Every substantive obligation in the PVARA No Objection Certificate Regulations 2025 — governance, fit and proper standards, the AML/CFT framework, ongoing reporting — exists to serve one of seven stated purposes. Regulation 3.1 lists them directly, and reading them together explains why the Regulations are built the way they are, rather than treating each later requirement as an isolated rule.
This piece works through all seven, in order, and connects each one to the parts of the Regulations that actually implement it.
What are the seven objectives PVARA states for the NOC Regulations?
Regulation 3.1 provides that “the objectives of these Regulations are to” achieve seven things, listed (a) through (g):
“(a) establish Anti-Money Laundering / Countering The Financing Of Terrorism (‘AML/CFT’) minimum standards for all VASPs; (b) ensure fitness and propriety of Controllers and Key Individuals; (c) ensure VASPs maintain systems to prevent, detect and report ML/TF; (d) ensure adoption of a risk-based and proportionate AML/CFT control frameworks; (e) ensure integration of all VASPs with the Financial Monitoring Unit (‘FMU’ and the goAML system) once registered and in receipt of the NOC; (f) prevent unregistered and non-compliant VASPs from operating in Pakistan; and (g) to facilitate a phased regulatory pathway whereby AML-Registered Services may be provided once registration has been completed and the NOC has been issued, and prior to full licensing under the Ordinance.”
| Objective | What it targets |
|---|---|
| (a) AML/CFT minimum standards | A floor applied to every VASP, not a case-by-case standard |
| (b) Fitness and propriety | Controllers and Key Individuals specifically |
| (c) Detection systems | The VASP’s own capability to prevent, detect and report money laundering and terrorist financing |
| (d) Risk-based frameworks | Proportionality to the VASP’s actual risk profile, not a one-size-fits-all control set |
| (e) FMU integration | Connection to goAML once the NOC issues |
| (f) Market gatekeeping | Keeping unregistered or non-compliant operators out of Pakistan entirely |
| (g) Phased pathway | Earlier market access for AML-Registered Services, ahead of full licensing |
What does “AML/CFT minimum standards for all VASPs” actually require in practice?
Objective (a) is implemented in Part 4 of the Regulations. Regulation 8.2 lists the minimum components of the framework every Applicant must maintain: a Board-approved AML/CFT policy, documented customer due diligence and enhanced due diligence procedures, targeted financial sanctions screening, transaction monitoring processes, suspicious and currency transaction report escalation procedures, a documented enterprise-wide risk assessment, a recordkeeping and data governance policy, a training programme, and an outsourcing risk management framework. That list is the practical shape of what “minimum standards” means under this instrument — it is not left as an abstract phrase.
How is fitness and propriety of Controllers and Key Individuals actually assessed?
Objective (b) is implemented through Parts 2 and 3 of the Regulations. Regulation 6.1 requires all Key Individuals to satisfy fit and proper standards of integrity, competence, financial soundness and experience “as prescribed by section 16 of the Act.” Regulation 6.3 sets hard exclusions — conviction for an AML-related or dishonesty offence, sanction by a regulator, or undischarged bankruptcy or insolvency — that automatically disqualify a candidate. Regulation 7.1 applies a parallel standard to any Controller holding 20% or more of voting power or share capital, requiring PVARA’s approval before AML registration may be granted.
Where does “systems to prevent, detect and report” show up in the Regulations?
Objective (c) is what Regulation 11 exists to enforce. Regulation 11.1 requires each Applicant to maintain “monitoring systems capable of detecting suspicious or unusual activity in real time or near real time.” Regulation 11.2 requires filing suspicious transaction reports in line with the Anti-Money Laundering Act 2010, and Regulation 11.3 requires currency transaction reports for fiat transactions above the applicable threshold. Form A4, the AML/CFT framework submission statement, requires the CEO and MLRO to jointly certify that these systems are “implemented, tested and operational” — not merely designed on paper.
What does “risk-based and proportionate” mean when it comes to the control framework?
Objective (d) is stated as a design principle in Regulation 8.1: “Each Applicant must maintain an AML/CFT framework that is proportionate to its business activities and operational complexity.” This is why Regulation 4.1 uses the same language for governance arrangements generally, requiring them to be “proportionate the nature, scale and complexity” of the Applicant’s operations. In practice, a smaller Applicant offering a narrower set of AML-Registered Services is not expected to build the same scale of control infrastructure as a large multi-jurisdictional exchange group — the standard scales with the risk, rather than applying a fixed control set regardless of size.
What does FMU and goAML integration actually involve?
Objective (e) is implemented through Regulation 11.4 through 11.6. Once the NOC issues, the foreign Applicant whose foreign chapter is already providing VASP services in Pakistan must register on the goAML platform as the reporting entity, unless FMU or the federal government directs otherwise. Regulation 11.5 transfers that reporting-entity role to the local entity once it is incorporated and licensed. Regulation 11.6 requires the Applicant to demonstrate technical readiness to file reports “immediately upon goAML registration” — objective (e) is framed around integration happening at the point of registration, not at some later point once the business feels ready.
How does Regulation 3.1(f) — preventing unregistered VASPs from operating — connect to enforcement?
Objective (f) is the underlying rationale for Part 6 of the Regulations. Regulation 18.1(a) requires a registered Applicant to “comply with all AML/CFT obligations at all times,” and Regulation 19.1 gives PVARA revocation powers where an Applicant provides false or misleading information, breaches AML/CFT obligations, or fails to progress toward a full licence within the required period. Objective (f) is also the reason rejection or revocation carries real consequences rather than a soft warning: the Regulations exist partly to keep operators who cannot or will not meet the standard out of the Pakistani market altogether, not simply to process paperwork.
How does the “phased regulatory pathway” objective tie the other six together?
Objective (g) is the structural idea that makes the rest of the Regulations coherent as a single system rather than a checklist. It describes AML-Registered Services becoming available “once registration has been completed and the NOC has been issued, and prior to full licensing under the Ordinance” — the mechanism set out in detail in Regulation 2.3. Our reading is that objectives (a) through (f) describe the standards a VASP must meet, and objective (g) describes the reward for meeting them early: staged market access rather than a binary “wait for full licensing or do not operate” choice. Read together, the seven objectives describe a regime that trades early market access for early, enforceable AML/CFT accountability — not one that grants access first and asks questions later.
About this analysis
This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025, principally Regulation 3.1(a) through (g), read alongside the Regulations that implement each objective — Regulations 2.3, 4.1, 6.1, 6.3, 7.1, 8.1, 8.2, 11.1 through 11.6, 18.1 and 19.1 — as published.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect