← Regulations / Guernsey / Operating Models / Crypto debit card

Crypto-funded debit card in Guernsey

A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.

Conditional AI-Generated · Unreviewed

Crypto debit card is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs must register with the GFSC and comply with the Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended) for CDD, record-keeping, and internal controls
  • Standard CDD required on all cardholders: identify customer (passport/national ID), verify identity via reliable independent sources, identify beneficial owner (25%+ threshold), understand purpose of business relationship, and collect source of funds/wealth information
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face business relationships without safeguards, and specific virtual-asset activities carrying higher risk
  • Ongoing monitoring of all customer transactions and relationships; significant behavioural changes trigger CDD review
  • Sanctions screening against UN, UK, EU, and Guernsey sanctions lists for all customers and transactions
  • Obligation to report suspicious activity to the FIU; no tipping-off offences apply; must appoint an MLRO with internal reporting procedures
  • Virtual-asset-related services are generally considered higher risk, requiring enhanced scrutiny under the GFSC AML/CFT Handbook

Key Restrictions

  • VASP licensing required — the GFSC's licensing regime for Virtual Asset Service Providers must be obtained before offering any crypto-to-fiat conversion or custody services
  • A local entity (Guernsey-incorporated) is required as the GFSC regulates licensed entities with local presence
  • Crypto-to-fiat conversion (the off-ramp) is a regulated VASP/financial services activity requiring GFSC authorisation
  • Partner-bank or BIN-sponsor arrangements with a GFSC-regulated or equivalent regulated institution are implicitly required — the card-issuance/payment side likely requires a licensed payment/e-money institution or a partnership with one under GFSC supervision
  • Non-face-to-face business relationships (card issuance without in-person meeting) require additional safeguards and likely trigger EDD

Key Risks

  • No specific e-money or payment-institution licence regime is detailed in the provided facts — the card-issuance/payment element may require a separate licence (e.g. as a payment service provider) that is not explicitly covered here
  • GFSC enforcement actions for systemic AML/CFT deficiencies are a material risk; fines may be imposed for governance/operational failings or unlicensed activity
  • The regulatory treatment of the crypto-to-fiat conversion as a VASP activity vs. as a payment/e-money activity has some ambiguity — whether a single VASP licence covers the full debit card value chain is not fully confirmed by the facts provided
  • Confidential settlements are common for smaller breaches, meaning compliance gaps may still attract enforcement but details may not be publicly known

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 60% confidence

The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.

aml 60% confidence

The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.

aml 60% confidence

Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.

aml 60% confidence

Standard CDD: For all customers, VASPs must:

aml 60% confidence

Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).

aml 60% confidence

Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.

aml 60% confidence

Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).

aml 60% confidence

Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.

aml 60% confidence

Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.

aml 60% confidence

Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:

aml 60% confidence

Politically Exposed Persons (PEPs).

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions.

aml 60% confidence

Transactions with no obvious economic or lawful purpose.

aml 60% confidence

Non-face-to-face business relationships without additional safeguards.

aml 60% confidence

Specific virtual asset activities or types that inherently carry higher risk.

aml 60% confidence

EDD measures may involve obtaining additional information, increased monitoring, requiring senior management approval, or independently verifying information.

aml 60% confidence

Simplified Due Diligence (SDD): SDD may be applied in specific, clearly defined low-risk scenarios (e.g., certain regulated financial institutions), but VASPs must be cautious and justify its application.

aml 60% confidence

Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.

aml 60% confidence

Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).

aml 60% confidence

Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.

aml 60% confidence

No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.

aml 60% confidence

Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.

enforcement 60% confidence

Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."

enforcement 60% confidence

Governance and operational failings: Breaches of regulatory principles, corporate governance, or data protection rules.

enforcement 60% confidence

Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a crypto-funded debit card is permissible in Guernsey but requires a GFSC VASP licence for the crypto-to-fiat conversion, a local entity, and full AML/CFT compliance; the specific e-money / payment-institution licence for the card-issuance side is not clearly addressed in available facts, creating residual regulatory ambiguity.

Questions this verdict aims to answer

  • What e-money / payment-institution license is required?
  • How is the crypto-to-fiat conversion regulated?
  • What KYC and AML obligations apply to cardholders?
  • What partner-bank or BIN-sponsor arrangements are required?