2024-12-11
Added · Updated
The Isle of Man Financial Services Authority issued updated guidance for Virtual Asset Service Providers to align with evolving international standards and the October 2024 Travel Rule Code. The document mandates rigorous Anti-Money Laundering and Countering the Financing of Terrorism measures, including specific risk assessments, enhanced due diligence, and compliance with the Travel Rule for virtual asset transfers. It further details sector-specific risks, red flags, and regulatory obligations under the Proceeds of Crime Act 2008 and the Designated Businesses Act 2015.
Get IOMFSA alerts — same-day email on every new publication.
Isle of Man Financial Services Authority
Version 4 Page 1 of 22
Last updated December 2024
Virtual Asset Service Provider Activity
Sector Specific AML/CFT Guidance Notes
December 2024
Whilst this publication has been prepared by the Financial Services Authority, it is not a legal document and should not be relied upon in respect of points of law. Reference for that purpose should be made to the appropriate statutory provisions. Contact:
AML/CFT Division
Financial Services Authority
PO Box 58
Finch Hill House
Bucks Road
Douglas
Isle of Man
IM99 1DT
Tel: 01624 646000
Email: aml@iomfsa.im
Website: www.iomfsa.im
Isle of Man Financial Services Authority
Version 4 Page 2 of 22
Last updated December 2024
Contents
Version history ...........................................................................................................................3
Isle of Man Financial Services Authority
Version 4 Page 3 of 22
Last updated December 2024
Version history
Version 2 (April 2020) Updates made to links in relation to the updated NRA Version 3 (August 2021) Updates to reflect changes to the main structure of the AML/CFT Handbook Updates to footnotes to include links in the main body for consistency purposes. 2 - Addition of further FATF reference papers 3 – Addition of further red flags following the publication of additional FATF reference papers 5 – removal of references to simplified customer risk assessment Version 4 (December 2024) Updates to reflect the change in terminology and definitions. Wording added around the provision of ‘Financial Services’ in relation to the VASP sector. Links have been updated to reflect the most up to date FATF guidance and documentation. Refreshed to better align with evolving international standards.
Isle of Man Financial Services Authority
Version 4 Page 4 of 22
Last updated December 2024
Isle of Man Financial Services Authority
Version 4 Page 5 of 22
Last updated December 2024
Financing of Terrorism (“AML/CFT”) purposes. The sectors subject to the designated business regime can be found in Schedule 1 to the DBROA. Further, the VASP sector is also now subject to the requirements of the Travel Rule Code that came into effect in October 2024 and which mandates certain originator and beneficiary information to be transmitted with a virtual asset transfer. Any person seeking to provide VASP services, in or from the Isle of Man (“the Island”), should obtain relevant independent legal advice to ensure that the proposed activities are subject to the appropriate framework i.e. whether the activity is designated business under the DBROA, or whether the activity may be licensable under other legislation such asthe Financial Services Act 2008 (“the FSA08”).
2. Introduction
The purpose of this document is to provide guidance specifically for the VASP sector in relation to AML/CFT. This document should be read in conjunction with the Code, the main body of the AML/CFT Handbook (“the Handbook”), the Travel Rule Code and the separate Travel Rule Code Guidance document. Though the guidance in the Handbook, and this sector specific guidance, is neither legislation nor constitutes legal advice, it is persuasive in respect of contraventions of AML/CFT legislation dealt with criminally, by way of civil penalty or in respect of the Authority’s considerations of a relevant person’s (as such a term is defined in paragraph 3 of the Code) regulatory / registered status and the fit and proper status of its owners and key staff where appropriate. This document covers unique money laundering and financing of terrorism (“ML/FT”) risks that may be faced by the sector and provides further guidance in respect of approaches to customer due diligence where it may vary across sectors. “financing of terrorism” includes the financing of proliferation and is to be construed in accordance with the definitions of “financing”, “terrorism” and “proliferation” in section 3 of the Terrorism and Other Crime (Financial Restrictions) Act 2014. This document includes references to the following Financial Action Task Force (“FATF”) documents:
FATF reports: Date of issue
Guidance for a risk-based approach – Virtual Assets and Virtual Asset Service Providers October 2021 Second 12-Month review of the revised FATF Standards on Virtual Assets and Virtual Asset Service Providers July 2021
Isle of Man Financial Services Authority
Version 4 Page 6 of 22
Last updated December 2024
Virtual Assets – Red Flag Indicators of Money Laundering and Terrorist Financing September 2020 12-Month review of the revised FATF Standards on Virtual Assets and Virtual Asset Services Providers June 2020 Guidance for a risk-based approach – Virtual Currencies June 2015 Virtual Currencies – Key definitions and potential AML/CFT Risks June 2014 The Authority recommends that relevant persons familiarise themselves with these documents and other typology reports concerning this sector. Also, some case studies are included in this document to provide context to the risks of the sector.
2.1 National Risk Assessment
The Island’s National Risk Assessment (“NRA”) was first published in 2015 and was updated in 2020. VASPs must ensure their business risk assessment (“BRA”) (and customer risk assessments (“CRA”) where necessary) take any relevant findings of the NRA into account. At the time of publication of this document, the NRA is currently undergoing a revision. Further to this, a standalone VASP Sector Risk Assessment will be produced, and relevant persons should ensure that this, along with any other sectoral or topical risk assessment that may be pertinent to VASPs or virtual assets, are considered when reviewing their own policies and procedures including their BRA. The VASP sector is evolving and exhibits its own key risks and vulnerabilities. It is the responsibility of VASPs to keep up to date with developments and any relevant case studies. This sector presents challenges in relation the level of regulatory (and investigatory) expertise in the field and keeping up with how this sector evolves. Services of this type provide a level of anonymity greater than traditional non-cash methods and can present a difficulty in linking an “account” to a real identity. VASPs should carefully consider features, products or services that potentially disguise transactions or hinder CDD and related measures and ensure business relationships are in compliance with the requirements of the Code at all times. A number of control measures have been put in place through the Code, however there are a number of ML and FT risks within the sector (some of which are covered above) that cannot easily be mitigated. Therefore, ML risk for VASPs on the Island is assessed as medium high and the FT risk as medium (as at the 2020 NRA). This will be updated accordingly when both the VASP Sector Risk Assessment and the refresh to the NRA has been completed in 2025.
Isle of Man Financial Services Authority
Version 4 Page 7 of 22
Last updated December 2024
2.2 Terminology
There are a number of terms used when describing concepts within this sector. The following definitions are those used by the FATF (unless otherwise stated):
Virtual Asset Service Provider section 1 of this document provides the Island’s legislative definition of this term. The decision to adopt a new sectoral definition in 2024 was taken to better align our framework with the global standards set by the FATF. Digital currency refers to any electronic representation of a fiat currency and can include representations of virtual currency. Fiat currency a.k.a. “real currency” or “real money” is a national currency that is not pegged to the price of a commodity such as gold or silver. Fiat currency is generally issued by a country’s government or central bank and is designated as legal tender. Non-convertible virtual currency, once purchased, cannot be transferred to another person and cannot be redeemed for fiat currency, either directly or through an exchange. (Note that the definition of VASP included in Schedule 4 to POCA does not extend to non-convertible currency businesses). Virtual Asset refers to a digital representation of value that can be digitally traded or transferred and can be used for payment or investment purposes. Virtual assets do not include digital representations of fiat currencies, securities, and other financial assets.
2.3 Context of the sector
By way of a breakdown of activity on the Island, registered VASPs typically undertake the following types of activity:
Isle of Man Financial Services Authority
Version 4 Page 8 of 22
Last updated December 2024 throughout the ICO (bigger discounts for early take-up and for higher amounts purchased).
3. transfer of virtual assets - allowing customers to transfer ownership or control of
virtual assets to another user, or to transfer virtual assets between virtual asset wallet addresses or accounts held by the same user.
4. safekeeping and/or administration of virtual assets or instruments enabling control
over virtual assets – the term “safekeeping” consists of the service of holding a virtual asset or the private keys to the virtual asset on behalf of another person. The term “administration” could also include the concept of managing virtual assets for, or on behalf of, another person. The term “control” should be understood as the ability to hold, trade, transfer or spend the Virtual Asset. Parties that can use a virtual asset or change its disposition have control of it.
5. participation in and provision of financial services related to an issuer’s offer and /or
sale of a virtual asset - covers persons who participate in, or provide related financial services to, issuer’s offer and/or sale of virtual assets through activities such as ICOs. This could include, for example, businesses accepting purchase orders and accompanying funds, and purchasing virtual assets from an issuer to resell and distribute the funds or assets. Also, possible market making for ICOs and acting as a placement agent for ICOs. Item 5 above refersthe provision of ‘financial services’ related to an issuer’s offer and/or sale of a virtual asset. The term ‘financial services activity’ is defined in the FSA08 and refers to the activity of:
a. deposit taking b. investment business
c. any service to a collective investment scheme
d. corporate services e. trust services f. crowdfunding platforms g. any service or activity involving money transmission h. any other financial service or financial activity of a specified kind that is carried on by a person of a specified description. If the VASP were undertaking any of the activities defined as ‘financial services activity’ in the normal course of their business, then there would be a requirement for the firm to apply to be licensed under the FSA08. The VASP would then be subject to full regulatory oversight and the conditions of the financial services rule book.
Isle of Man Financial Services Authority
Version 4 Page 9 of 22
Last updated December 2024
If a VASP believes they may be undertaking activities that would constitute ‘financial services activity’ then please contact the Authority to arrange a meeting to discuss further.
2.4 Non-Fungible Tokens
Digital assets that are unique, rather than interchangeable, and that are in practice used as collectibles rather than as payment or investment instruments, can be referred to as a nonfungible token (“NFT”). Such assets, depending on their characteristics, are generally not considered to be virtual assets under the definition. It is, however, important to consider the nature of an NFT and its function in practice and not just the terminology or the marketing terms that are used to promote it. Some NFTs, that on the face of it, do not appear to constitute a virtual asset may fall under the virtual asset definition if they are to be used for payment or investment purposes in practice. The characteristics and function of an NFT should be considered on a case-by-case basis when determining whether it is captured within the scope of the virtual asset definition, and therefore subject to the requirements of the legislation.
3. Risk Guidance
The Code mandates that a number of risk assessments are completed:
Isle of Man Financial Services Authority
Version 4 Page 10 of 22
Last updated December 2024 appropriate steps to keep knowledge up to date, given that both the sector and the risks are constantly evolving. Vigilance should govern all aspects of the business’ dealings with its customers, including: -
Isle of Man Financial Services Authority
Version 4 Page 11 of 22
Last updated December 2024
This list of higher risk indicators is by no means exhaustive, and relevant persons should be vigilant for any transactions where suspicion may be aroused and take appropriate measures. Also, please see the list of red flags included at 3.2 of this document. High risk indicators:
Isle of Man Financial Services Authority
Version 4 Page 12 of 22
Last updated December 2024
Isle of Man Financial Services Authority
Version 4 Page 13 of 22
Last updated December 2024
3.3 Risk factors specific to the sector
The following section of the guidance covers some of the risk factors specifically related to the VASP sector. Some of these have been included from this FATF reference paper. Further guidance surrounding the risk assessments is outlined in chapter 2 of the Handbook. This will be updated upon publication of the 2025 NRA.
3.3.1 Technology risk
Due to the nature of the rapidly evolving sector, particular focus should be given to the technology risk assessment (“TRA”). This must assess the risk of ML/FT posed by any technology utilised by the business, such as the use of online delivery channels and communication methods, to its business. A TRA should also be undertaken in respect of any third-party provider used by a VASP or relevant person to meet the requirements of the Travel Rule Code. The BRA must also take the TRA into account.
3.3.2 Anonymity
As stated in paragraph 40 of the Code:
40 Fictitious, anonymous and numbered accounts A relevant person must not set up or maintain an account in a name that it knows, or has reasonable cause to suspect, is fictitious, an anonymous account, or a numbered account for any new or existing customer. The following list, which is not exhaustive, includes some factors to consider in relation to anonymity when undertaking VASP and virtual asset activity:
Isle of Man Financial Services Authority
Version 4 Page 14 of 22
Last updated December 2024
Isle of Man Financial Services Authority
Version 4 Page 15 of 22
Last updated December 2024
Isle of Man Financial Services Authority
Version 4 Page 16 of 22
Last updated December 2024
In all cases where the requirements of Part 4 of the Code cannot be met (Paragraphs 8(5), 9(9), 10(5), 12(11), 14(6), 15(8) and 19(11)) the procedures and controls must provide that - (a) the business relationship must proceed no further; (b) the relevant person must consider terminating2 the business relationship; and (c) the relevant person must consider making an internal disclosure.
5.1 Source of funds
Paragraph 8(3)(e) of the Code requires the taking of reasonable measures to establish the source of funds for all new business relationships. 8 New business relationships (e) taking reasonable measures to establish the source of funds, including where the funds are received from an account not in the name of the customer — (i) understanding and recording the reasons for this; (ii) identifying the account holder and on the basis of materiality and risk of ML/FT taking reasonable measures to verify the identity of the account holder using reliable, independent source documents, data or information; and (iii) if the account holder is assessed as posing a higher risk of ML/FT, satisfying the requirements in paragraph 15. Please also see section 3.8 of the Handbook for further details on source of funds and source of wealth. The Authority considers that this includes any account number or reference (or similar), the name of the remitter (as to identify whether first- or third-party funding) and the geographical source. The source of funds will typically be from the customer themselves or from a third party. Where funds are being paid by a third party, the relevant person must identify and take reasonable measures to verify the identity of this third party where necessary, as per paragraphs 8(3)(e) and 11(3)(e) of the Code. It should also seek to establish the relationship between the customer and the third party and must understand and consider the rationale for the payment and whether this appears reasonable. Where the source of funds is a virtual asset address (or similar numbered remitter), reasonable steps should be taken to determine the source of the virtual asset. Determining 2 In relation to a new business relationship (paragraph 8) the business relationship must be terminated.
Isle of Man Financial Services Authority
Version 4 Page 17 of 22
Last updated December 2024 the source of the funds may take the form of a disclosure from the customer explaining the source of the funds. Should this explanation appear not to make sense based on the known information about the customer, then further investigation must be undertaken to establish the source of the funds as per the requirements of the Code.
5.2 Enhanced due diligence
Paragraph 15 of the Code requires enhanced due diligence to be undertaken in certain circumstances, for example in relation to a higher risk customer and where unusual and / or suspicious activity is identified. Paragraph 15(2) states enhanced due diligence includes:
15 Enhanced due diligence
(a) considering whether additional identification information needs to be obtained and, if so, obtaining such additional information; (b) considering whether additional aspects of the identity of the customer need to be verified by reliable independent source documents, data or information and, if so, taking reasonable measures to obtain such additional verification; (c) taking reasonable measures to establish the source of the wealth of a customer; (d) undertaking further research, where considered necessary, in order to understand the background of a customer and the customer’s business; and (e) considering what additional ongoing monitoring should be carried out in accordance with paragraph 13 and carrying it out. In addition to the above steps required by the Code, enhanced due diligence measures that may mitigate the potentially higher risks associated with this particular sector could include:
Isle of Man Financial Services Authority
Version 4 Page 18 of 22
Last updated December 2024
These solutions can help provide relevant persons engaged in virtual asset transactions with a more informed and risk-based understanding of the history behind a virtual asset, and the identification of ML/FT suspicions connected with a virtual asset transfer. Any new technology would be subject to a TRA in accordance with paragraph 7 of the Code (see section 3.3.1 of this document).
7. Simplified customer due diligence measures
The following section sets out further detail regarding concessions that may be applicable to the sector.
7.1 Exempted occasional transactions
Paragraph 11(5) of the Code provides a concession that the verification of identity is not required for customers carrying out an “exempted occasional transaction”. An exempted occasional transaction is defined in the Code as follows: - 3 Interpretation (1) In this Code - “exempted occasional transaction” means an occasional transaction (whether a single transaction or a series of linked transactions) where the amount of the transaction or, the aggregate in the case of a series of linked transactions, is less in value than — a) €5,000 in relation to an activity being undertaken which is included in Class 8(1) (bureau de change) and Class 8(3) (cheque encashment) of the Regulated Activities Order; b) €1,000 in relation to an activity being undertaken which is included in Class 8(4) (money transmission services apart from cheque encashment) of the Regulated Activities Order and paragraph 2(6)(r) (virtual asset service provider) of Schedule 4 to the Proceeds of Crime Act 2008; or c) €15,000 in any other case; If the conditions are met and this concession is utilised, the verification of the customer’s identity is not required. However, all other Code requirements such as paragraphs 6, 13, 14 and 15 continue to apply. This concession is typically used by VASP entities (where the conditions are met) where a customer: -
Isle of Man Financial Services Authority
Version 4 Page 19 of 22
Last updated December 2024
Isle of Man Financial Services Authority
Version 4 Page 20 of 22
Last updated December 2024 and withdrawals from users, Liberty Reserve evaded collecting information about them through banking transactions or other activity that would create a central paper trail. Once an account was established, a user could conduct transactions with other Liberty Reserve users by transferring LR from his or her account to other users, including front company “merchants” that accepted LR as payment. For an extra “privacy fee” (75 US cents per transaction), users could hide their Liberty Reserve account numbers when transferring funds, making the transfers completely untraceable. After learning it was being investigated by US law enforcement, Liberty Reserve pretended to shut down in Costa Rica but continued to operate through a set of shell companies, moving millions through their accounts in Australia, Cyprus, China, Hong Kong, Morocco, Russia, Spain and elsewhere.
8.2 Silk Road
Launched in January 2011, Silk Road operated as a global black-market cyber bazaar that brokered anonymous criminal transactions and was used by several thousand drug dealers and other unlawful vendors to distribute unlawful goods and services to over a hundred thousand buyers, a third of whom are believed to have been in the United States. It allegedly generated total sales revenue of approximately USD 1.2 billion (more than 9.5 million Bitcoins) and approximately USD 80 million (more than 600 000 Bitcoins) in commissions for Silk Road. Hundreds of millions of dollars were laundered from these illegal transactions (based on Bitcoin value as of dates of seizure). Commissions ranged from 8 to 15 percent of the total sale price. Silk Road achieved anonymity by operating on the hidden Tor (“The onion router”) network and accepting only Bitcoins for payment. Using Bitcoins as the exclusive currency on Silk Road allowed purchasers and sellers to further conceal their identity, since senders and recipients of peer-to-peer (“P2P”) Bitcoin transactions are identified only by the anonymous Bitcoin address/account. Moreover, users can obtain an unlimited number of Bitcoin addresses and use a different one for each transaction, further obscuring the trail of illicit proceeds. Users can also employ additional “anonymisers,” beyond the tumbler service built into Silk Road transactions (see discussion below). Silk Road’s payment system functioned as an internal Bitcoin bank, where every Silk Road user had to hold an account in order to conduct transactions on the site. Every Silk Road user had at least one Silk Road Bitcoin address (and potentially thousands) associated with the user’s Silk Road account, stored on wallets maintained on servers controlled by Silk Road. To make a purchase, a user obtained Bitcoins (typically through a Bitcoin exchanger) and sent them to a Bitcoin address associated with his or her Silk Road account to fund the account. When a purchase was made, Silk Road transferred the user’s Bitcoins to an escrow account it maintained, pending completion of the transaction, and then transferred the user’s / buyer’s Bitcoins from the escrow account to the vendor’s Silk Road Bitcoin address.
Isle of Man Financial Services Authority
Version 4 Page 21 of 22
Last updated December 2024
As a further step, Silk Road employed a “tumbler” for every purchase, which, as the site explained, “sent all payments through a complex, semi-random series of dummy transactions, making it nearly impossible to link your payment with any [bit] coins leaving the site.” [sic] In September 2013, the US Department of Justice shut down the website and arrested the founder. The Justice Department seized approximately 173 991 Bitcoins, worth more than USD 33.6 million at the time of the seizure, from seized computer hardware. In November 2013 Silk Road 2.0 came online, run by former administrators of Silk Road. It was also shut down, and the alleged operator was arrested on 6 November 2014. The founder of Silk Road was convicted of seven charges related to Silk Road in the U.S. Federal Court in Manhattan and was sentenced to life in prison without possibility of parole.
8.3 Western Express International
An eight-year investigation of a multinational, Internet-based cybercrime group, the Western Express Cybercrime Group, resulted in convictions or guilty pleas of 16 of its members for their role in a global identity theft/cyber fraud scheme. Members of the cybercrime group interacted and communicated primarily through Internet “carding” web sites devoted to trafficking in stolen credit card and personal identifying information and used false identities, anonymous instant messenger accounts, anonymous email accounts, and anonymous virtual currency accounts to conceal the existence and purpose of the criminal enterprise; avoid detection by law enforcement and regulatory agencies; and maintain their anonymity. The criminal enterprise was composed of vendors, buyers, cybercrime services providers, and money movers located in numerous countries, ranging from Ukraine and throughout Eastern Europe to the United States. The vendors sold nearly 100 000 stolen credit card numbers and other personal identification information through the Internet, taking payment mostly in eGold and Web Money. The buyers used the stolen identities to forge credit cards and purchase expensive merchandise, which they fenced (including via reshipping schemes), committing additional crimes, such as larceny, criminal possession of stolen property, and fraud, and generating about USD 5 million in credit card fraud proceeds. The cybercrime services providers promoted, facilitated, and aided in the purchase, sale and fraudulent use of stolen credit card numbers and other personal identifying information by providing computer services to the vendors and the buyers. The money mover laundered the cybercrime group’s illicit proceeds in a variety of high-tech ways, moving more than USD 35 million through various accounts. The hub of the entire operation was Western Express International, Inc., a New York corporation based in Manhattan that operated as a virtual currency exchanger and unregistered money transmitter to coordinate and facilitate the Internet payment methods used by the criminal enterprise, and to launder the group’s proceeds. One of the largest
Isle of Man Financial Services Authority
Version 4 Page 22 of 22
Last updated December 2024 virtual currency exchangers in the United States, Western Express International exchanged a total of USD 15 million in Web Money and USD 20 million in e-Gold for the cybercrime group and used banks and traditional money transmitters to move large sums of money. It also provided information and assistance through its websites (including Dengiforum.com and Paycard2000.com) on ways to move money anonymously and to insulate oneself from reporting requirements. Western Express International and its owner/operator, a Ukrainian national, pleaded guilty in February 2013 in New York State to money laundering, fraud, and conspiracy offenses. (In February 2006, Western Express was also indicted for running an illegal check cashing/wire transfer service.) Three other defendants were convicted after trial in June 2013; several more pleaded guilty in August 2009. Two indicted defendants remain fugitives. The investigation was conducted jointly by the US Secret Service and the Manhattan (New York County) District Attorney’s Office and was successfully prosecuted by the Manhattan District Attorney’s Office. There are a number of additional case studies available in this FATF reference paper.
Read the rest free
Source: Isle of Man Financial Services Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works