← Regulations / Albania / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Albania

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Albania with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) — identify and verify natural persons (ID/passport) and legal entities (incorporation docs, beneficial ownership) under Article 8-13 of Law No. 119/2019
  • Beneficial ownership identification — identify and verify beneficial owners, understanding ownership and control structure
  • Ongoing monitoring — scrutinize transactions throughout the business relationship on a risk-sensitive basis
  • Risk-based approach — apply simplified CDD (SDD) for low-risk relationships and enhanced CDD (EDD) for PEPs, high-value transactions, or higher-risk scenarios
  • Suspicious transaction reporting — report promptly (no threshold) to the General Directorate for the Prevention of Money Laundering (GDPML) if there is knowledge, suspicion, or reasonable grounds of criminal proceeds or terrorism financing
  • Record-keeping — maintain CDD, business relationship, and transaction records for at least 5 years after the end of the relationship or occasional transaction
  • Internal AML policies — establish and maintain AML/CFT policies, controls, and procedures proportionate to nature and size
  • AML officer — appoint a designated compliance officer at management level
  • Staff training — implement ongoing AML/CFT training programs for relevant staff
  • Institutional risk assessment — conduct risk assessments of ML/TF exposure
  • Tipping-off prohibition — cannot inform customers or third parties about a suspicious transaction report or investigation
  • Protection for reporters — legal protection for VASPs and employees who report suspicions in good faith

Key Restrictions

  • Must obtain prior authorization from the Albanian Financial Supervisory Authority (FSA) under Article 12 of Law No. 110/2020
  • Must be established as a legal entity in Albania with minimum capital requirements set by FSA secondary legislation
  • Client virtual assets must be segregated from proprietary assets (Article 21 — separate accounts, clear identification, regular reconciliation)
  • Must implement robust internal control mechanisms, governance, and risk management under Article 15 of Law No. 110/2020
  • Must comply with IT security and operational resilience requirements under Article 15 of Law No. 110/2020
  • Must meet 'fit and proper' criteria for directors and significant shareholders
  • Ongoing FSA reporting and client transparency obligations apply
  • No explicit statutory insurance or proof-of-reserves requirement — but the mandated risk management and capital buffer indirectly require financial stability against asset loss

Key Risks

  • Limited secondary legislation — the FSA has not yet issued detailed secondary regulations on capital requirements and specific custody operational rules, creating regulatory ambiguity
  • MiCA alignment pending — Albania is an EU candidate country and may adopt MiCA-level rules, potentially changing segregation, liability, and insurance requirements for custodians
  • Enforcement precedent — the Thodex case (founder arrested in Albania for international fraud/ML) signals that the authorities will act on crypto-related cross-border financial crime
  • SaaS model ambiguity — Law No. 110/2020 addresses DLT service providers broadly; the distinction between the SaaS custody provider (licensed VASP) and the white-label client (potentially also a VASP) is not clearly delineated in the facts available
  • No explicit insurance / proof-of-reserves rule — while Article 21 requires client asset protection, the absence of a statutory bonding or insurance mandate may expose operators to gaps in commercial coverage expectations from institutional clients

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Law No. 110/2020 "On Financial Markets Based on Distributed Ledger Technology": This is the foundational legal act regulating DLT-based financial markets and virtual assets in Albania. It defines virtual assets, DLT service providers, and sets out licensing and operational requirements.

licensing 20% confidence

Authorization from FSA: Any entity intending to offer DLT services, including custody of virtual assets, must obtain prior authorization from the FSA (Article 12).

licensing 20% confidence

Legal Form and Capital: Applicants must be established as legal entities in Albania and meet minimum capital requirements, which are determined by secondary legislation issued by the FSA.

licensing 20% confidence

Governance and Management: Requirements for sound and prudent management, including "fit and proper" criteria for directors and significant shareholders, robust internal control mechanisms, risk management procedures, and administrative arrangements.

licensing 20% confidence

Operational Capacity: Adequate technical and human resources to perform the intended services securely and efficiently. This implicitly covers aspects like cybersecurity, data protection, and operational resilience.

licensing 20% confidence

AML/CFT Compliance: Strict adherence to anti-money laundering and combating the financing of terrorism (AML/CFT) regulations, including customer due diligence (CDD), suspicious transaction reporting, and internal AML policies. These are primarily governed by Law No. 111/2019 "On Preventing Money Laundering and Terrorism Financing."

licensing 20% confidence

Transparency and Disclosure: Ongoing obligations for reporting to the FSA and providing transparent information to clients.

licensing 20% confidence

Regulatory Reference: Articles 12-16 of Law No. 110/2020 and subsequent secondary legislation/regulations issued by the FSA.

licensing 20% confidence

Article 21 (Client Asset Protection): DLT service providers, including custodians, are required to implement measures to protect the virtual assets and funds of their clients. This includes:

licensing 20% confidence

Segregation: Maintaining separate accounts for client virtual assets and funds from their own proprietary assets. This is a fundamental principle to ensure that client assets are not subject to claims from the DLT service provider's creditors in case of insolvency.

licensing 20% confidence

Identification: Clearly identifying client assets as such.

licensing 20% confidence

Reconciliation: Regularly reconciling client asset records with actual holdings.

licensing 20% confidence

Prevention of Misuse: Implementing robust controls to prevent the unauthorized use or misuse of client assets.

licensing 20% confidence

Regulatory Reference: Article 21 of Law No. 110/2020.

licensing 20% confidence

Minimum Capital Requirements: DLT service providers must meet minimum initial capital requirements, as determined by the FSA through secondary acts. This capital acts as a buffer against operational risks and potential liabilities.

licensing 20% confidence

Robust Risk Management: The law mandates comprehensive risk management systems, which would typically include assessing and mitigating various risks, including cyber risks, operational risks, and the potential for asset loss. While not explicit insurance, it indirectly requires financial stability and the ability to cover potential losses.

licensing 20% confidence

Regulatory Reference: Article 13 of Law No. 110/2020 (regarding capital requirements) and Article 15 (regarding internal governance and risk management).

licensing 20% confidence

Security Requirements (Article 15): DLT service providers must establish robust internal control mechanisms, including comprehensive IT security measures, to ensure the integrity, confidentiality, and availability of data and assets. This would naturally lead to the adoption of industry best practices for securing private keys, which typically include a significant portion of assets being held in offline (cold) storage.

licensing 20% confidence

Operational Resilience: The law requires measures to ensure operational continuity and resilience, which often involves disaster recovery plans and robust backup systems, again favoring secure storage solutions.

licensing 20% confidence

Regulatory Reference: Article 15 of Law No. 110/2020 (internal governance, risk management, and IT systems).

licensing 20% confidence

Regulatory Reference: Article 4 (Definitions) and Articles 12-16 (Licensing) of Law No. 110/2020.

licensing 20% confidence

More Specific Rules: MiCA provides very detailed requirements for custody service providers regarding governance, operational resilience, segregation of assets, liability, and safeguarding arrangements.

aml 40% confidence

Law No. 119/2019 "On Preventing Money Laundering and Terrorism Financing" (Ligji Nr. 119/2019 "Për parandalimin e pastrimit të parave dhe financimit të terrorizmit").

aml 95% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 95% confidence

Natural Persons: Identifying and verifying the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., identity cards, passports, official residence documents).

aml 95% confidence

Legal Entities: Identifying and verifying the identity of the customer, including its name, legal form, address, proof of incorporation, and powers that regulate and bind the legal person. This also extends to identifying and verifying the identity of the natural persons who hold senior management positions and the beneficial owners.

aml 95% confidence

Beneficial Ownership: Identifying the beneficial owner(s) of the customer and taking reasonable measures to verify their identity, including understanding the ownership and control structure of the customer.

aml 95% confidence

Purpose and Nature of the Business Relationship: Obtaining information on the purpose and intended nature of the business relationship.

aml 95% confidence

Ongoing Monitoring: Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 95% confidence

Risk-Based Approach: Applying CDD measures on a risk-sensitive basis. This means applying simplified CDD (SDD) measures where the risks are lower and enhanced CDD (EDD) measures where the risks are higher (e.g., transactions involving politically exposed persons (PEPs), high-value transactions, or relationships with customers from high-risk jurisdictions).

aml 95% confidence

Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of criminal activity, or are related to terrorism financing, it must promptly (without delay) report this to the General Directorate for the Prevention of Money Laundering (GDPML).

aml 98% confidence

No Threshold: There is no minimum monetary threshold for reporting suspicious transactions; any amount can be suspicious.

aml 95% confidence

Protection for Reporters: The law provides protection against civil or criminal liability for VASPs and their employees who report suspicions in good faith.

aml 95% confidence

"Tipping Off": VASPs and their employees are prohibited from "tipping off" the customer or third parties about the fact that a suspicious transaction report has been made or that an investigation is underway.

aml 95% confidence

Period: Records relating to CDD, business relationships, and transactions must be kept for at least five years after the end of the business relationship or after the date of an occasional transaction.

aml 95% confidence

Types of Records: This includes copies of identification documents, account files, business correspondence, and records of transactions (including the amounts, currencies, and dates).

aml 95% confidence

Accessibility: Records must be maintained in a way that allows for easy retrieval by competent authorities when requested.

aml 100% confidence

Internal Policies and Procedures: Establish and maintain internal policies, controls, and procedures for AML/CFT compliance, proportionate to their nature and size.

aml 95% confidence

AML Officer: Appoint a designated AML/CFT compliance officer at management level.

aml 100% confidence

Staff Training: Implement ongoing training programs for relevant staff members to ensure they are aware of their AML/CFT obligations, the risks faced by the VASP, and how to identify and report suspicious activities.

aml 95% confidence

Risk Assessment: Conduct institutional risk assessments to identify, assess, and understand the money laundering and terrorism financing risks to which they are exposed.

aml 100% confidence

General Directorate for the Prevention of Money Laundering (GDPML): http://www.gdpml.gov.al/ (Often lists relevant legislation and guidance, though primarily in Albanian).

enforcement 100% confidence

Entity Targeted: Faruk Fatih Özer, founder and CEO of the Turkish cryptocurrency exchange Thodex. Violation Type: International fraud, money laundering (related to the collapse of the Thodex exchange, which defrauded hundreds of thousands of users of an estimated $2 billion). The Albanian action related to his illegal entry and residence, and the execution of the international arrest warrant. Penalty Amount (Albania): No specific "penalty amount" was imposed by Albanian authorities on Özer directly for the crypto fraud. The outcome in Albania was his arrest and successful extradition. Outcome: Faruk Fatih Özer was arrested in Vlora, Albania, following an international manhunt. After a period of legal appeals, he was extradited to Turkey, where he faced trial. In Turkey, he was subsequently sentenced to 11,196 years in prison in September 2023 for aggravated fraud, leading a criminal organization, and money laundering.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet/SaaS provider is permitted in Albania only after obtaining prior authorization from the FSA as a DLT service provider under Law No. 110/2020, with mandatory local incorporation, minimum capital, client asset segregation (Article 21), full AML/CFT compliance under Law No. 119/2019, and ongoing governance/IT security obligations, though key secondary regulations remain unissued, creating moderate regulatory ambiguity.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?