← Back to blog

Examples of virtual asset businesses: UK guide

August 1, 2026
Examples of virtual asset businesses: UK guide

TL;DR:

  • A virtual asset service provider conducts activities like exchanges, transfer, safekeeping, or offering controlling instruments for virtual assets. The UK and FATF define VASPs based on custody, control, and operational functions, requiring compliance with AML, KYC, and the Travel Rule. Proper governance, asset segregation, and regulatory readiness are critical for licensing and operational success.

A virtual asset service provider (VASP) is any natural or legal person that, as a business, conducts one or more of the following activities on behalf of another person: exchange between virtual assets and fiat currency, exchange between virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets or instruments enabling control over them, or participation in services related to the offer or sale of a virtual asset. That definition comes from FATF, the global standard-setter, and it underpins the UK's own AML/CTF framework as administered by the Financial Conduct Authority (FCA).

The principal categories of virtual asset businesses operating in the UK today are:

  • Centralised exchanges — platforms that match buyers and sellers of crypto assets against fiat or other digital currencies
  • Custodial wallet providers — firms that hold private keys on behalf of clients
  • OTC trading desks — bilateral brokers facilitating large-block trades outside public order books
  • Crypto payment processors — businesses that accept, convert, or settle virtual assets as payment rails
  • Crypto ATM operators — physical kiosks enabling cash-to-crypto and crypto-to-cash conversion
  • Institutional custodians — regulated entities providing segregated, audited safekeeping for institutional clients

Software-only publishers, pure open-source protocol developers, and individual users transacting for personal purposes are generally excluded from the VASP definition, provided they do not take custody of client assets or operate exchange or transfer services.


What counts as a VASP under UK and FATF rules?

A business becomes a VASP the moment it performs one of the FATF-defined activities on behalf of another person in the course of business. In the UK, that threshold maps directly onto the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended), under which the FCA acts as the AML/CTF supervisor for cryptoasset businesses.

FATF Recommendation 15 requires countries to apply AML/CFT measures to VASPs and to ensure they are licensed or registered in the jurisdictions where they are created. The definition covers exchange, transfer, safekeeping/administration, and issuance-related services — and is deliberately technology-neutral so that new business models cannot sidestep it by changing their technical architecture.

The UK's practical application adds a layer of nuance. A firm does not need to be incorporated in the UK to fall within FCA oversight; if it actively markets to or serves UK customers, the FCA's registration requirement is likely to apply. The Travel Rule, derived from FATF Recommendation 16, further requires that originator and beneficiary information accompany qualifying transfers, creating additional data-handling and counterparty-screening obligations.

Common borderline cases that compliance teams frequently misclassify:

  • Non-custodial wallets — software that generates and stores private keys locally on the user's device, with no firm control, is generally outside the VASP definition
  • Pure open-source protocol codebases — publishing smart-contract code without operating a service or taking custody does not, on its own, constitute a VASP activity
  • Isolated developer tools — SDKs, node software, and block explorers that do not execute transfers or hold assets on behalf of users are typically excluded

The critical test is always custody and control: once a firm can move or access client assets, the VASP classification and its attendant obligations follow.


How VASPs actually operate day-to-day

VASPs perform five core functions, each of which triggers distinct compliance obligations. Chainalysis summarises the operational logic clearly: exchanges convert crypto for fiat or other crypto; custodial wallets hold private keys on behalf of users; OTC desks facilitate large trades; and payment processors move value across settlement rails.

Core functions and their compliance triggers:

  • Exchange (VA-to-fiat or VA-to-VA) — triggers KYC/AML obligations, transaction monitoring, and SAR reporting duties
  • Transfer — triggers Travel Rule obligations for qualifying cross-border transfers; requires originator and beneficiary data to travel with the transaction
  • Safekeeping/custody — triggers segregation requirements, independent audit expectations, and prudential capital considerations
  • Issuance facilitation — triggers securities-law analysis and, where the token qualifies as a specified investment, FCA authorisation requirements
  • Payment processing — may trigger both VASP and e-money or payment institution obligations depending on the settlement model

The operational flow for a typical retail VASP runs as follows:

  1. Customer onboarding — identity verification (KYC), risk scoring, sanctions screening, and source-of-funds assessment
  2. Transaction execution — order matching or bilateral settlement, with real-time transaction monitoring against typology libraries
  3. Settlement — on-chain transfer or internal ledger movement, with Travel Rule data packets transmitted to counterparty VASPs where required
  4. Custody and reporting — assets held in segregated wallets or with a sub-custodian; periodic regulatory reporting, SAR filing where suspicious activity is identified, and proof-of-reserves or attestation cycles for institutional counterparties

The Travel Rule deserves particular attention. FATF Recommendation 16 requires originator and beneficiary information to accompany transfers above the applicable threshold (typically USD/EUR 1,000 equivalent). VASPs that integrate Travel Rule-capable systems late face costly rework of their transactional pipelines; early integration is the operationally sound approach.


What kinds of virtual assets do VASPs handle?

VASPs handle a broad spectrum of digital assets, and the regulatory treatment of each depends on its functional characteristics rather than its technical label. The principal asset classes are:

  • Cryptocurrencies — Bitcoin, Ether, and similar proof-of-work or proof-of-stake assets used as a medium of exchange or store of value
  • Stablecoins — fiat-referenced tokens such as USDC, USDT, and DAI; in the UK, certain stablecoins used as a means of payment are subject to FCA oversight under the Financial Services and Markets Act 2023
  • Security tokens / digital securities — tokenised representations of equity, debt, or fund interests that constitute specified investments under the Financial Services and Markets Act 2000
  • NFTs used as investment or payment instruments — non-fungible tokens that function as a store of economic value, unit of account, or medium of exchange may fall within the VASP definition; purely collectible NFTs with no investment function generally do not
  • Gaming and governance tokens — utility tokens used in decentralised autonomous organisations (DAOs) or gaming ecosystems; governance tokens that can be traded or sold are increasingly within regulatory scope

The functional classification principle is decisive: when an NFT or utility token begins to operate as a payment instrument or investment vehicle, the regulatory analysis shifts, and the platform handling it may acquire VASP or even regulated-activity status. Boards and compliance teams should not rely on asset labels alone.


Examples of virtual asset businesses by category

The following categories represent the main types of virtual asset companies operating in or accessible to the UK market. TRM Labs identifies centralised exchanges, custodial wallets, OTC desks, payment processors, and ATM operators as the most commonly captured entities; crypto hedge funds and institutional custodians are frequently captured because of their trading or safekeeping roles.

Centralised exchanges

A centralised exchange (CEX) operates an order book or matching engine that allows customers to buy, sell, or swap virtual assets against fiat currency or other digital assets. The exchange holds custody of client assets during the trading process, which is the primary trigger for VASP classification. Coinbase and Kraken both operate in the UK and are registered with the FCA as cryptoasset businesses for AML/CTF purposes. Bitstamp, accessible to UK customers, similarly holds FCA registration. All three are subject to KYC/AML obligations, SAR reporting duties, and Travel Rule compliance for qualifying transfers.

Hands holding risk matrix in ADGM office

Custodial wallet providers and institutional custodians

A custodial wallet provider holds private keys on behalf of clients, meaning the firm controls access to the underlying assets. This is the clearest trigger for VASP classification and, at the institutional level, for independent custody audits and capital adequacy expectations. Copper provides institutional custody services to UK-based asset managers and funds, using multi-party computation (MPC) key management to reduce single-point-of-failure risk. BitGo offers qualified custodial services used by UK institutions, with segregated cold storage and independent attestation. Custodial control typically triggers stricter prudential and audit requirements from institutional counterparties.

Corporate office compliance documents with Dubai view

OTC trading desks

OTC desks facilitate large-block trades bilaterally, outside public order books. They are captured as VASPs because they execute exchange and, in many cases, transfer functions on behalf of clients. The typical client base is institutional: funds, family offices, and corporate treasuries. OTC desks must maintain full KYC on both sides of a trade and apply transaction monitoring calibrated to the higher-value, lower-frequency nature of their flow.

Crypto payment processors

Payment processors accept virtual assets as payment on behalf of merchants, converting them to fiat or holding them in custody pending settlement. Depending on the settlement model, a payment processor may simultaneously qualify as a VASP and as an e-money institution or authorised payment institution under the Payment Services Regulations 2017. Compliance teams should map the full settlement flow before concluding on the applicable regulatory perimeter. Firms looking to automate regulatory compliance reporting for exchange and payment functions can reduce manual reporting burden significantly.

Crypto ATM operators

Bitcoin ATM operators convert cash to crypto and vice versa at physical kiosks. They are unambiguously VASPs: they perform exchange (fiat-to-VA) and, in some configurations, transfer functions. The FCA has taken enforcement action against unregistered ATM operators in the UK, and the sector remains under active supervisory scrutiny. Enhanced due diligence is standard given the cash-intensive, anonymous-by-default nature of the channel.

NFT marketplaces

NFT marketplaces occupy a contested regulatory position. OpenSea, accessible to UK users, operates a platform for the listing and sale of non-fungible tokens. Whether it qualifies as a VASP depends on whether the NFTs traded function as investment or payment instruments and whether the platform provides custodial or exchange-like services. Chainalysis notes that NFT platforms providing custodial services or operating trading facilities may fall within FATF activities. Purely peer-to-peer, non-custodial NFT platforms are generally outside the definition, but the analysis is fact-specific.

Staking and validator services

Staking-as-a-service providers and validator node operators occupy an emerging regulatory category. Where a firm pools client assets, controls the staking keys, and distributes rewards, it may be performing safekeeping and, potentially, a collective investment scheme function. The FCA has signalled that staking arrangements warrant careful analysis under both the VASP and regulated-activity frameworks.

Crypto funds and hedge funds

Crypto hedge funds and digital asset investment funds are captured as VASPs when they trade or hold virtual assets on behalf of investors, because the trading and safekeeping functions fall squarely within the FATF definition. They are also typically subject to FCA authorisation as collective investment schemes or alternative investment fund managers. The dual regulatory perimeter — VASP and fund regulation — creates layered compliance obligations that boards must resource accordingly.

Category comparison

CategoryTypical licensable activityCustody/prudential implicationTravel Rule relevance
Centralised exchangeExchange (VA-to-fiat, VA-to-VA)Custody of client assets during trading; segregation requiredYes — qualifying transfers
Custodial wallet / institutional custodianSafekeeping/administrationFull custodial obligations; independent audit; capital adequacyYes — on transfer
OTC trading deskExchange and transferCustody during settlement; segregation expectedYes — bilateral transfers
Crypto payment processorTransfer; potentially e-moneyTransient custody; dual-perimeter riskYes — payment flows
Crypto ATM operatorExchange (fiat-to-VA)Limited custody; enhanced due diligenceLimited — typically retail
NFT marketplacePotentially exchange/custodyDepends on custodial modelDepends on function
Staking/validator serviceSafekeeping; potentially CISCustody of staked assets; fund-regulation riskLimited
Crypto fund / hedge fundExchange and safekeepingFull fund and VASP obligations; dual perimeterYes — portfolio transfers

Pro Tip: When assessing whether an NFT platform or DeFi protocol is a VASP, focus on two questions: does the platform control or can it access user assets at any point, and does it operate an exchange or transfer function on behalf of users? If the answer to either is yes, the VASP analysis applies regardless of the platform's self-description.


UK regulatory framework for VASPs

UK VASPs must satisfy three overlapping regulatory obligations: FCA registration or authorisation where applicable, compliance with the UK AML/CTF regime, and adherence to Travel Rule requirements for qualifying transfers. FATF standards inform UK expectations directly; the FCA's guidance translates those standards into practical supervisory requirements.

The UK's AML/CTF framework for cryptoasset businesses is set out in the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs), as amended. Any firm carrying on cryptoasset exchange or custodial wallet activity in the UK must register with the FCA before commencing business. Registration is not the same as authorisation; it is a lower threshold, but it still requires a credible AML/CTF programme, fit-and-proper senior management, and adequate systems and controls.

Regulator / instrumentScopeKey duties
FCA (MLRs 2017, as amended)All UK cryptoasset exchange and custodial wallet businessesRegistration; KYC/AML programme; SAR/STR reporting; Travel Rule compliance
FATF Recommendation 15Global standard; informs UK transpositionLicensing/registration; AML/CFT measures; supervision
FATF Recommendation 16 (Travel Rule)Qualifying VA transfers above thresholdOriginator/beneficiary data; counterparty VASP screening
Financial Services and Markets Act 2023Fiat-referenced stablecoins used as means of paymentFCA authorisation; additional prudential requirements
FCA Guidance on CryptoassetsAll FCA-registered cryptoasset businessesPractical application of MLR obligations; systems and controls expectations

The UK AML regime requires VASPs to maintain a documented risk assessment, appoint a nominated officer for SAR reporting, conduct ongoing transaction monitoring, and screen customers and counterparties against sanctions lists. The Travel Rule adds a data-sharing layer: for transfers above the applicable threshold, originator and beneficiary information must be transmitted to the receiving VASP and retained for five years.

Cross-border nexus issues are a persistent practical risk. A VASP incorporated outside the UK that actively markets to UK customers may be within the FCA's registration perimeter even without a UK legal entity. Boards should obtain a formal nexus opinion before launching UK-facing services.

Statistic callout: The FCA's cryptoasset register lists firms that have successfully completed the registration process. As of the time of writing, the register remains selective; the FCA has refused or cancelled registration for a significant proportion of applicants that could not demonstrate adequate AML/CTF controls. Firms should treat FCA registration as a substantive compliance exercise, not an administrative formality.


Main risks when dealing with VASPs and how to control them

The principal risk categories for any business engaging with or operating as a VASP are custody loss, counterparty insolvency, AML/TF exposure, sanctions breach, operational outage, and governance failure. Each carries distinct control requirements.

  • Custody loss — private key compromise, exchange hack, or operational error resulting in permanent loss of client assets. Control: MPC or HSM key management, cold storage for the majority of assets, independent security audits, and cyber insurance
  • Counterparty insolvency — a VASP becoming insolvent with client assets commingled on its balance sheet. Control: contractual segregation of client assets, independent custody attestation, and regular proof-of-reserves verification
  • AML/TF exposure — processing transactions linked to illicit finance, resulting in regulatory sanction or criminal liability. Control: risk-based KYC, real-time transaction monitoring using blockchain analytics tools, and a documented SAR reporting process
  • Sanctions breach — transacting with sanctioned individuals, entities, or jurisdictions. Control: automated sanctions screening against OFSI, OFAC, and UN lists at onboarding and on an ongoing basis
  • Operational outage — platform downtime during periods of market stress, resulting in client losses and regulatory scrutiny. Control: business continuity planning, redundant infrastructure, and contractual SLA protections
  • Governance failure — inadequate board oversight, undisclosed conflicts of interest, or inadequate capital buffers leading to regulatory intervention. Control: independent non-executive directors, documented board reporting cycles, and capital adequacy modelling against custodial exposures

PwC's practitioner guidance on custody classification notes that custodial status can be triggered by transient control of private keys, for example in payment processing or yield arrangements. Once custodial duties apply, independent audits and higher capital modelling are typically required. Enforcement exposure in the UK ranges from FCA supervisory notices and financial penalties to criminal prosecution under the Proceeds of Crime Act 2002 for serious AML failures.

For custody loss investigations and asset recovery, specialist crypto asset tracing services provide forensic-grade chain analysis to support both regulatory and civil proceedings.

Pro Tip: Do not treat proof-of-reserves as a binary pass/fail. A credible attestation names the auditor, states the methodology (Merkle-tree proof or full balance-sheet audit), and is dated within the last 90 days. An undated or self-certified proof-of-reserves is not an adequate trust signal for institutional counterparties.


How to assess whether a VASP is legitimate

Compliance and legal teams onboarding a VASP counterparty or vendor should apply a structured diligence framework. The following checklist covers the minimum verification steps for a UK-facing engagement.

  1. Confirm FCA registration or authorisation — search the FCA register; verify the firm's reference number, permitted activities, and any supervisory notices or warnings
  2. Review the AML/KYC programme — request a copy of the firm's AML policy, risk assessment, and KYC procedures; assess whether they are proportionate to the firm's risk profile
  3. Obtain proof-of-reserves or independent custody attestation — verify the auditor's identity, methodology, and the date of the attestation; institutional due diligence standards prioritise independent attestation, capital adequacy, and segregation as primary proof points
  4. Confirm segregation of client assets — review the custody agreement or terms of service; confirm that client assets are held in segregated accounts or wallets, not commingled with the firm's own assets
  5. Verify insurance cover — confirm the scope and limits of crime, cyber, and professional indemnity insurance; check whether coverage extends to custodial losses
  6. Assess sanctions screening and transaction monitoring — request evidence of the blockchain analytics tools in use and the sanctions lists screened; confirm the frequency of screening updates
  7. Check enforcement and breach history — search FCA enforcement notices, court records, and public regulatory databases for any prior sanctions, fines, or licence conditions
  8. Confirm Travel Rule capability — verify that the firm has integrated a Travel Rule-capable solution and can transmit and receive originator/beneficiary data for qualifying transfers
  9. Evaluate technology and security posture — confirm use of MPC or HSM key management, cold storage ratios, penetration testing cadence, and incident response procedures
  10. Review contractual protections — confirm that the custody or service agreement includes asset segregation covenants, audit rights, step-in rights on insolvency, and dispute resolution provisions

Pro Tip: For institutional counterparties, request the most recent SOC 2 Type II report alongside the proof-of-reserves attestation. SOC 2 Type II covers operational controls over a period of time, not just a point-in-time snapshot, and is a stronger indicator of sustained security posture.


Board-level structuring and governance for VASP licensing readiness

The single most important board-level priority for any business establishing or engaging a VASP is getting the governance, capital adequacy, segregation of client assets, and supervision readiness right before approaching a regulator. Successful VASP structuring is primarily a legal-regulatory exercise: entity residence, licensing nexus, and contract structuring determine regulatory exposure more than the chosen blockchain architecture.

Key structuring and governance considerations for boards and senior management:

  • Legal entity nexus — determine in which jurisdiction(s) the VASP activities are performed and where the legal entity must be registered or licensed; a formal nexus opinion is advisable before committing to an operating model
  • Capital modelling — model capital requirements against custodial exposures, operational risk, and any applicable prudential standards; do not assume that a registration-only regime imposes no capital floor
  • Independent custody — establish whether client assets will be held by the operating entity or a ring-fenced sub-custodian; the latter is strongly preferred for institutional credibility and regulatory resilience
  • Auditability — design the ledger, reconciliation, and reporting architecture so that an external auditor can verify balances and flows without reliance on management representations
  • Director and officer responsibilities — appoint a Money Laundering Reporting Officer (MLRO) with genuine authority and resource; document board-level oversight of AML/CTF programme performance
  • Board reporting cycles — establish quarterly compliance reporting to the board covering SAR volumes, transaction monitoring alerts, KYC refresh rates, and Travel Rule compliance metrics
  • Compliance resourcing — budget for a compliance function proportionate to the firm's risk profile; under-resourced compliance is the most common cause of FCA registration refusal

PwC's hybrid-model guidance notes that successful VASPs combine decentralised technology for value transfer with centralised, regulator-ready governance and documentation to secure banking partnerships and licensing. That combination is not optional for UK-facing businesses; it is the baseline expectation.

Travel Rule implementation should be treated as a day-one infrastructure decision, not a post-launch retrofit. Integrating a Travel Rule-capable provider early avoids disruptive rework of transactional pipelines and demonstrates supervision readiness to the FCA. For firms exploring multi-jurisdictional licensing, the regulatory compliance advisory framework offered by specialist legal advisers covers the full licensing lifecycle from pre-application to approval.

Pro Tip: When modelling capital adequacy for a custodial VASP, include a stress scenario in which the value of custodied assets falls by 50% and a major counterparty defaults simultaneously. Regulators and institutional banking partners will apply similar scenarios; presenting a pre-modelled stress analysis demonstrates board-level prudential seriousness.


CRYPTOVERSE's perspective on VASP licensing in practice

The most consistent error Cryptoverselawyers observes across VASP licensing mandates is the conflation of technical readiness with regulatory readiness. A firm can have best-in-class MPC custody infrastructure and still fail FCA registration because its AML policy is a template document with no genuine risk calibration, or because its MLRO has no real authority over the compliance function. Regulators assess governance and substance, not technology.

The immediate priority for any board preparing a VASP for UK licensing or institutional engagement is to establish three things before anything else: a documented, risk-calibrated AML/CTF programme; genuine segregation of client assets with independent attestation; and a Travel Rule solution that is live, not planned. Everything else, including branding, product features, and market positioning, is secondary to those three foundations.


Cryptoverselawyers provides specialist legal advisory services for virtual asset businesses at every stage of the licensing and compliance lifecycle. Whether you are structuring a new exchange, establishing a custodial model, drafting AML/CTF policies aligned with FATF standards and UK MLR obligations, or preparing a multi-jurisdictional licensing strategy, the firm delivers regulator-ready legal frameworks built for scrutiny.

Cryptoverselawyers

The firm's digital asset legal consultancy covers VASP licensing across the UAE's five regulators (VARA, SCA, DFSA, FSRA, and CBUAE) and extends to over 30 jurisdictions, including the FCA framework in the UK. For founders and compliance officers who need a clear path from concept to licensed operation, the starting point is a structured pre-application review. Contact Cryptoverselawyers to arrange an initial consultation and establish your firm's licensing readiness position.


Useful sources and further reading

The following primary sources and authoritative references support the claims in this article and provide further reading for compliance teams and legal counsel.

  • Financial Action Task Force (FATF) — the global standard-setter for AML/CFT; publishes Recommendations 15 and 16 (VASP definition and Travel Rule), updated guidance on virtual assets, and jurisdiction snapshots
  • FATF — Virtual Asset Contact Group jurisdiction snapshots — comparative data on how jurisdictions have implemented FATF standards for virtual assets
  • TRM Labs — VASP glossary and trust signals — practitioner-level definitions of VASP categories, institutional due diligence standards, and Travel Rule practical guidance
  • Chainalysis — VASP classification and edge cases — operational descriptions of VASP categories and analysis of NFT/DeFi classification edge cases
  • IMF — Considerations for regulatory and supervisory authorities — senior IMF perspective on the evolving regulatory framework for crypto assets
  • ESMA — Markets in Crypto-Assets Regulation (MiCA) — the EU's comprehensive crypto-asset regulatory framework; relevant for UK firms with EU nexus
  • AUSTRAC — Virtual asset designated services — detailed functional mapping of VASP activities; useful comparative reference for understanding how exchange, transfer, and safekeeping activities are defined across jurisdictions
  • Cryptoverselawyers — UK crypto licensing FCA decision tree — practical guidance on FCA authorisation requirements for UK cryptoasset businesses
  • Cryptoverselawyers — Crypto custody and asset safeguarding — detailed legal analysis of custody models, segregation obligations, and independent attestation requirements

This article provides general information about virtual asset businesses and the regulatory frameworks that apply to them. It does not constitute legal advice. Readers should obtain independent legal advice from a qualified professional for their specific circumstances and confirm current regulatory requirements with the FCA or other applicable regulator.