Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should VASPs move from licensing to ongoing…
Cyber Security

How should VASPs move from licensing to ongoing operational compliance across multiple jurisdictions?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Cyber Security

VASPs should treat licensing as the entry point, not the finish line. The stronger model is to align legal advice, internal governance, and compliance operations so policies can be demonstrated in practice. That means building evidence trails for risk assessment, controls, monitoring, and escalation, then testing whether those controls still hold as the business scales across jurisdictions and product lines.

Why ongoing compliance is harder than getting licensed

Licensing tells regulators that a VASP met the entry conditions at a point in time. Ongoing operational compliance is different: it must show that governance, controls, monitoring, and escalation still work after product changes, market expansion, and new jurisdictional obligations are introduced. That shift matters because many failures are not about one missing policy, but about weak evidence, inconsistent execution, or control drift between legal, compliance, and operations. For a cross-border VASP, the practical challenge is maintaining one operating model that can be evidenced locally without fragmenting into incompatible country-by-country processes.

For the control layer, this is less about writing more policy and more about proving that policies are operationalised. A useful reference point is NIST Cybersecurity Framework 2.0, because it reflects the need for governance, risk management, and continuous oversight rather than one-off certification activity. In practice, many VASPs discover compliance gaps only when a jurisdictional review, banking partner request, or internal audit forces them to reconstruct evidence after the process has already drifted.

How multi-jurisdiction compliance should work in practice

Operational compliance for a VASP needs a repeatable structure that can absorb local legal differences without losing control consistency. The core idea is to separate what must be globally standardised from what must be jurisdiction-specific. Group-level standards should usually cover governance, risk assessment methodology, issue escalation, record retention, third-party oversight, and approval authority. Local overlays then handle registration conditions, reporting thresholds, consumer disclosures, KYC or AML expectations, and any country-specific activity limits.

The strongest programmes build evidence as part of the workflow, not after the fact. That means compliance teams can show:

  • who approved the control and under what delegated authority
  • how the risk was assessed and when it was refreshed
  • what monitoring exists, what thresholds trigger review, and who receives exceptions
  • how incidents, alerts, and regulatory changes are escalated
  • where local law requires a different procedure, and how that deviation is tracked

This is also where FATF-aligned expectations become operationally relevant. FATF Recommendations and guidance matter because VASPs are usually judged on the effectiveness of customer due diligence, transaction oversight, sanctions awareness, and risk-based controls, not merely on whether a policy exists. The compliance function therefore needs a living control library, a regulatory obligations register, and a change-management process that forces review when products, corridors, wallets, or counterparties change.

The operating model should also define evidence retention by jurisdiction. If a regulator, auditor, or banking partner asks why a control was accepted, the organisation should be able to produce the decision, the rationale, the owner, the date of review, and the next scheduled reassessment. Where organisations fail is often at the boundary between central policy and local execution, especially when responsibility is shared but not clearly owned.

Where cross-border VASP compliance breaks down

Tighter compliance alignment often increases administrative overhead, requiring organisations to balance standardisation against the reality of local legal differences. That tradeoff becomes visible when a VASP tries to reuse one control design across every market without testing whether the local obligation is actually the same. In guidance versus consensus terms, there is broad agreement that global governance should be centralised, but no universal consensus that every local compliance obligation can be absorbed into one uniform control set without exception handling.

Common edge cases include joint ventures, outsourced compliance operations, and markets where registration, AML obligations, and reporting timelines change faster than the internal policy cycle. Another weak point is product segmentation: a VASP may have a sound compliance model for one service line, then extend into custody, brokerage, or payments without revalidating the monitoring and escalation model. External assurance also matters, but it should not be mistaken for operational compliance. A passed review does not prove the control still works after volume growth, new counterparties, or a revised customer mix.

The practical test is whether the organisation can explain local deviations without losing global accountability. If a jurisdiction requires a different approval path, evidence standard, or reporting trigger, that exception should be explicit, justified, and reviewed on a schedule. The model breaks down when local teams improvise controls, central teams cannot see exceptions, or compliance data is too fragmented to support a defensible supervisory response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST AI RMF and NIST IR 8596 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyCross-border compliance needs ongoing governance and risk oversight, not one-time licensing.
GV.OV — OversightThe question centers on board and management visibility into operating compliance.
Recommendation — Align compliance operations to continuous governance and risk review across jurisdictions. Establish recurring oversight of control performance, exceptions, and regulatory changes.
CIS Controls v88 — Audit Log ManagementOperational compliance depends on evidence trails, monitoring, and defensible records.
17 — Incident Response ManagementVASPs need escalation and response paths when controls fail or obligations change.
Recommendation — Retain and review logs and records that prove controls operated as intended. Define and test escalation paths for control failures and regulatory incidents.
NIST AI RMFGOV — GovernMulti-jurisdiction compliance requires AI-style governance discipline over policies and accountability.
Recommendation — Use governance structures to assign accountability and review compliance drift regularly.
NIST IR 8596IR-1 — Preparation and CoordinationOngoing compliance requires coordinated preparation for supervisory inquiries and reviews.
Recommendation — Prepare evidence, roles, and communications before regulators or auditors request them.

Practitioner Guidance

What to prioritise: Build a single obligations-to-controls mapping before expanding further. For a VASP, the first failure mode is usually not missing intent, but mismatched obligations across jurisdictions and product lines that nobody has explicitly reconciled.

What to verify: Confirm that every material control has an owner, an evidence source, a review cadence, and a documented exception path. If any one of those is missing, the control may exist on paper but will be difficult to defend under supervisory scrutiny.

  • Verify that local regulatory changes trigger a formal control review.
  • Verify that compliance testing covers the actual operating process, not just policy text.
  • Verify that exceptions are time-bound and re-approved, not left open-ended.

Practitioner takeaway: For multi-jurisdiction VASPs, the real standard is not whether the licence was granted, but whether the firm can keep proving control effectiveness as the business, geography, and regulatory footprint change.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org