Custodial wallet / SaaS in Armenia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Armenia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- VASPs are obligated entities under the Law on Combating Money Laundering and Terrorist Financing (2004, amended 2022 to cover VASPs).
- Customer due diligence required: obtain and verify full name, date of birth, nationality, residential address, and unique ID for individuals; legal entity name, legal form, registered address, registration number, and authorized persons for legal entities.
- Beneficial ownership identification and verification required.
- Ongoing transaction monitoring for consistency with customer profile and risk.
- Enhanced due diligence for Politically Exposed Persons (PEPs).
- Sanctions screening against national and international sanctions lists.
- Suspicious Transaction Reports (STRs) must be filed immediately with the Financial Monitoring Center (FMC) when funds or virtual assets are suspected to be proceeds of crime or related to terrorist financing.
- Record retention minimum 5 years after business relationship ends.
- No tipping-off rule applies — cannot disclose STR filing to customer or third parties.
- Risk-based approach: EDD for high-risk customers, SDD permitted for lower-risk under conditions.
- Source of funds/wealth may be required for higher-risk customers or transactions.
Key Restrictions
- No specific crypto custody license exists — custodial wallet/SaaS operators must comply as VASPs under the AML/CFT Law.
- No legal definition of 'qualified custodian' for crypto in Armenia — no specific capital, security, or operational standards for custodians.
- No mandatory insurance or bonding requirements for crypto custodians; clients have no regulatory-mandated recourse in case of theft, loss, or insolvency.
- No specific mandate for cold storage or technical security standards for custodians.
- If the service involves fiat currency processing (e.g., AMD conversion), a payment organization license under the Law on Payment and Settlement Systems and Payment Organizations may be triggered.
- If virtual assets qualify as securities, CBA securities regulation would apply — though unlikely for general custodial wallet/SaaS services.
- The Central Bank of Armenia has a cautious, non-recognition stance on crypto assets — no legal tender status.
Key Risks
- Regulatory ambiguity: no dedicated crypto custody framework means reliance on general AML/CFT law and potential for shifting interpretations by CBA or enforcement bodies.
- Enforcement risk: criminal fraud cases (Articles 178, 188, 190 of Criminal Code) have been aggressively pursued against crypto-related entities, including arrests, asset freezes, and seizures of multi-million dollar amounts.
- No client asset protection: absence of mandated insurance, segregation rules, or proof-of-reserves requirements leaves clients exposed to custodian insolvency or theft.
- Lack of clear Travel Rule implementation guidance for VASPs creates compliance uncertainty for cross-chain/cross-border transactions.
- All AML obligations fall on the VASP operator (custodial wallet/SaaS provider), not the white-label client — the SaaS provider bears full regulatory burden as the obligated entity under the AML/CFT law.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific "crypto custody license" exists. Armenia does not currently have a dedicated licensing regime for cryptocurrency custodians.
In Armenia, Virtual Asset Custody Providers (VACPs) are now subject to specific licensing and operational/security requirements under the updated Law on Combating Money Laundering and Terrorism Financing, making the original statement about the absence of a custody license inaccurate.
Armenia has specific laws and regulations, including the Law on Crypto-Assets (adopted May 29, 2025), that regulate crypto-asset service providers (including custodians) licensed by the Central Bank, with requirements for AML, transaction monitoring, record retention, and client protections, though explicit client asset segregation mandates are not detailed in the provided evidence.
Armenia imposes licensing and capital requirements for cryptocurrency custodians, but no mandatory insurance or bonding.
This means that clients would likely have no recourse through a regulatory-mandated insurance scheme in the event of theft, loss, or insolvency of a crypto custodian.
No specific mandates. There are no specific regulatory mandates or technical requirements for cryptocurrency custodians regarding the use of cold storage (offline storage) for digital assets.
Custodians might implement cold storage as a best practice for security, but it is not a legal obligation.
No specific definition. Given the absence of a dedicated regulatory framework for digital asset custody, there is no legal definition of a "qualified custodian" for cryptocurrencies in Armenia.
Lack of Specific Legislation: There is no dedicated law in Armenia regulating virtual assets or stipulating licensing requirements for crypto businesses. This creates a significant degree of legal uncertainty for operators.
Central Bank's Stance: The Central Bank of Armenia (CBA) has consistently maintained a cautious and conservative stance on cryptocurrencies. It has issued warnings to the public about the high risks associated with virtual assets, emphasizing that cryptocurrencies are not legal tender in Armenia and are not regulated or supervised by the CBA. They do not recognize cryptocurrencies as a form of electronic money, payment instrument, or security.
Existing laws in Armenia may provide an indirect foundation, but France and Italy are enacting new, direct laws defining antisemitism, aiming to supersede indirect applicability; the indirect approach is becoming insufficient or supplemented by explicit new statutes.
Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Law: This is the most significant piece of legislation relevant to virtual asset activities. Armenia, as a member of international bodies, adheres to FATF recommendations. The Law on Combating Money Laundering and Terrorist Financing (Հայաստանի Հանրապետության օրենքը «Փողերի լվացման և ահաբեկչության ֆինանսավորման դեմ պայքարի մասին») likely applies to entities dealing with virtual assets, even if not explicitly named as "VASPs" in the law. This means any entity facilitating the transfer, exchange, or custody of virtual assets would be expected to implement robust AML/KYC procedures.
Custody Providers: No specific license for virtual asset custody. Traditional banking or financial institution licenses are distinct and are not typically granted for pure crypto custody services.
Payment System Regulations: If a crypto-related service involves the processing of fiat currency (e.g., converting AMD to crypto or vice versa), it may inadvertently trigger requirements under the Law on Payment and Settlement Systems and Payment Organizations, potentially requiring a license for a payment organization or payment system operator from the CBA.
Securities Regulations: If a virtual asset is structured in a way that it qualifies as a security under Armenian law (e.g., representing ownership shares, debt, or a right to future profits), then it would fall under the regulation of the CBA, which supervises the securities market. This would require licenses for offering, trading, or managing securities.
Law of the Republic of Armenia on Combating Money Laundering and Terrorist Financing (ՀՀ օրենքը «Փողերի լվացման և ահաբեկչության ֆինանսավորման դեմ պայքարի մասին»): This is the primary legislation. It mandates financial institutions, including VASPs, to implement robust AML/CFT measures, which inherently include sanctions screening.
Specifics: This law, originally adopted in 2004, has undergone several amendments. Crucially, amendments in 2022 specifically brought virtual asset service providers (VASPs) within the scope of obligated entities. This means VASPs are now subject to the same AML/CFT obligations as traditional financial institutions.
These amendments align Armenia with FATF Recommendation 15 on new technologies, which requires countries to regulate and supervise VASPs for AML/CFT purposes. The Travel Rule application to VASPs has been clarified as distinct from the core Recommendation 15 VASP regulatory requirements.
Individuals: Obtain and verify the customer's full name, date of birth, place of birth, nationality, residential address, and unique identification number (e.g., passport, national ID card details). Verification typically requires reliable, independent source documents, data, or information.
Legal Entities: Obtain and verify the legal entity's name, legal form, address of registered office, registration number, and the names of individuals authorized to act on behalf of the entity.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, especially for legal entities and complex structures. This includes understanding the ownership and control structure.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing transactions for unusual patterns and ensuring documents, data, or information collected under the CDD process remain current and relevant.
Politically Exposed Persons (PEPs): Implement enhanced due diligence measures for customers identified as PEPs, their family members, and close associates.
Sanctions Screening: Screen customers and transactions against national and international sanctions lists.
Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds, virtual assets, or other assets are the proceeds of a criminal activity, or are related to terrorist financing, it must immediately file a Suspicious Transaction Report (STR) with the Financial Monitoring Center (FMC) of the CBA.
Period: Records related to customer identification data, beneficial ownership information, transaction data (including virtual asset addresses, transaction hashes, amounts, and timestamps), and any STRs filed must be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that an STR has been filed or that an AML/CFT investigation is being conducted (the "no tipping-off" rule).
Risk-Based Approach: Apply CDD measures according to the level of risk identified for each customer or transaction. This means higher-risk customers or transactions will require Enhanced Due Diligence (EDD), while lower-risk ones may permit Simplified Due Diligence (SDD) under specific conditions.
Source of Funds/Wealth: For higher-risk customers or transactions, VASPs may be required to ascertain the source of funds or source of wealth involved.
The Financial Monitoring Center (FMC) operates under the Central Bank of Armenia, but since July 2025, AML/CFT oversight has been expanded to include the State Revenue Committee’s Centralized Monitoring Center and CertScan system, along with new reporting obligations for designated non-financial entities such as lawyers, notaries, and accounting firms. Financial intelligence and monitoring are now shared across multiple agencies and private-sector gatekeepers, not solely the CBA’s FMC.
Entity Targeted: Individuals and organized criminal groups involved in establishing and operating large-scale fraudulent cryptocurrency investment schemes, often promising high returns from "mining farms" or fake trading platforms. Violation Type: Large-scale fraud (often under Article 178 of the Criminal Code of Armenia), money laundering (Article 190), illegal entrepreneurship (Article 188), and sometimes other related criminal offenses. Outcome: Multiple arrests of individuals involved, ongoing criminal proceedings, freezing and seizure of assets, and international cooperation to track down perpetrators and recover funds. As these are complex criminal cases, final verdicts and sentences can take significant time.
Armenian authorities are conducting mass raids and investigating nearly 40 individuals for money laundering, indicating that the situation has progressed beyond the initial multiple arrests and asset freezes described in the claim.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers can operate as VASPs under Armenia's AML/CFT Law (2004, amended 2022) but face material legal uncertainty due to the absence of a dedicated crypto custody license, no mandatory segregation/insurance/proof-of-reserves rules, and aggressive criminal enforcement against crypto-related activities.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?