VASP Due Diligence: Building an Onboarding Framework That Holds Up to Regulators
Financial institutions that bank virtual asset service providers now face a compliance bar that did not exist five years ago: regulators in the US, EU, and other major jurisdictions expect documented, defensible processes for assessing crypto counterparties, and "we sent a questionnaire" is no longer enough on its own. A new practical guide published by Elliptic on 20 August 2026 sets out how to build a two-layer VASP onboarding framework that combines traditional due diligence questionnaires with on-chain analytics, and how to keep that assessment current once a relationship is live. The implications stretch well beyond compliance teams: the data demands of this framework bear directly on how firms select and configure their crypto accounting software and the broader digital asset accounting infrastructure sitting underneath it.
Why VASP Counterparties Are Different from Any Other
Standard correspondent due diligence relies almost entirely on self-reporting. A bank cannot independently observe how another institution processes flows, so it verifies what it can through sanctions screening, adverse media, and public filings, then takes the rest on trust. VASPs break that pattern. A significant portion of their activity sits on public ledgers, and where those addresses can be attributed to the entity, a bank has the ability to cross-check what an applicant says it does against what the chain shows it actually did. That changes the regulatory calculus: once on-chain data is readily available, choosing not to consult it becomes difficult to explain to a supervisor.
There is also a strategic dimension that Elliptic's guide highlights. VASPs have historically been underserved by banks, yet they need services only licensed institutions can provide: holding client money, managing fiat reserves that back stablecoin issuance, and accessing settlement rails. As digital assets move into the mainstream, developing the capacity to bank VASPs well creates a genuine first-mover advantage. Crucially, the risk infrastructure required to assess a VASP counterparty is substantially the same infrastructure a bank would need if it decided to offer digital asset products directly, so the investment pays in more than one direction.
The Governance Questions Every FI Must Answer Before It Starts
Elliptic's framework begins with two internal questions that many institutions skip past in their rush to assess the applicant. Getting them right shapes everything that follows.
Decision-Making and Escalation
Who can approve what? The guide identifies three tiers: cases a relationship manager can handle independently, those requiring financial-crime review, and those needing senior-management sign-off. Documenting those thresholds before the first questionnaire goes out protects the institution when a regulator or auditor asks how a borderline onboarding was decided.
Staff Capability
Everyone involved in VASP due diligence needs a working knowledge of digital assets and the ability to read on-chain data in context. A compliance officer who can interpret a transaction volume chart but cannot distinguish between a self-custodied wallet and a mixing service will draw the wrong conclusions from the analytics layer. Firms should treat capability gaps here as a material risk, not a training footnote.
The Questionnaire Layer: Structure and Risk-Based Calibration
The standard for structured VASP self-assessment is the questionnaire built on the Wolfsberg Group's global Correspondent Banking Due Diligence Questionnaire (CBDDQ). Elliptic's guide notes that this instrument covers fourteen sections, making it thorough but demanding for both sides. A risk-based approach, in which the full version goes to higher-risk applicants and a shorter version to lower-risk ones, gives institutions a practical way to calibrate the burden without abandoning rigour.
What the Questionnaire Actually Tests
A well-constructed VASP questionnaire covers governance structure, AML and KYC policies, geographic footprint, licensing status across jurisdictions, customer categories served, and the controls applied to high-risk product lines such as privacy coins or peer-to-peer trading. Each section produces a set of representations that the analytics layer can then corroborate or challenge.
Accounting and Record-Keeping Considerations
For accounting and finance teams reviewing a VASP application, the questionnaire responses carry a secondary value: they inform how the relationship will need to be reflected in the institution's own books. A VASP that holds large fiat reserves backing a stablecoin programme, for example, raises distinct questions about how those liabilities are classified and disclosed. Firms using crypto accounting software to manage counterparty positions should map questionnaire disclosures directly into their chart-of-accounts tagging logic so that the compliance picture and the accounting picture stay aligned from day one.
The On-Chain Analytics Layer: Screening versus Entity Assessment
This is where VASP due diligence diverges most sharply from standard correspondent banking. Elliptic's guide draws a clear line between two distinct analytical operations, and conflating them is a common source of weaknesses that regulators flag.
Address-Level Screening
Screening takes a single address or transaction flow and checks it against known risk categories: sanctioned wallets, darknet market addresses, ransomware payment recipients, mixing services, confirmed exploit addresses, and fraud-linked wallets. The output tells you what risk attaches to a specific on-chain interaction. This is the operation that runs on an ongoing basis once the relationship is live, and it is the primary tool when attribution is thin, for example, in cases where only institutional settlement addresses are known.
Entity-Level Assessment
Entity assessment takes the counterparty as a whole. It combines on-chain activity with off-chain information such as licensing history, jurisdictional presence, and ownership structure into a consolidated risk profile. The output characterises the business: where the bulk of inflows originate, where outflows go, what share of activity touches illicit categories, and how those proportions move over time. This is the layer that supports the onboarding decision itself, because it speaks to the VASP's aggregate behaviour rather than any single transaction.
Why Both Layers Are Needed
Neither layer substitutes for the other. A VASP can have clean individual addresses and still show entity-level patterns that are concerning at aggregate. Conversely, an isolated flagged address may reflect a customer's deposit rather than the VASP's own activity. Reading both outputs together, in the context of what the questionnaire disclosed, is what produces a defensible assessment.
Ongoing Monitoring: Keeping the Assessment Current
Onboarding is not a one-time event. Elliptic's guide is explicit that the framework must remain live: the entity-level risk profile established at onboarding becomes the baseline against which subsequent screening and transaction monitoring are measured. Changes in a VASP's inflow sources, shifts in its geographic exposure, or new licensing actions in key jurisdictions can all alter the risk picture materially without triggering any questionnaire update.
Practical implications for B2B teams are significant. Firms should configure their digital asset accounting software to flag counterparty activity that deviates from the baseline captured at onboarding, not just to satisfy AML obligations but also to prompt a re-evaluation of credit and operational risk. Where a VASP's profile changes substantially, the accounting treatment of balances held with or for that counterparty may need revisiting in the same review cycle. Teams that keep compliance and accounting data in separate systems with no integration tend to discover these misalignments only at year-end, by which point remediation is costly.
Regulatory Expectations in the US, EU, and Beyond
Elliptic's guide highlights that regulators across major jurisdictions increasingly expect banks to have documented crypto counterparty risk management processes. In the US, bank supervisors have signalled that VASP relationships must be subject to the same rigour as any other high-risk correspondent relationship. In the EU, the Anti-Money Laundering Regulation and the accompanying transfer-of-funds rules impose Travel Rule obligations that directly affect how VASP-to-VASP flows must be recorded and verified. Global standards from the Financial Action Task Force underpin both frameworks and are the reference point supervisors will use when assessing whether an institution's processes are adequate.
For accounting firms advising FI clients, this regulatory environment creates a clear service opportunity: helping clients map their existing due diligence workflows against the two-layer framework, identify gaps, and select crypto bookkeeping software that captures the data points regulators will ask to see. Firms that have already developed this capability for VASP onboarding are well-positioned to extend it to direct digital asset product offerings if that becomes part of a client's strategy. Staying current on related developments, including the VASP onboarding AML framework covered in our earlier analysis, will be essential as supervisory expectations continue to evolve.
Accounting and Tax Implications for B2B Readers
The practical accounting demands of a robust VASP due diligence framework are not trivial. Several points deserve attention from CFOs and senior accounting professionals.
Data Capture Requirements
An entity-level risk assessment of a VASP counterparty generates structured data about on-chain volumes, jurisdictional exposure, and illicit-category percentages. That data should feed into the institution's crypto accounting software, not sit in a standalone compliance record. When an auditor or regulator asks how a counterparty balance was classified and risk-weighted, the answer needs to draw from both the compliance assessment and the accounting ledger.
Fiat Reserve and Stablecoin Exposure
VASPs that back stablecoin programmes hold fiat reserves that may appear as deposits or custodied balances at the banking institution. Correct classification of those balances depends on understanding the underlying contractual and regulatory structure, information that the questionnaire and entity-level assessment should surface. Accounting teams should not treat these balances as routine deposits without first reviewing the due diligence output.
Audit Trail Integrity
Regulators and auditors will ask for contemporaneous records showing how each onboarding decision was made. The analytics outputs, questionnaire responses, escalation records, and final approval need to be time-stamped and retained in a form that integrates with or is retrievable alongside the accounting records. Firms using crypto accounting software that supports audit-ready documentation will find this requirement significantly easier to meet than those relying on spreadsheets and email trails.
For context on how accounting standards are evolving around digital asset balances held with and for crypto counterparties, our recent coverage of the FASB stablecoin cash equivalents proposal is worth reviewing alongside this framework.
Frequently Asked Questions
What is VASP due diligence and why does it differ from standard counterparty checks?
VASP due diligence is the structured assessment of a virtual asset service provider before onboarding it as a customer or counterparty. Unlike standard checks, it can draw on public blockchain data to corroborate or challenge what the VASP says about itself in a questionnaire, giving banks a verification tool that does not exist in conventional correspondent banking.
What is the difference between address screening and entity-level assessment?
Address screening checks a specific wallet or transaction against known risk categories such as sanctions lists or darknet addresses. Entity-level assessment profiles the VASP as a whole business, combining on-chain volume and exposure data with off-chain information like licensing and jurisdiction. Both are needed: screening runs continuously, while entity assessment drives the onboarding decision.
How does a VASP due diligence framework affect crypto accounting software requirements?
The framework generates structured data about counterparty risk that must connect to the accounting ledger, not sit in isolation. Firms need crypto accounting software capable of ingesting compliance data, tagging counterparty balances according to risk classification, and producing an audit trail that integrates the compliance and accounting records.
What questionnaire standard applies to VASP onboarding?
The widely referenced standard is built on the Wolfsberg Group's Correspondent Banking Due Diligence Questionnaire, adapted for VASPs. The full instrument covers fourteen sections. A risk-based approach, using an abridged version for lower-risk applicants, is a practical way to calibrate the burden without reducing rigour for higher-risk cases.
How do ongoing monitoring obligations interact with accounting records?
The entity-level risk profile established at onboarding becomes the baseline for subsequent transaction monitoring. Material changes in that profile, such as shifts in inflow sources or new regulatory actions, can affect how counterparty balances are classified and whether additional disclosures are required. Accounting and compliance teams should run these reviews on the same cycle rather than treating them as separate processes.
Source: Elliptic
