Remote VASP serving residents in Micronesia
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Micronesia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) required under Title 27 of the FSM Code (Anti-Money Laundering and Terrorist Financing Act 2017), including identification and verification of natural and legal persons, beneficial ownership identification, and understanding the purpose of the business relationship.
- Risk-based approach to CDD, with Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, or complex/unusually large transactions.
- Ongoing monitoring of transactions throughout the business relationship.
- Suspicious Transaction Reporting (STR) to the FSM Financial Intelligence Unit (FIU) — obligation applies regardless of transaction amount or asset type (fiat or virtual).
- Travel Rule compliance: For cross-border transfers, collect and transmit originator/beneficiary information for transactions equivalent to USD 1,000 or more. For domestic transfers, threshold is USD 3,000 or more (per APG report July 2022).
- Recordkeeping: Maintain customer identification records, transaction records, and business correspondence for AML/CFT purposes.
- No-tipping-off prohibitions regarding STR filings.
- Registration/licensing under the 2020 amendments to the AML/CFT Act, which require VASPs to register, be licensed, and comply with AML/CFT obligations including Travel Rule.
Key Restrictions
- VASPs must be registered and licensed under the 2020 AML/CFT Act amendments (which specifically address FATF Recommendations on VAs and VASPs).
- Local entity or presence appears required to satisfy registration/licensing requirements — there is no framework for non-resident licensing.
- No comprehensive dedicated crypto regulatory framework exists — the legal basis rests on AML/CFT law and implicit securities law application.
- If tokens offered are classified as securities (under implicitly applied U.S.-style Howey Test), the operator would be subject to general securities registration and disclosure requirements, for which no specific crypto exemptions exist.
Key Risks
- Extremely limited enforcement capacity and regulatory understanding by FSM authorities (APG report notes lack of understanding/supervisory capacity for virtual assets).
- No publicly available enforcement examples or legal cases for crypto securities violations — creating significant legal uncertainty.
- No known registered or licensed VASPs in the jurisdiction as of latest assessments — unlicensed remote operation carries risk of future retroactive enforcement as framework develops.
- FATF/APG pressure on FSM to develop comprehensive VA/VASP regulation means the legal landscape may change rapidly.
- Ambiguity around whether payment tokens (Bitcoin, stablecoins) would be securities under implied Howey Test analysis creates classification risk.
- Finding and maintaining compliance contacts with FSM FIU can be difficult due to limited public web presence and institutional capacity.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No Specific Crypto Requirements: There are no specific registration or exemption requirements published by the FSM for token issuers.
Undefined/Indirect: The FSM currently lacks a comprehensive and explicit regulatory framework specifically for cryptocurrencies and virtual assets. The approach can be characterized as largely undefined or operating in a "grey area."
Partial/Indirect Application: While there's no dedicated crypto law, existing anti-money laundering (AML) and combating the financing of terrorism (CFT) legislation and regulatory bodies would likely apply to virtual asset activities, especially for entities operating within the FSM or facilitating transactions involving FSM residents. This aligns with global standards set by the Financial Action Task Force (FATF), which requires countries to regulate Virtual Asset Service Providers (VASPs).
The Howey Test (U.S. Standard): An "investment contract" (and thus a security) exists if there is:
Application of General Securities Law (if applicable): If a token were classified as a security under existing FSM law, then the issuer would theoretically be subject to any existing general securities registration and disclosure requirements. Given the nascent nature of crypto regulation in the FSM, it is highly improbable that existing securities laws would be practically adaptable to digital asset offerings without explicit guidance or amendments. Issuers would likely find themselves in a regulatory vacuum or an unworkable compliance scenario.
No Specific Crypto Rules: Similar to issuance, there are no specific rules governing the secondary trading of cryptocurrency tokens in the FSM.
Application of General Securities Trading Law (if applicable): If a token were deemed a security, secondary trading would technically be subject to general rules for securities exchanges, broker-dealers, and market conduct. However, these rules are not designed for decentralized or global crypto trading platforms, making practical application extremely difficult without tailored legislation.
Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27 of the FSM Code): This act establishes the general framework for combating money laundering and terrorist financing, including obligations for financial institutions and designated non-financial businesses and professions (DNFBPs). While it may not explicitly mention "virtual assets" or "VASPs" as distinct regulated entities, the FSM, as an APG member, is expected to apply these requirements to VASPs in line with FATF Recommendation 15 (now Recommendation 16 in the context of the FATF's June 2019 Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers).
Financial Intelligence Unit (FIU) of the Federated States of Micronesia (FSM FIU)
Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.
Asia/Pacific Group on Money Laundering (APG) Enhanced Follow-Up Report & Technical Compliance Re-Rating - Federated States of Micronesia (July 2022). Specifically, pages 21-23 regarding Recommendations 15 (New Technologies) and 16 (Wire Transfers).
For cross-border transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 1,000 or more.
For domestic transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 3,000 or more.
Risk-Based Approach: Applying a risk-based approach to CDD, meaning enhanced CDD (EDD) measures must be applied to higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, or where the customer's identity verification poses higher risk) and simplified CDD (SCDD) may be applied to lower-risk customers.
Reporting any transaction (or attempted transaction) that gives rise to a reasonable suspicion that it may be related to money laundering, terrorist financing, or other criminal activity.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Beneficial Ownership: Identifying and verifying the identity of the beneficial owner(s) of the customer, and taking reasonable measures to understand the ownership and control structure of legal persons and arrangements.
Customer Identification Records: All records obtained through CDD measures (e.g., copies of identification documents, verification data).
Transaction Records: Records of all transactions, including amounts, types of virtual assets, sending and receiving addresses/accounts, timestamps, and any other relevant transaction data.
Lack of a Dedicated Regulatory Framework: The FSM currently lacks a comprehensive legal and regulatory framework specifically addressing virtual assets (VAs) and virtual asset service providers (VASPs).
No Registered or Licensed VASPs: As of the latest assessments, there are no known or registered VASPs operating within the FSM that would fall under a regulatory scope (if one existed).
Limited Capacity and Awareness: International assessments indicate that the FSM's financial authorities are still developing their understanding and capacity to monitor and regulate the virtual asset sector.
No specific legislation: The FSM had not yet enacted specific legislation or regulations to address virtual assets or virtual asset service providers (VASPs).
No VASPs identified: The authorities had not identified any VASPs operating within the jurisdiction.
Lack of understanding and capacity: The report highlighted a lack of understanding by supervisory authorities regarding the risks associated with virtual assets and a need to develop supervisory capacity in this area.
Recommendations: The APG recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations, and ensure appropriate supervision and enforcement capabilities.
Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving residents of the Federated States of Micronesia must register and be licensed under the 2020 AML/CFT Act amendments (which apply FATF standards including Travel Rule), must comply with full AML/CFT obligations supervised by the FSM FIU, and likely requires a local entity; however, the jurisdiction lacks a dedicated comprehensive crypto framework, has no known licensed VASPs, and faces significant regulatory ambiguity and limited enforcement capacity.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?