Enforcement action by a financial regulator is among the most disruptive events a crypto firm can face. When a supervisor opens a formal AML audit – a structured examination of an entity's anti-money-laundering controls, transaction monitoring and customer due-diligence records – the gap between a confident response and a panicked one is almost always the gap between advance preparation and its absence. Regulated entities operating in digital-asset markets sit under intensifying scrutiny from VARA, the FCA, MAS, ESMA's network of national competent authorities and every comparable supervisor that has transposed FATF standards into domestic law. The stakes are not abstract: a supervisory finding can produce licence suspension, civil monetary penalties or a formal public censure that closes banking relationships overnight.
This page sets out how OBOLUS assists regulated entities – exchanges, custodians, token issuers and payment-service providers – through a regulator-initiated AML audit. We cover the regulatory basis for examination powers, the practical stages of a supervisory review, the cross-border complications that arise for multi-jurisdictional operators, and the structural mistakes that turn a routine inspection into an enforcement matter.
Why Regulator AML Audits Have Intensified for Digital-Asset Firms
Regulators across every flagship digital-asset hub have materially increased the frequency and depth of AML supervision since FATF updated its Recommendation 15 guidance to bring virtual asset service providers (VASPs) fully within the scope of AML/CFT obligations. Where supervisors once treated a VASP's registration as a box-ticking exercise, they now conduct cycle-based thematic reviews, desk-based information demands and on-site inspections with specialist forensic capacity. The FATF Recommendation 15 framework requires member states to regulate and supervise VASPs – and regulators are under international peer-review pressure to demonstrate that their supervision is effective.
In our practice, we see a consistent pattern. Firms that obtained registration early – often under lighter-touch transitional regimes – face the sharpest adjustment when the supervising authority moves to full-cycle examination. The FCA's registered cryptoasset firms, VARA-licensed entities in Dubai and MAS-supervised digital payment token service providers are all subject to supervisory examination powers that mirror those applied to traditional financial institutions. Gaps that were tolerated at registration are not tolerated at audit.
The cross-border reality compounds the risk. A VASP serving users in the EU while licensed in a third country may face simultaneous information demands from two supervisors. A custody firm with a Malta MFSA authorisation and operational staff in Singapore must satisfy both regulators that its AML program is genuinely effective – not merely documented.
For a scoped assessment of your AML audit exposure before a supervisor makes contact, write to OBOLUS at info@oboluslaw.com. The process above describes the standard supervisory path. Your entity structure, user geography and banking arrangements change the analysis significantly. Map your options.
What Is the Regulated Basis for a Supervisor's Examination Powers?
Every major digital-asset regulator derives its audit powers from the same structural source: the legislation that brought VASPs within the AML/CFT perimeter, typically implementing FATF standards at the national level. Under MiCA and the applicable AML directives, national competent authorities across the EU and EEA hold broad information-gathering and on-site inspection powers over authorised CASPs. VARA in Dubai exercises equivalent supervisory authority under its rulebooks. MAS operates under the Payment Services Act, which grants inspection and investigation powers to MAS examiners. The FCA may request information, attend premises and appoint a skilled-person review under the applicable MLR provisions.
What this means practically: a regulator can demand production of AML policies, transaction-monitoring alerts and disposals, customer due-diligence files, enhanced due-diligence records for high-risk counterparties, and governance documentation including board minutes and MLRO reports. The demand may arrive with a short response window – sometimes measured in working days. Counsel must be engaged before the response deadline, not after it passes.
For firms operating across multiple regimes, the applicable standard is cumulative. A firm must satisfy each supervisor's minimum requirements. Where those requirements diverge – as they often do on Travel Rule data thresholds, beneficial-ownership identification or PEP-screening depth – the operative standard is whichever jurisdiction sets the higher bar for each element, because failing one regulator's audit creates the risk of cross-notification to others.
What Are the Stages of a Supervisory AML Audit, and What Happens at Each?
A regulator-initiated AML audit typically proceeds through identifiable stages, each carrying distinct legal and strategic considerations. Understanding the stage you are at determines the correct response posture.
Stage 1 – Initial information request. The supervisor writes to request documentation. This is not optional and refusal or delay is itself a compliance failure. The response must be accurate, complete and presented in a form that demonstrates the firm's AML program is genuinely operational – not merely a set of written policies.
Stage 2 – Desktop review. The regulator's team analyses the submitted materials against its supervisory checklist. This is the stage at which documentation gaps, policy-to-practice inconsistencies and transaction-monitoring deficiencies are typically identified. In our experience, firms that have not conducted a recent internal gap analysis are routinely surprised by what the desktop review surfaces.
Stage 3 – Clarification and supplemental demands. The supervisor issues follow-up questions or requests for additional records. The framing of answers at this stage is critical. A poorly worded response can escalate a routine finding into a formal concern.
Stage 4 – On-site inspection (where applicable). Some supervisors, including VARA and the FCA, conduct on-site or virtual on-site interviews with the MLRO, compliance officers and senior management. Preparation for these interviews – which are not informal conversations – requires advance legal coordination.
Stage 5 – Supervisory outcome. The regulator issues findings, which may range from no action through informal guidance to a formal requirement, remediation plan or enforcement referral. The outcome at Stage 5 is substantially determined by the quality of engagement at Stages 1 through 4.
What AML Program Deficiencies Do Regulators Consistently Identify?
Supervisory findings in digital-asset AML audits cluster around a consistent set of structural deficiencies. Identifying and remediating these before an audit begins is the most effective form of defence.
The first and most common deficiency is a KYC framework (the policies and procedures governing customer identification, verification and ongoing due diligence) that was designed for a simpler product set and never updated to reflect the firm's current activity mix. A VASP that has added DeFi-linked products, institutional custody or stablecoin settlement since its original registration often finds that its CDD procedures do not cover the new risk vectors.
The second is transaction monitoring calibration. Alert thresholds set at the point of licence application may no longer reflect actual transaction volumes or typologies. A monitor tuned for retail spot trading generates different outputs than one appropriate for a firm now operating an OTC desk. Regulators increasingly expect documented evidence that alert parameters are reviewed and adjusted at defined intervals.
The third is Travel Rule compliance – the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data alongside a virtual asset transfer. In our practice, Travel Rule implementation is the single area where the gap between documented policy and operational reality is widest. Many firms have a Travel Rule policy; fewer have a functioning VASP-to-VASP data-exchange mechanism that covers their full transfer population, including transfers to and from unhosted wallets.
The fourth is MLRO governance. The Money Laundering Reporting Officer (MLRO) is the individual within the firm responsible for receiving internal suspicious activity reports, making external disclosures and producing periodic compliance reports. Regulators look for evidence that the MLRO has genuine authority, adequate resource and direct access to the board – not merely a title attached to a junior compliance analyst.
The fifth, and the one most likely to escalate a supervisory concern into a formal enforcement matter, is inadequate SAR (Suspicious Activity Report) practice: either a failure to file where the threshold is met, or a pattern of filing that suggests the function is box-ticking rather than substantive.
To pressure-test your AML program against current supervisory expectations before a regulator does, message us via t.me/oboluslaw or write to info@oboluslaw.com. If a prior audit surfaced findings that were not fully remediated, a second read of your program can identify the structural cause and the route to resolution. Map your options.
How Does a Multi-Jurisdiction Structure Affect AML Audit Defence?
For a business operating across more than one regulatory perimeter, an AML audit in one jurisdiction has immediate implications for every other. The cross-border dimension of digital-asset AML defence is not a secondary concern – it is frequently the primary one.
Consider a common structure: a group with a CASP authorisation under MiCA in one EU member state, a VARA licence in Dubai covering the MENA market, and a MAS-regulated DPT service in Singapore for the Asian corridor. Each regulator supervises the entity or branch within its jurisdiction. But the group's AML program is likely centrally designed. A finding by one supervisor that the group's transaction-monitoring procedures are inadequate is simultaneously a finding that applies to the entire AML architecture.
Cross-notification risk is real. Regulators in coordinated networks – including EU NCAs under MiCA's information-sharing provisions and FATF-member state regulators under the mutual evaluation process – do communicate. A formal enforcement action in one jurisdiction can trigger a proactive review by another without a new triggering event.
The Travel Rule creates its own cross-border complexity. The data obligation applies to transfers crossing jurisdictional boundaries. A transfer from a MAS-regulated VASP to a VARA-licensed counterpart must satisfy both regulators' Travel Rule expectations. In practice, this requires VASP-to-VASP counterparty verification, data-exchange protocol agreement and a documented approach to transfers where the receiving VASP is not registered in a FATF-equivalent jurisdiction.
In our cross-border practice, we regularly advise groups to treat their AML program as a single regulatory object that must satisfy the most demanding element of each applicable regime – and to document explicitly how each jurisdiction's specific requirements are met within the group-wide framework.
A Supervisory Examination in Practice
In a recent matter, a stablecoin exchange operator with licences in two EU jurisdictions received a formal information request from its primary supervisor, asking for two years of transaction-monitoring alert disposals, MLRO annual reports and evidence of Travel Rule implementation. The firm's documented Travel Rule policy was current; its operational implementation covered roughly half of its transfer population. We were engaged within 48 hours of the information request arriving. We structured the response to present the implemented portion accurately while providing a credible and time-bound remediation plan for the gap – framed in terms the regulator recognised as consistent with industry-standard deployment timelines. The supervisor accepted the response without escalating to formal enforcement, and the firm completed Travel Rule implementation within the agreed window. The matter closed without a public finding.
Which Response Posture Fits Your Situation?
Not every AML audit requires the same level of engagement, and the appropriate response strategy depends on the firm's profile, the regulator in question and the nature of the identified concern. The following describes the principal decision branches we work through with clients.
Profile A – Well-documented program, no prior findings, routine thematic review. The firm's policies are current, transaction monitoring is calibrated and the MLRO function is adequately resourced. The appropriate posture is a structured, accurate and complete response to the information request, managed with legal coordination to ensure consistency across the document set. Risk: low if the program is genuinely effective; moderate if there are undisclosed gaps.
Profile B – Documented program, but implementation gaps known internally. This is the most common profile we encounter. The firm has policies; the operational reality diverges from them in one or more areas. The appropriate posture is to conduct an accelerated internal gap analysis before the response deadline, structure the response accurately (never overstate compliance), and present a remediation plan that demonstrates genuine supervisory engagement. The timeline for remediation should be achievable – regulators discount plans that promise completion faster than realistic implementation allows.
Profile C – Prior findings, open remediation plan, new audit triggered. The firm is already under supervisory attention. The appropriate posture is immediate counsel engagement, a progress audit against the existing remediation plan and a coordinated response that demonstrates measurable progress. Failure to demonstrate progress against a prior commitment is the single fastest path to formal enforcement.
Profile D – Multi-jurisdiction group, audit by one supervisor only. The immediate response must satisfy the auditing supervisor. In parallel, a review of the group-wide program's alignment with other applicable regimes is necessary – because the auditing supervisor's findings, if adverse, will likely reach the others. Allied counsel in the relevant jurisdiction can manage local supervisory interaction where the group has regulated entities outside our direct footprint.
A Common Assumption We Address Regularly
A common assumption among operators entering digital-asset markets is that a single offshore licence – typically in a jurisdiction with a lighter regulatory touch – is sufficient to serve clients globally, including in major markets like the EU, the UK or Singapore. This assumption is incorrect and, when tested by a regulator, creates acute enforcement risk.
The logic of passporting and mutual recognition applies only within defined treaty or regulatory frameworks. A MiCA CASP authorisation pasports within the EU/EEA; it does not permit the holder to conduct regulated activities in Singapore without MAS authorisation, or in the UK without FCA registration. A VARA licence covers activities in mainland Dubai; it does not extend to DIFC, Abu Dhabi or any other jurisdiction. Operating cross-border without the appropriate authorisation in each market where regulated activity occurs exposes the firm not only to enforcement by the local regulator, but also to the risk that its primary regulator will treat the unlicensed activity as evidence of inadequate compliance governance – a finding that affects the primary licence.
In our practice, we map the full licence stack – covering the operating layer, the custody layer and the payment/settlement layer – across the jurisdictions where a firm's users, assets and banking relationships actually sit. That mapping exercise, done before the firm commits to a structure, is significantly less costly than remediation after a regulator identifies the gap.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – full practice overview covering the AML/CFT regime for VASPs and CASPs across jurisdictions
- KYC and onboarding framework in the Czech Republic – jurisdiction-specific guide to customer identification and verification requirements under Czech AML law
- Regulator AML audit defence – legal counsel for digital-asset firms – counsel-engagement model and service scope for firms under active supervisory review
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 and implemented domestically by each supervising jurisdiction – requires a VASP to collect, verify and transmit originator and beneficiary information alongside a virtual asset transfer. The precise data fields and the transfer-value threshold above which the obligation applies vary by jurisdiction. A VASP sending a transfer must pass the required data to the receiving VASP; a VASP receiving a transfer must verify that the data was transmitted. Failure to comply is a standalone AML deficiency, distinct from KYC failures.
Who must act as MLRO for a crypto firm?
The MLRO (Money Laundering Reporting Officer) must be a natural person with genuine authority within the firm, adequate seniority to access the board and sufficient resource to discharge the function. Most regulators – including the FCA under the MLR regime, VARA under its rulebooks and MAS under the Payment Services Act – require the MLRO to be identified to the regulator, approved or notified, and to produce periodic compliance reports. The role cannot be fulfilled by an external consultant without regulatory approval, and a nominal appointment will not survive supervisory scrutiny.
How do regulators audit crypto AML programs?
Regulators typically begin with a desk-based review: a formal information request covering AML policies, transaction-monitoring records, CDD files and MLRO reports. They then analyse the documentation against supervisory benchmarks, issue clarification requests and – where gaps are identified or the firm is considered higher-risk – conduct virtual or on-site interviews with the MLRO and senior management. The audit may conclude with no action, informal guidance, a formal requirement to remediate identified deficiencies or, in serious cases, referral to the enforcement division. The outcome is substantially shaped by the quality and consistency of the firm's responses at each stage.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and payment-service providers on AML compliance, Travel Rule implementation, supervisory audit defence and licence strategy across more than 70 jurisdictions and 25 dispute and recovery forums. Digital assets are the entirety of our practice. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit to a structure – and we assist firms under active supervisory review at any stage of the audit cycle. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML supervision, FATF-standard implementation and regulator audit response for digital-asset entities across the EU, UAE and Asia-Pacific.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.