A detailed 3D model illustrating the components and connections within a digital asset ecosystem
What Is a Virtual Asset Service Provider?
A Virtual Asset Service Provider, universally abbreviated VASP, is any natural or legal person who conducts one or more specific activities on behalf of a customer involving virtual assets. The term originates from the Financial Action Task Force’s 2019 update to its recommendations, and it has since been adopted, sometimes verbatim and sometimes with local variation, into national law across the European Union’s MiCA framework, Kenya’s VASP-KE regime, the United States’ money-transmitter licensing structure, and dozens of other jurisdictions. What makes the definition useful, and occasionally frustrating for founders trying to determine whether it applies to them, is that it is activity-based rather than technology-based: it does not matter what your product is called or how it is marketed, what matters is which specific functions it performs for someone else.
The Activities That Actually Trigger the Classification
FATF’s guidance identifies a small set of activities that, individually, are sufficient to make a business a VASP. Exchange between virtual assets and fiat currencies is the most obvious one, covering any standard crypto exchange. Exchange between one or more forms of virtual assets covers token-swap services, even those that never touch fiat at all. Transfer of virtual assets, meaning conducting a transaction on behalf of another person, covers payment processors and remittance services built on crypto rails. Safekeeping or administration of virtual assets or instruments enabling control over them covers custodians and most wallet providers that hold keys on a customer’s behalf. Participating in and providing financial services related to an issuer’s offer or sale of a virtual asset rounds out the list, capturing launch platforms and certain advisory arrangements. A business performing any one of these for a customer is a VASP regardless of what else it calls itself.

Figure 1. FATF’s definition is activity-based: perform any of these for a customer, and you’re a VASP.
What Being a VASP Actually Requires
Once an entity qualifies, a fairly standard set of obligations follows across most jurisdictions. Licensing or registration with the relevant national regulator is required before services can be offered, and that authorisation typically depends on demonstrating adequate governance, capital, and systems. An anti-money laundering and know-your-customer program has to identify customers and monitor their activity for anything suspicious. Travel Rule compliance requires passing originator and beneficiary data along with qualifying transfers. Ongoing reporting obligations, including suspicious activity reports to the relevant financial intelligence unit, apply for the life of the licence. None of this is unique to crypto; it largely mirrors what traditional money service businesses and payment institutions have operated under for decades, which is precisely the point FATF’s framework was designed to achieve: bringing virtual asset businesses into the same regulatory perimeter as their traditional finance counterparts.

Figure 2. Licensing, AML, Travel Rule compliance, and reporting mirror traditional money service obligations.
Where the Line Actually Sits
The dividing line that generates the most genuine debate is custody. A centralised exchange holding customer funds is unambiguously a VASP. A developer who writes and publishes non-custodial wallet software, where the user alone controls their private keys and the software provider never takes custody or conducts a transaction on the user’s behalf, generally falls outside the definition, because the software itself is not performing an activity for a customer in the way FATF’s list contemplates. This distinction matters enormously in practice: it is the reason self-hosted wallets are treated differently from exchange accounts under the Travel Rule, and it is the reason regulatory attention has concentrated so heavily on custodial platforms rather than on open-source protocol development. A practitioner assessing whether a given crypto business model needs a VASP licence should start by asking a single question: does this business ever take custody of, or execute a transaction on behalf of, someone else’s assets.

Figure 3. Merely writing non-custodial software is not, by itself, providing a virtual asset service.
The label VASP was built to make one point unavoidable: if you perform a financial service, it doesn’t matter that the asset is new. The obligations that come with the service are not.
Related reading on Blockchain People
What Is the Travel Rule? · What Is a Regulatory Sandbox? · Blockchain People Glossary
External References
FATF Guidance for a Risk-Based Approach to Virtual Assets and VASPs (FATF)
