Insight / AIFC / AFSA supervision

AFSA reviews before it fines.

The AIFC rebuilt its AML rulebook for 2025 and now supervises a fast-growing population of firms through examination, not headline penalties. That makes the thematic review, not the fine, the real exposure. Here is what AFSA expects, and the eight places programmes most often fall short.

INSIGHT

If you run compliance for a firm regulated in the Astana International Financial Centre, the pressure you feel is not a wave of fines. It is a rulebook that was rebuilt around you, a regulator that examines before it penalises, and a supervised population that has grown faster than most compliance benches. This is a read of where that leaves an AIFC AML programme, grounded in the public record, with no invented figures and no invented deadlines.

01 / The setup

A hub that outgrew its compliance benches

The AIFC launched in 2018 as an independent jurisdiction built on the principles of English common law, with its own court and its own regulator, the Astana Financial Services Authority. It is no longer a small experiment. The Centre passed 4,000 registered companies in mid-2025 and closed the year with more than 4,900, drawn from over 90 countries, having added more than 1,400 new registrations in 2025 alone. Over 1,500 of those firms provide financial and insurance services.

For a compliance leader, the number that matters is not the growth headline. It is that an expanding population of firms now sits under one regulator's authorisation and supervision, many of them young, many of them scaling faster than they are hiring, and all of them carrying the same AML obligations as the established names beside them.

02 / What changed

The 2025 rulebook, and what it actually moved

AFSA approved a set of amendments to the AIFC Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Rules in December 2024, effective 1 January 2025. AFSA has been clear that this was a clarification and consolidation exercise, refining existing requirements in light of participant questions and the findings of its own inspections and thematic reviews, not a wholesale new regime. That framing matters, because it tells you the changes came from what supervisors were actually seeing.

Three moves stand out. The Money Laundering Reporting Officer must now be genuinely independent, able to act on their own authority, and, in AFSA's own words, not also the business owner, shareholder or chief executive. Firms whose MLRO role overlapped with senior management were given a six-month window from the start of 2025 to separate the functions, and that window has since closed. Reliance on third parties was tightened, with an explicit bar on outsourcing the ongoing monitoring of customers and counterparties. And the rules added clarifications on the business risk assessment and risk scoring, together with new sanctions definitions.

One point of precision, because it has caused confusion in the market: the operative date is 1 January 2025, and there is no separate later compliance cut-off attached to this framework. If a date is circulating as a looming AFSA deadline, check it against the rulebook before you act on it. The only time-bound item was the MLRO transition, and it has already run its course.

03 / How AFSA supervises

The exposure is the review, not the fine

Here is the part that changes how you should read your own risk. AFSA supervises AML compliance mainly through examination and guidance, not through published punishment. Its record shows a real thematic-review programme: an AML thematic review of AIFC fintech firms in 2023, issued alongside a letter to senior executives; a further AML thematic review of non-profit institutions and foundations; and a sectoral risk assessment of money-laundering and terrorist-financing risk in the digital-asset sector. It then rebuilt the framework itself, drawing on those findings.

Public enforcement, by contrast, is thin. The only enforcement outcomes AFSA has published to date are a small number of modest settlements against payments and fintech firms, and none of them was for a money-laundering breach. They concerned carrying on regulated activity without full authorisation, non-compliant financial promotions, or general systems-and-controls weaknesses. AFSA has also noted that it only recently adopted a policy of publishing all enforcement outcomes, so the visible record is both new and, historically, incomplete.

A thin fine record is not a thin scrutiny record. In this regime the gap surfaces first in a thematic review or an inspection, not in a press release.

Read the two facts together and the picture is not reassuring, it is clarifying. There is no wave of AML fines to point to, which means firms cannot calibrate to the fear of a headline penalty. What there is instead is a supervisor with a documented habit of reviewing sectors, writing to executives, and reworking the rules around what it finds. In that world, the practical exposure is a request you cannot answer: the thematic questionnaire, the inspection, the file that has to reconstruct a decision. That is where a gap becomes visible, and AFSA has said it now publishes what it finds.

04 / The crypto layer

The heaviest load sits on the digital-asset cohort

The AIFC also runs one of the region's more developed virtual-asset regimes. AFSA licenses firms as Digital Asset Service Providers, with the operation of a regulated exchange as the central activity, under a consolidated rulebook in force since the start of 2024. That framework implements the FATF Travel Rule for digital-asset transfers, prohibits anonymous assets, and requires an annual independent technology audit. It grew out of a pilot that connected AIFC-registered exchanges to Kazakhstani banks' fiat channels.

By late 2025 the licensed cohort was on the order of two dozen and more service providers, about a dozen of them exchanges, including globally known names, alongside retail-client trading limits and a vetted list of admissible assets. For those firms the AML load is not lighter for being new. It is heavier: the Travel Rule, source-of-funds on crypto flows, and self-hosted-wallet handling sit on top of everything an AIFC financial firm already owes, and the digital-asset sector is exactly the one AFSA singled out for a dedicated risk assessment.

05 / Where programmes fall short

The eight places a review tends to land

Across the AIFC AML framework, the same handful of gaps recur, and they are the ones a thematic review or an inspection is built to find. None of these is exotic. Each is a supervisable expectation with a rule behind it, and each is answerable honestly with a yes or a no.

  • AML 13; GEN 2.2MLRO independence. An approved, resident MLRO who is not the owner or chief executive, with a deputy. The single most common post-2025 gap.
  • AML Ch. 4; 2.2Business risk assessment. A documented, senior-management-approved, current assessment that actually shapes the controls, not a filed formality.
  • AML 6.3.1; 6.6Beneficial ownership. A separate control test alongside the ownership test, and a rule to decline where owners cannot be identified.
  • AML 6.4.1Ongoing monitoring. Continuous scrutiny after onboarding, with an alert trail, not a one-off check. It cannot be outsourced.
  • AML Ch. 12Sanctions screening. Both the UN and the Kazakhstan lists, re-screened on every update, with a tested freeze-and-report step.
  • AML Ch. 13Suspicious-transaction trail. A per-case record of the MLRO's reasoned decision, filed or not, taken independently.
  • AML Ch. 11-1Travel Rule. For digital-asset firms, working transmission of originator and beneficiary data, with the right fields by transfer value.
  • AML 4.3.1Independent audit. A genuinely independent test of the programme, not the compliance officer reviewing their own work.

We turned these eight into a short self-check so a compliance officer can place their own programme against each one in a couple of minutes, with the rule cited beside every question and an honest read at the end. It stores nothing and asks for no sign-up.

AIFC AML readiness check
Eight questions, cited to the Rules, honest scoring. Two minutes, nothing stored.
Run the check →
Sources and posture

Figures and dates in this piece are drawn from public reporting by the AIFC and AFSA (the 2025 AML amendments, AFSA AML thematic reviews and enforcement pages, and the AIFC Rules on Digital Asset Activities), with growth and market figures corroborated by The Astana Times, and Kazakhstan's system assessed in a 2023 mutual evaluation. Participant, capital and cohort numbers originate with the AIFC and AFSA and are live figures that move over time. Rule references point to the AIFC AML, CFT and Sanctions Rules as amended, effective 1 January 2025; AFSA renumbers on amendment, so treat them as pointers to the current rulebook. Black Sea is an independent financial-crime compliance advisory that builds and runs the AML programme behind a regulated operator's licence. It is not a law firm, holds no licence, and is not affiliated with or endorsed by AFSA or the AIFC. This is general information, not legal advice.

Would rather find the gap before the review does?

Independent, conflict-free, senior only. Under NDA. We build what sits behind the licence.