EST · MMXXVI
Home/Jurisdictions/France/VASP business risk assessment in France (AMF/PSAN)
Compliance, AML & Travel Rule

VASP business risk assessment in France (AMF/PSAN)

Vasp business risk assessment in France (AMF/PSAN). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

VASP business risk assessment in France (AMF/PSAN)

Operating a virtual asset business in France without completing a rigorous VASP business risk assessment exposes the firm to enforcement action by the Autorité des marchés financiers (AMF), the suspension of banking relationships and the loss of client onboarding capacity at the worst possible moment. France's PSAN (Prestataire de Services sur Actifs Numériques) regime, established under the PACTE Law and now transitioning toward full MiCA (Markets in Crypto-Assets Regulation) alignment under ESMA oversight, places specific AML, KYC and Travel Rule obligations on every registered or licensed operator. A business that treats compliance as an afterthought discovers the cost when its correspondent bank exits, not before.

This page sets out the legal basis for the French PSAN regime, the components of a defensible business risk assessment, the cross-border complications that arise for inbound operators, and the decision points that determine whether a business is properly structured before French supervisors come calling.

What does the French PSAN regime actually cover?

The PSAN framework, administered by the AMF with support from the Autorité de contrôle prudentiel et de résolution (ACPR) for AML matters, covers a defined list of digital-asset services. These include custody of digital assets on behalf of third parties, the purchase or sale of digital assets against legal tender, the exchange of digital assets for other digital assets, the operation of a digital-asset trading platform, and certain portfolio management and advisory activities. Any business providing one or more of these services to clients located in France – whether from a French entity or from abroad – must assess whether PSAN registration or optional authorisation applies.

Registration is the baseline obligation. It is mandatory and carries full AML/CFT requirements drawn from FATF Recommendation 15 and the applicable French AML transposition. Optional authorisation under the regime goes further: it unlocks marketing authorisations and signals a higher compliance standard to institutional counterparties. With MiCA's CASP authorisation now operative across the EU, France is in active transition. A PSAN registration does not automatically convert to a CASP authorisation; firms must plan for reapplication under the MiCA process before the relevant transitional deadline.

The AMF and ACPR sit on the same supervisory file. AML failures at the ACPR level can unwind a clean AMF registration. Operators who separate their regulatory and compliance workstreams miss this structural coupling.

The process above describes the standard path. Your facts – the entity structure, the user geography, the banking layer – change the analysis materially. For a scoped assessment of your PSAN position, contact OBOLUS at info@oboluslaw.com.

What is a VASP business risk assessment in the French context?

A VASP business risk assessment is a documented, enterprise-wide analysis of the money-laundering, terrorism-financing and sanctions risks that a virtual asset service provider faces across its products, client base, delivery channels and geographic footprint. Under the French AML regime, this assessment is not optional: the ACPR expects a written, current risk assessment as a precondition to any serious supervisory interaction, and it forms the backbone of the firm's AML/CFT programme.

The assessment must address at minimum four dimensions. First, the inherent risk of the business model: which asset types are handled, whether DeFi protocols or privacy-enhanced tokens are in scope, whether custody is full or partial. Second, client risk: the geographic distribution of users, the presence of politically exposed persons, the proportion of institutional versus retail counterparties. Third, channel risk: whether the onboarding is fully remote, whether fiat on-ramps are provided, and whether third-party payment processors introduce layering risk. Fourth, residual risk after controls: the gap between the inherent risk profile and the strength of the KYC, transaction monitoring and Travel Rule infrastructure actually deployed.

In our cross-border practice, we see this assessment treated as a document produced once for registration and never revisited. That approach fails. The ACPR expects demonstrable ongoing review, triggered at minimum by material changes in product scope, client geography or asset coverage. A firm that expanded to offer staking rewards or bridging services without updating its risk assessment is carrying an undisclosed risk that a supervisory inspection will surface immediately.

How do AML and Travel Rule obligations apply to a PSAN-registered business?

A PSAN-registered business in France carries full AML/CFT obligations aligned with the FATF standards and implemented through French law. The Travel Rule – the obligation to transmit originator and beneficiary identification data with any virtual asset transfer above the applicable threshold – applies to transfers between VASPs and, in the French interpretation, to transfers to or from unhosted wallets where the transfer exceeds the de minimis level set under applicable rules.

Practically, this means the compliance infrastructure must include a Travel Rule solution capable of communicating with other VASPs in real time, a process for handling transfers where the counterpart VASP is not Travel-Rule-compliant, and a clear policy for unhosted wallet transfers including the verification steps required before the transfer proceeds. The ACPR has signalled that it will treat gaps in Travel Rule implementation as material AML deficiencies, not as technical issues. Firms should not assume that a standard banking-sector AML programme adapted for crypto satisfies the Travel Rule component.

FATF Recommendation 15 governs the Travel Rule at the international level. Within France, the ACPR has authority to issue guidance and impose sanctions on firms that cannot demonstrate compliant transfer-data workflows. We regularly advise firms on building these workflows before the first supervisory exchange, because retrofitting them under pressure is significantly more expensive.

What are the risks for inbound operators serving French clients from abroad?

An operator domiciled outside France but serving French clients faces a risk profile that differs from a locally registered PSAN, and is in several respects more exposed. The ACPR's position on inbound VASP activity is informed by the same FATF standards that treat the location of the customer as a key jurisdictional anchor. A business holding only an offshore registration – in the BVI under the VASP Act 2022, in the Cayman Islands under CIMA, or in any other jurisdiction – does not carry a French regulatory permission. It cannot assert that its home-jurisdiction compliance programme satisfies French expectations.

The cross-border risk manifests in three places. Banking is the first: French correspondent banks and payment processors will typically require evidence of PSAN registration before opening or maintaining a euro account for a crypto business with French-facing activity. The second is enforcement: the AMF has shown an increasing willingness to pursue non-registered entities actively marketing to French retail clients. The third is the MiCA gateway: once MiCA's passporting regime is fully operational, a CASP authorised in another EU member state may be able to passport into France – but only if the underlying authorisation is substantively compliant, not a minimal-effort registration in a permissive jurisdiction.

In a recent matter, a payments company with a Caribbean registration had acquired a French user base through a white-label partnership. When the French banking counterpart required a PSAN compliance certificate, the company discovered that its home-jurisdiction AML programme did not meet the ACPR's documentation standards. We advised on a structural remediation – including a parallel PSAN registration process and an interim Travel Rule solution – that restored the banking relationship before the contractual deadline. The matter resolved over the course of several months. The cost of the remediation was materially higher than a pre-launch assessment would have been.

A single offshore licence is not sufficient to serve French clients. This assumption is one of the most consistently costly errors we see in our practice. The solution is a jurisdiction-by-jurisdiction assessment of where the business has clients, where the entity sits, and where the banking infrastructure is located.

How does MiCA change the PSAN picture for France?

MiCA creates a single EU-wide authorisation for CASPs (Crypto-Asset Service Providers) supervised under ESMA and the relevant national competent authority. For France, the AMF is the NCA for CASP authorisation. The MiCA transition means that a business currently operating under PSAN registration must plan for a CASP authorisation application before the transitional period closes. The MiCA authorisation process is more demanding than the prior PSAN registration: it requires a fuller governance and compliance package, a detailed business description, and evidence of adequate prudential resources, among other elements.

The critical planning point is timing. Firms that delay the MiCA application risk a gap period during which they hold neither a valid PSAN registration nor a MiCA authorisation. A gap period raises immediate questions from banking partners and institutional clients. In our cross-border practice, we advise firms to begin the MiCA preparation well in advance of the formal window, treating the gap analysis between the existing PSAN programme and MiCA requirements as a primary deliverable of the business risk assessment.

The passporting benefit of MiCA is real but conditional. A firm authorised in, for example, Lithuania as a CASP under MiCA can passport into France. But the business risk assessment prepared for the home-state application must reflect the full scope of activities across all passported jurisdictions. ESMA has been explicit that the passporting mechanism is not a route to regulatory arbitrage. The AMF can flag concerns to the home-state regulator if the French-facing business appears disproportionate to the licensing footprint.

What KYC framework and transaction monitoring does the ACPR expect?

The ACPR expects a KYC framework that is genuinely risk-based, documented, tested and capable of independent audit. The starting point is customer due diligence at onboarding: identity verification, beneficial ownership determination, source-of-funds analysis for higher-risk clients and, for institutional counterparties, a full corporate KYC file. The regime does not prescribe the specific technology used for identity verification, but it expects the outcome – a verified, documented client record – to meet the standard regardless of the delivery channel.

Ongoing monitoring is the component most frequently underdeveloped in the businesses we assess. A KYC file that is accurate at onboarding and stale six months later does not satisfy the ACPR's expectation of continuous customer risk management. Transaction monitoring must be calibrated to the actual risk profile of the business: a high-volume retail exchange requires a different alert ruleset than a custody platform serving twenty institutional clients. The documentation of the monitoring calibration – including the rationale for each threshold and the process for reviewing alerts – is as important as the monitoring itself.

Operators we advise regularly underestimate the ACPR's focus on the audit trail. Every compliance decision – a cleared alert, an escalation, a SAR filed – needs to be recorded in a way that allows a supervisor to reconstruct the decision process. The ACPR can request these records during an inspection, and their absence is treated as a governance failure independent of whether any underlying AML breach occurred.

How do banking and tax considerations interact with the PSAN risk profile?

Banking access is the practical chokepoint for any PSAN-registered business. French banks and those operating in France under EU passporting rights apply their own due diligence standards to crypto business clients, and those standards are consistently more demanding than the PSAN registration requirement alone. A business that holds a PSAN registration but cannot produce a current business risk assessment, a named MLRO, a Travel Rule solution and a transaction monitoring report will find it difficult to open or maintain a euro account at a domestic institution.

The tax dimension is distinct but intersecting. France taxes gains from the disposal of digital assets under a specific regime applicable to private individuals, with a separate treatment for professional traders. For a PSAN-registered business, the relevant issues are different: the VAT treatment of exchange fees, the deductibility of compliance infrastructure costs, and the corporate tax treatment of token inventories held on behalf of clients or on proprietary account. These positions require engagement with French tax counsel. The interaction between the regulatory and tax analyses is often underestimated by inbound operators who treat the two workstreams as parallel and non-overlapping.

For a business with entities in multiple jurisdictions – say, a PSAN registration in France, a CASP application pending in an EU member state, and custody assets held through a Swiss structure supervised by FINMA – the risk assessment must address the interplay between the regimes. FINMA's token taxonomy, which distinguishes payment, utility and asset tokens, may produce a different risk classification than the French AML analysis of the same instrument. Reconciling these classifications at the group level is a necessary step before any cross-border business risk assessment is considered complete.

If a banking relationship has already stalled or a registration application has hit an obstacle, a second-read analysis can often surface the structural cause. Write to OBOLUS at info@oboluslaw.com to map the remediation path.

Which operator profile needs which approach to the French risk assessment?

Operators approaching the French market fall into broadly three profiles, each with a different risk posture and a different starting point for the business risk assessment.

A startup launching a French-facing crypto exchange from a new EU entity will need to build the entire compliance infrastructure from the ground up – AML programme, KYC framework, Travel Rule solution, MLRO appointment and the business risk assessment – before submitting a PSAN registration and, in parallel, beginning the MiCA CASP preparation. The timeline from a clean start to a complete registration-ready file is typically measured in months, depending on the complexity of the product and the readiness of the governance documentation. The key risk is underestimating the ACPR's documentation expectations and submitting a file that triggers a request for supplementary information, which restarts the effective clock.

An established offshore VASP expanding into France from a non-EU base faces a different problem. Its existing AML programme may be substantively compliant but not formatted or documented in a way that meets AMF and ACPR expectations. The business risk assessment in this profile requires a gap analysis between the home-jurisdiction standard and the French standard, a remediation plan and, frequently, a rewrite of the core compliance documentation. The banking question is often the first crisis: a French correspondent bank may require PSAN evidence before an account is open, which creates a sequencing problem if the registration takes time.

A firm already holding a PSAN registration that is preparing for the MiCA transition needs a different kind of assessment: one focused on the delta between its existing programme and the CASP authorisation requirements, and on the transitional timeline. The risk here is a compliance programme that was adequate for PSAN registration but falls short of MiCA's more detailed governance expectations. In our practice, this gap is most commonly found in the area of ongoing customer risk monitoring and in the documentation of the internal audit function.

What are the most common mistakes in PSAN compliance, and how are they avoided?

The most consistent mistake is treating the business risk assessment as a registration document rather than a living governance tool. The ACPR's inspection approach looks for evidence that the assessment is used to drive decisions – about onboarding policies, about product risk, about monitoring thresholds – not filed away after submission. A document that has not been updated since the initial registration will draw immediate adverse comment in a supervisory inspection.

The second common mistake is MLRO appointments that are nominal rather than substantive. The MLRO must have genuine authority, adequate resources and direct board-level access. Appointing a junior compliance officer as MLRO to satisfy a formal requirement, without giving that officer the authority to escalate, delay transactions or file SARs independently, does not satisfy the regime. The ACPR assesses the MLRO's actual operational position, not the title on the file.

A common assumption in our practice is that a transaction monitoring system purchased off the shelf – without calibration to the firm's specific product, client and geographic risk profile – is sufficient. It is not. The ACPR expects firms to document why each monitoring rule is set at each threshold, and to demonstrate periodic review of those settings against emerging risk. A generic ruleset applied to a business with an unusual asset mix or an atypical client geography will produce either excessive false positives or systematic blind spots. Neither outcome survives inspection.

Finally, the cross-border Travel Rule gap is frequently overlooked. Many firms implement Travel Rule solutions for transfers between known VASPs but apply no structured process to transfers involving unhosted wallets. The ACPR's approach treats this gap as a material AML deficiency. A defensible position requires a documented unhosted-wallet policy, a risk-based verification process and evidence that the policy is applied consistently.

Related at OBOLUS

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit – so that structural problems are resolved on paper, not in production. To discuss your situation, contact info@oboluslaw.com or reach us on Telegram at t.me/oboluslaw. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions.

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – drawn from FATF Recommendation 15 – requires a VASP to collect and transmit originator and beneficiary identification data with every virtual asset transfer above the applicable threshold. This means the sending VASP must pass the originator's name, account and address data to the receiving VASP before or simultaneously with the transfer. For transfers to unhosted wallets, additional verification steps apply in most leading regimes, including France under ACPR guidance. Failure to implement a compliant Travel Rule workflow is treated as a material AML deficiency.

Who must act as MLRO for a crypto firm?

The MLRO (Money Laundering Reporting Officer) must be a senior individual with genuine authority to escalate, delay transactions and file suspicious activity reports independently of commercial pressure. In France, the ACPR assesses the MLRO's operational position – not merely the title. The role requires board-level access, adequate resources and documented authority. A nominal appointment to satisfy a formal requirement, without substantive authority, does not satisfy the regime and will draw adverse supervisory comment. For PSAN-registered businesses, the MLRO's qualifications and reporting lines should be documented in the AML programme.

How do regulators audit crypto AML programs?

Regulators such as the ACPR typically audit crypto AML programmes through a combination of document review and on-site or remote inspection. They will request the current business risk assessment, the KYC policy, transaction monitoring documentation including alert calibration rationale, SAR filing records and evidence of ongoing staff training. The key test is not whether documents exist but whether they are current, used in practice and capable of supporting a supervisory decision trail. A programme that cannot demonstrate live application – rather than one-time drafting – is treated as a governance failure regardless of its written quality.

By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML programme design, PSAN/MiCA compliance obligations and supervisory engagement for virtual asset businesses across the EU and cross-border.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours