Remote VASP serving residents in Germany
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full adherence to GwG (German Money Laundering Act) with customer identification and transaction monitoring (de.licensing.amlcft-compliance-full-adherence-to)
- KYC verification of all transaction parties' identities (de.licensing.know-your-customer-kyc-verification)
- Travel Rule compliance under §3 KryptoTransferV — share originator's account, beneficiary's name and account (public keys) with zero-threshold (de.travel-rule.3-kryptotransferv-mandates-sharing-originators)
- Transaction monitoring and suspicious activity reporting to BaFin and FIU (de.licensing.amlcft-compliance-full-adherence-to)
- Ongoing AML/CFT supervision by BaFin under KWG and KMAG (de.aml.kmag-crypto-markets-supervision-act)
Key Restrictions
- Must establish a German legal entity (GmbH, AG, or bank) — pure cross-border remote service from abroad without local incorporation is not permitted (de.licensing.establishing-a-german-legal-entity)
- At least one managing director must satisfy BaFin's fit-and-proper requirements (de.licensing.fit-and-proper-requirements-at-least-one)
- Minimum capital of EUR 125,000 for custody license; EUR 150,000 for exchange/trading platform CASP authorization (de.licensing.custody, de.licensing.exchange)
- Professional liability insurance of minimum EUR 1,000,000 required (de.licensing.professional-liability-insurance-minimum-1000000)
- Customer asset segregation: complete separation of client and proprietary crypto assets (de.licensing.customer-asset-segregation-complete-separation)
- IT security procedures must comply with BAIT (BaFin IT Guidance) and DORA (de.licensing.it-security-procedures-per-bait)
Key Risks
- BaFin has a track record of issuing public warnings and enforcement actions against unlicensed foreign VASPs serving German residents (e.g., Binance warning in 2023)
- 6–12 month licensing process with thorough BaFin review — significant delay risk for market entry
- Travel Rule technical compliance is required at zero threshold; absence of standardized protocols may create operational gaps
- Regulatory ambiguity during MiCA transition period (pre-existing KWG regime vs. new CASP regime under MiCA) may cause dual-application burdens
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied
Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum
VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).
CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.
EXCHANGE: CASP authorization under MiCA — EUR 150,000 minimum capital for trading platforms
Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance
Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.
Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.
Customer asset segregation: Complete separation of client and proprietary crypto assets required.
IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.
AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.
Know Your Customer (KYC): Verification of all transaction parties' identities.
GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.
KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.
Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)
§3 KryptoTransferV mandates sharing: originator's account (e.g., public key), beneficiary's name and account (e.g., public key).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-resident VASP cannot serve German residents from abroad without establishing a local entity and obtaining BaFin licensing (either a crypto custody license under KWG or CASP authorization under MiCA), with high licensing burden including minimum capital, fit-and-proper requirements, and full AML/CFT obligations.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?