BriteBase
Industry primer · VASPs

VASP compliance primer: AML and sanctions expectations for Canadian crypto firms

A virtual asset service provider (VASP) is captured under Canadian law as a money services business where it deals in virtual currency for the public. The label "VASP" comes from the FATF, but the operational obligations come from the PCMLTFA, FINTRAC guidance, and Canadian sanctions law. This primer covers the regulatory framework, the Travel Rule, the Large Virtual Currency Transaction Report, blockchain analytics expectations, sanctioned-wallet screening, the technology stack, and the in-house expertise Canadian crypto firms need.

By BriteBase team · Published June 4, 2026 · 13 min read

Canadian crypto firms operate under the same PCMLTFA regime as any other money services business, with two important additions: the Travel Rule on virtual currency transfers, and the Large Virtual Currency Transaction Report (LVCTR) at CAD $10,000. Layered on top, sanctions screening for virtual asset service providers now extends to wallet addresses, not just names. This primer is the operating manual for a Canadian VASP.

What is a VASP under Canadian law?

"VASP" is the term used by the Financial Action Task Force (FATF) for entities that deal in virtual assets. Canadian law does not use the term VASP directly. Instead, the PCMLTFA captures crypto firms as money services businesses (MSBs) where they deal in virtual currency for the public. Dealing in virtual currency includes:

  • Exchanging virtual currency for fiat (and vice versa).
  • Exchanging one virtual currency for another.
  • Transferring virtual currency at the direction of a customer.
  • Providing custody or holding accounts for virtual currency on behalf of customers.

A foreign crypto firm that directs services at Canadian customers is treated equivalently and must register with FINTRAC as a foreign MSB.

Registration with FINTRAC

Every Canadian VASP and every foreign VASP serving Canadian customers must register with FINTRAC as a money services business before its first virtual currency activity. Registration must be renewed every two years. The FINTRAC MSB guidance sets out the process. Securities regulators (CSA and provincial commissions) may impose additional registration where a virtual asset is also a security or a derivative; this primer focuses on the AML and sanctions framework.

What are the five PCMLTFA program pillars for VASPs?

The five pillars are the same as for any reporting entity (CAMLO, risk assessment, policies and procedures, training, independent effectiveness review). Two pieces of that framework are VASP-specific in operation.

1. The risk assessment

A VASP risk assessment must explicitly cover virtual currency risk drivers: the pseudonymous nature of on-chain activity, cross-border-by-default settlement, mixing and tumbling, privacy coins, sanctioned address exposure, unhosted wallet activity, and the specific protocols and chains the VASP supports. A generic MSB risk assessment is insufficient.

2. The CAMLO’s scope

The Chief Anti-Money Laundering Officer needs working knowledge of blockchain analytics, the Travel Rule landscape, and the operational realities of unhosted-wallet due diligence. Many late-stage VASPs operate with a fractional CAMLO who specialises in crypto compliance.

What are the three layers of a VASP compliance program?

The three layers of a VASP compliance program, with VASP-specific items at each layer.

GOVERNANCE What the firm owns CAMLO appointment VC risk assessment Policies Travel Rule policy Independent review OPERATIONS What the firm operates Wallet attribution Sanctions and PEP Counterparty DD LVCTR / STR Unhosted wallet DD TECHNOLOGY What the firm runs on KYC platform Blockchain analytics Wallet screening Travel Rule protocol Case workflow

Which reports does a VASP have to file?

Report Threshold Who files Deadline
Suspicious Transaction Report (STR)No threshold; suspicion testVASP (as MSB)As soon as practicable after reasonable grounds to suspect
Large Virtual Currency Transaction Report (LVCTR)CAD $10,000 in virtual currency in 24 hoursVASP receiving virtual currencyWithin 5 working days
Electronic Funds Transfer Report (EFTR)International fiat EFT of CAD $10,000 or moreVASP sending or receiving fiat internationallyWithin 5 working days
Travel Rule information (transmission obligation)CAD $1,000 or more virtual currency transferVASP originating or receiving the transferOn or before settlement
Terrorist Property Report (TPR)Property in possession of a listed personVASPImmediately

The LVCTR is the VASP-specific report. It is filed for receipts of virtual currency at CAD $10,000 or more (single or aggregated over 24 hours) and requires the same originator and beneficiary information as the Travel Rule. Filing through FINTRAC’s F2R channels is the standard route.

What does the Travel Rule require for virtual currency transfers?

The Travel Rule under the PCMLTFA requires that originator and beneficiary information travel with a virtual currency transfer at CAD $1,000 or more. The minimum data set is:

  • Originator (sender). Name, account number or unique transaction reference (the transaction hash for virtual currency), and address.
  • Beneficiary (recipient). Name and account number or unique reference.
  • Transfer details. Amount, virtual currency type, and timestamp.

Canada accepts compliant counterparty messaging protocols, including IVMS 101-aligned protocols such as TRP, OpenVASP, and TRISA, provided the information that ends up captured matches the regulatory minimum. The full requirements explainer is the Travel Rule primer; the most common failure modes are covered in Crypto and the Travel Rule.

What due diligence applies to unhosted wallets?

Where a counterparty wallet is unhosted (self-custodied, no VASP on the other side to message with), FINTRAC expects the Canadian VASP to conduct enhanced due diligence on the customer and on the destination wallet. Reliance on counterparty messaging that does not exist is not an acceptable substitute. Typical controls include:

  • Customer attestation of unhosted wallet control (cryptographic proof of control through signed message or micro-deposit).
  • Blockchain analytics screening of the destination wallet against sanctioned addresses, known mixers and tumblers, darknet markets, ransomware-associated clusters, and exchange-of-illicit-funds patterns.
  • Risk-based limits on unhosted-wallet transfer size or frequency.
  • Documented rationale for any unhosted transfer above a defined threshold.

What are a VASP’s sanctions screening obligations?

Canadian VASPs screen at three levels:

  • Name-based screening. Customers, beneficial owners, and (where transferred fiat goes international) transfer parties against SEMA, JVCFOA, the UN Act regulations, and the Criminal Code listed entities. The OSFI Consolidated Lists are the practical source.
  • Wallet-address screening. Every deposit and withdrawal against lists of sanctioned wallet addresses. OFAC SDN-listed crypto addresses (including the Tornado Cash-adjacent and Garantex-associated addresses) are the most actively-tracked, but Canadian VASPs should also screen against the addresses associated with Canadian-listed entities.
  • On-chain exposure analysis. Blockchain analytics that surface indirect exposure to sanctioned addresses through transaction chains. Direct screening alone misses the most common evasion patterns.

Canadian VASPs that serve US-jurisdiction users or interact with US-domiciled counterparties should also screen against the OFAC SDN list. US extraterritorial sanctions enforcement reaches non-US VASPs through US correspondent banking and US dollar settlement.

What does the VASP technology stack need to cover?

A defensible Canadian VASP technology stack covers seven capabilities:

  • KYC and identity verification. Document authenticity, liveness, name and address verification, beneficial ownership.
  • Sanctions and PEP name screening. Real-time at onboarding and continuously on the customer book.
  • Wallet-address screening. Real-time at every deposit and withdrawal. Sanctioned address lists, mixer and tumbler lists, exchange of illicit funds patterns.
  • Blockchain analytics. On-chain transaction tracing, cluster attribution, exposure scoring, and case investigation. Major providers include Chainalysis, TRM Labs, and Elliptic.
  • Travel Rule messaging. An IVMS 101-aligned protocol (TRP, OpenVASP, TRISA) with counterparty discovery, secure transmission, and audit trail.
  • Transaction monitoring. Rules tuned to VC-specific patterns: structuring around the LVCTR threshold, rapid in-and-out patterns, mixer/tumbler indirect exposure, sanctioned-address proximity.
  • Case management. One workflow that holds alerts, blockchain analytics output, customer files, dispositions, and LVCTR and STR drafting.

What in-house expertise does a VASP need?

A Canadian VASP at meaningful volume needs:

  • CAMLO with crypto and AML experience. Named compliance officer with current PCMLTFA knowledge, working understanding of blockchain analytics, and authority to halt activity. Fractional CAMLO is the standard pattern for late-stage VASPs without in-house leadership.
  • Blockchain analytics analysts. Investigators who can read on-chain activity, work with Chainalysis or equivalent tooling, and document findings for STR or LVCTR support.
  • Sanctions specialist. Owns the wallet-screening engine, list updates (including OFAC SDN crypto addresses where applicable), and disposition policy.
  • Counterparty due diligence lead. Owns the policy and operations for unhosted wallet transfers and counterparty VASP discovery under the Travel Rule.
  • Independent reviewer. Engaged for the two-year PCMLTFA effectiveness review. Should have prior VASP examination experience.

What do FINTRAC examiners look for in a VASP?

The questions a current FINTRAC examination of a VASP tends to lead with:

  • Walk me through how you capture and transmit Travel Rule information for a virtual currency transfer above CAD $1,000.
  • Show me the wallet-screening result for a deposit from a sanctioned address and your disposition rationale.
  • How do you handle an unhosted wallet withdrawal at the customer’s request, and what is the documented threshold?
  • Walk me through an LVCTR filing end to end, including the underlying case file and the originator information.
  • Where is the audit trail for blockchain analytics output that contributed to a closed alert?

How does BriteBase help Canadian VASPs?

The BriteBase screening platform integrates KYC and KYB screening, real-time sanctions, PEP, and adverse-media screening, ongoing monitoring, alert triage, and the full audit trail. VASPs can embed it through the self-serve screening API or run the unified case management interface, with every disposition recorded as audit-ready case history.

FAQ

What is a VASP under Canadian law?

'VASP' is a Financial Action Task Force term for entities that deal in virtual assets, but Canadian law does not use it directly. Instead, the PCMLTFA captures crypto firms as money services businesses under section 5(h) where they deal in virtual currency for the public. Dealing in virtual currency includes exchanging virtual currency for fiat and the reverse, exchanging one virtual currency for another, transferring virtual currency at the direction of a customer, and providing custody or holding accounts for virtual currency on behalf of customers. A foreign crypto firm that directs services at Canadian customers is treated equivalently and must register with FINTRAC as a foreign MSB. So the label comes from the FATF, but the operational obligations come from the PCMLTFA, FINTRAC guidance, and Canadian sanctions law. Understanding that a VASP is legally an MSB is the starting point: the whole MSB framework applies, plus virtual-currency-specific additions.

Do Canadian crypto firms have to register with FINTRAC?

Yes. Every Canadian crypto firm dealing in virtual currency for the public, and every foreign crypto firm that serves Canadian customers, must register with FINTRAC as a money services business before conducting its first virtual currency activity. Registration must be renewed every two years, and the FINTRAC MSB guidance sets out the process. Registering as an MSB is the AML and sanctions entry point, but it is not necessarily the only registration a crypto firm needs. Securities regulators, meaning the Canadian Securities Administrators and the provincial commissions, may impose additional registration where a virtual asset is also a security or a derivative. That securities layer sits alongside, not instead of, the FINTRAC obligation. A firm that assumes MSB registration covers every regulatory relationship can miss the securities dimension entirely. The AML and sanctions framework is the focus here, and for that framework FINTRAC registration before first activity is mandatory and non-negotiable.

What is the LVCTR?

The Large Virtual Currency Transaction Report (LVCTR) is the virtual-currency-specific report a Canadian VASP files with FINTRAC. It is triggered when the VASP receives CAD $10,000 or more in virtual currency, either in a single transaction or in multiple related transactions aggregated over 24 hours. The filing window is within five working days of the transaction. The required information includes originator and beneficiary details consistent with the Travel Rule, so the same data set that has to travel with a transfer also feeds the report. Filing runs through FINTRAC's F2R channels, which is the standard route for all MSB reporting. The LVCTR is the virtual currency analogue of the Large Cash Transaction Report that applies to cash-handling MSBs. Because the threshold aggregates over 24 hours, a VASP cannot avoid the report by splitting one receipt into smaller amounts, and its transaction monitoring should watch for structuring around the CAD $10,000 line.

Does Canada’s Travel Rule apply to virtual currency transfers?

Yes. Under the PCMLTFA, originator and beneficiary information must travel with a virtual currency transfer at CAD $1,000 or more, on or before settlement. The minimum data set has three parts. For the originator, or sender, it is the name, an account number or unique transaction reference (the transaction hash for virtual currency), and address. For the beneficiary, or recipient, it is the name and an account number or unique reference. The transfer details cover the amount, the virtual currency type, and a timestamp. Canada accepts compliant counterparty messaging protocols, including IVMS 101-aligned protocols such as TRP, OpenVASP, and TRISA, provided the information that ends up captured matches the regulatory minimum. The protocol choice is less important than the completeness of the data. A VASP that transmits a message missing a required field has not met the obligation, even if it used an accepted protocol, so field-level completeness is what examiners test.

How should a Canadian VASP handle transfers to unhosted wallets?

Where the counterparty wallet is unhosted (self-custodied, with no VASP on the other side to message with), FINTRAC expects the Canadian VASP to conduct enhanced due diligence on both the customer and the destination wallet. Reliance on counterparty messaging that does not exist is not an acceptable substitute. Typical controls include customer attestation of unhosted wallet control, evidenced by cryptographic proof through a signed message or a micro-deposit; blockchain analytics screening of the destination wallet against sanctioned addresses, known mixers and tumblers, darknet markets, ransomware-associated clusters, and exchange-of-illicit-funds patterns; risk-based limits on unhosted-wallet transfer size or frequency; and a documented rationale for any unhosted transfer above a defined threshold. The common thread is that the VASP cannot lean on another regulated intermediary, so it has to build its own evidence that the wallet is controlled by the customer and is not connected to illicit activity before allowing the transfer.

What sanctions screening do Canadian VASPs need beyond names?

Beyond name-based screening, Canadian VASPs need wallet-address screening and on-chain exposure analysis. Wallet-address screening runs at every deposit and withdrawal against lists of sanctioned wallet addresses, known mixers and tumblers, darknet markets, and ransomware-associated clusters. On-chain exposure analysis uses blockchain analytics to surface indirect exposure to sanctioned addresses through transaction chains, because direct address screening alone misses the most common evasion patterns, where funds pass through intermediate hops rather than moving straight from a listed wallet. The address lists include OFAC SDN-listed crypto addresses where applicable, with the Tornado Cash-adjacent and Garantex-associated addresses among the most actively tracked, as well as addresses associated with Canadian-listed entities. Screening a name against sanctions lists tells the VASP who the customer is, but it says nothing about where the crypto came from or is going. Only address and on-chain screening close that gap, which is why FINTRAC expects both alongside conventional name screening.

What in-house expertise does a Canadian VASP need?

A Canadian VASP at meaningful volume needs a compliance team built around crypto-specific expertise. The CAMLO must hold current PCMLTFA knowledge, a working understanding of blockchain analytics, and the authority to halt activity; a fractional CAMLO who specialises in crypto compliance is the standard pattern for late-stage firms without in-house leadership. Blockchain analytics analysts read on-chain activity, work with Chainalysis or equivalent tooling, and document findings to support STR or LVCTR filings. A sanctions specialist owns the wallet-screening engine, list updates including OFAC SDN crypto addresses where applicable, and disposition policy. A counterparty due diligence lead owns the policy and operations for unhosted wallet transfers and counterparty VASP discovery under the Travel Rule. An independent reviewer, ideally with prior VASP examination experience, is engaged for the two-year effectiveness review. Higher-volume VASPs typically add a regulatory affairs lead. The common requirement across every role is genuine crypto fluency, not generic MSB compliance experience.

Back to all resources

Reading is useful. A conversation is faster.

Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.

Book a call
Prefer to talk now? Email hello@gobritebase.com