Join our Newsletter — 33% off our NHI Course

VASP

A VASP is a virtual asset service provider, such as an exchange, custodian, or transfer platform that handles crypto-related services for customers. In compliance work, the term usually refers to firms that must manage customer due diligence, transaction controls, and information sharing obligations under Travel Rule requirements.

Expanded Definition

A VASP is a business that provides services involving virtual assets, most commonly exchange, transfer, brokerage, or custody functions. The term is used most often in AML and Travel Rule contexts, where the service provider is expected to know who its customers are, understand transaction purpose and flow, and preserve enough information to support screening, recordkeeping, and information sharing obligations.

The boundary matters: not every crypto-adjacent platform is automatically a VASP, and the classification usually depends on the role the firm actually plays in moving, safeguarding, or intermediating value. Guidance can vary by jurisdiction, so the compliance meaning of VASP is partly regulatory rather than purely technical. For this reason, a firm can be operationally significant even before it becomes large, because regulated status is tied to function, not marketing language.

In practice, the most common misunderstanding is to treat VASP as a technology label. It is better understood as a regulated service category with identity, transaction, and governance duties attached.

Examples and Use Cases

VASP appears in several common operating models across the virtual asset ecosystem:

  • A centralised exchange that matches buyers and sellers and must apply customer due diligence before allowing higher-risk activity.
  • A custodian that stores client assets and must maintain strong account segregation, access oversight, and withdrawal controls.
  • A transfer platform that moves virtual assets between parties and needs to collect, retain, and transmit required sender and recipient information.
  • A brokerage or over-the-counter desk that intermediates trades and may sit between the customer and the on-chain settlement layer.
  • A payment or conversion service that accepts virtual assets and converts them into another form of value under local regulatory definitions.

The implementation tradeoff is usually between user friction and control depth. Stronger onboarding and transaction checks improve assurance, but they can also slow customer journeys and increase operational burden. That tension is one reason VASP programs often combine compliance, fraud, and security functions rather than leaving the term to any single team.

Security Implications

When VASP status is misunderstood, organisations can underbuild controls that are expected in a regulated financial-intermediation role. The consequence is not only compliance exposure, but also weaker detection of mule activity, suspicious transfers, account takeovers, and laundering patterns that rely on rapid movement across platforms.

A VASP also concentrates sensitive trust relationships. It holds customer identity data, transaction histories, keys or custody privileges in some models, and routing details that can reveal operational patterns. If those controls are weak, the blast radius extends beyond a single account to the platform’s reporting integrity, its counterparties, and the downstream firms that rely on its records for Travel Rule sharing.

Common failure conditions include poor beneficiary screening, incomplete records, weak segregation between customer and operator actions, and inadequate monitoring of high-velocity transfers. The practitioner observation is simple: in VASP environments, security gaps often surface first as compliance gaps, then as fraud or abuse.

Domain and Governance Relevance

VASP is primarily a financial compliance and identity-governance term, but it has direct security implications because the service depends on knowing who is transacting, what assets are moving, and which entities are entitled to act. That makes customer onboarding, authentication, authorization, and record integrity part of the control surface, not just back-office administration.

For NHI and machine-operated workflows, the relevance increases when VASP platforms use APIs, automation, wallets, signing services, or internal service accounts to process transfers and screening. Those non-human components can become privileged execution paths, so ownership, secret handling, and access boundaries matter as much as the customer-facing application.

NHIMG treats VASP as a governance term that sits at the intersection of regulated identity assurance and transaction control. The core question is not only whether the platform can move value, but whether it can prove who initiated, authorised, and received it.

Risk and Threat Considerations

VASP environments are exposed to both compliance risk and adversarial abuse because they combine financial value, identity data, and high-speed transfer capabilities. The main risk is that weak customer verification, monitoring, or transfer controls allow illicit flows to blend into legitimate activity.

Failure mechanism: Attackers and abusers exploit gaps in onboarding, beneficiary checks, transaction monitoring, or record retention to move funds through accounts that appear normal at the surface. Where custody or API access is involved, stolen credentials or abused service paths can accelerate transfers before detection.

Impact: The result can be sanctions exposure, laundering facilitation, loss of counterparties’ trust, regulatory action, and operational disruption if the platform must freeze assets or rebuild evidence after suspicious activity is detected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC — Access Control VASP controls depend on verified customer and operator access boundaries.
Recommendation — Enforce access control boundaries for customer, operator, and service-account actions.
CIS Controls v8 5 — Account Management VASPs must govern identities that can move funds or access sensitive records.
Recommendation — Inventory and disable unused accounts tied to transfer, custody, and compliance workflows.
NIST SP 800-63 IAL — Identity Assurance Level Customer due diligence in VASP onboarding relies on identity assurance strength.
Recommendation — Set identity proofing strength to match the transaction and regulatory risk.
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Management VASP automation often depends on secrets that can directly move or expose assets.
Recommendation — Rotate and protect API keys, signing secrets, and service credentials used in transfer flows.
PCI DSS v4.0 8 — Identify Users and Authenticate Access Custody and transaction systems need strong authentication for privileged access paths.
Recommendation — Require strong authentication for staff and privileged access to sensitive VASP systems.

Practitioner Guidance

Governance implication: Treat VASP classification as a role-based obligation, not a branding choice, because regulatory duties attach to the services actually performed. Ownership should sit across compliance, security, and operations so that identity checks, transfer controls, and evidence retention are managed as one control set.

What to watch for: Pay close attention when a platform adds custody, cross-platform transfer, or automation features, because those changes can move the firm into a more demanding VASP posture even if the customer experience looks unchanged.