Operating a virtual asset business in Pakistan means navigating a developing regulatory landscape. As the Pakistan Virtual Assets Regulatory Authority (PVARA) finalises its framework, understanding core compliance obligations like Customer Due Diligence (CDD) is critical for all Virtual Asset Service Providers (VASPs). Proactive preparation ensures your business can secure the necessary licences and operate legally, avoiding significant penalties.

Ignoring these requirements is not an option. Robust CDD processes are fundamental to an effective Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) regime. They protect your business from being exploited by illicit actors, safeguard your reputation, and are essential for maintaining the trust of both your customers and the regulator.

This practical walkthrough explains the key aspects of CDD, helping you implement strong compliance measures as Pakistan’s virtual asset sector matures. It is designed to equip operators with the knowledge needed to build a compliant and resilient business model from the outset.

What is Customer Due Diligence (CDD)?

Customer Due Diligence (CDD) is the process by which a financial institution, or in this case, a Virtual Asset Service Provider (VASP), identifies and verifies the identity of its customers. It involves understanding the nature of their business and assessing the risks associated with them to prevent money laundering and terrorist financing. This foundational step ensures transparency and accountability within the virtual asset ecosystem.

CDD is a cornerstone of any effective Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) framework. It goes beyond simply collecting identification documents. It requires an ongoing understanding of the customer’s activities and transaction patterns. For VASPs, this means adapting traditional financial sector practices to the unique characteristics of virtual assets, which can sometimes offer greater anonymity and speed. The Financial Action Task Force (FATF) recommendations, particularly FATF Recommendation 15: Shaping Pakistan’s Virtual Asset Rules, heavily influence Pakistan’s approach to CDD for virtual assets.

Who needs to perform CDD?

All entities operating as Virtual Asset Service Providers (VASPs) in Pakistan are expected to perform CDD on their customers. This includes crypto exchanges, wallet providers, and any business facilitating the transfer, exchange, or safekeeping of virtual assets. The specific requirements apply to any business that falls under the definition of a VASP, as outlined by PVARA.

This obligation extends to both individual and corporate customers. If your business facilitates virtual asset transactions, you must implement CDD procedures. This is a core part of the regulatory expectations for who needs a VASP licence in Pakistan and who does not. The scope also includes those engaging in initial coin offerings (ICOs) or providing custodial services for virtual assets. Essentially, if you are handling customer funds or virtual assets, you are responsible for knowing who your customers are.

What are the core components of CDD?

The core components of CDD involve identifying the customer, verifying their identity using reliable sources, and understanding the purpose and intended nature of the business relationship. This also includes identifying the beneficial owner of an account if it’s not the direct customer. Ongoing monitoring of the business relationship is also a crucial part of CDD.

Let’s break down these components:

  1. Customer Identification:
    • Individuals: Full legal name, date of birth, national identity number (e.g., CNIC), residential address, contact information.
    • Legal Persons/Entities: Registered name, legal form, proof of incorporation (e.g., Certificate of Incorporation), registered address, names of directors and beneficial owners, and details of the company’s business activities.
  2. Identity Verification:
    • This requires obtaining independent, reliable source documents, data, or information.
    • For Individuals: Valid Computerised National Identity Card (CNIC), passport, or other government-issued photo identification. Utility bills or bank statements can verify address.
    • For Legal Persons: Certified copies of incorporation documents, memorandum and articles of association, board resolutions, and identification documents for key personnel and beneficial owners.
  3. Understanding the Business Relationship:
    • This involves assessing the customer’s risk profile based on factors like their geographic location, the type of virtual assets involved, the volume of expected transactions, and the nature of their business.
    • For example, a customer intending to trade high volumes of privacy coins might pose a higher risk than one making small, infrequent transactions in Bitcoin.
  4. Beneficial Ownership Identification:
    • For corporate customers, VASPs must identify the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted. This is crucial to prevent the misuse of legal entities for illicit purposes.
  5. Ongoing Monitoring:
    • CDD is not a one-time process. VASPs must continuously monitor customer transactions and activities to ensure they are consistent with the VASP’s knowledge of the customer, their business, and their risk profile. This includes reviewing customer information periodically to ensure it remains current.

How does Enhanced Due Diligence (EDD) differ from standard CDD?

Enhanced Due Diligence (EDD) involves more intensive scrutiny and higher levels of verification than standard CDD, applied when a VASP identifies a higher risk of money laundering or terrorist financing. It requires additional measures to mitigate these elevated risks. EDD is a critical tool for managing complex or suspicious customer relationships.

Circumstances that typically trigger EDD include:

EDD measures often include:

What are Simplified Due Diligence (SDD) circumstances?

Simplified Due Diligence (SDD) allows for reduced CDD measures when the risk of money laundering or terrorist financing is demonstrably low. This approach is applied in specific, well-defined situations where the customer or product type presents minimal risk, streamlining the onboarding process without compromising overall AML/CFT integrity. PVARA’s framework will detail these specific low-risk scenarios.

Examples of situations where SDD might be permitted, generally based on international practice, include:

It is crucial for VASPs to have clear internal policies for applying SDD. These policies must be risk-based and backed by a thorough risk assessment. If at any point the risk assessment changes, or if there is suspicion of money laundering or terrorist financing, SDD must be immediately suspended, and standard or enhanced CDD procedures must be applied.

What about ongoing monitoring?

Ongoing monitoring is a continuous process of scrutinising customer transactions and activity throughout the business relationship to ensure consistency with the VASP’s understanding of the customer and their risk profile. It is not a one-time check but an integral, dynamic part of the CDD framework. This includes monitoring for unusual or suspicious activities.

Key aspects of ongoing monitoring include:

What records must be kept?

Virtual Asset Service Providers (VASPs) are required to maintain comprehensive records of all customer due diligence information, transactions, and risk assessments. These records must be readily accessible for regulatory inspection and audit purposes. The specific retention period will be stipulated by PVARA, but generally aligns with international standards of several years after the business relationship ends.

The types of records to be maintained include:

Maintaining accurate and organised records is not just a compliance requirement; it is a vital operational practice that supports internal audits and demonstrates adherence to regulatory standards. This is part of the broader compliance framework that includes VASP licensing service and other operational standards.

What are the penalties for non-compliance?

Non-compliance with Customer Due Diligence (CDD) requirements can lead to severe penalties for Virtual Asset Service Providers (VASPs) in Pakistan. These penalties are designed to deter illicit activities and ensure the integrity of the financial system. Operators must understand these risks to prioritise robust compliance frameworks.

Potential penalties include:

Summary of Due Diligence Levels

To provide a clearer picture, here is a comparison of the three main levels of Customer Due Diligence. This table is based on general international AML/CFT standards and will be further refined by PVARA’s specific guidelines.

Feature Simplified Due Diligence (SDD) Standard Customer Due Diligence (CDD) Enhanced Due Diligence (EDD)
Risk Level Low Normal/Medium High
Trigger Specific low-risk scenarios (e.g., regulated entities, very low-value products) All standard customer relationships High-risk factors (e.g., PEPs, high-risk jurisdictions, complex structures)
Identification Basic identity collection Full identity collection (name, address, DOB, CNIC/passport, etc.) More extensive identity collection, deeper background checks
Verification Reduced verification, relying on public information or existing trust Independent verification of identity using reliable documents Multiple sources for verification, in-depth document analysis
Beneficial Owner May be simplified or assumed known for regulated entities Identify and verify beneficial owner More rigorous identification and verification of all beneficial owners
Purpose of Rel. Basic understanding Understand purpose and intended nature of business relationship Detailed understanding of purpose, source of funds/wealth
Monitoring Less frequent or automated monitoring Ongoing monitoring of transactions and relationship Increased frequency and depth of ongoing monitoring, senior management oversight

Staying Compliant in a Evolving Landscape

The virtual asset regulatory landscape in Pakistan is dynamic, with PVARA actively working to establish a comprehensive framework. Operators must remain vigilant and proactive in adapting their compliance programmes. Regularly reviewing Sarzif Policy’s regulatory updates and engaging with PVARA directly will be crucial for long-term success.

Implementing robust CDD processes from the outset is not merely a box-ticking exercise; it is an investment in the security, integrity, and sustainability of your virtual asset business. By understanding and adhering to these requirements, you contribute to a safer virtual asset ecosystem in Pakistan and position your firm for future growth. Remember, the ultimate goal is to foster innovation while preventing illicit financial activities within the sector. You can find more information about what is PVARA? A plain-English guide to Pakistan’s virtual asset regulator on our blog. For direct engagement with the authority, visit the official PVARA website at https://pvara.org.

About this analysis

This analysis was prepared by Sarzif Policy using publicly available information from Pakistani regulatory bodies, including the State Bank of Pakistan, the Securities and Exchange Commission of Pakistan, and the Federal Board of Revenue, as well as guidance from the Financial Action Task Force. It also draws on insights from Pakistani court decisions and industry best practices.

The regulatory framework for virtual assets in Pakistan is currently under development by PVARA. While this article provides a practical overview of Customer Due Diligence requirements based on current understanding and international standards, specific thresholds, procedures, and final rules are subject to change. Operators are strongly advised to verify the latest requirements directly with PVARA or consult with qualified legal and compliance professionals. This article is intended for informational purposes only and does not constitute legal advice. For further information about our research, please review our /about/ page and our /editorial-policy/. You can also /contact/ our team for general enquiries.

Noor Aslam, Chief Executive Officer of Sarzif Policy

Noor Aslam

Chief Executive Officer of Sarzif Policy, with eight years in virtual assets — four of them advising on VARA licensing in Dubai. She leads the research team that tracks Pakistan's framework and reviews every consultant shortlist that goes out. More about the team.

This article is information, not legal or financial advice. Regulatory positions change. Confirm any requirement against the official position published by PVARA before you act on it. Spotted an error? Write to sarzifpolicy@gmail.com and we will correct it.

Related updates