There is a dangerous sentence in almost every regulatory project:

“We have submitted the application, so the clock has started.”

Under Pakistan’s PVARA framework, that may be wrong.

Uploading Form II and a folder full of policies does not automatically make a licence application complete. The regulatory clock begins only when the Pakistan Virtual Assets Regulatory Authority confirms in writing that all required information and documents have been received in a satisfactory form.

That distinction—between submitted and complete—can separate a controlled licensing project from months of unexpected delay.

This guide provides a practical PVARA application checklist, covering Form I, the No Objection Certificate (NOC), Pakistan incorporation, Form II and the 35 principal documentation categories required for a full Virtual Asset Service Provider licence.

PVARA documentation 

  • Standard pathway: NOC → regulatory registrations → Pakistan incorporation → full VASP licence
  • NOC application: Form I and Parts A–E of its Annexure
  • Full licence application: Form II, the updated Annexure to Form I and Part F evidence | Part F: 35 principal document categories
  • NOC review: 60 days after completeness
  • NOC validity: Three months, extendable by up to another three months
  • Licence review: 90 days after completeness, extendable by up to 60 days
  • Incomplete response: The decision clock is suspended while requested information remains outstanding

How the PVARA application process is structured

The standard NOC-to-licence route has two regulatory submissions separated by a corporate implementation phase.

Stage 1: Form I and the NOC

An applicant intending to establish a Pakistan company for virtual asset services submits Form I under regulation 6 of the Pakistan Virtual Asset Services Regulations, 2026. Parts A–E of the Annexure principally apply at this stage.

PVARA assesses the proposed activities, owners, controllers, directors, business plan, funding, financial projections, delivery model and initial licensing readiness.

An NOC is not a VASP licence and does not authorise commercial virtual asset services. It is preliminary approval to proceed towards the regulated Pakistan structure.

Stage 2: Implementation after the NOC

The successful applicant completes applicable Financial Monitoring Unit and other regulatory registrations, incorporates the Pakistan entity, injects capital, appoints personnel, contracts with vendors and implements the control environment.

Stage 3: Form II and the full licence

The incorporated Pakistan company submits Form II under regulation 7. It must provide the Annexure to Form I again, updated where necessary, together with the Part F licensing documents and the prescribed processing fee.

PVARA’s licensing page and application portal provide access to the NOC, Sandbox and VASP licence pathways.

Phase 1 checklist: Work to complete before Form I

The best PVARA NOC application begins with a controlled evidence-gathering process.

1. Regulatory classification

Prepare a written analysis mapping every activity to the relevant PVARA category:

  • Advisory Services;
  • Broker-Dealer Services;
  • Custody Services;
  • Exchange Services;
  • Lending and Borrowing Services;
  • Virtual Asset Derivatives Services;
  • Management and Investment Services;
  • Transfer and Settlement Services;
  • Fiat-Referenced or Asset-Referenced Token Issuance; and
  • Mining-Related Virtual Asset Services.

The analysis should also record exclusions, incidental functions and possible SBP, SECP, FMU or foreign-exchange overlap.

Do not allow the licence categories to be chosen from a marketing description. Use transaction flows, wallet control, order execution, customer agreements and revenue mechanics.

2. Applicant and ownership file

Collect:

  • sponsor and proposed-company details;
  • identity and address documents;
  • shareholder and ultimate-beneficial-owner information;
  • ownership and group charts;
  • voting and control rights;
  • associated-company details;
  • net-worth information;
  • source-of-wealth and source-of-funds evidence; and
  • any shareholder, nominee or voting arrangements.

The structure must identify Controllers, including persons holding or controlling at least 20% or exercising significant influence.

3. Proposed governance file

Identify the proposed directors, Managing Director or CEO and other Key Individuals. Prepare curricula vitae, employment histories, qualifications, business interests, regulatory history, litigation and enforcement disclosures.

The proposed governance model should anticipate at least three directors and ordinarily one-third independent representation. It should also show resident decision-making authority and a resident Compliance Officer at the licensing stage.

4. Business-model evidence

Prepare diagrams showing:

  • legal and operational entities;
  • order and execution flow;
  • fiat and virtual asset movement;
  • wallet and private-key control;
  • customer onboarding;
  • liquidity and counterparty relationships;
  • custody and settlement;
  • fees, spreads and other revenue; and
  • outsourced and group-supported functions.

These diagrams should use the same entities, product names and terminology as the business plan and Form I.

Phase 2 checklist: Form I and the NOC documentation

Form I must be signed by all sponsors and proposed directors. The information must be true, complete and correct, and material changes must be notified without undue delay.

The Annexure is divided into five main NOC-stage parts.

Part A: Applicant information

Complete and verify:

  • applicant name and proposed company name;
  • intended legal form—private limited, public unlisted or public listed;
  • proposed licence category or categories;
  • draft memorandum and articles of association;
  • proposed registered-office details;
  • authorised contact person;
  • proposed directors, shareholders, sponsors and CEO;
  • percentage shareholding and net worth; and
  • identification of each Controller.

Check the proposed name and corporate objects against the intended PVARA activities. A company constitution drafted for generic software services may not support a regulated exchange, custody or token-issuance business.

Part B: Capital and financial information

The application should address:

  • proposed authorised capital;
  • proposed paid-up capital;
  • applicable Schedule I minimum;
  • capital source and availability;
  • capital-injection plan;
  • board-approved capital-maintenance arrangements;
  • liquidity calculation and methodology;
  • 12-month capital and liquidity forecast; and
  • base and stress scenarios.

The applicant must attest that it will meet and maintain the capital and net-liquid-assets requirements. If applying for several categories, explain the prudential treatment and any assumptions requiring PVARA confirmation.

Part C: Business plan and financial projections

A credible PVARA business plan should cover:

  • executive summary and strategic rationale;
  • regulated services and initial product scope;
  • target customers and geographical markets;
  • branding, marketing and distribution;
  • revenue model and fee structure;
  • customer journey and transaction lifecycle;
  • custody model—internal, third-party or hybrid;
  • omnibus, segregated or mixed wallet structure;
  • liquidity providers, custodians, banks and partners;
  • technology and cybersecurity architecture;
  • governance and staffing plan;
  • AML/CFT, sanctions and transaction monitoring;
  • customer-asset safeguarding;
  • risk management and operational resilience;
  • outsourcing and group dependencies; and
  • implementation and wind-down strategy.

Three-year financial projections should include profit and loss, balance sheet, cash flow, customer and volume assumptions, capital position, liquidity and downside stress.

Every figure should tell the same story. If the plan forecasts 100,000 retail customers but budgets for one compliance analyst and minimal screening costs, the issue is not just financial modelling. It is operational credibility.

Jurisdictional delivery model

Part C also requires a clear explanation of:

  • whether services are provided onshore, cross-border or digitally;
  • which legal entity provides each service;
  • jurisdictions in which group entities are incorporated or regulated;
  • retail, professional or institutional customer segments;
  • geo-targeting, geo-blocking and eligibility controls;
  • location of onboarding, compliance, custody, support and complaints; and
  • use of branches, affiliates, agents, distributors or outsourced providers.

For an international group, this section is where the applicant proves that the Pakistan company will be more than a nameplate subsidiary.

Part D: Sponsors, CEO and directors

Prepare complete schedules for each relevant person, covering:

  • full legal name;
  • CNIC, NICOP or passport;
  • nationality and residential address;
  • proposed position and directorship type;
  • contact details and tax status;
  • highest academic or professional qualification;
  • positions held during the previous ten years;
  • experience certificates;
  • shareholdings of at least 10% in other businesses;
  • affiliations and outsourcing relationships;
  • legal proceedings;
  • insolvency or bankruptcy; and
  • criminal, penal, regulatory or disciplinary action.

Do not use “none” without internal verification. Search group records, public regulatory registers, litigation files and the individual’s full business history.

Part E: Declarations and confirmations

The sponsors and proposed leadership provide extensive confirmations concerning:

  • accuracy and completeness of information;
  • compliance with the regulatory framework;
  • illegal banking or deposit-taking activity;
  • loan and financial defaults;
  • tax defaults;
  • fraud, breach of trust and misconduct;
  • insolvency and creditor defaults;
  • fitness and propriety;
  • interests in other licensed VASPs;
  • the Managing Director’s other appointments;
  • UBO criminal history;
  • sanctions and designated-person status; and
  • authority of the person representing the applicant.

These are legal declarations, not administrative boilerplate. Verify them through a signed internal questionnaire and supporting checks before execution.

Phase 3 checklist: Submitting and managing the NOC

Before submission, confirm that:

  • Form I and every annexure are complete;
  • all sponsors and proposed directors have signed where required;
  • identity documents are valid and legible;
  • translations and certifications are included where required;
  • the licence categories match the business plan;
  • ownership percentages total correctly;
  • Controllers and UBOs are consistently identified;
  • financial projections reconcile across all statements;
  • application-fee evidence is attached once the amount is confirmed; and
  • filenames and annexure references are accurate.

Under regulation 6, PVARA is to grant or refuse a complete NOC application within 60 days. PVARA can request additional information, so maintain a regulatory-questions log and update every affected document when an answer changes the model.

An issued NOC is valid for three months. A reasoned extension request made before expiry may extend it for up to another three months. The NOC can be withdrawn if obtained through materially false, misleading or incomplete information.

Phase 4 checklist: Post-NOC implementation

The period after the NOC is not simply a wait for Form II. It is when the proposed VASP becomes a licensable institution.

Corporate documents

Obtain and organise:

  • certificate of incorporation under the Companies Act, 2017;
  • CUIN and statutory registers;
  • final memorandum and articles;
  • registered-office evidence;
  • shareholder and board resolutions;
  • share-issuance and capital records;
  • tax and applicable FMU/goAML registrations; and
  • Pakistan bank-account evidence.

Confirm that the final entity, ownership, capital and directors remain consistent with the NOC.

Staffing and governance documents

Finalise:

  • employment or appointment letters;
  • job descriptions;
  • organisational chart;
  • delegated-authority matrix;
  • board and committee terms of reference;
  • board skills matrix;
  • Compliance Officer and MLRO responsibilities;
  • conflicts and outside-interest declarations; and
  • board-approved policies and implementation minutes.

Capital and vendor evidence

Collect bank evidence showing paid-up capital, its source and continuing availability. Finalise material contracts with custodians, banks, liquidity providers, KYC and blockchain-analytics vendors, cloud providers and group-service companies.

The contract file should include audit, data access, security, incident notification, business continuity, subcontracting, regulatory cooperation and exit rights.

Phase 5 checklist: Form II and all Part F licence documents

Form II is submitted after Pakistan incorporation and within the NOC validity period. It identifies the company, NOC and requested licence categories and is signed by the sponsors and directors.

The updated Annexure to Form I must accompany Form II. Part F identifies the following 35 principal requirements.

Corporate, ownership and financial evidence

  1. Certificate of incorporation: Evidence that the applicant is incorporated under the Companies Act, 2017.
  2. Shareholder and UBO list: Complete direct and indirect ownership information.
  3. Directors and Key Individuals: Final role holders and responsibility allocation.
  4. Fit-and-proper affidavits: Prescribed Annexure A affidavit for every sponsor, Controller, director and Key Individual.
  5. Paid-up capital evidence: Proof that capital is injected and maintained in Pakistan, with acceptable repatriation and availability arrangements.
  6. Source-of-funds evidence: Documents tracing the origin and transfer of regulatory capital.
  7. Organisational structure: Group chart and list of associated companies.
  8. Official website address: The live or controlled website intended for the VASP.
  9. Insurance contracts: Professional indemnity and commercial crime cover effective before regulated activity begins.

Governance and enterprise-control documents

  1. Wind-down plan: Solvent and stressed exit, customer communication, asset return, records and accountability.
  2. Outsourcing policy: Classification, due diligence, approval, monitoring, concentration, exit and register requirements.
  3. Anti-bribery and corruption policy: Risk assessment, gifts, third parties, reporting, investigation and training.
  4. Conflicts-of-interest policy: Identification, prevention, recusal, disclosure and conflicts-register procedures.
  5. Personal-data protection mechanism: Collection, access, retention, security, sharing and breach arrangements.
  6. FATF and AML/CFT/CPF policy: CDD, beneficial ownership, sanctions, blockchain analytics, monitoring, reporting and Travel Rule.
  7. Marketing policy and plan: Approval, risk warnings, channels, affiliates, influencers, claims and recordkeeping.
  8. Market-conduct policy: Fair treatment, disclosures, execution, manipulation, conflicts and customer communications.
  9. Records-management policy: Ownership, format, retrieval, security, retention and regulatory access.

Technology, security and resilience documents

  1. Technology infrastructure design: Architecture, systems, integrations, data and critical dependencies.
  2. Technology-governance and risk framework: Ownership, change management, testing, vendor risk and board oversight.
  3. Business continuity and disaster recovery: Impact analysis, recovery targets, backups, communications and testing.
  4. Key and wallet-management policy: Generation, storage, access, approval, backup, recovery, rotation and destruction.
  5. Information-security policy: Data classification, access, encryption, monitoring and asset protection.
  6. Cybersecurity policy: Threat management, vulnerability testing, incident response and regulatory notification.

Customer, compliance and activity-specific documents

  1. Complaint-handling mechanism: Intake, investigation, escalation, resolution, reporting and records.
  2. Insider list: Persons with access to inside or material non-public information.
  3. Compliance manual: Regulatory obligations, monitoring plan, breaches, training, reporting and board oversight.
  4. Client-asset protection and segregation: Money and virtual asset accounts, wallets, reconciliations, insolvency treatment and proof of reserves.
  5. Risk-management framework: Risk taxonomy, appetite, assessment, limits, controls, reporting, stress tests and remediation.
  6. Five-year regulatory history: Material enforcement, supervisory findings and regulatory actions affecting the applicant or group.
  7. Overseas regulatory approvals: Current and historic virtual asset authorisations held in other jurisdictions.
  8. Client onboarding and consumer protection: Customer classification, KYC, suitability where relevant, disclosures and vulnerable-customer safeguards.
  9. Virtual asset listing policy: Admission, due diligence, risk classification, monitoring, suspension and delisting.
  10. Virtual assets to be managed: Product universe, rights, risks, protocols, liquidity and restrictions.
  11. Other information: Any additional evidence requested by PVARA.

Not every item applies identically to every category, but “not applicable” should be supported by a reason. For example, a non-custodial advisory applicant may explain why a wallet-management policy is inapplicable while still documenting how it prevents custody or control.

What a regulator-ready policy should contain

A policy title is not evidence of compliance. Each material document should answer:

  1. Scope: Which entity, product, customer and system does it cover?
  2. Ownership: Which board committee or Key Individual is accountable?
  3. Rules: What must or must not happen?
  4. Procedure: Who performs each step, using which system?
  5. Thresholds: What triggers review, rejection or escalation?
  6. Evidence: Which records prove the control operated?
  7. Reporting: What reaches management, the board or PVARA?
  8. Testing: How is effectiveness checked?
  9. Exceptions: Who approves them, and how are they recorded?
  10. Review: When is the document updated?

Generic language becomes obvious when PVARA asks for a system demonstration or sample record. If the policy refers to a committee, tool or approval layer that does not exist, it weakens the entire submission.

Final completeness and consistency review

Before filing Form II, perform a line-by-line review across:

  • Form I and Form II;
  • NOC and its conditions;
  • incorporation and shareholder records;
  • business plan and financial projections;
  • capital and banking evidence;
  • ownership and fit-and-proper files;
  • policies and procedures;
  • customer agreements and disclosures;
  • vendor and outsourcing contracts;
  • website and marketing materials;
  • technology and wallet diagrams; and
  • system configuration and test evidence.

Check for conflicting legal entities, outdated personnel, different customer types, unexplained product names, inconsistent wallet models, incorrect ownership percentages and financial assumptions that changed after the NOC.

Maintain a master document register containing the filename, version, owner, approving body, signature date, regulatory reference, applicability, submission date and replacement history.

PVARA review, information requests and the completeness clock

Under regulation 7, PVARA decides on a complete licence application within 90 days. It may extend the period by up to 60 days for complexity, novel risks or consultation with other authorities.

The application is complete only when PVARA confirms in writing that the information and documents have been received satisfactorily. When PVARA requests information, the decision period is suspended until the response is provided.

Every response should therefore:

  • answer the precise question;
  • identify affected documents;
  • explain any change from the original filing;
  • attach verifiable evidence;
  • receive appropriate internal approval; and
  • be added to the application’s permanent audit trail.

Speed matters, but consistency matters more. A quick answer that contradicts the business plan can create several new questions.

Application fees

Regulation 11 refers to processing, licensing, annual supervisory, renewal and other fees. Processing fees are non-refundable, and annual fees are payable in advance.

However, as at 24 August 2026, numerical fee amounts are not stated in the notified regulations or PVARA’s public licensing materials; the forms contain placeholders. Applicants should obtain the current schedule through the portal or directly from PVARA and should not insert unofficial figures.

Common documentation failures

  1. A generic business plan: It describes the market but not the actual transaction lifecycle.
  2. Untraceable capital: Bank evidence does not explain the ultimate source of the money.
  3. Inconsistent ownership: Group charts, forms and corporate records show different percentages or Controllers.
  4. Template policies: Documents mention systems, committees or personnel that do not exist.
  5. Unsigned governance: Policies are drafted but have no board approval or effective date.
  6. Missing implementation evidence: The applicant cannot produce sample files, logs, reconciliations or test results.
  7. Poor version control: PVARA receives conflicting copies of the same document.
  8. Unsupported “not applicable”: The applicant excludes a document without analysing its business model.
  9. Stale information: Personnel, vendors or products change after the NOC but the application is not updated.
  10. Fragmented responses: Legal, technology and compliance teams answer PVARA differently.

Final word

A complete PVARA application is not the one with the most files. It is the one in which every required fact can be found, verified and connected to a functioning control.

Form I introduces the proposed business. The NOC permits the structure to move forward. Incorporation creates the applicant. Form II asks whether that applicant is genuinely ready to become a regulated VASP.

Treat the documentation as evidence of a real institution—not content created merely for the portal. When the ownership chart, business plan, capital, policies, contracts, people and systems all tell the same story, the application becomes easier to assess and far more difficult to misunderstand.

Legal disclaimer: This article provides general information as at 24 August 2026 and does not constitute legal, regulatory, tax, financial or investment advice. PVARA may issue new forms, fee schedules, directions, documentary standards or interpretations. Applicants should obtain professional advice and confirm the current application and documentation requirements directly with PVARA and other relevant authorities.

FAQs

1. What documents are needed for a PVARA NOC?

Form I and Parts A–E of its Annexure principally govern the NOC stage. They cover the applicant, proposed company, licence categories, ownership, directors, capital, business plan, projections, custody, delivery model, regulatory history and declarations.

2. What documents are needed for the full PVARA licence?

The incorporated Pakistan company submits Form II, an updated Annexure to Form I and the Part F evidence pack containing 35 principal categories of corporate, governance, financial, AML, conduct, technology, customer-asset and risk documentation.

3. Does PVARA’s 90-day period begin when Form II is uploaded?

Not necessarily. The period starts when PVARA confirms in writing that the application is complete. It is suspended while requested information is outstanding.

4. Must every policy be operational before submission?

The applicant should be able to demonstrate that its material controls are implemented or will satisfy any clearly defined pre-commencement conditions. Policies describing fictional or entirely future systems create serious readiness concerns.

5. Can foreign group policies be submitted?

They may support the application, but they must be localised to the Pakistan entity, PVARA requirements, local reporting lines, customer model and applicable laws. Group policy does not replace local accountability.

6. Can PVARA ask for documents not listed in Part F?

Yes. Item 35 and the Authority’s general information powers permit additional requests based on the application and its risks.