Join our Newsletter — 33% off our NHI Course

What are the signs that a VASP risk review is too shallow for compliance use?

A shallow review usually relies on a name check alone, ignores counterparties, or fails to include both on-chain and off-chain data. It also becomes weak when teams review a VASP only periodically, rather than watching for changes in activity and risk score. Those gaps can hide licensing, jurisdiction, or exposure issues.

What makes a VASP risk review too shallow for compliance use?

A review is too shallow when it treats the VASP as a static label instead of a changing counterparty risk. Compliance teams need to see whether the review actually tests ownership, licensing, jurisdiction, sanctions and control exposure, then updates that view when the relationship, transaction profile or risk signals change. Otherwise the result may look documented while missing material compliance obligations.

What the review must cover to be defensible

A useful VASP review should connect the entity you are screening to the activity you are relying on. That means confirming the counterparty identity, its jurisdictional footprint, the services it provides, and whether its stated controls match the risk it presents. A name match alone is weak because many compliance failures arise from assuming that a familiar brand, exchange name or wallet service is enough to establish trust.

For compliance use, the review also has to combine on-chain and off-chain evidence. On-chain indicators show movement, counterparties and flow patterns, while off-chain data shows licensing status, corporate ownership, operating location and regulatory posture. When teams only inspect one side, they miss the context needed to decide whether the VASP is appropriate for the intended business relationship.

Periodic review is another common weakness. A VASP can move from acceptable to high-risk if its activity profile changes, it enters a new jurisdiction, loses a licence, changes control ownership, or begins interacting with higher-risk counterparties. A shallow review often fails because it produces a one-time answer instead of a living risk view tied to monitoring and refresh triggers.

Why shallow reviews fail under compliance pressure

Compliance use is about evidence, not just screening. If the review cannot explain why the VASP is permitted, what data was checked, and what would trigger re-review, it is hard to defend in an audit or investigation. The practical failure is usually not that a team skipped every check, but that it used checks that were too narrow to support a compliance decision.

Shallow reviews also create blind spots around exposure. A VASP may appear low-risk if judged only on its public name or a single due diligence field, yet still present licensing gaps, jurisdictional issues, or counterparties that raise the risk of indirect exposure. That is why review depth should be measured by the quality of the underlying evidence, not by the number of fields completed.

What a deeper review should prove before you rely on it

A stronger approach proves four things: the VASP is the entity you think it is; the jurisdictions involved are understood; the activity profile is current; and the evidence can be refreshed when something changes. If those points are not explicit, the review may be adequate for an initial triage but not for ongoing compliance reliance.

Teams should also be able to explain the difference between a low-risk relationship and a low-visibility relationship. A VASP can look ordinary while still being hard to assess because ownership is opaque, transaction patterns are inconsistent, or third-party dependency is high. Those conditions do not always mean the relationship is prohibited, but they do mean the review needs more substance before it can be treated as complete.

Risk and Threat Considerations

Shallow VASP reviews create compliance exposure because gaps in licensing, jurisdictional scope, counterparties and flow visibility can let higher-risk activity pass as acceptable. The danger is not only missed documentation, but also false confidence that a static review is still valid after the entity’s operating profile has changed.

Failure mechanism: Teams rely on a one-time name check or incomplete dataset, fail to correlate on-chain and off-chain evidence, and do not refresh the assessment when the VASP’s activity or risk score changes.

Impact: The organisation can continue transacting with a counterparty whose regulatory status, exposure or control environment is no longer fit for compliance use, which weakens auditability and can hide material jurisdictional or licensing issues.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy VASP reviews need a defined risk strategy for current and changing counterparty exposure.
ID.RA-01 — Asset Vulnerabilities Are Identified and Documented The review depends on identifying evidence gaps, jurisdictional exposure and counterparties.
GV.OV-02 — Risk Strategy Is Established and Communicated Compliance teams need a defensible standard for when a VASP review is sufficient.
Recommendation — Define refresh criteria that keep VASP risk decisions current as the counterparty changes. Document the evidence gaps that make a VASP assessment too shallow for compliance use. Set a clear standard for the evidence required before a VASP can be relied on for compliance.
GDPR Article 5 — Principles relating to processing of personal data If VASP records include personal data, review quality affects accuracy and lawful processing.
Recommendation — Keep VASP review evidence accurate, current and limited to what is needed for the purpose.

Practitioner Guidance

What to prioritise: Treat the review as a living counterparty assessment, not a screening event. The first question is whether you can defend the decision with current evidence on identity, jurisdiction, licensing and transaction behaviour.

What to verify: Require a clear refresh trigger for changes in activity, ownership, regulatory status or risk score. If the review process cannot show when and why a VASP is re-evaluated, it is too shallow for compliance reliance.

Practitioner takeaway: A compliant VASP review is only as strong as its ability to combine evidence, explain the decision, and stay current when the counterparty changes.