← Regulations / Austria / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Austria

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Austria with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASP registration with FMA under FM-GwG (Geldwäsche- und Terrorismusfinanzierungsgesetz) required before offering custodial services (at.aml.vasp-registration-there-is-no, at.licensing.geldwsche--und-terrorismusfinanzierungsgesetz-gwg-anti-money)
  • Fit and proper management: key persons must demonstrate suitability and reliability (at.aml.fit-and-proper-management-key)
  • Robust AML/KYC framework including customer due diligence, transaction monitoring, risk management, and suspicious transaction reporting to the FIU (at.aml.robust-amlkyc-framework-implementation-of)
  • Appointment of a designated AML officer (at.aml.designated-aml-officer-appointment-of)
  • Internal controls and risk management systems to prevent money laundering and terrorist financing (at.aml.internal-controls-establishment-of-internal)
  • Professional indemnity insurance or equivalent capital reserves covering loss of client crypto assets required as a matter of general business practices (at.aml.general-business-practices-custodians-are)
  • Post-MiCA (from 30 Dec 2024): CASP authorization required with additional prudential safeguards, capital requirements, and organizational/governance obligations beyond AML (at.aml.comprehensive-requirements-mica-introduces-robust, at.aml.prudential-safeguards-capital-requirements-see)

Key Restrictions

  • No dedicated 'custody license' exists under current law; custody is treated as a VASP service under FM-GwG (at.aml.vasp-registration-there-is-no)
  • Current FM-GwG does not explicitly mandate prudential segregation of client crypto assets from the custodian's own assets; only implicit expectations from good business conduct and FMA supervisory expectations (at.aml.current-the-fm-gwg-being-an)
  • No explicit insurance or bonding requirements for crypto custodians under current FM-GwG; only implicit professional indemnity insurance expectation (at.aml.current-there-are-no-explicit)
  • No explicit mandate for cold storage, though FMA expects robust IT security and operational resilience which implicitly encourages cold storage (at.aml.current-austrian-regulation-does-not, at.aml.general-security-requirements-the-fma)
  • Post-MiCA: 'qualified custodian' status will require licensed MiCA-compliant CASP authorization with specific prudential, capital, and custody requirements beyond AML/CTF (at.aml.current-the-term-qualified-custodian)
  • If the custodian's services involve crypto-assets that qualify as financial instruments (security tokens), WAG 2018/KMG securities laws may also apply (at.licensing.wertpapieraufsichtsgesetz-2018-wag-2018-securities)

Key Risks

  • Regulatory ambiguity during the pre-MiCA transitional period: custody rules are thin on segregation, insurance, and proof-of-reserves (at.aml.current-the-fm-gwg-being-an, at.aml.current-there-are-no-explicit)
  • Enforcement risk: FMA has demonstrated willingness to act (e.g., KuCoin EU ban) where regulatory gaps were exploited (at.aml.comprehensive-requirements-mica-introduces-robust)
  • SaaS provider versus white-label client AML responsibility split is not clearly delineated in current Austrian guidance; both parties may have overlapping VASP registration obligations
  • Tax complexity: crypto assets treated as property with capital gains tax; income from staking/mining taxed as ordinary income — custody of staking assets creates additional tax reporting risks (at.licensing.einkommensteuergesetz-estg-income-tax-act)
  • Transition to MiCA CASP regime (by 30 Dec 2024) imposes a step-change in prudential requirements — custodians must prepare for higher capital, governance, and segregation standards

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 80% confidence

VASP Registration: There is no dedicated "custody license" per se. Instead, entities providing custody of virtual assets are classified as Virtual Asset Service Providers (VASPs) and are required to register with the Austrian Financial Market Authority (FMA).

aml 85% confidence

Scope: The FM-GwG defines "providers of services related to virtual currencies" to include "the safekeeping of virtual currencies for third parties" (i.e., custody).

aml 92% confidence

Robust AML/KYC Framework: Implementation of comprehensive policies and procedures for customer due diligence (KYC), transaction monitoring, risk management, and reporting of suspicious activities to the Financial Intelligence Unit (FIU).

aml 95% confidence

Custodians of crypto assets in Austria are required to hold professional indemnity insurance or equivalent capital reserves specifically covering the loss of client crypto assets.

aml 90% confidence

Current: There are no explicit, dedicated insurance or bonding requirements specifically for crypto custodians under the current FM-GwG VASP registration.

aml 85% confidence

General Security Requirements: The FMA expects VASPs to have robust IT security measures and operational resilience to protect client assets from theft, loss, or unauthorized access. This implicitly encourages the use of secure storage solutions, which commonly include cold storage for a significant portion of assets.

aml 70% confidence

As of Austria's 2025 MiCA implementation, 'qualified custodian' for crypto assets has a distinct regulatory definition: only licensed MiCA-compliant CASPs authorized for 'custody and administration of crypto-assets' with specific prudential, capital, and custody requirements (beyond just AML/CTF) qualify.

aml 95% confidence

MiCA introduces robust requirements beyond AML, but Austrian regulator action (banning KuCoin EU from new business) shows that enforcement was still needed to address gaps, with KuCoin subsequently hiring a new AML chief and expanding compliance in Vienna

licensing 100% confidence

Geldwäsche- und Terrorismusfinanzierungsgesetz (GWG) – Anti-Money Laundering and Counter-Terrorist Financing Act (as amended):

licensing 100% confidence

Wertpapieraufsichtsgesetz 2018 (WAG 2018) – Securities Supervision Act 2018 & Kapitalmarktgesetz (KMG) – Capital Market Act (as amended):

licensing 95% confidence

Crypto Involvement: The FMA is responsible for the registration of Virtual Asset Service Providers (VASPs) under AML/CFT laws and will be the competent authority for licensing and supervising crypto-asset service providers (CASPs) under MiCA. It also provides guidance on the classification of crypto assets.

enforcement 100% confidence

The remaining provisions of MiCA for other crypto-assets and crypto-asset service providers will apply from 30 December 2024.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers can operate in Austria as VASPs registered with FMA under the FM-GwG, but must transition to full MiCA CASP licensing by 30 Dec 2024, with no explicit current segregation/insurance rules (creating ambiguity) and a step-change in prudential requirements post-MiCA.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?