Podcast
Compliance Champions

Beyond Policies: Building an AML Programme That Works

Delphine Forma
Head of Policy, Europe
,
Solidus Labs
Tigran Rostomyan
CEO and Founder
,
AML Incubator

What does an effective crypto AML programme actually look like in practice?

In this episode of Compliance Champions, Delphine Forma speaks with Tigran Rostomyan, Founder and CEO of AML Incubator, about Canada's AML framework for digital asset businesses and, more importantly, what it takes to build a compliance programme that actually works.

Using Canada as a practical example, Tigran explains how FINTRAC registration interacts with provincial securities regulation, when MSB and Foreign MSB requirements apply, and why being registered is very different from having an effective compliance programme.

The conversation goes beyond policies to explore the five core components of an AML programme, why the risk assessment should be its foundation, and how firms can translate identified risks into meaningful controls.

Delphine and Tigran also discuss customer due diligence, corporate onboarding, the practical challenges of the Travel Rule and unhosted wallets, and how to build transaction monitoring that identifies genuine financial crime rather than simply generating alerts.

They explore the importance of bringing KYC, customer behaviour, fiat and crypto transactions, blockchain analytics and sanctions screening together into one holistic view, as well as current financial crime typologies, regulatory reporting and examination readiness.

The discussion closes with Canada's increasing focus on firms being able to demonstrate that their controls are implemented, risk-based and effective in practice, alongside emerging requirements under the Retail Payment Activities Act.

They discuss:

  • FINTRAC registration and its interaction with Canada's securities framework
  • The five core components of an AML programme and why the risk assessment should drive the controls
  • Why the risk assessment is the foundation of the AML programme and should drive mitigating controls and transaction monitoring
  • Practical implementation of the Travel Rule, including unhosted wallets and missing counterparty information
  • How to build effective transaction monitoring based on the firm's actual risks, customer behaviour and transaction patterns
  • Bringing KYC, transaction monitoring, blockchain analytics and sanctions screening together to create a holistic view of customer activity
  • Key crypto financial crime typologies, regulatory reporting and examination readiness
  • Why regulators increasingly expect firms to demonstrate that their AML controls actually work in practice
Loader Animation