Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Virtual Asset Service Provider (VASP) Register
Governance, Ownership & Risk

Virtual Asset Service Provider (VASP) Register

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

A VASP register is the authoritative list of businesses authorised to provide covered virtual asset services. In practice, it becomes a market trust signal as much as a compliance record, because counterparties and users rely on it to judge whether a provider is currently legitimate and active.

What the register represents in practice

A VASP register is more than a compliance list. It is the market’s current reference point for whether a provider is authorised, active, and expected to meet the obligations that come with handling virtual asset services.

That makes the register part of the trust layer around exchange, custody, brokerage, transfer, and related activity. For users, counterparties, and banks, it is often the first place they look to confirm that a firm is operating within an approved perimeter rather than in an unregulated or suspended state.

What the register typically contains

Registers vary by jurisdiction, but they usually identify the legal entity, trading names, registration or licence status, scope of permitted services, and sometimes the jurisdiction or supervisor that issued the authorisation. Some also show whether approval is current, conditional, suspended, or revoked.

The important point is that the register is not merely a name-and-number directory. It is a governed record of scope and status, which means the presence of a firm on the list does not automatically mean every virtual asset activity is permitted. Users still need to check what services are actually covered.

Why the register matters for trust and due diligence

For virtual asset markets, the register serves as a practical due diligence tool. It helps firms screen vendors and trading partners, and it helps customers distinguish between a properly authorised provider and an entity that may be operating outside the regulatory perimeter.

It also reduces ambiguity in fast-moving markets where branding, subsidiaries, and cross-border service models can make it hard to tell who is responsible for the service. A clear register creates a shared reference for supervision, onboarding, and external trust decisions.

How the register should be interpreted

A register should be treated as a snapshot, not a guarantee. Status can change, scope can be narrow, and authorisation in one jurisdiction may not translate into permission elsewhere. A listed provider can still present operational, custody, liquidity, or control risks even when it is properly registered.

For that reason, the register works best when paired with service-specific checks, such as verifying the exact legal entity, reviewing the permitted activity set, and confirming whether the provider is currently subject to restrictions or enforcement action.

Risk and Threat Considerations

Because users and counterparties rely on the register as a legitimacy signal, stale, incomplete, or misread entries can create real exposure. The main risk is not only fraud by unregistered actors, but also false confidence in a provider whose status has changed or whose permissions are narrower than expected.

Failure mechanism: Attackers and bad actors can exploit confusion around names, entities, jurisdictional scope, or withdrawn authorisation to impersonate legitimate firms, redirect onboarding, or support scams that depend on perceived regulatory approval.

Impact: The result can be unauthorised transfers, custody exposure, failed due diligence, regulatory breach, and loss of trust in the provider or in the market registry itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextA VASP register defines the regulated operating context for virtual asset service providers.
GV.RM-01 — Risk Management StrategyRegisters support risk decisions about third-party legitimacy and regulatory exposure.
Recommendation — Map registry checks to business context and verify provider status before onboarding. Use the register as an input to third-party risk decisions and periodic revalidation.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)VASP registers help validate external provider legitimacy before trust is extended.
AC-20 — Use of External Information SystemsRegister checks support decisions to allow reliance on external virtual asset providers.
Recommendation — Verify the external provider's authorised status before granting access or relying on it. Require current registry validation before using an external VASP for sensitive activity.
CIS Controls v8CIS-15 — Service Provider ManagementA VASP register is a third-party trust and due-diligence reference for service providers.
Recommendation — Confirm a VASP's legal status and scope before approving it as a service provider.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsRegistering and checking VASPs supports supplier trust and due diligence.
A.5.22 — Monitoring, review and change management of supplier servicesRegistry status can change and must be monitored over time.
Recommendation — Validate the provider's registered status as part of supplier relationship checks. Monitor VASP register status and review service scope for material changes.
DORAICT third-party risk management — ICT third-party risk managementRegisters support oversight of third-party financial service providers and their authorisation status.
Recommendation — Use register checks to support third-party oversight and ongoing resilience assessments.

Practitioner Guidance

Why practitioners should care: Treat the register as a control input, not a final assurance. It should feed onboarding, vendor review, and periodic revalidation processes, especially when a provider operates across multiple jurisdictions or under a narrow authorisation scope.

What to watch for: The highest-value checks are entity-name mismatches, outdated status, coverage gaps between the listed permission and the service actually being offered, and any sign that a provider is relying on registration in one place to imply approval everywhere else.

Practitioner takeaway: The register is strongest when it is used as a live verification source, with status and scope checked against the exact service relationship the organisation is entering into.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org