
A practical guide for financial institutions
Most financial institutions have stopped asking whether to work with virtual asset service providers. Banks custody cryptoassets, stablecoins are moving onto mainstream payment rails and asset managers hold digital assets on behalf of their clients.
So the question is no longer whether to work with VASPs, but how to do it well.
What changes is not the principle but the information environment. Much of a VASP's activity sits on a public ledger, so once that information is available, doing nothing with it is harder to explain to a supervisor.
This practical guide draws on more than a decade of experience working with financial institutions and regulators. It walks through VASP onboarding in practice: getting your institution ready, the two layers of due diligence, how to read what the analytics actually tell you, and how to monitor a relationship whose risk profile can shift in days.
In this guide, you'll get:
- A readiness checklist covering risk appetite, governance, escalation paths and team fluency
- The two layers of due diligence, including the GDF VADDQ and the areas that deserve most attention
- How to read on-chain exposure, and why inflow and outflow exposure tell you different things about a counterparty's controls
- Reassessment cadences by risk level, plus the events that should trigger a review regardless of the calendar
You will finish with a framework you can document, apply consistently and explain to a supervisor: how to assess a VASP before you onboard it, and how to keep that assessment current once the relationship is live.

