Sector 01 / 09  ·  VASP · Crypto

The VASP licence is the easy part. We build what sits behind it.

Virtual asset service providers carry one of the heaviest financial-crime loads in regulated finance, in real time. Black Sea builds, remediates and runs the AML/CFT, sanctions and Travel Rule programme a VASP licence assumes is already there. We are the reviewer, not the seller: no exchange fees, no tooling commissions.

Sector VASP / Crypto Coverage 19 markets Operator-side Travel Rule end to end
Scroll
OPERATIONAL
6
Distinct load factors
19
Markets served
5
Service lines
100%
Operator-side
02

A VASP exchanges, transfers, custodies or administers crypto assets, often several at once. Exchange, brokerage, custody, staking, on and off ramps to fiat, stablecoin issuance and settlement, OTC desks: each is a distinct regulated activity with its own AML and sanctions exposure.

The load differs from a bank's in three ways, each one raising the bar:

  • Settlement is near-instant and irreversible: a control that fires after value has left is worthless.
  • The counterparty is often a wallet address, not a named institution: identity and provenance are reconstructed from chain data, not read off a correspondent record.
  • Value moves across borders regardless of any single regulator's perimeter: one market's VASP routinely touches the risk surface of a dozen others.
The full framework a VASP carries
  • CDD and beneficial-ownership identification at onboarding.
  • Sanctions screening at the wallet and the person.
  • Transaction monitoring calibrated to typologies that shift monthly.
  • Suspicious-activity reporting to the local financial-intelligence unit.
  • The FATF Travel Rule: collect, verify and transmit originator and beneficiary data alongside a transfer.
  • Blockchain analytics, source-of-funds tracing, and exposure to mixers, bridges and high-risk chains on top.

It is a live programme, not a filing.

R/01
Identity from chain
Provenance reconstructed from addresses, not correspondent records.
R/02
Irreversible settlement
Controls must clear before value leaves, not after.
R/03
Sanctions at the wallet
Screening the address and the person, against moving lists.
R/04
Travel Rule
Originator and beneficiary data collected, verified and transmitted.
R/05
Typology drift
Monitoring rules that decay unless they are re-tuned.
R/06
Cross-border by default
One licence, many regulators' risk surfaces.

What an examiner tests for

When a regulator or an external auditor reads a VASP programme, they are not reading the policy. They are testing whether the policy is operated. For this sector the questions are specific.

What each test looks for
  • Does CDD actually establish beneficial ownership, and does EDD trigger where the risk model says it should?
  • Is sanctions screening applied to wallet addresses as well as names, run against current lists, and evidenced at the moment of transfer?
  • Is transaction monitoring calibrated to virtual-asset typologies, not a generic rule set bolted onto a crypto book?
  • Can the firm demonstrate Travel Rule compliance end to end: data collected, counterparty VASP identified, information transmitted, sunrise-gap cases handled by a documented policy?
  • Are suspicious activities escalated, decided and reported to the local FIU on a defensible timeline?
  • Is there a governance record: a named MLRO, a board that sees the risk, and a testing regime that has actually run?

An examiner tests the evidence, not the intention. A programme that cannot show a screened result, a monitoring alert worked to conclusion, or a filed report on time fails, whatever the manual says.

Test
CDD and beneficial ownership established, EDD triggered on risk.
Test
Wallet-level and name-level sanctions screening, current lists, evidenced at transfer.
Test
Monitoring tuned to virtual-asset typologies, not generic rules.
Test
Travel Rule end to end, sunrise gaps handled by policy.
Test
SAR and STR escalation, decision and filing on a defensible timeline.
Test
Governance: named MLRO, board oversight, a testing regime that has run.

Five service lines, weighted equally. For a VASP each one maps to a concrete piece of the programme behind the licence.

S/01
Licensing and new-regime programme build
We build the compliance the licence assumes.
We construct the AML/CFT and sanctions programme the regulator expects operating on day one: risk assessment, CDD and EDD framework, screening and monitoring design, Travel Rule solution and governance. Lawyers file the application. We build what it certifies.
S/02
Remediation
The programme after the finding.
After an enforcement action, an adverse audit or a regulator's finding, we rebuild the failed controls, clear the backlog, and produce evidence the remediation is real and can survive a re-examination.
S/03
Outsourced and bridge MLRO, with a managed FIU function
The programme as a live function.
We run the MLRO role, permanently outsourced or as a bridge while you recruit, and operate the financial-intelligence capability behind it: alert triage, investigation, source-of-funds tracing and reporting to the local FIU. A named, accountable officer, not a policy on a shelf.
S/04
Independent AML audit
The reviewer, not the seller.
We conduct the independent audit a VASP framework requires, testing the programme against the local rule set and FATF standards, and report the uncomfortable finding plainly. We sell no software and take no commissions, so nothing we earn depends on the answer.
S/05
Sanctions, export-control and integrity DD, including the Travel Rule
Screening that holds.
We build and test wallet-level and counterparty sanctions screening, integrity due diligence on counterparties and beneficial owners, and full FATF Travel Rule compliance across the originator and beneficiary data chain.
See how we work →

Across all 19 markets

We serve VASPs and crypto operators across all nineteen frontier and Gulf markets, evenly. No flagship, none out of reach. The regulator, the perimeter and the maturity of the regime change by jurisdiction, and the programme is calibrated to the body that will actually examine it. A few concrete anchors from the verified regulator map:

UAE
VARA (Virtual Assets Regulatory Authority), with ADGM FSRA and DIFC DFSA in the financial free zones, and the CMA at federal level.
Kazakhstan
AFSA (Astana Financial Services Authority) inside the AIFC, with the AFM as the national financial-monitoring agency.
Turkey
CMB / SPK (Capital Markets Board of Türkiye), with MASAK as the financial-crimes body.
Nigeria
SEC (Securities and Exchange Commission), alongside the CBN.
South Africa
FSCA (Financial Sector Conduct Authority), with the FIC as the financial-intelligence centre.
Bahrain
CBB (Central Bank of Bahrain).
Georgia
NBG (National Bank of Georgia).
Pakistan
PVARA (Pakistan Virtual Assets Regulatory Authority).

Each of these regimes tests the same underlying programme: due diligence, screening, monitoring, reporting, Travel Rule and governance. What changes is who examines it and to which standard. We build to the regulator in front of you. The full matrix, market by market:

Even coverage. 19 markets. One programme, calibrated per regulator.

Where the activity is limited or prohibited

We do not pretend every market is open. In some of the nineteen, virtual asset activity is restricted or banned outright, and we say so before you spend.

Kuwait maintains an absolute prohibition on virtual asset activity. No dedicated VASP regulator exists and no licences are issued: the ban is enforced jointly by the Central Bank of Kuwait, the Capital Markets Authority, the Insurance Regulatory Unit and the Ministry of Commerce and Industry. A VASP cannot be licensed there, and no programme changes that.

Elsewhere the position is not a clean yes or no:

  • Dedicated regimes: the UAE through VARA, Kazakhstan through the AIFC and AFSA, Turkey through the CMB, Pakistan through PVARA.
  • Perimeter-based: others regulate virtual assets through an existing securities or central-bank perimeter, not a bespoke authority, which changes what a firm can do and how the activity is characterised.

In every case we ground the position in the current framework and the named regulator, and where a rule or perimeter would decide your case, we verify it against that regulator before we advise.

Prohibited
Kuwait: absolute ban, no licences issued.
Dedicated regime
UAE (VARA), Kazakhstan (AFSA / AIFC), Turkey (CMB / SPK), Pakistan (PVARA), and others.
Perimeter-based
Several markets regulate virtual assets through an existing securities or central-bank framework.
We verify first
The licensing position is checked against the named regulator before we scope.

The sector page tells you what we build. The market pages tell you who examines it. A handful of the VASP combinations:

See all markets and sectors →
PartnershipLocal partnersLicensed local law-firm and compliance partners in our markets.Partners →
Published workBriefing seriesA standing series on frontier and Gulf financial-crime regulation, including virtual-asset supervision.Insights →
CredentialsCAMS / ICACredentialed practitioners, with front-line KYC and financial-intelligence experience on the team.The firm →
Fresh proofVerifiable todayCurrent dated evidence rather than client references. The briefing series runs continuously, tracking virtual-asset supervision across the theatre, and has independent Kazakh press pickups. No published client names, no invented case studies.The record →

The VASP licence is the easy part. We build what sits behind it.

Start with a scoping call under NDA. We map the programme you have, the programme your regulator expects, and the distance between them, including your Travel Rule position and your sanctions-screening evidence. You get a fixed-scope, fixed-fee plan within 48 hours. No hourly billing, no meter, no obligation.

NDA-first scoping. Fixed-scope plan within 48 hours. No hourly billing.
Book a scoping call → Get a costed plan →