KYCifi logo KYCifi
Services
All Services Crypto & Digital Assets Fractional MLRO AML Programme Build Business KYC
Sectors AboutContact Insights
LÆdar AI
Company Intelligence Screening Intelligence Conveyancing AML Check Law Firm AML Record Corporate KYC Review
PVARA workflows · within LÆdar AI
NOC Readiness Assessment VASP CDD Workflow NOC Application Pack goAML STR Generator Annual Return (Form A6) Fit and Proper (Form A3) Travel Rule Checker VASP KYC Review
Book Consultation
KYCifi logo KYCifi
Services All Services Crypto & Digital Assets Fractional MLRO AML Programme Build Business KYC Sectors About Contact Insights LÆdar AI Company Intelligence Screening Intelligence Conveyancing AML Check Law Firm AML Record Corporate KYC Review PVARA · NOC Readiness Assessment PVARA · VASP CDD Workflow PVARA · NOC Application Pack PVARA · goAML STR Generator PVARA · Annual Return (Form A6) PVARA · Fit and Proper (Form A3) PVARA · Travel Rule Checker PVARA · VASP KYC Review Book Consultation
VASP KYC Review · Powered by LÆdar AI

Risk-based KYC reviews, led by practitioners.

KYCifi combines specialist AML, KYC and virtual asset compliance expertise with intelligent technology, so customer relationships are kept current and defensible through periodic and trigger-based reviews, distinct from onboarding CDD.

Access KYC Review → See the workflow

The workflow tools are client software, available to KYCifi clients and engagement partners. New to KYCifi? Book a consultation and we’ll set up your access.

Periodic reviewsTrigger eventsScreening refreshEDD reviews
kyc / periodic-reviewReviewed
RelationshipInstitutional · high-risk
Last reviewed14 months ago
TriggerOwnership change
New screening hit · since last reviewEDD
Risk reassessed, escalation and rationale documented. Audit-ready
KYC review support for BanksExchangesBrokersCustodiansOTC desks
The challenge

Why customer reviews are where risk re-emerges.

Onboarding is a moment; risk is continuous. Between reviews, customers change, screening lists move and relationships drift from the picture on file.

Outdated information

Profiles captured at onboarding age quickly and drift from reality.

Customer changes

Ownership, activity and product use shift, often without notice.

High-risk relationships

PEPs, complex structures and high-risk profiles need closer, recurring scrutiny.

Screening updates

Sanctions, PEP and adverse media lists change; a clear customer may not stay clear.

Ongoing monitoring

Activity must be watched between reviews, with triggers acted on promptly.

Regulatory expectations

Supervisors expect periodic and event-driven reviews, evidenced consistently.

Documentation quality

Each review must be recorded to a standard that holds up later.

Audit readiness

The full review history must be evidenced and retained for inspection.

The workflow

From review trigger to a documented decision.

Every periodic or event-driven review runs the same disciplined way, so customer risk stays current and defensible.

01

Customer Review Triggered

A periodic cycle or a trigger event opens a review of the relationship.

Periodic · trigger
02

Profile Refresh

Customer details and ownership are refreshed against the latest position.

Refresh
03

Documentation Review

Records and evidence are checked for currency, completeness and gaps.

Records
04

Screening Refresh

Sanctions, PEP and adverse media re-screened, and new hits adjudicated.

Re-screen
05

Risk Reassessment

Risk is re-rated against the refreshed picture and any new findings.

Re-rate
06

EDD Escalation

Where risk rises, enhanced due diligence and investigation are applied.

EDD
07

Review Decision

A documented decision to continue, restrict or exit, with senior referral where it matters.

Decision
The practitioner advantage

A refreshed file is not a re-assessed risk.

KYCifi is, first, a specialist AML and KYC practice with deep virtual asset experience. A new screening hit, an ownership change or a shift in activity is investigated and judged by specialists, not just re-flagged on a schedule.

A review reminder gives you

A date in a diary

  • A prompt that a review is due
  • A refreshed set of fields
  • No view on whether risk has changed
  • Evidence left for you to assemble
KYCifi gives you

A re-assessed risk

  • AML, KYC & virtual asset specialists
  • New findings investigated and judged
  • Enhanced due diligence where it matters
  • A documented, defensible review decision
KPMGDeloitteBank of New York MellonVirtual assetsAML / CFT
The technology

LÆdar AI supports our specialists.

Our practitioners lead every review. LÆdar AI, our intelligence platform, does the legwork behind them, so judgement stays with the people, and the review file is built as they work.

Company IntelligenceScreening IntelligenceOwnership mappingRisk assessmentAudit-ready documentation
Deliverables

What you receive.

Defensible, audit-ready outputs for every review, built to the standard supervisors expect.

KYC Review Reports

A complete record of each periodic or trigger-based review and its outcome.

Risk Reassessments

An updated, documented risk rating with a clear, per-factor rationale.

EDD Reviews

Enhanced due diligence with investigation for relationships that escalate.

Monitoring Records

Ongoing monitoring and trigger-review records across the relationship.

Audit-Ready Documentation

A complete review history and audit trail, ready for supervisory inspection.

Who this is for

Built for virtual asset businesses and their banks.

From exchanges to the banks that serve them, KYCifi keeps customer risk current between onboardings.

BanksExchangesBrokersCustodiansOTC DesksVASPs

Keep customer risk current and defensible.

See how KYCifi combines specialist compliance expertise and intelligent technology to support virtual asset businesses.

Book Consultation → Access KYC Review

Questions? Contact contact@kycifi.com

Bank VASP KYC Review

VASP Corporate KYC Review

Guided due diligence for banks onboarding Virtual Asset Service Providers under SBP BPRD Circular No.10 of 2026. Complete all six steps to produce a structured, audit-ready KYC record.

SBP BPRD Circular No.10 2026 Approx. 20 to 25 minutes Audit-Ready PDF Output
1
VASP Identity
2
Ownership
3
VASP Risk
4
AML Programme
5
Circular Check
6
Decision
Step 1 of 6

VASP Identity and Registration

Record the reviewing bank's details and the VASP's registration information, PVARA NOC status, and operational profile. All required fields are marked with an asterisk.

Review Details
Bank and analyst conducting this review
Bank name is required
Analyst name is required
Case reference is required
VASP Identity
Legal registration details of the Virtual Asset Service Provider
VASP legal name is required
SECP registration number is required
LÆdar AI Website Intelligence
PVARA Regulatory Status
VASP registration and licence status with the Pakistan Virtual Assets Regulatory Authority

Elevated Regulatory Risk. Under SBP BPRD Circular No.10 of 2026, banks should only provide services to VASPs that are registered or in the process of registering with PVARA. A VASP that has not applied for NOC presents elevated regulatory risk. Consider whether to proceed with this review.

Operational Profile
Current operational status and transaction volume
PKR
Step 2 of 6

Beneficial Ownership and Directors

Record all directors, beneficial owners, and key officers of the VASP. Complete PEP status and sanctions screening for each individual. Up to 5 individuals may be recorded.

1
Person 1

PEP Identified. A Politically Exposed Person has been identified in the VASP ownership or management structure. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval is required before proceeding.

2
Person 2

PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.

3
Person 3

PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.

4
Person 4

PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.

5
Person 5

PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.

Overall UBO Assessment
Confirm the completeness of the beneficial ownership review

Corporate UBO Tracing Required. Corporate UBOs require full ownership tracing to identify the ultimate natural person. Obtain a corporate structure chart and shareholder registers for all corporate entities in the ownership chain.

FATF Blacklisted Jurisdiction. A UBO is from a FATF blacklisted jurisdiction. Enhanced due diligence is mandatory under AMLA 2010. Consider whether to proceed with this onboarding.

Step 3 of 6

VASP-Specific Risk Assessment

Assess the virtual assets handled, customer base profile, geographic exposure, and technology controls. These factors feed directly into the risk score calculated in Step 6.

Virtual Assets Handled
Select all virtual asset types the VASP deals in

Privacy Coins -- Elevated ML/TF Risk. Privacy coins present elevated money laundering and terrorist financing risk due to enhanced anonymity features. Specific enhanced controls are required. Consider whether this is acceptable under your bank's risk appetite.

Customer Base Profile

VASP-to-VASP Relationships. Relationships with other VASPs carry elevated risk under FATF Recommendation 16. Travel Rule compliance is mandatory for all transfers with counterpart VASPs. Verify that the VASP has adequate controls for these relationships.

Geographic Exposure
Geographic Markets
Select all jurisdictions in which your VASP will operate or serve customers. Risk classifications are sourced live from the FATF database.
FATF country risk classifications. Source: FATF / OpenSanctions. Last updated: loading.... Verify at fatf-gafi.org before relying on this classification.
Technology and Monitoring Controls

No Blockchain Analytics Tool. This is a significant gap in the VASP's transaction monitoring capability. A blockchain analytics tool is essential for identifying high-risk transactions, sanctions exposure, and illicit fund flows.

No Automated Transaction Monitoring. Manual monitoring processes only present elevated money laundering risk. An automated transaction monitoring system is required for effective AML controls at any meaningful transaction volume.

Step 4 of 6

AML/CFT Programme Review

Review the VASP's AML/CFT/CPF programme against PVARA NOC Regulations 2025 requirements. Each No answer is a mandatory compliance gap that must be resolved before account opening.

No Board-Approved AML/CFT/CPF Policy. This is a mandatory requirement under PVARA NOC Regulations 2025. This VASP does not meet the minimum compliance standard for onboarding.

Not Registered on goAML FMU Portal. goAML FMU registration is mandatory for all VASPs under PVARA NOC Regulations 2025. The VASP cannot file STRs without this registration.

No NACTA Screening. Screening against NACTA proscribed organisations and designated persons is mandatory under PVARA NOC Regulations 2025. Failure to screen constitutes a serious compliance breach.

No MLRO Appointed. Appointment of a qualified MLRO is mandatory under PVARA NOC Regulations 2025. This VASP does not meet the minimum compliance standard.

No Travel Rule Compliance Solution. Travel Rule compliance is required under FATF Recommendation 16 for VASPs conducting virtual asset transfers. The VASP must have a technical solution for transmitting originator and beneficiary data.

Step 5 of 6

SBP BPRD Circular No.10 2026 -- Conditions Checklist

Verify each condition required under SBP BPRD Circular No.10 of 2026 before providing banking services to this VASP. All 15 conditions should be met for onboarding to proceed.

01
VASP is registered with PVARA or has submitted a NOC application to PVARA
02
VASP has provided certified copies of PVARA registration or NOC documents to the bank
03
VASP has a Board-approved AML/CFT/CPF programme that is current and reviewed annually
04
VASP has appointed a qualified Money Laundering Reporting Officer (MLRO)
05
VASP is registered on the goAML Financial Monitoring Unit (FMU) portal
06
VASP conducts NACTA proscription list and sanctions screening on all customers and transactions
07
VASP has documented KYC/CDD onboarding procedures for all customer categories
08
VASP has an operational transaction monitoring capability for detecting suspicious activity
09
VASP maintains customer and transaction records for a minimum of 7 years per NOC Regulations
10
VASP has conducted AML/CFT staff training in the last 12 months
11
VASP has provided most recent audited financial statements to the bank
12
VASP has fully disclosed beneficial ownership structure (all persons owning or controlling 25% or more) to the bank
13
VASP has signed the bank's standard terms and conditions for VASP accounts
14
Senior management of the bank has reviewed and approved the VASP onboarding
15
Enhanced due diligence file has been completed and signed off by the bank's MLRO
-- / 15
Not yet assessed
Answer all 15 checklist items above to see the outcome.
Step 6 of 6

Risk Rating and Decision

Review the auto-calculated composite risk score derived from all previous steps, record the onboarding decision, complete the analyst declaration, and generate the KYC review file.

Composite Risk Score
-- pts
Not yet calculated
Click Recalculate to compute the risk score from your answers in Steps 1 to 5.
MLRO Referral Required

A composite risk score of 9 or above requires referral to the bank's MLRO before an onboarding decision can be recorded. Complete the referral details below.

Onboarding Decision
Decline Decision -- Action Required: A written decline notice must be issued to the VASP in accordance with the bank's procedures. Retain all documentation on file for a minimum of 7 years per AMLA 2010 s.7. Do not destroy this KYC review file.
Narrative summary of the key findings, risk factors identified, and rationale for the decision.
AI-Assisted Narrative (LÆdar AI)

Generate a professional compliance narrative using LÆdar AI, KYCifi's regulatory AI. The output is fully editable before being included in the downloaded review file.

Generating narrative -- please wait...
LÆdar AI Narrative -- Editable Edit freely before downloading
Analyst Declaration
I declare that this VASP Corporate KYC Review has been conducted in accordance with SBP BPRD Circular No.10 of 2026, the Anti-Money Laundering Act 2010, and the bank's internal AML/CFT policies and procedures. The information recorded is accurate to the best of my knowledge based on the documents and representations provided by the VASP. I understand that this review must be retained on file for a minimum of 7 years.
Supervisor Approval
Download and Finalise

Download the complete KYC review file as a PDF. The file includes all answers, the risk score breakdown, the AI narrative (if generated), and the analyst declaration. Retain on file pursuant to SBP BPRD Circular No.10 of 2026.

0161 706 0333 Book Consultation
KYCifi logo KYCifi

Specialist AML, KYC and financial crime compliance advisory for banks, fintechs, payment providers and virtual asset firms.

contact@kycifi.com 0161 706 0333 Manchester, United Kingdom
Connect on LinkedIn →

Services

  • Fractional MLRO
  • Business KYC
  • AML Programme Build
  • Crypto & Digital Assets

Resources

  • Insights
  • Company Intelligence
  • PVARA Resources
  • Book Consultation

Trust & Credibility

  • Practitioner-led
  • Independent Advisory
  • Global Coverage
  • Banking, Fintech & Crypto Expertise

© 2026 KYCifi. All rights reserved.

Privacy Policy Terms & Conditions Cookies Policy

Compliance intelligence powered by LÆdar AI, KYCifi's intelligence platform. Not a law firm. No legal advice provided.

KYCifi provides compliance consulting and documentation support services. We are not a regulated legal or financial advisory firm. Nothing on this website constitutes legal advice. If you require legal advice, please consult a qualified solicitor.

This website does not use tracking or advertising cookies.