
Financial institutions (FIs) assess a new counterparty by asking it questions. The due diligence questionnaire is a self-report instrument, and for most counterparties there is no alternative to it. A bank cannot independently observe how another institution actually handles the flows it describes, so it verifies what it can through adverse media, sanctions screening and public filings, and takes the rest on the counterparty's word.
A virtual asset service provider (VASP) is the exception. Much of its activity sits on a public ledger. Where that activity can be attributed to the entity, a bank can check the applicant's account of itself against what it actually did: not just whether the controls it described are the controls it operates, but also whether its risk profile looks the way it said it does.
This changes what a supervisor will accept, because once the on-chain information is available, choosing not to look at it becomes harder to explain.
Elliptic's new How to onboard a VASP guide sets out how to build an onboarding framework that uses both layers of a VASP assessment, and how to keep it current once the relationship is live.
Why should banks onboard VASPs?
The operational argument for banking VASPs is straightforward: They are companies that need services only licensed banks can provide, including holding client monies and fiat reserves backing stablecoin issuance, operating accounts and settlement rails.
But there's also a strategic argument for financial institutions to work with VASPs. VASPs have been historically underserved. Now that digital assets are increasingly intertwined with traditional finance, learning how to bank them well can create a significant first-mover advantage.
Additionally, the risk infrastructure and operational knowledge required to carry out effective VASP due diligence is largely the same as what FIs must put in place if they wanted to venture into digital assets themselves.
Even for those that haven't made an active decision to enter the space, it is valuable to have the right risk infrastructure in place, as many FIs already have some exposure to digital assets.
A framework for effective crypto counterparty risk management
Before an FI onboards a VASP, it needs to be clear on the following questions:
- Which types of VASPs is the institution willing (and not willing) to bank?
- How are onboarding and escalation decisions made? Which cases can a relationship manager handle, which ones require financial-crime review and which ones need senior-management sign-off?
- Does everyone who will be involved in VASP due diligence have a working knowledge of digital assets? Are they able to interpret on-chain data in context?
Once that has been established, Elliptic recommends a two-pronged approach:
- A due diligence questionnaire as the first layer
- Blockchain analytics as the second layer
The first layer of VASP due diligence: the questionnaire
The Global Digital Finance Virtual Asset Due Diligence Questionnaire, which is built on the Wolfsberg Group's global standard Correspondent Banking Due Diligence Questionnaire, is considered a good due diligence questionnaire for VASPs.
This said, with 14 sections, it is long and thorough. Depending on an FI’s risk appetite, a risk-based approach, where the full version is sent to high-risk applicants and an abridged version sent to lower-risk ones, could be the solution that works best for both parties.
The second layer of VASP due diligence: blockchain analytics
By evaluating a VASP’s on-chain activity, blockchain analytics solutions contextualize and corroborate (or challenge) the information a VASP provides in the due diligence questionnaire. This works on two levels:
Wallet and transaction screening takes a single address or flow, such as one a VASP has disclosed as its own, and checks it against the risk categories like sanctioned addresses, darknet markets, ransomware wallets, mixers, confirmed exploits and scams. It tells you what risk attaches to a specific address or transfer.
Entity-level assessment takes the business as a whole. A solution like Elliptic Discovery combines a VASP’s on-chain information with off-chain information such as licensing, jurisdiction and ownership into a single risk score. Discovery tells you where the bulk of inflows originate, where outflows go, what proportion of activity touches illicit categories and how those proportions move over time.
Entity-level assessment is what you lean on for the onboarding decision, because it characterizes the counterparty as a business. Screening is what you rely on where attribution is thin, which is usually the institutional-only case, and it is also the operation that runs continuously once the relationship is live.
What's in Elliptic's How to onboard a VASP guide?
Elliptic's guide tackles every aspect of VASP due diligence in more detail, including:
- What qualifies as a VASP
- How banks should determine their risk appetite and approach to governance
- How to combine the two VASP onboarding layers effectively
- How to interpret on-chain risk indicators
Regulators in the US, EU and other major jurisdictions increasingly expect banks to have effective crypto counterparty risk management processes in place. Whether you already have several VASP clients and must show regulators how those relationships are managed, or want to capitalize on the opportunities that come with digital assets, our guide shows you how to build a robust VASP onboarding framework.

