← Regulations / Cyprus / Operating Models / Crypto ATM

Crypto ATM / kiosk operator in Cyprus

Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.

Conditional AI-Generated · Unreviewed

Crypto ATM is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD required on all customers: natural persons (full name, DOB, nationality, address, ID/passport number) verified via independent source documents (cy.aml.identification-and-verification-of-customer, cy.aml.natural-persons-full-name-date)
  • Legal entity CDD: company name, legal form, registration number, registered address, directors, articles, and proof of legal existence (cy.aml.legal-entities-company-name-legal)
  • Beneficial ownership identification: identify and verify UBOs holding ≥25% of shares/voting rights (cy.aml.identification-of-beneficial-ownership-for)
  • Enhanced Due Diligence (EDD) required for: PEPs, customers from high-risk third countries, non-face-to-face relationships, unusual/high-value transactions (cy.aml.enhanced-due-diligence-edd-must, cy.aml.business-relationships-with-politically-exposed, cy.aml.customers-residing-in-or-conducting, cy.aml.non-face-to-face-business-relationships-without-adequate, cy.aml.transactions-involving-unusual-patterns-high)
  • EDD measures include: additional information, senior management approval, increased monitoring, deeper SoF/SoW verification (cy.aml.measures-include-obtaining-additional-information)
  • Source of Funds / Source of Wealth verification required for higher-risk clients or significant transactions (cy.aml.source-of-funds-sof-source)
  • Ongoing monitoring of business relationships for suspicious patterns (cy.aml.ongoing-monitoring-continuously-monitoring-the)
  • Internal reporting to MLRO; MLRO must submit STRs to MOKAS (Cyprus FIU) (cy.aml.internal-reporting-employees-must-report, cy.aml.mlros-duty-the-mlro-must)
  • Record-keeping for at least 5 years from transaction or termination of business relationship; records must be accessible to CySEC and MOKAS (cy.aml.duration-records-must-be-kept, cy.aml.accessibility-records-must-be-readily)
  • Appointment of an MLRO at management level; mandatory staff training on AML/CFT (cy.aml.money-laundering-reporting-officer-mlro, cy.aml.staff-training-regular-and-ongoing)
  • Tipping-off prohibition strictly applies (cy.aml.tipping-off-casps-and-their-employees)

Key Restrictions

  • CASP must have a physical presence in Cyprus and demonstrate substance (cy.licensing.physical-presence-the-casp-must)
  • Minimum initial capital of €125,000 for custody/administration services (Class 2) — applicable as ATM/kiosk operators hold crypto keys (cy.licensing.capital-requirements-minimum-initial-capital)
  • Directors and key personnel must be 'fit and proper' — at least 4 board members (2 executive, 2 non-executive) for CIF-type structures (cy.licensing.management-personnel-directors-and-key)
  • Robust internal controls, risk management systems, IT security, business continuity plans required (cy.licensing.organisational-requirements-robust-internal-controls)
  • Safeguarding of client assets via secure systems, segregation, and strong cryptographic key security (cy.licensing.safeguarding-client-assets-through-secure, cy.licensing.robust-security-measures-for-cryptographic)
  • The entity must meet local management and control tests (cy.licensing.legal-form-the-entity-must)
  • Must register as a CASP with CySEC under the Prevention and Suppression of Money Laundering Law and CySEC Directive 342/2021 (cy.licensing.cysec-directive-for-the-prevention, cy.licensing.the-prevention-and-suppression-of)

Key Risks

  • Crypto ATM/kiosk operators are inherently high-cash, high-risk for money laundering — EDD triggers frequently (non-face-to-face, cash-heavy transactions) (cy.aml.non-face-to-face-business-relationships-without-adequate, cy.aml.transactions-involving-unusual-patterns-high)
  • Enforcement precedent exists: CySEC fined eToro (Europe) Ltd and Bitpanda GmbH for AML/CFT compliance failures, indicating active supervision and significant penalty risk (cy.enforcement.entity-targeted-etoro-europe-ltd, cy.enforcement.entity-targeted-bitpanda-gmbh-a)
  • MiCA regulation is in the process of superseding the current CySEC CASP framework, creating regulatory transition risk (cy.licensing.cysec-policy-statement-ps-01-2021-regarding)
  • Cash-transaction reporting thresholds not explicitly provided in available facts — operator must confirm with CySEC/MOKAS whether a specific cash threshold applies beyond standard STR obligations
  • STR obligations create tipping-off risk for kiosk operators whose staff may interact directly with customers in physical locations

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Directive (EU) 2018/843 (5AMLD): Crucially extended the scope of EU AML rules to include crypto-asset exchanges and custodian wallet providers, requiring them to be regulated and subject to AML/CFT obligations.

licensing 80% confidence

The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (as amended) remains the foundational law, but CySEC has issued additional strengthened anti-money laundering guidelines beyond the original text, incorporating new risk requirements.

licensing 20% confidence

CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.

licensing 20% confidence

Exchange between crypto assets and fiat currencies.

licensing 20% confidence

Management, transfer, holding, and/or safekeeping of crypto assets or cryptographic keys or means which allow the exercise of control over crypto assets.

licensing 100% confidence

CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.

licensing 90% confidence

Application Process: Submission of a detailed application to CySEC.

licensing 90% confidence

The entity must meet local management and control tests to maintain its status, not strictly be a legal person established in Cyprus.

licensing 90% confidence

Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.

licensing 90% confidence

Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.

licensing 90% confidence

Organisational requirements in Cyprus continue to include robust internal controls and compliance with data protection laws, while effective risk management systems, IT systems, security mechanisms, and business continuity plans have been significantly enhanced and made more prescriptive through the Security of Networks and Information Systems Law (N.89 (I)/2020 as amended by N.60 (I)/2025) implementing the NIS2 Directive, which mandates specific technical, operational, and organisational measures for essential and important organisations with compliance by October 2024.

licensing 80% confidence

AML/CFT Compliance: Comprehensive AML/CFT policies, procedures, and internal controls, including customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting.

licensing 80% confidence

Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.

licensing 60% confidence

Robust record-keeping to identify client holdings.

licensing 80% confidence

Strong internal controls to prevent misuse or commingling.

licensing 100% confidence

Safeguarding client assets through secure systems.

licensing 90% confidence

Mitigation of operational risks.

licensing 100% confidence

Robust security measures for cryptographic keys.

aml 20% confidence

Identification and Verification of Customer Identity:

aml 20% confidence

Natural Persons: Full name, date and place of birth, nationality, permanent residential address, unique identification number (e.g., passport or ID number). Verification requires reliable, independent source documents and/or data.

aml 20% confidence

Legal Entities: Company name, legal form, registration number, registered address, names of directors and company secretary, articles of association, and proof of legal existence.

aml 20% confidence

Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.

aml 20% confidence

Understanding the Purpose and Nature of the Business Relationship: CASPs must understand why the customer wants to use their services and the expected type and volume of transactions.

aml 20% confidence

Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.

aml 20% confidence

Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:

aml 20% confidence

Business relationships with Politically Exposed Persons (PEPs), their family members, or close associates.

aml 20% confidence

Customers residing in or conducting transactions with high-risk third countries (as identified by the EU or FATF).

aml 20% confidence

Non-face-to-face business relationships without adequate safeguards.

aml 20% confidence

Transactions involving unusual patterns, high value, or complex structures.

aml 20% confidence

Measures include: Obtaining additional information, senior management approval, increased monitoring, and requiring deeper SoF/SoW verification.

aml 20% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.

aml 20% confidence

Internal Reporting: Employees must report suspicions to the appointed Money Laundering Reporting Officer (MLRO).

aml 20% confidence

MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).

aml 20% confidence

Tipping-off: CASPs and their employees are strictly prohibited from disclosing to the customer or any third party that an STR has been or will be submitted, or that a money laundering investigation is underway.

aml 20% confidence

Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.

aml 20% confidence

Copies of all documents obtained for CDD (identification data, verification documents).

aml 20% confidence

Originals or copies of transaction records, including the amount, currency, date, and parties involved.

aml 20% confidence

Records of internal policies, procedures, risk assessments, and training provided to staff.

aml 20% confidence

Accessibility: Records must be readily accessible to CySEC, MOKAS, and other competent authorities upon request.

aml 20% confidence

Internal Policies and Procedures: CASPs must establish and maintain robust internal AML/CFT policies, controls, and procedures, including a comprehensive risk assessment. These should be documented in an "AML Manual."

aml 20% confidence

Money Laundering Reporting Officer (MLRO): Appointment of a suitably qualified and experienced MLRO at management level responsible for overseeing AML/CFT compliance.

aml 20% confidence

Staff Training: Regular and ongoing training for all relevant employees on AML/CFT risks, regulations, and internal procedures.

enforcement 70% confidence

Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.

enforcement 70% confidence

Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.

enforcement 70% confidence

Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — Crypto ATM/kiosk operators may operate in Cyprus as registered CASPs with CySEC, subject to stringent AML/CFT obligations, a minimum capital of €125,000, physical presence in Cyprus, and enhanced due diligence particularly given the high-cash, non-face-to-face nature of kiosk operations.

Questions this verdict aims to answer

  • What money-transmitter / kiosk-specific license is required?
  • What cash-transaction reporting thresholds apply?
  • What enhanced-KYC obligations attach to cash-in / cash-out?