AML Audit Readiness for Crypto Firms in Cyprus: The Gaps We Find Most

By Panayiotis Kattides · August 5, 2026
Most crypto firms in Cyprus do not fail an AML review because a control is missing. They fail because a control exists on paper, was never tuned to the business, and cannot be evidenced when someone asks.
We review AML frameworks at crypto exchanges, CASPs, custodians and payment firms, and the findings repeat. Not because compliance teams are careless — the people we meet are usually stretched, competent and aware of at least half of what we are about to write down. The gaps repeat because they are structural. They come from frameworks assembled quickly during authorisation, vendor tooling deployed with default settings, and a business that changed faster than its documentation.
This is a readiness checklist rather than a description of what an audit covers. If you want the latter, it is set out on our AML compliance audit page. What follows is the shortlist of things to go and look at yourself, this week, before someone external looks at them for you.
The Supervisory Backdrop, Briefly
Crypto-asset service providers in Cyprus are supervised by the Cyprus Securities and Exchange Commission and are obliged entities under Cyprus AML law implementing the EU directives. MiCA brought CASPs into a harmonised EU authorisation regime, which means your AML framework is now assessed as a component of a supervised firm rather than as a voluntary standard — a change of posture more than a change of rules. Our note on the MiCA transition window covers that shift in more detail.
Layered on top is the EU AML package: a directly applicable AML Regulation that narrows the national discretion firms have been reading around, and AMLA, the new EU-level authority that will push supervisory expectations toward a common standard. The Transfer of Funds Regulation extends the Travel Rule to crypto transfers. Suspicious transaction reports go to MOKAS, the Cyprus financial intelligence unit.
Parts of this are still bedding in. Where supervisory expectation has not settled, we say so rather than presenting one reading as settled law — and you should take the same approach in your own documentation. A stated interpretation with reasoning behind it is defensible. Silence is not.
Gap 1: A Risk Assessment About Crypto Businesses in General
The business-wide risk assessment is where most reviews start, and it is where the tone of the whole engagement gets set. The common failure is a document that describes a generic crypto business: the standard threat typologies, the standard geographic risk categories, the standard conclusion that residual risk is medium.
What good looks like: the assessment names your actual products, your actual customer segments, your real onboarding jurisdictions in volume order, and the specific chains and asset types you support. It explains why a risk is rated as it is, with reference to your own data. It is dated, approved at board level, and revisited when you launch something new — not annually by calendar reflex. If a reader who has never met you could not describe your business after reading it, it is not your risk assessment.
Gap 2: Monitoring Rules Nobody Tuned
Transaction monitoring is usually bought, deployed with the vendor's starter rule set, and left. Two years later the customer base has shifted, the product set has doubled, and the thresholds are still whatever the implementation consultant typed in.
What good looks like: a documented mapping from each risk identified in your risk assessment to the rule or rules intended to detect it, so coverage gaps become visible. Thresholds justified against your own distribution of customer behaviour, not against a market average. A record of every tuning decision — what changed, why, who approved it, what the before-and-after alert volumes were. Above-the-line and below-the-line testing when thresholds move. Crypto AML controls that were never calibrated to the book they monitor are, functionally, an expensive log.
Gap 3: Treating Alert Volume as Evidence of Diligence
This one is worth stating bluntly. A backlog of thousands of open alerts is not proof that you are monitoring carefully. It is proof that you are generating output nobody is consuming. We have seen firms present alert counts as a compliance metric while the average alert had been open for months and dispositions read, in full, "reviewed — no action".
What good looks like: alert volume that a team of your size can actually clear, with an ageing report the compliance officer sees weekly. Dispositions that record what was checked and what the reviewer concluded, in enough detail that a second person could reach the same conclusion from the file. Quality assurance sampling of closed alerts. A defined escalation path with named roles. If the backlog is genuinely unmanageable, the honest fix is tuning plus resourcing, documented as a decision — not quiet accumulation.
Gap 4: Sanctions Screening Nobody Has Tested
Almost every firm screens. Far fewer can tell us what their fuzzy-matching threshold is set to, who set it, or what it does with transliterated names, name order reversal, or common regional spelling variants. And a large number screen at onboarding only, so a customer who was clean in 2024 is still clean in your system today regardless of what has happened since.
What good looks like: documented list coverage and refresh frequency, including which lists and from what source. Match-threshold settings that have been tested with a deliberate set of known-difficult names, with the results kept. Rescreening of the entire existing book on list updates, on a schedule you can evidence. Screening that reaches counterparties and beneficial owners, not customers alone. A false-positive process that does not quietly train staff to clear everything. The European Banking Authority guidelines on internal policies and controls in this area are a useful reference point even where they are not directly binding on you.
Gap 5: Travel Rule Exception Handling
Travel Rule compliance for crypto is the gap that has moved fastest and is understood least evenly. Most firms have the happy path working: an in-scope transfer to a counterparty on the same messaging network, with complete originator and beneficiary data, goes through fine. That is not where the risk sits.
The risk sits in the exceptions, and there are three that come up constantly:
- The counterparty who does not respond. You sent the required information. Nothing came back. What is your policy — hold, release, release and flag? For how long? Who decides? Is the decision recorded per transfer or is it an unwritten desk convention?
- The self-hosted wallet transfer. There is no counterparty institution to exchange data with. What verification do you perform on the claimed ownership, at what value, and how is the outcome recorded? What blockchain analytics screening applies before release?
- The transfer arriving with information missing or obviously implausible. A beneficiary name of "customer" is missing information wearing a hat. What happens next, and does anything feed back into the customer's risk rating or into your view of that counterparty?
What good looks like: a written exception matrix covering each case, with a decision, an owner, a time limit, and a record. Counterparty due diligence performed before you start exchanging data with another provider, not after. Periodic sampling of failed and held transfers to check the policy is what actually happened. And a straightforward acknowledgement in your documentation where market practice is still consolidating — this is an area where interoperability between messaging solutions remains imperfect, and pretending otherwise reads worse than describing your workaround.
Gap 6: Analytics Scores With No Decision Attached
Blockchain analytics is now an expected control, and most firms have a provider. The gap is that the risk score arrives on a dashboard and stops there. There is no documented threshold at which a score changes an outcome, no escalation trigger, and no record of what the score was at the time a decision was made.
What good looks like: a written policy stating the score bands, what each band requires, and who can override — with overrides logged and reviewed. Scores captured and retained at the point of decision, because providers reclassify addresses over time and a screenshot from last year will not reconstruct itself. Periodic reassessment of exposure for existing customers, not just at deposit. And an independent check, at least occasionally, that what your tooling reports matches what the chain shows; that is a core part of what we do in blockchain auditing engagements, and it is the one control most firms have never had verified by anyone other than the vendor selling it.
Gap 7: Training That Trains Nobody in Particular
Annual e-learning with a multiple-choice quiz produces a completion certificate. It does not produce a support agent who recognises a structuring pattern, or an onboarding analyst who knows when source of wealth evidence is inadequate rather than merely absent.
What good looks like: role-specific content. Onboarding staff get due diligence and escalation. Monitoring analysts get typologies drawn from your own closed cases and your own chains. Senior management gets governance and personal exposure. Board members get enough to challenge what they are shown. Training records that log content and role, not just attendance. And at least one internal case study a year built from something that actually happened at your firm.
Gap 8: The Documentation Mismatch, in Both Directions
The last gap is the one that turns manageable findings into serious ones, and it runs two ways.
In one direction, the procedure describes a control nobody performs — a quarterly review that stopped happening in 2024, a second-line check that was dropped when someone left. That reads to a supervisor as a control failure plus a governance failure, because nobody noticed.
In the other, the control is performed diligently and never evidenced. The analyst genuinely checked three things; the file records none of them. Unevidenced work is, for review purposes, indistinguishable from work not done, and arguing otherwise during an inspection is a losing position.
What good looks like: a periodic walkthrough where the person who performs each control reads the procedure describing it and confirms line by line that this is what they do. Version-controlled documents with owners and review dates. Case file templates that capture the reasoning, not just the outcome. Where a control has lapsed, a dated record of the decision and the compensating measure — a documented, remediated gap is a far better finding than a live undisclosed one.
A Realistic Sequence
You cannot fix all eight at once, and firms that try tend to produce a lot of new documents and very little changed behaviour. In our experience the order that works is: risk assessment first, because everything else should trace back to it; then monitoring coverage and alert backlog, because those are the ones a supervisor can quantify in an afternoon; then Travel Rule exception handling and sanctions testing; then analytics thresholds, training and documentation, which are cheaper to close once the substance underneath is right.
Two honest caveats. First, an independent audit is not regulatory approval. We are not a regulator and cannot bind one. An audit is an opinion on the controls tested, on the evidence seen, at the time it was seen. CySEC, MOKAS and any other authority reach their own conclusions and may weigh things differently. Second, your obligations continue in full regardless — between reviews, after a clean report, and in every period outside the sample. Sampling means an unqualified report is evidence that a competent independent party tested the framework and set out what it found. It is not proof that nothing was missed.
The reason to do any of this early is unglamorous but real. A gap you find yourself is a remediation plan. The same gap found during supervision is a finding, with a timetable you did not set. The FATF standards on virtual assets that sit underneath the EU framework have not moved much in substance; what has moved is how closely anyone is checking.
How Ondology Labs can help: We run independent AML compliance audits for crypto exchanges, CASPs, custodians and payment firms in Cyprus and across the EU — testing the controls you actually operate, on real case files, with on-chain exposure verified independently. Findings come ranked and evidenced, with a remediation plan you can sequence.
Related reading: MiCA's closing transition window · The EU privacy token ban and what it signals for Cyprus.