A virtual asset service provider (VASP) is any business that, for or on behalf of another person, conducts the exchange, transfer, safekeeping or administration of virtual assets – and that designation, under the FATF Recommendations and the domestic regimes built on them, triggers a mandatory licensing or registration obligation in virtually every major financial hub. As regulators across the EU, the Gulf, Asia-Pacific and the offshore centers converge on the FATF model, the question is no longer whether a digital-asset business falls inside the VASP perimeter; it is which regimes apply simultaneously, and whether the business can demonstrate compliance with each of them.
This guide examines the VASP definition across the frameworks that matter most to a cross-border operator, the compliance obligations that attach, and the enforcement risks that arise when those obligations go unmet. It is written for founders, general counsel and compliance officers who need the legal answer before the board call, not after the regulator's letter arrives.
What Exactly Is a VASP – and Why Does the Definition Matter?
The VASP definition is a functional test, not a form test. Under the FATF Recommendations – specifically the guidance addressing Recommendation 15 on virtual assets – a business is a VASP if it performs any one of five activities as a business: exchanging virtual assets for fiat or other virtual assets, transferring virtual assets, safeguarding or administering virtual assets or instruments enabling control over them, participating in or providing financial services related to an issuer's offer or sale, or a combination of those. The label the business uses for itself is irrelevant. What matters is the function it performs.
That breadth is intentional. FATF designed the definition to capture the full spectrum of crypto-native activity – exchanges, custodians, brokers, OTC desks, staking-as-a-service platforms and payment gateways – within a single supervisory perimeter. National legislatures then transpose the concept. The EU's MiCA regulation recasts the VASP as a CASP (crypto-asset service provider), but the functional logic is the same. VARA in Dubai, the MAS Payment Services Act in Singapore, the SFC's VATP regime in Hong Kong and the FCA's MLR registration in the UK all trace back to the same FATF architecture.
For a business, the definition matters because a single product – say, a non-custodial wallet with an embedded swap function – can simultaneously satisfy the exchange and transfer limbs of the VASP test in multiple jurisdictions. The cross-border reality is that the entity's domicile, its users' location and its banking counterparties' jurisdiction each carry independent regulatory exposure. Operating without the right licence risks enforcement, frozen banking rails and the loss of correspondent relationships that are already difficult to establish for digital-asset businesses.
How Do the Major Regulatory Regimes Define and License VASPs?
Each flagship regime applies the FATF functional test through its own licensing architecture, and the differences in category, capital and process create real optionality – and real risk – for an operator choosing where to domicile.
European Union – MiCA and CASP authorisation. Under MiCA, a CASP authorisation is required before providing any of the ten enumerated crypto-asset services within the EU. The authorisation is issued by the national competent authority (NCA) in the member state of domicile, and it passports across the entire EU/EEA without further local approval. That passporting right is the dominant reason operators continue to enter through an EU gateway. ESMA coordinates supervisory convergence, but day-to-day supervision remains national. MiCA also introduces distinct regimes for asset-referenced tokens (ARTs) and e-money tokens (EMTs), each carrying its own authorisation and whitepaper requirements. An exchange that also lists an ART may need to satisfy both the CASP and the ART issuer limb of the regulation.
UAE – VARA and the activity-based licence. VARA in Dubai operates an activity-based licensing model. Each regulated virtual-asset activity – advisory, broker-dealer, custody, exchange services, lending and borrowing, management and investment, transfer and settlement – requires a separate authorisation under the applicable VARA rulebook. Operators providing multiple services must hold multiple activity endorsements. VARA's remit covers mainland Dubai; the DIFC financial free zone sits under the separate FSRA/ADGM regime in Abu Dhabi. A business serving UAE clients from offshore without a VARA licence is conducting unlicensed regulated activity on VARA's position, which the authority has enforced publicly.
Singapore – MAS and the Payment Services Act. The MAS Payment Services Act establishes tiered licensing for digital payment token (DPT) service providers. The tier – money-changing, standard payment institution or major payment institution – turns on transaction volumes and e-money float. DPT service includes the exchange of DPTs for money or other DPTs and the transmission of DPTs. MAS has demonstrated a willingness to use its licensing conditions and risk-management requirements as a supervisory tool; several high-profile operators received licence restrictions in the wake of the 2022 market dislocations.
Hong Kong – SFC and VATP licensing. The SFC's VASP licensing regime, which came into effect in mid-2023, requires virtual-asset trading platforms (VATPs) to hold an SFC licence before operating a centralised exchange accessible to Hong Kong investors. The regime applies even to platforms domiciled offshore if they actively market to Hong Kong retail or professional investors. Licensing criteria cover fit-and-proper tests, insurance or compensation arrangements, cybersecurity standards and conduct requirements that mirror the securities licensing framework.
United Kingdom – FCA and MLR registration. In the UK, the FCA administers cryptoasset business registration under the Money Laundering Regulations. Registration is the gateway to operating as a crypto firm in the UK; the financial-promotion regime adds a parallel approval requirement for any communication that constitutes a qualifying cryptoasset promotion. The FCA has maintained a high refusal rate on registration applications, signalling that operational AML controls, not just policy documentation, are what the regulator inspects.
BVI and Cayman – offshore registration. The BVI FSC administers registration under the Virtual Asset Service Providers Act 2022. CIMA operates a parallel registration and licensing framework for virtual-asset service providers in the Cayman Islands. Both offshore regimes align to FATF standards and impose AML program requirements, but neither grants market access to the EU, UK, Singapore or UAE. A common structural error is treating an offshore VASP registration as a substitute for onshore licensing in the jurisdictions where the business's users actually reside.
A practical note on cross-border exposure. In our practice, the most common compliance gap for a growing exchange or custodian is the mismatch between the entity's registered domicile and the regulators that claim supervisory jurisdiction over its user base. A Cayman-registered entity with material EU user traffic, a UAE-licensed platform with a Singapore customer-service team, and a BVI VASP onboarding US persons all face overlapping obligations that a single offshore licence does not resolve.
Contact OBOLUS to map your licence stack. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of which regimes apply to your business model, contact OBOLUS at info@oboluslaw.com.
What AML and KYC Obligations Apply to a VASP?
Every licensed or registered VASP must maintain an AML/CFT program that satisfies the FATF Recommendations, and the domestic legislation transposing them, as a condition of its authorisation. The core components are consistent across regimes: a risk-based customer due diligence program, transaction monitoring calibrated to the specific risk profile of the business, a designated MLRO (money laundering reporting officer) with sufficient seniority and independence to escalate concerns to the board, suspicious-activity reporting obligations and a documented risk assessment refreshed at regular intervals.
The risk-based approach is the operative standard. That means the intensity of due diligence scales with the assessed risk of the customer relationship and the transaction. A retail customer conducting small, periodic purchases of a major token through a regulated exchange attracts a different level of scrutiny than a corporate treasury counterparty depositing significant digital-asset value through a third-party custodian with an opaque beneficial-ownership chain. Regulators have consistently criticised VASPs that apply a uniform, low-threshold process to all customers, treating the risk-based approach as a compliance checkbox rather than a live analytical exercise.
Enhanced due diligence (EDD) is mandatory in defined circumstances: politically exposed persons (PEPs), high-risk third countries identified by the relevant NCA or the FATF grey and black lists, and customers whose transaction activity is inconsistent with their stated profile. In our cross-border practice, we regularly see EDD gaps emerge not at onboarding but at the monitoring stage – a customer passes initial KYC but the monitoring system fails to flag subsequent behaviour that would trigger EDD had it appeared at the outset.
Sanctions screening is a distinct but adjacent obligation. VASPs must screen customers and counterparties against applicable sanctions lists – OFAC, EU consolidated list, UN and domestic lists – and must maintain the capability to block or freeze activity involving designated persons or entities in real time. The stablecoin freeze capability held by issuers such as Tether and Circle is not a substitute for the VASP's own sanctions controls; it is a last-resort tool that operates on court order or law-enforcement designation, not on the VASP's own compliance trigger.
How Does the Travel Rule Apply to VASPs in Practice?
The Travel Rule – the obligation to collect, verify and transmit originator and beneficiary information alongside a virtual-asset transfer – is the most operationally complex FATF requirement a VASP faces. The rule extends to digital-asset transfers the same counterparty data obligations that have applied to wire transfers in the traditional financial system since the 1990s. For a VASP, compliance requires the technical and operational capability to (a) collect originator data at the point of a customer withdrawal, (b) transmit that data securely to the receiving VASP, and (c) verify inbound data on deposits from other VASPs before crediting the receiving customer.
The threshold above which the Travel Rule applies varies by jurisdiction and is set by domestic legislation; the data-field requirements also vary slightly. What is consistent across MiCA, VARA, the MAS Payment Services Act and the FCA's MLR implementation is that the obligation applies to transfers between VASPs (and, under some regimes, to transfers to or from unhosted wallets above a defined threshold). Operators we advise routinely underestimate the complexity of the sunrise problem: the mismatch between a VASP in a Travel-Rule-compliant regime sending data to a counterparty VASP in a jurisdiction that has not yet implemented the rule. The sending VASP still has an obligation; the question is how to document the attempt and the failure to receive a compliant response.
Technical implementation typically uses one of the market-standard Travel Rule protocols – solutions that allow VASPs to identify each other, exchange encrypted counterparty data and confirm receipt. Regulatory expectations on protocol choice are expressed differently across jurisdictions; some regulators endorse specific industry standards, others require only that the VASP demonstrate a compliant solution. The MLRO must be able to evidence the end-to-end flow, including failed transmissions, to a regulator on inspection.
In a recent compliance matter, a payments company expanding from an EU gateway into the Gulf discovered that its existing Travel Rule solution did not support the API integration required by its new UAE banking counterparty. We worked through the technical specification and the VARA-specific data-field requirements, and the operator was able to demonstrate compliant transmission capability before its VARA licence condition review. The process took several weeks; attempting it after a regulatory inquiry would have compressed that window dangerously.
What Does Effective Transaction Monitoring Look Like for a VASP?
Effective transaction monitoring for a VASP requires a risk-calibrated system that flags anomalous activity patterns for review by the compliance team – not a static ruleset applied uniformly to all transactions. Regulators in the leading hubs increasingly expect VASPs to supplement behavioural monitoring with on-chain analytics, using blockchain forensics tools to assess the provenance and risk profile of incoming transactions before crediting customer accounts.
The on-chain analytics layer – offered by firms in the forensics market – assigns a risk score to a wallet address based on its transaction history, its association with known illicit actors or sanctioned addresses, and its exposure to high-risk counterparties. A high-risk score on an incoming transfer should trigger enhanced review and, depending on the specifics, a suspicious-activity report. The VASP that relies solely on off-chain KYC and ignores on-chain provenance is, in the view of most leading regulators, not operating a risk-based AML program.
Suspicious-activity reporting (SAR) obligations tie the monitoring output to a legal filing requirement. The MLRO reviews flagged transactions, makes a determination and, where the threshold is met, files with the relevant financial intelligence unit. The timeframe for filing, the format and the disclosure-prohibition rules (tipping-off) vary by jurisdiction. A VASP operating in multiple jurisdictions may face parallel SAR obligations to multiple financial intelligence units for the same transaction.
In our cross-border practice, we have seen compliance teams build strong monitoring programs for their primary domicile and then fail to extend equivalent capability to a subsidiary or branch in a second jurisdiction – typically because the monitoring vendor's coverage does not include the secondary jurisdiction's reporting format. The gap is invisible until an audit surfaces it.
The Cross-Border VASP Stack: Licence, Banking and Tax
The cross-border reality for a digital-asset business is that three separate stacks must align: the regulatory licence stack, the banking stack and the tax stack. Each is independently complex; misalignment between them is the most common structural failure we see in businesses that have secured a licence but cannot operate effectively.
Licence stack. A VASP operating across multiple jurisdictions must hold – or demonstrably qualify for an exemption from – a licence in each jurisdiction where its activity is regulated. The passporting right under MiCA is a significant efficiency for EU-scale ambitions, but it does not extend to the UAE, Singapore, Hong Kong or the UK. A separate authorisation or registration is required in each of those regimes. Operators who attempt to serve clients in those markets through an EU CASP authorisation alone, relying on reverse-solicitation arguments, face real regulatory risk as those defences have been tested and found wanting in several jurisdictions.
Banking stack. VASP banking is genuinely difficult. Most traditional banks apply heightened due diligence to digital-asset businesses; many decline the relationship outright. The banking relationship that does exist is often fragile – subject to derisking decisions at the bank's discretion with limited notice. In our practice, the VASP that has invested in a strong AML program, clean regulatory history and documented compliance infrastructure is materially better placed to open and retain banking relationships than one that treats compliance as a minimum viable effort. Banks make those distinctions.
Tax stack. The tax treatment of virtual-asset activities – income classification, withholding, VAT or GST on exchange fees, treatment of staking rewards and the corporate residence question – varies by jurisdiction and is not resolved by the VASP licence. A UAE VARA licence does not, by itself, determine the tax treatment of income earned through a server operated from another country. Pre-structuring the entity to align tax residence, regulatory licence and operational reality requires a separate analytical exercise, and the interaction between the VASP regime and applicable tax rules should be mapped before an entity is incorporated, not after its first tax audit.
A decision framework for the cross-border operator. A platform with EU retail users, Gulf institutional clients and offshore holding structure faces the following profile: a MiCA CASP authorisation through an EU gateway entity (for EU users and the passporting right); a VARA licence or a considered offshore position (for UAE-resident institutional clients); an assessment of whether Singapore or Hong Kong activity triggers MAS or SFC obligations; and a tax-optimised group structure that does not inadvertently create permanent establishment exposure in a high-tax jurisdiction. The banking strategy threads between those licensed entities. That stack is not a theoretical exercise – it is the minimum viable structure for a regulated, bankable cross-border digital-asset business.
If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com to discuss.
What Enforcement Risks Do Unlicensed VASPs Face?
Enforcement against unlicensed VASPs has accelerated across every major regime, and the tools regulators use now extend well beyond administrative fines. A business that operates without the correct VASP authorisation faces the risk of: a public cease-and-desist order that destroys banking relationships instantly; criminal referral of senior management in jurisdictions where unlicensed operation is a criminal offence; asset-freeze orders over the business's operating accounts; and, in the most serious cases, customer-account restrictions that prevent the business from returning client funds.
The cross-border dimension of enforcement adds a layer of complexity. A business licensed in jurisdiction A but actively soliciting customers in jurisdiction B without the requisite B authorisation is exposed to enforcement in B regardless of its compliance standing in A. VARA has been explicit that its licensing requirement applies to any entity that markets to, or onboards, UAE-resident clients, regardless of where the entity is incorporated. The SFC in Hong Kong has adopted a similar position. The FCA's financial-promotion rules apply to crypto marketing targeted at UK persons, creating an enforcement vector for offshore platforms that run UK-targeted advertising without an approved promoter.
A common assumption is that operating through a corporate structure – with the regulated entity sitting offshore and client-facing activity conducted by an unregulated affiliate – insulates the group from enforcement. In our practice, that assumption is tested and usually fails. Regulators in the leading hubs increasingly pierce the affiliate structure and examine the economic reality of who is conducting the regulated activity, where the decisions are made and where the clients are located. The group's AML program is examined as a whole, not entity by entity.
Which VASP Structure Is Right for Your Business Profile?
The appropriate VASP structure depends on the operator's user base, product mix, capital position and appetite for supervisory relationship. There is no universal answer, but the following decision orientations reflect patterns we see in practice.
EU-focused exchange or custody business. The natural entry point is a MiCA CASP authorisation through an EU gateway – historically Lithuania or Malta, though the field is now wider as more NCAs have developed CASP processing capability. The gateway choice affects supervisory intensity, local office requirements and the composition of the compliance team. Once passported, the CASP can operate across the EU/EEA. The key risk at this stage is undercapitalising the compliance function relative to the NCA's expectations – a common reason applications stall.
Gulf-facing institutional platform. A VARA licence in Dubai, with a parallel ADGM/FSRA authorisation for Abu Dhabi-based counterparties, is the standard structure. The activity-based licence model means an operator providing exchange, custody and transfer services needs to plan the licence stack from the outset rather than add endorsements reactively. Banking in the UAE is available for licensed VASPs but requires a demonstrable compliance infrastructure. The timeline from application to operation is typically several months.
Asia-Pacific exchange. A Singapore DPT licence under the MAS Payment Services Act is the regional anchor for an operator seeking access to Southeast Asian markets. A Hong Kong SFC VATP licence addresses retail access to Hong Kong investors. The two regimes are distinct and non-passporting. An operator serving both markets typically maintains separate licensed entities, which has tax and operational consequences that should be modelled before incorporation.
Global OTC desk or custodian without a retail-facing product. An operator serving only institutional counterparties on a negotiated, non-public basis may qualify for a more limited registration (BVI, Cayman) paired with specific in-scope registrations in jurisdictions where counterparties are located. That structure works for a genuinely wholesale business; it does not work for a business that characterises retail-facing activity as institutional to avoid the licensing obligation.
In each of these profiles, the MLRO appointment, the AML program design and the Travel Rule implementation are built in parallel with the licence application – not after the licence is received. Regulators treat the compliance program as evidence of intent and operational readiness, not as a post-authorisation formality.
Related Practices at OBOLUS
Related at OBOLUS
- Compliance, AML and Travel Rule for Digital-Asset Businesses – full-service program design and regulatory liaison across FATF-aligned regimes
- VASP Business Risk Assessment for Institutional Clients – scoped risk assessment mapping AML gaps and Travel Rule exposure before regulatory review
- Pre-Exit Tax Restructuring for Regulated Entities – tax-optimised group restructuring for VASPs planning a liquidity event or change of domicile
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary information – including names, account identifiers and, where required, address data – alongside any virtual-asset transfer above the applicable threshold. The obligation applies to transfers between VASPs and, under certain regimes, to transfers involving unhosted wallets. The sending VASP must transmit the data to the receiving VASP before or simultaneously with the transfer. The receiving VASP must verify the data and flag discrepancies before crediting the beneficiary. Implementation requires a compliant technical solution and a documented process for failed transmissions.
Who must act as MLRO for a crypto firm?
Most VASP regimes require the appointment of a designated MLRO (money laundering reporting officer) who holds sufficient seniority to report directly to the board and is independent enough to escalate concerns without business-side interference. The MLRO is responsible for overseeing the AML program, approving suspicious-activity reports, managing the relationship with the financial intelligence unit and certifying the adequacy of the program to the regulator. Some jurisdictions require the MLRO to be based locally; others permit a remote appointment. The MLRO's fitness and propriety is assessed during the licence application and on an ongoing basis.
How do regulators audit crypto AML programs?
Regulators typically audit VASP AML programs through a combination of document review and operational testing. Inspectors examine the written AML policy, the risk assessment, onboarding files for a sample of customers, transaction monitoring alert logs, SAR filing records and Travel Rule transmission records. They then test the live system – submitting test transactions or requesting demonstrations of alert-handling workflows. The FCA, MAS and VARA have each conducted targeted thematic reviews of VASP AML programs. Common findings include insufficient calibration of monitoring rules, inadequate EDD for high-risk customers and Travel Rule implementation gaps.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance programs that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, AML and Travel Rule stack across operating, custody and payment layers before you commit – so the compliance infrastructure is in place when the regulator inspects, not after. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing frameworks, AML program design and cross-border compliance obligations across FATF-aligned regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.