A virtual asset service provider applying for a no objection certificate cannot treat anti-money laundering compliance as a function that lives entirely inside a compliance department. Under the Regulations that govern the application, the applicant’s board carries defined, named duties of its own.
This piece sets out what Regulation 4 of the PVARA No Objection Certificate Regulations 2025 actually requires of a board, what the proportionality principle means in practice, and how each of the four listed duties is meant to work.
What does PVARA require of a VASP applicant’s board on AML/CFT?
Regulation 4.2 requires the applicant’s governing body — referred to throughout the Regulations as the “Applicant Board” — to ensure oversight of AML/CFT compliance across four specific areas: approving policies, reviewing risk assessments, monitoring resourcing and systems, and overseeing reporting trends and audit findings. This is a standing governance duty, not a one-off sign-off at application stage.
The requirement sits in Part 2 of the Regulations, under the heading “Governance & Key Individuals,” alongside the rules on key individuals and fit and proper standards. That placement is deliberate: PVARA treats board-level AML/CFT oversight as part of the same governance architecture as the appointment and vetting of senior individuals, not as a separate technical compliance topic.
What is the proportionality principle in Regulation 4.1?
Regulation 4.1 states that an applicant “must maintain adequate governance, internal control and compliance arrangements proportionate the nature, scale and complexity of its operations.” In practice, this means the size and formality of a board’s AML/CFT oversight arrangements should track the size and complexity of the business — not a fixed, one-size-fits-all committee structure applied identically to every applicant.
“An Applicant must maintain adequate governance, internal control and compliance arrangements proportionate the nature, scale and complexity of its operations.”
The Regulations do not define specific thresholds for what proportionate governance looks like at different scales — no minimum number of board meetings, no required committee structure, no headcount trigger. Our reading is that this is left deliberately open, to be assessed case by case as part of the Regulation 16 assessment process, rather than fixed by a formula. A narrower-scope virtual asset service provider offering a single AML-Registered Service should expect a lighter-touch expectation than a multi-service exchange group, but the Regulations do not spell out exactly where that line falls. Applicants should confirm PVARA’s expectations for their specific business model directly with the Authority rather than assume a fixed benchmark.
What are the four AML/CFT oversight duties a board must perform?
Regulation 4.2 lists four duties. Together they cover policy approval, risk review, resourcing oversight and reporting oversight — the full cycle from setting the framework to checking that it is actually working.
| Duty | Regulation 4.2 reference | What it covers |
|---|---|---|
| Policy approval | (a) | Board sign-off on AML/CFT policies and procedures |
| Risk review | (b) | Review of enterprise-wide ML/TF risk assessments |
| Resourcing and systems monitoring | (c) | Oversight of whether compliance is adequately resourced |
| Reporting and audit oversight | (d) | Review of STR/CTR trends and independent audit findings |
Each of these connects to a separate operational obligation elsewhere in the Regulations. None of the four stands alone as a paperwork exercise; each is meant to feed into how the business actually runs its compliance programme day to day.
Duty (a): what does “approval of AML/CFT policies and procedures” require?
The board must formally approve the applicant’s AML/CFT policies and procedures, not merely receive them for information. This connects directly to Regulation 8.2(a), which lists “an AML/CFT Policy approved by the Applicant Board” as the first of nine minimum components of the AML/CFT framework every applicant must maintain.
Form A4 — the AML/CFT Framework Submission Statement — requires the Chief Executive Officer and the Money Laundering Reporting Officer to jointly certify, under Section 3, that “the Board of Directors has reviewed and formally approved the AML/CFT Framework and all related documents submitted with the application,” and that “a Board resolution evidencing such approval is attached to the application.” In practice, this means an applicant cannot submit a compliance framework drafted by external advisers or a compliance officer without a documented board resolution behind it — PVARA is asking for evidence of formal governance sign-off, not just a completed policy document.
Duty (b): what does “review of enterprise-wide ML/TF risk assessments” mean?
The board must review the applicant’s documented, enterprise-wide money laundering and terrorist financing risk assessment — the same assessment required under Regulation 8.2(f) as a minimum component of the AML/CFT framework. This is not a one-time exercise completed for the application and then filed away.
Form A6, the Annual AML/CFT Return, requires a registered applicant to report annually on “new ML/TF risks identified during the year,” “material changes to inherent or residual risk ratings,” and “emerging risk trends observed.” Our reading is that Regulation 4.2(b) is the governance mechanism that makes those annual disclosures meaningful: the board is expected to actually engage with the risk assessment’s findings, not simply note that a document exists. Where risk ratings shift materially, the expectation implied by reading Regulation 4.2(b) alongside Form A6 is that the board should be aware of the change and its implications before the annual return is filed, not first learn of it from the return itself.
Duty (c): what does “monitoring of compliance resourcing and systems” cover?
The board is expected to oversee whether the applicant’s compliance function has adequate staffing, budget and technology to do its job — not simply whether a compliance officer and a money laundering reporting officer have been appointed on paper. This connects to the wider requirement in Regulation 8.1 that the AML/CFT framework be “proportionate to [the applicant’s] business activities and operational complexity,” and to Form A4 Section 4, which requires certification that AML-relevant systems — onboarding and KYC tools, sanctions screening, transaction monitoring, blockchain analytics, case management and data retention systems — are “implemented, tested and operational.”
In practice, this duty gives the board a supervisory role over resourcing decisions that might otherwise sit entirely with management: if a compliance officer is under-resourced, understaffed, or working with systems that are still “under implementation” rather than operational, Regulation 4.2(c) puts that gap in front of the board as a governance issue, not just an operational one.
Duty (d): what does “oversight of STR/CTR trends and findings of independent audits” require?
The board must oversee trends in suspicious transaction reports and currency transaction reports filed by the applicant, together with the findings of independent AML audits required under Regulation 18.1(d). Form A6 Section 6 requires annual reporting of the number of STRs filed via goAML, the broad categories of suspicion reported, and the number of CTRs filed where fiat exposure exists; Form A6 Section 7 requires a summary of independent audit findings and the status of remediation — described in the form as fully implemented, partially implemented, in progress, or not yet started.
Our reading is that Regulation 4.2(d) is the mechanism that connects the applicant’s day-to-day reporting activity, and the results of its own independent audits, back to the same body responsible for approving policy and reviewing risk under duties (a) and (b). A pattern of unresolved audit findings, or a rising or falling trend in suspicious activity reports without explanation, is squarely within what the board is expected to be tracking under this duty — not something that surfaces for the first time when PVARA asks about it directly.
What happens if a board fails to meet these oversight duties?
The Regulations do not attach a standalone penalty to a breach of Regulation 4 in isolation. Instead, inadequate board oversight is the kind of underlying governance failure that feeds into the broader revocation grounds in Regulation 19.1 — including “systemic or material AML/CFT failures” and breach of AML/CFT obligations generally — and into the fit-and-proper assessment of the key individuals who sit on that board.
Regulation 19.2 requires that any revocation be applied proportionately, “taking into account the severity and impact of the breach.” Where guidance has not been issued on exactly how PVARA weighs a governance failure such as inadequate board oversight against a specific compliance breach, applicants should verify the current position directly with the Authority rather than assume a fixed escalation path.
About this analysis
This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025, principally Regulations 4.1, 4.2, 8.1, 8.2, 18.1 and 19, together with Form A4 and Form A6 in Annex A, read as published. Where practice is not yet settled or specific thresholds have not been published, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect