Compliance

When Is Enhanced Due Diligence Mandatory for a VASP?

Regulation 10 of the NOC Regulations lists four triggers for enhanced due diligence — high-risk jurisdictions, PEPs, complex transactions and adverse media.

Standard customer due diligence is not always enough. Regulation 10 of the PVARA No Objection Certificate Regulations 2025 lists four specific circumstances in which a virtual asset service provider must step up to enhanced due diligence (“EDD”) — a higher standard of scrutiny applied on top of the baseline checks every customer already receives.

This article reads Regulation 10 as published and sets out each of the four triggers, what distinguishes EDD from ordinary CDD, and where the Regulation leaves judgement to the applicant.

What does Regulation 10 require, and how does it relate to ordinary CDD?

Regulation 9 of the NOC Regulations sets the baseline customer due diligence standard applied to every customer and every Controller. Regulation 10 sits alongside it and requires a higher standard where the risk profile of a particular relationship warrants it. Regulation 10.1 states the trigger condition directly:

Applicants shall conduct EDD where higher ML/TF risks are identified, including for: (a) customers from high-risk jurisdictions; (b) Politically Exposed Persons (“PEPs”); (c) unusually large, complex or opaque transactions; and (d) customers flagged through adverse media or other high-risk indicators.

The word “including” before the four-item list is significant on a plain reading: it signals that the four triggers are illustrative of the kinds of circumstances that call for EDD, not an exhaustive list closing off any other basis on which higher money laundering or terrorist financing (“ML/TF”) risk might be identified. An applicant’s own risk assessment — the enterprise-wide ML/TF risk assessment required as one of the nine components of the AML/CFT framework under Regulation 8.2(f) — is the document that should identify any additional triggers specific to its business model.

What are the four listed triggers, in detail?

Four circumstances, each addressing a different source of elevated risk.

  1. Customers from high-risk jurisdictions. The Regulation does not itself define “high-risk jurisdiction” or reference a specific list. Our reading is that an applicant should look to internationally recognised jurisdictional risk classifications — including those published by the Financial Action Task Force — and to any list FMU or PVARA separately issues, rather than inventing its own criteria, since neither the Act nor the NOC Regulations we reviewed publish a jurisdiction list of their own.
  2. Politically Exposed Persons. Form A2 — the Controller and Beneficial Owner Disclosure Form — requires a direct declaration of PEP status from every Controller and beneficial owner, asking whether the individual is a PEP and, if so, for details of the public office held, the country, the dates, and close associates. A customer identified as a PEP through onboarding checks falls within the same EDD trigger.
  3. Unusually large, complex or opaque transactions. This trigger is transactional rather than customer-based — it can apply to an otherwise low-risk customer whose specific transaction pattern departs from the norm the applicant’s monitoring baseline expects.
  4. Customers flagged through adverse media or other high-risk indicators. The reference to “other high-risk indicators” mirrors the “including” language in the chapeau of Regulation 10.1 itself — a second signal that the Regulation is setting a standard to be applied with judgement, not a closed checklist.
Trigger Nature of the risk What EDD should establish
(a) High-risk jurisdiction Geographic — customer’s location or connections Enhanced verification of identity and purpose given jurisdictional risk
(b) PEP status Person-based — political exposure Source of wealth, source of funds, close-associate mapping
(c) Unusually large, complex or opaque transactions Transaction-based Rationale for the transaction pattern itself
(d) Adverse media or other high-risk indicators Reputational and open-source intelligence Investigation of the specific adverse finding

Does Regulation 10 say what enhanced due diligence actually has to consist of?

No. Regulation 10.1 identifies when EDD is required; it does not itself list the additional steps EDD must include, in the way Regulation 9.2 lists five specific elements for ordinary CDD. This is a gap in the text as we read it — the Regulations require EDD documentation to exist as part of the AML/CFT framework under Regulation 8.2(b), and Form A4’s document confirmation table describes “EDD Procedures” as covering “high-risk customer handling, PEPs, adverse media, high-risk jurisdictions and complex structures,” which lines up closely with Regulation 10.1’s four triggers. But the specific control measures an applicant must apply once EDD is triggered — additional documentary verification, senior management sign-off, more frequent monitoring, or something else — are left to the applicant’s own procedure, subject to PVARA’s assessment of whether that procedure is adequate under Regulation 16.1(b).

How does the PEP trigger connect to the Controller and Beneficial Owner disclosure regime?

Directly, and doubly. A PEP identified as a customer triggers EDD under Regulation 10.1(b) in the ordinary course of onboarding. A PEP identified as a Controller or beneficial owner of the applicant itself is caught separately by Form A2’s own PEP declaration question, which asks not only whether the individual is a PEP, but whether they are “a former PEP, or a close associate/family member of a PEP.” Regulation 9.2(b) already requires verification of all Controllers as part of ordinary CDD; where that verification surfaces PEP status, Regulation 10.1(b) is the provision that escalates the applicant’s own ownership check to the enhanced standard, on the same logic applied to any other customer.

What should an applicant document to evidence EDD compliance?

Three things follow from reading Regulation 10 alongside the wider framework requirements:

  • A documented EDD trigger list that starts from the four items in Regulation 10.1 and extends them, using the applicant’s own enterprise-wide ML/TF risk assessment, to any jurisdiction-specific or product-specific risk factor the “including” language in Regulation 10.1’s chapeau leaves room for.
  • A defined EDD procedure, separate from the CDD procedure, setting out the specific additional steps applied once a trigger is identified — since Regulation 10 itself does not prescribe those steps, the applicant’s own procedure is what PVARA will assess against Regulation 16.1(b)’s “adequacy” standard.
  • A jurisdictional risk reference source, since Regulation 10.1(a) does not define “high-risk jurisdictions” and an applicant should be able to show which external classification — FATF’s own lists, or any PVARA or FMU guidance — its procedure relies on, rather than an undocumented internal judgement.

An applicant that treats EDD as “extra paperwork for a few flagged customers” is reading Regulation 10 too narrowly. The word “including” appears twice in a single provision — once for the list of triggers, once inside the fourth trigger itself — and both instances point the same way: PVARA has drafted a standard that expects the applicant’s own risk judgement to extend beyond the four examples given, not to stop at them.

About this analysis

This analysis was prepared by the CoinConnect research desk from Regulations 8.2(b), 9.2(b), 10.1 and 16.1 of the PVARA No Objection Certificate Regulations 2025, together with Form A2 and Form A4 at Annex A, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect