Virtual asset service provider: an entity licensed to exchange, transfer, safekeep or administer digital assets on behalf of others. The term is the Financial Action Task Force’s, written into Recommendation 15 in 2018. The category follows the activity and the authorisation follows the category: an entity that performs one of five listed activities as a business for other people falls inside the definition, and the jurisdiction it operates in then licenses it, registers it, or prohibits the activity outright. The acronym therefore names a class of conduct rather than a permission, and says nothing about which activities a given provider may perform, under whose authority, in which market, or as at what date.
What makes an entity a VASP
FATF’s definition catches any natural or legal person not already covered elsewhere in the Recommendations that, as a business, conducts one or more of five activities for or on behalf of another person:
- exchange between virtual assets and fiat currencies;
- exchange between one or more forms of virtual assets;
- transfer of virtual assets;
- safekeeping or administration of virtual assets, or of instruments enabling control over them;
- participation in and provision of financial services related to an issuer’s offer or sale of a virtual asset.
Two qualifiers carry the weight. As a business excludes a person moving their own holdings. For or on behalf of another person turns the test on control: an entity that can move a customer’s assets sits inside the definition, while one that supplies software and never holds or moves anything generally sits outside it. The test is functional. What the entity calls itself decides nothing, and a single provider commonly performs three limbs at once — a payment interface that receives a digital-asset payment, converts it and pays a merchant in national currency is exchanging, transferring, and usually holding the asset for the moments in between.
Licence, registration or prohibition: what the status actually is
FATF is a standard-setter, not a regulator. It has no register, issues no licence, and supervises no provider. Recommendation 15 requires countries to license or register VASPs and to supervise them, and each country chooses its own instrument: a licence with itemised permissions, a registration on an anti-money-laundering list, or a ban. Prohibition is permitted under the standards. FATF’s seventh targeted update, published 16 July 2026, records that prohibition regimes continue to struggle to identify and sanction the activity they have already outlawed.
Two structural choices decide who is caught at all. An incorporation-based approach regulates providers formed under the jurisdiction’s own law. An activity-based approach extends licensing or registration to any provider serving that market, wherever it was formed. FATF’s March 2026 report on offshore VASPs found that under half of jurisdictions — 46% — have adopted the activity-based approach. Offshore providers, in that report’s terms, are those created under one jurisdiction’s law, with or without a physical presence, serving clients resident in another. The gap between the two approaches is the reason a provider can be lawfully registered where it is incorporated, unregistered where its clients are, and describe itself as a VASP with equal accuracy in both places.
What the same provider is called under other frameworks
The acronym travels; the legal status does not. National frameworks implement the FATF category under their own names, with their own perimeters, so the same conduct can be a licence in one place, an entry on a register in another, and captured by money-transmission, payment-services or securities rules in a third, with no two permitted scopes identical.
The European Union is the current worked example. Under the Markets in Crypto-Assets Regulation the statutory category is the crypto-asset service provider, or CASP, and the transitional regime that let firms continue on pre-existing national VASP registrations closed on 1 July 2026. From that date a legacy national registration is not a basis for serving EU clients; only an authorisation granted under MiCA is, and a pending application is not an authorisation. Several member states closed their windows earlier than the EU-wide backstop.
The practical residue is vocabulary that outlives the instrument it described. A provider may go on presenting itself as a registered VASP after the register that recorded it has been superseded, because the acronym is descriptive and no authority polices its use in marketing copy.
What obligations attach once the status applies
Inside the perimeter, a provider carries the obligations of a financial institution: customer due diligence and beneficial-ownership identification; sanctions, politically-exposed-person and adverse-media screening; transaction monitoring; record-keeping; suspicious-transaction reporting; and the Travel Rule — originator and beneficiary information accompanying a transfer between providers, under Recommendation 16. Thresholds, verification standards and message formats are set nationally and are not uniform.
Legislation and implementation are separate facts, and the distance between them is the live one. The 2026 targeted update reports that 83% of surveyed jurisdictions have now passed Travel Rule legislation, up from 73% a year earlier, with eleven more reporting implementation under way — while finding that many jurisdictions have not yet turned those frameworks into supervision and enforcement in practice. The strengthened Recommendation 16 agreed in June 2025 carries an expectation that countries are ready to implement by the end of 2030, and FATF put its draft guidance for that standard out to public consultation in June 2026. A transfer-information regime described as current is, in part, a regime still four years from its own readiness date.
How a claim to be a VASP is verified
A claim resolves to four things, or it does not resolve:
- The legal entity. The registered name and number of the entity that performs the conversion — which is frequently not the brand on the interface, and not the group holding company named in a footer.
- The instrument. The licence or registration, the authority that issued it, and its reference in that authority’s public register.
- The scope. The activities the instrument permits. Exchange, transfer and safekeeping are separately permissioned in many regimes, and an entity authorised for one is not authorised for the others.
- The date. Status as at the date of the transaction, not as at the date the provider last revised its website.
Where the authority publishes a searchable register, all four are checkable in minutes. Where it does not, the claim rests entirely on documents the provider supplies about itself — a different quality of evidence, and read as one.
Where the status fails in practice
Nesting. FATF’s offshore-VASP report describes unlicensed offshore providers obtaining service from a licensed provider by presenting as an ordinary individual customer. The licensed entity is genuine and its authorisation is genuine; the flow standing behind it is not the flow its authorisation describes. This is the failure mode that a licence check alone cannot detect, because the licence is real.
Group structure. A provider authorised in one jurisdiction may route particular clients or corridors through an affiliate authorised nowhere. FATF’s stated expectation is that firms apply consistent rules across every entity in the group and ensure none of them operates offshore outside supervision.
Scope mismatch. The instrument permits one limb; the conduct spans three. Common where a provider adds custody or on-chain transfer to what began as an exchange service.
Lapse and supersession. Registrations are withdrawn, expire, or are extinguished when a regime is replaced — the EU register closure of 1 July 2026 being the largest single instance to date.
The sunrise gap. Travel Rule obligations bind the sending provider under its own law and the receiving provider under a different one, or under none. Information that must be sent may have no counterparty obliged to receive it, and the gap sits at the border between two frameworks rather than inside either.
VASP and the terms it is confused with
| Term | What it names |
|---|---|
| CASP | The European Union’s statutory category under MiCA. A specific authorisation with a specific scope, not a synonym for the FATF category. |
| Exchange | One business model inside the definition. A VASP need not operate an order book, and many never do. |
| Custodian | The safekeeping limb alone. Custody is separately permissioned in most regimes. |
| Payment gateway | The interface through which a payer pays a merchant. The gateway operator is the VASP where it converts and settles; the merchant is not. |
| Off-ramp | A function, not a status: converting digital assets into national currency and paying the proceeds to a bank account. |
| OTC desk | Bilateral dealing against the desk’s own book on a privately requested quote. A VASP where it holds or moves client assets. |
| Unhosted wallet | Assets held by a person under their own keys. No provider, therefore no VASP, and no transfer between providers to attach information to. |
What the status is worth to the party at the receiving end
The material published on VASP status is written for the providers seeking it and the supervisors granting it: how to obtain the authorisation, how to keep it, how to examine the firm that holds it. The party that most often has to rely on the status is absent from that material — the seller at the far end of a converted payment, who never touches a digital asset, receives national currency, and has to explain the origin of that money to its own bank, its auditor, and any counterparty that asks.
For that party the status is not a credential. It is evidence, and evidence has an issuer, a scope and a date. Three developments of 2026 cut in the same direction. The European Union extinguished a whole class of legacy registrations on 1 July. FATF named nesting in March as the mechanism by which an unlicensed provider stands behind a licensed one, so that the licence at the visible end of a chain describes only the visible end. And the strengthened transfer-information standard is not expected to be fully implemented anywhere before the end of 2030, which means the information travelling with a transfer today is set by whichever national rule happened to bind the sending provider.
A receiving counterparty that records the acronym has recorded a category. What survives a reviewer is narrower and duller: which legal entity performed the conversion, under which instrument and scope, what it screened before accepting the transaction, what it settled and in what currency, and the reference that ties that settlement to one instruction rather than to a general inflow of funds. Each of those is a document. The acronym is not.
Where digital-asset proceeds are converted by a licensed digital-asset platform and settled in national currency against a single order reference, the route and the documents it produces are set out at Buy Physical Gold with Crypto.
