Skip to main content
Category: Virtual Assets and Technology

Virtual Asset Service Provider (VASP)

Also known as: VASP, Virtual asset service provider, crypto asset service provider
Simply put

A Virtual Asset Service Provider (VASP) is a person or business that provides services involving virtual assets (crypto assets) on behalf of others, for example, exchanging, transferring, or safekeeping cryptocurrency. A virtual asset is any digital representation of value that can be digitally traded, transferred, or used for payment. Because VASPs handle value that can move quickly and across borders, they are commonly brought within anti-money laundering frameworks, though the exact obligations depend on the jurisdiction where confirmation should be sought.

Formal definition

Under the FATF conceptual framework, a VASP is any natural or legal person that, as a business, conducts one or more of the following activities or operations for or on behalf of another natural or legal person: (i) exchange between virtual assets and fiat currencies; (ii) exchange between one or more forms of virtual assets; (iii) transfer of virtual assets; (iv) safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets; and (v) participation in, and provision of, financial services related to an issuer's offer and/or sale of a virtual asset. A 'virtual asset' is a digital representation of value that can be digitally traded, transferred, or used for payment. The 'as a business' and 'for or on behalf of another' elements are integral to the definition: activity conducted purely for one's own account, or on a non-business basis, generally falls outside the VASP perimeter. The FATF Recommendations are international standards rather than binding law; whether and how the VASP definition is implemented, including licensing, registration, and thresholds, varies by jurisdiction and should be confirmed against the applicable national regime.

Why it matters

The VASP concept is central to how anti-money laundering frameworks have been extended to the crypto asset sector. Virtual assets can be traded, transferred, or used for payment digitally, often at speed and across borders, which creates money laundering and terrorist financing risks that traditional financial-institution controls were not originally designed to address. By defining a category of persons and businesses that provide services involving virtual assets on behalf of others, the FATF conceptual framework gives national regulators a reference point for bringing exchanges, transfer services, and custodians within registration, licensing, and AML/CFT obligations. Whether a given actor is treated as a VASP determines whether it must, in the relevant jurisdiction, implement customer due diligence, monitoring, and reporting measures, or whether it falls outside the regulated perimeter entirely.

Who it's relevant to

Crypto exchanges, transfer services, and custodians
Businesses that exchange virtual assets for fiat or other virtual assets, transfer virtual assets, or safekeep and administer them on behalf of customers are the core population captured by the VASP concept. For these firms, VASP classification typically triggers registration or licensing and AML/CFT obligations, though the specific requirements and thresholds depend on the jurisdiction where they operate and should be confirmed against the applicable regime.
Compliance officers and MLROs at virtual asset businesses
Those responsible for AML programs at crypto-related businesses need to assess whether their firm's activities fall within the VASP definition, including the 'as a business' and 'for or on behalf of another' elements, and to identify which national implementation applies. This assessment shapes the design of due diligence, monitoring, and reporting controls used to detect and mitigate money laundering and terrorist financing risk.
Regulators, supervisors, and policymakers
Authorities implementing or supervising AML/CFT frameworks use the VASP concept to define which actors fall within scope and to set registration, licensing, and thresholds. Because the FATF Recommendations are standards rather than binding law, national bodies determine how the definition is transposed, and divergence between regimes is common.
Financial intelligence analysts and investigators
Analysts and investigators examining flows of virtual assets benefit from understanding whether a counterparty is a regulated VASP, an unregulated actor, or a person transacting for their own account, as this affects what records and reporting may exist. A firm's VASP status is a matter of regulatory classification and does not by itself indicate any wrongdoing.

Inside VASP

FATF Definition and Origin
The term 'Virtual Asset Service Provider' derives from the FATF Recommendations, which are international standards rather than binding law. Under the FATF glossary, a VASP is any natural or legal person that is not otherwise covered elsewhere in the Recommendations and that, as a business, conducts one or more specified virtual asset activities or operations for or on behalf of another natural or legal person. Importantly, a VASP can be an individual (natural person) as well as a business entity, and the activities must be carried out 'as a business' to fall within the definition.
In-Scope Activity: Exchange Between Virtual Assets and Fiat Currencies
Exchange between virtual assets and fiat (legal tender) currencies is one of the FATF-listed activities that brings a person or entity within the VASP definition when conducted as a business for or on behalf of another person.
In-Scope Activity: Exchange Between Virtual Assets
Exchange between one or more forms of virtual assets is a distinct listed activity under the FATF definition, separate from fiat-to-virtual exchange.
In-Scope Activity: Transfer of Virtual Assets
The transfer of virtual assets is a listed activity, referring to conducting a transaction on behalf of another person that moves a virtual asset from one address or account to another.
In-Scope Activity: Safekeeping and Administration
Safekeeping and/or administration of virtual assets, or instruments enabling control over virtual assets (such as custody of private keys), is a listed activity within scope of the VASP definition.
In-Scope Activity: Participation in and Provision of Financial Services Related to an Issuer's Offer or Sale of a Virtual Asset
Participation in, and provision of, financial services related to an issuer's offer and/or sale of a virtual asset is a listed activity. Omitting this activity, or fiat-to-virtual exchange, materially narrows the regulatory perimeter and understates who may qualify as a VASP.
AML/CFT Obligations
Where a jurisdiction treats VASPs as obliged entities, they are typically subject to AML/CFT measures broadly comparable to those applied to traditional financial institutions, which may include customer due diligence, record-keeping, and suspicious activity or suspicious transaction reporting. These are measures to detect, deter, and mitigate money laundering and terrorist financing risk, not guarantees of prevention. Exact obligations depend on the implementing regime.
Jurisdictional Implementation and Divergence
The VASP concept is a FATF standard; its legal force depends on national implementation. Terminology, licensing or registration requirements, scope of covered activities, and applicable thresholds vary by jurisdiction. Practitioners should confirm the precise definition and obligations against the applicable local regulation.

Common questions

Answers to the questions practitioners most commonly ask about VASP.

Does a person or business become a VASP simply by holding or transacting in virtual assets for themselves?
No. Under the FATF glossary, the VASP definition turns on conducting specified activities for or on behalf of another person, and doing so as a business. Individuals or entities that merely buy, hold, or transfer virtual assets for their own account generally fall outside the definition, because they are not providing a covered service to others as a business. The status of VASP attaches to the business activity of providing services, not to mere ownership or use of virtual assets. Because jurisdictions transpose the FATF standards differently, the precise perimeter should be confirmed against the applicable national law.
Is a VASP always a company or licensed institution rather than an individual?
No. The FATF glossary makes clear that a VASP can be a natural person as well as a legal entity. What matters is whether the person or entity conducts one or more of the covered virtual asset activities as a business for or on behalf of another person, not the legal form it takes. Treating the term as applying only to incorporated businesses can understate the regulatory perimeter, and national implementations may set their own registration or licensing structures that should be checked directly.
Which activities bring a person within the VASP definition?
The FATF glossary lists covered activities carried out as a business for or on behalf of another person, including: exchange between virtual assets and fiat currencies; exchange between one or more forms of virtual assets; transfer of virtual assets; safekeeping or administration of virtual assets or instruments enabling control over virtual assets; and participation in and provision of financial services related to an issuer's offer or sale of a virtual asset. Because these categories are drawn from FATF standards rather than a single binding law, the exact scope in any jurisdiction depends on how the standards have been transposed, and each covered activity should be mapped against the applicable national framework.
How should a firm determine whether its activities are conducted 'as a business' for VASP purposes?
The FATF definition qualifies the covered activities with the requirement that they be carried out as a business for or on behalf of another person. In practice this typically calls for an assessment of factors such as whether the activity is provided to third parties, whether it is conducted on an ongoing or commercial basis, and whether it forms part of the person's business model rather than an isolated or personal transaction. Because there is no single global test and jurisdictions may apply their own indicators or thresholds, firms generally document this analysis and confirm the applicable criteria against national law and guidance.
If a firm conducts several of the listed activities, does it need to assess each one separately?
Generally, yes. Because the FATF definition captures a range of distinct activities, a firm offering more than one covered service typically maps each activity against the relevant national implementation to confirm which registration, licensing, and AML/CFT obligations apply. Different activities may attract different requirements or supervisory expectations in a given jurisdiction, so a service-by-service analysis helps ensure the full regulatory perimeter is captured. The precise obligations attached to each activity should be confirmed against the applicable regulation.
How does VASP status relate to a firm's AML/CFT obligations?
Where a person or entity meets the VASP definition as implemented in a jurisdiction, it is typically treated as an obliged entity and becomes subject to AML/CFT requirements such as customer due diligence, record-keeping, and suspicious activity or transaction reporting, alongside any registration or licensing conditions. The FATF Recommendations set these expectations as standards rather than directly binding law, so the specific measures, thresholds, and supervisory arrangements depend on national transposition and should be confirmed against the applicable regime.

Common misconceptions

A VASP must be a company or incorporated business.
Under the FATF glossary, a VASP can be a natural person as well as a legal person or entity. What matters is whether the person conducts the listed virtual asset activities as a business for or on behalf of another person.
The VASP definition only captures exchanges between virtual assets and fiat currency.
The FATF definition covers several activities, including exchange between virtual assets and fiat, exchange between different virtual assets, transfer of virtual assets, safekeeping and administration, and participation in and provision of financial services related to an issuer's offer or sale of a virtual asset. Focusing only on fiat-to-virtual exchange materially narrows the regulatory perimeter.
Any person who deals in virtual assets is automatically a VASP.
The listed activities must be carried out 'as a business' and for or on behalf of another natural or legal person to meet the FATF VASP definition. Activity conducted purely for one's own account, or not as a business, may fall outside the definition, though jurisdictional implementation should be checked.

Best practices

Assess your activities against the full list of FATF-defined VASP activities, including fiat-to-virtual exchange, virtual-to-virtual exchange, transfer, safekeeping and administration, and participation in or provision of financial services related to an issuer's offer or sale of a virtual asset, rather than relying on a narrow view of the perimeter.
Evaluate whether the 'as a business' and 'for or on behalf of another person' criteria are met, since these elements determine whether a person or entity falls within the VASP definition.
Confirm the precise definition, covered activities, thresholds, and licensing or registration requirements against the applicable national regulation, as the FATF standard is implemented differently across jurisdictions.
Consider that both natural persons and legal entities can qualify as VASPs when scoping your customer base, counterparties, or your own regulatory status.
Where you qualify as an obliged entity, implement AML/CFT measures such as customer due diligence, record-keeping, and suspicious activity or transaction reporting, treating them as risk-mitigation controls rather than guarantees against financial crime.
Document your scoping analysis and periodically re-assess it, as both the range of virtual asset activities and the applicable regulatory definitions may evolve.