← Regulations / Malaysia / Operating Models / On-shore VASP

On-shore VASP in Malaysia

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in Malaysia with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Register as a Recognised Market Operator (RMO) / Digital Asset Exchange (DAX) with the Securities Commission Malaysia (SC) under the Capital Markets and Services Act 2007 (CMSA) and Guidelines on Digital Assets (2020)
  • Maintain minimum shareholders' funds of MYR 5M (~$1.1M USD)
  • Comply with the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLATFPUAA 2001)
  • Apply CDD measures: obtain and verify identity (name, address, DOB, nationality, ID document, contact info) for individual customers
  • For corporate customers: obtain legal name, legal form, proof of existence, registered address, directors/partners/trustees, shareholder/beneficial owner details, governing documents
  • Identify and verify Ultimate Beneficial Owner (UBO) for all corporate/legal arrangements
  • Understand purpose and intended nature of business relationship
  • Obtain source of funds/wealth for higher-risk customers
  • Conduct ongoing transaction monitoring to ensure consistency with customer risk profile
  • Apply Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, high-risk products/services (privacy coins, mixers)
  • Implement robust non-face-to-face (NFF) CDD measures (multi-factor authentication, video verification, cross-referencing)
  • Travel Rule compliance: collect, transmit, and store originator and beneficiary information for virtual asset transfers — threshold MYR 3,000 for domestic transfers; all cross-border transfers require full information regardless of amount
  • Sanctions screening of both originator and beneficiary information
  • Record-keeping for prescribed period (at least 7 years under AMLA)
  • Submit Suspicious Transaction Reports (STRs) to Bank Negara Malaysia (BNM) Financial Intelligence Unit (FIU)

Key Restrictions

  • Must be locally incorporated in Malaysia to obtain DAX registration
  • Only 5 operators currently registered — SC is strict and slow on new registrations (6–12 months timeline)
  • IEO offerings require separate SC approval beyond DAX registration
  • Customer assets must be segregated — custody is bundled under DAX registration
  • SC has issued cease-and-desist orders against unregistered operators (e.g., Binance 2021) — operating without registration is a violation under CMSA
  • Operator must not facilitate unregistered offerings of digital assets that qualify as prescribed securities under Capital Markets and Services (Prescription of Securities) Order 2019

Key Risks

  • SC has active enforcement precedent: Binance was targeted for operating a DAX without registration — risk of cease-and-desist orders, fines, or criminal liability for directors/CEO
  • Regulatory bottleneck: only 5 DAX operators registered; SC is described as 'strict and slow' — application timeline of 6–12 months with uncertain outcome
  • Tax ambiguity: gains may be treated as capital gains (not taxable for individuals) or business income depending on frequency/system — operator must correctly classify and advise users
  • Travel Rule compliance burden for MYR 3,000+ domestic transfers and all cross-border transfers requires significant operational investment in information transmission systems
  • Non-compliance with AML/CFT obligations can lead to monetary penalties, imprisonment of responsible individuals, and license revocation

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 30% confidence

SC Malaysia — Digital asset exchange registration, IEO oversight, cease-and-desist enforcement

licensing 40% confidence

BNM — AML/CFT standards

licensing 20% confidence

Capital Markets and Services (Prescription of Securities) Order 2019 (2019) — Digital currency and digital token as prescribed securities

licensing 20% confidence

Guidelines on Digital Assets (2020) — DAX operator requirements

licensing 20% confidence

VASP: Recognized Market Operator (RMO) — DAX registration with SC. Only 5 operators registered (Luno, Tokenize, MX Global, Sinegy, Hata). SC strict and slow on registrations. 6-12 months.

licensing 20% confidence

CUSTODY: Included under DAX registration; customer asset segregation required

licensing 20% confidence

EXCHANGE: DAX registration with SC — MYR 5M (~$1.1M USD) minimum shareholders' funds. SC issued cease-and-desist orders against unregistered operators (incl. Binance 2021). IEO framework requires separate SC approval.

aml 60% confidence

Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLATFPUAA 2001)

aml 60% confidence

AML/CFT and Targeted Financial Sanctions for Financial Institutions (AML/CFT TFS for FIs) Policy Document (BNM Policy Document): Issued by Bank Negara Malaysia, this comprehensive policy document provides detailed guidance and requirements for reporting institutions to comply with AMLATFPUAA 2001. This document has specific sections/appendices applicable to "Digital Currencies" or "Virtual Assets."

aml 60% confidence

Capital Markets and Services Act 2007 (CMSA): For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.

aml 60% confidence

Guidelines on Recognised Markets (SC Guidelines): Specifically for operators of recognised markets, including DAX, detailing operational, conduct, and AML/CFT requirements.

aml 60% confidence

Bank Negara Malaysia (BNM):

aml 60% confidence

Securities Commission Malaysia (SC):

aml 60% confidence

Exchanges between digital currencies and fiat currencies.

aml 60% confidence

Exchanges between one or more forms of digital currencies.

aml 60% confidence

Transfers of digital currencies.

aml 60% confidence

Safekeeping and/or administration of digital currencies or instruments enabling control over digital currencies.

aml 60% confidence

Participation in and provision of financial services related to an issuer’s offer and/or sale of a digital currency.

aml 60% confidence

Customer Identification and Verification:

aml 60% confidence

Obtain and verify the identity of individual customers (name, address, date of birth, nationality, identification document details, contact information).

aml 60% confidence

For legal entities/corporate customers, obtain and verify: legal name, legal form, proof of existence (e.g., certificate of incorporation), address of registered office, names of directors/partners/trustees, details of shareholders and beneficial owners, and constitution/governing documents.

aml 60% confidence

Beneficial Ownership: Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.

aml 60% confidence

Purpose and Intended Nature of Business Relationship: Understand the rationale behind the customer's request to use the VASP's services and the anticipated level and type of activity.

aml 60% confidence

Source of Funds/Wealth: For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.

aml 60% confidence

Non-Face-to-Face (NFF) Customers: Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.

aml 60% confidence

Politically Exposed Persons (PEPs): Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.

aml 60% confidence

High-Risk Customers: PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.

aml 60% confidence

High-Risk Products/Services: Products or services that facilitate anonymity (e.g., privacy coins, mixing services).

travel-rule 20% confidence

Travel Rule adopted — threshold: MYR 3,000

travel-rule 60% confidence

Bank Negara Malaysia (BNM) Policy Document on Anti-Money Laundering, Counter-Terrorism Financing and Targeted Financial Sanctions for Financial Institutions (AML/CFT and TFS Policy Document): This is the primary document.

travel-rule 60% confidence

Specifically, Paragraph 10.1.2 states: "A reporting institution that conducts virtual asset transfers shall apply the obligations outlined in this policy document relating to funds or wire transfers to virtual assets." This explicitly extends the Travel Rule to virtual assets.

travel-rule 60% confidence

Securities Commission Malaysia (SC) Guidelines on Digital Assets: These guidelines govern Digital Asset Exchanges (DAX) and other entities dealing with digital assets. They mandate compliance with BNM's AML/CFT framework.

travel-rule 60% confidence

Section 9 (Anti-Money Laundering and Counter-Terrorism Financing): Requires registered Digital Asset Exchanges (DAX) to comply with the AMLA and BNM's AML/CFT and TFS Policy Document.

travel-rule 60% confidence

Cross-Border Transfers (both traditional and virtual assets): All required originator and beneficiary information must be obtained and transmitted, regardless of the amount.

travel-rule 60% confidence

Domestic Transfers (both traditional and virtual assets):

travel-rule 60% confidence

For transfers equal to or exceeding RM3,000 (or equivalent in foreign currency/virtual assets): All required originator and beneficiary information must be obtained and transmitted.

travel-rule 60% confidence

For transfers below RM3,000 (or equivalent): Reporting institutions are permitted to omit certain information (e.g., originator's address or national identity number, beneficiary's address), provided they can produce this information within 3 working days if requested by authorities.

travel-rule 60% confidence

Digital Asset Exchanges (DAX) registered with the Securities Commission Malaysia: These are explicitly identified as VASPs and reporting institutions under the SC's guidelines and are thus fully covered.

travel-rule 60% confidence

Information Collection: VASPs must collect the required originator (sender) and beneficiary (recipient) information, including names, account numbers (or wallet addresses), and physical addresses or national identity numbers/customer identification numbers.

travel-rule 60% confidence

Information Transmission: The collected information must be transmitted to the beneficiary VASP during or before the virtual asset transfer.

travel-rule 60% confidence

Sanctions Screening: Both originator and beneficiary information must be screened against relevant sanctions lists.

travel-rule 60% confidence

Record Keeping: Records of all transactions and the associated Travel Rule data must be maintained for a prescribed period (typically at least 7 years under AMLA).

travel-rule 60% confidence

Fines: Significant monetary penalties, which can run into millions of Ringgit for entities.

travel-rule 60% confidence

Imprisonment: Individuals (e.g., directors, compliance officers) found responsible for non-compliance may face imprisonment.

travel-rule 60% confidence

Revocation or Suspension of Licenses: For regulated entities like DAXes, their licenses can be revoked or suspended by the SC or BNM.

travel-rule 60% confidence

Enforcement Actions: BNM and SC have the power to issue directives, impose administrative penalties, or take other enforcement actions.

enforcement 50% confidence

Entity Targeted: Binance Holdings Limited and its CEO, Changpeng Zhao (CZ). Violation Type: Operating a Digital Asset Exchange (DAX) without registration/license, which is a violation under the Capital Markets and Services Act 2007. The SC considers digital assets as securities, and operating a platform for trading them requires authorization. Penalty Amount: No explicit monetary fine was announced at the time of the public reprimand. The penalties were operational: a public reprimand, an order to cease all operations in Malaysia, disable access to its website and mobile applications, and cease all media and marketing activities targeting Malaysian investors. Outcome: Binance was forced to shut down its direct operations in Malaysia. Malaysian users were advised to withdraw their funds. The action led Binance to later pursue a compliant pathway to re-enter the Malaysian market by acquiring a stake in and partnering with a licensed local Digital Asset Exchange (DAX), MX Global, demonstrating the effectiveness of the SC's enforcement in driving regulatory compliance.

enforcement 50% confidence

Entity Targeted: Various unauthorized digital asset platforms, investment schemes involving crypto, and individuals promoting them. (Specific names are too numerous to list here, but are updated frequently). Violation Type: Operating or promoting unauthorized investment schemes, digital asset exchanges, or services without the necessary licenses or approvals from the SC Malaysia. Penalty Amount: Typically no specific monetary penalty is announced publicly for being added to the alert list. The "penalty" is a public warning, which often leads to the platform being unable to operate effectively in Malaysia and subsequent cessation of operations or blocking of access. Outcome: Public awareness is raised, and investors are warned against dealing with these entities. This often leads to reduced or ceased operations for the targeted entities within Malaysia.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — on-shore VASPs are permitted in Malaysia but must undergo a high-burden DAX (RMO) registration with SC Malaysia requiring MYR 5M minimum capital, local incorporation, full AML/CFT compliance under BNM oversight, Travel Rule compliance at MYR 3,000 threshold, and face a 6–12 month application timeline with only 5 operators currently registered.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?