Operating a virtual asset service provider (VASP) – a business that exchanges, transfers, safeguards or administers digital assets on behalf of clients – without a defensible AML compliance architecture is one of the fastest routes to enforcement action in digital-asset markets today. Regulators across the major hubs have moved from registration-light regimes to full supervisory scrutiny, and the first test a supervisor applies is almost always the business-wide risk assessment. With FATF Recommendation 15 now embedded in domestic law across dozens of jurisdictions, a VASP that cannot produce a current, documented business risk assessment faces licence suspension, correspondent banking termination and, in serious cases, criminal referral of its officers.
A VASP business risk assessment is a structured, documented evaluation of every ML/TF risk a firm faces across its product lines, customer segments, delivery channels and geographic exposure – the foundational document that drives every downstream AML compliance and Travel Rule control. The applicable regimes include MiCA and its national competent authorities across the EU, VARA in Dubai, the MAS Payment Services Act regime in Singapore, the SFC's VASP licensing framework in Hong Kong, and the FCA's cryptoasset registration rules in the UK, among others. All of them require it. This page explains what the assessment covers, how to build one that survives regulatory scrutiny, and where cross-border operators consistently go wrong.
Why the Risk Assessment Is the Centrepiece of VASP AML Compliance
The business risk assessment is not a disclosure form. It is the document that determines the calibration of every other AML/CFT control a VASP operates. Get it wrong – or treat it as a one-time exercise – and the entire KYC framework, transaction monitoring logic and Travel Rule programme sits on an unsound foundation.
Supervisors across every major regime now expect a risk assessment that is proportionate, current and demonstrably linked to actual controls. ESMA and national competent authorities under MiCA have signalled that risk-assessment quality will be a primary supervisory priority for newly authorised CASPs (crypto-asset service providers). VARA's rulebooks require ongoing risk assessment reviews tied to material business changes. The MAS DPT licensing regime demands documented evidence that risk appetite is set at board level and reviewed at least annually.
In our practice, the most common enforcement trigger is not the absence of a risk assessment – most firms have one. It is a risk assessment that was written at authorisation and never updated, or one that identifies risks without mapping them to proportionate controls. Regulators call this a "paper programme." It satisfies no one.
Loss-aversion framing: a VASP that is found to have a paper AML programme does not receive a warning and an opportunity to remediate first. In several leading jurisdictions, the first public outcome has been an immediately effective licence suspension combined with a demand to commission an independent skilled-person review at the firm's expense. Banking correspondents monitor regulatory bulletins; a public sanction typically triggers account termination within days.
If your risk assessment has not been updated since your licence was granted, the exposure is live now. To get a scoped gap analysis started, contact OBOLUS at info@oboluslaw.com.
The process above describes the standard supervisory expectation. Your facts – the product mix, the user geography, the banking stack – change both the risk profile and the appropriate control calibration.
What a VASP Business Risk Assessment Must Cover
A compliant VASP business risk assessment addresses six core risk domains, each of which must be assessed for inherent risk, existing controls and residual risk, and each of which must be evidenced by supporting documentation the firm can produce on demand.
The six domains are: (1) customer and counterparty risk – the profile of the firm's account holders, institutional counterparties and liquidity providers; (2) product and service risk – the ML/TF characteristics of each service offered, including custody, exchange, staking, lending and settlement; (3) delivery channel risk – how the service is accessed, including whether onboarding is fully remote or in-person, and whether intermediaries are involved; (4) geographic risk – the jurisdictions in which customers are resident, in which the firm is licensed, and in which its banking and liquidity infrastructure sits; (5) transaction risk – the size, velocity and pattern of transactions the firm facilitates; (6) counterpart VASP risk – the risk profile of the VASPs and exchanges with which the firm interacts in the context of the Travel Rule (the FATF-derived obligation to pass originator and beneficiary data alongside a virtual asset transfer).
A common mistake is to treat the geographic risk domain as the jurisdiction in which the firm is incorporated. That is too narrow. FATF Recommendation 15, as implemented in the applicable VASP provisions across the EU, UAE, Singapore and the UK, requires the risk assessment to reflect where customers are located and where transactions flow – not merely where the registered office sits. A Maltese-licensed exchange whose users are predominantly resident in jurisdictions on the FATF grey list carries a different residual risk profile than the same firm serving exclusively EEA customers.
The assessment must also address the firm's exposure to anonymity-enhancing assets (privacy coins and mixing services) and to decentralised protocols, where the identity of a counterpart is not determinable through conventional KYC processes. Several competent authorities now explicitly ask whether the firm supports such assets and, if so, what compensating controls it applies.
How Does the Travel Rule Interact with the Business Risk Assessment?
The Travel Rule is not a standalone compliance module – it is a control whose scope, thresholds and operational procedures must be anchored in the business risk assessment itself. A firm that assesses its counterpart VASP pool as high-risk must apply more stringent Travel Rule procedures than one operating exclusively within a well-supervised, bilateral-agreement network.
Under the applicable VASP provisions in the EU (as updated under MiCA), the UK (under the FCA's MLR regime), Singapore (under MAS guidance) and the VARA rulebooks in Dubai, the Travel Rule requires VASPs to collect, verify and transmit originator and beneficiary information on virtual asset transfers above a specified threshold. The threshold itself is a [VERIFY]-class figure that varies by jurisdiction and is subject to ongoing revision; our practice invariably checks the current regulatory text before advising a client on de-minimis treatment.
Where a counterpart VASP cannot be identified – a transaction directed to an unhosted wallet (a wallet not held at a regulated intermediary) – the Travel Rule creates a specific risk event. The business risk assessment must document whether the firm permits such transfers, under what conditions, and what enhanced due diligence procedures apply. Regulators in Singapore and the UK have both issued guidance specifying that unhosted wallet transactions carry elevated ML risk absent compensating controls.
In our cross-border practice, we see a recurring failure at precisely this intersection: Travel Rule procedures that were written against a single jurisdiction's requirements, while the firm's actual transaction flow crosses three or four regulatory regimes. A transfer that is compliant under MAS rules may not satisfy VARA's disclosure expectations if the originating counterpart VASP is in the UAE. The risk assessment is the document that should map this multi-jurisdiction exposure and set the control standard accordingly.
The MLRO and Governance Architecture Every VASP Needs
Every major VASP licensing regime requires the appointment of a qualified MLRO (money laundering reporting officer) with sufficient seniority, independence and resource to execute the AML programme. The business risk assessment must reflect both who holds that role and the governance architecture through which the MLRO reports to the board.
VARA, ESMA's MiCA guidance, the MAS DPT framework and the FCA's MLR registration requirements all condition the quality of a VASP's AML programme on the MLRO's demonstrable competence in digital-asset-specific risk. A generalist AML officer whose background is in banking, without evidence of applied crypto-sector knowledge, will attract scrutiny during a supervisory review. Regulators increasingly expect the MLRO to be able to speak to the specific ML typologies associated with DeFi, cross-chain bridges and smart-contract-based settlement – not merely to traditional wire-transfer risk.
The governance architecture also determines how the risk assessment is approved, updated and escalated. Best practice – and the expectation of most supervisors – is board-level approval of the risk assessment annually and following any material change (a new product line, a new jurisdiction, a new liquidity provider). A risk assessment that was signed off by the compliance function without board approval is a governance gap that a skilled-person reviewer will highlight immediately.
In a recent matter, an exchange operator in a leading common-law licensing jurisdiction had appointed a well-qualified MLRO but had not given the MLRO formal access to the board's risk committee. The annual risk assessment was therefore approved by the COO alone. The regulator's inspection identified the gap, and the firm was required to commission a remediation report within a compressed timeframe. We assisted in restructuring both the governance documentation and the reporting lines before the inspection conclusion was finalised.
Cross-Border Risk Assessment Challenges: Where Multi-Jurisdictional Operators Go Wrong
For a VASP that is licensed in one jurisdiction but serves customers across several others – or that routes transactions through banking infrastructure in a third – a single-jurisdiction risk assessment is almost never sufficient. The cross-border architecture creates compounded risk exposures that must each be assessed and documented.
The most common structural failure we see is a group that operates a licensed entity in, say, an EU member state under MiCA, a separate custodian in an ADGM-regulated entity in Abu Dhabi, and a payment-processing layer running through a third-country bank – each entity with its own risk assessment written in isolation, and none of them addressing the intra-group transfer risks or the Travel Rule obligations that arise when a customer's assets move between the licensed entities.
FATF's guidance on group-wide AML programmes requires that parent entities set a group AML policy that applies minimum standards to all subsidiaries, including in jurisdictions where the local AML regime is less stringent. A VASP group that treats each entity's risk assessment as a standalone document, without a parent-level view of consolidated customer risk, geographic exposure and intra-group transaction risk, has a structural gap that will be visible in any group-level supervisory review.
The banking dimension adds a further complication. Correspondent banks that maintain payment rails for VASPs increasingly run their own due-diligence reviews of their VASP customers' AML programmes. We have seen multiple situations where a VASP's licence remained in good standing with its primary regulator but its banking relationship was terminated because the bank's compliance team, on reviewing the risk assessment, concluded it did not meet the bank's own risk appetite. The risk assessment is therefore not only a regulatory document – it is also a banking-relationship document.
To map the full compliance stack across your operating, custody and payment layers before you commit capital to a structure, contact OBOLUS at info@oboluslaw.com.
If a prior application stalled or a banking relationship was closed, a second read of your risk assessment and control architecture can surface the structural reason – and the route back.
The Risk Assessment Build Process: Steps and Decision Points
Building a VASP business risk assessment that survives regulatory scrutiny follows a defined sequence; shortcuts at any step tend to produce the "paper programme" outcome that regulators penalise.
Step one is a current-state inventory: every product, every service, every customer segment, every jurisdiction of customer residence, every transaction corridor and every material counterparty is documented. This is not a corporate-law question; it requires the involvement of product, operations and finance teams alongside legal and compliance.
Step two is inherent risk scoring: each domain (customer, product, channel, geography, transaction and counterpart VASP) is rated for inherent ML/TF risk against the applicable national risk assessment published by the relevant regulator and against FATF typologies for virtual assets. The scoring methodology must be documented and defensible.
Step three is control mapping: for each identified risk, the existing control is documented and evaluated for adequacy. This is where most firms discover gaps – not in identifying the risk, but in the honest assessment of whether the control is proportionate and operational.
Step four is residual risk determination and gap remediation planning. Where residual risk exceeds the board-approved risk appetite, a time-bound remediation plan is required before the document is final.
Step five is board approval and record-keeping. The final document, the scoring matrix and the board resolution approving it must be retained and producible on demand. For most major-hub regulators, the expectation is that these records are available within a short number of business days of a supervisory request – and in some regimes the formal inspection notice period is brief enough that pre-organisation of this documentation is not optional.
The cross-border note at each step: a firm operating across multiple regimes must align its risk assessment methodology with the most stringent applicable standard, while retaining jurisdiction-specific annexes that address local regulatory requirements. A single document with no local annexes will typically not satisfy every regulator simultaneously.
Self-Assessment Checklist: Is Your Risk Assessment Fit for a Supervisory Review?
A VASP approaching a supervisory review – or preparing for one that has not yet been announced – should work through the following checklist before external counsel is engaged, because the answers determine the scope and urgency of remediation work.
- Is the business risk assessment dated within the past twelve months, or has it been formally reviewed and reaffirmed since any material change to the business?
- Does it address all six risk domains (customer, product, channel, geography, transaction and counterpart VASP), with documented inherent risk scores, control assessments and residual risk determinations?
- Has the board formally approved the current version, and is that approval recorded in board minutes?
- Does the Travel Rule section address unhosted wallet exposure, counterpart VASP due diligence and the multi-jurisdiction transaction corridors the firm actually uses?
- Are the MLRO's qualifications and reporting lines documented, and does the MLRO have formal access to the board or its risk committee?
- Does the assessment reflect the current geographic distribution of the customer base – not just the jurisdiction of incorporation?
- Is the risk assessment consistent with the KYC framework and transaction monitoring logic actually in production, or does a gap exist between the document and the operational reality?
A common assumption is that a risk assessment produced by a large consultancy at licence application is sufficient for ongoing supervisory purposes. It is not. The document must evolve with the business. A firm that has added a staking product, onboarded institutional liquidity providers or begun serving customers in a new geographic market since the original assessment was produced has a material gap – and the regulator will ask when the assessment was last updated as one of its first questions.
Decision Matrix: Which VASP Profile Needs What Level of Assessment Work
Profile A – Early-stage VASP seeking initial authorisation under MiCA or a comparable regime: the risk assessment must be produced as part of the authorisation application. The applicable standard is set by the national competent authority's application guidance. The timeline for producing a compliant assessment from scratch is typically a matter of weeks for a simple business model, and longer for a firm with multiple product lines or a cross-border customer base. The key risk at this stage is underestimating the depth of documentation required, which causes application delays.
Profile B – Operating VASP with an existing assessment, facing an upcoming supervisory review: the priority is a gap analysis against current regulatory expectations. Supervisory standards have tightened materially since many first-generation VASP risk assessments were written. A gap analysis typically takes a shorter time than a build-from-scratch exercise, but the remediation work it identifies may be substantial. The key risk is discovering gaps after the regulator has already opened an inspection.
Profile C – Multi-jurisdictional VASP group with entity-level assessments but no group-level view: the priority is a consolidated group AML policy and a parent-level risk assessment that maps intra-group exposures and sets minimum standards for subsidiaries. This is the most complex profile. The timeline and scope depend on the number of regulated entities and jurisdictions involved. The key risk is a group supervisor identifying the absence of a consolidated view before the group has addressed it.
Profile D – VASP that has received a supervisory letter, notice of inspection or skilled-person direction: the engagement is urgent. The risk assessment must be reviewed against the specific concerns raised in the supervisory correspondence, and a response strategy must be developed before any regulatory dialogue begins. In our practice, the most important step at this stage is ensuring that nothing said in response to the regulator understates the gap or commits the firm to a remediation timeline it cannot meet.
Across all four profiles, the cross-border dimension – where the entity sits, where its users are, and where its banking and liquidity infrastructure operates – materially affects both the risk profile and the applicable regulatory standard.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – the full practice overview covering KYC, Travel Rule and ongoing supervisory compliance
- Regulator AML audit defence in Canada – how Canadian VASP operators respond to FINTRAC audit and enforcement action
- Founder relocation and tax in South Korea – structuring considerations for operators and founders expanding into or relocating from the Korean market
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15 and implemented through the applicable VASP provisions in the EU, UK, UAE, Singapore and other major hubs, requires a VASP to collect, verify and transmit originator and beneficiary information alongside each virtual asset transfer above the relevant threshold. The precise threshold varies by jurisdiction and should be checked against current regulatory text. VASPs must also conduct due diligence on counterpart VASPs before transmitting information to them, and must have documented procedures for transfers to or from unhosted wallets.
Who must act as MLRO for a crypto firm?
Most major VASP licensing regimes – including MiCA, the VARA rulebooks, the MAS DPT framework and the FCA's MLR registration requirements – require a designated MLRO with appropriate seniority, independence and digital-asset-specific compliance knowledge. The MLRO must have formal reporting lines to the board or its risk committee, sufficient resource to carry out the role, and demonstrable familiarity with the ML/TF typologies specific to virtual assets. Regulators increasingly scrutinise MLRO appointments for evidence of genuine crypto-sector competence rather than generic financial-crime background alone.
How do regulators audit crypto AML programs?
Supervisors across the major VASP regimes – including national competent authorities under MiCA, VARA, the MAS and the FCA – typically begin an AML audit by requesting the current business risk assessment, the board minutes approving it, and the KYC and transaction monitoring policies. Inspectors then test whether operational practice matches the documented controls: they may review a sample of customer files, transaction monitoring alerts and Travel Rule records. The most common finding is a gap between the documented programme and what the firm actually does. Skilled-person reviews, required at the firm's expense, are the standard consequence for material programme failures.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and KYC compliance that sit around them. We map the licence and compliance stack across operating, custody and payment layers before clients commit to a structure – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when matters escalate. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme architecture, Travel Rule implementation and supervisory review preparation for VASPs across the major licensing hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.