Crypto ATM / kiosk operator in Guernsey
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including crypto ATM/kiosk operators) must register with and be licensed by the GFSC under the VASP licensing regime.
- Standard CDD required for all customers: identify and verify the customer using reliable, independent source documents (passport, national ID).
- Identify beneficial owners (25% ownership threshold) for legal persons.
- Collect source of funds/wealth information.
- Understand the purpose and intended nature of the business relationship.
- Enhanced Due Diligence (EDD) required for higher-risk situations including: non-face-to-face relationships, complex or unusually large transactions, customers from high-risk jurisdictions, PEPs, and specific virtual asset activities carrying higher risk.
- Ongoing monitoring of customer relationships and transactions to ensure consistency with risk profile.
- Sanctions screening against UN, UK, EU, and Guernsey sanctions lists.
- Obligation to report knowledge or suspicion of ML/TF to the Guernsey Financial Intelligence Unit (FIU).
- No tipping-off offence applies regarding STR filings.
- Must appoint a Money Laundering Reporting Officer (MLRO) and Deputy MLRO with internal reporting procedures.
- Cash-transaction reporting thresholds not explicitly stated in provided facts — likely follows the GFSC Handbook's guidance on high-value cash transactions and suspicious activity reporting.
- Risk-Based Approach (RBA) required: VASPs must assess ML/TF risks specific to their business and apply commensurate CDD.
Key Restrictions
- Must be licensed as a VASP by the Guernsey Financial Services Commission (GFSC) before operating any crypto ATM/kiosk.
- Must maintain a local entity (incorporated in Guernsey or at minimum registered/licensed with GFSC).
- Must comply with the Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 and the Terrorism and Crime (Bailiwick of Guernsey) Law, 2002.
- Must follow the GFSC's AML/CFT Handbook, which includes a dedicated section on Virtual Assets and VASPs.
- Crypto ATM/kiosk operations involving cash-in/cash-out inherently carry higher AML/CFT risk, triggering mandatory EDD for such transactions.
- Non-face-to-face business relationships (a typical feature of ATM/kiosk transactions) require additional safeguards and may trigger EDD obligations.
- Must have robust internal controls and record-keeping under the Criminal Justice (Proceeds of Crime) Regulations, 2017.
Key Risks
- High-cash business model (cash-in/cash-out) is a recognised higher-risk virtual asset activity, attracting enhanced regulatory scrutiny from GFSC.
- GFSC enforcement actions may result in fines, public censure, or licence revocation for AML/CFT deficiencies — enforcement outcomes may not always be publicly disclosed.
- Limited public precedent for crypto-ATM-specific enforcement in Guernsey creates some regulatory uncertainty around operational expectations.
- Stringent CDD requirements may be difficult to fulfil in an unattended kiosk environment — potentially requiring remote verification or a hotline/intermediary for in-person ID checks.
- The small size of the Guernsey market combined with high licensing/regulatory burden may make operations commercially challenging.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 (as amended)
The Terrorism and Crime (Bailiwick of Guernsey) Law, 2002 (as amended): This law addresses terrorist financing and associated offences.
The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.
The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.
Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.
Standard CDD: For all customers, VASPs must:
Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).
Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.
Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.
Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.
Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:
Transactions with no obvious economic or lawful purpose.
Non-face-to-face business relationships without additional safeguards.
Specific virtual asset activities or types that inherently carry higher risk.
EDD measures may involve obtaining additional information, increased monitoring, requiring senior management approval, or independently verifying information.
Simplified Due Diligence (SDD): SDD may be applied in specific, clearly defined low-risk scenarios (e.g., certain regulated financial institutions), but VASPs must be cautious and justify its application.
Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.
Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).
Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.
No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.
Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.
Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.
Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."
The GFSC often works to prevent breaches through proactive supervision, guidance, and licensing requirements for VASPs.
Public statements of censure or fines are typically reserved for more significant, often systemic, breaches.
GFSC Enforcement Actions: https://www.gfsc.gg/news/enforcement-actions
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto ATM/kiosk operator may operate in Guernsey only if licensed as a VASP by the GFSC, subject to full AML/CFT obligations including mandatory EDD for the inherently high-risk cash-based model, with a local regulated entity required.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?