A virtual asset service provider is a business that moves, exchanges, or safeguards crypto assets on behalf of others, and doing so brings defined regulatory obligations. This guide sets out the FATF definition, how registration and licensing work across jurisdictions, and the core compliance duties every VASP carries. It is written for teams building or operating crypto services who need to know where the obligations sit.
What Counts as a Virtual Asset Service Provider?
The term comes from the Financial Action Task Force (FATF), the intergovernmental body that sets anti-money-laundering standards. A VASP is defined by activity, not by branding. Under FATF’s definition, a business is a VASP if it carries out one or more of the following for or on behalf of another person:
- Exchange between virtual assets and fiat currency
- Exchange between different forms of virtual assets
- Transfer of virtual assets
- Safekeeping or administration of virtual assets, or instruments enabling control over them
- Participation in and provision of financial services related to an asset’s offer or sale
In plain terms, exchanges, custodial wallet providers, and transfer facilitators are VASPs (Chainalysis). What matters is whether you handle other people’s assets or arrange their movement. A business that only holds its own assets, or that provides software without touching customer funds, is generally not a VASP, though the line depends on the exact model and jurisdiction.
Registration and licensing
A virtual asset service provider must first determine which national or regional licensing regimes apply to its activities.FATF sets the standard, but each jurisdiction implements it through its own regime, so a VASP must be registered or licensed where it operates. The approaches vary.
Singapore regulates digital-payment-token services under the Payment Services Act, administered by the Monetary Authority of Singapore, with standard and major payment institution licences depending on volume (MAS). A separate framework under the Financial Services and Markets Act, effective 30 June 2025, covers providers that serve customers outside Singapore (MAS).
The European Union brings crypto-asset service providers under the Markets in Crypto-Assets Regulation (MiCA), which requires authorisation to operate across member states, with a transitional period running to 1 July 2026 (ESMA).
Because a company established in a FATF member’s jurisdiction is generally expected to be regulated there regardless of where its customers are (MAS), the practical task is mapping every place you have a nexus and confirming the local requirement in each.
Core compliance obligations
Whatever the jurisdiction, the substantive duties of a VASP cluster around the same themes.
Customer due diligence: KYC and KYB
A VASP must identify and verify its customers before providing services, and understand who it is dealing with on an ongoing basis. For individuals this is know-your-customer; for business customers it extends to know-your-business, verifying the entity and its beneficial owners. For the mechanics of verifying corporate customers, see what is KYB.
AML programme and monitoring
Beyond onboarding, a VASP needs an anti-money-laundering programme: risk assessment, transaction monitoring for suspicious patterns, sanctions screening, suspicious-activity reporting, and record retention. These are continuous obligations, not one-off checks. The building blocks are covered in AML compliance solutions.
The Travel Rule
FATF Recommendation 16, the Travel Rule, requires a VASP to collect and pass on originator and beneficiary information for qualifying transfers, and to share it with the counterparty provider. FATF recommends a de minimis threshold of USD/EUR 1,000, above which fuller information applies, though jurisdictions set their own limits (Chainalysis). Meeting it in practice means being able to send, receive, and store counterparty data alongside the on-chain transfer.

VASP obligations at a glance
| Obligation | What it requires |
|---|---|
| Customer due diligence | Verify identity of individuals and businesses before service |
| Ongoing monitoring | Screen transactions for suspicious activity and sanctions hits |
| Travel Rule | Exchange originator and beneficiary data for qualifying transfers |
| Reporting and records | File suspicious-activity reports and retain records |
| Licensing | Hold the registration or licence required in each jurisdiction |
How infrastructure supports compliance
Meeting these obligations is largely an engineering and operations problem. For a virtual asset service provider, these controls must connect directly to onboarding, wallets, transaction monitoring, and reporting workflows. A VASP needs identity verification wired into onboarding, screening running against live sanctions and watch lists, monitoring that flags unusual behaviour, and a mechanism to exchange Travel Rule data with counterparties. Much of this can be provided by infrastructure rather than built from scratch: KYC and KYB tooling, monitoring engines, and Travel Rule messaging that connect to the provider’s wallets and transaction flow.
A distinction worth holding onto: infrastructure and software support compliance, but the regulatory status belongs to the operating entity. The licence, the VASP registration, and custody of client funds sit with the regulated business or its regulated infrastructure partners, not with the software layer that helps it meet its duties. A company assembling a crypto service should be clear which party is the VASP of record in each market. If the business also holds its own assets, the operational controls in crypto treasury management apply on that side.
Frequently Asked Questions
Is every crypto company a VASP?
No. VASP status follows the FATF-defined activities: exchanging, transferring, or safeguarding virtual assets for others. A business that only handles its own assets, or supplies software without touching customer funds, is generally outside the definition, but the specific model and jurisdiction decide it.
Does the Travel Rule apply to every transfer?
FATF recommends applying full requirements above a de minimis threshold of USD/EUR 1,000, but jurisdictions vary, and some require information regardless of amount (Chainalysis). Check the rule in each market you operate in.
Where do we need to be licensed?
Generally wherever you are established and wherever you serve customers, subject to each regime. Singapore, the EU, and others each have their own frameworks, so registration has to be mapped market by market (ESMA).
Can a software provider be our VASP of record?
No. The VASP registration and licensing attach to the entity carrying out the regulated activity and holding customer funds. Software and infrastructure support compliance, but the operating company or its regulated partner is the VASP of record.
Artha Fintech supplies the compliance infrastructure a crypto business needs, including KYC and KYB, monitoring, and Travel Rule messaging, while the VASP registration, licensing, and custody remain with the client or regulated infrastructure partners. To see how the pieces fit a regulated operation, explore regulated VASPs.





