Skip to main content
Category: Virtual Assets and Technology

VASP Registration

Also known as: Virtual Asset Service Provider Registration, VASP notification
Simply put

VASP registration is the process by which a business that provides services involving virtual assets (such as crypto exchange or custody) formally notifies or applies to its regulator before operating. In some jurisdictions it is a lighter-touch step where the provider simply informs the regulator of its intention to operate, while in others it involves a more formal application. The exact requirements, and whether registration or a fuller license is needed, vary considerably by jurisdiction.

Formal definition

VASP registration refers to a regulatory requirement, applied to Virtual Asset Service Providers, to notify or apply to the relevant supervisory authority prior to or as a condition of conducting virtual asset activities such as exchange, transfer, or custody. The nature of the obligation differs across regimes: in some frameworks it operates as a lighter-touch notification mechanism through which a VASP informs its regulator of its intention to operate, while other regimes require submission of a formal registration application to the competent authority (for example, a national central bank or financial services authority). Registration should be distinguished from full authorization or licensing, which typically imposes more extensive conditions; some jurisdictions phase these obligations or exempt certain entity categories from registration while still requiring notification. Practitioners should confirm the applicable scope, thresholds, entity classifications, and whether registration versus licensing applies against the specific regulation and supervisory guidance governing the jurisdiction in question.

Why it matters

VASP registration is a foundational gateway control in the regulation of virtual asset activity. By requiring providers of exchange, transfer, or custody services to notify or apply to a supervisory authority before operating, regimes create a point of visibility over an otherwise fast-moving and cross-border sector. Without such a step, regulators would have limited ability to identify who is offering virtual asset services within their jurisdiction, to assess their AML/CFT controls, or to bring them within the perimeter of supervision. Registration therefore supports the broader effort to detect, deter, and manage the money laundering and terrorist financing risks associated with virtual assets, though it should not be understood as a guarantee that any registered provider is free of such risk.

Who it's relevant to

Virtual Asset Service Providers
Businesses offering services such as crypto exchange, transfer, or custody are the direct subjects of these requirements. They must determine whether they fall within their jurisdiction's VASP definition and whether a notification, a registration application, or a fuller license applies before commencing operations. Because obligations and entity classifications differ by regime, providers operating across borders may face multiple, non-identical requirements.
Compliance and MLRO Functions
Compliance officers and money laundering reporting officers within virtual asset firms are responsible for identifying the applicable registration obligations, preparing submissions to the supervisory authority, and ensuring that AML/CFT controls meet the standards expected as a condition of, or alongside, registration. They must also track phased or transitional requirements that may change what is required over time.
Supervisory and Regulatory Authorities
National central banks and financial services authorities that administer VASP registration, such as the Central Bank of Ireland or the Cayman Islands Monetary Authority, use the process to bring virtual asset providers within their supervisory perimeter, assess controls, and maintain visibility over who is offering these services in their jurisdiction.
Legal and Advisory Professionals
Lawyers and consultants advising virtual asset businesses assist in interpreting whether registration or full licensing applies, mapping obligations across jurisdictions, and managing the distinctions between notification-based and application-based regimes, as well as any exemptions or phased treatment for particular entity categories.

Inside VASP Registration

Definition of VASP
A Virtual Asset Service Provider is, in the FATF conceptual framing, a natural or legal person that conducts one or more specified activities as a business on behalf of another person, typically including exchange between virtual assets and fiat currencies, exchange between different virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets, and participation in and provision of financial services related to an issuer's offer or sale of a virtual asset. The precise scope of who qualifies as a VASP varies by jurisdiction, and some activities or actors that fall within the FATF standard may be excluded or defined differently under national law.
Registration versus licensing
Jurisdictions differ in whether they impose a registration regime, a licensing regime, or both. Registration generally establishes that an entity has notified and been recorded by the competent authority as an obliged entity, while licensing typically involves a more substantive authorization and fitness assessment before operations may commence. The applicable obligations and thresholds should be confirmed against the specific national regime.
Competent authority and source instrument
The body responsible for VASP registration and the legal basis for it differ by regime. For example, requirements may stem from FATF Recommendation 15 as an international standard (which is not binding law), from EU instruments, from FinCEN money services business rules under the US Bank Secrecy Act, or from the UK Money Laundering Regulations administered by the relevant supervisor. Practitioners should identify the correct instrument and supervisor for each jurisdiction of operation.
AML/CFT program obligations arising from registration
Registration or licensing typically brings a VASP within the scope of anti-money laundering and counter-terrorist-financing obligations as an obliged entity. These generally include customer due diligence, ongoing monitoring, record-keeping, and suspicious transaction or activity reporting, though the exact obligations and terminology depend on the applicable regime.
Fit and proper / beneficial ownership assessment
Many registration or licensing regimes require disclosure and assessment of the entity's beneficial owners, controllers, and senior management. Beneficial ownership (the natural persons who ultimately own or control the entity) is distinct from legal ownership (the registered holders), and regimes may assess both as part of an integrity or fitness check.
Travel Rule applicability
Registered VASPs are, in many jurisdictions, subject to requirements to obtain, hold, and transmit originator and beneficiary information for virtual asset transfers, reflecting the FATF standard commonly referred to as the Travel Rule. The specific data elements, thresholds, and implementation timelines vary by jurisdiction and should be confirmed against local rules.
Cross-border and scope considerations
Because VASP activity is frequently cross-border, an entity may face registration or licensing obligations in multiple jurisdictions depending on where it operates, targets customers, or is established. What falls in or out of scope, for example certain peer-to-peer arrangements or purely software-provision activities, differs between regimes.

Common questions

Answers to the questions practitioners most commonly ask about VASP Registration.

Is VASP registration the same thing as being licensed to operate a virtual asset business?
Not necessarily. In many jurisdictions, registration for AML/CFT purposes and licensing to conduct virtual asset activity are distinct processes administered under different frameworks, and sometimes by different authorities. AML registration typically focuses on bringing the entity within the scope of AML/CFT supervision and obligations, whereas a broader operating licence may address prudential, conduct, consumer protection, or market-integrity requirements. Some regimes combine these into a single authorisation while others keep them separate, so the relationship should be confirmed against the applicable local rules. Being registered for AML purposes does not, by itself, confirm that an entity holds all other authorisations it may need.
Does registering as a VASP mean the provider has been vetted and its customers or transactions are safe?
No. Registration generally signals that an entity has come within the scope of AML/CFT supervision and has met the applicable registration criteria at the point of assessment; it is not a certification that any particular customer, transaction, or asset is legitimate or low-risk. Registration status is a supervisory and gatekeeping measure, not a guarantee against financial crime. Registered VASPs remain subject to ongoing obligations and supervision, and registration does not eliminate the money laundering, terrorist financing, or fraud risks associated with their activities.
How does a business determine whether its activities require VASP registration?
The starting point is typically the definition of virtual asset service provider used in the applicable jurisdiction, which draws in many cases on the FATF standards but is transposed differently across regimes. Businesses generally assess whether they conduct qualifying activities, such as exchange between virtual assets and fiat or between virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets, or participation in and provision of financial services related to an issuer's offer or sale of a virtual asset. Because scope, terminology, and covered activities vary by jurisdiction, the specific definitions and any exemptions should be confirmed against the local instruments, and legal advice is often warranted for borderline models such as certain decentralised or non-custodial arrangements.
What AML/CFT obligations typically apply once a VASP is registered?
Once within scope, VASPs are generally treated as obliged entities and are typically expected to implement risk-based AML/CFT programmes. These commonly include customer due diligence and, where warranted, enhanced due diligence, ongoing monitoring, sanctions and PEP screening as applicable, suspicious activity or transaction reporting to the relevant financial intelligence unit, record-keeping, and governance measures such as appointing a compliance officer. Many regimes also apply travel-rule-type requirements to virtual asset transfers. The precise obligations, thresholds, and reporting mechanics differ by jurisdiction and should be confirmed against the applicable regulations.
What happens if a VASP operates without the required registration?
Operating without a required registration is generally treated as a regulatory breach and, in some jurisdictions, may constitute a criminal offence. Potential consequences can include enforcement action, orders to cease activity, financial penalties, and, in certain regimes, personal liability for responsible individuals. The nature and severity of consequences vary significantly by jurisdiction and by the applicable instrument, so specific penalties should be confirmed against the relevant local law rather than assumed.
How does VASP registration interact with cross-border operations?
Registration is typically jurisdiction-specific, so being registered in one jurisdiction does not generally confer the right to provide services in another. A VASP offering services to customers in multiple jurisdictions may need to assess registration or authorisation requirements in each relevant location, and it may face differing definitions of covered activity, differing thresholds, and differing supervisory expectations. Because regimes diverge and the treatment of inbound cross-border services varies, entities operating across borders should confirm their obligations in each applicable jurisdiction rather than relying on a single home registration.

Common misconceptions

A single global VASP registration exists that grants worldwide authorization to operate.
There is no single global regime. FATF Recommendation 15 sets an international standard that is not itself binding law, and jurisdictions implement VASP registration or licensing differently. An entity generally must comply separately with the requirements of each jurisdiction in which it operates or offers services.
Registration and licensing mean the same thing.
These are not interchangeable. Registration generally records an entity as an obliged entity with the competent authority, whereas licensing typically involves a more substantive authorization and fitness assessment before operations may begin. Some jurisdictions use one, some the other, and some both; the applicable requirement should be confirmed against the relevant national regime.
Once a VASP is registered, it has satisfied its financial crime obligations.
Registration is generally an entry point that brings the entity within scope as an obliged entity rather than an endpoint. Registered VASPs typically remain subject to ongoing AML/CFT obligations such as customer due diligence, monitoring, record-keeping, and suspicious activity reporting, and in many jurisdictions to Travel Rule requirements. These measures are intended to manage and mitigate risk, not to guarantee prevention of financial crime.

Best practices

Map every jurisdiction in which the entity operates, is established, or targets customers, and confirm the applicable registration or licensing requirement and competent authority for each rather than assuming a single regime applies.
Verify against the specific national instrument whether the activities performed fall within the local definition of a VASP, and document which activities are in scope and which are treated as out of scope.
Distinguish registration from licensing in your compliance planning, and confirm any thresholds, timelines, and pre-operation authorization requirements directly against the applicable regulation rather than relying on general summaries.
Build the AML/CFT program obligations that follow from obliged-entity status, customer due diligence, ongoing monitoring, record-keeping, and suspicious transaction or activity reporting, into operations from the outset, and confirm the exact requirements and terminology used in each jurisdiction.
Assess and document beneficial ownership as distinct from legal ownership, along with controllers and senior management, to meet fit-and-proper or integrity requirements where they apply.
Confirm the applicability, data elements, and thresholds of Travel Rule requirements in each relevant jurisdiction, treating exact values as items to be verified against the applicable regulation rather than assumed.