← Regulations / Guernsey / Operating Models / On-shore VASP

On-shore VASP in Guernsey

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Must comply with The Criminal Justice (Proceeds of Crime) Regulations 2017 for CDD, record-keeping, and internal controls (gg.aml.the-criminal-justice-proceeds-of)
  • Must adopt a Risk-Based Approach (RBA), assessing ML/TF risks across business, customers, products, and geography (gg.aml.risk-based-approach-rba-vasps-must)
  • Standard CDD: identify and verify customer identity (passport/ID for individuals; incorporation docs for entities), identify beneficial owners (25% threshold), understand purpose of business relationship, collect source of funds/wealth information (gg.aml.standard-cdd-for-all-customers, gg.aml.identify-the-customer-obtain-proof, gg.aml.verify-the-customers-identity-use, gg.aml.identify-the-beneficial-owner-bo, gg.aml.understand-the-purpose-and-intended, gg.aml.collect-source-of-fundswealth-information)
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and specific high-risk virtual asset activities (gg.aml.enhanced-due-diligence-edd-edd, gg.aml.politically-exposed-persons-peps, gg.aml.customers-from-high-risk-jurisdictions, gg.aml.complex-or-unusually-large-transactions, gg.aml.transactions-with-no-obvious-economic, gg.aml.non-face-to-face-business-relationships-without-additional, gg.aml.specific-virtual-asset-activities-or)
  • Ongoing monitoring of customer relationships and transactions, with trigger-based CDD review on significant changes (gg.aml.ongoing-monitoring-vasps-must-continuously)
  • Sanctions screening against UN, UK, EU, and Guernsey sanctions lists for all customers and transactions (gg.aml.sanctions-screening-all-customers-and)
  • Obligation to report suspicions of ML/TF to the Guernsey FIU; mandatory internal reporting via a designated MLRO (gg.aml.obligation-to-report-vasps-have, gg.aml.internal-reporting-vasps-must-have)
  • No tipping-off offence applies (gg.aml.no-tipping-off-it-is-an)
  • Must comply with The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook), which includes a dedicated section on Virtual Assets and VASPs (gg.aml.the-handbook-for-financial-services)

Key Restrictions

  • Must hold a license under The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000 (gg.custody.the-regulation-of-fiduciaries-administration)
  • Client virtual assets must be clearly separated and identifiable from the firm's own assets; on-chain segregation is the ideal, with robust internal accounting as a minimum (gg.custody.core-principle-licensed-custodians-must, gg.custody.on-chain-segregation-ideally-client-assets)
  • Must have experienced and fit-and-proper directors and senior management; comprehensive risk management including cybersecurity; operational resilience plans (gg.custody.experienced-and-fit-and-proper, gg.custody.comprehensive-risk-management-policies-and, gg.custody.operational-resilience-plans)
  • Capital requirements apply based on nature and scale of business; no mandatory insurance but insurance is a best-practice expectation for risk management (gg.custody.adequate-financial-resources-capital-requirements, gg.custody.capital-requirements-instead-of-mandatory)
  • Robust cryptographic key management, multi-signature schemes, geographically distributed backups, and effective cold-storage practices expected (gg.custody.security-principle-the-gfsc-mandates, gg.custody.best-practice-expectation-while-not, gg.custody.key-management-firms-must-demonstrate)

Key Risks

  • GFSC enforcement actions for AML/CFT deficiencies, governance failures, and operational failings carry reputational and financial exposure (gg.enforcement.broader-anti-money-laundering-aml-and, gg.enforcement.governance-and-operational-failings-breaches)
  • Unlicensed VASP activity is enforceable; GFSC may take action against operators without the required license (gg.enforcement.unlicensed-activity-the-gfsc-has)
  • Enforcement outcomes may be confidential settlements, creating uncertainty about precedents (gg.enforcement.enforcement-actions-might-involve-confidential)
  • The evolving GFSC guidance on virtual assets means the regulatory framework may tighten, requiring ongoing compliance adaptation

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 60% confidence

The Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 (as amended)

aml 60% confidence

The Terrorism and Crime (Bailiwick of Guernsey) Law, 2002 (as amended): This law addresses terrorist financing and associated offences.

aml 60% confidence

The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.

aml 60% confidence

The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.

aml 60% confidence

Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.

aml 60% confidence

Standard CDD: For all customers, VASPs must:

aml 60% confidence

Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).

aml 60% confidence

Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.

aml 60% confidence

Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).

aml 60% confidence

Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.

aml 60% confidence

Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.

aml 60% confidence

Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:

aml 60% confidence

Politically Exposed Persons (PEPs).

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions.

aml 60% confidence

Transactions with no obvious economic or lawful purpose.

aml 60% confidence

Non-face-to-face business relationships without additional safeguards.

aml 60% confidence

Specific virtual asset activities or types that inherently carry higher risk.

aml 60% confidence

Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.

aml 60% confidence

Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).

aml 60% confidence

Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.

aml 60% confidence

No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.

aml 60% confidence

Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.

custody 60% confidence

The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law

custody 60% confidence

Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:

custody 60% confidence

Adequate financial resources (capital requirements vary based on the nature and scale of the business).

custody 60% confidence

Experienced and fit and proper directors and senior management.

custody 60% confidence

Comprehensive risk management policies and procedures, including cybersecurity.

custody 60% confidence

Core Principle: Licensed custodians must ensure that client virtual assets are clearly separated and identifiable from the firm's own assets. This is crucial for investor protection, particularly in the event of insolvency of the custodian.

custody 60% confidence

On-chain segregation: Ideally, client assets are held in distinct, segregated wallet addresses or accounts on the blockchain that are clearly identifiable as belonging to clients, not the firm.

Evidence fact gg.custody.security-principle-the-gfsc-must not found (may have been renamed).

custody 60% confidence

Best Practice Expectation: While not explicitly mandated as "cold storage," GFSC's expectations regarding the safeguarding of client assets effectively necessitate the use of industry best practices. For digital assets, this means that a significant portion (and ideally the vast majority) of assets under custody should be held in "cold" (offline) storage environments to minimize exposure to online threats.

custody 60% confidence

Key Management: Firms must demonstrate highly secure key generation, storage, and recovery processes, often involving multi-signature schemes and geographically distributed backups.

custody 60% confidence

Capital Requirements: Instead of mandatory insurance, the GFSC imposes capital requirements designed to ensure that firms have sufficient financial resources to withstand operational shocks.

enforcement 60% confidence

Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."

enforcement 60% confidence

Governance and operational failings: Breaches of regulatory principles, corporate governance, or data protection rules.

enforcement 60% confidence

Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.

enforcement 60% confidence

Enforcement actions might involve confidential settlements or outcomes that are not fully disclosed publicly, especially for smaller breaches.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — On-shore VASPs are permitted in Guernsey but must obtain a license under the Fiduciaries Law (2000), satisfy fit-and-proper management requirements, meet capital requirements, implement full AML/CFT obligations under the 2017 Regulations and GFSC Handbook, segregate client assets, and undergo a comprehensive GFSC application process; the framework is well-defined but light on published licensing timelines.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?