2026-08-21
Added
The Pakistan Virtual Asset Regulatory Authority establishes licensing and regulatory requirements for Virtual Asset Service Providers (VASPs) operating in or from Pakistan under the Virtual Assets Act, 2026. The Regulations define key terms, including Professional and Retail Clients, and mandate that VASPs hold valid licenses for specific service categories while prohibiting the use of virtual assets as a means of payment for domestic commercial transactions without State Bank of Pakistan approval. Existing service providers are required to apply for licenses within six months of the Act's commencement, and pure virtual asset mining is exempt from licensing unless it involves customer assets or third-party services.
Page 1 of 77 The Gazette of Pakistan Extraordinary PART II Notification PAKISTAN VIRTUAL ASSET REGULATORY AUTHORITY NOTIFICATION Islamabad, August 21, 2026 S.R.O. 1419(I)/2026. In exercise of the powers conferred by section 68 of the Virtual Assets Act, 2026, the Pakistan Virtual Asset Regulatory Authority is pleased to make public the following Pakistan Virtual Asset Services Regulations, 2026 for licensing and regulation of VASPs carrying out one or more Virtual Asset Services as stated by Schedule 1 of the Virtual Assets Act, 2026 and any other service as may be notified by the Federal Government and subsequently included in Schedule I in accordance with section 18 of the Act: PAKISTAN VIRTUAL ASSET SERVICES REGULATIONS, 2026 CHAPTER – I General
Page 2 of 77 to establish or impose a requirement of general application on Licensees or a class of Licensees, unless expressly authorized by the Act or by Rules or Regulations made thereunder. 2A. Definitions. (1) In these Regulations, unless there is anything repugnant in the subject or context: (a) “Affiliate” means, in relation to a Person, any other Person that Controls, is Controlled by, or is under common Control with, that Person. (b) “Board” means the governing body of a VASP. (c) “Business Day” means a day on which banks are open for general business in Pakistan or such other place as specified by the Authority; and “Working Day” shall be read as “Business Day”. (d) “Change of Control” means any event, transaction, arrangement or series of transactions or arrangements (whether direct or indirect) that results in a Person acquiring, increasing, decreasing or ceasing to have Control of a Licensee, including where: (i). a Person becomes a Controller of the Licensee; (ii). a Controller ceases to be a Controller; (iii). there is any change in the identity of a Controller; (iv). a Person’s level of Control results in that Person becoming or ceasing to be a Controller within the meaning of the Act (including by reference to voting rights, share capital, decision-making rights or other means of Control); or (v). Control is acquired or altered through any means other than share ownership, including arrangements conferring the ability to appoint or remove a majority of directors, to exercise dominant influence, or to direct or materially influence management or policies (including through shareholder agreements, voting arrangements, veto rights, or acting jointly or in concert). (e) “Client” and “Customer” mean the same concept, and unless the context otherwise requires, any reference in these Regulations to a ‘Client’ shall be read as a reference to a ‘Customer’ as defined in the Act. (f) “Client Agreement” means the written agreement required under regulation 52. (g) “Control” means the ability to exercise, directly or indirectly, decisive influence over the management or policies of a Person, whether through ownership of voting rights, share capital, contractual arrangements, or otherwise, and includes acting jointly or in concert with others. (h) “Counter Proliferation Financing - CPF” means countering of Proliferation Financing as defined in the AML Act, 2010. (i) “Critical Function” means a Function the disruption, failure, or compromise of which would be likely to: (i). materially impair the Licensee’s ability to meet its obligations regarding safeguarding of Customer Assets; (ii). materially impair market integrity or the orderly operation or wind down of trading; (iii). materially impair AML/CFT/CPF compliance (including screening, transaction monitoring, or Travel Rule controls); (iv). prevent the Authority from exercising effective supervision, inspection, or access to records; or (v). materially impair financial stability.
Page 3 of 77 The Authority may specify additional Critical Functions by Regulations made under the Act or by written instrument issued under the Act. (j) “Dormant or In-Operative wallet” means the wallet in which no customer initiated transaction (debit or credit) or activity (e.g. login) has taken place during the preceding one year. (k) “Employee” means an individual employed by a Licensee on a full-time, part-time, temporary or seconded basis, and includes contractors and secondees where they perform Functions on behalf of the Licensee. (l) "ESG" means environmental, social and governance. (m)“Fit and Proper Person” means a person who meets the Fit and Proper Criteria set out in Schedule-II. (n) “Function” includes any operational, technological, governance, compliance, risk, custody, settlement, customer support, onboarding, screening, monitoring, recordkeeping, or other activity relevant to providing a Virtual Asset Service. (o) "Group" means a group of Persons consisting of a Person and its Affiliates. (p) “Independent Director” means a director who is free of any relationship, interest, or arrangement that could materially interfere with the exercise of independent judgment, including any material business, employment, remuneration (other than director fees), familial, or controlling-shareholder relationship with the Licensee, its Controllers, or its Affiliates in the opinion of the Board and documented in Board minutes. (q) "Insolvency Appointee" means a liquidator, receiver, administrator, compulsory manager, trustee or similar officer appointed in respect of a Person or its assets. (r) “Instrument” means: (i). any Rules or Regulations made under the Act; and (ii). any direction, circular, standard, directive, guideline or other written instrument issued by the Authority under the Act, in each case only to the extent, and with the legal effect (if any), expressly provided under the Act or under Rules or Regulations made thereunder, and for the avoidance of doubt, no Instrument may create a generally applicable obligation of a kind that, under the Act, is required to be prescribed by Rules or Regulations. (s) “Key Individual” means any natural Person who occupies or performs whether on a full-time, part-time, acting or outsourced basis, one or more of the following positions in relation to a Licensee: (i). director (executive or non-executive) registered under the Companies Act, 2017; (ii). Managing Director; (iii). chief financial officer; (iv). chief operating officer; (v). head of internal audit; (vi). head of compliance; (vii). money-laundering reporting officer (MLRO) or equivalent AML, CFT or CPF compliance officer designated under the AML, CFT and CPF Regulations issued pursuant to the Anti-Money Laundering Act, 2010; (viii). head of risk management; (ix). head of information-security and cyber-security; or (x). any other position that the Authority, by written notice to the Licensee, declares to be a Key Individual. (t) "Material" means any change, event or circumstance relating to a Licensee (or, where relevant, its Controllers, Group, or key arrangements) that may reasonably be expected to have, or give rise to a material risk of, or a material effect on:
Page 4 of 77 (i). the Licensee’s continued satisfaction of licensing conditions, including fit and proper status, financial resources, governance, or systems and controls; (ii). the nature, scope, scale, or risk profile of any Virtual Asset Service for which the Licensee is licensed; (iii). the safety, segregation, availability, or safeguarding of Customer Assets; (iv). the Licensee’s ability to comply with the Act, these Regulations, or any instruments made thereunder; or (v). customer protection, market integrity, financial stability, or AML/CFT/CPF outcomes. Unless otherwise expressly stated, references in these Regulations or any Rulebook to ‘material’, ‘significant’, ‘harm’, ‘loss’, ‘disadvantage’, ‘change’ or similar expressions shall be interpreted by reference to the definition of ‘Material’ set out in these Regulations, taking into account the nature, scale, complexity and risk profile of the Licensee and the relevant activity. A matter may be considered material where it gives rise to a material risk to the outcomes specified in the definition of ‘Material’, whether or not actual harm or loss has occurred. (u) “Material Outsourcing” means Outsourcing of a function which, if disrupted, degraded, or compromised, could materially impair: (i). the Licensee’s ability to comply with the Act, these Regulations, or any instruments made thereunder; (ii). the Licensee’s financial soundness or operational resilience; (iii). the integrity, availability, confidentiality, or security of Customer Assets or customer data; or (iv). the Authority’s ability to supervise the Licensee effectively. (v) "Outsourcing" means an arrangement (whether contractual or otherwise) under which a Service Provider performs, provides, supports, or makes available to a Licensee a Function, process, service, activity, system, infrastructure, resource, or role that the Licensee would otherwise perform, provide, or manage itself, on a recurrent, ongoing, or material basis. Outsourcing includes: (i). intra-group arrangements (including where the Service Provider is an Affiliate, related entity, or Group entity); (ii). arrangements involving sub-outsourcing or chain outsourcing; (iii). arrangements performed within or outside Pakistan, including cross-border outsourcing; and (iv). cloud computing. Outsourcing does not include the mere procurement of standardized, off-the-shelf goods or utilities that do not involve the performance of a function relevant to a Virtual Asset Service. (w)“Personal Data” means any information that relates to an identified or identifiable natural person, and includes any information defined as “personal data” or equivalent under any applicable personal data protection law in force in Pakistan from time to time. (x) “Prescribed” means prescribed by Rules or Regulations made under the Act. (y) “Professional Client” means a Client that meets following criteria: (i). a regulated financial institution in Pakistan; (ii). a public company listed on a recognized exchange; and (iii). a body corporate meeting at least two of the following, as evidenced by its most recent audited financial statements (or such other reliable evidence as may be specified by the Authority):
Page 5 of 77 a. net assets equal or greater than PKR 100,000,000; b. annual turnover equal or greater than PKR 250,000,000; c. treasury/investment function with a designated qualified officer; and includes any other Person meeting experience and knowledge tests as may be prescribed by the Authority. Without prejudice to the foregoing, a Retail Client may be treated as a Professional Client (“opt-up”) where the Licensee has assessed that such Client possesses sufficient knowledge and experience to understand the risks of the relevant Virtual Asset Services, and the Client has provided a written request and written acknowledgement of the loss of protections applicable to retail Clients. (z) “Retail Client” means a Client that is not a Professional Client. (aa) “Service Provider” means any Person (including an Affiliate, related entity, or Group entity) that provides, performs, supports, or makes available any Function, service, process, activity, system, infrastructure, personnel, or resource to or for a Licensee, whether under an Outsourcing arrangement or otherwise. (bb) “Related Party” means, in relation to a Licensee, any of the following Persons, whether acting directly or indirectly and whether within or outside Pakistan: (i). any Controller of the Licensee; (ii). any director of the Licensee; (iii). any Key Individual of the Licensee; (iv). any Ultimate Beneficial Owner of the Licensee or its Controller (to the extent the Licensee is required to identify such Person under applicable AML/CFT/CPF requirements); (v). any Subsidiary of the Licensee, any Holding Company of the Licensee, or any other entity within the same Group as the Licensee; (vi). any entity in which any Person referred to in paragraphs (a) to (d) directly or indirectly: a. holds ten percent (10%) or more of the voting rights or share capital; or b. has the ability to exercise significant influence over management or policies; (vii). any close relative of a Person referred to in paragraphs (b) to (d), meaning a spouse, parent, child, sibling, or any other person who is financially dependent on, or whose financial affairs are interdependent with, that Person; and (viii). any Person or arrangement (including a partnership, trust, or similar structure) where the Authority has reasonable grounds to believe that the relationship creates a material conflict of interest or risk of preferential treatment in relation to the Licensee. For the avoidance of doubt, a Service Provider is not a Related Party solely because it provides services to the Licensee on arm’s length terms. For the avoidance of doubt, this definition applies for the purposes of the Act and these Regulations and does not limit, replace or modify any obligation relating to Related Parties or related-party transactions arising under the Companies Act, 2017, applicable related-party transaction rules or applicable financial-reporting standards. (cc) “Subsidiary” means, in relation to a Person, any legal person that is controlled by that Person, whether directly or indirectly, including through one or more other Subsidiaries, and “control” means:
Page 6 of 77 (i). the power to exercise more than 50% of the voting rights in that legal person; or (ii). the power to appoint or remove a majority of the members of the governing body; or (iii). the power to exercise a dominant influence over that legal person by virtue of a contract, constitutional document, or other arrangement (dd) “Ultimate Beneficial Owner” or “UBO” shall have the meaning assigned to it under the Anti-Money Laundering Act, 2010 and any rules, regulations, or binding directions/guidelines issued under the AML Act, 2010 by the competent authority thereunder, as applicable. (2) Words and expressions used but not defined in these Regulations shall have the same meanings as assigned to them in the Act, the State Bank of Pakistan Act, 1956, the Securities Act, 2015, the Anti-Money Laundering Act, 2010, or the Companies Act, 2017. (3) The additional definitions in this Regulation apply for the purposes of these Regulations only. CHAPTER – II Scope and Categories of Virtual Asset Service Providers 3. Scope of Regulation. (1) These Regulations apply to any Person who carries on, or holds itself out as carrying on, a Virtual Asset Service: (a) in Pakistan; or (b) from Pakistan; to the extent such activity falls within the scope of the Act and any determination made under the Act (2) These Regulations apply in addition to the Act and any Rules or Regulations made thereunder, and any standards, directives, guidelines, or other instruments issued by the Authority under the Act, as applicable. (3) In the event of any inconsistency, the Act shall prevail. These Regulations shall prevail over any standards, directives, guidelines, or other instruments issued by the Authority under the Act, to the extent of such inconsistency. (4) For the purposes of sub-regulation (1)(a), an activity may be regarded as carried on “in Pakistan” where it targets, solicits, promotes to, or onboard persons in Pakistan, including through marketing (where through website, mobile app or any other medium), payment rails, or provision of services in PKR or through channels accessible to Persons in Pakistan. (5) Safe harbours. -For the purposes of sub-regulation (1)(a), an activity shall not, of itself, be regarded as carried on “in Pakistan” solely because a website, application or other digital interface is accessible in Pakistan, where the Person: (a) does not market or solicit in Pakistan; (b) does not onboard Persons in Pakistan; (c) does not support PKR payment rails or Pakistantargeted channels; and (d) takes reasonable steps to prevent onboarding where it does not intend to serve Persons in Pakistan. The Authority may nevertheless determine otherwise only where it has reasonable grounds, recorded in writing, that the Person has in substance targeted Persons in Pakistan or has a real and substantial connection with Pakistan. Any such determination shall be reasoned and communicated in writing.
Page 7 of 77 (6) Virtual assets shall not facilitate, or be used or recognized as, a means of payment for domestic commercial transactions, except where specifically approved by the State Bank of Pakistan pursuant to Section 9(1)(f) of the Act. 4. Categories of License. (1) For operational and licensing purposes, the Authority shall issue Licenses in one or more of the Categories as defined in Schedule I to the Act. (2) A Person may apply for one or more Licence Categories. A Licence shall specify the Licence Categories authorised and any limitations, conditions, or permissions applicable thereto. (3) Where an activity could fall within more than one Licence Category, the applicant or Licensee shall seek license for respective category. (4) Unless expressly stated otherwise, requirements in these Regulations shall be applied in a manner proportionate to the nature, scale, complexity and risk-profile of the Licensee's business and the Virtual Asset Services it provides. Proportionality permits a Licensee to comply with a requirement through systems, controls, governance arrangements, reporting mechanisms, or other measures that are appropriate to its business model, provided that the underlying regulatory objective is achieved. The Authority shall take proportionality explicitly into account in rulemaking, licensing, supervision and enforcement decisions, and shall not impose requirements that are disproportionate to the risks identified that are over and above the ones expressly stated in the Act, the Rules or Regulations. Where a Licensee considers that a requirement has been applied in a manner that is disproportionate to its risk profile, it may make written representations to the Authority and the Authority shall provide a reasoned response. For the avoidance of doubt, nothing in this regulation limits or modifies the application of any offence, penalty, administrative sanction, or enforcement power under the Act, and any contravention of these Regulations shall be enforceable in accordance with the Act, including through administrative sanctions under section 59 of the Act and any criminal sanctions or offences to the extent specified in the Act or in Rules made under section 67 of the Act. (5) Sub-regulation (4) constitutes the core proportionality obligation for the purposes of these Regulations and shall apply to the interpretation, application and exercise of discretion under these Regulations unless a provision expressly states otherwise. For the avoidance of doubt: (a) proportionality does not permit a Licensee to disapply or reduce compliance with an express, fixed or unconditional requirement of the Act or the Regulations; and (b) where these Regulations confer a discretion on the Authority (including in relation to licensing conditions, supervisory requirements, reporting, audits, capital add-ons, or enforcement measures), the Authority shall exercise that discretion consistently with sub-regulation (4), having regard to the risks identified and the regulatory objectives. (6) With respect to the Mining-related virtual asset activities License, pure Virtual Asset mining, by itself, shall not constitute a Virtual Asset Service requiring a Licence under the Act, in accordance with section 37(2) of the Act. Mining operations involving Customer Assets or Customer funds, or otherwise involving the provision of services to third parties on a professional basis in a manner that falls within the categories of Virtual Asset Services in the Act, shall be treated as Virtual Asset Services and shall require licensing in accordance with the Act. Where the Authority establishes a registration or declaration framework for mining operators exceeding thresholds of scale, energy use, or hash rate, as set by Regulations, a Licensee that engages in mining activities within the scope of such framework shall comply
Page 8 of 77 with the prescribed registration or declaration requirements, in accordance with section 37(3) of the Act. CHAPTER – III Licensing of Virtual Asset Service Providers 5. Eligibility criteria. (1) No Person shall, by way of business, engage in, or hold themselves out as engaging in, any Virtual Asset Service in or from Pakistan unless that Person: (a) is a company incorporated under the Companies Act, 2017 or any other law for the time being in force in Pakistan governing the incorporation of companies, as required under the Act, for the purpose of providing Virtual Asset Services; and (b) holds a valid Licence granted by the Authority under the Act for the relevant Category or Categories of Virtual Asset Services. (2) The Authority may, by Regulations, prescribe additional eligibility requirements for specified Licence Categories, including governance arrangements, and prudential requirements, where proportionate to the primary objectives of the Act. (3) A licence granted by the Authority authorizes the VASP to provide only those categories of Virtual Asset Services which are expressly specified in the Licence and any schedule or annex to it and is subject to such conditions as the Authority may impose. (4) A Licensed VASP shall not carry on any activity which falls within another category of Virtual Asset Services unless it is also licensed for that category or is otherwise authorised by the Authority in writing. 5A. Transitional arrangements for existing service providers. — (1) Any Person providing Virtual Asset Services immediately before the commencement of the Act shall, within six (6) months of such commencement, apply to the Authority for a Licence under the Act or shall cease to provide such services, in accordance with section 70(1) of the Act and Regulation 6 of these regulations. (2) Where, within six (6) months of commencement of the Act, such Person has submitted a complete application that satisfies the requirements of the No Objection Certificate application referred herein, it may continue to provide its existing Virtual Asset Services pending the determination of the application, provided that it fully complies with any interim directives issued by the Authority and continues to adhere to the core obligations of the Act, particularly regarding customer asset protection and AML, CFT and CPF, in accordance with section 70(2) of the Act. Provided further that till the determination of the application, if the applicant intends to conduct any marketing activity, it shall seek prior approval of the Authority. (3) The Authority may, by written direction, impose proportionate interim limitations or conditions on such Person during the pendency of its application, including limitations on onboarding, products, transaction volumes, or custody arrangements, where necessary to protect customers or market integrity. (4) Any guideline, direction, circular, approval, exemption, permission, sandbox arrangement, or other instrument issued or granted by the Authority under the Virtual Assets Ordinance (including any regulatory sandbox guideline or permission) and in force immediately before
Page 9 of 77 the commencement of the Act shall, to the extent not inconsistent with the Act or these Regulations, continue in full force and effect as if issued under the corresponding powers of the Act, until amended, replaced, or revoked by the Authority under the Act. (5) Where the Authority considers that any such instrument requires modification to ensure consistency with the Act, the Authority may, by written notice, amend or impose conditions on the continued application of such instrument, provided that any material modification of general application shall be effected by Rules or Regulations made under the Act. 6. Preliminary Approval / No-Objection Certificate (NOC) for incorporation. — (1) A Person intending to establish a company in Pakistan for the purpose of applying for a Licence to carry on one or more Virtual Asset Services may apply to the Authority for a Preliminary Approval / No-Objection Certificate (NOC). (2) An application (Form I) under this regulation shall include such minimum information and documents as specified in Annexure to Form 1. The Authority may while reviewing the application seek any additional information as may be required (3) The Authority shall, within sixty (60) days of receiving a complete application: (a) grant a NOC, subject to the conditions specified therein; or (b) refuse the application, providing written reasons. (4) A NOC granted under this regulation: (a) does not constitute a Licence or authorization to carry on any Virtual Asset Service; (b) is without prejudice to the Authority’s full assessment of any subsequent Licence application; (c) may be withdrawn where it was obtained on the basis of materially false, misleading or incomplete information. (5) A NOC shall be valid for three (3) months from the date of issuance and may, on application made before expiry and for reasons recorded, be extended for a further period not exceeding three (3) months. (6) Where an application for a NOC is refused, the applicant may submit a fresh application once the grounds for refusal have been addressed, or may request reconsideration in the manner Prescribed. (7) Where a Person incorporated pursuant to a NOC does not submit a Licence application within the applicable period, the Authority shall give the Person written notice and not less than thirty Business Days to: (a) submit the Licence application (b) request an extension for reasonable cause; or (c) confirm that it will not conduct or hold itself out as conducting a Virtual Asset Service and take any necessary steps under the Companies Act, 2017. (8) The Authority may refer the matter to SECP where the Person fails to respond within the applicable period or continues to represent that it will conduct a Virtual Asset Service without a Licence.
Page 10 of 77 (9) The Authority may issue guidance. guidelines or other non-binding instruments describing the process and typical documentation for NOC applications, including examples of activities likely to fall within or outside the regulatory perimeter. 7. Application for License. - (1) Following incorporation in Pakistan and within the validity period of an NOC, an applicant shall apply to the Authority for the grant of one or more Licence Categories to carry on Virtual Asset Services, including submission of the documents and information specified in the Annexure to Form I (as updated/amended, where required, from earlier submission at the time of NOC application) and payment of the applicable non-refundable processing fee as prescribed. (2) An application shall be treated as complete only when the Authority has confirmed, in writing, that all required information and documents have been received in a satisfactory form. Where the Authority requests further information, the time for deciding the application shall be suspended until the requested information is provided. (3) The Authority shall decide a complete application within ninety (90) days, unless extended in accordance with sub-regulation (4). (4) The Authority may extend the period in sub-regulation (3) by up to sixty (60) days, for reasons recorded in writing, where the application is complex, involves novel risks, or requires consultation with other competent authorities. (5) Limited-scope Licence. The Authority may grant a limited scope Licence where necessary to advance the primary objectives of the Act. The Authority shall specify the scope, duration, conditions, and exit criteria in such limited Licence. (6) Sandbox transition. Participation in a regulatory sandbox does not create an entitlement to a Licence. Where a sandbox participant successfully completes its testing to the satisfaction of the Authority, it may apply directly for a Licence under regulation 7, and shall not be required to apply for or obtain a separate Preliminary Approval / No-Objection Certificate under regulation 6. The Authority may, however, take into account testing outcomes and compliance history in assessing a subsequent Licence application, subject to the applicant meeting all applicable requirements. (7) NOC Regulation 2025 transition: Where an No-Objection Certificate under NOC Regulation 2025 has been granted, the applicant may directly apply for a License under regulation 7. Further applicants who have submitted NOC application under NOC Regulations 2025 and are in correspondence with the Authority shall not be required to submit fresh NOC application under Regulation 5A and Regulation 6 of these Regulations. The Authority may require any additional information at any point in time. 8. Fit-and-Proper Assessment. - (1) The Authority shall assess the fitness and propriety of Controllers, Directors, sponsors, managing director of an applicant or Licensee in accordance with the Act and these Regulations, and any fit-and-proper requirements prescribed by Regulations made under the Act. (2) In conducting a fit-and-proper assessment, the Authority shall have regard to: (a) integrity, honesty and reputation; (b) competence, capability and relevant experience; (c) financial soundness; and
Page 11 of 77 (d) conflicts of interest and independence, where relevant to the role. (3) For the purposes of sub-regulation (1), the Authority may require any information reasonably necessary, which may include criminal record checks, regulatory references, financial/credit information, professional qualifications, and declarations of investigations or enforcement action in Pakistan or any other jurisdiction. (4) The Authority may conduct interviews, request additional information, and conduct independent verification through third parties or competent authorities, subject to applicable law. (5) Controllers, Directors, and Key Individuals shall remain fit and proper on an ongoing basis, and the Licensee shall notify the Authority of any matter that may reasonably affect such assessment, including any Material change, in the manner and timeframe prescribed. 9. Grant or refusal of Licence and conditions. — (1) The Authority shall, within the timeframe specified in regulation 7, and after making such inquiries as it considers appropriate, either: (a) grant a Licence for one or more Licence Categories, subject to such conditions, limitations, and requirements as the Authority considers necessary and proportionate to advance the objectives of the Act; or (b) refuse the application, providing written reasons. (2) Before refusing an application or imposing any materially adverse condition or limitation, the Authority shall afford the applicant an opportunity to make representations, except in urgent cases, provided that the applicant shall be given an opportunity to be heard as soon as reasonably practicable thereafter. (3) A Licence remains in force subject to compliance with the Act, these Regulations, any Rules or Regulations made under the Act, any applicable standards, directives, guidelines or other instruments issued by the Authority under the Act, and the Licence conditions, unless suspended, varied, or revoked by the Authority in accordance with the Act. (4) The Authority may require a Licensee to commence business within a specified period stated in the Licence. Where the Licensee does not commence within that period, it shall promptly notify the Authority and the Authority may vary, suspend, or revoke the Licence, unless an extension is granted for reasons recorded in writing. (5) The Licensee shall pay applicable annual supervisory, renewal, and other fees as prescribed by the Authority. (6) The Authority shall maintain and publish an up-to-date public register of Licensees in accordance with the Act. 10. Ongoing Obligations of Licensee. - (1) A Licensee shall at all times: (a) conduct its business with due skill, care and diligence and maintain systems and controls appropriate to its nature, scale and complexity; (b) maintain adequate governance, risk management, compliance, and internal control arrangements, including an effective compliance function and internal audit arrangements commensurate with its business;
Page 12 of 77 (c) maintain books and records sufficient to enable the Authority to assess compliance and the Licensee’s financial position, and retain such records for not less than seven (7) years or such longer period as may be required under the applicable law; (d) prepare financial statements in accordance with the applicable law and international standards as adopted in Pakistan, and submit periodic returns in the manner and frequency specified; (e) comply with AML/CFT/CPF obligations under AML Act, 2010 and applicable law, including reporting obligations to relevant competent authorities; and (f) maintain operational resilience, cybersecurity, business continuity, and incident management arrangements in accordance with the Act, these Regulations, any Rules or Regulations made under the Act, and any applicable direction, circular, standard, directive, guideline or other written instrument issued by the Authority under the Act. (2) Notification duties. - A Licensee shall comply with the notification and reporting requirements set out in these Regulations, and any requirements specified in its Licence conditions, and any Rules or Regulations made under the Act, and any applicable direction, circular, standard, directive, guideline or other written instrument issued by the Authority under the Act. (3) Capital and prudential requirements. A Licensee shall maintain at all times the minimum paid-up capital and any other prudential requirements applicable to its Licence Category or Categories as set out in Schedule I. (4) Local presence. - A Licensee shall maintain a registered office in Pakistan and shall ensure that it has one key individual, to be resident in Pakistan and is vested with operational and decision-making authority and accountable to the Authority for regulatory compliance. The Authority may, having regard to the Licensee’s nature, scale, complexity and risk profile, require that number of such officers be increased. (5) Regulatory approvals. A Licensee shall not, without the prior written approval of the Authority: (a) effect a change in Control or a Material change in ownership; (b) merge with, acquire, or dispose of a material part of its business or assets; or (c) outsource a material or critical function in a manner that materially affects its ability to comply with the Act or these Regulations, except as otherwise Prescribed. (6) For the purposes of regulation 10 (5)(c) above, a Licensee shall obtain the Authority’s prior written approval only for the outsourcing of a Critical Function. The licensee shall update its outsourcing register in accordance with Chapter V. (7) The Authority may provide detailed procedures for matters under these Regulations (including operational resilience, cybersecurity, proof-of-reserves, segregation of customer assets, disclosures, audits and reporting) by issuing standards, directives, guidelines or other instruments under the Act to support implementation.. (8) A Licensee shall be able to demonstrate, its compliance with the Act and these Regulations, including the adequacy and effectiveness of its systems and controls, through such documentation, records, reports, and independent assurance as the Authority may require under the Act and these Regulations.
Page 13 of 77 (9) A Licensee shall disclose the sources of liquidity and funding used in their operations, to support oversight of financial soundness, with the Authority on monthly basis. 11. Payment of fee. - (1) An applicant or Licensee shall pay the processing fees, licensing fees, annual supervisory fees, renewal fees, and any other charges as published in the Rules. (2) Processing fees are non-refundable. Annual fees are payable in advance in the manner and time specified by the Authority. CHAPTER – IV Variation, Suspension, Revocation and Surrender of License 12. Variation of License. – (1) A Licensee may apply to the Authority to vary its Licence to: (a) add one or more Licence Categories; (b) remove a Licence Category; or (c) vary, substitute, or amend any limitation or condition of its Licence, in the form and manner specified by the Authority. (2) An application under sub-regulation (1) shall be accompanied by such information and documents as the Authority may reasonably require to assess the proposed variation, which may include an updated business plan, risk assessment, governance arrangements, operational readiness, and AML/CFT/CPF controls, and payment of the applicable non-refundable fee as prescribed. (3) The Authority may grant the variation subject to such conditions, limitations, or transitional arrangements as it considers necessary and proportionate to advance the objectives of the Act. (4) The Authority may refuse an application for variation, giving written reasons and affording the applicant an opportunity to make representations, except in urgent cases, provided that an opportunity to be heard shall be given as soon as reasonably practicable thereafter. (5) The Authority may on its own initiative vary a Licence (including by varying the authorised scope of activities within an existing Licence Category, or varying limitations) where necessary to address material risk, non-compliance, or to protect customers or market integrity, provided that the Authority shall give prior written notice stating reasons and an opportunity to make representations, except in urgent cases to be dealt in accordance with Section 60 of the Act, provided that the applicant shall be given an opportunity to be heard as soon as reasonably practicable thereafter. 13. Suspension of License. – (1) The Authority may suspend a Licence in whole or in part, for a specified period or until specified conditions are met, where the Authority is reasonably satisfied that the Licensee: (a) is in material breach of the Act, these Regulations, any Rules or Regulations made under the Act, any applicable direction, circular or other regulatory requirement made or issued thereunder, or the Licence conditions; (b) no longer meets applicable prudential, governance, fit-and-proper, or operational resilience requirements; (c) has failed to provide required returns or information, or has provided materially false, misleading, or incomplete information;
Page 14 of 77 (d) has suffered a material cybersecurity, operational, or safeguarding incident; (e) has failed to pay fees due; (f) is insolvent; (g) has ceased to carryon Virtual Asset Service for a continuous period of one year, or any other period as specified by the Authority, for which it is licensed; (h) the license was obtained by fraud, misrepresentation, or concealment of material facts; or (i) otherwise presents a material risk to customers, market integrity, financial stability, or AML/CFT/CPF objectives. Or such action is necessary or expedient in the public interest including for the protection of consumers, the integrity of the market or financial stability. (2) Before suspending a Licence, the Authority shall give written notice stating reasons and the proposed effective date, and afford the Licensee an opportunity to make representations, except in urgent cases where immediate action is necessary, to be dealt in accordance with section 60 of the Act; provided that the Licensee shall be afforded an opportunity to be heard as soon as reasonably practicable thereafter. (3) A Licensee whose Licence is suspended shall comply with any Direction issued by the Authority, which may include requirements for orderly wind-down, safeguarding and return of Customer Assets, maintenance of records, continued reporting, and restrictions on onboarding or trading. (4) A Licensee may apply for removal of suspension by demonstrating remediation of the grounds for suspension, supported by evidence. The Authority shall decide such application within a reasonable time and may impose conditions on resumption. 14. Revocation of License. – (1) The Authority may revoke a Licence (in whole or in part) where, after inquiry and consideration of representations, it is satisfied that the Licensee: (a) has committed: (i) a serious or repeated contravention of the Act, these Regulations, any Rules or Regulations made under the Act, any applicable direction, circular or other regulatory requirement made or issued thereunder, or the Licence conditions, having regard to the nature, impact, and materiality of the contravention; or (ii)repeated contraventions of the Act, these Regulations, any Rules or Regulations made under the Act, any applicable direction, circular or other regulatory requirement made or issued thereunder, or the Licence conditions, whether of the same or similar nature, that demonstrate persistent noncompliance or a failure to remediate within a reasonable period; (b) no longer meets fit-and-proper, governance, prudential, or operational requirements and cannot remediate within a reasonable period; (c) obtained the Licence through fraud, material misrepresentation, or concealment; or (d) presents a continuing material risk to customers, market integrity, financial stability, or AML/CFT/CPF objectives such that revocation is necessary and proportionate. (e) has failed to obtain required approvals for Material changes in control, ownership, or business, or has carried on activities outside the scope of its Licence, where such conduct is material or persistent; or (f) is in non-compliance with any of the conditions listed in Section 23(1) of the Virtual Assets Act, 2026 Or such action is necessary or expedient in the public interest including for the protection of consumers, the integrity of the market or financial stability.
Page 15 of 77 (2) Prior to revocation, the Authority shall provide written notice stating reasons and the proposed effective date, and afford an opportunity of being heard, except in urgent cases to be dealt in accordance with section 60 of the Act, provided that an opportunity to be heard shall be given as soon as reasonably practicable thereafter. (3) The Authority may impose conditions or issue Directions to ensure an orderly cessation of operations, including measures relating to Customer Assets, withdrawals, record retention, communications to customers, and continued reporting. (4) The Authority may publish notice of revocation on its website and through other appropriate means, subject to confidentiality and legal constraints, including, where appropriate, a summary of the reasons for revocation. (5) Where appropriate, the Authority may notify the Securities and Exchange Commission of Pakistan or other competent authorities and may take steps consistent with applicable law relating to winding-up, administration, or other insolvency processes. (6) Revocation shall not affect any accrued rights, obligations, or liabilities arising before the effective date of revocation. 15. Cybersecurity and data protection during variation, suspension, revocation, or surrender. — (1) Where a Licence is varied, suspended, revoked, or surrendered, the Licensee shall ensure secure preservation, integrity, and (where applicable) orderly transfer or disposal of Customer data, Customer Assets, private keys and credentials, and relevant system logs, in accordance with the Act, these Regulations, any Rules or Regulations made under the Act, and any applicable direction, circular or other regulatory requirement made or issued thereunder. (2) The Authority may require the Licensee to obtain an independent cybersecurity, systems, or controls assurance report, or may conduct or commission a targeted review, where necessary to manage risks of unauthorized access, tampering, loss, or leakage. 16. Voluntary Surrender of VASP License. – (1) A Licensee may apply in writing to surrender its Licence (in whole or in part), stating reasons and providing such information as the Authority may reasonably require. (2) Surrender shall not take effect until the Authority confirms in writing that adequate arrangements have been made for an orderly wind-down, including safeguarding and return of Customer Assets, settlement of liabilities, record retention, and customer communications, and any other matters necessary to ensure that the Licensee has met its outstanding obligations. (3) The Authority may impose conditions or issue Directions in connection with surrender to protect customers and market integrity, including requiring the appointment of an independent person to oversee wind-down where proportionate, and may take such measures as it considers appropriate to ensure an orderly wind-down. (4) Any Person aggrieved by an order or decision of the Authority under these Regulations may prefer an appeal in accordance with Chapter 11 of the Act and the Prescribed Rules. 17. Administrative sanctions. – (1) Without prejudice to any other power under the Act or these Regulations, where the Authority is reasonably satisfied that any Person has contravened
Page 16 of 77 any provision of the Act, or any Rules, Regulations, directions, circulars, or other regulatory requirements made thereunder, the Authority may impose one or more administrative sanctions in accordance with section 59 of the Act. (2) Administrative sanctions may include, as applicable: (a) a written reprimand or public censure; (b) a directive requiring the Person to cease or remedy the contravention; (c) a financial penalty up to the maximum amount permitted under the Act and any Rules; (d) suspension or revocation of a Licence; and (e) disqualification of any Person from holding any office or position of responsibility in a Licensee, as provided in section 59(1) of the Act. (3) Before imposing a sanction under these Regulations, the Authority shall provide written notice stating the proposed sanction, reasons, and statutory basis, and shall afford the Person an opportunity to make representations, except where urgency justifies immediate action, provided that an opportunity to be heard shall be given as soon as reasonably practicable thereafter. (4) The Authority shall communicate its decision in writing stating reasons and statutory basis and may publish such decision where appropriate, subject to confidentiality and legal constraints. (5) Nothing in these Regulations shall be construed as expanding or modifying the emergency intervention powers set out in section 60 of the Act. CHAPTER – V Governance and Operations of Virtual Asset Service Providers 18. Ownership and control structure. - (1) A Licensee shall maintain a transparent ownership and control structure, including a clear chain of ownership and voting rights, such that the Authority can identify each Controller and the basis on which Control is exercised, including, where applicable, ultimate beneficial owners and persons exercising control through other arrangements. (2) A Licensee shall maintain and keep updated a group structure chart and such supporting information as the Authority may reasonably require, including information on direct and indirect ownership interests, voting arrangements and persons acting in concert, and any delegated authority relevant to the exercise of Control. (3) For the avoidance of doubt, any requirements relating to identification of beneficial owners for AML/CFT/CPF purposes shall be complied with in accordance with applicable AML/CFT/CPF laws and requirements. 19. Change of Control. - A Licensee shall not affect any Change of Control except with the Authority’s prior approval, in accordance with the Act and regulation 48 and 49. 20. Board composition and fitness and propriety. - (1) A Licensee shall appoint at least 3 directors in accordance with the Companies Act, 2017 and the Act.
Page 17 of 77 (2) A Licensee shall ensure that its Board includes Independent Directors to support effective oversight, risk management and customer protection. (3) Unless the Authority specifies otherwise based on the Licensee’s nature, scale, complexity and risk profile, Independent Directors shall comprise at least one third (1/3) of the Board. (4) The Authority may permit a lower proportion for limited scope licenses under regulation 7(5), or where the Board is small, provided equivalent independent challenge and oversight is achieved through governance arrangements acceptable to the Authority, including through board committees, external advisors, or other mechanisms as may be appropriate. (5) A Licensee shall ensure that its Board collectively has skills, knowledge and experience proportionate to the nature, scale and complexity of the Licensee and the Virtual Asset Services it provides, including competence in risk management, technology and cybersecurity, and financial crime compliance. (6) A Person shall not act as a Controller, Sponsor, Managing Director or Director(s) unless that Person meets the fit and proper requirements under the Act and these Regulations, and has been approved by the Authority. (7) The Authority shall, within thirty (30) Business Days of receiving a complete application for approval of a Controller, Sponsor, Managing Director or Director, notify the Licensee in writing of its decision. Where the Authority cannot determine the application within that period because specified information is awaited from the applicant or an identified competent authority, it shall, before expiry of the period (a) identify the outstanding information or matter; (b) notify the Licensee of the reason for the delay and the revised expected decision date; and (c) provide an updated status at least every fifteen (15) Business Days until the application is determined, The determination shall be made as soon as reasonably practicable, and the period shall not be extended solely because of internal administrative delays. 21. Responsibilities of the Board. — (1) The Board shall have overall responsibility for the governance and oversight of the Licensee and for ensuring compliance with the Act and instruments made thereunder. (2) Without prejudice to subsection (1), the Board shall ensure that the Licensee maintains effective arrangements for: (a) governance, internal controls and risk management, including operational resilience and cybersecurity; (b) AML/CFT/CPF compliance and market integrity controls; (c) safeguarding and segregation of Customer Assets, where applicable; (d) oversight of Outsourcing and Service Providers; and (e) recordkeeping and regulatory reporting. (3) The Board may delegate functions to committees or Key Individuals, provided that it retains ultimate responsibility and maintains adequate oversight, reporting lines and documentation of such delegation.
Page 18 of 77 22. Board performance and training. - (1) A Licensee shall ensure that each director receives induction training and ongoing training appropriate to the director’s responsibilities and the Virtual Asset Services carried on by the Licensee. (2) A Licensee shall periodically assess the effectiveness of the Board and its committees and shall take reasonable steps to address identified gaps through training, resourcing or governance enhancements. 23. Compliance function and Compliance Officer. - (1) A Licensee shall establish and maintain an independent compliance function proportionate to its nature, scale and complexity. (2) A Licensee shall appoint a Compliance Officer responsible for overseeing compliance with the Act and instruments made thereunder, including AML/CFT/CPF obligations, and for reporting material compliance matters to the Board. (3) The Compliance Officer shall: (a) be sufficiently senior and have adequate resources and access to information to perform the role effectively; and (b) meet the fit and proper requirements under these Regulations; and (c) be a resident in Pakistan. (4) A Licensee shall notify the Authority of the appointment, replacement or departure of the Compliance Officer, including reasons for the change. 24. Key Individuals and management structure. - (1) A Licensee shall establish, document and maintain a management structure that clearly allocates responsibilities, authorities and reporting lines for Key Individuals. (2) A Licensee shall ensure that Key Individuals are fit and proper and collectively have the skills and experience necessary to manage the Licensee’s business, including operational risk, technology and cybersecurity, and financial crime compliance. (3) A Key Individual, other than directors, shall act under the direction and oversight of the Board and shall manage day-to-day activities in a manner that complies with the Act and instruments made thereunder. (4) A Licensee shall maintain and apply conflict-of-interest arrangements applicable to Key Individuals, including rules on external directorships and employment, and shall provide such information as the Authority may reasonably require. 25. Company Secretary. — (1) Where required under the Companies Act, 2017 or where directed by the Authority having regard to the nature, scale and complexity of the Licensee, the Board shall appoint a Company Secretary on terms approved by the Board. (2) The Company Secretary shall perform the functions required under applicable company law and such additional functions as may be assigned by the Board.
Page 19 of 77 26. Segregation of duties. — (1) A Licensee shall maintain organizational and procedural arrangements that ensure effective segregation between: (a) business and revenue-generating functions; and (b) control functions, including compliance, risk management, internal audit, and any other independent review function. (2) A Licensee shall ensure that operational duties, including sales, dealing, order handling, accounting, settlement, reconciliation, custody or safekeeping of Customer Assets, and related recordkeeping, are appropriately segregated to reduce the risk of conflicts of interest, errors, misconduct, or abuse. (3) The Compliance Officer and Head of Internal Audit (where appointed) shall have sufficient independence, authority, and access to the Board (or a Board committee) to discharge their duties, and shall not be involved in day-to-day revenue generation or operational decisionmaking. (4) Where the nature, scale, and complexity of the Licensee does not permit full segregation by personnel, the Licensee shall implement compensating controls, including enhanced supervision, dual controls, independent checks, and increased frequency of internal review. 27. Conflicts of interest. - (1) A Licensee shall take reasonable steps to identify, prevent, manage and, where necessary, disclose conflicts of interest, and shall ensure fair treatment of Customers in all circumstances. (2) Where a conflict of interest cannot be effectively prevented or sufficiently managed by organizational and procedural arrangements, the Licensee shall disclose the general nature and source of the conflict to affected Customers in a clear and timely manner before providing the relevant service, and shall document the basis on which Customer interests remain adequately protected. (3) A Licensee shall establish, maintain and implement a written conflicts-of-interest policy that includes, at a minimum: (a) identification and categorization of conflicts (including conflicts arising from proprietary trading, group structures, remuneration, listings, token issuance, and referral arrangements); (b) governance, escalation, approval and recusal procedures; (c) controls for gifts, hospitality, inducements and outside business interests; (d) personal account dealing controls for directors, Key Individuals and staff; and (e) recordkeeping and periodic review requirements. (4) A Licensee shall maintain a conflicts register recording conflicts identified, the measures taken, disclosures made, and any residual risk accepted. (5) Where a Board member or Key Individual has a material interest in a matter, that person shall promptly declare the interest, shall not participate in deliberations or voting on that matter, and shall not seek to influence the outcome. The Company Secretary (or equivalent) shall record the declaration and recusal in the minutes. 28. Disclosure governance. — (1) A Licensee shall establish and maintain policies and procedures to ensure that disclosures required under applicable law, these Regulations, and any instruments made under the Act are accurate, clear, not misleading, and kept up to date.
Page 20 of 77 (2) A Licensee shall ensure that required public disclosures and customer-facing disclosures are made in the form and manner specified by the Authority, including through its website or other channels as applicable. (3) The Board shall review disclosure governance periodically to ensure continued adequacy having regard to the Licensee’s business model, products, and risk profile. (4) Without prejudice to sub-regulations (1) to (3), disclosure governance shall apply to: (a) marketing materials and promotions issued, approved, procured, facilitated or disseminated by or on behalf of the Licensee, including ensuring inclusion of required risk disclosures and compliance with conditions, standards and limitations prescribed by the Authority, in accordance with section 43(2) of the Act; and (b) where the Licensee facilitates, approves or makes available a Virtual Asset offering to the public, the Licensee’s controls to verify and retain evidence of issuer disclosures (including whitepapers and ongoing disclosures) required under section 42 of the Act and Regulations made thereunder. 29. Personal account dealing and insiders’ transactions. - (1) A Licensee shall implement and enforce written policies and controls governing personal transactions in Virtual Assets by directors, Key Individuals, and relevant employees, including pre-clearance requirements, restricted lists, closed periods, and monitoring. (2) The policies shall prohibit, in accordance with section 52 of the Act: (a) dealing in Virtual Assets on the basis of inside information or material non-public information; (b) recommending or inducing any Person to deal in Virtual Assets on the basis of inside information or material non-public information; and (c) unlawful disclosure of inside information or material non-public information, and shall include procedures for identification and handling of inside information, information barriers, restricted lists and closed periods, pre-clearance, monitoring and escalation, and reporting to the Compliance Officer. (3) The Licensee shall maintain comprehensive records of personal account dealing approvals, disclosures, breaches, and monitoring outcomes, and shall provide such records to the Authority upon request. 30. Transactions with Related Parties. - (1) A Licensee shall not enter into a material transaction with a Related Party unless: (a) the transaction is on arm’s length terms; (b) the transaction is approved in advance by the Board (or an independent Board committee); and (c) any conflicted person is excluded from deliberation and voting. (2) A Licensee shall maintain a related party transactions register recording the identity of the Related Party, the nature and value of the transaction, the approval process followed, and the basis on which arm’s length terms were assessed.
Page 21 of 77 (3) A Licensee shall notify the Authority of any material related party transaction on quarterly basis, and shall provide supporting documentation upon request. (4) Nothing in these Regulations shall require disclosure of confidential information to Customers or shareholders beyond what is required under applicable law; provided that the Authority may require access to records for supervisory purposes in accordance with the Act. 31. Minimum paid-up capital. - (1) A Licensee shall, at all times, maintain minimum paidup capital in accordance with Schedule-I to these Regulations and any applicable conditions of its Licence. (2) Where a Licensee is authorized for more than one Licence Category, the Authority may, on a risk-based basis, specify in the Licence, or by Rules or Regulations made under the Act, or by applicable direction, circular, standard, directive, guideline or other written instrument issued under the Act, the methodology for determining the applicable minimum paid-up capital and any additional prudential add-ons (including for custody exposure, operational/technology risk, market risk, or cross-border risk), provided that the Licensee is afforded an opportunity to make representations except in urgent cases. (3) Any written direction under these Regulations shall state reasons, specify the amount and timeframe for compliance, and be proportional to the primary objectives in section 9(1) of the Act. 32. Liquid financial resources. - (1) A Licensee shall maintain at all times net liquid assets equivalent to 1.2 times of the adjusted monthly operating expenses to meet its obligations as they fall due, including during periods of stress. Paid-Up Capital maintained in assets that qualify as Eligible Liquid Assets may be counted towards satisfaction of this requirement. Where a Licensee holds more than one Licence Category, the applicable prudential floor shall be the highest requirement applicable to those Licence Categories, unless the Authority determines that an additional activity creates a separate and non-overlapping risk requiring an additional amount. (2) A Licensee shall maintain Net Liquid Assets at or above the applicable minimum requirement specified under subsection (1). For the purposes of this section: (a) “Net Liquid Assets” means Eligible Liquid Assets minus Current Liabilities; and (b) “Eligible Liquid Assets” means assets that qualify as Eligible Liquid Assets under sub-regulation (3). (3) Eligible Liquid Assets for all purposes other than capital and reserve requirements (ART/FRT) of the VASP shall comprise only assets that are readily convertible into cash within a short period and without material discount, and shall include, subject to limits, haircuts and concentration thresholds specified by the Authority: (a) high-quality liquid assets (HQLA), including cash and cash equivalents, government securities or other instruments recognized as HQLA by the Authority; (b) high-quality liquid fiat-referenced tokens or asset-referenced tokens approved by the Authority; and (c) specified Virtual Assets with demonstrated deep liquidity and robust market infrastructure, as approved by the Authority. (d) such other assets as the Authority may approve, subject to conditions.
Page 22 of 77 33. Client asset safeguarding and backing. - (1) A Licensee that holds, controls, safeguards, or administers Customer Assets shall ensure that Customer Assets are properly segregated and protected in accordance with the requirements in regulations 103 to 107 (Client Money) and regulations 108 to 112 (Client Virtual Assets), the Act, any Rules or Regulations made under the Act, and any applicable direction, circular or other regulatory requirement made or issued thereunder, in each case only to the extent, and with the legal effect (if any), provided under the Act or under Rules or Regulations made thereunder. (2) A Licensee shall not treat Customer Assets as its own assets and shall not use, pledge, encumber, lend, rehypothecate, or otherwise dispose of Customer Assets except as expressly permitted under these Regulations and with the Customer’s prior informed explicit consent, and shall maintain records evidencing such consent and any permitted use. (3) Where a Licensee owes an obligation to return Customer Assets, whether on-demand or upon specified withdrawal or settlement terms, the Licensee shall maintain arrangements ensuring that Customer Assets are available for timely return, including governance, reconciliations, controls, and safeguarding measures including periodic reconciliations and internal controls to verify the accuracy and completeness of Customer Asset holdings. (4) Without prejudice to subsections (1) to (3), the Authority may, for specified Categories of Licence or business models, require that assets held to meet Customer withdrawal or redemption obligations including but not limited to: (a) equal one hundred percent (100%) of the relevant Customer liabilities at all times, calculated in the manner specified at Regulations 108 to 112; (b) be safeguarded in accordance with the custody and safeguarding requirements applicable to the Licensee; and (c) consist of assets that mirror Customer liabilities in denomination and liquidity characteristics, subject to permitted operational tolerances. (5) Substitute assets may be held only where operationally necessary and only in accordance with conditions specified by the Authority, including requirements that such substitute assets remain liquid, readily realizable, and available to meet withdrawal or redemption obligations. 34. Prudential requirements for token issuers. — (1) An Issuer of a Fiat-Referenced Token or Asset-Referenced Token shall, in addition to any other applicable requirements under the Act, Rules or regulation in general and these Regulations in specific, comply with the issuance requirements in sections 31 and 32 of the Act. (2) Without prejudice to sub-regulation (1), an Issuer shall maintain reserve assets and redemption arrangements in accordance with these Regulations, including requirements relating to asset composition, custody, liquidity, valuation, segregation, audit, attestations, disclosures, and redemption timelines. (3) Reserve assets maintained under this regulation shall, be maintained at a level equal to one hundred percent (100%) of the Issuer’s outstanding redemption liabilities at all times, and shall be held as a segregated reserve. (4) For a Fiat-Referenced Token, reserve assets under sub-regulation (3) shall comprise HighQuality Liquid Assets or such other eligible assets as may be specified, and the Issuer shall maintain mechanisms for redemption at par value without Undue Delay, in accordance with section 31 of the Act.
Page 23 of 77 (5) For an Asset-Referenced Token, reserve assets under sub-regulation (3) shall comprise the underlying assets referenced by the token (or such eligible categories of underlying assets as may be specified), held in custody in accordance with Regulations, and the Asset-Referenced Token shall at all times be fully backed by the underlying assets and shall not be backed or derive its value from other Virtual Assets, in accordance with section 32 of the Act. (6) Reserve assets shall be held with a custodian of reserve assets that complies with such requirements, oversight and inspection standards as may be prescribed by Regulations, in accordance with section 28 of the Act. (7) The Issuer shall publish audited reserve disclosures and such other disclosures (including ongoing disclosures of material information and reserve attestations) in the manner and frequency prescribed, and shall maintain robust AML, CFT, CPF and sanctions compliance programmes, in accordance with sections 31 and 32 of the Act. (8) The Issuer shall ensure prioritized holder protections in insolvency, including legal and operational arrangements supporting segregation and timely redemption and return of reserve assets for the benefit of holders, in accordance with sections 31 and 32 of the Act. (9) Any permitted deviations, buffers, or operational tolerances, including the use of substitute assets, shall be specified by the Authority and shall not prejudice redemption at par value (where applicable) or timely redemption. (10) Reserve asset requirements under this regulation shall not apply to a Licensee solely by reason of providing non-issuance Virtual Asset Services, unless otherwise specified by Regulations applicable to that Category of Licence. (11) The Authority may grant a limited scope licence under regulation 7(5) for issuance of an FRT or ART for a limited scope including but not limited to: (a) caps on outstanding supply, number/type of holders, and transaction volumes; (b) limitations on distribution channels and use cases; (c) enhanced disclosures to holders regarding pilot status and risks; (d) redemption controls and operational safeguards; and (e) any additional conditions necessary to protect holders and market integrity. (12) For a limited scope license under these Regulations, the Authority may permit proportionate assurance and reporting arrangements, including attestations at intervals prescribed by Regulations made under the Act or specified by written direction issued under the Act, provided that reserves remain fully segregated and that redemption rights are protected. (13) Nothing in these Regulations permits the Issuer to maintain reserves below one hundred percent (100%) unless expressly authorised by the Act. 34A. Significant Issuers. - (1) An Issuer shall be deemed a Significant Issuer if it meets the thresholds and criteria prescribed by Regulations, having regard to size, scale, systemic importance, market impact, number of holders, and cross-border activity, in accordance with section 33(1) of the Act.
Page 24 of 77 (2) A Significant Issuer shall be registered with the Authority and shall comply with enhanced requirements, including enhanced reporting, disclosure, governance, and risk management, as prescribed in Regulations, in accordance with section 33(2) of the Act. (3) Without prejudice to sub-regulations (1) and (2), the Authority may impose proportionate additional conditions on a Significant Issuer’s Licence or registration having regard to financial stability, consumer protection, market integrity, and cross-border risks. 35. Monitoring, notification and remediation. - (1) A Licensee shall establish systems and controls to monitor compliance with these Regulations on an ongoing basis, including stress testing and contingency planning commensurate with its nature, scale and complexity. (2) A Licensee shall notify the Authority without delay where it reasonably anticipates, or becomes aware, that it has failed or is likely to fail to meet any requirement under this Regulations, and shall provide a remedial action plan within the timeframe specified by the Authority. (3) The Authority may require enhanced reporting, restrictions, or remedial measures where a Licensee is in breach or is likely to breach any requirement under this Regulations. (4) The Authority may, on a risk-based basis and where necessary to advance the objectives of the Act, require a Licensee to hold and maintain additional paid-up capital, liquid financial resources, insurance, or reserve assets, having regard to the size, scope, geographic exposure, complexity and nature of the Licensee’s activities and operations. (5) A requirement under subsection (4) shall be proportionate, reasoned, and time-bound where appropriate, and shall specify the basis for the requirement, the compliance timeframe, and any reporting obligations; provided that in urgent cases the Authority may impose interim requirements subject to an opportunity to make representations as soon as reasonably practicable thereafter. 36. Insurance coverage. - (1) A Licensee shall maintain insurance arrangements, commensurate with the nature, scale, complexity, and risk profile of its Licensed Activities, to support customer protection and operational resilience. (2) Without limiting sub-regulation (1), the Authority may specify in the Licence, or by Rules or Regulations made under the Act, or by applicable direction, circular or other regulatory requirement made or issued thereunder, minimum insurance types, coverage limits, deductibles, and other requirements, which may include but not limited to: (a) professional indemnity insurance; (b) crime/fidelity or commercial crime insurance covering employee dishonesty and theft; (c) cyber risk insurance; and (d) such other insurance as the Authority considers appropriate to the Licensee’s activities and custody model. (3) Insurance shall be obtained from an insurer licensed or authorised to provide insurance in Pakistan, unless the Authority permits otherwise in specified circumstances. (4) The Licensee shall provide the Authority with evidence of coverage and shall promptly notify the Authority of any material change, lapse, cancellation, or non-renewal of coverage.
Page 25 of 77 (5) The Licensee shall disclose insurance coverage in its audited financial statements, and shall not represent insurance as a guarantee of customer recovery 37. Outsourcing general requirements. - (1) A Licensee may outsource any activity, process or service to a Service Provider, whether within or outside Pakistan, provided that the Licensee remains fully responsible for compliance with the Act and the Regulations in relation to the outsourced activity, process or service. (2) A Licensee shall ensure that outsourcing does not materially impair: (a) the effectiveness of its governance arrangements, risk management, or internal controls; (b) its operational resilience, cybersecurity, or business continuity; (c) the safety, segregation, or timely return of Customer Assets; or (d) the Authority’s ability to obtain timely access to information reasonably required to exercise its functions under the Act. (3) A Licensee shall designate a Key Individual as responsible for oversight of outsourcing arrangements and for coordinating regulatory engagement relating to outsourcing. 38. Material Outsourcing classification and proportionality. - (1) For the purposes of these Regulations, an outsourcing arrangement is “Material Outsourcing” where a failure, disruption, or deficiency in performance could reasonably be expected to have a significant adverse effect on: (a) the Licensee’s ability to comply with the Act or these Regulations; (b) the security, availability, or timely return of Customer Assets; (c) the confidentiality, integrity, or availability of customer data or critical records; or (d) the continuity of a core Virtual Asset Service. (2) A Licensee shall apply the requirements in regulations 37 to 43 in a manner proportionate to the nature, scale and complexity of its business and the criticality of the outsourced activity, process or service; provided that the minimum requirements in regulations 39 to 43 shall apply to all Material Outsourcing arrangements. 39. Risk assessment, due diligence and ongoing oversight. - (1) Before entering into, renewing, or materially varying an outsourcing arrangement, the Licensee shall conduct and document a risk assessment proportionate to the risks of the arrangement. (2) The risk assessment shall consider, as relevant: (a) the criticality of the outsourced activity, process or service and the feasibility of substitution; (b) information security controls and incident response capabilities of the Service Provider; (c) data access controls, confidentiality, retention and integrity safeguards; (d) business continuity and recovery capabilities; and (e) the Licensee’s ability to monitor performance and implement exit arrangements without material disruption. (3) The Licensee shall conduct due diligence to satisfy itself that the Service Provider is competent, capable, and reliable, and has controls appropriate to the outsourced activity, process or service.
Page 26 of 77 (4) In relation to Material Outsourcing, the Licensee shall review the arrangement at least annually, and promptly following any material incident, breach, or change affecting performance, security, continuity, or compliance. 40. Outsourcing policy and register. - (1) A Licensee shall establish and maintain an outsourcing policy approved by its Board (or equivalent governing body), setting out governance, approval thresholds, monitoring, incident escalation, and exit management for outsourcing arrangements. (2) A Licensee shall maintain an up-to-date register of Material Outsourcing arrangements in the form and manner specified by the Authority, including: (a) the identity of the Service Provider; (b) a description of the outsourced activity, process or service; (c) whether the Service Provider is an intra-group entity or an external provider; (d) the location(s) where the outsourced activity, process or service is performed and where relevant data is stored or processed; and (e) the responsible Key Individual within the Licensee. 41. Outsourcing agreements required provisions - (1) A Licensee shall ensure each outsourcing arrangement is governed by a written agreement appropriate to the nature and risk of the arrangement. (2) In relation to Material Outsourcing, the agreement shall, at a minimum, provide for: (a) a clear description of the outsourced activity, process or service, service levels, and reporting; (b) information security obligations, including incident notification to the Licensee; (c) business continuity and disaster recovery arrangements; (d) termination and exit assistance to support orderly transition, transfer, or insourcing; and (e) the Licensee’s ability to obtain, on a timely basis, information and records relating to the outsourced activity, process or service that are reasonably required for the Licensee to demonstrate compliance with the Act and these Regulations. (3) Nothing in these Regulations shall require a Licensee to procure contractual rights that are unlawful or incapable of being granted under applicable foreign law; provided that the Licensee shall implement reasonable alternative measures to achieve the outcomes in subsection (2), which may include independent assurance reports, pooled audits, certifications, or other verification mechanisms acceptable to the Authority. 42. Sub-outsourcing. - (1) A Service Provider shall not sub-outsource any outsourced activity, process or service that constitutes Material Outsourcing without the Licensee’s prior written consent. (2) The Licensee shall ensure that sub-outsourcing does not reduce the Licensee’s ability to meet the requirements of regulations 37 to 41, and that the Service Provider remains responsible for the performance of the outsourced activity, process or service. 43. Notifications to the Authority. - (1) A Licensee shall notify the Authority without delay upon becoming aware of:
Page 27 of 77 (a) a material disruption, outage, incident, or control failure affecting a Material Outsourcing arrangement; (b) a material breach by a Service Provider that has, or is likely to have, a significant adverse impact on Customers, Customer Assets, market integrity, or the Licensee’s compliance; or (c) termination of a Material Outsourcing arrangement where continuity of service or customer outcomes may be affected. (2) A Licensee shall notify the Authority in advance where reasonably practicable, and otherwise without Undue Delay, of any outsourcing of a Material Function that is not a Critical Function. (3) The notification shall include: (a) the Function outsourced; (b) the service provider and location(s); (c) the risk assessment; d) controls for data access and audit rights; and (e) the planned implementation date. (4) A Licensee shall, upon request, provide to the Authority information reasonably necessary to explain how the Licensee manages outsourcing risks and complies with regulations 37 to 43, including by reference to its outsourcing policy and register. (5) Nothing in this regulation shall be construed as conferring a general veto over outsourcing decisions. This does not affect any prior approval requirement expressly set out in these Regulations or in a Licence condition. 44. ESG governance and disclosures. - (1) A Licensee shall maintain governance arrangements proportionate to the nature, scale and complexity of its business to identify and manage material environmental, social and governance risks that could reasonably affect: (a) operational resilience, cybersecurity or business continuity; (b) the fair treatment and protection of Customers; or (c) the Licensee’s ability to comply with the Act and these Regulations. (2) The Authority may, by written direction or as a Licence condition, require a Licensee to make disclosures relating to material environmental or social risks only to the extent that such risks are proportionate and reasonably necessary to advance the primary objectives set out in section 9(1) of the Act, including where such risks could reasonably affect: (a) operational resilience, cybersecurity or business continuity; (b) the safeguarding, custody integrity or availability of Customer Assets; (c) the fair treatment and protection of Customers; (d) the prevention or mitigation of financial crime, fraud, market abuse or market integrity risks; or (e) financial stability or systemic risk. (3) Any disclosure requirement imposed under subsection (2) shall be calibrated having regard to the Licensee’s nature, scale and complexity, and shall be limited to information that the Licensee can reasonably obtain and verify.
Page 28 of 77 45. Scope of ESG disclosures. — (1) Where the Authority imposes ESG disclosure requirements under regulation 44(2), the Authority may specify the scope, format and frequency of such disclosures, which may include: (a) a brief description of the Licensee’s governance and accountability arrangements for ESG matters; (b) a description of any material ESG risks identified and the steps taken to manage them; and (c) where applicable, disclosures on workforce practices, complaints trends, and customer outcomes relevant to consumer protection and market integrity. (2) The Authority may specify, by Regulations made under the Act or by written instrument issued under the Act, examples of proportionate ESG disclosures for different Categories of Licence. 46. Publication. - (1) Where the Authority requires a Licensee to publish ESG disclosures, the Licensee shall make such disclosures available in a prominent and accessible manner on its website, or by such other means as the Authority may specify. (2) A Licensee shall not make ESG-related statements that are false, misleading or likely to create a misleading impression, including by omitting material information necessary to make the statements not misleading. 47. Service providers. - (1) A Licensee shall consider, as part of its outsourcing and procurement governance, whether a Service Provider’s practices create material risks to the Licensee’s: (a) operational resilience, cybersecurity or business continuity; or (b) compliance with the Act and these Regulations. (2) Regulation 47(1) does not require a Licensee to ensure that a Service Provider complies with any particular international ESG standard, unless expressly required by applicable Pakistani law or specified by the Authority for the purpose of managing the material risks referred to in subsection (1). 48. Material changes to business and operations. - (1) A Licensee shall establish and maintain arrangements to identify, assess and manage Material changes to its business, operations, governance, risk profile, or control, and shall notify the Authority in accordance with this section. (2) A Licensee shall seek prior approval for any material change in control or business as per Section 22(d) of the Act and shall notify the Authority of any proposed Material change as soon as practicable (3) The application under this section shall include sufficient detail to enable supervisory assessment, including: (a) a description of the change and expected timing; (b) an assessment of the impact on Customers, market integrity, operational resilience, and AML/CFT/CPF controls; (c) updates to governance, risk management, cybersecurity, outsourcing and business continuity arrangements where relevant; and (d) mitigating measures and an implementation plan.
Page 29 of 77 (4) The Authority may, on a risk-based basis and having regard to the primary objectives in section 9(1) of the Act: (a) require the Licensee to provide additional information; (b) require remedial measures, enhanced reporting, or restrictions; (c) direct the Licensee to defer implementation for a reasonable period; or (d) require the Licensee to apply for a variation of Licence or other approval under these Regulations where the change affects the scope of any Category of Licence or materially alters the Licensee’s risk profile. (e) require the Licensee to submit a remediation plan or to take specified steps to address risks arising from the Material change.” (5) For the avoidance of doubt, nothing in this section prevents a Licensee from ordinary-course treasury management, working capital facilities, or intra-group funding arrangements, provided that the Licensee remains compliant with prudential requirements and notification obligations under these Regulations. (6) The Authority may issue non-binding guidance, or an applicable directive, guideline, circular or other written instrument issued under the Act, setting out non-exhaustive examples of Material changes and indicative notification timelines for different Categories of Licence. 49. Change of Control requirements. - (1) Every Licensee shall seek the Authority’s prior written approval for any material change in control or business, in the manner prescribed. (2) For the purposes of this section, “Material change in control” means any change in the business, operations, ownership, structure, or control of a VASP that could reasonably be expected to have a significant effect on the VASP’s fitness or propriety to carry on regulated activities; the adequacy of the VASP’s risk management, compliance, or governance arrangements; the interests or protection of clients, investors, or counterparties; or he integrity or stability of the virtual asset market (3) An application for approval under subsection (1) shall be submitted by the Licensee and the proposed acquirer, and shall include information required to assess fitness and propriety, financial soundness, governance arrangements, and any other matters specified by the Authority. (4) The Authority may approve an application under this section subject to conditions necessary to advance the primary objectives in section 9(1) of the Act. 50. Mergers and acquisitions. - (1) A Licensee shall notify the Authority in advance of any proposed merger, demerger, or acquisition involving the Licensee that constitutes a Material change. (2) The Authority’s prior written approval is required only where the transaction would result in (a) a Change of Control; or (b) a transfer of a Substantial Part of Assets of the Licensee. (3) For the purposes of subsection (2)(b), “Substantial Part of Assets” means a transfer or disposition (in one transaction or a series of related transactions) that (a) represents ten percent (10%) or more of the Licensee’s total assets; or
Page 30 of 77 (b) relates to assets that are critical to the Licensee’s ability to provide a Category of Licence; or (c) would reasonably be expected to materially impair the Licensee’s ability to meet its obligations to Customers or to comply with these Regulations. (4) The Authority may impose conditions to ensure orderly continuity of service, safeguarding of Customer Assets, and compliance during and after completion of a transaction under this section. (5) A Licensee shall ensure compliance with all applicable laws in relation to any transaction under this section, including the Companies Act, 2017 and the Competition Act, 2010. 51. Recovery and wind-down planning. - (1) A Licensee shall maintain a documented Recovery and Wind-Down Plan commensurate with the nature, scale and complexity of its business and the risks of the Categories of Licence it conducts. (2) The Recovery and Wind-Down Plan shall be designed to support the orderly cessation of regulated activities and the protection and timely return of Customer Assets, and shall include, at a minimum: (a) governance arrangements and decision-making triggers for recovery actions and wind-down; (b) an assessment of material impediments to orderly wind-down and mitigating measures; (c) operational steps to safeguard, reconcile and return Customer Assets, including key dependencies on service providers and systems; (d) communications arrangements for Customers, the Authority and other relevant stakeholders; (e) record retention, access to systems and logs, and arrangements to maintain customer-facing channels necessary to support withdrawals and claims; (f) staffing and key role continuity arrangements during wind-down; (g) a plan for funding and resourcing the wind-down period; and (h) where applicable and to the extent practicable, arrangements for any insurance, guarantee, or other risk-mitigant required under these Regulations or the Licence conditions to remain effective during wind-down, recognizing that such arrangements may be impacted by insolvency proceedings. (3) A Licensee shall review and, where necessary, update its Recovery and Wind-Down Plan (a) at least annually; and (b) upon the occurrence of a Material change. (4) Where a Licensee decides to cease carrying on all or any regulated activity, it shall notify the Authority without delay, provide its current Recovery and Wind-Down Plan, and implement the plan subject to subsection (6) and any written direction lawfully issued by the Authority under the Act and these Regulations. (5) Where a Licensee becomes insolvent, enters into insolvency or restructuring proceedings, or becomes aware of an event that may materially impair its ability to meet obligations to Customers, it shall notify the Authority without delay and cooperate with any insolvency appointee, administrator, trustee, custodian or other competent person to support the orderly return of Customer Assets and continuity of critical customer protections.
Page 31 of 77 (6) The Authority may, on a risk-based basis and where necessary to protect Customers or market integrity (a) require the Licensee to provide progress reports, information, reconciliations, and independent assurance in such form and at such intervals as the Authority may specify; (b) require the Licensee to propose amendments to its Recovery and Wind-Down Plan, or to implement specific remedial measures, provided that any such requirement shall be reasoned, proportionate, and limited to measures necessary to address identified risks; and (c) where the Authority considers that an amendment is necessary and urgent, direct the Licensee to implement specified measures on an interim basis, provided that the Licensee shall be given an opportunity to make representations as soon as reasonably practicable thereafter. CHAPTER – VI Market Conduct 52. Client Agreements. - (1) A Licensee shall enter into a written Client Agreement with each Customer prior to providing any Virtual Asset Service to that Customer. (2) A Client Agreement shall be fair, clear, transparent, accurate and not misleading, having regard to the nature of the service and the intended class of Customers. (3) A Client Agreement shall, at a minimum, set out: (a) the Virtual Asset Services to be provided and any material limitations or conditions; (b) the fees, charges, spreads, commissions and other costs payable by the Customer, and how they are calculated; (c) material risks relevant to the service, including custody, technology, market volatility and settlement risks; (d) the arrangements for safeguarding Customer Assets, including segregation and any permitted use of Customer Assets (if any); (e) the complaints handling process, including applicable steps and timelines, and the dispute resolution process, including (where applicable) the right of the Customer to refer eligible claims to any independent dispute-resolution scheme established or recognized by the Authority under section 45(2) of the Act, and how to access such scheme; and (f) circumstances in which the Licensee may suspend, restrict or terminate the service, including where required to comply with law or to address security or market integrity risks. (4) A Licensee shall obtain valid acceptance from the Customer in a manner compliant with applicable law, and shall provide the Customer with a copy of the Client Agreement after it is concluded. (5) A Licensee shall notify Customers of any material change to a Client Agreement at least thirty (30) days prior to such change taking effect, except where an urgent change is required to address a legal requirement, a cybersecurity incident, a fraud risk, or a market integrity risk; provided that the Licensee shall notify Customers as soon as practicable in such cases. (6) A Licensee shall maintain records of all versions of Client Agreements and evidence of Customer acceptance for a period of 7 years from the date of discontinuation of client
Page 32 of 77 relationship unless otherwise required by any other applicable law. For the purposes of this sub-regulation, “date of discontinuation” means the later of (a) the date on which the business relationship with the Customer is formally terminated; and (b) the date on which the Customer’s account is closed and all outstanding positions and obligations are settled. 53. Complaints handling. - (1) A Licensee shall establish and maintain internal complainthandling procedures in accordance with the requirements prescribed by Regulations and section 45(1) of the Act. (2) The procedures under sub-regulation (1) shall be prompt, fair, transparent, and consistently applied, and shall include, at a minimum: (a) accessible channels for submission of complaints (including electronic channels); (b) acknowledgement of receipt within 24 hours; (c) investigation and resolution as soon as practicable within a reasonable time, having regard to the complexity of the complaint; (d) where a complaint cannot be resolved within seven working days, a written update to the complainant stating reasons for delay and the expected timeframe for resolution; (e) clear communication of outcomes, reasons, and (where applicable) remedial actions; and (f) governance, escalation, and oversight arrangements proportionate to the Licensee’s nature, scale, and risk profile. (3) A Licensee remains responsible for complaint resolution notwithstanding the involvement of any service provider, agent, or group entity in the delivery of the service. (4) A Licensee shall keep records of complaints received, actions taken, and outcomes and shall publish on its website clear information on how Customers may submit complaints and the steps and timelines applicable to the complaint-handling process. (5) Where the Authority establishes or recognizes an independent dispute-resolution scheme under section 45(2) of the Act for claims below a prescribed monetary threshold, the Licensee shall: (a) inform complainants, in writing, of their right to refer eligible complaints to such scheme once the Licensee has issued a final response or the prescribed internal timeline has elapsed without resolution; (b) cooperate with the scheme, including by providing relevant records and information in a timely manner; and (c) implement outcomes of the scheme to the extent required under the Act, these Regulations, or any Rules or Regulations made under the Act. 54. Public disclosures. - (1) A Licensee shall publish, in an easily accessible location on its website and kept accurate and up to date: (a) its legal name, registered office address in Pakistan (if applicable), and contact details; (b) its Licence number and the Categories of Licence and Virtual Asset Services for which it is authorised; (c) the names or titles of Key Individuals or controlled functions responsible for the licensed activities, as specified by the Authority;
Page 33 of 77 (d) a schedule or description of fees and charges and any material pricing methodology used for Customers; and (e) the complaints handling process and channels for Customer support. (2) A Licensee shall publish fair, clear and not misleading risk warnings regarding Virtual Assets and the relevant services, including: (a) volatility and potential loss of value; (b) liquidity risks; (c) irreversibility of certain transfers and operational errors; (d) technology and cybersecurity risks; and (e) fraud, scams, manipulation and theft risks. (3) The Authority may specify the format, prominence and minimum content of disclosures required under this section. (4) A Licensee shall comply with any order or direction issued by the Authority under section 61 of the Act, including any direction to remove, block, or facilitate the removal or blocking of online material that promotes, operates, or relates to an unlicensed Virtual Asset Service or contravenes the Act, its Rules or Regulations. 55. Dealing controls and inside information safeguards. - (1) A Licensee shall comply with regulation 27 in relation to the identification, prevention, management and disclosure of conflicts of interest, including the maintenance of a conflicts-of-interest policy and conflicts register. (2) Without prejudice to regulation 27, a Licensee shall establish and maintain controls to prevent misuse of inside information or material non-public information, including restricted access, need-to-know arrangements, information barriers, restricted dealing rules, watch lists and restricted lists, and escalation and reporting to the Compliance Officer. (3) A Licensee shall establish and maintain personal account dealing controls for directors, Key Individuals and relevant Employees, including (as applicable) pre-clearance, restricted periods, monitoring and surveillance, recordkeeping, and periodic attestations. (4) The Authority may prescribe minimum standards for controls under these Regulations (including personal account dealing controls, restricted lists, pre-clearance, and periodic attestations) proportionate to the Licensee’s activities and risk profile. 56. Dealing as principal and proprietary activity. - (1) Where a Licensee deals as principal, makes markets, or trades on its own account in connection with providing Virtual Asset Services, it shall do so in a manner that is transparent, conflicts-controlled and consistent with market integrity and Customer protection. (2) Without prejudice to subsection (1), a Licensee shall (a) implement governance controls to approve and oversee proprietary activity, including limits, permitted purposes, and monitoring; (b) maintain records of proprietary transactions and the rationale for such activity; (c) ensure that proprietary activity does not misuse Customer order information or materially disadvantage Customers; and (d) make appropriate disclosures to Customers where its role as principal may create conflicts.
Page 34 of 77 (3) The Authority may specify additional restrictions for particular Categories of Licence or business models where necessary and proportionate to advance the primary objectives in section 9(1) of the Act. 57. Virtual Asset standards for admission and continued availability. - (1) A Licensee that makes a Virtual Asset available to Customers (including by listing, admitting to trading, or enabling purchase, sale or exchange) shall establish, implement and publish objective, transparent and non-discriminatory standards for the admission and continued availability of Virtual Assets. (2) Such standards shall be proportionate to the Licensee’s business model and shall address, where relevant: (a) liquidity and market quality considerations; (b) technology and security risks of the underlying protocol; (c) risks of fraud, manipulation, and market abuse; (d) legal and regulatory risks, including whether the Virtual Asset is prohibited or restricted under the Act or any other law in Pakistan, including section 53 of the Act (Prohibition on Algorithmic tokens); and (e) conflicts of interest in relation to the Virtual Asset. Assessments may be conducted on a risk-based basis and shall not require formal legal opinions unless otherwise specified by the Authority. (3) A Licensee shall conduct initial and ongoing assessments against its standards and shall keep records of such assessments for three years following delisting.. (4) A Licensee shall establish clear triggers and procedures for suspension, restriction or delisting where a Virtual Asset no longer meets its standards or where continued availability presents a material and demonstrable risk of significant harm to Customers or market integrity. (5) The Authority may direct a Licensee to suspend, restrict or cease a specified activity in relation to a Virtual Asset where the Authority has reasonable grounds to believe this is necessary to advance the objectives in section 9(1) of the Act, subject to the Licensee being afforded an opportunity to make representations as soon as practicable. While issuing such direction the Authority shall give due consideration to the specific risk identified based on the principle of proportionality. Any prohibition of a class of Virtual Assets shall be preceded by a reasoned public notice, unless urgency justifies interim restriction or other temporary measures taken in accordance with section 60 of the Act. CHAPTER – VII Technology 58. Technology governance and risk management framework. - (1) A Licensee shall establish, implement and maintain a technology governance and risk management framework designed to identify, assess, mitigate and monitor technology and cybersecurity risks arising from its business and licensed activities. (2) The framework shall be proportionate to the nature, scale and complexity of the Licensee’s business model, technology stack, and risk profile, including whether the Licensee (a) holds or controls Customer Assets;
Page 35 of 77 (b) operates trading, matching, settlement or wallet infrastructure; (c) relies materially on third-party or group technology services; or (d) provides services to a large retail customer base. (3) The Licensee shall implement policies, procedures and controls to address identified risks, including layered security measures (defense-in-depth) where appropriate, and shall ensure that such controls are operating effectively on an ongoing basis. (4) Without prejudice to subsections (1) to (3), the framework shall address, to the extent relevant (a) technology governance and accountability, including Board and senior management oversight; (b) system development and change management controls, including secure development, testing, and release procedures; (c) operational controls, including access management, logging, monitoring, and vulnerability management; (d) back-up, restoration and recovery controls; (e) capacity, resilience and performance management; and (f) periodic availability and disaster recovery testing. (5) The Licensee shall review and update the framework and related controls periodically, and in any event following any material change to its technology, business model, threat landscape, or after a significant incident. (6) The Authority may prescribe, by Regulations made under the Act, baseline expectations, illustrative risk parameters, assessment methodologies and minimum controls for the purposes of this regulation; and may also issue standards, directives, guidelines or other written instruments under the Act to support implementation.. Such expectations, parameters, methodologies, controls, standards, directives, guidelines or other written documents shall be proportionate and technology-neutral and shall not prescribe specific vendors, architectures or proprietary solutions unless objectively necessary. (7) A Licensee shall designate a senior individual responsible for information security and cyber risk management (“Information Security Officer”), with appropriate authority, independence and resources; and where the Authority determines having regard to the Licensee’s risk profile that a dedicated Chief Information Security Officer is required, the Licensee shall appoint a Chief Information Security Officer as may be specified by the Authority. 59. Cybersecurity policy and control framework. - (1) A Licensee shall establish, implement and maintain a written cybersecurity policy and supporting procedures designed to protect the confidentiality, integrity and availability of: (a) its information systems and technology assets; and (b) Customer Data and other confidential information processed or stored by the Licensee or on its behalf. (2) The cybersecurity policy shall be approved by the Board (or a Board committee) and shall be reviewed at least annually, and promptly following any material change to the Licensee’s technology environment, threat landscape, business model, or after a significant cyber incident.
Page 36 of 77 (3) The Licensee shall submit its cybersecurity policy, and any material updates thereto, to the Authority (a) as part of the licensing process; and (b) thereafter, upon request, within the timeframe specified by the Authority. (4) The cybersecurity policy shall be proportionate to the nature, scale and complexity of the Licensee’s licensed activities and shall address, to the extent relevant: (a) information security governance, roles, responsibilities and escalation; (b) asset and data classification, access controls and authentication safeguards; (c) secure configuration, patching, vulnerability management and malware protection; (d) logging, monitoring and detection capabilities; (e) incident response and recovery, including root cause analysis and remediation; (f) business continuity, backup and restoration arrangements; (g) third-party technology and service provider risk management; and (h) controls for the initiation, authorization and execution of Virtual Asset transactions, including risk-based measures for high-risk or anomalous activity. (5) The Licensee shall designate a senior individual responsible for oversight of cybersecurity risk management and implementation of the cybersecurity policy, which may be the Information Security Officer or Chief Information Security Officer designated under section 58(7). (6) The Authority may issue standards, directives, guidelines, circulars or other written instruments under the Act specifying baseline cybersecurity controls, testing expectations, and illustrative measures for the purposes of this section; provided that any requirement intended to be mandatory and generally applicable shall be prescribed by Rules or Regulations made under the Act (or otherwise issued in a manner expressly authorised to have binding effect under the Act or under Rules or Regulations made thereunder). 60. Compliance with applicable cybersecurity and data protection requirements. - (1) A Licensee shall ensure that its technology governance arrangements, cybersecurity policy and related controls comply with all applicable laws in Pakistan relating to cybersecurity, electronic crimes, data protection and confidentiality, to the extent applicable. (2) Where a Licensee relies on service providers to process or store Customer Data or to operate material systems supporting its licensed activities, the Licensee shall ensure appropriate contractual and operational measures are in place to meet the requirements of subsection (1). (3) A Licensee may store or process data outside Pakistan, subject to compliance with applicable laws relating to data protection, cybersecurity, and cross-border data transfers, and subject to such safeguards as may be prescribed by Regulations, in accordance with section 39(1) of the Act. (4) A Licensee shall implement appropriate technical, organizational, and governance measures to ensure the segregation of sensitive information from other operational data, in such manner as may be prescribed by Regulations, in accordance with section 40(1) of the Act. The Authority may prescribe, by Regulations, minimum technical standards, cybersecurity controls, storage architectures, encryption requirements, and data-governance frameworks to give effect to this regulation, in accordance with section 40(4) of the Act.
Page 37 of 77 61. Cryptographic key and wallet management. - (1) A Licensee that generates, holds, controls, or otherwise can initiate or approve transactions using cryptographic keys in relation to Customer Assets shall establish, implement and maintain policies, procedures and controls for secure key and wallet management. (2) Without prejudice to subsection (1), a Licensee shall ensure that its key and wallet management arrangements provide an appropriate level of security and operational resilience, including (a) governance and accountability for key management, including documented roles, responsibilities and approvals; (b) secure key generation, storage, use and backup arrangements appropriate to the custody model, including measures to minimize single points of failure and unauthorized access; (c) robust access management and segregation of duties for any individual or system that can initiate, approve, sign, or execute Virtual Asset transactions; (d) maintenance of auditable records of key access and key-related administrative actions, and periodic review of such records; (e) procedures to promptly revoke or modify access where personnel roles change or employment ends, and to address key compromise or suspected compromise; and (f) controls to manage risks arising from technology dependencies, integrations, and service providers involved in key or wallet operations. (3) A Licensee shall regularly assess, test and review the effectiveness of its key and wallet management controls and shall remediate identified deficiencies without delay, having regard to the risk profile of the Licensee and any Customer Assets affected. (4) Where a Licensee provides services to Customers that involve Customer-controlled wallets or self-custody, the Licensee shall provide clear information and risk warnings regarding (a) the Customer’s responsibility for safeguarding private keys, seed phrases and authentication factors; and (b) the consequences of loss, compromise or unauthorized disclosure. (5) The Authority may also issue standards, directives, guidelines or other instruments under the Act, specifying baseline expectations, control examples, and assurance or audit practices for secure key management and wallet operations for the purposes of this section. 62. Technology testing, assurance and audits. - (1) A Licensee shall implement a risk-based testing and assurance programme covering the technology, cybersecurity and operational resilience of the systems used to provide Virtual Asset Services, proportionate to the nature, scale, complexity and risk profile of its activities. (2) Without prejudice to subsection (1), a Licensee shall ensure that: (a) vulnerability assessments and penetration testing are conducted at appropriate intervals and after material changes to systems, architecture or controls; (b) security monitoring and internal control testing are performed on an ongoing basis; and (c) identified high-risk findings are remediated within reasonable timeframes, with escalation to the Board or senior management where material. (3) Where a Licensee uses smart contracts or other programmable protocols that are material to the provision of its services or to the safeguarding, transfer, settlement, or issuance of Virtual
Page 38 of 77 Assets, the Licensee shall ensure that such smart contracts or code are subject to independent security review and testing: (a) prior to deployment or material upgrade; and (b) thereafter on a periodic basis commensurate with their criticality and risk. (4) A Licensee shall maintain appropriate documentation evidencing the tests, reviews, findings and remediation actions under this section and shall make such documentation available to the Authority upon request. (5) The Authority may, by written direction and where necessary and proportionate having regard to the Licensee’s risk profile, customer impact, custody or market infrastructure role, or credible threat indicators, require the Licensee to undertake enhanced testing, including threatled or scenario-based testing, and to submit a remediation plan and progress updates in the timeframe specified by the Authority. (6) Where enhanced testing under subsection (5) is required, the Authority may specify: (a) the scope and objectives of the testing, including whether testing may be conducted on production or a representative environment; (b) minimum competence, independence and integrity requirements for external testers; and (c) requirements for safe handling of testing outputs, vulnerabilities, sensitive data and reporting, to minimize disruption and prevent misuse. (7) A Licensee shall ensure that any engagement with external testers includes contractual provisions addressing confidentiality, data handling, responsible disclosure, conflict management, and secure retention and destruction of testing artefacts. 63. Controls for Virtual Asset transactions and automated activity. - (1) A Licensee shall implement systems and controls to detect, prevent and respond to market abuse, manipulation, abusive trading practices, and technology-enabled attacks or misuse, including where relevant automated or coordinated activity. (2) Where a Licensee processes, executes, transmits, settles, or safeguards Virtual Asset transactions for Customers, it shall maintain transaction monitoring controls, including the capability to identify higher-risk transactions and addresses, and to escalate and respond in accordance with its AML/CFT/CPF policies and applicable law. (3) The controls under subsection (2) may include the use of distributed-ledger analytics tools or equivalent measures, selected and calibrated on a risk basis having regard to the Licensee’s business model, customer profile, products, and exposure to illicit finance risks. 64. Algorithm governance and controls. - (1) Where a Licensee uses algorithms that materially affect pricing, execution, risk controls, customer onboarding, transaction monitoring, safeguarding arrangements, or other regulated activities, it shall establish and maintain governance and controls to ensure effective oversight by the Board and senior management. (2) The governance and controls under subsection (1) shall include, at a minimum: (a) documented design objectives and intended use; (b) testing and validation prior to deployment and following material changes; (c) change management, including version control and approval processes;
Page 39 of 77 (d) ongoing monitoring of performance and outcomes, including alerts for abnormal behaviour; and (e) the ability to suspend or disable the algorithm promptly where necessary to protect Customers, market integrity, or operational resilience. (3) A Licensee shall maintain adequate records to evidence compliance with this section, including key assumptions, data inputs where relevant, material limitations, and remediation actions taken. (4) This section shall not require disclosure of proprietary algorithms, source code or trading logic, except where required under lawful investigation. 65. Business continuity and disaster recovery. - (1) A Licensee shall establish, implement, maintain and periodically test a business continuity and disaster recovery plan proportionate to the nature, scale and complexity of its activities and technology dependencies. (2) The plan under subsection (1) shall, at a minimum, address: (a) governance, roles and escalation procedures for disruption events; (b) recovery objectives and priorities for material systems and services; (c) backup, restoration and integrity controls for data and records; (d) communications arrangements for Customers, counterparties and the Authority, where relevant; and (e) post-incident remediation and lessons learned to reduce recurrence. (3) Where the Licensee safeguards Customer Assets or operates technology that is material to market functioning, the Authority may require enhanced resilience measures or testing on a risk-based basis. 66. Information security officer and staff readiness. - (1) A Licensee shall designate a senior individual responsible for information security oversight, including implementation of the Technology and Information requirements under these Regulations. (2) Where the nature, scale or risk profile of the Licensee’s activities warrants, the Authority may require the appointment of a Chief Information Security Officer, and may specify role expectations, reporting lines, and independence safeguards. (3) A Licensee shall ensure that staff receive periodic awareness training appropriate to their roles, including training on cyber risks relevant to Virtual Assets and common attack vectors, and shall maintain records of such training. (4) Senior management shall periodically review the effectiveness of information security controls and allocate responsibilities to mitigate conflicts of interest and ensure adequate segregation between security oversight and operational delivery, where practicable. 67. Cyber incident and BCDR event notification. - (1) Where a Licensee detects: (a) a material cybersecurity event; or (b) an event triggering activation of its business continuity and disaster recovery plan that materially impacts its operations, the Licensee shall notify the Authority as soon as reasonably practicable and, in any event, within twenty-four (24) hours of detection.
Page 40 of 77 (2) The notification under subsection (1) shall be an initial notification and shall include, to the extent known at the time (a) a brief description of the event and the date/time of detection; (b) the systems, services, or customer segments likely affected; (c) an initial assessment of impact on confidentiality, integrity, availability, and safeguarding of Customer Assets and data; (d) immediate containment and mitigation steps taken or planned; and (e) whether the Licensee has made, or expects to make, notifications to other competent authorities or law-enforcement agencies. (3) The Licensee shall provide the Authority with follow-up updates in such form and at such intervals as may be specified by the Authority, and in any event (a) a written interim update within five (5) Working Days of the initial notification (or earlier where requested), providing updated impact assessment, indicators of compromise (where relevant), and progress on remediation; and (b) a final report within thirty (30) calendar days of detection (or such other period as the Authority may allow), setting out the root cause analysis, the full scope and impact, Customer outcomes, and corrective and preventive actions. (4) The Licensee shall maintain records and supporting evidence relating to the event, including relevant logs and investigation outputs, and shall make such records available to the Authority upon request. 68. Personal data protection and privacy. — (1) A Licensee shall comply with all applicable data protection, data privacy and secrecy requirements in relation to Personal Data processed in connection with its licensed activities. (2) The licensee shall be bound to provide all the requisite information to the Authority as required under the Act, Rules, Regulations or as required from time to time under applicable laws in Pakistan. (3) Where a Licensee reasonably identifies a material conflict between applicable requirements under subsection (1) or (2) (including conflicts relating to cross-border transfers, secrecy laws, or cloud jurisdiction restrictions), the Licensee shall: (a) document the conflict and the legal basis for its assessment; (b) implement proportionate technical and organizational measures to mitigate associated risks; and (c) notify the Authority immediately where the conflict materially affects the Licensee’s ability to comply with these Regulations or to provide the Authority with access to information as required by the Authority. 69. Personal data protection compliance programme. - (1) A Licensee shall establish, document, implement and maintain a written programme for the governance and protection of Personal Data, proportionate to the nature, scale and complexity of its business and the sensitivity of the Personal Data processed. (2) The programme under subsection (1) shall, at a minimum, include: (a) assignment of responsibility and accountability for Personal Data protection; (b) policies and procedures for lawful processing, retention, access control, security, and disposal of Personal Data;
Page 41 of 77 (c) risk assessments and controls for cross-border transfers and the use of service providers; (d) staff training and periodic awareness measures; and (e) incident detection, response and notification arrangements aligned with these Regulations and applicable law. (3) A Licensee shall appoint a Data Protection Officer or designate a responsible senior person to oversee compliance with subsection (1), where this is required by applicable law or where directed by the Authority on a risk-based basis. (4) Subject to conflict-of-interest safeguards and adequacy of resources, the Authority may permit the Data Protection Officer function to be performed by the Chief Information Security Officer or another senior officer in smaller Licensees, where proportionate. 70. Provision of information to the Authority on data protection. - (1) A Licensee shall provide the Authority with information reasonably required to assess the Licensee’s compliance with this Chapter, in the manner and within the timeframe specified by the Authority. (2) The obligation under subsection (1) shall apply subject to applicable law, including data protection, banking secrecy, confidentiality, legal privilege, and restrictions arising from court orders or ongoing investigations in Pakistan or any relevant jurisdiction. (3) Where a Licensee is unable to provide information requested under subsection (1) due to a legal restriction under subsection (2), it shall: (a) promptly notify the Authority of the restriction and its basis; (b) provide such information as can lawfully be provided; and (c) propose lawful alternatives, which may include summaries, redactions, controlled access, or provision through an appropriate legal process. 71. Notification of personal data incidents. - (1) Where a Licensee becomes aware of a Personal Data breach or other incident affecting, or reasonably likely to affect, the confidentiality, integrity or availability of Personal Data, it shall notify the Authority without Undue Delay and, in any event, within seventy-two (72) hours of becoming aware of the incident, unless the Licensee demonstrates that a longer period is justified due to the circumstances and the Licensee has provided an initial notification. (2) The notification under subsection (1) may be staged and shall include, to the extent known at the time: (a) the nature of the incident and categories of Personal Data affected; (b) the likely impact on data subjects and the Licensee’s operations; (c) immediate containment measures taken or planned; and (d) the Licensee’s plan and timeline for further investigation and follow-up reporting. (3) The Licensee shall provide supplemental updates to the Authority as material information becomes available, including root cause analysis and remediation actions, within the timeline specified by the Authority. (4) Where the Licensee is required by applicable law to notify a data regulator or data subjects, the Licensee shall inform the Authority of such notifications as soon as reasonably practicable, and shall provide copies or summaries to the extent not prohibited by applicable law.
Page 42 of 77 72. Confidential information. - (1) A Licensee shall take reasonable steps to protect the confidentiality of information relating to its Customers and their affairs, and shall implement and enforce policies, procedures and controls to prevent unauthorized access, use or disclosure. (2) Confidential information may be used only: (a) for providing authorised Virtual Asset Services to the Customer; (b) for compliance with applicable law and regulatory requirements; or (c) where otherwise permitted by the Customer or applicable law. (3) A Licensee shall ensure that access to confidential information is limited on a “need-toknow” basis and is supported by appropriate access controls, monitoring and audit trails. (4) A Licensee shall provide training to relevant Employees on confidentiality obligations and shall require periodic attestations or acknowledgements, in the manner specified by the Licensee’s governance arrangements. (5) Neither a Licensee nor any of its Employees shall misuse confidential information, including by using such information for personal benefit or for any market abuse, fraud, or unfair dealing in relation to Virtual Assets. 73. Guidance on Technology Governance and Risk Assessment Framework. - (1) This Chapter sets out supervisory expectations to assist Licensees in designing, implementing and maintaining a Technology Governance and Risk Assessment Framework required under these Regulations. (2) The guidance in this Chapter (a) does not create independent legal obligations beyond those expressly set out elsewhere in these Regulations; and (b) may be taken into account by the Authority in licensing, supervision and risk assessment, including when determining whether a Licensee’s controls are proportionate and effective. (3) A Licensee shall apply this guidance in a manner proportionate to its nature, scale and complexity, including its custody model, technology stack, use of service providers, customer base, and risk profile. 74. Risk categories to be addressed. - (1) In developing and maintaining its Technology Governance and Risk Assessment Framework, a Licensee should consider risks including, as applicable (a) organizational and governance risks; (b) technical and security architecture risks; (c) detection, response and recovery risks; (d) customer asset protection and user security risks; and (e) operational resilience risks. (2) The Authority may publish supplementary guidance, examples and good practices for the risk categories in subsection (1), including sector-specific expectations for custody providers, exchanges, brokers, and token issuers.
Page 43 of 77 75. Organizational and governance risk considerations. - (1) A Licensee should maintain governance arrangements that allocate clear accountability for technology and security, including oversight by senior management and periodic reporting to the Board or equivalent governing body. (2) A Licensee should adopt a documented approach to technology risk management, which may include periodic security assessments, secure development practices, workforce security controls, and controls for technology service providers, proportionate to the Licensee’s risk profile. 76. Technical risk considerations. - (1) A Licensee should implement security controls that are appropriate to its custody model and threat profile, including controls for key management and wallet security where the Licensee holds or controls Customer Assets. (2) A Licensee should adopt defense-in-depth measures, which may include segregation of duties, access controls, monitoring, secure key storage arrangements, and procedures for responding to suspected compromise. (3) Where a Licensee deploys smart contracts or relies on smart contracts in providing services, it should implement controls for secure development, review and testing proportionate to the materiality and risk of such contracts. 77. Detection, response and recovery risk considerations. - (1) A Licensee should maintain capabilities to detect, investigate and respond to cyber threats and operational incidents, including escalation, containment and remediation processes. (2) Where appropriate to the business model, a Licensee should maintain capabilities for transaction monitoring and analysis, including supporting fraud prevention, incident response and Customer protection, consistent with applicable law. 78. Customer asset protection and user security considerations. - (1) A Licensee should implement controls designed to reduce the risk of unauthorized access to customer accounts and loss of Customer Assets, including authentication, withdrawal controls and customer awareness measures, proportionate to its client base and service model. (2) Where Customer Assets are held or controlled by the Licensee, it should consider concentration risk and implement appropriate operational arrangements for wallet management and diversification consistent with its safeguarding obligations. 79. Digital operational resilience testing considerations. - (1) A Licensee should establish and maintain a testing programme proportionate to its risks, including vulnerability assessments, penetration testing, and operational resilience testing. (2) The Authority may, on a risk-based basis, require a Licensee to undertake enhanced testing by qualified independent parties, having regard to the Licensee’s size, risk profile, systemic importance, custody footprint, and threat landscape. CHAPTER – VIII Compliance and Risk Management
Page 44 of 77 80. Compliance management system. - (1) A Licensee shall establish, implement and maintain an effective compliance management system (“CMS”) that is proportionate to the nature, scale and complexity of its business and the Virtual Asset Services it provides. (2) The CMS shall be able to: (a) cover all relevant aspects of the Licensee’s operations, including policies, procedures, processes, systems, controls, training, monitoring and escalation; (b) provide the Compliance Officer with timely access to information, records and personnel necessary to discharge the Compliance Officer’s responsibilities; (c) include arrangements to identify, assess, monitor and remediate compliance risks, including a risk-based testing and monitoring programme; and (d) ensure that material non-compliance is escalated promptly to the Board and, where required under these Regulations, notified to the Authority. (3) The CMS shall be documented, approved by the Board, and reviewed at least annually and following any material change to the Licensee’s business, risk profile, or applicable legal and regulatory requirements. (4) A Licensee shall establish and maintain written compliance policies and procedures that are consistent with these Regulations and any applicable Rules or Directives issued by the Authority. (5) An employee of the Licensee who in good faith reports to the Authority a contravention of the Act or any Rules or Regulations made thereunder it shall not be subjected to any form of retaliation. 81. Appointment of Compliance Officer. - (1) A Licensee shall appoint a Compliance Officer who: (a) is a Fit and Proper Person; (b) has appropriate seniority, competence and relevant experience to discharge the role, commensurate with the nature, scale and complexity of the Licensee’s activities and risk profile; (c) resident in Pakistan; (d) is a full-time employee of the Licensee or such other arrangement as may be permitted by the Authority having regard to the nature, scale and complexity of the Licensee; and (e) reports to the Board or a Board committee with responsibility for compliance oversight. (2) Where the Authority requires another appropriately authorised senior compliance representative to be ordinarily resident in Pakistan, such requirements shall be proportionate to the Licensee’s scale, customer footprint in Pakistan, and risk profile. (3) The Licensee shall notify the Authority of the appointment, replacement, or departure of the Compliance Officer in the manner and timeframe specified by the Authority. 82. Duties of the Compliance Officer. - (1) The Compliance Officer shall be responsible for establishing, administering and maintaining the CMS and for advising the licensee’s board or relevant board committees on the Licensee’s compliance with applicable legal and regulatory requirements.
Page 45 of 77 (2) Without prejudice to subsection (1), the Compliance Officer shall (a) implement and maintain compliance policies and procedures, systems and controls, including compliance training arrangements for Employees and Key Individuals; (b) monitor and assess compliance risks, including emerging regulatory and conduct risks relevant to the Licensee; (c) report periodically to the Board on the Licensee’s compliance posture, material findings, remediation progress and significant compliance incidents; and (d) ensure that material non-compliance is investigated, escalated and remediated, and where required, notified to the Authority. (3) Compliance activities may be delegated to appropriately qualified personnel or service providers, provided that the Compliance Officer remains accountable for the effectiveness of the CMS. (4) The Compliance Officer may perform additional non-client-facing roles only where this does not compromise independence, creates no material conflict of interest, and does not impair the discharge of compliance responsibilities. 83. Risk management framework. - (1) A Licensee shall establish, implement and maintain a risk management framework that is proportionate to the nature, scale and complexity of its business and the risks arising from the Virtual Asset Services it provides. (2) The risk management framework shall include policies, procedures and methodologies to identify, measure, monitor, manage and report material risks, including financial, operational, technology and conduct risks. (3) The Licensee’s board shall approve the risk management framework and ensure it is reviewed periodically and following any material change to the Licensee’s business, operations, Key Individuals, or the market conditions and legal or regulatory requirements applicable to the Licensee. (4) Where a Licensee’s nature, scale or risk profile warrants a dedicated risk function, the Licensee shall appoint a Head of Risk with appropriate authority and competence, who shall have direct access to the Board. 84. Risk reporting. - (1) A Licensee shall provide the Board with periodic risk reporting sufficient to enable effective oversight of the Licensee’s risk profile and compliance with these Regulations. (2) Risk reporting shall be provided at least quarterly, or more frequently where warranted by the Licensee’s risk profile or where a material risk event occurs. (3) Risk reporting should, as applicable, cover: (a) financial risks (including liquidity, capital adequacy, treasury and exposures); (b) operational and technology risks (including cybersecurity and resilience); (c) conduct and market integrity risks (including conflicts of interest and market abuse risks where relevant); (d) financial crime risks (including AML/CFT/CPF); and (e) customer asset and consumer protection risks (including safeguarding arrangements).
Page 46 of 77 85. Operational management. - (1) A Licensee shall establish and maintain operational policies, procedures and controls to ensure (a) fair, honest and professional treatment of clients and market participants; (b) safeguarding of Customer Assets in accordance with regulations 103 to 112, the Act, any Rules or Regulations made under the Act, and any applicable direction, circular, standard, directive, guideline or other written instrument issued by the Authority under the Act; (c) integrity and reliability of records and management information; and (d) compliance by the Licensee and its Employees with applicable legal and regulatory requirements. (2) Where a Licensee may act on behalf of a client in relation to account operation or transactions, the Licensee shall disclose to the client the scope of its authority and the procedures and terms under which it may act, and shall act consistently with the client agreement and the client’s instructions. (3) A Licensee shall perform reconciliations and verification checks at a frequency proportionate to its business model and risks, including reconciliation of internal records against relevant third-party statements and distributed ledger records where applicable, to identify errors, omissions or misallocation of assets. (4) A Licensee may establish committees to perform its responsibilities and to support compliance and risk oversight. 86. Books and records. - (1) A Licensee shall maintain complete, accurate and up-to-date books and records sufficient to demonstrate compliance with these Regulations and to enable effective supervision by the Authority. (2) Records shall be retained in original form or native file format, where practicable, and shall include an audit trail of material activities and transactions, including the information necessary to support investigations, dispute resolution and regulatory reporting. (3) Without prejudice to subsection (2), records should include, as applicable: (a) transaction records (amount, date/time, fees/charges, relevant account or wallet identifiers, and counterparties where available); (b) client onboarding and due diligence records; (c) general ledger and financial records; (d) governance records (Board minutes and committee records); (e) complaints handling and error resolution records; and (f) conflicts of interest registers. (4) Records shall be retained at least for the period required under the Anti-Money Laundering Act, 2010 (VII of 2010), in accordance with section 47(4) of the Act or seven (7) years whichever is higher. Records shall be produced to the Authority in the manner required. 87. Audit. - (1) A Licensee shall appoint an external auditor, a firm of chartered accountants approved by the Division concerned that is independent under applicable law and any other requirements specified by the Authority. (2) The external auditor shall audit the Licensee’s financial statements in accordance with International Financial Reporting Standards and applicable company law requirements, and the
Page 47 of 77 Licensee shall submit audited financial statements to the Authority as specified in Schedule I of these Regulations. (3) A Licensee shall cause its operations to be audited annually and shall include a verification of the segregation of Customer Assets as required under section 24 of the Act. (4) The Authority may, on reasonable grounds and having regard to the nature, scale and complexity of the Licensee, require the Licensee to appoint an alternative auditor or to procure additional assurance engagements relating to specified risk areas. Any additional assurance engagement shall be risk-based and proportionate and shall not duplicate existing statutory audit or assurance requirements unless justified by identified supervisory concerns. (5) A Licensee shall establish an internal audit function that is independent of operational activities and reports to the Board or an audit committee. (6) Internal audit shall be conducted on a risk-based plan and at a frequency proportionate to the Licensee’s risks, and shall report findings, recommendations and remediation tracking to the Board. 88. Regulatory reporting. - (1) A Licensee shall submit to the Authority such returns, statements and information as may be required by the Authority, in the form, manner and frequency specified by the Authority, having regard to the nature, scale, complexity and risk profile of the Licensee and the Virtual Asset Services it provides. (2) Without prejudice to subsection (1), the Authority may require periodic reporting to include, as applicable (a) financial statements and prudential returns sufficient to demonstrate compliance with applicable capital, liquidity and safeguarding requirements; (b) information on Customer Assets safeguarding arrangements and reconciliations, where relevant to the Licensee’s business model; (c) risk and compliance reporting, including key risk indicators, AML/CFT reporting as required under the AML Act, 2010 and material control findings; and (d) such other information as the Authority considers reasonably necessary for effective supervision. (3) The Authority shall, where practicable, specify standard templates and reporting timelines and may vary reporting frequency on a risk-based basis, including for Licensees that are newly licensed, operating under limitations, or subject to enhanced supervision. 89. Additional information. - (1) The Authority may, by written notice, require a Licensee to provide additional information or documents where necessary for supervisory purposes, including to verify compliance with these Regulations or to assess risks to customers or market integrity. (2) A Licensee shall provide information under subsection (1) within the timeframe specified by the Authority, subject to applicable law. 90. Regulatory notifications. - (1) A Licensee shall notify the Authority without delay, and in any event within any timeframe specified in these Regulations or, where no such timeframe is specified, within the timeframe specified by the Authority, upon becoming aware of any matter that materially affects, or is reasonably likely to materially affect:
Page 48 of 77 (a) the Licensee’s ability to comply with these Regulations; (b) the Licensee’s financial soundness or operational resilience; (c) the safety of Customer Assets; or (d) the Licensee’s fitness and propriety governance arrangements. (2) Without prejudice to subsection (1), notifiable events include: (a) commencement of Insolvency Proceedings in respect of the Licensee; (b) any material criminal or civil proceedings, or material regulatory investigation or enforcement action, involving the Licensee, or any Controller, Board member, or Key Individual, where relevant to fitness and propriety or the Licensee’s operations; (c) any material breach of law or of these Regulations relating to the conduct of Virtual Asset Services; and (d) cybersecurity and data incidents in accordance with the Technology chapter. (3) A notification under this Regulation shall include such information as is reasonably available at the time, and the Licensee shall provide supplemental updates as further information becomes available. 91. Employees management and training. - (1) A Licensee shall ensure that Employees are competent, suitably qualified and appropriately supervised for the roles they perform, having regard to the nature of the Virtual Asset Services provided. (2) A Licensee shall maintain adequate staffing and resources to operate safely and in compliance with these Regulations. (3) A Licensee shall implement and maintain training programmes that are proportionate to roles and risks, including induction training and periodic refresher training. (4) Without prejudice to subsection (3), a Licensee shall provide periodic training on AML/CFT/CPF, sanctions compliance, fraud risk, and conduct expectations, and shall maintain records of training completion. (5) A Licensee shall ensure that material updates to policies and procedures are communicated to relevant Employees promptly and are readily accessible. 92. Tax reporting and compliance. - (1) A Licensee shall comply with the obligations imposed under the applicable tax laws and any Rules or Regulations issued by the relevant tax authority, in accordance with section 66 of the Act, and shall comply with all other applicable tax laws and tax reporting obligations in Pakistan that are relevant to its business and the Virtual Asset Services it provides. (2) Where the Authority issues requirements under these Regulations relating to tax reporting, such requirements shall apply to the extent and in the manner specified by the Authority and subject to applicable law. 93. Appointment of Money Laundering Reporting Officer. - (1) A Licensee shall appoint an individual as Money Laundering Reporting Officer (“MLRO”) who: (a) is a Fit and Proper Person; (b) has adequate knowledge and experience in AML/CFT/CPF, commensurate with the nature, scale and complexity of the Licensee’s Virtual Asset Services; and
Page 49 of 77 (c) is of sufficient seniority and authority to discharge the responsibilities under applicable AML/CFT/CPF laws and these Regulations. (2) The Licensee shall ensure that the MLRO has direct access to the Board and unfettered access to relevant records, systems, and personnel necessary to perform the MLRO function. (3) The appointment of the MLRO and the continuing suitability of the MLRO shall be reviewed periodically and, in any event, at least annually. 94. Duties of the MLRO. - (1) The MLRO shall be responsible for establishing, implementing and maintaining the Licensee’s AML/CFT/CPF framework, including: (a) AML/CFT/CPF policies, procedures and internal controls; (b) enterprise-wide AML/CFT/CPF risk assessment and risk-based mitigation measures; (c) oversight of customer due diligence, transaction monitoring and sanctions screening; (d) suspicious transaction reporting and liaison with the Financial Monitoring Unit (“FMU”) and other competent authorities, as applicable; and (e) periodic reporting to the Board on the effectiveness of the AML/CFT/CPF framework, material issues, and remediation status. (2) AML/CFT/CPF tasks may be delegated under the MLRO’s oversight, provided that the Licensee remains responsible for compliance and the MLRO remains accountable for the effectiveness of the AML/CFT/CPF framework. 95. AML/CFT/CPF policies and procedures. - (1) A Licensee shall establish, implement and maintain AML/CFT/CPF policies and procedures that comply with: (a) applicable federal AML/CFT/CPF laws of Pakistan and binding instruments issued thereunder; and (b) such requirements, guidance, or directions, in the context, as may be issued by the competent Authority within their respective mandates. (2) The AML/CFT/CPF policies and procedures shall be risk-based and shall, as a minimum, address (a) prohibition of anonymous or fictitious relationships where prohibited by applicable law; (b) targeted financial sanctions compliance, including mechanisms to implement applicable UNSCR-related measures as required under AML Act, 2010, in interpreting and applying those requirements, regard may be had to relevant FATF Standards and guidance, requirements and other applicable laws; (c) recordkeeping and retrieval capabilities consistent with applicable law; (d) customer due diligence (including beneficial ownership), ongoing monitoring, and enhanced due diligence for higher-risk relationships; and (e) controls relevant to Virtual Assets, including the Travel Rule where applicable. (3) The Authority may require a Licensee to provide copies of its AML/CFT/CPF policies and procedures, and material updates thereto, within the timeframe specified by the Authority. 96. AML/CFT/CPF systems and controls. - (1) A Licensee shall implement systems and controls proportionate to its risks, including screening and monitoring arrangements capable of
Page 50 of 77 identifying suspicious activity, sanctions exposure, and other illicit finance risks relevant to its Virtual Asset Services. (2) Where a Licensee uses distributed ledger analytics or similar tools, it shall (a) document the rationale for selecting the tool(s), including known limitations; (b) implement governance and quality controls over tuning, scenarios, thresholds and alerts; and (c) periodically review the effectiveness of such tool(s) and associated controls. 97. AML/CFT/CPF risk assessments. - (1) A Licensee shall conduct and maintain an enterprise-wide AML/CFT/CPF risk assessment covering, as relevant, customer types, products/services, delivery channels, transaction patterns, geographies, and Virtual Assetspecific risk factors (including anonymity-enhancing features where applicable). (2) The Licensee shall only permit the issuance, custody, transfer, trading, or other dealing in Virtual Assets incorporating anonymity-enhancing or privacy-enhancing features where it is able to comply with all applicable AML/CFT/CPF obligations/FATF Recommendations including customer due diligence, ongoing monitoring, record-keeping, sanctions screening, and the Travel Rule. Provided that where the Licensee is unable to comply with AML/CFT/CPF obligations and FATF recommendations, it shall not provide services in respect of such Virtual Assets (3) The risk assessment shall be reviewed (a) at least annually; and (b) promptly following any material change in the Licensee’s business model, products, customer base, geographic exposure, or material threat landscape. (4) The Licensee shall ensure that the outcomes of the risk assessment inform its AML/CFT/CPF controls, resourcing, monitoring scenarios, and enhanced due diligence measures, and shall be able to demonstrate this to the Authority upon request. 98. Customer due diligence. - (1) A Licensee shall apply customer due diligence measures on a risk-based basis in accordance with section 46 of the Act and applicable federal AML/CFT/CPF laws of Pakistan, including the Anti-Money Laundering Act, 2010 (VII of 2010) and any rules, regulations or guidelines issued thereunder. (2) A Licensee shall identify and verify customers and beneficial owners on the basis of documents, data and information obtained from the reliable source, understand the purpose and intended nature of the business relationship, and conduct ongoing monitoring. (3) A Licensee shall apply enhanced due diligence in accordance with the internal policy compliant with AML Act, 2010 and FATF requirements in the context, for higher-risk relationships, including where the customer or beneficial owner is a Politically Exposed Person, or where anonymity-enhancing features materially elevate risk. (4) As part of the CDD process, a Licensee shall verify customer’s identity by reference to the following documents, data or information from a reliable and independent source: (a)For individuals - full name as shown on CNIC or a passport; nationality; address; place of birth; Bank account details; and Source of fund.
Page 51 of 77 (b)For legal person which are not individuals - full name of the legal person; type of legal person; constitutional documents; principle place of business; authorized person and its relationship; names and details of Ultimate Beneficial Owner of the legal person; Bank account details; and Source of fund. (5) A Licensee shall not establish or continue a business relationship, or execute a transaction, where it is unable to complete required due diligence measures, except as otherwise permitted under applicable law. (6) Where a Licensee relies on third parties for elements of due diligence, it shall remain responsible for compliance and shall ensure appropriate controls, oversight and information access as envisaged in these Regulation and in compliance with the FATF Recommendation 17. (7) VASPs may apply following measures for dormant or in-operative wallets: VASP shall send prior notice to the wallet holder through any registered medium, before marking the wallet as dormant. Notices shall be sent one (1) month, seven (7) days and one (1) day prior to marking the wallet as dormant. Notice shall also include the wallet activation procedures/ channels. (a) VASP may allow credit entries in dormant or in-operative wallets subject to compliance with other applicable AML/CFT/CPF regulations. (b) Debit transactions/ withdrawals shall not be allowed until the wallet is activated. However, transactions e.g. debits under the recovery of any liability, any permissible charges/fee, government duties or levies and instructions issued under any law or from the court will not be subject to debit or withdrawal restriction. (c) VASP may activate the dormant wallet upon receipt of a formal request from the customer through any authenticated medium.
(8) Unclaimed wallets/assets, which have not been operated for the last ten years except a wallet/asset in the name of a minor or a Government or a court of law, shall be surrendered to Strategic Digital Wallet Company (SDWC). The requirement to transfer unclaimed Customer Assets to the SDWC shall take effect only once an applicable regulatory procedure establishes: (a) that the SDWC receives the assets solely in a custodial capacity and not as Government property; (b) the transfer of responsibility and liability from the Licensee; (c) continued segregation, safeguarding, reconciliation and recordkeeping; (d) the treatment of forks, airdrops, staking rewards and other blockchain events; (e) responsibility for losses occurring after transfer; and (f) an effective and continuing right for the Customer to reclaim the assets. Until that regulatory procedure takes effect, the Licensee shall continue to safeguard the assets for the Customer in accordance with the Act and these Regulations. 99. Suspicious transaction monitoring and reporting. - (1) A Licensee shall maintain ongoing monitoring to identify suspicious transactions and activity and shall submit reports to the FMU in the manner and form required under the AML Act, 2010 and other regulations and guidelines issued thereunder. (2) The Licensee shall ensure internal escalation arrangements enable timely review and decision-making by the MLRO, including prompt filing to the FMU where required.
Page 52 of 77 (3) The Licensee shall notify the Authority of material AML/CFT/CPF breaches, material control failures, or significant exposure events in the manner and timeframe specified by the Authority, subject to applicable law and confidentiality constraints. (4) The Licensee shall maintain appropriate records relating to suspicious activity reviews and reports in accordance with provisions of AML Act, 2010, and shall provide information to the Authority upon request, subject to applicable law. Provided that nothing in these Regulations shall require disclosure of Suspicious Transaction Reports and related information, or any protected information, in a manner inconsistent with the AML Act, 2010. (5) Nothing in these Regulations shall be construed as limiting or replacing the obligation of a Licensee to submit STRs, CTRs or any other reports required under the AML Act, 2010 to the Financial Monitoring Unit. 100. Travel Rule compliance. - (1) A Licensee shall comply with section 47 of the Act (Travel rule and record-keeping obligations) and the requirements applicable to “wire transfers” and “virtual asset transfers” under the Federal AML-CFT Laws, including the requirements implementing the FATF Recommendation 16 and its Interpretive Note, as updated from time to time, and any detailed procedures, standards and formats prescribed by Regulations under the Act. (2) For the purposes of sub-regulation (1), a Licensee shall obtain, verify where required, and transmit or make available (as applicable) required and accurate originator and beneficiary information for Virtual Asset transfers meeting or exceeding the threshold of PKR equivalent of USD 1,000,. . (3) Prior to initiating a Virtual Asset transfer at or above the applicable threshold, an ordering Licensee shall ensure that it has obtained and holds the required originator information and required beneficiary information, and is able to make such information available to the FMU, the Authority and other competent authorities upon lawful request. (4) Prior to making Virtual Assets received through a transfer at or above the applicable threshold available to a customer, a beneficiary Licensee shall ensure that it has obtained and holds the required originator information and required beneficiary information, and is able to make such information available to the FMU, the Authority and other competent authorities upon lawful request. (5) Subject to the Federal AML-CFT Laws, the minimum originator information shall include (a) the originator’s full name; and (b) the originator’s account number, or Virtual Asset wallet address, or other unique transaction identifier; and (c) such additional identifiers as may be required under applicable law (which may include address, national identification number, customer identification number, or date and place of birth). (6) Subject to the Federal AML-CFT Laws, the minimum beneficiary information shall include (a) the beneficiary’s name; and (b) the beneficiary’s account number, or Virtual Asset wallet address, or other unique transaction identifier.
Page 53 of 77 (7) A Licensee shall implement risk-based controls to manage Travel Rule compliance risks relating to (a) transfers to or from unhosted wallets and other non-obliged persons and give regard to relevant FATF Standards and guidance; (b) deposits and withdrawals where counterparty information is incomplete, unavailable, or unreliable; (c) transactions or patterns designed to evade thresholds or information requirements; and (d) anonymity-enhancing features or services, where applicable. (8) Prior to establishing a material relationship for Virtual Asset transfers with a counterparty VASP in another jurisdiction, a Licensee shall conduct risk-based due diligence on the counterparty’s Travel Rule and AML/CFT controls in accordance with AML Act, 2010, in interpreting and applying those requirements, regard may be had to relevant FATF Standards and guidance, and shall review such due diligence annually and upon the occurrence of heightened risk indicators. (9) A Licensee shall be required to demonstrate to the Authority, during licensing and on an ongoing basis, the policies, procedures, systems and controls implemented to comply with this Regulation, and shall provide evidence of their effectiveness within the timeframe specified by the Authority. 101. Compliance with targeted financial sanctions. - (1) A Licensee shall maintain policies, procedures and controls to comply with applicable targeted financial sanctions obligations under: (a) relevant United Nations Security Council Resolutions as implemented in Pakistan; and (b) the Federal AML-CFT Laws and any binding directions issued by competent authorities in Pakistan. (2) The controls under subsection (1) shall be proportionate to the Licensee’s risk profile and shall include, as applicable (a) screening of customers (including beneficial owners) and relevant counterparties; (b) screening of transfers against applicable designations; (c) escalation and decision-making processes for potential matches; and (d) procedures to implement freezing, blocking, rejection, or other required measures to the extent mandated by applicable law, FATF recommendation (if any) and competent authority directions. (3) A Licensee shall maintain records of sanctions screening actions, escalations, and measures taken under subsection (2) for the period required by applicable law, and shall make such records available to the Authority upon request, subject to applicable law. 102. AML/CFT recordkeeping. - (1) A Licensee shall retain records relating to AML/CFT/CPF in accordance with the Federal AML-CFT Laws, including: (a) Virtual Asset transaction records (including identifiers, wallet addresses, timestamps, and audit trails sufficient to reconstruct transactions); (b) customer due diligence and beneficial ownership records; (c) ongoing monitoring records, alerts, investigations and dispositions; and (d) suspicious transaction reports and related internal analysis, to the extent permitted by applicable law.
Page 54 of 77 (2) Records under subsection (1) shall be retained for the minimum period required under the AML Act, 2010 and the rules and regulations issued thereunder, and where no minimum period is specified, for a period of at least seven (7) years. 103. Client Money: application, interpretation and safeguarding. - (1) For the purposes of this Chapter, “Client Money” means money (including fiat currency) owned by a Client which is received, held or controlled by a Licensee on behalf of that Client in the course of, or in connection with, the provision of any Virtual Asset Service, excluding (a) money that is immediately due and payable to the Licensee for its own account (including fees and charges) in accordance with the Client Agreement; (b) money received by the Licensee as reimbursement of expenses properly incurred on behalf of the Client and due and payable to the Licensee; and (c) any other amounts that are due and payable to the Licensee in accordance with the Client Agreement. (2) Client Money does not include Virtual Assets held on behalf of a Client, which shall be subject to regulations 108 to 112 (Client Virtual Assets: safeguarding, segregation, reconciliations and proof of reserves). (3) Client Money shall be treated as held or controlled by a Licensee where it is (a) held by the Licensee; (b) held in an account in the name of the Licensee (including an account designated for Clients); or (c) held by a Person controlled by the Licensee, or in an account in the name of such Person, for the benefit of Clients. (4) A Licensee that receives, holds or controls Client Money shall establish and maintain policies, systems and controls, proportionate to the nature, scale and complexity of its business, to ensure that Client Money is (a) segregated from the Licensee’s own money; (b) identifiable and appropriately safeguarded at all times; and (c) not used to meet obligations of the Licensee or of any other Client. 104. Client Accounts and treatment of Client Money. - (1) A Licensee that holds Client Money shall hold such Client Money in one or more segregated accounts designated for Clients (each a “Client Account”) with a bank licensed by State Bank of Pakistan (a “Permitted Bank”). (2) Client Money held in a Client Account in accordance with section 24(2) of the Act, shall not be treated as the Licensee’s property and shall not form part of the Licensee’s estate in the event of Insolvency, subject to applicable insolvency law and any directions of the competent court or insolvency office-holder. (3) A Licensee shall ensure that each Client Account is appropriately designated to distinguish it from the Licensee’s own accounts, including through account naming conventions and internal records. (4) A Licensee shall pay Client Money into a Client Account immediately after receipt and, in any event, no later than the end of the next Business Day, unless (a) the money is held only temporarily for onward transmission in accordance with a Client instruction and is transmitted within the same timeframe; or
Page 55 of 77 (b) the money is received in connection with a delivery-versus-payment arrangement and is settled in accordance with the arrangement within the same timeframe; or (c) the money is held in an account in the Client’s own name and the Licensee has a mandate to operate that account on behalf of the Client. (5) A Licensee shall not pay into a Client Account any money of its own, except (a) a minimum amount required by the Permitted Bank to open or maintain the account; or (b) money used temporarily to meet an identified shortfall in Client Money, provided that such top-up is clearly recorded, justified, and reversed as soon as practicable after the shortfall is resolved. (6) Withdrawals or transfers out of a Client Account shall be subject to appropriate authorization controls and shall only be made where the relevant amount is (a) due and payable to the Licensee in accordance with the Client Agreement; (b) payable to, or at the instruction of, the relevant Client; (c) required to meet the payment obligations of the relevant Client in connection with the authorised service; or (d) otherwise permitted by these Regulations or directed by the Authority. (7) A Licensee shall not use Client Money of one Client to meet an obligation owed to another Client or to any other Person, and shall maintain controls to prevent offsetting, netting or negative balances within Client Accounts. 105. Banking arrangements for Client Accounts. - (1) A Licensee shall select one or more Permitted Banks taking into account safety, resilience, operational capability, and legal protections applicable to client asset segregation, in a manner proportionate to the Licensee’s business model and risk profile. (2) A Licensee shall take reasonable steps to ensure that the terms governing each Client Account support segregation and do not permit the Permitted Bank to apply set-off or combination of accounts in respect of the Licensee’s obligations, to the extent achievable under applicable law and standard banking arrangements. (3) Where a Licensee is unable to obtain a specific contractual acknowledgement from a Permitted Bank, the Licensee shall refrain from opening Client Account from said Permitted Bank. 106. Records, client statements and audit trail. - (1) A Licensee shall maintain accurate books and records sufficient to identify Client Money, track receipts and payments, and reconcile Client Money to Client Accounts, including (a) date of receipt; (b) the relevant Client identifier; (c) payer / source where available; and (d) transaction reference and banking value date. (2) A Licensee shall provide Clients with periodic statements of Client Money balances and movements at a frequency appropriate to the service and Client type, and in any event: (a) at least monthly for retail Clients; and
Page 56 of 77 (b) at such other frequency as agreed with professional Clients, provided that information remains clear and accessible. (3) Statements under subsection (2) shall be made available promptly following the statement date, and in any event within a timeframe that is reasonable having regard to the Licensee’s systems and the delivery channel used. 107. Reconciliation and discrepancy notification. - (1) A Licensee shall perform reconciliations of Client Money and Client Accounts at a frequency proportionate to its activity, and in any event no less frequently than daily where the Licensee processes Client Money movements on a daily basis. (2) Reconciliations shall compare (a) aggregate Client ledger balances; (b) Client Account cash book balances; and (c) Permitted Bank statements or confirmations as at the reconciliation point. (3) A Licensee shall investigate and resolve shortfalls, excesses and unexplained differences promptly, and where necessary may use its own funds temporarily to address a shortfall pending resolution. (4) A Licensee shall notify the Authority without delay of any material discrepancy that is not rectified within the timeframe specified by the Authority, and shall provide a summary of cause and remediation steps. 108. Client Virtual Assets: application and interpretation. - (1) In this Chapter, “Client Virtual Assets” means Virtual Assets beneficially owned by a Client which are held, controlled, safeguarded or administered by a Licensee on behalf of that Client in the course of, or in connection with, the provision of any Virtual Asset Service, excluding Virtual Assets that are due and payable to the Licensee for its own account in accordance with the Client Agreement (including fees and charges), or properly payable as reimbursement of expenses. (2) Client Virtual Assets are treated as held, controlled, safeguarded or administered by a Licensee where (a) they are held in a wallet, account or other arrangement operated by or for the Licensee; (b) they are held in a wallet or account in the name of the Licensee or a Person controlled by the Licensee; or (c) the Licensee (or a Person acting on its behalf) holds, controls or can access the private keys, seed phrases, signing devices, authorization credentials, or other means necessary to transfer or otherwise dispose of those Virtual Assets. 109. Safeguarding and segregation of Client Virtual Assets. - (1) A Licensee shall establish and maintain policies, systems and controls, proportionate to the nature, scale and complexity of its business, to safeguard Client Virtual Assets and ensure they are identifiable, appropriately protected, and segregated from the Licensee’s own assets. (2) Client Virtual Assets are not owned by the Licensee. The Licensee shall hold or control Client Virtual Assets solely for the benefit of Clients and shall not treat Client Virtual Assets as its own assets.
Page 57 of 77 (3) A Licensee shall maintain records that clearly identify which wallets, addresses, accounts or sub-accounts contain Client Virtual Assets and shall label such wallets or ledger designations accordingly (including through internal ledger tagging). (4) A Licensee shall not use, pledge, encumber, lend, stake, rehypothecate, or otherwise dispose of Client Virtual Assets except (a) as required to execute an instruction of the Client; or (b) where expressly permitted under these Regulations and with the Client’s prior explicit written consent, including clear disclosure of the nature of the activity, associated risks, withdrawal restrictions (if any), and how rewards/losses are allocated. (5) Any rewards, proceeds or benefits attributable to Client Virtual Assets (including airdrops, forks, staking rewards, or similar) shall accrue to the Client unless otherwise agreed with the Client in advance in the Client Agreement and disclosed in a fair, clear and not misleading manner. (6) A Licensee shall not take ownership of Client Virtual Assets under any Client Agreement except as expressly permitted under these Regulations. 110. Insolvency treatment and client asset protection. - (1) A Licensee shall structure its custody and safeguarding arrangements to support the segregation and protection of Client Virtual Assets in the event of Insolvency. (2) The Licensee shall maintain records, wallet structures and reconciliation capabilities sufficient to facilitate the timely identification and return (or transfer) of Client Virtual Assets, subject to applicable insolvency law and any directions of the competent court or insolvency office-holder. 111. Reconciliations and discrepancy notification. - (1) A Licensee shall conduct reconciliations of Client Virtual Assets at a frequency proportionate to its activity, and in any event no less frequently than daily where the Licensee processes Client Virtual Asset movements on a daily basis. (2) Reconciliations shall include, as applicable (a) Client ledger balances per asset; (b) on-chain balances for relevant wallets/addresses (or equivalent control evidence); (c) pending transactions, unconfirmed deposits/withdrawals, and other timing items; and (d) identification and investigation of breaks, shortfalls or excesses. (3) The Licensee shall notify the Authority without delay of any material discrepancy that is not rectified within an appropriate timeframe, and shall provide a summary of cause, impact and remediation. (4) The Licensee shall conduct a root cause analysis of any material discrepancy and implement appropriate remedial measures to prevent recurrence. 112. Proof of reserves and independent validation. - (1) Where a Licensee holds, controls, safeguards or administers Client Virtual Assets, the Licensee shall maintain procedures to demonstrate that its liabilities to Clients in respect of Client Virtual Assets held, controlled, safeguarded or administered by the Licensee are fully matched by reserve assets (or equivalent safeguarding arrangements) in accordance with the custody and safeguarding requirements in
Page 58 of 77 regulations 108 to 112 and as prescribed by the Authority under the Act or these Regulations. Provided that, for the purposes of this regulation, “liabilities to Clients” shall be determined net of the following, however, the VASP shall report to the Authority both gross and net liabilities on six monthly basis (a) authorised margin arrangements; and (b) risk exposures and losses contractually agreed by Clients, to the extent such exposures do not constitute Client Virtual Assets held, controlled, safeguarded or administered by the Licensee. The reporting can be at an earlier or more frequent interval required by the Authority by written notice, where reasonably necessary having regard to the Licensee’s scale, custody arrangements, risk profile, any material discrepancy or another identified supervisory concern. The notice shall specify the reasons, scope, frequency and duration of the requirement and shall allow a reasonable implementation period, unless urgent action is necessary to protect Customer Assets. (2) Proof of reserves procedures under subsection (1) may include automated or cryptographic methods, including third-party attestation and cryptographic verification, provided that such methods are capable of demonstrating, to the satisfaction of the Authority: (a) the existence and control of the relevant reserve assets; and (b) that Client liabilities are fully matched in accordance with this Chapter and prescribed by the Authority under the Act or these Regulations (including by Rules or Regulations made under the Act or by written instrument issued under the Act) (3) Proof of reserves shall be subject to independent validation on six monthly basis or earlier as required by the Authority. Such validation may be carried out by (a) an external auditor; (b) a qualified assurance provider; or (c) an internal assurance function that is independent of custody operations, including through methods such as third-party attestation or cryptographic verification, only where permitted by the Authority Such validation report must be submitted to the Authority within 30 days of the end of six months period. (4) For avoidance of doubt, compliance with this Regulation does not derogate from the Licensee’s obligations to safeguard and segregate Client Virtual Assets under this Chapter, nor does it limit any other prudential or custody requirements applicable to the Licensee. 113. Anti-bribery and corruption programme. - (1) A Licensee shall establish, implement and maintain an effective anti-bribery and corruption programme that is proportionate to the nature, scale and complexity of its business and risks. (2) The programme shall be documented in an Anti-Bribery and Corruption Policy and supporting procedures and shall be designed to prevent, detect and address bribery and corruption risks in the Licensee’s operations, including in dealings with public officials and private counterparties.
Page 59 of 77 (3) The programme shall be aligned with applicable anti-bribery and anti-corruption laws and regulations and may take account of internationally recognized good practices to the extent consistent with applicable law. (4) The Board retains overall responsibility for ensuring the programme is effective. The Compliance Officer shall oversee implementation and monitoring, and shall report material findings to the Board at intervals appropriate to the Licensee’s risk profile. 114. Minimum policy requirements. - (1) The Anti-Bribery and Corruption Policy shall, as a minimum: (a) prohibit bribery and corruption in any form, including direct and indirect bribes, facilitation payments, and improper advantages; (b) set clear rules and controls for gifts, hospitality, sponsorships, charitable contributions, political contributions (if any), and conflicts of interest; (c) require risk-based due diligence and contractual controls for Third-Party Service Providers and other relevant counterparties; (d) provide for escalation, investigation, remediation, and disciplinary measures that are fair, consistently applied and compliant with applicable law; and (e) require recordkeeping sufficient to evidence compliance with this Chapter. (2) The Policy shall permit confidential reporting, including by persons outside the Licensee, through appropriate reporting channels, and shall include measures to protect reporters from retaliation, subject to applicable law. 115. Prohibited conduct. - (1) A Licensee, and any person acting on its behalf, shall not: (a) offer, promise, give, request, agree to receive, or accept any undue advantage in connection with the Licensee’s business; (b) make or accept facilitation payments; or (c) use Third-Party Service Providers, intermediaries, or other arrangements to circumvent the requirements of this Chapter. (2) The Licensee shall maintain controls designed to prevent payments for services that are not legitimate, not properly documented, or not commensurate with services actually provided. (3) Hospitality and gifts are permitted only where they are reasonable, proportionate, transparently recorded, and consistent with the Licensee’s Policy and applicable law. 116. Reporting, investigation and remediation. - (1) The Licensee shall maintain and publish (as appropriate) methods of contact for reporting suspected or actual bribery or corruption, including anonymous or confidential reporting where feasible. (2) The Compliance Officer shall ensure that credible reports are assessed promptly, investigated where appropriate, and escalated to the Board in accordance with the Licensee’s procedures. (3) The Licensee shall document investigation steps, findings and remediation actions, and shall retain such records for at least seven (7) years or such longer period as required under applicable law. 117. Training and communication. - (1) The Licensee shall provide periodic anti-bribery and anti-corruption training to the Board, Key Individuals and Employees, and tailored training to
Page 60 of 77 higher-risk roles (including those involved in procurement, third-party management, government engagement, sales, and finance). (2) The Policy shall be made accessible to all relevant persons, and material updates shall be communicated promptly. (3) Anti-bribery and anti-corruption training shall form part of induction for new Board members, Key Individuals and Employees. 118. Notifications to the Authority. - (1) The Licensee shall notify the Authority without delay where it becomes aware of a material bribery or corruption incident relating to the Licensee’s regulated activities, including where (a) a matter is referred to, or investigated by, a competent law enforcement authority; (b) the incident may materially affect the Licensee’s integrity, governance, financial position, or ability to comply with these Regulations; or (c) the incident involves a Key Individual, Controller, or other person in a position of significant influence. (2) Notifications under subsection (1) shall be made to the extent permitted by applicable law (including restrictions relating to legal privilege, confidentiality, or ongoing investigations). FORM-I [see regulation 6(1)] APPLICATION FOR NO OBJECTION CERTIFICATE TO INCORPORATE A VIRTUAL ASSET SERVICE PROVIDER The information and documents listed in Parts A–E mainly apply to the NOC stage. Part F mainly applies to the Licensing Application stage following incorporation unless otherwise specified by the Authority. Date: _______________ To The Pakistan Virtual Asset Regulatory Authority (the Authority) Islamabad, Pakistan Subject: Application for No Objection Certificate to incorporate a Virtual Asset Service Provider Dear Sir/Madam, We, the undersigned sponsors and proposed directors (the Applicants), hereby apply for the grant of a No Objection Certificate in accordance with regulation 6 of the Pakistan Virtual Asset Services Regulations, 2026 , to incorporate a company under the Companies Act, 2017 under the proposed name * --------------------------------------------- (the Proposed VASP) for
Page 61 of 77 the purpose of undertaking the following [Category(ies) of Licence / VA Activity(ies)]: ------ ----------.** The information and documents required under the Annexure to this Form, duly completed, verified and signed by all Applicants, are enclosed. We solemnly declare that the information provided in this application and in the enclosed Annexure is true, complete and correct to the best of our knowledge and belief, and that no material information has been concealed or omitted. We undertake to keep the information and documents submitted under this application up to date and to notify the Authority in writing of any material change thereto without Undue Delay and in accordance with the requirements in these Regulations. Evidence of payment of the prescribed processing fee in the amount of PKR [x] (receipt/reference no. [x]), paid on [x] through [bank/PSID/channel], is enclosed. Yours faithfully, ------------------------ Name: [●] CNIC/Passport No.: [●] Signature: [●] (On behalf of all Applicants) Signed by all sponsors and proposed directors (Applicants) *Proposed name of the company **Category(ies) of Licence / VA Activity(ies) to be undertaken ANNEXURE TO FORM-I [see regulation 6] INFORMATION TO BE SUPPLIED FOR OBTAINING A NO-OBJECTION CERTIFICATE (NOC) AND, WHERE APPLICABLE, FOR LICENSING READINESS Date of Application; DD/MM/YYYY
Part A – Applicant Information
Page 62 of 77 3. Deposit Date; //______ DD/MM/YYYY Challan #: M-______________________ (Annex the Original Challan as Annexure) 4. Legal Status (intended for business in Pakistan): ☐ Private Limited ☐ Public Limited (Unlisted) ☐ Public Limited (Listed) 5. Type of Licence applied for: Advisory Services Broker-Dealer Services; Custody and Administration Services; Exchange Services Lending and Borrowing Services; Virtual Asset Derivatives Services; Virtual Asset Management and Investment Services; Virtual Asset Transfer and Settlement Services; Asset-Referenced Token Issuance Services; Fiat-Referenced Token Issuance Services; Mining Related Virtual Asset Service. (Please attach a copy of /draft of memorandum and Articles of Association of the company, as an Annexure) 6. Registered Office Address: 7. Contact Person Name, email and Mobile Number: Name & Designation: Mobile Number: Email: 8. Composition of Board of Directors and shareholders, including identification of the Controller of the proposed VASP: Name of Person Position; Shareholder /Director/CEO /Sponsor Shareholding Percentage (%) of Shareholding Net Worth (for NOC application, related to Shareholder) Rs. i ii iii iv v Total Part B – Capital & Financial Information of the proposed VASP:
Page 63 of 77
Page 64 of 77 2. Jurisdictional delivery model and channels Provide a description of how the proposed Virtual Asset Services will be delivered, including: (a) whether services will be provided onshore in Pakistan, cross-border into Pakistan, and/or through digital channels (website, mobile application, API, affiliates, or other online distribution); (b) the proposed legal structure and jurisdictional model (including the legal entity/entities providing the services in Pakistan, and the jurisdictions in which those entities are already incorporated and/or regulated); (c) the intended target customer base by geography and customer type (retail/professional/institutional), and how geo-targeting/geo-blocking and onboarding eligibility controls will be implemented; (d) the location of key operational functions relevant to the Pakistan business (including customer onboarding, compliance, transaction monitoring, custody/key management, customer support, and complaint handling); and (e) any planned use of group entities, branches, agents, affiliates, third-party distributors, or outsourcing arrangements that support cross-border delivery. Part D – Sponsors /CEO/Directors of the Proposed VASP
Name of Organization Designa tion Period (from oldest to Current) From To
Page 65 of 77 i. Company A ii. Company B iii. Company C 3. Details of Director/Shareholder’s having 10% or more shareholding in other businesses: Name of Director/Shareholder Business Name Address Shareholding i. ii. 4. Details of material legal proceedings/insolvency/bankruptcy/penal actions against Applicant/CEO/Directors/Sponsors Name of Person Legal Proceedings Insolvency/bankruptc y Penal actions i . 5. Details of the affiliation and outsourcing contracts: Name of Person Nature of Affiliation Name and Nature of Agreement Validity i.
Page 66 of 77 Part E – Declarations and Confirmations We, hereby declare that:
Designation: _________________________________ Signature & Date:
Company Seal / Stamp
Page 67 of 77 Part F - Additional Information/Documents to be Submitted along with the Licensing Application
Page 68 of 77 Annexure A Affidavit Affidavit by every sponsor, Controller, Directors and Key Individuals Before the Pakistan Virtual Asset Regulatory Authority (On Stamp Paper of Appropriate Value) I, ________________ son/daughter/wife of _______________________ adult, resident of _______________________________________________________________________ and holding CNIC/ Passport No. ______________________________ do hereby state on solemn affirmation as under: -
Page 69 of 77 no overdue loan payment and instalment outstanding towards banks or other financial institutions; 11. I have not been associated with any illegal banking business, deposit taking or financial dealings; 12. Neither I nor companies in which I am a director or controller has defaulted in paying taxes as on the date of application; 13. I have never been convicted of fraud or breach of trust or of an offence involving moral turpitude or removed from service for misconduct; 14. I have neither been adjudged an insolvent nor has defaulted in making payments, to my creditors; 15. I do solemnly declare that no investigations have been initiated against me by any Law Enforcement Agencies.
DEPONENT The Deponent is identified by me Signature _______________________ ADVOCATE (Name and Seal) Solemnly affirmed before me on this ______ day of _____________ at ______________ by the Deponent above named who is identified to me by , Advocate, who is known to me personally. Signature______________ OATH COMMISSIONER FOR TAKING AFFIDAVIT (Name and Seal)]
Page 70 of 77 FORM-II [see regulation 7] APPLICATION FOR LICENSE AS A VIRTUAL ASSET SERVICE PROVIDER Date: _______________ To The Pakistan Virtual Asset Regulatory Authority (the Authority) Islamabad, Pakistan Subject: Application for License as a Virtual Asset Service Provider Dear Sir/Madam, We, the undersigned sponsors and directors (the Applicants), hereby apply for the grant of a License in accordance with regulation 7 of the Pakistan Virtual Asset Services Regulations, 2026, under the company name * --------------------------------------------- (the VASP) for the purpose of undertaking the following [Category(ies) of Licence / VA Activity(ies)]: ----------- -----.** The information and documents required under the Annexure to Form I, duly completed, verified and signed by all Applicants, are enclosed. This application is submitted pursuant to NOC granted to the VASP on -------. We solemnly declare that the information provided in this application and in the enclosed Annexure is true, complete and correct to the best of our knowledge and belief, and that no material information has been concealed or omitted. We undertake to keep the information and documents submitted under this application up to date and to notify the Authority in writing of any material change thereto without Undue Delay and in accordance with requirements in these Regulations. Evidence of payment of the prescribed processing fee in the amount of PKR [x] (receipt/reference no. [x]), paid on [x] through [bank/PSID/channel], is enclosed. Yours faithfully, ------------------------ Name: [●] CNIC/Passport No.: [●] Signature: [●] (On behalf of all Applicants) Signed by all sponsors and directors (Applicants) *Proposed name of the company **Category(ies) of Licence / VA Activity(ies) to be undertaken
Page 71 of 77 FORM -III [see regulation 9(1)] PAKISTAN VIRTUAL ASSETS REGULATORY AUTHORITY Islamabad, Date __________ Licence No. _________ LICENCE TO CARRY OUT VIRTUAL ASSET SERVICES The Pakistan Virtual Assets Regulatory Authority (the Authority), having considered the application submitted under regulation 7 of the Pakistan Virtual Asset Services Regulations, 2026 by [Full legal name of company], a company incorporated under the Companies Act, 2017 (SECP Registration No. [x]) with its registered office at [x] (the Licensee), and being satisfied that the Licensee meets the eligibility requirements, hereby grants this Licence pursuant to regulation 9(1) of the Pakistan Virtual Asset Services Regulations, 2026 authorizing the Licensee to carry on the following Category(ies) of Licence / VA Activity(ies): ● [●] ● [●] ● … This Licence takes effect on [effective date] and shall remain valid [until revoked/suspended], subject to the Virtual Assets Act, 2026, these Regulations and any additional conditions imposed by the Authority by written direction in accordance with the Act and these Regulations. This Licence is issued to the Licensee only and is non-transferable. Authorised Officer Pakistan Virtual Asset Regulatory Authority Official Seal and Stamp *Authorised Virtual Asset Services / VA Activities as specified above. **Name of the Licensee (company).
Page 72 of 77 SCHEDULE-I [See regulations 5(2), 7, 9, 10(3), and 31] Minimum Paid-Up Capital and Prudential Conditions S. No. Category of Virtual Asset Service Type of Company & Minimum Number of Directors Minimum Paid up Capital (PKR) Number of directors with relevant experience of at least five years at a senior management level for a particular category of Virtual Asset Services, or related field. Submission of Financial Statements
Page 73 of 77 Unless expressly stated otherwise, the governance conditions in this Schedule (including board composition and experience requirements) apply to all Licence Categories. SCHEDULE-II FIT AND PROPER CRITERIA [see regulation 8, 9] APPLICATION AND SCOPE (1). The Fit and Proper Criteria in relation to the VASP is applicable to the following persons: (a) Controller, whether Individual or Body Corporate. (b) Directors. (c) Key Individuals. (d) Sponsors (e) Managing Director/Chief Executive Officer (2) A proposed director or managing director shall not assume the charge of office until their appointment has been approved by the Authority. (3) The application for seeking approval of the Authority under clause (2) shall be submitted along with the requisite information as specified in Part D of ANNEXURE TO FORM-I along with requisite attachments and an Affidavit as specified in Annexure “A”. (4) The appointment of Key Individuals (other than Managing Director and Directors) does not require the approval of the Authority; however, the Virtual Asset Service Provider shall ensure at the time of appointment of Key Individual (other than CEO and Directors) that such person is compliant with the Fit and Proper Criteria. (5) The fitness and propriety of Key Individuals shall be assessed by taking into account all the relevant factors including but not limited to the following: (a) Integrity and track record; (b) Financial soundness; (c) Professional Competence and Experience; and (d) Conflict of interest with the business of the VASP and its customers. Provided that 5 (c) and (d) may not be considered while assessing the fitness and propriety of promotors and controllers. Provided further that in case the Controller, being a sponsor and major shareholder, is a body corporate, in addition to the fit and proper criteria, the Authority shall assess the corporate behaviour of the said body corporate, as well as the integrity and track record of the ultimate beneficial owners of such body corporate. Explanation: For the purpose of this clause, the term “ultimate beneficial owner” shall have the similar meaning as defined under the AML Act, 2010 and any rules, regulations, directions/guidelines issued by the competent Authority thereunder as applicable. (6) In assessing whether an individual is a Fit and Proper Person, the Authority will:
Page 74 of 77 (a) consider all relevant factors in assessing the application of the fit and proper principles contained herein on a case-by-case basis, taking into account: i. the conditions of the License held by the VASP; ii. the business model of the VASP; iii. the market within which the VASP operates; iv. the governance structure, the internal control systems and the competence of the VASP’s Staff; v. decisions made by any other authority or regulatory body in respect of that individual, whether in Pakistan or in other jurisdictions; vi. the state of affairs of any other business which that the individual carries on or proposes to carry on. (7) The Fit and Proper Criteria is perpetual in nature and the person subject to Fit and Proper Criteria shall ensure compliance with the provisions of Fit and Proper Criteria. (8) All person’s subject to Fit and Proper Criteria shall report any change with reference to their fitness and propriety to the Company Secretary of the VASP within three business days of such change taking effect and the Company Secretary subject to Fit and Proper Criteria shall within a period of seven business days from the date of receipt, report the same to the Authority. (9) The VASP shall monitor whether any change in the status of its managing director, directors and key individuals is contrary to the requirements of the Fit and Proper Criteria. In case of any change in status, results in non-compliance with the Fit and Proper Criteria, the Board of Directors of the VASP shall immediately stop the person from performing his assigned functions, shall inform the Authority and initiate the process for replacement of the individual with a fit and proper individual. (10) Any violations or circumvention of the Fit and Proper Criteria shall be dealt with under the provisions of the Act. ASSESSMENT OF FITNESS AND PROPRIETY (i) Integrity, and track record: A person shall not be considered Fit and Proper if he: (a) has been convicted of an offence involving moral turpitude (both inside and outside Pakistan). (b) has been convicted of any offence including mismanagement, financial or business misconduct or, fraud (both inside and outside Pakistan). (c) has been convicted, after conducting an inquiry, by the Authority or any other regulatory or professional body or government agency. (d) has been subject to an ongoing investigation by the Authority or any other regulatory body on matters relating to financial fraud, financial misconduct, market abuse, violation of the Virtual Asset Act or law administered by any other regulatory body or any other matter raising concerns on the integrity of the person. (e) actively involved in the management or decision making of a company or firm whose registration or license has been revoked/cancelled or which has gone into liquidation or other similar proceedings due to mismanagement of affairs, financial misconduct or malpractice. Provided that in case of non-executive nominee directors representing institutional interest and who otherwise do not have any personal interest, the Authority may,
Page 75 of 77 after seeking explanation and if satisfied, after reasons to be recorded in writing, relax this requirement on case-to-case basis subject to such conditions as it may deem fit. (f) Is ineligible, under the Companies Act, 2017, or any other legislation or regulation, from acting as a director or serving in a managerial capacity of a company. (g) debarred from acting as director of the Company. (h) has been convicted in criminal breach of trust, fraud, offences of terrorism financing or money laundering including predicate offences as provided in the Anti-Money Laundering (AML) Act, 2010, laws make thereunder, or any other AML/ CFT (Countering Financing of Terrorism) requirements notified by the Authority, and is a proscribed/designated persons, either convicted or not, “as mentioned in the notifications issued by the Ministry of Foreign Affairs on United Nations Security Councils Resolutions or intimation from National Counter Terrorism Authority/ Law Enforcement Agencies/ Home Departments of Provinces/ Ministry of Interior. (i) entered into a plea bargain arrangement with the National Accountability Bureau (j) entered into scheme of compromise or arrangement with its creditor. (k) in case of Controller or major shareholder, does not have the requisite disclosed and verifiable financial resources. (ii) Financial Soundness: In assessing financial soundness of the person, the following shall be considered: (a) Whether the person is active tax payer and his/her name is appearing on active tax payer list of the tax authorities. (b) whether the person has been declared by a court of competent jurisdiction as defaulter in repayment of loan or financial obligation to a financial institution; (c) whether any instance of overdue or past due payment to a financial institution, irrespective of amount, is appearing in the overdue column of latest CIB report of the person and of the associated companies, firms, sole proprietorship etc. where the person is a managing director, director (other than nominee director), owner or partner etc. Provided that the Authority shall provide an opportunity of making representation to the person in case of overdue or past due payment; Provided further that the following exceptions may be granted by the Authority for the purpose of this sub-clause in case where: - (i) Amount overdue is under litigation and the same is also appearing as amount under litigation in the CIB report; and (ii) No overdue payment appearing in the overdue column in the subsequent latest CIB report. (d) Whether Lender has history of multiple loans being written-off provided to the person and no write-off is appearing in CIB report of the person. (e) Whether the person has been declared bankrupt by any court inside or outside Pakistan. (f) Whether the person has applied to be adjudicated as an insolvent and his application is pending. (g) whether the person is an un-discharged insolvent
Page 76 of 77 (iii) Professional Competence and Experience: In assessing Professional Competence and Experience of the person, the following shall be considered: (a) the directors should be individuals having management or business experience of at least five years at a senior level; Provided that this condition shall not apply in case of sponsor directors. (b) The directors shall have experience and knowledge in any related profession such as finance, banking, accounting, law, or information technology etc. (c) The Managing Director shall possess, at a minimum, a Master’s degree in business, Finance, digital finance, Information Technology, Economics, Accounting, or any other related discipline, or shall be a member of a recognized professional body such as the CFA Institute, the ICAP, the Institute of Chartered Accountants in England and Wales (ICAEW), the Association of Chartered Certified Accountants (ACCA), the Certified Public Accountants (CPA), the Global Association of Risk Professional or any other recognized professional body. (d) The Managing Director shall have relevant professional experience at senior management position within the financial or information technology industry, including at least two (2) years of experience in matters relating to blockchain technology, virtual assets, virtual asset services, or related domains. (e) the managing director should have demonstrated, through his qualification and experience, the capacity to successfully undertake the cognate responsibilities of the position; and (f) where the Authority is not satisfied on sufficiency of the suitability criteria, it may conduct an interview of the managing director to assess his/her suitability for the position. (g) Executive Director of a Virtual Asset Service Provider shall possess at a minimum, a Master’s degree in Finance, Information Technology, Economics, Accounting, or any other related discipline, or shall be a member in good standing of a recognized professional body such as the CFA Institute, the ICAP, the Institute of Chartered Accountants in England and Wales (ICAEW), the Association of Chartered Certified Accountants (ACCA), the Certified Public Accountants (CPA), the Global Association of Risk Professional or any other recognized professional body. (h) Executive Director shall have professional experience at senior management position within the financial or information technology industry, including at least one (1) year of experience in matters relating to blockchain technology, virtual assets, virtual asset services, or related domains. (i) Key Individuals excluding Managing Director and Directors should possess relevant qualification and shall have relevant work experience at a senior position. (iv) Conflict of interest The directors, controller, sponsors, Managing Director, and Key Individuals of the Virtual Asset Service Provider shall provide an undertaking to the Board of Directors, to identify,
Page 77 of 77 manage, and disclose any Conflicts of Interest, and to act at all times in the best interests of both the Customers and the VASP. -sdMariam Mumtaz Joint Secretary (Regulatory Authorities)