Remote VASP serving residents in European Union
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in European Union with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CASP authorization required under MiCA (EU 2023/1114) via home Member State NCA — covers custody, exchange, transfer, execution, placement, advice, portfolio management, reception/transmission, and trading platform services
- Travel Rule applies at EUR 0 threshold (no de minimis) under TFR recast (EU 2023/1113) — originator and beneficiary data must be transmitted on all crypto-asset transfers
- Minimum capital requirements per service class: custody (EUR 50K), exchange (EUR 125K), trading platform (EUR 150K), transfer services (EUR 50K), order execution (EUR 50K), etc.
- Asset segregation and client asset trust obligations mandatory for custody services
- Transitional provisions under Article 127 MiCA — up to 18 months (varies by Member State; e.g. France 6 months, Germany 12 months); existing operators without authorization after transition face enforcement
- AML/CFT harmonization obligations under AMLD6 apply
- DAC8 tax reporting obligations effective 2026
- EBA Travel Rule Guidelines (final July 2024, applicable Dec 30, 2024) specify handling of missing/incomplete beneficiary data
Key Restrictions
- Must be authorized as a CASP by the home Member State NCA (e.g. AMF, BaFin, CNMV, CBI) — remote non-EU entities cannot serve EU residents without EU establishment
- EU-wide passporting available after authorization (notify home NCA, 20 business days) — but requires a local entity in at least one Member State
- No de minimis threshold for Travel Rule — applies to all transfers, including peer-to-peer where a CASP is involved
- Transitional periods vary by Member State — creates compliance complexity for operators serving multiple EU jurisdictions
- National transitional provisions are optional — operators must check each Member State's stance
Key Risks
- Enforcement risk: NCAs have mandate under Article 114 MiCA to pursue unauthorized operators; ESMA (Dec 2024) warned unregulated entities serving EU retail clients face enforcement
- Precedent: AMF (Jan 2026) issued cease-and-desist against unregistered non-EU CASP (CryptoFlow Ltd.) soliciting French residents — demonstrates active enforcement against remote operators
- Supervisory fragmentation risk: 8 of 27 NCAs had not finalized MiCA enforcement guidelines by Q1 2026 (ESRB March 2026 analysis) — uneven enforcement landscape across Member States
- Dutch AFM issued formal warnings to 14 firms for incomplete authorization applications by Feb 28, 2026 deadline
- Practical enforcement examples still limited as of April 2026, but trajectory is toward increasing NCA action against unauthorized cross-border service
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP: CASP authorization under MiCA via home NCA. 9 service classes: custody (EUR 50K), trading platform (EUR 150K), exchange (EUR 125K), order execution (EUR 50K), placing (EUR 50K), reception/transmission (EUR 50K), advice (EUR 50K), portfolio mgmt (EUR 50K), transfer services (EUR 50K). Prudential: higher of fixed minimum or 1/4 prior year fixed overhead.
EXCHANGE: CASP authorization with EU-wide passporting (notify home NCA, 20 business days). Transition: up to 18 months for existing operators (July 2026 deadline). France chose 6 months, Germany 12 months.
CUSTODY: CASP Class 1 — EUR 50,000 minimum capital. Asset segregation mandatory. Client assets held on trust.
MiCA Regulation (EU 2023/1114) (2023) — Comprehensive CASP authorization, token issuance, white paper requirements — fully effective Dec 30, 2024
Transfer of Funds Regulation (recast) (2023) — Travel Rule — EUR 0 threshold (no de minimis)
AMLD6 (2024) — AML/CFT harmonization across EU
DAC8 (2024) — Crypto reporting directive for tax authorities — effective 2026
Threshold Amounts: No de minimis threshold; the rule applies to all crypto-asset transfers, exceeding basic FATF requirements.
Technical Implementation Requirements: CASPs must securely transmit and retain detailed data on originators (e.g., name, address, wallet addresses) and beneficiaries during transfers. EBA's Travel Rule Guidelines (finalized July 2024, applicable December 30, 2024) specify detecting/handling missing data, risk-based approaches, and compliance with prior guidelines like JC/GL/2017/16. The EU mandates more extensive data points than FATF or jurisdictions like Singapore.
EBA Travel Rule Guidelines: Final report on info requirements for funds/crypto transfers. Direct PDF: https://www.eba.europa.eu/sites/default/files/2024-07/6de6e9b9-0ed9-49cd-985d-c0834b5b4356/Travel%20Rule%20Guidelines.pdf
In January 2026, the French Autorité des Marchés Financiers (AMF) became the first NCA to publicly announce a formal enforcement action under MiCA, issuing a cease-and-desist order against an unregistered non-EU CASP (CryptoFlow Ltd., registered in the Cayman Islands) for soliciting French residents without authorization; the AMF noted this action as a "test case" for MiCA enforcement coordination across NCAs AMF MiCA Enforcement Action January 2026
A March 2026 analysis by the European Systemic Risk Board (ESRB) identified that 8 of the 27 EU NCAs had not yet finalized their MiCA enforcement guidelines by Q1 2026, creating "supervisory fragmentation risks" for CASPs operating across multiple member states; the ESRB warned that this could lead to inconsistent application of authorization requirements and investor protections by the April 2026 enforcement date ESRB Analysis of MiCA Supervisory Fragmentation
The European Commission's March 2026 enforcement update confirmed that the Netherlands Authority for the Financial Markets (AFM) had issued formal warnings to 14 crypto-asset firms for failing to submit complete authorization applications by the February 28, 2026 deadline; the AFM warned that firms without approved authorization by April 1, 2026, would face immediate suspension orders European Commission MiCA Enforcement Update March 2026
By April 2026, NCAs have the mandate under Article 114 to process authorization applications, monitor ongoing compliance, and initiate enforcement actions against non-compliant entities, particularly those operating without authorization and not covered by transitional provisions; enforcement powers include suspension of services, imposition of fines, and public warnings MiCA Article 114 Enforcement
ESMA has issued a public statement in December 2024 reminding market participants that unregulated entities offering services to EU retail clients without authorization or transitional grandfathering may face enforcement actions, and has called for convergent supervisory practices across Member States ESMA December 2024 Statement
Practical enforcement examples by April 2026 remain limited; however, in late 2025, the Dutch Authority for the Financial Markets (AFM) issued warnings against several unregistered crypto firms operating without transitional provisions AFM Crypto Warnings
The application of national transitional provisions under Article 127 is optional for Member States, leading to significant variability: for example, Germany has applied a transitional period until June 30, 2026 for existing CASPs, while France opted for a shorter period ending March 31, 2025, creating uneven enforcement intensity across jurisdictions BaFin Transitional Provisions; AMF France MiCA
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-resident VASP cannot serve EU residents remotely without establishing a local entity and obtaining CASP authorization under MiCA via a home Member State NCA, with full AML/Travel Rule obligations (EUR 0 threshold), and faces active enforcement risk for non-compliance.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?