A well-prepared institutional client knows, before the regulator arrives, exactly what the examination will cover. In our cross-border practice, regulatory AML examinations of digital-asset businesses cluster around five areas.
Governance and MLRO function. Regulators examine whether the MLRO (money laundering reporting officer) is genuinely senior, resourced and independent. They will ask for evidence of MLRO reports to the board, for evidence that the MLRO can and does escalate without interference, and for the MLRO's own professional competence documentation. A nominal MLRO appointment – a title attached to a compliance analyst with no direct board access – is one of the most common findings we see in post-audit remediation instructions.
Risk assessment quality. The firm's business-wide risk assessment is the foundation of the examination. Regulators test whether it maps actual products, geographies, client types and delivery channels against money-laundering and terrorist-financing risk. A generic template that has not been updated since the firm added new product lines will not survive scrutiny.
Customer due diligence and KYC framework. Examiners review onboarding files, enhanced due diligence documentation for high-risk clients and the firm's criteria for triggering EDD. For institutional clients – funds, OTC desks, corporate treasury customers – the KYC depth expected is substantially higher than for retail accounts.
Transaction monitoring. Regulators increasingly request evidence that the firm's monitoring rules are calibrated to its own risk assessment, not simply set to vendor defaults. They will ask how rules are tuned, who tunes them and how often. Alert disposition rationale – why a particular alert was closed without a report – is an area of particular focus.
Travel Rule compliance. Under the applicable VASP provisions in every leading regime, the firm must transmit originator and beneficiary data on qualifying transfers. Regulators examine whether the firm has a compliant technical solution, whether it handles unhosted wallet transfers in a manner consistent with its jurisdiction's interpretation of the regime, and whether records are complete.
How Should an Institution Prepare for a Regulatory AML Audit?
Preparation begins well before the examination notice arrives, and the firms that fare best are those that have run their own internal examination cycle first. The process has a defined structure.
The first step is a gap analysis against the specific supervisory standards of each jurisdiction in which the firm holds a licence or, under the applicable provisions of the relevant regime, is deemed to be conducting regulated activities. A firm licensed under VARA but passporting services to EU clients via a local partner must understand both VARA's examination expectations and those of the relevant national competent authority under MiCA. These are not identical.
The second step is documentation review and remediation. Policy documents, the business-wide risk assessment, the MLRO's annual report, onboarding procedures, monitoring rule logs and staff training records should each be reviewed against current supervisory guidance. Outdated documents are a red flag in any examination.
The third step is a mock examination interview. Regulators interview the MLRO, the compliance officer and, in some jurisdictions, senior management directly. Preparation for those interviews – understanding the question framework, identifying weak areas in advance, and knowing how to answer accurately without over-volunteering – is a discrete skill. We regularly advise clients on this preparation.
The fourth step is building the examination file itself: an organised, indexed set of documents that allows the regulator to move efficiently through the firm's programme. A well-organised examination file signals competence before a single question is asked. Its absence signals the opposite.
Cross-Border Complications in Multi-Jurisdiction AML Audit Defence
The cross-border dimension is where AML audit defence becomes genuinely complex for institutional digital-asset businesses. A firm may hold a primary CASP authorisation in an EU member state, operate its exchange technology from a VARA-regulated entity in Dubai, custody assets through a BVI-registered vehicle and bank in Singapore. Each layer carries its own supervisory relationship, and an examination by one regulator can create disclosure obligations toward another.
Under the applicable provisions of the MiCA regime, a CASP that identifies a material control failure in one member state must assess whether that failure affects its passported activities in other member states. Failure to make that assessment – and to document it – is itself a finding. VARA's rulebooks similarly expect that a licensee with related entities in other jurisdictions maintains consolidated AML governance, not silo'd compliance by entity.
The Travel Rule adds a layer of cross-border complexity that catches many institutional operators unprepared. Where the sending and receiving VASPs are in different jurisdictions, the applicable data-transmission standard may differ. The firm's technical solution must accommodate those differences without creating gaps in the originator/beneficiary data chain. In our practice, we have seen examinations where the transaction monitoring was technically adequate but the Travel Rule implementation created blind spots that a regulator identified immediately.
One micro-matter illustrates the point. In a recent examination-preparation engagement, an exchange operator licensed in two EU jurisdictions discovered that its onboarding documentation for corporate clients met the standard of the primary jurisdiction but fell short of the enhanced due diligence expectations of the secondary authority. We worked through the gap analysis, produced a remediation plan and helped the firm present the work-in-progress to the regulator before the examination concluded. The firm received a recommendation rather than a formal finding – a materially different outcome.
If a prior examination produced findings that remain unresolved, or if a new supervisory cycle is approaching, contact OBOLUS at info@oboluslaw.com. A second read can surface the structural reason behind a finding and the route to remediation. Map your options.
Common Mistakes in Regulatory AML Audit Defence
In every AML audit defence engagement, we encounter a recurring set of errors. Identifying them in advance is one of the highest-value things a firm can do.
Treating the audit notice as the start of preparation. A regulatory examination notice typically gives the firm a limited window to organise documents and prepare personnel. That window is far too short to fix structural problems. Firms that prepare continuously – running quarterly internal reviews, maintaining live documentation and tracking regulatory guidance as it evolves – manage examinations materially more effectively.
MLRO under-resourcing. The MLRO cannot be a part-time function in an institutional digital-asset business. Regulators under every leading regime assess whether the MLRO has sufficient time, authority and budget to discharge the role. An MLRO who also serves as head of operations, or who reports to a business-line head rather than directly to the board, will generate examination findings regardless of the quality of the firm's other controls.
Monitoring rules that do not reflect the firm's actual risk profile. Vendor-default monitoring rules calibrated for a generic payment institution are not appropriate for a digital-asset exchange serving institutional clients executing large OTC trades. The rule set must be justified by reference to the firm's own risk assessment. Where that justification is absent, the examination will expose it.
Assuming that a single offshore licence covers global operations. A common misconception is that a VASP licence in one jurisdiction provides legal cover for serving clients anywhere in the world. Every leading regime – MiCA, VARA, the MAS Payment Services Act, the SFC's VASP regime in Hong Kong – applies on the basis of where clients are located and where the activity is conducted, not simply where the licence is held. An institutional operator serving EU clients from a non-EU licensed entity must take specific legal advice before assuming that arrangement is compliant.
Decision Matrix: Which Examination Profile Requires Which Response
Different examination profiles warrant different preparation and response strategies. The matrix below, set out in prose, is designed to help general counsel and compliance officers calibrate the firm's approach.
Profile A – Scheduled periodic examination, programme broadly current. The regulator has given advance notice as part of its routine supervision cycle. The firm's AML programme has been maintained and documentation is substantially complete. The appropriate response is a structured documentation review, a focused mock-interview programme for the MLRO and senior compliance personnel, and assembly of an indexed examination file. The primary risk is documentation gaps; the key objective is demonstrating programme maturity.
Profile B – Ad hoc examination triggered by a suspicious activity report or a third-party referral. The regulator's examination is not routine; it has been triggered by a specific event. The risk profile is substantially higher. Legal counsel should be involved from the moment the notice arrives. The response strategy must distinguish between what the firm is required to disclose, what it may disclose and what is protected by privilege. Preparation here is not simply logistical; it is strategic.
Profile C – Post-acquisition or post-licensing integration, first examination by a new regulator. The firm has recently obtained a new licence or acquired a regulated entity and faces its first examination in that jurisdiction. The risk is that the regulator's expectations differ from those of the firm's primary regulator and that the firm is unaware of those differences. The appropriate response begins with a jurisdiction-specific gap analysis before any regulatory contact, followed by early voluntary engagement with the regulator to demonstrate programme awareness.
Profile D – Examination with preliminary findings already issued. The regulator has issued preliminary findings and is awaiting the firm's response. At this stage, the legal quality of the written response is determinative. A response that acknowledges findings, demonstrates root-cause analysis and presents a credible remediation plan with timelines can transform a formal enforcement action into a supervisory recommendation. A defensive or incomplete response has the opposite effect.
A Common Assumption About AML Audit Readiness – and Why It Is Wrong
A common assumption among institutional digital-asset operators is that a well-drafted AML policy manual is, by itself, sufficient for a regulatory examination. It is not. Regulators test whether the policy is implemented, not whether it is well-written. An examiner who finds a policy that requires quarterly risk-assessment updates but a risk assessment that has not been updated in eighteen months will record a finding regardless of the quality of the prose in the policy document. Implementation evidence – the paper trail that shows the policy is being followed – is what distinguishes a compliant programme from a documented one.
Operators we advise routinely discover this gap during internal review: the policies are sound, the controls are conceptually correct, but the evidence that the controls were operated – training completion records, monitoring-rule review logs, MLRO escalation records, EDD sign-off documentation – is incomplete or inconsistent. Building that evidence base is the work of the months before an examination, not the days after notice arrives.
Self-Assessment Checklist: Is Your Programme Examination-Ready?
Before engaging external counsel, a general counsel or compliance officer can run a rapid internal assessment against the following indicators.
- Is the business-wide risk assessment current – updated to reflect every active product, client segment and geographic market the firm serves?
- Does the MLRO have direct board access, a documented reporting line and evidence of substantive engagement with senior management in the last twelve months?
- Are monitoring rules documented by reference to the firm's risk assessment, with a change log showing when rules were last reviewed and by whom?
- Is the KYC framework differentiated between retail, professional and institutional client types, with enhanced due diligence criteria that are applied consistently?
- Is the firm's Travel Rule solution technically capable of transmitting and receiving compliant data for every counterparty jurisdiction in which it operates?
- Does the examination file – the organised set of documents the regulator will review – exist as a live document, not as a collection of folders to be assembled under pressure?
- Has the firm conducted a gap analysis against the supervisory guidance of every regulator that has jurisdiction over any of its activities, not only its primary supervisor?
A "no" answer to any of these questions indicates a preparation gap. In our practice, two or more "no" answers ahead of an examination notice signal a material remediation requirement.
Related at OBOLUS
- AML and Travel Rule Compliance for Digital-Asset Businesses – the full practice overview covering programme design, Travel Rule implementation and ongoing supervision.
- MLRO and Compliance Officer Function in the Czech Republic – jurisdiction-specific guidance on the MLRO role under the applicable Czech regime.
- Crypto Exchange Setup in the British Virgin Islands – the BVI FSC VASP Act framework for exchange licensing, custody and cross-border structuring.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 16 as applied to virtual assets, requires a VASP to transmit identifying information about the originator and beneficiary of a transfer to the receiving VASP. The specific data fields and the threshold that triggers the obligation vary by jurisdiction. In practice, a compliant VASP needs a technical solution capable of transmitting and receiving that data across counterparty institutions, including those in different regulatory regimes, and must maintain records of each transmission for the period required under the applicable supervisory framework.
Who must act as MLRO for a crypto firm?
Under every leading VASP regime – including those administered by VARA, MAS, the FCA and the national competent authorities under MiCA – the MLRO must be a named individual of sufficient seniority to report directly to the board or senior management. The person must have appropriate AML competence and adequate time and resource to discharge the role. A nominal appointment, or a shared function that does not carry genuine authority, will be identified as a finding in any supervisory examination. Regulators in the leading hubs increasingly expect the MLRO to be resident in, or substantively connected to, the jurisdiction of the licence.
How do regulators audit crypto AML programs?
Regulators typically examine documentation first – the business-wide risk assessment, AML policies, KYC procedures and transaction-monitoring rule logs – before moving to transaction testing and personnel interviews. For digital-asset businesses, examiners increasingly request on-chain data and evidence that transaction-monitoring rules are calibrated to the firm's actual product and client-risk profile. The MLRO and senior compliance personnel are interviewed directly. Post-examination, the regulator issues findings that may be informational, recommendatory or formal; the distinction turns on the severity and systemic nature of the issues identified.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance obligations that sit around every digital-asset operation. We map the compliance stack across operating, custody and payment layers before you commit to a structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme design, regulatory examination defence and VASP supervisory engagement across multi-jurisdiction digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.