Custodial wallet / SaaS in Bulgaria
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes (bg.aml.national-revenue-agency-nra--)
- Customer Due Diligence (CDD) under MAMLA, including identity verification (name, DOB, nationality, address, national ID number for natural persons; company name, legal form, registration number, address for legal entities) (bg.aml.natural-persons-name-date-and, bg.aml.legal-entities-company-name-legal)
- Beneficial Owner identification (25%+1 share threshold or control) and verification (bg.aml.identification-and-verification-of-the, bg.aml.for-legal-entities-vasps-must)
- Understanding purpose and intended nature of business relationship and source of funds/wealth (bg.aml.understanding-the-purpose-and-intended)
- Ongoing transaction monitoring throughout the business relationship (bg.aml.regular-scrutiny-of-transactions-undertaken)
- Suspicious Transaction Reports (STRs) to SANS Financial Intelligence Directorate (bg.aml.state-agency-for-national-security, bg.aml.role-this-is-bulgarias-financial)
- Record-keeping obligations under MAMLA (bg.aml.keeping-customer-documents-data-and)
- Enhanced due diligence for PEPs and high-risk third countries (bg.aml.politically-exposed-persons-peps-customers, bg.aml.high-risk-third-countries-transactions-involving)
- Reporting of complex, unusual, large transactions or unusual patterns (bg.aml.complex-unusual-large-transactions-or)
- Ongoing internal control rules and compliance program (bg.aml.identification-and-verification-of-the)
Key Restrictions
- Must register as a VASP with the National Revenue Agency (NRA) before offering custodial wallet services (bg.aml.national-revenue-agency-nra--)
- Must comply with MAMLA defining virtual asset safekeeping/administration as a regulated activity (bg.aml.safekeeping-andor-administration-of-virtual)
- The SaaS provider (custodian) is the obliged entity — not just the white-label client — because the provider holds the keys and performs safekeeping (bg.aml.safekeeping-andor-administration-of-virtual)
- No specific custody license / qualified-custodian framework identified in the facts — VASP registration under AML law appears to be the primary gateway
Key Risks
- No dedicated custody license regime (capital/reserve/segregation rules) described in the provided facts — regulatory gaps around proof-of-reserves and insurance requirements are unaddressed and create uncertainty
- AML obligations attach to the custodial SaaS provider as the obliged entity performing safekeeping, but the facts do not clarify how obligations split between provider and white-label client in a SaaS model
- Enforcement exposure: administrative fines, cessation orders, and potential criminal investigation for non-compliance with MAMLA (bg.enforcement.violation-type-non-compliance-with-the)
- EU sanctions directly applicable — custodians must implement sanctions screening without national transposition gap (bg.enforcement.legal-basis-eu-sanctions-are)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Understanding the Purpose and Intended Nature of the Business Relationship:
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are permitted in Bulgaria as VASPs but must register with the National Revenue Agency for AML/CFT purposes under MAMLA; no dedicated custody-license framework (capital, segregation, insurance, proof-of-reserves rules) is apparent from the provided facts, creating regulatory uncertainty for this operating model.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?