Remote VASP serving residents in Belgium
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Belgium with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the FSMA as a VASP under the Law of 18 September 2017 (AML Law) — this is a mandatory AML/CFT registration, not a full prudential license.
- Customer due diligence (CDD) obligations under the Belgian AML Law (Law of 18 September 2017) as transposed from AMLD5.
- Travel Rule compliance under EU Regulation 2023/1113 (recast TFR), effective 30 December 2024 — must collect and transmit originator and beneficiary information for all crypto-asset transfers, with no de minimis threshold for CASP-to-CASP transfers.
- For transfers ≥€1,000: full originator and beneficiary identification required (name, address, account number/transaction ID, date/place of birth for originator).
- For transfers <€1,000: wallet addresses (originator and beneficiary DLT addresses) required.
- Ongoing transaction monitoring and suspicious transaction reporting to the Belgian Financial Intelligence Processing Unit (CTIF-CFI).
- Travel Rule data handling must comply with GDPR.
- Under MiCA (from 30 Dec 2024 for CASPs): additional organizational, operational, and prudential requirements including capital requirements, governance arrangements, and risk management procedures.
Key Restrictions
- Foreign-incorporated entities serving Belgian residents from abroad must register with the FSMA as a VASP — cross-border service without registration is unlawful.
- The current regime (pre-MiCA full implementation) is an AML registration regime only; it does not grant a full financial services license.
- From 30 December 2024, MiCA will require authorization as a Crypto-Asset Service Provider (CASP) from the FSMA, superseding the current AML registration for many activities.
- If the operator also handles fiat payment services linked to crypto, it may fall under PSD2 and require authorization as a Payment Institution or Electronic Money Institution.
- Registration requires providing information on the company, governance, internal organization, shareholders, and AML/CFT policies and procedures to the FSMA for assessment.
- No explicit exemption for foreign entities serving Belgian residents on a reverse-solicitation or cross-border basis — the registration requirement applies to services offered to Belgian residents.
Key Risks
- Enforcement risk for unregistered remote operators: the FSMA has authority to impose substantial administrative sanctions including fines, public warnings/reprimands, and withdrawal of authorization; serious or repeated breaches can lead to criminal sanctions including imprisonment.
- Regulatory ambiguity exists for purely crypto-to-crypto payment services without custody or fiat exchange — the FSMA would assess on a case-by-case basis.
- MiCA transition risk: operators registering under the current AML regime will need to upgrade to full CASP authorization under MiCA, with more stringent capital and governance requirements.
- The Belgian AML Law (2017) does not explicitly detail segregation or insurance rules for crypto assets currently, but MiCA will impose mandatory client asset segregation (Article 67(2)).
- The FSMA actively issues consumer warnings about crypto risks and may take enforcement action against non-compliant operators operating remotely into Belgium.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Required: Registration with the FSMA.
Scope: This includes services for the exchange between virtual currencies and fiat currencies, as well as exchange services between one or more virtual currencies.
Current Regime (Belgium): It is a registration regime, primarily focused on AML/CTF compliance. It does not imply a full prudential licensing similar to banks, traditional investment firms, or e-money institutions. The FSMA grants "registration" but does not "license" in the broader financial sense that implies comprehensive prudential oversight of capital, risk management beyond AML, consumer protection, etc.
Future Regime (EU MiCA): The upcoming EU Markets in Crypto-Assets (MiCA) Regulation will introduce a comprehensive, harmonized licensing regime across the EU for a much broader range of crypto-asset services. This will supersede the current national AML-driven registration frameworks for many activities.
Law of 18 September 2017:
Partial, Moving Towards Comprehensive: Before MiCA, Belgium's approach was characterized by specific AML/CFT regulations for certain crypto service providers, consumer warnings, and a general "wait and see" stance for broader market regulation. With MiCA's staggered implementation (July 2024 for stablecoins, December 2024 for other crypto-assets), Belgium is in the process of fully integrating a comprehensive regulatory framework for crypto-asset issuance, trading, and services.
Focus Areas: AML/CFT, consumer protection, market integrity, and financial stability.
EU Harmonization: Belgium, as an EU member state, is directly impacted by and actively transposing/implementing EU regulations.
Financial Services and Markets Authority (FSMA - Autoriteit voor Financiële Diensten en Markten / Autorité des services et marchés financiers):
Belgian Level: As an EU Regulation, Regulation (EU) 2023/1113 is directly applicable in Belgium without the need for national transposition into Belgian law. Belgium's existing AML/CFT framework (primarily the Law of 18 September 2017) provides the national enforcement and supervisory structure, and will be supplemented by the TFR.
The Travel Rule applies to all crypto-asset transfers involving a CASP, but with differentiated requirements based on transaction value: transfers below €1,000 require only wallet addresses (originator and beneficiary distributed ledger addresses), while transfers of €1,000 or more require full identifying information including names, addresses, and IDs. For self-hosted wallets, ownership verification is only required for amounts exceeding €1,000.
Unlike traditional wire transfers where there might be a threshold for full data collection, for crypto-asset transfers handled by CASPs, there is no de minimis threshold. Information must be collected and transmitted for every transaction.
Originator Information: Name, crypto-asset account number (or transaction identifier), address (or national ID/customer ID, date/place of birth).
Beneficiary Information: Name, crypto-asset account number (or wallet address)
Data Protection: Implementation must comply with the General Data Protection Regulation (GDPR) regarding the collection, processing, and storage of personal data.
Requirement: Providers of "custodian wallet services" are required to register with the FSMA. This is not a full financial services license but an AML registration.
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
In Belgium’s twin‑peaks model, virtual asset service providers and similar intermediaries that fall under the FSMA’s remit must register and provide information on the company, its governance and internal organization, shareholders, and their AML/CFT policies and procedures. The FSMA assesses these elements in line with its conduct‑of‑business and AML supervisory role, while key prudential and certain fit‑and‑proper/AML responsibilities for many institutions lie with the National Bank of Belgium (NBB).
Authorization: Providers of "safekeeping and administration of crypto-assets on behalf of clients" will need to obtain authorization as a Crypto-Asset Service Provider (CASP) from their national competent authority (the FSMA in Belgium). This is a more comprehensive authorization than the current AML registration.
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
In the Belgian context, FSMA refers to the Financial Services and Markets Authority, a financial regulator that can impose substantial administrative sanctions (including high monetary fines, public warnings/reprimands, and withdrawal of authorisation) under Belgian financial legislation. This is distinct from the U.S. Food Safety Modernization Act (FSMA), which is a U.S. food safety law enforced by the FDA and does not act as a Belgian supervisory authority or impose euro‑denominated travel‑rule fines.
Criminal Penalties: Serious or repeated breaches can also lead to criminal sanctions, including imprisonment for natural persons and substantially higher criminal fines for both natural and legal persons.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Belgian residents must register with the FSMA under the AML Law of 18 September 2017 (and, from 30 December 2024, obtain MiCA CASP authorization) and comply with full AML/CFT obligations including Travel Rule requirements; cross-border service without registration carries significant enforcement risk including administrative fines and criminal penalties.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?