Operating a Virtual Asset Service Provider (VASP) in Pakistan involves navigating a complex regulatory landscape, especially concerning Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) obligations. Transfers involving unhosted wallets represent a significant area of focus for regulators globally, and Pakistan is no exception. Understanding the proposed compliance expectations for these transactions is critical for maintaining operational integrity and avoiding potential enforcement actions.

The inherent pseudonymity and decentralised nature of unhosted wallets pose unique challenges for financial crime prevention. As Pakistan continues to develop its virtual asset regulatory framework, influenced by international standards set by the Financial Action Task Force (FATF), VASPs must prepare for robust requirements designed to mitigate these risks. Proactive engagement with these evolving standards will be essential for any firm seeking to operate legitimately within the country.

Ignoring or underestimating the compliance burden associated with unhosted wallet transfers could expose a VASP to substantial regulatory scrutiny, including penalties and reputational damage. This analysis aims to clarify the proposed compliance treatment for such transfers under Pakistan’s developing virtual asset regulations, helping operators build resilient AML programmes.

What are unhosted wallets?

Unhosted wallets, also known as self-custodial or non-custodial wallets, are software or hardware applications that allow individuals to directly control their virtual assets without relying on a third-party service provider to hold the private keys. These wallets give users full autonomy over their funds.

Unlike hosted wallets, which are managed by a VASP (such as an exchange or custodian) that holds the private keys on behalf of its clients, unhosted wallets place the responsibility for security and key management entirely on the user. This distinction is crucial for regulatory purposes because transactions involving unhosted wallets lack a regulated intermediary on at least one side of the transfer, making it harder to trace the ultimate beneficial owner. The Pakistan Virtual Assets Regulatory Authority (PVARA), the designated regulator for virtual assets, is expected to focus on this distinction in its compliance guidelines. For more on the role of PVARA, see our guide on what is PVARA? A plain-English guide to Pakistan’s virtual asset regulator.

Why are unhosted wallets a compliance challenge?

Unhosted wallets present a compliance challenge primarily due to the difficulty in identifying the ultimate beneficial owner of the funds, which increases the risk of money laundering and terrorism financing. Without a regulated entity on both sides of a transaction, it becomes harder for VASPs to collect and verify sender or receiver information.

This lack of transparency conflicts directly with the core principles of AML/CFT, which require financial institutions to know their customers and monitor transactions for suspicious activity. The FATF has highlighted unhosted wallets as a key risk area, urging member jurisdictions, including Pakistan, to implement measures that address these vulnerabilities. The State Bank of Pakistan and the Securities and Exchange Commission of Pakistan (SECP) have also expressed concerns regarding illicit finance risks associated with virtual assets.

What are the proposed rules for unhosted wallet transfers in Pakistan?

The proposed rules for unhosted wallet transfers in Pakistan are expected to align with FATF Recommendation 15, specifically the “Travel Rule,” requiring VASPs to collect and transmit originator and beneficiary information for certain transactions. PVARA’s framework is likely to mandate that licensed VASPs implement processes to identify and verify the identity of the unhosted wallet owner.

This means that when a VASP’s customer sends virtual assets to or receives them from an unhosted wallet, the VASP will need to undertake specific due diligence. The goal is to ensure that even when one side of the transaction is outside the regulated perimeter, the VASP still performs its AML/CFT duties. For a deeper dive into the Travel Rule, refer to our article on understanding the Travel Rule for Pakistani Virtual Asset Businesses.

How should VASPs manage unhosted wallet risks?

VASPs should manage unhosted wallet risks by implementing a robust, risk-based approach that includes enhanced due diligence, transaction monitoring, and appropriate controls based on the assessed risk level of each transaction. This involves assessing factors such as transaction size, frequency, and the jurisdictions involved.

A comprehensive VASP Risk Assessment: Building an AML Methodology for Pakistan is crucial. Firms must develop internal policies and procedures tailored to these risks, ensuring staff are trained to identify red flags associated with unhosted wallet transfers. This proactive stance helps mitigate potential exposure to illicit activities and demonstrates commitment to regulatory compliance.

What information must VASPs collect for unhosted wallet transfers?

For unhosted wallet transfers, VASPs are expected to collect information about both the originator and beneficiary, even if one party uses an unhosted wallet, subject to established thresholds. This typically includes the name of the unhosted wallet owner, their physical address, and the wallet address itself.

While the exact thresholds and required data points will be specified in PVARA’s final regulations, the general principle is to gather sufficient information to identify the parties involved and assess the transaction’s risk. If the unhosted wallet belongs to the VASP’s own verified customer, the process may be streamlined. However, if it belongs to an unverified third party, more stringent checks will be necessary. This aligns with broader customer due diligence for crypto exchanges: a practical walkthrough requirements.

What happens if a VASP cannot collect required information?

If a VASP cannot collect the required information for an unhosted wallet transfer, it is generally expected to reject, block, or suspend the transaction and consider filing a suspicious transaction report (STR). This obligation arises when the VASP cannot adequately identify the unhosted wallet owner or verify their identity.

The inability to obtain necessary data elevates the transaction’s risk profile significantly. In such cases, the VASP’s compliance officer, often the Money Laundering Reporting Officer (MLRO), must assess whether the circumstances warrant reporting to Pakistan’s financial intelligence unit. Our article on what is a suspicious transaction report and when must a VASP file one provides further guidance.

What about transfers to/from foreign unhosted wallets?

Transfers involving foreign unhosted wallets introduce additional complexities due to varying international regulatory standards and jurisdictional risks. VASPs in Pakistan must apply the same diligence requirements, potentially with enhanced scrutiny, to these cross-border transactions.

The VASP should consider the AML/CFT regime of the foreign jurisdiction, if identifiable, and the overall risk associated with that region. Where the foreign jurisdiction has weak AML/CFT controls or is subject to FATF monitoring, the VASP should apply a higher level of scrutiny. This is part of a broader strategy for managing global virtual asset risks, and firms should consult the PVARA’s guidance for specific requirements related to international transfers.

How can technology assist with unhosted wallet compliance?

Technology plays a crucial role in assisting VASPs with unhosted wallet compliance by providing tools for blockchain analytics, transaction monitoring, and identity verification. These solutions can help automate data collection, risk scoring, and the identification of suspicious patterns.

Implementing these technologies can significantly enhance a VASP’s ability to meet its compliance obligations, particularly for the high volume of transactions characteristic of virtual asset operations.

How will PVARA supervise unhosted wallet compliance?

PVARA will supervise unhosted wallet compliance through a combination of regular reporting requirements, on-site inspections, and enforcement actions for non-compliance. They will expect VASPs to demonstrate robust internal controls and a clear audit trail for all unhosted wallet transfers.

During inspections, PVARA will assess the adequacy of a VASP’s policies, procedures, and systems for managing unhosted wallet risks. They will also review transaction records and the effectiveness of the VASP’s AML/CFT programme. Failure to meet these expectations can lead to penalties, including fines, licence suspension, or revocation, highlighting the cost of non-compliance: penalties across jurisdictions. For information on preparing for regulatory oversight, read our guide on crypto regulator inspections in Pakistan: what to expect and how to prepare.

Key Compliance Steps for VASPs

To effectively manage unhosted wallet transfers, VASPs should consider the following key steps, which are likely to be central to PVARA’s expectations:

  1. Develop Clear Policies and Procedures:
    • Establish specific guidelines for identifying, assessing, and mitigating risks associated with unhosted wallet transfers.
    • Define internal thresholds for enhanced due diligence (EDD) on unhosted wallet transactions, potentially lower than for hosted wallet transfers.
    • Outline procedures for verifying the ownership or control of an unhosted wallet, such as requiring screenshots, signed messages, or micro-deposit verification.
  2. Implement Enhanced Due Diligence (EDD):
    • For high-value or high-risk unhosted wallet transfers, conduct EDD on the counterparty, even if they are not a direct customer. This might involve collecting additional information or scrutinising the source of funds.
    • Screen unhosted wallet addresses against sanctions lists and watchlists.
  3. Strengthen Transaction Monitoring:
    • Configure transaction monitoring systems to specifically flag unusual patterns or high-risk indicators related to unhosted wallet interactions.
    • Pay attention to rapid transfers to/from multiple unhosted wallets, or transfers involving privacy-enhancing virtual assets.
  4. Maintain Comprehensive Record-Keeping:
    • Document all efforts to collect and verify information related to unhosted wallet transfers, including any challenges encountered.
    • Retain records for the period specified by PVARA, which is typically five years from the date of the transaction or the end of the business relationship. This is crucial for demonstrating compliance during audits, as discussed in our article on VASP record keeping in Pakistan: what to retain and for how long.
  5. Staff Training:
    • Regularly train compliance teams and relevant operational staff on the specific risks and compliance requirements for unhosted wallet transfers.
    • Ensure they understand how to identify red flags and when to escalate concerns to the MLRO.
  6. Leverage Technology:
    • Invest in and effectively utilise blockchain analytics and transaction monitoring tools to enhance visibility and risk assessment capabilities for unhosted wallet interactions.
    • Explore solutions that can help automate the collection and verification of necessary data points.
  7. Engage with PVARA:
    • Stay informed about PVARA’s evolving guidance and actively participate in consultations regarding virtual asset regulations. The official PVARA website (https://pvara.org) is a primary source for updates.
    • Seek clarity from the regulator when specific situations regarding unhosted wallets are not explicitly covered by existing or proposed rules.

By proactively addressing these areas, VASPs can build a robust compliance framework that effectively manages the unique risks posed by unhosted wallet transfers within Pakistan’s developing regulatory environment. Firms looking to secure a licence will find that a strong approach to these challenges is a key requirement for VASP licensing service.

About this analysis

This analysis has been prepared by Sarzif Policy based on publicly available information, including international standards set by the FATF and the anticipated direction of virtual asset regulation in Pakistan as indicated by bodies such as PVARA, the State Bank of Pakistan, and the SECP. It reflects our understanding of the proposed framework, which is currently in development and subject to change. Specific requirements, thresholds, and timelines will be formally issued by PVARA. Operators must verify all current obligations and figures directly with PVARA or other relevant Pakistani authorities. This article is intended for informational purposes only and does not constitute legal, financial, or regulatory advice.

Noor Aslam, Chief Executive Officer of Sarzif Policy

Noor Aslam

Chief Executive Officer of Sarzif Policy, with eight years in virtual assets — four of them advising on VARA licensing in Dubai. She leads the research team that tracks Pakistan's framework and reviews every consultant shortlist that goes out. More about the team.

This article is information, not legal or financial advice. Regulatory positions change. Confirm any requirement against the official position published by PVARA before you act on it. Spotted an error? Write to sarzifpolicy@gmail.com and we will correct it.

Related updates