Remote VASP serving residents in Albania
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Albania with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- AML/CFT compliance is mandatory under Law No. 119/2019 'On Preventing Money Laundering and Terrorism Financing' — applies to all VASPs including remote operators serving residents
- Customer Due Diligence (CDD): must identify and verify identity of natural persons (reliable ID documents) and legal entities (name, legal form, address, proof of incorporation, senior management, beneficial owners)
- Beneficial ownership: must identify and verify beneficial owner(s), understand ownership and control structure
- Purpose and nature of business relationship: must obtain information on the intended use of the relationship
- Ongoing monitoring: must scrutinize transactions throughout the relationship to ensure consistency with customer risk profile
- Risk-based approach: apply Simplified CDD for lower risk, Enhanced CDD for higher risk (PEPs, high-value transactions, complex structures)
- Suspicious Transaction Reporting: must report without delay to the General Directorate for the Prevention of Money Laundering (GDPML) — no minimum threshold; any amount can be suspicious
- Tipping-off prohibition: cannot disclose to customers or third parties that an STR has been filed
- Record-keeping: CDD and transaction records must be kept for at least 5 years after end of business relationship or occasional transaction
- Internal policies: must maintain AML/CFT policies, controls, procedures proportionate to nature and size
- AML Officer: must appoint a designated AML/CFT compliance officer at management level
- Staff training: must implement ongoing AML/CFT training programs for relevant staff
- Risk assessment: must conduct institutional ML/TF risk assessments
- Travel Rule: for cross-border virtual asset transfers exceeding €1,000 / USD 1,000 (or equivalent in ALL), originator and beneficiary information must be collected and transmitted; FATF June 2025 guidance sets $1,000 USD/EUR threshold for domestic transfers
Key Restrictions
- Entity must be established as a legal entity in Albania (Law No. 110/2020, Article 12) — foreign-incorporated remote VASP cannot serve Albanian residents without a local entity
- Must obtain prior authorization from the Financial Supervisory Authority (FSA) before offering DLT services
- Must meet minimum capital requirements set by FSA secondary legislation (Article 13)
- Must meet legal form requirements for Albanian entities
- Must comply with governance and management requirements including fit-and-proper criteria for directors and significant shareholders (Article 15)
- Client asset protection: segregation of client virtual assets/funds from proprietary assets, identification, reconciliation, prevention of misuse (Article 21)
- Robust risk management, IT security, and operational resilience measures required (Article 15)
- Potential future alignment with MiCA may introduce additional requirements once Albania transposes EU crypto-asset markets regulation
Key Risks
- Operating without local licensing as a remote VASP serving Albanian residents is illegal — unlicensed operators face enforcement risk including administrative fines, license suspension/revocation, and potential criminal charges
- Enforcement precedent exists: Albania has taken action against foreign crypto executives (e.g., Thodex founder Faruk Fatih Özer arrested in Albania for fraud/money laundering), indicating willingness to pursue cross-border crypto misconduct
- Regulatory ambiguity during transition to MiCA-aligned framework may create compliance uncertainty
- Language barrier: primary regulatory materials are in Albanian; official English translations are limited, increasing compliance complexity for foreign operators
- No threshold for STR filing — any potentially suspicious transaction must be reported regardless of amount, creating broad reporting obligations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 110/2020 "On Financial Markets Based on Distributed Ledger Technology": This is the foundational legal act regulating DLT-based financial markets and virtual assets in Albania. It defines virtual assets, DLT service providers, and sets out licensing and operational requirements.
Authorization from FSA: Any entity intending to offer DLT services, including custody of virtual assets, must obtain prior authorization from the FSA (Article 12).
Legal Form and Capital: Applicants must be established as legal entities in Albania and meet minimum capital requirements, which are determined by secondary legislation issued by the FSA.
Governance and Management: Requirements for sound and prudent management, including "fit and proper" criteria for directors and significant shareholders, robust internal control mechanisms, risk management procedures, and administrative arrangements.
AML/CFT Compliance: Strict adherence to anti-money laundering and combating the financing of terrorism (AML/CFT) regulations, including customer due diligence (CDD), suspicious transaction reporting, and internal AML policies. These are primarily governed by Law No. 111/2019 "On Preventing Money Laundering and Terrorism Financing."
Article 21 (Client Asset Protection): DLT service providers, including custodians, are required to implement measures to protect the virtual assets and funds of their clients. This includes:
Minimum Capital Requirements: DLT service providers must meet minimum initial capital requirements, as determined by the FSA through secondary acts. This capital acts as a buffer against operational risks and potential liabilities.
Regulatory Reference: Article 13 of Law No. 110/2020 (regarding capital requirements) and Article 15 (regarding internal governance and risk management).
Security Requirements (Article 15): DLT service providers must establish robust internal control mechanisms, including comprehensive IT security measures, to ensure the integrity, confidentiality, and availability of data and assets. This would naturally lead to the adoption of industry best practices for securing private keys, which typically include a significant portion of assets being held in offline (cold) storage.
Regulatory Reference: Article 15 of Law No. 110/2020 (internal governance, risk management, and IT systems).
Law No. 119/2019 "On Preventing Money Laundering and Terrorism Financing" (Ligji Nr. 119/2019 "Për parandalimin e pastrimit të parave dhe financimit të terrorizmit").
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.
Natural Persons: Identifying and verifying the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., identity cards, passports, official residence documents).
Legal Entities: Identifying and verifying the identity of the customer, including its name, legal form, address, proof of incorporation, and powers that regulate and bind the legal person. This also extends to identifying and verifying the identity of the natural persons who hold senior management positions and the beneficial owners.
Beneficial Ownership: Identifying the beneficial owner(s) of the customer and taking reasonable measures to verify their identity, including understanding the ownership and control structure of the customer.
Purpose and Nature of the Business Relationship: Obtaining information on the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying CDD measures on a risk-sensitive basis. This means applying simplified CDD (SDD) measures where the risks are lower and enhanced CDD (EDD) measures where the risks are higher (e.g., transactions involving politically exposed persons (PEPs), high-value transactions, or relationships with customers from high-risk jurisdictions).
Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of criminal activity, or are related to terrorism financing, it must promptly (without delay) report this to the General Directorate for the Prevention of Money Laundering (GDPML).
No Threshold: There is no minimum monetary threshold for reporting suspicious transactions; any amount can be suspicious.
Protection for Reporters: The law provides protection against civil or criminal liability for VASPs and their employees who report suspicions in good faith.
"Tipping Off": VASPs and their employees are prohibited from "tipping off" the customer or third parties about the fact that a suspicious transaction report has been made or that an investigation is underway.
Period: Records relating to CDD, business relationships, and transactions must be kept for at least five years after the end of the business relationship or after the date of an occasional transaction.
Internal Policies and Procedures: Establish and maintain internal policies, controls, and procedures for AML/CFT compliance, proportionate to their nature and size.
AML Officer: Appoint a designated AML/CFT compliance officer at management level.
Staff Training: Implement ongoing training programs for relevant staff members to ensure they are aware of their AML/CFT obligations, the risks faced by the VASP, and how to identify and report suspicious activities.
Risk Assessment: Conduct institutional risk assessments to identify, assess, and understand the money laundering and terrorism financing risks to which they are exposed.
Cross-border transfers: The Travel Rule typically applies to transactions exceeding €1,000 / USD 1,000 (or its equivalent in Albanian Lek - ALL). For these transactions, both originator and beneficiary information must be collected and transmitted.
FATF’s June 2025 revised standards introduced a $1,000 USD/EUR minimum threshold for domestic transfers under the Travel Rule; transfers below that amount are not subject to mandatory information collection, though jurisdictions may still apply lower thresholds. VASPs in Albania should align with the updated $1,000 threshold, not a zero-threshold assumption for all domestic transfers.
Implement robust Know Your Customer (KYC) processes to identify and verify the identity of their customers.
Maintain records of transaction information and customer data for the prescribed period (typically 5 years).
Report suspicious transactions to the General Directorate for the Prevention of Money Laundering (GDPML).
Entity Targeted: Faruk Fatih Özer, founder and CEO of the Turkish cryptocurrency exchange Thodex. Violation Type: International fraud, money laundering (related to the collapse of the Thodex exchange, which defrauded hundreds of thousands of users of an estimated $2 billion). The Albanian action related to his illegal entry and residence, and the execution of the international arrest warrant. Penalty Amount (Albania): No specific "penalty amount" was imposed by Albanian authorities on Özer directly for the crypto fraud. The outcome in Albania was his arrest and successful extradition. Outcome: Faruk Fatih Özer was arrested in Vlora, Albania, following an international manhunt. After a period of legal appeals, he was extradited to Turkey, where he faced trial. In Turkey, he was subsequently sentenced to 11,196 years in prison in September 2023 for aggravated fraud, leading a criminal organization, and money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP cannot serve Albanian residents from abroad without first establishing a local legal entity in Albania, obtaining prior FSA authorization under Law No. 110/2020, and complying with full AML/CFT obligations under Law No. 119/2019, including Travel Rule requirements, making the typical "remote VASP" model unlawful in this jurisdiction.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?