Vietnam Tightens AML Oversight on Digital Assets Growth
AML Editor•December 26, 2025

The headline describes a sequence that has repeated across many jurisdictions: activity in digital assets grows, and the anti-money-laundering perimeter is widened to take it in. What follows is background on the framework such measures are normally drawn from, and on what widening that perimeter usually requires of firms.
Why digital assets sit inside the AML perimeter
The international baseline is set by the Financial Action Task Force (FATF), whose recommendations most jurisdictions use as the template for domestic law. FATF treats virtual asset service providers as regulated obliged entities rather than as an unregulated adjacent market, and defines them by function rather than by label. A business generally falls within scope if, as a business for or on behalf of another person, it conducts:
- exchange between virtual assets and fiat currency;
- exchange between one form of virtual asset and another;
- transfer of virtual assets;
- safekeeping or administration of virtual assets, or of the instruments enabling control over them;
- provision of financial services connected to the offer or sale of a virtual asset by an issuer.
Because the test is functional, businesses that describe themselves as technology providers, wallet developers or marketplaces can still be captured. The first task under any new regime is therefore a scoping exercise: establishing which legal entities and which product lines fall inside the definition.
What tightened oversight usually involves
National regimes built on the FATF model tend to share a common set of obligations. Providers must register or obtain a licence, and controllers and senior officers are assessed for fitness and propriety. Customer due diligence must be performed at onboarding and refreshed on a risk-sensitive basis, with enhanced measures for higher-risk relationships such as those involving politically exposed persons or higher-risk jurisdictions. Records must be retained, sanctions screening applied, and suspicious activity reported to the national financial intelligence unit. A requirement distinctive to this sector is the travel rule, under which originator and beneficiary information must accompany transfers between providers — an obligation that is operationally awkward where counterparties sit in jurisdictions that have not yet implemented it.
How compliance is assessed internationally
Adherence is reviewed through mutual evaluation, conducted by FATF or by the FATF-style regional body covering the jurisdiction; in South-East Asia that role belongs to the Asia/Pacific Group on Money Laundering. Evaluations examine both technical compliance — whether the laws exist and say the right things — and effectiveness, meaning whether supervision, reporting and enforcement actually function in practice. Weak outcomes can lead to follow-up reporting or to placement under increased monitoring, which in turn affects how foreign correspondent banks and counterparties price the risk of dealing with local institutions.
What firms typically do in response
- map products and entities against the statutory definition of a regulated provider;
- appoint a responsible compliance officer and document a board-approved business-wide risk assessment;
- implement identity verification, sanctions screening and blockchain analytics for wallet and counterparty risk;
- adopt a travel rule messaging solution and a documented policy for transfers involving self-hosted wallets;
- establish suspicious-transaction reporting lines to the financial intelligence unit, and test that they work;
- commission independent testing of the programme once it is operating.
Sequencing matters more than speed. Regimes of this kind normally carry transitional periods, and firms that use them to build evidence of a functioning programme tend to fare better than those treating registration as the end of the exercise rather than the beginning.
