Why Most Crypto Exchanges Fail the Audit They Were Never Expecting
Every exchange under examination can produce an AML policy document. Fewer can produce evidence that the policy describes what actually happens inside the business. That gap, between the programme as written and the programme as run, is where most Nigerian crypto exchanges get into trouble with SCUML, the NFIU, or the SEC. And it's rarely because the policy itself was badly drafted. It's because nobody built the operational muscle to match it.
What examiners look at first
A regulatory examiner walking into an AML review has a fairly predictable checklist, and it isn't "read the policy document cover to cover." It's evidence that the policy is being lived:
- Risk assessment currency. Is there a documented, business-specific money laundering and terrorist financing risk assessment, and has it been updated to reflect the business as it operates today, not as it operated at licensing?
- Transaction monitoring calibration. Are monitoring thresholds and rules actually tuned to the exchange's real transaction patterns, or copied from a template and left untouched since implementation?
- STR filing evidence trail. Can the exchange show not just that Suspicious Transaction Reports were filed, but the internal decision trail? Who flagged the activity, who reviewed it, why it was or wasn't escalated, and how long that took.
- Staff training records. Not a generic "AML awareness" slide deck signed off once at hiring, but role-specific, dated, current training records for the people actually making onboarding and monitoring decisions.
- Governance and accountability. Is there a named, empowered compliance officer with actual authority to block onboarding or freeze a relationship, or does compliance sit as an advisory function that can be overruled by the commercial side?

An exchange that can produce a polished policy manual but stumbles on any of these five isn't failing on documentation. It's failing on operation.
Why policy documents alone don't survive scrutiny
A policy document describes intent. It says the exchange will apply risk-based CDD, will screen for PEPs, will monitor transactions, will file STRs within statutory timeframes. None of that is evidence that any of it happened. Examiners have seen enough template policies, often visibly adapted from a generic AML consultancy pack with the company name swapped in, that a policy alone now reads as a starting point for questions, not an answer to them. The real question an examiner is testing is whether the policy produced any operational output: logs, tickets, escalations, decisions, timestamps.
Transaction monitoring: calibrated, not just installed
Buying a transaction monitoring system and turning it on isn't the same as running an effective one. Calibration means setting thresholds and typology rules against the exchange's actual customer base and transaction volumes. A threshold tuned for a platform doing ₦50 million in daily volume will drown a platform doing ₦5 billion in false positives, or miss real structuring on a platform doing ₦500 million because the threshold was left at a default meant for something else entirely.
An examiner will ask to see the rationale behind current thresholds, evidence of periodic re-calibration as volume and customer mix change, and, this is the part most programmes miss, evidence that alerts generated by the system are actually being reviewed and closed out, not accumulating in a queue nobody has capacity to work through. A monitoring system generating thousands of unreviewed alerts is, from a regulator's perspective, functionally the same as having no monitoring system.
STR filing: the trail matters as much as the filing
Filing STRs with the NFIU within the required timeframe is the visible obligation. What examiners actually probe is the internal decision-making that precedes the filing: how an alert or a manually flagged transaction moved from "something looked odd" to "we filed a report," including cases where the internal review concluded a report wasn't warranted. That second category, the documented decision not to file, is just as important as the filings themselves, because it's the evidence that the review process is substantive rather than a rubber stamp that only ever says yes.
An exchange that can produce STR filings but can't reconstruct why those specific transactions were flagged, or show what happened to the alerts that didn't turn into filings, has a documentation gap that reads, to an examiner, exactly like a detection gap. Whether or not one actually exists.

Training records: proof people know the policy, not that the policy exists
A staff training programme that consists of a single onboarding session, undocumented and unrepeated, doesn't demonstrate an operating AML culture. What holds up under review is dated, role-specific training: onboarding staff trained on red flags in identity and KYB documents, monitoring staff trained on typologies relevant to crypto specifically (not generic bank AML material), and refresher training on a defined cadence, with attendance and comprehension records kept. The absence of this record doesn't just look bad. It directly undermines the credibility of every other control, because a control operated by untrained staff isn't reliably operating at all.
Having a programme vs. running one
The distinction that separates exchanges that pass examinations from those that don't is rarely the quality of the policy prose. It's whether the five things above, current risk assessment, calibrated monitoring, a real STR decision trail, documented training, and empowered governance, generate evidence as a byproduct of normal operations, every week, without anyone scrambling to manufacture it before an audit.
If your AML programme only exists convincingly in the three days before an examiner arrives, it isn't a programme. It's a document with a compliance officer's name on it, and regulators have gotten very good at telling the difference.
This article is part of the Obiex Compliance Academy, a series built to help our business customers understand the compliance requirements behind onboarding and working with Obiex. It's for general guidance and doesn't constitute legal advice.