← Regulations / Bulgaria / Operating Models / Remote VASP

Remote VASP serving residents in Bulgaria

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes under the Measures Against Money Laundering Act (MAMLA).
  • Conduct customer due diligence (CDD) including identification and verification of natural persons (name, date/place of birth, nationality, permanent address, unique ID number) and legal entities (company name, legal form, registration number, registered address, authorized representatives).
  • Identify and verify beneficial owners (BO) — natural persons holding 25% + one share or more voting rights or exercising control.
  • Understand the purpose and intended nature of the business relationship; gather information on expected transaction patterns and source of funds/wealth where relevant.
  • Perform ongoing transaction monitoring and regular scrutiny to ensure consistency with customer risk profile.
  • Keep customer documents, data, and information up-to-date.
  • Apply enhanced due diligence for Politically Exposed Persons (PEPs), high-risk third countries, and complex/unusual/large transactions.
  • Report suspicious transactions (STRs) to the State Agency for National Security (SANS) — Financial Intelligence Directorate (Bulgaria's FIU).
  • Comply with the EU Travel Rule under Regulation (EU) 2023/1113 (amended TFR) — collect and transmit originator (name, crypto-asset account number, address/national ID, date/place of birth) and beneficiary (name, crypto-asset account number) information for ALL crypto-asset transfers between CASPs, with no de minimis threshold.
  • For transfers to/from unhosted wallets above €1,000, verify that the wallet is owned/controlled by the originator or beneficiary; below €1,000, verification is not strictly mandated absent suspicion.
  • Retain records of collected information for five years.
  • Implement risk-based procedures and internal policies to mitigate ML/TF risks, including systems to detect missing/incomplete information on transfers.
  • Comply with GDPR for all data processing.

Key Restrictions

  • A foreign-incorporated entity serving Bulgarian residents from abroad must register with the NRA as a VASP under MAMLA, effectively requiring a local compliance presence or local entity.
  • The entity must be licensed/authorized as a Crypto-Asset Service Provider (CASP) under the EU MiCA framework (transposed into Bulgarian law via the Law on Crypto-Asset Markets on 20 June 2025), which imposes authorization requirements on any entity providing crypto-asset services to EU residents on a professional basis.
  • Providing services without proper registration/licensing would constitute unlicensed operation, exposing the entity to enforcement action including administrative fines, cessation orders, and potential criminal investigation for money laundering.

Key Risks

  • High enforcement risk for unlicensed remote operators — Bulgarian authorities (NRA and SANS) can impose administrative fines, cessation of activities, and refer cases for criminal investigation.
  • Fines for legal entities can reach up to BGN 1,000,000 or more depending on severity, and supervisory bodies may suspend or withdraw registrations.
  • Prior to full MiCA implementation, some remote VASPs operated without local registration; this era is ending — strict enforcement of registration and Travel Rule requirements applies from December 2024 onward, with MiCA fully applicable from 2026.
  • Lack of a local entity exposes the operator to practical difficulties in meeting CDD, record-keeping, and supervisory inspection requirements.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 95% confidence

Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).

aml 95% confidence

This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.

aml 95% confidence

Exchange between virtual assets and fiat currencies.

aml 100% confidence

Exchange between one or more forms of virtual assets.

aml 90% confidence

Transfer of virtual assets.

aml 90% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 90% confidence

In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.

aml 90% confidence

National Revenue Agency (NRA) (Национална агенция за приходите - НАП)

aml 90% confidence

Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.

aml 80% confidence

Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).

aml 80% confidence

Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.

aml 95% confidence

For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.

aml 88% confidence

Understanding the Purpose and Intended Nature of the Business Relationship:

aml 83% confidence

Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Keeping customer documents, data, and information up-to-date.

aml 95% confidence

Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.

aml 95% confidence

High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.

aml 95% confidence

Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.

travel-rule 95% confidence

Adopted: Yes, the principles of the FATF Travel Rule for crypto assets are adopted in Bulgaria through the Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, also known as the amended Transfer of Funds Regulation (TFR). This regulation is directly applicable in all EU member states, including Bulgaria, without the need for national transposition.

travel-rule 84% confidence

The EU Transfer of Funds Regulation as amended by Regulation (EU) 2023/1113 extends the Travel Rule to crypto‑asset transfers, and these requirements have applied in the EU (including Bulgaria) since 30 December 2024.

travel-rule 86% confidence

For crypto-asset transfers between EU Crypto-Asset Service Providers (CASPs) under Regulation (EU) 2023/1113, there is no de minimis threshold: all such transfers, regardless of amount, must include complete originator and beneficiary information. However, the EU framework now distinguishes these CASP‑to‑CASP transfers from transactions involving self‑hosted wallets, for which additional rules apply above €1,000, so any description of the regime should situate the zero‑threshold rule within this broader, MiCA‑aligned CASP/Transfer of Funds Regulation context rather than as a generic VASP rule.

travel-rule 90% confidence

As of July 1, Bulgaria applies MiCA’s strict rules to all crypto transfers, including those involving self-hosted wallets, ending any prior unregulated status.

travel-rule 80% confidence

CASPs must collect originator and beneficiary information for all transfers.

travel-rule 100% confidence

For transfers exceeding €1,000, the CASP must verify that the unhosted wallet is owned or controlled by the originator or beneficiary.

travel-rule 95% confidence

Verification is now mandatory for all unhosted wallets in Bulgaria, regardless of transaction value below €1,000.

travel-rule 90% confidence

Any natural or legal person whose occupation or business is to provide one or more crypto-asset services to third parties on a professional basis, as defined under Bulgaria's Law on Crypto-Asset Markets transposing MiCA into national law on 20 June 2025.

travel-rule 90% confidence

Collect and transmit information: Ensure that crypto-asset transfers are accompanied by the following information:

travel-rule 90% confidence

Originator: Name, crypto-asset account number, address (or national ID number/customer ID number), date and place of birth (for natural persons), legal entity registration number (for legal entities).

travel-rule 95% confidence

Beneficiary: Name, crypto-asset account number.

travel-rule 95% confidence

Verify information: Take reasonable steps to verify the accuracy of the information, especially for transfers to/from unhosted wallets above the €1,000 threshold.

travel-rule 90% confidence

Retain records: Keep records of the collected information for a period of five years.

travel-rule 90% confidence

Detect missing information: Implement systems to detect if the required originator or beneficiary information is missing or incomplete for incoming or outgoing transfers.

travel-rule 85% confidence

Implement risk-based procedures: Establish robust internal policies, controls, and procedures to mitigate money laundering and terrorist financing risks, including procedures for handling transfers with incomplete information or to/from unhosted wallets.

travel-rule 100% confidence

Data Protection: All data processing must comply with the GDPR (General Data Protection Regulation).

travel-rule 93% confidence

For legal entities in Bulgaria, fines can vary widely and may be set as fixed amounts or as a percentage of annual turnover, with some regimes allowing penalties up to BGN 1,000,000 or more depending on the specific law, the severity of the breach, repeat offenses, and the type of entity.

enforcement 98% confidence

Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a remote VASP serving Bulgarian residents must register with the NRA for AML purposes and obtain authorization as a CASP under MiCA (transposed into Bulgarian law), which effectively requires a local entity or at minimum a local compliance presence, and full Travel Rule/CDD obligations apply from December 2024 onward.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?