Controls break down when firms assume initial approval is enough. VARA 2.0 makes clear that regulated activity needs ongoing alignment to rulebooks, especially as requirements change for custody, exchange, lending, and settlement services. If organisations do not keep policies, risk assessments, and operational procedures current, they can drift out of compliance and lose supervisory confidence.
When Initial Licensing Stops Being Enough
Licensing is only the entry point. For virtual asset firms, supervision is continuous because the business model, control environment, product scope, and custody model can all change after approval. If policies, risk appetite, and operational procedures do not move with the regulated activity, the firm may still be “licensed” while no longer being aligned to what the supervisor expects.
That is the practical breakage: firms begin to treat authorization as a permanent permission slip, rather than as a living obligation to keep the licensed activity inside its approved bounds. VARA 2.0 reflects that reality by requiring ongoing alignment as services evolve, especially where custody, exchange, lending, and settlement are part of the operating model.
Where Compliance Drift Usually Starts
Drift typically begins when the firm changes something material but does not re-baseline the control set. New products, new counterparties, new wallets, new outsourcing arrangements, or a revised settlement flow can all alter the risk profile without triggering a fresh supervisory review if governance is weak.
That creates a gap between the paper licence and the actual operating posture. The organisation may still have policies on record, but if the risk assessment no longer matches the current service set, the controls are stale, accountability is blurred, and evidence of compliance becomes fragile.
- Service expansion without updated approvals or controls creates scope creep.
- Stale risk assessments undermine the basis on which the activity was originally accepted.
- Procedures that no longer match reality make internal assurance unreliable.
What Supervisors Expect to Keep Seeing
Ongoing supervision is not just about keeping a registration active. It is about showing that the firm can keep its operating model, customer protections, and control environment synchronized with the rulebook as the business changes.
That means the strongest evidence is not a one-time policy pack, but a repeatable governance cycle: periodic review of the licensed activity, timely updates to risk assessments, and operational procedures that still describe how the firm actually handles custody, trade execution, lending, and settlement today.
Firms that maintain that cycle usually preserve supervisory confidence because they can explain not only what was approved, but how they keep the approved state current. Firms that cannot do that invite questions about control ownership, escalation discipline, and whether supervisory reporting is still trustworthy.
Risk and Threat Considerations
The main risk is regulatory drift, where the firm’s real operating model moves faster than its documented controls. That can lead to non-compliance, restrictions on activity, remediation demands, or loss of supervisory confidence even if no single incident has occurred.
Failure mechanism: Management treats the initial licence as sufficient, so rule changes, business expansion, and control changes are not re-validated against current supervisory expectations. Policies, risk assessments, and procedures then diverge from actual operations until the gap becomes visible in review or inspection.
Impact: The firm can drift outside approved bounds, weaken custody and transaction oversight, and lose the credibility needed to operate confidently under supervision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.31 — Legal, statutory, regulatory and contractual requirements | Virtual asset supervision depends on keeping controls aligned with changing regulatory duties. |
| A.5.36 — Compliance with policies, rules and standards for information security | The answer centers on whether the firm continues to operate in line with its rulebook obligations. | |
| Recommendation — Track rule changes and update policies and procedures before the operating model drifts out of compliance. Verify that day-to-day operations still follow the approved rulebook and documented procedures. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk management strategy is established and communicated | The issue is ongoing governance of risk as services and controls change over time. |
| GV.OV-01 — Organizational cybersecurity risk management strategy is established and maintained | Continuous supervision requires the control environment to stay aligned with current operations. | |
| Recommendation — Reassess risk whenever custody, exchange, lending, or settlement changes alter the licensed activity. Maintain a recurring review cycle that keeps policies, procedures, and operating controls current. | ||
Practitioner Guidance
What to prioritise: Re-baseline the control environment whenever the firm adds a service, changes a custody or settlement flow, or alters outsourcing in a way that affects regulated activity. The question is not whether the licence still exists, but whether the current operating model still matches the approved one.
What to verify: The firm should be able to show a current map from each regulated activity to its owner, policy, risk assessment, and operating procedure. If any of those cannot be tied back to the live service model, treat that as a supervisory gap, not a documentation issue.
Practitioner takeaway: The real failure is not losing the licence on day one, it is letting the control environment age until the firm can no longer prove that today’s business still fits yesterday’s approval.
Related resources from NHI Mgmt Group
- What breaks when organisations treat cyber resilience rules as a one-time compliance exercise?
- What breaks when organisations treat FedRAMP as a one-time compliance exercise?
- What breaks when crypto firms treat Travel Rule checks as a one-time onboarding step?
- What breaks when organisations treat identity compliance as a one-time legal exercise instead of an ongoing governance function?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org