← Regulations / Guernsey / Operating Models / CEX

Centralized exchange in Guernsey

Order-book exchange that takes custody of user assets and matches trades between users.

Conditional AI-Generated · Unreviewed

CEX is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs must register/license with the GFSC and are captured under the Fiduciaries Law (The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000)
  • Risk-Based Approach (RBA): VASPs must assess ML/TF risks associated with their business, customers, products, services, and geographic areas
  • Standard CDD required for all customers: identify and verify customer identity (passport/national ID for individuals; incorporation docs for legal entities)
  • Identify and verify Beneficial Owner (BO) at 25% ownership threshold or control
  • Collect purpose of business relationship and source of funds/wealth information
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships
  • Simplified Due Diligence (SDD) may be applied only in clearly defined low-risk scenarios
  • Ongoing monitoring of customer relationships and transactions
  • Sanctions screening against UN, UK, EU, and Guernsey sanctions lists
  • Mandatory obligation to report knowledge/suspicion of ML/TF to the FIU (STR filing via designated MLRO)
  • No tipping-off on STR filings
  • Internal reporting procedures with designated Money Laundering Reporting Officer (MLRO) and Deputy MLRO
  • Comprehensive AML/CFT frameworks required as part of licensing under the GFSC Handbook on Countering Financial Crime and Terrorist Financing
  • Travel Rule: The GFSC AML/CFT Handbook includes a dedicated section on Virtual Assets and VASPs — virtual asset transfers are expected to comply with FATF Recommendation 16 (travel rule) requirements on originator/beneficiary information

Key Restrictions

  • Must be licensed as a VASP under the Fiduciaries Law (The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000)
  • Must be incorporated locally or have a local licensed presence
  • Client virtual assets must be clearly separated and identifiable from the firm's own assets (on-chain segregation or robust internal accounting)
  • Clients must retain beneficial ownership of assets held in custody
  • Must demonstrate sound governance, adequate financial resources/capital, fit and proper directors/senior management, and operational resilience plans
  • Must demonstrate robust cybersecurity, cryptographic key management (multi-signature, geographically distributed backups), and security measures
  • Majority of client assets expected to be held in cold storage (industry best practice expectation from GFSC)
  • Insurance not mandatory but strongly expected as part of risk management framework; capital requirements serve as the primary financial backstop

Key Risks

  • Enforcement exposure for unlicensed activity — the GFSC has a VASP licensing regime and may take action against operators without a license
  • Regulatory ambiguity in specific areas (e.g., precise travel-rule technical implementation expectations)
  • Capital requirements may be high depending on nature and scale of business
  • Confidential enforcement outcomes create precedent uncertainty — public enforcement actions are typically reserved for significant/systemic breaches
  • GFSC expects segregation on-chain ideally; technical commingling requires impeccable internal records which creates operational risk in insolvency scenarios
  • Cyber theft, key loss, and insider fraud are key operational risks; GFSC expects thorough risk assessment and robust security frameworks

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.

custody 60% confidence

The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law

custody 60% confidence

Guidance on Virtual Assets & VASPs (GFSC): The GFSC has issued specific guidance for firms dealing with virtual assets, emphasizing their obligations under the Fiduciaries Law and AML/CFT framework. These are usually found in policy statements and handbooks on the GFSC website under "Laws & Regulations" or "Policy & Guidance."

custody 60% confidence

Core Principle: Licensed custodians must ensure that client virtual assets are clearly separated and identifiable from the firm's own assets. This is crucial for investor protection, particularly in the event of insolvency of the custodian.

custody 60% confidence

On-chain segregation: Ideally, client assets are held in distinct, segregated wallet addresses or accounts on the blockchain that are clearly identifiable as belonging to clients, not the firm.

custody 60% confidence

Robust internal accounting: Where technical commingling might occur for operational reasons (e.g., using shared liquidity pools in some complex scenarios), the firm must maintain impeccable internal records and accounting that clearly delineate each client's beneficial ownership and entitlements. However, direct on-chain segregation is generally preferred and expected for primary custody.

custody 60% confidence

Legal Ownership: The legal framework must ensure that clients retain beneficial ownership of their assets.

custody 60% confidence

Regulatory Reference: This requirement stems from the general principles of the Fiduciaries Law and the GFSC's broader expectations for licensed entities, which mandate the safeguarding of client money and assets. While there might not be a single "crypto segregation rule" distinct from traditional assets, the principles apply directly.

custody 60% confidence

Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:

custody 60% confidence

Adequate financial resources (capital requirements vary based on the nature and scale of the business).

custody 60% confidence

Experienced and fit and proper directors and senior management.

custody 60% confidence

Comprehensive risk management policies and procedures, including cybersecurity.

custody 60% confidence

Robust Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) frameworks.

custody 60% confidence

Capital Requirements: Instead of mandatory insurance, the GFSC imposes capital requirements designed to ensure that firms have sufficient financial resources to withstand operational shocks.

custody 60% confidence

Security Principle: The GFSC mandates that licensed custodians implement robust security measures to protect client assets from theft, loss, or unauthorized access. This includes comprehensive cybersecurity frameworks, strong cryptographic key management, multi-factor authentication, and resilient operational procedures.

custody 60% confidence

Key Management: Firms must demonstrate highly secure key generation, storage, and recovery processes, often involving multi-signature schemes and geographically distributed backups.

custody 60% confidence

Best Practice Expectation: While not explicitly mandated as "cold storage," GFSC's expectations regarding the safeguarding of client assets effectively necessitate the use of industry best practices. For digital assets, this means that a significant portion (and ideally the vast majority) of assets under custody should be held in "cold" (offline) storage environments to minimize exposure to online threats.

custody 60% confidence

Best Practice: Carrying adequate insurance coverage (such as crime insurance, cyber insurance, or professional indemnity insurance) is highly recommended and would be viewed favorably by the GFSC as part of demonstrating a sound and responsible business. It's often a commercial necessity for attracting clients.

custody 60% confidence

Risk Management Expectation: However, insurance and bonding are considered critical components of a robust risk management framework. The GFSC expects licensed custodians to assess their operational risks thoroughly, including those unique to digital assets (e.g., cyber theft, key loss, insider fraud), and to implement appropriate mitigation strategies.

custody 60% confidence

GFSC Handbook on Countering Financial Crime and Terrorist Financing: https://www.gfsc.gg/commission/laws-regulations/amlcft-handbook (This handbook includes specific sections on virtual assets and related risks, indirectly supporting the need for robust asset management and segregation for AML/CFT purposes).

aml 60% confidence

The Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 (as amended)

aml 60% confidence

The Terrorism and Crime (Bailiwick of Guernsey) Law, 2002 (as amended): This law addresses terrorist financing and associated offences.

aml 60% confidence

The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.

aml 60% confidence

The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.

aml 60% confidence

Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.

aml 60% confidence

Standard CDD: For all customers, VASPs must:

aml 60% confidence

Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).

aml 60% confidence

Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.

aml 60% confidence

Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).

aml 60% confidence

Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.

aml 60% confidence

Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.

aml 60% confidence

Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:

aml 60% confidence

Politically Exposed Persons (PEPs).

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions.

aml 60% confidence

Transactions with no obvious economic or lawful purpose.

aml 60% confidence

Non-face-to-face business relationships without additional safeguards.

aml 60% confidence

Specific virtual asset activities or types that inherently carry higher risk.

aml 60% confidence

EDD measures may involve obtaining additional information, increased monitoring, requiring senior management approval, or independently verifying information.

aml 60% confidence

Simplified Due Diligence (SDD): SDD may be applied in specific, clearly defined low-risk scenarios (e.g., certain regulated financial institutions), but VASPs must be cautious and justify its application.

aml 60% confidence

Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.

aml 60% confidence

Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).

aml 60% confidence

Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.

aml 60% confidence

No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.

aml 60% confidence

Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.

enforcement 60% confidence

Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.

enforcement 60% confidence

Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."

enforcement 60% confidence

Governance and operational failings: Breaches of regulatory principles, corporate governance, or data protection rules.

enforcement 60% confidence

Enforcement actions might involve confidential settlements or outcomes that are not fully disclosed publicly, especially for smaller breaches.

enforcement 60% confidence

Public statements of censure or fines are typically reserved for more significant, often systemic, breaches.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A centralized exchange (custodial VASP) is permitted in Guernsey but requires a full GFSC license under the Fiduciaries Law, a locally incorporated entity, stringent asset segregation (on-chain ideally), robust AML/CFT compliance including travel-rule obligations, and satisfaction of capital/resourcing requirements.

Questions this verdict aims to answer

  • What exchange / VASP license applies?
  • What custody segregation rules apply to user assets?
  • What market-conduct and listing rules apply?
  • What travel-rule obligations apply on withdrawals?