Remote VASP serving residents in Vietnam
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Vietnam with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- KYC required for transactions ≥ USD 1,000 (or VND equivalent)
- Ongoing AML/CTF risk management and internal policies required as part of licensing (Resolution No. 05/2025/NQ-CP)
- Transaction monitoring for suspicious transaction detection (STR capability implied via MPS/SBV coordination)
- Customer due diligence (CDD) with identity verification integrated into IT systems with audit trails
- Data retention for 10 years on Vietnam servers (transaction history, originator/beneficiary details, wallet addresses, IP/device logs, account info)
- Platform must implement programmed AML/KYC processes with anti-tampering logs, secure key management
- Cybersecurity at Level 4 standard (encryption, intrusion detection, continuous monitoring) to support CDD
- No explicit STR filing mechanism detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination
- Proactive adoption of FATF VASP standards recommended for compliance transition
Key Restrictions
- Foreign VASPs must be licensed under the new framework (Resolution No. 05/2025/NQ-CP, effective September 2025)
- A local entity is effectively required — licensing demands incorporation and a single VND account at a licensed local bank
- All transactions must be settled in VND
- Systems must achieve the highest cybersecurity standard (Level 4)
- Data must be stored on Vietnam servers for 10 years — this may conflict with cross-border remote operations
- Travel Rule not yet finalized in Vietnam — no confirmed obligation to comply, but recommended as part of FATF alignment
Key Risks
- Operating without a license carries significant enforcement risk — MoPS has demonstrated willingness to pursue criminal fraud and money laundering charges against crypto platforms (ONUS case, 7–9 arrests, March 2026)
- Regulatory framework is very new (pilot program started 2025/2026) with undefined STR filing mechanisms and no finalized Travel Rule, creating compliance ambiguity
- Remote cross-border service without local entity or licensing is high-risk — the licensing framework mandates local incorporation, local bank accounts, and on-shore data storage, making pure remote operation likely unlawful
- No explicit STR filing mechanism in pilot docs — unclear how to report suspicious transactions, exposing operators to AML compliance gaps
- Foreign operators face enforcement from MoPS for cybersecurity and financial integrity violations, with criminal liability exposure (fraud, money laundering charges)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Ministry of Finance (MOF) — Lead authority
State Securities Commission (SSC) — Licensing review and compliance monitoring
State Bank of Vietnam (SBV) — Financial oversight
Ministry of Public Security (MPS) — Cybersecurity and financial integrity
The framework mandates VASPs to apply AML/CTF obligations as part of licensing, treating crypto exchanges as market infrastructure akin to securities exchanges. This includes internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.
Oversight involves MOF (lead), SSC (receiving applications), SBV (financial integrity), and MPS (AML, cybersecurity).
Prior to 2026, VASPs were not explicitly regulated under AML laws, but the pilot program (five-year duration) now enforces compliance to prevent illicit flows.
Key reference: Resolution No. 05/2025/NQ-CP (September 9, 2025) establishes the licensing regime with AML/CTF as a core objective; Decision No. 96/QD-BTC details procedures, including AML appraisals.
VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.
Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.
Foreign investors require a single VND account at a licensed local bank; all transactions use VND.
Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.
Proactive adoption of FATF VASP standards is recommended for compliance transition.
VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.
Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.
No explicit STR filing mechanism is detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.
Custody and client protection rules reinforce STR through risk controls and complaint handling.
Regulator: Ministry of Public Security (MoPS).
Entity Targeted: ONUS cryptocurrency platform (including tokens VNDC, ONUS, and HNG), operated by Vương Lê Vĩnh Nhân (Eric Lê/Vuong Le Vinh Nhan) and associates. Violation Type: Fraud via token price manipulation, deceptive marketing, misleading promotions, artificial trading to control supply/demand, property appropriation, and money laundering using platform infrastructure. Penalty Amount: Not yet finalized; investigation targets billions of dollars in mobilized funds and investor losses (preliminary estimates in billions of USD).
Date: Criminal proceedings launched March 23, 2026; investigation ongoing with raids across Hanoi, Ho Chi Minh City, Da Nang, and Can Tho.
Outcome: At least 7–9 arrests (including Vương Lê Vĩnh Nhân and 6–8 accomplices); over 140 individuals summoned; platform operations dismantled; charges filed for fraud and money laundering.
Vietnam falls under "Countries That Have Initiated the FATF’s Travel Rule Process", indicating ongoing development of crypto regulations but no finalized Travel Rule legislation or mandates requiring VASPs to comply during transactions.
No specific effective date, threshold amounts (e.g., FATF's recommended $1,000/€1,000), VASPs covered, technical implementation requirements (such as data collection/retention standards or interoperability protocols), or penalties for non-compliance are detailed for Vietnam in available sources.
No Vietnam-specific legislation (e.g., laws or decrees mandating Travel Rule compliance) is referenced; sources highlight general FATF progress without local URLs or documents for Vietnam.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — foreign VASPs may serve Vietnamese residents only after obtaining a license under the new 2025 framework (Resolution No. 05/2025/NQ-CP), which effectively requires local incorporation, a local VND bank account, on-shore data hosting, and a high-burden licensing process with AML/KYC obligations; pure remote (no-local-entity) operation is not permitted and exposes operators to criminal enforcement risk (MoPS).
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?