What Is a VASP? Virtual Asset Service Provider Obligations, Explained
A virtual asset service provider (VASP) is any business that exchanges, transfers, custodies, or issues virtual assets on behalf of customers, a FATF-defined category that comes with a specific set of KYC and AML obligations attached. What counts, who's on the hook, and what compliance actually requires.
A founder building a crypto exchange, a custodial wallet, or an OTC desk runs into three different labels for what is, functionally, the same regulatory category, depending on which jurisdiction's paperwork is in front of them: a "VASP" in the FATF's own vocabulary and in most countries' implementing law, a "money services business" if the filing is FinCEN's, or a "crypto-asset service provider" if it's the EU's MiCA framework. It is easy to read one of those terms in a term sheet or a competitor's compliance page and assume it does not apply, on the theory that the business is registered under a different name. It applies anyway.
The Financial Action Task Force defines VASP status by activity, not by label: any natural or legal person conducting virtual asset exchange, transfer, safekeeping, or certain issuance-related financial services for a customer, as a business, meets the definition regardless of what the local license is called. Once a business crosses that line, the same core obligations attach no matter which word is on the registration: customer due diligence, ongoing monitoring, suspicious activity reporting, and, in most jurisdictions now, Travel Rule compliance for outbound transfers.
What Actually Makes a Business a VASP
The FATF added "virtual asset" and "virtual asset service provider" to its Glossary in the June 2019 update to Recommendation 15, extending the same AML and counter-terrorist financing measures that apply to banks and other financial institutions to businesses dealing in crypto. The Interpretive Note to Recommendation 15 sets out five activities that qualify an entity as a VASP when conducted for or on behalf of another person, as a business:
- Exchange between virtual assets and fiat currencies
- Exchange between one or more forms of virtual assets
- Transfer of virtual assets
- Safekeeping or administration of virtual assets, or of instruments enabling control over them
- Participation in and provision of financial services related to an issuer's offer or sale of a virtual asset
This is deliberately activity-based rather than tied to a specific business model or technology, which is why the FATF's framing holds up across exchanges, wallet providers, and token issuers alike without needing a separate definition for each. A business that does none of these five things for another party is not a VASP, even if it touches crypto in some other capacity; a business that does even one of them, as a service to customers, is.
VASP vs. CASP vs. MSB: The Same Category, Three Different Words
The confusion is almost always terminology, not substance. Each major jurisdiction has bolted the FATF's activity-based test onto its own existing regulatory vocabulary rather than adopting "VASP" as a legal term outright.
Every CASP is a VASP under the FATF's definition. Every MSB dealing in convertible virtual currency is a VASP too. The regulatory label changes; the activity test that triggers it does not.
What Counts: Exchanges, Wallets, OTC Desks, ATMs, and Token Issuers
Mapped against the five FATF activities, the businesses that most often qualify as VASPs are recognizable ones. Centralized crypto exchanges and peer-to-peer trading platforms conduct both fiat-to-virtual-asset and virtual-asset-to-virtual-asset exchange. Custodial wallet providers, the kind that hold private keys on a customer's behalf rather than handing over full self-custody, fall under safekeeping and administration. OTC desks conducting large trades on behalf of clients qualify under exchange or transfer, depending on structure. Crypto ATM operators conduct exchange between fiat and virtual assets at the point of transaction. Token issuers and the platforms that run their offerings can qualify under the fifth activity, participation in an issuer's offer or sale, though the scope here is narrower and depends on what services the platform actually performs rather than simply hosting a listing.
What does not typically qualify is instructive too: a business that only develops non-custodial wallet software, without ever taking control of a user's keys or conducting transactions on their behalf, generally sits outside the definition, since it isn't conducting any of the five activities for another person. The line is control and service, not mere involvement with the technology.
Getting Licensed: What Actually Gets Filed, by Jurisdiction
In the United States, a VASP dealing in convertible virtual currency registers as an MSB with FinCEN by filing Form 107, a federal filing that records the business under the Bank Secrecy Act but does not by itself authorize it to operate. Registration is free and does not replace the money transmitter license most states require separately, each with its own application, bonding, and net-worth requirements.
In the EU, the picture is starker right now. Of the more than 1,200 crypto entities that held national VASP registrations across the EU and EEA before MiCA, only about 17% had converted to full CASP authorization by the July 1, 2026 transitional deadline (Yahoo Finance). As of the July 31, 2026 ESMA register update, 321 firms held CASP authorization (GN Crypto News), and the transitional window that let pre-existing providers keep operating under national law expired EU-wide on that date under Article 143(3) (Elliptic). A national VASP registration issued before MiCA does not convert automatically; a firm has to apply for CASP authorization separately and wait for a national competent authority to grant it, and ESMA's own statement makes clear that firms still mid-application hold no authorization to operate in the meantime.
Elsewhere, licensing generally means direct VASP registration with the national regulator implementing Recommendation 15, on terms that vary by jurisdiction far more than the US or EU frameworks do. There is no substitute for checking the specific requirements of every jurisdiction a VASP intends to serve customers in before onboarding begins there.
The Obligations That Follow: CDD, EDD, Monitoring, SARs, and the Travel Rule
Licensing is the gate. What a VASP actually has to build to stay compliant once it's through that gate is a specific, recurring set of controls.
In the EU specifically, MiCA layers additional onboarding and record-retention requirements on top of this baseline, five-year retention of KYC and transaction records among them, which is where a CASP-specific build becomes relevant; see MiCA Crypto User Verification for what that adds.
Where This Leaves a VASP Building Its Compliance Stack
Not every VASP needs every piece of this on day one. Travel Rule infrastructure only matters once transfer volume with counterparty VASPs crosses the applicable threshold and cross-VASP transfers are actually part of the business; a VASP that only serves retail customers with no outbound transfers to other providers can reasonably sequence that build later. Enhanced due diligence is a trigger, not a default, applied when a customer's risk profile calls for it rather than run uniformly across every account. A VASP already operating a mature AML program under a national registration has a narrower gap to close than one building from zero, and the gap that matters most is usually whichever jurisdiction's licensing deadline is closest, not the theoretical full list of FATF obligations. The honest answer to "what do we need" is jurisdiction, volume, and risk profile specific, not a single checklist that applies identically to every VASP.
Questions About VASP Compliance
What is a VASP in crypto?
A VASP, virtual asset service provider, is any natural or legal person conducting virtual asset exchange, transfer, safekeeping, or issuance-related financial services for a customer as a business, under the FATF's activity-based definition in Recommendation 15. Crypto exchanges, custodial wallet providers, OTC desks, and crypto ATM operators are the most common examples. The label is functional, not tied to which word a local regulator uses for it.
Is a crypto exchange a VASP?
Yes. A crypto exchange conducts the exchange between virtual assets and fiat currency and between different virtual assets, both of which are activities the FATF's Interpretive Note to Recommendation 15 defines as qualifying VASP activity. This holds regardless of whether the exchange's home jurisdiction registers it under the term VASP, MSB, or CASP.
What's the difference between a VASP and a CASP?
CASP, crypto-asset service provider, is the term the EU's MiCA regulation uses for the same FATF-defined VASP category, authorized under MiCA Article 59 rather than registered as a VASP under national law. Every CASP is a VASP under the FATF's definition; CASP is simply the EU's licensing label for it since MiCA's provisions took effect.
Do VASPs need a license?
In most FATF member jurisdictions, yes. The specific mechanism varies: FinCEN registration as a money services business plus state money transmitter licenses in the US, CASP authorization under MiCA in the EU, and direct VASP licensing or registration with the local regulator elsewhere. A business conducting VASP-qualifying activity without the applicable registration is typically operating in breach of that jurisdiction's AML law.
What KYC does a VASP need to do?
A VASP's core obligations are customer due diligence at onboarding, enhanced due diligence for higher-risk customers, ongoing transaction monitoring, suspicious activity reporting, and, for transfers above the applicable threshold, Travel Rule compliance to exchange originator and beneficiary data with counterparty VASPs. Which of these apply in full depends on jurisdiction, transaction volume, and customer risk profile.
References
- FATF, "Virtual Assets"
On the 2019 addition of VASP to the FATF Glossary and the activity-based framing of Recommendation 15. - FATF, Interpretive Note to Recommendation 15
On the five activities that qualify an entity as a VASP. - FATF, Best Practices: Travel Rule Supervision (June 2025)
On Recommendation 16 and originator/beneficiary data requirements for VASP-to-VASP transfers. - FinCEN, Guidance FIN-2019-G001
On which convertible virtual currency business models qualify as money services businesses under the Bank Secrecy Act. - FinCEN, Money Services Business (MSB) Registration
On federal MSB registration via Form 107 and its relationship to state money transmitter licensing. - EUR-Lex, Regulation (EU) 2023/1114 (MiCA)
On Article 59 CASP authorization requirements. - Elliptic, "The End of MiCA's Transitional Period"
On Article 143(3) transitional periods and their EU-wide July 1, 2026 expiry. - GN Crypto News, "ESMA Adds 12 Firms to MiCA Register, CASPs 321"
On the July 31, 2026 ESMA register count of authorized CASPs. - Yahoo Finance, "83% of Europe's Crypto Firms Not..."
On the roughly 17% national-VASP-to-CASP conversion rate by the transitional deadline.
About Hypersign
Hypersign is identity infrastructure for regulated onboarding: a W3C verifiable-credential layer that lets a VASP verify a customer once and reuse the result, screening status included, across KYC, AML, and Travel Rule data exchange, instead of rebuilding the same evidence for every counterparty and every regulatory request. It plugs into the specific obligations above through onboarding verification, AML screening, transaction monitoring, and Travel Rule infrastructure. Hypersign is not itself a VASP, MSB, or CASP, does not hold any of the licenses discussed above, and does not replace legal counsel for a specific jurisdiction's registration or authorization filing; it is the verification and credential layer a VASP builds its compliance stack on top of, whichever licenses that stack ultimately needs.
Ready to add identity verification to your platform?
See how Hypersign's enterprise identity verification and reusable credential infrastructure works book a 30-minute demo.
Book a Demo →