Custodial wallet / SaaS in Austria
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Austria with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with FMA under FM-GwG (Geldwäsche- und Terrorismusfinanzierungsgesetz) required before offering custodial services (at.aml.vasp-registration-there-is-no, at.licensing.geldwsche--und-terrorismusfinanzierungsgesetz-gwg-anti-money)
- Fit and proper management: key persons must demonstrate suitability and reliability (at.aml.fit-and-proper-management-key)
- Robust AML/KYC framework including customer due diligence, transaction monitoring, risk management, and suspicious transaction reporting to the FIU (at.aml.robust-amlkyc-framework-implementation-of)
- Appointment of a designated AML officer (at.aml.designated-aml-officer-appointment-of)
- Internal controls and risk management systems to prevent money laundering and terrorist financing (at.aml.internal-controls-establishment-of-internal)
- Professional indemnity insurance or equivalent capital reserves covering loss of client crypto assets required as a matter of general business practices (at.aml.general-business-practices-custodians-are)
- Post-MiCA (from 30 Dec 2024): CASP authorization required with additional prudential safeguards, capital requirements, and organizational/governance obligations beyond AML (at.aml.comprehensive-requirements-mica-introduces-robust, at.aml.prudential-safeguards-capital-requirements-see)
Key Restrictions
- No dedicated 'custody license' exists under current law; custody is treated as a VASP service under FM-GwG (at.aml.vasp-registration-there-is-no)
- Current FM-GwG does not explicitly mandate prudential segregation of client crypto assets from the custodian's own assets; only implicit expectations from good business conduct and FMA supervisory expectations (at.aml.current-the-fm-gwg-being-an)
- No explicit insurance or bonding requirements for crypto custodians under current FM-GwG; only implicit professional indemnity insurance expectation (at.aml.current-there-are-no-explicit)
- No explicit mandate for cold storage, though FMA expects robust IT security and operational resilience which implicitly encourages cold storage (at.aml.current-austrian-regulation-does-not, at.aml.general-security-requirements-the-fma)
- Post-MiCA: 'qualified custodian' status will require licensed MiCA-compliant CASP authorization with specific prudential, capital, and custody requirements beyond AML/CTF (at.aml.current-the-term-qualified-custodian)
- If the custodian's services involve crypto-assets that qualify as financial instruments (security tokens), WAG 2018/KMG securities laws may also apply (at.licensing.wertpapieraufsichtsgesetz-2018-wag-2018-securities)
Key Risks
- Regulatory ambiguity during the pre-MiCA transitional period: custody rules are thin on segregation, insurance, and proof-of-reserves (at.aml.current-the-fm-gwg-being-an, at.aml.current-there-are-no-explicit)
- Enforcement risk: FMA has demonstrated willingness to act (e.g., KuCoin EU ban) where regulatory gaps were exploited (at.aml.comprehensive-requirements-mica-introduces-robust)
- SaaS provider versus white-label client AML responsibility split is not clearly delineated in current Austrian guidance; both parties may have overlapping VASP registration obligations
- Tax complexity: crypto assets treated as property with capital gains tax; income from staking/mining taxed as ordinary income — custody of staking assets creates additional tax reporting risks (at.licensing.einkommensteuergesetz-estg-income-tax-act)
- Transition to MiCA CASP regime (by 30 Dec 2024) imposes a step-change in prudential requirements — custodians must prepare for higher capital, governance, and segregation standards
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Registration: There is no dedicated "custody license" per se. Instead, entities providing custody of virtual assets are classified as Virtual Asset Service Providers (VASPs) and are required to register with the Austrian Financial Market Authority (FMA).
Scope: The FM-GwG defines "providers of services related to virtual currencies" to include "the safekeeping of virtual currencies for third parties" (i.e., custody).
Fit and Proper Management: Key persons involved in the management must demonstrate their suitability and reliability.
Robust AML/KYC Framework: Implementation of comprehensive policies and procedures for customer due diligence (KYC), transaction monitoring, risk management, and reporting of suspicious activities to the Financial Intelligence Unit (FIU).
Designated AML Officer: Appointment of a dedicated officer responsible for AML compliance.
Internal Controls: Establishment of internal controls and risk management systems to prevent money laundering and terrorist financing.
Custodians of crypto assets in Austria are required to hold professional indemnity insurance or equivalent capital reserves specifically covering the loss of client crypto assets.
Current: The FM-GwG, being an AML law, does not explicitly mandate prudential segregation of client crypto assets from the custodian's own assets.
Current: There are no explicit, dedicated insurance or bonding requirements specifically for crypto custodians under the current FM-GwG VASP registration.
Current: Austrian regulation does not explicitly mandate the use of cold storage for crypto assets.
General Security Requirements: The FMA expects VASPs to have robust IT security measures and operational resilience to protect client assets from theft, loss, or unauthorized access. This implicitly encourages the use of secure storage solutions, which commonly include cold storage for a significant portion of assets.
As of Austria's 2025 MiCA implementation, 'qualified custodian' for crypto assets has a distinct regulatory definition: only licensed MiCA-compliant CASPs authorized for 'custody and administration of crypto-assets' with specific prudential, capital, and custody requirements (beyond just AML/CTF) qualify.
MiCA introduces robust requirements beyond AML, but Austrian regulator action (banning KuCoin EU from new business) shows that enforcement was still needed to address gaps, with KuCoin subsequently hiring a new AML chief and expanding compliance in Vienna
Prudential Safeguards: Capital requirements (see below).
Geldwäsche- und Terrorismusfinanzierungsgesetz (GWG) – Anti-Money Laundering and Counter-Terrorist Financing Act (as amended):
Wertpapieraufsichtsgesetz 2018 (WAG 2018) – Securities Supervision Act 2018 & Kapitalmarktgesetz (KMG) – Capital Market Act (as amended):
Einkommensteuergesetz (EStG) – Income Tax Act (as amended):
Finanzmarktaufsicht (FMA) – Austrian Financial Market Authority:
Crypto Involvement: The FMA is responsible for the registration of Virtual Asset Service Providers (VASPs) under AML/CFT laws and will be the competent authority for licensing and supervising crypto-asset service providers (CASPs) under MiCA. It also provides guidance on the classification of crypto assets.
The remaining provisions of MiCA for other crypto-assets and crypto-asset service providers will apply from 30 December 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers can operate in Austria as VASPs registered with FMA under the FM-GwG, but must transition to full MiCA CASP licensing by 30 Dec 2024, with no explicit current segregation/insurance rules (creating ambiguity) and a step-change in prudential requirements post-MiCA.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?