Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why does 5AMLD create more operational pressure for…
Identity Beyond IAM

Why does 5AMLD create more operational pressure for virtual asset service providers than the earlier framework?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

5AMLD brings virtual asset service providers into the scope of obliged entities, which means they face registration, supervision, and AML obligations that many had not previously built for. That creates pressure because firms must stand up governance, monitoring, and reporting processes quickly, while also meeting jurisdiction specific rules that may be stricter than the directive itself.

Why the operational burden rises so quickly

5AMLD does more than widen the policy scope. It turns virtual asset service provider into entities that must operate like regulated financial firms in practice, with traceable controls, accountable ownership, and evidence that obligations are being met. The pressure is operational because many firms have to build those capabilities while still running fast-moving products, exchanges, wallets, and customer support at the same time.

That shift is especially hard when the business was designed around product delivery first and compliance second. Once supervision, registration, monitoring, and reporting enter the picture, teams need repeatable workflows, durable records, and clear escalation paths, not just policy statements.

For AML grounding, the broader international benchmark remains the FATF Recommendations, which sets expectations around due diligence, suspicious activity reporting, and virtual asset regulation that many national regimes build on.

What changes operationally for a VASP

The biggest change is that compliance becomes a standing operating function rather than a periodic legal review. A VASP now has to know who its customers are, what activity is expected, which transactions need review, when to file reports, and how to prove the control operated as intended. That means workflow design, case handling, audit trails, and management oversight all matter.

Jurisdictional variation adds another layer of pressure. Even where the directive is the common baseline, local registration rules, supervisory expectations, recordkeeping obligations, and enforcement posture can differ. Firms operating across borders therefore have to maintain enough process discipline to satisfy the strictest applicable rule set without fragmenting their control environment into inconsistent local variants.

Operationally, this is where governance and evidence become part of the product. If a team cannot show how alerts were triaged, how decisions were made, or how suspicious activity was escalated, the control may exist on paper but still fail under supervision. For practical control design, CIS Controls v8 is useful because it reinforces account management, logging, and secure operational hygiene that support compliance execution.

  • Registration is not just a filing task, it creates an ongoing regulatory relationship.
  • Monitoring must be sufficiently tuned to detect unusual behavior without overwhelming analysts.
  • Reporting needs documented triggers, owners, and evidence retention.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV — Oversight5AMLD requires ongoing governance and supervision of AML operations.
PR.AA — Identity Management, Authentication, and Access ControlOperational AML depends on controlled access to customer and transaction systems.
RS.CO — CommunicationsAML reporting depends on disciplined communication and escalation paths.
Recommendation — Establish oversight for AML controls, reporting, and accountability across the VASP. Restrict access to AML systems and protect case-handling workflows. Define who escalates, approves, and submits suspicious activity reports.
CIS Controls v88 — Audit Log Management5AMLD pressure increases the need for reviewable evidence and traceable decisions.
5 — Account ManagementVASP compliance operations depend on governed accounts and traceable ownership.
17 — Incident Response ManagementSuspicious activity escalation and reporting need defined response handling.
Recommendation — Centralise and retain logs needed to reconstruct AML decisions and reporting. Review and remove unused or excessive accounts that can weaken compliance workflows. Define and test escalation paths for suspicious activity and regulatory reporting.

Practitioner Guidance

What to prioritise: Build the minimum viable compliance operating model before scaling product or geography. If you cannot assign ownership for customer due diligence, alert handling, escalation, and record retention, the directive becomes an unfunded obligation rather than a control framework.

What to verify: Confirm that supervisory reporting, customer onboarding, and transaction monitoring are connected to actual case records and decision logs. Regulators usually care less about policy language than whether the firm can reconstruct what happened and why.

Common mistake: Treating 5AMLD as a legal update instead of an operating-model change. The firms that struggle most are usually the ones that underestimate staffing, tooling, training, and quality assurance demands.

Practitioner takeaway: The real pressure comes from having to industrialise AML control execution quickly, with evidence, accountability, and cross-border consistency, while the business is still evolving.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org