[codicts-css-switcher id=”346″]

Global Law Experts Logo
aml for crypto companies liechtenstein

How to Build an AML Programme for Crypto Companies in Liechtenstein (2026): Risk Assessment, KYC & FMA Expectations

By Global Law Experts
– posted 1 hour ago

Who this is for: Founders, CEOs, MLROs and compliance leads at VASPs, TT service providers and token-economy businesses operating in, or relocating to, Liechtenstein.

Outcome: A practical AML programme blueprint aligned to Liechtenstein law and Financial Market Authority (FMA) expectations, covering risk assessment, KYC, transaction monitoring and reporting.

Introduction, why 2026 matters for AML in Liechtenstein

AML for crypto companies Liechtenstein has moved from a licensing formality to a live supervisory priority. For 2026, Liechtenstein compliance teams should expect a heightened, evidence-led supervisory focus, with the compliance quality of AML/CFT frameworks increasingly assessed against effectiveness rather than form. For any virtual asset service provider operating in Liechtenstein, this shift means that a well-drafted policy binder is no longer enough, the FMA and, where applicable, external reviewers now expect demonstrable, documented evidence that controls actually work in practice. This guide sets out a step-by-step AML programme for crypto and token-economy businesses subject to the Liechtenstein Due Diligence Act (Sorgfaltspflichtgesetz, SPG), showing what to build, how to score risk, and how to prepare for review.

The scope covers token service providers under the Token and Trusted Technology Service Providers Act (TVTG) and other virtual asset service providers (VASPs). Read it as an operational roadmap rather than a summary, each section maps to a component the FMA will expect to see.

Below, we move from the legal framework through risk assessment, KYC and customer due diligence, transaction monitoring, sanctions screening and governance, and finish with a concrete 12-week readiness plan. Wherever an obligation is stated, verify the exact statutory article or FMA guidance passage before relying on it, because supervisory expectations evolve and the primary sources govern.

Liechtenstein AML requirements, legal & supervisory framework

Understanding the Liechtenstein AML requirements begins with the primary legislation and the role of the supervisor. Crypto businesses established in Liechtenstein sit within the same anti-money laundering and counter-terrorist financing (AML/CFT) architecture that governs banks, fiduciaries and payment institutions, but with additional risk factors specific to virtual assets. The framework is shaped by domestic statute, FMA supervisory practice, EEA-transposed European standards, and the international recommendations of the Financial Action Task Force (FATF).

Primary legislation & regulations

The core domestic instrument is the Liechtenstein Due Diligence Act (Sorgfaltspflichtgesetz, SPG) together with its implementing Due Diligence Ordinance (Sorgfaltspflichtverordnung, SPV). These instruments set out the obligated persons, the requirement to conduct customer due diligence, ongoing monitoring, record-keeping, the appointment of responsible officers, and the duty to report suspicious activity. Activities involving tokens are additionally governed by the Token and Trusted Technology Service Providers Act (TVTG). The consolidated statutory texts are published on the Liechtenstein legal database (Gesetze. li). Because Liechtenstein is an EEA member, its AML regime also reflects the European Union’s anti-money laundering directives as transposed into national law.

Crypto firms providing cross-border services into or from other EEA states should treat the EU AML framework as directly relevant to their obligations.

FMA guidance and supervisory expectations for aml for crypto companies liechtenstein

The FMA is the competent supervisory authority for AML/CFT in the financial sector, including virtual asset activity. It publishes guidance, expects a documented risk-based approach, and conducts supervision that increasingly emphasises effectiveness over form. Firms must be able to show sample files, monitoring outputs, escalation records and remediation logs, not merely policies. Liechtenstein’s AML/CFT framework is also periodically peer-reviewed by the Council of Europe’s MONEYVAL committee, whose assessment reports and typologies inform national supervisory priorities. Reading MONEYVAL findings alongside FMA guidance helps a compliance team anticipate where scrutiny will fall.

So, in direct answer to a common question, what are the AML requirements in Liechtenstein for crypto companies?, the essentials are: register or license as required, maintain a written risk-based AML programme, perform customer due diligence and beneficial ownership checks, monitor transactions on an ongoing basis, screen against sanctions lists, appoint a suitably qualified responsible officer, retain records, and file suspicious activity reports to the competent authority. Each of these is expanded below.

Who is in scope: VASPs and TT service providers

A virtual asset service provider in Liechtenstein is, in practice, any business that conducts virtual-asset activities on a professional basis. The precise categorisation depends on the activity and the applicable licensing or registration regime, but the AML obligations follow the function rather than the label. If your business touches customer funds, converts between fiat and crypto, or transfers value on behalf of others, assume you are in scope until legal analysis confirms otherwise.

Examples of in-scope activities

  • Exchange services. Converting between virtual assets and fiat currency, or between one virtual asset and another.
  • Custody and administration. Safekeeping or administering virtual assets or the private keys that control them on behalf of clients.
  • Transfer services. Moving virtual assets from one address or account to another on a customer’s instruction.
  • Token issuance and placement. Issuing, offering or placing tokens, including activities under the Liechtenstein TVTG.
  • Brokerage and order execution. Arranging or executing transactions in virtual assets for customers.

Firms that combine several of these functions face aggregated risk and should map each activity to a discrete set of controls. The registration and licensing signals, the need to notify or register with the FMA, appoint responsible persons and evidence fit-and-proper standards, are strong indicators that full AML obligations apply.

Risk assessment: building a crypto-specific AML risk matrix (aml risk assessment liechtenstein)

The AML risk assessment is the foundation of the entire programme. Every downstream control, the intensity of KYC, the monitoring thresholds, the frequency of review, should flow from a documented, defensible risk assessment. For virtual asset businesses the assessment must be crypto-specific: generic banking risk models understate the exposures created by pseudonymity, cross-chain movement and rapid settlement.

A step-by-step risk assessment methodology

  1. Define the risk universe. List every product, service, customer type, delivery channel, geography and asset class you handle.
  2. Identify inherent risk factors. For each item, capture the drivers that raise inherent risk before controls are applied.
  3. Score inherent risk. Apply a consistent scale (for example 1–5) to likelihood and impact, and combine them into an inherent score.
  4. Map mitigating controls. Record the specific control that addresses each risk, KYC depth, monitoring rules, screening cadence.
  5. Calculate residual risk. Adjust the inherent score for control strength to reach a residual rating.
  6. Set the risk appetite and escalation triggers. Define which residual ratings require senior sign-off or refusal.
  7. Review and re-run. Refresh at least annually and on any material change to products, customers or the threat environment.

Client-level, product-level and institutional risk

A robust methodology separates three layers. Client-level risk looks at the individual customer, jurisdiction, occupation, source of wealth, transaction profile. Product-level risk examines the intrinsic exposure of a service, such as anonymity-enhanced coins or peer-to-peer transfers. Institutional (enterprise-wide) risk aggregates the firm’s overall exposure to inform governance and resourcing. The FMA expects to see all three, coherently linked.

Red flags and typologies

  • Deposits from mixers, tumblers or known high-risk services.
  • Use of privacy coins or chain-hopping to obscure fund origin.
  • Structuring, many small transactions below apparent thresholds.
  • Rapid in-and-out movement with no economic rationale.
  • Customer reluctance to provide source-of-funds evidence.
  • Wallet addresses linked to darknet marketplaces or sanctioned entities.

Sample risk-scoring matrix

Risk factor Example Inherent score (1–5) Typical control Residual
Customer geography High-risk / sanctioned nexus 5 EDD + senior sign-off 3
Asset type Privacy coin 5 Enhanced monitoring / restriction 3
Delivery channel Fully remote onboarding 4 Liveness + document verification 2
Product Fiat on/off ramp 4 Source-of-funds checks 2
Customer type Regulated institution 2 Standard CDD 1

Keep the scoring logic, weightings and rationale documented. When a reviewer asks why a customer was rated medium rather than high, the answer must be traceable to the matrix, not to individual judgement recalled after the fact.

KYC & Customer Due Diligence (CDD) for virtual assets

KYC for Liechtenstein crypto customers is where policy meets daily operations. Customer due diligence in Liechtenstein must be risk-based, identify and verify the customer and any beneficial owner, establish the purpose and intended nature of the relationship, and be maintained through ongoing monitoring. For virtual asset businesses the challenge is applying these requirements to remote, high-velocity, cross-border relationships.

CDD levels: standard, simplified and enhanced

Liechtenstein customer due diligence operates on a tiered basis calibrated to risk:

  • Standard CDD. Verify identity from reliable, independent documents or electronic data; identify the beneficial owner; establish the purpose of the relationship; and monitor on an ongoing basis. For a retail crypto customer this typically means government ID verification, a liveness check, address confirmation and a baseline expected-activity profile.
  • Simplified CDD. Permitted only in narrowly defined lower-risk situations and subject to strict criteria. Given the inherent risk profile of virtual assets, simplified measures are rarely appropriate for crypto onboarding and should never be a default; document any reliance carefully.
  • Enhanced due diligence (EDD). Required for higher-risk customers, politically exposed persons, high-risk jurisdictions, unusual transaction patterns or opaque ownership. EDD adds source-of-funds and source-of-wealth verification, senior management approval, and intensified ongoing monitoring.

A practical KYC checklist for virtual asset onboarding

  1. Verify identity: full name, date of birth, nationality, and a verified government-issued document.
  2. Confirm liveness and match the person to the document via biometric or video checks for remote onboarding.
  3. Identify and verify beneficial owners for corporate customers, tracing the ownership chain.
  4. Establish the purpose and intended nature of the relationship.
  5. Capture and, where risk requires, verify source of funds and source of wealth.
  6. Screen the customer and connected parties against sanctions and PEP lists.
  7. Assign a customer risk rating and set the corresponding monitoring parameters.
  8. Record wallet addresses provided and assess them with on-chain analytics before first transaction.

On the recurring question of ongoing monitoring, what KYC and ongoing monitoring does Liechtenstein expect for virtual asset customers?, the answer is that KYC is not a one-off event. The FMA expects continuous review: keeping data current, refreshing risk ratings, monitoring transactions against the expected profile, and escalating deviations. Remote onboarding controls, identity-proofing and periodic re-verification are all part of a defensible programme.

Transaction monitoring, sanctions screening & suspicious activity reporting

Transaction monitoring for crypto firms in Liechtenstein must span both the off-chain (fiat, account) and on-chain (blockchain) dimensions. This is the operational heart of AML for crypto companies Liechtenstein, because it is where suspicious activity is actually detected. Supervisors and reviewers look for evidence that alerts are generated, triaged, investigated and, where warranted, reported, with a clear audit trail throughout.

On-chain analytics & blockchain forensic tools

Effective monitoring of virtual asset flows requires capabilities that traditional rules engines lack:

  • Wallet clustering. Grouping addresses controlled by the same entity to reveal true counterparties.
  • Address risk scoring. Scoring incoming and outgoing addresses against known exposures, mixers, darknet markets, sanctioned wallets.
  • Transaction tracing. Following funds across hops and, where possible, across chains.
  • Typology detection. Flagging patterns such as peel chains, layering and rapid pass-through activity.
  • Alert triage and case management. Documented workflows that record who reviewed an alert, what was decided and why.

Sanctions screening in Liechtenstein: lists and cadence

Sanctions screening in Liechtenstein must be both at onboarding and ongoing. Screen customers, beneficial owners and, where feasible, counterparties and wallet addresses against the consolidated sanctions lists relevant to Liechtenstein. Best practice, and the FMA’s expectation for larger providers, is continuous screening combining batch re-screening of the customer base against updated lists with real-time screening of new relationships and, ideally, of virtual asset counterparties. Every hit needs a documented disposition and clear escalation path. False-positive management should be recorded, not just resolved informally.

Suspicious activity reporting

When a firm knows or suspects, or has reasonable grounds to suspect, that funds are the proceeds of crime or connected to terrorist financing, it must file a report to the competent authority without delay, and refrain from tipping off the customer. In Liechtenstein, such reports are directed to the Financial Intelligence Unit (Stabsstelle FIU); confirm the current filing channel and format via FMA and FIU guidance before submitting. Practical tips: file promptly once suspicion crystallises, retain the underlying evidence, document the internal decision to report (or not to report), and never delay a transaction beyond what the law permits without appropriate authorisation.

Internal controls, governance and MLRO responsibilities

A programme is only as strong as the governance around it. The FMA expects clear accountability, adequate resourcing, staff competence and independent oversight, proportionate to the size and risk profile of the firm.

Does the FMA require an approved MLRO?

Liechtenstein firms must appoint a suitably qualified individual responsible for AML/CFT, typically referred to as the money laundering reporting officer (MLRO) or the responsible officer for due diligence. In answer to the frequent question, do crypto businesses in Liechtenstein need an FMA-approved compliance officer/MLRO? , the person must meet fit-and-proper and suitability standards, be available, have sufficient seniority and authority, and be notified to the supervisor as part of the firm’s governance arrangements. Whether a formal approval or registration step applies depends on the licence or registration category and current FMA practice, so confirm the exact notification and approval requirements against FMA guidance before appointment.

To appoint: document the role, verify qualifications and independence, secure board approval, and notify the FMA as required.

Core governance components

  • Senior accountability. A named senior officer accountable for AML/CFT effectiveness, with board-level visibility.
  • Written policies and procedures. Approved, versioned and reviewed at least annually.
  • Training. Role-appropriate AML training on induction and periodically, with attendance records.
  • Record-keeping. Retention of CDD records, transaction data and reports for the statutory retention period; confirm the applicable duration under the SPG/SPV.
  • Independent testing. Periodic independent review of the programme’s design and effectiveness, with findings tracked to closure.

Sample roles & responsibilities matrix

Function Primary responsibility Escalates to
Board / senior management Approve risk appetite, resource the programme ,
MLRO / responsible officer Own the AML programme, file reports, advise the business Board
Onboarding / KYC team Perform CDD, escalate high-risk cases MLRO
Monitoring analysts Triage alerts, investigate, document decisions MLRO
Independent testing / audit Assess effectiveness, log findings Board

Preparing for evidence-led compliance quality review

A distinguishing feature of current supervision is external, evidence-led review. In direct answer to the question, how are AML programmes in Liechtenstein assessed or audited?, reviewers examine whether controls are not just documented but operating effectively, sampling real files and testing outcomes. The single most valuable preparation is assembling an organised, current documentation pack that lets a reviewer verify each obligation quickly. Regulatory triggers of this kind sit alongside other compliance obligations for firms in the jurisdiction; for related context on when specialist advice becomes necessary, see the guide on when to hire a tax lawyer in Liechtenstein.

A 12-week pre-review readiness plan

  1. Weeks 1–2: Confirm scope and refresh the enterprise-wide risk assessment; document methodology and results.
  2. Weeks 3–4: Review and version-control all policies and procedures; close any gaps against current FMA guidance.
  3. Weeks 5–6: Pull a sample of CDD files across risk tiers and remediate deficiencies; evidence beneficial ownership and source-of-funds where required.
  4. Weeks 7–8: Test transaction monitoring, review alert generation, triage records and investigation quality; confirm on-chain analytics coverage.
  5. Weeks 9–10: Verify sanctions screening cadence, hit disposition logs and escalation trails; confirm list currency.
  6. Week 11: Compile management evidence, training records, governance minutes, MLRO reports and the remediation register.
  7. Week 12: Run a mock review or independent test; log findings and assign owners and deadlines for closure.

Review documentation pack, sample checklist

  • Current enterprise-wide risk assessment and methodology.
  • Approved AML/CFT policies and procedures with version history.
  • Sample CDD and EDD files across risk ratings.
  • Transaction monitoring rules, alert logs and investigation records.
  • Sanctions screening configuration and disposition evidence.
  • Report register and internal decision records.
  • Training records and staff competency evidence.
  • Independent testing reports and a live remediation register.

Comparison table: minimum controls vs FMA expected standards

Control area Minimum controls (small VASP) FMA expected standard (evidence-led review)
Governance Named compliance contact, basic policy Senior accountable officer, documented governance with independent oversight
KYC ID + basic onboarding checks Risk-based ID + source of funds + proof of purpose + beneficial owner verification
Monitoring Manual review of large transactions Automated transaction monitoring + on-chain analytics + alert triage
Sanctions List screening at onboarding Continuous screening + batch and real-time coverage + escalation
Independent testing Internal spot checks Independent quality review with remediation logs (evidence)

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Julia von der Osten at VON DER OSTEN Legal, a member of the Global Law Experts network.

Practical templates & resources

To operationalise the programme, prepare a core set of documents. Each should carry a short usage note and be tailored to Liechtenstein law before use:

  • AML policy. The master document setting out the firm’s risk-based approach and obligations.
  • CDD checklist. A step-by-step onboarding checklist for standard, simplified and enhanced due diligence.
  • Risk assessment template. A structured matrix with scoring logic for inherent and residual risk.
  • Reporting checklist. Triggers, decision record and filing steps to the competent authority.
  • MLRO job description. Qualifications, responsibilities, reporting lines and authority.

Treat these as living documents. Version them, review them on a set cadence, and retain superseded versions so that reviewers can see how the programme has evolved.

Conclusion & next steps

Building effective AML for crypto companies Liechtenstein is now a demonstrable, evidence-led discipline rather than a documentary exercise. Current supervision rewards firms that can show a coherent chain, from a crypto-specific risk assessment, through risk-based KYC and enhanced due diligence, into on-chain and off-chain transaction monitoring, continuous sanctions screening and prompt suspicious activity reporting, all underpinned by clear governance and independent testing. The practical priorities are straightforward: refresh your risk assessment, tighten your documentation pack, test your monitoring in practice, and run a mock review before the real one. Firms that treat compliance as a genuine effectiveness review, not a form-filling exercise, will be best placed to satisfy the FMA and to operate with confidence. To review your AML programme against Liechtenstein law and FMA expectations, or to prepare for external review, consult a Liechtenstein regulatory compliance specialist.

Sources

  1. Financial Market Authority (Liechtenstein), FMA
  2. National Administration of Liechtenstein (LLV)
  3. Gesetze.li, Liechtenstein Legal Database
  4. Financial Action Task Force (FATF)
  5. Council of Europe, MONEYVAL
  6. European Commission, Anti-Money Laundering
  7. University of Liechtenstein

FAQs

What are the AML requirements in Liechtenstein for crypto companies?
Crypto businesses must maintain a written, risk-based AML programme under the Liechtenstein Due Diligence Act (SPG) and its ordinance (SPV), supervised by the FMA, with token activities also governed by the TVTG. Core duties include customer due diligence and beneficial ownership checks, ongoing transaction monitoring, sanctions screening, appointment of a suitably qualified responsible officer, record-keeping, and filing suspicious activity reports to the competent authority.
Firms must appoint a suitably qualified, available and senior individual to lead AML/CFT and file reports. This person must meet fit-and-proper standards and be notified to the FMA as part of the firm’s governance. Whether a formal approval or registration step applies depends on the licence or registration category and current FMA practice, so confirm the exact requirement against FMA guidance before appointing.
At minimum, verified identity documents, beneficial ownership for corporate customers, the purpose of the relationship, and, where risk requires, source of funds and source of wealth. Screen customers against sanctions and PEP lists, assess provided wallet addresses with on-chain analytics, and apply enhanced due diligence to higher-risk relationships.
Assemble a current documentation pack: enterprise-wide risk assessment, versioned policies, sample CDD and EDD files, transaction monitoring alert and investigation records, sanctions screening evidence, a reports register, training records, and independent testing findings with a live remediation register. A 12-week readiness plan culminating in a mock review is a practical approach.
File without delay once you know or suspect, or have reasonable grounds to suspect, that funds are proceeds of crime or linked to terrorist financing. In Liechtenstein, reports go to the Financial Intelligence Unit (Stabsstelle FIU); confirm the current channel and format via FMA and FIU guidance. Do not tip off the customer, and retain the evidence and internal decision record.
Look for wallet clustering, address risk scoring, transaction tracing across hops and chains, typology detection, and documented alert triage with case management. These capabilities allow a firm to detect exposures, mixers, sanctioned wallets, darknet links, that traditional rules engines miss, which is central to effective AML for crypto companies Liechtenstein.
Simplified customer due diligence is permitted only in narrowly defined lower-risk situations under strict criteria. Given the inherent risk profile of virtual assets, simplified measures are rarely appropriate for crypto onboarding and should not be a default. Where risk is elevated, apply enhanced due diligence and document the rationale.
property transfer fees cyprus
By Global Law Experts

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Build an AML Programme for Crypto Companies in Liechtenstein (2026): Risk Assessment, KYC & FMA Expectations

Send welcome message

Custom Message