An NOC is not a general licence to provide any virtual asset service. It opens a narrow door for four specific services and leaves the rest closed. The final paragraph of Regulation 2.3 of the PVARA No Objection Certificate Regulations 2025 draws that line explicitly, and the Virtual Assets Act’s Schedule I shows exactly what sits on the wrong side of it.
This piece sets out which services are excluded, why the exclusion exists, and what it means for an Applicant sequencing its Pakistan launch.
What does the NOC Regulations say about services outside the AML-Registered list?
Regulation 2.3 closes with an express exclusion: “For the avoidance of doubt, all other Virtual Asset Services defined under the Ordinance not otherwise constituted as an AML Registered Service may only be provided following the grant of a full license under Section 17, unless otherwise agreed with PVARA.” The wording “for the avoidance of doubt” signals that this is not a new rule so much as a clarification closing off any argument that AML Registration might extend further than the four named services.
The four services that do fall inside the AML-Registered category — broker-dealer, custody, exchange services and virtual asset derivatives services — are named earlier in the same Regulation. Everything else defined as a virtual asset service under the Ordinance falls outside that list by default.
Which six Schedule I service categories stay locked until full licensing?
Schedule I of the Virtual Assets Act, referenced under section 18, sets out ten categories of virtual asset service in total. Four of those ten are the AML-Registered Services described above. The remaining six are not, and under Regulation 2.3 they require a full licence before an Applicant may provide them.
| Schedule I category | What it covers |
|---|---|
| Advisory Services | Personalised recommendations to a customer about virtual asset transactions |
| Lending and Borrowing Services | Facilitating or directly providing lending or borrowing arrangements involving virtual assets |
| Virtual Asset Management and Investment Services | Acting in a fiduciary or agency capacity to manage another person’s virtual assets, including discretionary staking |
| Virtual Asset Transfer and Settlement Services | Transfer, transmission or settlement of virtual assets between parties, excluding exchange execution |
| Virtual Assets Issuance Services | Creation, issuance, initial offering and ongoing management of virtual assets, including reserve management and redemption |
| Mining-related Virtual Asset Services | Mining operations that provide services to third parties involving customer assets or funds |
Schedule I describes these using the Act’s own definitions rather than the NOC Regulations, which is why the underlying category descriptions come from the Act text and not from the Regulations document itself.
Does this mean an Applicant with an NOC cannot touch these six services at all?
Not entirely, but the default position is that it cannot provide them commercially until a full licence issues. Regulation 2.3’s own text leaves one narrow exception: “unless otherwise agreed with PVARA.” Neither Regulation 2.3 nor the wider Regulations describe what form that agreement would take, what criteria PVARA would apply, or how an Applicant would request it. Where the source document is silent on that mechanism, that gap is stated here rather than filled in with a guess.
Absent such an agreement, an Applicant operating under an NOC should treat these six categories as fully off-limits, not merely discouraged. Regulation 19.1(a) allows PVARA to revoke an NOC where “the Applicant has provided false, misleading or incomplete information,” and an Applicant that represented its business model in Form A1 as limited to AML-Registered Services while quietly also running a lending desk or an advisory practice would be exposed to exactly that risk.
Why did PVARA restrict early access to only four service categories?
The Regulations frame this as a deliberate risk calibration rather than an oversight. Regulation 3.1(g) lists among the Regulations’ objectives the intent “to facilitate a phased regulatory pathway whereby AML-Registered Services may be provided once registration has been completed and the NOC has been issued, and prior to full licensing under the Ordinance.” The four services chosen — dealing, custody, exchange and derivatives — are the core market-facing activities that generate the transaction volume PVARA most needs visibility over through goAML reporting.
Our reading is that the six excluded categories share a common feature that likely explains their exclusion: several of them — issuance, management with discretionary staking, and mining involving customer funds — carry either a fiduciary dimension or a product-design dimension that a lighter, AML-focused registration regime is not built to supervise. The Regulations do not state this reasoning directly, so it is offered here as analysis rather than as a quoted justification.
How does this exclusion interact with the fitness-and-propriety assessment PVARA runs at the NOC stage?
Regulation 16.1 lists the AML/CFT framework for AML-Registered Services specifically as one of the six matters PVARA assesses when reviewing an NOC application — not the framework for the six excluded categories, since those are not yet in scope at the NOC stage. That distinction matters for how an Applicant scopes its Form A4 submission: the AML/CFT framework submission statement should be built around the four AML-Registered Services the Applicant is actually requesting, rather than a generic framework attempting to cover every Schedule I category the business might eventually want to offer.
An Applicant that later applies for a full Section 17 licence covering, say, lending and borrowing services or issuance services will face a fresh assessment of governance, technology and risk controls specific to that category at the licensing stage — the NOC assessment under Regulation 16.1 does not pre-clear those six categories in advance, since they were never part of what the NOC reviewed in the first place.
How should an Applicant plan its service roadmap around this restriction?
Map every planned product line against the ten Schedule I categories before submitting Form A1, not after. Section 2.1 of Form A1 asks the Applicant to list “all Virtual Asset Services for which AML Registration is sought,” restricted on the form itself to the four AML-Registered Services. An Applicant whose actual business model includes, for example, a discretionary staking product under Management and Investment Services needs a plan for when that product can lawfully launch — namely, after a full Section 17 licence is granted, or after securing PVARA’s agreement under the narrow exception in Regulation 2.3 — rather than assuming AML Registration covers it.
- Confirm which of the ten Schedule I categories the business model actually touches.
- Separate the launch-day product set (limited to the four AML-Registered Services) from any product that must wait for full licensing.
- Build the three-month licensing-application clock from Regulation 15.3(c) into the roadmap for every excluded service the business intends to add.
About this analysis
This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025, principally the final paragraph of Regulation 2.3 and Regulation 3.1(g), read alongside Schedule I of the Virtual Assets Act (section 18) for the category descriptions. Where the Regulations do not describe the mechanism behind the “unless otherwise agreed with PVARA” exception, that gap is stated in the text above rather than assumed.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect