CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

VARA, FCA and HKMA Signal a New Era of Real-Time AML Supervision

CryptaCount Editorial · · 11 min read
AML / KYC / LICENSING VARA, FCA and HKMA Signal a New Era ofReal-Time AML Supervision

Three of the world's most influential crypto and financial regulators have, within weeks of each other, made nearly identical arguments: the quarterly-inspection, periodic-reporting model of supervision is finished. In its place, regulators in Dubai, London, and Hong Kong are building toward continuous, AI-powered monitoring of the financial sector in real time. For accounting firms, auditors, and CFOs who rely on crypto accounting software and periodic compliance cycles, this is not a distant policy aspiration. It is an operational signal that demands attention now.

VARA, FCA and HKMA Signal a New Era of Real-Time AML Supervision

What the Regulators Actually Said

The convergence of views across three geographically distinct regulators is striking, and it is worth working through what each authority has put on record.

VARA (Dubai): Programmable Compliance Over Rule Engines

The Virtual Assets Regulatory Authority, established in 2022 as the world's first cryptoasset-specific regulatory body, has articulated the most pointed critique of legacy supervision. In a public article, VARA's head described the core problem plainly: you cannot audit a 24/7 cross-border smart contract through a quarterly inspection, and you cannot police an autonomous lending protocol through paperwork.

The alternative VARA is pointing toward includes on-chain audits replacing sampled reviews, real-time monitoring replacing after-the-fact reporting, and programmable compliance replacing rule-engine workflows. These are not vague aspirations. They describe a structural change in what regulated firms will be expected to demonstrate and when.

VARA's head also framed a two-wave timeline for AI-driven change. In the near term, within roughly two years, AI should allow regulated firms to cut false positives in AML/CFT monitoring alerts significantly, freeing compliance resources to focus on genuinely high-risk activity. Simultaneously, regulators will use AI to speed up authorization reviews, giving the private sector faster feedback. Over a five-year horizon, the supervisory model transforms completely: periodic data submissions give way to live data feeds, and sample-based examinations give way to continuous, AI-powered risk detection across the sector.

Critically, VARA's head identified human accountability for AI-generated outputs as the key blocker to this transition. Jurisdictions that resolve this question proactively, he argued, will gain a material competitive advantage.

FCA and Bank of England: Agentic Commerce Changes Everything

On 24 June, the CEO of the UK's Financial Conduct Authority addressed the dual developments of agentic commerce and tokenization, stating that the FCA is rethinking what it means to be an effective regulator in the age of AI. The FCA is exploring real-time monitoring for market manipulation and other supervisory uses of AI-generated data analytics.

The FCA CEO was candid that traditional rule-making will not work in all areas. Some domains will still need detailed rules. Others will require a stewardship model where the regulator works collaboratively with firms to navigate technological change and may act before legislation catches up. To support this, the FCA plans to expand existing initiatives, including its AI Lab, Supercharged Sandbox, and AI Consortium, with additional programs to let firms test and deploy AI under supervisory oversight.

The Bank of England's Deputy Governor for Financial Stability added a governance-specific concern on 30 June: existing frameworks were not built to contemplate autonomous agents, and requiring a human in the loop for every agent action is unlikely to be realistic at scale. More sophisticated accountability frameworks will be needed.

These remarks set the context for an FCA Board-commissioned review published on 6 July. Produced by an FCA Executive Director, the review recommends that the UK build and adopt an AI-enabled agentic supervisory model. The practical output described is a shift from periodic reporting toward continuous, event-driven data and intelligence flows, with the explicit goal of improving timeliness while reducing the burden on firms from ad hoc data requests.

HKMA: From Productivity Tool to Strategic Intelligence Partner

The Hong Kong Monetary Authority has published a report on how banks in Hong Kong are currently using AI in AML/CFT compliance, along with its vision for where the technology should go. The current state, the HKMA acknowledges, is largely efficiency-focused: better alert triaging, less intensive manual review. The HKMA wants to see firms go further, using AI for earlier threat detection, more complex decision-making, and proactive disruption of financial crime.

The HKMA describes its ambition as facilitating a shift from AI as a productivity tool to AI as a strategic intelligence partner. Achieving this will require the authority to work deliberately with regulated firms to clarify expectations around the accountability and governance of AI systems, an almost identical theme to what VARA and the FCA have each raised independently.

The Pattern Across Three Jurisdictions

Shared Themes That Matter to Compliance Teams

Read together, the VARA article, the FCA CEO's June speech, the Bank of England Deputy Governor's remarks, the Mills Review, and the HKMA report share four consistent themes that accounting firms and CFOs should treat as a coordinated regulatory direction of travel.

First, periodic reporting is being replaced. All three regulators are explicitly moving toward continuous or event-driven data flows. The quarterly-filing and annual-audit model of AML/CFT compliance is the specific target of this critique.

Second, real-time monitoring is the destination. Regulators want live views of sector-wide risk, not retrospective snapshots. This implies that regulated firms must be capable of producing structured, machine-readable data on demand and in near real time.

Third, human accountability for AI outputs is unresolved and is the critical blocker. VARA, the FCA, and the HKMA have each flagged this independently. Until accountability frameworks are clarified, firms that deploy AI in compliance workflows carry governance risk that regulators have not yet eliminated.

Fourth, the jurisdictions that move fastest on clarifying AI governance will attract business. VARA's head stated this directly. The FCA's willingness to let firms test AI under supervisory oversight before legislation catches up signals a similar competitive awareness in the UK.

Accounting and AML Implications for Firms and CFOs

Rethinking the Compliance Stack

The shift from periodic to continuous supervision has direct consequences for how firms architect their compliance infrastructure. Crypto accounting software and digital asset accounting software that produce reports on a batch or month-end basis will not satisfy a regulatory expectation of continuous, event-driven data flows. Firms need to assess now whether their current systems can generate structured transaction data and AML alerts in real time, or whether an infrastructure upgrade is required before regulators formalize the expectation.

This is not merely a technology question. It is an audit and engagement quality question. Accounting firms advising digital asset clients need to understand whether those clients' compliance architectures are compatible with the supervisory direction each regulator is signaling. An engagement that passes today's periodic-review standard may not pass the real-time monitoring standard that the FCA and HKMA are actively building toward.

For a practical reference point on how CSSF warning on unlicensed operators and what it means for AML workflows illustrates the licensing and monitoring gap that regulators are already acting on, the pattern is the same: supervisory bodies are moving faster than many firms' compliance cycles.

AML/CFT Alert Tuning: The Near-Term Opportunity

VARA's two-year horizon for AI-driven false-positive reduction is achievable with current technology. Firms that have not yet systematically tuned their AML alert models are leaving a compliance efficiency gain on the table, and they are also accumulating a relative risk: as regulators shift to AI-powered oversight, they will increasingly expect regulated firms to demonstrate that their own monitoring is similarly capable. A firm still generating high volumes of low-quality alerts will be a visible outlier in a sector-wide real-time data feed.

The HKMA's framing of AI as a strategic intelligence partner rather than a productivity tool is worth internalizing here. Compliance teams that treat AI-driven alert tuning as a cost-reduction exercise may miss the deeper point: regulators are beginning to evaluate the quality of a firm's AI-enabled decision-making as a proxy for the quality of its risk management overall. That is a governance and accountability question as much as a technology one.

On-Chain Audit Readiness

VARA's explicit mention of on-chain audits replacing sampled reviews is the most operationally specific signal in the public record. For accounting firms providing assurance services to digital asset businesses in or serving the UAE, this is a direct call to develop on-chain audit capability: the ability to verify transaction histories, smart contract states, and wallet balances directly from blockchain data rather than from management-produced reports.

This connects to a broader point about crypto bookkeeping software and record-keeping obligations. If regulators can monitor on-chain activity in real time, discrepancies between a firm's books and the on-chain record become immediately visible rather than discovered at the next inspection cycle. The margin for error, and for deliberate omission, narrows sharply. Firms advising on digital asset record-keeping need to factor this into their engagement scoping.

For a broader view on how how the CLARITY Act AML provisions are shaping crypto compliance strategies in another major jurisdiction, the directional alignment with what VARA, FCA, and HKMA are building is consistent: regulators globally are moving toward tighter, faster, more data-driven oversight of digital asset activity.

What Accounting Firms and CFOs Should Do Before Frameworks Are Formalized

Immediate Steps

The accountability question flagged by all three regulators is a governance gap that firms can close now, before formal rules arrive. Compliance teams should document how AI-generated outputs are reviewed, who is responsible for acting on them, and what the escalation path is when an AI system produces an output that a human cannot readily verify. This documentation will likely become a regulatory expectation; building it now reduces the risk of scrambling when formal guidance lands.

CFOs of digital asset businesses operating across the UAE, UK, and Hong Kong should also assess whether their current crypto accounting software and compliance technology can produce structured, event-driven data exports. If the answer is no, or if this requires manual intervention, that is a gap to raise with technology and compliance leadership now. The FCA's Mills Review specifically targets the reduction of ad hoc data requests from regulators as a benefit of the new model; firms that cannot respond to structured data requests quickly will bear a disproportionate burden in the transition period.

Medium-Term Planning

Over the two-to-five-year horizon that VARA has described, accounting firms should plan for a material change in what assurance over digital asset businesses looks like. On-chain audit methodology, real-time data reconciliation, and AI-governance attestation may each become standard engagement components. Firms that invest in building these capabilities during the transition period, rather than waiting for standards to be finalized, will be better positioned to serve clients and to attract mandates from the digital asset sector.

For CFOs, the medium-term planning question is whether the firm's compliance architecture is being built to meet the supervisory model that regulators are building toward, not just the one that exists today. That is a capital allocation and vendor selection question that belongs on the CFO agenda alongside the more immediate operational considerations.

VARA, FCA and HKMA Signal a New Era of Real-Time AML Supervision

Frequently Asked Questions

What does real-time AML supervision mean for a crypto business operating in Dubai?

VARA has signaled a move toward on-chain audits and continuous monitoring rather than quarterly inspections. In practice, this means businesses operating under VARA's oversight should expect regulators to have direct visibility into transaction flows rather than relying on periodic reports. Compliance systems need to be capable of producing structured, machine-readable data continuously, not just at reporting deadlines.

Does the FCA's AI supervisory direction apply to crypto firms, or only to traditional financial services?

The FCA CEO's June speech addressed both agentic commerce and tokenization as dual drivers of the need to rethink supervision. The FCA's AI-enabled supervisory model is being developed for the financial sector broadly, and digital asset businesses authorized or registered with the FCA are within scope. Firms should not assume that the new supervisory framework will treat crypto businesses differently from other financial services entities.

How does the HKMA's AI and AML report affect banks with crypto custody or trading operations in Hong Kong?

The HKMA's report describes a clear expectation that AI should move beyond alert efficiency toward earlier threat detection and proactive disruption of financial crime. Banks in Hong Kong with digital asset operations will need to demonstrate that their AML/CFT AI deployments are evolving in line with the HKMA's stated ambitions, and that governance and accountability frameworks for those systems are clearly documented and understood internally.

What is the human accountability issue that regulators keep raising, and why does it matter for accounting firms?

All three regulators have flagged the same unresolved question: when an AI system generates a compliance output or a supervisory decision, who is legally and professionally accountable for it? For accounting firms providing assurance over AI-driven compliance processes, this is a direct risk. Until regulators clarify the accountability framework, firms should ensure that every AI-generated compliance output has a named human reviewer who can be held responsible for the decision taken on the basis of that output.

Should firms wait for formal regulatory guidance before upgrading their crypto accounting and compliance systems?

Waiting carries more risk than acting. All three regulators have described this as a direction of travel, not a consultation with an uncertain outcome. The FCA's Mills Review has already recommended the agentic supervisory model formally. Firms that invest in real-time data capability, on-chain record-keeping, and AI governance documentation now will be ahead of the compliance curve rather than scrambling to catch up when formal rules arrive.

Source: Elliptic

AEUKHKGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Four Financial Centres Racing to Lead on Crypto Regulation
AML/KYC & Licensing
AI Governance in Compliance: The Accountability and Control Gap Regulators Are Already Watching
AML/KYC & Licensing
Reed Smith Launches Aquarius: What the MiCA Compliance Tool Means for Accounting Firms and CFOs
AML/KYC & Licensing
Dubai VARA Rolls Out Digital Asset Framework Including Privacy Coin Ban