A VASP exchanges, transfers, custodies or administers crypto assets, often several at once. Exchange, brokerage, custody, staking, on and off ramps to fiat, stablecoin issuance and settlement, OTC desks: each is a distinct regulated activity with its own AML and sanctions exposure.
The load differs from a bank's in three ways, each one raising the bar:
- Settlement is near-instant and irreversible: a control that fires after value has left is worthless.
- The counterparty is often a wallet address, not a named institution: identity and provenance are reconstructed from chain data, not read off a correspondent record.
- Value moves across borders regardless of any single regulator's perimeter: one market's VASP routinely touches the risk surface of a dozen others.
The full framework a VASP carries
- CDD and beneficial-ownership identification at onboarding.
- Sanctions screening at the wallet and the person.
- Transaction monitoring calibrated to typologies that shift monthly.
- Suspicious-activity reporting to the local financial-intelligence unit.
- The FATF Travel Rule: collect, verify and transmit originator and beneficiary data alongside a transfer.
- Blockchain analytics, source-of-funds tracing, and exposure to mixers, bridges and high-risk chains on top.
It is a live programme, not a filing.
What an examiner tests for
When a regulator or an external auditor reads a VASP programme, they are not reading the policy. They are testing whether the policy is operated. For this sector the questions are specific.
What each test looks for
- Does CDD actually establish beneficial ownership, and does EDD trigger where the risk model says it should?
- Is sanctions screening applied to wallet addresses as well as names, run against current lists, and evidenced at the moment of transfer?
- Is transaction monitoring calibrated to virtual-asset typologies, not a generic rule set bolted onto a crypto book?
- Can the firm demonstrate Travel Rule compliance end to end: data collected, counterparty VASP identified, information transmitted, sunrise-gap cases handled by a documented policy?
- Are suspicious activities escalated, decided and reported to the local FIU on a defensible timeline?
- Is there a governance record: a named MLRO, a board that sees the risk, and a testing regime that has actually run?
An examiner tests the evidence, not the intention. A programme that cannot show a screened result, a monitoring alert worked to conclusion, or a filed report on time fails, whatever the manual says.
Five service lines, weighted equally. For a VASP each one maps to a concrete piece of the programme behind the licence.
Across all 19 markets
We serve VASPs and crypto operators across all nineteen frontier and Gulf markets, evenly. No flagship, none out of reach. The regulator, the perimeter and the maturity of the regime change by jurisdiction, and the programme is calibrated to the body that will actually examine it. A few concrete anchors from the verified regulator map:
Each of these regimes tests the same underlying programme: due diligence, screening, monitoring, reporting, Travel Rule and governance. What changes is who examines it and to which standard. We build to the regulator in front of you. The full matrix, market by market:
Where the activity is limited or prohibited
We do not pretend every market is open. In some of the nineteen, virtual asset activity is restricted or banned outright, and we say so before you spend.
Kuwait maintains an absolute prohibition on virtual asset activity. No dedicated VASP regulator exists and no licences are issued: the ban is enforced jointly by the Central Bank of Kuwait, the Capital Markets Authority, the Insurance Regulatory Unit and the Ministry of Commerce and Industry. A VASP cannot be licensed there, and no programme changes that.
Elsewhere the position is not a clean yes or no:
- Dedicated regimes: the UAE through VARA, Kazakhstan through the AIFC and AFSA, Turkey through the CMB, Pakistan through PVARA.
- Perimeter-based: others regulate virtual assets through an existing securities or central-bank perimeter, not a bespoke authority, which changes what a firm can do and how the activity is characterised.
In every case we ground the position in the current framework and the named regulator, and where a rule or perimeter would decide your case, we verify it against that regulator before we advise.
The sector page tells you what we build. The market pages tell you who examines it. A handful of the VASP combinations:
The VASP licence is the easy part. We build what sits behind it.
Start with a scoping call under NDA. We map the programme you have, the programme your regulator expects, and the distance between them, including your Travel Rule position and your sanctions-screening evidence. You get a fixed-scope, fixed-fee plan within 48 hours. No hourly billing, no meter, no obligation.