Before a virtual asset service provider can obtain a no objection certificate from PVARA, it has to put named individuals in eight specific roles. This is not a suggestion about good governance — it is a listed requirement in the Regulations, tied directly to the fit and proper assessment that decides whether the application succeeds.
This piece works through the eight roles listed in Regulation 5.1, what documentation each one requires, and where this list differs from the wider definition of “Key Individual” used elsewhere in Pakistan’s virtual asset framework.
What are the eight Key Individual roles PVARA requires an NOC applicant to appoint?
Regulation 5.1 of the PVARA No Objection Certificate Regulations 2025 requires the applicant to maintain eight named roles: Chief Executive Officer, Director, Chief Financial Officer, Compliance Officer, Money Laundering Reporting Officer, Head of Internal Audit, Head of Risk Management, and Head of Information Security. These roles must be filled — and evidenced with supporting documentation — before an NOC can be granted.
“5.1 The Applicant must maintain the following Key Individuals: (a) Chief Executive Officer; (b) Director (executive or non-executive) (c) Chief Financial Officer; (d) Compliance Officer; (e) Money Laundering Reporting Officer (‘MLRO’); (f) Head of Internal Audit; (g) Head of Risk Management; and (h) Head of Information Security.”
| Role | Regulation 5.1 reference | Core function |
|---|---|---|
| Chief Executive Officer | (a) | Overall executive leadership and accountability |
| Director (executive or non-executive) | (b) | Board-level governance, feeding into the board oversight duties |
| Chief Financial Officer | (c) | Financial management and reporting |
| Compliance Officer | (d) | Day-to-day AML/CFT and regulatory compliance |
| Money Laundering Reporting Officer | (e) | STR/CTR decision-making and FMU liaison |
| Head of Internal Audit | (f) | Independent assurance over controls |
| Head of Risk Management | (g) | Enterprise risk identification and mitigation |
| Head of Information Security | (h) | Cybersecurity and technology risk |
Why does PVARA require these specific roles rather than leaving staffing to the applicant?
Regulation 3.1(b) states that one of the stated objectives of the Regulations is to “ensure fitness and propriety of Controllers and Key Individuals.” Naming eight specific roles gives that objective a concrete anchor: rather than requiring generic “adequate staffing,” PVARA specifies exactly which functions must exist and be personally accountable to a named individual before an NOC can issue.
In practice, this means an applicant cannot rely on outsourced or informal arrangements for these eight functions at key individual level, even where day-to-day tasks are performed by a broader team. Someone named must hold ultimate responsibility for each of the eight functions, and that person is the one who goes through the fit and proper assessment described below.
What documentation must be submitted for each Key Individual?
Form A1, Section 3.2 of the application requires the applicant to list, for each Key Individual, their full name, nationality, date of appointment, and contact details — for both the global entity being registered on the goAML portal and the proposed local entity in Pakistan. Beyond the table entry, three specific attachments are required per person.
- A completed Form A3 — the Fit & Proper Questionnaire — covering employment history, qualifications, regulatory and criminal record, financial soundness, conflicts of interest and professional references.
- An up-to-date CV.
- A copy of the individual’s passport.
Any later appointment or change to one of these eight roles requires a separate submission of Form A8 — the Key Individual Appointment / Change Form — which itself requires a fresh Form A3, an updated CV, a copy of identification, a board approval resolution, and, for a new appointment, a police clearance certificate.
How does the fit and proper standard apply to these eight roles?
Regulation 6.1 requires all Key Individuals to satisfy “Fit and Proper standards of integrity, competence, financial soundness and experience, as prescribed by section 16 of the Act.” Section 20 of the Virtual Assets Act 2026 splits responsibility for this assessment: PVARA itself determines fitness and propriety for the Controller, Sponsor, Chief Executive Officer and Director, while it is “the responsibility of the applicant for a licence or the Licensee to assess and maintain” the fitness and propriety of the remaining Key Individuals — the Chief Financial Officer, Compliance Officer, MLRO, Head of Internal Audit, Head of Risk Management and Head of Information Security under Regulation 5.1 — and to submit a written undertaking confirming ongoing compliance.
In practice, this means the eight roles under Regulation 5.1 split into two tiers of scrutiny: PVARA directly assesses two of them — the CEO and the Director — while the applicant carries first-line responsibility for the other six, subject to PVARA’s power to interview any Key Individual under Regulation 16.2 and to revoke the NOC where any of them ceases to meet the standard under Regulation 19.1(c).
Can one person hold more than one of these eight roles?
Regulation 5.2 permits combining the Compliance Officer and MLRO functions “where justified by the size and complexity of the applicant.” The Regulations do not extend that combination provision to any of the other six roles listed in Regulation 5.1, and do not state a general rule for combining roles beyond the Compliance Officer and MLRO pairing.
Our reading is that, absent further guidance, the other six roles — CEO, Director, CFO, Head of Internal Audit, Head of Risk Management and Head of Information Security — are expected to be held by distinct individuals, though the Regulations do not expressly prohibit combinations for a very small applicant. Applicants considering combining any role outside the Compliance Officer/MLRO pairing should raise the specific proposed structure with PVARA directly rather than assume it is permitted by default.
How does this eight-role list compare to the Act’s broader “Key Individual” definition?
Section 3(1)(xv) of the Virtual Assets Act 2026 defines “Key Individual” more broadly than Regulation 5.1 of the NOC Regulations. The Act’s definition lists ten categories: director, Managing Director, Chief Financial Officer, Chief Operating Officer, head of internal audit, head of compliance, MLRO or equivalent, head of risk management, head of information-security and cyber-security, and any other position PVARA declares by written notice.
There are two notable differences worth flagging. First, the Act’s definition uses “Managing Director,” while Regulation 5.1(a) of the NOC Regulations specifies “Chief Executive Officer” instead — the two documents do not use identical terminology for this role. Second, the Act’s definition includes “Chief Operating Officer” as a Key Individual category, while Regulation 5.1 does not list a Head of Operations or Chief Operating Officer among the eight mandatory roles for NOC purposes. The Regulations do not explain this discrepancy, and it is not clear from the source documents whether it is deliberate — for example, reflecting that the NOC stage requires a narrower core team than full licensing — or simply a drafting variance between the two instruments. Applicants should not assume the NOC-stage list of eight is the final word on which roles the Authority will expect once a full VASP licence is sought.
What happens if one of the eight Key Individual roles is left unfilled or fails fit and proper?
Regulation 19.1(c) of the NOC Regulations lists “any Key Individual ceases to satisfy Fit and Proper requirements” as a ground for revoking the NOC, including AML registration status. Section 20(3) of the Act separately gives PVARA the power to refuse, suspend or revoke a licence where a Key Individual fails to meet the prescribed fit and proper criteria.
In practice, this means the eight roles are not simply an intake checklist — they are a continuing condition of holding the NOC. Regulation 20.4 of the wider Act framework requires that fit-and-proper status be “continuing in nature,” meaning a person occupying one of these roles must notify PVARA of any matter that could affect their fitness, not only disclose their history at the point of appointment.
About this analysis
This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025 — principally Regulations 3.1(b), 5.1, 5.2, 6.1, 16.2 and 19.1(c), and Forms A1, A3 and A8 in Annex A — read alongside Section 3(1)(xv) and Section 20 of the Virtual Assets Act 2026, as published.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect