5AMLD brings virtual asset service providers into the scope of obliged entities, which means they face registration, supervision, and AML obligations that many had not previously built for. That creates pressure because firms must stand up governance, monitoring, and reporting processes quickly, while also meeting jurisdiction specific rules that may be stricter than the directive itself.
Why the operational burden rises so quickly
5AMLD does more than widen the policy scope. It turns virtual asset service provider into entities that must operate like regulated financial firms in practice, with traceable controls, accountable ownership, and evidence that obligations are being met. The pressure is operational because many firms have to build those capabilities while still running fast-moving products, exchanges, wallets, and customer support at the same time.
That shift is especially hard when the business was designed around product delivery first and compliance second. Once supervision, registration, monitoring, and reporting enter the picture, teams need repeatable workflows, durable records, and clear escalation paths, not just policy statements.
For AML grounding, the broader international benchmark remains the FATF Recommendations, which sets expectations around due diligence, suspicious activity reporting, and virtual asset regulation that many national regimes build on.
What changes operationally for a VASP
The biggest change is that compliance becomes a standing operating function rather than a periodic legal review. A VASP now has to know who its customers are, what activity is expected, which transactions need review, when to file reports, and how to prove the control operated as intended. That means workflow design, case handling, audit trails, and management oversight all matter.
Jurisdictional variation adds another layer of pressure. Even where the directive is the common baseline, local registration rules, supervisory expectations, recordkeeping obligations, and enforcement posture can differ. Firms operating across borders therefore have to maintain enough process discipline to satisfy the strictest applicable rule set without fragmenting their control environment into inconsistent local variants.
Operationally, this is where governance and evidence become part of the product. If a team cannot show how alerts were triaged, how decisions were made, or how suspicious activity was escalated, the control may exist on paper but still fail under supervision. For practical control design, CIS Controls v8 is useful because it reinforces account management, logging, and secure operational hygiene that support compliance execution.
- Registration is not just a filing task, it creates an ongoing regulatory relationship.
- Monitoring must be sufficiently tuned to detect unusual behavior without overwhelming analysts.
- Reporting needs documented triggers, owners, and evidence retention.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV — Oversight | 5AMLD requires ongoing governance and supervision of AML operations. |
| PR.AA — Identity Management, Authentication, and Access Control | Operational AML depends on controlled access to customer and transaction systems. | |
| RS.CO — Communications | AML reporting depends on disciplined communication and escalation paths. | |
| Recommendation — Establish oversight for AML controls, reporting, and accountability across the VASP. Restrict access to AML systems and protect case-handling workflows. Define who escalates, approves, and submits suspicious activity reports. | ||
| CIS Controls v8 | 8 — Audit Log Management | 5AMLD pressure increases the need for reviewable evidence and traceable decisions. |
| 5 — Account Management | VASP compliance operations depend on governed accounts and traceable ownership. | |
| 17 — Incident Response Management | Suspicious activity escalation and reporting need defined response handling. | |
| Recommendation — Centralise and retain logs needed to reconstruct AML decisions and reporting. Review and remove unused or excessive accounts that can weaken compliance workflows. Define and test escalation paths for suspicious activity and regulatory reporting. | ||
Practitioner Guidance
What to prioritise: Build the minimum viable compliance operating model before scaling product or geography. If you cannot assign ownership for customer due diligence, alert handling, escalation, and record retention, the directive becomes an unfunded obligation rather than a control framework.
What to verify: Confirm that supervisory reporting, customer onboarding, and transaction monitoring are connected to actual case records and decision logs. Regulators usually care less about policy language than whether the firm can reconstruct what happened and why.
Common mistake: Treating 5AMLD as a legal update instead of an operating-model change. The firms that struggle most are usually the ones that underestimate staffing, tooling, training, and quality assurance demands.
Practitioner takeaway: The real pressure comes from having to industrialise AML control execution quickly, with evidence, accountability, and cross-border consistency, while the business is still evolving.
Related resources from NHI Mgmt Group
- How should virtual asset service providers implement Travel Rule compliance across APAC jurisdictions with different licensing timelines?
- Why do virtual asset service providers struggle to operationalise the Travel Rule consistently?
- Why does eKYC create regulatory and operational pressure for payment providers in ASEAN?
- Why do managed service providers create concentrated cyber risk for clients?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org