← Regulations / Czech Republic / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Czech Republic

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Czech Republic with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration as a trade license (živnostenské oprávnění) under the Trade Licensing Act for 'Provision of services relating to virtual assets' (custody services are explicitly listed as a VASP activity).
  • Must register with the Financial Analytical Office (FAÚ) as an obliged entity under Act No. 253/2008 Coll. (AML Act).
  • Customer identification (KYC): full name, date/place of birth, permanent address, nationality for natural persons; company name, registered office, IČO, and statutory representative details for legal entities.
  • Beneficial owner identification and verification for legal entities and trusts (any natural person holding >25% ownership or control).
  • Verification of identity using reliable, independent sources (government-issued IDs, official company registers).
  • Enhanced verification for non-face-to-face relationships (remote onboarding), which applies to SaaS wallet models.
  • Enhanced Due Diligence (EDD) for higher-risk situations including PEPs and complex/unusual transactions.
  • Ongoing transaction monitoring and regular reviews of customer information and risk assessments.
  • Source of funds/wealth measures for higher-risk customers or transactions.
  • Travel Rule compliance (TFR / EU Travel Rule for crypto transfers) as part of evolving EU framework.
  • Reporting of suspicious transactions to FAÚ.
  • Compliance with MiCA Regulation (once fully applicable) including authorisation and prudential requirements for CASPs offering custody services.

Key Restrictions

  • A local trade license (živnostenské oprávnění) is required — the operator must have a registered presence in Czechia.
  • Custodial wallet services are classified as a VASP activity requiring FAÚ registration and AML compliance.
  • The Trade Licensing Act was amended effective April 1, 2025, with further amendments July 1, 2025 — the regulatory framework is in flux.
  • MiCA Regulation will apply, introducing a harmonised EU authorisation regime for crypto-asset service providers (CASPs) including custodial wallet providers.

Key Risks

  • Regulatory burden is increasing: the shift from light-touch trade-license registration to full MiCA authorisation raises operational and capital requirements.
  • FAÚ AML/CFT enforcement against obliged entities (including crypto service providers) is active — fines for compliance failures are a real risk.
  • Severe criminal enforcement precedent exists (e.g., BTC-e/Vinnik case involving Czech police/EPPO) — operating without proper registration or AML controls carries criminal liability risk.
  • The regulatory position on segregation, insurance, and proof-of-reserves for custodial wallets in Czechia is not clearly articulated in available public facts — this ambiguity creates operational risk.
  • SaaS / white-label structures may create ambiguity about which party (SaaS provider vs white-label client) bears primary AML obligations under Czech law.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

VASP Activities (Virtual Assets Only): For services exclusively involving virtual assets (e.g., crypto-to-crypto exchange, crypto custody), the Czech Republic requires registration as a trade license (živnostenské oprávnění) under the Trade Licensing Act, specifically for "Provision of services related to virtual assets." This is generally considered a "free trade" (volná živnost).

aml 100% confidence

Act No. 253/2008 Coll., on Certain Measures Against Legalisation of Proceeds of Crime and Financing of Terrorism (the "AML Act"): This is the primary national law transposing the EU AML directives. It was amended to include VASPs as obliged entities.

aml 90% confidence

Act No. 455/1991 Coll., the Trade Licensing Act, was amended effective April 1, 2025, and further amendments will take effect July 1, 2025, affecting the regulatory framework for virtual asset service providers under Czech AML law.

aml 40% confidence

Custodial Wallet Services: Providing services to safeguard private cryptographic keys on behalf of customers, to hold, store, and transfer virtual assets.

aml 90% confidence

While the Fifth Anti-Money Laundering Directive (EU 2018/843) (5AMLD) initially brought virtual asset service providers under AML/CFT scope in Czechia, the framework has evolved with newer EU regulations (e.g., MiCA, Travel Rule, upcoming AMLR/AMLD legislation by 2025) now also being relevant and superseding aspects of previous directives.

aml 95% confidence

The legal framework for money laundering harmonization in Czechia is now governed by Directive (EU) 2024/1640, which replaced the earlier Sixth Anti-Money Laundering Directive (EU 2018/1673).

aml 40% confidence

Identification of the Customer:

aml 80% confidence

Natural Persons: Full name, date and place of birth, permanent address, nationality.

aml 100% confidence

Legal Entities: Company name, registered office address, identification number (IČO), and details of their statutory representatives.

aml 100% confidence

Beneficial Owner (BO): For legal entities and trusts, VASPs must identify and verify the beneficial owner(s) – i.e., the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted. This typically involves identifying any natural person holding more than 25% of the shares or voting rights, or otherwise exercising control.

aml 40% confidence

Verification of Identity:

aml 90% confidence

Information must be verified using reliable, independent sources (e.g., valid government-issued identification documents for individuals like passports or ID cards; official company registration documents for legal entities).

aml 100% confidence

For non-face-to-face relationships, enhanced verification measures are required.

aml 40% confidence

Enhanced Due Diligence (EDD):

aml 90% confidence

Customers or beneficial owners who are Politically Exposed Persons (PEPs).

aml 40% confidence

Source of Funds/Wealth (When Applicable):

aml 95% confidence

VASPs must continuously monitor the business relationship and transactions to ensure they are consistent with their knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 95% confidence

Regular reviews of customer information and risk assessments must be conducted.

licensing 85% confidence

AML/CFT fines by the FAÚ for failures in compliance, which can apply to any "obliged entity," including crypto service providers. However, large, publicly detailed fines against prominent crypto platforms are not as common as in some other countries.

enforcement 100% confidence

Entity Targeted: Alexander Vinnik (primary alleged operator of BTC-e/WEX), and associated individuals/entities involved in money laundering. Violation Type: Operating an unlicensed money transmission business, money laundering (estimated billions of dollars), and wire fraud using Bitcoin. Outcome: Disruption of a major global cryptocurrency-based money laundering operation. Seizure of significant assets. Conviction and ongoing prosecution of key individuals.

enforcement 100% confidence

Entity Targeted: Various obliged entities, including (but not limited to) payment institutions, banks, and potentially smaller crypto service providers. Specific names and detailed violations for smaller crypto firms are not always publicly disclosed unless the fine is exceptionally large or the case is particularly egregious. Violation Type: Failure to comply with anti-money laundering and counter-terrorist financing (AML/CFT) obligations (e.g., insufficient customer due diligence, inadequate risk assessment, failure to report suspicious transactions). Penalty Amount: Varies significantly depending on the severity and scale of the violation. Fines can range from tens of thousands CZK to millions CZK. FAÚ annually publishes statistics on fines but not always specific details for each entity unless it's a high-profile case. Outcome: Improved AML compliance among obliged entities, deterrence of future violations.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators may serve Czech residents after obtaining a local trade license, registering with the FAÚ as an obliged entity, and implementing full AML/KYC/EDD programs under Act No. 253/2008 Coll., with MiCA authorisation becoming mandatory once fully applicable; segregation, insurance, and proof-of-reserves rules are not clearly specified in available sources.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?