Purpose
Define the FATF requirement to assess counterparty VASPs, jurisdiction risk and offshore or weakly regulated VASP exposure.
Normative
Bitkaya shall assess counterparty VASP risk before establishing or processing relevant virtual asset relationships or transfers, including jurisdiction, licensing or registration status, AML/CFT controls, sanctions exposure and ability to comply with Travel Rule expectations.
Descriptive
FATF guidance and targeted updates emphasize risks from offshore VASPs, weak licensing or registration regimes and uneven Travel Rule implementation. The assessment should be proportionate to transaction type, counterparty profile and jurisdiction risk.
Source reference: SRC-FATF-001 FATF Virtual Assets and VASP Standards.
Assurance Assertions
- Counterparty VASP due diligence criteria are defined.
- Higher-risk jurisdictions or weakly supervised VASPs are escalated.
- Counterparty decisions are documented and periodically reviewed.
Relationships
- Source: SRC-FATF-001 FATF Virtual Assets and VASP Standards
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Regulatory-change procedure: PROC-ECM-002 Assess Regulatory Change and Framework Impact
- Regulatory-change control: CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed
- Framework library: SYS-ECM-001 Compliance Framework Library
- Related VASP requirements: REQ-VASP-001 through REQ-VASP-015, where applicable
- Detailed AML/CFT/CPF manual objects: pending
Assurance
- Source verified: yes
- Implementation linked: parent-framework only
- Wording unambiguous: review
- Detailed operating procedure linked: pending future detailed manuals where applicable
History
- 2026-07-25: Created from consolidated FATF VA/VASP source object.