EST · MMXXVI
Home/Jurisdictions/United Kingdom/VASP business risk assessment in United Kingdom
Compliance, AML & Travel Rule

VASP business risk assessment in United Kingdom

Vasp business risk assessment in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A virtual asset service provider entering or already operating in the United Kingdom faces a compliance environment that has tightened considerably as the Financial Conduct Authority (FCA) has moved from observer to active enforcer. The UK's digital-asset regulatory regime is built on two reinforcing pillars: mandatory registration under the Money Laundering Regulations for cryptoasset businesses, and the FCA's financial-promotion rules that restrict how crypto products may be marketed to UK persons. Miss either, and the consequences run to enforcement action, suspended banking relationships and, in the worst cases, criminal liability for senior individuals. This page maps the business risk assessment that any VASP must complete before operating in – or directing services toward – the UK market.

VASP business risk assessment in the United Kingdom centers on the FCA's cryptoasset registration regime, the AML/CFT obligations that flow from it, and the cross-border complexity that arises when a business is licensed offshore but its customers are UK-based. The risk is not theoretical: regulators in leading hubs increasingly expect every VASP to demonstrate a documented, evidence-based assessment of its exposure before the first customer onboards.

The sections below follow the sequence a VASP should work through: the regulatory perimeter, the registration process, AML and Travel Rule obligations, the financial-promotion overlay, banking and tax interaction, the cross-border dimension, and the decision points that determine whether the UK is the right home or a market to be approached with extreme structural care.

Who needs FCA registration – and why the perimeter is wider than most operators expect

Any business carrying on a cryptoasset activity by way of business in the UK must register with the FCA under the Money Laundering Regulations. The defined activities reach exchange services, peer-to-peer trading platforms, crypto ATM operators, issuers of certain tokens and custodian wallet providers. The perimeter is drawn broadly, and the FCA has made clear that a non-UK entity directing its services at UK customers falls within scope even if it holds no UK entity.

The registration requirement is not a licensing regime in the traditional regulatory sense. It does not grant permission to conduct regulated financial services more broadly. What it does – and this is the point operators consistently underestimate – is subject the business to the full weight of UK AML law. That means a documented whole-firm risk assessment, customer due diligence, ongoing transaction monitoring, a nominated Money Laundering Reporting Officer, and annual review obligations. The FCA may refuse registration, impose conditions, or cancel registration at any point if it is not satisfied with the quality of the AML program. Refusal statistics published by the FCA make clear that a substantial proportion of applications have been rejected or withdrawn, a signal that the bar is higher than many applicants anticipate.

In our practice, one of the most common structural errors we see is a business that has obtained a VASP registration in a smaller EU jurisdiction, applied that registration as a proxy for UK compliance, and then routed UK users through the same entity. Under the FCA's regime, that approach does not work. The UK operates its own standalone regime, and offshore registration in another jurisdiction – even an EU one – does not substitute for UK registration.

What does an FCA cryptoasset registration application actually require?

The FCA application for cryptoasset business registration demands a level of documentary substance that resembles a full authorisation application more than an administrative filing. At its core, the FCA is assessing whether the applicant has the people, systems and controls to prevent money laundering and terrorist financing. That assessment has several distinct dimensions.

First, the firm must submit a detailed business risk assessment covering its customer base, the geographies it serves, the assets it handles and the channels through which funds flow. The FCA scrutinises the methodology, not just the conclusions. A templated assessment that does not reflect the firm's actual business model will not pass review.

Second, the firm must demonstrate adequate customer due diligence and enhanced due diligence procedures for higher-risk scenarios. This includes the treatment of politically exposed persons (PEPs) and their associates, correspondent relationships with other VASPs, and high-value or high-velocity accounts. The procedures must be written, tested and evidenced.

Third, a nominated MLRO (Money Laundering Reporting Officer) must be identified and their competence demonstrated to the FCA. The MLRO is personally accountable for the AML program. The FCA has shown willingness to hold MLROs directly responsible when controls fail, so the role carries genuine individual liability.

Fourth, the firm must describe its transaction monitoring systems – the rules, the thresholds, the investigation workflow and the escalation path to MLRO review and, where required, Suspicious Activity Reports filed with the National Crime Agency. The FCA expects a risk-based approach, which means monitoring intensity is calibrated to the risk profile of the customer and the transaction, not applied uniformly across the book.

For a business with a cross-border footprint – say, a Cayman-incorporated exchange with a UK-resident management team and a material percentage of UK users – the application must also address how the UK element of the business is ring-fenced or managed to ensure that the UK AML controls operate independently of any offshore permissive regime.

For a scoped assessment of your FCA registration position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis materially. Map your options.

AML and KYC: what does ongoing compliance look like for a registered VASP?

Registration is not a one-time event. Once on the FCA's cryptoasset register, a VASP carries continuing obligations that the FCA enforces through supervisory visits, information requests and, where controls are found wanting, enforcement action. The AML and KYC (Know Your Customer) framework that the FCA expects is not a static document – it is a live operating system.

Customer risk profiling begins at onboarding and must be refreshed as the customer's activity evolves. A customer who opened an account as a retail user and then begins high-volume business-style trading requires a risk uplift and, in many cases, enhanced due diligence. The firm's procedures must document how that trigger is identified and what the enhanced process entails.

Source-of-funds and source-of-wealth checks are required for higher-risk customers. For a VASP, higher risk is not an unusual category – it captures PEPs, customers from high-risk third countries identified by the FCA, customers whose transaction patterns are inconsistent with their stated profile, and corporate customers with complex or opaque ownership structures. In our experience, this is where most AML programs are weakest: the initial onboarding may be solid, but the periodic review and the trigger-based reassessment are under-resourced.

Transaction monitoring must cover both fiat and on-chain flows. A VASP that monitors its bank rails but does not analyse the blockchain provenance of incoming crypto assets is operating an incomplete program. The FCA expects the firm to use available tools to assess whether assets received carry on-chain risk indicators – exposure to sanctioned addresses, darknet market history or mixing service involvement.

In a recent compliance restructuring matter, a payments company with a UK user base and an offshore VASP registration sought to upgrade its AML program ahead of a supervisory visit. We reviewed the existing framework, identified gaps in the transaction monitoring rules and the PEP screening logic, and rebuilt the risk assessment to reflect the firm's actual customer segments. The program was substantially strengthened within a short engagement window, before any adverse supervisory finding was issued.

What does the Travel Rule require from a UK VASP?

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data alongside a virtual asset transfer – applies to UK VASPs under the Money Laundering Regulations. The FCA has adopted the FATF standard and expects registered VASPs to have implemented compliant Travel Rule procedures.

In practice, this means that when a UK VASP sends or receives a transfer above the applicable de-minimis threshold, it must exchange the required customer data with the counterpart VASP. That data exchange must occur securely, must be retained as required, and must be verified where the counterpart VASP is the originator. The FCA's expectation is that the VASP has a documented inter-VASP due diligence process – it is not sufficient to pass data; the receiving VASP must also assess the reliability of the data it receives.

Cross-border transfers introduce complexity. A UK VASP receiving a transfer from an offshore exchange operating in a jurisdiction without a Travel Rule regime must decide how to treat the information gap. The FCA expects a risk-based response: in the absence of required data, the firm should apply enhanced scrutiny rather than simply reject the transfer or, worse, process it without additional controls. The FCA has signalled that it will assess Travel Rule compliance as part of its AML supervision program.

For VASPs operating across multiple jurisdictions, Travel Rule data exchange is not a bilateral UK matter – it interacts with the Travel Rule obligations of every jurisdiction in which counterpart VASPs are registered. A business with a UK entity, an EU CASP authorisation under MiCA and a Singapore DPT licence must manage three overlapping Travel Rule regimes simultaneously. We map those obligations as a combined compliance layer, not three separate workstreams.

The financial-promotion overlay: a separate risk that catches operators by surprise

The FCA's financial-promotion regime for cryptoassets adds a layer of risk that operates entirely independently of the AML registration. Under the applicable FCA rules, a communication that is a financial promotion in relation to a qualifying cryptoasset must either be communicated by an FCA-authorised person or be approved by one before it reaches a UK person. This applies to marketing on websites, social media, applications and direct communications.

The practical consequence is significant for offshore VASPs. A business that is not FCA-registered, or that is registered but not authorised for financial services purposes, cannot simply publish promotional content accessible to UK users without a specific approval arrangement. The FCA has taken enforcement action in this area, and the financial-promotion rules carry criminal sanctions for breach.

This is a common source of unexpected risk in a cross-border context. A token issuer running a global marketing campaign, a VASP advertising on social media without geo-blocking, or a custody platform whose website describes investment-like returns – all may be in breach of the financial-promotion regime regardless of where they are incorporated. The FCA's jurisdictional reach follows the content, not the legal seat of the publisher.

In our cross-border practice, we regularly advise businesses that have inadvertently created UK financial-promotion exposure through global campaigns, and the remediation path – approval arrangements, geo-blocking, content restructuring – varies significantly depending on the content type and the volume of UK user exposure already created.

If a prior application stalled or a banking rail closed unexpectedly, the structural reason is often identifiable – and the route back is clearer than it appears. Write to info@oboluslaw.com or map your options with our team.

Banking and tax interaction: the constraints that shape the UK VASP operating model

Obtaining FCA registration does not guarantee access to UK banking. The UK banking environment for VASPs has been challenging, with a number of major banks maintaining restrictive policies toward cryptoasset businesses regardless of their regulatory status. A registered VASP must nonetheless have a credible banking arrangement to operate, and the gap between registration and banking access is a structural reality the business plan must address.

E-money institutions and payment institutions regulated by the FCA provide an alternative channel for some VASPs, but they carry their own due diligence requirements. A UK VASP that relies on an EMI for its fiat rails must expect that EMI to apply its own AML scrutiny to the VASP's customers and transactions – a dual-layer compliance obligation that increases operational cost and complexity.

On the tax side, the UK treats cryptoassets as capital assets in most cases, with disposal triggering a capital gains event for individuals and a corporation tax event for companies. For VASPs themselves, the tax treatment of trading income, staking rewards, transaction fees and token treasury positions requires specific analysis. HMRC's published guidance has evolved, and the firm's position should be documented and reviewed periodically. A cross-border structure – for example, a UK operating entity with a BVI or Cayman parent holding the token treasury – introduces transfer pricing and permanent establishment considerations that require careful management.

We work through the licence, banking and tax stack as an integrated analysis. The entity that holds the FCA registration may not be the entity that holds the treasury, and the entities that interface with UK customers may differ from those that hold the licence. That structure must be designed, not assumed.

The cross-border dimension: offshore licence plus UK users is not a safe structure

A common assumption among operators is that a VASP registered in a permissive offshore jurisdiction – or, more commonly, holding an EU CASP authorisation following the implementation of MiCA – can serve UK customers without UK registration. That assumption is wrong, and it is the single most consequential misconception we encounter in our practice.

The FCA's position is unambiguous. A business carrying on cryptoasset activity in the UK, or directing its services at UK persons, requires registration. Directing services at UK persons is assessed by reference to the marketing content, the language, the currency options, the customer support and the practical ease with which a UK person can open and fund an account. A geo-block that is easily circumvented, or that is inconsistently applied, will not protect a business from the FCA's jurisdiction.

Post-Brexit, the UK has constructed a fully autonomous regulatory regime for cryptoassets. EU passporting does not reach the UK. An EMT issuer authorised under MiCA in an EU member state cannot use that authorisation to distribute to UK persons. A CASP passporting across the EU/EEA must treat the UK as a separate, third-country market requiring its own access analysis.

For a business sitting between an EU hub and the UK, the structure question turns on where the customer-facing activity sits, where the AML controls are located and whether the UK entity, if any, is genuinely standalone or merely a marketing front for the offshore operation. The FCA has shown itself willing to look through corporate structures to assess the substance of the UK nexus.

Allied counsel in the relevant jurisdiction can provide the local law advice in each affected market. What we provide is the cross-cutting analysis that maps the interaction between the UK regime and the offshore structure – the layer that most single-jurisdiction advisers do not routinely address.

Decision matrix: which VASP profile should approach the UK market, and how

Not every VASP should seek UK registration as its primary market entry. The decision depends on the business's user base, product type, banking capacity and management substance. The following profiles illustrate the key branches.

Profile A – Exchange or custodian with genuine UK customer demand: FCA cryptoasset registration is the required path. The business should build its AML program to the full UK standard before filing, appoint a substantive MLRO with documented competence, and invest in transaction monitoring tooling that covers both fiat and on-chain flows. Timeline from a submission-ready application to a registration decision varies and is not guaranteed – the FCA has discretion to request additional information, extending the review period. Budget for a process of several months at minimum.

Profile B – Token issuer with a global campaign including UK persons: The financial-promotion regime is the primary concern before the AML registration. The issuer must either secure FCA authorisation, arrange approval through an authorised person, or structure the campaign to exclude UK persons. Registration under the Money Laundering Regulations may also be required depending on the activities conducted. These two obligations are not the same thing and must be addressed in sequence.

Profile C – Offshore VASP directing services at UK users without a UK entity: The risk is highest in this category. The FCA's enforcement reach extends to foreign entities, and the practical consequences of non-compliance – loss of banking, inability to obtain registration retroactively, personal liability for senior management – are severe. The correct approach is to either cease UK activity, establish a compliant UK entity and register, or implement and maintain a credible geo-block while the long-term structure is resolved.

Profile D – DeFi protocol or DAO with UK-based developers or governance participants: The perimeter analysis is more complex. The FCA's approach to decentralised protocols is still developing, but the presence of identifiable UK persons in control or development roles creates a nexus that must be assessed. In our practice, we advise on this analysis as a first step before any other structural decision is made.

In each case, the risk assessment is a precondition, not an afterthought. The FCA will ask to see it – and if it does not exist, that absence is itself an AML control failure.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to transmit originator and beneficiary data – names, account identifiers and, where applicable, address information – alongside a virtual asset transfer that meets or exceeds the applicable de-minimis threshold. The receiving VASP must verify and retain that data. The FCA expects UK-registered VASPs to maintain documented inter-VASP due diligence procedures and to apply enhanced scrutiny where counterpart VASP data is incomplete or absent. Obligations interact with Travel Rule regimes in each jurisdiction where a counterpart VASP operates.

Who must act as MLRO for a crypto firm?

Every FCA-registered cryptoasset business must nominate a Money Laundering Reporting Officer. The MLRO must be an individual of sufficient seniority and competence to oversee the firm's AML program and to receive, assess and file Suspicious Activity Reports with the National Crime Agency where required. The FCA assesses the MLRO's fitness and propriety as part of the registration process. A VASP that fails to maintain a substantive, active MLRO – rather than a nominal figurehead – risks both registration consequences and personal liability for the individual named.

How do regulators audit crypto AML programs?

The FCA supervises registered cryptoasset businesses through a combination of information requests, desk-based reviews and on-site visits. It assesses the whole-firm risk assessment, the customer due diligence policies, the transaction monitoring system and the MLRO's independence and reporting record. Regulators in the leading hubs increasingly expect VASPs to demonstrate not only that controls exist on paper but that they are applied in practice and reviewed periodically. A gap between the written program and operational reality is treated as a control failure, not an administrative shortcoming.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and where disputes arise, our team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP registration strategy, AML program design and cross-border compliance obligations for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours