← Regulations / Bulgaria / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Bulgaria

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes (bg.aml.national-revenue-agency-nra--)
  • Customer Due Diligence (CDD) under MAMLA, including identity verification (name, DOB, nationality, address, national ID number for natural persons; company name, legal form, registration number, address for legal entities) (bg.aml.natural-persons-name-date-and, bg.aml.legal-entities-company-name-legal)
  • Beneficial Owner identification (25%+1 share threshold or control) and verification (bg.aml.identification-and-verification-of-the, bg.aml.for-legal-entities-vasps-must)
  • Understanding purpose and intended nature of business relationship and source of funds/wealth (bg.aml.understanding-the-purpose-and-intended)
  • Ongoing transaction monitoring throughout the business relationship (bg.aml.regular-scrutiny-of-transactions-undertaken)
  • Suspicious Transaction Reports (STRs) to SANS Financial Intelligence Directorate (bg.aml.state-agency-for-national-security, bg.aml.role-this-is-bulgarias-financial)
  • Record-keeping obligations under MAMLA (bg.aml.keeping-customer-documents-data-and)
  • Enhanced due diligence for PEPs and high-risk third countries (bg.aml.politically-exposed-persons-peps-customers, bg.aml.high-risk-third-countries-transactions-involving)
  • Reporting of complex, unusual, large transactions or unusual patterns (bg.aml.complex-unusual-large-transactions-or)
  • Ongoing internal control rules and compliance program (bg.aml.identification-and-verification-of-the)

Key Restrictions

  • Must register as a VASP with the National Revenue Agency (NRA) before offering custodial wallet services (bg.aml.national-revenue-agency-nra--)
  • Must comply with MAMLA defining virtual asset safekeeping/administration as a regulated activity (bg.aml.safekeeping-andor-administration-of-virtual)
  • The SaaS provider (custodian) is the obliged entity — not just the white-label client — because the provider holds the keys and performs safekeeping (bg.aml.safekeeping-andor-administration-of-virtual)
  • No specific custody license / qualified-custodian framework identified in the facts — VASP registration under AML law appears to be the primary gateway

Key Risks

  • No dedicated custody license regime (capital/reserve/segregation rules) described in the provided facts — regulatory gaps around proof-of-reserves and insurance requirements are unaddressed and create uncertainty
  • AML obligations attach to the custodial SaaS provider as the obliged entity performing safekeeping, but the facts do not clarify how obligations split between provider and white-label client in a SaaS model
  • Enforcement exposure: administrative fines, cessation orders, and potential criminal investigation for non-compliance with MAMLA (bg.enforcement.violation-type-non-compliance-with-the)
  • EU sanctions directly applicable — custodians must implement sanctions screening without national transposition gap (bg.enforcement.legal-basis-eu-sanctions-are)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 95% confidence

Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).

aml 95% confidence

This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.

aml 90% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 90% confidence

In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.

aml 90% confidence

National Revenue Agency (NRA) (Национална агенция за приходите - НАП)

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 80% confidence

Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).

aml 80% confidence

Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.

aml 95% confidence

For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.

aml 88% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 83% confidence

Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Keeping customer documents, data, and information up-to-date.

aml 95% confidence

Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.

aml 95% confidence

High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.

aml 95% confidence

Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.

enforcement 98% confidence

Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.

enforcement 70% confidence

Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers are permitted in Bulgaria as VASPs but must register with the National Revenue Agency for AML/CFT purposes under MAMLA; no dedicated custody-license framework (capital, segregation, insurance, proof-of-reserves rules) is apparent from the provided facts, creating regulatory uncertainty for this operating model.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?