CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

VASP Onboarding: The AML Due Diligence Framework Financial Institutions Need Now

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING VASP Onboarding: The AML Due DiligenceFramework Financial Institutions NeedNow

The debate about whether regulated financial institutions should work with virtual asset service providers is effectively over. Banks are custodying cryptoassets, stablecoins are moving through mainstream payment rails, and asset managers hold digital assets on behalf of clients. The real compliance question in 2026 is not whether to onboard a VASP, but how to do it in a way that is documented, consistent, and defensible to a supervisor. This article sets out the core components of that framework, drawing on guidance published by Elliptic for financial institutions building or upgrading their VASP intake processes.

VASP Onboarding: The AML Due Diligence Framework Financial Institutions Need Now

Why "Wait and See" Is No Longer Viable

Supervisors across major jurisdictions have signalled, through enforcement actions, thematic reviews, and published expectations, that passive treatment of VASP counterparties is not acceptable. The specific dynamic that has changed the calculus is transparency: a material portion of a VASP's activity sits on a public ledger. Once that data is accessible, a compliance function that ignores it faces a straightforward supervisory question: why did you not use the information that was available to you?

That framing matters because it shifts the burden. Institutions that previously cited a lack of reliable data as a reason for light-touch VASP due diligence no longer have that argument. On-chain analytics are a mature capability. The expectation is that regulated institutions deploy them.

The shift from "if" to "how"

Financial institutions that have already integrated VASP clients, or that hold crypto-exposed counterparties on their books, need a methodology they can apply consistently across onboarding, periodic review, and event-triggered reassessment. Those still developing their approach need to move quickly. Stablecoin adoption in particular is accelerating the timeline: correspondent banking relationships, payment processing, and even trade settlement now involve VASP counterparties in ways that were theoretical just a few years ago.

Getting the Institution Ready Before Onboarding Begins

Due diligence quality is constrained by institutional readiness. Before any individual VASP is assessed, the compliance function needs a clear answer to several internal questions.

Governance and risk appetite

Who owns the VASP onboarding decision? In most institutions, this sits across compliance, legal, and the relevant business line, but the decision rights and escalation path need to be explicit. Risk appetite for VASP exposure also needs to be defined at a category level: centralised exchanges, decentralised protocols, custodians, and payment processors each carry a distinct risk profile. Without that taxonomy, individual case decisions will be inconsistent.

Policy and procedural infrastructure

VASP-specific onboarding policies should be distinct from the institution's standard corporate KYC procedures. VASPs are regulated entities in most jurisdictions but their underlying client base, the breadth of assets they touch, and the cross-border nature of their activity create risk factors that generic CDD templates do not capture. The policy infrastructure needs to be built before the caseload arrives, not retrofitted case by case.

The Two Layers of Due Diligence

A defensible VASP onboarding process operates on two distinct layers: a structured questionnaire-based review of the entity itself, and an on-chain analysis of its actual transaction behaviour. Neither layer is sufficient alone.

Layer one: entity-level review

The first layer covers the VASP as a legal and regulatory entity. Key areas include licensing status across the jurisdictions in which it operates, the quality and scope of its own AML and KYC programme, governance structure, and the asset types it supports. Stablecoin-heavy VASPs, for example, require specific scrutiny of how they handle redemption flows and counterparty concentration.

One structured tool for this layer is the Global Digital Finance VASP Due Diligence Questionnaire, known as the GDF VADDQ. This is an industry-developed standardised questionnaire that allows financial institutions to collect comparable information across multiple VASP counterparties. Using a recognised standard matters for documentation: it demonstrates to a supervisor that the assessment methodology is not ad hoc.

The areas that tend to deserve the most attention within any entity-level review are the VASP's own customer acceptance policy, how it handles high-risk customer segments, and whether its sanctions screening is jurisdictionally comprehensive. A VASP that is licensed in one jurisdiction but actively serves customers in high-risk jurisdictions without supplementary controls presents a meaningful gap.

Layer two: on-chain exposure analysis

The second layer is where the public ledger becomes a direct input into due diligence rather than background context. On-chain analytics allow a compliance team to assess what types of wallets and services a VASP's addresses have interacted with, and in what volumes.

A critical distinction here is directional. Inflow exposure and outflow exposure tell different stories about a VASP's controls. Inflow exposure, where funds from high-risk sources have arrived at the VASP's wallets, speaks primarily to the VASP's customer acceptance and transaction monitoring quality: it raises the question of whether illicit funds are entering the platform. Outflow exposure, where the VASP has sent funds to high-risk destinations, is a different signal and can indicate that the VASP's own sanctions screening or withdrawal controls have gaps.

Reading these two dimensions separately, rather than aggregating them into a single score, produces a more nuanced and accurate picture of where the risk actually lies. Compliance teams using crypto accounting software that integrates on-chain analytics should ensure their workflow captures both directions, not just overall exposure percentages.

Cross-chain activity adds another layer of complexity. VASPs that support bridging between blockchains, or that hold assets across multiple chains, require analytics that follow asset flows across those chains rather than treating each chain in isolation. A purely single-chain view can miss significant exposure routed through bridge protocols.

Interpreting What the Analytics Actually Show

Raw on-chain exposure data requires interpretation. A VASP that shows some exposure to high-risk counterparties is not automatically a problem: large centralised exchanges process enormous volumes, and statistical exposure to a broad range of wallet types is expected. What matters is the nature, proportion, and concentration of that exposure, and whether it is consistent with the VASP's stated business model.

Red flags that warrant escalation

Certain patterns should trigger escalation regardless of the VASP's size or licensing status. These include a high concentration of exposure to sanctioned addresses or jurisdictions, significant flows through mixing or obfuscation services, exposure to darknet market wallets above a de minimis threshold, and patterns that are inconsistent with the VASP's declared geographic scope or customer base.

Equally, a VASP whose on-chain profile is cleaner than its entity-level questionnaire would suggest is not necessarily lower risk: it may reflect a smaller sample period, a recently launched operation, or a platform whose volume is growing rapidly. Analytics should be read alongside the entity review, not as a substitute for it.

For accounting firms using how machine learning is reshaping blockchain analytics and AML workflows, the key operational implication is that machine-generated risk scores require human validation at the escalation stage. A score is a triage tool, not a decision.

Ongoing Monitoring and Reassessment Cadences

Onboarding approval is not a permanent clearance. VASP risk profiles can shift materially in a short period: regulatory action in a key jurisdiction, a change in ownership, a breach of the VASP's own systems, or a shift in the asset mix it supports can each alter the risk calculus significantly.

Risk-tiered review schedules

Reassessment frequency should be calibrated to the risk tier assigned at onboarding. Higher-risk VASPs warrant more frequent periodic review than lower-risk counterparties. The specific cadence should be documented in the institution's policy and applied consistently: ad hoc review, even when thorough, is harder to defend to a supervisor than a scheduled programme with clear triggers.

Event-triggered reassessment

Alongside calendar-based reviews, certain events should trigger an immediate reassessment regardless of when the last periodic review took place. These include public regulatory action against the VASP, credible adverse media coverage, material changes in the VASP's licensing status, significant changes in transaction volume or asset mix, and any on-chain analytics flags that were not present at onboarding. Building a clear list of trigger events into policy, rather than leaving this to analyst discretion, ensures that the monitoring programme is consistent and auditable.

For firms advising clients on VASP relationships, understanding how Korea's VASP registration manual revision and what it means for compliance teams demonstrates how quickly the regulatory environment can shift, requiring institutions to reassess counterparties that were fully compliant at onboarding but may face changed licensing conditions.

Documentation: Building a Record That Survives Scrutiny

The framework described above is only as useful as the documentation it generates. Supervisors assessing a firm's VASP compliance programme will look for evidence that decisions were made on the basis of defined criteria, applied consistently across cases, and reviewed at appropriate intervals.

What the file needs to contain

At a minimum, the VASP file should contain the completed due diligence questionnaire with responses verified against primary sources where possible, the on-chain analytics report with the date it was generated and the methodology used, the risk tier assigned and the rationale, the approval record including the level at which approval was granted, and the scheduled date for the next periodic review. Any event-triggered reassessments should be documented as addenda to the original file, not as separate unlinked records.

The documentation standard also matters for digital asset accounting software workflows. Where VASP counterparty data feeds into financial reporting, for example in correspondent banking, payment processing, or fund administration, the compliance file and the accounting record need to be linked. An auditor reviewing a firm's stablecoin payment flows, for instance, should be able to trace back to the VASP due diligence record for the counterparty that issued or redeemed those stablecoins.

VASP Onboarding: The AML Due Diligence Framework Financial Institutions Need Now

Frequently Asked Questions

What is a VASP for the purposes of AML due diligence?

A virtual asset service provider is any entity that, as a business, conducts one or more of the following on behalf of another person: exchange between virtual assets and fiat currencies, exchange between different virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets, and participation in financial services related to an issuer's offer or sale of virtual assets. The FATF definition is the reference standard used by most major jurisdictions. For due diligence purposes, the category includes centralised exchanges, custodians, payment processors, and certain DeFi protocol operators depending on jurisdiction.

What is the GDF VADDQ and should our institution use it?

The Global Digital Finance VASP Due Diligence Questionnaire is a standardised information request framework developed by the industry body Global Digital Finance. It is designed to allow financial institutions to collect comparable, structured information from VASP counterparties. Using a recognised standard does not replace the need for independent verification, but it demonstrates to supervisors that the institution's methodology is not ad hoc. For institutions onboarding multiple VASPs, it also makes cross-counterparty comparison more tractable.

Why does the direction of on-chain exposure matter?

Inflow exposure and outflow exposure carry different risk implications. If high-risk funds flow into a VASP's wallets, that raises questions about the VASP's customer acceptance and monitoring controls. If the VASP sends funds to high-risk destinations, that raises questions about its sanctions screening and withdrawal controls. Treating both as a single aggregate figure masks where the risk is actually concentrated and can lead to misdiagnosis of the counterparty's risk profile.

How frequently should VASP relationships be reassessed?

Reassessment frequency should reflect the risk tier assigned at onboarding, with higher-risk VASPs reviewed more frequently. Beyond scheduled reviews, a defined set of trigger events, including regulatory action, adverse media, changes in licensing status, and on-chain analytics flags, should prompt immediate reassessment regardless of when the last periodic review took place. The trigger event list should be written into policy rather than left to analyst discretion.

How does VASP due diligence connect to financial reporting obligations?

Where a VASP counterparty is involved in transactions that flow through the institution's books, for example stablecoin settlements, crypto custody arrangements, or payment processing, the compliance file for that VASP is directly relevant to the audit trail for those transactions. Auditors and regulators reviewing financial statements that include digital asset flows will expect to be able to trace those flows back to a documented, approved counterparty assessment. Firms using crypto bookkeeping software should ensure that VASP compliance records and transaction records are linked rather than siloed.

Source: Elliptic

GLOBALGeneral#stablecoinsAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
BDO 2026 Fintech Predictions: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
Chainalysis Adds Cronos to Its Monitoring Suite: AML and Accounting Implications for Firms and CFOs
AML/KYC & Licensing
Chainalysis Adds Cronos to Its Monitoring Suite: AML and Accounting Implications for Firms and CFOs
AML/KYC & Licensing
BVI as a Crypto Legal Home: What Accounting Firms and CFOs Must Know