Every crypto business eventually has to trust another crypto business. An exchange routes a withdrawal to another exchange. A custodian settles with an OTC desk. A payments firm relies on a liquidity provider it has never met in person. Each of those relationships is a counterparty exposure, and the entity on the other side is what regulators call a VASP — a virtual asset service provider. VASP due diligence is the process of deciding, with evidence, whether that counterparty is safe to transact with, and then re-checking that decision for as long as the relationship lasts.
This is not the same problem as onboarding a retail customer. A customer gives you a passport and a selfie. A counterparty VASP gives you a licensing story spread across four jurisdictions, a compliance program you cannot inspect directly, and thousands of blockchain addresses whose behavior you absolutely can inspect. Teams that treat VASP review as "KYC but bigger" end up with a folder of PDFs that says nothing about where the counterparty's funds actually come from. This guide explains what a defensible VASP due diligence program looks like in 2026, which tools automate the on-chain half of it, and where teams most often get burned.
Quick solution
If you need a working VASP due diligence process this quarter, do this: build a risk-tiered questionnaire covering licensing, ownership, AML program, and sanctions controls; verify the answers against public registers instead of accepting them on faith; pull an on-chain risk profile of the counterparty from an analytics platform such as Chainalysis, Elliptic, or TRM Labs before signing anything; set exposure thresholds that trigger alerts when the counterparty's illicit-source percentage moves; and put every counterparty on a review calendar — annually for low risk, quarterly for high risk. Document each step with dates. A regulator who asks about a counterparty will want the file, not a verbal summary.
Customer due diligence answers one question: is this person who they claim to be, and does their activity match their profile? Counterparty VASP due diligence answers a harder one: is this entire business — its owners, its licenses, its compliance program, and its customer base — something we can safely be connected to?
The customer-base part is what makes crypto counterparty review unique. When a bank evaluates a correspondent bank, it cannot see the correspondent's customers. When a crypto exchange evaluates another exchange, it can see a great deal, because the counterparty's deposits and withdrawals happen on public blockchains. If a meaningful share of the counterparty's inflows arrives from darknet markets, mixers, or sanctioned addresses, that pattern is visible to anyone with the right analytics tooling — before a single dollar of your money is at risk.
Image: Chainalysis — an entity profile for an exchange, with a severe risk score triggered by indirect ransomware exposure and continuous monitoring switched on.
That visibility cuts both ways. Regulators know it exists, which means "we did not know our counterparty was laundering" is no longer a defensible position. The Financial Action Task Force has said repeatedly, most recently in its June 2025 targeted update, that VASPs must apply the same counterparty risk framework banks apply to correspondent relationships — identify the counterparty, assess its AML controls, and understand the nature of its business — with the added expectation that blockchain analytics inform the assessment. Jurisdictions that license VASPs, from Singapore to the EU under MiCA, have written counterparty due diligence obligations directly into their rulebooks.
There is also a commercial reason to care. Correspondent-style relationships in crypto fail suddenly. When a counterparty loses its banking, gets sanctioned, or collapses, funds in transit can be frozen for months. A due diligence file that flagged deteriorating risk three months earlier is the difference between an orderly wind-down and an emergency.
What regulators actually expect in the file
Strip away the jurisdiction-specific language and regulatory expectations for VASP due diligence converge on the same core file. Before establishing the relationship, you should be able to show five things.
First, corporate identity: legal name, registration number, jurisdiction of incorporation, and ultimate beneficial owners past whatever holding-company layers exist. Second, licensing status: which regulators actually supervise this entity, verified against the regulator's own public register rather than the counterparty's marketing page. Third, the AML program: policies, the name and qualifications of the compliance officer, independent audit results, and how the counterparty screens its own customers. Fourth, sanctions posture: which lists the counterparty screens against, how fast it implements new designations, and whether it serves customers in comprehensively sanctioned jurisdictions. Fifth, the on-chain risk profile: measured exposure to illicit categories across the counterparty's known addresses.

Image: Chainalysis — a monitoring alert flagging that a tracked exchange's risk score increased to severe after crossing an exposure threshold.
The first four items look like classic financial-institution due diligence, and they are. The Wolfsberg-style questionnaire approach — a standardized set of questions the counterparty answers in writing — remains the backbone. But questionnaires are self-reported. The counterparty's compliance officer fills in the boxes, and you are trusting that the answers are accurate today and will stay accurate next year. The fifth item is the crypto-native check that keeps the other four honest. If the questionnaire says "we do not serve sanctioned jurisdictions" and the on-chain profile shows steady flows to addresses in one, you have learned something no PDF would ever have told you.
Scale of the problem is worth internalizing. Chainalysis measured tens of billions of dollars leaving illicit wallets for conversion services every year — over 30 billion dollars at the 2022 peak. Conversion services means exchanges and other off-ramps. Some of that value crossed a VASP that a compliant business was transacting with at the time.

Image: Chainalysis — measured value flowing from illicit wallets to conversion services each year from 2019 to 2024. Every dollar of it passed through somebody's counterparty.
More in Guides
The five pillars of a working program
A program that survives both a regulator's exam and a real counterparty failure rests on five pillars.
Risk tiering before depth. Not every counterparty deserves the same file. A licensed exchange in your own jurisdiction that you settle with daily is a different exposure than an offshore OTC desk you use twice a year. Tier counterparties by volume, jurisdiction, licensing, and on-chain profile, and let the tier set the depth of review and the refresh cadence. Most programs use three tiers; more than four collapses into busywork.
Independent verification. Every material claim in the questionnaire gets checked against an external source: the corporate register for ownership, the regulator's license register for authorization, sanctions lists for principals and owners, and blockchain analytics for the customer-base claim. The questionnaire tells you what the counterparty says; verification tells you what is true.
Quantified on-chain assessment. "We looked at their addresses" is not an assessment. A defensible one states the counterparty's direct and indirect exposure to each illicit category — sanctions, darknet markets, ransomware, scams, mixers, no-KYC exchanges — as percentages of flow over a defined window, from a tool whose methodology you can explain. Direct exposure means the counterparty transacted straight with an illicit address. Indirect means value reached it through intermediaries, which matters because layering through clean-looking hops is exactly how laundering works.
Thresholds with owners. Decide in advance what number triggers what action. For example: indirect sanctions exposure above one percent triggers enhanced review within five business days; any direct darknet exposure triggers escalation to the MLRO; sustained deterioration over two quarters triggers relationship review. A threshold without a named owner and a deadline is a dashboard decoration.
Documented decisions. Every approval, every exception, every risk acceptance gets written down with the evidence that supported it and the name of the person who made the call. When a counterparty later fails, the question will not be "did you know?" but "what did you know, when, and what did you do about it?" The file is your answer.
The manual half of VASP due diligence — registers, questionnaires, license checks — has resisted automation. The on-chain half has not. Modern analytics platforms maintain attribution databases mapping millions of addresses to named services, which turns "assess this counterparty's customer base" from an impossible task into a query.
A typical workflow: look up the counterparty in the platform's entity database, pull its current risk score and the exposure breakdown behind it, and drill into anything severe. The platforms visualize how funds reached the counterparty, which converts an abstract percentage into a concrete story you can put in the file.

Image: Chainalysis — a due diligence graph tracing funds from multiple source addresses through a mixer into an exchange, with darknet market exposure flagged in the insight panel.
Exposure views break the picture down by category and time. Instead of a single score, you see which illicit categories the value came from and when, which lets you distinguish a counterparty with an old, resolved problem from one whose risk is trending up right now.

Image: Chainalysis — an exposure timeline for a monitored counterparty. One spike day is dominated by inflows from a no-KYC exchange, exactly the pattern a threshold should catch.
Benchmarking closes the loop. An exposure number in isolation is hard to act on — is two percent indirect mixer exposure bad? Benchmarking views compare a counterparty's risk profile against its peer group, so you can see whether it behaves like a regulated exchange or like the no-KYC platforms it claims not to resemble.

Image: Chainalysis — benchmarking a monitored counterparty against the exchange peer group and the no-KYC peer group over time.
One caution: attribution coverage differs between vendors, and none of them sees everything. A counterparty that looks clean may simply have addresses the vendor has not attributed yet. That is why on-chain assessment complements the questionnaire instead of replacing it, and why serious programs record which tool, which date, and which address set produced each number.
Comparing VASP due diligence platforms
Because no single public source compares counterparty VASP due diligence capabilities side by side, we compiled one from vendor documentation, product pages, and regulatory guidance reviewed in early 2026. Verify current capabilities directly with vendors — this market moves quickly.
| Platform | Counterparty focus | Entity risk scores | Continuous monitoring | Peer benchmarking | Best fit |
|---|---|---|---|---|---|
| Chainalysis | Dedicated VASP screening and entity profiles | Yes, with severity tiers and exposure triggers | Yes, with alerting on score changes | Yes, against exchange peer groups | Exchanges and institutions standardizing on one attribution set |
| Elliptic | Discovery product for VASP risk profiles | Yes, holistic VASP scores | Yes | Partial | Teams wanting broad asset coverage in one screen |
| TRM Labs | VASP screening within its risk suite | Yes | Yes | Partial | Agencies and institutions already on TRM for investigations |
| Notabene | Counterparty checks embedded in Travel Rule flows | Via integrated analytics partners | Transaction-time checks | No | Teams that want due diligence wired into Travel Rule messaging |
| Merkle Science | Entity screening within compliance platform | Yes | Yes | No | Asia-Pacific focused businesses |
| ComplyAdvantage | Corporate and sanctions screening, limited on-chain | Corporate risk, not address-level | Yes for list changes | No | The off-chain half: owners, PEPs, adverse media |
The practical pattern we see: one blockchain analytics platform for the on-chain half, one corporate screening tool for owners and adverse media, and a questionnaire process stitched around both. Teams already running crypto sanctions screening tools usually extend the same vendor to counterparty work, because sharing one attribution database between transaction screening and counterparty review means both functions flag the same address the same way.
The most common structural failure in VASP programs is treating due diligence as a gate you pass once. A counterparty approved in January can be a different business by June — new owners, a lost license, a compromised hot wallet, or a drifting customer base. Point-in-time review catches none of that.
Continuous monitoring means three feeds. On-chain: the analytics platform watches the counterparty's exposure and alerts when a threshold trips or the risk score jumps, as in the severe-score alert shown earlier. Off-chain: sanctions list updates, license register changes, and adverse media on the entity and its principals. Relationship data: your own settlement volumes and patterns with the counterparty, which your crypto AML compliance software already tracks and which should feed the same case queue.
Cadence then follows tier. High-risk counterparties get a quarterly refresh of the full file; low-risk ones get an annual refresh plus event-driven review whenever an alert fires. If your counterparties are also Travel Rule counterparties, align the two programs — the counterparty you exchange travel rule compliance messages with is the same entity you are risk-assessing, and running the two files separately doubles the work while halving the visibility.
Common mistakes that undermine the file
- Accepting the questionnaire as evidence. A completed questionnaire is a claim, not a fact. Programs that skip independent verification of licensing and ownership routinely discover, mid-crisis, that the "regulated" counterparty held a lapsed registration in a different entity's name.
- Scoring the entity but not the flows. A counterparty's corporate paperwork can be immaculate while its inflows are toxic. If your file contains no measured exposure percentages, you have assessed the shell and ignored the business.
- Setting thresholds nobody owns. An alert that routes to a shared inbox is an alert that ages silently. Every threshold needs a named owner, a response deadline, and an escalation path — otherwise monitoring generates evidence of what you ignored.
- Reviewing on a calendar but never on events. Annual review cycles miss the sanctions designation that happened in week three. Event-driven triggers — score changes, list updates, license actions — must be able to pull a review forward, or the calendar becomes a liability.
"We are a mid-size exchange and our banking partner just asked for our counterparty risk framework as a condition of keeping the account." This is the most common trigger we hear. Banks extend their own correspondent logic to crypto clients, and an exchange that cannot produce tiering, thresholds, and monitoring evidence looks like an unmanaged risk. The five-pillar file in this guide maps almost one-to-one onto what bank compliance teams expect to see.
"We are a payments company adding crypto off-ramps, and we need to pick three liquidity providers from a list of twelve." Use due diligence as a selection filter, not just an approval gate. Pull entity risk profiles on all twelve before commercial conversations get serious — the on-chain screen typically disqualifies a few candidates in an afternoon, before anyone has spent a week on questionnaires.
"We are a custodian and a client is asking us to settle with a counterparty we have never reviewed." Client-directed counterparties are still your exposure. A fast-track tier — register check, sanctions screen of principals, entity risk profile, documented approval — lets you respond in days while keeping the decision defensible. What you cannot do is let the client's urgency substitute for the file.
Frequently asked questions
What counts as a VASP for due diligence purposes?
The FATF definition covers any business conducting exchange between virtual assets and fiat, exchange between virtual assets, transfer of virtual assets, custody, or participation in financial services around issuance. Practically: exchanges, custodians, OTC desks, payment processors, and many brokerage services. If a counterparty touches customer crypto as a business, run the process.
How is VASP due diligence different from Travel Rule compliance?
The Travel Rule governs the data you exchange with a counterparty about each transfer's originator and beneficiary. Due diligence governs whether you should have the relationship at all. They intersect — you must assess a counterparty before trusting it with Travel Rule data — but a Travel Rule integration is not a due diligence file, and vice versa.
What illicit exposure percentage should block a counterparty?
There is no regulatory bright line, which is why your program must set its own and document the rationale. Common practice treats any direct exposure to sanctioned entities as a hard stop, sets single-digit percentage triggers for indirect exposure to severe categories, and judges the trend as much as the level. A rising line at two percent is worse than a stable line at three.
How often should counterparty reviews be refreshed?
Tier-driven: annually for low risk, semi-annually for medium, quarterly for high — plus event-driven reviews whenever monitoring fires. The event-driven half matters more than the calendar half, because counterparty failures cluster around events, not anniversaries.
Can a small team run this without dedicated staff?
Yes, if it automates the on-chain half and keeps tiers honest. A two-person compliance function can maintain files on twenty counterparties using platform monitoring for the continuous piece and reserving manual effort for onboarding and escalations. What a small team cannot afford is a program designed for fifty counterparties applied to five hundred — cut the counterparty list before cutting the depth.
Sources
- Financial Action Task Force, "Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers," June 26, 2025.
- Chainalysis, "Money Laundering and Cryptocurrency" report, July 2024.
- Chainalysis, "2025 Crypto Crime Report," February 2025.




