Remote VASP serving residents in Cyprus
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): identification and verification of customer identity for natural persons (full name, DOB, place of birth, nationality, address, unique ID) and legal entities (company name, legal form, registration number, registered address, directors, articles).
- Beneficial ownership identification: identify and verify UBOs holding ≥25% shares/voting rights or exercising control.
- Source of Funds / Source of Wealth verification for higher-risk clients or significant transactions.
- Enhanced Due Diligence (EDD) required for PEPs, high-risk third-country customers, non-face-to-face relationships without safeguards, and unusual/high-value/complex transactions.
- Ongoing monitoring of business relationships and transactions for suspicious patterns or deviations.
- Internal reporting to Money Laundering Reporting Officer (MLRO); MLRO evaluates and submits STRs to MOKAS (Cyprus FIU).
- Tipping-off prohibition: cannot disclose to customer that an STR has been submitted.
- Record-keeping for at least 5 years from transaction completion or termination of business relationship; records must be accessible to CySEC, MOKAS, and other authorities.
- Appointment of an MLRO at management level.
- Regular and ongoing AML/CFT staff training.
Key Restrictions
- A remote VASP serving Cyprus residents must be registered with CySEC as a CASP under the Prevention and Suppression of Money Laundering and Terrorist Financing Law and CySEC Directive 342/2021, and will need MiCA authorization by December 30, 2024.
- Physical presence required in Cyprus (must have a local entity/office and demonstrate substance).
- Local management and control tests apply — the entity must meet local substance requirements.
- Directors and key personnel must be 'fit and proper'; capital requirements apply (minimum €125,000 for custody/administration of crypto-assets under Class 2).
- Cannot operate on a pure cross-border basis without a local licensed entity — unlicensed remote servicing is not permitted.
- Organisational requirements include robust internal controls, risk management systems, IT security, business continuity plans, and data protection compliance.
Key Risks
- Unlicensed remote operation carries clear enforcement risk: CySEC has fined major firms (eToro Europe Ltd, Bitpanda GmbH) for AML/CFT and organisational non-compliance under the existing framework.
- Pending full MiCA application by December 30, 2024, creates regulatory transition risk — operators may need to dual-comply with current CySEC CASP regime and new MiCA requirements.
- Physical presence and substance requirements make the 'remote VASP' model structurally non-viable without establishing a Cyprus entity.
- Non-compliance with STR obligations to MOKAS or tipping-off restrictions could result in criminal or administrative penalties.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Directive (EU) 2018/843 (5AMLD): Crucially extended the scope of EU AML rules to include crypto-asset exchanges and custodian wallet providers, requiring them to be regulated and subject to AML/CFT obligations.
CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.
CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.
Application Process: Submission of a detailed application to CySEC.
Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.
Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.
The entity must meet local management and control tests to maintain its status, not strictly be a legal person established in Cyprus.
Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.
Organisational requirements in Cyprus continue to include robust internal controls and compliance with data protection laws, while effective risk management systems, IT systems, security mechanisms, and business continuity plans have been significantly enhanced and made more prescriptive through the Security of Networks and Information Systems Law (N.89 (I)/2020 as amended by N.60 (I)/2025) implementing the NIS2 Directive, which mandates specific technical, operational, and organisational measures for essential and important organisations with compliance by October 2024.
AML/CFT Compliance: Comprehensive AML/CFT policies, procedures, and internal controls, including customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting.
Identification and Verification of Customer Identity:
Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.
Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.
Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.
Internal Reporting: Employees must report suspicions to the appointed Money Laundering Reporting Officer (MLRO).
MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).
Tipping-off: CASPs and their employees are strictly prohibited from disclosing to the customer or any third party that an STR has been or will be submitted, or that a money laundering investigation is underway.
Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.
Money Laundering Reporting Officer (MLRO): Appointment of a suitably qualified and experienced MLRO at management level responsible for overseeing AML/CFT compliance.
Staff Training: Regular and ongoing training for all relevant employees on AML/CFT risks, regulations, and internal procedures.
CASPs offering "custody and administration of crypto-assets on behalf of clients" will require authorization as a CASP under MiCA. CySEC will be the competent authority for authorizing and supervising CASPs in Cyprus.
December 30, 2024: Rules for all other crypto-assets and CASPs (including custody providers) will apply.
Article 67: CASPs providing custody services must hold crypto-assets on behalf of clients separately from their own assets. They must ensure that client crypto-assets are not used for their own account and are identifiable from the CASP's own crypto-assets.
Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.
Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP cannot serve Cyprus residents from abroad without a local CySEC-registered entity; full CASP registration is required under the AML/CFT framework and will be superseded by MiCA authorization by December 30, 2024, with substantial capital, substance, and AML obligations.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?