Custodial wallet / SaaS in Belgium
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Belgium with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the FSMA as a 'provider of custodian wallet services' under Article 5, §1, 37° of the Law of 18 September 2017 (AML Law).
- Ongoing AML/CFT compliance obligations including customer due diligence (CDD), transaction monitoring, record-keeping, and internal governance/policies.
- Reporting of suspicious transactions to the Belgian Financial Intelligence Processing Unit (CTIF-CFI).
- Under MiCA (applicable from 30 December 2024): authorization as a CASP for 'safekeeping and administration of crypto-assets on behalf of clients' under Article 67 — includes stricter organizational, operational, and prudential requirements (governance, risk management, capital).
- Segregation of client crypto-assets from own assets and from other clients' assets is mandatory under MiCA Article 67(2).
- A written agreement with clients specifying duties and responsibilities is required under MiCA Article 67(2).
- No use of client crypto-assets or funds for the provider's own account (MiCA Article 67(2)).
- The SaaS provider (custodian) bears the primary AML/CFT obligations as the registered VASP/CASP; white-label clients relying on the SaaS may have their own AML duties depending on whether they face end users.
Key Restrictions
- A local Belgian entity (or EU-established entity) is required to register with the FSMA; non-EU operators must establish a branch or entity in Belgium/the EU.
- The current FSMA registration regime is AML-focused and does not constitute a full prudential license (no banking-style capital requirements yet — MiCA will introduce prudential requirements).
- No explicit national mandates for insurance, bonding, or specific cold-storage ratios currently exist under the AML Law, though MiCA introduces broader organizational requirements.
- The white-label client's own regulatory status depends on the services they offer to end users — they may independently need VASP/CASP registration if they touch custody or exchange.
Key Risks
- Dual-regime transition risk: operators are currently under the AML registration regime but must shift to the MiCA CASP authorization framework by 30 December 2024 (or applicable transitional period).
- No explicit national segregation rules pre-MiCA — reliance on implicit expectations of sound business practices creates ambiguity until MiCA applies.
- Lack of explicit insurance, bonding, or cold-storage mandates under current Belgian law means supervisors may apply ad hoc expectations during inspections.
- White-label SaaS structure creates AML allocation risk — unclear whether the FSMA would expect the SaaS provider or the white-label client to own the end-user CDD relationship.
- Enforcement precedent is limited — Belgium has issued consumer warnings but has not yet conducted high-profile enforcement actions against custodian wallet providers.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Requirement: Providers of "custodian wallet services" are required to register with the FSMA. This is not a full financial services license but an AML registration.
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
Regulator: Financial Services and Markets Authority (FSMA).
In Belgium’s twin‑peaks model, virtual asset service providers and similar intermediaries that fall under the FSMA’s remit must register and provide information on the company, its governance and internal organization, shareholders, and their AML/CFT policies and procedures. The FSMA assesses these elements in line with its conduct‑of‑business and AML supervisory role, while key prudential and certain fit‑and‑proper/AML responsibilities for many institutions lie with the National Bank of Belgium (NBB).
Explicit Rules for Crypto: The current AML Law of 2017 does not explicitly detail segregation rules specifically for crypto assets.
Implicit Expectations: However, as entities subject to AML/CFT, registered custodian wallet providers are generally expected to adhere to sound business practices, which would imply the segregation of client assets from the firm's own operational assets to protect clients in case of insolvency or operational issues. This is a general principle of good governance and risk management in financial services.
Explicit Requirements: There are no explicit national mandates for specific insurance or bonding requirements for crypto custodian wallet providers under the current AML framework.
Implied: Prudent risk management would nevertheless encourage such providers to consider adequate insurance coverage.
Explicit Mandates: There are no explicit national mandates for the use of cold storage or specific percentages of assets to be held in cold storage under the current AML framework.
Implied: Robust cybersecurity and operational risk management are expected, and the use of cold storage is generally considered a best practice for securing a significant portion of client digital assets. The FSMA would expect appropriate security measures as part of the operational risk assessment during registration.
Specific Definition for Crypto: The current Belgian framework does not define a "qualified custodian" specifically for digital assets beyond the "custodian wallet provider" designation under the AML Law. This designation focuses on AML/CFT compliance rather than broader financial regulatory standards.
Authorization: Providers of "safekeeping and administration of crypto-assets on behalf of clients" will need to obtain authorization as a Crypto-Asset Service Provider (CASP) from their national competent authority (the FSMA in Belgium). This is a more comprehensive authorization than the current AML registration.
Scope: MiCA defines "safekeeping and administration of crypto-assets on behalf of clients" as the activity of safeguarding or controlling crypto-assets or instruments giving access to crypto-assets on behalf of third parties.
Requirements: CASPs will need to meet stringent organizational, operational, and prudential requirements, including having robust governance arrangements, internal control mechanisms, risk management procedures, and capital requirements.
Article 53 (General obligations for CASPs) and Article 67 (Specific obligations for providers of safekeeping and administration of crypto-assets on behalf of clients) are particularly relevant.
Explicit Mandate: MiCA explicitly mandates the segregation of client assets.
Details (Article 67(2)): Providers of safekeeping and administration of crypto-assets on behalf of clients must:
Enter into an agreement with their clients specifying their duties and responsibilities.
Keep records and establish accounts in their internal accounting systems that enable them to distinguish crypto-assets held on behalf of clients from their own crypto-assets and other clients' crypto-assets, and the funds of clients from their own funds.
Not use crypto-assets or funds held on behalf of clients for their own account.
Custody Providers (Custody wallet providers):
Scope: This covers services that provide the safekeeping and management of virtual currencies on behalf of clients, including holding private cryptographic keys.
Current Regime (Belgium): It is a registration regime, primarily focused on AML/CTF compliance. It does not imply a full prudential licensing similar to banks, traditional investment firms, or e-money institutions. The FSMA grants "registration" but does not "license" in the broader financial sense that implies comprehensive prudential oversight of capital, risk management beyond AML, consumer protection, etc.
Future Regime (EU MiCA): The upcoming EU Markets in Crypto-Assets (MiCA) Regulation will introduce a comprehensive, harmonized licensing regime across the EU for a much broader range of crypto-asset services. This will supersede the current national AML-driven registration frameworks for many activities.
Partial, Moving Towards Comprehensive: Before MiCA, Belgium's approach was characterized by specific AML/CFT regulations for certain crypto service providers, consumer warnings, and a general "wait and see" stance for broader market regulation. With MiCA's staggered implementation (July 2024 for stablecoins, December 2024 for other crypto-assets), Belgium is in the process of fully integrating a comprehensive regulatory framework for crypto-asset issuance, trading, and services.
Impact: Extended the scope of AML/CFT rules to include providers engaged in exchange services between virtual currencies and fiat currencies, and custodian wallet providers. This mandated registration requirements at the national level.
Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash (AML Law)
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators may serve Belgian residents by registering with the FSMA under the AML Law of 18 September 2017, but will need to transition to the full MiCA CASP authorization (including mandatory asset segregation, governance, and capital requirements) by the applicable deadline, and the SaaS provider vs. white-label client allocation of AML duties remains somewhat ambiguous under current guidance.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?