[codicts-css-switcher id=”346″]

Global Law Experts Logo
vasp licensing ukraine

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

How to Obtain a VASP Licence in Ukraine, Registration, NSSMC/NBU Supervision and AML Obligations

By Jonathon Richards
– posted 55 minutes ago

Introduction, why this guide matters now

VASP licensing Ukraine has moved from a question of legislative design to one of practical implementation, and for crypto founders, exchanges, custodians and token issuers the window to align early is narrowing. Ukraine adopted its Virtual Assets Law to create a formal framework for virtual asset service providers (VASPs), and attention has now shifted to how that framework is enforced in practice. Supervisory expectations are sharpening, anti-money-laundering (AML) frameworks are under closer review, and the authorities responsible for licensing are preparing to receive and scrutinise applications.

For any company contemplating vasp licensing Ukraine as part of its market-entry or compliance strategy, understanding the sequence of steps, the documents required and the supervisory relationships involved is now a commercial priority, not a theoretical exercise.

This guide sets out, in practical terms, what vasp licensing Ukraine involves. It explains the legal framework and who regulates virtual asset activity, maps the step-by-step application and registration process, details the documents you must prepare, and unpacks the AML/CFT obligations that apply from day one. It also addresses how to engage with the National Securities and Stock Market Commission (NSSMC), the National Bank of Ukraine (NBU) and the State Financial Monitoring Service, together with indicative timelines, costs and post-licensing duties. Throughout, we cite primary legal and regulatory sources so that each major claim is grounded in authoritative material rather than secondary summaries.

The legal framework and who regulates VASPs in Ukraine

The foundation of vasp licensing Ukraine is the Law of Ukraine “On Virtual Assets”, adopted by the Verkhovna Rada to define virtual assets, categorise service providers and establish the licensing regime. It operates alongside Ukraine’s AML/CFT legislation, which imposes financial-monitoring duties on obliged entities.

Key laws and regulators

The supervisory split places the NSSMC in the lead regulatory and licensing role for VASPs, while the NBU retains influence where crypto activity touches money transmission and the financial system. The SFMS sits across all obliged entities for AML reporting. Understanding this division early avoids misdirected applications and duplicative engagement.

From framework to enforcement, current trends and regulator focus

The trajectory of vasp licensing Ukraine is one of movement from statute to supervisory practice. As implementation matures, several themes are visible to industry observers monitoring regulator communications and international standards.

  • Sharper AML/CFT expectations: regulators are expected to scrutinise the quality and operability of AML frameworks rather than accept policies that exist only on paper, consistent with FATF guidance on virtual assets.
  • Compliance-officer accountability: the appointment of a qualified compliance officer (MLRO) with genuine authority is treated as a substantive licensing condition, not a formality.
  • Increased scrutiny of foreign entrants: applicants with cross-border ownership and offshore structures should expect closer review of beneficial ownership and source of funds.
  • Alignment with FATF standards: Ukraine’s framework reflects the FATF “travel rule” and risk-based approach, so technical readiness to capture and transmit counterparty data is increasingly relevant.
  • Transparency and governance: regulators favour demonstrable internal controls, segregation of client assets and clear reporting lines.

The practical consequence is that firms treating vasp licensing Ukraine as a documentation exercise alone will struggle. The regulator wants evidence that controls function in operation.

How to get a VASP licence in Ukraine, step-by-step

The route to a Ukraine crypto license follows a logical sequence. The steps below describe what each stage demands, the typical pitfalls, and the documents to assemble. Treat these as a working map for vasp registration Ukraine, adapting the detail to your specific business model.

Step 1, Decide your business model and VASP activity scope. Determine precisely which regulated activities you will perform: exchange of virtual assets for fiat or other assets, custody and administration of virtual assets, brokerage or intermediation, or issuance. The Virtual Assets Law distinguishes categories of service, and the scope you select drives the licence type, the capital and governance expectations, and the depth of technical controls required. A common pitfall is applying for a narrow scope and later needing to re-apply; another is over-claiming activities you are not operationally ready to deliver. Map your product to statutory categories before anything else.

Step 2, Determine your legal vehicle and jurisdictional structure. Decide whether you will operate through a Ukrainian entity or a licensed local representative. In most cases, a local presence is required to hold a VASP authorisation and to maintain a direct supervisory relationship with the regulator (this is addressed in detail in the eligibility section below). Choose between establishing a Ukrainian subsidiary or restructuring an existing group. The pitfall here is assuming an offshore licence or foreign entity can passport into Ukraine; it generally cannot without a local anchor.

Step 3, Prepare governance, internal controls and the AML/CFT framework. Build the policy architecture: an AML/CFT policy, customer due diligence and enhanced due diligence procedures, transaction monitoring methodology, sanctions screening, risk assessment and training plan. Appoint a compliance officer with appropriate seniority and independence. Regulators increasingly test whether these documents reflect operational reality, so avoid generic templates that do not match your actual customer flows and risk profile.

Step 4, Compile corporate documents and beneficial ownership evidence. Gather incorporation documents, the corporate charter, the shareholder register, board resolutions authorising the application, and ultimate beneficial owner (UBO) disclosures. Beneficial ownership transparency is a recurring friction point; incomplete or inconsistent UBO data is among the most frequent causes of regulator queries. Reconcile corporate records across every jurisdiction in your ownership chain before filing.

Step 5, Prepare technical and security documentation. Document your system architecture, wallet management and key-custody controls, access management, incident response, and business continuity. Where you offer custody, expect to evidence segregation of client assets and robust key-management arrangements. Supporting materials typically include a security policy and the results of an independent technical audit or penetration test. Underestimating the technical evidence burden is a frequent pitfall for firms used to lighter-touch jurisdictions.

Step 6, Assemble capitalisation proof, financial projections and source-of-funds evidence. Prepare financial statements, proof of required capital, and clear documentation of the source of funds behind the business and its shareholders. For foreign-owned applicants, source-of-funds and source-of-wealth narratives carry particular weight. Weak or undocumented funding trails attract enhanced scrutiny and delay.

Step 7, Submit the application to the NSSMC. File the complete application with the designated regulator through its prescribed channels, ensuring every mandatory document is present and consistent. Incomplete submissions are the single largest avoidable cause of delay. A pre-submission internal review against the documents checklist on this page helps ensure the file is coherent and the narrative across corporate, AML and technical materials aligns.

Step 8, Respond to regulator follow-up and complete background checks. Expect the regulator to raise clarifications, request additional evidence and run fit-and-proper and background checks on shareholders, directors and the compliance officer. Respond promptly, fully and consistently. Contradictions between your written responses and your submitted documents are damaging; maintain a single source of truth for every factual assertion.

Step 9, Receive the licensing decision and complete post-licence registrations. On a positive decision, complete the registrations that follow authorisation, including tax registration, reporting set-up and registration with the State Financial Monitoring Service as an obliged entity for AML reporting. Treat these as part of the licensing project, not an afterthought, because they condition your ability to operate lawfully from launch.

Step 10, Maintain ongoing supervision and compliance. After authorisation, meet continuing obligations: periodic compliance reporting, independent audits, and prompt notification of material changes such as new shareholders, changes of control, new product lines or significant technical changes. Firms that neglect ongoing obligations risk corrective action; building a compliance calendar at licensing stage keeps you ahead of deadlines.

Documents required for VASP licensing in Ukraine

A well-organised document file is the backbone of successful vasp registration Ukraine. Group your materials into four categories and ensure internal consistency across them.

Mandatory corporate and governance documents

  • Certificate of incorporation for the applicant entity.
  • Corporate charter / constitutional documents defining the company’s objects and governance.
  • Shareholder register and share-capital evidence.
  • Board minutes / resolutions authorising the licence application.
  • UBO / beneficial ownership registry extracts disclosing the ultimate controllers.

Compliance and AML documents

  • AML/CFT policy tailored to your customer base and products.
  • Transaction monitoring description explaining rules, thresholds and escalation.
  • Compliance officer appointment letter evidencing authority and independence.
  • Risk assessment methodology and sanctions-screening procedures.

Technical and security documentation

  • Security policy covering access control and incident response.
  • Custody model description and key-management arrangements.
  • Penetration test / independent audit report validating your controls.

Evidence of capital and finances

  • Financial statements and projections.
  • Proof of capital and bank references.
  • Source-of-funds documentation for the business and its owners.

Key requirements and eligibility

Beyond documents, vasp licensing Ukraine depends on meeting substantive eligibility conditions. These typically include fit-and-proper assessment of directors, shareholders and the compliance officer; restrictions on prohibited or sanctioned shareholders; minimum capital where applicable to the activity; and, in many cases, local-residency or local-presence expectations for certain control functions. Applicants should also plan for a local agent or representative where the regulator requires a domestic point of contact.

Do foreign crypto companies need a local entity to operate in Ukraine? In most cases, yes. To obtain a VASP authorisation and maintain a direct supervisory relationship with the NSSMC, a foreign group will ordinarily need either a Ukrainian subsidiary or a licensed local representative. A purely offshore structure typically cannot access the Ukrainian market without a domestic anchor. The practical options are to incorporate a Ukrainian subsidiary that holds the licence, or to appoint a local representative able to interface with the regulator. The choice has consequences for tax treatment, licensing eligibility and the shape of your supervisory relationship, so structure the entity deliberately rather than defaulting to the fastest route.

AML/CFT rules that apply to crypto firms in Ukraine

AML/CFT compliance is the heart of crypto compliance Ukraine. VASPs are obliged entities under Ukraine’s AML/CFT law and must build a programme that functions in practice, consistent with FATF recommendations on virtual assets.

Scope of AML obligations

  • Customer due diligence (CDD): identify and verify customers and, where relevant, their beneficial owners before establishing a business relationship.
  • Enhanced due diligence (EDD): apply heightened measures to higher-risk customers, politically exposed persons and higher-risk jurisdictions.
  • Ongoing monitoring: keep customer profiles current and monitor activity against expected behaviour.
  • Recordkeeping: retain CDD and transaction records for the statutory retention period.

Reporting obligations to the State Financial Monitoring Service

VASPs must report suspicious transactions to the State Financial Monitoring Service and comply with threshold-based reporting under the AML law. Reports must be filed within the timeframes prescribed by the legislation, and firms must be able to demonstrate the analysis supporting a decision to file or not to file. A weak audit trail behind reporting decisions is a common supervisory finding.

Compliance programme elements

  • Enterprise risk assessment documenting your money-laundering and terrorist-financing exposure.
  • Transaction monitoring calibrated to crypto-specific typologies.
  • Sanctions screening of customers and counterparties.
  • AML training for staff, refreshed on a regular cadence.

Appointment and duties of the compliance officer / MLRO

Every VASP must appoint a compliance officer with the authority, independence and resources to run the AML programme, oversee reporting and act as the regulator’s point of contact for financial monitoring. The officer’s seniority and competence are assessed as part of licensing.

Practical red flags for crypto activity include rapid movement of funds through newly created accounts, structuring to avoid thresholds, transactions linked to mixing or tumbling services, use of privacy-enhancing tools inconsistent with the customer profile, and counterparties connected to sanctioned or high-risk addresses. A robust programme documents how each indicator is detected and escalated. For a deeper operational treatment, our AML/CFT compliance playbook sets out template policies and monitoring matrices.

Dealing with NSSMC and the National Bank of Ukraine

Effective engagement with regulators is central to vasp licensing Ukraine. Understanding who handles what, and how the supervisory lifecycle runs, shortens timelines and reduces friction.

Who handles what

The NSSMC leads on licensing and ongoing supervision of VASPs, making it your principal counterparty throughout the application and operating phases. The NBU engages where virtual asset activity interacts with payments, currency regulation and banking-sector stability, so firms with payment or fiat-rail dependencies should anticipate NBU-relevant considerations. The SFMS is the AML reporting authority and relevant to financial-monitoring supervision.

Typical supervisory lifecycle

The lifecycle usually runs from application review, through clarification rounds and fit-and-proper checks, to a decision; thereafter it continues with periodic compliance inspections and, where needed, corrective-action directions. Treating supervision as a continuous relationship rather than a one-off gate is the mindset that keeps firms in good standing.

Expected timelines for queries and decisions

Response and decision times vary with the completeness of the file and the regulator’s workload. As a working estimate, firms should plan for several weeks of review following a complete submission, with additional time where clarifications or technical audits are needed. The comparison table below sets out indicative ranges; treat them as planning aids, not guarantees.

Common triggers for scrutiny and appeals

Supervisory scrutiny is commonly triggered by inconsistent beneficial ownership data, weak AML operability, unexplained source of funds, material changes not notified, or customer complaints. Where the regulator takes an adverse decision, applicants and licensees generally have rights to seek review and to appeal through the procedures established in Ukrainian administrative law. Prepare any appeal with the same evidential rigour as the original application.

Costs and how long VASP licensing Ukraine takes

Costs for vasp licensing Ukraine fall into state fees and professional fees, and timelines depend heavily on the applicant’s readiness. Factors that extend timing include incomplete documentation, technical audits, background checks and the complexity of ownership structures. The ranges below are indicative and will vary with scope, structure and advisers engaged; treat them as a budgeting starting point rather than a quotation.

Activity Typical requirement Estimated cost range (USD/EUR) Typical timeline (weeks)
Application filing Complete corporate, AML and technical file submitted to NSSMC Varies with state fees and advisory support 1–2
Compliance programme build AML/CFT policies, risk assessment, monitoring, training Mid range professional fees 3–6
Technical audit / pen-test Independent security and custody assessment Dependent on system complexity 2–5
Capital deposit / proof Evidence of required capital and source of funds Capital amount plus banking costs 1–3
Responding to regulator queries Clarifications, additional evidence, background checks Variable advisory time 2–6+

Aggregating these phases, many well-prepared applicants plan for roughly 8–16 weeks from complete submission to decision, with complex or cross-border cases extending further. Build contingency into both your budget and your launch plan.

Operating after the licence, reporting, audits and custody requirements

Authorisation is the start of a continuing compliance obligation, not the finish line.

Ongoing reporting, audits and major-change notifications

Licensed VASPs must maintain a regular reporting cadence to the regulator and the SFMS, undergo periodic independent audits, and notify the authority promptly of material changes such as changes of control, new products or significant technical alterations. A compliance calendar prevents missed deadlines.

Custody models and insurance expectations

Whether you operate a crypto custody license Ukraine model or a non-custodial service shapes your obligations. Custodial providers face heightened expectations around segregation of client assets, key management, operational resilience and, increasingly, insurance or equivalent protections. Document your custody model clearly and align controls to the risk you hold on behalf of clients.

Next steps and where to get authoritative support

With implementation and supervision intensifying, vasp licensing Ukraine rewards firms that prepare early and thoroughly. The most successful applicants treat the exercise as an operational readiness project: they map their activities to statutory categories, build an AML/CFT framework that works in practice, assemble consistent corporate and beneficial ownership evidence, and engage the NSSMC, NBU and SFMS with a coherent, well-documented file. Those that approach vasp licensing Ukraine as a tick-box formality tend to encounter avoidable delays and heightened scrutiny.

Begin by defining your business model, confirming your legal vehicle, and drafting your governance and AML documentation to match your real customer flows. Prepare your technical and capital evidence in parallel so that nothing holds up submission. Downloadable templates and checklists are available to support each stage of your application and to help you track progress toward a complete, decision-ready file.

Sources

FAQs

How do I get a VASP licence in Ukraine?
Follow the structured application process: define your VASP activities, form a Ukrainian legal entity if required, prepare governance and AML/CFT documentation, compile technical security evidence, submit the application to the NSSMC, respond to follow-up queries, and complete post-licence registrations including SFMS registration and tax set-up. The numbered steps and documents checklist on this page cover each stage in full.
The National Securities and Stock Market Commission (NSSMC) is the primary regulator for VASPs. The National Bank of Ukraine (NBU) engages where crypto activity intersects with payments and financial-sector stability, and the State Financial Monitoring Service (SFMS) oversees AML/CFT reporting and suspicious transaction reporting. The legal basis sits in the Virtual Assets Law and Ukraine’s AML/CFT law.
Ukraine AML crypto obligations require VASPs to implement customer due diligence, enhanced due diligence for higher-risk customers, ongoing transaction monitoring, recordkeeping and suspicious transaction reporting to the SFMS. A documented AML programme, an enterprise risk assessment and an appointed compliance officer with genuine authority are all required.
Timelines depend on preparedness. A typical range is 8–16 weeks from complete submission to decision, though complex structures or remedial queries can extend this. The main variables are technical readiness, completeness of AML documentation, beneficial-ownership clarity, background checks and regulator workload.
Core documents include corporate formation records, shareholder and beneficial ownership information, AML policies and procedures, the compliance officer appointment, technical security evidence (architecture, custody controls, audit or penetration-test reports), financial statements and proof of capital and source of funds. Consistency across all four categories is essential to a smooth review.
In most cases, yes. A Ukrainian subsidiary or a licensed local representative is typically required to obtain a VASP authorisation and maintain a direct supervisory relationship with the regulator. A purely offshore structure generally cannot access the market without a domestic anchor, and the structuring choice affects tax, eligibility and supervision.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

letter of intent netherlands
By Global Law Experts

posted 1 hour ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Obtain a VASP Licence in Ukraine, Registration, NSSMC/NBU Supervision and AML Obligations

Send welcome message

Custom Message