Singuard Home Blog Contact eTrader eTrader for Businesses eTrader for Traders Broker Broker CRM Live Demo Prop Firm Prop Firm CRM Live Demo
Licenses & Regulation

VASP Registration: Crypto Compliance Before MiCA.

The term "virtual asset service provider" was written by financial crime regulators, not by the crypto industry. That single fact explains almost everything about how these registrations behave.

By May 25, 2026 6 min read

The Financial Action Task Force extended its Recommendation 15 in 2019 and, in doing so, invented a category of firm that had not existed on any statute book. A virtual asset service provider was defined by activity: exchanging virtual assets for fiat currency, exchanging one virtual asset for another, transferring them on behalf of another person, holding custody of them, or taking part in the sale of a new issuance. Countries that wanted to avoid an unfavourable mutual evaluation then had to build a domestic register for those activities, quickly.

The result was a patchwork. Some regulators built a light notification regime that took weeks. Others attached fit and proper testing, on the ground presence, audited accounts and a named compliance officer, and took the better part of a year. Both were called VASP registration.

Registration is an AML gate, not a product licence

This is the point most applicants get wrong. A VASP register entry usually confirms one thing: the supervisor has checked the firm against money laundering and terrorist financing standards and is satisfied with its controls, its ownership and the people running it. It rarely says anything about how much capital the firm holds, how client crypto is segregated from company crypto, what happens in an insolvency, or how the firm is allowed to market itself.

In the EU the origin of these registers was the fifth anti money laundering directive, which pulled exchange providers between virtual and fiat currencies and custodian wallet providers into the same obligations as other obliged entities. If you want the wider context of how those directives fit together, we cover it in the AML directive series. What matters here is the consequence: the obligation was to identify customers, monitor transactions and report suspicion, and the register existed so supervisors knew who they were supervising.

A register entry is not a badge of quality. Marketing a firm as "regulated" because it appears on a national VASP list overstates what the supervisor actually reviewed, and several regulators have published warnings saying exactly that.

What supervisors actually ask for

Across jurisdictions the file looks similar even when the statute does not. Expect an ownership chart down to the ultimate beneficial owners, criminal record certificates and CVs for directors, a money laundering reporting officer with real experience and enough time allocated to the role, a risk assessment written for the specific business model rather than copied from a template, and transaction monitoring rules that a supervisor can read and understand.

Two areas fail applications more often than the rest. The first is the travel rule: originator and beneficiary information has to move with a transfer, and a supervisor will ask which tool you use, what you do when the counterparty wallet is unhosted, and what your threshold policy is. We look at that in more detail in the travel rule guide. The second is substance. Regulators in Europe, and increasingly in the offshore centres, have stopped accepting a mailbox address and a part time contractor as a local presence.

Then MiCA changed the question

Regulation (EU) 2023/1114 replaced the national approach with a single authorisation for crypto asset service providers, applying to services such as custody, operating a trading platform, exchange, order execution, placement, reception and transmission of orders, advice and portfolio management. Unlike an AML register entry, that authorisation carries capital requirements, conduct rules, complaint handling obligations, custody segregation rules and, critically, the right to serve clients in other member states.

The practical effect is that "VASP" and "CASP" describe two different things in Europe now. One was an anti money laundering formality with a domestic footprint. The other is a full financial services authorisation with a passport. Firms that treat the first as a shortcut to the second get a short letter from the supervisor. The differences are worth reading side by side in our comparison of the two regimes, and the authorisation process itself in the MiCA licence walkthrough.

The transitional windows caught people out

MiCA let member states run a grandfathering period for firms already providing crypto asset services under national law before the regulation applied. The length of that period was a national choice, and states did not choose the same length. A firm registered in three countries could therefore face three different cut off dates, with the shortest one setting the real deadline for the group.

Two operational mistakes followed from that. Firms assumed the transitional period was a right to keep operating indefinitely while an application sat in a queue, which it was not. And firms assumed a national registration would convert automatically into an authorisation, which in most states it did not: the file had to be resubmitted against a much heavier standard.

Where this lands for a trading firm

Most brokers and prop firms are not crypto asset service providers and do not want to be. Offering CFDs on crypto underlyings is a different activity from holding client crypto, and it falls under investment services rules rather than MiCA's service catalogue. The line gets blurry in one place: deposits. A firm that accepts stablecoin deposits, converts them and holds a balance can drift into custody or exchange activity depending on how the flow is built and who holds the keys.

The safer pattern, and the one most operators end up with, is to keep the crypto leg with a regulated third party processor that converts on receipt, so the firm never holds a customer's virtual assets on its own book. That does not remove the AML work, and it does not remove the need to know where your processor is authorised, but it keeps the licensing question on one side of the line instead of both. Jurisdiction shopping for the crypto side is covered separately in our review of crypto licence jurisdictions.

One last point on sequencing. Applicants often build the product first and write the compliance file afterwards, then discover the file describes a business the product cannot support: monitoring thresholds nothing enforces, wallet screening nobody integrated, a travel rule policy with no tooling behind it. Supervisors read those documents as promises. Build the controls into the system before you describe them on paper.

"People ask me which country gives the fastest VASP registration. That is the wrong question. Ask which country's register your banking partner will accept, because a permission nobody will bank is worth nothing."

— Roman Onta, Executive Director, SINGUARD

Key Takeaways

Frequently Asked Questions

Is a VASP registration the same thing as a crypto licence?

In most countries it is narrower. A VASP registration confirms that a firm has been screened for anti money laundering purposes and that its owners and compliance officer passed a fit and proper check. It usually says nothing about capital, client asset protection or conduct rules, which is what a full authorisation covers.

Does a VASP registration in one EU country let me serve clients across the EU?

No. National registrations created under the EU anti money laundering directives were domestic measures with no passport attached. Cross border rights in the EU for crypto asset services come from the MiCA authorisation as a crypto asset service provider, not from an older AML register entry.

What happens to firms that were already on a national VASP register when MiCA applied?

MiCA allowed member states to run a transitional period during which firms already operating under national rules could continue while they applied for the new authorisation. The length of that window was set nationally and was not the same everywhere, so a firm operating in several countries had to track several deadlines.

Your Own Trading Firm, Live in 24 Hours.

SINGUARD builds the technology behind brokers and prop firms: trading platform, CRM, client portal and payment rails, one bundle, one predictable price. Book a call and see it working, or keep reading the guides.

More in Licenses & Regulation