Remote VASP serving residents in Guernsey
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Standard CDD requirements: identify and verify customer identity (passport, national ID for individuals; incorporation docs for legal entities); identify beneficial owners (25%+ ownership threshold); understand purpose and intended nature of business relationship; collect source of funds/wealth information (gg.aml.standard-cdd-for-all-customers, gg.aml.identify-the-customer-obtain-proof, gg.aml.verify-the-customers-identity-use, gg.aml.identify-the-beneficial-owner-bo, gg.aml.understand-the-purpose-and-intended, gg.aml.collect-source-of-fundswealth-information)
- Enhanced Due Diligence (EDD) for higher-risk scenarios: PEPs, high-risk jurisdiction customers, complex/unusually large transactions, non-face-to-face relationships without additional safeguards, specific high-risk virtual asset activities (gg.aml.enhanced-due-diligence-edd-edd, gg.aml.politically-exposed-persons-peps, gg.aml.customers-from-high-risk-jurisdictions, gg.aml.complex-or-unusually-large-transactions, gg.aml.non-face-to-face-business-relationships-without-additional)
- Simplified Due Diligence (SDD) may be applied only in clearly defined low-risk scenarios, with caution (gg.aml.simplified-due-diligence-sdd-sdd)
- Ongoing monitoring of customer relationships and transactions; triggers review of CDD on significant changes (gg.aml.ongoing-monitoring-vasps-must-continuously)
- Sanctions screening against applicable sanctions lists (UN, UK, EU, Guernsey) (gg.aml.sanctions-screening-all-customers-and)
- Obligation to report knowledge, suspicion, or reasonable grounds of money laundering/terrorist financing to the FIU; no tipping-off offence (gg.aml.obligation-to-report-vasps-have, gg.aml.no-tipping-off-it-is-an)
- Internal reporting procedures with designated Money Laundering Reporting Officer (MLRO) responsible for evaluating reports and filing STRs with the FIU (gg.aml.internal-reporting-vasps-must-have)
- Risk-Based Approach (RBA) assessment of ML/TF risks associated with business, customers, products, services, and geographic areas (gg.aml.risk-based-approach-rba-vasps-must)
- Compliance framework under The Proceeds of Crime (Bailiwick of Guernsey) Law 1999, The Terrorism and Crime (Bailiwick of Guernsey) Law 2002, and Criminal Justice (Proceeds of Crime) Regulations 2017 (gg.aml.the-proceeds-of-crime-bailiwick, gg.aml.the-terrorism-and-crime-bailiwick, gg.aml.the-criminal-justice-proceeds-of)
- Adherence to the GFSC AML/CFT Handbook, which includes a dedicated section on Virtual Assets and VASPs (gg.aml.the-handbook-for-financial-services)
Key Restrictions
- Remote (non-resident) VASPs cannot serve Guernsey residents from abroad without a GFSC license — the VASP licensing regime under the Fiduciaries Law requires a local licensed entity (gg.custody.vasp-definition-the-gfsc-recognizes, gg.enforcement.unlicensed-activity-the-gfsc-has)
- The operator must incorporate or establish a local presence in the Bailiwick of Guernsey to obtain a license (local entity required) — custody and VASP regulation implies a locally regulated entity (gg.custody.application-process-prospective-licensees-must)
- Capital requirements apply based on the nature and scale of the business (gg.custody.adequate-financial-resources-capital-requirements)
- Licensed custodians must segregate client virtual assets from firm's own assets, ideally on-chain (gg.custody.core-principle-licensed-custodians-must, gg.custody.on-chain-segregation-ideally-client-assets)
- Fit and proper directors and senior management required; comprehensive governance, risk management, and cybersecurity frameworks mandated (gg.custody.experienced-and-fit-and-proper, gg.custody.comprehensive-risk-management-policies-and, gg.custody.sound-governance-arrangements)
Key Risks
- Enforcement risk for unlicensed remote operators: the GFSC has a licensing regime for VASPs and may pursue enforcement for unlicensed activity, though public records do not detail large fines specifically for this in recent years (gg.enforcement.unlicensed-activity-the-gfsc-has)
- Regulatory ambiguity about whether the GFSC would actively pursue foreign-incorporated, non-resident VASPs targeting Guernsey residents without any local presence — enforcement precedents are limited (gg.enforcement.broader-anti-money-laundering-aml-and)
- If operating unlicensed, operator would lack the legal framework to hold client assets in compliance with segregation rules, exposing the business to significant liability (gg.custody.core-principle-licensed-custodians-must)
- The cost and difficulty of full GFSC licensing (capital requirements, fit-and-proper directors, AML/CFT frameworks, cybersecurity) may be commercially disproportionate to serving a small jurisdiction like Guernsey
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Proceeds of Crime (Bailiwick of Guernsey) Law, 1999 (as amended)
The Terrorism and Crime (Bailiwick of Guernsey) Law, 2002 (as amended): This law addresses terrorist financing and associated offences.
The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.
The Handbook for Financial Services Businesses on Countering Financial Crime and Terrorist Financing (the AML/CFT Handbook): Issued by the GFSC, this handbook provides detailed guidance and specific requirements for regulated entities, including a dedicated section on Virtual Assets and VASPs (typically Section 11). This is where the operational details of the Travel Rule are explained.
Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.
Standard CDD: For all customers, VASPs must:
Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).
Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.
Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.
Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.
Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:
Non-face-to-face business relationships without additional safeguards.
Simplified Due Diligence (SDD): SDD may be applied in specific, clearly defined low-risk scenarios (e.g., certain regulated financial institutions), but VASPs must be cautious and justify its application.
Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.
Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).
Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.
No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.
Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.
VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.
Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:
Adequate financial resources (capital requirements vary based on the nature and scale of the business).
Experienced and fit and proper directors and senior management.
Comprehensive risk management policies and procedures, including cybersecurity.
Sound governance arrangements.
Core Principle: Licensed custodians must ensure that client virtual assets are clearly separated and identifiable from the firm's own assets. This is crucial for investor protection, particularly in the event of insolvency of the custodian.
On-chain segregation: Ideally, client assets are held in distinct, segregated wallet addresses or accounts on the blockchain that are clearly identifiable as belonging to clients, not the firm.
Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.
Broader Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) deficiencies: These actions are usually against regulated financial services businesses (e.g., fiduciaries, banks, investment firms) for systemic failures in their AML/CFT frameworks, rather than specifically for engaging in or facilitating cryptocurrency transactions improperly. While these failures could indirectly impact virtual asset activities if the entities were involved, the enforcement isn't explicitly "crypto-focused."
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Guernsey residents must obtain a GFSC license under the Fiduciaries Law, establish a local entity, meet capital and governance requirements, and comply with the full AML/CFT framework (CDD, EDD, sanctions screening, STR reporting); operating without a license carries enforcement risk, though public enforcement precedents for unlicensed VASP activity are limited.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?