On-shore VASP in Bosnia and Herzegovina
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Bosnia and Herzegovina with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as a VASP with the relevant authority — likely the Financial Intelligence Unit (FIU BiH) or the Financial Intelligence Department (FID) within SIPA — under the Law on Prevention of Money Laundering and Financing of Terrorist Activities (Official Gazette of BiH, No. 13/2024).
- Conduct Customer Due Diligence (CDD): identify and verify the customer (natural persons: full name, address, date/place of birth, unique ID number; legal entities: name, legal form, registered address, registration number, directors, proof of incorporation).
- Identify and verify beneficial owners, including understanding ownership and control structure for legal entities.
- Determine purpose and intended nature of the business relationship.
- Conduct ongoing transaction monitoring throughout the business relationship to ensure transactions are consistent with knowledge of customer, business, and risk profile.
- Maintain up-to-date records and documentation.
- Apply Enhanced Due Diligence (EDD) for: PEPs, cross-border correspondent relationships involving virtual assets, high-risk geographic areas, and complex/unusually large transactions with no apparent economic/lawful purpose.
- Report suspicious transactions to the FIU.
- Covered activities under the AML framework: exchange between virtual assets and fiat, exchange between virtual assets, transfer of virtual assets, safekeeping/administration of virtual assets or instruments enabling control, participation in financial services related to an issuer's offer/sale of a virtual asset.
Key Restrictions
- No dedicated crypto custody license exists — operator must rely on AML/CFT registration and the general AML framework as the regulatory basis.
- No specific legal mandate for segregation of client digital assets from proprietary assets; asset segregation is only a best practice.
- No regulatory requirement for insurance/bonding to cover hacks, operational failures, or losses.
- No regulatory mandate for cold storage; storage decisions are operational choices.
- No statutory definition of 'qualified custodian' for digital assets exists.
- The regulatory framework is fragmented between state-level (BiH) and entity-level (FBiH, RS, Brčko District); a VASP operating on-shore may need to address both the state AML regime and Republika Srpska's registration/notification regime via the RS Securities Commission.
- Operator must be locally incorporated in BiH to qualify as an on-shore VASP.
Key Risks
- Regulatory ambiguity: no dedicated VASP licensing regime, no specific crypto tax guidance, and no custodian rules — operator bears interpretation risk on most compliance obligations.
- Pending MiCA alignment: BiH is an EU candidate country and expected to eventually align with MiCA, which would introduce a comprehensive CASP licensing regime with capital, governance, and segregation requirements — creating regulatory transition risk.
- Enforcement precedent: ongoing Operation Black Diamond cases demonstrate law enforcement (SIPA, Prosecutor's Office of BiH) attention on crypto-linked money laundering and organized crime, raising enforcement exposure for any compliance gaps.
- Tax uncertainty: no official tax guidance on crypto transactions; conservative treatment (income at receipt, capital gains on disposal) is recommended but carries audit risk if different interpretations are applied.
- Fragmented jurisdiction: operator must navigate a complex multi-level regulatory environment (state level + two entities + Brčko District), each with potentially different interpretations and requirements.
- No specific rules on asset segregation, insurance, or qualified custody create commercial risk for clients and reputational risk for the operator.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
AML Registration for VASPs: The primary regulatory requirement for entities providing services related to virtual assets, including those that might engage in custody (e.g., exchanges holding client funds), stems from the AML/CFT framework. BiH has aligned its AML legislation with FATF recommendations, which includes treating Virtual Asset Service Providers (VASPs) as obliged entities.
The Law on Prevention of Money Laundering and Terrorist Financing (Zakon o sprečavanju pranja novca i finansiranja terorističkih aktivnosti) mandates that VASPs, which would typically include entities offering custodial services for virtual assets, must register with the relevant authority (likely the Financial Intelligence Unit - FIU BiH) and implement robust AML/CFT procedures, including Know Your Customer (KYC) checks.
Law on Prevention of Money Laundering and Terrorist Financing of Bosnia and Herzegovina (Official Gazette of BiH, No. 100/17, 36/18, 55/19, 32/22, 12/23, 12/24). While an official English translation with a direct government URL for the latest consolidated version can be hard to pinpoint, the law is accessible via official legislative databases. The Ministry of Security often publishes updates or related information.
Ministry of Security of BiH (responsible for AML policy): http://www.msb.gov.ba/?lang=en (You may need to navigate to legislative sections to find the specific law).
Under the newly adopted AML/CFT Law in Bosnia & Herzegovina, VASP registration and oversight is subject to a three-way regulatory split depending on the entity's incorporation location (FBiH, Republika Srpska, or Brčko District), with the FIU retaining a coordinating AML/CFT role but no longer being the sole first point of contact for VASP registration.
No specific "crypto custody license" exists. Unlike some EU countries with dedicated VASP (Virtual Asset Service Provider) licensing regimes that explicitly cover custody, BiH has not yet introduced such a license.
No specific rules for digital assets. Given the absence of a dedicated custody framework, there are no specific legal mandates requiring the segregation of client digital assets from the custodian's proprietary assets.
General Fiduciary Principles (by analogy): While not legally binding for crypto, general principles of good corporate governance and financial trust would suggest that responsible custodians should segregate assets. However, this is currently a best practice rather than a regulatory requirement in BiH for digital assets.
No specific requirements. There are no explicit regulatory requirements for digital asset custodians in BiH to hold specific insurance or bonding to cover potential losses from hacks, operational failures, or other risks.
No specific mandates. BiH law does not currently mandate the use of cold storage (offline storage) for digital assets under custody. Responsible custodians would typically employ a combination of cold and hot storage for security reasons, but this is an operational choice rather than a regulatory obligation.
No specific definition. BiH law does not currently define what constitutes a "qualified custodian" for digital assets. Without a dedicated custody framework, such definitions are absent.
EU Alignment and MiCA: This is the most significant pending development. Bosnia and Herzegovina is an EU candidate country. As such, it is expected to gradually align its legislation with the EU acquis communautaire. The European Union's Markets in Crypto-Assets (MiCA) Regulation (Regulation (EU) 2023/1114) entered into force in June 2023, with most provisions becoming applicable from December 2024 and June 2025.
Bosnia and Herzegovina now has a state-level AML/CFT framework that expressly covers virtual asset/virtual currency service providers, and Republika Srpska has a dedicated registration/notification regime for virtual currency service providers administered by the RS Securities Commission. While there is still no MiCA-style, fully harmonized crypto-asset licensing law at the state level, RS does operate a specific regulatory and registration regime for crypto businesses, so it is no longer correct to say that BiH operates under ‘no specific licensing regime’ or lacks any mandated authority for crypto businesses.
For virtual asset service providers, AML/CTF registration is no longer best described as an informal or merely ‘implied’ reporting registration. In line with FATF standards and recent reforms (including Australia’s Tranche 2 and comparable EU/Ireland approaches), VASPs are explicitly required to register with the competent AML/CTF authority (e.g., AUSTRAC or the Central Bank) before providing designated services, and must comply with a comprehensive set of ongoing AML/CTF obligations. While this registration is technically for AML/CTF purposes rather than a full prudential or conduct-of-business licence, it is a formal, mandatory regime with significant, licence-like compliance and enforcement requirements—not simply an implied reporting status.
Cryptocurrency exchanges in Bosnia and Herzegovina (BiH), particularly in Republika Srpska, require registration as a VASP with the Securities Commission and obtaining a specific crypto license or authorization, especially for exchange, custody, or related services. Pure crypto-to-crypto exchanges may still face ambiguity, but fiat-related activities trigger stricter oversight under AML laws and banking agencies.
Zakon o sprečavanju pranja novca i finansiranja terorističkih aktivnosti (Law on Prevention of Money Laundering and Financing of Terrorist Activities) – Official Gazette of BiH, No. 13/2024.
Crucial Amendment: The latest significant amendments, particularly those published in Official Gazette of BiH, No. 13/20 (Law on Amendments to the Law on Prevention of Money Laundering and Financing of Terrorism), explicitly brought Virtual Asset Service Providers (VASPs) under the scope of obliged entities. This amendment defined virtual assets and established obligations for entities dealing with them.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Identifying the customer (and any person acting on behalf of the customer) and verifying their identity using reliable, independent source documents, data, or information.
For natural persons: full name, address, date and place of birth, unique identification number (e.g., ID card, passport number).
For legal entities: name, legal form, address of registered office, registration number, names of directors/authorized persons, and proof of incorporation.
Identifying the beneficial owner(s) and taking reasonable measures to verify their identity.
Understanding the ownership and control structure of the customer (for legal entities or arrangements).
Purpose and Intended Nature of the Business Relationship:
Conducting ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure that transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Enhanced CDD (EDD) is required only for specific high-risk activities in Bosnia & Herzegovina, not universally for all higher‑risk situations.
Transactions or business relationships with Politically Exposed Persons (PEPs).
Cross-border correspondent relationships involving virtual assets.
Transactions or relationships involving high-risk geographic areas.
Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
Entity Targeted: An organized international criminal group. Violation Type: International drug trafficking, organized crime, and money laundering through cryptocurrencies. The use of encrypted applications (Sky ECC and Anom) and cryptocurrencies was central to their operations for communication and financial transactions.
The case highlights the growing use of cryptocurrencies by organized crime groups in BiH and the region for illicit financial flows, prompting law enforcement to adapt.
**Exchange of Crypto for Fiat:** Under the CJEU Hedqvist precedent (C-264/14), exchange of crypto for fiat is likely exempt from VAT as a financial service. However, **this has no explicit support from UIO BiH**. BiH is not an EU member and has not issued guidance adopting this precedent.
Services related to virtual assets, such as transaction fees charged by crypto exchanges, software development services for blockchain, or consulting services, would generally be subject to the standard 17% VAT, provided the supplier is VAT-registered and the service is deemed to be supplied in BiH.
Any taxable capital gains or income derived from cryptocurrency must be reported on their annual personal income tax return (Obrazac GPD-10K in FBiH, Obrazac 1004 in RS), just like any other income or gain.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — an on-shore VASP may operate in Bosnia and Herzegovina by incorporating locally and registering under the AML/CFT framework (no dedicated VASP/custody license exists yet), but faces regulatory ambiguity, no specific rules on custody/segregation/insurance, fragmented entity-level requirements, and pending MiCA alignment that will restructure the regime.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?