Operating a virtual asset service provider (VASP) – any business that exchanges, transfers, safeguards or administers digital assets for clients – means operating under regulatory regimes that are converging on a single expectation: demonstrable, documented risk management. When a regulator flags your entity for heightened scrutiny, the clock starts immediately. Frozen correspondent banking, suspended licences and formal enforcement notices are the direct consequences of an inadequate response. This page sets out what heightened scrutiny means in practice, how a structured VASP business risk assessment works, and where the cross-border complexity bites hardest.
What does heightened scrutiny mean for a VASP?
Heightened scrutiny is a regulatory designation – applied by supervisors including the Financial Conduct Authority (FCA), VARA (the Virtual Assets Regulatory Authority in Dubai), MAS (the Monetary Authority of Singapore) and national competent authorities operating under MiCA (Markets in Crypto-Assets Regulation) – that signals the regulator has identified material gaps in a VASP's AML/CFT controls, risk framework or governance. It is not a final sanction. It is, however, a hard deadline: the entity must respond with evidence-backed remediation.
The designation typically follows a supervision cycle: an initial assessment, a desk review of submitted AML documentation, and either a thematic examination or a targeted on-site inspection. FATF Recommendation 15, which applies to virtual assets across all major regimes, sets the floor for what supervisors expect to find. In our cross-border practice, we have seen entities miss that floor not because they have no AML program, but because the program was never scoped to the actual product and customer risk the business carries.
The practical consequence is acute. Correspondent banks monitor regulatory status. A heightened-scrutiny designation – or the mere rumour of one in the market – can trigger a banking relationship review. For a VASP that depends on fiat on-ramps and off-ramps, that is an existential risk, not an administrative inconvenience.
We regularly advise VASPs at the point when a supervisory letter arrives. The first priority is always the same: establish the factual basis for the designation and scope the remediation before responding to the regulator.
To assess your exposure before a regulator does, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. An early mapping session typically surfaces the structural issue faster than any internal review.
What is the regulatory basis for a VASP risk assessment?
Every major regime requires VASPs to conduct and document a business risk assessment (BRA) – a structured evaluation of the ML/TF risks inherent in the entity's products, customers, geographies and delivery channels. Under MiCA and the applicable CASP authorisation requirements administered by ESMA and national competent authorities, the BRA is a pre-authorisation condition and an ongoing obligation. Under the VARA regime in Dubai, VARA's rulebooks require equivalent documented risk identification as a licence condition. Under the MAS Payment Services Act, DPT service providers face analogous obligations tied to MAS's AML/CFT notices.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) adds a second layer. A VASP that cannot demonstrate Travel Rule compliance – including its technical solution, its counterparty VASP due-diligence process and its handling of unhosted wallets – will rarely survive a heightened-scrutiny examination intact. The Travel Rule threshold and the specific data fields required vary by jurisdiction, but the underlying FATF standard is consistent.
The FCA's MLR (Money Laundering Regulations) registration regime in the UK, FINMA's AML affiliation requirements in Switzerland, and the AFSA digital-asset framework in the AIFC (Astana Financial Services Authority in Kazakhstan) each apply similar principles. The common thread: the BRA must be risk-based, evidence-grounded and proportionate to actual activity – not a generic template downloaded from the internet.
In our practice, we see one regulatory mistake consistently: operators treat the BRA as a one-time document produced at licensing rather than a live control that evolves with the business. When the product changes – a new staking service, a fiat corridor to a new geography, a custody offering added mid-cycle – the BRA must be updated. Regulators now routinely compare BRA vintage against product launch dates.
How does a VASP business risk assessment process work?
A defensible VASP business risk assessment follows a structured sequence, and cutting any step creates a gap a regulator will find.
The first step is scope definition: map every regulated activity the entity carries out – exchange, transfer, custody, administration, issuance – against the applicable regime in each jurisdiction where users or counterparties are located. A VASP licensed in one hub but serving users in multiple markets carries multi-regime risk that a single-jurisdiction BRA will not capture.
The second step is inherent risk identification. Products with anonymising features, high-velocity transaction patterns, peer-to-peer settlement and exposure to jurisdictions on FATF's grey or black lists each carry elevated inherent risk scores. The BRA must document these explicitly, with reference to the relevant FATF typologies and any sector guidance issued by the applicable regulator.
The third step is control assessment: for each identified risk, evaluate the control in place – the KYC framework, the transaction monitoring logic, the Travel Rule solution, the sanctions screening layer. The control assessment must be honest. A control that exists on paper but is not operationally effective is a liability, not an asset, in a regulatory review.
The fourth step is residual risk scoring and the response matrix: where residual risk remains above appetite, document the mitigant, the timeline for remediation and the responsible owner. This is the section a regulator scrutinises hardest during an audit.
The fifth step is governance and sign-off: the BRA must be reviewed and approved at board or senior management level. The MLRO (Money Laundering Reporting Officer) typically leads the process, but ultimate accountability sits with senior management – a point VARA, MAS and ESMA's supervisory expectations all make explicit.
What are the most common mistakes VASPs make under heightened scrutiny?
The most common mistake is treating a heightened-scrutiny designation as a documentation problem rather than a structural one. Submitting a revised AML policy without addressing the underlying gap – a transaction monitoring system that does not alert on typologies relevant to the product, a KYC framework calibrated to retail risk when the business serves institutional counterparties – only invites a follow-up examination.
A second persistent failure is the mismatch between the Travel Rule solution and the actual transaction flow. Many VASPs implement a Travel Rule tool that addresses transfers to and from other regulated VASPs but fails to handle unhosted-wallet transactions in a documented, defensible way. Regulators including the FCA and MAS have issued specific expectations on unhosted wallet risk, and VARA's rulebooks address the point directly.
A third mistake is MLRO resourcing. An MLRO who holds the role nominally but lacks the authority, budget and bandwidth to operate independently creates a governance gap that supervision will expose. The expectation under virtually every applicable regime is that the MLRO can escalate to the board and, if necessary, to the regulator without interference from the commercial side of the business.
We have also seen entities under heightened scrutiny make the mistake of responding to the regulator directly, without legal review, on the assumption that transparency will be interpreted as cooperation. Transparency matters. But the form of the response – what you volunteer, how you characterise the gap, what remediation timeline you commit to – has significant implications for the scope and duration of the enhanced supervision period that follows.
If a prior application stalled, an account was closed or a supervisory letter has arrived, a structured second read often surfaces both the root cause and the route back. Contact OBOLUS at info@oboluslaw.com to scope a review under NDA.
How does the cross-border structure affect a VASP risk assessment?
The cross-border dimension is where single-entity risk assessments most often fail. A VASP incorporated in one jurisdiction, licensed in a second, banking through a third and serving users across multiple markets carries a risk profile that no single regime's template fully addresses. The BRA must reflect the actual operational map, not the licensing map.
Under MiCA, a CASP authorised in one EU member state can passport across the EU and EEA – but the passporting entity still carries host-state AML obligations for local customers, and the home-state supervisor retains primary oversight of the BRA. When the home state's national competent authority applies heightened scrutiny, the effect flows across every market where the passport operates. Operators we advise routinely underestimate that transmission effect.
Outside the EU, the issue is more acute. A VASP using a BVI FSC registration or a Cayman CIMA licence as its primary regulatory anchor, while routing user activity through a Dubai VARA-licensed operating entity and settling through a Singapore-regulated payment institution, carries three distinct regulatory perimeters. Each regulator expects a BRA that reflects its own regime's risk factors. A consolidated group-level BRA is a starting point, not a solution.
The banking layer adds a further dimension. Correspondent banks apply their own enhanced due diligence to VASP clients – driven in part by FATF guidance on virtual asset exposure and in part by their own internal risk appetite. A VASP under heightened regulatory scrutiny will typically face parallel pressure from its banking relationships. Addressing the regulatory gap and the banking relationship simultaneously, with a consistent narrative, requires coordination that many operators do not have in place.
In a recent matter, a payments-focused VASP operating across two jurisdictions received simultaneous supervisory queries from regulators in both markets. The underlying issue was a gap in the Travel Rule implementation that created a reconciliation failure on cross-border transfers. We worked with the entity to rebuild the Travel Rule process documentation, align the two regulatory responses and brief the correspondent bank – averting a formal enforcement referral in both markets.
Which VASP profile needs what kind of risk assessment?
Not every VASP faces the same regulatory exposure, and the appropriate scope of a BRA varies with the entity's activity, structure and user base.
Profile A – A startup VASP seeking initial CASP authorisation under MiCA needs a foundational BRA that maps inherent risk against the specific services applied for, documents the KYC framework and transaction monitoring baseline, and addresses Travel Rule readiness. The timeline for building this from scratch is typically a matter of weeks for a single-service entity, longer for a multi-service applicant. The key risk at this stage is underscoping – producing a BRA that addresses the licensing template but not the actual product pipeline.
Profile B – An established VASP under heightened scrutiny from its home regulator needs a gap-analysis-first approach: identify what the regulator has flagged, map the gap against the existing BRA and control environment, and produce a remediation plan with defensible timelines. The urgency is high. Responding to a heightened-scrutiny designation without a structured gap analysis risks committing to remediation steps that do not address the root cause.
Profile C – A multi-jurisdictional group with a consolidated licence structure needs a BRA architecture that works at both entity and group level, addresses each regulator's specific expectations, and maintains consistency across the consolidated AML narrative. This profile typically requires coordination with allied counsel in the relevant jurisdictions where local regulatory relationships are involved.
Profile D – A VASP adding a new product or corridor mid-cycle – for example, introducing a staking service, a custody tier or a new fiat on-ramp geography – needs a BRA update process, not a full rebuild. The update must be documented, approved at the appropriate governance level and filed or disclosed as the applicable regime requires. Operators we advise increasingly treat the BRA update as a product-launch gate, not an afterthought.
Is a single offshore licence enough to manage VASP compliance globally?
A common assumption among early-stage digital-asset businesses is that a single offshore registration – in the BVI, Cayman or a similar jurisdiction – provides adequate regulatory cover for a global user base. It does not. This assumption is one of the most consequential misconceptions in the sector, and regulators in the leading hubs have moved aggressively to address it.
The legal basis is straightforward. Most major regimes apply on the basis of where the client is located, not where the VASP is incorporated. A BVI-registered VASP serving UK retail customers is subject to FCA registration requirements under the MLR, regardless of where it is domiciled. A Cayman-registered entity providing services to users in an EU member state is subject to MiCA's CASP authorisation requirements for those users. The offshore registration does not displace the host-state obligation.
The practical consequence is that an entity discovered to be operating without the required authorisation in a jurisdiction where it actively serves clients faces the full force of that jurisdiction's enforcement regime: civil penalties, criminal referrals in serious cases, and the reputational damage that comes with a public enforcement notice. Banking relationships in that market are typically the first casualty.
The correct approach is a licence-stack analysis: map where the regulated activity occurs against the regime that applies in each market, assess the licensing obligation, and build the structure accordingly. We map the licence stack across operating, custody and payment layers before you commit – because the cost of a gap discovered in enforcement is orders of magnitude higher than the cost of the analysis upfront.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – the full practice overview covering KYC, transaction monitoring and Travel Rule implementation across leading regimes
- Regulator AML audit defence – the disputes angle – analysis of how enforcement and litigation risk interact when a regulator escalates an AML audit
- Corporate tax residency planning for regulated entities – how tax residency interacts with licensing strategy for multi-jurisdictional VASP structures
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, grounded in FATF Recommendation 16 as applied to virtual assets, requires a VASP to collect and transmit originator and beneficiary information alongside a virtual asset transfer above the applicable threshold. The specific data fields and de-minimis threshold vary by jurisdiction, but the core obligation – pass the information, verify it, and retain records – is consistent across the regimes of MiCA, VARA, MAS and the FCA. Compliance requires both a technical solution and a documented counterparty VASP due-diligence process.
Who must act as MLRO for a crypto firm?
The MLRO (Money Laundering Reporting Officer) must be a named individual with sufficient seniority, independence and operational authority to perform the role effectively. Under virtually every applicable regime – including the FCA's MLR requirements, VARA's rulebooks and MAS's AML/CFT notices – the MLRO must be approved or notified to the regulator and must have direct access to senior management and the board. A nominal appointment that lacks real authority is a governance gap that supervision will identify. In our practice, we assess MLRO resourcing as part of any BRA review.
How do regulators audit crypto AML programs?
Regulators audit crypto AML programs through a combination of desk-based document reviews, on-site or virtual examinations, and thematic inspections targeting specific risk areas – transaction monitoring calibration, Travel Rule implementation and customer due diligence are among the most common focuses. Supervisors including ESMA's national competent authorities, VARA and the FCA have each issued detailed supervisory expectations. A regulator reviewing an AML program will compare the documented BRA against actual transaction activity, alert rates and escalation records. Gaps between the documented control and the operational reality are the most common trigger for heightened scrutiny.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit – because enforcement-stage discovery costs multiples of upfront legal analysis. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where matters escalate. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP AML program design, heightened-scrutiny responses and cross-border compliance architecture for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.