Capital Markets / AML

Platform AML/CFT and Travel Rule Review

A platform AML/CFT and Travel Rule review is an independent check of a crowdfunding or digital asset platform's anti-money laundering and sanctions programme against the SC guidelines. Online investor onboarding, issuer funds flows and digital asset transfers create money laundering risks that bank-style AML programmes miss. We review your platform's programme against the SC guidelines and the Travel Rule for digital asset transfers.

Against the SC AML/CFT/CPF guidelines revised 13 June 2024 Investor, issuer and wallet risk Travel Rule and sanctions screening tested
Overview

Platform AML/CFT and Travel Rule Review

What it is

An independent review of a platform's AML/CFT and targeted financial sanctions programme: risk assessment, customer and issuer due diligence, monitoring, digital asset transfer information, screening and reporting.

Why organisations need it

The SC's AML/CFT/CPF guidelines were revised on 13 June 2024 with specific obligations for digital asset transactions and proliferation financing. Platforms onboard many investors remotely, move issuer funds, and for token offerings handle wallet transfers. These are the areas where platform programmes most often fall short.

Key features

What the engagement covers

Risk assessment

Platform-specific money laundering and proliferation financing risk.

Investor due diligence

Remote onboarding and ongoing monitoring.

Issuer due diligence

Issuers, directors and beneficial owners.

Digital asset transfers

Travel Rule information and wallet screening.

Sanctions screening

Investors, issuers and wallets.

Reporting and records

Suspicious transaction reports and record keeping.

Business value

What the business gets out of it

Platform-specific

Built for platforms, not banks.

Travel Rule tested

Digital asset duties covered.

Examination ready

Evidence the SC will ask for.

Clear remediation

Owners and dates.

Independent view

For the board and compliance officer.

How it works

How the engagement runs

01

Scoping

Models and period.

02

Review

Policies, procedures and systems.

03

Testing

Sample onboarding, transfers and alerts.

04

Gap analysis

Against SC guidelines.

05

Report

Findings and remediation.

Deliverables

What you receive

AML review report

Findings ranked by risk.

Risk assessment review

Strengths and gaps.

Sample test results

Onboarding, transfers, alerts.

Remediation plan

Owners and dates.

Board summary

Position for directors.

Who it is for

Who this is built for

Industries

Equity crowdfunding platformsP2P platformsToken crowdfunding platformsDigital asset exchanges

Company sizes

Registered platform operators

Departments

ComplianceAMLOperationsBoard
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is this different from a bank AML review?

Yes. It focuses on the risks that bank-style programmes miss on platforms: remote onboarding of many investors, issuer fund flows, and for token offerings, digital asset transfers to and from wallets. The review tests the controls around those flows rather than a branch-based model.

What is the Travel Rule?

The Travel Rule is the requirement to obtain and pass on originator and beneficiary information with digital asset transfers, reflected in the SC's AML/CFT/CPF guidelines as revised on 13 June 2024. For token platforms, it is often the least mature part of the programme.

Do you test our screening system?

We test how your screening is used and configured within the AML programme, including when screening happens and how alerts are handled. For a deeper test of list currency, matching and alert adjudication, our Sanctions Screening Review covers screening on its own.

How often should we review?

At least annually, and after significant changes to your products, your platform model or the regulation. A new token offering, a new payment route or a guideline revision each changes the risk the programme was designed for.

Can you help with an SC examination?

Yes. We help you prepare the evidence an examiner is likely to ask for, and if findings are raised, we help build and evidence the remediation so your response shows the controls working in practice.