TK Global OS — Regulatory notesCryptoasset licensing: United Kingdom, Kenya, Brazil

The crypto compliance officer: three regulators, three different jobs

Cross Published 2026-08-30

The same job title, three different legal shapes

Firms licensing in more than one market tend to write one compliance officer job description and reuse it. That works until a reviewer reads it. Kenya names the officer in a regulation and tells you who cannot hold the post. Brazil never names a compliance officer for virtual asset providers at all, but ties the central AML obligations to a responsible director whose approval an independent auditor has to see. The UK does not create a crypto-specific role either, and instead pulls cryptoasset firms into the Senior Managers and Certification Regime in full. Three regimes, three different documents to produce.

Kenya: the regulation names the person, and rules people out

Kenya's detail sits in the Proceeds of Crime and Anti-Money Laundering Regulations 2023 (Legal Notice 153 of 2023), which apply to virtual asset service providers because the VASP Act 2025 amended the definition of reporting institution in POCAMLA (Cap 59A) to include them, with effect from 4 November 2025.

The statutory clocks around the officer are short. A suspicious transaction report goes to the Financial Reporting Centre within two days of the suspicion arising, and attempted transactions count (POCAMLA s.44(2) and (3)). Follow-up questions from the Centre are answered not later than 30 days (s.44(9)). Registration with the Centre and notification of changes in particulars run on their own timetable under s.47A.

One structural point that catches groups: under Legal Notice 134, the gazetted VASP Regulations, the compliance officer is not the only named individual. The gazetted text also requires a chief information security officer. Those are two posts, and a reviewer reading a file where one person holds both will ask about it.

Brazil: no named officer, but a director who has to sign up to the risk assessment

Brazil's authorisation rules do not prescribe a compliance officer for virtual asset providers in the way Kenya does. The obligation surfaces instead through Anexo IV to Normative Instruction BCB 704, added by IN BCB 739 of 29 May 2026, which sets out what an independent auditor registered with the CVM must reach a conclusive opinion on. Two of the eight heads are governance statements about individuals:

So Brazil does not ask you to name a compliance officer; it asks an auditor to confirm that a director owns the risk assessment and that a board approved the policy. That is a harder thing to retrofit.

Worth correcting while we are here, because it is widely stated the other way: the reasonable assurance report added by IN BCB 739 is not part of the Phase 1 set due 30 October 2026. IN 739 did not touch art. 9. The report lands in Phase 2 (art. 10, item X) and in the new-entrant route (art. 5, item XV). At least one published Brazilian alert binds it to the October filing, and that is wrong.

The UK: the role is an approved function, not a job description

The UK does not add a crypto compliance officer. PS26/13 applies the Senior Managers and Certification Regime to cryptoasset firms in full — senior management functions, certification, prescribed responsibilities and conduct rules — from the start of the regime on 25 October 2027. Almost every firm will sit in the standard, Core population: the Enhanced thresholds are GBP 100bn in safe custody assets and client cryptoassets combined, and GBP 20bn in backing assets calculated as a three-year rolling average, and the FCA does not anticipate many, if any, firms meeting them.

The second UK change is easy to miss. Authorised cryptoasset firms come off the FCA's money laundering register entirely. Registration is replaced by a notification duty: notify before acting or within 28 days of doing so, with 30 days for firms already acting at commencement, 30 days for material changes or inaccuracies, and 28 days on ceasing. Breach is enforceable. If your compliance calendar still has an annual MLR registration item on it, it is describing a regime you will have left.

What this means for hiring

The three regimes disagree about independence in ways that matter to an org chart. Kenya bars the CEO and the internal auditor from holding the MLRO post. Brazil expects a director's signature on the risk assessment and an auditor who will look for it. The UK expects an individual approved to hold the function, with conduct rules reaching every employee. A group that appoints one regional compliance officer across all three will fail the Kenyan independence test or leave the Brazilian director role unfilled, or both. Budget for separate appointments, and appoint the Kenyan one early enough for the 14-day notification to be a formality rather than a scramble.

The checklists behind this article

Each of our readiness checklists takes one regime and maps it item by item to the rule, regulation or article number behind it, marking every figure as instrument text or as reporting of it, and leaving open questions marked open. UK gateway checklist, USD 149; Kenya VASP checklist, USD 79; Brazil PSAV checklist, USD 79. Updated editions are free as each position develops.

If you are staffing a single entity in a single market, the relevant checklist is enough and you do not need anything else from us. If you are staffing one compliance function across two or three of these regimes, the 48-hour gap check looks at your actual reporting lines against each regulator's independence rules.

Get the note when something actually changes

The UK gateway, Kenya's VASP Act and Brazil's BCB regime. Only when a rule, date or figure moves — and primary sources are always marked separately from press reporting.

More on Cross