Accountability sits with the VASP’s leadership, compliance function, and control owners, because regulators expect firms to prove that policy, technical implementation, and monitoring all work together. When AML or fraud controls fail, responsibility usually follows the decision chain that approved the control design, resourcing, and ongoing oversight.
Why This Matters for Security Teams
When virtual asset compliance fails, the issue is rarely limited to a missed alert or a single analyst error. Regulators and auditors look for whether the VASP had accountable ownership, adequate resourcing, and controls that actually operated as designed across onboarding, transaction monitoring, sanctions screening, escalation, and recordkeeping. That means exposure to AML or fraud risk often becomes a governance question, not just a tooling question. The FATF Recommendations frame this as a firm-wide obligation, while NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives shows how control ownership becomes visible only when evidence is requested.
Security teams often underestimate how quickly weak identity control, poor alert triage, or undocumented exceptions can turn into a compliance finding. If a compromised NHI can move funds, trigger customer actions, or alter risk scoring, then the liability extends beyond the security stack to the people who approved access, tolerated drift, or failed to verify monitoring coverage. In practice, many compliance failures are discovered only after an examiner or fraud case forces a review of who signed off on the control design and who was supposed to catch the breakdown.
How It Works in Practice
Accountability usually follows the decision chain, not just the incident. Leadership sets the risk appetite, the compliance function defines the AML and fraud requirements, engineering implements the controls, and operations owns day-to-day monitoring and exception handling. Under NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022 Information Security Management, that chain should be documented so the firm can prove who owns prevention, detection, response, and assurance.
For virtual asset providers, practical accountability means translating policy into measurable control ownership:
- Compliance defines what must be monitored, escalated, and retained.
- Technology owners prove that rule logic, identity controls, and logging are functioning.
- Operations evidence alert review, escalation timing, and disposition quality.
- Senior management reviews residual risk, exceptions, and remediation progress.
This matters because compliance failures often involve non-human access as much as human decision-making. NHIMG’s 52 NHI Breaches Analysis and Top 10 NHI Issues show why exposed secrets, stale tokens, and over-privileged automation can undermine transaction controls before anyone notices. A strong program therefore links AML and fraud rules to NHI lifecycle management, access review, and alert evidence. These controls tend to break down when ownership is split across vendors, product teams, and compliance staff because no one function can prove end-to-end control effectiveness.
Common Variations and Edge Cases
Tighter compliance oversight often increases operational burden, requiring organisations to balance faster product movement against stronger evidence, review, and approval discipline. That tradeoff becomes more visible in exchanges, custodians, and payment platforms where automation is heavy and manual review capacity is limited. Current guidance suggests that accountability can be shared, but responsibility cannot be vague: if no named owner can explain a control failure, the firm will usually absorb the finding even if a third party built part of the stack.
Edge cases arise when fraud controls are outsourced, monitoring is partially automated, or a breach begins with an NHI rather than a human user. In those situations, the firm still needs clear control ownership, because regulators typically expect oversight of vendors, model outputs, and privileged automation. NHIMG’s LLMjacking: How Attackers Hijack AI Using Compromised NHIs illustrates how quickly exposed credentials can be exploited, which is relevant when virtual asset workflows depend on long-lived secrets or weak service-account governance.
Best practice is evolving, but the practical rule is simple: if a compliance failure exposes AML or fraud risk, the accountable parties are the leaders who accepted the risk, the compliance owners who defined the control, and the operators who had the duty to keep it effective.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Weak NHI secret rotation can expose payment and compliance systems. |
| OWASP Agentic AI Top 10 | A2 | Autonomous tools can trigger fraud or compliance actions without tight oversight. |
| CSA MAESTRO | GOV-2 | Agent and automation governance needs named accountability for control failures. |
| NIST CSF 2.0 | GV.RM-03 | Risk ownership is central when compliance failures create AML exposure. |
| NIST AI RMF | AI risk governance helps structure accountability for automated decision systems. |
Use AI risk governance to document owners, controls, and escalation for automated compliance decisions.
Related resources from NHI Mgmt Group
- Who is accountable when faster verification creates compliance or fraud risk in regulated sectors?
- Who should be accountable when identity fraud moves across compliance, fraud, and verification teams?
- Who is accountable when bank account verification is used for PSD2 and AML CTF compliance?
- Who is accountable when Travel Rule compliance fails in a digital asset transfer workflow?