Join our Newsletter — 33% off our NHI Course

What is the difference between being licensed and being operationally audit-ready as a VASP?

A licensed VASP has met a regulator’s entry requirements. An operationally audit-ready VASP can prove that its controls work in practice, across governance, risk, and operations. Audit readiness requires evidence of ongoing monitoring, documented decisions, resilient processes, and the ability to respond to scrutiny without scrambling to reconstruct what happened after the fact.

Why Licensing and Audit Readiness Answer Different Questions for a VASP

Licensing shows that a virtual asset service provider has satisfied a regulator’s threshold for operating. Operational audit readiness is a different test: it shows whether the firm can produce credible evidence that its governance, controls, and operational discipline actually work under scrutiny. That distinction matters because a licence can be granted before day-to-day control maturity is proven, and that gap is where surprises emerge during examinations, partner due diligence, or incident reviews. For a broader control perspective, NIST Cybersecurity Framework 2.0 is useful because it frames how organisations demonstrate ongoing security outcomes rather than one-time approval.

In practice, many security and compliance teams discover the difference only when they are asked to evidence control operation, not when the licence application is approved.

What Operational Audit Readiness Looks Like in Day-to-Day VASP Operations

Audit readiness is not a document set that sits on a shelf. It is the ability to trace decisions, transactions, exceptions, access changes, reconciliations, and monitoring activity back to reliable records. A VASP may be licensed with policies, procedures, and named owners in place, yet still fail an operational review if it cannot show that controls are consistently followed, reviewed, and escalated. The practical test is whether evidence exists before the audit starts, and whether that evidence is coherent across compliance, operations, security, and finance functions.

For VASPs, the strongest indicators of readiness usually include:

  • clear control ownership and approval records
  • repeatable monitoring and review cycles with retained evidence
  • documented exception handling, including approvals and remediation dates
  • incident and issue management that links problems to corrective action
  • access governance for privileged staff, administrators, and critical systems
  • reconciliation and reporting processes that can be reproduced on demand

The difference is especially visible when a reviewer asks for samples. A licensed firm may be able to point to its policy, but an audit-ready firm can show the ticket, log entry, approval trail, and follow-up action that prove the control operated in practice. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant here because it reinforces the need for controls to be implemented, assessed, and evidenced, not merely stated.

This guidance breaks down when a firm treats evidence collection as a periodic project instead of a normal operating condition.

Where Licensing Ends and Audit Readiness Becomes Hard in Practice

Tighter regulatory posture often increases operational overhead, requiring organisations to balance faster market entry against more durable evidence generation. The hardest edge cases are usually not about the licence itself, but about change: new products, new jurisdictions, new custody models, outsourcing arrangements, or rapid growth can make previously acceptable evidence incomplete or inconsistent.

There is also a genuine consensus gap in the industry: some firms assume “audit-ready” means they have policies and controls on paper, while mature reviewers often expect proof of control effectiveness, not just existence. That means a VASP can be licensed yet still be fragile if logs are incomplete, ownership is unclear, or compensating controls are informal. The reverse is also possible in limited cases: a firm can be well-run operationally but still be blocked from licensing because a regulator requires specific structural conditions that have not yet been met.

Operational readiness also becomes more difficult where evidence is spread across vendors, cloud services, and outsourced operations. In those cases, the question is not whether controls exist somewhere in the stack, but whether the VASP can assemble an accurate, timely, and defensible record when challenged.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV — Govern Licensing versus readiness hinges on governance, ownership, and oversight of operating controls.
DE — Detect Audit readiness depends on monitoring, logging, and the ability to show control operation over time.
RS — Respond A ready VASP must demonstrate documented response and exception handling under scrutiny.
Recommendation — Establish control ownership and oversight so evidence of security outcomes is continuously available. Retain monitoring evidence that proves detection controls operate consistently in production. Document response actions and exception decisions so incidents can be reconstructed later.
CIS Controls v8 5 — Account Management Audit readiness for a VASP often depends on provable ownership and control of privileged access.
8 — Audit Log Management The question is fundamentally about proving controls worked through durable audit evidence.
Recommendation — Review and record account ownership and access changes before an audit requires proof. Protect and retain logs so control operation can be evidenced without reconstruction.
PCI DSS v4.0 12 — Support Information Security with Organizational Policies and Programs Although not payment-specific, the licensing-readiness gap is a policy-to-operation accountability problem.
Recommendation — Translate formal policy into retained evidence that operations actually follow.

Practitioner Guidance

What to prioritise: Treat evidence integrity as part of the control, not as a reporting afterthought. If a control cannot be shown to operate consistently, it is not audit-ready even if it is formally approved.

What to verify: Check whether the organisation can answer three questions quickly: who owns each control, what evidence proves it ran, and where exceptions are recorded. If those answers depend on memory or ad hoc file gathering, readiness is weak.

Common mistake: Teams often conflate “we passed licensing” with “we can survive scrutiny.” Licensing is a permission state; audit readiness is an operating state, and the two diverge as soon as controls change faster than documentation and evidence discipline.

Practitioner takeaway: A VASP should measure readiness by how reliably it can reconstruct control performance without improvisation, because regulators and counterparties usually test the operating system, not the application form.