A virtual asset service provider (VASP) – any business that exchanges, transfers, safeguards or administers digital assets on behalf of clients – faces a compliance environment that differs materially from one jurisdiction to the next. The applicable AML/CFT (anti-money laundering and countering the financing of terrorism) obligations, the Travel Rule trigger thresholds, the KYC framework depth, and the enforcement posture of the relevant regulator all vary. A business that maps only its home-jurisdiction obligations is carrying unpriced risk in every market where its clients actually live.
This analysis compares the risk profile a VASP assumes across the major licensing hubs – from MiCA in the EU to VARA in Dubai, MAS in Singapore and the FCA in the United Kingdom – across four axes: regulatory perimeter, AML and Travel Rule posture, transaction monitoring expectations, and enforcement exposure. The cross-border interaction between those regimes is where the real risk concentrates. Each section opens with a direct answer so that operators can calibrate quickly and engage counsel on the specific gap.
The Regulated Perimeter: Who Is a VASP?
The threshold question for any risk assessment is whether a particular activity requires authorisation at all – and the answer turns on how each regime defines the regulated perimeter. Under MiCA, the EU's Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities, the authorised entity is a CASP (crypto-asset service provider), and the defined services span exchange, custody, transfer, portfolio management, advice and the operation of a trading platform. The regime is activity-based: if you perform a listed service for clients in the EU, you are in scope regardless of where your entity is incorporated.
VARA in Dubai takes a similarly activity-based approach, identifying discrete services – advisory, broker-dealer, custody, exchange, lending, management, and transfer/settlement – each carrying its own rulebook and capital expectation. The FSRA within ADGM applies its own virtual-asset framework, maintaining a list of recognised virtual assets and setting regulated-activity thresholds that can catch a product or service not obviously captured elsewhere.
For businesses operating out of Singapore, the MAS Payment Services Act governs digital payment token (DPT) services. The MAS regime distinguishes between money-changing, standard payment institution and major payment institution tiers – a distinction that affects not only capital but also the scope of permitted activity. In Hong Kong, the SFC's VASP licensing regime applies to virtual-asset trading platforms (VATPs). An operator that runs even a partial matching engine faces the full SFC authorisation process.
The practical risk: a VASP incorporated in the BVI or Cayman Islands – under the BVI FSC's VASP Act or CIMA's Virtual Asset Service Providers Act respectively – may believe its registration satisfies global obligations. It does not. Each jurisdiction where clients are onboarded, where funds settle or where marketing is directed applies its own perimeter test. We regularly advise businesses that discovered mid-growth that they were carrying unlicensed-activity exposure in two or three markets simultaneously.
How Does the Travel Rule Apply Across Jurisdictions?
The Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data with a virtual-asset transfer – is now embedded in every leading VASP regime, but its implementation differs enough to create real operational risk at the boundaries. FATF's Recommendation 15 sets the baseline; each jurisdiction translates it into domestic law with its own de-minimis threshold, data fields and enforcement timeline.
Under MiCA and the accompanying Transfer of Funds Regulation as applied to crypto assets, a CASP must transmit originator and beneficiary information for virtually all transfers – the threshold is set at a low level, and the regime covers unhosted wallets in a way that goes further than many operators anticipated when they first read the headline. The FCA in the UK has implemented a parallel regime under its money-laundering rules, with similar data-transmission requirements but its own compliance clock.
VARA in Dubai has issued specific Travel Rule guidance as part of its compliance rulebook. MAS in Singapore has incorporated Travel Rule obligations into the Payment Services Act regime, and SFC in Hong Kong imposes equivalent requirements on licensed VATPs. The AIFC/AFSA in Kazakhstan applies FATF-aligned standards, though the enforcement infrastructure is newer.
The cross-border friction point is the sunrise problem: when two VASPs in different jurisdictions transact, one or both may face a domestic obligation to collect and transmit data that the counterparty's local regime has not yet mandated. In our cross-border practice, we have seen Travel Rule compliance failures that arose not from inattention but from an incorrect assumption that the counterparty's regime was equivalent. A jurisdiction-by-jurisdiction mapping of data fields, thresholds and unhosted-wallet rules is now a baseline expectation for any operator with a cross-border transfer book.
The Travel Rule applies to both sides of a transfer – the sending VASP and the receiving VASP each carry independent obligations. An operator cannot outsource compliance to its counterparty.
For a scoped assessment of your Travel Rule obligations across the jurisdictions where you operate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard mapping. Your entity structure, your transfer corridors and your counterparty mix change the analysis materially.
AML and KYC Framework Depth: How Do Leading Regimes Compare?
The depth of the KYC framework a VASP must maintain – the identity verification steps, the beneficial ownership checks, the enhanced due diligence triggers and the ongoing monitoring cadence – varies significantly across the major hubs, and the variance creates risk for any business that treats its most permissive jurisdiction as the compliance floor.
MiCA and the EU's AML package, supervised by ESMA and the national competent authorities, set a high baseline. CASPs must apply customer due diligence consistent with the EU's broader AML framework, with enhanced due diligence required for higher-risk customers and business relationships. The regime's definition of beneficial ownership – who is ultimately behind the entity – aligns with the EU's broader corporate-transparency standards and is enforced by the same national supervisors that oversee traditional financial institutions.
VARA's compliance rulebook for Dubai-licensed operators similarly requires tiered KYC, with specific expectations around high-risk customer categories and geographic risk. FSRA within ADGM applies a financial-services-grade AML standard that in practice aligns closely with FCA expectations – the two regimes share a common-law heritage and a mutual recognition of professional standards.
The MAS in Singapore has published detailed guidance on DPT service providers' AML/CFT obligations, including expectations around correspondent-VASP due diligence – the KYC that a VASP must conduct on another VASP it transacts with, not just on end customers. This is an area where operators consistently underinvest, and where regulators in the leading hubs increasingly focus their examination activity.
The FCA's UK regime requires cryptoasset businesses to register under the Money Laundering Regulations and to maintain a full AML program consistent with the relevant provisions. The FCA has published detailed expectations and has used its de-registration power against firms that failed to meet them – making the UK a high-compliance, low-tolerance environment for AML shortfalls.
An important distinction: offshore jurisdictions such as the BVI and Cayman Islands have VASP registration regimes, but their AML frameworks are calibrated to international standards at a level of domestic supervisory capacity that differs from the major onshore hubs. A business that is BVI-registered but serving EU or UK clients faces the EU or UK AML standard for those client relationships – regardless of where the entity sits.
What Does Transaction Monitoring Look Like in Practice?
Transaction monitoring for a VASP is not a single obligation but a layered system of controls that must be calibrated to the risk profile of the business and the expectations of each applicable regulator. The leading regimes – MiCA/ESMA, VARA, MAS, SFC and FCA – all require a documented, risk-based monitoring program; they differ in how they define adequacy.
At minimum, regulators expect automated screening of transactions against sanctions lists and politically exposed persons (PEP) databases, with manual review workflows for flagged items. Under the FATF framework that all these regimes implement, a VASP must also be capable of detecting structuring patterns, layering across multiple accounts or wallets, and flows that are inconsistent with a customer's declared profile. On-chain analysis – the use of blockchain forensics tools to trace transaction history – is now an expected component of a mature monitoring program in all the leading hubs.
Operators we advise routinely underestimate the operational complexity of transaction monitoring in a multi-chain environment. A VASP that supports Bitcoin, Ether, multiple EVM-compatible chains and stablecoins such as USDT and USDC is running four or more separate transaction graphs, each with different forensic-tool coverage and different confirmation-time risk windows. Regulators examining monitoring programs look not only at whether the tools exist but at whether the alert-handling capacity is proportionate to the volume and risk of the book.
VARA has been explicit in its rulebook about the expectation that licensed businesses maintain documented monitoring policies that are reviewed at defined intervals and updated when the risk profile changes. The FCA has similarly published expectations that treat monitoring as a living program, not a point-in-time implementation. In our practice, we have seen supervisory findings that focused on the gap between a well-written policy and an under-resourced operations team – the two must be matched.
Enforcement Posture: Which Jurisdictions Carry the Highest Regulatory Risk?
Enforcement risk is not simply a function of how strict the rules are – it is a function of supervisory capacity, political priority and the penalty toolkit available to the regulator. A rigorous rule with limited supervisory follow-through is a different risk profile from a moderate rule backed by an active examination program.
The FCA has demonstrated a willingness to de-register or refuse registration for cryptoasset businesses that cannot evidence AML compliance to the standard applied to mainstream financial firms. Its financial-promotion rules – which apply to crypto marketing directed at UK persons – carry criminal as well as civil enforcement consequences. The EU's MiCA regime, enforced by national competent authorities with ESMA coordination, brings the full weight of EU financial-services enforcement to the CASP category, including the ability to withdraw authorisation and impose administrative penalties.
VARA in Dubai has built an active supervision function since launch, with a focus on conduct-of-business and AML compliance. The FSRA within ADGM operates as a financial-services regulator with a track record of formal enforcement action in the traditional financial sector – an operator should not assume that a smaller licensing hub means lighter enforcement. MAS in Singapore has a well-established examination and enforcement program and has taken public action against entities that failed Travel Rule and KYC requirements.
Offshore regimes – BVI FSC and CIMA – carry lower domestic enforcement intensity, but that calculus reverses when the business has material activity in a higher-enforcement market. An enforcement action by the FCA or MAS can trigger parallel scrutiny from a home-jurisdiction regulator, and can precipitate banking-relationship termination – a consequence that in practice stops a business more quickly than any regulatory suspension order.
The cross-border enforcement risk is asymmetric: a business registered in an offshore jurisdiction but with EU, UK or Singapore activity is exposed to the full enforcement toolkit of those jurisdictions with no offsetting benefit from the lighter home-regime posture. We regularly advise on restructuring the entity and licensing layer to close this gap before it becomes a supervisory issue.
A micro-matter from our practice: In a recent compliance matter, a custodian structured under an offshore registration was expanding its institutional client base into EU-regulated funds. We mapped the full CASP authorisation requirement triggered by the client profile, identified a 90-day window before the next scheduled client onboarding, and advised on an interim operating structure with a passportable EU authorisation path. The client avoided an unlicensed-activity finding and preserved its banking relationships.
If a prior application stalled or a banking relationship was terminated for compliance reasons, a structural review can identify the cause and the route forward. Contact OBOLUS at info@oboluslaw.com.
A Common Assumption Debunked: Does One Offshore Licence Cover Global Operations?
The most persistent and damaging myth in VASP compliance planning is that a single offshore registration – in the BVI, Cayman, or a light-touch onshore regime – is sufficient to serve clients worldwide. It is not, and regulators across every major market have said so explicitly.
The operative principle is that regulatory perimeter tests are user-based, not entity-based. MiCA applies to a CASP that provides services to clients in the EU, regardless of where the CASP is incorporated. The FCA's financial-promotion regime applies to crypto marketing directed at UK persons, regardless of where the marketer sits. MAS applies its DPT licensing requirements to any business that solicits Singapore-based customers for regulated services. The VARA regime covers virtual-asset activity conducted in or from Dubai.
The practical consequence: a BVI-registered VASP with EU, UK and Singapore customers is carrying unlicensed-activity risk in three of the world's most active enforcement jurisdictions simultaneously. Each of those regulators has the authority to impose injunctions, fines, and – critically – to direct banks in their jurisdiction to terminate the VASP's accounts. That last consequence is the operational one that terminates businesses in practice.
The correct structure is a licensing stack mapped to the actual user base and the actual activity. For a business with global institutional clients, that typically means a passportable EU CASP authorisation, a UK FCA registration, and one or more additional licences depending on where the book is heaviest. The offshore entity may remain useful as a holding structure or for activity genuinely confined to that jurisdiction – but it is not a licence for the world.
We map the licence, banking and tax stack for your build before you commit to a structure. To begin that mapping, write to info@oboluslaw.com.
Decision Matrix: Which Risk Profile Points to Which Structure?
No single compliance structure is optimal for every VASP. The right answer depends on client geography, product type, activity scope and growth horizon. The matrix below is illustrative; it is not legal advice and does not substitute for a jurisdiction-specific analysis.
Profile A – EU-focused exchange or custodian. A VASP with primarily EU retail or institutional clients, operating an exchange or custody service, needs CASP authorisation in at least one EU member state, with passporting to cover the broader EU/EEA market. The authorisation process involves engagement with the relevant national competent authority under MiCA, a full AML/KYC program, capital requirements that vary by service category, and an ongoing ESMA supervisory relationship. The key risk is timeline: authorisation is not instantaneous, and operating without it while the application is pending carries enforcement exposure unless the business qualifies for a transitional provision.
Profile B – Global OTC desk or liquidity provider. A business executing large-volume bilateral transactions across multiple currencies and jurisdictions typically needs a licensing stack spanning at least the EU, the UK and one Asia-Pacific hub – Singapore or Hong Kong depending on where the book is heaviest. The Travel Rule compliance program must be calibrated to all three regimes simultaneously, because each transaction corridor is subject to the rules of both the sending and receiving jurisdiction. The key risk is correspondent-VASP due diligence: regulators in all three markets scrutinise the quality of due diligence conducted on counterparty VASPs, not just end customers.
Profile C – Dubai-based exchange with MENA and emerging-market clients. VARA authorisation is the appropriate foundation, with activity-specific rulebook compliance. Where the client base extends to EU or UK persons, a secondary CASP or FCA registration becomes necessary. The AIFC/AFSA in Kazakhstan offers a supplementary option for Central Asian corridors. The key risk in this profile is the tendency to treat VARA authorisation as sufficient for the entire client base – it governs activity in Dubai but not the client-side obligations in the clients' home jurisdictions.
Profile D – Token issuer with a global retail offering. This is the highest-complexity profile. The token's legal classification – payment token, utility token, ART or EMT under MiCA, security under applicable national law – determines the regulatory regime and the applicable AML/KYC requirements at each point of sale. The whitepaper regime under MiCA, the FCA's financial-promotion rules, and the SFC's product-authorisation requirements may all apply simultaneously, depending on where the token is marketed. A legal opinion on classification, jurisdiction by jurisdiction, is the starting point – not the conclusion of the compliance analysis.
Banking: The Silent Constraint on VASP Compliance Structures
For a VASP, the regulatory licence and the banking relationship are co-dependent risks. A business can hold a valid authorisation and still be unable to operate if no compliant bank will maintain its accounts. Banking access for VASPs remains constrained across most markets – not because it is legally prohibited, but because most banks apply conservative correspondent-risk policies to the category.
The jurisdictions where VASP banking is most accessible tend to correlate with the jurisdictions where the regulatory regime is most developed and most credible to banking compliance officers: the EU under MiCA, the UAE under VARA, Singapore under the MAS Payment Services Act. A CASP authorisation from a credible EU national competent authority is a more effective banking-relationship door than a registration from a lower-profile jurisdiction, even if the business is technically compliant in both.
The AML/KYC framework a VASP maintains is also a banking-access factor. A bank considering whether to maintain a VASP's accounts will examine the VASP's customer due diligence program, its transaction monitoring capability, its Travel Rule compliance and its MLRO (money laundering reporting officer) function. A VASP that can demonstrate a documented, audited AML program aligned with the standards of a major hub is materially better positioned than one relying on a light-touch registration with minimal supporting documentation.
In our practice, we regularly advise on structuring the compliance documentation and the licensing layer precisely to optimise banking access – treating the bank's due-diligence process as a parallel audience alongside the regulator. The two audiences ask slightly different questions, but a well-designed compliance program satisfies both.
Self-Assessment: Where Is Your VASP Carrying Unpriced Risk?
The following questions identify the most common compliance gaps we encounter in cross-border VASP risk assessments. They are not exhaustive and are not a substitute for legal advice – but they indicate where to look first.
- Is your entity authorised in every jurisdiction where your clients are located, or only where you are incorporated?
- Does your Travel Rule program cover all the corridors in your transfer book, including transfers to and from unhosted wallets?
- Have you conducted due diligence on each VASP counterparty to the same standard you apply to retail and institutional customers?
- Is your transaction monitoring program calibrated to the risk profile of your actual client base and product mix – or is it a generic policy that has not been reviewed since implementation?
- Does your MLRO have the authority, resources and reporting line to escalate suspicious activity reports without business-side interference?
- Have you assessed whether your marketing materials and client-acquisition channels trigger the financial-promotion regimes of the FCA, MiCA or any other applicable regulator?
- Is your banking relationship built on a licensing foundation that the bank's compliance team can verify and explain to its own regulator?
A second micro-matter from our practice: In a recent matter involving a mid-size token issuer, we identified during a pre-launch review that the issuer's planned marketing channels triggered FCA financial-promotion obligations for UK-based social-media audiences – an obligation the client had not mapped because its primary licence was in a non-UK jurisdiction. We restructured the marketing rollout and obtained appropriate confirmation before launch, avoiding a criminal liability exposure for the management team.
Related at OBOLUS
- Compliance, AML & Travel Rule for Digital Asset Businesses – the full practice overview covering AML program design, Travel Rule implementation and regulatory engagement across 70+ jurisdictions.
- KYC and Onboarding Framework Legal Counsel for Digital Asset Firms – scoped legal counsel on customer due diligence design, beneficial-ownership verification and enhanced due diligence protocols.
- Creditor Claims in Crypto Insolvency in Guernsey – analysis of creditor rights and recovery options in a Guernsey-based digital-asset insolvency.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 15 and implemented by MiCA, the FCA regime, MAS, VARA and other leading regulators – requires a VASP to collect and transmit originator and beneficiary information alongside a virtual-asset transfer. Both the sending and the receiving VASP carry independent obligations. The specific data fields and the transfer threshold at which the obligation is triggered vary by jurisdiction and must be mapped to each corridor in your transfer book.
Who must act as MLRO for a crypto firm?
A money laundering reporting officer (MLRO) is the designated individual responsible for overseeing a VASP's AML program, receiving and evaluating internal suspicious-activity reports, and filing reports with the relevant financial intelligence unit. Every VASP authorised in a major hub – under MiCA, the FCA regime, MAS or VARA – is required to appoint an MLRO with sufficient seniority, authority and resources. Regulators examine the MLRO's independence from commercial functions and the quality of the escalation process, not just the appointment itself.
How do regulators audit crypto AML programs?
Regulators in the leading hubs – ESMA and national competent authorities under MiCA, the FCA, MAS and VARA – examine AML programs through a combination of document review, transaction-testing and management interviews. They assess whether the written policy matches the operational reality: whether monitoring alerts are investigated within a documented timeframe, whether customer risk ratings are updated when risk factors change, and whether the MLRO function operates with genuine independence. A well-written policy that is not operationally evidenced will not satisfy an examination.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery matters arise. To discuss your situation, contact info@oboluslaw.com.
By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border VASP compliance cost analysis, AML program structuring and the interaction between tax and licensing obligations in multi-hub digital-asset operations.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.