AML & Compliance Audits in Cyprus

    Crypto AML compliance audits in Cyprus

    We test the controls you actually run.

    Independent AML audits for crypto exchanges, CASPs, custodians, payment firms, and funds in Cyprus and across the EU. We review KYC and onboarding, transaction monitoring, sanctions screening, wallet risk exposure, and Travel Rule handling against CySEC supervision, MiCA, and the EU AML package — then tell you plainly what needs fixing.

    Written Controls Versus Operating Controls

    Most firms we review have a policy manual. Fewer can show that what the manual says is what the case files record. An audit is the difference between the two.

    What we read

    The business-wide risk assessment, AML policies and procedures, the compliance officer's terms of reference, training records, board and committee minutes, and the vendor documentation behind your screening and monitoring stack. We check whether these describe your business or someone else's template.

    What we test

    Samples of real customer files, monitoring alerts and how they were closed, screening hits and their disposition, Travel Rule transfers including the ones that failed, and internal reports. We also screen and trace a sample of wallets on-chain ourselves rather than relying only on your dashboard.

    What an AML Audit Covers

    Six control areas, tested against the obligations that apply to your permissions and your product set rather than a generic checklist.

    KYC, CDD & onboarding

    Identification and verification, beneficial ownership, source of funds and wealth, enhanced due diligence triggers, and whether the risk rating assigned at onboarding is actually driven by the evidence collected.

    Transaction monitoring

    Rule coverage against your real product and customer risk, threshold calibration, alert volumes, disposition quality, escalation, and whether tuning decisions are documented and approved.

    Sanctions & PEP screening

    List coverage and refresh frequency, fuzzy matching settings, false positive handling, rescreening of the existing book, and screening of counterparties rather than customers alone.

    Wallet risk & blockchain analytics

    Which analytics provider is used, how risk scores drive decisions, escalation thresholds, and independent sampling of exposure on-chain to see whether the tooling output matches reality.

    Travel Rule & TFR compliance

    Collection and transmission of originator and beneficiary data, counterparty due diligence, self-hosted wallet handling, and what happens when required information is missing or unanswered.

    Reporting, records & governance

    Suspicious transaction reporting to MOKAS, internal escalation to the compliance officer, record retention, staff training, the business-wide risk assessment, and board and senior management oversight.

    Who We Audit

    Obliged entities under Cyprus AML law, firms preparing for supervision, and businesses whose banking or acquiring relationships depend on showing independent assurance.

    Exchanges & trading platforms

    High onboarding volume and fast-moving flows put the most pressure on monitoring rules and alert handling. We test whether the controls scale with the book rather than only with the policy.

    CASPs authorised or applying in Cyprus

    Whether you hold a CySEC authorisation or are preparing the application, the AML framework is assessed as part of the firm. We review it against what a supervisor will look for.

    Custodians & wallet providers

    Client asset safeguarding sits next to AML obligations. We look at onboarding, source of funds, and the screening applied to deposits and withdrawals from self-hosted wallets.

    Payment & e-money firms handling crypto

    Crypto rails bolted onto an existing payments business often inherit a framework designed for fiat. We identify where the old controls do not reach the new flows.

    Funds & asset managers

    Investor due diligence, source of wealth, and the provenance of subscribed assets. Administrators and depositaries increasingly expect independent evidence rather than assertion.

    Crypto-native businesses & token issuers

    Firms that grew before the framework did. We help establish a defensible baseline and a realistic sequence for closing the gap, without pretending it can be done in a week.

    How the Engagement Works

    Scope agreed in writing first, testing on real files second, findings ranked so you can sequence the work rather than face an undifferentiated list.

    01

    Scoping & risk assessment review

    We agree which entities, products, and jurisdictions are in scope, and start from your business-wide risk assessment. If it does not reflect the business you actually run, that is the first finding.

    02

    Policy & framework review

    Policies, procedures, and the compliance officer function are read against the obligations that apply to you. We note where documents are current, where they are inherited boilerplate, and where they contradict each other.

    03

    Control testing on real files

    We sample customer files, alerts, screening hits, Travel Rule transfers, and reports. Written controls are compared with what the case files show was actually done.

    04

    On-chain exposure testing

    We independently screen a sample of wallets and flows against risk data and trace them ourselves, so exposure is measured against the chain rather than against your dashboard.

    05

    Report & remediation plan

    A written report with findings ranked by severity, the evidence behind each one, and a sequenced remediation plan. We can re-test after you have implemented the fixes.

    What an Audit Does and Doesn't Cover

    An AML audit is a point-in-time review of controls. It is useful precisely because it is bounded, and we state those bounds in the report rather than leaving them implied.

    It does cover

    • Whether the controls you documented were operating on the files we sampled
    • Where your framework diverges from CySEC, MiCA, and EU AML obligations
    • Whether monitoring and screening settings match your real customer and product risk
    • On-chain exposure measured independently rather than taken from your tooling
    • A ranked, evidenced set of findings with a sequenced remediation plan

    It does not cover

    • Any guarantee of regulatory approval — we are not a regulator and cannot bind one
    • Your ongoing obligations, which continue in full between and after reviews
    • Suspicious transaction reporting, which remains yours to decide and file with MOKAS
    • Remediation itself, which your team or your vendors implement, not us
    • Transactions or periods outside the agreed scope and sample

    Sampling means an unqualified report is not proof that nothing was missed. It is evidence that a competent independent party tested the framework and set out what it found.

    The Cyprus and EU Rulebook

    Crypto-asset service providers in Cyprus are supervised by CySEC and are obliged entities under the Cyprus AML law implementing the EU directives. MiCA brought CASPs into a harmonised authorisation regime, so the AML framework is now assessed as part of a supervised firm rather than as a voluntary standard.

    The EU AML package layers on top of that. A directly applicable AML Regulation replaces much of the national discretion firms have relied on, and the new EU authority, AMLA, will drive common supervisory expectations across member states. The Transfer of Funds Regulation applies the Travel Rule to crypto transfers with no de minimis threshold, so originator and beneficiary information has to travel with the transfer. Suspicious transaction reports go to MOKAS, the Cyprus financial intelligence unit, and the quality of that reporting is itself something a supervisor will look at.

    We test against this framework as it applies to your permissions. Where a requirement is still bedding in or the supervisory expectation is not yet settled, we say so instead of presenting an interpretation as settled law.

    Read our note on the MiCA transition window

    AML Compliance Audit FAQ

    What is an AML compliance audit for a crypto business?

    It is an independent review of the anti-money-laundering controls you actually operate, tested against the obligations that apply to you. We look at customer due diligence and onboarding, ongoing monitoring, transaction monitoring rules, sanctions and PEP screening, blockchain analytics screening of wallet exposure, Travel Rule handling, suspicious transaction reporting, record-keeping, training, and the compliance officer function. The output is a written report with findings ranked by severity and a remediation plan you can work through.

    Who needs one in Cyprus?

    Crypto-asset service providers supervised by CySEC, firms preparing an authorisation application, and any obliged entity whose AML framework has to withstand supervisory review. It is also common for firms whose banking partner, payment processor, or acquirer asks for independent assurance before opening or keeping an account. Cyprus AML law, implementing the EU directives, requires obliged entities to maintain an independent audit function to test their AML policies and controls where that is appropriate to the size and nature of the business — and for smaller firms, outsourcing that review is usually the practical route. Whether it applies to you specifically is a question for your own counsel.

    Is passing your audit a regulatory approval?

    No. We are not a regulator and we cannot bind one. An audit is an independent opinion on the controls we tested, on the evidence we saw, at the time we saw it. CySEC, MOKAS, and any other authority reach their own conclusions and may weigh things differently. What an audit gives you is a documented, independent view of where you stand and what to fix, which is materially better than discovering both during an inspection.

    How do MiCA and the EU AML package change what you review?

    MiCA brought crypto-asset service providers into a harmonised authorisation regime, so the AML framework is now assessed as part of a supervised firm rather than a voluntary standard. Separately, the EU AML package introduces a directly applicable AML Regulation and the new EU authority AMLA, which narrows national discretion and raises expectations on risk assessment, beneficial ownership, and group-wide policies. The Transfer of Funds Regulation applies the Travel Rule to crypto transfers with no de minimis threshold. In practice this means we test against a rulebook that is converging across the EU rather than a purely Cypriot one.

    What does Travel Rule testing actually involve?

    We check whether originator and beneficiary information is collected, transmitted, and received in the required form on every in-scope transfer, not just the ones your provider happens to cover. That includes how you handle counterparties who do not respond, transfers to and from self-hosted wallets, the due diligence you perform on other providers before exchanging data, and what happens to a transfer when required information is missing. Most gaps we find are in the exception handling rather than the happy path.

    Do you tune our transaction monitoring rules?

    We test them and tell you what we find. That means reviewing whether the rule set reflects your actual customer base and product risk, sampling alerts to check the thresholds are producing meaningful output rather than noise, and looking at how alerts are dispositioned and escalated. A monitoring system generating thousands of alerts nobody closes is a finding, not a control. We recommend changes; implementing and validating them is work your team or your vendor performs.

    How does blockchain analytics fit into the review?

    Screening addresses and counterparties against risk data is now an expected control, and it is one we can test on the chain itself rather than only on paper. We review which provider you use, how risk scores feed into your decisions, what thresholds trigger escalation, and whether exposure is reassessed over time. We also independently sample wallets and flows to see whether the exposure your tooling reports matches what the chain shows.

    What happens if you find serious problems?

    We tell you plainly, in writing, with the evidence. Findings are ranked so you can sequence the work, and we distinguish between a control that is missing, one that exists but is not operating, and one that is operating but is not documented. We do not report to your regulator on your behalf, and we do not make suspicious transaction reports for you. Deciding what to report to MOKAS and when remains your obligation, and remediation is yours to execute.

    How long does an engagement take, and how often should we repeat it?

    For a mid-sized firm, typically a few weeks from scoping to report, depending on how quickly policies, system exports, and case files reach us. Annual is the usual cadence, with a follow-up review after remediation if the first round found material gaps. A review also makes sense ahead of an authorisation application, after a change of business model or major new product, or when onboarding volume grows faster than the compliance function did.

    More questions answered on our general FAQ.

    Find the gaps before a supervisor does

    Tell us your permissions, products, and where you think the weak points are. We will scope the review, agree the sample, and give you a report you can hand to your board.