AML Audits for Crypto Exchanges and VASPs: What Regulators Expect
Blogs

AML Audits for Crypto Exchanges and VASPs: What Regulators Expect

FATF’s July 2026 targeted update on virtual assets revealed a striking gap: only 34% of jurisdictions are largely compliant with Recommendation 15, the standard that governs AML/CFT obligations for virtual asset service providers. At the same time, enforcement is accelerating. In 2025, a major crypto exchange agreed to pay approximately US$500 million to resolve AML-related regulatory breaches. Supervisory expectations worldwide are becoming increasingly consistent. Having a compliance policy on file is no longer enough. Regulators expect evidence that your controls work in practice and independent audits are one of the primary mechanisms used to demonstrate the effectiveness of AML controls.

With more than 60 jurisdictions now requiring VASP licensing or registration, the scope of what auditors examine has expanded well beyond traditional financial crime controls. FATF’s latest guidance pushes supervisors to test Travel Rule compliance, stablecoin risk management and sanctions screening effectiveness. As a result, independent audit requirements have become more rigorous across every major market.

This article explains what an independent AML audit for VASPs should cover, what global regulators are scrutinising most closely and how your firm can prepare.

Audit area Key requirement Why it matters
Business risk assessment Documented, data-driven and reviewed regularly Regulators treat the BRA as a live risk management tool, not a static document
Customer due diligence Risk-based CDD/EDD with ongoing monitoring Weak onboarding controls are among the most common audit failures
Transaction monitoring Tuned detection rules, alert quality review and escalation Auditors test whether rules catch real typologies, not just generate volume
Sanctions and PEP screening Fuzzy matching, real-time screening and hit disposition Gaps in screening logic create direct regulatory exposure
Travel Rule compliance Originator and beneficiary data exchange above thresholds FATF and local regulators actively test Travel Rule implementation
Suspicious activity reporting Timely STR/SAR filing with quality checks Late or poorly drafted reports draw immediate supervisory attention

Why regulators increasingly expect independent AML testing for VASPs

Independent testing has been a cornerstone of financial regulation for decades. Banks, insurers and money service businesses routinely commission external reviews of their AML controls. The shift in recent years is that regulators now apply this same expectation to VASPs.

FATF Recommendation 15 requires jurisdictions to regulate and supervise VASPs for AML/CFT purposes. The standard covers licensing, risk assessments, customer due diligence, transaction monitoring, sanctions compliance, record-keeping and suspicious activity reporting. According to FATF’s July 2026 targeted update, 83% of surveyed jurisdictions have now passed Travel Rule legislation, yet only 34% are rated largely compliant with the full scope of Recommendation 15, meaning implementation gaps remain widespread.

This gap between policy adoption and effective implementation is exactly what an independent AML audit is designed to close. Regulators do not simply want to see a compliance manual. They want evidence that the manual has been followed, that controls function as designed and that the firm can demonstrate this to an independent examiner.

Enforcement actions reinforce this point. In 2025 alone, global AML fines exceeded $850 million across traditional finance and crypto. The trend toward personal accountability for senior executives makes the case for proactive independent auditing even stronger.

For VASPs operating across multiple jurisdictions, the audit obligation may arise under several regulatory frameworks simultaneously, including the EU’s Transfer of Funds Regulation, the UK’s Money Laundering Regulations 2017, FinCEN requirements in the United States, AUSTRAC obligations in Australia and FINTRAC rules in Canada. Each framework carries its own audit expectations and firms must satisfy all of them.

What a VASP independent AML audit covers

An independent AML audit for a VASP examines the full lifecycle of the firm’s compliance program. The scope typically spans six core areas. An auditor will test each through document reviews, interviews, data sampling and scenario walkthroughs.

Governance and risk assessment

The auditor begins by reviewing the firm’s enterprise-wide risk assessment. This includes checking whether it covers the FATF risk categories (customer, geographic, product, channel and transaction), whether the methodology is defensible and whether the resulting risk ratings drive operational controls. Board-level approval and independent challenge of the risk assessment methodology are key indicators of framework maturity.

Customer due diligence and onboarding

Auditors test the CDD and EDD processes against regulatory requirements and the firm’s own policies. They review a sample of customer files to verify that risk ratings are consistent, that enhanced measures apply to high-risk customers and that ongoing monitoring is in place. Gaps in onboarding controls remain one of the most common deficiencies identified during AML reviews of VASPs.

Transaction monitoring and suspicious activity reporting

This area receives close scrutiny. Auditors evaluate the detection logic, alert scoring models, typology coverage and tuning methodology. They also review STR/SAR filings for timeliness, quality and escalation procedures. FATF guidance encourages supervisors to ensure firms test their monitoring controls against real-world typologies, including those specific to virtual assets such as layering through decentralised exchanges and privacy-enhancing technologies. Auditors should also assess how blockchain analytics tools are integrated into the monitoring framework, including wallet risk scoring, exposure to sanctioned entities and investigation workflows.

Sanctions and PEP screening

The audit covers screening coverage, matching logic (including fuzzy matching thresholds), hit disposition processes and the frequency of rescreening. Auditors verify whether screening happens at onboarding and on an ongoing basis and whether the firm screens against all relevant lists including OFAC, UN, EU and UK sanctions.

Travel Rule compliance

With the FATF Travel Rule now adopted in law across more than 91 jurisdictions, auditors test whether the VASP exchanges required originator and beneficiary information for qualifying transfers. Thresholds vary by jurisdiction. The EU applies a zero threshold for CASP-to-CASP transfers under the Transfer of Funds Regulation, while the US maintains a $3,000 threshold under the Funds Transfer Rule and the UK uses a zero threshold for cross-border transfers.

Record-keeping and training

Auditors verify retention periods (at least five years under the FATF standard), retrieval capability and audit trails. They also review training records, checking coverage, frequency, whether content is role-based and whether attendance is documented.

How FATF standards shape VASP audit expectations

FATF’s 2025 targeted update on virtual assets and its Best Practices on Travel Rule Supervision, published alongside the update, together set a clear direction for what supervisors expect auditors to examine.

The targeted update found that while more jurisdictions have adopted Recommendation 15 legislation, enforcement remains uneven. According to FATF’s July 2026 update, of the 91 jurisdictions with Travel Rule legislation in force, 60% have yet to issue a single finding, directive or enforcement action related to compliance. FATF views this as a critical weakness. The organisation has urged supervisors to move beyond licensing paperwork and begin testing whether controls work on the ground.

For auditors, this translates into a practical shift. A VASP independent AML audit must now evaluate not just the existence of policies but their operational effectiveness. FATF expects supervisors to verify that firms test Travel Rule coverage, cross-border counterparty exposure, stablecoin lifecycle risks, unhosted wallet controls, sanctions escalation and evidence around deposit and withdrawal decisions.

Stablecoin risks have received particular attention. Stablecoins account for an increasing share of identified illicit virtual asset activity, with FATF’s update noting continued growth in usage by state-sponsored actors, terrorist financiers and drug traffickers. The July 2026 update also highlights a new risk: criminal networks are now developing proprietary stablecoins engineered to resist freezing and asset seizure by centralised entities. Auditors should expect to review how VASPs identify, monitor and report stablecoin-related suspicious activity, particularly for cross-border transfers.

The overarching theme is operational proof. Regulators want to see that a VASP’s compliance program responds to real data, adapts to emerging risks and produces measurable outcomes.

Multi-jurisdictional audit challenges for VASPs

VASPs rarely operate in a single regulatory environment. A firm licensed in one jurisdiction will typically handle customers and counterparties across several others. This creates distinct challenges for independent auditors.

The most visible issue is the Travel Rule “sunrise problem.” Countries are adopting the Travel Rule at different speeds, which means a compliant VASP in one jurisdiction regularly interacts with partially compliant or non-compliant VASPs in another. Auditors must evaluate how the firm manages these mismatches, including fallback procedures when counterparty information is incomplete or unavailable.

Threshold differences add further complexity. The EU applies a zero threshold for CASP-to-CASP transfers under the Transfer of Funds Regulation. The United States maintains a $3,000 threshold under the Funds Transfer Rule. The United Kingdom uses a zero threshold for cross-border transfers. An auditor reviewing a multi-jurisdictional VASP must verify that the firm applies the correct threshold rules for each market it serves.

Interoperability remains an unsolved problem as well. There is no universal protocol for transmitting Travel Rule data and networks operated by different providers often use incompatible systems. When originating and beneficiary VASPs use different messaging solutions, transfers can fail or produce incomplete records. Auditors will test whether the firm has procedures to identify and resolve these failures.

Privacy and data protection conflicts round out the challenge. Differences in privacy laws across jurisdictions mean that a VASP’s compliance with one country’s Travel Rule requirements may conflict with another country’s data protection obligations. The auditor should evaluate how the firm navigates these tensions without creating compliance blind spots.

Jurisdictions differ considerably in their legal requirements for independent testing. Some require formal independent AML audits, while others require independent testing or periodic compliance reviews. Firms should determine the applicable requirements in each jurisdiction where they operate and ensure the audit scope satisfies all of them.

Choosing the right auditor for your VASP

Independence is the starting point. Individuals responsible for designing or operating the AML compliance program should generally not perform its independent review. The auditor must bring an external perspective, free from conflicts of interest.

Beyond independence, the auditor must have demonstrable AML/CFT expertise relevant to your regulatory framework, products and jurisdictions. A generalist financial auditor without specific AML experience will produce a report that may not satisfy supervisory expectations. Look for credentials such as CAMS (Certified Anti-Money Laundering Specialist), ICA diplomas, CGSS (Certified Global Sanctions Specialist) or equivalent qualifications. Prior experience with regulatory bodies, Big Four AML practices or specialist compliance consultancies adds further credibility.

Virtual asset expertise matters equally. The auditor should understand crypto-specific risks including unhosted wallets, decentralised finance exposure, stablecoin lifecycle risks, cross-border virtual asset transfers and Travel Rule implementation challenges. Without this knowledge, the audit will miss the risks that are unique to VASPs and that regulators are now scrutinising most closely.

For firms operating across borders, consider the auditor’s familiarity with your specific regulatory environments. A VASP licensed in the EU faces different supervisory expectations from one regulated in the United States, the United Kingdom or the Asia-Pacific region. The auditor should understand both the letter of the applicable regulations and the practical priorities of each supervisory authority.

Preparing your VASP for an independent AML audit

Preparation separates a productive audit from a resource-intensive one. Firms that invest in pre-audit readiness consistently achieve better outcomes and fewer regulatory follow-ups.

Run a pre-audit gap analysis

Before the auditor arrives, conduct an internal review against the applicable regulations and your own policies. Identify gaps early so you can address them proactively. Pay particular attention to your business risk assessment, CDD procedures, transaction monitoring rules and sanctions screening configuration.

Document everything

Auditors work from evidence. Every policy decision, risk assessment update, board approval and training session should be documented with dates, attendees and outcomes. If you adjusted a transaction monitoring threshold, record why, when and who approved the change. Undocumented decisions are, from an audit perspective, decisions that never happened.

Test your own controls

Run sample tests on your transaction monitoring system before the audit. Check whether your rules detect known typologies. Review a sample of screened alerts to confirm that your disposition process is consistent and defensible. Test your Travel Rule messaging to verify that data flows correctly between counterparty VASPs.

Confirm your team is audit-ready

Ensure that your compliance officer, MLRO and key operational staff can explain the firm’s AML program clearly and consistently. Auditors interview staff to assess whether the program is understood and applied in practice, not just written into policy documents. Training records should be current and staff should know how to escalate suspicious activity without hesitation.

Next steps for your compliance program

The regulatory bar for VASPs continues to rise worldwide. With FATF pushing supervisors to enforce compliance in practice, the expectation is clear: VASPs are increasingly expected to demonstrate that their controls work, not just that they exist. An independent AML audit is the most effective way to prove this to regulators, to your board and to your customers.

Conduct independent AML audits at a frequency appropriate to your regulatory obligations and risk profile, with annual reviews representing good practice for many VASPs. Choose an auditor with both AML expertise and virtual asset knowledge. Review and update your enterprise-wide ML/TF/PF risk assessment regularly. Document every decision and test your controls before the auditor does.

If your firm needs independent AML audit or strengthening your AML/CFT compliance program, Compliance7 can help. Our CAMS-certified team has over 12 years of experience working across multi-jurisdictional AML engagements. Book a free consultation to discuss your specific requirements.

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.

Leave a Reply

Your email address will not be published. Required fields are marked *