Offshore VASP Registration: The Token Issuer's Compliance Checklist
The offshore foundation is the default vehicle for token issuance, but forming the entity is only the first step. Any token issuance that touches virtual asset service activities triggers the jurisdiction's virtual asset service provider (VASP) framework. Across leading offshore centers, that framework requires registration or licensing with the local financial regulator before the activity can lawfully begin.
This post is the token issuer's compliance checklist. It covers which activities trigger the framework, the registration versus licensing split, the registration package the corporate services firm assembles, the senior officer designations required, the AML and KYC obligations, and the ongoing reporting the entity carries after registration lands.
The Offshore VASP Framework
Most major offshore financial centers introduced dedicated virtual asset service provider legislation over the past several years, with amendments that expanded the covered activities and refined the registration and licensing thresholds. The jurisdiction's virtual asset service provider (VASP) framework is the primary statute governing virtual asset services in the jurisdiction, and it is administered by the jurisdiction's financial regulator.
The framework applies to any locally registered entity that provides one or more of the specified virtual asset services. It does not matter whether the entity is a foundation, an exempted company, an LLC, or another structure. The trigger is the activity, not the entity type. An offshore foundation that issues a token triggers the framework. An offshore exempted company that operates a trading platform triggers the framework. An offshore entity that only holds a treasury without operating any virtual asset service does not trigger the framework.
The framework has two operational tracks: registration for lower-risk activities and licensing for higher-risk activities. The entity's activities determine which track applies, and the track determines the depth of the compliance package, the ongoing reporting obligations, and the level of supervisory engagement with the regulator.
Which Activities Trigger Registration
Six categories of activity trigger the framework.
Issuance of virtual assets. The token generation event itself, the initial coin offering, the primary distribution of a new virtual asset. A foundation issuing a governance token, a utility token, or a fungible protocol asset triggers the framework at this category.
Exchange between virtual assets and fiat currency. Any entity operating the conversion between a virtual asset and government-issued currency, whether at scale as an exchange or as a discrete service such as an on-ramp or off-ramp provider.
Exchange between one or more forms of virtual assets. Trading, swapping, or converting between virtual assets. This covers automated market makers, order book exchanges, and swap services.
Transfer of virtual assets. Custody-linked transfer services where the entity moves virtual assets on behalf of a customer. This covers payment processors, remittance services, and account-based transfer services.
Custody of virtual assets. Holding virtual assets on behalf of customers. This covers wallet providers, custodial exchanges, and institutional custody services.
Participation in and provision of financial services related to virtual asset issuance. Underwriting, market making, placement services, and other financial services layered on top of virtual asset issuance.
Most token issuance foundations trigger the first category, issuance. Foundations that also custody the token treasury on behalf of the DAO or operate an on-chain revenue-sharing mechanism may trigger the fifth, custody. Understanding which categories apply is the first substantive analysis the corporate services firm and the regulatory counsel conduct.
Registration Versus Licensing
The regulator applies two operational tracks under the framework.
Registration is the lighter track and covers virtual asset service providers offering the following activities: issuance of virtual assets, transfer services that do not involve custody of customer assets, and certain limited exchange and brokering activities. The registration process is procedural and focuses on the entity's fitness to conduct the specific activity within the AML and CFT framework.
Licensing is the heavier track and covers custody providers and trading platforms. Licensing requires substantially more documentation than registration, including detailed operational manuals, cybersecurity certifications, capital adequacy demonstrations, and ongoing supervisory examinations. Licensed VASPs are subject to regulator supervisory examinations and enhanced ongoing reporting.
For a typical token issuance foundation that does not custody customer assets or operate a trading platform, registration is the applicable track. The foundation registers under the issuance of virtual assets category. The registration package is procedurally simpler than a full licensing package, though the AML and CFT obligations are equivalent.
For an offshore exempted company operating a trading platform or a custody service, licensing is the applicable track. The setup timeline and cost profile are materially higher than the registration track.
The Registration Package
The registration package that the corporate services firm assembles for a token issuance foundation covers ten substantive components.
Business plan. A detailed description of the token, the issuance mechanics, the intended distribution, the use of proceeds, the operational model, and the token holder rights.
Description of virtual asset service. The specific activity or activities the entity will conduct under the framework, cross-referenced against the six categories.
AML and CFT policies. Written policies covering customer identification and verification, transaction monitoring, sanctions screening, suspicious activity reporting, record retention, and compliance officer oversight.
KYC procedures. Written procedures covering the specific customer identification and verification steps the entity will apply. For a token issuance foundation with a public token distribution, the KYC procedures apply at token holder registration or at any custodial touchpoint.
Compliance officer designation. A named compliance officer with the qualifications the regulator specifies and with ultimate responsibility for the AML and CFT program. The compliance officer must be a natural person and typically holds the operational relationship with the regulator.
Money Laundering Reporting Officer (MLRO). A named MLRO with responsibility for suspicious activity reporting. The MLRO can be the same person as the compliance officer for smaller entities or a separately designated officer for larger ones.
Beneficial ownership disclosure. Identification of the natural persons who ultimately control the entity through the ownership or control chain. This is consistent with the jurisdiction's beneficial ownership transparency rules that the entity already maintains.
Directors' fit-and-proper information. Documentation on each director covering identification, qualifications, employment history, regulatory history, and any disciplinary or enforcement actions. The regulator reviews the fit-and-proper submissions before approving the registration.
Cybersecurity policy. A written policy covering technical safeguards, access controls, incident response, and the specific measures applicable to the virtual asset service.
Risk management framework. A written framework covering the operational, technology, financial, and compliance risks the activity introduces, and the specific mitigations the entity applies.
The corporate services firm assembles the package and files it with the regulator. The firm also handles the regulator's follow-up questions during the review.
Senior Officer Designations
Three senior officer roles require specific designation under the framework.
Compliance Officer. Ultimate responsibility for the AML and CFT program. Must be a natural person, must have appropriate qualifications, and must have direct reporting access to the board of directors or the council. The Compliance Officer is not required to be resident in the jurisdiction but must be appropriately qualified and reachable by the regulator.
Money Laundering Reporting Officer (MLRO). Ultimate responsibility for filing suspicious activity reports with the jurisdiction's financial reporting authority. This role can be filled by the same person as the Compliance Officer for smaller entities.
Deputy MLRO. A named deputy to the MLRO. This ensures suspicious activity reporting continues when the MLRO is unavailable.
Additional roles are designated depending on the specific activity. For custody activities, an operations lead responsible for wallet and cold storage management. For trading platforms, a risk management lead responsible for market abuse monitoring. For issuance activities specifically, a token issuance officer responsible for the ongoing distribution mechanics.
Each named officer's fit-and-proper information is filed with the registration package. Changes to the named officers after registration require notification to the regulator and, in some cases, prior approval.
AML and KYC Requirements
The AML and CFT framework under the jurisdiction's VASP framework is substantially aligned with the Financial Action Task Force (FATF) Recommendations for virtual asset service providers. This alignment is the norm across leading offshore centers, because access to correspondent banking and international payment rails depends on it.
Customer identification and verification. For token holders, customers, or counterparties, the VASP verifies the identity through documented evidence. The threshold, the specific data collected, and the verification methods vary by activity type. For issuance activities, the verification typically occurs at token holder registration or at any custodial touchpoint.
Transaction monitoring. The VASP monitors transactions for patterns consistent with money laundering, terrorist financing, or other financial crime. For on-chain activities, the monitoring integrates with chain-analysis providers that flag high-risk wallets, including mixers, ransomware operations, darknet markets, and sanctioned addresses.
Sanctions screening. Every customer and every counterparty is screened against the OFAC Specially Designated Nationals list, the UK Consolidated List, the EU Consolidated List, and any other sanctions lists applicable to the entity's operating profile.
Suspicious activity reporting. The MLRO files suspicious activity reports with the jurisdiction's financial reporting authority when the entity detects activity that meets the reporting threshold. The reporting is confidential. The customer does not learn of the report.
Record retention. AML and CFT records are retained for the periods the regulator specifies, typically five years from the transaction date or the customer relationship termination, aligned with FATF guidance.
Travel Rule compliance. For virtual asset transfers above the specified threshold, the VASP transmits the sender and beneficiary information to the receiving VASP consistent with the FATF Travel Rule as adopted in the jurisdiction.
Ongoing Reporting Obligations
Registered VASPs carry ongoing reporting obligations to the regulator and other local authorities.
Annual audited financial statements. The entity files annual audited financial statements with the regulator. The audit is conducted by an approved auditor. The statements are filed within the timeframe the regulator specifies after the entity's financial year end.
Annual return. The entity files an annual return with the regulator covering the activities conducted during the reporting year, the volumes, the customer profile, any AML incidents, and any changes to the senior officers or the operational model.
Suspicious activity reporting. The MLRO files reports with the jurisdiction's financial reporting authority as reportable activity is detected. There is no minimum frequency. Reports are event-triggered.
Compliance officer reporting. The Compliance Officer provides regular reports to the board or council on the AML and CFT program status, any incidents, and any material changes. The reporting cadence is set by internal policy but typically runs quarterly or at each board meeting.
Notification of material changes. Changes to the entity's operating model, the named officers, the beneficial ownership, or the AML and CFT policies require notification to the regulator. Certain changes require prior approval before implementation.
Supervisory examinations. Registered VASPs are subject to on-site and remote supervisory examinations by the regulator. Licensed VASPs are subject to enhanced examination frequency and depth. Preparing for and responding to these examinations is a substantive ongoing operational responsibility.
Cost Layers
Three cost layers apply to VASP registration and ongoing compliance.
Registration setup. The corporate services firm's setup fee for the VASP registration package runs a low-to-mid five-figure engagement covering the drafting of policies and procedures, the assembly of the registration package, the regulatory filing, and the follow-up with the regulator. Legal fees for specialized crypto regulatory counsel add a further layer where the counsel is engaged separately from the corporate services firm.
Regulatory registration fee. The registration fee paid to the regulator is a fixed statutory amount, typically a four-figure US dollar amount. The fee is paid at the time of the registration filing.
Ongoing compliance. Annual audited financial statements, the annual return filing, the ongoing compliance officer and MLRO time, and the corporate services firm's ongoing advisory time all add ongoing cost. Budget a mid-five-figure annual ongoing cost for a token issuance foundation with a standard operating profile. Trading platforms and custody providers run substantially higher on the ongoing cost profile because of the licensing requirements and the enhanced supervisory engagement.
Regulated-activity operational cost. The technical and operational cost of running the compliance program, including chain-analysis subscriptions, KYC and AML software, sanctions screening tools, and cybersecurity infrastructure, is separate from the registration and legal cost layers and depends on the specific activity profile.
A Note on Meow
Meow's agentic onboarding flow does not currently support offshore entities, and does not support VASP registration. The agent supports Delaware LLCs, C Corps, LLPs, and LPs. Offshore VASP registration runs through the traditional path: select a corporate services firm with a VASP practice, engage specialized crypto regulatory counsel where the operating model requires it, assemble the registration package, file with the regulator, and manage the ongoing compliance through the firm's retainer.
Token issuance foundations that plan to register as VASPs typically bundle the VASP registration into the same firm engagement that handles the foundation formation. The offshore foundation playbook covers the foundation formation. This post covers the VASP layer that sits on top.
Frequently Asked Questions
How does an offshore foundation register as a Virtual Asset Service Provider? The foundation engages a corporate services firm with a VASP practice, works with the firm to determine which activities under the jurisdiction's virtual asset service provider (VASP) framework apply, assembles the ten-component registration package (business plan, activity description, AML and CFT policies, KYC procedures, compliance officer and MLRO designations, beneficial ownership disclosure, directors' fit-and-proper information, cybersecurity policy, risk management framework), files the package with the jurisdiction's financial regulator, and responds to the regulator's follow-up questions during the review. Registration is the applicable track for issuance-only foundations. Licensing applies to custody providers and trading platforms.
Which activities trigger the offshore VASP framework? Six activity categories: issuance of virtual assets, exchange between virtual assets and fiat, exchange between virtual assets, transfer of virtual assets, custody of virtual assets, and participation in or provision of financial services related to virtual asset issuance. Most token issuance foundations trigger the first category. Custody or on-chain revenue-sharing mechanics can trigger additional categories.
What is the difference between VASP registration and licensing? Registration is the lighter track for issuance activities, non-custodial transfers, and limited exchange or brokering activities. Licensing is the heavier track for custody providers and trading platforms. Licensing requires more documentation, including operational manuals, cybersecurity certifications, and capital adequacy demonstrations, carries higher setup and ongoing cost, and is subject to enhanced supervisory examinations by the regulator.
Who is the Compliance Officer and does the entity need one? Yes. The Compliance Officer holds ultimate responsibility for the AML and CFT program, must be a natural person, and must have appropriate qualifications and direct board or council reporting access. The Compliance Officer is not required to be resident in the jurisdiction. The Money Laundering Reporting Officer (MLRO) role is separate but can be filled by the same person for smaller entities.
Does the VASP have to comply with the FATF Travel Rule? Yes. For virtual asset transfers above the specified threshold, the VASP transmits sender and beneficiary information to the receiving VASP consistent with the FATF Travel Rule as adopted in the jurisdiction. The specific technical implementation depends on the VASP's operating profile and the Travel Rule solution the entity adopts.
What are the ongoing reporting obligations after registration? Annual audited financial statements filed with the regulator, an annual return covering activities and any material changes, suspicious activity reporting to the jurisdiction's financial reporting authority as reportable activity is detected, compliance officer reporting to the board or council, and notification to the regulator on material changes to the operating model, the named officers, the beneficial ownership, or the AML and CFT policies. Supervisory examinations apply to all registered VASPs.
Does Meow support offshore VASP registration? No. Meow's agentic onboarding does not support offshore entities and does not support VASP registration. The registration runs through traditional corporate services firms with VASP practices and specialized crypto regulatory counsel where required.
What to Read Next
The offshore foundation primer covers the foundation structure that most token issuance VASPs use as the underlying entity. The offshore foundation playbook covers the foundation formation setup that runs before the VASP registration layer. Both are the natural upstream reads for any founder approaching VASP registration for a token issuance foundation.
For the operating-business counterpart to the foundation, The Offshore Exempted Company covers the structure most crypto exchanges, custodians, and funds use as their underlying entity.
Banking services are provided by Grasshopper Bank, N.A., Member FDIC.