Brief
Understanding virtual asset service providers
Virtual asset service providers have been defined as a new financial sector facing significant money laundering and terrorist financing risks.
Michaela Clarke
Operations & Compliance Coordinator

What are virtual asset service providers (VASPs)?
Virtual asset service providers have been defined as a new financial sector facing significant money laundering and terrorist financing risks.
The Financial Action Task Force (FATF) issued its guidance (2019) on how virtual asset service providers could be abused by criminals and terrorists to launder money and finance terrorist acts.
As of March 2021, the FATF has issued a new consultation to amongst others, provide more clarity on which businesses are undertaking VASP activities and are subject to the FATF Standards
Remember as a VASP you will need to:
- Implement the same preventive measures as financial institutions, including customer due diligence, record-keeping, and reporting of suspicious transactions
- Obtain, hold and securely transmit originator and beneficiary information when making transfers
- Must know who your customers are
- Keep adequate and up to date records aligned to record-keeping requirements
- Ensure a framework is in place to report transactions where suspicions of money laundering or terrorist financing remain
- Securely and confidentially transmit customer information when sending a payment to another virtual asset provider
These are also covered in FATF Recommendations 10 and 16
If you are a Virtual Asset Service Provider or plan to set up as one, you must ensure you can comply with the FATF requirements.
At MEMA we support VASPs in understanding and implementing their regulatory requirements.
Need expert regulatory guidance?
Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.
Book a Free Scoping CallRelated insights
View all insights →
CACEIS and WealthTek: testing the control chain behind client-asset protection
The FCA censured CACEIS UK and recorded a £31.7m voluntary payment after failures to act on information that exposed WealthTek clients to financial-crime risk.

CP26/16 has closed: what firms should prepare for next
CP26/16 closed on 9 July 2026. Its proposals concern safekeeping delegation and the authorised fund registration function, not a new FCA data return.

In-house, outsourced or co-sourced compliance: a governance comparison
A comparison of compliance resourcing models through accountability, capability, information access, provider oversight, continuity and exit planning.