Crypto VASP AML Requirements: A Multi-Jurisdiction Compliance Framework

AMLComplianceVASP Compliance
July 27, 2026
4 min read

Crypto VASP AML requirements are tightening across every major jurisdiction at once. FATF sets the baseline; individual regulators (FinCEN, the EU, Hong Kong's SFC, Singapore's MAS, Australia's AUSTRAC) implement it with their own timelines, thresholds, and reporting rules. This page is part of the AML Compliance Hub; it maps the landscape jurisdiction by jurisdiction and translates it into the four program pillars every VASP must build.

The FATF Risk-Based Approach, The Global AML Foundation for VASPs

FATF Recommendations 15 and 16 establish the global VASP baseline: a risk-based approach, customer due diligence, ongoing transaction monitoring, and the Travel Rule. "Risk-based" does not mean treating all transactions equally, it means allocating monitoring intensity by risk tier. FATF's 2025 targeted update (FATF Virtual Assets Targeted Update 2025) surfaced six core risk findings:

  1. Compliance is rare. Only one jurisdiction was assessed as fully compliant with Recommendation 15.

  2. Permitting is the norm. The majority of jurisdictions permit virtual assets under some framework.

  3. Prohibitions persist. A minority still prohibit them outright.

  4. State-actor theft remains a concern. The $1.5B Bybit hack, with little recovered, is the leading example.

  5. Stablecoins are rising in illicit flows. The update flagged growing stablecoin use across illicit channels.

  6. Fraud and scams are accelerating. A marked uptick was recorded over the reporting period.

The macro backdrop is why pressure is accelerating: a single 2025 US–UK operation seized roughly $15 billion in Bitcoin from Southeast Asian scam networks. In its wake, jurisdictions with pending VASP frameworks moved them toward implementation.

Infographic showing multi-jurisdiction VASP AML requirements

United States, FinCEN BSA + GENIUS Act Stablecoin Requirements

In the U.S., FinCEN's Bank Secrecy Act framework has applied to crypto money services businesses since 2013: suspicious-activity reports, currency-transaction reports, and program requirements apply regardless of asset type (FinCEN suspicious-activity framework). The 2025 GENIUS Act (congress.gov) adds stablecoin-specific AML obligations for USD-pegged issuers: on-chain KYT monitoring and automated STR capability. Enforcement gives the numbers weight: Binance's 2023 settlement of $4.3 billion for multi-year AML failures remains the largest crypto AML penalty on record. The failures behind it were basic: inadequate CDD, unfiled SARs, processing for sanctioned jurisdictions. Sanctions reach compounds it: OFAC can designate blockchain addresses directly, and any VASP with USD or USD-stablecoin touchpoints is exposed regardless of where it is incorporated (OFAC FAQ 561).

Phalcon Compliance VASP AML monitoring interface

Asia-Pacific, Hong Kong, Singapore (MAS), Australia (AUSTRAC)

Asia-Pacific runs three distinct regimes a multi-jurisdiction VASP must satisfy simultaneously: Hong Kong's stablecoin and VA-licensing framework (AMLO), Singapore's Payment Services Act under MAS, and Australia's AML/CTF regime under AUSTRAC, updated in 2026. The comparison below covers the jurisdictions where crypto programs most often need jurisdiction-specific analysis:

Jurisdiction Regulator Address screening Travel Rule threshold STR / SMR timeline Key framework
United States FinCEN Required $3,000 30 days BSA, GENIUS Act
European Union EBA / ESMA Required (MiCA) €1,000 Immediate flag MiCA + AMLA
Hong Kong SFC / HKMA Required (AMLO) HKD 8,000 Within 24 hrs AMLO, VA licensing
Dubai (UAE) VARA Required (Rulebook) USD 1,000 5 business days VARA Rulebook V2
Singapore MAS Required (PS Act) SGD 1,500 Reasonable time PSA 2019
Australia AUSTRAC Required (AML/CTF Act) AUD 10,000 (threshold transaction / IFTI reporting) SMR within 3 business days AML/CTF Act 2006 + 2026 update

Two patterns matter for program design. Thresholds vary widely (€1,000 in the EU to $3,000 in the U.S.), so a VASP operating across both must apply the lower one. STR/SMR timelines diverge sharply: Hong Kong's 24 hours and Australia's 3 business days are far tighter than the U.S.'s 30 days. So incident-response workflows must be built to the most demanding timeline in the operating portfolio. Address screening, however, is now universal across all six.

Building a VASP AML Program, The Four Pillars

Across every framework above, four pillars recur. Build to these and you satisfy the structural requirements of all of them:

  1. KYA, address screening at pre-deposit and pre-withdrawal, against current risk data, covering both incoming and outgoing addresses. (For the concept, see What Is KYA (Know Your Address).)

  2. KYT, continuous transaction monitoring with real-time scoring, not point-in-time onboarding checks.

  3. STR workflow: automated detection and multi-jurisdiction filing, increasingly a regulatory expectation rather than a convenience.

  4. Audit trail: a complete, retained monitoring record; a program that cannot produce a monitoring record for a specific relationship over a specific period does not meet the standard. Full requirements sit on the crypto AML compliance hub.

Crypto VASP AML reporting and screening workflow

Common AML Compliance Gaps in Crypto Exchanges

The recurring gaps map one-to-one to enforcement risk: (1) deposit screening only, with no outbound KYT; (2) stale label databases on 3–7 day cycles; and (3) no cross-chain monitoring. Two further gaps appear just as often: (4) manual STR handling and (5) no audit trail. These are not hypothetical: Dubai's VARA has taken enforcement action against dozens of entities, with inadequate AML programs, missing KYT monitoring, and late STR filing among the cited causes. Closing all five at production scale is what Phalcon Compliance is built for. Multi-jurisdiction licensed operators have used it to cover their core obligations through a single integration. Interlace completed that integration in days.

Map Your AML Program to Every Jurisdiction You Serve

Multi-jurisdiction compliance is not the minimum of each regime aggregated—it is building each pillar to the most demanding standard, then configuring jurisdiction-specific thresholds and timelines within that architecture.

Frequently Asked Questions

Upgrade Your Crypto Compliance Architecture

Transition from traditional identity verification to proactive address-based risk management; master the core strategies and technologies for crypto AML.