FAQs_VASP.pdf

virtual assets under philippine law

Page 1 of 5
Frequently Asked Questions (FAQs) on the Guidelines for Virtual Asset Service Providers
(Circular No. 1108 dated 26 January 2021)
Why are Virtual Currencies (VC) and VC Exchanges (VCE) now referred to as Virtual
Assets (VA) and Virtual Asset Service Providers (VASP)?
The BSP has decided to refer to virtual currencies as defined under Circular No. 944 dated
06 February 2017 as “virtual assets” or VAs, in recognition of the evolving nature of this
financial innovation. We have adopted the definition espoused by the Financial Action Task
Force (FATF), the global money laundering and terrorist financing watchdog, in referring to
cryptocurrencies and other digital assets harnessing such technology.
In the same manner, the virtual asset market has developed business models beyond the
exchange and conversion between virtual currencies and fiat currencies. Adopting the
FATF’s definition of "virtual asset service providers" better captures such developments.
Overall, this provides the BSP’s regulatory framework with the flexibility to handle a fast-
moving and technologically dynamic sector.
How do VCs differ from VAs?
VCs refer to any type of digital unit that is used as a medium of exchange or form of digitally
stored value created by agreement within the community of VC users. VA expands on the
definition of VC by highlighting the use of such digital unit beyond the typical functions of
a currency (i.e., VAs refer to any type of digital unit that can be digitally traded, or
transferred, and can be used for payment or investment purposes). Similar to VCs, VAs are
not issued nor guaranteed by any jurisdictions and do not have legal tender status.
For the purposes of applying the FATF Recommendations on anti-money laundering, the
BSP also considers all funds- or value-based terms in the FATF Recommendations, such as
“property,” “proceeds,” “funds,” “funds or other assets,” and other “corresponding value,”
to also include and be applicable to VAs.
Digital units of exchange that is used for (i) the payment of goods and services solely
provided by its issuer or a limited set of merchants specified by its issuer (e.g., gift checks);
or (ii) the payment of virtual goods and services within an online game (e.g., gaming tokens)
are also not considered as VAs in the context of the BSP’s guidelines.
Page 2 of 5
How do VCEs differ from VASPs?
VCEs as defined in BSP Circular No. 944 dated 06 February 2017 only covers businesses
involved in the exchange of fiat currency and virtual currency. BSP Circular No. 1108
expands the scope of activities to be regulated as VASPs to include businesses that perform
• exchange between one or more forms of VAs;
• transfer of VAs; and
• safekeeping and/or administration of VAs or instruments enabling control over VAs.
This is to ensure that activities relating to VASP are executed within an unbroken chain of
regulated entities.
What are VA Custodians (i.e., VASP with safekeeping and/or administration of VAs)?
Follow the FATF Guidance on VAs and VASPs1, the BSP recognizes VA custodians as entities
that provide services or business models that either (i) safeguards the customer’s VA
wallet; and/or (ii) permits the VASP to manage the customer’s VA wallet.
As an example, a VASP with capabilities to execute VA transfers on behalf of the customer
through its platform can be considered as a VA Custodian. They may also have the ability
to create and secure VA wallets of their customers through their platform. In addition, the
FATF Guidance considers safekeeping and administration services to include businesses
that “have exclusive or independent control of the private key associated with VAs
belonging to another person or exclusive and independent control of smart contracts to
which they are not a party that involve VAs belonging to another person.”
The BSP shall use such basis as well as documentations from the applicant in evaluating
whether a VASP provides VA custodial services or not.
What is the “travel rule” requirement and how does it apply to VASPs?
The VASP guidelines emphasizes that all transactions involving the transfer of VA shall be
treated as cross-border wire transfer and that VASPs are expected to comply with
corresponding BSP rules governing wire transfer, particularly on the obligation to provide
immediate and secure transmittal of originator and beneficiary information from one VASP
to another for certain transactions. This particular requirement is also commonly known as
the “travel rule” across jurisdictions.
The travel rule aids in the prevention of money laundering and other financial crimes by
maintaining an information trail about individuals that send and receive funds.
VASPs and other supervised entities must be able to obtain and hold originator and
beneficiary information for VA transfers amounting to P50,000.00 or more (or its
equivalent in foreign currency) and transmit such information to the receiving institution.
1
https://www.fatf-gafi.org/media/fatf/documents/recommendations/RBA-VA-VASPs.pdf
Page 3 of 5
The required information includes the following:
a. originator’s name (i.e., the sending customer);
b. originator’s account number used to process the transaction (e.g., the VA wallet);
c. any of the following: originator’s physical (geographical) address, national identity
number, customer identification number that uniquely identifies the originator to
the ordering institution, or date and place of birth;
d. beneficiary’s name; and
e. beneficiary account number where such an account is used to process the
transaction (e.g., the VA wallet).
The BSP does not prescribe a specific technology for the obtaining and sending of originator
information as well as the obtaining and holding of beneficiary information between VASPs.
VASPs and other obliged entities in VA transfers may leverage on existing commercially
viable technology or harness new technologies (e.g., tokenization) to comply with this
requirement.
Are VASPs different from Electronic Money Issuers (EMI-Others)?
Below is a table providing a general comparison between two distinct money service
business operations: EMI-Others and VASPs2
.
Electronic Money Issuer
(EMI-Others)
Virtual Asset Service Provider (VASP)
Regulation Part 4 of the Manual of
Regulations for Non-
Bank Financial
Institutions (MORNBFI)
Part 9 of the MORNBFI
Related
Circulars
Circular No. 649, Circular
No. 942
Circular No. 942, Circular No. 944, Circular No.
1108
Definition An EMI provides money
transfer or remittance
services using
electronically stored
money value system and
similar digital financial
services.
VASP refers to any entity that offers services or
engages in activities that provide facility for the
transfer or exchange of virtual assets, which
involve the conduct of one or more of the
following activities:
(1) exchange between VAs and fiat currencies;
(2) exchange between one or more forms of
VAs;
(3) transfer of VAs; and
(4) safekeeping and/or administration of VAs or
instruments enabling control over VAs.
Product /
Service
e-money, e-wallets virtual assets/currencies (Bitcoin, Ethereum,
Ripple, etc.), e-wallets
2
Full list of registered EMIs and VCE/VASPs can be found in the BSP website.
Page 4 of 5
Will the BSP regulate Initial Coin Offerings (ICO)?
The BSP's guidelines do not cover businesses involved in the participation and provision of
financial services related to an issuer's offer and/or sale of a VA. Initial Coin Offerings or
ICOs are under the regulatory purview of the Securities and Exchange Commission (SEC).
According to the SEC Proposed Rules on Initial Coin Offerings, ICOs or token sales are
defined as distributed ledger technology fundraising operations involving the issuance of
tokens in return for cash, other cryptocurrencies or other assets. They involve coins (or
"tokens") being issued in order to raise money from the general public. Once the project
reaches a certain stage, benefits to tokenholders may include, but is not limited to, any of
the following:
a. Gains through profits or increase in the value of tokens which can be sold if
the project is successful;
b. Voting or governance rights; or
c. Usage rights.
What security features are required for VASPs?
VASPs are expected to comply with the requirements of BSP Circular No. 808 on
Information Technology Risk Management and BSP Circular No. 982 covering the Enhanced
Guidelines on Information Security Management for BSP-Supervised Financial Institutions
(BSFIs).
Moreover, VASPs providing wallet services for holding and storing VAs must establish an
adequate cybersecurity framework and adopt appropriate security measures/controls in
its VA platform to ensure confidentiality, integrity and availability of data/information
uploaded, stored, processed and transmitted into and out of the system and protect the
infrastructure from malware, cyber-attacks and other evolving and emerging threats. They
are required to employ appropriate security mechanisms commensurate to the sensitivity
and criticality of applications used. This may include robust authentication methods in
offering their products and services, such as multi-factor authentication. VASPs are
expected to conduct at least an annual vulnerability assessment and penetration tests, as
well as application security tests to ensure applications and platforms meet the desired
level of security.
These security-related regulations are periodically updated in response to the dynamically
evolving security, regulatory, and business environment where VASPs operate.
How do clients go about complaints processing in cases where they experience any issues
with VASPs?
VASPs are required to set up customer awareness measures to educate its customers,
which includes, among others: (i) safeguarding of VA and/or fiat currency wallets as well as
protection of client information such as log-in credentials; (ii) use of the mobile platform
Page 5 of 5
and wallets; (iii) actual fees and charges related to the use of the mobile platform and
withdrawal transactions; and (iv) problem resolution procedures.
VASPs shall clearly communicate and explain to its customers the terms and conditions
prescribing the manner on how the losses and liabilities from security breaches, system
failure, or human error will be settled between the VASP and its customers.
Clients/Users, on the other hand, should be aware of the risks involved in transacting or
engaging in the use of VA. As such, they should take full responsibility of their
virtual/electronic wallets, VAs, and transactions with VASPs. Should clients/user experience
any issues with VASPs, they should first directly communicate with the VASP through their
hotlines, emails, or available contact information to raise any concerns with regard to using
their product/service. Nevertheless, they may raise their concerns to the BSP by following
the instructions posted in the BSP’s Consumer Assistance Channels and Chatbot page.
(https://www.bsp.gov.ph/Pages/InclusiveFinance/ConsumerAssistanceChannelsChatbot.asp).
Any issues received from the public will be duly attended and communicated to the erring
VASP. Reported complaints shall be closely monitored with the VASP until full resolution.
How can an entity obtain a Certificate of Authority (COA) to operate as a VASP?
For new applications, entities may refer to the existing registration process for EMIs/VCEs
as provided in the 2020 BSP Citizen's Charter.
For VCEs (now referred to as VASP) with existing Certificate of Registration (COR), a letter
of intent (LOI) and gap assessment may be submitted to trisd@bsp.gov.ph with the subject:
DDMMYYYY_VASP LOI_Name of Entity. Submission must be made within three (3) months
from the effectivity date of subject Circular or 16 May 2021.
Note: DDMMYYYY refers to the date of submission

Recomendados

Overview of VFA Act - 26th july por
Overview of VFA Act - 26th julyOverview of VFA Act - 26th july
Overview of VFA Act - 26th julySilvan Mifsud
301 vistas23 diapositivas
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a... por
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...Lesa Moné
284 vistas34 diapositivas
Payments 101 por
Payments 101Payments 101
Payments 101Cory Barba
332 vistas37 diapositivas
A regulator’s view of virtual currencies as the first use-case of blockchain... por
 A regulator’s view of virtual currencies as the first use-case of blockchain... A regulator’s view of virtual currencies as the first use-case of blockchain...
A regulator’s view of virtual currencies as the first use-case of blockchain...thebitcoinconference
619 vistas20 diapositivas
Occ stablecoin guide por
Occ stablecoin guideOcc stablecoin guide
Occ stablecoin guidedecentralizedfinance
98 vistas6 diapositivas
Final presentation prepaid cards asia 2010 por
Final presentation   prepaid cards asia 2010Final presentation   prepaid cards asia 2010
Final presentation prepaid cards asia 2010Jahid Blackrose
1.3K vistas27 diapositivas

Más contenido relacionado

Similar a FAQs_VASP.pdf

Cyber Security Unit laws_and_regulatory_requirements.pptx por
Cyber Security Unit  laws_and_regulatory_requirements.pptxCyber Security Unit  laws_and_regulatory_requirements.pptx
Cyber Security Unit laws_and_regulatory_requirements.pptxSourabhNath4
4 vistas35 diapositivas
Latest updates on SWIFT FCC and correspondent banking por
Latest updates on SWIFT FCC and correspondent bankingLatest updates on SWIFT FCC and correspondent banking
Latest updates on SWIFT FCC and correspondent bankingSWIFT
880 vistas62 diapositivas
Prepaid Payment Regulatory Aspects por
Prepaid Payment Regulatory AspectsPrepaid Payment Regulatory Aspects
Prepaid Payment Regulatory AspectsRaghavendra L Rao
2.2K vistas29 diapositivas
Blockchain - The Regulatory Framework por
Blockchain - The Regulatory FrameworkBlockchain - The Regulatory Framework
Blockchain - The Regulatory FrameworkSilvan Mifsud
139 vistas126 diapositivas
Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN: por
  Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:  Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:
Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:Dr. Oliver Massmann
1.8K vistas9 diapositivas
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up... por
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...Cummings
184 vistas5 diapositivas

Similar a FAQs_VASP.pdf(20)

Cyber Security Unit laws_and_regulatory_requirements.pptx por SourabhNath4
Cyber Security Unit  laws_and_regulatory_requirements.pptxCyber Security Unit  laws_and_regulatory_requirements.pptx
Cyber Security Unit laws_and_regulatory_requirements.pptx
SourabhNath44 vistas
Latest updates on SWIFT FCC and correspondent banking por SWIFT
Latest updates on SWIFT FCC and correspondent bankingLatest updates on SWIFT FCC and correspondent banking
Latest updates on SWIFT FCC and correspondent banking
SWIFT880 vistas
Blockchain - The Regulatory Framework por Silvan Mifsud
Blockchain - The Regulatory FrameworkBlockchain - The Regulatory Framework
Blockchain - The Regulatory Framework
Silvan Mifsud139 vistas
Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN: por Dr. Oliver Massmann
  Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:  Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:
Lawyer in Vietnam Oliver Massmann BANKING and FINANCING ACTION PLAN:
Dr. Oliver Massmann1.8K vistas
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up... por Cummings
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...
Legal shorts 05.12.14 including Chancellor’s 2014 Autumn statement and FCA up...
Cummings184 vistas
Vietnam - Banking - Modernizing the System - What must be done: por Dr. Oliver Massmann
Vietnam - Banking - Modernizing the System - What must be done: Vietnam - Banking - Modernizing the System - What must be done:
Vietnam - Banking - Modernizing the System - What must be done:
Dr. Oliver Massmann3.2K vistas
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada por Christina Gagnier
Initial Coin Offerings (ICOs) and Cryptocurrencies in CanadaInitial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Initial Coin Offerings (ICOs) and Cryptocurrencies in Canada
Christina Gagnier900 vistas
Understanding SAR (Suspicious Activity Reporting) por HEXANIKA
Understanding SAR (Suspicious Activity Reporting)Understanding SAR (Suspicious Activity Reporting)
Understanding SAR (Suspicious Activity Reporting)
HEXANIKA572 vistas
PwC and Pole Star_ financial crime risks and trade finance_ July 2016 - WEB por Amanda Northey
PwC and Pole Star_ financial crime risks and trade finance_ July 2016 - WEBPwC and Pole Star_ financial crime risks and trade finance_ July 2016 - WEB
PwC and Pole Star_ financial crime risks and trade finance_ July 2016 - WEB
Amanda Northey185 vistas
Crypto asset regulators directory por Rein Mahatma
Crypto asset regulators directoryCrypto asset regulators directory
Crypto asset regulators directory
Rein Mahatma700 vistas
Regulation of ICOs in Ireland: An Overview of the Legal, Tax and Regulatory P... por Matheson Law Firm
Regulation of ICOs in Ireland: An Overview of the Legal, Tax and Regulatory P...Regulation of ICOs in Ireland: An Overview of the Legal, Tax and Regulatory P...
Regulation of ICOs in Ireland: An Overview of the Legal, Tax and Regulatory P...
Matheson Law Firm505 vistas
Sia partners aml_and_hedge_funds.01 por Daniel Connor
Sia partners aml_and_hedge_funds.01Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01
Daniel Connor87 vistas
The Case Of The Securities And Exchange Commission Essay por Rebecca Rogers
The Case Of The Securities And Exchange Commission EssayThe Case Of The Securities And Exchange Commission Essay
The Case Of The Securities And Exchange Commission Essay
Rebecca Rogers3 vistas
oversight-the-national-payement-system.pdf por Alemayehu
oversight-the-national-payement-system.pdfoversight-the-national-payement-system.pdf
oversight-the-national-payement-system.pdf
Alemayehu 14 vistas
Corp law presentation por Varun Vaish
Corp law presentationCorp law presentation
Corp law presentation
Varun Vaish536 vistas

Último

Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT por
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITShapeBlue
138 vistas8 diapositivas
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P... por
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...ShapeBlue
120 vistas62 diapositivas
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ... por
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...ShapeBlue
48 vistas17 diapositivas
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda... por
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...ShapeBlue
93 vistas13 diapositivas
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O... por
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...ShapeBlue
59 vistas13 diapositivas
Microsoft Power Platform.pptx por
Microsoft Power Platform.pptxMicrosoft Power Platform.pptx
Microsoft Power Platform.pptxUni Systems S.M.S.A.
74 vistas38 diapositivas

Último(20)

Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT por ShapeBlue
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
ShapeBlue138 vistas
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P... por ShapeBlue
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
ShapeBlue120 vistas
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ... por ShapeBlue
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
ShapeBlue48 vistas
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda... por ShapeBlue
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
ShapeBlue93 vistas
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O... por ShapeBlue
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...
ShapeBlue59 vistas
Webinar : Desperately Seeking Transformation - Part 2: Insights from leading... por The Digital Insurer
Webinar : Desperately Seeking Transformation - Part 2:  Insights from leading...Webinar : Desperately Seeking Transformation - Part 2:  Insights from leading...
Webinar : Desperately Seeking Transformation - Part 2: Insights from leading...
Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates por ShapeBlue
Keynote Talk: Open Source is Not Dead - Charles Schulz - VatesKeynote Talk: Open Source is Not Dead - Charles Schulz - Vates
Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates
ShapeBlue178 vistas
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue por ShapeBlue
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlueMigrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue
ShapeBlue147 vistas
Automating a World-Class Technology Conference; Behind the Scenes of CiscoLive por Network Automation Forum
Automating a World-Class Technology Conference; Behind the Scenes of CiscoLiveAutomating a World-Class Technology Conference; Behind the Scenes of CiscoLive
Automating a World-Class Technology Conference; Behind the Scenes of CiscoLive
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ... por ShapeBlue
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
ShapeBlue52 vistas
Digital Personal Data Protection (DPDP) Practical Approach For CISOs por Priyanka Aash
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Priyanka Aash103 vistas
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti... por ShapeBlue
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...
DRaaS using Snapshot copy and destination selection (DRaaS) - Alexandre Matti...
ShapeBlue69 vistas
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas... por Bernd Ruecker
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
iSAQB Software Architecture Gathering 2023: How Process Orchestration Increas...
Bernd Ruecker50 vistas
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue por ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
ShapeBlue75 vistas
KVM Security Groups Under the Hood - Wido den Hollander - Your.Online por ShapeBlue
KVM Security Groups Under the Hood - Wido den Hollander - Your.OnlineKVM Security Groups Under the Hood - Wido den Hollander - Your.Online
KVM Security Groups Under the Hood - Wido den Hollander - Your.Online
ShapeBlue154 vistas
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ... por ShapeBlue
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...
Backup and Disaster Recovery with CloudStack and StorPool - Workshop - Venko ...
ShapeBlue114 vistas
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava... por ShapeBlue
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
ShapeBlue74 vistas
State of the Union - Rohit Yadav - Apache CloudStack por ShapeBlue
State of the Union - Rohit Yadav - Apache CloudStackState of the Union - Rohit Yadav - Apache CloudStack
State of the Union - Rohit Yadav - Apache CloudStack
ShapeBlue218 vistas
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ... por ShapeBlue
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...
ShapeBlue121 vistas

FAQs_VASP.pdf

  • 1. Page 1 of 5 Frequently Asked Questions (FAQs) on the Guidelines for Virtual Asset Service Providers (Circular No. 1108 dated 26 January 2021) Why are Virtual Currencies (VC) and VC Exchanges (VCE) now referred to as Virtual Assets (VA) and Virtual Asset Service Providers (VASP)? The BSP has decided to refer to virtual currencies as defined under Circular No. 944 dated 06 February 2017 as “virtual assets” or VAs, in recognition of the evolving nature of this financial innovation. We have adopted the definition espoused by the Financial Action Task Force (FATF), the global money laundering and terrorist financing watchdog, in referring to cryptocurrencies and other digital assets harnessing such technology. In the same manner, the virtual asset market has developed business models beyond the exchange and conversion between virtual currencies and fiat currencies. Adopting the FATF’s definition of "virtual asset service providers" better captures such developments. Overall, this provides the BSP’s regulatory framework with the flexibility to handle a fast- moving and technologically dynamic sector. How do VCs differ from VAs? VCs refer to any type of digital unit that is used as a medium of exchange or form of digitally stored value created by agreement within the community of VC users. VA expands on the definition of VC by highlighting the use of such digital unit beyond the typical functions of a currency (i.e., VAs refer to any type of digital unit that can be digitally traded, or transferred, and can be used for payment or investment purposes). Similar to VCs, VAs are not issued nor guaranteed by any jurisdictions and do not have legal tender status. For the purposes of applying the FATF Recommendations on anti-money laundering, the BSP also considers all funds- or value-based terms in the FATF Recommendations, such as “property,” “proceeds,” “funds,” “funds or other assets,” and other “corresponding value,” to also include and be applicable to VAs. Digital units of exchange that is used for (i) the payment of goods and services solely provided by its issuer or a limited set of merchants specified by its issuer (e.g., gift checks); or (ii) the payment of virtual goods and services within an online game (e.g., gaming tokens) are also not considered as VAs in the context of the BSP’s guidelines.
  • 2. Page 2 of 5 How do VCEs differ from VASPs? VCEs as defined in BSP Circular No. 944 dated 06 February 2017 only covers businesses involved in the exchange of fiat currency and virtual currency. BSP Circular No. 1108 expands the scope of activities to be regulated as VASPs to include businesses that perform • exchange between one or more forms of VAs; • transfer of VAs; and • safekeeping and/or administration of VAs or instruments enabling control over VAs. This is to ensure that activities relating to VASP are executed within an unbroken chain of regulated entities. What are VA Custodians (i.e., VASP with safekeeping and/or administration of VAs)? Follow the FATF Guidance on VAs and VASPs1, the BSP recognizes VA custodians as entities that provide services or business models that either (i) safeguards the customer’s VA wallet; and/or (ii) permits the VASP to manage the customer’s VA wallet. As an example, a VASP with capabilities to execute VA transfers on behalf of the customer through its platform can be considered as a VA Custodian. They may also have the ability to create and secure VA wallets of their customers through their platform. In addition, the FATF Guidance considers safekeeping and administration services to include businesses that “have exclusive or independent control of the private key associated with VAs belonging to another person or exclusive and independent control of smart contracts to which they are not a party that involve VAs belonging to another person.” The BSP shall use such basis as well as documentations from the applicant in evaluating whether a VASP provides VA custodial services or not. What is the “travel rule” requirement and how does it apply to VASPs? The VASP guidelines emphasizes that all transactions involving the transfer of VA shall be treated as cross-border wire transfer and that VASPs are expected to comply with corresponding BSP rules governing wire transfer, particularly on the obligation to provide immediate and secure transmittal of originator and beneficiary information from one VASP to another for certain transactions. This particular requirement is also commonly known as the “travel rule” across jurisdictions. The travel rule aids in the prevention of money laundering and other financial crimes by maintaining an information trail about individuals that send and receive funds. VASPs and other supervised entities must be able to obtain and hold originator and beneficiary information for VA transfers amounting to P50,000.00 or more (or its equivalent in foreign currency) and transmit such information to the receiving institution. 1 https://www.fatf-gafi.org/media/fatf/documents/recommendations/RBA-VA-VASPs.pdf
  • 3. Page 3 of 5 The required information includes the following: a. originator’s name (i.e., the sending customer); b. originator’s account number used to process the transaction (e.g., the VA wallet); c. any of the following: originator’s physical (geographical) address, national identity number, customer identification number that uniquely identifies the originator to the ordering institution, or date and place of birth; d. beneficiary’s name; and e. beneficiary account number where such an account is used to process the transaction (e.g., the VA wallet). The BSP does not prescribe a specific technology for the obtaining and sending of originator information as well as the obtaining and holding of beneficiary information between VASPs. VASPs and other obliged entities in VA transfers may leverage on existing commercially viable technology or harness new technologies (e.g., tokenization) to comply with this requirement. Are VASPs different from Electronic Money Issuers (EMI-Others)? Below is a table providing a general comparison between two distinct money service business operations: EMI-Others and VASPs2 . Electronic Money Issuer (EMI-Others) Virtual Asset Service Provider (VASP) Regulation Part 4 of the Manual of Regulations for Non- Bank Financial Institutions (MORNBFI) Part 9 of the MORNBFI Related Circulars Circular No. 649, Circular No. 942 Circular No. 942, Circular No. 944, Circular No. 1108 Definition An EMI provides money transfer or remittance services using electronically stored money value system and similar digital financial services. VASP refers to any entity that offers services or engages in activities that provide facility for the transfer or exchange of virtual assets, which involve the conduct of one or more of the following activities: (1) exchange between VAs and fiat currencies; (2) exchange between one or more forms of VAs; (3) transfer of VAs; and (4) safekeeping and/or administration of VAs or instruments enabling control over VAs. Product / Service e-money, e-wallets virtual assets/currencies (Bitcoin, Ethereum, Ripple, etc.), e-wallets 2 Full list of registered EMIs and VCE/VASPs can be found in the BSP website.
  • 4. Page 4 of 5 Will the BSP regulate Initial Coin Offerings (ICO)? The BSP's guidelines do not cover businesses involved in the participation and provision of financial services related to an issuer's offer and/or sale of a VA. Initial Coin Offerings or ICOs are under the regulatory purview of the Securities and Exchange Commission (SEC). According to the SEC Proposed Rules on Initial Coin Offerings, ICOs or token sales are defined as distributed ledger technology fundraising operations involving the issuance of tokens in return for cash, other cryptocurrencies or other assets. They involve coins (or "tokens") being issued in order to raise money from the general public. Once the project reaches a certain stage, benefits to tokenholders may include, but is not limited to, any of the following: a. Gains through profits or increase in the value of tokens which can be sold if the project is successful; b. Voting or governance rights; or c. Usage rights. What security features are required for VASPs? VASPs are expected to comply with the requirements of BSP Circular No. 808 on Information Technology Risk Management and BSP Circular No. 982 covering the Enhanced Guidelines on Information Security Management for BSP-Supervised Financial Institutions (BSFIs). Moreover, VASPs providing wallet services for holding and storing VAs must establish an adequate cybersecurity framework and adopt appropriate security measures/controls in its VA platform to ensure confidentiality, integrity and availability of data/information uploaded, stored, processed and transmitted into and out of the system and protect the infrastructure from malware, cyber-attacks and other evolving and emerging threats. They are required to employ appropriate security mechanisms commensurate to the sensitivity and criticality of applications used. This may include robust authentication methods in offering their products and services, such as multi-factor authentication. VASPs are expected to conduct at least an annual vulnerability assessment and penetration tests, as well as application security tests to ensure applications and platforms meet the desired level of security. These security-related regulations are periodically updated in response to the dynamically evolving security, regulatory, and business environment where VASPs operate. How do clients go about complaints processing in cases where they experience any issues with VASPs? VASPs are required to set up customer awareness measures to educate its customers, which includes, among others: (i) safeguarding of VA and/or fiat currency wallets as well as protection of client information such as log-in credentials; (ii) use of the mobile platform
  • 5. Page 5 of 5 and wallets; (iii) actual fees and charges related to the use of the mobile platform and withdrawal transactions; and (iv) problem resolution procedures. VASPs shall clearly communicate and explain to its customers the terms and conditions prescribing the manner on how the losses and liabilities from security breaches, system failure, or human error will be settled between the VASP and its customers. Clients/Users, on the other hand, should be aware of the risks involved in transacting or engaging in the use of VA. As such, they should take full responsibility of their virtual/electronic wallets, VAs, and transactions with VASPs. Should clients/user experience any issues with VASPs, they should first directly communicate with the VASP through their hotlines, emails, or available contact information to raise any concerns with regard to using their product/service. Nevertheless, they may raise their concerns to the BSP by following the instructions posted in the BSP’s Consumer Assistance Channels and Chatbot page. (https://www.bsp.gov.ph/Pages/InclusiveFinance/ConsumerAssistanceChannelsChatbot.asp). Any issues received from the public will be duly attended and communicated to the erring VASP. Reported complaints shall be closely monitored with the VASP until full resolution. How can an entity obtain a Certificate of Authority (COA) to operate as a VASP? For new applications, entities may refer to the existing registration process for EMIs/VCEs as provided in the 2020 BSP Citizen's Charter. For VCEs (now referred to as VASP) with existing Certificate of Registration (COR), a letter of intent (LOI) and gap assessment may be submitted to trisd@bsp.gov.ph with the subject: DDMMYYYY_VASP LOI_Name of Entity. Submission must be made within three (3) months from the effectivity date of subject Circular or 16 May 2021. Note: DDMMYYYY refers to the date of submission