On-shore VASP in Albania
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Albania with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required for natural persons (reliable, independent source documents), legal entities (name, legal form, address, proof of incorporation, senior management), and beneficial ownership — Law No. 119/2019
- Ongoing monitoring of business relationships and transaction scrutiny (risk-sensitive basis)
- EDD required for PEPs, high-value transactions, and high-risk scenarios
- Suspicious transaction reporting to the General Directorate for the Prevention of Money Laundering (GDPML) — no minimum monetary threshold
- Tipping-off prohibition
- Record-keeping for at least 5 years after end of business relationship (CDD docs, transaction records, correspondence)
- Mandatory AML/CFT compliance officer at management level
- Staff training programs on AML/CFT obligations
- Institutional risk assessments to identify ML/TF risks
- Travel Rule compliance: cross-border transfers >€1,000 require originator and beneficiary info collection and transmission; FATF June 2025 revised standards set $1,000 USD/EUR threshold for domestic transfers
Key Restrictions
- Must be established as a legal entity in Albania
- Must obtain prior authorization from the Financial Supervisory Authority (FSA) before offering DLT services (Article 12, Law No. 110/2020)
- Client virtual assets must be segregated from proprietary assets (Article 21, Law No. 110/2020)
- Robust internal control mechanisms and IT security measures required (Article 15)
- Fit and proper criteria apply to directors and significant shareholders
- Must meet minimum capital requirements as set by FSA secondary legislation
Key Risks
- Regulatory ambiguity: secondary legislation (capital requirements, detailed rules) may still be evolving — FSA discretion creates uncertainty
- Enforcement precedent limited — the Thodex case shows Albania can act on crypto-related financial crime, signaling active enforcement risk
- MiCA alignment expected — future regulatory changes may impose additional obligations (governance, operational resilience, liability) under a new crypto-asset markets law
- Tax complexity: no explicit crypto tax law — capital gains (15% flat) and VAT treatment (20% on service fees) rely on interpretive application of existing tax law
- Language barrier: primary legal sources are in Albanian; official English translations limited
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Authorization from FSA: Any entity intending to offer DLT services, including custody of virtual assets, must obtain prior authorization from the FSA (Article 12).
Legal Form and Capital: Applicants must be established as legal entities in Albania and meet minimum capital requirements, which are determined by secondary legislation issued by the FSA.
Governance and Management: Requirements for sound and prudent management, including "fit and proper" criteria for directors and significant shareholders, robust internal control mechanisms, risk management procedures, and administrative arrangements.
Operational Capacity: Adequate technical and human resources to perform the intended services securely and efficiently. This implicitly covers aspects like cybersecurity, data protection, and operational resilience.
AML/CFT Compliance: Strict adherence to anti-money laundering and combating the financing of terrorism (AML/CFT) regulations, including customer due diligence (CDD), suspicious transaction reporting, and internal AML policies. These are primarily governed by Law No. 111/2019 "On Preventing Money Laundering and Terrorism Financing."
Transparency and Disclosure: Ongoing obligations for reporting to the FSA and providing transparent information to clients.
Article 21 (Client Asset Protection): DLT service providers, including custodians, are required to implement measures to protect the virtual assets and funds of their clients. This includes:
Segregation: Maintaining separate accounts for client virtual assets and funds from their own proprietary assets. This is a fundamental principle to ensure that client assets are not subject to claims from the DLT service provider's creditors in case of insolvency.
Minimum Capital Requirements: DLT service providers must meet minimum initial capital requirements, as determined by the FSA through secondary acts. This capital acts as a buffer against operational risks and potential liabilities.
Robust Risk Management: The law mandates comprehensive risk management systems, which would typically include assessing and mitigating various risks, including cyber risks, operational risks, and the potential for asset loss. While not explicit insurance, it indirectly requires financial stability and the ability to cover potential losses.
Security Requirements (Article 15): DLT service providers must establish robust internal control mechanisms, including comprehensive IT security measures, to ensure the integrity, confidentiality, and availability of data and assets. This would naturally lead to the adoption of industry best practices for securing private keys, which typically include a significant portion of assets being held in offline (cold) storage.
Regulatory Reference: Articles 12-16 of Law No. 110/2020 and subsequent secondary legislation/regulations issued by the FSA.
Regulatory Reference: Article 13 of Law No. 110/2020 (regarding capital requirements) and Article 15 (regarding internal governance and risk management).
Regulatory Reference: Article 15 of Law No. 110/2020 (internal governance, risk management, and IT systems).
Regulatory Reference: Article 4 (Definitions) and Articles 12-16 (Licensing) of Law No. 110/2020.
Law No. 119/2019 "On Preventing Money Laundering and Terrorism Financing" (Ligji Nr. 119/2019 "Për parandalimin e pastrimit të parave dhe financimit të terrorizmit").
Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of criminal activity, or are related to terrorism financing, it must promptly (without delay) report this to the General Directorate for the Prevention of Money Laundering (GDPML).
No Threshold: There is no minimum monetary threshold for reporting suspicious transactions; any amount can be suspicious.
Period: Records relating to CDD, business relationships, and transactions must be kept for at least five years after the end of the business relationship or after the date of an occasional transaction.
AML Officer: Appoint a designated AML/CFT compliance officer at management level.
Staff Training: Implement ongoing training programs for relevant staff members to ensure they are aware of their AML/CFT obligations, the risks faced by the VASP, and how to identify and report suspicious activities.
Risk Assessment: Conduct institutional risk assessments to identify, assess, and understand the money laundering and terrorism financing risks to which they are exposed.
Natural Persons: Identifying and verifying the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., identity cards, passports, official residence documents).
Legal Entities: Identifying and verifying the identity of the customer, including its name, legal form, address, proof of incorporation, and powers that regulate and bind the legal person. This also extends to identifying and verifying the identity of the natural persons who hold senior management positions and the beneficial owners.
Beneficial Ownership: Identifying the beneficial owner(s) of the customer and taking reasonable measures to verify their identity, including understanding the ownership and control structure of the customer.
Ongoing Monitoring: Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying CDD measures on a risk-sensitive basis. This means applying simplified CDD (SDD) measures where the risks are lower and enhanced CDD (EDD) measures where the risks are higher (e.g., transactions involving politically exposed persons (PEPs), high-value transactions, or relationships with customers from high-risk jurisdictions).
Cross-border transfers: The Travel Rule typically applies to transactions exceeding €1,000 / USD 1,000 (or its equivalent in Albanian Lek - ALL). For these transactions, both originator and beneficiary information must be collected and transmitted.
FATF’s June 2025 revised standards introduced a $1,000 USD/EUR minimum threshold for domestic transfers under the Travel Rule; transfers below that amount are not subject to mandatory information collection, though jurisdictions may still apply lower thresholds. VASPs in Albania should align with the updated $1,000 threshold, not a zero-threshold assumption for all domestic transfers.
Tax Rate (Individuals): For individuals, capital gains from the sale of shares, financial instruments, and other assets are subject to a 15% flat rate under the Law on Income Tax. It is widely understood that gains from virtual assets would fall under this category.
Tax Rate (Businesses): If a business deals with virtual assets, any gains from their disposal would be included in the company's taxable profit and subject to the Corporate Income Tax rate of 15% (or 0% for small businesses meeting specific criteria).
Fees charged by virtual asset service providers (e.g., exchanges, wallet providers) for services like trading fees, platform usage, custodial services, or brokerage services are generally considered subject to standard VAT rates (currently 20%).
Entity Targeted: Faruk Fatih Özer, founder and CEO of the Turkish cryptocurrency exchange Thodex. Violation Type: International fraud, money laundering (related to the collapse of the Thodex exchange, which defrauded hundreds of thousands of users of an estimated $2 billion). The Albanian action related to his illegal entry and residence, and the execution of the international arrest warrant. Penalty Amount (Albania): No specific "penalty amount" was imposed by Albanian authorities on Özer directly for the crypto fraud. The outcome in Albania was his arrest and successful extradition. Outcome: Faruk Fatih Özer was arrested in Vlora, Albania, following an international manhunt. After a period of legal appeals, he was extradited to Turkey, where he faced trial. In Turkey, he was subsequently sentenced to 11,196 years in prison in September 2023 for aggravated fraud, leading a criminal organization, and money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — an on-shore VASP in Albania must incorporate locally, obtain prior FSA authorization under Law No. 110/2020 (Articles 12–16), meet minimum capital requirements (set by FSA secondary legislation), comply with comprehensive AML/CFT obligations under Law No. 119/2019 (including CDD, STR reporting to GDPML, Travel Rule compliance), and adhere to client asset segregation and governance/fit-and-proper requirements.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?