A virtual asset service provider (VASP) operating across borders today faces a layered risk environment that regulators are actively re-drawing. A firm may hold a licence in one jurisdiction, serve users in three more, custody assets through a fourth, and process payments via a fifth – each layer carrying its own legal exposure. When a regulator, a correspondent bank, or a counterparty audits that structure, the question is not simply whether the entity is licensed. The question is whether every activity, in every market, is covered by the right instrument, supported by a credible anti-money laundering (AML) program, and aligned with the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer). This analysis maps the legal lines that define VASP risk – where they fall, how they interact, and what happens when they are crossed.
What Activity Triggers VASP Regulation?
VASP regulation is triggered by activity, not by incorporation address. A firm incorporated offshore that operates an exchange interface accessible to users in the European Union is subject to MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities) regardless of where its servers sit. The same logic applies under VARA in Dubai, under the MAS Payment Services Act in Singapore, and under SFC rules in Hong Kong. Each regime defines a list of regulated activities – exchange, transfer, custody, advisory, lending, management – and any entity performing one of those activities for persons in that jurisdiction is inside the perimeter.
The practical consequence is that most VASP structures are multi-jurisdictional from day one. An exchange with a Malta MFSA authorisation (now transitioning to MiCA CASP status) passports across the EU but does not cover users in the Gulf, Singapore, or the United States. A VARA licence in mainland Dubai does not extend to the DIFC financial free zone. A BVI FSC registration under the Virtual Asset Service Providers Act 2022 addresses the BVI perimeter but says nothing about the jurisdictions where the firm's clients reside.
In our cross-border practice, the single most common structural gap we identify is the assumption that one licence covers the global user base. It does not. Regulators in the leading hubs increasingly expect an entity-level analysis: which legal entity is performing which activity, for users in which jurisdiction, under which regulatory instrument.
The operative test across virtually every major regime is whether the firm performs a regulated virtual asset activity for persons resident or domiciled in the jurisdiction. The entity's place of incorporation is a secondary factor – relevant to the licensing analysis, but not determinative of the obligation.
CTA #1 — For the reader encountering this issue at the planning stage: The perimeter analysis above describes the standard framework. Your facts – the entity structure, the user base, the product mix – change the analysis materially. Map your options with us before you commit to a structure.
Where Do AML Obligations Attach Across the Stack?
AML obligations for VASPs attach at the activity layer, not the entity layer, meaning a group with multiple operating entities must run a compliant KYC framework (know-your-customer identification and verification program) at every point where a regulated service is delivered. The FATF Recommendations – particularly Recommendation 15 on virtual assets – establish the baseline: customer due diligence, transaction monitoring, suspicious activity reporting, and record-keeping. Every major licensing regime incorporates that baseline into its domestic rulebook.
The practical architecture has three tiers. First, customer onboarding: identity verification, sanctions screening, PEP checks, and risk scoring at the point of account opening. Second, ongoing transaction monitoring (automated surveillance of on-chain and off-chain activity for patterns consistent with money laundering, sanctions evasion, or fraud). Third, the reporting and escalation layer: a designated Money Laundering Reporting Officer, internal suspicious activity procedures, and regulatory filing obligations.
Each tier varies in its specific requirements by jurisdiction. MiCA and ESMA guidance set the EU standard. VARA's rulebooks prescribe detailed AML obligations for every licensed activity category in Dubai. MAS expects robust transaction monitoring calibrated to the risk profile of the customer base. The FCA in the UK requires that cryptoasset firms registered under the Money Laundering Regulations maintain systems genuinely capable of detecting financial crime – not paper policies.
Operators we advise routinely underestimate the second tier. A KYC framework that works well at onboarding can fail at the transaction monitoring layer if it is not calibrated to the specific risk profile of the asset class – high-frequency stablecoin flows, DeFi interactions, or cross-chain bridges each generate patterns that generic bank-grade monitoring tools may not catch.
The cross-border angle compounds the challenge. A firm licensed in Lithuania under the Bank of Lithuania's regime and serving users across the EU under MiCA passporting must maintain AML procedures that satisfy both the home-state NCA and the expectations of host-state regulators. A discrepancy between the two – even a procedural one – can trigger a supervisory inquiry in the host market.
How Does the Travel Rule Change the Risk Profile?
The Travel Rule materially raises the compliance floor for every VASP that processes transfers between accounts at different institutions. Under the FATF framework, a VASP initiating a transfer must collect and transmit originator and beneficiary information to the receiving VASP; the receiving VASP must screen that information before making funds available. The obligation applies regardless of whether the counterpart VASP is in the same jurisdiction or a different one – which is where the cross-border complexity becomes acute.
The specific data threshold and any de-minimis carve-out vary by jurisdiction and must be verified against current domestic rules. What is consistent across the leading regimes is the underlying obligation: the transfer of virtual assets must carry structured data about the parties. A VASP that cannot transmit or receive that data is functionally unable to transact with compliant counterparts in regulated markets.
This creates a two-sided problem. On the sending side, the VASP must have a Travel Rule messaging solution – a technology layer capable of formatting and transmitting the required data fields to the counterpart institution before or simultaneously with the on-chain transfer. On the receiving side, the VASP must be able to ingest, screen, and store that data, and must have a policy for what to do when the counterpart is not Travel Rule-capable or when the data is incomplete.
In our practice, we have seen Travel Rule gaps cause bank account closures, not just regulatory notices. Correspondent banks auditing a VASP's operations increasingly treat Travel Rule capability as a baseline indicator of the firm's overall compliance posture. A firm without a credible solution is flagged as a de-risking candidate. The financial-crime risk the bank perceives attaches not to a particular transaction but to the structural inability to know who the counterpart is.
The Travel Rule is now a de facto market-access condition in every jurisdiction that has implemented the FATF standard – not simply a regulatory box to check.
What Happens When the Licence Stack Has Gaps?
A licence stack with gaps exposes the VASP to enforcement action, banking termination, and civil liability simultaneously – and the exposure compounds across layers. If the operating entity lacks the right authorisation in a market where it has active users, the firm is conducting unlicensed regulated activity. The consequences range from supervisory warning letters to criminal referrals, depending on the jurisdiction and the scale of the breach. VARA in Dubai, MAS in Singapore, and the SFC in Hong Kong have each demonstrated willingness to pursue enforcement against firms operating outside their authorised scope.
Banking exposure is often faster than regulatory exposure. Correspondent banks and EMI partners conduct ongoing due diligence on VASP clients. A gap in the licence stack – particularly an entity performing custody or exchange in a jurisdiction where it holds no authorisation – can trigger an account exit within weeks of discovery. In a market where VASP banking access is already structurally constrained, a bank exit can be operationally fatal.
Civil liability is the third vector. Where a VASP has offered a service in a jurisdiction without the required authorisation, the client may have a restitution claim, the transaction may be voidable, and the firm may face private damages actions in addition to the regulatory penalty. This is not a theoretical risk: it is one we have seen asserted in cross-border disputes, particularly where the client suffered a loss and sought to argue that the contract was unenforceable for want of a licence.
A single offshore licence – the BVI, the Cayman Islands, or an older EU VASP registration – does not resolve these exposures. Those instruments address the home-jurisdiction perimeter. They do not licence the firm to serve users in markets with their own applicable regimes. The myth that a single offshore licence is sufficient for global operations is the most consistently expensive assumption we encounter in practice.
CTA #2 — For the operator who has already structured a business and encountered a banking or regulatory obstacle: A structural gap at the licence or AML layer is usually identifiable and addressable – but the route back depends on the specific facts. If an account was closed or an application returned, the structural reason matters more than the immediate symptom. Map your options before the clock runs further.
Which Licence Profile Fits Which Operator?
The right licence architecture depends on the operator's activity profile, user geography, and the assets it touches. There is no single correct answer – only a correct answer for a given set of facts. The matrix below identifies the primary decision branches.
Profile A: Exchange with EU retail users. The operative regime is MiCA CASP authorisation via an EU member state NCA. Lithuania, Malta (via MFSA), and several other member states are common entry points; each has different processing postures and local requirements. Passporting then covers the broader EU/EEA user base. The key risk at this profile is the whitepaper obligation for token listings and the AML expectations of the home NCA, which vary more than the MiCA text might suggest.
Profile B: Exchange or broker-dealer with Gulf-region users. VARA (mainland Dubai) and ADGM/FSRA (Abu Dhabi) are the primary regimes. VARA's activity-based licence framework means a firm advising on virtual assets, brokering transactions, and offering custody must hold separate authorisations for each activity – or a combined authorisation covering all three. The capital and operational requirements scale with the activity set. DIFC-based operations fall outside VARA's scope and require engagement with the DIFC Financial Services Regulatory Authority.
Profile C: Payments-focused VASP or stablecoin operator. The applicable regimes turn on whether the firm is issuing the stablecoin, transmitting value, or providing off-ramp services. MiCA treats stablecoins as either ART (asset-referenced tokens) or EMT (e-money tokens), each with distinct issuer authorisation and reserve requirements. The MAS Payment Services Act in Singapore and the FCA's financial promotion and e-money rules in the UK each add layers. A firm operating across these markets needs an instrument in each.
Profile D: Institutional fund or custodian. Custody is a regulated activity in every major regime. FINMA in Switzerland, the FCA, VARA, ADGM/FSRA, and MAS each impose safeguarding and segregation expectations. A fund domiciled in the Cayman Islands under CIMA oversight and deploying into EU markets may still require a CASP authorisation for the management or advisory component it performs for EU investors.
The cross-border overlay is that most operators touch more than one profile. A firm that issues a stablecoin (Profile C), distributes it through an exchange (Profile A), and offers custody of the proceeds (Profile D) has three distinct regulatory footprints, each requiring its own instrument in each relevant market.
What Are the Most Consequential Structural Mistakes?
The most consequential structural mistakes we encounter follow a pattern. The first is licensing the holding company rather than the operating entity. Regulators licence the entity performing the regulated activity, not the group parent. A licence held by a parent company in one jurisdiction does not cover a subsidiary performing exchange or custody operations in another. The subsidiary is unlicensed, and the parent's authorisation provides no regulatory cover.
The second is the KYC framework that was designed for one market and was not updated as the firm expanded geographically. An AML program built to the Bank of Lithuania's expectations may not satisfy VARA's rulebook or the MAS's risk-based approach expectations. As the user base grows across jurisdictions, the AML architecture must grow with it – specifically, not generically.
The third is the absence of a Travel Rule solution at the point of launch. Some operators defer Travel Rule implementation on the assumption that they will address it once the business reaches a certain scale. Regulators and banks do not share that view. The obligation applies from the first qualifying transfer, and the absence of a solution is itself a compliance failure – regardless of transaction volume.
The fourth is the failure to map the product through the token classification regime before launch. A token that is marketed as a utility token may be treated as a security or an asset-referenced token by the applicable regulator. Token classification under MiCA, FINMA guidance, the FCA's perimeter rules, and the SEC/CFTC frameworks in the United States each apply a substance-over-label analysis. Getting the classification wrong at launch creates a retroactive authorisation problem that is much harder to resolve than a pre-launch filing.
In a recent matter, an exchange operator had structured its custody and trading operations through two separate entities in different jurisdictions. The trading entity held a licence; the custody entity did not. When the banking partner conducted a periodic review, it identified the unlicensed custody entity as the account holder and exited the relationship. Re-structuring and re-licensing the custody entity took the better part of a year, during which the group operated with materially restricted banking access. The structural fix was straightforward in retrospect; the cost of not anticipating it was significant.
Is the Current Structure Good Enough?
A common assumption among operators who have been in market for some time is that an existing structure – perhaps built before the current regulatory cycle – is adequate because it has not yet attracted enforcement attention. That reasoning confuses the absence of enforcement with compliance. Regulators in the leading hubs are not auditing every VASP on a continuous basis. The absence of a supervisory notice does not mean the structure is sound; it means it has not yet been examined under current standards.
The current regulatory cycle is specifically closing the gaps that prior structures relied on. MiCA's passporting regime makes it harder to serve EU users from an unregulated offshore vehicle. VARA has materially expanded its supervision of Dubai-based virtual asset activities. The FCA's financial promotion rules for cryptoassets have been strengthened. The FATF's grey-listing process applies pressure at the country level that flows through to firm-level compliance expectations.
The practical test is not whether the structure has survived to date, but whether it would survive a current-standards audit by the home-state regulator, a prospective banking partner, or an institutional counterparty conducting due diligence. We regularly advise operators who have passed that test internally but failed it in the market – at the point of a bank onboarding request, an institutional investor due-diligence process, or a cross-border acquisition. The time to assess the structure is before one of those events forces the question.
Self-Assessment: The Five Questions to Ask Before the Regulator Does
A structured self-assessment of VASP compliance risk should address five operational questions. Each identifies a category of exposure; a gap in any one of them is a signal that the legal structure needs review.
First: does the operating entity hold the right authorisation in every jurisdiction where it performs a regulated virtual asset activity? The answer must be entity-specific and activity-specific, not group-level and generic.
Second: is the AML program – the KYC framework, transaction monitoring, and MLRO function – calibrated to the actual risk profile of the user base and the asset mix, or was it designed for a different product set and carried forward?
Third: does the firm have a Travel Rule solution in production that covers inbound and outbound transfers, including a policy for unhosted wallets and for counterpart VASPs that are not Travel Rule-capable?
Fourth: have all tokens in the product set been classified under the applicable regimes – not simply labelled as utility tokens by the issuer?
Fifth: does the banking and payments architecture align with the licensed entity structure, such that the account holder performing the regulated activity is the entity that holds the relevant authorisation?
A clean answer to all five does not guarantee regulatory safety – the regime evolves, and what was compliant last year may require updating this year. But a gap in any one of the five is a near-certain source of future exposure.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – our practice overview covering the full compliance lifecycle for VASPs.
- Travel Rule compliance programs in Estonia – jurisdiction-specific analysis of Travel Rule implementation under EU and Baltic rules.
- Staking: legal and regulatory treatment for digital-asset businesses – a guide to the regulatory classification of staking activity across major regimes.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from the FATF Recommendations, requires a VASP initiating a virtual asset transfer to collect structured originator and beneficiary information and transmit it to the receiving VASP before or simultaneously with the transfer. The receiving VASP must screen and retain that data. The specific data fields and any de-minimis threshold vary by jurisdiction; every major licensing regime – MiCA, VARA, MAS, FCA, SFC – incorporates an equivalent obligation into its domestic rulebook.
Who must act as MLRO for a crypto firm?
Every VASP subject to AML regulation in a major jurisdiction must designate a Money Laundering Reporting Officer (MLRO) – a named, senior individual responsible for the firm's financial crime compliance program, internal suspicious activity reporting, and regulatory filings. Most regulators, including VARA, the FCA, MAS, and EU national competent authorities under MiCA, require the MLRO to be individually approved or notified. The role cannot be filled by an external provider acting without genuine authority over the program.
How do regulators audit crypto AML programs?
Regulators audit VASP AML programs through a combination of supervisory reviews, document requests, and on-site inspections. They examine the firm's policies and procedures, the calibration and testing of transaction monitoring systems, the quality of customer due diligence files, the MLRO's authority and reporting lines, and the firm's Travel Rule solution. Regulators including the FCA, VARA, and MAS have all issued public findings identifying inadequate transaction monitoring and weak customer due diligence as primary deficiencies.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance architecture that sits around them. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – treating licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in the intersection of VASP regulatory architecture, on-chain product structures, and cross-border compliance obligations for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.