Virtual Asset Service Providers (VASPs) in Pakistan, like financial institutions globally, often rely on external service providers to handle various operational functions. This can range from IT infrastructure and software development to customer support, compliance checks, and even elements of custody. While outsourcing can offer significant benefits such as cost efficiency, access to specialised expertise, and scalability, it also introduces complex risks.
For a VASP, these risks are amplified by the nascent and evolving nature of virtual asset regulation. Regulators worldwide, including Pakistan’s proposed Pakistan Virtual Assets Regulatory Authority (PVARA), are keenly focused on ensuring that firms maintain control and accountability even when delegating tasks. The principle is clear: a VASP cannot outsource its regulatory obligations.
Understanding and effectively managing these third-party risks is not just good business practice; it is a fundamental requirement for obtaining and maintaining a VASP licence. Failure to adequately oversee outsourced activities can lead to significant operational disruptions, data breaches, financial losses, and severe regulatory penalties, potentially jeopardising a firm’s ability to operate.
What is VASP outsourcing risk?
VASP outsourcing risk refers to the potential for negative consequences arising from a Virtual Asset Service Provider delegating operational functions or services to an external third party. This risk includes issues related to data security, operational resilience, compliance, and the VASP’s ultimate accountability for the outsourced activity.
When a VASP engages a third-party service provider, it essentially extends its own operational and regulatory perimeter. The risks associated with this arrangement are diverse and can impact various aspects of the VASP’s business. For instance, if a VASP outsources its know-your-customer (KYC) processes, it must ensure the third party adheres to the same rigorous customer due diligence (CDD) standards expected by PVARA. A lapse by the third party in verifying customer identities could lead to the VASP inadvertently facilitating illicit activities, resulting in regulatory censure. Similarly, outsourcing critical IT infrastructure components means the VASP must have robust oversight of the third party’s cybersecurity practices. A security breach at the service provider could directly compromise the VASP’s systems and client assets, leading to reputational damage and financial losses. The proposed regulatory framework for virtual assets in Pakistan, influenced by international standards set by the Financial Action Task Force (FATF), emphasises that VASPs remain fully responsible for all outsourced activities. This means the VASP must maintain the capacity to monitor, audit, and, if necessary, terminate the relationship with the service provider while ensuring continuity of services.
Why do regulators focus on outsourcing?
Regulators focus on outsourcing because it can create a gap between a firm’s legal obligations and its practical control over critical functions, potentially undermining financial stability, consumer protection, and anti-money laundering efforts. They aim to ensure accountability and maintain oversight of regulated activities.
The State Bank of Pakistan and the Securities and Exchange Commission of Pakistan (SECP) have long held clear expectations regarding outsourcing for traditional financial institutions and listed companies. These principles are expected to extend to virtual asset firms under the proposed PVARA framework. The core concern is that outsourcing could dilute a VASP’s ability to meet its licence conditions and ongoing obligations. For example, if a VASP outsources its transaction monitoring systems, and the third party’s system fails to flag suspicious activity, the VASP remains responsible for the breach of anti-money laundering (AML) rules. Regulators want to ensure that even when functions are externalised, the VASP retains the expertise and resources to supervise the third party effectively. This includes understanding the third party’s operational capabilities, financial health, and adherence to relevant laws and regulations. The regulator’s ability to supervise the VASP must not be hindered by outsourcing arrangements. This means PVARA will likely expect access to information about outsourced services and the right to inspect third-party providers if necessary.
What types of activities are typically outsourced?
VASPs commonly outsource a range of non-core and specialised functions, including IT infrastructure, software development, customer support, data storage, compliance processes like KYC/AML, and certain aspects of cybersecurity. The specific activities vary depending on the VASP’s business model and scale.
Here are some common examples of outsourced activities for VASPs:
- Information Technology (IT) Services:
- Cloud hosting and infrastructure management.
- Software development and maintenance for trading platforms or wallets.
- Network security and incident response.
- Data backup and disaster recovery.
- For more on general IT requirements, see our analysis on cybersecurity requirements for licensed virtual asset firms.
- Compliance and Regulatory Functions:
- Know-Your-Customer (KYC) and Customer Due Diligence (CDD) checks. Our guide on Crypto KYC & CDD for Pakistan’s VASPs provides further detail.
- Transaction monitoring and sanctions screening.
- AML/CFT (Counter-Financing of Terrorism) software solutions.
- Compliance consulting and auditing.
- Customer Support:
- Helplines, email support, and live chat services.
- Onboarding assistance for new users.
- Back-Office Operations:
- Accounting and payroll.
- Human resources administration.
- Record keeping and data management. Information on VASP record keeping obligations is available.
- Marketing and Public Relations:
- Digital marketing campaigns.
- Social media management.
It is important to note that while these functions can be outsourced, the ultimate responsibility for their proper execution and compliance with regulatory standards always remains with the VASP.
What are a VASP’s responsibilities when outsourcing?
A VASP remains fully accountable for all outsourced activities, meaning it must conduct thorough due diligence on service providers, establish clear contractual agreements, implement robust oversight mechanisms, and ensure business continuity. The VASP cannot transfer its regulatory obligations to a third party.
The proposed PVARA framework is expected to align with international best practices, particularly those outlined by FATF Recommendation 15 on virtual assets and related guidance. This means VASPs looking for VASP licensing services will likely need to demonstrate a comprehensive approach to managing outsourcing risks from the outset. Key responsibilities include:
- Due Diligence: Before engaging any third party, a VASP must conduct extensive due diligence. This involves assessing the service provider’s:
- Financial stability and operational capacity.
- Reputation and track record.
- Expertise in the relevant field.
- Information security and data protection measures.
- Compliance with applicable laws and regulations, including AML/CFT standards.
- Business continuity and disaster recovery plans.
- Contractual Agreements: All outsourcing arrangements must be formalised through legally binding written contracts. These contracts should clearly define:
- The scope of services, service levels, and performance metrics.
- Data ownership, confidentiality, and security requirements.
- Rights of audit and inspection for the VASP and PVARA.
- Termination clauses, exit strategies, and data return/destruction protocols.
- Liability and indemnity provisions.
- Sub-contracting limitations.
- Risk Assessment and Management: VASPs must identify, assess, and mitigate the risks associated with each outsourcing arrangement. This should be an ongoing process, with regular reviews of the risk profile.
- Oversight and Monitoring: Continuous monitoring of the third-party provider’s performance and adherence to contractual terms is crucial. This includes:
- Regular performance reviews.
- Audits of controls and security measures.
- Reviewing incident reports and remediation actions.
- Ensuring the third party complies with data protection laws.
- Business Continuity Planning (BCP): The VASP’s BCP must account for potential disruptions to outsourced services. This means having contingency plans in place, such as identifying alternative providers or bringing services in-house. Our article on VASP Business Continuity Planning offers more insights.
- Reporting to PVARA: VASPs will likely be required to notify PVARA of significant outsourcing arrangements, both at the application stage and on an ongoing basis. This ensures the regulator is aware of critical dependencies.
How should VASPs manage third-party risk?
VASPs should manage third-party risk through a structured framework encompassing initial risk assessment, robust contractual agreements, continuous monitoring, and clear governance structures. This proactive approach ensures that outsourced functions do not compromise the VASP’s regulatory compliance or operational integrity.
An effective third-party risk management framework involves several key components, often integrated into the VASP’s overall enterprise risk management strategy. This framework should be proportionate to the scale and complexity of the VASP’s operations and the criticality of the outsourced functions.
Key Steps for Managing Third-Party Risk:
- Establish a Clear Policy: Develop an internal policy that defines the VASP’s approach to outsourcing, including roles, responsibilities, approval processes, and risk appetite. This policy should be approved by senior management or the board.
- Risk Assessment Matrix: Create a matrix to assess the criticality and inherent risk of each outsourced service. Factors to consider include:
- Impact on Customers: How would a failure affect VASP users?
- Regulatory Impact: Does the service involve sensitive data or regulated activities?
- Operational Impact: How critical is the service to the VASP’s daily operations?
- Data Sensitivity: What type of data will the third party access or process?
- Geographic Location: Where is the service provider located and where will data be processed?
- Selection and Due Diligence:
- Request for Proposal (RFP): Clearly define requirements and expectations.
- Vendor Assessment: Evaluate potential providers based on financial health, security posture, compliance track record, and technical capabilities.
- On-site Visits: Where feasible and necessary, conduct physical inspections.
- Contract Negotiation: Ensure the contract addresses all identified risks and regulatory requirements. This includes service level agreements (SLAs), data protection clauses, audit rights, and clear termination procedures.
- Ongoing Monitoring and Performance Management:
- Regular Meetings: Schedule routine check-ins with the service provider.
- Performance Reviews: Measure performance against agreed SLAs and key performance indicators (KPIs).
- Security Audits: Conduct or commission independent security audits of the third party.
- Incident Reporting: Establish clear protocols for reporting and managing incidents, including data breaches or service outages.
- Exit Strategy: Develop a comprehensive exit plan for each critical outsourced service. This plan should detail how the VASP would transition services to another provider or bring them in-house, ensuring minimal disruption.
- Internal Controls and Governance:
- Dedicated Oversight: Assign specific individuals or teams to manage and monitor third-party relationships.
- Reporting: Ensure regular reporting to senior management and the board on the performance and risks associated with outsourced activities.
- Training: Provide staff with training on managing third-party risks.
By implementing these steps, a VASP can build a robust defence against the potential pitfalls of outsourcing, aligning with the expected regulatory standards for virtual asset firms in Pakistan.
What contractual provisions are important?
Important contractual provisions for VASP outsourcing agreements include clearly defined scope of services, service level agreements, data security and confidentiality clauses, audit and inspection rights, termination rights, and robust liability and indemnity frameworks. These ensure accountability and risk mitigation.
The contract is the cornerstone of any outsourcing relationship, particularly for regulated entities like VASPs. It must reflect the VASP’s ultimate responsibility and PVARA’s expected oversight.
Key Contractual Provisions:
- Scope of Services: Precise definition of services, deliverables, and responsibilities of both parties.
- Service Level Agreements (SLAs): Measurable performance standards, uptime guarantees, response times, and remedies for non-compliance.
- Data Protection and Confidentiality:
- Specific requirements for handling client data, including encryption, access controls, and data residency.
- Compliance with Pakistani data protection laws.
- Provisions for reporting data breaches.
- Security Requirements: Mandated security standards, penetration testing, vulnerability assessments, and incident response procedures. This ties directly into the cybersecurity requirements for licensed virtual asset firms.
- Audit and Inspection Rights: The VASP, and potentially PVARA, must have the right to audit the service provider’s systems, processes, and records relevant to the outsourced services. This includes access to premises and personnel.
- Sub-contracting: Strict controls or outright prohibitions on the service provider sub-contracting services without the VASP’s prior written consent and PVARA’s notification.
- Business Continuity and Disaster Recovery: Requirements for the service provider to maintain robust BCP and DR plans, and to participate in testing.
- Termination Rights and Exit Strategy:
- Clear conditions under which either party can terminate the agreement.
- Detailed plan for the orderly transfer of services, data, and assets back to the VASP or to a new provider.
- Obligations for data return or secure destruction upon termination.
- Liability and Indemnity: Allocation of responsibility for losses, damages, or regulatory fines arising from the service provider’s actions or omissions.
- Regulatory Compliance: Obligation for the service provider to comply with all relevant laws and regulations, including AML/CFT, and to assist the VASP in meeting its regulatory obligations.
- Governing Law and Dispute Resolution: Specification of Pakistani law as the governing law and agreed mechanisms for resolving disputes.
What are the reporting requirements for outsourcing?
VASPs are likely to have reporting requirements to PVARA regarding their outsourcing arrangements, particularly for critical functions. This may involve initial notification during the licensing process, ongoing updates for new or changed arrangements, and regular reporting on the performance and risk management of third parties.
The exact reporting requirements will be detailed in PVARA’s final regulations. However, based on international standards and the practices of other Pakistani financial regulators, VASPs should anticipate the following:
- Initial Licence Application: When applying for a VASP licence, firms will likely need to disclose all material outsourcing arrangements. This demonstrates to PVARA that the VASP has considered and mitigated associated risks from the outset. This disclosure would include details of the service provider, the nature of the outsourced service, and the VASP’s risk management framework for that arrangement.
- Notification of New or Changed Arrangements: VASPs may be required to notify PVARA prior to entering into new material outsourcing contracts or making significant changes to existing ones. This allows the regulator to assess the potential impact on the VASP’s risk profile and its ability to comply with regulatory requirements.
- Regular Reporting: As part of ongoing regulatory reporting, VASPs might need to submit periodic reports on their outsourcing activities. This could include:
- Summaries of key outsourced functions.
- Performance metrics of critical service providers.
- Details of any significant incidents or breaches involving third parties.
- Updates on risk assessments and mitigation measures.
- Information on the VASP Regulatory Reporting Calendar in Pakistan: A Guide for Operators can be found in our blog.
- Ad-hoc Reporting: In the event of a material incident, such as a major service disruption or a data breach at a third-party provider, VASPs will likely be required to report this to PVARA immediately. This is consistent with the broader licence conditions and ongoing obligations expected of licensed entities.
The regulator’s aim is to maintain transparency and ensure that PVARA has a complete picture of a VASP’s operational dependencies and associated risks. For further information on PVARA and its role, you can visit https://pvara.org.
What happens if an outsourced service fails?
If an outsourced service fails, the VASP remains fully responsible for the consequences, which can include operational disruption, financial losses, reputational damage, and regulatory enforcement actions from PVARA. The VASP must have robust business continuity plans and an exit strategy to mitigate such failures.
The principle of “you can outsource the activity, but not the responsibility” is paramount. A failure by a third-party provider is treated as a failure by the VASP itself. The potential repercussions are significant:
- Operational Disruption: A failure in outsourced IT, customer support, or compliance systems can bring the VASP’s operations to a halt, preventing clients from accessing services or trading virtual assets.
- Financial Losses: This can stem from direct service disruption, compensation to affected clients, costs of remediation, and potential regulatory fines.
- Reputational Damage: Loss of customer trust and public confidence can be severe and long-lasting, impacting the VASP’s ability to attract and retain users.
- Regulatory Enforcement: PVARA has a range of enforcement powers it can exercise if a VASP fails to meet its obligations due to an outsourced service failure. These can include:
- Warnings and Directions: Formal warnings or specific instructions to rectify issues.
- Fines: Monetary penalties for non-compliance.
- Restrictions on Operations: Limiting the scope of the VASP’s activities.
- Licence Suspension or Revocation: In severe cases, the VASP’s licence could be suspended or revoked, effectively ending its ability to operate in Pakistan.
- Data Breach: If an outsourced data storage or processing service fails, leading to a data breach, the VASP is responsible for notifying affected individuals and PVARA, and for managing the fallout.
- AML/CFT Breaches: A failure in outsourced KYC/CDD or transaction monitoring could lead to the VASP being implicated in money laundering or terrorist financing activities, resulting in severe legal and regulatory consequences.
To mitigate these outcomes, VASPs must ensure their business continuity plans specifically address third-party failures, including clear communication protocols, alternative service arrangements, and a well-defined exit strategy for critical outsourced functions.
About this analysis
This analysis has been prepared by Sarzif Policy, an independent research desk in Islamabad, based on our understanding of emerging virtual asset regulatory frameworks globally and the specific proposals and discussions within Pakistan. Our insights are drawn from public statements, consultation papers, and guidance from bodies such as PVARA, the State Bank of Pakistan, SECP, FBR, and FATF. We also consider the evolving landscape of Pakistani courts and virtual assets.
It is crucial for operators to verify specific requirements with PVARA once final regulations are issued, as the framework for virtual assets in Pakistan is still under development. This article provides general information and does not constitute legal or regulatory advice. For specific guidance, firms should consult with qualified legal and compliance professionals. You can learn more about Sarzif Policy on our about page or review our editorial policy. For further regulatory updates, please visit our blog.