Custodial wallet / SaaS in Germany
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- KYC verification of all transaction parties' identities under GwG (German Money Laundering Act)
- Transaction monitoring obligations per GwG AML/CFT requirements
- Travel rule compliance under KryptoWTransferV (Crypto Asset Transfer Regulation) — originator/beneficiary identification for crypto transfers
- Full adherence to German Money Laundering Act (GwG) for customer identification and transaction monitoring
- BaFin supervision for AML compliance as CASP/custody licensee
Key Restrictions
- Must be licensed as a crypto custodian (Kryptoverwahrgeschaeft) under KWG § 1(1a) Sentence 2 No. 6 — EUR 125,000 minimum capital
- Must establish a German legal entity (GmbH, AG, or bank) with proper corporate governance
- Complete segregation of client and proprietary crypto assets required (no co-mingling)
- Professional liability insurance minimum €1,000,000 covering custody service operation risks
- IT security procedures per BAIT (BaFin Guidance on IT Requirements) including encryption, access controls, and incident response
- CASP authorization under MiCA is also applicable — transition from pre-MiCA KWG regime to MiCA within 12-month transition period
Key Risks
- BaFin known for thorough/slow processing — 6-12 month licensing timeline
- AML obligations apply to the licensed custodian (SaaS operator); white-label clients may introduce shared AML responsibility and regulatory uncertainty regarding cascading KYC
- IT security and BAIT/DORA compliance burdens are high — operational complexity for SaaS operators managing multi-tenant key infrastructure
- Ambiguity around whether the SaaS operator's corporate clients need separate CASP licenses if they control the wallet front-end
- €125,000 minimum capital may be insufficient for operational scale, BaFin may require higher capital on assessment
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied
Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum
VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).
CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.
German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.
Markets in Crypto-Assets Regulation (MiCAR): Applies EU-wide as of the end of 2024, establishing harmonized licensing requirements for crypto-asset service providers throughout the EU.
Safekeeping, administration, and safeguarding of crypto assets or private keys
Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.
Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.
IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.
Customer asset segregation: Complete separation of client and proprietary crypto assets required.
AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.
Know Your Customer (KYC): Verification of all transaction parties' identities.
Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance
Preparing a comprehensive business plan describing crypto custody offerings, technology platform, and security procedures
Documenting capital adequacy with €125,000 minimum through bank accounts and audited financial statements
German Banking Act (KWG): § 1(1a) Sentence 2 No. 6
Markets in Crypto-Assets Regulation: EU 2023/1114
GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.
KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.
KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.
KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators must obtain a KWG crypto custody license (Kryptoverwahrgeschaeft) from BaFin with €125k minimum capital, establish a German legal entity, segregate client assets, carry €1M professional liability insurance, and comply with full GwG AML obligations including travel rule; transition to MiCA CASP authorization applies.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?