PVARA does not accept a generic anti-money laundering policy bought off a template site and lightly edited for crypto. Regulation 8 of the PVARA No Objection Certificate Regulations 2025 lists, item by item, what an applicant’s AML/CFT framework must contain before an NOC application can succeed.
This article sets out all nine components exactly as Regulation 8.2 lists them, explains what each one has to demonstrate, and notes where the Regulations leave the detail of implementation to the applicant’s own judgement.
What does Regulation 8 require of an applicant’s AML/CFT framework?
Regulation 8.1 sets the governing standard: every applicant must maintain an AML/CFT framework that is proportionate to its business activities and operational complexity. The Regulation does not prescribe a single fixed model — it requires fit to the applicant’s actual risk profile, size and activity mix. The text reads:
Each Applicant must maintain an AML/CFT framework that is proportionate to its business activities and operational complexity.
“Proportionate” cuts both ways. A framework that is too thin for a large exchange with retail custody will fail the standard; equally, our reading is that a framework copied wholesale from a large exchange onto a narrow-scope broker-dealer applicant risks looking unconsidered rather than thorough. Regulation 8.2 then lists, “at a minimum,” nine specific components the framework must include.
What are the nine required components?
Regulation 8.2 lists them as items (a) through (i). All nine must be present; the Regulation does not describe any of them as optional or as applicable only to certain business models.
- An AML/CFT Policy approved by the Applicant Board — the top-level document setting governance, roles, responsibilities and escalation lines for the whole programme.
- Documented CDD and EDD procedures — customer due diligence and enhanced due diligence procedures covering identification, verification, onboarding and ongoing monitoring.
- Targeted Financial Sanctions (TFS) screening procedures — screening customers, beneficial owners, counterparties and transactions against domestic and United Nations sanctions lists.
- Transaction monitoring processes — systems capable of detecting suspicious or unusual activity.
- Suspicious Transaction Reports and Currency Transaction Reports escalation procedures — the internal pathway from a flagged transaction to an external report filed with the Financial Monitoring Unit.
- A documented enterprise-wide money laundering and terrorist financing risk assessment — the analytical basis the rest of the framework is built to address.
- A recordkeeping and data governance policy.
- An AML/CFT training programme.
- An outsourcing risk management framework — governing any AML-relevant function performed by a third party.
Regulation 8.2 sets these out in a single list:
The framework shall, at a minimum, include: (a) an AML/CFT Policy approved by the Applicant Board; (b) documented CDD and EDD procedures; (c) Targeted Financial Sanctions (“TFS”) screening procedures; (d) Transaction monitoring processes; (e) Suspicious Transaction Reports (“STR”) and Currency Transaction Reports (“CTR”) escalation procedures; (f) a documented enterprise-wide money laundering and terrorist financing (“ML/TF”) risk assessment; (g) recordkeeping and data governance policy; (h) an AML/CFT training programme; and (i) an outsourcing risk management framework.
| # | Component | What it establishes |
|---|---|---|
| (a) | Board-approved AML/CFT Policy | Governance ownership at board level |
| (b) | CDD and EDD procedures | Customer identification and enhanced scrutiny where risk is higher |
| (c) | TFS screening procedures | Sanctions-list screening of customers, owners, counterparties |
| (d) | Transaction monitoring | Detection of suspicious or unusual activity |
| (e) | STR/CTR escalation procedures | Internal-to-external reporting pathway to FMU |
| (f) | Enterprise-wide ML/TF risk assessment | Analytical basis for the rest of the framework |
| (g) | Recordkeeping and data governance policy | Retention, security and auditability of records |
| (h) | AML/CFT training programme | Staff competence across the organisation |
| (i) | Outsourcing risk management framework | Oversight of any third party performing AML-relevant functions |
Why does the Board-approved policy come first?
Because Regulation 8.2(a) fixes accountability at the top of the organisation before any procedural detail is assessed. A policy signed off only by a compliance officer, without a documented board resolution, does not satisfy item (a) as drafted — the requirement is specific to board approval, and Regulation 4.2 of the same Regulations separately requires the Applicant Board to oversee approval of AML/CFT policies and procedures, review of enterprise-wide risk assessments, monitoring of compliance resourcing, and oversight of STR/CTR trends and independent audit findings. Read together, items (a) and (f) of Regulation 8.2 are the two documents the board is most directly answerable for.
How do the nine components connect to the statutory forms an applicant must submit?
Directly. Form A4 — the AML/CFT Framework Submission Statement — requires the Chief Executive Officer and the Money Laundering Reporting Officer to certify that the applicant’s framework is complete, accurate, tailored to its business model, and fully operational. Section 1 of Form A4 lists a document confirmation table that mirrors Regulation 8.2’s nine components almost line for line: AML/CFT Policy, CDD Procedures, EDD Procedures, Transaction Monitoring Framework, Sanctions/TFS Policy, STR/CTR Reporting Procedures, Recordkeeping and Data Governance Policy, Enterprise-Wide ML/TF Risk Assessment, AML/CFT Training Programme, and Outsourcing Policy and Register. A ninth document — Business Continuity and Disaster Recovery arrangements relating to AML systems — appears in the Form A4 confirmation table without a directly corresponding numbered item in Regulation 8.2, which our reading takes as PVARA requiring evidence of resilience alongside the nine substantive components rather than as a tenth listed component of the framework itself.
Practically, this means an applicant assembling its NOC submission should build each of the nine Regulation 8.2 components as a discrete, final, board-approved document, because Form A4 asks the CEO and MLRO to certify — by name, in a signed declaration — that each one exists, is operational, and is “not a template or generic framework.”
Do the nine components have to be entirely new documents, or can they build on existing policies?
The Regulations do not require the documents to be written from scratch, but they do require the substance to be applicant-specific. Section 2 of Form A4 states that the applicant confirms its framework “has been tailored specifically to its business model and is not a template or generic framework.” A group entity bringing a policy set from a foreign parent can use that set as a starting point, but Regulation 8A on documentation standards (covered separately) requires every submitted document to carry version control and be paginated and indexed — which in practice forces a genuine review and rewrite pass rather than a straight import.
Two of the nine — the enterprise-wide ML/TF risk assessment at item (f) and the outsourcing risk management framework at item (i) — are the components least amenable to reuse from an unrelated jurisdiction, because both depend on facts specific to the Pakistan operation: the customer base actually being onboarded, the counterparties actually being used, and the specific service providers actually engaged. Outsourcing arrangements are governed separately by Regulation 14 of the same Regulations, which restricts outsourcing of AML-critical functions such as CDD, sanctions screening, transaction monitoring, STR/CTR reporting and MLRO responsibilities unless the applicant conducts due diligence on the provider, maintains effective oversight, and retains enforceable audit and inspection rights.
What happens if one of the nine components is missing or incomplete?
The Regulations frame Regulation 8.2 as a minimum, and Section 16.1(b) of the NOC Regulations lists “adequacy and operational readiness of the AML/CFT Framework for AML-Registered Services” as one of the matters PVARA assesses — and may re-assess — at both the NOC and the subsequent licensing stage. A missing or thin component is therefore not merely a documentation gap; it is a factor the Authority is entitled to weigh in a decision to refuse the No Objection Certificate outright, and Regulation 16.3 gives PVARA an express power to conduct inspections or request additional information to test what has actually been submitted.
Once an NOC is granted, the nine components do not become a fixed, one-time submission. Regulation 18.1(a) requires ongoing compliance with all AML/CFT obligations, and the Annual AML/CFT Return at Form A6 requires the MLRO to report material audit gaps, remediation status and any changes in the framework year over year — so a framework built once for the application has to be maintained as a living set of documents, not filed and forgotten.
What should an applicant do to build all nine components correctly?
Sequence the work so the analytical document comes first. Four practical steps follow directly from the text:
- Complete the enterprise-wide ML/TF risk assessment (item (f)) before drafting the rest. Every other component — CDD/EDD thresholds, transaction monitoring rules, training content — should be calibrated to the risks that assessment actually identifies, rather than to a generic industry template.
- Secure the board resolution for item (a) in writing, since Regulation 8A.1(e) separately requires written evidence of board approval to accompany submitted documents.
- Map every outsourced function against Regulation 14 before finalising item (i), and use Form A5 — the Outsourcing Declaration and Register — as the working document, since it requires a line entry for each outsourced service, its AML/CFT relevance, and an audit-rights confirmation.
- Cross-check the finished set against the Form A4 confirmation table, since that table is the document PVARA’s assessors will use to verify the nine components are present before the CEO and MLRO are asked to sign.
About this analysis
This analysis was prepared by the CoinConnect research desk from Regulations 4.2, 8.1, 8.2, 8A.1, 14, 16.1, 16.3 and 18.1 of the PVARA No Objection Certificate Regulations 2025, together with Forms A4, A5 and A6 at Annex A, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect