Navigating the licensing landscape for Virtual Asset Service Providers (VASPs) in Pakistan involves a continuous dialogue with regulatory bodies. This interaction is often characterised by requests for information, which are crucial checkpoints in the application process. How an operator handles these requests can significantly influence the outcome of their licence application.

A well-organised, timely, and comprehensive response demonstrates an applicant’s commitment to compliance and operational integrity. Conversely, inadequate or delayed responses can lead to delays, further scrutiny, or even the rejection of a licence. Understanding the nature and purpose of these requests is therefore fundamental for any VASP seeking to operate in Pakistan.

This analysis outlines best practices for managing information requests, helping virtual asset businesses streamline their licensing journey and build a strong, transparent relationship with their prospective regulator.

What is a regulator’s information request?

An information request from a regulator is a formal communication asking an applicant or regulated entity to provide specific documents, data, or explanations. These requests are a standard part of regulatory oversight, designed to gather necessary details for assessment, clarification, and ongoing supervision, particularly during the VASP licensing process.

Regulators, such as the Pakistan Virtual Assets Regulatory Authority (PVARA), use these requests to deepen their understanding of an applicant’s business model, operational capabilities, compliance frameworks, and financial health. They serve as a critical tool for due diligence, ensuring that only fit and proper entities are granted licences. Requests can range from simple clarifications on submitted documents to extensive demands for detailed operational policies or financial records. They often follow the initial submission of a licence application, as regulators review the provided materials and identify areas requiring further detail or substantiation.

Why do regulators issue information requests?

Regulators issue information requests to ensure that Virtual Asset Service Providers (VASPs) meet all statutory and prudential requirements before and after licensing. These requests help verify the accuracy of submitted information, assess compliance with anti-money laundering (AML) and counter-terrorist financing (CTF) standards, and evaluate the overall fitness and propriety of the applicant.

The primary objective is to protect consumers, maintain market integrity, and prevent the financial system from being used for illicit activities. By asking for specific details, regulators can identify potential risks, scrutinise internal controls, and confirm that the VASP has robust systems in place to manage its operations responsibly. For instance, an information request might seek to clarify aspects of a VASP’s risk assessment methodology for a virtual asset business, ensuring it aligns with regulatory expectations. This proactive approach helps regulators make informed decisions, ensuring that licensed entities contribute positively to Pakistan’s virtual asset ecosystem.

Who issues these requests in Pakistan?

In Pakistan, the primary authority expected to issue information requests to Virtual Asset Service Providers (VASPs) seeking a licence is the Pakistan Virtual Assets Regulatory Authority (PVARA). Other bodies like the State Bank of Pakistan, the Securities and Exchange Commission of Pakistan (SECP), and the Federal Board of Revenue (FBR) may also have specific information requirements relevant to their respective domains.

While PVARA is being established as the dedicated regulator for virtual assets, other existing financial regulators retain oversight on aspects of business operations that fall under their purview. For example, the SECP’s role in Pakistan’s virtual asset regulation might involve requests related to corporate governance or company registration, even for a VASP. Similarly, the State Bank of Pakistan’s crypto policy could lead to requests concerning financial flows or foreign exchange implications. The FBR may issue requests related to tax compliance for virtual asset businesses, including queries on declaring crypto holdings to FBR. It is crucial for VASPs to understand which regulator is making the request and the specific legal basis for it.

When might a VASP receive an information request?

A Virtual Asset Service Provider (VASP) can receive an information request at various stages, most commonly during the initial licence application review, but also during ongoing supervision, thematic reviews, or in response to specific incidents. The timing often depends on the complexity of the application or the regulator’s assessment of emerging risks.

During the VASP licensing service application process, requests are frequent as PVARA reviews submitted documents and seeks clarification or additional detail. After licensing, requests may arise as part of routine VASP regulatory reporting calendar obligations, or if the regulator identifies potential non-compliance through monitoring. For example, if a VASP is undergoing a regulatory inspection, information requests will be a key component of that process. They can also be triggered by changes in a VASP’s business model, new product launches, or reports of suspicious activity.

What types of information do regulators typically ask for?

Regulators typically ask for a broad range of information, covering operational, financial, compliance, and governance aspects of a Virtual Asset Service Provider (VASP). These requests aim to build a comprehensive picture of the applicant’s ability to meet regulatory standards and manage associated risks.

Common categories of information requested include:

This list is not exhaustive, and the specifics of any request will depend on the VASP’s business model and the regulator’s particular concerns.

How should a VASP prepare for an information request?

Preparing for an information request involves proactive organisation, establishing clear internal processes, and maintaining comprehensive records. A Virtual Asset Service Provider (VASP) should anticipate potential questions by understanding regulatory expectations and ensuring all relevant documentation is readily accessible and accurate.

Key preparatory steps include:

  1. Maintain Comprehensive Records: Implement robust record-keeping obligations for all business operations, transactions, customer due diligence (CDD) information, and internal policies. This ensures that when a request arrives, the required data can be retrieved efficiently.
  2. Develop Clear Internal Processes: Establish internal protocols for handling information requests, including who is responsible for receiving, reviewing, compiling, and submitting responses. This should involve designated compliance, legal, and operational teams.
  3. Conduct Regular Internal Audits: Periodically review your compliance framework and operational readiness. An audit readiness checklist for Pakistani firms can be invaluable here, helping identify gaps before regulators do.
  4. Stay Updated on Regulatory Developments: Keep abreast of the latest regulatory updates from PVARA and other relevant authorities. Understanding evolving expectations helps anticipate the nature of future requests.
  5. Build a Strong Compliance Team: Ensure your compliance team, including the MLRO, is adequately resourced and trained to understand and address regulatory requirements. Their expertise is critical in interpreting requests and formulating appropriate responses.

What is the process for responding to an information request?

Responding to an information request requires a structured, systematic approach to ensure accuracy, completeness, and timeliness. A well-managed response process minimises potential issues and reinforces the VASP’s commitment to regulatory compliance.

Consider the following steps:

  1. Acknowledge Receipt: Immediately acknowledge the request to the regulator. This confirms receipt and can open a dialogue for clarifying deadlines or scope if needed.
  2. Understand the Scope: Carefully read and analyse the request. Identify exactly what information is being asked for, the format required, and the deadline. If anything is unclear, seek clarification from the regulator promptly.
  3. Designate a Lead and Team: Appoint a single point of contact responsible for coordinating the response. Assemble a cross-functional team (e.g., compliance, legal, IT, operations) to gather the necessary information.
  4. Gather Information: Collect all requested documents, data, and explanations from relevant departments. Ensure the information is accurate, consistent, and directly addresses each point in the request. For example, if the request relates to customer onboarding, ensure your customer due diligence for crypto exchanges documentation is in order.
  5. Review and Verify: Before submission, a senior member of the team, preferably the lead, should thoroughly review the entire response. Check for accuracy, completeness, consistency, and clarity. Ensure that no sensitive or irrelevant information is inadvertently included.
  6. Draft a Cover Letter: Prepare a formal cover letter that summarises the contents of the submission, references the original request, and confirms that all requested information has been provided (or explains any outstanding items).
  7. Submit the Response: Submit the information through the specified channel (e.g., secure online portal, encrypted email, physical delivery) by the deadline. Keep a complete record of the submission for your internal files.

What are the common pitfalls to avoid?

Virtual Asset Service Providers (VASPs) often encounter common pitfalls when responding to information requests, which can lead to delays or negative outcomes. Avoiding these mistakes is crucial for a smooth licensing process and maintaining a good regulatory standing.

Common pitfalls include:

What are the consequences of not responding adequately?

Failing to respond adequately to a regulator’s information request can have serious repercussions for a Virtual Asset Service Provider (VASP), ranging from delays in licence approval to significant enforcement actions. The severity of the consequences typically depends on the nature of the request, the extent of the inadequacy, and the VASP’s history of compliance.

Potential consequences include:

It is imperative for VASPs to treat every information request with the utmost seriousness and ensure a diligent, comprehensive, and timely response. For more information on Pakistan’s proposed virtual asset regulatory framework, you can visit the Pakistan Virtual Assets Regulatory Authority (PVARA).

About this analysis

This analysis has been prepared by Sarzif Policy, an independent research desk, based on publicly available information regarding global best practices in virtual asset regulation and the anticipated framework in Pakistan. While we strive for accuracy and clarity, the virtual asset regulatory landscape in Pakistan is currently at a consultation stage, and specific rules and requirements are subject to change. Operators must verify all specific requirements, thresholds, and deadlines directly with PVARA or other relevant Pakistani authorities. This article is intended for informational purposes only and does not constitute legal, financial, or regulatory advice. For further insights into our approach, please review our editorial policy. For more information about our work, please visit our about us page. If you have specific questions or require assistance, please do not hesitate to contact us.

Noor Aslam, Chief Executive Officer of Sarzif Policy

Noor Aslam

Chief Executive Officer of Sarzif Policy, with eight years in virtual assets — four of them advising on VARA licensing in Dubai. She leads the research team that tracks Pakistan's framework and reviews every consultant shortlist that goes out. More about the team.

This article is information, not legal or financial advice. Regulatory positions change. Confirm any requirement against the official position published by PVARA before you act on it. Spotted an error? Write to sarzifpolicy@gmail.com and we will correct it.

Related updates