Pakistan flag on blue background

Pakistan

Pakistan's Virtual Assets Act, 2026 introduces the country’s first comprehensive legal framework for overseeing virtual assets and the businesses operating in this sector.

A key focus of the framework is compliance with global Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) requirements. These measures are intended to help prevent the misuse of virtual assets for illegal activities while aligning Pakistan’s regulatory framework with international Financial Action Task Force (FATF) standards.

The framework establishes requirements for Virtual Asset Service Providers (VASPs), covering areas including customer due diligence, transaction monitoring, record-keeping, sanctions screening, data security and Travel Rule compliance.

Breakdown of Pakistan's Crypto Travel Rule. Includes threshold, self-hosted wallets, supervisory body and when to comply. White and green text on blue background with 21 Analytics logo and contact details
Breakdown of Pakistan's Travel Rule Regulations


What is the scope of the Travel Rule in Pakistan?

The framework applies to any VASP that carries out a virtual asset service in or from Pakistan. It also applies to any Issuer that offers, originates or distributes a virtual asset on its own behalf in or from Pakistan.

Licensees must comply with the Travel Rule and applicable requirements under the Federal AML-CFT Laws, including requirements implementing FATF Recommendation 16 and its Interpretive Note.

It is important to note the distinction between VASP and Licensee. Under the Pakistani virtual asset framework, VASP describes any person who, as a business, provides one or more virtual asset services to third parties on a professional basis, while Licensee describes the legal status of an entity that has obtained a licence under the Pakistani framework. 


Who is the supervisory body for VASPs in Pakistan?

The Pakistan Virtual Assets Regulatory Authority (PVARA) 


What is the Travel Rule threshold in Pakistan?

The Travel Rule applies to virtual asset transfers meeting or exceeding the threshold of the PKR equivalent of USD 1 000.

For transfers at or above this threshold, a Licensee must obtain, verify where required, and transmit or make available the required and accurate originator and beneficiary information, which includes:

  • originator’s full name;
  • originator’s account number, virtual asset wallet address or another unique transaction identifier; and
  • any additional identifiers required under applicable law, which may include an address, national identification number, customer identification number, or date and place of birth.
  • beneficiary’s name; 
  • beneficiary’s account number, virtual asset wallet address or another unique transaction identifier.


Obligations of Virtual Asset Service Providers

Licensees have a range of obligations to support Travel Rule compliance and broader AML/CFT/CPF requirements.

Counterparty due diligence

Before establishing a material relationship for virtual asset transfers with a counterparty VASP in another jurisdiction, Licensees must conduct risk-based due diligence on the counterparty’s Travel Rule and AML/CFT controls.

This due diligence must be reviewed annually and whenever heightened risk indicators arise.

Risk-based controls

Licensees must address risks relating to:

  • Deposits and withdrawals where counterparty information is incomplete, unavailable or unreliable;
  • Transactions or patterns designed to evade thresholds or information requirements; and
  • Anonymity-enhancing features or services, where applicable.

Licensees must also maintain controls covering customer due diligence, transaction monitoring, record-keeping, suspicious activity reporting and sanctions screening as part of the broader AML/CFT/CPF framework.

Transaction integrity and accuracy

Licensees must establish controls to ensure the integrity and accuracy of transfers and settlements. These include:

  • Pre-execution validation of transfer instructions;
  • Verification of destination details, including wallet addresses and account identifiers;
  • Reconciliation between internal records and on-chain or account balances; and
  • Error-prevention measures appropriate to the business model.

Licensees must also maintain documented procedures for failed, delayed, erroneous and disputed transfers. These procedures must cover identification and escalation, timely communication with affected clients and counterparties, remediation and, where appropriate, compensation arrangements.

A Licensee must not process a transfer instruction where available information creates a material concern that the destination is invalid, incomplete or inconsistent with the client’s instruction, or otherwise presents a material risk of error, fraud, sanctions breach or loss, unless the issue is first resolved.

Transaction monitoring and suspicious activity

Licensees must implement transaction monitoring systems to detect suspicious patterns and unusual activities.

Suspicious transactions or activities must be reported to the FMU.


Obligations of Originator Virtual Asset Service Providers

Before initiating a virtual asset transfer at or above the applicable threshold, the ordering Licensee must ensure that it has obtained and holds the required originator and beneficiary information.


Obligations of Beneficiary Virtual Asset Service Providers

Before making the received virtual assets received to a customer, the beneficiary Licensee must ensure that it has obtained and holds the required originator and beneficiary information.


Does Pakistan's Travel Rule apply to self-hosted wallets?

Licensees must establish and maintain controls governing transfers involving external wallet (self-hosted wallet) addresses. These controls must cover, as applicable, wallet verification, sanctions screening, Travel Rule compliance, transaction monitoring, source and destination checks, and risk-based restrictions.

Licensees must implement risk-based controls to manage Travel Rule compliance risks relating to transfers to or from self-hosted wallets and other non-obliged persons, with regard to relevant FATF Standards and guidance.

Transfers to or from self-hosted, unverified or otherwise non-compliant wallet arrangements are not permitted unless they are carried out in accordance with controls, conditions, restrictions or approvals specified by the Authority.

The Authority may also restrict, prohibit or impose conditions on transfers involving self-hosted wallets, privacy-enhancing technologies, anonymising protocols, mixers, cross-chain bridge arrangements or other arrangements that materially impair regulatory visibility, AML/CFT/CPF compliance or transaction traceability.


When do you need to comply with Pakistan's Travel Rule?

Now - The Travel Rule is live. 

Become Travel Rule Compliant with 21 Analytics

Request a Demo


Which regulations are applicable to Pakistan's Travel Rule?

Pakistan Virtual Asset Services Regulations, 2026 (S.R.O. 1419(I)/2026)

Pakistan Virtual Asset Regulatory Authority Notification (S.R.O. 1420(I)/2026)

The Virtual Assets Act, 2026

Written by:
About Nicole
Nicole Giani
Content & Social Media Manager
With an Honours in English Linguistics, Nicole started her career as an educator before transitioning to education management and curriculum development.  Thereafter, she moved to crypto writing - uniting her passion for education with crypto to educate the ecosystem on the Travel Rule.
X
Trust Graphic

New: TRUST Network

Transact with Coinbase, Kraken, Gemini and others.