The crypto compliance officer: three regulators, three different jobs
The same job title, three different legal shapes
Firms licensing in more than one market tend to write one compliance officer job description and reuse it. That works until a reviewer reads it. Kenya names the officer in a regulation and tells you who cannot hold the post. Brazil never names a compliance officer for virtual asset providers at all, but ties the central AML obligations to a responsible director whose approval an independent auditor has to see. The UK does not create a crypto-specific role either, and instead pulls cryptoasset firms into the Senior Managers and Certification Regime in full. Three regimes, three different documents to produce.
Kenya: the regulation names the person, and rules people out
Kenya's detail sits in the Proceeds of Crime and Anti-Money Laundering Regulations 2023 (Legal Notice 153 of 2023), which apply to virtual asset service providers because the VASP Act 2025 amended the definition of reporting institution in POCAMLA (Cap 59A) to include them, with effect from 4 November 2025.
- Regulation 12: the money laundering reporting officer must be at management level and independent, and cannot be the internal auditor or the chief executive officer, unless the business is a sole proprietorship.
- Regulation 12 also requires appointment or removal to be notified to the Financial Reporting Centre and the supervisory body within 14 days, and requires the MLRO to report "forthwith".
- Regulation 11: internal controls that include screening on hire, ongoing training, a compliance manual and an independent audit function.
- Regulation 7(3): the AML policies are board-approved, not management-approved. Regulation 8 requires a risk assessment before launching any new product, practice, delivery mechanism or technology — a product approval gate that belongs inside the risk policy rather than in a slide.
- Regulation 44: an annual compliance report due 31 January.
The statutory clocks around the officer are short. A suspicious transaction report goes to the Financial Reporting Centre within two days of the suspicion arising, and attempted transactions count (POCAMLA s.44(2) and (3)). Follow-up questions from the Centre are answered not later than 30 days (s.44(9)). Registration with the Centre and notification of changes in particulars run on their own timetable under s.47A.
One structural point that catches groups: under Legal Notice 134, the gazetted VASP Regulations, the compliance officer is not the only named individual. The gazetted text also requires a chief information security officer. Those are two posts, and a reviewer reading a file where one person holds both will ask about it.
Brazil: no named officer, but a director who has to sign up to the risk assessment
Brazil's authorisation rules do not prescribe a compliance officer for virtual asset providers in the way Kenya does. The obligation surfaces instead through Anexo IV to Normative Instruction BCB 704, added by IN BCB 739 of 29 May 2026, which sets out what an independent auditor registered with the CVM must reach a conclusive opinion on. Two of the eight heads are governance statements about individuals:
- Head I: the institutional AML policy, organisational structure and staff training must be documented and board-approved.
- Head II: the internal risk assessment must be formalised and approved by the responsible director, with the Risk and Audit Committees and the board aware of it.
So Brazil does not ask you to name a compliance officer; it asks an auditor to confirm that a director owns the risk assessment and that a board approved the policy. That is a harder thing to retrofit.
Worth correcting while we are here, because it is widely stated the other way: the reasonable assurance report added by IN BCB 739 is not part of the Phase 1 set due 30 October 2026. IN 739 did not touch art. 9. The report lands in Phase 2 (art. 10, item X) and in the new-entrant route (art. 5, item XV). At least one published Brazilian alert binds it to the October filing, and that is wrong.
The UK: the role is an approved function, not a job description
The UK does not add a crypto compliance officer. PS26/13 applies the Senior Managers and Certification Regime to cryptoasset firms in full — senior management functions, certification, prescribed responsibilities and conduct rules — from the start of the regime on 25 October 2027. Almost every firm will sit in the standard, Core population: the Enhanced thresholds are GBP 100bn in safe custody assets and client cryptoassets combined, and GBP 20bn in backing assets calculated as a three-year rolling average, and the FCA does not anticipate many, if any, firms meeting them.
The second UK change is easy to miss. Authorised cryptoasset firms come off the FCA's money laundering register entirely. Registration is replaced by a notification duty: notify before acting or within 28 days of doing so, with 30 days for firms already acting at commencement, 30 days for material changes or inaccuracies, and 28 days on ceasing. Breach is enforceable. If your compliance calendar still has an annual MLR registration item on it, it is describing a regime you will have left.
What this means for hiring
The three regimes disagree about independence in ways that matter to an org chart. Kenya bars the CEO and the internal auditor from holding the MLRO post. Brazil expects a director's signature on the risk assessment and an auditor who will look for it. The UK expects an individual approved to hold the function, with conduct rules reaching every employee. A group that appoints one regional compliance officer across all three will fail the Kenyan independence test or leave the Brazilian director role unfilled, or both. Budget for separate appointments, and appoint the Kenyan one early enough for the 14-day notification to be a formality rather than a scramble.
The checklists behind this article
Each of our readiness checklists takes one regime and maps it item by item to the rule, regulation or article number behind it, marking every figure as instrument text or as reporting of it, and leaving open questions marked open. UK gateway checklist, USD 149; Kenya VASP checklist, USD 79; Brazil PSAV checklist, USD 79. Updated editions are free as each position develops.
If you are staffing a single entity in a single market, the relevant checklist is enough and you do not need anything else from us. If you are staffing one compliance function across two or three of these regimes, the 48-hour gap check looks at your actual reporting lines against each regulator's independence rules.