Institutional operators running digital-asset businesses face a compounding legal risk that most discover too late: the compliance posture that opened their first banking relationship is no longer adequate once the client base scales, the product set widens and regulators in multiple jurisdictions begin comparing notes. A VASP business risk assessment (a structured legal and operational review of a virtual asset service provider's AML exposure, governance and cross-border obligations) is the instrument that converts that risk into a managed programme. This page sets out the regulated basis for the assessment, the process OBOLUS applies, the common failure points we see in institutional mandates and a decision matrix to help operators identify where they sit.
Why Institutional VASPs Face a Distinct Risk Profile
Institutional clients carry a risk profile that retail-focused VASP assessments do not adequately address. The product mix – prime brokerage, custody, over-the-counter settlement, tokenized asset management – creates intersecting regulatory perimeters across multiple regimes simultaneously. A single entity may be a CASP (crypto-asset service provider) under MiCA in the EU, a licensed exchange under VARA in Dubai and a registered VASP under the BVI FSC, all at once. Each layer carries its own AML/CFT baseline, its own Travel Rule obligations and its own expectations for institutional counterparty risk.
FATF Recommendation 15 – the global standard for virtual assets and VASPs – requires member-state regimes to apply risk-based AML/CFT measures to all covered entities. The major hubs have transposed that standard into binding domestic rules. Supervisors at ESMA's partner national competent authorities, VARA and MAS are increasingly coordinating examination cycles. An institutional VASP that passes a domestic audit but has not mapped its cross-border exposure can face enforcement action in a jurisdiction it assumed was outside its regulatory perimeter.
In our cross-border practice, we regularly advise institutional operators who discovered this mismatch only after a banking correspondent began requesting enhanced due diligence documentation that the existing AML programme did not anticipate. The cost of a reactive remediation is multiples of what a structured assessment costs at the outset.
Operating without an adequate risk assessment exposes the business to enforcement, frozen banking rails and, in the worst case, regulatory revocation. That is the institutional risk in plain terms.
What Is the Regulated Basis for a VASP Risk Assessment?
Every material VASP regime now mandates a documented, risk-based assessment as a condition of authorisation and as a standing supervisory expectation. The specific content requirements vary, but the core architecture – risk appetite, customer risk rating, product risk rating, geographic risk rating and a controls map – is consistent across the flagship hubs.
Under MiCA and the underlying AML directives, CASPs authorised in any EU member state must maintain an enterprise-wide risk assessment that is proportionate to the nature, scale and complexity of the business. National competent authorities are empowered to request that document at any examination. Under the VARA regime in Dubai, the applicable rulebooks set out explicit compliance obligations, including a risk-based AML/CFT framework that must be reviewed at regular intervals and updated following material changes to the business model. MAS in Singapore requires DPT service licensees to conduct and document AML/CFT risk assessments under the applicable notices, with board-level sign-off expected.
The Travel Rule (the obligation to transmit originator and beneficiary data with virtual asset transfers above the applicable threshold) adds a second documentation layer. A VASP risk assessment that does not map Travel Rule compliance – which counterparties are covered, what the technical transmission solution is, and how unhosted-wallet transactions are handled – is incomplete by the standards of any tier-one regulator.
What the assessment is not: it is not a KYC file review. It is a legal and structural instrument, not an operational audit of individual customer accounts. Conflating the two is one of the most common mistakes we see when institutional operators commission assessments from compliance technology vendors rather than legal counsel.
How Does OBOLUS Structure the Assessment Process?
Our assessment process runs in five defined stages, each of which produces a discrete output that feeds the next.
Stage one: regulatory perimeter mapping. Before reviewing internal controls, we map every jurisdiction in which the business operates, solicits clients or processes transactions. This includes the jurisdiction of incorporation, the locations of key management and technology infrastructure, and the jurisdictions of the client base. A VASP whose entity sits in Cayman but whose institutional clients are EU-domiciled funds may be within MiCA's extraterritorial reach. We establish the full perimeter before any control review begins.
Stage two: licence and authorisation status review. We verify that the entity holds the correct licence or registration for each covered activity in each jurisdiction. Gaps between the activity map and the authorisation map are the primary source of enforcement risk in institutional mandates. We have seen businesses operating custody services under a licence that covered exchange activity only – a distinction that regulators draw sharply.
Stage three: AML/CFT programme assessment. We review the existing programme against the requirements of each applicable regime: the risk appetite statement, the customer risk classification methodology, the product and channel risk analysis, the MLRO (money laundering reporting officer) appointment, the board AML policy, the suspicious activity reporting process and the record-keeping architecture. We identify gaps against the regulatory standard and, where the gap is material, assess the enforcement exposure it creates.
Stage four: Travel Rule compliance mapping. We assess the technical and legal solution the business uses for Travel Rule transmission – whether that is a TRISA-compatible protocol, a VASP directory integration or a bilateral contractual approach with counterparties. We map the unhosted-wallet procedure, the sunrise-period legacy and any jurisdiction-specific threshold divergences.
Stage five: remediation roadmap. The final output is a prioritized action plan: critical gaps addressed immediately, significant gaps addressed within a defined window, and improvement recommendations for the medium term. The roadmap distinguishes between legal obligations and supervisory best practice, so the business allocates resources proportionately.
For a scoped assessment of your AML posture and Travel Rule compliance, contact OBOLUS at info@oboluslaw.com.
The contextual note for first-time readers: the process above describes the standard path. Your facts – the entity structure, the client base, the product set, the banking relationships – change the analysis. A business with a proprietary custody solution and institutional fund clients in three jurisdictions needs a materially different assessment from a straightforward exchange.
What Are the Most Common AML Mistakes Institutional VASPs Make?
Institutional operators make a set of recurring errors that a well-structured assessment is designed to surface before a regulator does.
The first is relying on the licensing jurisdiction's AML standard as if it were universal. A VASP authorised under the BVI FSC regime or the Cayman VASP Act is subject to FATF-aligned standards in its home jurisdiction. But if it onboards institutional clients domiciled in the EU or Singapore, the AML/CFT expectations of MiCA, ESMA and MAS become operationally relevant, even without a local licence. Correspondent banks and prime brokers already apply those higher standards when conducting their own due diligence on the VASP as a counterparty.
The second is an MLRO appointment that is nominal rather than functional. Regulators across all flagship regimes – VARA, the FCA, AFSA at the AIFC – increasingly scrutinize the MLRO's seniority, resource allocation and decision-making authority. An MLRO who holds the title but lacks access to the board and adequate staffing is a supervisory red flag, not a compliance solution.
The third is a transaction monitoring system calibrated for retail volumes and thresholds that has not been recalibrated for institutional transaction sizes and counterparty profiles. Institutional transactions are fewer in number but larger in value, and the typologies differ materially from retail. A monitoring programme that generates alerts based on retail baselines will miss the patterns that matter to a regulator examining an institutional book.
The fourth – and the one most specific to the institutional segment – is the absence of a formal counterparty VASP due diligence programme. An institutional operator that settles with other VASPs, provides liquidity to exchanges or operates as a prime broker is exposed to its counterparties' AML posture. Regulators treat that exposure as part of the VASP's own risk profile. We have seen this gap cited in supervisory correspondence even where the underlying AML programme was otherwise sound.
How Does the Cross-Border Structure Change the Risk Analysis?
Cross-border institutional structures amplify every compliance obligation. The legal question is not just which regime applies – it is which regime's standard the business must meet in order to maintain banking, retain institutional clients and avoid enforcement action in any relevant jurisdiction.
Consider a structure common in the institutional market: an operating entity in a Gulf free zone licensed by VARA or the FSRA, a custody entity in the BVI registered under the BVI FSC, and a fund-management vehicle in Cayman supervised by CIMA. Each entity has its own AML/CFT obligations. The group, however, presents to a single institutional client as one business. Supervisors in any of those three jurisdictions may request documentation of the group-wide AML programme, and a failure in one entity's programme can trigger regulatory inquiry in the others.
Banking adds a further layer. Correspondent banks conducting their own customer due diligence on an institutional VASP will evaluate the entity against the standards of the strictest relevant jurisdiction, not the domicile. A business banking in a jurisdiction with rigorous financial-crime controls must demonstrate that its AML programme meets those controls even if its regulatory home requires less.
In our practice, we map the licence, banking and AML compliance stack as a single exercise, not three separate work streams. That integration is what closes the gap between what the regulator requires, what the bank expects and what the institutional client's own due diligence will find.
Micro-matter: In a recent mandate, a multi-jurisdictional custody and settlement business approached us after its prime banking relationship was placed under review. The bank had identified inconsistencies between the entity's stated AML programme and the coverage it applied to institutional counterparties outside its licensed jurisdiction. We conducted a rapid perimeter review, identified the gap in the counterparty VASP due diligence process, restructured the documentation and produced an updated risk assessment. The banking relationship was preserved and the business subsequently passed a supervisory examination by the relevant regulator in its licensed hub.
Decision Matrix: Which Assessment Scope Fits Your Profile?
Not every institutional operator requires the same scope of assessment. The following profiles describe the three most common situations we encounter and the appropriate response in each case.
Profile A – Early-stage institutional operator, single jurisdiction, limited product set. The business is licensed or in the process of seeking authorisation in one hub, operates a defined product (exchange or custody, not both) and has a client base that is geographically concentrated. The appropriate scope is a standard VASP risk assessment covering the home regime's AML/CFT requirements, Travel Rule compliance and MLRO governance. Timeline to completion is typically a matter of weeks rather than months. The primary risk is gaps in the initial programme that will generate findings in the first supervisory examination.
Profile B – Established institutional operator, multi-jurisdictional, expanding product set. The business holds authorisations in two or more hubs, offers custody and exchange services, and is beginning to onboard institutional fund clients. The assessment scope expands to cover the full regulatory perimeter, group-wide AML programme coherence, counterparty VASP due diligence and Travel Rule technical compliance. Timeline is longer, as the perimeter mapping stage alone requires coordination with allied counsel in each relevant jurisdiction. The primary risk is conflicting compliance standards between the home regime and the banking jurisdiction.
Profile C – Institutional operator facing a regulatory inquiry or banking review. A regulator has issued a request for information, commenced an examination or an AML audit, or a correspondent bank has raised concerns about the AML programme. The assessment is no longer a planning exercise – it is an urgent remediation. The scope is determined by the regulatory request rather than an internal preference. Timeline is dictated by the regulator or the bank. The primary objective is identifying and addressing material gaps before formal enforcement action is taken.
Operators in Profile C should act without delay. If a regulatory clock is running or a bank review has been initiated, contact OBOLUS now at info@oboluslaw.com.
A Common Assumption About Offshore Licences and Global Reach
A persistent assumption among institutional operators – particularly those who established their first structure rapidly during a period of lighter regulatory scrutiny – is that a single offshore licence provides adequate cover to serve clients globally. That assumption is no longer accurate in any of the major institutional markets.
The regulatory reality is that each of the tier-one regimes – MiCA, VARA, MAS, SFC – applies its own perimeter rules to determine whether a foreign VASP serving local clients requires local authorisation. MiCA's reverse solicitation provisions are narrower than most operators assume. MAS applies a similar analysis under the Payment Services Act. The SFC in Hong Kong has publicly stated that VASPs targeting Hong Kong investors require a VATP licence regardless of where the entity is incorporated.
The institutional client base exacerbates this risk. Pension funds, family offices and institutional fund managers conducting their own due diligence on a VASP as a service provider will request evidence of regulatory authorisation in the relevant jurisdiction as a standard procurement step. A VASP that cannot provide that evidence will lose the mandate, regardless of the quality of its service.
We map the licence stack across the operating, custody and payment layers before a business commits to a structure. That mapping accounts for where the client base sits, not just where the entity is domiciled – which is the analysis that matters when a regulator or a client's compliance team asks the question.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – the full practice overview covering VASP AML obligations across all flagship regimes
- Regulator AML audit defence for institutional clients – legal support when a supervisor initiates an examination of your AML programme
- DeFi legal meaning: a guide for digital-asset operators – how decentralised finance structures interact with VASP classification and AML obligations
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect and transmit originator and beneficiary information when conducting virtual asset transfers above the applicable threshold. The specific data fields and the threshold vary by jurisdiction, but the FATF standard sets the baseline that all major regimes have transposed. VASPs must also have a procedure for transfers involving unhosted wallets, where counterparty identification is not automatic. Failure to maintain a compliant Travel Rule programme is one of the most common findings in supervisory examinations of institutional operators.
Who must act as MLRO for a crypto firm?
A MLRO (money laundering reporting officer) must be an individually appointed, sufficiently senior person responsible for the firm's AML/CFT compliance, including the review and submission of suspicious activity reports. Regulators across all major VASP regimes – including VARA, the FCA and MAS – expect the MLRO to have genuine authority, adequate resources and direct access to the board. A nominal appointment without operational authority is treated as a governance failure. In cross-border structures, each regulated entity typically requires its own MLRO appointment.
How do regulators audit crypto AML programs?
Regulators typically examine VASP AML programmes through a combination of documentation requests, onsite or remote inspection, and transaction sample reviews. They will assess the written risk assessment, the customer risk rating methodology, the transaction monitoring calibration, MLRO governance records and Travel Rule compliance evidence. National competent authorities under MiCA, VARA and MAS have all published supervisory expectations that set out the documentation they expect to find. An operator that cannot produce a current, board-approved risk assessment at the outset of an examination starts the process in a materially weaker position.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance work that sits around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – which is how institutional operators avoid the gaps that regulators and correspondent banks find first. To discuss your AML exposure or commission a VASP business risk assessment, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP AML programme design, Travel Rule compliance and cross-border regulatory risk assessments for institutional digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.