Centralized exchange in Guernsey
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must register/license with the GFSC and are captured under the Fiduciaries Law (The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000)
- Risk-Based Approach (RBA): VASPs must assess ML/TF risks associated with their business, customers, products, services, and geographic areas
- Standard CDD required for all customers: identify and verify customer identity (passport/national ID for individuals; incorporation docs for legal entities)
- Identify and verify Beneficial Owner (BO) at 25% ownership threshold or control
- Collect purpose of business relationship and source of funds/wealth information
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships
- Simplified Due Diligence (SDD) may be applied only in clearly defined low-risk scenarios
- Ongoing monitoring of customer relationships and transactions
- Sanctions screening against UN, UK, EU, and Guernsey sanctions lists
- Mandatory obligation to report knowledge/suspicion of ML/TF to the FIU (STR filing via designated MLRO)
- No tipping-off on STR filings
- Internal reporting procedures with designated Money Laundering Reporting Officer (MLRO) and Deputy MLRO
- Comprehensive AML/CFT frameworks required as part of licensing under the GFSC Handbook on Countering Financial Crime and Terrorist Financing
- Travel Rule: The GFSC AML/CFT Handbook includes a dedicated section on Virtual Assets and VASPs — virtual asset transfers are expected to comply with FATF Recommendation 16 (travel rule) requirements on originator/beneficiary information
Key Restrictions
- Must be licensed as a VASP under the Fiduciaries Law (The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000)
- Must be incorporated locally or have a local licensed presence
- Client virtual assets must be clearly separated and identifiable from the firm's own assets (on-chain segregation or robust internal accounting)
- Clients must retain beneficial ownership of assets held in custody
- Must demonstrate sound governance, adequate financial resources/capital, fit and proper directors/senior management, and operational resilience plans
- Must demonstrate robust cybersecurity, cryptographic key management (multi-signature, geographically distributed backups), and security measures
- Majority of client assets expected to be held in cold storage (industry best practice expectation from GFSC)
- Insurance not mandatory but strongly expected as part of risk management framework; capital requirements serve as the primary financial backstop
Key Risks
- Enforcement exposure for unlicensed activity — the GFSC has a VASP licensing regime and may take action against operators without a license
- Regulatory ambiguity in specific areas (e.g., precise travel-rule technical implementation expectations)
- Capital requirements may be high depending on nature and scale of business
- Confidential enforcement outcomes create precedent uncertainty — public enforcement actions are typically reserved for significant/systemic breaches
- GFSC expects segregation on-chain ideally; technical commingling requires impeccable internal records which creates operational risk in insolvency scenarios
- Cyber theft, key loss, and insider fraud are key operational risks; GFSC expects thorough risk assessment and robust security frameworks
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.
The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law
Guidance on Virtual Assets & VASPs (GFSC): The GFSC has issued specific guidance for firms dealing with virtual assets, emphasizing their obligations under the Fiduciaries Law and AML/CFT framework. These are usually found in policy statements and handbooks on the GFSC website under "Laws & Regulations" or "Policy & Guidance."
Core Principle: Licensed custodians must ensure that client virtual assets are clearly separated and identifiable from the firm's own assets. This is crucial for investor protection, particularly in the event of insolvency of the custodian.
On-chain segregation: Ideally, client assets are held in distinct, segregated wallet addresses or accounts on the blockchain that are clearly identifiable as belonging to clients, not the firm.
Robust internal accounting: Where technical commingling might occur for operational reasons (e.g., using shared liquidity pools in some complex scenarios), the firm must maintain impeccable internal records and accounting that clearly delineate each client's beneficial ownership and entitlements. However, direct on-chain segregation is generally preferred and expected for primary custody.
Legal Ownership: The legal framework must ensure that clients retain beneficial ownership of their assets.
Regulatory Reference: This requirement stems from the general principles of the Fiduciaries Law and the GFSC's broader expectations for licensed entities, which mandate the safeguarding of client money and assets. While there might not be a single "crypto segregation rule" distinct from traditional assets, the principles apply directly.
Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:
A robust business plan.
Sound governance arrangements.
Adequate financial resources (capital requirements vary based on the nature and scale of the business).
Experienced and fit and proper directors and senior management.
Comprehensive risk management policies and procedures, including cybersecurity.
Robust Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) frameworks.
Operational resilience plans.
Capital Requirements: Instead of mandatory insurance, the GFSC imposes capital requirements designed to ensure that firms have sufficient financial resources to withstand operational shocks.
Security Principle: The GFSC mandates that licensed custodians implement robust security measures to protect client assets from theft, loss, or unauthorized access. This includes comprehensive cybersecurity frameworks, strong cryptographic key management, multi-factor authentication, and resilient operational procedures.
Key Management: Firms must demonstrate highly secure key generation, storage, and recovery processes, often involving multi-signature schemes and geographically distributed backups.
Best Practice Expectation: While not explicitly mandated as "cold storage," GFSC's expectations regarding the safeguarding of client assets effectively necessitate the use of industry best practices. For digital assets, this means that a significant portion (and ideally the vast majority) of assets under custody should be held in "cold" (offline) storage environments to minimize exposure to online threats.
Best Practice: Carrying adequate insurance coverage (such as crime insurance, cyber insurance, or professional indemnity insurance) is highly recommended and would be viewed favorably by the GFSC as part of demonstrating a sound and responsible business. It's often a commercial necessity for attracting clients.
Risk Management Expectation: However, insurance and bonding are considered critical components of a robust risk management framework. The GFSC expects licensed custodians to assess their operational risks thoroughly, including those unique to digital assets (e.g., cyber theft, key loss, insider fraud), and to implement appropriate mitigation strategies.
GFSC Handbook on Countering Financial Crime and Terrorist Financing: https://www.gfsc.gg/commission/laws-regulations/amlcft-handbook (This handbook includes specific sections on virtual assets and related risks, indirectly supporting the need for robust asset management and segregation for AML/CFT purposes).
The Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 (as amended)
The Terrorism and Crime (Bailiwick of Guernsey) Law, 2002 (as amended): This law addresses terrorist financing and associated offences.
The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.
The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.
Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.
Standard CDD: For all customers, VASPs must:
Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).
Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.
Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.
Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.
Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:
Transactions with no obvious economic or lawful purpose.
Non-face-to-face business relationships without additional safeguards.
Specific virtual asset activities or types that inherently carry higher risk.
EDD measures may involve obtaining additional information, increased monitoring, requiring senior management approval, or independently verifying information.
Simplified Due Diligence (SDD): SDD may be applied in specific, clearly defined low-risk scenarios (e.g., certain regulated financial institutions), but VASPs must be cautious and justify its application.
Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.
Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).
Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.
No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.
Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.
Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.
Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."
Governance and operational failings: Breaches of regulatory principles, corporate governance, or data protection rules.
Enforcement actions might involve confidential settlements or outcomes that are not fully disclosed publicly, especially for smaller breaches.
Public statements of censure or fines are typically reserved for more significant, often systemic, breaches.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A centralized exchange (custodial VASP) is permitted in Guernsey but requires a full GFSC license under the Fiduciaries Law, a locally incorporated entity, stringent asset segregation (on-chain ideally), robust AML/CFT compliance including travel-rule obligations, and satisfaction of capital/resourcing requirements.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?