Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should compliance teams handle money laundering risk…
Governance, Ownership & Risk

How should compliance teams handle money laundering risk in digital asset businesses that operate across borders?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Compliance teams should treat cross-border digital asset activity as a higher-risk AML environment and build controls around customer verification, sanctions screening, ongoing monitoring, and case escalation. The weak point is often fragmented oversight across jurisdictions, where supervisory cooperation lags behind new products such as DeFi. Programs work best when they combine policy, transaction review, and regulator-ready evidence.

How cross-border AML risk changes the control problem

Digital asset businesses that operate across borders face a control problem, not just a policy problem. Different customer bases, payment rails, wallets, intermediaries, and local rules can create gaps between who is onboarding, who is transacting, and which jurisdiction can actually see the activity. The practical objective is to reduce blind spots by tying customer due diligence, transaction surveillance, and escalation thresholds to the highest-risk jurisdictions and product flows.

That means compliance teams should treat the business as a single risk program even when the legal obligations differ by country. A fragmented approach, where each region runs its own ruleset without a shared view of exposure, usually weakens alert quality and makes it harder to prove why a transfer, counterparty, or wallet was accepted. For digital asset firms, consistency matters because activity can move faster than supervisory coordination.

Cross-border programs work best when the operating model defines one global minimum standard, then overlays local exceptions where law requires it. That lets compliance teams maintain a defensible baseline for customer verification, sanctions screening, source-of-funds checks, and escalation while still respecting jurisdiction-specific obligations and product restrictions.

Where digital asset businesses need tighter AML controls

The most important controls sit at the points where identity, transaction flow, and exposure meet. Customer verification should be risk-based and refreshed when behaviour changes, not just at onboarding. Screening should cover customers, beneficial owners, counterparties where appropriate, and destination addresses when the business has a reliable method to do so. Ongoing monitoring should look for structuring, layering, rapid movement across wallets or venues, and patterns that are hard to justify economically.

Cross-border operations also need clear treatment for products that reduce visibility, including some DeFi interactions, bridge activity, and fast-moving on-chain transfers. These products do not automatically indicate wrongdoing, but they often reduce the quality of traditional controls. Where the business cannot support effective monitoring or escalation, the right answer is to constrain the activity, add manual review, or decline the relationship.

Policy alone is not enough. Compliance teams need evidence that controls were actually run, that alerts were dispositioned consistently, and that exceptions were approved by the right owners. That evidence becomes critical when multiple regulators, auditors, or banking partners ask how the firm applied a common standard across markets.

How to keep cross-border oversight defensible

Defensibility depends on governance and auditability as much as on surveillance logic. The program should define who owns local rule changes, who approves higher-risk onboarding, how sanctions hits are escalated, and when a case must be frozen or exited. It should also establish a single taxonomy for risk ratings, alert reasons, and case outcomes so that compliance teams can compare activity across countries without translating between inconsistent labels.

For regulatory readiness, firms should preserve the evidence trail that explains decisions, not just the final outcome. That includes customer due diligence records, source-of-funds support, screening hits, alert narratives, case actions, and the rationale for any jurisdiction-specific exception. When the business uses external standards to shape its program, FATF Recommendations on AML and KYC remain the clearest anchor for building a cross-border baseline around due diligence, beneficial ownership, and virtual asset oversight.

Where the operating model spans cloud infrastructure, customer platforms, and internal case tooling, broad control sets can help structure the evidence chain. For example, the CIS Controls v8 are useful for organising account management, logging, and monitoring requirements, while ISO/IEC 27002:2022 helps teams map governance, access control, and supplier oversight into a broader control framework.

Risk and Threat Considerations

Cross-border digital asset activity raises both compliance risk and adversarial risk because the same transfer can pass through multiple rulesets, venues, and intermediaries before anyone has a full picture. That creates opportunity for layering, sanctions evasion, mule activity, and jurisdiction shopping, especially when firms rely on manual review alone.

Failure mechanism: Fragmented supervision, inconsistent customer data, and uneven monitoring thresholds let suspicious activity appear acceptable in one jurisdiction even when it would trigger escalation in another.

Impact: The business can miss suspicious transaction patterns, file weak reports, or onboard higher-risk customers without a defensible rationale, increasing regulatory exposure and the chance of financial crime abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementCross-border AML programs depend on governed account and access ownership for case and review tooling.
AU-6 — Audit Record Review, Analysis, and ReportingOngoing monitoring and alert review need auditable review and escalation of suspicious activity.
IA-2 — Identification and Authentication (Organizational Users)Compliance operations rely on controlled access to monitoring and case management systems.
Recommendation — Enforce governed account lifecycle and access assignment for compliance and investigations tools. Review audit data to detect suspicious transactions and support case escalation. Require strong authentication for compliance staff and privileged reviewers.
ISO/IEC 27001:2022A.5.15 — Access controlCross-border AML oversight needs controlled access to sensitive customer and case data.
A.5.18 — Access rightsRole changes and regional responsibility shifts can weaken AML oversight if rights are not managed.
A.5.30 — ICT readiness for business continuityAML monitoring and escalation must continue across jurisdictions during operational disruption.
Recommendation — Apply access restrictions to customer due diligence and investigation records. Review and revoke compliance access rights when responsibilities change. Keep AML monitoring and case handling resilient across sites and vendors.
CIS Controls v8CIS-5 — Account ManagementCompliance tooling needs disciplined account lifecycle and privileged access management.
CIS-8 — Audit Log ManagementAML monitoring relies on logs that prove what was reviewed and when.
CIS-13 — Network Monitoring and DefenseCross-border digital asset activity needs visibility into unusual flows and control bypasses.
Recommendation — Minimise and review access to AML systems and casework platforms. Centralise and protect logs used for transaction monitoring and investigations. Monitor unusual traffic and data flows supporting AML detection.
SOC 2 (AICPA)CC6.1 — Logical and Physical Access ControlsAML case data and monitoring systems require restricted access and accountability.
Recommendation — Restrict access to AML evidence, cases, and screening systems.

Practitioner Guidance

What to prioritise: Build one cross-border AML control standard first, then layer local legal exceptions on top of it. The global baseline should cover customer verification, sanctions screening, alert triage, escalation, and record retention, so regional teams are not inventing their own thresholds.

What to verify: Check whether the program can explain every high-risk decision with evidence. If a reviewer cannot reconstruct why a customer, wallet, or transaction was accepted, the control design is too weak for cross-border use.

Decision rule: If a product, venue, or jurisdiction prevents meaningful monitoring or case escalation, treat that as a control limitation, not a tooling problem. Either add compensating review steps or restrict the activity until the firm can support it.

Practitioner takeaway: The main test is whether compliance can produce a consistent, regulator-ready story across jurisdictions, product types, and transaction paths, because inconsistency is where both enforcement risk and laundering risk concentrate.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org