Because regulators will still expect those obligations to be met through the correct legal basis outside MiCA. CASPs need separate evidence for identity verification, screening, and Travel Rule handling so the licensing file does not blur distinct compliance duties into one narrative.
Why MiCA Compliance Still Splits Along AML/CFT and Travel Rule Lines
MiCA regulates crypto-asset markets, but it does not replace the separate legal duties that govern anti-money laundering, counter-terrorist financing, and travel rule handling. If a CASP treats those obligations as “covered by MiCA,” it risks building the wrong licensing narrative and the wrong control set.
That distinction matters because supervisors review whether the firm can evidence each duty on its own terms: customer due diligence, screening, suspicious activity handling, and originator or beneficiary information transfer are not the same control problem as MiCA authorisation.
What Must Still Be Proven Outside the MiCA File
The practical issue is not whether the firm is compliant in a general sense, but whether it can show the right legal basis for each compliance activity. AML/CFT controls usually sit under financial-crime obligations, while Travel Rule controls address the regulated transfer of payer and payee data across VASPs or CASPs.
That means the evidence pack needs clean separation. Identity verification evidence should show how the customer or counterparty was established. Screening evidence should show when sanctions, PEP, or adverse-media checks were run and what thresholds triggered escalation. Travel Rule evidence should show how required originator and beneficiary information was captured, validated, transmitted, and retained.
How the Obligation Split Affects Supervision and Audit Readiness
When these obligations are merged into one generic “MiCA compliance” story, reviewers lose visibility into where each control begins and ends. That becomes a problem during authorisation, audit, remediation, or an enforcement inquiry, because the firm may be unable to demonstrate which obligations are supported by policy, tooling, and operating procedure.
This is why the legal split matters operationally: AML/CFT and Travel Rule requirements often come from different rulesets, different supervisory expectations, and different evidence standards. A control can be technically sound and still fail review if the file does not show the correct obligation mapping.
Risk and Threat Considerations
Blurring MiCA with AML/CFT creates a control gap that is easy to miss until a regulator or auditor asks for line-by-line evidence. The main risk is not only non-compliance, but also weak ownership of screening, false-confidence in onboarding records, and gaps in Travel Rule data handling across counterparties.
Failure mechanism: The firm collapses distinct legal duties into one compliance narrative, so the control owner, evidence source, and retention basis no longer match the actual obligation being tested.
Impact: Supervisors can view the licensing pack as incomplete or misleading, and the firm may need to rebuild controls, re-document procedures, or remediate gaps after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Identity verification evidence must show how parties were established. |
| AU-6 — Audit Review, Analysis, and Reporting | The question is about evidence separation and supervisory review readiness. | |
| Recommendation — Document how customers or staff are identified and authenticated before relying on downstream compliance records. Retain and review separate artefacts for CDD, screening, and Travel Rule handling. | ||
| ISO/IEC 27001:2022 | A.5.31 — Legal, statutory, regulatory and contractual requirements | MiCA does not erase other legal duties, so obligation mapping is central. |
| Recommendation — Map each control to the correct legal obligation before presenting the licensing file. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Travel Rule and screening controls depend on traceable evidence and retention. |
| Recommendation — Ensure logs and case records can prove when checks ran and what information was transmitted. | ||
| GDPR | A.5.1 — Lawfulness, fairness and transparency | The need for the correct legal basis parallels the question’s obligation-splitting issue. |
| Recommendation — Confirm each processing activity is documented under its own lawful basis and purpose. | ||
Practitioner Guidance
What to prioritise: Build a three-part evidence structure for onboarding, transaction monitoring, and Travel Rule transmission so each obligation can be tested separately. Keep the control owner, policy basis, and artefact set aligned to the duty being met.
What to verify: Check that the licensing file distinguishes customer due diligence, sanctions and screening activity, and Travel Rule message handling, rather than treating all three as interchangeable compliance outputs.
Decision rule: If an artefact would not still make sense when read against the underlying AML/CFT or Travel Rule obligation alone, it is too vague for supervisory use.
Practitioner takeaway: The safest posture is to treat MiCA as the market-access framework and keep financial-crime obligations documented as separate, auditable control lines.
Related resources from NHI Mgmt Group
- Why does Travel Rule compliance matter for AML and CFT controls in virtual asset businesses?
- Why do beneficial ownership and representative verification matter in Kenya’s AML and CFT controls?
- Who is accountable for ensuring crypto monitoring controls meet travel rule and AML requirements?
- Why do KYC, KYB, AML screening, and Travel Rule controls need to work together in crypto payments?