2025-12-08
Added · Updated
The Pakistan Virtual Asset Regulation Authority establishes requirements for Virtual Asset Service Providers to obtain a No Objection Certificate, which serves as approval for AML registration on the goAML portal and permission to incorporate a local entity. Applicants must maintain specific governance structures, including designated Key Individuals who satisfy fit and proper standards, and disclose all controllers holding 20% or more voting power. The regulations mandate the implementation of comprehensive AML/CFT frameworks, including customer due diligence, transaction monitoring, and recordkeeping for a minimum of seven years. Successful applicants are authorized to provide limited AML-registered services prior to full licensing, provided they submit a full license application within three months of the promulgation of VASP licensing regulations.
i 1000021938.2 NO OBJECTION CERTIFICATE REGULATIONS 2025 Document Code: PVARA/REG/AML-REG/2025-1 Version: 1.0 (Final) Status: For Official Publication Effective Date: 2nd December 2025 Prepared By: Pakistan Virtual Asset Regulation Authority Licensing & Supervision Division
1000021938.2 TABLE OF CONTENTS Page PART 1 — PRELIMINARY ......................................................................................................1 PART 2 — GOVERNANCE & KEY INDIVIDUALS..................................................................2 PART 3 — OWNERSHIP & CONTROLLERS .........................................................................3 PART 4 — AML/CFT OBLIGATIONS......................................................................................3 PART 5 — APPLICATION PROCESS ....................................................................................6 PART 6 — ONGOING OBLIGATIONS....................................................................................7 ANNEX A – STATUTORY FORMS .........................................................................................9 FORM A1 — APPLICATION FOR AML REGISTRATION.....................................................10 FORM A2 - CONTROLLER & BENEFICIAL OWNER DISCLOSURE FORM.......................21 FORM A3 - FIT & PROPER QUESTIONNAIRE (KEY INDIVIDUALS)..................................28 FORM A4 — AML/CFT FRAMEWORK SUBMISSION STATEMENT...................................36 FORM A5 — OUTSOURCING DECLARATION & REGISTER.............................................41 FORM A6 — ANNUAL AML/CFT RETURN ..........................................................................43 FORM A7 — INTERNAL SUSPICIOUS ACTIVITY REPORT (ISAR) ...................................48 FORM A8 — KEY INDIVIDUAL APPOINTMENT / CHANGE FORM....................................50
1 1000021938.2 PART 1 — PRELIMINARY
1000021938.2 (c) ensure VASPs maintain systems to prevent, detect and report ML/TF; (d) ensure adoption of a risk-based and proportionate AML/CFT control frameworks; (e) ensure integration of all VASPs with the Financial Monitoring Unit (“FMU” and the goAML system) once registered and in receipt of the NOC; (f) prevent unregistered and non-compliant VASPs from operating in Pakistan; and (g) to facilitate a phased regulatory pathway whereby AML-Registered Services may be provided once registration has been completed and the NOC has been issued, and prior to full licensing under the Ordinance. PART 2 — GOVERNANCE & KEY INDIVIDUALS 4. Governance Requirements 4.1 An Applicant must maintain adequate governance, internal control and compliance arrangements proportionate the nature, scale and complexity of its operations. 4.2 The governing body (“Applicant Board”) shall ensure oversight of AML/CFT compliance, including: (a) approval of AML/CFT policies and procedures; (b) review of enterprise-wide ML/TF risk assessments; (c) monitoring of compliance resourcing and systems; and (d) oversight of STR/CTR trends and findings of independent audits. 5. Key Individuals 5.1 The Applicant must maintain the following Key Individuals: (a) Chief Executive Officer; (b) Director (executive or non-executive) (c) Chief Financial Officer; (d) Compliance Officer; (e) Money Laundering Reporting Officer (“MLRO”); (f) Head of Internal Audit; (g) Head of Risk Management; and (h) Head of Information Security. 5.2 The functions of Compliance Officer and MLRO may be combined where justified by the size and complexity of the applicant.
1000021938.2 6. Fit and Proper Requirements 6.1 All Key Individuals must satisfy Fit and Proper standards of integrity, competence, financial soundness and experience, as prescribed by section 16 of the Act. 6.2 The Authority may conduct interviews with Key Individuals to satisfy itself of their competence, independence, knowledge and suitability for the role. 6.3 No individual may serve as a Key Individual if he or she: (a) has been convicted of an offence under the Anti-Money Laundering Act, 2010 (“AMLA 2010”), the Act, or any law involving dishonesty, fraud or financial misconduct; (b) has been sanctioned by any regulatory body in Pakistan or abroad; and / or (c) is subject to bankruptcy or insolvency proceedings, except where duly discharged. 6.4 Each Key Individual shall submit a Fit and Proper Declaration in the form prescribed in Annex A (Form A3). PART 3 — OWNERSHIP & CONTROLLERS 7. Controllers 7.1 Any person holding, directly or indirectly, 20% or more of voting power or share capital of the Applicant is deemed a “Controller”. 7.2 Applicants must disclose all Controllers including Beneficial Owners (as defined in the AMLA 2010) and submit Form A2. 7.3 The Authority must approve each Controller before AML registration may be granted. Once registered, no Controller may acquire or increase control above thresholds to be determined by PVARA without written approval from the Authority. PART 4 — AML/CFT OBLIGATIONS 8. AML/CFT Framework 8.1 Each Applicant must maintain an AML/CFT framework that is proportionate to its business activities and operational complexity. 8.2 The framework shall, at a minimum, include: (a) an AML/CFT Policy approved by the Applicant Board; (b) documented CDD and EDD procedures; (c) Targeted Financial Sanctions (“TFS”) screening procedures; (d) Transaction monitoring processes; (e) Suspicious Transaction Reports (“STR”) and Currency Transaction Reports (“CTR”) escalation procedures;
1000021938.2 (f) a documented enterprise-wide money laundering and terrorist financing (“ML/TF”) risk assessment; (g) recordkeeping and data governance policy; (h) an AML/CFT training programme; and (i) an outsourcing risk management framework 8A. Documentation Standards 8A.1 All documents submitted to the Authority must: (a) be written in English or Urdu; (b) include version control; (c) be paginated and indexed; (d) be submitted in a searchable electronic format; and (e) include written evidence of Board approval where required. 9. Customer Due Diligence (“CDD”) 9.1 Each Applicants shall implement CDD procedures that comply fully with AMLA 2010 and all applicable rules issued under it. 9.2 CDD procedures shall include: (a) identification and verification of all customers; (b) verification of all Controllers; (c) assessment of the nature and purpose of the business relationship; (d) understanding and, where appropriate, verification of sources of funds and wealth; and (e) ongoing monitoring and periodic updating of customer profiles. 9.3 CDD must be completed before the Applicant provides any AML Registered Service. 10. Enhanced Due Diligence (“EDD”) 10.1 Applicants shall conduct EDD where higher ML/TF risks are identified, including for: (a) customers from high-risk jurisdictions; (b) Politically Exposed Persons (“PEPs”); (c) unusually large, complex or opaque transactions; and (d) customers flagged through adverse media or other high-risk indicators.
1000021938.2 11. Monitoring, STRs, CTRs, goAML 11.1 Each Applicant shall maintain monitoring systems capable of detecting suspicious or unusual activity in real time or near real time. 11.2 Applicants shall file STRs in accordance with AMLA 2010. 11.3 Applicants shall file CTRs for all fiat-based transactions that meet or exceed the applicable threshold. 11.4 Following issuance of NOC by the Authority, the foreign Applicant (the applicants whose foreign chapter is already providing VASP services in Pakistan) shall register on the FMU goAML platform as the reporting entity for AML-Registered Services, unless otherwise directed by FMU or the Federal Government. 11.5 Once the Applicant incorporates its local entity in Pakistan, the local entity after being granted the license shall assume the role of reporting entity on go-AML and must maintain active reporting credentials at all times. 11.6 The Applicant shall demonstrate technical readiness to file STRs and CTRs immediately upon goAML registration. . 12. Targeted Financial Sanctions 12.1 Applicants shall implement controls to screen all customers, beneficial owners, counterparties and transactions against domestic and United Nations sanctions lists. 12.2 Applicants must immediately freeze assets of designated persons and report such freezes to FMU and any other designated authority in accordance with Pakistan’s TFS framework. 13. Recordkeeping 13.1 All AML/CFT records shall be maintained for a minimum of seven (7) years. 13.2 Records shall be stored securely and must be auditable, retrievable and tamperevident. 14. Outsourcing 14.1 Applicants may not outsource AML-critical functions, meaning those that go to the core of the Applicant’s AML/CFT duties such as CDD, EDD, sanctions/TFS screening, transaction monitoring, STR/CTR reporting and MLRO responsibilities, unless the Applicant: (a) conducts due diligence on the service provider; (b) maintains effective oversight arrangements; (c) retains audit and inspection rights; and (d) ensures the legal enforceability of audit and supervisory rights, including cross-border arrangements.
1000021938.2 14.2 Outsourcing arrangements must not impair the Applicant’s ability to meet AMLA or PVARA obligations. PART 5 — APPLICATION PROCESS 15. Submission 15.1 Applications for an NOC shall be submitted using Form A1, as prescribed in Annex A, together with all required documentation. 15.2 The Authority may specify electronic submission requirements from time to time. 15.3 Upon issuance of the NOC, the successful Applicant shall: (a) Register the foreign entity already providing AML Registered Services in Pakistan on the goAML portal; (b) Incorporate a local company as required under Section 15(1) of the Ordinance; and (c) Submit the licensing application, in the form prescribed by the Authority, within three months of the issuance of the VASP licensing regulations. 15.4 The Authority’s grant of the NOC shall satisfy the pre-incorporation regulatory clearance required under Section 15 of the Act and shall permit the Applicant to provide AML-Registered Services in accordance with these Regulations. 16. Assessment 16.1 The documentation submitted by the Applicant to the Authority on the fitness and propriety shall be assessed as part of the NOC process and the same along with the below mentioned matters may be evaluated/re-evaluated during the subsequent licensing application stage: (a) fitness and propriety of Key Individuals and Controllers; (b) adequacy and operational readiness of the AML/CFT Framework for AMLRegistered Services; (c) governance and internal control arrangements; (d) financial soundness of the Applicant; (e) adequacy of technology architecture and monitoring systems; and (f) the Applicant’s inherent and residual ML/TF risk profile. 16.2 The Authority may conduct interviews with Key Individuals to verify competence and suitability. 16.3 The Authority may conduct inspections or request additional information to support its assessment. 17. Decision
1000021938.2 17.1 Following assessment, the Authority shall (within a period not exceeding 60 calendar days): (a) issue the NOC to (i). the applicant to register the foreign chapter, already providing AMLRegistered Services in Pakistan, in accordance with the No Objection Certificate Regulations on the goAML portal; (ii). incorporate a local entity in Pakistan for the purpose of applying for a full VASP Licence under Section 17 of the Ordinance; (iii). to provide “AML-Registered Services” (limited to Exchange, Broker-Dealer, Custody and Derivative Services) upon completion of goAML registration, in advance of obtaining a full VASP Licence; and (iv). submit licensing application within three months of promulgation of VASP licensing regulations; or (b) refuse NOC. 17.2 Where an application is refused, the Authority shall provide written reasons for its decision. 17.3 The conditions referenced here include goAML registration, incorporation and the commitment to apply for a full license under the Ordinance. PART 6 — ONGOING OBLIGATIONS 18. Ongoing Obligations 18.1 A registered Applicant shall: (a) comply with all AML/CFT obligations at all times; (b) notify the Authority of any material changes affecting AML compliance, governance, ownership or technology; (c) submit an Annual AML/CFT Return in the prescribed form (Form A6); (d) undergo independent AML audits when directed by the Authority; (e) maintain active FMU goAML registration; and (f) apply for and progress diligently toward a full VASP License within the time period required by the Authority. 19. Revocation 19.1 The Authority may revoke an Applicant's NOC, including AML Registration status, where: (a) the Applicant has provided false, misleading or incomplete information; (b) the Applicant has breached AML/CFT obligations;
1000021938.2 (c) any Key Individual ceases to satisfy Fit and Proper requirements; (d) systemic or material AML/CFT failures occur; and/or (e) failure to apply for or progress toward obtaining a full VASP License within the prescribed period. 19.2 Revocation shall be applied proportionately, taking into account the severity and impact of the breach.
1000021938.2 ANNEX A – STATUTORY FORMS
1000021938.2 FORM A1 — APPLICATION FOR No Objection Certificate (Issued under Regulation 15.1 of the No Objection Certificate Registration Regulations 2025) This Form must be completed by any entity (“Applicant”) seeking No Objection Certificate from PVARA. Please answer all questions fully and attach supporting documents where indicated. Incomplete applications may be delayed or returned. SECTION 1 — APPLICANT DETAILS All information in this section should be completed with respect to the global entity that is to be registered on the goAML portal. Section Question Applicant Response 1.1 Legal Name of Applicant (as per Incorporation Certificate): 1.2 Registered Company Number (): 1.3 Date of Incorporation (DD/MM/YYYY): 1.4 Country of Incorporation: 1.5 Registered Office Address: 1.6 Principal Place of Business (if different from registered office): 1.7 Website (if any): 1.8 Contact Person for this Application • Full Name: • Position/Title: • Email Address: • Direct Phone Number: 1.9 Group Membership (if applicable) Is the Applicant part of a group of companies? □ Yes □ No If Yes, provide: • Name of Parent Entity: • Country of Parent’s Incorporation:
1000021938.2 • Brief description of group structure and main business activities: Attach a Group Structure Chart showing all entities and jurisdictions. SECTION 2 — LICENSING ACTIVITY SOUGHT & BUSINESS MODEL Section Question Applicant Response 2.1 List all Virtual Asset Services for which AML Registration is sought: • Broker-Dealer Services • Custody Services • Exchange Services • Virtual Asset Derivatives Services 2.2 Primary Licence Type (if applicable): (If Exchange Services will be the primary license, indicate here.) 2.3 Planned Launch Date of Operations (DD/MM/YYYY): 2.5 Business Model Description Provide a detailed narrative describing the Applicant’s proposed business model in Pakistan, including at a minimum: • Types of customers (retail, institutional, professional, foreign vs domestic) together with reasonable estimates of the number of clients in each category being offered on the date of NOC application • Products and services to be offered • Whether the Applicant will operate a centralised exchange, brokerage, OTC desk, custodian, wallet service, issuer platform, etc. • Fiat on-ramp and off-ramp arrangements (banks, EMI, payment providers) • Stablecoin usage and handling (if applicable) • Use of custodians, banks and payment processors (onshore and offshore) • Any cross-border elements (foreign customers, foreign booking centres, foreign affiliates)
1000021938.2 Attach additional pages if required. SECTION 3 — GOVERNANCE & KEY INDIVIDUALS 3.1 Directors Provide a list of all Directors (executive and non-executive), including: Full Name Role (Executive/ NonExecutive/ Independent) Nationality Date of Appointment CV attached for each director □ □ □ □ □ □ Please also attach current Board composition chart. 3.2 Key Individuals Details of Key Individuals must be provided for both the global entity being registered on the goAML portal and the proposed local entity in Pakistan. Key Individual Role Full Name Nationality Date of Appointment Email and Phone Number Chief Executive Officer (CEO)
1000021938.2 Key Individual Role Full Name Nationality Date of Appointment Email and Phone Number Chief Financial Officer (CFO) Compliance Officer Money Laundering Reporting Officer (MLRO) Head of Internal Audit Head of Risk Management Head of Information Security Attach for each Key Individual: • Completed Form A3 — Fit & Proper Questionnaire • Up-to-date CV • Copy of Passport 3.3 Additional Senior Management Roles (if any) List any other senior roles (e.g., Chief Operating Officer, Head of Operations, Head of Compliance for Technology) and provide brief descriptions of their responsibilities. SECTION 4 — CONTROLLERS, OWNERSHIP & BENEFICIAL OWNERSHIP 4.1 Controllers (20% or more voting power or share capital) List all Controllers of the Applicant: Full Name Nature of entity (individual / company / trust) Country of Residency / Incorporation Percentage of Ownership (%) Percentage of Voting Power (%)
1000021938.2 4.2 Beneficial Owners The information requested in this section must be provided for both the global entity being registered on the goAML portal and the proposed local entity to be incorporated in Pakistan. List all Beneficial Owners of the Applicant in accordance with AMLA definitions: Full Name Nationality Basis of beneficial ownership (equity, control rights, other) Percentage of ultimate ownership or control 4.3 Ownership and Control Structure Attach a complete Ownership and Control Structure Chart, which must show: • All shareholding layers; • All intermediate entities and jurisdictions; and • The ultimate natural person(s) who own or control the Applicant 4.4 Controller / UBO Forms Attach a completed Form A2 — Controller & Beneficial Owner Disclosure Form for each Controller and each Beneficial Owner. SECTION 5 — AML/CFT FRAMEWORK DOCUMENTATION Confirm that the following documents, as applicable to the Applicant’s business, are submitted with this application: Document Attached Comments Board-approved AML/CFT Policy □
1000021938.2 Document Attached Comments Customer Due Diligence (CDD) Procedures □ Enhanced Due Diligence (EDD) Procedures □ PEP management procedures □ Sanctions / Targeted Financial Sanctions (TFS) Policy and Procedures □ Transaction Monitoring Policy and Procedures □ Blockchain Analytics Methodology and Use Case Description □ STR/CTR Internal Escalation and External Reporting Procedures □ Enterprise-wide ML/TF Risk Assessment □ Recordkeeping and Data Governance Policy (including 7-year retention) □ AML/CFT Training Policy and Annual Training Plan □ Outsourcing Policy and Outsourcing Register □ Business Continuity and Disaster Recovery (BCP/DR) arrangements relevant to AML □ Form A4 — AML/CFT Framework Submission Statement, signed by the CEO and MLRO. □ SECTION 6 — TECHNOLOGY & SYSTEMS 6.1 Overview of Technology Architecture Provide a high-level description of the Applicant’s technology environment, covering: • Core systems used to support onboarding, trading, custody, transfers and recordkeeping • Location of primary and backup data centres
1000021938.2 • Any use of cloud services (with jurisdictional details) 6.2 AML-Relevant Systems Describe, and where appropriate list, all systems used for: • Blockchain analytics • Identity verification (KYC tools, e-KYC solutions) • Sanctions and TFS screening • Transaction monitoring and case management • Data storage, backup and archival • Information security and cyber defence 6.3 System Readiness Confirm whether these systems are currently implemented and operational: • Fully operational • In testing phase • Under implementation (provide expected completion date)
1000021938.2 SECTION 7 — FMU COMPLIANCE (goAML) 7.1 Internal STR/CTR Workflow Briefly describe how internal suspicious activity will be escalated and submitted as STRs/CTRs via goAML once the Applicant has registered (or cross-reference the relevant section of the attached STR/CTR procedures). SECTION 8 — FINANCIAL RESOURCES AND CAPITAL POSITION 8.1 Financial Statements Attach: • The Applicant’s latest audited financial statements (if available) • Management accounts or pro forma financials if the Applicant is newly incorporated 8.2 Minimum Capital Requirement Provide details of how the Applicant meets any applicable minimum capital requirement, including: • Amount of paid-up capital • Evidence of capital (bank statements, subscription agreements, etc.) 8.3 External Auditor Details
1000021938.2 Information Required Applicant response Name of Audit Firm: Address: Contact Person: Email / Phone: 8.4 Sources of Initial Funding Provide a brief description of how the Applicant’s initial capital and funding were sourced, with reference to Controllers and UBOs where applicable. SECTION 9 — OTHER REGULATORY LICENCES 9.1 Existing Licences in Pakistan Does the Applicant (or its group entities) hold any licence from SBP, SECP or any other Pakistani authority? □ Yes □ No If Yes, provide the below details: License number Regulator Nature of License Date of issuance 9.2 Foreign Licences and Registrations Does the Applicant (or its group entities) hold any regulatory licence or registration outside Pakistan (e.g. VASP, EMI, securities broker, bank, MSB)? □ Yes □ No If Yes, provide details and attach supporting documents.
1000021938.2 SECTION 10 — DECLARATION BY THE APPLICANT This declaration must be signed by two authorised signatories of the Applicant, typically the CEO and another Key Individual (e.g., CFO, Compliance Officer or MLRO). Declaration I/We, the undersigned, hereby declare that:
1000021938.2 Signature: ___________________________ Date: _______________________________ Authorised Signatory 2 Name: ______________________________ Position/Title: ________________________ Signature: ___________________________ Date: _______________________________
1000021938.2 FORM A2 - CONTROLLER & BENEFICIAL OWNER DISCLOSURE FORM (Issued under Regulation 7 of the No Objection Certificate Regulations 2025) This Form must be completed by every Controller (holding 20% or more direct or indirect control) and every Beneficial Owner of the Applicant and the proposed local entity. All information must be true, complete and supported by documentary evidence. Failure to submit a complete and accurate Form may result in rejection of the application, suspension of assessment or regulatory action. SECTION 1 — PERSONAL IDENTIFICATION DETAILS Please provide the following information exactly as it appears on official identification documents. Section Question Applicant Response
1000021938.2 Section Question Applicant Response 18. Are you a Politically Exposed Person (PEP)? □ Yes □ No If Yes, provide details of the public office held, country, dates and close associates. Required Attachments: • Certified CNIC/Passport copy • Proof of residential address (utility bill, bank statement, tenancy agreement) • Tax residency documentation (if applicable) SECTION 2 — OWNERSHIP, CONTROL & BENEFICIAL INTERESTS 2.1 Nature of Control Indicate all applicable forms of control exercised over the Applicant. • Direct shareholding • Indirect shareholding • Voting rights • Board control or influence • Senior management influence • Control via shareholders’ agreement • Control via financing arrangements • Control via trust or nominee structures • Other (explain): _______________________________ Provide a detailed narrative explaining how control is exercised, including any agreements, arrangements or relationships relevant to influence or control. 2.2 Shareholding / Voting Power Ownership □ Direct Ownership □ Indirect Ownership
1000021938.2 Percentage of ownership If indirect ownership exists, attach a complete Ownership and Control Chart, showing each intermediary entity, ownership percentage at each layer, and jurisdiction. 2.3 Beneficial Ownership Status
1000021938.2 Section Question Applicant Response 3. Professional roles held within the last 10 years, including directorships 4. Summary of relevant qualifications and experience 5. List any regulated entities you have owned, controlled or served as a director/officer of. Attach: • Detailed CV • Copies of degrees/certifications 3.2 Regulatory, Supervisory & Compliance Record Indicate whether you have ever been: Section Question Applicant Response If yes to any item, provide complete details, dates, outcomes and attach supporting documents
1000021938.2 Section Question Applicant Response Comments
1000021938.2 SECTION 4 — SOURCE OF FUNDS AND SOURCE OF WEALTH 4.1 Source of Wealth (SoW) Provide a full narrative explaining how your wealth was accumulated, including: • Employment income history • Business ownership or profits • Investments (equities, real estate, private companies) • Inheritances or gifts • Dividends, bonuses or asset disposals Attach supporting documents wherever available. 4.2 Source of Funds for Investment (SoF) Explain the specific origin of funds used to acquire ownership or control in the Applicant. Provide documentary evidence, such as: • Bank statements • Sale agreements • Dividend or bonus records • Tax filings • Asset disposal documents • Investment portfolio statements • Trust deeds or beneficiary documents If funds originate offshore, provide full details of jurisdiction, bank, and transfer pathway. SECTION 5 — SANCTIONS AND POLITICAL EXPOSURE CHECKS
1000021938.2
1000021938.2 FORM A3 - FIT & PROPER QUESTIONNAIRE (KEY INDIVIDUALS) (Issued Under Regulation 6.4 of the No Objection Certificate Regulations 2025) This Form must be completed by every Key Individual of the Applicant, including the Chief Executive Officer, Chief Financial Officer, Compliance Officer, MLRO, Head of Internal Audit, Head of Risk Management, Head of Information Security, and any other individual performing a senior management function of the applicant and the proposed local entity. All information must be true, complete and accurate. False or misleading declarations may result in refusal of AML Registration, removal of a Key Individual, or further regulatory action. SECTION 1 — PERSONAL INFORMATION Section Question Applicant Response
1000021938.2 Required Attachments: • Certified CNIC/Passport copy • Proof of residential address SECTION 2 — EMPLOYMENT HISTORY (LAST 10 YEARS) For each role held in the last ten years, provide (please add more tables as needed): Section Question Applicant Response
1000021938.2 (e.g., CAMS, ICA, CFA, CPA, CISA, cybersecurity or risk-related certifications) Attach supporting certificates. 3.3 AML/CFT Training Provide details of AML/CFT training completed in the last three years (if any): • Training provider • Course name • Key topics covered • Dates attended 3.4 Special Skills Describe any specialised skills relevant to your Key Individual role (risk, blockchain, cybersecurity, governance, legal, audit, etc.). SECTION 4 — REGULATORY & SUPERVISORY RECORD Indicate whether you have ever been:
1000021938.2
1000021938.2 2. Entered into a debt restructuring or insolvency arrangement: □ Yes □ No 3. Been subject to a civil judgment for debt or damages: □ Yes □ No 4. Failed to meet financial obligations or defaulted on a loan: □ Yes □ No 5. Been subject to tax enforcement or penalties: □ Yes □ No 6. Been prohibited from acting as a director or officer due to financial misconduct: □ Yes □ No If Yes to any, provide full details, including amounts, dates, circumstances and supporting documents. SECTION 7 — CONFLICTS OF INTEREST Disclose any potential or actual conflicts, including:
1000021938.2 2. Breached fiduciary duties in any role: □ Yes □ No 3. Been found negligent, dishonest or unethical by any court or tribunal: □ Yes □ No 4. Been subject to internal disciplinary actions of a serious nature: □ Yes □ No 5. Been involved in activities likely to bring disrepute to a regulated entity: □ Yes □ No If Yes to any, provide full explanations and attach evidence. SECTION 9 — HEALTH, FITNESS & CAPACITY
1000021938.2 Relationship to You: Email Address: Reference 2 Full Name: Organisation: Position/Title: Relationship to You: Email Address: Phone Number: References must not be from relatives, subordinates or individuals with conflicts of interest. SECTION 11 — OTHER ROLES AND TIME COMMITMENTS
1000021938.2 I agree that PVARA may verify the information provided, conduct background checks, and obtain information from domestic and foreign regulators, law enforcement authorities and financial institutions. Signature: ______________________________ Full Name: _____________________________ Date: __________________________________
1000021938.2 FORM A4 — AML/CFT FRAMEWORK SUBMISSION STATEMENT (Issued under Regulation 8 of the No Objection Certificate Registration Regulations 2025) This Statement must be completed and signed by the Chief Executive Officer (CEO) and the Money Laundering Reporting Officer (MLRO) of the Applicant. By submitting this Form, the Applicant certifies that its AML/CFT Framework is complete, accurate, tailored to its business model, fully operational, and compliant with all applicable legal and regulatory requirements. Failure to provide accurate or complete information may result in refusal of AML Registration or regulatory action. SECTION 1 — CONFIRMATION OF DOCUMENTATION SUBMISSION The Applicant confirms that it has submitted final, Board-approved versions of the following documents as part of its AML Registration Application: Document Attached Comments AML/CFT Policy — including governance structure, roles, responsibilities and escalation lines. □ Customer Due Diligence (CDD) Procedures — covering identification, verification, onboarding, non-face-toface controls and ongoing monitoring. □ Enhanced Due Diligence (EDD) Procedures — including high-risk customer handling, PEPs, adverse media, high-risk jurisdictions and complex structures. □ Transaction Monitoring Framework — covering alert scenarios, thresholds, case management, escalation processes and behavioural/VA-specific typologies. □ Sanctions / Targeted Financial Sanctions (TFS) Policy — including wallet-address screening, name screening, freeze and reporting procedures. □ STR/CTR Reporting Procedures — covering internal reporting (ISAR), MLRO escalation and external reporting to FMU via goAML. □ Recordkeeping and Data Governance Policy — including retention □
1000021938.2 Document Attached Comments requirements (minimum 7 years), storage, retrieval and audit trail controls. Enterprise-Wide ML/TF Risk Assessment — covering inherent risks, residual risks, mitigating controls and alignment with Pakistan’s National Risk Assessment. □ AML/CFT Training Programme — including annual training, role-specific training and induction training. □ Outsourcing Policy and Outsourcing Register — identifying all outsourced AML-relevant functions and oversight mechanisms. □ Business Continuity & Disaster Recovery (BCP/DR) Arrangements relating to AML systems and reporting processes. □ Where relevant, supporting data, system screenshots, workflow diagrams, risk methodologies or technical descriptions have also been provided. SECTION 2 — COMPLIANCE WITH APPLICABLE LAWS AND STANDARDS The Applicant confirms that its AML/CFT Framework is fully compliant with the following instruments:
1000021938.2 4. The Board accepts responsibility and accountability for the Applicant’s ongoing AML/CFT compliance. SECTION 4 — OPERATIONAL READINESS OF AML/CFT SYSTEMS The Applicant confirms that all systems necessary for AML compliance are:
1000021938.2 Date: ___________________________________
1000021938.2
1000021938.2 FORM A5 — OUTSOURCING DECLARATION & REGISTER (Issued under Regulation 14 of the No Obejction Certificate Regulations 2025) This Form must be completed by the Compliance Officer of the Applicant. It must disclose all outsourcing arrangements that relate to AML/CFT obligations. SECTION A — APPLICANT DECLARATION The Applicant confirms that:
1000021938.2 11. Monitoring Frequency □ Monthly □ Quarterly □ Annually Repeat this table for each outsourced function. SECTION C — COMPLIANCE OFFICER SIGNATURE I, the undersigned Compliance Officer, declare that: • the information provided in this Form is true, complete and accurate; • all AML-relevant outsourcing arrangements have been disclosed; • all outsourcing complies with the No Objection Certificate Regulations; • the Applicant remains fully accountable for AML/CFT compliance. Name: ____________________________________ Signature: __________________________________ Date: _______________________________________
1000021938.2 FORM A6 — ANNUAL AML/CFT RETURN (Issued under Regulation 18 of the No Objection Certificate Registration Regulations 2025) This Return must be completed once every calendar year by applicants who have been granted NOC and submitted within the deadline specified by PVARA. All information must reflect the full reporting period and must be accurate and complete. SECTION 1 — ENTITY PROFILE Section Information Licensee Response 1.1 Legal Name of Licensee 1.2 PVARA Registration Number 1.3 Reporting Period (From — To) 1.4 Key Individuals in Post During Reporting Period (CEO, CFO, Compliance Officer, MLRO, Head of Risk, Head of Internal Audit, Head of Information Security) Attach updated organisation chart if any changes occurred. SECTION 2 — GOVERNANCE 2.1 MLRO Annual Statement Provide a brief statement summarising overall AML/CFT compliance status for the year, including key improvements or concerns. 2.2 Changes in Governance Summarise any changes in: • Key Individuals, • Board composition, • Governance committees, • Reporting lines or compliance structure.
1000021938.2 2.3 Changes in Outsourcing Arrangements List any AML-relevant outsourcing additions, removals or modifications during the period. SECTION 3 — RISK ASSESSMENT UPDATE 3.1 New ML/TF Risks Identified During the Year: 3.2 Material Changes to Inherent or Residual Risk Ratings: 3.3 Emerging Risk Trends Observed:
1000021938.2 (e.g., typologies, customer behaviours, cross-border trends) Attach updated ML/TF Risk Assessment if applicable. SECTION 4 — CUSTOMER DUE DILIGENCE (CDD) METRICS Provide totals for the reporting period: Section Totals Licensee Response 4.1 Total Customers Onboarded 4.2 Total Customers Classified as HighRisk 4.3 Total Politically Exposed Persons (PEPs) 4.4 Customers Refused During Onboarding (CDD/EDD failure) 4.5 Customers Exited Due to AML/CFT Concerns SECTION 5 — TRANSACTION MONITORING METRICS Section Totals Licensee Response 5.1 Total Monitoring Alerts Generated 5.2 Alerts Escalated to Compliance/MLRO 5.3 Alerts Closed After Review 5.4 Alerts Remaining Pending at YearEnd
1000021938.2 4.5 Customers Exited Due to AML/CFT Concerns If available, attach summary statistics from monitoring systems. SECTION 6 — STR/CTR REPORTING Section Information Required Licensee Response 6.1 Number of STRs Filed via goAML 6.2 Broad Categories of Suspicion Reported (e.g., fraud, sanctions, high-risk jurisdiction links, structuring, unusual VA transfers) 6.3 Number of CTRs Filed (if fiat exposure exists) Attach list of internal ISARs (Internal Suspicious Activity Reports) if requested by PVARA. SECTION 7 — INDEPENDENT AUDIT & REMEDIATION 7.1 Summary of Independent AML Audit Findings: 7.2 Status of Audit Remediation: • Fully Implemented • Partially Implemented • In Progress • Not Yet Started (explain)
1000021938.2 7.3 Any Material Audit Gaps Still Outstanding: Provide brief explanation or attach remediation plan. SECTION 8 — DECLARATION By signing below, the MLRO and CEO confirm that:
1000021938.2 FORM A7 — INTERNAL SUSPICIOUS ACTIVITY REPORT (ISAR) VASPs are welcome to use their own ISAR, but they should include the below information at a minimum: SECTION 1 — REPORTER DETAILS Section Information Licensee Response 1.1 Name 1.2 Position 1.3 Date of Report SECTION 2 — CUSTOMER DETAILS Section Information Licensee Response 2.1 Customer name / ID 2.2 Wallet addresses 2.3 Account numbers SECTION 3 — TRANSACTION DETAILS Section Information Licensee Response 3.1 Date(s): 3.2 Amount(s): 3.3 Type of transaction: 3.4 On-chain / offchain details SECTION 4 — SUSPICION NARRATIVE Please describe the relevant facts, observed behaviour, identified indicators, and any applicable red flags.
1000021938.2 SECTION 5 — MLRO DETERMINATION Determination Action File STR □ Do not file □ Additional information required □ MLRO Signature: __________________________ Name : _______________________________________________ Date: ________________________________________________
1000021938.2 FORM A8 — KEY INDIVIDUAL APPOINTMENT / CHANGE FORM This Form must be submitted whenever an Applicant appoints a new Key Individual or makes a change affecting an existing Key Individual, in accordance with the No Objection Certificate Regulations. A separate Form A8 must be completed for each individual. SECTION 1 — LICENSEE DETAILS Section Information Licensee Response 1.1 Legal Name of Licensee 1.2 PVARA Registration Number SECTION 2 — DETAILS OF THE APPOINTMENT OR CHANGE 2.1 Role Being Appointed or Changed: (e.g., CEO, CFO, Compliance Officer, MLRO, Head of Risk, Head of Internal Audit, Head of Information Security) 2.2 Type of Change: Type of Change Action New Appointment □ Replacement □ Role Modification □ Resignation / Removal □ 2.3 Effective Date of Appointment / Change (DD/MM/YYYY): 2.4 Information on new appointee: Information Response Legal Name
1000021938.2 Contact details (email and phone number) SECTION 3 — REQUIRED DOCUMENTATION The following documents must be attached: Document Attached Comments Fit & Proper Questionnaire (Form A3) □ Curriculum Vitae (updated and signed) □ Copy of CNIC/Passport □ Board Approval Resolution confirming the appointment/change □ Police Clearance Certificate (if new appointment) □ Employment Contract / Offer Letter (if applicable) □ PVARA may request additional documents as part of its fitness and propriety assessment. SECTION 4 — DECLARATION BY APPLICANT By signing below, the Applicant certifies that:
1000021938.2 SECTION 5 — ACKNOWLEDGMENT BY THE KEY INDIVIDUAL I confirm that: