Web3 practice · Service · India, UAE and EU

Crypto AML programme design and MLRO support, after the registration.

FIU-IND registration, a VARA licence or a MiCA authorisation is the gate. What the regulator supervises afterwards is the programme behind it: named officers, risk assessments, monitoring, reporting and audit. We design that programme, document it and support the officer who runs it.

A crypto AML compliance consultant for India, the UAE and the EU does not hold your Compliance Officer or Principal Officer role; the rules reserve those for your own appointee. VARA requires a full-time Compliance Officer, UAE resident or passport holder, approved by VARA, and FIU-IND a full-time, India-based Principal Officer. Infinilex designs the AML programme those officers run, documents it against the FIU-IND guidelines of 8 January 2026, the VARA rulebooks and MiCA with the AML Directive, and supports the MLRO or Principal Officer on a retainer.

This page is about what happens after the gate; the gate is on FIU-IND registration, VARA licensing and MiCA authorisation. Principal Officer and Designated Director requirements are in FIU-IND registration for crypto businesses in India; travel rule thresholds are on the travel rule page.

Schedule A: who must be named, and what the programme must do, in each regime

Schedule A · Named officers and programme duties: FIU-IND, VARA with UAE federal law, MiCA with the AML Directive, as at 25 September 2026
DimensionIndia: FIU-INDDubai: VARA and UAE federal lawEU: MiCA and the AML Directive
Named officersDesignated Director (PMLR rule 2(1)(ba)) and Principal Officer (rule 2(1)(f)), separate people, both notified through FINGate.Compliance Officer at management level with independent decision-making (Cabinet Resolution 134 of 2025, Art 22). VARA: a Compliance Officer (Part I.C) and an MLRO (Part III.A), one person absent conflicting duties.Compliance officer at management level (AMLD Art 8(4)(a)) and a responsible board member (Art 46(4)); from 10 July 2027, a compliance manager plus a compliance officer (AMLR Art 11).
Who can hold itManagement level, full-time and exclusive, based in India, three years’ AML experience, outside business and operations.CO: five years’ experience, Fit and Proper, VARA-approved, UAE resident or passport holder, full-time employee reporting to the Board. MLRO: two years’ AML/CFT experience, Fit and Proper.AMLR Art 11: sufficiently high hierarchical standing; until then, national transposing law.
OutsourcingAlert analysis may be delegated; the STR decision rests with the Principal Officer.MLRO, CISO and Data Protection Officer may be outsourced (Company Rulebook Part IV.A.3), the individual accountable to VARA, which may require a full-time employee; cross-border outsourcing needs prior notification. The CO is not outsourced.From 10 July 2027: permitted with prior notification and full liability retained, save six reserved tasks (AMLR Art 18).
Risk assessment cadenceEnterprise assessment at most yearly and before any new product or technology; client classification reviewed at least six-monthly.Business and client risk assessments no longer than every three months and on significant change (Part III.D).Procedures monitored and regularly evaluated (MiCA Art 68(8)); business-wide risk assessment by the compliance officer, approved by the management body (AMLR Art 10).
Independent auditIndependent annual audit of AML, CFT and CPF controls; internal audit at least yearly, reported to the Board.Independent audit function (Cabinet Resolution 134 of 2025, Art 21); VARA internal audit at least quarterly and an annual auditor attestation on the internal control structure.Independent audit function where size warrants (AMLD Art 8(4)(b)); an external expert where none exists (AMLR Art 9(2)(b)).

Sources, read 25 September 2026: FIU-IND VDA guidelines, 8 January 2026; VARA Compliance and Risk Management Rulebook (current version, 2025), Parts I.C, I.G, I.H, III.A, III.B, III.D; VARA Company Rulebook Part IV; Decree-Law 10 of 2025; Cabinet Resolution 134 of 2025; MiCA; Directive 2015/849; Regulation 2024/1624; Regulation 2023/1113.

What crypto AML programme design covers

  • Enterprise and client risk assessment. Documented and proportionate, built to the shortest cycle you are under (quarterly under VARA, at most annual under FIU-IND with a six-monthly client review) and re-run before any new product or technology goes live.
  • The policy set and its approvals. Board-level AML, CFT and CPF Policies, the website summary FIU-IND requires, the group-basis policy where PMLR rule 3A applies, and for VARA a policy pack prepared for third-party attestation and the 21-day resubmission after every change.
  • CDD, enhanced due diligence and KYC refresh. The FIU-IND onboarding standard, VARA’s risk-based CDD with occasional-transaction checks at AED 3,500 and MLRO plus Senior Management sign-off for PEPs, enhanced measures for FATF grey and black list exposure, and the refresh calendar. The India build list is in our FIU-IND registration checklist.
  • Monitoring, screening and the travel rule. Scenarios mapped to FIU-IND red-flag indicators and the FATF Virtual Assets Red Flag Indicators report, distributed ledger analytics with the capability review VARA expects, real-time sanctions screening, the FIU-IND rules on anonymity-enhancing tokens, mixers and unhosted wallets, and travel rule information moving before or with the transfer (thresholds: the travel rule page).
  • Reporting lines. STRs to FIU-IND filed promptly, irrespective of amount and including attempted transactions, the Monthly Report and tipping-off controls; under VARA, immediate reporting to the UAE FIU on goAML, the 48-hour response to FIU or VARA requests, and the Part I.H returns.
  • MLRO and Principal Officer support. Alert quality assurance, the Board pack at each regulator’s cadence (FIU-IND at least annually, VARA quarterly), training, regulator correspondence and the evidence file for the annual audit, so your appointee decides on a complete record.

How the programme is built: ten steps

  1. Enterprise risk assessment. FIU-IND para 3.6.1, VARA Part III.D, AMLD Art 8(1), AMLR Art 10 from 2027; outcome to the Board.
  2. Board-approved policies. FIU-IND para 3.4, VARA Part III.B with third-party attestation, AMLD Art 8(5), Cabinet Resolution 134 of 2025, Art 21.
  3. Client risk classification. At least High and Medium under FIU-IND, reviewed six-monthly; quarterly under VARA.
  4. CDD and enhanced due diligence. FIU-IND chapter 4, VARA Part III.E, and the originator and beneficiary information the TFR requires with every transfer.
  5. Sanctions screening. UNSC, UAPA and WMDA lists at onboarding, on list changes and at every transaction (FIU-IND para 5.4); automated real-time screening and immediate freezing (VARA Part III.H).
  6. Transaction monitoring with chain analytics. Systems that identify a VDA’s origin and destination (FIU-IND para 5.2); ledger analytics and red-flag scenarios (VARA Part III.C).
  7. Travel rule technology. FIU-IND para 5.3, VARA Part III.G, TFR Art 14; counterparty VASP due diligence and the sunrise plan.
  8. STR and regulator reporting lines. FIU-IND paras 5.5 to 5.7, VARA Parts III.F and I.H, AMLR Art 11(2); who decides, who files, and the reasons recorded on closed alerts.
  9. Training and hiring screening. FIU-IND para 3.7, VARA Part I.J, AMLD Art 46, AMLR Art 12.
  10. Independent annual audit. FIU-IND para 3.6.3, Cabinet Resolution 134 of 2025, Art 21, AMLD Art 8(4)(b), AMLR Art 9(2)(b), alongside VARA’s quarterly internal audit and annual auditor attestation.

How a crypto AML programme engagement is staged

Fixed-scope stages, mapped on a free discovery call. Stage one is the gap assessment: your current programme read against the FIU-IND guidelines, the VARA rulebooks or MiCA with the AML Directive, with a finding on each of the ten steps; it stands on its own. Stage two is the build: policies, procedures, risk assessments, training, reporting templates and the audit evidence file. Stage three, optional, is MLRO or Principal Officer support on a monthly retainer. Plan and cost are agreed first: how engagements work.

Who signs what on crypto AML programme work

Infinilex is a consultancy: we design and document the programme and hold the evidence file. The statutory roles stay with your appointees: the Designated Director and Principal Officer under the PMLA, the Compliance Officer and MLRO under VARA and UAE federal law, the compliance officer and responsible board member under the AML Directive. They take the reserved decisions: the STR, the risk profile, the onboarding call. The India leg of the advisory work is signed by Infinilex counsel enrolled as advocates in India, or by Infinilex’s company secretary or chartered accountant where a statute names that professional; the UAE leg by Infinilex counsel qualified for VARA matters. For the EU, Infinilex scopes the work, builds the fact record and briefs the EU local counsel who sign and file, named to you before they act. VARA’s policy attestation is by the competent third party the rulebook requires.

Frequently asked questions

Can a VASP outsource its Compliance Officer or MLRO under VARA?

Yes, with conditions. The VARA Company Rulebook, Part IV.A.3, lets a VASP outsource the MLRO, CISO and Data Protection Officer roles if Part IV is complied with and the individual accepts personal responsibility to VARA. VARA may at its discretion require a full-time employee in any of those roles, encourages in-house resourcing, and must be notified before any cross-border outsourcing. The Compliance Officer is different: Part I.C.1 of the Compliance and Risk Management Rulebook requires a full-time employee, UAE resident or passport holder, approved by VARA.

Can Infinilex be our Compliance Officer or Principal Officer?

No, and the rules are the reason. FIU-IND requires a Principal Officer exclusively engaged with the reporting entity full-time, based in India, with at least three years of AML experience, and a separate Designated Director. VARA requires a full-time Compliance Officer, UAE resident or passport holder, approved by VARA. Both appointments are yours. Infinilex designs the programme those officers run, documents it, trains the team, prepares the Board and regulator reporting and supports the officer on a retainer, so the role does not rest on one person.

What does the annual independent AML audit cover?

For an FIU-IND reporting entity, paragraph 3.6.3 of the 8 January 2026 guidelines requires an independent annual audit of AML, CFT and CPF controls, systems, procedures and safeguards, an internal audit at least yearly reported to the Board or a Board committee, plus an annual independent review of the Policies by people who did not write them. In the UAE, Article 21 of Cabinet Resolution 134 of 2025 requires an independent audit function testing AML controls; VARA adds a quarterly internal audit and an annual auditor attestation on the internal control structure. In the EU, AMLD Article 8(4) requires an independent audit function where size warrants it.

Which AML decisions can never be outsourced?

In the EU, Article 18 of Regulation (EU) 2024/1624, applying from 10 July 2027, lists six tasks that can never be outsourced: proposing and approving the business-wide risk assessment, approving internal policies, the customer risk-profile decision, the decision to onboard, suspicious transaction and threshold reporting to the FIU, and approving the criteria for detecting suspicious transactions. FIU-IND places the ultimate STR decision with the Principal Officer, who records the reasons for reporting or closing every alert. VARA keeps the Compliance Officer accountable for anything delegated. Infinilex builds the programme around those reserved decisions; your appointee takes them.

Next step

Tell us which regulator has you, and who holds the role today.

Send the registration or licence you hold, the officers you have named and the last Board report. We will tell you on the discovery call where to look first, before any commitment.

Further reading

FIU-IND registration for crypto businesses in India · FIU-IND registration checklist · The crypto travel rule: India, the UAE, the EU and the US · UAE VASP licensing-readiness checklist · Self-custody compliance controls checklist · MPC and smart-contract wallets: which key arrangements are custody?

Related services: FIU-IND registration · VARA licensing · MiCA authorisation · ADGM and DIFC crypto licensing · Fractional general counsel and compliance retainer

This page is general information about the service, not advice on your facts. Guidelines and rulebooks change; positions are stated as at 25 September 2026 and re-verified quarterly. Whether a regulator accepts a programme, officer or outsourcing arrangement depends on your facts; no outcome is promised.