Customer due diligence is not a single onboarding step that ends once a wallet is verified. Regulation 9 of the PVARA No Objection Certificate Regulations 2025 sets out what customer due diligence (“CDD”) has to cover for a virtual asset service provider, and fixes a hard sequencing rule: no CDD, no service.
This article reads Regulation 9 as published, lists the five CDD elements it requires, and explains the timing rule that governs when CDD has to be complete.
What does Regulation 9 require of a VASP’s CDD procedures?
Regulation 9.1 sets the baseline standard: every applicant must implement CDD procedures that comply fully with the Anti-Money Laundering Act, 2010 (“AMLA 2010”) and all applicable rules issued under it. The provision reads:
Each Applicants shall implement CDD procedures that comply fully with AMLA 2010 and all applicable rules issued under it.
This is an incorporation-by-reference standard. Regulation 9 does not restate AMLA 2010’s own CDD requirements in full — it requires the applicant’s procedures to comply with that separate statute, which is not one of the source documents behind this analysis and should be read directly for its own detail. What Regulation 9.2 adds is a Pakistan-VASP-specific list of the elements PVARA expects to see in the procedure document itself, on top of whatever AMLA 2010 already requires.
What are the five CDD elements Regulation 9.2 lists?
Regulation 9.2 sets out five elements a VASP’s CDD procedures must include:
CDD procedures shall include: (a) identification and verification of all customers; (b) verification of all Controllers; (c) assessment of the nature and purpose of the business relationship; (d) understanding and, where appropriate, verification of sources of funds and wealth; and (e) ongoing monitoring and periodic updating of customer profiles.
- Identification and verification of all customers — the baseline know-your-customer check applied to every customer, without an exception for low-value or occasional users stated in the text.
- Verification of all Controllers — a check that extends CDD beyond the retail customer relationship to the applicant’s own ownership structure, tying Regulation 9 to the Controller disclosure regime set out separately in Regulation 7.
- Assessment of the nature and purpose of the business relationship — understanding why a customer wants the service, not only who the customer is.
- Understanding, and where appropriate verifying, sources of funds and wealth — a qualified obligation: verification is required “where appropriate,” which leaves the applicant’s own risk assessment to determine when documentary evidence of source of funds is warranted versus when an understanding recorded from the customer relationship suffices.
- Ongoing monitoring and periodic updating of customer profiles — CDD as a continuing duty rather than a one-off check completed at onboarding.
| Element | What it requires | Applies to |
|---|---|---|
| (a) Identification and verification | ID checks on every customer | All customers |
| (b) Controller verification | Verification of the applicant’s own Controllers | The applicant’s ownership structure |
| (c) Nature and purpose | Understanding why the relationship exists | All customers |
| (d) Source of funds and wealth | Understanding, and where appropriate verifying, origin of funds | Risk-dependent |
| (e) Ongoing monitoring | Periodic updating of customer profiles | All customers, continuously |
Why does Regulation 9 require verification of the applicant’s own Controllers, not just customers?
Because a VASP’s ownership can itself be a money laundering or terrorist financing vector, and Regulation 9.2(b) treats Controller verification as part of the same CDD discipline applied to customers, rather than as a separate governance-only exercise. This connects directly to Regulation 7.1 of the NOC Regulations, which deems any person holding 20% or more of voting power or share capital a Controller, and to Form A2 — the Controller and Beneficial Owner Disclosure Form — which requires a full source-of-wealth narrative, sanctions checks and a Politically Exposed Person (“PEP”) declaration for every Controller. Regulation 9.2(b)’s inclusion inside the CDD provision, rather than only inside Regulation 7’s ownership rules, is our reading of why PVARA treats Controller checks as an AML control and not merely a licensing formality.
When does CDD have to be complete?
Before the first service. Regulation 9.3 fixes the timing directly, and it is the strictest sentence in the whole provision:
CDD must be completed before the Applicant provides any AML Registered Service.
“AML Registered Service” is a defined term under the NOC Regulations, covering the four service categories an applicant may provide once it has an NOC and has completed goAML registration, ahead of a full licence: Broker-Dealer Services, Custody Services, Exchange Services and Virtual Asset Derivatives Services. Regulation 9.3’s rule means a VASP cannot onboard a customer provisionally and complete verification afterward while a trade or transfer is already underway — CDD is a precondition to service delivery, not a parallel process that can run alongside it.
How does CDD differ from enhanced due diligence under the same Regulations?
CDD under Regulation 9 is the baseline procedure applied to every customer and every Controller. Enhanced due diligence (“EDD”) is a separate, additional layer that Regulation 10 of the NOC Regulations requires where higher money laundering or terrorist financing risks are identified — for customers from high-risk jurisdictions, PEPs, unusually large or complex transactions, and customers flagged through adverse media. Regulation 9 does not itself trigger EDD; it sets the standard procedure that applies before any risk-based escalation to the enhanced standard occurs. A VASP building its onboarding workflow needs both layers documented as distinct procedures, since Regulation 8.2(b) of the same Regulations lists “documented CDD and EDD procedures” as a single required component of the wider AML/CFT framework, while Regulations 9 and 10 set out what each procedure has to contain separately.
What should an applicant document to evidence compliance with Regulation 9?
Four things follow directly from the text, each tied to a specific element of Regulation 9.2:
- A documented identification and verification workflow covering every customer type the business model anticipates onboarding, referenced against the customer categories described in the applicant’s business model narrative submitted with Form A1.
- A Controller verification checklist that cross-references Form A2 submissions for every Controller holding 20% or more of voting power or share capital, so Regulation 9.2(b) and Regulation 7’s disclosure regime are satisfied by the same underlying evidence rather than by duplicated, inconsistent records.
- A documented basis for when source-of-funds verification is triggered, since Regulation 9.2(d)’s “where appropriate” standard leaves that judgement to the applicant’s own risk assessment rather than fixing a threshold in the Regulations themselves.
- A periodic review schedule for ongoing monitoring, evidencing that customer profiles are updated on a cycle rather than left static after onboarding — the specific frequency is not fixed by Regulation 9 itself and should be set by the applicant’s own risk-based policy.
About this analysis
This analysis was prepared by the CoinConnect research desk from Regulations 2.3, 7.1, 8.2(b), 9.1, 9.2, 9.3 and 10.1 of the PVARA No Objection Certificate Regulations 2025, together with Form A1 and Form A2 at Annex A, read as published. The Anti-Money Laundering Act, 2010, referenced by Regulation 9.1, was not among the three source documents reviewed, and its own CDD requirements are not restated here. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect