Remote VASP serving residents in Bulgaria
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes under the Measures Against Money Laundering Act (MAMLA).
- Conduct customer due diligence (CDD) including identification and verification of natural persons (name, date/place of birth, nationality, permanent address, unique ID number) and legal entities (company name, legal form, registration number, registered address, authorized representatives).
- Identify and verify beneficial owners (BO) — natural persons holding 25% + one share or more voting rights or exercising control.
- Understand the purpose and intended nature of the business relationship; gather information on expected transaction patterns and source of funds/wealth where relevant.
- Perform ongoing transaction monitoring and regular scrutiny to ensure consistency with customer risk profile.
- Keep customer documents, data, and information up-to-date.
- Apply enhanced due diligence for Politically Exposed Persons (PEPs), high-risk third countries, and complex/unusual/large transactions.
- Report suspicious transactions (STRs) to the State Agency for National Security (SANS) — Financial Intelligence Directorate (Bulgaria's FIU).
- Comply with the EU Travel Rule under Regulation (EU) 2023/1113 (amended TFR) — collect and transmit originator (name, crypto-asset account number, address/national ID, date/place of birth) and beneficiary (name, crypto-asset account number) information for ALL crypto-asset transfers between CASPs, with no de minimis threshold.
- For transfers to/from unhosted wallets above €1,000, verify that the wallet is owned/controlled by the originator or beneficiary; below €1,000, verification is not strictly mandated absent suspicion.
- Retain records of collected information for five years.
- Implement risk-based procedures and internal policies to mitigate ML/TF risks, including systems to detect missing/incomplete information on transfers.
- Comply with GDPR for all data processing.
Key Restrictions
- A foreign-incorporated entity serving Bulgarian residents from abroad must register with the NRA as a VASP under MAMLA, effectively requiring a local compliance presence or local entity.
- The entity must be licensed/authorized as a Crypto-Asset Service Provider (CASP) under the EU MiCA framework (transposed into Bulgarian law via the Law on Crypto-Asset Markets on 20 June 2025), which imposes authorization requirements on any entity providing crypto-asset services to EU residents on a professional basis.
- Providing services without proper registration/licensing would constitute unlicensed operation, exposing the entity to enforcement action including administrative fines, cessation orders, and potential criminal investigation for money laundering.
Key Risks
- High enforcement risk for unlicensed remote operators — Bulgarian authorities (NRA and SANS) can impose administrative fines, cessation of activities, and refer cases for criminal investigation.
- Fines for legal entities can reach up to BGN 1,000,000 or more depending on severity, and supervisory bodies may suspend or withdraw registrations.
- Prior to full MiCA implementation, some remote VASPs operated without local registration; this era is ending — strict enforcement of registration and Travel Rule requirements applies from December 2024 onward, with MiCA fully applicable from 2026.
- Lack of a local entity exposes the operator to practical difficulties in meeting CDD, record-keeping, and supervisory inspection requirements.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Measures Against Money Laundering Act (MAMLA) (Закон за мерките срещу изпирането на пари - ЗМИП).
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
In Bulgaria, AML/CFT supervision of VASPs is shared among multiple authorities, with the National Revenue Agency (NRA) as the leading registration and enforcement body, the Financial Supervision Commission (FSC) overseeing crypto-asset service providers within its regulatory perimeter, and DANS-FID retaining a role but no longer the sole or primary supervisor.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Bulgarian law now mandates continuous identification and verification of beneficial owners, requiring ongoing monitoring and periodic updates beyond a static registration step.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Understanding the Purpose and Intended Nature of the Business Relationship:
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Adopted: Yes, the principles of the FATF Travel Rule for crypto assets are adopted in Bulgaria through the Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, also known as the amended Transfer of Funds Regulation (TFR). This regulation is directly applicable in all EU member states, including Bulgaria, without the need for national transposition.
The EU Transfer of Funds Regulation as amended by Regulation (EU) 2023/1113 extends the Travel Rule to crypto‑asset transfers, and these requirements have applied in the EU (including Bulgaria) since 30 December 2024.
For crypto-asset transfers between EU Crypto-Asset Service Providers (CASPs) under Regulation (EU) 2023/1113, there is no de minimis threshold: all such transfers, regardless of amount, must include complete originator and beneficiary information. However, the EU framework now distinguishes these CASP‑to‑CASP transfers from transactions involving self‑hosted wallets, for which additional rules apply above €1,000, so any description of the regime should situate the zero‑threshold rule within this broader, MiCA‑aligned CASP/Transfer of Funds Regulation context rather than as a generic VASP rule.
As of July 1, Bulgaria applies MiCA’s strict rules to all crypto transfers, including those involving self-hosted wallets, ending any prior unregulated status.
CASPs must collect originator and beneficiary information for all transfers.
For transfers exceeding €1,000, the CASP must verify that the unhosted wallet is owned or controlled by the originator or beneficiary.
Verification is now mandatory for all unhosted wallets in Bulgaria, regardless of transaction value below €1,000.
Any natural or legal person whose occupation or business is to provide one or more crypto-asset services to third parties on a professional basis, as defined under Bulgaria's Law on Crypto-Asset Markets transposing MiCA into national law on 20 June 2025.
Collect and transmit information: Ensure that crypto-asset transfers are accompanied by the following information:
Originator: Name, crypto-asset account number, address (or national ID number/customer ID number), date and place of birth (for natural persons), legal entity registration number (for legal entities).
Beneficiary: Name, crypto-asset account number.
Verify information: Take reasonable steps to verify the accuracy of the information, especially for transfers to/from unhosted wallets above the €1,000 threshold.
Retain records: Keep records of the collected information for a period of five years.
Detect missing information: Implement systems to detect if the required originator or beneficiary information is missing or incomplete for incoming or outgoing transfers.
Implement risk-based procedures: Establish robust internal policies, controls, and procedures to mitigate money laundering and terrorist financing risks, including procedures for handling transfers with incomplete information or to/from unhosted wallets.
Data Protection: All data processing must comply with the GDPR (General Data Protection Regulation).
For legal entities in Bulgaria, fines can vary widely and may be set as fixed amounts or as a percentage of annual turnover, with some regimes allowing penalties up to BGN 1,000,000 or more depending on the specific law, the severity of the breach, repeat offenses, and the type of entity.
Sanctions by supervisory bodies:
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Bulgarian residents must register with the NRA for AML purposes and obtain authorization as a CASP under MiCA (transposed into Bulgarian law), which effectively requires a local entity or at minimum a local compliance presence, and full Travel Rule/CDD obligations apply from December 2024 onward.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?