2026-08-21
Added
The Pakistan Virtual Asset Services Activity Specific Regulations, 2026, establish general requirements for all Virtual Asset Service Providers (VASPs) licensed under the Virtual Assets Act, 2026. These regulations mandate prudent exposure limits for margin, leveraged, derivative, lending, or borrowing products and prohibit the use of client assets without prior explicit written consent. Licensees must also implement documented staff competency frameworks, adhere to specific outsourcing conditions, and ensure operational resilience with prompt reporting of material incidents. Furthermore, the regulations introduce specific rules for Advisory Services, requiring licensees to provide recommendations in clients' best interests and conduct suitability assessments based on client knowledge, investment objectives, and financial circumstances.
Page 1 of 101 The Gazette of Pakistan Extraordinary PART II Notification PAKISTAN VIRTUAL ASSET REGULATORY AUTHORITY NOTIFICATION Islamabad, August 21, 2026 S.R.O. 1420(I)/2026. In exercise of the powers conferred by section 68 of the Virtual Assets Act, 2026, the Pakistan Virtual Asset Regulatory Authority is pleased to make public the following Pakistan Virtual Asset Services Activity Specific Regulations, 2026 for licensing and regulation of VASPs carrying out one or more Virtual Asset Services as stated by Schedule 1 of the Virtual Assets Act, 2026 and any other service as may be notified by the Federal Government and subsequently included in Schedule I in accordance with section 18 of the Act: GENERAL REGULATIONS [APPLICABLE ON ALL VIRTUAL ASSET SERVICE PROVIDERS (VASPs)]
Page 2 of 101 counterparty limits proportionate to the nature, scale, complexity and risk profile of those products or services. The limits shall be reasonably designed to manage risks to Customers and the Licensee and to prevent material risks to market integrity or financial stability. 2. Licence perimeter. — (1) A Licensee shall not rely on a Licence Category to carry on any activity that falls within another Licence Category, except where such activity is expressly permitted/licensed in accordance with the Virtual Assets Act, 2026 and the Regulations and any binding direction or other instrument issued by the Authority under express authority conferred by the Act. Any binding direction or other instrument shall identify its statutory basis, binding status and effective date. Guidance may explain the Authority’s supervisory expectations but shall not create a generally applicable mandatory obligation unless issued under express authority conferred by the Act. (2) A Licensee shall not structure or operate its business in a manner that circumvents the requirements applicable to any other Licence Category under the Act or the Regulations. (3) Where a product or service combines features falling within more than one Licence Category, the Licensee shall obtain license of that specific activity. (4) A broader reference to Schedule 1 of the Act shall be applied when determining the scope of regulated activities. (5) A Licence Category authorizes a Licensee to carry on an activity that is reasonably necessary or ancillary to an authorised Virtual Asset Service, provided that the activity. (a) is subordinate to the authorised Virtual Asset Service (b) is not separately marketed, offered or remunerated as a standalone service (c) does not constitute a material independent business line or materially alter the Licensee’s risk profile; and (d) is conducted in accordance with the safeguarding, conduct, AML/CFT/CPF and other regulatory requirements relevant to the risks arising from that activity A Licensee shall identify and describe any activity that it proposes to conduct in reliance on this provision in its Licence application or, where the activity is proposed after the grant of the Licence, in an application to vary the scope of its approved activities. The Licensee shall obtain the Authority’s written approval before undertaking the activity. The Authority may approve an activity individually or by reference to a defined class or description of incidental activities and shall document the approval and any applicable conditions as part of the Licensee’s regulatory record. Such approval shall not, by itself, require the Licensee to obtain an additional Licence Category. The Authority may require an additional Licence Category where the scale, frequency, risk or commercial significance of the activity causes it to constitute a substantive Virtual Asset Service in its own right. 3. Multi-activity obligations. — (1) A Licensee holding more than one License Category shall comply with each applicable Activity-Specific Regulation and with the general requirements in respect of all activities carried on.
Page 3 of 101 (2) All activities carried on under these Regulation shall be subject to the Client protection outcomes applicable to that activity, applied proportionately to its nature, scale and purpose, and shall not be structured or operated so as to circumvent applicable requirements. (3) A Licensee shall not use, lend, pledge, rehypothecate, stake, encumber or otherwise dispose of Client Assets solely by virtue of its Licence. Any such use shall only be undertaken with the Client’s prior written explicit and informed consent and the Licensee shall clearly disclose the nature of the activity, the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated. (4) A Licensee carrying on multiple activities shall maintain effective controls to distinguish those activities and to manage conflicts, disclosures and conduct obligations appropriately. 4. Staff competency framework. — (1) A Licensee shall ensure that every person involved in the provision, supervision, approval, control, oversight or review of any Virtual Asset service is competent, suitably trained and appropriately supervised, having regard to the nature of the service provided and the risks of the products and activities concerned. (2) A Licensee shall maintain a documented competency framework covering at least (a) minimum knowledge and skills requirements for relevant roles; (b) initial and ongoing training, including training on market conduct, conflicts of interest, AML/CFT/CPF obligations, technology and operational risks; (c) assessment and periodic reassessment of competence; and (d) escalation, restriction and remediation procedures where competency concerns arise. (3) A person shall not perform a role relevant to a Virtual Asset service unless the Licensee is satisfied that the person is competent to do so and is subject to appropriate supervision and conduct controls. (4) A Licensee shall ensure that remuneration, incentives, targets and performance management structures do not create an undue incentive to act in a manner inconsistent with the best interests of Clients or with the Licensee’s obligations under the Act, the Regulations and any binding direction or other instrument issued by the Authority under express authority conferred by the Act. Any binding direction or other instrument shall identify its statutory basis, binding status and effective date. Guidance may explain the Authority’s supervisory expectations but shall not create a generally applicable mandatory obligation unless issued under express authority conferred by the Act. 5. Outsourcing obligations. — (1) A Licensee shall not outsource the principal activity for which it is licensed and ensure that any outsourcing or third-party arrangement relating to its licensed activities complies with the outsourcing, governance, technology, cybersecurity and operational resilience requirements under the Regulations and any applicable guidance issued by the Authority.
Page 4 of 101 (2) A Licensee may outsource any function, including a material function and on a cross-border or intra-group basis, other than core/principal activity, provided that the arrangement does not materially impair, (a) the Licensee’s ability to comply with its legal and regulatory obligations (b) the effectiveness of its governance, risk management and internal controls (c) the Authority’s ability to supervise the Licensee or obtain timely access to relevant information, systems, premises and personnel (d) the continuity and security of the relevant Virtual Asset Service The Licensee shall remain fully responsible and accountable for all outsourced functions and shall conduct appropriate due diligence, maintain written outsourcing arrangements, oversee service-provider performance and maintain appropriate business-continuity and exit arrangements. Material outsourcing arrangements shall be subject to any applicable notification or prior-approval requirements prescribed by the Authority. (3) Principal Licensed Activity means the provision by a Licensee, in its capacity as the contracting and regulated service provider, of a Virtual Asset Service specified in its Licence, together with the assumption of the corresponding legal and regulatory responsibility towards Customers and the Authority. A Principal Licensed Activity does not include each individual operational, technological, administrative, control or supporting function used in the delivery of that Virtual Asset Service, including where the function is necessary, recurring or material to its delivery, provided that the Licensee retains effective direction and control, remains fully responsible and accountable, and complies with the applicable outsourcing requirements. Where a Licensee requires clarification as to whether a proposed outsourcing arrangement involves the Principal Licensed Activity, it may seek written clarification from the Authority before entering into or implementing the arrangement. The request shall describe the function, the proposed service provider, the allocation of responsibilities and the arrangements through which the Licensee will retain effective direction, control and regulatory accountability. (4) A Licensee shall remain fully responsible for compliance with the Act, the Regulations and any binding direction or other instrument issued by the Authority under express authority conferred by the Act. Any binding direction or other instrument shall identify its statutory basis, binding status and effective date in respect of any function, process or service outsourced to a third party, regardless of the terms of the outsourcing arrangement. Guidance may explain the Authority’s supervisory expectations but shall not create a generally applicable mandatory obligation unless issued under express authority conferred by the Act. (5) Where a third party provides material components of a licensed service, including Client interfaces, suitability tools, profiling tools, technology infrastructure, algorithmic tools, risk management systems, custody infrastructure, AML/CFT systems or other components that are material to the Licensee’s regulated activities, the Licensee shall: (a) assess the materiality of the outsourcing arrangement in accordance with criteria specified by the Authority; (b) conduct appropriate due diligence before entry into the arrangement and on an ongoing basis;
Page 5 of 101 (c) ensure that the arrangement includes appropriate rights of access, audit, oversight, information, step-in and termination; and (d) notify the Authority of material outsourcing arrangements in accordance with the Regulations. (6) A Licensee shall maintain and keep current a register of material outsourcing and thirdparty arrangements, including details of the function outsourced, the service provider, and the risk assessment conducted. 6. Operational resilience. — (1) A Licensee shall ensure that its systems, controls and infrastructure meet operational resilience, availability and recovery standards proportionate to the criticality of the services provided. (2) A Licensee shall maintain contingency procedures for material outages, technology incidents, chain disruption, banking rail disruption, counterparty failure, routing failures, wallet disruption, chain reorganization, chain congestion, stale status information and other events that could materially affect the provision of services to Clients. (3) A Licensee shall maintain business continuity, backup and disaster recovery arrangements sufficient to support the continuity of critical functions, consistent with the requirements of the Regulations. (4) Material incidents that affect the provision of licensed services shall be communicated to affected Clients and to the Authority without undue delay where the incident is material, in accordance with the incident reporting requirements under the Regulations. (5) A Licensee shall disclose material operational, technology, network, settlement, third-party and Virtual Asset infrastructure risks relevant to the services provided, including risks relating to congestion, chain reorganizations, finality, forks, validator dependencies, bridge risks, smart contract vulnerabilities and third-party service providers where applicable. 7. Reporting to the Authority. — (1) A Licensee shall notify the Authority without undue delay of any material failure, deficiency, control breach, misconduct or other event that is required to be notified under the Act, the Regulations or any applicable Regulation. (2) The Authority may require a Licensee to provide such information, reports, management attestations, remediation plans, file reviews or thematic data as it reasonably considers necessary for supervisory purposes. (3) A Licensee shall maintain records sufficient to demonstrate compliance with the Regulations and all applicable Activity-Specific Regulations, and shall make such records available to the Authority upon request. (4) Records required to be maintained under any Activity-Specific Regulation shall be retained for at least seven (7) years, or such longer period as may be required under the Act, the Regulations, AML/CFT/CPF requirements, or any written direction of the Authority. (5) A Licensee shall notify the Authority without undue delay of any material failure, deficiency, control breach or misconduct affecting the provision of the licensed activity,
Page 6 of 101 including any material suitability failure, systemic mis-selling issue, major model or algorithm defect, or material conflict of interest issue. (6) A Licensee shall document materiality assessments concerning matters potentially notifiable under the Act or these Regulations and shall make them available to the Authority upon reasonable request. The annual return shall include only matters determined to be Material, the corresponding notification and any material remediation status. Preliminary assessments of matters determined not to be Material need not be submitted routinely. (7) The Authority may require the Licensee to provide such information, reports, management attestations, remediation plans, file reviews or thematic data as it reasonably considers necessary for supervisory purposes. 8. Breach and enforcement. — (1) A breach of these Regulations shall constitute a breach of the Licensee’s obligations and shall be taken into account for licensing, conduct, prudential and supervisory purposes. (2) Nothing in this Regulation limits the application of any other provision of the Act or the Regulations, including provisions relating to Client categorization, market conduct, disclosures, complaints handling, AML/CFT/CPF, governance, technology, operational resilience, safeguarding, reporting or enforcement. (3) The Authority may exercise any power available to it under the Act and the Regulations in relation to a breach, including the power to impose conditions, require remediation, issue directions, restrict activities, impose penalties, or suspend or revoke a licence, as applicable. (4) The Authority may, on application or on its own initiative, modify or waive the application of a provision of this Regulation in whole or in part in respect of a specified Licensee, class of Licensee, product, service, Client category or business model, where the Authority is satisfied that the underlying regulatory objectives remain adequately met. (5) The Authority may, by written order recording its reasons, suspend or cancel a licence in accordance with section 23 of the Act, where it is satisfied that such action is necessary in the public interest.
Page 7 of 101 Advisory Services Regulations
Page 8 of 101 (4) A Licensee shall ensure that Advisory Services are clearly distinguished from executiononly services, dealing as principal, placement services, marketing communications, and general education or research. (5) A Licensee shall not structure its Advisory Services in a manner that results in de facto execution, order routing control, or discretionary management of Client assets without the relevant Licence Category and compliance with the applicable Regulation. 4. Policies, procedures and governance. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Advisory Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) the basis on which advice is formulated; (b) the collection, verification and periodic updating of Client information relevant to suitability; (c) the approval, review and use of research, market data, third-party information, models, algorithms, scoring tools and other inputs used in the provision of advice; (d) conflicts of interest, inducements, referral arrangements and staff personal dealing; (e) controls to distinguish General Market Commentary from Personalized Recommendations; (f) record-keeping and surveillance of Advisory Services activity; and (g) review, escalation and remediation of any deficiency identified in the advisory process. (2) The Licensee shall ensure that the advisory framework is adequately resourced, independently overseen, and subject to effective compliance monitoring. (3) The Licensee shall review the effectiveness of its advisory policies and procedures at least annually, and more frequently where there is a material change to its business model, distribution model, Client base, products, systems, or applicable law or regulation. (4) The Licensee shall take appropriate remedial action without undue delay where any material deficiency is identified. 5. Public disclosures. — (1) A Licensee providing Advisory Services shall publish on its website, or make available through another publicly accessible mean approved by the Authority, clear, fair and not misleading disclosures including at least the following: (a) a description of the Advisory Services offered; (b) whether the advice is independent, restricted, product-limited, issuer-limited, venue-limited or otherwise subject to commercial or structural limitations; (c) a description of any material actual or potential conflicts of interest and how such conflicts are identified, managed, mitigated or disclosed; (d) the Licensee’s policies and procedures relating to data privacy, complaints handling and whistleblowing;
Page 9 of 101 (e) whether the Licensee refers or introduces Clients to other Persons, including other Licensees, and if so a description of any material monetary or non-monetary benefit received in connection with such arrangements; (f) whether any material advisory function, research input, model, data source, Client interface, or other relevant component of the service is provided or maintained by a third party; and (g) such other information as the Authority may require. (2) The disclosures required under sub-regulation (1) shall be kept current and reviewed whenever a material change occurs. 6. Client information and suitability assessment. — (1) Before providing a Personalized Recommendation, a Licensee shall obtain sufficient information regarding the relevant Client to enable the Licensee to assess whether the recommendation is suitable for that Client. (2) The Suitability Assessment shall consider, at a minimum the following: (a) the Client’s knowledge and experience in relation to Virtual Assets and relevant products or services; (b) the Client’s investment objectives, including risk tolerance, expected holding period, return objectives and any relevant restrictions or preferences; and (c) the Client’s financial circumstances, including the Client’s capacity to bear loss. (3) The Licensee shall take reasonable steps to ensure that the information obtained for the Suitability Assessment is reliable, accurate, and up to date. (4) The Licensee shall not provide a Personalized Recommendation where it lacks sufficient information to conclude that the recommendation is suitable for the Client, and shall not treat the absence of sufficient information as a basis to default to execution-only treatment without appropriate disclosure to the Client. (5) The Licensee shall review and update relevant Client information periodically and upon becoming aware of a material change in the Client’s circumstances. (6) A Licensee shall establish procedures to ensure that Clients understand the principal risks associated with the relevant recommendation and the types of losses that may arise from acting upon it. 7. Basis of advice and methodology. — (1) A Licensee shall establish and maintain a documented methodology governing how Personalized Recommendations are formulated, approved, communicated, and reviewed. (2) The methodology shall be reasonably designed to ensure that recommendations are based on appropriate information and analysis and are suitable for the relevant Client. (3) Nothing in this Regulation shall require a Licensee to assess the whole market or a broad range of Virtual Assets, unless the Licensee expressly represents to the Client that its assessment does so. Where the Licensee’s advisory process considers only a limited range of Virtual Assets, issuers, venues, counterparties, products, strategies or affiliated offerings, it shall clearly disclose that limitation to the Client before the recommendation is relied upon.
Page 10 of 101 (4) Where a Licensee’s advisory process considers only a limited range of tokens, issuers, venues, counterparties, products, strategies or affiliated offerings, the Licensee shall clearly disclose that limitation to the Client before the recommendation is relied upon. (5) A Licensee shall not present a recommendation as suitable merely because it falls within a broad risk category or model output, unless the recommendation is in fact suitable having regard to the Client’s individual circumstances. (6) Where automated tools, algorithms or models are used to generate or support Personalized Recommendations, the Licensee shall: (a) understand and document the methodology, assumptions, limitations and data dependencies of the tool, algorithm or model; (b) validate the tool, algorithm or model before deployment and on an ongoing basis thereafter; (c) maintain effective governance, oversight and change controls; and (d) ensure that the use of automation does not diminish the Licensee’s responsibility for suitability, fairness and regulatory compliance of the resulting recommendation. 8. Verification of information and fair presentation. - (1) A Licensee shall not provide advice containing any statement, promise, forecast, estimate, projection or other information which it knows, suspects, or ought reasonably to know is false, misleading, deceptive or presented in a misleading manner. (2) Prior to making any factual statement or using any factual input material to the advisory process, the Licensee shall take reasonable steps to verify such information against appropriate and reliable source materials. (3) Where forward-looking statements, scenario analysis or projections are used, the Licensee shall ensure that: (a) they are fair and not misleading; (b) their assumptions, uncertainties and limitations are appropriately disclosed; and (c) they are not presented as certain outcomes. (4) The Licensee shall use reasonable endeavors to verify the continued accuracy of material factual information used in an ongoing advisory relationship and shall correct any material error or outdated statement without undue delay. 9. Advice records and rationale. — (1) A Licensee shall create and maintain a contemporaneous Advice record for each Personalized Recommendation. (2) The Advice record shall include at least the following: (a) the Client information relied upon; (b) the recommendation made; (c) the principal basis on which the recommendation was assessed as suitable; (d) any limitations in the scope of products, venues, issuers, counterparties or information considered; and
Page 11 of 101 (e) the date on which the recommendation was made and the identity of the relevant adviser, approver, system or model, as applicable. (3) Where the recommendation is generated wholly or partly through an automated process, the Advice record shall include the relevant system, model or logic used and sufficient information to permit supervisory review. (4) A Licensee shall retain Advice records and all related suitability documentation for at least seven (7) years, or such longer period as may be required under the Act, the Regulations, AML/CFT requirements, or any written direction of the Authority. 10. Conflicts of interest, referrals and inducements. — (1) A Licensee providing Advisory Services shall identify, manage, mitigate and, where appropriate, disclose conflicts of interest arising in relation to the provision of advice. (2) Without prejudice to the generality of sub-regulation (1), the Licensee shall maintain controls addressing at least the following: (a) advice relating to affiliated tokens, affiliated issuers, affiliated venues or relatedparty arrangements; (b) staff incentives or compensation structures linked to product distribution, Client trading volumes, or specific outcomes; (c) personal account dealing by relevant employees; (d) referral, introduction, distribution and reciprocal business arrangements; and (e) receipt or payment of monetary or non-monetary benefits that may impair the objectivity of the advisory service; (f) recommendations that directly or indirectly favour affiliated venues, products, liquidity providers or counterparties. (3) A Licensee shall not recommend a product or transaction primarily to generate fees, commissions, spreads, trading volume or other benefit for itself or a related person. (4) A Licensee shall disclose to the Client, before the recommendation is acted upon, any material conflict that cannot be effectively prevented or otherwise managed. 11. Outsourcing and third-party tools. — (1) A Licensee shall not outsource their core/principal activity for which it is licensed and shall ensure that any outsourcing or thirdparty arrangement relating to Advisory Services complies with the outsourcing, governance, technology, cybersecurity and operational resilience requirements under the Regulations. (2) Where a third party provides research, Client interfaces, suitability tools, profiling tools, robo-advisory engines, algorithmic recommendation tools or other components material to the advisory process, the Licensee shall remain fully responsible for compliance with this Regulation. (3) The Licensee shall ensure that any such arrangement includes appropriate rights of access, audit, oversight, information and termination, consistent with the Regulations and any applicable direction of the Authority.
Page 12 of 101 Broker-Dealer Services Regulations
Page 13 of 101 (2) A Licensee providing Broker-Dealer Services may, subject to its Licence and the Act and Regulations: (a) receive and transmit Client Orders in relation to Virtual Assets; (b) execute Client Orders on behalf of Clients; (c) deal in Virtual Assets as principal or agent; (d) trade on its own account where expressly permitted; and (e) provide placement or distribution services for Issuers acting as intermediary. (3) A Licensee shall not rely on a Broker-Dealer License to provide discretionary portfolio management, custodial control, transfer and settlement activity, lending and borrowing activity, derivatives and leverage activity, or issuance activity where, the relevant service falls within another Licence Category under the Regulations. 4. General conduct obligations. — (1) A Licensee providing Broker-Dealer Services shall act honestly, fairly and professionally in accordance with the best interests of its Clients. (2) The Licensee shall comply with the Client categorization, disclosure, conflicts of interest, complaints handling and market conduct requirements under the Regulations and any binding direction, circular, standard or other instrument issued by the Authority under the Act or the Regulations. (3) The Licensee shall ensure that its business model, remuneration arrangements, distribution arrangements, inventory management practices, and principal dealing activities do not result in the unfair treatment of Clients. (4) Where the Licensee acts in more than one capacity, including as agent, principal, market maker, request-for-quote counterparty, placement intermediary or proprietary trader, it shall clearly identify the relevant capacity in the Client Agreement and in its disclosures, as applicable. (5) The Licensee shall maintain effective controls to identify, manage, mitigate and, where appropriate, disclose conflicts arising from the dual role of serving Clients while also trading for its own account, warehousing inventory, supporting issuances, or routing orders to affiliated venues or liquidity providers. 5. Policies, procedures and governance. — (1) A Licensee providing Broker-Dealer Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale, complexity and business model of its activities, including such policies and procedures as are necessary to govern order handling, execution, conflicts of interest, Client disclosures, market conduct, Customer Asset handling where relevant, and operational resilience. (2) The Licensee shall ensure that the Broker-Dealer control framework is adequately resourced, independently overseen, and subject to effective compliance monitoring, risk oversight and internal escalation.
Page 14 of 101 (3) The Licensee shall review the effectiveness of its Broker-Dealer policies and procedures at least annually, and more frequently where there is a material change to its products, venues, systems, Client base, execution model, market conditions or applicable legal requirements. (4) The Licensee shall take appropriate remedial action without undue delay where any material deficiency is identified. (5) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that: (a) they are appropriate to the Licensee’s business; (b) they are legally and operationally applicable in Pakistan; (c) they do not impair the Authority’s supervisory access, oversight or enforcement capabilities; and (d) the Licensee maintains sufficient local oversight, governance, operational capability and access to information necessary to ensure compliance with the Act, the Regulations and any binding direction or other instrument issued by the Authority under express authority conferred by the Act. Any binding direction or other instrument shall identify its statutory basis, binding status and effective date. Guidance may explain the Authority’s supervisory expectations but shall not create a generally applicable mandatory obligation unless issued under express authority conferred by the Act. 6. Public disclosures. — (1) A Licensee providing Broker-Dealer Services shall publish on its website, or make available through another publicly accessible means approved by the Authority, clear, fair and not misleading disclosures including at least: (a) a description of the Broker-Dealer Services provided, including whether the Licensee acts as agent, principal, or both; (b) a summary of its order handling and execution arrangements, including the types of Execution Venues or liquidity sources it may use and any material circumstances in which Client Orders may be executed on an affiliated venue, internalized, crossed, or executed over-the-counter; (c) a summary of its Best Execution or Fair Pricing approach, as applicable to its business model; (d) the material fees, commissions, spreads, mark-ups, mark-downs, rebates or other charges relevant to Broker-Dealer Services; (e) a statement of the Licensee’s arrangements for the safeguarding of Client Assets, where the Licensee holds or controls Client Assets; (f) a statement of whether the Licensee refers or introduces Clients to other Persons, including other Licensees, and if so a description of any material monetary or nonmonetary benefit received in connection with such arrangements; (g) a statement of whether any Client money, Client Virtual Assets, accounts, or other material service components are maintained or performed by a third party; (h) a link or connectivity with VASP Exchange for providing detail of the Virtual Assets for which they are providing services;
Page 15 of 101 (i) the Licensee’s policies relating to data privacy, complaints handling and whistleblowing; and (j) such other information as the Authority may require. (2) A Licensee shall be required to disclose any information expressly required by the Authority in light of the Licensee’s actual business model. (3) The disclosures required under sub-regulation (1) shall be kept current and reviewed whenever a material change occurs. (4) A Licensee may satisfy the disclosure requirements under this Regulation in a manner proportionate to the nature, scale, and complexity of its Broker-Dealer activities, provided that all material information relevant to Clients is clearly disclosed. The extent and detail of disclosures may reflect the nature of the services actually provided by the Licensee, including whether the Licensee holds Client Assets or performs execution functions directly. (5) A Licensee shall disclose to the Authority, within thirty (30) Business Days after the end of each quarter: (a) the identity of any single liquidity source or affiliated venue to which twenty percent (20%) or more of the Licensee’s total Client order flow was routed during that quarter, measured by volume or value; and (b) any routing relationship that created a material conflict of interest The disclosure shall include a description of the relevant routing practices and the measures used to identify, manage and mitigate any material conflict of interest. Nothing in this subregulation limits any obligation to disclose a material conflict to affected Clients. 7. Client Agreements. — (1) In addition to any general requirements under the Regulations, a Client Agreement for Broker-Dealer Services shall, at a minimum, specify: (a) whether the Licensee will act on an execution-only, advisory, principal, agency, placement, distribution or other basis, or a combination thereof; (b) the capacity in which the Licensee may act for each type of order, transaction or service, including agent, principal, request-for-quote counterparty, market maker or other capacity; (c) the order types and execution methods offered; (d) the Execution Venues and mechanisms that may be used, including any internalization, crossing or over-the-counter arrangements; (e) the circumstances in which Client Orders may be aggregated, split, prioritized, suspended, rejected, cancelled or partially executed; (f) the basis on which prices are determined, including any mark-ups, mark-downs, spreads or fees; (g) the circumstances in which the Licensee may deal as principal to satisfy a Client Order, support an issuance, or manage inventory; (h) any arrangements affecting Client Assets, collateral, margin or ancillary financing, where applicable and lawfully permitted;
Page 16 of 101 (i) any special risks associated with leveraged, derivative, structured, illiquid, thinly traded or other higher-risk Virtual Asset products made available to the Client; and (j) any other matter necessary to ensure that the Client understands the nature of the service and the material risks and conflicts associated with it. (2) A Client Agreement shall be clear, fair and not misleading and shall be updated or supplemented where a material change occurs. 8. Order handling – general principles. — (1) A Licensee shall handle Client Orders promptly, fairly and expeditiously, in accordance with the Client’s instructions, the Client Agreement and the Licensee’s order handling policy. (2) Orders for different Clients shall be treated fairly and shall not be unfairly prejudiced in favour of the Licensee, its Proprietary Trades, related parties, affiliated venues, preferred liquidity providers or other Clients. (3) The Licensee shall maintain policies and procedures addressing at least: (a) receipt, validation and acceptance or rejection of orders; (b) time-stamping or other reliable sequencing of order events; (c) priority rules where multiple Client Orders compete; (d) the handling of partially filled, unfilled, stale, duplicate, erroneous or suspended orders; (e) aggregation and allocation of orders; (f) the handling of trading halts, market disruption events, system outages and severe volatility; and (g) escalation and remediation of order handling errors. (4) The Licensee shall ensure that its systems and controls are capable of receiving, processing and executing Client Orders in an orderly manner consistent with the scale and complexity of its business. (5) Where a Client provides specific instructions, the Licensee shall execute in accordance with those instructions to the extent possible and lawful, and shall explain to the Client where following such instructions may limit the Licensee’s ability to pursue Best Execution or Fair Pricing considerations. In the absence of such instructions, the Licensee shall execute in accordance with its Execution Policy. 9. Best Execution and Fair Pricing. — (1) Where a Licensee executes Client Orders on an agency basis, it shall comply with the Best Execution standard and take all reasonable steps to obtain the best possible result for its Clients, taking into account price, costs, speed, likelihood of execution and settlement, size, nature and any other relevant consideration. (2) Where a Licensee executes Client Orders on a principal basis, including through requestfor-quote, internalization or similar arrangements, it shall ensure that pricing is fair, transparent and non-discriminatory, consistent with its disclosed pricing policies and prevailing market conditions. No licensee shall delegate its responsibility of best execution of it’s client orders.
Page 17 of 101 (3) Where a Licensee executes Client Orders against its own account, inventory or through internalization, it shall ensure that: (a) the price is consistent with prevailing market conditions across reasonably available liquidity sources; and (b) Clients are not systematically disadvantaged as a result of such execution. (4) A Licensee shall establish, implement and maintain an Execution Policy describing: (a) the factors considered when determining how Client Orders will be executed; (b) the relative importance of those factors in different circumstances; (c) the Execution Venues or mechanisms relied upon; (d) how the Licensee monitors execution quality or pricing quality; and (e) how deficiencies are identified and remediated. (5) In evaluating Best Execution and/or Fair Pricing, the Licensee shall consider, where relevant: (a) the characteristics of the relevant market, including price levels, spreads, volatility, relative liquidity and execution resilience; (b) the size, nature and urgency of the transaction; (c) the number and nature of liquidity sources reasonably available; (d) accessibility and reliability of quotes under prevailing market conditions; (e) the costs, fees and settlement risks associated with the execution route; and (f) the terms and conditions of the order communicated by the Client. (6) Where a Licensee executes a Client Order off-market, over-the-counter, or against another Person outside an exchange or venue, the burden of demonstrating compliance with the applicable Best Execution or Fair Pricing standard remains with the Licensee. (7) The Best Execution standard under this Regulation does not impose a guarantee of the best price in all circumstances, but requires reasonable steps, documented policy, ongoing monitoring and conduct consistent with the Licensee’s business model and the Client’s legitimate interests. 10. Selection and review of Execution Venues. — (1) A Licensee shall take reasonable steps to select and monitor Execution Venues in a manner consistent with achieving Best Execution or Fair Pricing for Clients, as applicable to its business model. (2) Criteria for venue selection and review shall include, where relevant: (a) price levels and spreads; (b) available liquidity; (c) execution reliability and settlement risk; (d) incidental costs and fees; (e) operational resilience; (f) market integrity and surveillance standards of the venue; and (g) any conflicts, ownership links or economic interests that may affect routing decisions.
Page 18 of 101 (3) The Licensee shall periodically review the performance of Execution Venues used and adjust its Execution Policy, routing logic or venue list where appropriate. (4) The Licensee shall not route Client Orders to a venue solely because the venue provides the Licensee with rebates, revenue-sharing, reciprocal business or other benefits inconsistent with the Licensee’s obligations to Clients. (5) The Licensee shall maintain sufficient records to demonstrate the basis on which venues are selected, reviewed and, where relevant, removed or restricted. 11. Routing to affiliated venues and related parties. — (1) Where a Licensee routes or executes Client Orders on an Exchange or other Execution Venue operated by itself, an Affiliate or another related party, it shall: (a) disclose the affiliated or related-party relationship to Clients in a clear and prominent manner; (b) ensure that Clients are not disadvantaged relative to comparable orders routed to comparable third-party venues; (c) manage conflicts of interest arising from the dual role of venue operator and BrokerDealer, or other related-party relationship; and (d) maintain records sufficient to demonstrate that routing decisions remain consistent with its obligations under this Regulation. (2) Disclosure under sub-regulation (1) shall cover, where relevant, the nature of the relationship, any shared management or ownership, and any material economic interest in order flow routed to the affiliated or related-party venue. (3) A Licensee shall not represent routing to an affiliated venue as neutral or market-wide if, in substance, its execution model favours that venue. 12. Aggregation and allocation of orders. — (1) A Licensee may aggregate Client Orders with orders of other Clients or with Proprietary Trades only where: (a) such aggregation is unlikely overall to disadvantage any Client whose order is to be aggregated; and (b) the Licensee has disclosed to Clients that aggregation may occur and that it may operate to their disadvantage in certain circumstances. (2) A Licensee shall establish and maintain fair allocation rules for aggregated orders, including rules addressing partial fills and scenarios where Proprietary Trades are aggregated with Client Orders. (3) Allocation decisions shall be documented and shall not systematically favour the Licensee, its related parties, preferred Clients or proprietary positions. (4) A Licensee shall not use aggregation or allocation practices to mask preferential treatment, front-running or misuse of Client Order information.
Page 19 of 101 13. Dealing as principal and proprietary trading. — (1) A Licensee may deal as principal for the purpose of satisfying Client Orders, supporting placement or distribution activity, managing inventory, making markets, or otherwise as permitted by its Licence, subject to compliance with the Regulations. (2) Where a Licensee deals as principal with a Client or against a Client Order, it shall ensure that: (a) the capacity in which it acts is clearly disclosed; (b) the pricing is fair, transparent and non-discriminatory; (c) the transaction is not structured or timed so as to disadvantage the Client; and (d) any related conflicts are effectively managed. (3) A Licensee shall establish, implement and maintain effective controls governing Proprietary Trades, including controls to prevent: (a) front-running of Client Orders; (b) misuse of Client Order information or confidential Client information; (c) unfair preference of Proprietary Trades over Client Orders; and (d) improper inventory management practices that undermine fair treatment of Clients. (4) Proprietary trading activity shall be subject to risk limits, monitoring, escalation and board or senior management oversight proportionate to the scale and risk of the activity. 14. Suitability and appropriateness interfaces. — (1) Where a Licensee provides investment advice or discretionary services in relation to Virtual Assets in the course of Broker-Dealer Services, it shall comply with the applicable suitability requirements under the Advisory Services Regulation, the Management and Investment Services Regulation, and other applicable Regulations, as relevant. (2) Where a Licensee offers execution-only or non-advised services in complex or higher-risk Virtual Asset products, including derivatives, leveraged positions, structured products or similarly complex arrangements, it shall assess whether the product or service is appropriate for the Client. (3) For the purpose of an appropriateness assessment, the Licensee shall obtain information regarding the Client’s knowledge and experience in relation to the specific type of product or service concerned. 15. Placement and distribution services for Issuers. — (1) Where a Licensee provides placement or distribution services for an Issuer acting as intermediary, it shall establish and maintain controls appropriate to that role, including controls relating to: (a) due diligence on the Issuer and the relevant Virtual Asset or offering; (b) fair and not misleading marketing and distribution communications; (c) allocation of offerings; (d) management of conflicts of interest, including affiliated issuer relationships; and (e) segregation of intermediary activities from any advisory, custody, exchange or principal trading activity that may create conflicts.
Page 20 of 101 (2) A Licensee shall not distribute, place or intermediate the offer of a Virtual Asset where it knows, suspects, or ought reasonably to know that the disclosures, statements or marketing materials used are false, misleading, deceptive or materially incomplete. (3) Where placement or distribution services are provided in connection with Issuance Services, the Licensee shall comply with any applicable Issuance Services Regulation and any conditions imposed by the Authority. 16. Client Assets, collateral and margin interface. — (1) Where Client Assets are held on an incidental basis, such holding shall be limited to temporary operational possession strictly necessary for execution, transfer, or settlement and shall not amount to ongoing custody, independent safeguarding, or unrestricted control of Client Assets. (2) A Licensee shall not use incidental holding arrangements to circumvent the requirement to obtain a Custody Services Licence where the substance of the activity involves ongoing holding, safeguarding, administration or control of Client Assets. (3) Client Assets held on an incidental basis shall remain subject to safeguarding, reconciliation, segregation, record-keeping and control measures appropriate to the nature, scale and duration of the activity. (4) A Licensee shall not use, lend, pledge, rehypothecate, stake, encumber or otherwise dispose of Client Assets solely by virtue of its Broker-Dealer Licence. Any such use shall be in light of Client’s prior written explicit and informed consent where required and shall clearly disclose the nature of the activity, the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated. (5) Where a Broker-Dealer intends to offer margin, collateral or financing arrangements, it shall comply with all applicable prudential, safeguarding, conduct and disclosure requirements under the Regulations and any relevant Lending and Borrowing Services Regulation or Derivatives Services Regulation. The Broker- Dealer shall seek specific approval for offering margin products as detailed in Regulation 20 of the Exchange Services Regulations. (6) A Broker-Dealer License shall not of itself entitle a Licensee to provide a standalone margin financing, lending, borrowing, leveraged or derivatives business. 17. Technology, resilience and continuity of execution. — (1) A Licensee shall maintain systems, controls and business continuity arrangements sufficient to support the orderly receipt, routing, execution, confirmation and recording of Client Orders, including during periods of high uncertainty, severe volatility, market disruption, cyber incident or operational stress. (2) This Regulation is without prejudice to the broader technology, cybersecurity, incident reporting and operational resilience requirements under the Act and the Regulations. 18. Record-keeping. — (1) A Licensee shall keep, for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations, records sufficient to:
Page 21 of 101 (a) evidence compliance with this Regulation; (b) reconstruct individual transactions and Client Orders; and (c) support investigations into suspected misconduct, execution failures, pricing anomalies or misuse of Client Order information. (2) Records shall include, at a minimum: (a) Client Orders and any amendment, rejection, suspension, cancellation or execution event; (b) time-stamped records or equivalent sequencing records of order receipt, routing and execution; (c) allocation decisions and rationales; (d) suitability or appropriateness assessments and warnings, where applicable; (e) execution quality, pricing quality and venue review reports; (f) records of Proprietary Trades and monitoring outcomes; and (g) communications with Clients relating to orders, execution issues, pricing issues and complaints. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation, reconstruction of events and effective remediation. 19. Management information, oversight and reporting to the Authority. — (1) A Licensee shall produce regular management information on matters relevant to Broker-Dealer Services, including at least: (a) execution quality and venue performance; (b) order handling statistics, including error rates, rejects, partial fills and material exceptions; (c) complaints related to execution, pricing, routing or order handling; and (d) incidents involving market abuse, front-running, misuse of Client Order information, execution system failures or conflicts incidents. (2) The Licensee’s board shall review such information at a frequency commensurate with the scale and risk of the business and shall direct remedial action where necessary. (3) A Licensee shall report to the Authority, in the manner and frequency determined by the Authority: (a) material breaches of this Regulation or the relevant market conduct provisions of the Regulations; (b) serious or systemic execution failures; (c) material pricing control failures; (d) incidents of suspected market abuse or misuse of Client Order information involving the Licensee, its staff or its Clients; and (e) any other matter which the Authority may reasonably require for supervisory purposes.
Page 22 of 101 Provided further that reporting to the Authority under this Regulation shall not relieve a VASP of its obligation to submit STRs and other reports to the FMU in accordance with the AML Act, 2010. (4) The Authority may require the Licensee to provide additional information, management attestations, file reviews, remediation plans or thematic data, and may direct the Licensee to take specific remedial measures. Custody Services Regulations
Page 23 of 101 (b) nothing in this Regulation alters the legal treatment of Client Assets as set out in the Act and the Regulations. 3. Nature and perimeter of Custody Services. — (1) A Licensee shall not hold itself out as providing Custody Services unless it is authorised for that Licence Category or is otherwise permitted to hold or control Client Assets on an incidental basis under the Regulations. (2) A Licensee providing Custody Services shall perform the safekeeping or administration, on behalf of customers and pursuant to their instructions, of: Virtual Assets; or private cryptographic keys seed phrases, signing devices, authorization credentials or other means of access that allow the customer to transfer or dispose of Virtual Assets independently but excludes the mere provision of software, hardware or infrastructure that enables a customer to retain exclusive control over their own private keys. (3) A Custody authorization does not, of itself, authorize the Licensee to lend, stake, pledge, rehypothecate, transfer, settle, manage, invest, issue, or otherwise deploy Client Assets except with prior written explicit consent. (4) Where a custody arrangement forms part of another licensed activity, the Licensee shall comply with this Regulation to the extent applicable to the holding, control, safeguarding or administration of Client Assets in connection with that activity, and such arrangement shall not be structured or operated in a manner that circumvents the requirements applicable to any other Licence Category under the Act or the Regulations. 4. Custody governance and accountability. — (1) The Licensee shall be responsible for the oversight of custody arrangements and the protection of Client Assets. (2) The Licensee shall ensure the effective implementation of custody policies, procedures and controls approved by the Licensee’s board. (3) The Licensee shall establish clear segregation and appropriate independence between custody operations, trading activities, compliance, risk, and technology functions, commensurate with the nature, scale and complexity of its activities. (4) The Licensee shall approve and periodically review, at a minimum: (a) custody models and wallet architecture; (b) safeguarding and segregation arrangements; (c) Key Management and access-control standards; (d) reconciliation and discrepancy management arrangements; (e) incident response and recovery arrangements; (f) policies governing any permitted use of Client Assets; and (g) outsourcing and Third-Party Custodian arrangements. (5) The Licensee shall maintain adequate governance, committee structures, reporting lines and management information to enable effective oversight of custody risks, technology risks, operational risks and Client protection risks. (6) The Licensee shall, at a frequency proportionate to the scale and risk of its activities, obtain independent assurance over its custody controls, including safeguarding, reconciliation and
Page 24 of 101 Key Management arrangements, and shall make such reports available to the Authority on half yearly basis. 5. Safeguarding and segregation of Client Assets. — (1) A Custodian shall safeguard Client Assets in a manner that ensures they are segregated from the Custodian’s own assets and from the assets of other Persons, in accordance with the Act, the Regulations and this Regulation. (2) Client Virtual Assets are not owned by the Custodian. The Custodian shall hold or control Client Virtual Assets solely for the benefit of Clients and shall not treat Client Assets as its own assets. (3) The Custodian shall maintain records that clearly identify which wallets, addresses, accounts, sub-accounts or ledger designations contain Client Assets, including through internal ledger tagging where appropriate. (4) Segregation shall be implemented in wallet structures, account structures and internal ledgers and records, including by jurisdiction where relevant. (5) The Custodian shall structure its arrangements so as to support the identification, protection and return of Client Assets in accordance with the insolvency and Client asset protection requirements under the Act and the Regulations. 6. Insolvency protection and legal treatment of Client Assets. — (1) A Custodian shall structure its custody arrangements to support the legal protection afforded to Client Assets under the Act and the Regulations, including protection from: (a) claims of the Custodian’s creditors; and (b) inclusion in the Custodian’s insolvency estate, to the extent permitted by applicable law. Notwithstanding anything to the contrary contained in any other law for the time being in force, Customer Assets held by a Licensee shall not form part of the Licensee’s estate in the event of its insolvency or liquidation. (2) The Custodian shall maintain records, wallet structures, Client agreements and reconciliation capabilities sufficient to facilitate the timely identification and return, or transfer, of Client Assets, subject to applicable insolvency law and any directions of a competent court or insolvency officeholder. (3) The Custodian shall assess and document any material legal uncertainty affecting the enforceability or practical effectiveness of its custody structure, including cross-border insolvency issues where relevant, and shall disclose material residual risk to Clients in a fair, clear and not misleading manner. (4) Where custody arrangements involve cross-border structures or legal uncertainty, the Custodian shall obtain and maintain legal analysis or opinions sufficient to support its assessment of Client Asset protection.
Page 25 of 101 7. Control, access and wallet management. — (1) A Custodian shall establish and maintain effective controls governing access to Client Assets, including the management of private keys, seed phrases, signing devices, account credentials and other means of control. (2) Access controls shall ensure, as appropriate to the custody model and risk profile: (a) segregation of duties; (b) secure key generation, storage, backup and recovery; (c) multi-factor, multi-approval or multi-signature arrangements where appropriate; (d) controlled and auditable transaction approval processes; and (e) timely revocation of access rights where no longer required. (3) The Custodian shall maintain documented wallet architecture standards, including the basis for using hot, cold and warm Wallets, and the methodology for transferring assets between wallets. (4) The use of Segregated Wallets shall not, of itself, require or permit direct independent control of Client Virtual Assets by the Client unless otherwise expressly approved by the Authority. (5) The Custodian shall identify, assess and mitigate risks of collusion, single points of failure, credential compromise, insider misuse and unauthorized access. (6) The Custodian shall ensure that manually executed core/principal custody functions are performed only by authorised personnel under controlled procedures. (7) A Custodian shall implement a risk-based wallet allocation framework that: (a) limits the proportion of Client Assets held in hot or online environments to levels commensurate with operational needs and risk appetite; (b) ensures that the majority of Client Assets are held in secure offline or equivalent environments where appropriate; and (c) is approved by the Licensee’s board and subject to periodic review. 8. Key generation, storage, backup and recovery. — (1) A Custodian shall generate seeds, private keys and related cryptographic mechanisms using secure generation practices appropriate to industry standards and the Custodian’s risk profile. (2) The Custodian shall apply secure storage and encryption controls to primary and backup keys and shall avoid any arrangement that creates a single point of access enabling a transaction without further control. (3) Key and seed backups shall be stored separately from primary keys and protected by controls at least equivalent to those applied to primary keys. (4) The Custodian shall establish and maintain effective policies and procedures to respond where any seed, private key, signing device or other credential is lost, stolen, corrupted or otherwise compromised. (5) Such procedures shall address, where relevant: (a) recovery or protection of affected Client Assets; (b) timely communication with affected Clients, counterparties and the Authority; (c) cooperation with law enforcement and other competent authorities; and
Page 26 of 101 (d) activation of wind-down or emergency migration arrangements where necessary. (6) Key Management arrangements shall, where appropriate to the scale and risk of the custody model: (a) incorporate multi-party computation, multi-signature or equivalent distributed control mechanisms; (b) ensure that no single individual or system can unilaterally transfer Client Assets; (c) implement geographic, organizational and logical separation of key components; and (d) be subject to periodic independent testing and validation. 9. Reconciliations and discrepancy notification. — (1) A Custodian shall conduct reconciliations of Client Assets at least daily, and more frequently where appropriate having regard to transaction volumes, asset values and risk profile. (2) Reconciliations shall include, as applicable: (a) Client ledger balances per asset; (b) on-chain balances for relevant wallets or addresses, or equivalent control evidence; (c) Client Money balances and Client Accounts where relevant to the custody model; (d) pending transactions, unconfirmed deposits or withdrawals, and other timing items; and (e) identification and investigation of breaks, shortfalls, excesses or unexplained differences. (3) Discrepancies shall be identified, investigated and resolved promptly. (4) The Custodian shall notify the Authority without delay of any material discrepancy that is not rectified within twenty-four (24) hours and shall provide a summary of cause, impact and remediation based on information then available. The Custodian shall provide material updates as further information becomes available and a final report as soon as reasonably practicable and, in any event, within thirty (30) days, unless the Authority permits a longer period for reasonable cause. (5) The Custodian shall maintain a register or equivalent record evidencing each Client’s position and the reconciliation basis supporting that position. (6) Where a shortfall in Client Assets is identified: (a) the Custodian shall take immediate steps to make good the shortfall from its own resources or other available arrangements; (b) the Custodian shall not allocate losses to Clients except where expressly permitted under the Act, the Regulations and the Client Agreement; and (c) the Custodian shall notify the Authority and affected Clients without delay. 10. Proof of reserves. — (1) A Custodian shall maintain proof-of-reserves or equivalent assurance procedures sufficient to demonstrate on an ongoing basis that liabilities to Clients in respect of Client Virtual Assets are fully matched by safeguarded holdings or other equivalent arrangements.
Page 27 of 101 (2) Proof of Reserves procedures may include automated or cryptographic methods, including third-party attestation and cryptographic verification. 11. Use of Client Assets. — (1) A Custodian shall not use, sell, transfer, assign, pledge, loan, stake, rehypothecate, encumber or otherwise dispose of Client Assets solely by virtue of its Custody Licence. (2) Client Assets may be used only where: (a) such use is expressly permitted under the Act and the Regulations; (b) the Client has provided explicit, prior, informed consent within the limits clearly defined by the client where required under law or regulation; (c) the relevant Client Agreement clearly discloses the nature of the activity, the associated risks, withdrawal restrictions, and how rewards, proceeds, losses and liabilities are allocated; and (d) the Licensee holds any additional Licence Category required for the substance of the relevant activity. (3) Nothing in this Regulation permits the use of Client Assets other than as expressly allowed under the Act, the Regulations and applicable law. (4) Where consent-based use of Client Assets is permitted, the Custodian shall operate within clearly defined limits approved by the Licensee’s board and shall maintain additional riskmanagement controls and, where required, capital or liquidity buffers. (5) Any rewards, proceeds or benefits attributable to Client Virtual Assets, including airdrops, forks, staking rewards or similar benefits, shall accrue to the Client unless otherwise agreed in advance in the Client Agreement and disclosed in a fair, clear and not misleading manner. 12. Account statements and Client reporting. — (1) A Custodian shall provide Clients with periodic statements at intervals appropriate to the nature of the custody service and, in any event, not less frequently than monthly unless otherwise agreed with Professional Clients or Institutional Clients or otherwise permitted by the Authority. (2) Statements shall include, at a minimum, as applicable: (a) all Virtual Asset transactions specific to the Client account during the reporting period; (b) the dates and transaction amounts of corresponding transactions; (c) balances and value for each type of Virtual Asset held for the Client; and (d) such other information as is necessary for the Client to understand its holdings, movements and material restrictions. (3) Statements shall be made available promptly following the statement date and within a timeframe that is reasonable having regard to the Custodian’s systems and delivery channel. (4) Nothing in this Regulation limits any requirement under the Regulations to provide more frequent or more detailed reporting for particular Client categories, products or business models.
Page 28 of 101 13. Client disclosures and custody agreements. — (1) A Custodian shall disclose to Clients material information relating to custody arrangements in a clear, fair and not misleading manner. (2) Such disclosures shall include, at a minimum: (a) the nature of the custody service and the custodial framework applied; (b) wallet arrangements, including use of Omnibus versus Segregated Wallets and hot versus cold and warm storage, where relevant; (c) the principal custody risks applicable to the service; (d) the treatment of Client Assets in the event of insolvency or wind-down; (e) whether and on what terms Client Assets may be used, pledged, rehypothecated, staked or otherwise deployed; (f) the Custodian’s outsourcing arrangements and any use of Third-Party Custodians; and (g) the cybersecurity, incident response and reimbursement framework applicable to the custody service, where relevant. (3) Client agreements for Custody Services shall state clearly that ownership of Client Assets remains with the Client, unless otherwise expressly permitted under the Regulations for a separately regulated service. (4) Client agreements shall, at a minimum, address— (a) the circumstances, timing and process for the return or transfer of Client Assets; (b) the treatment of material changes to supported Virtual Assets, including forks or protocol changes; (c) settlement finality, including when a transfer is deemed complete and when the Custodian’s obligations cease in relation to that transfer; (d) frequency and content of account statements; (e) the party responsible for safeguarding Client Assets; and (f) policies and controls governing access to Client Assets. (5) Custody Services shall be provided pursuant to a contractual arrangement under which the Client transfers control of a Virtual Asset to the Custodian solely for the purpose of receiving Custody Services, without transferring beneficial ownership or discretionary authority except as expressly authorised under the Client Agreement and the Regulations. 14. Public disclosures. — (1) In addition to any disclosure requirements under the Regulations, a Custodian shall publish in a prominent place on its website, or via other accessible means approved by the Authority: (a) a description of material conflicts of interest arising from custody activities and how they are managed; (b) policies on data privacy, whistleblowing and handling of Client complaints; and (c) any additional information the Authority may require. (2) Public disclosures under this regulation shall be kept current and reviewed whenever a material change occurs.
Page 29 of 101 15. Outsourcing. — (1) A Custodian shall not outsource or delegate the principal custody activity for which it is licensed. The Custodian shall at all times retain effective control, governance, oversight, and responsibility in respect of Client Assets and custody operations. (2) For the purposes of this regulation, core/principal custody activity includes: (a) ultimate responsibility for safeguarding Client Assets; (b) governance and oversight of custody arrangements; (c) approval and control of wallet architecture and custody models; (d) provision of Key Management arrangements; (e) reconciliation and Client asset recordkeeping; and (f) control and supervision of access to Client Assets. (3) A Custodian may utilize wallet infrastructure providers, technology service providers in a limited support capacity only, and only to the extent that: (a) such arrangements do not result in the transfer of ultimate responsibility and/or effective control over custody functions; (b) the Custodian retains effective oversight, governance and supervisory access; (c) the arrangement does not impair the Authority’s ability to supervise Client Asset protection arrangements; and (d) the arrangement complies with this Regulation, the Regulations and any conditions imposed by the Authority. (e) the arrangement does not result in the transfer of beneficial ownership of Client Assets except as otherwise expressly permitted under the Act and the Regulations. (4) A Custodian shall not outsource or delegate custody arrangements in a manner that: (a) materially impairs its ability to safeguard Client Assets; (b) results in the Custodian ceasing to exercise effective oversight, governance or control over Client Assets or core/principal custody functions; or (c) prevents the Custodian or the Authority from obtaining timely access to records, systems, controls or information necessary for supervisory, safeguarding or recovery purposes. (5) Where a Custodian outsources its function in light of this Regulation, the Act or applicable regulatory framework, it shall: (a) conduct due diligence on the regulatory status, financial strength, operational resilience, controls and reputation; (b) enter into a written agreement specifying responsibilities, segregation standards, reporting obligations and audit rights; and (c) monitor performance and risk on an ongoing basis. (6) The Authority shall have access, audit and information rights in respect of outsourced arrangements to the extent permitted by law and the relevant contractual framework. (7) A Custodian shall apply documented selection criteria designed to ensure that any appointed wallet infrastructure provider possesses the operational capability, security standards,
Page 30 of 101 governance arrangements, and regulatory standing appropriate to the protection of Client Assets. Such criteria shall include, at a minimum, that the provider: (a) demonstrates institutional-scale operational capability and experience in Virtual Asset custody or wallet infrastructure services; (b) operates under, or is subject to, regulatory oversight in a jurisdiction acceptable to the Authority; (c) maintains recognized independent security certifications, including SOC 2 Type II or equivalent standards acceptable to the Authority; (d) maintains arrangements relating to segregation, operational resilience, business continuity and, where applicable, insurance, consistent with the requirements of this Regulation; and (e) is capable of supporting the Custodian’s reconciliation, audit and supervisory reporting obligations. (8) A Custodian shall ensure that any wallet infrastructure arrangement: (a) preserves the Custodian’s ability to comply with the Act, the Regulations and this Regulation; (b) provides the Authority with appropriate audit, inspection, access and information rights; (c) maintains appropriate safeguards over Client Assets, including segregation and reconciliation controls; and (d) does not result in Client Assets being held in individually controlled wallets or structures outside the custody and control framework approved by the Custodian and the Authority. (9) The Authority may, by policy, Regulation, circular, directive, or other written instrument issued under the Act or the Regulations, prescribe additional requirements, standards, eligibility criteria or evidential requirements applicable to wallet infrastructure providers, and compliance with such instrument shall be deemed compliance with the relevant requirements of this Regulation. 16. Operational resilience and incident management. — (1) A Custodian shall ensure that custody systems and controls meet operational resilience and availability standards appropriate to the criticality of custody services, in accordance with the Regulations. (2) The Custodian shall maintain incident response, escalation and recovery arrangements appropriate to wallet infrastructure, key-management processes, reconciliation processes and Client asset protection. (3) Material custody incidents, including loss of keys, cyber breaches, misallocation of Client Assets or significant delays in returning Client Assets, shall be reported to the Authority as soon as practicable and, in any event, within any timeframe specified by the Authority under the Regulations or by supervisory notice. (4) The Custodian shall maintain an incident log recording near misses as well as actual losses, to support lessons learned, remediation and supervisory engagement.
Page 31 of 101 (5) The Custodian shall maintain business continuity, backup and disaster recovery arrangements sufficient to support the continuity of critical custody functions. 17. Staking and yield-generating activities from custody. — (1) A Licensee shall not provide staking-related, protocol participation, yield-generating or similar activities in connection with Custody Services except with explicit prior written informed consent of the client. (2) Where a Licensee is permitted to provide such activities, the Licensee shall comply with all applicable safeguarding, disclosure, governance, technology, operational resilience, conflict management and conduct requirements under the Act, the Regulations and this Regulation. (3) The Authority may impose restrictions, conditions or prohibitions on staking-related or yield-generating activities involving Client Assets. 18. Sovereign Clients and permissible yield-related activities. — (1) The Authority may issue a policy Regulation or other guidance setting out prudential, operational and riskmanagement requirements applicable to any yield-related activities conducted in respect of Virtual Assets held for a Sovereign Client by Strategic Digital Wallet Company, licensed in light of Section 38 of the Act. (2) A Licensee holding license for conducting activities under Section 38 of the Act may facilitate limited yield-related activities in respect of Virtual Assets held for a Sovereign Client, including staking or other arrangements specifically approved by the Authority, subject to: (a) the Act; (b) the Regulations; (c) any applicable policy Regulation, guidance or direction issued by the Authority; and (d) the express written mandate of the relevant Sovereign Client. (3) Such Licensee shall not engage in any yield-related activity involving Virtual Assets held for a Sovereign Client unless: (a) the activity has been expressly authorised in writing by the relevant Sovereign Client; (b) the Licensee has conducted and documented an assessment of the associated operational, custody, liquidity, counterparty and technology risks; (c) the activity complies with the safeguarding, segregation, reconciliation and disclosure requirements of this Rulebook; and (d) beneficial ownership of the relevant Client Assets remains identifiable at all times. (4) Unless otherwise expressly approved by the Authority in a specific case, such Licensee shall not: (a) engage in unsecured lending of Sovereign Client assets; (b) transfer Sovereign Client assets under arrangements involving rehypothecation or unrestricted onward use by counterparties; or (c) deploy Sovereign Client assets through structures that materially impair custody control, transparency or recoverability.
Page 32 of 101 (5) Nothing in this Rule alters the legal character of the underlying holdings as Client Assets, or limits the obligations of the Licensee under the Act, the Regulations or this Regulation to safeguard, segregate, and properly account for Client Assets held for a Sovereign Client.
Page 33 of 101 Exchange Services Regulations
Page 34 of 101 4. Exchange governance and accountability. — (1) The Exchange shall be responsible for the oversight of exchange operations, market integrity and compliance with the Act, the Regulations and this Regulation. (2) The Licensee shall be responsible for the day-to-day management of exchange activities, including implementation of the policies, procedures and controls approved by the Licensee’s board. (3) The Licensee shall establish clear segregation and appropriate independence between trading operations, market surveillance, compliance, risk management and technology functions, commensurate with the nature, scale and complexity of its activities. (4) The Licensee shall approve and periodically review, at a minimum: (a) Trading Rules; (b) listing and delisting standards; (c) market surveillance and escalation arrangements; (d) proprietary trading policies, if any; (e) business continuity and trading disruption arrangements; and (f) conflicts of interest controls relevant to Exchange Services. (5) The Exchange shall maintain adequate governance, committee structures, reporting lines and management information to enable effective oversight of venue risks, technology risks, abuse risks and Client protection risks. 5. Policies, procedures and governance framework. — (1) In addition to all other applicable requirements under the Regulations, an Exchange shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) admission and ongoing participation of Participants; (b) listing, suspension, restriction and delisting of Virtual Assets; (c) market operations, Trading Rules, order types and matching logic; (d) market surveillance and abuse prevention; (e) conflicts of interest management, including related-party listings, affiliated trading activity and proprietary trading; (f) Client protection, including disclosures, treatment of Client Assets and handling of Client instructions where relevant; (g) handling of system outages, disruptions, Trading Halts, market stress and venuewide or asset-specific suspension events; (h) settlement, delivery, reconciliation and post-trade processing; (i) use of market data, reference prices and price-formation methodologies; and (j) such other matters as the Authority may reasonably require. (2) The Exchange shall assess and, in any case, at least annually review the effectiveness of its policies and procedures and take appropriate measures to address any deficiency. (3) The Exchange shall maintain records sufficient to demonstrate compliance with its policies and procedures and the basis for material exchange decisions.
Page 35 of 101 (4) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that: (a) they are appropriate to the Licensee’s business and risk profile; (b) they are legally and operationally applicable in Pakistan; (c) the Licensee retains full responsibility for compliance with the Act, the Regulations and this Regulation; and (d) the Authority is able to obtain access, directly or indirectly, to relevant records, systems, personnel and information necessary for supervisory purposes. 6. Public disclosures. — (1) An Exchange shall publish on its website, trading interface or another publicly accessible means approved by the Authority, clear, fair and not misleading disclosures including at least: (a) the Trading Rules, including order types, matching priority, market sessions and any special trading conditions; (b) fee schedules, including trading, listing and ancillary fees; (c) eligibility criteria for Participants and access arrangements; (d) policies for handling outages, system disruptions, Trading Halts, suspensions, reopenings and other material market events; (e) procedures for suspension, restriction or delisting of Listed Virtual Assets; (f) a summary of the Exchange’s standards for admission and continued availability of Virtual Assets; (g) a description of how Client Assets relevant to Exchange activity are safeguarded, where the Exchange holds or controls such assets; (h) a summary containing the following information pertaining to each Virtual Asset offered for exchange by the VASP: i). name and symbol; ii). date of issuance; iii). market capitalization and fully diluted value; iv). circulating supply, including as a percentage of maximum total supply (if applicable); v). whether the Virtual Asset has been subject to an independent smart contract audit and the date of the most recent audit; and vi). largest reduction in price from high to low stated as both an absolute amount and a percentage change, including when it occurred; (i) the Exchange’s policies relating to data privacy, complaints handling and whistleblowing; and (j) such other information as the Authority may reasonably require. (2) The Exchange may publish factual information regarding Listed Virtual Assets, including asset identifiers, circulating supply, audit status, and other neutral descriptive information, provided that such disclosures are presented in a fair, clear and not misleading manner and do
Page 36 of 101 not amount to financial promotion, endorsement or recommendation activity inconsistent with the Act or the Regulations. (3) The Exchange shall keep disclosures under this regulation current and update them promptly where a material change occurs. 7. Admission and participation criteria. — (1) An Exchange shall establish objective, transparent and non-discriminatory criteria for the admission and ongoing participation of Participants. (2) Admission criteria shall address, at a minimum the following: (a) eligibility and onboarding requirements; (b) access to trading systems and market interfaces; (c) ongoing compliance obligations; (d) operational, financial and technical conditions for participation, where relevant; and (e) grounds for refusal, suspension, restriction or termination of access. (3) The Exchange shall apply admission criteria consistently and shall not grant or maintain access on terms that materially prejudice market integrity or Client protection. (4) The Exchange shall maintain adequate records of admission, refusal, suspension and termination decisions and the basis for such decisions. 8. Participant rules and code of conduct. — (1) An Exchange shall publish and enforce a code of conduct or equivalent Participant rules governing conduct on the trading venue. (2) The code of conduct or equivalent rules shall include, at a minimum the following: (a) compliance with the Act, the Regulations, this Regulation and applicable market conduct obligations; (b) prohibitions on Market Abuse and abusive trading practices; (c) obligations to provide accurate information to the Exchange; (d) cooperation with surveillance, compliance and investigative processes; and (e) sanctions or disciplinary consequences for breach of applicable rules. (3) An Exchange shall ensure that Participants are fairly informed of the rules applicable to them and that relevant Clients or Participants validly accept those rules through contractual, platform or other lawful means. (4) Nothing in this regulation limits the powers of the Authority to impose supervisory, disciplinary or enforcement measures directly under the Act or the Regulations. 9. Virtual Asset admission and continued availability. — (1) An Exchange shall establish, implement and publish objective, transparent and non-discriminatory standards for the admission and continued availability of Virtual Assets on its venue. (2) Such standards shall be proportionate to the Exchange’s business model and shall address, where relevant, the following (a) liquidity and market quality considerations; (b) technology and security risks of the underlying protocol;
Page 37 of 101 (c) risks of fraud, manipulation and Market Abuse; (d) legal and regulatory risks, including whether the Virtual Asset is prohibited or restricted under the Act or any other law in Pakistan; (e) issuer disclosures and transparency, where relevant; and (f) conflicts of interest in relation to the Virtual Asset. (3) The Exchange shall conduct initial and ongoing assessments against its standards and shall keep records of such assessments. (4) The Exchange shall establish clear triggers and procedures for suspension, restriction or delisting where a Virtual Asset no longer meets its standards or where continued availability presents a material and demonstrable risk of significant harm to Clients or market integrity. 10. Listing procedures and notification. — (1) Subject to the Act, the Regulations andthis Regulation and any direction of the Authority, an Exchange may admit or list a Virtual Asset without prior product approval by the Authority, provided that: (a) the Virtual Asset is not subject to any explicit restriction or prohibition by the Authority or by law; (b) the Virtual Asset complies with the Exchange’s internal listing policies and due diligence standards; (c) where the Virtual Asset has previously been launched or admitted to trading in another jurisdiction, the Exchange has considered any available regulatory, market integrity and trading history information relevant to its assessment; provided that prior launch or admission to trading on another venue shall not be a condition for listing in Pakistan; and (d) the Exchange complies with any notification or information requirement specified by the Authority in relation to listing decisions. (2) Any notification made to the Authority in connection with a listing shall not constitute approval of the Virtual Asset by the Authority, and the Exchange remains fully responsible for its listing decision. (3) The Authority may, by direction, notice or supervisory requirement, require prior notification, accelerated notification, delayed notification, additional information, or risk-based escalation for particular classes of Virtual Assets, Exchanges or business models. (4) An Exchange shall not admit for trading any derivative, leveraged or synthetic product unless permitted under its Licence and consistent with the Derivatives Services framework and any applicable conditions imposed by the Authority. 11. Market operations and fair trading. — (1) An Exchange shall operate its trading systems in a fair, orderly and transparent manner. (2) The Exchange shall take reasonable steps to ensure fair and non-discriminatory access to trading information for Participants, subject to lawful and transparent differentiation based on access type, technical connectivity, market model, or Participant category, provided that such differentiation does not result in unfair advantage or undermine market integrity.
Page 38 of 101 (3) Trading Rules shall be applied consistently and without undue preference. (4) The Exchange shall establish and disclose rules governing at least the following: (a) market sessions and trading hours; (b) order entry, modification and cancellation; (c) matching logic and priority; (d) treatment of partially filled, unfilled, stale, erroneous or duplicate orders; (e) Trading Halts, suspensions and reopenings; and (f) circumstances in which the Exchange may reject, cancel, bust, reverse or otherwise remediate trades or orders. (5) The Exchange shall maintain systems and controls reasonably designed to prevent disorderly trading, unfair discrimination and systemic operational disruption. 12. Pricing methodology and market data integrity. — (1) Where the Exchange determines, calculates, publishes or uses prices, indices, reference rates, market data or valuation metrics in connection with Exchange Services, it shall establish documented methodologies designed to support integrity, reliability and resistance to manipulation. (2) Such methodologies shall address, where relevant, the following: (a) data sources and eligibility criteria; (b) handling of outliers, stale data and anomalous prints; (c) fallback arrangements for unavailable or unreliable data; (d) governance over methodology changes; and (e) controls to prevent conflicts of interest affecting price determination. (3) An Exchange shall disclose in clear terms the basis on which prices quoted or displayed to Participants are determined, to the extent necessary for Participants to understand execution, pricing outcomes and the operation of the market. (4) The Exchange shall not present price information in a misleading manner and shall maintain controls appropriate to the integrity of any benchmark-like or reference pricing process it operates. 13. Market surveillance and abuse prevention. — (1) An Exchange shall establish and maintain effective market surveillance arrangements to detect, deter and escalate Market Abuse, manipulation and other misconduct. (2) Surveillance arrangements shall be proportionate to the nature and scale of trading activity and shall include monitoring of trading behaviour, order activity, participant conduct and other relevant market signals. (3) The Exchange shall have procedures for investigating suspicious activity and taking appropriate action, including referral, restriction, suspension, escalation to the Authority, and preservation of relevant records. (4) Surveillance arrangements shall be supported by adequate staffing, systems, escalation protocols and management oversight.
Page 39 of 101 (5) An Exchange shall share information relevant to surveillance, disciplinary and supervisory purposes with the Authority in accordance with the Act, the Regulations and any lawful request or reporting requirement of the Authority. (6) Where the Exchange suspects potential abuse affecting the market, it shall notify the Authority without undue delay and provide such information as is relevant and reasonably available to the Exchange at the time of the report, including, where applicable, information relating to positions, exposures, order activity, inventory levels, delivery mode, margin changes or other actions taken by the Exchange. 14. Conflicts of interest, related-party listings and proprietary activity. — (1) An Exchange shall identify, prevent, manage and disclose conflicts of interest relevant to Exchange Services and shall not allow such conflicts to materially prejudice Clients, Participants or market integrity. (2) Without prejudice to the generality of sub-regulation (1), the Exchange shall maintain policies and procedures addressing at least: (a) related-party or affiliated listings; (b) affiliated Participants or connected trading activity; (c) proprietary trading by the Exchange or any group entity; (d) economic interests in listed assets, venues, issuers, market makers, or liquidity providers; and (e) decision-making conflicts affecting surveillance, listing or disciplinary outcomes. (3) Where an Exchange or any group entity trades on its own account, such activity shall be subject to strict controls to prevent conflicts of interest and unfair advantage. (4) Proprietary trading policies shall be approved by the Licensee’s baord, disclosed to the Authority, and supported by controls to prevent misuse of Client or Participant order information and unfair preference over other market users. (5) The Exchange shall maintain a record of material conflicts identified and the measures taken to manage, mitigate or disclose them. 15. Client Assets and custody interface. — (1) Where an Exchange holds or controls Client Virtual Assets or Client Money, whether on a standalone or incidental basis, it shall comply with the applicable safeguarding, segregation, reconciliation, record-keeping and disclosure requirements under the Regulations and, where applicable, the Custody Services Regulation. (2) An Exchange shall not use, lend, pledge, encumber, rehypothecate, stake or otherwise dispose of Client Assets solely by virtue of its Exchange Licence. Any such use shall require Client’s prior written, explicit and informed consent. (3) Where reserve assets are held in respect of Client liabilities arising from Exchange activities, such assets shall be maintained and safeguarded in accordance with the applicable prudential, safeguarding and reserve requirements under the Regulations.
Page 40 of 101 16. Settlement and settlement finality. — (1) An Exchange shall establish, document and maintain settlement arrangements designed to achieve timely, accurate and orderly settlement of transactions executed on its venue, having regard to the product, settlement model, underlying distributed ledger or other infrastructure used, and the associated operational, liquidity, counterparty and market risks. (2) The Exchange shall disclose to Participants: (a) the applicable settlement cycle; (b) the point at which a trade is treated as final under the Exchange’s rules and operational procedures; and (c) the circumstances in which settlement may be delayed, suspended, cancelled, reversed, or subject to close-out or default procedures. Such disclosure shall not be taken as determining the legal finality of settlement under applicable law. (3) Settlement arrangements shall be supported by appropriate reconciliations, exception management, participant communications, and default-management controls, and shall not expose Clients or the market to undue and avoidable settlement risk. (4) Where settlement is dependent on third-party infrastructure, on-chain confirmation standards, banking rails, custodial movement, or other external dependencies, the Exchange shall maintain procedures for handling delays, failures and exceptions and shall communicate material settlement disruptions to affected Participants and to the Authority without undue delay. (5) Where an Exchange’s ordinary settlement model requires a settlement cycle longer than twenty-four (24) hours because of infrastructure dependencies, market conditions, product design or another objectively justified factor, the Exchange shall notify the Authority before implementing that settlement model and shall disclose the applicable settlement cycle to Participants. A material and unexpected failure to meet the applicable settlement cycle shall be notified to the Authority without undue delay. Other settlement exceptions shall be documented and may be reported on an aggregated quarterly basis. (6) An Exchange shall complete final settlement within twenty-four (24) hours of execution, or within an alternative settlement cycle notified under sub-regulation (5), to the extent settlement is within its reasonable control. Where settlement is delayed by external infrastructure, distributed-ledger conditions, counterparties, custodians, banking rails or necessary compliance controls, the Exchange shall take reasonable steps to complete settlement and communicate any material delay to affected Participants. 17. Trading systems continuity, resilience and controls. — (1) In addition to the broader technology, cybersecurity and operational resilience requirements under the Regulations, an Exchange shall have in place effective systems, procedures and arrangements to ensure that its trading systems: (a) are resilient;
Page 41 of 101 (b) have sufficient capacity to ensure orderly trading under conditions of high uncertainty and extreme volatility; (c) are able to reject orders that exceed pre-determined volume and price thresholds or are clearly erroneous, where appropriate to the market model; (d) are fully tested to ensure that applicable conditions and controls are met; and (e) are subject to effective business continuity arrangements, including backup and disaster recovery systems, facilities and sites, to ensure continuity of services and reporting capability in the event of system failure. (2) The Exchange shall maintain and disclose procedures for handling outages, connectivity failures, Trading Halts, system degradations and resumptions of trading. (3) The Exchange shall maintain escalation and decision-making arrangements for venue-wide disruption, including criteria for halting, suspending, reopening or restricting trading. 18. Market disruption, suspension and delisting powers. — (1) An Exchange shall have documented powers and procedures to suspend, restrict or halt trading in a Virtual Asset or on the venue where necessary to preserve orderly markets, protect Clients, or respond to operational, legal or market integrity risks. (2) The Exchange shall also maintain documented procedures for the lifting of a suspension or restriction, including any conditions that must be satisfied before trading resumes. (3) The Authority may, where it has reasonable grounds to believe that a Virtual Asset, market function, or specified activity gives rise to a material risk to market integrity, Client protection, financial stability, compliance with applicable law, or any other objective of the Act, direct the Exchange to suspend, restrict, delist or cease the relevant activity. (4) Any direction under sub-regulaiton (3) shall be lawful, necessary and proportionate to the risk identified and shall specify the scope of the direction and, where practicable, the reasons for it. (5) The Exchange shall comply with any lawful direction issued under this Regulation. (6) The Exchange shall immediately communicate material suspension, restriction, halt, reopening or delisting decisions to the Authority, to affected Participants and to Clients. 19. Margin, leverage and derivatives interface. — (1) An Exchange shall not offer, list, facilitate or otherwise make available margin trading, leveraged spot products, futures, options, perpetual contracts, contracts for difference, leveraged tokens or other derivatives or leveraged products unless the Licensee holds the relevant Licence Category or the applicable and relevant permissions within such Categories required under the Act and the Regulations and such permission is expressly stated in its Licence. (2) Where an Exchange facilitates any margin or leveraged activity, it shall maintain rules, controls and disclosures addressing at least: (a) eligibility of Participants and Clients; (b) collateral and margin methodologies; (c) liquidation, close-out and default handling;
Page 42 of 101 (d) position limits, concentration risk and market integrity controls; and (e) Client risk disclosures and appropriateness controls, where applicable. (3) An Exchange shall not treat authorization to operate a trading venue as sufficient authority to conduct a standalone margin financing, lending, or derivatives business where, in substance, the relevant activity falls within another Licence Category. (4) Detailed rules on margin methodologies, collateral standards, liquidations and leveraged or derivatives products may be specified by the Authority in the applicable Regulation or by licence condition. (5) VASPs must ensure that they have sufficient assets to provide Margin Trading services in order that they can fully satisfy client obligations, at all times. 20. Authority approval and powers - (1) Authority may approve an application for the provision of Margin Trading services, provided that the VASP can demonstrate, to the Authority's satisfaction, compliance with the following requirements a) the VASP has submitted for the Authority's approval details of the terms and conditions upon which it proposes to offer Margin Trading services to clients, including a copy of the template Margin Trading Agreement to be used by the VASP, together with information relating to the VASP's financial condition and compliance with all Capital and Prudential Requirements applicable to the VASP; b) the VASP has established, and is able to demonstrate the Authority, appropriate policies and procedures as well as systems and controls with regards to Margin Trading services, which shall include but not be limited to i). the Margin which may be called, the applicable Margin rates and the method of calculating the Margin; ii). the acceptable methods of Margin payment and forms of collateral; iii). the circumstances under which a client or counterparty may be required to provide Margin and additional Margin, and the consequences of a failure to meet a Margin call, including the actions which the VASP may be entitled to take; and iv). applicable escalation procedures where a client or counterparty fails to meet Margin calls; and v). the VASP ensures, and is able to demonstrate to the Authority that Virtual Assets collected as collateral for Initial Margin and Maintenance Margin purposes are liquid and can be liquidated within a reasonable timeframe. (2) The Authority may require to inspect the Margin Trading system of the VASP used to calculate clients' Margin Trading positions and Margin and, prior to granting approval, request any other clarifications, information or documents it deems necessary. (3) Notwithstanding a VASP having approval from the Authority for the provision of Margin Trading, the Authority may instruct VASPs to take any of the following actions
Page 43 of 101 which shall be lawful, necessary and proportionate to the risk identified and shall specify the scope of the direction and, where practicable, the reasons for it, in its sole and absolute discretion from time to time, and VASPs must comply with such instructions a) suspend Margin Trading services for specified Virtual Assets or clients; b) close existing client positions; and c) increase Initial Margin and/or Maintenance Margin requirements. 21. Record-keeping. — (1) An Exchange shall keep, for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations, records sufficient to: (a) evidence compliance with this Regulation; (b) reconstruct market events, trading decisions, surveillance escalations and exchange actions; and (c) support investigations into suspected misconduct, listing decisions, disruption events or participant breaches. (2) Records shall include, at a minimum: (a) Trading Rules and amendments thereto; (b) listing, suspension and delisting assessments and decisions; (c) participant admission, refusal, suspension and termination decisions; (d) order, trade and market event data sufficient to support surveillance and reconstruction; (e) records of Trading Halts, outages, system incidents and remedial actions; (f) surveillance alerts, investigations and escalations; and (g) records relating to proprietary trading, related-party activity and conflict management decisions, where applicable. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation, reconstruction of events and effective remediation. 22. Management information, reporting and board oversight. — (1) An Exchange shall produce regular management information on matters relevant to Exchange Services, including at least: (a) trading volumes, concentration and market quality indicators; (b) listing, suspension and delisting activity; (c) surveillance alerts, investigations and outcomes; (d) system performance, outages, Trading Halts and operational incidents; (e) participant disciplinary actions and serious rule breaches; and (f) Client or participant complaints relevant to Exchange operations. (2) The Licensee’s board shall review such information at a frequency commensurate with the scale and risk of the business and shall direct remedial action where necessary. (3) An Exchange shall report to the Authority, in the manner and frequency determined by the Authority:
Page 44 of 101 (a) material breaches of this Regulation or applicable market conduct requirements; (b) serious or systemic trading, surveillance, technology or settlement failures; (c) material changes to listing standards, Trading Rules or market structure; (d) significant incidents of suspected Market Abuse; and (e) any other matter that the Authority may reasonably require for supervisory purposes. (4) The Authority may require the Exchange to provide additional information, management attestations, remediation plans, file reviews or thematic data, and may direct the Exchange to take specific remedial measures. Lending and Borrowing Services Regulations
Page 45 of 101 (a) facilitate or enter into collateralized or uncollateralized Lending Arrangements involving Virtual Assets; (b) provide borrowing, lending, margin lending, or similar financing arrangements linked to Virtual Assets; and 4. Governance and risk oversight. — (1) The Licensee’s board shall approve and oversee the Lending and Borrowing business, including the following: (a) product design, approval, review and eligibility criteria for Clients; (b) risk appetite and limits for credit, concentration, liquidity, market and operational risks; (c) collateral, margin and liquidation policies; (d) target-market determinations, where applicable; and (e) governance over any Re-use of Client Assets, if lawfully permitted. (2) Senior management shall implement policies, procedures and controls to manage risks arising from Lending and Borrowing Services, including credit, concentration, liquidity, market, technology, operational and legal enforceability risks, and shall ensure that those risks are reflected in the Licensee’s prudential, capital and liquidity planning under the Regulations. (3) A Licensee shall maintain adequate governance, reporting lines, escalation procedures and management information to enable effective oversight of asset sufficiency, collateral adequacy, withdrawal obligations, counterparty exposure, concentration risk and Client asset protection. (4) The Licensee’s board shall review the Lending and Borrowing business at a frequency commensurate with its scale and risk and shall direct remedial action, where required. 5. Policies, procedures and control framework. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Lending and Borrowing Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) product design and approval; (b) Client onboarding and eligibility; (c) credit assessment and counterparty due diligence; (d) collateral eligibility, valuation, margining and liquidation; (e) liquidity management and asset sufficiency; (f) withdrawal rights and restrictions; (g) the use, holding, safeguarding and any permitted Re-use of Client Assets; (h) valuation, reporting and record-keeping; (i) stress-testing and contingency planning; (j) outsourcing and third-party arrangements; and (k) such other matters as the Authority may reasonably require. (2) A Licensee shall assess and, in any event, at least annually review the effectiveness of those policies and procedures and take appropriate measures to address any deficiency.
Page 46 of 101 (3) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that they are appropriate to the Licensee’s business, legally and operationally applicable in Pakistan, and sufficient to ensure compliance with the Act, the Regulations and this Regulation. 6. Product governance and target market. — (1) A Licensee shall not offer a Lending Arrangement unless it has assessed the nature, legal character, risks, collateral profile, liquidity profile and operational dependencies of the arrangement and is satisfied that the arrangement is consistent with the Act, the Regulations, this Regulation and the terms of its Licence. (2) A Licensee shall identify the target market, if any, for each material type of Lending Arrangement and shall ensure that the arrangement is distributed only to those categories of Clients for whom it is appropriate. (3) A Licensee shall not design, market or distribute a Lending Arrangement in a manner that obscures the legal character of the arrangement, the use of Client Assets, the existence of lockups or notice periods, or the order in which losses may be borne. (4) The Licensee shall periodically review each material product type and suspend, restrict or withdraw it where it no longer remains appropriate or where it presents material and unmanaged risks to Clients or to the Licensee. 7. Client disclosures and agreements. — (1) A Licensee providing Lending and Borrowing Services shall disclose to Clients, in a clear, fair, timely and not misleading manner, material information including at least the following: (a) the nature and terms of the Lending Arrangement; (b) whether the arrangement is pooled, bilateral, principal-based, agency-based, margin-based or otherwise; (c) interest, fees and charges, including whether interest is simple or compound, fixed or variable, and how it is calculated, adjusted and paid; (d) collateral requirements, valuation methodologies, loan-to-value ratios, margin calls and liquidation triggers; (e) withdrawal rights, notice periods, lock-ups, gates, delays or other restrictions; (f) risks associated with price volatility, liquidity mismatch, counterparty default, rehypothecation or other Re-use, liquidation, operational failure and legal enforceability; and (g) whether and on what terms Client Assets may be Re-used, including the categories of counterparties to whom assets may be exposed. (2) Client Agreements shall be clear, fair and not misleading and shall comply with the market conduct requirements under the Regulations. (3) In addition to general Client Agreement requirements under the Regulations, a Client Agreement for Lending and Borrowing Services shall, to the extent applicable, set out clearly the following: (a) the nature of the Lending Arrangement;
Page 47 of 101 (b) descriptions of the assets lent, borrowed or used as Collateral sufficient to identify them; (c) rights of the parties with respect to custody, use and return of lent assets and Collateral; (d) interest basis, rate determination, payment frequency and adjustment mechanisms; (e) withdrawal rights, applicable notice periods and any lock-ups; (f) defaults, Liquidation Events and associated recovery mechanisms, including the order of application of Collateral and any shortfall allocation, and a clear statement that the relevant arrangement is not equivalent to custody or safekeeping arrangements; (g) whether and on what terms the Licensee may Re-use Client Assets and the Client’s explicit consent thereto where required; (h) termination rights and consequences of termination; and (i) the Licensee’s complaints procedure and escalation channels. 8. Liquidity and asset sufficiency. — (1) A Licensee offering Lending and Borrowing Services shall at all times maintain sufficient Virtual Assets and/or fiat to meet its contractual obligations to Clients when due, taking into account the following: (a) the maturity profile of Lending Arrangements; (b) agreed withdrawal rights; (c) haircut, margin and Collateral requirements; (d) potential stressed outflows; and (e) any concentration in counterparties, assets, maturities or funding sources. (2) A Licensee shall not operate a Lending and Borrowing business model that results in a structural or persistent mismatch between its obligations to Clients and the assets available to meet those obligations. (3) The Licensee shall implement governance controls, monitoring frameworks and usagetracking mechanisms capable of: (a) identifying emerging shortfalls in assets, Collateral or liquidity; and (b) triggering escalation to senior management and the Authority where a shortfall arises or is reasonably foreseeable. (4) The Licensee shall notify the Authority without undue delay where it is, or is likely to be, unable to meet its obligations to Clients in respect of Lending Arrangements. (5) A Licensee shall not represent a Lending Arrangement as withdrawable on demand, or as low-risk or equivalent to custody, unless that representation is accurate having regard to the legal terms, liquidity profile and use of assets within the arrangement. 9. Withdrawal rights and restrictions. — (1) Clients’ contractual rights to withdraw Virtual Assets or fiat from Lending Arrangements must be clearly documented in the Client Agreement, including the following: (a) whether assets are redeemable on demand, subject to notice, or locked up; (b) any minimum or maximum withdrawal amounts;
Page 48 of 101 (c) any fees or penalties for early withdrawal; and (d) the circumstances in which withdrawals may be delayed, gated, suspended or otherwise restricted. (2) Where withdrawal rights are restricted as part of a Lending Arrangement, the Licensee shall: (a) disclose such restrictions clearly before the Client enters the arrangement; and (b) ensure that marketing and communications are consistent with those restrictions and are not misleading. (3) Where withdrawals are permitted, the Licensee shall ensure that transfers out are executed in accordance with the Transfer and Settlement Services Regulation and the Custody Services Regulation, except where delayed due to factors outside the Licensee’s control, in which case the Licensee shall promptly inform affected Clients. 10. Collateral management. — (1) A Licensee shall establish and maintain written policies governing the acceptance, valuation, monitoring and liquidation of Collateral, ensuring such policies remain prudent, transparent and appropriate to the nature, scale and complexity of the activity. (2) Collateral policies shall address, at a minimum: (a) eligible Collateral types and any concentration limits; (b) valuation methodologies, frequency of revaluation and application of haircuts; (c) initial and variation margin requirements and triggers, including automated triggers where operationally feasible; (d) Collateral liquidation processes, including priority of application of proceeds; and (e) governance over exceptions, overrides and non-standard Collateral. (3) Where Collateral consists of Client Virtual Assets or Client Money, the Licensee shall ensure that Collateral arrangements are consistent with the safeguarding requirements in the Regulations and any applicable Custody Services Regulation requirements. (4) Eligible Collateral shall consist of assets that are liquid, readily realizable and capable of valuation using observable market data or otherwise conservative methodologies appropriate to the relevant risk. High-quality Collateral may include cash, cash equivalents, short-term government securities of high credit quality, high-quality liquid Fiat-Referenced Tokens and Asset-Referenced Tokens, and specified Virtual Assets with deep and demonstrable liquidity, subject to appropriate haircuts. (5) Collateral shall only be used in accordance with governing agreements and the terms of the relevant Lending Arrangement. 11. Use and Re-use of Client Assets. — (1) Client Assets, including lent assets and Collateral, shall not be Re-used, lent on, pledged, rehypothecated, staked or otherwise deployed for the Licensee’s own benefit or for third parties unless: (a) such use is permitted by applicable law and the Pakistan Virtual Asset Services Regulations, 2026;
Page 49 of 101 (b) the Client’s explicit, prior, informed consent has been obtained and should be utilized within the limits clearly defined by the client; and (c) the scope, risks, withdrawal implications and counterparties or categories of counterparties relevant to such use are clearly set out in the Client Agreement. (2) Where Re-use is permitted, the Licensee shall maintain: (a) Prior, explicit written consent of the clients for the re-use of such assets; (b) records of which assets are Re-used, with whom and under what terms; (c) additional risk management and, where required, capital or liquidity buffers to reflect the increased risk to Clients; and (d) a clear understanding and documentation of the resulting exposure of Clients to counterparty, liquidity and market risks arising from such re-use. (3) A Lending and Borrowing authorization does not disapply or dilute the safeguarding standards applicable to Client Money and Client Virtual Assets under the Regulations. (4) The Licensee shall not obscure Re-use of Client Assets by describing the arrangement as “custody”, “safekeeping” or other language suggesting that the assets remain fully insulated from lending counterparty risk where that is not the case. 12. Counterparty due diligence and credit assessment. — (1) A Licensee shall conduct comprehensive due diligence on Borrowers and lending counterparties on a periodic basis, including: (a) identity verification and beneficial ownership; (b) business purpose and economic rationale of the Lending Arrangement; (c) financial strength, liquidity and leverage; (d) market, concentration and country risk; and (e) any other information that a prudent lender would require to assess the risks associated with the arrangement. (2) Risk profiles shall be updated periodically and whenever a material change occurs in a counterparty’s risk profile. (3) The Licensee shall integrate such assessments into its credit-risk limits, Collateral requirements, pricing, tenor limits and exposure management. (4) Before providing any Lending and Borrowing Services on behalf of a third party, the Licensee shall ensure that sufficient steps are taken on behalf of that third party to meet applicable requirements. 13. Risk management framework and stress-testing. — (1) In addition to the governance and prudential requirements under the Regulations, a Licensee shall maintain a riskmanagement framework for Lending and Borrowing Services covering, at a minimum: (a) credit risk, including Borrower default and counterparty failure; (b) market risk, including price volatility of lent assets and Collateral; (c) liquidity risk, including the ability to meet withdrawals and obligations; (d) operational and technology risk; and
Page 50 of 101 (e) legal and enforceability risk, including Collateral realization and close-out risk. (2) The Licensee shall ensure that liquidity risk and market risk are each monitored and tested regularly, and that appropriate measures are put in place to address such risk promptly. (3) The Licensee shall conduct periodic stress-tests tailored to its Lending and Borrowing portfolio, including scenarios involving: (a) sharp market declines in Collateral and lent asset values; (b) concentrated Borrower defaults; (c) spikes in withdrawal demands; and (d) combined scenarios of market, liquidity and counterparty stress. (4) Stress-test results shall be reported to the Licensee’s board and used to adjust limits, Collateral requirements and contingency plans. 14. Liquidation, close-out and default management. — (1) A Licensee shall maintain documented policies and procedures governing margin calls, top-up requirements, Liquidation Events, close-out and enforcement of Collateral. (2) Such procedures shall be transparent, non-discriminatory, consistent with Client disclosures and reasonably designed to minimize disorderly liquidation and avoidable harm to Clients. (3) Procedures shall address at least: (a) triggers for margin calls and Liquidation Events; (b) notice, where commercially and operationally appropriate; (c) methods for valuing Collateral during stressed conditions; (d) priority and sequence of asset liquidation; (e) treatment of shortfalls, excess proceeds and fees; and (f) communication with Clients and the Authority where material disruption or deficiency arises. (4) A Licensee shall not rely on discretionary or opaque liquidation powers that are materially inconsistent with its Client Agreement or disclosures. 15. Client reporting and valuation. — (1) A Licensee shall furnish to each Client, at least monthly and more frequently where necessary having regard to the product or risk profile, statements showing: (a) total asset holdings of the Client subject to Lending Arrangements; (b) lending and borrowing transactions executed during the period; (c) interest accrued or payable; (d) Collateral posted, required and any margin calls; and (e) any liquidations, forced close-outs, defaults or other material events affecting the Client’s positions. (2) Statements shall be clear, timely and accessible and retained for at least the minimum period required under applicable law and the Regulations. (3) Where market prices are not readily observable, the Licensee shall: (a) use conservative valuation techniques; and
Page 51 of 101 (b) disclose to Clients the limitations and uncertainties in such valuations. (4) The Licensee shall have comprehensive and documented valuation policies and procedures sufficient to support prudent risk management, accurate Client reporting and supervisory review. 16. Public disclosures and transparency. — (1) A Licensee offering Lending and Borrowing Services shall, in a prominent place on its website or via other accessible means approved by the Authority, disclose at least: (a) the principal risks to Client assets, including volatility, counterparty and liquidity risk; (b) the Licensee’s use-of-funds policy, including whether Client assets are on-lent and, if so, to what categories of counterparties; (c) Collateral policies, including acceptable Collateral types, haircuts and margin practices; (d) material concentrations of counterparty exposure, in aggregated and appropriately anonymized form; and (e) governance, reporting and assurance arrangements relating to assets and liabilities, updated at a frequency appropriate to the business model and, in any event, not less frequently than quarterly where the Authority so requires. (2) A Licensee shall also publish a clear explanation of: (a) its Lending and Borrowing Services; (b) which services are available to which Client types; and (c) any licensing and regulatory restrictions on such services. (3) A Licensee shall not be required to publish a fixed-format public asset-and-liability report every three months in all cases, unless the Authority specifically requires such publication. Instead, the Authority may specify the form, content and frequency of any public prudential or transparency disclosure having regard to the Licensee’s business model and risk profile. 17. Record-keeping. — (1) A Licensee shall keep complete and accurate records of all Lending Arrangements, including: (a) Client agreements and consents; (b) transaction histories; (c) Collateral movements and valuations; (d) margin calls and responses; and (e) defaults, restructurings, recoveries, liquidations and other material events. (2) The Licensee shall maintain records sufficient to confirm and identify all Client positions and to demonstrate compliance with this Regulation and the Regulations. (3) Records shall be retained for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law and the regulations and shall be made available to the Authority upon request.
Page 52 of 101 18. Outsourcing and third-party arrangements. — (1) Where a Licensee relies on third parties for credit assessment, Collateral management, valuation, servicing, technology, wallet infrastructure, collection or recovery functions, the Licensee shall remain fully responsible for compliance with this Regulation and the Regulations. (2) Such arrangements shall comply with applicable outsourcing and third-party risk requirements under the Regulations and shall include appropriate rights of access, audit, oversight, information and termination. (3) The Licensee shall monitor third-party performance, conflicts, concentration risk and dependency risk on an ongoing basis. Management and Investment Services Regulations
Page 53 of 101 (3) For the avoidance of doubt, Management and Investment Services may include responsibility for staking on behalf of Clients where such staking is performed on a discretionary basis or forms part of a broader investment management Mandate. Where the relevant staking structure also falls within another regulated activity, the Licensee shall comply with the applicable Regulation and any related licence condition to the extent relevant. 3. Nature and perimeter of Management and Investment Services. — (1) A Licensee shall not hold itself out as providing Management and Investment Services unless it is authorised for that Licence Category. (2) A Licensee providing Management and Investment Services may, subject to its Licence and the Act and Regulations: (a) act in a fiduciary, agency or similar capacity for the purpose of managing or administering another Customer’s Virtual Assets; (b) carry out portfolio management services for one or more identified Customers; (c) provide discretionary or non-discretionary portfolio or investment management involving Virtual Assets; (d) operate, manage or administer a managed investment arrangement involving Virtual Assets, to the extent permitted under applicable law; and (e) undertake ancillary functions necessary for the operation of such services, subject to compliance with all applicable safeguarding, prudential, technology and conduct requirements, and provided that such functions do not constitute a separate regulated activity requiring an additional Licence Category under the Regulations. (3) Where a Portfolio includes derivatives, leverage, lending, liquidity provision, or other features requiring another Licence Category, the Licensee shall hold the relevant Licence Category and comply with the applicable Regulation and any related Licence condition to the extent relevant. Where a Portfolio includes staking, the Licensee shall determine the applicable regulatory treatment having regard to whether the staking is discretionary, non-discretionary, custodial or otherwise structured, and further having regard to the fact that prior written informed, explicit client consent has been obtained and kept on record, and shall comply with any applicable Regulation and licence condition accordingly. 4. Governance and fiduciary responsibility. — (1) The Licensee’s board shall approve and oversee the provision of Management and Investment Services, including: (a) investment strategies; (b) risk appetite and limits; (c) conflicts of interest arrangements; (d) Mandate structures and target-market determinations; and (e) valuation, reporting and Client asset use controls. (2) A Licensee shall ensure that Management and Investment Services are conducted in accordance with approved policies, procedures and applicable regulatory obligations.
Page 54 of 101 (3) A Licensee providing Discretionary Management shall act in the best interests of Clients and exercise due skill, care and diligence in carrying out its responsibilities. (4) The Licensee shall maintain adequate governance, reporting lines, escalation procedures and management information to enable effective oversight of strategy risk, liquidity risk, market risk, operational incidents, concentration risk, valuation risk, Client asset use risk and Client protection issues. 5. Policies, procedures and control framework. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Management and Investment Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) Mandate design, approval and review; (b) portfolio construction, rebalancing and monitoring; (c) asset selection criteria and any listing or delisting triggers relevant to managed strategies; (d) risk limits, including concentration, leverage, liquidity and counterparty limits; (e) order handling, execution and trading venue selection; (f) suitability, appropriateness and Client onboarding; (g) conflicts of interest, inducements and personal account dealing; (h) valuation and performance measurement; (i) use of Client Assets, including any permitted staking, lending, liquidity provision or other yield strategies; (j) periodic reporting and public disclosures; (k) outsourcing and third-party dependencies; and (l) such other matters as the Authority may reasonably require. (2) The Licensee shall assess and, in any event, at least annually review the effectiveness of those policies and procedures and take appropriate measures to address any deficiency. (3) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that they are appropriate to the Licensee’s business, legally and operationally applicable in Pakistan, and sufficient to ensure compliance with the Act, the Regulations and this Regulation. 6. Public disclosures. — (1) A Licensee providing Management and Investment Services shall publish on its website, or make available through another publicly accessible means approved by the Authority, clear, fair and not misleading disclosures, including at least: (a) a description of the services offered, including whether the service is discretionary, non-discretionary, model-based, mandate-based or otherwise; (b) broad investment strategies and asset classes in scope; (c) material risk factors, including market, liquidity, protocol, custody, operational, leverage and concentration risks, where relevant;
Page 55 of 101 (d) fee structures, including Performance Fees where applicable; (e) whether Client Assets may be used in connection with staking, lending, liquidity provision, leverage or similar strategies, and the principal risks of such use; (f) high-level information on order execution and venue selection practices, where relevant; (g) historical quarterly and annual performance of VASP in relation to managing different funds and/or investment portfolios; (h) a statement as to how liquidity risk is managed i) the Licensee’s policies relating to data privacy, complaints handling and whistleblowing; and (j) such other information as the Authority may reasonably require. (2) A Licensee shall not represent in any marketing material that its Management and Investment Services are: (a) risk-free or capital-guaranteed; or (b) equivalent to staking-only, custody-only or yield-only services, where the service involves active management, market exposure or investment discretion. (3) Where a service includes staking or protocol-based rewards as part of a broader Mandate, marketing shall fairly describe that component and the associated risks, including slashing, lock-up, unbonding, liquidity and protocol risks. (4) Disclosures under this regulation shall be kept current and reviewed whenever a material change occurs. 7. Client onboarding, suitability and appropriateness. — (1) A Licensee shall establish and maintain processes to assess the suitability or appropriateness of Management and Investment Services for each Client, having regard to: (a) the Client’s investment objectives; (b) risk tolerance; (c) financial circumstances; and (d) knowledge and experience relating to Virtual Assets and relevant strategies. (2) Where a service is assessed as not suitable or not appropriate, the Licensee shall: (a) provide a clear warning to the Client; or (b) refrain from providing the service, where doing so would be inconsistent with law, regulation, Licence conditions, internal risk policies or the Licensee’s duties to act fairly and professionally. (3) The Licensee shall collect all necessary information from Clients for the purpose of assessing relevant factors depending on the nature of the service and shall take reasonable steps to ensure such information is accurate and up to date. (4) The Licensee shall maintain procedures for periodic review of Client information and Mandate suitability, particularly where there is a material change in strategy, risk profile, market conditions or the Client’s known circumstances.
Page 56 of 101 (5) The Licensee shall maintain records of suitability and appropriateness assessments for at least the minimum period required under applicable law and the Regulations. 8. Mandate definition and approval. — (1) A Licensee shall not provide Management and Investment Services to a Client unless a documented Mandate has been agreed with that Client. (2) The Mandate shall set out, at a minimum: (a) the Client’s investment objectives, risk tolerance and time horizon; (b) whether the service is discretionary or non-discretionary; (c) the types of Virtual Assets, strategies, products or protocols in scope; (d) any restrictions, including whether derivatives, leverage, staking, lending, liquidity provision, yield strategies or unlisted tokens are permitted; (e) any diversification, concentration, liquidity, custody or counterparty limits; (f) the basis on which fees and charges are calculated; and (g) the circumstances in which the Mandate may be varied, suspended or terminated. (3) The Licensee shall maintain procedures for approving, monitoring and reviewing Mandates and any material amendment to a Mandate. (4) The Licensee shall not depart materially from a Mandate unless— (a) the departure is necessary to protect the Client or preserve the Portfolio in exceptional circumstances; (b) the departure is consistent with the Client Agreement and applicable law; and (c) the reasons for the departure are documented, recorded, and communicated to the Client. 9. Portfolio construction, execution and portfolio management. — (1) A Licensee providing Discretionary Management shall establish policies and procedures governing: (a) portfolio construction; (b) execution and order handling; (c) portfolio monitoring; and (d) rebalancing. (2) Investment and execution decisions shall be taken in the best interests of Clients and on the basis of fair, reasonable and consistently applied criteria. (3) The Licensee shall establish documented rules or methodologies for portfolio allocation, rebalancing, risk monitoring and deviations from Model Portfolios or strategy guidelines. (4) Where Client Orders are routed or transmitted to a trading venue, Broker-Dealer or other intermediary, the Licensee shall ensure prompt and proper transmission of those instructions and shall maintain controls over venue selection, execution quality and allocation fairness. (5) The Licensee shall not receive any remuneration, discount or other benefit for routing Client Orders to a particular trading platform or service provider unless that arrangement is disclosed in the Client Agreement, managed as a conflict of interest, and consistent with the Licensee’s duty to act in the best interests of Clients.
Page 57 of 101 10. Conduct and Client first duty. — (1) A Licensee providing Management and Investment Services shall act honestly, fairly and professionally in accordance with the best interests of its Clients. (2) In assessing a Client’s best interests, the Licensee may take into account factors including, but not limited to, Client suitability, price of Virtual Assets, costs, speed, likelihood of execution and settlement, transaction size, custody arrangements, liquidity profile and any other relevant conditions, provided that the Licensee shall act in accordance with any specific instructions provided by the Client where the service is non-discretionary. (3) The Licensee shall not: (a) misuse information relating to Clients’ Virtual Assets, Portfolios, positions, strategies or orders; or (b) allow proprietary trading or related-party dealings to improperly benefit from knowledge of Client positions or orders. (4) The Licensee shall maintain policies on personal account dealing by relevant staff that prohibit front-running, misuse of confidential information and other abusive conduct. 11. Conflicts of interest and inducements. — (1) A Licensee shall identify, prevent, manage and, where appropriate, disclose conflicts of interest arising in the provision of Management and Investment Services. (2) Such conflicts shall include, where relevant: (a) simultaneous management of multiple Client Portfolios; (b) management of proprietary or related-party Portfolios alongside Client Portfolios; (c) receipt of fees, rebates or other benefits from trading venues, counterparties, issuers, validators or protocol operators; (d) allocation of limited investment opportunities among Clients or between Clients and proprietary accounts; and (e) any interest in assets, protocols, issuers or service providers included in a Client Portfolio. (3) Inducements, commissions or other benefits shall be structured and managed in a manner that does not impair the Licensee’s obligation to act in the best interests of Clients. (4) Where a material conflict cannot be effectively prevented or otherwise managed, it shall be disclosed to the Client clearly and before the relevant action is taken. 12. Use of Client Assets in management services. — (1) Whether or not Client Virtual Assets used by a Licensee in the course of Management and Investment Services are held on behalf of the Client shall be clearly stated in the Client Agreement. (2) Where the use, lending, staking, rehypothecation, liquidity provision, leverage deployment or other deployment of Client Virtual Assets requires the Client’s consent under the Act or the Regulations and within the limits clearly defined by the Client, the Licensee shall obtain the Client’s explicit, prior and informed consent and shall clearly disclose the nature of the activity,
Page 58 of 101 the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated. (3) The Licensee shall clearly explain the increased risks where Client Assets are used, including: (a) the likelihood and severity of potential losses; and (b) the impact on the Client’s ability to withdraw or realize those assets. (4) The Licensee shall not use, lend, stake, pledge, encumber or otherwise deploy Client Assets except: (a) as required to execute an instruction of the Client or implement an agreed Mandate in accordance with the Client Agreement and the Regulations; or (b) where expressly permitted under the Act or the Regulations and, where applicable, supported by the Client’s consent in accordance with sub-regulation (2). (5) Any rewards, proceeds or benefits attributable to Client Virtual Assets, including gains, rewards, interest, airdrops, forks or staking rewards, shall accrue to the Client unless otherwise agreed with the Client in advance in the Client Agreement and disclosed in a fair, clear and not misleading manner. (6) A Licensee shall not take ownership of Client Virtual Assets under any Client Agreement except as expressly permitted under the Regulations. 13. Client Agreements – minimum content. — (1) In addition to all general Client Agreement requirements under the Regulations, Client Agreements for Management and Investment Services shall set out the following, to the extent applicable: (a) a description of the Virtual Assets in scope of the Mandate sufficient to identify them; (b) the respective rights of the Licensee, the Client and any other relevant Person in respect of the Portfolio and any staking or yield components; (c) how and when any proceeds, gains, rewards or interest are paid or payable and, in the case of variable proceeds, how they are calculated and communicated; (d) whether Client Virtual Assets shall be held on behalf of the Client and in what form; (e) the Client’s explicit, informed, written prior consent for any use of Client Virtual Assets by the Licensee and shall clearly disclose the nature of the activity, the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated; (f) any right of the Client to withdraw Virtual Assets during the Mandate, including any notice, lock-up or gating provisions; (g) any rights of the Licensee to vary the terms of the Client Agreement; (h) any rights of the Licensee and the Client to terminate the Mandate and the consequences of termination, including settlement, unwinding and treatment of open positions or staked assets; (i) any terms relating to fluctuation in the value of Virtual Assets to which the Mandate relates;
Page 59 of 101 (j) consequences of any event of default; (k) an explanation of the risks to which the Client may be exposed; (l) full details of the Licensee’s Client complaints procedure; and (m) whether the Licensee receives any remuneration, discount or other benefit for routing Client Orders to a particular trading platform or service provider. (2) Client Agreements shall be clear, fair and not misleading and shall be updated or supplemented where a material change occurs. 14. Valuation and pricing. — (1) A Licensee shall establish and apply reasonable and consistently applied methodologies for determining the value of Virtual Assets and managed Portfolios for the purposes of Client reporting, performance calculation, fee calculation, risk management and record-keeping. (2) Where reliable and observable market prices are available, the Licensee shall ordinarily use such market prices or pricing derived from reasonably available market sources. (3) Where market prices are not readily observable, are materially unreliable, or do not reasonably reflect the value of the relevant Virtual Asset or Portfolio position, the Licensee shall apply prudent and consistently applied alternative valuation methodologies and document the basis for doing so. (4) Valuation methodologies, pricing sources and any material assumptions shall be documented and applied consistently. (5) A Licensee shall not use valuation methodologies in a manner that materially misrepresents Portfolio value, performance, risk or fees. 15. Client reporting, performance measurement and transparency. — (1) A Licensee shall provide Clients with periodic reports relating to: (a) portfolio performance; (b) fees and charges; (c) Portfolio composition and valuation; (d) transactions during the reporting period; and (e) changes affecting the managed Portfolio. (2) Reports shall be clear, accurate and provided at appropriate intervals, and in any event not less frequently than quarterly unless a more frequent reporting period is required by the nature of the service, the Mandate, the Client category or a direction of the Authority. (3) Where the service involves higher frequency trading, leverage, derivatives, liquidity risk or use of Client Assets, the Licensee shall provide more frequent reporting where necessary for fair and effective Client understanding. (4) Periodic reports shall include, where applicable: (a) the total value of Virtual Assets in the Client’s account or Portfolio; (b) all transactions entered into during the reporting period; (c) changes in amount and valuation of assets during the reporting period; (d) any fees, Performance Fees, expenses or charges deducted; and
Page 60 of 101 (e) any material operational, protocol, custody, liquidity or counterparty event affecting the Portfolio. (5) Performance measurement methodologies shall be documented, consistently applied and not presented in a misleading manner. 16. Fees and charges. — (1) No payment may be made, or benefit given, to the Licensee out of any Virtual Assets under its management, whether by way of fees for its services, reimbursement of expenses or otherwise, unless: (a) it is permitted by the Client Agreement; and (b) the Client Agreement specifies how it will be calculated and accrued, and when it will be paid. (2) A Licensee shall not introduce any new category of fees, nor increase the rate or amount of existing fees payable out of assets under management, unless the Licensee has provided Clients with prior written notice of such introduction or increase and its effective date. (3) The Authority may prescribe minimum notice standards for fee changes by direction, circular or other written instrument. (4) Performance Fees, where used, shall be structured and disclosed in a fair, clear and not misleading manner and shall not incentivize conduct inconsistent with the best interests of Clients. 17. Risk management and due diligence. — (1) In addition to requirements under the Regulations and all other applicable instruments of the Authority, a Licensee shall ensure that liquidity risk and market risk in respect of Management and Investment Services are monitored and tested regularly, and that appropriate measures are put in place to address such risks promptly. (2) The Licensee shall maintain a risk-management framework covering, at a minimum: (a) market risk; (b) liquidity risk; (c) custody and safeguarding risk; (d) counterparty and venue risk; (e) valuation risk; (f) leverage and derivatives risk, where relevant; and (g) operational and technology risk. (3) Due diligence on assets, venues, counterparties, validators, protocols or other service providers used within Client Portfolios shall be proportionate to the nature of the strategy and documented appropriately. (4) Risk-management and due-diligence arrangements shall be subject to periodic internal assurance, compliance, risk, internal audit or external review appropriate to the nature, scale and complexity of the business. (5) The Licensee shall provide such risk-management and due-diligence materials to the Authority upon request.
Page 61 of 101 18. Record-keeping. — (1) A Licensee shall keep complete and accurate records of all Management and Investment activities, including: (a) Client Agreements and Mandates; (b) suitability and appropriateness assessments; (c) Portfolio allocations, transactions, rebalancing and performance records; (d) valuation methodologies, valuation records and pricing sources; (e) conflict management decisions and inducement records; (f) consents relating to Client Asset use; (g) fee calculations and deductions; and (h) complaints, incidents, remediation actions and communications with Clients relating to material matters. (2) Records shall be retained for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law and regulations and shall be made available to the Authority upon request. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation and reconstruction of events. Transfer and Settlement Services Regulations
Page 62 of 101 (f) “Transfer and Settlement Services” means the activity as defined in schedule I of the Act; and (g) “Transfer Instruction” means any instruction from or on behalf of a Client to send, transmit, transfer, settle, redeem, burn or otherwise move a Virtual Asset or related obligation. (3) For the avoidance of doubt, this Regulation applies to transfer and settlement activity whether conducted on-chain, off-chain, through internal ledgers, through banking rails, or through hybrid arrangements. 3. Nature and perimeter of Transfer and Settlement Services. — (1) A Licensee shall not hold itself out as providing Transfer and Settlement Services unless it is authorised for that Licence Category or is otherwise permitted under the Act or Regulations to perform such activity in connection with another licensed activity. (2) A Licensee provides Transfer and Settlement Services where, as a business or service for or on behalf of another person, it initiates, routes, transmits, processes, settles or completes the movement of Virtual Assets or related obligations between Clients, between a Client and a third party, or as part of another Virtual Asset Service. (3) A Transfer and Settlement authorization does not, of itself, authorize the Licensee to operate an exchange, provide discretionary management, provide standalone custody, provide lending and borrowing, provide derivatives, or conduct issuance activity other than the transfer and settlement elements of those activities to the extent separately authorised or otherwise permitted under the Act or Regulations. (4) Where transfer and settlement functions are provided as part of Exchange Services, BrokerDealer Services, Custody Services, Issuance Services, or other licensed activities, the Licensee shall comply with this Regulation in addition to the Regulation applicable to the primary activity. 4. Governance and oversight. — (1) The Licensee’s board shall approve and oversee arrangements for the licensed services, including the following: (a) settlement models and cycles; (b) risk controls for operational, liquidity, counterparty and settlement risk; (c) participant or user access criteria, where the Licensee operates or administers settlement arrangements; and (d) escalation and incident-management frameworks for transfer and settlement failures. (2) A Licensee shall implement policies, procedures and controls to ensure the safe, timely and accurate execution of transfers and settlements in accordance with the Act, the Regulations and this Regulation. (3) A Licensee shall maintain adequate governance, reporting lines and management information to enable effective oversight of transfer and settlement risks, third-party dependencies, settlement failures, Client protection issues and operational incidents.
Page 63 of 101 5. Policies, procedures and control framework. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Transfer and Settlement Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) receipt, validation and execution of Transfer Instructions; (b) routing logic and destination verification; (c) settlement cycles, cut-off times and Settlement Finality; (d) reconciliation between internal records and on-chain, off-chain or account balances; (e) handling of Failed Transfers, delayed transfers, erroneous transfers and disputed transfers; (f) communication with Clients and counterparties in relation to transfer status, failures and exceptions; (g) safeguarding and treatment of Client Assets used in transfer and settlement processes; (h) Travel Rule and other AML/CFT/CPF controls relevant to transfers; (i) outsourcing and Third-Party Settlement Arrangements; (j) default, close-out, suspension and termination procedures where the business model includes participant obligations, prefunding, collateral, netting or similar arrangements; and (k) such other matters as the Authority may reasonably require. (2) A Licensee shall assess and, in any case, at least annually review the effectiveness of its policies and procedures and take appropriate measures to address any deficiency. (3) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that they are appropriate to the Licensee’s business, legally and operationally applicable in Pakistan, and sufficient to ensure compliance with the Act, the Regulations and this Regulation. 6. General prudential and legal compliance requirements. — (1) A Licensee providing Transfer and Settlement Services shall comply with all applicable laws of Pakistan relevant to transfer, settlement, remittance, payments, foreign exchange, sanctions, AML/CFT/CPF, consumer protection and related matters, to the extent such laws apply to the Licensee or the relevant activity. (2) Nothing in this Regulation shall be construed as deeming the Licensee subject to every legal regime of every foreign jurisdiction connected to a transfer or settlement. (3) Where a transfer or settlement has a cross-border element, the Licensee shall identify and manage the resulting legal, sanctions, AML/CFT/CPF, operational, and settlement risks on a risk-based basis in compliance with applicable AML framework. (4) A Licensee shall not market or represent its service as able to complete a transfer or settlement in circumstances where it knows, or ought reasonably to know, that the relevant
Page 64 of 101 transfer route, network, bank rail, counterparty arrangement or destination infrastructure is materially constrained or unavailable. 7. Integrity and accuracy of transfers. — (1) A Licensee shall establish controls to ensure the integrity and accuracy of transfers and settlements, including at least: (a) pre-execution validation of Transfer Instructions; (b) verification of destination details, including wallet addresses, account identifiers or equivalent routing details; (c) reconciliation between internal records and on-chain or account balances; and (d) error-prevention measures, including limits, validation checks and other controls appropriate to the business model. (2) A Licensee shall maintain documented procedures for handling Failed Transfers, delayed transfers, erroneous transfers and disputed transfers, including: (a) identification and escalation; (b) timely communication with affected Clients and counterparties; (c) remediation; and (d) where appropriate, compensation arrangements. (3) The Licensee shall not process a Transfer Instruction where available information gives rise to a material concern that the destination is invalid, incomplete, inconsistent with the Client’s instruction, or otherwise gives rise to a material risk of error, fraud, sanctions breach or loss, unless the issue is first resolved. 8. Authorization and Client instructions. — (1) A Licensee shall have procedures for ensuring that all Transfer and Settlement Services carried out for a Client are authorised by the relevant Client or other person lawfully entitled to give the relevant instruction, and that the Licensee acts in accordance with that instruction at all times. (2) A Licensee shall keep records of all Client instructions and any material amendment, cancellation, rejection, failure or execution event for at least the minimum period required under applicable law and the Regulations. (3) A Licensee shall implement controls to authenticate the origin of instructions, prevent unauthorized execution, and detect anomalies, fraud indicators or suspicious activity. (4) Where the Licensee receives conflicting, ambiguous or incomplete instructions, it shall suspend execution until the issue is clarified or otherwise resolved in accordance with documented procedures. 9. Responsibility for execution and failed transfers. — (1) A VASP shall be responsible for executing the Transfer Instruction in accordance with the Client’s instructions and its disclosed service conditions. (2) Where a transfer or settlement is not executed, is defectively executed, or is incomplete due to a failure attributable to the Licensee, the Licensee shall take prompt remedial action,
Page 65 of 101 including tracing, correction, reversal, restoration or compensation, as appropriate to the circumstances and applicable law. (3) A Licensee shall not be required under this Regulation to guarantee settlement outcomes that depend wholly on factors outside its control, including the functioning of public distributed ledger networks, third-party banking rails or recipient-side infrastructure, provided that the Licensee: (a) has acted in accordance with the Client’s instructions and its disclosed procedures; (b) has taken reasonable steps to trace and remediate the failure; and (c) has communicated the position to the Client without undue delay. (4) Where the Recipient Licensee is the point of failure, responsibility shall be allocated according to the facts, contractual arrangements, and applicable law, and the Sender Licensee shall cooperate in tracing and resolution. (5) Nothing in this regulation prevents the Authority from requiring a Licensee to make a Client whole where Client protection considerations and the facts of the case justify such outcome under the Act or the Regulations. 10. Settlement Finality and execution arrangements. — (1) A Licensee shall establish arrangements to ensure the timely, reliable and accurate execution of transfers and settlements. (2) Transfer and settlement processes shall be designed to minimize operational, liquidity and counterparty risks, taking into account the characteristics of the underlying Virtual Asset networks and any off-chain settlement mechanisms used. (3) A Licensee shall clearly disclose to Clients, and document in its internal procedures, the point at which a transfer or settlement is considered final and the conditions under which a transfer may be reversed or cancelled, if at all. (4) Settlement arrangements shall be supported by appropriate reconciliations, exception management and Client communications and shall not expose Clients or the market to undue and avoidable settlement risk. (5) Where a Licensee’s ordinary settlement model requires a settlement cycle longer than twenty-four (24) hours because of infrastructure dependencies, market conditions, product design or another objectively justified factor, the Licensee shall notify the Authority before implementing that settlement model and shall disclose the applicable settlement cycle to Customers. A material and unexpected failure to meet the applicable settlement cycle shall be notified to the Authority without undue delay. Other settlement exceptions shall be documented and may be reported on an aggregated quarterly basis (6) A Licensee providing Transfer and Settlement Services shall complete final settlement within twenty-four (24) hours of execution, or within an alternative settlement cycle notified under sub-regulation (5), to the extent settlement is within its reasonable control. Where settlement is delayed by distributed-ledger congestion or malfunction, counterparty or custodian performance, banking or payment rails, Travel Rule requirements, sanctions or fraud-prevention controls, or another factor outside the Licensee’s reasonable control, the
Page 66 of 101 Licensee shall take reasonable steps to complete settlement and communicate any material delay to affected Customers. 11. Client disclosures and transparency. — (1) A Licensee shall disclose to Clients, in a clear, fair and not misleading manner, material information relating to Transfer and Settlement Services, including at least: (a) processing times and settlement cycles, including any cut-off times; (b) fees and charges; (c) risks associated with transfers and settlement, including network congestion, chain reorganizations, finality risk, counterparty dependencies and reliance on third-party providers; (d) procedures for handling Failed Transfers, delayed transfers or disputed transfers; (e) the point of Settlement Finality and the circumstances in which a transfer may be reversed, rejected, delayed or cancelled; and (f) any material restriction affecting the Licensee’s ability to process a transfer, including sanctions, Travel Rule, screening or destination-related limitations. (2) Where the service includes exchange, trade or conversion as part of the transfer or settlement flow, the Licensee shall disclose all material terms associated with such exchange, trade or conversion, including applicable fees, rates, spreads and material execution assumptions. (3) Disclosures under this regulation shall be consistent with the Licensee’s obligations under the market conduct provisions of the Regulations. 12. Wallet controls and transfer restrictions. — (1) A Licensee shall establish and maintain controls governing transfers involving external wallet addresses, including controls relating to wallet verification, sanctions screening, Travel Rule compliance, transaction monitoring, source and destination checks, and risk-based restrictions. (2) A Licensee shall not permit transfers of Client Virtual Assets to or from self-hosted, unverified, or otherwise non-compliant wallet arrangements except in accordance with controls, conditions, restrictions or approvals specified by the Authority. (3) The Authority may restrict, prohibit, or impose conditions on transfers involving self-hosted wallets, privacy-enhancing technologies, anonymizing protocols, mixers, cross-chain bridge arrangements, or other arrangements that materially impair regulatory visibility, AML/CFT/CPF compliance, or transaction traceability. 13. Receipts, confirmations and status notifications. — (1) A Licensee shall provide the Client with an acknowledgement or receipt after receiving a Transfer Instruction, containing, where applicable: (a) confirmation of receipt or initiation status; (b) date and time of receipt of the instruction; (c) amount and type of the relevant Virtual Asset or related obligation; (d) destination or recipient reference details, where appropriate and lawful;
Page 67 of 101 (e) a breakdown of fees paid or payable; (f) transaction identification details or reference; and (g) contact details for enquiries or complaints. (2) Following completion or final determination of the relevant transfer or settlement event, the Licensee shall provide the Client with a completion confirmation or status update containing, where applicable: (a) date and time of completion or other final status; (b) amount and type of the relevant Virtual Asset transferred or settled; (c) transaction identification details or reference; and (d) where relevant, details of any exchange, trade or conversion completed in the course of the transfer or settlement. (3) A Licensee may comply with this regulation through platform notifications, account statements, receipts, electronic confirmations or other durable medium appropriate to its business model, provided the information is available to the Client in a timely and intelligible manner. (4) A Licensee shall retain all such acknowledgements, confirmations and receipts for at least the minimum period required under applicable law and the Regulations. 14. Client Assets used in transfer and settlement. — (1) A Licensee shall not use, lend, pledge, convert, encumber or otherwise dispose of Client Assets for the purposes of Transfer and Settlement Services except to the extent strictly necessary to execute the Client’s instructions or otherwise as expressly permitted. (2) A Transfer and Settlement authorization does not, of itself, permit the Licensee to rehypothecate, lend or otherwise deploy Client Assets for yield, liquidity management, treasury or proprietary purposes. (3) Where a transfer or settlement arrangement requires temporary holding, prefunding, buffering or movement of Client Assets, the Licensee shall ensure that such arrangements comply with the safeguarding, segregation, disclosure and record-keeping requirements under the Regulations and, where applicable, the Custody Services Regulation. (4) Any consent given by a Client for a particular settlement-related movement of assets shall not be treated as blanket consent for unrelated use of Client Assets. 15. AML/CFT/CPF, Travel Rule and sanctions interface. — (1) Transfer and Settlement Services shall be conducted in compliance with applicable AML/CFT/CPF obligations, including requirements relating to the transmission of originator and beneficiary information under the Regulations and applicable law. (2) A Licensee shall ensure that systems and processes supporting Transfer and Settlement Services, can (a) collect, transmit and receive required originator and beneficiary information; (b) implement counterparty screening and risk controls; and
Page 68 of 101 (c) support the retention and retrieval of records for the periods required under applicable AML/CFT/CPF laws and the Regulations. (3) A Licensee shall implement controls to identify and manage sanctions risks, high-risk jurisdictions, high-risk counterparties, typologies of illicit finance, and other indicators relevant to transfer and settlement activity. (4) Where required originator or beneficiary information cannot be obtained, transmitted, received or verified in accordance with applicable requirements, the Licensee shall apply riskbased escalation, restriction, rejection, suspension or reporting procedures, as appropriate. 16. Outsourcing and Third-Party Settlement Arrangements. — (1) A Licensee shall maintain sufficient operational capability, systems, personnel, and control over Transfer and Settlement Services to perform the regulated activity on a substantive and ongoing basis and shall not operate as a mere intermediary, booking entity, or pass-through arrangement for an unlicensed or third-party operator. (2) A Licensee shall not outsource the core/principal operational responsibility for Transfer and Settlement Services. (3) Where Transfer and Settlement functions rely on outsourcing or Third-Party Settlement Arrangements, the Licensee shall retain full responsibility for compliance with this Regulation and with its obligations to Clients. (4) Outsourcing and third-party arrangements shall: (a) comply with applicable outsourcing and third-party risk requirements under the Regulations; (b) provide the Licensee with adequate audit, access and information rights; and (c) allow the Authority, where applicable, to obtain information and to conduct or commission reviews of relevant arrangements. (5) The Licensee shall conduct due diligence on material third-party providers and monitor their performance, legal risk, operational resilience and dependency risk on an ongoing basis. (6) Where a material third-party dependency creates a risk of interruption or disorderly failure of transfer or settlement services, the Licensee shall maintain contingency arrangements and escalation procedures appropriate to that risk. 17. Default, prefunding and participant-failure procedures. — (1) Where a Licensee’s actual business model includes participant obligations, prefunding, collateral, netting, closeout, or similar settlement mechanisms, it shall maintain documented default-management procedures proportionate to that business model and risk profile. (2) Nothing in sub-regulation (1) shall be construed as permitting settlement netting, offsetting or similar arrangements in a manner inconsistent with applicable foreign exchange, paymentsystem, or banking laws, including requirements relating to routing, reporting or settlement of fiat currency transactions through authorised channels. (3) Such procedures may include suspension, cancellation, reversal, close-out, use of collateral, restriction of further activity, or other remedial measures, but shall not require a default fund,
Page 69 of 101 portability regime, or central-counterparty style structure unless the Licensee in fact operates such a model or the Authority specifically requires it. (4) Default procedures shall clearly define: (a) the circumstances constituting financial or operational default; (b) how different types of default may be treated; (c) decision-making authority and escalation processes; and (d) communication with affected Clients, Participants, counterparties and the Authority. (5) A Licensee shall be able to demonstrate, upon request, the rationale for its defaultmanagement arrangements, including how any such arrangements correspond to the specific risks arising from its activities. 18. Record-keeping and audit trail. — (1) A Licensee shall keep, for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations, records sufficient to: (a) evidence compliance with this Regulation; (b) reconstruct individual transfers, settlements and related events; and (c) support investigations into failed execution, fraud, sanctions concerns, Travel Rule issues or other misconduct. (2) Records shall include, at a minimum: (a) Transfer Instructions and any amendments, cancellations, rejects or exceptions; (b) time-stamped records or equivalent sequencing records of receipt, routing and execution; (c) screening results and Travel Rule transmission data, where applicable; (d) communications with Clients and counterparties relating to material transfer or settlement events; (e) reconciliations, discrepancy investigations and remediation actions; and (f) records of use of Third-Party Settlement Arrangements and any material incident affecting them. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation and reconstruction of events. 19. Public disclosures. — (1) In addition to any disclosure requirements under the Regulations, a Licensee providing Transfer and Settlement Services shall publish on its website, or make available through another publicly accessible means approved by the Authority: (a) a description of material conflicts of interest arising from its transfer and settlement activities and how they are managed; (b) its policies relating to data privacy, complaints handling and whistleblowing; (c) whether it refers or introduces Clients to other Persons in connection with Transfer and Settlement Services and whether it receives any material monetary or non-monetary benefit from such arrangements;
Page 70 of 101 (d) whether any accounts, funds, Virtual Assets or other material service components are maintained or performed by a third party; (e) a statement in terms of Travel Rule compliance; and (f) such other information as the Authority may reasonably require. (2) Public disclosures under this regulation shall be kept current and reviewed whenever a material change occurs. Issuance Services Regulation
Page 71 of 101 (b) manage the issuance, burning, circulation, reserve management, redemption and disclosure arrangements associated with ART or FRT issuance that programme; and (c) perform ancillary functions that are integral to the operation of such services, subject to compliance with all applicable safeguarding, conduct, prudential and disclosure requirements, and provided that such functions do not constitute a separate regulated activity requiring an additional Licence Category unless permitted. (3) Nothing in this Regulation limits the types of assets that may be tokenized, provided that the resulting Virtual Asset is not otherwise prohibited by applicable law and complies with the applicable issuance, disclosure, prudential and conduct requirements. 4. Issuance authorization and approval. — (1) An Issuer shall not issue an ART or FRT unless the relevant Issuance has been notified to, or approved by, the Authority in accordance with the risk-based approach. The Authority may require prior approval for specified categories of Issuance, including restricted, retail-facing, complex or systemically significant issuance. (2) An application for approval of an Issuance shall include, at a minimum: (a) a description of the token structure, stabilization mechanism and intended use cases; (b) proposed reserve composition, custody and valuation arrangements; (c) redemption modalities and any conditions or limitations; (d) key risk factors and mitigation measures; (e) the proposed Whitepaper and related disclosure materials; and (f) such other information as the Authority may require. (3) The Authority may grant approval, grant approval subject to conditions, or refuse approval, having regard to: (a) the adequacy and quality of Reserve Assets; (b) governance and operational arrangements; (c) the effect on holders, markets and financial stability; and (d) consistency with applicable law and regulatory policy. (4) The Authority may impose conditions on approval, including conditions relating to reserve management, disclosures, redemption rights, issuance limits, distribution restrictions, operational controls, or enhanced reporting, and may vary such conditions over time. (5) Notwithstanding subregulaion (2) above, an application or notification for an Issuance shall include such information as is proportionate to the nature, scale, complexity and risk profile of the relevant Issuance. The Authority may specify simplified requirements for pilot, restricted, professional-only or low-risk programmes 5. Governance and accountability of issuers. — (1) The Licensee’s board shall approve and oversee: (a) the design and operation of each Issuance; (b) reserve, liquidity and risk-management policies for each issuance; (c) redemption policies, including any gating, suspension or limitation mechanisms; and
Page 72 of 101 (d) disclosure and reporting frameworks to token holders, the public and the Authority. (2) Senior management shall be responsible for: (a) implementing policies, procedures and controls approved by the Licensee’s board; (b) ensuring that issuance, reserve management, custody, transfer and redemption processes are operated in accordance with the Act, the Regulations, notices, directives, circulars, guidelines issued thereunder; and (c) ensuring adequate resources, including treasury, legal, risk, compliance and technology, to support safe and continuous operation of each Issuance. (3) An Issuer shall establish clear segregation, proportionate to the nature, scale and complexity of its activities, between: (a) token issuance and lifecycle management; (b) reserve management and treasury; (c) custody and safekeeping of Reserve Assets as specified by the Authority; (d) compliance, risk and internal audit; and (e) technology, including smart-contract management and supporting systems. 6. Reserve assets and full backing. — (1) An Issuer shall maintain Reserve Assets sufficient at all times to support the value and redemption of issued tokens in accordance with the terms disclosed to token holders and approved by the Authority. (2) Reserve Assets shall: (a) be appropriately valued on a regular basis using robust and transparent methodologies; (b) be segregated from the Issuer’s own assets and clearly identified as backing the relevant Issuance; (c) be held and structured so as to provide, to the extent permitted by applicable law, protection from claims of the Issuer’s creditors in the event of insolvency; and (d) be composed in accordance with standards specified by the Authority, including any requirements on asset quality, maturity, currency, diversification and concentration limits. (3) Reserve Assets shall be maintained at a level sufficient to support the Issuer’s outstanding redemption liabilities in accordance with the Act and the Regulations. The Authority may prescribe, by direction, the timing, methodology, and operational tolerances applicable to reserve maintenance and remediation of temporary mismatches. (4) Nothing in this Rulebook permits the Issuer to maintain Reserve Assets below one hundred percent (100%). Any temporary deviation that may arise from bona fide operational or settlement timing differences shall be promptly identified, monitored, and rectified in accordance with standards specified by the Authority. (5) The Issuer shall maintain policies and procedures for regular calculation of outstanding token liabilities and for monitoring reserve adequacy at a frequency proportionate to the nature, scale, complexity and redemption profile of the Issuance, and in accordance with any minimum frequency specified by the Authority.
Page 73 of 101 7. ART-specific reserve requirements. — (1) For an Asset-Referenced Token, Reserve Assets shall comprise the underlying assets referenced by the token or such eligible categories of underlying assets as may be prescribed by the Authority. (2) An ART shall at all times be fully backed by the relevant underlying assets and shall not be backed by, or derive its value from, other Virtual Assets. (3) The Issuer shall ensure that the composition of Reserve Assets for an ART is appropriate to the reference structure, disclosed to holders, and capable of supporting the redemption arrangements of the issuance. (4) Where the ART refers to more than one underlying asset, the Issuer shall maintain and disclose a methodology for allocation, valuation and rebalancing of Reserve Assets consistent with the disclosed stabilization mechanism. 8. FRT-specific reserve requirements. — (1) For a Fiat-Referenced Token, Reserve Assets shall comprise High quality liquid assets as defined in Pakistan Virtual Assets Services Regulations, 2026 or such other eligible assets as may be specified or approved by the Authority. (2) Reserve Assets for an FRT shall, unless otherwise approved by the Authority, be exclusively denominated in the reference fiat currency. (3) Reserve Assets for an FRT shall be unencumbered and freely available to meet redemption obligations. 9. Custody and safeguarding of reserve assets. — (1) Reserve Assets shall be held with a Custodian licensed under the Custody Services framework or with another entity that is regulated, supervised, as specified and agreed by the Authority for this purpose, having regard to the nature of the Reserve Assets and the risk profile of the Issuance. (2) Custody arrangements shall ensure: (a) legal and operational segregation of Reserve Assets from the Issuer’s own assets; (b) appropriate control over movements of Reserve Assets, including segregation of duties and multi-level approvals; and (c) auditability and timely reconciliation between reserve records, custodial records and the outstanding token supply. (3) Reserve Assets shall be held in a manner that provides effective protection for holders in the event of the Issuer’s insolvency, including legal and operational arrangements that support segregation and bankruptcy remoteness and the timely redemption or return of assets for the benefit of holders. (4) Reserve Assets shall not be rehypothecated, pledged, encumbered, subjected to set-off or otherwise made unavailable for redemption obligations, except to the extent expressly permitted by law and approved by the Authority.
Page 74 of 101 10. Redemption rights and mechanisms. — (1) An Issuer shall provide clear, enforceable and transparent rights for holders to redeem ARTs or FRTs: (a) in the case of an FRT, at par value; and (b) in the case of an ART, in accordance with the valuation and redemption basis approved under these Regulations and disclosed in the Whitepaper. (2) A redemption request shall be executed without undue delay and ordinarily within twentyfour (24) hours of receipt of a complete and valid request. A longer period may apply where reasonably necessary because of non-Business Days, banking or settlement hours, the nature or liquidity of the Reference Asset, distributed-ledger conditions, third-party infrastructure, fraud-prevention controls, sanctions screening or another factor outside the Issuer’s reasonable control, provided that the applicable timeframe and material conditions are clearly disclosed to holders. The Issuer shall notify the Authority without undue delay of any material or recurring failure to meet the applicable timeframe. Other exceptions and the reasons for them shall be documented and included in the Issuer’s quarterly regulatory report. (3) Redemption processes shall be accessible to eligible holders and executed within the timelines disclosed in advance, subject to the nature of the product, distribution model, Client category, applicable law and any operational, fraud-prevention or sanctions-related controls that are reasonably necessary. (4) Any proposed temporary suspension, gating or limitation of redemptions shall: (a) be permitted under the terms and conditions disclosed to holders; (b) be objectively justified on risk, operational or prudential grounds; and (c) be promptly notified to the Authority and disclosed to holders, including the reasons and expected duration. (5) An Issuer shall maintain documented redemption procedures and shall ensure that marketing and other communications do not misrepresent the speed, certainty or conditions of redemption. (6) The Authority may specify, by rule, regulation, direction or condition, more detailed redemption timelines, operational procedures or permissible exceptions for specified categories of token or Issuer. 11. Whitepaper and primary disclosure obligation. — (1) An Issuer shall prepare, publish and maintain a Whitepaper or such other principal disclosure document as may be specified by the Authority for the relevant category of Issuance before the relevant token is offered, marketed or otherwise made available to the public, unless otherwise exempted by the Authority. (2) A Whitepaper shall be clear, accurate, fair and not misleading and shall contain the information necessary for an informed assessment of the Issuance, the token, the rights of holders and the principal risks associated with holding, using or redeeming the token. (3) The Issuer shall be fully responsible for the accuracy, completeness and ongoing maintenance of the Whitepaper.
Page 75 of 101 (4) The Whitepaper shall be updated without undue delay where a material change occurs in relation to the Issuance, the token, the reserve structure, redemption rights, key risks, or any other information the omission or misstatement of which would make the Whitepaper materially misleading. (5) The Authority may prescribe the form, content, timing, language, publication method and update process for Whitepapers by implementation Instrument issued under this Regulation. 12. Minimum content of Whitepaper. — (1) A Whitepaper shall include the contents as specified in the Schedule 1 of these Regulations. (2) Notwithstanding the content specified above, the Authority may issue templates or simplified disclosure requirements for restricted, pilot, professional-only or otherwise lowerrisk issuances. 13. Ongoing disclosures and public transparency. — (1) An Issuer shall disclose to token holders and the public, in a prominent and accessible manner, information, including, but not limited to: (a) the nature and structure of the token, including Reference Assets, stabilization mechanism and intended use cases; (b) Reserve Assets, reserve composition and custody arrangements; (c) redemption rights, processes and any limitations or conditions; (d) key risks associated with the token, including legal, operational, liquidity, custody and market risks; and (e) fees and charges, where applicable. (2) Disclosures shall be: (a) clear, accurate, fair and not misleading; (b) consistent with obligations under the market conduct framework and any applicable marketing rules; and (c) updated on a timely basis where material changes occur. (3) An Issuer shall publish, at a frequency and in a form specified by the Authority, information on reserve composition, reserve adequacy and token liabilities, including any assurance or attestation reports where required. (4) For an FRT, the Issuer shall disclose on its website, or through another public channel approved by the Authority, information on tokens in circulation, Reserve Assets and reserve sufficiency at the frequency specified by the Authority, taking into account the size, scale, risk profile, holder base and systemic relevance of the Issuer or the token. (5) The Authority may require more frequent or more granular public disclosures where warranted by the size, scale, risk profile or systemic relevance of the Issuer or the token. (6) The Authority may differentiate public reporting, assurance and disclosure frequency between Significant Issuers and other Issuers, and between retail-facing issuances and professional-only or restricted issuances.
Page 76 of 101 14. Audits, attestations and assurance. — (1) An Issuer shall ensure that its Issuance is subject to independent external audit or assurance to the extent and at the frequency required by the Authority, having regard to the nature, scale and risk profile of the programme. (2) The Issuer shall obtain, at the intervals prescribed by the Authority, independent assurance in relation to at least the following, but not limited to: (a) the number and value of tokens in circulation; (b) the composition and value of Reserve Assets; and (c) such other matters as the Authority may reasonably require, having regard to the materiality and risk profile of the relevant Issuance. (3) The form, scope, methodology and frequency of any audit, attestation or assurance exercise shall be determined by the Authority having regard to the nature, scale and risk profile of the relevant Issuance. (4) A restricted or pilot Issuance may be subject to proportionate assurance and reporting arrangements specified by the Authority, provided that Reserve Assets remain fully segregated and redemption rights remain protected. (5) An Issuer shall submit to the Authority the results of any assurance exercise immediately after completion. 15. Stabilization and risk management. — (1) An Issuer shall establish and maintain arrangements to identify, measure, monitor and manage risks affecting the stability of ARTs or FRTs, including market, liquidity, credit, operational, technology and legal risks. (2) Stabilization mechanisms, including where applicable creation and redemption procedures, use of market makers and rebalancing of reserves, shall be: (a) clearly documented and disclosed; (b) subject to governance oversight; and (c) operated in a manner that is consistent with disclosed terms and does not unduly disadvantage holders. (3) The Issuer shall conduct stress testing and contingency planning at a frequency and level of sophistication commensurate with the nature, scale and complexity of the Issuance and any specific requirements imposed by the Authority. (4) Where a material risk to programme continuity, reserve adequacy or redemption integrity is identified, the Issuer shall take prompt remedial action and notify the Authority without delay. 16. Outsourcing and third-party arrangements. — (1) Where an Issuer relies on third parties for reserve management, custody, technology, transfer and settlement, redemption processing, Whitepaper preparation, assurance or other material functions, the Issuer shall remain fully responsible for compliance with the Act, the Regulations and this Regulation.
Page 77 of 101 (2) Such arrangements shall comply with applicable outsourcing and third-party risk requirements under the Regulations and shall provide the Issuer with adequate rights of access, audit, oversight, information and termination. (3) The Issuer shall conduct due diligence on material third parties and monitor their performance, resilience, legal risk, conflicts and dependency risk on an ongoing basis. (4) The Authority shall have access, audit and information rights in respect of material outsourced arrangements to the extent permitted by law and contract. 17. Significant Issuers. — (1) A Significant Issuer shall comply with enhanced requirements, including enhanced reporting, disclosure, governance and risk-management requirements, as prescribed by the Regulations or otherwise imposed by the Authority in accordance with the Act. (2) An Issuer shall be deemed “significant” where: (a) the total market capitalization of the fiat referenced or Asset-Referenced token exceeds five billion Pakistani Rupees (PKR 5,000,000,000); or (b) the number of users based in Pakistan holding the fiat referenced or Asset-Referenced token exceeds five million (5,000,000); or (c) such other thresholds as may be Prescribed by the Authority. (3) Significant Issuers shall be required to maintain additional own funds equivalent to at least three percent (3%) of reserve assets, capped at PKR 3 billion (or such lower or higher cap as the Authority may prescribe in Regulations) and shall submit enhanced risk assessment and governance. (4) Without prejudice to sub-regulation (1), the Authority may impose proportionate additional conditions on a Significant Issuer’s licence or registration having regard to financial stability, consumer protection, market integrity and cross-border risks. (5) The Authority may require a Significant Issuer to maintain enhanced monitoring, testing, wind-down planning, operational resilience measures, redemption controls, reserve governance arrangements or additional disclosures. 18. Limited Scope Issuance. — (1) The Authority may grant a limited scope licence for issuance of an ART or FRT on a pilot basis, subject to: (a) caps on outstanding supply, number or type of holders, and transaction volumes; (b) limitations on distribution channels and use cases; (c) enhanced disclosures to holders regarding pilot status and risks; (d) redemption controls and operational safeguards; and (e) any additional conditions necessary to protect holders and market integrity. (2) A limited scope issuance shall remain subject to the core requirements on reserve segregation, programme governance, clear disclosures and protection of redemption rights, except to the extent the Authority expressly modifies specific requirements on a proportionate basis.
Page 78 of 101 19. Monitoring, notification and remediation. — (1) An Issuer shall establish systems and controls to monitor compliance with this Regulation on an ongoing basis, including stress testing and contingency planning commensurate with the nature, scale and complexity of the Issuance. (2) An Issuer shall notify the Authority without delay where it reasonably anticipates, or becomes aware, that it has failed or is likely to fail to meet any requirement under this Regulation, and shall provide a remedial action plan within the timeframe specified by the Authority. (3) The Authority may require enhanced reporting, restrictions, programme modifications, redemption controls or other remedial measures where an Issuer is in breach or is likely to breach any requirement under this Regulation. (4) The Authority may, on a risk-based basis and where necessary to advance the objectives of the Act, require an Issuer to hold and maintain additional paid-up capital, liquid financial resources, insurance, reserve assets or operational safeguards, having regard to the size, scope, geographic exposure, complexity and nature of the Issuer’s activities and operations. 20. Record-keeping. — (1) An Issuer shall keep complete and accurate records relating to each Issuance, including the following: (a) programme approvals and related conditions; (b) Whitepapers and all material updates; (c) reserve calculations, reserve holdings and reconciliations; (d) assurance reports, attestations and audit materials; (e) redemption requests, processing times, restrictions and outcomes; (f) disclosures to holders and the public; (g) complaints, incidents, remediation actions and communications with the Authority; and (h) material outsourcing and third-party arrangements. (2) Records shall be retained for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations and shall be made available to the Authority upon request. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation and reconstruction of events. Derivatives Services Regulation
Page 79 of 101 (2) In this Regulation: (a) “Derivatives Services” means as defined in Schedule 1 of the Act; (b) “Derivative Contract” means a futures contract, perpetual contract, option, swap, contract for difference or other contract whose value is derived from a Virtual Asset or other permitted underlying or reference; (c) “Eligible Collateral” means collateral that the Licensee has determined, in accordance with its documented policies, to be acceptable for Margin purposes having regard to liquidity, volatility, concentration, legal certainty and realizability; (d) “Funding Payment” means any periodic payment, adjustment or transfer associated with a perpetual or similar contract; (e) “Initial Margin” means the Margin required to establish a Derivative Contract or Leverage Arrangement; (f) “Leverage Arrangement” means any arrangement under which a Client obtains a leveraged, margined or synthetic exposure to a Virtual Asset or related market movement, whether through a Derivative Contract, leveraged token, financing mechanism or similar structure; (g) “Liquidation” means the forced reduction, close-out, or termination of a Derivative Contract or Leverage Arrangement due to insufficient Margin, breach of risk limits, or other event specified in the relevant Regulation or the Client Agreement; (h) “Maintenance Margin” means the minimum Margin that must be maintained to keep a Derivative Contract or Leverage Arrangement open; and (i) “Margin” means collateral posted by a Client or Licensee in support of an open Derivative Contract or Leverage Arrangement; (3) For the avoidance of doubt, Derivatives Services may be cash-settled, fiat-margined, coinmargined, physically settled or otherwise settled, provided the structure is lawful and permitted under the Act, the Regulations and the terms of the Licence. 3. Eligibility for authorization. — (1) A Person shall not be eligible to apply for, obtain or hold a licence to provide Derivatives Services unless that Person: (a) holds a valid Broker-Dealer Services licence or Exchange Services licence; or (b) otherwise satisfies such operational, prudential, conduct and client-protection requirements as the Authority may specify for a Derivatives Services licence, including where services are limited to Professional Clients or Institutional Clients. (2) Where a Licensee holding Derivatives Services ceases to hold the underlying Broker-Dealer Services licence or Exchange Services licence referred to in sub-regulation (1), the Licensee shall: (a) notify the Authority immediately; and (b) cease offering new Derivatives Services unless otherwise directed by the Authority. (3) The Authority may impose such restrictions, wind-down requirements or other licence conditions as it considers necessary where a Licensee no longer satisfies the requirement in sub-regulation (1).
Page 80 of 101 4. Nature and perimeter of Derivatives Services. — (1) A Licensee shall not hold itself out as providing Derivatives Services unless it is authorised for that Licence Category and provided explicit approval of the Authority to deal with institutional, professional and/or retail clients. (2) A Licensee providing Derivatives Services may, subject to its Licence and the Act and Regulations, and in compliance with Regulation 3 (Eligibility for authorization): (a) offer, arrange, deal in, or facilitate Derivative Contracts; (b) offer margin or leveraged arrangements, including leveraged spot products, leveraged tokens, synthetic exposures and similar products; (c) provide margining, liquidation, risk management and default-management arrangements that are integral to such services; and (d) perform ancillary functions that are integral to the operation of such services, subject to compliance with all applicable safeguarding, conduct, prudential and disclosure requirements, and provided that such functions do not constitute a separate regulated activity requiring an additional Licence Category under the Regulations (3) Where there is doubt whether a product, arrangement or instrument falls within the mandate of the Securities and Exchange Commission of Pakistan or the State Bank of Pakistan, the Licensee shall not offer the product until regulatory clarity has been obtained in accordance with the Act and the Regulations. (4) The Authority may approve a modified or lighter application of specified conduct, disclosure, reporting or appropriateness requirements for Derivatives Services offered exclusively to Professional Clients or Institutional Clients, provided that prudential, market integrity and Client asset protection objectives remain adequately met. 5. Governance and risk oversight. — (1) The Licensee’s board shall approve and oversee the Derivatives business, including: (a) product design, approval and review; (b) risk appetite and limits for market, credit, liquidity, counterparty, settlement and operational risks; (c) Margin, collateral and Liquidation policies; (d) Client eligibility and target-market determinations; and (e) conflicts of interest arrangements relevant to derivatives and leveraged products. (2) Senior management shall implement policies, procedures and controls to manage the risks arising from Derivatives Services and shall ensure that those risks are reflected in the Licensee’s prudential, capital and liquidity planning. (3) The Licensee shall ensure that Derivatives activities are subject to effective governance, risk oversight and control by Key Individuals and staff with competence appropriate to the scale, complexity and risk profile of the business. (4) The Licensee shall maintain adequate governance, reporting lines, escalation procedures and management information to enable effective oversight of exposures, margin sufficiency, liquidation events, concentration risk, operational incidents and Client protection issues.
Page 81 of 101 6. Policies, procedures and control framework. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Derivatives Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to: (a) product approval and classification; (b) Client onboarding, eligibility and appropriateness; (c) Margin methodologies and collateral standards; (d) leverage limits and exposure controls; (e) valuation, mark-to-market and price-source controls; (f) Funding Payments and contract adjustment mechanisms, where applicable; (g) Liquidation, close-out and default management; (h) handling of market disruption, trading suspension, system outage and severe volatility; (i) safeguarding and treatment of Client Assets used as Margin or collateral; (j) management of conflicts of interest, including proprietary trading and related-party activity; (k) stress-testing, model validation and back-testing; and (l) such other matters as the Authority may reasonably require. (2) The Licensee shall assess and, in any event, at least annually review the effectiveness of those policies and procedures and take appropriate measures to address any deficiency. (3) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that they are appropriate to the Licensee’s business, legally and operationally applicable in Pakistan, and sufficient to ensure compliance with the Act, the Regulations and this Regulation. 7. Product governance and scope notification. — (1) Before offering a new type of Derivative Contract or Leverage Arrangement, a Licensee shall assess the nature, legal character, settlement model, leverage features, target market, risk profile, valuation methodology, margin methodology, operational dependencies and market-abuse risks of the product. (2) The Licensee shall not offer a Derivative Contract or Leverage Arrangement unless it is satisfied that the product is consistent with the Act, the Regulations, this Regulation and the terms of its Licence. (3) The Licensee shall maintain internal records identifying, for each material product type: (a) the type of contract or arrangement; (b) whether it is made available to Retail Clients, Professional Clients or any other category of Client recognized under the Act, the Regulations or a direction of the Authority; (c) the settlement model; (d) the underlying Virtual Asset or other permitted reference; and
Page 82 of 101 (e) the principal conduct, risk and operational controls applicable to the product. (4) The Authority may require the Licensee to provide prior notification, additional information, restrictions, or enhanced controls in relation to particular classes of Derivative Contracts or Leverage Arrangements. 8. Client categorization, onboarding and appropriateness. — (1) A Licensee shall not provide Derivatives Services to a Client unless it has assessed the Client’s eligibility and, where applicable, the appropriateness of the relevant product or service for that Client. (2) In assessing appropriateness, the Licensee shall obtain sufficient information regarding the Client’s knowledge and experience in relation to derivatives, leverage, margining, liquidation risk and relevant Virtual Asset markets. (3) If the Licensee concludes that a product or service is not appropriate for a Retail Client, it shall warn the Client clearly of that assessment and record that the warning has been provided. (4) If the Client does not provide sufficient information to enable an appropriateness assessment, the Licensee shall warn the Client that such a determination cannot be made. (5) Nothing in sub-regulations (3) and (4) requires the Licensee to proceed with the transaction where doing so would be inconsistent with law, regulation, Licence conditions, internal risk policies or the Licensee’s duties to act fairly and professionally. (6) A Licensee shall maintain procedures for heightened onboarding and suitability-related review where it offers particularly complex, high-leverage or high-volatility products. 9. Client disclosures and risk warnings. — (1) A Licensee providing Services shall disclose to Clients, in a clear, fair, timely and not misleading manner, material information including at least: (a) the nature of the Derivative Contract or Leverage Arrangement; (b) the extent and effect of leverage, including the potential for amplified losses and total loss of Margin; (c) Margin requirements, margin-call processes, top-up obligations and Liquidation triggers; (d) fees, charges, spreads, commissions and Funding Payments; (e) settlement model and, where relevant, delivery mechanics; (f) outage, system disruption, trading suspension and market-dislocation risks; (g) the basis on which prices, marks, indices, reference rates or valuations are determined; (h) any rights of the Licensee to amend Margin requirements, risk limits, settlement parameters or other product terms; and (i) conflicts of interest, including proprietary trading, internalization, related-party liquidity and liquidation arrangements. (2) A Licensee shall not market a leveraged or derivative product as low-risk, capital-protected, or suitable for all Clients unless that representation is accurate and substantiated.
Page 83 of 101 (3) Risk disclosures shall be tailored to the nature of the product and the category of Client to whom it is offered. 10. Client Agreements. — (1) In addition to general Client Agreement requirements under the Regulations, a Client Agreement for Derivatives Services shall, to the extent applicable, set out clearly: (a) the nature of the Derivative Contract or Leverage Arrangement; (b) Initial Margin and Maintenance Margin requirements and how they are determined; (c) the circumstances in which Margin requirements may be changed; (d) acceptable forms of collateral and applicable haircuts; (e) margin calls, timing, permitted methods of satisfaction, and consequences of failure to meet a margin call; (f) Liquidation and close-out rights, including when and how the Licensee may reduce or terminate a position; (g) settlement terms, including whether the product is cash-settled, physically settled, fiat-margined or coin-margined; (h) Funding Payments, financing charges, commissions, fees and other costs; (i) any rights of the Licensee to suspend trading, reject orders, restrict positions, amend risk limits or otherwise intervene in exceptional circumstances; (j) any rights of the Client to withdraw excess Margin or terminate positions and the consequences of doing so; and (k) the Licensee’s complaints procedure and escalation channels. (2) The Client Agreement shall be clear, fair and not misleading and shall be consistent with the market conduct requirements under the Regulations. 11. Margin framework. — (1) A Licensee shall establish and maintain a documented Margin framework that is prudent, risk-sensitive, transparent and appropriate to the nature, scale and complexity of its Derivatives business. (2) The Margin framework shall address, at a minimum: (a) Initial Margin and Maintenance Margin methodologies; (b) eligible forms of Margin and collateral; (c) valuation methodologies and application of haircuts; (d) concentration limits and wrong-way risk; (e) frequency of margin calculation and revaluation; (f) margin-call processes and escalation procedures; and (g) treatment of exceptional volatility, illiquidity or other stressed market conditions. (3) Margin requirements shall be designed to reflect the risk profile of the product, the Client, the underlying market, the settlement model and any operational or liquidity constraints. (4) A Licensee shall not rely on a fixed leverage cap alone as a substitute for a prudent Margin framework.
Page 84 of 101 12. Eligible collateral and safeguarding of margin assets. — (1) A Licensee shall establish and maintain documented policies governing the acceptance, valuation, monitoring and liquidation of collateral used for Derivatives Services. (2) Where a Licensee holds, controls, safeguards or administers Client Assets as Margin or collateral in connection with Derivatives Services, it shall ensure that such arrangements achieve an outcome equivalent to the safeguarding, segregation, reconciliation, disclosure and Client protection standards applicable under the Act, the Regulations and, where relevant, the Custody Services framework, having regard to the nature, scale and risk profile of the relevant activity. (3) Eligible Collateral shall consist only of assets that are sufficiently liquid, readily realizable, capable of prudent valuation and legally available for enforcement. (4) Where Client Assets are held, controlled or applied as Margin or collateral on an incidental basis, the Licensee shall have requisite license and achieve Client protection outcomes equivalent to those applicable to standalone Custody Services, applied proportionately to the nature, scale and purpose of the activity, and shall not use such arrangements to circumvent applicable custody requirements. (5) Client Margin and collateral must be fully segregated and safeguarded, or otherwise protected by equivalent safeguarding arrangements, to the extent required under the Regulations and shall not be treated as the Licensee’s proprietary assets. (6) The Licensee shall not use, lend, pledge, stake, rehypothecate or otherwise deploy Client Margin or collateral except with client’s prior written explicit and informed consent and shall clearly disclose the nature of the activity, the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated. 13. Leverage limits and exposure controls. — (1) A Licensee shall implement leverage limits proportionate to its risk profile, Client base, product characteristics and operational capacity. (2) Leverage limits shall be supported by exposure controls at Client level, product level and firm level and shall address, where relevant: (a) concentration risk; (b) wrong-way risk; (c) correlation risk; (d) liquidity stress; (e) intraday and overnight exposure; and (f) contagion between products, Clients or venues. (3) The Licensee shall have the ability to reduce leverage, require additional Margin, restrict new positions or close existing positions where necessary to protect Clients, preserve market integrity or manage prudential risks. (4) The Licensee shall document the basis on which leverage limits are set, reviewed and amended.
Page 85 of 101 14. Valuation, mark-to-market and pricing controls. — (1) A Licensee shall establish documented methodologies for valuing Derivative Contracts, Leverage Arrangements, Margin and collateral. (2) Such methodologies shall address, where relevant, including but not limited to: (a) pricing sources and hierarchy; (b) mark-to-market frequency; (c) handling of stale prices, outliers and anomalous prints; (d) fallback arrangements where primary data is unavailable or unreliable; and (e) controls to prevent conflicts of interest affecting valuations. (3) Valuation methodologies shall be subject to governance review and periodic validation commensurate with the nature, scale and complexity of the Licensee’s business. (4) A Licensee shall not use a valuation methodology that materially understates risk, overstates collateral value, or otherwise distorts Client positions or the Licensee’s prudential picture. 15. Liquidation, close-out and default management. — (1) A Licensee shall maintain documented policies and procedures governing margin calls, Liquidation, close-out and default management. (2) Such procedures shall be transparent, non-discriminatory, consistent with Client disclosures and reasonably designed to minimize disorderly Liquidation and avoidable harm to Clients and the market. (3) Procedures shall address at least: (a) triggers for margin calls and Liquidation; (b) timing, notice and escalation, where operationally appropriate; (c) methods for valuing positions and collateral during stressed conditions; (d) partial liquidation, full close-out and staged reduction mechanisms; (e) treatment of shortfalls, excess proceeds and fees; (f) default management and communication with affected Clients; and (g) communication with the Authority where material disruption or deficiency arises. (4) A Licensee shall not rely on opaque or unlimited discretionary liquidation powers that are materially inconsistent with its Client Agreement or disclosures. (5) Where the business model includes default funds, guarantee funds, insurance arrangements or similar buffers, the Licensee shall disclose their function and limitations clearly and shall not represent them as eliminating Client risk. 16. Stress-testing, model validation and back-testing. — (1) A Licensee shall conduct periodic stress-testing of its Derivatives and Leverage exposures, including stress-testing of Margin sufficiency, collateral values, concentrated positions, liquidation capacity and liquidity under severe but plausible scenarios.
Page 86 of 101 (2) A Licensee shall ensure that any risk model, valuation model, margin model or liquidation model used in connection with Derivatives Services is subject to appropriate validation, testing, governance and change control. (3) Back-testing and benchmarking shall be conducted where appropriate to the model and business model concerned. (4) Stress-test and validation results shall be reported to the Licensee’s board or an appropriate committee and used to adjust risk limits, Margin methodologies, collateral standards and contingency arrangements. 17. Market conduct and conflicts of interest. — (1) A Licensee providing Derivatives Services shall act honestly, fairly and professionally in accordance with the best interests of its Clients. (2) The Licensee shall maintain effective controls to identify, prevent, manage and, where appropriate, disclose conflicts of interest arising from: (a) proprietary trading; (b) internalization or principal dealing; (c) market making or liquidity provision; (d) related-party counterparties, venues or liquidity sources; (e) liquidation arrangements; and (f) the use of Client Order information or position information. (3) A Licensee shall prohibit front-running, abusive self-trading, manipulation of mark prices, abusive liquidations, misuse of Client information, or any other abusive practice prohibited under the Act, the Regulations or applicable law. (4) Where the Licensee also operates an Exchange or Broker-Dealer business, it shall maintain effective information barriers and conflict management controls proportionate to the scale and complexity of the integrated model. 18. Exchange and Broker-Dealer interface. — (1) Where Derivatives Services are offered through an Exchange, the Exchange shall maintain policies, procedures, systems, controls, and disclosures appropriate to leveraged and derivatives activity, including those relating to participant eligibility, collateral, Liquidation, concentration limits and market integrity. (2) Where Derivatives Services are offered through a Broker-Dealer, the Broker-Dealer shall comply with the relevant appropriateness, order handling, Fair Pricing, conflict management and Client disclosure requirements in addition to this Regulation. (3) A Licensee shall not continue to provide Derivatives Services if it ceases to hold a valid Broker-Dealer Services licence or Exchange Services licence on which premise the Derivatives Services were authorised, except to the extent necessary to close out, transfer or otherwise wind down existing positions in accordance with a direction of the Authority.
Page 87 of 101 19. Technology, operational resilience and trading continuity. — (1) A Licensee shall ensure that systems supporting Derivatives Services are resilient, secure and capable of orderly operation under conditions of high uncertainty and extreme volatility. (2) The Licensee shall maintain contingency procedures for system outages, pricing failures, order-routing failures, margining failures, liquidation system failures, stale market data, chain disruption, banking rail disruption and other events that could materially affect derivatives or leveraged positions. (3) Material incidents affecting derivatives or leveraged products shall be communicated to affected Clients and to the Authority immediately. (4) The Licensee shall maintain business continuity, backup and disaster recovery arrangements sufficient to support the continuity of critical derivatives and leverage functions. 20. Client reporting and statements. — (1) A Licensee shall furnish to each Client periodic statements at intervals appropriate to the nature, scale and risk profile of the relevant product and Client category and, in any event, not less frequently than monthly for Retail Clients unless otherwise required by the Authority. (2) Statements shall be clear, timely and accessible and retained for at least the minimum period required under applicable law and the Regulations. (3) The Licensee shall provide additional information promptly where a material event significantly affects the Client’s position, margin status or exposure. 21. Public disclosures. — (1) A Licensee offering Derivatives Services shall, in a prominent place on its website or via other accessible means approved by the Authority, disclose at least: (a) the categories of derivatives or leveraged products offered; (b) the categories of Clients to whom such products are made available; (c) material risk warnings relating to leverage, Margin, Liquidation and volatility; (d) high-level information on collateral standards and pricing methodology; (e) whether the Licensee acts as principal, agent, venue operator, or in more than one such capacity; and (f) such other information as the Authority may reasonably require. (2) A Licensee shall keep public disclosures under this regulation current and review them whenever a material change occurs. 22. Record-keeping. — (1) A Licensee shall keep complete and accurate records of all Derivatives and Leverage activities, including: (a) Client Agreements and risk acknowledgements; (b) product approvals and reviews; (c) Client categorization and appropriateness assessments; (d) orders, trades, positions, valuations, Margin movements and Liquidation events; (e) model validation, back-testing and stress-testing results; (f) conflict management decisions and proprietary trading controls; and
Page 88 of 101 (g) defaults, incidents, complaints and remediation actions. (2) Records shall be retained for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations and shall be made available to the Authority upon request. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation and reconstruction of events. Mining Services Regulation
Page 89 of 101 3. Nature and perimeter of Mining Services. — (1) A Person shall not hold itself out as providing Mining Services unless it is authorised for that Licence Category. (2) A Licensee providing Mining Services may, subject to its Licence and the Act and Regulations: (a) operate Mining Infrastructure or Hosted Mining Arrangements for or on behalf of Clients; (b) pool, administer, route or otherwise manage mining or validation participation for Clients; (c) receive, hold, allocate or distribute Mining Rewards for Clients; and (d) perform ancillary functions that are integral to the operation of such services, subject to compliance with all applicable safeguarding, conduct, prudential and disclosure requirements, and provided that such functions do not constitute a separate regulated activity requiring an additional Licence Category under the Regulations (3) Where a Mining Services business model includes custody, transfer, pooling of Client Mining Assets, reward distribution, staking, validator activity, or any other function that falls within another Licence Category, the Licensee shall hold the relevant Licence Category and comply with the applicable Regulation. (4) For the avoidance of doubt, staking, validator activity or similar protocol-participation activity performed on behalf of Clients shall be assessed on a substance-over-form basis and may constitute Custody Services, Management and Investment Services, or another regulated activity depending on the nature of the authority exercised, the treatment of Client Assets, the degree of discretion involved, and the overall structure of the arrangement. (5) The Authority may require a Person conducting large-scale proprietary mining, even where licensing is not otherwise required, to register or make declarations in accordance with any registration or declaration framework established under the Act or the Regulations, or as may be prescribed by the Authority. 4. Governance and oversight. — (1) The Licensee’s board shall approve and oversee the provision of Mining Services, including: (a) business model and service scope; (b) operational and technology risk appetite; (c) custody and safeguarding arrangements for Client Mining Assets; (d) reward allocation methodology; (e) outsourcing and Mining Pool arrangements; and (f) conflict management arrangements. (2) Senior management shall ensure that Mining Services are conducted in accordance with approved policies, procedures and applicable regulatory obligations. (3) The Licensee shall maintain adequate governance, reporting lines, escalation procedures and management information to enable effective oversight of operational uptime, service
Page 90 of 101 continuity, reward allocation, energy and infrastructure dependency, concentration risk, Client protection issues and incident management. (4) The Licensee shall identify the Key Individuals responsible for Mining Services, including responsibility for operations, technology, safeguarding, compliance and risk management. 5. Policies, procedures and control framework. — (1) In addition to all other applicable requirements under the Regulations, a Licensee providing Mining Services shall establish, implement, maintain and enforce written policies and procedures appropriate to the nature, scale and complexity of its business, including at least policies and procedures relating to— (a) Client onboarding and eligibility; (b) operation, maintenance and security of Mining Infrastructure; (c) uptime, resilience, failover and business continuity; (d) treatment, safeguarding and reconciliation of Client Mining Assets; (e) reward generation, calculation, allocation and distribution; (f) fees, expenses, deductions and charges; (g) Mining Pool participation or other third-party participation arrangements; (h) incident management, outage handling and Client notification; (i) conflicts of interest, including proprietary mining alongside Client mining; (j) outsourcing and third-party dependencies; and (k) such other matters as the Authority may reasonably require. (2) The Licensee shall assess and, in any event, at least annually review the effectiveness of those policies and procedures and take appropriate measures to address any deficiency. 3) A Licensee may rely on group-level policies, procedures, systems, controls or assurance arrangements, provided that they are appropriate to the Licensee’s business, legally and operationally applicable in Pakistan, and sufficient to ensure compliance with the Act, the Regulations and this Regulation. 6. Client disclosures and transparency. — (1) A Licensee providing Mining Services shall disclose to Clients, in a clear, fair, timely and not misleading manner, material information including at least: (a) the nature of the Mining Services provided; (b) whether the service involves hosted mining, pooled participation, validator operation, reward administration, or another structure; (c) the treatment of Client Mining Assets and any role of the Licensee in holding, controlling or administering those assets; (d) the basis on which Mining Rewards are calculated, allocated and distributed; (e) fees, deductions, operating costs, energy charges, pool charges and any other amounts that may reduce Client proceeds; (f) operational, technology, protocol, downtime, slashing, maintenance, regulatory and counterparty risks relevant to the service; (g) any lock-up, withdrawal, unbonding, payout timing or distribution restrictions; and
Page 91 of 101 (h) the circumstances in which the Licensee may suspend, restrict, terminate or materially modify the service. (2) A Licensee shall not market Mining Services as guaranteed, risk-free, or capable of producing a fixed level of rewards or returns unless that representation is accurate and substantiated. (3) Where the service involves a Mining Pool, third-party node operator, external infrastructure provider or similar arrangement, the Licensee shall disclose the role of that third party and the principal risks associated with that dependency. 7. Client Agreements. — (1) A Licensee shall not provide Mining Services to a Client unless a written Client Agreement has been agreed with that Client. (2) In addition to general Client Agreement requirements under the Regulations, a Client Agreement for Mining Services shall, to the extent applicable, set out clearly: (a) the nature and scope of the Mining Services; (b) the respective rights and obligations of the Licensee, the Client and any third party materially involved in the service; (c) whether Client Mining Assets or Client Money are transferred to, held by, controlled by, or otherwise exposed to the Licensee; (d) the basis for calculation, timing and distribution of Mining Rewards; (e) all fees, deductions, charges and expenses payable by the Client or deductible from rewards; (f) any lock-up, unbonding, maintenance, withdrawal, payout or termination conditions; (g) service levels, uptime commitments if any, and the consequences of outages or performance failures; (h) any right of the Licensee to modify, suspend or terminate the service and the consequences of doing so; (i) the treatment of Client Assets and Mining Rewards on termination or insolvency; and (j) the Licensee’s complaints procedure and escalation channels. (3) The Client Agreement shall be clear, fair and not misleading and shall be consistent with the market conduct requirements under the Regulations. 8. Treatment of Client Assets and Client Money. — (1) A Licensee shall not receive, hold, control, safeguard or administer Client Mining Assets except in accordance with the Act, the Regulations, this Regulation, and any other applicable Regulation. (2) Where a Licensee holds or controls Client Mining Assets or Client Money in connection with Mining Services, it shall comply with the safeguarding, segregation, reconciliation, record-keeping and disclosure requirements under the Regulations and, where applicable, the Custody Services Regulation.
Page 92 of 101 (3) A Mining Services licence does not, of itself, permit the Licensee to use, lend, pledge, stake, rehypothecate, encumber or otherwise deploy Client Mining Assets for its own benefit or for third parties. Any such use shall require Client’s prior written, explicit, and informed consent and shall clearly disclose the nature of the activity, the associated risks, any withdrawal restrictions, and the basis on which rewards, proceeds, losses and liabilities are allocated. (4) The Licensee shall structure its arrangements so that Client Mining Assets are identifiable, segregated from the Licensee’s own assets, and capable of timely return, transfer or payout in accordance with the Client Agreement and applicable law. 9. Reward calculation, allocation and distribution. — (1) A Licensee shall establish and maintain a documented methodology for the calculation, allocation and distribution of Mining Rewards. (2) The methodology referred to in sub-regulation (1) shall be fair, transparent, consistently applied and disclosed to Clients in an understandable manner. (3) The methodology shall address, where relevant, including but not limited to: (a) how rewards are attributed to individual Clients or groups of Clients; (b) treatment of pool fees, third-party fees, infrastructure costs, slashing losses, penalties, downtime losses and other deductions; (c) timing and frequency of distributions; (d) treatment of rounding, dust balances and residual amounts; and (e) treatment of forks, airdrops, protocol changes, restatements or retroactive adjustments affecting Mining Rewards. (4) A Licensee shall not change its reward allocation methodology in a way that materially disadvantages Clients without prior notice consistent with the Client Agreement and any applicable requirements under the Regulations. (5) The Licensee shall maintain records sufficient to demonstrate the basis on which Mining Rewards were calculated, allocated and distributed. 10. Mining infrastructure, operational integrity and maintenance. — (1) A Licensee shall establish, operate and maintain Mining Infrastructure in a manner consistent with the technology, cybersecurity and operational resilience requirements under the Regulations. (2) The Licensee shall maintain documented standards and procedures relating to: (a) hardware and software maintenance; (b) patching, upgrades and configuration management; (c) physical security and environmental controls where relevant; (d) uptime monitoring, performance monitoring and fault detection; and (e) failover, backup and recovery arrangements. (3) A Licensee shall ensure that Mining Infrastructure is fit for purpose, reasonably resilient, and capable of supporting the service levels and reward expectations disclosed to Clients.
Page 93 of 101 (4) A Licensee shall not continue to accept new Clients or additional Client Mining Assets where it is aware, or ought reasonably to be aware, that its Mining Infrastructure is materially inadequate to support the relevant service safely and effectively. 11. Protocol, pool and network due diligence. — (1) Before supporting a protocol, Mining Pool, validator framework or other network arrangement in connection with Mining Services, a Licensee shall conduct due diligence appropriate to the nature, scale and complexity of the activity. (2) Such due diligence shall address, where relevant: (a) technology and security characteristics; (b) protocol governance and operational history; (c) reward mechanism and sustainability of reward generation; (d) slashing, penalty, downtime or similar risk; (e) degree of concentration, centralization or dependency on a limited number of operators; (f) legal and regulatory risks; and (g) the Licensee’s ability to operate or support the relevant arrangement in a compliant and resilient manner. (3) The Licensee shall actively monitor supported protocols, pools and network arrangements on an ongoing basis. (4) Where the Licensee becomes aware that a protocol, pool or network arrangement no longer meets its risk standards or presents a material risk to Clients, the Licensee shall: (a) cease accepting new Client Mining Assets or new participation in the affected arrangement where appropriate; (b) notify affected Clients and the Authority without undue delay where the matter is material; and (c) determine and implement an appropriate remediation, migration, suspension or wind-down plan. 12. Outsourcing and third-party arrangements. — (1) Where a Licensee relies on third parties for hosting, colocation, power supply, pool participation, validator operation, reward administration, custody, payout processing, software, monitoring or other material functions, the Licensee shall remain fully responsible for compliance with the Act, the Regulations and this Regulation. (2) Such arrangements shall comply with applicable outsourcing and third-party risk requirements under the Regulations and shall provide the Licensee with adequate rights of access, audit, oversight, information and termination. (3) The Licensee shall conduct due diligence on material third parties and monitor their performance, resilience, legal risk, conflicts and dependency risk on an ongoing basis.
Page 94 of 101 (4) The Authority shall have access, audit and information rights in respect of material outsourced arrangements to the extent permitted by law and contract. 13. Conflicts of interest. — (1) A Licensee shall identify, prevent, manage and, disclose conflicts of interest arising in the provision of Mining Services. (2) Such conflicts shall include, where relevant, including but not limited to: (a) proprietary mining or validation activity conducted alongside Client-facing Mining Services; (b) preferential allocation of infrastructure capacity, rewards or service quality between proprietary and Client activity; (c) related-party participation in pools, infrastructure providers or counterparties; and (d) fee or reward structures that may distort the Licensee’s treatment of Clients. (3) A Licensee shall not allocate Mining Rewards, infrastructure capacity or operational priority in a manner that unfairly disadvantages Clients. (4) Material conflicts that cannot be effectively prevented or otherwise managed shall be disclosed to Clients clearly and before the relevant service is provided or continued. 14. Reporting to Clients. — (1) A Licensee shall furnish to each Client, at least monthly and more frequently where necessary having regard to the service model or Client Agreement, statements showing, including but not limited to: (a) Client Mining Assets or Client Money held or used in connection with the service; (b) Mining Rewards generated, allocated and distributed during the reporting period; (c) fees, charges, costs or deductions applied; (d) any material outages, slashing events, penalties, pool failures, protocol issues or similar events affecting the service; and (e) any material changes to the service, reward methodology or operational arrangements. (2) Statements shall be clear, timely and accessible and retained for at least the minimum period required under applicable law and the Regulations. (3) The Licensee shall provide additional information promptly where a material event significantly affects the Client’s participation, assets or expected rewards. 15. Public disclosures. — (1) A Licensee providing Mining Services shall publish on its website, or make available through another publicly accessible means approved by the Authority, clear, fair and not misleading disclosures including at least: (a) a description of the Mining Services provided; (b) broad categories of supported protocols, pools or infrastructure arrangements; (c) the principal risks relevant to the service; (d) fee structures and reward allocation principles; (e) whether Client Assets or Client Money are held by the Licensee or a third party in connection with the service;
Page 95 of 101 (f) the Licensee’s policies relating to data privacy, complaints handling and whistleblowing; and (g) such other information as the Authority may reasonably require. (2) Public disclosures under this regulation shall be kept current and reviewed whenever a material change occurs. 16. Operational resilience and incident management. — (1) A Licensee shall ensure that systems, controls and infrastructure supporting Mining Services meet operational resilience, availability and recovery standards proportionate to the criticality of those services. (2) The Licensee shall maintain contingency procedures for material outages, Mining Infrastructure failures, software or firmware failures, power disruption, cooling failure, cyber incidents, protocol changes, pool failures, payout failures and other events that could materially affect Mining Services. (3) Material incidents affecting Mining Services shall be communicated to affected Clients and to the Authority without undue delay where the incident is material. (4) The Licensee shall maintain business continuity, backup and disaster recovery arrangements sufficient to support the continuity of critical Mining Services functions. 17. Record-keeping. — (1) A Licensee shall keep complete and accurate records of all Mining Services activities, including: (a) Client Agreements; (b) onboarding and service eligibility records; (c) Client Mining Assets and Client fund records; (d) reward calculations, allocations and distributions; (e) protocol, pool and network due-diligence records; (f) outage, incident, slashing, penalty and remediation records; (g) outsourcing and third-party arrangements; and (h) complaints, communications and material disclosures to Clients. (2) Records shall be retained for at least the minimum period required under AML Act, 2010, AML Rules, applicable AML/CFT Regulations and any other applicable law, and the Regulations and shall be made available to the Authority upon request. (3) Records shall be sufficiently complete, accessible and reliable to permit supervisory review, internal investigation and reconstruction of events.
Page 96 of 101 Schedule 1 – VA Whitepaper Requirements Not all of the information listed herein will be applicable for every Virtual Asset. At such time, Issuers and/or their Licensed Distributors must exercise professional judgement, acting in accordance with the regulatory requirements at all times, when determining if the information listed herein is applicable for the purposes of inclusion in a Whitepaper of a specific Virtual Asset. Issuer shall be fully responsible for the accuracy and completeness of all Whitepapers. A. Information about the Issuer
Page 97 of 101 B. Information about the Virtual Asset
Page 98 of 101 9. information on the nature and enforceability of rights, including permanent rights of redemption and any claims that owners may have against the Issuer; 10. information on any rights an owner of the Virtual Asset will have in the event the Issuer is Insolvent, including in the context of any scheme of arrangement or recovery plan; 11. information on whether different rights are allocated to different owners, and the nondiscriminatory reasons for such different rights; 12. information on the arrangements put in place by the Issuer to ensure the liquidity of the Virtual Asset, including the name of the Entities in charge of ensuring such liquidity; 13. the contact details for submitting complaints, and a description of the complaintshandling procedures and any dispute resolution mechanism or redress procedure established by the Issuer of the Virtual Asset; 14. detailed information on any rights of redemption and how the Virtual Asset is redeemed, including whether the owner will be able to choose the form of redemption, the form of transference, or the official currency of redemption; 15. any material legal or regulatory considerations applicable to owning, storing, transferring, or otherwise using the Virtual Asset, including to give legal effect to a transfer of ownership; and 16. the law applicable to the Virtual Asset, as well as the competent court. D. Information about underlying technology
Page 99 of 101 4. a specific notice that purchasers participating in the offer to the public of Virtual Asset will be reimbursed if the minimum target subscription goal is not reached at the end of the offer to the public, or if the offer is cancelled, and a detailed description of the refund mechanism, including the expected timeline of when such refunds will be completed; 5. the issue price of the Virtual Asset being offered to the public, denominated in both PKR and/or any other Virtual Assets; 6. the total number of Virtual Assets to be offered to the public, and the percentage of the total supply in circulation (i.e. supply available prior to the intended new issuance) of the Virtual Asset that the offer to the public represents; 7. an indication of the prospective owners targeted by the offer to the public, including any restriction as regards the type of owners for such Virtual Assets; 8. information about the various phases of the offer to the public of Virtual Assets, including information on discounted purchase prices for early purchasers of Virtual Assets (prepublic sales). In the case of discounted purchase prices for some purchasers, an explanation why purchase prices may be different, and a description of the impact on the other investors; 9. for time-limited offers, the subscription period during which the offer to the public is open; 10. arrangements to safeguard funds or other Virtual Assets during the time-limited offer to the public or during the withdrawal period; 11. methods of payment to purchase the Virtual Assets offered, and methods of transfer of the value to the purchasers when they are entitled to be reimbursed; 12. information on any rights the Issuer has to withdraw or cancel the offer to the public; 13. information on the manner and time schedule of transferring the purchased Virtual Assets to the owners and/or holder; 14. expenses to be incurred by purchasers of the Virtual Asset related to the offer to the public of the Virtual Asset, including any applicable subscription fee or the method in accordance with which the offer price will be determined; 15. potential conflicts of interest of the persons involved in the offer to the public arising in relation to the offer; and 16. the law applicable to the offer to the public of Virtual Assets, as well as the competent court. F. Information about Virtual Asset – ART
Page 100 of 101 3. Where the value of a Reference Asset cannot be established by reference to a reliable and observable market price, the Whitepaper shall a) describe the methodology used to determine its value; and b) include or be accompanied by an independent valuation report, or other independent valuation evidence approved by the Authority, with a valuation date not more than three (3) months before submission of the Whitepaper The valuation report or evidence shall identify, where available i). the name, qualifications and independence of the valuer ii). the valuation date iii). the methodology, material assumptions and principal data sources iv). the resulting value or valuation range v). any material limitation, uncertainty or conflict of interest. Where a material change occurs between the valuation date and issuance, the Issuer shall update the valuation or explain the effect of that change before issuance. The Authority may permit alternative evidence where an independent valuation report would not be meaningful or proportionate having regard to the nature of the Reference Asset. 4. whether the types of Reference Asset will change and, if so, the circumstances in which any such changes may take place; 5. whether the ART represents, or purports to represent, a direct right of ownership of the Reference Assets, or a fractional proportion thereof, and if so, a detailed description of how the right of ownership is established and/or such fractionalisation is structured; 6. if transactions in the Reference Assets are subject to legal or regulatory requirements relating to their settlement and/or transfer of title, a detailed description of how such requirements will be met and an explanation of how the VASP will respond to transactions in the ART not resulting in corresponding transactions in the Reference Asset being legally settled, completed and/or transferred, and any mitigation employed by the VASP to address such risks; 7. whether the ART maintains, or purports to maintain, a stable reference to the value of the Reference Assets, and if so, a detailed description of how such stable reference is maintained and the weighting of each type of Reference Asset in the unit value of the ART; 8. whether the VASP will maintain Reserve Assets in respect of the ART; 9. the types and composition of Reserve Assets, and criteria for how such Reserve Assets were identified; 10. whether the types of Reserve Asset may be subject to change and, if so, the circumstances in which any such changes may take place, including a detailed description of the VASP’s investment policy for the Reserve Assets; 11. a clear and detailed policy on the procedure for the creation and destruction of the ARTs in public circulation and the consequence of such creation or destruction on the increase and decrease of the Reserve Assets; 12. full details of the rights of owners and/or holders of the ART to redeem the value of the ART, including but not limited to the requirements under these Regulations and the procedures and timeline for owners and/or holders of the ART to redeem such value;
Page 101 of 101 13. the custody arrangement of the Reference Asset and/or Reserve Assets, including but not limited to, the custodians involved and how the VASP ensures it has timely access to Reserve Assets to process redemption requests; 14. detailed assessments of risks relevant to the management, custody, investment and/or liquidation of the Reference Asset and/or Reserve Assets, including but not limited to, credit risk, market risk, counterparty risk and liquidity risk, and policies and procedures to manage such risks for the purpose of processing redemption requests; and 15. any other relevant information as may be determined by the Authority. G. Information about Fiat Asset – FRT
More like this from PVARA
PVARA published 2 documents in the last 30 days. We email you each new one the day it's published.