CRYPTO & DIGITAL ASSETS · REGULATED CRYPTOINS-20221108-01

Why MLRO Hiring Delays Crypto Projects

In regulated crypto, the MLRO is not a name added at the end of an application. Qualified people, fit-and-proper review and real accountability can become the critical path.

Libertax editorial visualization for “Why MLRO Hiring Delays Crypto Projects”
A Libertax editorial composition about Why MLRO Hiring Delays Crypto Projects.

KEY TAKEAWAYS

KEY POINT 01People can sit on the critical path. A qualified MLRO, Compliance Officer or Responsible Individual has to exist, accept the role and satisfy the regulator; a policy template cannot replace that dependency.
KEY POINT 02Role design matters as much as headcount. VARA permits some non-client-facing functions to be combined where conflicts are controlled and fit-and-proper requirements remain satisfied, so the question is accountability, capacity and independence rather than a universal minimum number of employees.
KEY POINT 03AML staffing is not tax reporting or bankability. The MLRO owns an AML/CFT control function; that role does not determine CARF/DAC8 obligations, the company's tax position or whether a bank will onboard the business.

A regulated crypto project can have the entity, capital and application documents ready and still be unable to move on schedule because a required person is missing. The MLRO is a good example of why regulatory staffing is part of the architecture of the business, not an administrative line added after the licence strategy is chosen.

That conclusion should not be turned into a universal claim about every jurisdiction. The exact role, experience, residence and independence requirements differ by regime. Dubai’s current VARA framework provides a concrete example of the mechanism.

Key takeaways

  • People can sit on the critical path. A qualified MLRO, Compliance Officer or Responsible Individual has to exist, accept the role and satisfy the regulator; a policy template cannot replace that dependency.
  • Role design matters as much as headcount. VARA permits some non-client-facing functions to be combined where conflicts are controlled and fit-and-proper requirements remain satisfied, so the question is accountability, capacity and independence rather than a universal minimum number of employees.
  • AML staffing is not tax reporting or bankability. The MLRO owns an AML/CFT control function; that role does not determine CARF/DAC8 obligations, the company’s tax position or whether a bank will onboard the business.

What the 2022 project problem really was

By late 2022, founders were already learning that a crypto licence was not merely a form-filling exercise. A credible application increasingly depended on the people who would actually operate and control the regulated business.

The historical point must be kept honest. VARA had been created in Dubai in 2022, but the complete rulebook architecture that now makes the staffing requirements explicit was not yet available on 8 November 2022. The current rules therefore belong in the what changed since analysis, not in a fictional reconstruction of what an applicant could have read that day.

What was already visible was the operational mechanism: where a regulator expects named people with defined responsibilities, recruitment and approval become dependencies in the licensing timetable.

The MLRO is a function, not a label

Under VARA’s current Compliance and Risk Management Rulebook, a VASP must appoint an MLRO with at least two years of experience handling AML/CFT matters who is also fit and proper. The MLRO’s responsibilities include AML/CFT policies, risk assessments, suspicious-transaction monitoring and reporting, staff and board training, corrective action and quarterly board reporting.

That is materially different from writing “MLRO” on an organisational chart.

The person needs enough knowledge, authority and access to information to perform the role. If transaction monitoring, customer due diligence or sanctions screening produces a problem, the MLRO must be able to investigate it, escalate it and evidence the response.

The operational question is therefore not simply:

Have we appointed an MLRO?

It is:

Can this person perform the control function the business model creates?

The Compliance Officer is another dependency

VARA separately requires a Compliance Officer. Under the current rulebook, that person must have at least five years of relevant compliance experience, be fit and proper, be a UAE resident or UAE passport holder, work full-time for the VASP and report directly to the board.

The distinction matters because founders can otherwise collapse “compliance” into a single generic job title.

The Compliance Officer is responsible for the broader compliance management system, regulatory training, emerging compliance risks, board reporting and corrective action. The MLRO has a specific AML/CFT mandate.

Those functions overlap, but they are not conceptually identical.

One person can sometimes hold more than one role

This is where simplistic staffing tables become dangerous.

VARA expressly allows the Compliance Officer to hold more than one non-client-facing role, including MLRO or head of risk, where the roles do not create conflicting duties and the individual remains fit and proper. The equivalent rule also appears from the MLRO side.

That means a regulated crypto business should not infer that every named function automatically requires a different employee.

It also means the opposite shortcut is unsafe: permission to combine roles is not permission to ignore workload, conflicts or competence.

A small VASP may be able to design a lean control structure. A more complex exchange, custody or institutional business may make the same combination unrealistic even where it is legally possible.

Responsible Individuals add another people layer

VARA’s Company Rulebook requires two Responsible Individuals of sufficient seniority. They must be full-time employees, fit and proper, resident in the UAE or UAE passport holders and approved by VARA during licensing.

Again, this is not a universal template for every crypto jurisdiction. It is a useful demonstration of the underlying principle: the regulator is licensing an operating organisation, not only an incorporated entity.

A founder who designs the structure first and asks who will fill the regulated functions later has reversed the dependency.

Why recruitment delays the project before filing

Hiring for a regulated role has more steps than ordinary recruitment.

The project may need to test experience, conflicts, availability, residence, contractual status and the ability to withstand regulatory scrutiny. The candidate may need to supply evidence. The regulator may ask questions or reject the proposed arrangement. Notice periods and relocation can add further time.

This turns staffing into a critical-path problem:

business model → required functions → candidate profile → evidence → appointment → regulatory approval → operational readiness.

If any earlier step is unresolved, the later steps do not accelerate merely because the legal entity already exists.

The best objection: a consultant can solve this

Sometimes external support is entirely appropriate.

VARA allows certain compliance and AML/CFT activities to be delegated to appropriate professionals, subject to the applicable outsourcing requirements. But the rulebook preserves accountability: the Compliance Officer or MLRO remains responsible for the relevant function.

That is an important distinction between outsourcing work and outsourcing responsibility.

A consultant can provide expertise, systems, testing or additional capacity. The regulated business still needs a governance model showing who owns the decision and who is answerable when a control fails.

Bankability is a separate people test

A bank assessing a crypto business may care about the same people for a different reason.

It may want to understand who controls the company, who owns AML decisions, who can explain transaction monitoring and who is responsible for the expected flows. A strong MLRO or compliance function can therefore improve the credibility of the banking file.

It does not create a right to a bank account.

The bank performs its own due diligence and risk assessment. A regulator’s approval of a person is useful evidence, not a transfer of the bank’s decision.

Tax and reporting sit on another map

The MLRO is not automatically the owner of tax reporting.

AML/CFT asks whether customers, transactions and counterparties create financial-crime risk. CARF and DAC8 ask whether specified crypto-asset information must be collected, reported and exchanged for tax-transparency purposes. Corporate Tax asks who is taxable and on what income.

The data can overlap. The legal duties do not become the same duty.

A regulated firm therefore needs an explicit ownership map for AML, regulatory reporting, accounting, tax and tax-information reporting rather than assuming that “compliance” covers all of them.

What changed since 2022

The current VARA rulebooks make the people dependency far easier to see than it was when the market was still focused on headline licence categories.

Today, a founder can identify concrete requirements for the MLRO, Compliance Officer and Responsible Individuals before building the application timetable. That does not remove recruitment risk. It allows the risk to be planned instead of discovered late.

For EU projects, the same discipline is necessary but the legal analysis must be performed against MiCA together with the applicable AML framework and national implementation. MiCA should not be paraphrased as a universal rule that every CASP must appoint a locally resident MLRO under one identical formula.

The practical consequence

Before quoting a licensing timeline, a crypto project should answer:

  1. Which named regulatory and control functions does this exact activity require?
  2. What experience, fit-and-proper, residence, employment or independence conditions apply?
  3. Which roles may legally and practically be combined?
  4. Which work can be outsourced without outsourcing accountability?
  5. What evidence will the regulator need for each proposed person?
  6. What happens to the launch plan if one critical appointment takes three months longer?

That is not an HR appendix. It is part of the feasibility analysis.

Sources

Disclaimer

This article provides general regulatory and business-planning information. It is not legal, regulatory, AML, tax, banking or employment advice. Staffing, fit-and-proper, residence, outsourcing and governance requirements depend on the exact activity, regulator and jurisdiction and must be verified against the rules in force before appointment or filing.