EST · MMXXVI
Home/Services/Compliance Aml Travel Rule/VASP business risk assessment: Legal Counsel for Digital-Asset Firms
Compliance, AML & Travel Rule

VASP business risk assessment: Legal Counsel for Digital-Asset Firms

Vasp business risk assessment: Legal Counsel for Digital-Asset Firms. Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

Operating a virtual asset service provider (VASP) – a business that exchanges, transfers, safeguards or otherwise intermediates digital assets – without a documented, regulator-ready business risk assessment is one of the most consequential oversights a digital-asset firm can make. Enforcement actions, frozen banking rails and licence suspensions rarely announce themselves in advance. They follow the gaps regulators find in AML programs, transaction-monitoring calibrations and Travel Rule compliance stacks. This page explains what a VASP business risk assessment covers, how the process works, what the cross-border variables are, and when legal counsel adds material value.

A VASP business risk assessment is a structured legal and compliance review of the regulated activities, customer base, product set and jurisdictional footprint of a digital-asset firm. The output is a documented risk rating and a remediation roadmap. Regulators under MiCA (the EU's Markets in Crypto-Assets Regulation), VARA (Dubai's Virtual Assets Regulatory Authority), MAS (the Monetary Authority of Singapore) and the FCA (Financial Conduct Authority) in the UK all require VASPs to maintain a current, written business-wide risk assessment as a foundation of the AML/CFT compliance framework. Absent that document, a firm is exposed – regardless of how well its front-end KYC performs.

What a VASP Business Risk Assessment Actually Covers

A proper VASP business risk assessment is not a KYC checklist. It is a holistic legal map of every dimension of risk the business carries – across its regulated activities, its entity structure, its counterparties and its jurisdictions. The scope typically divides into five analytical layers.

The first layer is the regulated-activity perimeter: identifying which activities the firm conducts (exchange, transfer, custody, issuance, advisory, staking-as-a-service) and which regulatory regimes govern each. An entity holding assets for clients in an ADGM (Abu Dhabi Global Market) structure while running an exchange through a BVI company and accepting customers from Singapore is carrying three concurrent regulatory obligations. Mapping that stack is the starting point.

The second layer is the customer and product risk profile. This involves classifying the customer base by origin, transaction volumes, wallet typology and product access. High-risk indicators – jurisdictions under FATF mutual evaluation scrutiny, unhosted wallet exposure, high-frequency micro-transactions, DeFi bridge activity – each alter the residual risk score and the calibration thresholds for transaction-monitoring rules.

The third layer addresses the legal entity and group structure. A single offshore licence is rarely enough. In our practice, we regularly advise firms that assumed a Cayman or BVI registration covered their EU-resident customers; it does not under MiCA. Jurisdiction of incorporation, the location of staff who conduct regulated activities and the domicile of the customer base all interact to determine which regime actually applies.

The fourth layer is delivery channel and technology risk. This covers counterparty VASP relationships, smart contract dependencies, third-party custodians and the firm's current Travel Rule solution. FATF Recommendation 15 – the international standard that applies the Travel Rule to virtual asset transfers – requires VASPs to pass originator and beneficiary data with transactions above the applicable threshold. The precise threshold varies by jurisdiction; in our cross-border practice we have seen mismatches between the originating VASP's de-minimis setting and the receiving VASP's configuration create significant compliance gaps.

The fifth layer is governance: who is the MLRO (Money Laundering Reporting Officer), what are the escalation paths, and do the documented policies reflect actual practice? Regulators increasingly use the gap between written policy and operational reality as the primary indicator of systemic weakness.

The Regulated Basis: What Law Requires and Who Enforces It

VASP business risk assessments are mandatory – not advisory – under every major AML/CFT regime. The legal requirement flows from FATF standards, implemented into national law at varying levels of granularity.

Under MiCA and the accompanying Transfer of Funds Regulation as adapted for crypto assets, CASPs (Crypto-Asset Service Providers) operating within the EU must maintain documented, risk-sensitive AML programs that include a business-wide risk assessment. ESMA and the relevant national competent authorities assess compliance with that requirement as part of the CASP authorisation review and ongoing supervision cycle.

VARA in Dubai issues detailed rulebooks covering AML, compliance and risk management. Those rulebooks impose explicit obligations on regulated entities to maintain and periodically update a written business risk assessment, with the MLRO holding formal accountability. A firm operating under a VARA licence without a current assessment document is in breach of its supervisory conditions – a point enforcement teams have underscored in supervisory communications.

In Singapore, MAS requires Digital Payment Token service licensees under the Payment Services Act to conduct and document risk assessments covering business type, customer profile, transaction volumes and geographic reach. The MAS inspection process specifically requests evidence of that assessment.

The FCA's cryptoasset MLR registration regime requires registered firms to demonstrate a risk-based AML framework. The FCA's supervisory track record shows a pattern of de-registration actions where firms could not produce adequate risk documentation on inspection.

Across all regimes, the practical standard is the same: the assessment must be written, current, and evidenced in the firm's operations. A policy document that has not been updated since the firm doubled its customer base or added a new product line will not satisfy a regulator.

For a scoped assessment of your current AML documentation and compliance posture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking and the regulatory regime – change the analysis materially.

What Does the Assessment Process Look Like in Practice?

A legal-counsel-led VASP business risk assessment follows a structured four-phase process, typically executable within a matter of weeks for a single-jurisdiction operation – longer where a multi-entity, multi-licence structure is involved.

Phase 1 – Intake and document review. We request the firm's existing AML/KYC policies, the current MLRO terms of reference, transaction-monitoring rule sets, customer risk-rating methodology, the corporate structure chart and any prior regulatory correspondence. This phase normally takes a small number of business days and flags the most acute gaps immediately.

Phase 2 – Regulatory mapping. We map each activity the firm conducts to the applicable regime – identifying which regulator has supervisory authority, whether a licence or registration is required, what the AML/CFT obligations are and whether current policies satisfy them. Where the firm operates across borders, this mapping covers each material jurisdiction. We have seen firms in our practice operating under the mistaken belief that their AFSA (Astana Financial Services Authority) structure in the AIFC exempted them from MAS oversight of Singapore-resident customers; it did not.

Phase 3 – Risk scoring and gap analysis. Each risk dimension – customer, product, geography, delivery channel, legal entity – receives a documented score. The output is a gap register: a ranked list of compliance deficiencies with their legal basis, the applicable regime that the gap breaches and a recommended remediation action.

Phase 4 – Remediation roadmap and legal sign-off. We draft or redraft the policies and procedures that the gap analysis identifies as deficient. Where the gap requires a regulatory notification (a material change to a licence condition, for example), we manage that process with the relevant regulator. The final deliverable is a written business risk assessment document, drafted to withstand supervisory scrutiny, together with an updated MLRO accountability framework.

For a firm with a single licence and a straightforward product set, the full process is typically achievable within a compressed timeline. Multi-jurisdiction structures with concurrent VARA, MiCA and MAS obligations require more time – rarely more than a matter of months even in complex cases.

The Most Costly Mistakes VASPs Make in Business Risk Assessments

The four errors we see most frequently have one thing in common: each is invisible until a regulator or a bank looks closely.

The first is scope truncation – treating the risk assessment as a KYC document rather than a business-wide analysis. Firms document their customer onboarding process in detail but say almost nothing about counterparty VASP risk, geographic concentration in high-risk corridors, or the risk profile of the underlying blockchain infrastructure. That truncation is exactly what a supervisory review probes.

The second is stale documentation. A risk assessment completed at the time of licensing that has not been updated to reflect product launches, customer growth, new jurisdictions or regulatory change is worse than no assessment in some respects – it demonstrates that the documented process is not the operational one. Regulators treat that as a governance failure, not just a paperwork issue.

The third is Travel Rule misconfiguration. The Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual asset transfer) requires that both the originating and receiving VASP run compatible data-transfer solutions. Many firms implement a Travel Rule tool at launch and never test interoperability with their counterparty VASP set. The result is a large proportion of outgoing transfers that are technically non-compliant even though the firm believes it has a solution in place.

The fourth error is MLRO accountability diffusion. In early-stage crypto firms, the MLRO role is often held by the CFO or a founder alongside other responsibilities. Regulators – particularly VARA and the FCA – expect the MLRO to have clear, documented authority, adequate resource and a direct line to the board. Where that structure is missing, an otherwise competent AML program can fail its supervisory examination.

Cross-Border Considerations: Where One Regime Ends and Another Begins

The single most expensive misconception in VASP compliance is that a licence in one jurisdiction authorizes the firm to serve customers globally.

A CASP authorised under MiCA has EU-wide passporting rights – but that passport does not extend to the UK, to Singapore, to the UAE or to the United States. A VARA-licensed exchange in Dubai may accept clients from a range of geographies, but where it solicits, onboards or transacts with customers in jurisdictions that have their own VASP regime, those regimes independently apply. The MAS Payment Services Act, for example, has broad extraterritorial reach: providing digital payment token services to Singapore residents without a licence is an offence regardless of where the VASP is incorporated.

Banking amplifies the risk. Correspondent banks and EMI partners increasingly run their own VASP due-diligence programs. A VASP whose business risk assessment does not address cross-border flows, counterparty risk and unhosted wallet exposure will fail the bank's own AML review – and lose its account. In our practice, we regularly advise operators who discover the banking problem only after the account is closed. Rebuilding banking access from that position is materially harder than structuring correctly from the start.

The Travel Rule creates its own cross-border friction. Where an EU VASP sends assets to a non-EU VASP in a jurisdiction that has not yet implemented FATF Recommendation 15 to the same standard, the data cannot always be passed through a compliant channel. The documented risk assessment must address these gaps – and the firm must have a protocol for how it handles transfers to unresponsive or non-compliant counterparties.

Where a firm's activities span multiple regimes, allied counsel in the relevant jurisdiction are engaged to verify the local interpretation. We do not assume that a risk assessment standard developed for one regime transfers without adjustment to another.

If a prior application stalled, an account was closed, or a regulatory query arrived without warning, write to info@oboluslaw.com. A second read of the structure often surfaces the underlying reason and the path to resolution.

Which Firms Need a Full Legal-Counsel-Led Assessment?

Not every firm has the same risk profile. The decision on scope and depth of legal involvement turns on four variables: regulatory maturity, product complexity, jurisdictional spread and supervisory proximity.

Profile A – Pre-licence applicant. A firm applying for its first VASP licence (whether a CASP authorisation under MiCA, a VARA licence or a MAS DPT licence) needs a full legal-counsel-led risk assessment as a primary application deliverable. Regulators assess the quality of the written document as a signal of governance maturity. A weak assessment at this stage delays authorisation; a strong one accelerates it. Timeline from instruction to delivery is typically a small number of weeks for a focused scope.

Profile B – Licensed firm approaching a supervisory review or periodic renewal. The assessment must be current at the point of examination. Firms in this position often have an assessment on file that is one or two product generations out of date. The priority is a gap analysis against the current product and customer set, followed by rapid documentation. We work to a tight timeline in these engagements.

Profile C – Multi-jurisdiction operator adding a new market. Each new licence jurisdiction resets the regulatory-mapping requirement. A firm adding a Singapore DPT licence to an existing VARA structure must reconcile the two compliance frameworks – they are not identical. The risk assessment must reflect both regimes and document how the firm manages the points of difference.

Profile D – Firm that has received a regulatory query or notice. This is the highest-urgency profile. A regulator's written query about AML compliance or risk documentation is an early signal that enforcement attention has landed. Legal counsel involvement at this stage is essential – the response is a legal document, not an internal memo, and the stakes are the licence and the banking relationship simultaneously.

A Recent Matter

In a recent engagement, a mid-sized crypto exchange holding a VARA licence in Dubai sought to add a payment services component and expand customer onboarding to EU residents. The firm's existing AML program had been drafted at the time of the original VARA application and had not been updated in over a year. A review of the transaction-monitoring rule set showed that the Travel Rule data-transfer protocol was configured for outgoing transfers only – inbound transfers from counterparty VASPs were being received without the required originator data. Separately, the firm's planned EU activities fell squarely within the MiCA CASP regime, requiring a new authorisation that the firm had not anticipated. We produced a cross-regime risk assessment addressing both the VARA and MiCA obligations, restructured the MLRO accountability framework to satisfy both regulators' expectations, and advised on the Travel Rule configuration gap. The firm proceeded to its MiCA application with a compliant, documented compliance posture.

A Common Assumption: Does a Good KYC Tool Replace a Business Risk Assessment?

A common assumption among early-stage digital-asset firms is that sophisticated KYC technology – automated onboarding, real-time sanctions screening, behaviour-based transaction monitoring – constitutes a business risk assessment. It does not.

KYC technology addresses one dimension of regulatory compliance: the onboarding and ongoing monitoring of individual customers. A business risk assessment addresses the firm itself: its activities, its structure, its counterparties and its cross-border exposure. Regulators are explicit on this distinction. The FCA, VARA and MAS all require the business-wide assessment as a separate, documented governance artifact that sits above the operational KYC layer.

Strong technology is necessary. It is not sufficient. The written legal analysis that maps the firm's risk profile to its regulatory obligations is the document the regulator reads, the document the bank requests and the document that matters when an enforcement inquiry arrives. Investing in one without the other leaves a critical gap.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP initiating a virtual asset transfer to pass originator and beneficiary identifying information to the receiving VASP. The applicable data threshold varies by jurisdiction – each regime sets its own de-minimis level. Both the sending and receiving VASP must operate compatible data-transfer solutions. Failure to comply is a breach of the firm's AML obligations under the applicable regime, whether MiCA, the MAS Payment Services Act or VARA's rulebooks.

Who must act as MLRO for a crypto firm?

A MLRO (Money Laundering Reporting Officer) is the individual accountable for the firm's AML/CFT compliance program. Most leading regimes – including VARA, MiCA and MAS – require the MLRO to be a named individual with documented authority, adequate resource and direct board access. In smaller firms the role is sometimes shared with another function; regulators increasingly scrutinize that arrangement. The MLRO must be capable of discharging the role independently and of evidencing that to supervisors on inspection.

How do regulators audit crypto AML programs?

Regulatory audits of VASP AML programs typically involve a document request (policies, risk assessments, MLRO reports, transaction-monitoring calibration records, SAR/STR logs), a review of customer file samples and interviews with the MLRO and compliance staff. Regulators compare documented policy against operational practice. The most common findings involve stale risk assessments, untested transaction-monitoring thresholds and incomplete Travel Rule data on inbound transfers. A well-prepared business risk assessment, current at the time of review, is the primary defense against an adverse finding.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programs that regulators require. Digital assets are the whole of our practice. We map the licence and compliance stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is at issue. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML/CFT program design, VASP business risk assessments and cross-border regulatory mapping for digital-asset firms.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours