Join our Newsletter — 33% off our NHI Course

How should compliance teams assess VASP risk before onboarding or licensing decisions?

Compliance teams should assess a VASP’s on-chain exposure, counterparties, and off-chain profile together before making onboarding, partnership, or licensing decisions. A practical review should compare the entity’s activity with similar VASPs, check jurisdiction and licensing data, and monitor for changes over time. That produces a defensible risk picture instead of relying on a one-time snapshot.

Compliance teams should treat VASP onboarding as a risk classification exercise, not a checkbox review. The key question is whether the entity’s activity, counterparties, and jurisdictional profile point to ordinary exchange operations or to a higher-risk footprint that needs tighter controls, more evidence, or a different decision threshold. That makes the assessment defensible and repeatable.

What to assess before you approve a VASP

Start with the VASP’s on-chain exposure: the types of assets handled, transaction patterns, wallet concentration, and whether flows are consistent with the business model the firm claims. Then compare those patterns with comparable VASPs so you can spot outliers instead of treating every application the same. This is especially important when a firm’s transaction profile is growing faster than its compliance maturity.

Jurisdiction matters just as much as chain activity. A VASP licensed in a well-supervised market with clear obligations presents a different assurance profile from one operating through opaque or fragmented registrations. The compliance team should verify the legal entity, where it is actually licensed, and whether the scope of that licence matches the activities being proposed. FATF Recommendations for virtual asset risk are the strongest baseline for that review.

Off-chain evidence is the other half of the picture. Ownership structure, sanctions exposure, customer base, adverse media, governance quality, and compliance resourcing all affect whether a VASP can safely onboard, partner, or be licensed. The question is not whether the firm has a polished application, but whether its operating reality matches the control obligations that a regulated counterparty would need to trust.

How to build a defensible risk view

A useful assessment compares the applicant against peers and against itself over time. Peer comparison helps identify abnormal volumes, risky counterparties, or unusual geographies. Trend review shows whether risk is stable, improving, or deteriorating. A one-time snapshot can miss rapid expansion, changing business models, or new exposure introduced through acquisitions, new corridors, or product changes.

Documentation should support the decision path. If the VASP is licensed, the team should retain the licence scope, registry data, any supervisory statements, and the rationale for how those facts affected the onboarding decision. If the VASP is unlicensed or lightly supervised, the team should be able to explain what compensating controls or restrictions were required before approval. In practice, that is where a clear case file matters more than a generic score.

Risk tolerance also changes by use case. A low-value technology integration, a trading counterparty, and a licensing decision do not carry the same exposure, even if they involve the same firm. The practical control is to align the due diligence depth to the downstream permission being granted, and to tighten review when the relationship creates greater money-movement, custody, or reputational exposure.

What good ongoing monitoring looks like

Onboarding should not be the end of review. Compliance teams need a monitoring cadence that watches for licence changes, entity changes, sanctions hits, unusual chain activity, and shifts in counterparties or geographies. If a VASP’s profile changes materially after approval, the original decision should be reopened rather than left to age in place.

The best operating model treats monitoring signals as triggers for re-scoring, not as isolated alerts. A jurisdiction change without a business model change may be manageable; a jurisdiction change plus new high-risk counterparties plus rapid flow growth is a stronger reason to escalate. That is how teams move from static approval to a living risk view.

Where available, EBA AML/CFT guidance helps anchor that review in supervisory expectations for customer due diligence, risk-based controls, and ongoing monitoring.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this topic.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context VASP approval depends on the organisation's risk context and business model.
ID.AM-01 — Assets are inventoried and categorised Assessing VASP exposure requires inventorying counterparties, services, and activity patterns.
GV.RM-01 — Risk Management Strategy Established and Maintained Onboarding and licensing decisions require a repeatable risk appetite and decision method.
Recommendation — Define the VASP relationship in business context before setting approval thresholds. Inventory VASP relationships and classify them by activity, jurisdiction, and exposure. Apply a consistent risk strategy to approve, restrict, or reject VASPs.

Practitioner Guidance

What to prioritise: Focus first on the facts that change exposure fastest, namely licensing status, jurisdiction, counterparties, and transaction profile. Those four usually determine whether a VASP is routine, elevated, or unsuitable for the intended relationship.

What to verify: Confirm that the licence is current, the legal entity matches the operating entity, and the business scope matches the services being offered. If those do not line up, treat the application as unresolved rather than partially approved.

What to measure: Track how often a VASP’s profile changes after onboarding, because post-approval drift is often the clearest signal that the original risk view is stale.

Practitioner takeaway: The safest decision is rarely based on a single score; it comes from matching on-chain behaviour, off-chain facts, and supervisory reality into one explainable risk judgment.