A licensed Virtual Asset Service Provider in Pakistan does not sit in a separate compliance category from a bank or a securities firm when it comes to anti-money laundering law. Section 46 of the Virtual Assets Act 2026 puts it inside the same statutory category — deemed a financial institution — and pulls in an entire body of obligations by reference.
This piece explains what that deeming provision does, the three baseline obligations Section 46(2) sets out expressly, and how the arrangement connects to the Financial Monitoring Unit and the wider AML/CFT framework administered by PVARA.
What does it mean for a VASP to be “deemed” a financial institution?
It means the Anti-Money Laundering Act 2010 (“AMLA 2010”) applies to a licensed VASP as if it were a financial institution in the ordinary sense, even though a virtual asset business does not fit the traditional description of a bank or a securities dealer. Section 46(1) of the Act states this directly:
“46.(1) For the purposes of the Anti-Money Laundering Act, 2010 (VII of 2010), Virtual Asset Service Providers licensed under this Act shall be deemed to be financial institutions, and shall comply with all obligations thereunder.”
A “deeming” provision of this kind is a drafting technique that avoids having to rewrite AMLA 2010 itself to add virtual assets as a named category. Instead, the Virtual Assets Act reaches into AMLA 2010 and pulls a licensed VASP inside its scope by legal fiction — “shall be deemed” — so that every obligation AMLA 2010 places on a financial institution now also binds a licensed VASP, without AMLA 2010’s own text needing to change.
What are the three baseline obligations Section 46(2) sets out?
Section 46(2) does not stop at the general deeming clause — it names three specific duties that apply to “every Virtual Asset Service Provider and Issuer,” a formulation that reaches beyond licensed VASPs alone to cover Issuers as well:
“46.(2) Without prejudice to sub-section (1), every Virtual Asset Service Provider and Issuer shall— (a) report suspicious transactions to the Financial Monitoring Unit (FMU) in accordance with Anti-Money Laundering Act, 2010 (VII of 2010) and any rules, regulations or guidelines issued thereunder; (b) maintain records of customer due diligence, transactions and other relevant information for the period prescribed under Anti-Money Laundering Act, 2010 (VII of 2010); and (c) establish and maintain internal controls and compliance programmes to prevent money laundering and terrorist financing, including the appointment of an AML, CFT or CPF compliance officer.”
| Obligation | What it requires | Basis |
|---|---|---|
| Suspicious transaction reporting | Report to the FMU in line with AMLA 2010 and any rules or guidance issued under it | Section 46(2)(a) |
| Recordkeeping | Retain customer due diligence, transaction and related records for the period AMLA 2010 prescribes | Section 46(2)(b) |
| Internal controls | Maintain internal controls and a compliance programme, including an AML, CFT or CPF compliance officer | Section 46(2)(c) |
The phrase “without prejudice to sub-section (1)” signals that these three duties are not the full extent of what Section 46(1)’s deeming clause imports — they are specific obligations the drafters chose to spell out expressly, on top of the general “all obligations thereunder” language in Section 46(1).
Does this mean a VASP has to register separately with the FMU?
Registration with the FMU’s goAML platform is handled through the NOC process rather than as a freestanding step. Regulation 11.4 and 11.5 of the PVARA No Objection Certificate Regulations 2025 set out the sequence: following NOC issuance, the Applicant (or its foreign chapter already providing services in Pakistan) registers as the reporting entity on goAML; once the local entity is incorporated and granted a full licence, that local entity assumes the reporting-entity role and “must maintain active reporting credentials at all times.” Regulation 11.6 requires the Applicant to demonstrate technical readiness to file Suspicious Transaction Reports (“STRs”) and Currency Transaction Reports (“CTRs”) immediately upon goAML registration — the readiness obligation is live from the point of registration, not deferred to first use.
How does PVARA’s supervisory role fit alongside AMLA 2010?
Section 46(3) assigns PVARA a specific alignment function rather than leaving AMLA 2010 compliance entirely to the FMU:
“46.(3) The Authority shall, through AML, CFT or CPF Regulations, align its supervisory framework with the standards of the Financial Action Task Force (FATF) and may issue additional guidance, consistent with FMU’s mandate, to address risks specific to Virtual Assets.”
PVARA’s role here is supervisory and guidance-issuing, calibrated to FATF’s international standards and to risks specific to virtual assets, while staying “consistent with FMU’s mandate” — meaning PVARA is not positioned to override or duplicate the FMU’s own statutory role as Pakistan’s financial intelligence unit under AMLA 2010, but to build a virtual-asset-specific supervisory layer alongside it.
How does this connect to the travel rule and real-time reporting duties elsewhere in the Act?
Section 46 sits at the head of Chapter 8 of the Act, which goes on to set additional AML-adjacent duties for Licensees specifically — narrower in scope than Section 46(2)’s “every VASP and Issuer” language. Section 47 requires a Licensee to obtain, hold and transmit originator and beneficiary information for virtual asset transfers meeting a prescribed threshold, consistent with FATF recommendations — the so-called travel rule — and to retain related records for a period “not less than the period required under” AMLA 2010. Section 48 requires Licensees to establish secure reporting channels and, where required, automated interfaces giving PVARA and other notified agencies access to prescribed data. Read together with Section 46, the pattern is a deeming clause that imports the AMLA 2010 baseline, followed by virtual-asset-specific reporting and record-transmission duties layered on top of it.
Does the NOC Regulations’ AML-Registered Services designation sit consistently with this deeming clause?
There is a point worth flagging rather than glossing over. Regulation 2.3 of the NOC Regulations designates four specific services — Broker-Dealer, Custody, Exchange and Virtual Asset Derivative Services — as “non-financial businesses and professions in accordance with Section 38(1) of the Ordinance” for the purposes of AML registration on the goAML portal, once an NOC is granted. That designation, “non-financial business,” sits alongside Section 46(1)’s “deemed to be financial institutions” language, and the two use different classification labels drawn from different instruments — the Act as finally passed, and the earlier Virtual Assets Ordinance 2025 the NOC Regulations were issued under. Our reading is that this is not necessarily a contradiction: AMLA 2010’s own framework recognises both “financial institutions” and “non-financial businesses and professions” as reporting-entity categories, and the NOC Regulations’ designation governs the interim AML-registered phase before a full licence, while Section 46(1)’s deeming clause governs the fully licensed VASP. But the source documents do not state explicitly how the two labels reconcile, and a reader relying on either classification for a specific compliance purpose should confirm the applicable category with PVARA or the FMU directly.
What should a VASP take from the deeming provision in practice?
The practical effect of Section 46 is that a VASP cannot treat its AML/CFT obligations as bespoke or self-designed. Because AMLA 2010 obligations attach by deeming, a VASP’s compliance programme has to be built against the AMLA 2010 baseline first, with the Virtual Assets Act’s own additional duties — travel rule compliance under Section 47, real-time reporting interfaces under Section 48, and the nine-part AML/CFT framework PVARA’s NOC Regulations require in more granular form — layered on top, not substituted for it.
About this analysis
This analysis was prepared by the CoinConnect research desk from Sections 46, 47 and 48 of the Virtual Assets Act 2026, and Regulations 2.3, 11.4, 11.5 and 11.6 of the PVARA No Objection Certificate Regulations 2025, as published. Where the classification used in the NOC Regulations and the deeming language in Section 46(1) appear to use different labels, that is noted in the text above rather than resolved by assumption.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect