What a VASP business risk assessment actually means in Lithuania
A VASP business risk assessment (a structured, documented evaluation of money-laundering, terrorist-financing and sanctions risks across a virtual asset service provider's products, customers and channels) is the legal foundation of crypto compliance in Lithuania. Under the Bank of Lithuania's supervision and the country's AML legislation – which implements the EU's anti-money-laundering directives and aligns with FATF Recommendation 15 on virtual assets – every registered VASP must maintain a current, written risk assessment before it can satisfy either a regulator or a correspondent bank. Without it, enforcement exposure is immediate and banking relationships collapse. This page maps the regulatory basis, the assessment process, the cross-border complications, and the decision point at which outside counsel adds the most value.
Lithuania entered the EU's MiCA transition period as one of the continent's most active VASP registration hubs. That history brings both opportunity and scrutiny. The Bank of Lithuania now applies heightened supervisory expectations to crypto firms registered there, and CASP authorisation under MiCA (the EU Markets in Crypto-Assets Regulation) raises the compliance bar further. A risk assessment that was adequate under the prior regime may already be insufficient.
The regulatory basis: Bank of Lithuania and the MiCA transition
The Bank of Lithuania is the competent authority for VASP supervision in Lithuania, and it exercises that authority within the broader EU AML/CFT regime. Lithuania has transitioned – and continues to transition – from its earlier VASP registration model toward the CASP authorisation framework under MiCA, which ESMA coordinates at the EU level.
The practical consequence for an operating VASP is layered obligation. First, the firm must maintain AML/CFT systems adequate under Lithuanian national law. Second, it must prepare for CASP authorisation requirements that MiCA imposes across all EU member states. Third, it must satisfy the FATF Travel Rule, which Lithuania has implemented for transfers above the applicable threshold. These are not sequential obligations – they run concurrently, and a risk assessment must address all three layers.
The Bank of Lithuania has signalled, through supervisory guidance and on-site inspections, that it expects VASPs to treat their risk assessments as living documents, not one-time filings. Regulators across the leading EU hubs increasingly expect quarterly or event-triggered reviews – particularly after product changes, geographic expansion, or material shifts in customer profile.
MiCA's CASP regime introduces new categories of regulated activity – exchange, custody, advisory, portfolio management, transfer services – and the risk profile for each differs. A firm offering exchange and custody simultaneously carries a materially different inherent risk score than one offering advisory services only. The risk assessment must reflect that granularity.
For a scoped assessment of your Lithuania risk exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements – change the analysis materially.
What does a compliant risk assessment cover?
A compliant VASP risk assessment in Lithuania covers six core dimensions: customer risk, product and service risk, channel risk, geographic risk, transaction-pattern risk, and governance risk. Each dimension must be scored, documented, and linked to a mitigation control.
Customer risk is typically the highest-weighted dimension for crypto businesses. It requires segmentation of the client base by KYC tier, PEP exposure, source-of-funds complexity, and business type. A KYC framework (the documented set of policies, procedures and controls for identifying and verifying customers) must be explicitly referenced in the risk assessment – not described generically, but mapped to the specific customer categories the firm actually serves.
Product risk analysis for a VASP is more demanding than for a conventional financial institution. Pseudonymous on-chain transfers, self-custodied wallets interacting with the firm's platform, stablecoin settlement, and DeFi integrations all create risk vectors that standard bank-style templates do not capture. In our practice, assessments that fail Bank of Lithuania review most often do so because the product risk section treats blockchain-native products as equivalent to wire transfers.
Geographic risk must address where the VASP's customers are actually located – not merely where the entity is incorporated. A Lithuania-registered VASP serving customers in jurisdictions on FATF's grey list, or in sanctioned territories, carries a different aggregate risk score than one operating exclusively within the EU/EEA. This is the dimension that most frequently surprises inbound businesses: registration in Lithuania does not immunize a firm against the risk profile of its customer geography.
Transaction monitoring – the automated and manual review of activity for suspicious patterns – is both a risk mitigation control and itself a subject of the risk assessment. The assessment must document the firm's monitoring thresholds, escalation protocols, and Suspicious Activity Report (SAR) filing history in a way that allows the Bank of Lithuania to evaluate whether the monitoring program is calibrated to the firm's actual risk profile.
How does the Travel Rule interact with the risk assessment?
The Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data alongside a virtual asset transfer – is not separate from a VASP's risk assessment: it is a stress test of the assessment's adequacy. If the firm cannot demonstrate a functioning Travel Rule compliance process, the risk assessment is incomplete regardless of how well every other section scores.
Lithuania implements the Travel Rule through its AML legislation, and the Bank of Lithuania expects VASPs to have adopted a technical solution for data transmission between VASPs before regulatory review. The standard compliance path involves selecting an interoperability protocol, onboarding counterparty VASPs, and maintaining audit trails for each transaction above the applicable threshold. Where a counterparty VASP cannot be identified – because the transfer originates from or is destined for an unhosted wallet – the risk assessment must contain a specific policy for that scenario.
In our cross-border practice, Travel Rule failures are among the three most common findings in Bank of Lithuania supervisory reviews of Lithuania-registered VASPs. The failure mode is rarely a refusal to comply – it is an implementation gap: the policy exists on paper, but the technical transmission has not been tested against real transaction flows. A risk assessment that includes a Travel Rule section without evidence of operational testing will not satisfy an examiner.
The cross-border dimension compounds the issue. A VASP operating from Lithuania but receiving transfers from VASPs in Singapore (supervised by MAS under the Payment Services Act), Hong Kong (supervised by SFC under the VATP licensing regime), or Switzerland (supervised by FINMA) must account for the different Travel Rule thresholds and data-format expectations in each of those jurisdictions. A single global Travel Rule policy rarely works without jurisdiction-specific annexes.
What is the inbound assessment process for a new VASP in Lithuania?
For a business establishing or restructuring a VASP in Lithuania, the risk assessment process has a defined sequence – and each step conditions the next.
The first step is a legal-entity and activity mapping exercise. Before a risk score can be assigned, the firm must define precisely which MiCA-defined activities it will conduct from the Lithuanian entity, which customers it will serve, and which jurisdictions those customers are in. This is not an administrative formality – it sets the scope of every subsequent compliance obligation.
The second step is an inherent risk scoring exercise, conducted against a documented methodology. The Bank of Lithuania does not prescribe a single scoring template, but it expects firms to use a methodology consistent with EU AML guidelines and to be able to defend their scoring choices on examination. Firms that import generic risk templates without adapting them to their actual product set invariably produce assessments that cannot survive scrutiny.
Third, the firm maps its existing controls against the scored risks and identifies gaps. Gap identification is the operative output of the assessment – it drives the compliance roadmap and is the document the Bank of Lithuania most wants to see. An assessment that scores all risks as "medium" and maps all controls as "adequate" signals to an examiner that it was not conducted in good faith.
Fourth, the firm documents its residual risk position and obtains senior management sign-off. Under the applicable regime, the MLRO (Money Laundering Reporting Officer) is personally accountable for the adequacy of the assessment. The sign-off is not a formality; it carries regulatory and, in some circumstances, personal liability implications.
Finally, the completed assessment is integrated into the firm's AML policy framework and made available for regulatory inspection. The timeline from initiation to completion varies with the firm's complexity – a single-product, EU-only VASP can complete the process in a matter of weeks; a multi-product firm with a global customer base and DeFi integrations will typically require a materially longer process.
In a recent matter, a payments-infrastructure business registered in Lithuania engaged us after a supervisory inquiry identified gaps in its transaction monitoring calibration and Travel Rule documentation. We rebuilt the risk assessment from the entity-activity mapping stage, introduced jurisdiction-specific Travel Rule annexes, and supported the MLRO through the Bank of Lithuania's follow-up examination. The business retained its registration and its primary banking relationship.
How does the risk assessment interact with banking and tax arrangements?
A Lithuania VASP's risk assessment is read by more than the Bank of Lithuania. Correspondent and custodian banks use it – or the absence of it – as a primary input into their own AML due diligence on the VASP as a customer. A well-documented, current risk assessment is among the most effective tools a VASP has to open and maintain banking relationships.
Banks in Lithuania and across the EU apply their own risk-scoring frameworks to crypto business customers. They expect to see not only the risk assessment itself but evidence that it is actively maintained – board minutes referencing AML committee reviews, updated gap-closure timelines, and a demonstrably functioning transaction monitoring program. In our practice, VASPs that present a thorough risk assessment alongside evidence of ongoing monitoring consistently achieve faster and more durable banking relationships than those presenting a static policy document.
The tax dimension is distinct but connected. Lithuania offers a corporate tax environment within the EU standard, and the risk assessment has no direct tax consequence. However, the entity structure that the risk assessment documents – which legal entity conducts which activity, where customers are located, where revenue is booked – is precisely the information a tax adviser needs to assess transfer pricing, VAT, and permanent establishment exposure. Firms that engage tax counsel before finalizing the risk assessment's entity-activity mapping avoid the common mistake of structuring for compliance in a way that creates unintended tax liabilities.
For cross-border structures where the Lithuania entity is one layer of a multi-jurisdiction stack – with, say, custody held through a BVI entity supervised by the BVI FSC under the VASP Act 2022, and institutional clients served from a Cayman entity supervised by CIMA – the risk assessment must address the group-level risk picture, not merely the Lithuania node. Regulators and banks alike will probe whether the Lithuania assessment adequately reflects the group's aggregate risk.
If a prior application stalled or a banking relationship closed unexpectedly, the structural reason is often visible in the risk assessment. Write to info@oboluslaw.com – a second read frequently surfaces the issue and the route back.
What are the most common risk assessment failures the Bank of Lithuania identifies?
The Bank of Lithuania's supervisory record points to recurring failure modes that go beyond the obvious.
The first is the generic template problem. Firms import standard bank AML risk assessment frameworks without adapting them to blockchain-native product features – unhosted wallets, smart contract interactions, pseudonymous on-chain transfers, and cross-chain bridges all require bespoke treatment. A template that does not account for these features will fail on product-risk adequacy.
The second is the static document problem. An assessment completed at registration and left unrevised does not satisfy the regulator's expectation of a living document. Event-triggered review obligations – product launches, new customer segments, geographic expansion, material AML incidents – must be built into the firm's governance calendar.
Third is the MLRO accountability gap. Assessments are frequently prepared by external consultants and signed off without genuine senior management ownership. When the Bank of Lithuania's examiner asks the MLRO to explain a scoring decision, a credible answer is expected. Firms where the MLRO cannot speak to the methodology underlying the assessment create a governance red flag that outlasts the examination itself.
Fourth – and directly relevant to the cross-border reality of most Lithuania VASPs – is inadequate geographic risk treatment. Registration in an EU member state does not neutralize the risk created by serving customers in high-risk jurisdictions. Assessments that score geographic risk as uniformly low because the entity is EU-registered are methodologically incorrect and will not survive challenge.
Who should engage counsel for a VASP risk assessment in Lithuania, and when?
The decision to engage external legal counsel on a risk assessment is driven by complexity and timing, not by firm size alone.
A startup VASP with a single-product offering, an EU-only customer base, and no complex group structure can often complete an initial risk assessment with a qualified compliance consultant. Legal counsel adds the most value at the point of CASP authorisation preparation, where the assessment must satisfy MiCA's higher threshold, or at the point of a supervisory inquiry, where the stakes are regulatory.
For firms with multi-product activity, cross-border customer bases, or group structures spanning more than one jurisdiction, legal counsel is the appropriate lead from the start. The risk assessment for such a firm is not a compliance document – it is a legal opinion about the firm's aggregate regulatory exposure, written in a format the regulator can examine. That requires a lawyer's analytical structure, not a consultant's template.
Profile A – a single-jurisdiction crypto exchange serving EU retail customers from a Lithuania entity – should conduct its initial risk assessment internally or with a specialist compliance consultant, engage legal counsel at CASP authorisation, and schedule annual legal review thereafter.
Profile B – a multi-product VASP with custody, exchange and lending activities, institutional customers in multiple time zones, and a group structure involving offshore holding entities – should engage legal counsel before the risk assessment begins. The entity-activity mapping at step one is itself a legal exercise, and errors made there propagate through every subsequent compliance obligation.
Profile C – a VASP that has received a supervisory inquiry, a banking termination notice, or a request from the Bank of Lithuania for additional information – should treat that as an immediate trigger for legal counsel engagement. The window between inquiry and enforcement action is typically measured in weeks, not months.
We map the licence stack across operating, custody and payment layers before firms commit to a structure. That mapping is the fastest way to identify whether a proposed risk assessment will hold under the scrutiny that Lithuania-registered VASPs now routinely face.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – our full-service compliance practice across licensing, AML and Travel Rule obligations.
- MLRO and compliance officer function in El Salvador – jurisdiction-specific guidance on the MLRO role and its liability exposure.
- Digital-asset licensing in the Isle of Man – licensing structure, process and cross-border considerations for Isle of Man VASPs.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires a VASP to collect and transmit originator and beneficiary identification data alongside each virtual asset transfer above the applicable threshold. The sending VASP must pass this data to the receiving VASP before or at the time of the transfer. Lithuania implements the Travel Rule through its AML legislation, and the Bank of Lithuania expects VASPs to maintain audit-ready records of each transmission. Transfers involving unhosted wallets require a specific policy documented within the firm's risk assessment.
Who must act as MLRO for a crypto firm?
A Money Laundering Reporting Officer (MLRO) must be a named individual with sufficient seniority, knowledge and independence to fulfil the role effectively. Under Lithuanian AML requirements, the MLRO is personally accountable for the adequacy of the firm's AML/CFT program – including the risk assessment. The MLRO must understand the firm's products and risk methodology well enough to answer examiner questions directly. For cross-border structures, each regulated entity in the group typically requires its own designated MLRO in its home jurisdiction.
How do regulators audit crypto AML programs?
Regulators including the Bank of Lithuania typically audit crypto AML programs through a combination of documentation review, transaction-sample testing, and direct interviews with the MLRO and senior management. Examiners assess whether the risk assessment reflects the firm's actual activities, whether transaction monitoring is calibrated to that risk profile, and whether SAR filing decisions are documented and defensible. Remote desk-based reviews are common for initial assessments; on-site inspections are triggered by identified concerns or by the firm's risk classification within the supervisor's portfolio.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is needed. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP compliance architecture, AML program assessment and MiCA transition obligations across EU jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.