Licensing

The Six Criteria PVARA Assesses in an NOC Application

Regulation 16.1 lists six criteria PVARA assesses in an NOC application, plus its power to interview Key Individuals and inspect the Applicant.

An NOC application is not decided on the strength of the forms alone. Regulation 16.1 of the PVARA No Objection Certificate Regulations 2025 lists six specific matters PVARA weighs when assessing an Applicant, and two further Regulations give PVARA the power to look beyond the paperwork entirely.

This piece works through each of the six criteria, and the interview and inspection powers that sit alongside them.

What six criteria does PVARA assess when reviewing an NOC application?

PVARA assesses fitness and propriety of Key Individuals and Controllers; the adequacy and operational readiness of the AML/CFT framework for AML-Registered Services; governance and internal control arrangements; the Applicant’s financial soundness; the adequacy of its technology architecture and monitoring systems; and its inherent and residual money-laundering and terrorist-financing risk profile. Regulation 16.1 sets this out directly:

“The documentation submitted by the Applicant to the Authority on the fitness and propriety shall be assessed as part of the NOC process and the same along with the below mentioned matters may be evaluated/re-evaluated during the subsequent licensing application stage: (a) fitness and propriety of Key Individuals and Controllers; (b) adequacy and operational readiness of the AML/CFT Framework for AML-Registered Services; (c) governance and internal control arrangements; (d) financial soundness of the Applicant; (e) adequacy of technology architecture and monitoring systems; and (f) the Applicant’s inherent and residual ML/TF risk profile.”

Criterion What PVARA is checking
(a) Fitness and propriety Whether Key Individuals and Controllers meet integrity, competence and financial-soundness standards
(b) AML/CFT framework Whether the framework for AML-Registered Services is complete and actually operational, not just documented
(c) Governance Board oversight, internal controls and reporting lines
(d) Financial soundness Whether the Applicant has the financial resources to support its proposed activities
(e) Technology and monitoring Whether the technology architecture and transaction-monitoring systems are adequate
(f) ML/TF risk profile The Applicant’s inherent risk before controls, and residual risk after them

Why are these criteria assessed again at the full licensing stage?

Because Regulation 16.1 says so explicitly: the same fitness-and-propriety documentation and the six listed matters “may be evaluated/re-evaluated during the subsequent licensing application stage.” The NOC review is not a one-time check that a full licensing decision then takes on faith. An Applicant that satisfied PVARA on governance or technology architecture at the NOC stage has not banked that finding permanently — the same ground can be walked again once the Applicant applies for its full VASP licence, by which point the business will typically have grown, added staff, or changed systems, any of which could shift the answer.

Our reading is that this re-evaluation right gives PVARA a practical safeguard against an Applicant presenting a strong picture at the NOC stage — often while operations are still small and largely on paper — and a materially different one once it is actually running AML-Registered Services under the NOC.

Can PVARA interview a Key Individual as part of the NOC review?

Yes. Regulation 16.2 states plainly that “the Authority may conduct interviews with Key Individuals to verify competence and suitability.” This power sits directly on top of the fitness-and-propriety criterion in Regulation 16.1(a) and is echoed separately in Regulation 6.2, which gives PVARA the same interview power in the context of the general fit and proper requirements applicable to all Key Individuals — Chief Executive Officer, Director, Chief Financial Officer, Compliance Officer, the Money Laundering Reporting Officer (MLRO), Head of Internal Audit, Head of Risk Management, and Head of Information Security, per Regulation 5.1.

Neither regulation describes the interview format, who conducts it, or how long an Applicant has to prepare for one. Where that operational detail is not fixed in the Regulations reviewed, that gap is stated here rather than assumed. An Applicant should treat the completed Form A3 Fit & Proper Questionnaire submitted for each Key Individual as the document an interview is most likely to test against, since Regulation 6.4 requires that form as the baseline fitness-and-propriety declaration.

Can PVARA inspect an Applicant before deciding on an NOC?

Yes. Regulation 16.3 gives PVARA a separate power: “The Authority may conduct inspections or request additional information to support its assessment.” This is broader than the interview power in Regulation 16.2 because it is not limited to Key Individuals — it can extend to the Applicant’s systems, premises, or records generally, at PVARA’s discretion, and can be exercised alongside a request for further documentation rather than only as a stand-alone site visit.

Together, Regulations 16.2 and 16.3 mean an Applicant’s written submission is a starting point for PVARA’s assessment, not the entire basis for it. A complete Form A1 application accompanied by every supporting document listed in Section 5 of that form — the Board-approved AML/CFT policy, customer due diligence and enhanced due diligence procedures, transaction monitoring policy, and the rest — does not foreclose PVARA following up with an interview, an inspection, or a request for more information before it decides.

How does the fitness-and-propriety assessment connect to the Key Individuals named in the application?

Directly, through Regulation 5.1’s list of required Key Individual roles: Chief Executive Officer, a Director (executive or non-executive), Chief Financial Officer, Compliance Officer, MLRO, Head of Internal Audit, Head of Risk Management, and Head of Information Security. Regulation 5.2 allows the Compliance Officer and MLRO functions to be combined “where justified by the size and complexity of the applicant,” but does not permit any of the other roles to be merged or left vacant. Regulation 6.3 sets hard exclusions that apply to every one of these roles: no individual may serve as a Key Individual if they have been convicted of an offence under the Anti-Money Laundering Act, 2010, the Act, or any law involving dishonesty, fraud or financial misconduct; have been sanctioned by a regulator in Pakistan or abroad; or are subject to undischarged bankruptcy or insolvency proceedings.

Criterion (a) in Regulation 16.1, in other words, is not assessed against a general reputation standard — it is assessed against the specific exclusions in Regulation 6.3 and the specific declarations each Key Individual makes on Form A3, which the interview power in Regulation 16.2 exists to test.

What should an Applicant do to prepare for each of the six criteria?

Treat each of the six as requiring its own evidence file, not a single narrative covering all of them. For fitness and propriety, that means a completed Form A3 for every Key Individual, with CVs, passport copies and — where any answer is “Yes” to a regulatory, criminal or financial-soundness question — full supporting detail rather than a bare disclosure. For the AML/CFT framework, Regulation 8.2 lists the minimum components PVARA expects: a Board-approved AML/CFT policy, documented customer due diligence and enhanced due diligence procedures, targeted financial sanctions screening, transaction monitoring, suspicious and currency transaction report escalation procedures, an enterprise-wide risk assessment, a recordkeeping and data governance policy, a training programme, and an outsourcing risk management framework.

For governance, Regulation 4.2 specifies what the Applicant Board itself must actually do — approve AML/CFT policies, review enterprise-wide risk assessments, monitor compliance resourcing, and oversee reporting trends and audit findings — which is different from simply having a board that exists on paper. For financial soundness, Section 8 of Form A1 calls for audited financial statements or pro forma financials, evidence of paid-up capital, and a description of the sources of initial funding. For technology and monitoring, Section 6 of Form A1 asks for a description of core systems, AML-relevant systems specifically, and a candid statement of whether each is fully operational, in testing, or still under implementation. For the ML/TF risk profile, the enterprise-wide risk assessment required under Regulation 8.2(f) is the document this criterion is actually tested against — a generic or template risk assessment is unlikely to satisfy Regulation 16.1(f) on its own terms, since Section 2 of the Regulations’ framework confirmation statement requires the AML/CFT framework to be “tailored specifically to its business model,” not a template.

About this analysis

This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025 — principally Regulations 16.1, 16.2 and 16.3, read alongside Regulations 4.2, 5.1, 5.2, 6.2, 6.3, 6.4, 8.2 and the associated Form A1 and Form A3 — as published. Where the Regulations leave interview or inspection procedure undescribed, that gap is stated in the text above rather than assumed.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect