Compliance

The Six Continuing Obligations of Every VASP Licensee

Section 22 of the Virtual Assets Act sets six duties every VASP licensee owes PVARA at all times: capital, compliance, reporting, approvals, systems and fees.

Getting a PVARA licence is the beginning of a compliance relationship, not the end of one. Section 22 of the Virtual Assets Act 2026 opens with a phrase that does most of the work in this article: a licensee shall, “at all times,” meet six duties. Not at the point of application. Not once, when the licence is granted. At all times.

This piece works through each of the six obligations in the order the Act lists them, what “at all times” actually requires in practice, and what happens when a licensee falls short.

What are the six ongoing obligations under section 22 of the Virtual Assets Act?

A licensee must, at all times: maintain the prescribed minimum paid-up capital and financial resources; comply with the Act and all Rules, Regulations, directives and guidelines; submit periodic returns, reports and audited financial statements as prescribed; obtain PVARA’s prior approval for any material change in control or business; maintain risk-management, compliance and cybersecurity systems including data privacy standards; and pay supervision, renewal or other prescribed fees. Section 22 states it directly:

“A Licensee shall, at all times— (a) maintain the prescribed minimum paid-up capital and financial resources; (b) comply with this Act and all Rules, Regulations, directives and guidelines issued by the Authority; (c) submit such periodic returns, reports and audited financial statements as may be prescribed; (d) obtain the prior approval of the Authority for any material change in control or business, in the manner prescribed; (e) maintain risk-management, compliance and cybersecurity systems in accordance with applicable legal and regulatory requirements including adherence to data privacy standards; and (f) pay such supervision, renewal or other fees as may be prescribed.”

Six duties, one sentence, no exceptions carved out in the text. A licensee that satisfies five of the six is still in breach of the sixth.

Obligation What it covers
(a) Capital and financial resources Prescribed minimum paid-up capital, maintained continuously
(b) Legal compliance The Act plus every Rule, Regulation, directive and guideline PVARA issues
(c) Reporting Periodic returns, reports and audited financial statements
(d) Prior approval Written PVARA sign-off before material change in control or business
(e) Systems Risk-management, compliance and cybersecurity systems, including data privacy
(f) Fees Supervision, renewal and other prescribed fees

Why doesn’t meeting the capital bar once at licensing satisfy the Act?

Because section 22(a) is written as a continuous test, and section 25 confirms the same logic for financial resources generally. Under section 25(1), a licensee “shall, at all times, maintain such minimum paid-up capital, liquid assets and financial resources not less than such amounts as may be prescribed.” A licensee that meets the capital requirement on the day its licence is granted and then lets reserves fall below the prescribed floor — through losses, withdrawals or a bad quarter — is no longer compliant, even though nothing about its licence document has changed.

Section 25 also gives PVARA room to move the bar for individual licensees. Under section 25(2), the Authority may prescribe higher financial-resource requirements “having regard to the category, size, complexity, or risk profile” of a licensee, and section 25(3) allows additional liquidity, margin or risk-based capital requirements. In practice, our reading is that a licensee expanding into higher-risk services, such as broker-dealer or custody activity, should expect its capital floor to move with that expansion rather than stay fixed at the level set when it first applied. Section 25(4) does allow PVARA to grant conditional or risk-based exemptions for limited-scope or low-risk licensees, so the obligation is not applied identically to every business model — but the exemption is discretionary, not automatic.

What reporting does a licensee owe PVARA, and how often?

Section 22(c) requires “periodic returns, reports and audited financial statements as may be prescribed” — the Act sets the obligation but leaves the calendar, the format and the specific content to Regulations PVARA has not yet published in the source documents available for this analysis. Where guidance has not been issued, that is stated here rather than guessed at.

Two related duties elsewhere in the Act give a sense of the shape reporting will take. Section 27(1) requires a licensee to furnish “cryptographic proof-of-reserves reconciled against its liabilities to customers” at intervals to be prescribed by Regulations. Section 27(2) separately requires an annual audit by a firm of Chartered Accountants approved by the Division concerned, and that audit must specifically verify the segregation of customer assets required under section 24. A Pakistani-incorporated licensee already registered with SECP should not assume that its existing company-law filings satisfy this — section 22(c) and section 27 are PVARA-specific obligations that sit alongside, not inside, ordinary corporate reporting.

When must a licensee ask PVARA’s permission before making a change?

Section 22(d) requires prior approval for “any material change in control or business, in the manner prescribed.” The Act does not define “material” for this purpose, so a licensee cannot rely on a fixed numeric threshold from the text alone. What the Act does fix is the trigger most likely to count as a change in control: section 3(1)(v) defines a Controller as a person who, alone or with associates, holds or can exercise 20% or more of the voting power, ownership interest or share capital of a licensee, or otherwise exercises significant influence over its management. A transaction that creates a new Controller, or moves an existing one across that 20% line, sits squarely inside what section 22(d) is built to catch.

A change in business model — adding a new Schedule I service category, for instance, or materially altering how customer assets are handled — plausibly falls within “material change in business” even without any change in ownership. Because the Act leaves “material” undefined, our reading is that a licensee facing an ambiguous case should raise it with PVARA directly rather than assume silence is permission. The Act imposes no exception for changes a licensee judges to be minor; it only exempts changes PVARA has approved in advance.

What do “risk-management, compliance and cybersecurity systems” actually require?

Section 22(e) is a single clause covering three overlapping systems, and several other sections of the Act flesh out what “in accordance with applicable legal and regulatory requirements” means for each. Section 34 requires licensees to comply with cybersecurity and operational-resilience requirements prescribed by PVARA, “including, but not limited to, technical standards, security controls, and reporting mechanisms.” Section 40 requires segregation of sensitive information — customer due-diligence records, transaction data capable of identifying a customer, private keys and cryptographic credentials — from ordinary operational data, with access controlled on a need-to-know basis. Section 49 adds a data-privacy layer specifically: a licensee must implement “strict limits on the collection, use, and sharing of customer data,” requiring explicit, informed and revocable consent for any non-essential processing.

The compliance limb connects directly to the Act’s anti-money laundering chapter. Section 46(1) deems every licensed virtual asset service provider a financial institution for the purposes of the Anti-Money Laundering Act, 2010, and section 46(2)(c) requires internal controls and compliance programmes “including the appointment of an AML, CFT or CPF compliance officer.” A licensee’s section 22(e) systems, in other words, are not a generic IT policy — they have to be built around the specific reporting, screening and record-keeping duties the Act places on it elsewhere.

What happens if a licensee fails to meet an ongoing obligation?

Failing any limb of section 22 is, on its own terms, a contravention of the Act — and section 23(1)(a) lists exactly that as the first ground on which PVARA may vary, suspend or revoke a licence, after written notice and an opportunity to be heard. Failing the fit and proper standard tied to a Controller (section 22(d) territory) is a separate, explicit ground under section 23(1)(b). Beyond licence action, section 59(1) gives PVARA a menu of administrative sanctions for any contravention of the Act or Regulations: a written reprimand or public censure, a directive to cease or remedy the breach, a financial penalty up to the amount prescribed by Rules, suspension or revocation of the licence, or disqualification of an individual from holding office at a licensee. Section 59(4) separately caps a fine for any contravention at twenty-five million rupees.

None of these consequences require a criminal conviction — administrative sanctions under section 59 sit entirely within PVARA’s own supervisory powers. A licensee that treats section 22 as satisfied once, at the point of licensing, rather than as a live obligation it has to keep meeting is exposed to this enforcement track regardless of intent.

About this analysis

This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act 2026 as passed by the National Assembly — principally section 22, read alongside sections 20, 23, 25, 27, 34, 40, 46 and 59 — as published. Where the Act defers detail to Regulations that have not yet been published in the source material reviewed, that is stated in the text above rather than assumed.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect