Risk assessment
Platform-specific money laundering and proliferation financing risk.
A platform AML/CFT and Travel Rule review is an independent check of a crowdfunding or digital asset platform's anti-money laundering and sanctions programme against the SC guidelines. Online investor onboarding, issuer funds flows and digital asset transfers create money laundering risks that bank-style AML programmes miss. We review your platform's programme against the SC guidelines and the Travel Rule for digital asset transfers.
An independent review of a platform's AML/CFT and targeted financial sanctions programme: risk assessment, customer and issuer due diligence, monitoring, digital asset transfer information, screening and reporting.
The SC's AML/CFT/CPF guidelines were revised on 13 June 2024 with specific obligations for digital asset transactions and proliferation financing. Platforms onboard many investors remotely, move issuer funds, and for token offerings handle wallet transfers. These are the areas where platform programmes most often fall short.
Platform-specific money laundering and proliferation financing risk.
Remote onboarding and ongoing monitoring.
Issuers, directors and beneficial owners.
Travel Rule information and wallet screening.
Investors, issuers and wallets.
Suspicious transaction reports and record keeping.
Built for platforms, not banks.
Digital asset duties covered.
Evidence the SC will ask for.
Owners and dates.
For the board and compliance officer.
Models and period.
Policies, procedures and systems.
Sample onboarding, transfers and alerts.
Against SC guidelines.
Findings and remediation.
Findings ranked by risk.
Strengths and gaps.
Onboarding, transfers, alerts.
Owners and dates.
Position for directors.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Yes. It focuses on the risks that bank-style programmes miss on platforms: remote onboarding of many investors, issuer fund flows, and for token offerings, digital asset transfers to and from wallets. The review tests the controls around those flows rather than a branch-based model.
The Travel Rule is the requirement to obtain and pass on originator and beneficiary information with digital asset transfers, reflected in the SC's AML/CFT/CPF guidelines as revised on 13 June 2024. For token platforms, it is often the least mature part of the programme.
We test how your screening is used and configured within the AML programme, including when screening happens and how alerts are handled. For a deeper test of list currency, matching and alert adjudication, our Sanctions Screening Review covers screening on its own.
At least annually, and after significant changes to your products, your platform model or the regulation. A new token offering, a new payment route or a guideline revision each changes the risk the programme was designed for.
Yes. We help you prepare the evidence an examiner is likely to ask for, and if findings are raised, we help build and evidence the remediation so your response shows the controls working in practice.