Custodial wallet / SaaS in Andorra
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Andorra with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs are obliged entities under Law 9/2023 and Law 14/2017 (ad.aml.law-92023-of-23-march, ad.aml.law-142017-of-22-june)
- Risk-based Customer Due Diligence (CDD) on all clients — identity verification using reliable independent source documents (ad.aml.identification-and-verification, ad.aml.vasps-must-apply-a-risk-based)
- Beneficial ownership identification at the 25%+ threshold (ad.aml.beneficial-ownership-bo)
- Ongoing monitoring of business relationships and transactions (ad.aml.conduct-ongoing-due-diligence-on)
- Suspicious Activity Reporting (SAR) to UIFAND — Andorra's Financial Intelligence Unit (ad.licensing.suspicious-activity-reporting-sar-reporting)
- Appointment of a qualified AML officer (ad.licensing.designation-of-an-aml-officer)
- Record-keeping of client ID, transactions, and due diligence for a specified period (ad.licensing.record-keeping-maintaining-records-of)
- Risk assessment covering business, clients, products, and geographies (ad.licensing.risk-assessment-conducting-a-comprehensive)
- The white-label client (if performing any VASP activity itself) may have its own independent AML obligations; the SaaS operator must satisfy AML requirements as a VASP in its own right
Key Restrictions
- Must be authorized by the Autoritat Financera Andorrana (AFA) as a VASP under Ley 28/2022 (ad.custody.requirement-any-entity-providing-custody)
- Minimum initial capital of EUR 125,000 for custody and administration of virtual assets (ad.licensing.eur-125000-for-services-related)
- Higher capital may be required based on volume/complexity of operations (ad.licensing.higher-amounts-may-be-required)
- Must maintain sufficient regulatory capital to cover operational risks and continuous solvency (ad.licensing.in-addition-to-initial-capital)
- Must have physical operational base in Andorra (ad.licensing.physical-office-establishing-an-operational)
- Client virtual assets must be clearly identifiable and protected from the custodian's own assets; commingling risks client assets (ad.custody.authorized-vasps-providing-custody-services)
- AFA expects state-of-the-art cybersecurity protocols including cold/warm/hot storage strategies with multi-signature or MPC (ad.custody.the-afa-in-its-assessment)
- Detailed segregation and insolvency-protection rules to be specified in secondary regulations / AFA guidance (ad.custody.detailed-rules-on-how-client)
- Professional indemnity insurance or equivalent guarantees likely required (ad.custody.it-is-highly-probable-that)
Key Risks
- Ley 28/2022 is relatively new (May 2023 effective date) — secondary regulations on segregation, insurance, and proof-of-reserves are not yet finalized, creating regulatory ambiguity (ad.custody.ley-282022-is-relatively-new, ad.custody.detailed-rules-on-how-client)
- The AFA may impose additional capital or insurance requirements through future guidance that are not yet known
- Conflicting or outdated facts exist in the source material (e.g., references to Brazil's regulations, US FAR, GENIUS Act) which must be ignored — this reduces confidence in completeness
- White-label SaaS model creates ambiguity: the SaaS provider is the VASP and bears full licensing/AML obligations, but white-label clients may also require their own VASP authorization depending on their activities
- No explicit proof-of-reserves or audit requirement is established in primary legislation — future AFA guidance may impose such obligations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Requirement: Any entity providing custody services for virtual assets on behalf of third parties is considered a "Virtual Asset Service Provider" (VASP) under Ley 28/2022 and must be authorized by the Autoritat Financera Andorrana (AFA).
Definition of Custody: Article 3, point 16 of Ley 28/2022 defines "custodia de activos virtuales" (custody of virtual assets) as the safekeeping or administration of virtual assets or instruments enabling control over them on behalf of third parties.
Applicants must comply with stringent requirements covering corporate governance, internal controls, risk management, financial resources (including minimum capital), anti-money laundering (AML) and counter-terrorist financing (CFT) policies, and operational integrity.
Ley 28/2022, de 15 de desembre, de representació digital d'actius: Articles 3.16, 5, 8, 9, and subsequent articles detailing VASP authorization.
Autoritat Financera Andorrana (AFA): Regulator responsible for VASP authorization.
Authorized VASPs providing custody services are subject to fiduciary duties and robust internal control requirements. This implies that client assets must be clearly identifiable, protected from the custodian's own assets, and not be used for proprietary trading or commingled in a way that risks their availability to the client.
Detailed rules on how client virtual assets must be held, distinguished from the custodian's own assets, and protected in the event of insolvency, will be specified in secondary regulations and AFA guidance. This is a common practice where the foundational law sets the principle, and the regulator provides the operational details.
The AFA, in its assessment of a VASP's operational security and risk management policies, would expect state-of-the-art cybersecurity protocols, which typically incorporate cold, warm, and hot storage strategies with multi-signature authorization or multi-party computation (MPC), and robust disaster recovery plans, tailored to jurisdiction-specific risks.
It is highly probable that the AFA, through secondary regulations, will require VASPs providing custody services to hold specific professional indemnity insurance or equivalent guarantees (e.g., capital buffers, guarantees from parent companies, or specific bonding) to cover potential operational risks, cyberattacks, or negligence resulting in loss of client assets. This is standard practice for regulated financial services and high-risk activities.
Ley 28/2022 is relatively new, having been approved in December 2022 and entering into force in May 2023.
Custody and administration of digital assets on behalf of third parties: This covers services where an entity holds or controls private keys for virtual assets on behalf of clients.
There is no specific EUR 125,000 threshold for custody and administration services for virtual assets under Andorra’s Law 24/2022; licensing is based on compliance requirements rather than a fixed monetary amount.
Higher amounts may be required depending on the volume and complexity of operations, or if combined with other licensed activities.
In addition to initial capital, VASPs must maintain sufficient regulatory capital to cover operational risks and ensure continuous solvency.
Physical office: Establishing an operational base in Andorra.
AML/KYC (Anti-Money Laundering / Know Your Customer):
Customer Due Diligence (CDD): Implementing appropriate risk-based procedures for identifying and verifying the identity of clients (individuals and legal entities).
Ongoing Monitoring: Continuous monitoring of business relationships and transactions to detect unusual or suspicious activities.
Risk Assessment: Conducting a comprehensive risk assessment of their business, clients, products, and geographies.
Suspicious Activity Reporting (SAR): Reporting suspicious transactions to the Unitat d'Inteligència Financera d'Andorra (UIFAND).
Record Keeping: Maintaining records of client identification, transactions, and due diligence for a specified period.
Designation of an AML Officer: Appointing a qualified AML officer responsible for overseeing compliance.
Law 14/2017 of 22 June on the prevention and fight against money laundering and the financing of terrorism: This is Andorra's principal AML/CFT law, establishing the general obligations for all obliged entities. It has been subsequently amended to incorporate international recommendations.
Law 9/2023 of 23 March on digital assets: This specific law regulates virtual assets and their service providers, bringing VASPs under the scope of Law 14/2017 and defining the specific licensing and operational requirements for these entities. This law formally identifies VASPs as obliged entities for AML/CFT purposes.
Custody and/or administration of virtual assets or instruments enabling control over virtual assets.
Conduct ongoing due diligence on the business relationship, including scrutinizing transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity’s knowledge of the customer, their business, and risk profile.
VASPs must apply a risk-based approach to CDD. This means the intensity of CDD measures should be proportionate to the assessed ML/TF risks.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet / SaaS provider must obtain AFA authorization as a VASP under Ley 28/2022 (minimum EUR 125,000 capital, physical Andorran presence, state-of-the-art cybersecurity/storage, AML/CFT compliance under Laws 14/2017 and 9/2023), with detailed segregation, insurance, and proof-of-reserves rules pending secondary regulations.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?