Glossary

VASP (Virtual Asset Service Provider)

A VASP is any business that facilitates virtual asset transactions, including exchanges, custodians, and transfer services, subject to AML/KYC regulations.

Key Takeaways

  • A VASP is any business that exchanges, transfers, safeguards, or administers virtual assets on behalf of customers. The classification was introduced by the FATF in October 2018 to bring crypto businesses under existing anti-money laundering frameworks.
  • VASPs must comply with KYC/AML requirements and the travel rule, which mandates sharing originator and beneficiary information for qualifying transfers. As of July 2026, 83% of surveyed jurisdictions have travel rule legislation in force.
  • Whether DeFi protocols and self-hosted wallets qualify as VASPs remains one of the most contested questions in crypto regulation, with only 2 of 143 jurisdictions having licensed or registered a DeFi arrangement as of mid-2026.

What Is a VASP?

A Virtual Asset Service Provider (VASP) is any natural or legal person that conducts certain virtual asset activities as a business on behalf of another person. The term was coined by the Financial Action Task Force (FATF), the intergovernmental body that sets global standards for combating money laundering and terrorist financing. In October 2018, the FATF adopted the VASP definition alongside a companion definition for "virtual asset" and updated Recommendation 15 to clarify that existing AML/CFT standards apply to businesses handling crypto.

The VASP classification is not a license type or a single law: it is a regulatory concept that each jurisdiction translates into its own legal framework. The EU calls them Crypto-Asset Service Providers (CASPs) under MiCA. The US classifies them as Money Services Businesses and money transmitters under FinCEN rules. Singapore regulates them as Digital Payment Token service providers under the Payment Services Act. The underlying obligations are similar: know your customer, monitor transactions, and report suspicious activity.

The Five VASP Categories

The FATF defines five activities that qualify a business as a VASP. An entity that performs any one of these on behalf of a customer falls under the classification:

  1. Exchange between virtual assets and fiat currencies: converting government-issued money into a virtual asset, or vice versa. This covers the primary on-ramp and off-ramp services that most crypto exchanges provide.
  2. Exchange between one or more forms of virtual assets: swapping one digital asset for another, such as trading bitcoin for ether on a centralized platform.
  3. Transfer of virtual assets: conducting a transaction on behalf of a customer that moves a virtual asset from one address or account to another.
  4. Safekeeping and/or administration of virtual assets or instruments enabling control over them: holding virtual assets in custody or maintaining the private keys that control them. This covers custodial services and institutional wallet providers.
  5. Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset: underwriting, placing, or providing other financial services in connection with token issuances or ICOs.

A critical qualifier: the entity must be conducting these activities as a business and on behalf of another person. An individual trading their own crypto does not qualify. A self-custodial wallet user managing their own keys does not qualify. The VASP designation targets intermediaries, not end users.

How VASP Compliance Works

Once classified as a VASP, a business faces three core regulatory obligations that apply across virtually all jurisdictions: KYC, AML program maintenance, and travel rule compliance.

KYC and AML Requirements

VASPs must verify the identity of every customer at onboarding using government-issued identification. This includes ongoing customer due diligence, risk-based assessment, and enhanced scrutiny for higher-risk customers such as politically exposed persons. Beyond identity verification, VASPs must maintain a risk-based AML/CFT program that includes transaction monitoring, filing of suspicious activity reports, and record-keeping for a minimum of five years.

The Travel Rule

FATF Recommendation 16, renamed "Payment Transparency" in June 2025, requires VASPs to collect, verify, and transmit originator and beneficiary information for qualifying virtual asset transfers. The originator's VASP must share the sender's full name, account number or wallet address, and at least one additional identifier (physical address, national ID number, or date and place of birth). The beneficiary's VASP must receive the recipient's name and account number or wallet address.

Thresholds vary by jurisdiction. The FATF recommends a minimum threshold of USD/EUR 1,000. The EU applies the travel rule to all CASP-to-CASP transfers with no minimum threshold. The US sets its threshold at USD 3,000 under FinCEN rules. Singapore uses SGD 1,500. As of July 2026, 91 of 109 surveyed jurisdictions (83%) have travel rule legislation in force, though fewer than half have taken supervisory action to verify compliance.

Licensing and Registration

Recommendation 15 requires countries to license or register VASPs before they can operate. This typically includes fit-and-proper tests for beneficial owners and management, disclosure of beneficial ownership, capital requirements, and cybersecurity standards. Operating without registration is a criminal offense in most jurisdictions.

Jurisdictional Approaches

European Union: MiCA

The EU's Markets in Crypto-Assets Regulation (MiCA) entered into force on June 29, 2023, with a phased rollout. The full CASP authorization regime became applicable on December 30, 2024, with a final transitional deadline of July 1, 2026 for grandfathered firms. MiCA imposes capital requirements between EUR 50,000 and EUR 150,000 depending on the services offered, along with governance standards, customer asset segregation, and cybersecurity requirements. Unlike fragmented national regimes, a single CASP authorization under MiCA allows EU-wide passporting of services.

The companion Transfer of Funds Regulation (TFR) applies the travel rule to all CASP-to-CASP crypto transfers with no minimum threshold. For transfers to or from self-hosted wallets exceeding EUR 1,000, CASPs must verify that the customer owns or controls the wallet.

United States: MSB and Money Transmitter

The US does not use the term "VASP" in its statutes. Instead, FinCEN classifies crypto businesses as Money Services Businesses (MSBs) and specifically as money transmitters under the Bank Secrecy Act. This requires registration with FinCEN at the federal level and money transmitter licenses in each state where the business operates: a patchwork of 49+ separate state regimes. VASPs must maintain risk-based AML programs, file SARs and currency transaction reports, and perform KYC at onboarding. California's Digital Financial Assets Law, which takes effect July 1, 2026, creates a dedicated licensing framework for crypto businesses serving California residents.

Singapore: Payment Services Act

Singapore regulates crypto businesses under the Payment Services Act 2019, with amendments extending to Digital Payment Token (DPT) services. The Monetary Authority of Singapore (MAS) offers three tiers of licensing: Money-Changing Licence, Standard Payment Institution Licence, and Major Payment Institution Licence. As of early 2026, MAS had received over 380 DPT licence applications and approved approximately 90.

In June 2025, MAS expanded its regime under the Financial Services and Markets Act (FSMA), requiring all Singapore-incorporated digital token service providers serving only overseas clients to obtain a Part 9 licence or cease operations. Singapore also imposes strict custodial rules: 90% of customer assets must be held in offline cold wallets, assets must be held on trust with separate blockchain addresses, and daily reconciliation is mandatory.

The DeFi and Self-Hosted Wallet Debate

One of the most contentious questions in crypto regulation is whether DeFi protocols, decentralized exchanges, and self-hosted wallets constitute VASPs. The FATF's 2021 Updated Guidance states that DeFi projects qualify as VASPs "when they engage as a business in facilitating or conducting" the covered activities. If a DeFi protocol is "completely decentralized," entirely automated, and outside the control of any owner or operator, it may fall outside the VASP definition. However, the FATF notes that truly decentralized arrangements are rare.

The FATF's July 2026 DeFi Targeted Report reinforced this view, finding that centralized elements "frequently persist in practice" in ostensibly decentralized protocols. These elements include governance token concentration, administrative privileges, control over contract upgrades, and influence over protocol development. The report found that only 2 of 143 jurisdictions had actually licensed or registered a DeFi arrangement, while 93% had not yet implemented FATF Standards for qualifying DeFi arrangements.

Self-hosted wallets present a different challenge. Peer-to-peer transfers between self-hosted wallets are not explicitly covered by AML/CFT rules in most jurisdictions. The FATF has signaled a potential "future paradigm change" if P2P transactions show distinct growth trends. In the meantime, the EU's TFR takes a middle path: CASPs must collect originator and beneficiary information for transfers involving self-hosted addresses, and must verify wallet ownership for transfers exceeding EUR 1,000.

Why VASP Classification Matters

The VASP classification determines whether a crypto business can legally operate and under what conditions. For businesses building payment infrastructure, understanding where you fall in the VASP framework is foundational. A payment processor handling stablecoin settlements, an exchange offering fiat-to-crypto conversion, or a custodian holding customer funds: each of these triggers VASP obligations in nearly every major jurisdiction.

For users of protocols like Spark, the distinction between self-custodial and custodial models directly affects regulatory treatment. Self-custodial wallets that never take control of user funds operate outside the VASP definition. Services that custody assets, facilitate transfers on behalf of users, or offer exchange functionality fall squarely within it.

The stakes are significant. The largest VASP enforcement action to date resulted in a $4.3 billion settlement with Binance in November 2023 for BSA violations and operating as an unlicensed money services business. In the first half of 2025 alone, regulators globally issued 139 fines totaling $1.23 billion for AML, KYC, and sanctions violations across the crypto industry.

VASP Compliance in Practice

A typical VASP compliance program involves several interconnected systems. The following illustrates the core data flow for travel rule compliance between two VASPs:

Originator VASP                    Beneficiary VASP
─────────────────                  ──────────────────
1. Collect customer info
   - Full name
   - Account/wallet address
   - National ID or DOB

2. Initiate transfer ──────────────> 3. Receive transfer request
                                      - Validate originator data
                                      - Screen against sanctions

4. Transmit originator info ──────> 5. Match beneficiary
   via travel rule protocol           - Verify identity
   (e.g., TRISA, OpenVASP)            - Apply risk scoring

                                   6. Accept or reject transfer
                                      - Log for recordkeeping
                                      - File SAR if suspicious

Several interoperability protocols have emerged to facilitate travel rule data exchange between VASPs, including TRISA, OpenVASP, and Notabene. These protocols address the practical challenge of securely transmitting customer data between entities that may have no prior relationship.

Risks and Considerations

Regulatory Fragmentation

Despite the FATF's efforts to harmonize standards, implementation varies significantly across jurisdictions. The EU applies no threshold for CASP-to-CASP travel rule transfers, while the US sets a $3,000 threshold. Singapore requires 90% cold storage for customer assets, while other jurisdictions have no specific custodial requirements. This fragmentation creates compliance complexity for VASPs operating across borders and can lead to de-risking, where financial institutions cut off relationships with crypto businesses rather than manage the compliance burden.

Privacy and Surveillance Concerns

Critics argue that applying traditional financial surveillance frameworks to crypto undermines the privacy and censorship-resistance properties that make these systems valuable. The travel rule requires sharing personal information across institutional boundaries, creating new attack surfaces for data breaches. Self-hosted wallet restrictions could push users toward centralized services, concentrating risk rather than distributing it.

Innovation and Compliance Costs

VASP compliance imposes substantial costs. Smaller startups may struggle to meet capital requirements, maintain compliance teams, and navigate multi-jurisdictional licensing. In Singapore, fewer than one in four DPT licence applications have been approved, suggesting that the compliance bar is high enough to limit market entry. The regulatory sandbox model adopted by some jurisdictions attempts to balance innovation with consumer protection, but coverage remains limited.

Evolving Scope

The VASP definition continues to expand. The FATF's June 2025 revision of Recommendation 16 extended the travel rule to domestic transfers, not just cross-border ones, with a compliance deadline of 2030. Future revisions may bring P2P transfers, DeFi protocols, and NFT platforms more firmly within scope. Businesses building in the crypto space must design for regulatory change, not just current requirements. For deeper analysis of how stablecoin regulation is evolving alongside VASP frameworks, see the research on global stablecoin regulation and the GENIUS Act.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.