Custodial wallet / SaaS in Gibraltar
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Gibraltar with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- DLT Provider Licence mandatory under Section 8 of the Financial Services Act 2019 (FSA) — covers custody, wallet, and SaaS operations using DLT to store or transmit digital assets
- Proceeds of Crime Act 2015 (POCA) applies — must implement CDD, transaction monitoring, risk assessments, staff training, and appoint a compliance officer
- Registration of Money Laundering Reporting Officer (MLRO) with GFSC required
- FATF Travel Rule implemented via Proceeds of Crime Act 2015 (Transfer of Virtual Assets) Regulations 2021 — requires information sharing on virtual asset transfers
- Sanctions Act 2019 compliance required (counter-proliferation screening)
- AML/CFT/CPF policies and manuals must be submitted as part of the DLT Provider Licence application (Stage 2 submission pack)
- GFSC issues comprehensive AML/CFT/CPF guidance; VASPs must adhere to GFSC oversight
- RFBR Regs 2021: VASPs not otherwise regulated must register for AML/CFT supervision
Key Restrictions
- Must obtain a DLT Provider Licence from GFSC — no separate 'crypto-only' license exists; the DLT license covers all blockchain/DLT activities
- Must have physical presence in Gibraltar (local office, local hires including a manager, proof of domestic operations — 'mind and management' in Gibraltar)
- Must be incorporated under the Companies Act 2014 (updated 2022)
- Authorized capital is not fixed but firm must demonstrate financial stability via business plan showing sufficient resources
- Substance mandates: real office, local employees, manager domiciled in Gibraltar — GFSC verifies genuine local operations
- Three-stage licensing process: Initial Application (viability assessment), Full Application (policy manuals, risk/IT/governance/AML), Final Submissions (conduct-of-business policies, individual fit and proper checks for directors/shareholders/key personnel)
- Annual fee (e.g., £50,000 benchmark for exchanges — applicable scale for DLT licensees)
- If features of the hosted wallet/token resemble security-like investments, may qualify under the Specialised Investment Business Act (SIBA) framework, adding parallel requirements
Key Risks
- High licensing burden with multi-stage application process and ongoing GFSC supervision — significant upfront cost and timeline risk
- Substance requirements (local office, local hires, manager) create operational complexity and cost for remote/foreign operators
- No specific segregation, insurance, or proof-of-reserves rules identified in the provided facts — regulatory gap creates uncertainty for custodial wallet models
- GFSC may assess token features as security-like under SIBA, adding parallel regulatory burden
- White-label SaaS model creates ambiguity in AML allocation: unclear whether obligations sit with the SaaS provider (custodian) or the white-label client, and whether both need separate DLT licences
- Stablecoin-specific rules (e.g., 1:1 reserve requirements) absent from sources — potential future regulatory shift
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Services Act 2018 – establishes the 10 key principles for DLT business operations
The DLT Regulations – govern distributed ledger technology providers
GFSC supervision ensures market integrity, but stablecoin-specific rules (e.g., 1:1 reserves) are absent from sources.
Gibraltar Financial Services Commission (GFSC): The main authority, responsible for licensing, supervising, and enforcing rules on DLT firms, virtual asset service providers (VASPs), crypto exchanges, custody services, and trading platforms. It ensures compliance with international standards like FATF, including customer verification and risk management.
Financial Services Act 2019 (FSA): Oversees virtual/digital asset activities, ensuring GFSC compliance for transfers, storage, and management.
Proceeds of Crime Act 2015 – addresses AML/CFT/CPF requirements
DLT Framework (introduced 2018): Pioneering principles-based regulations for DLT operators, covering licensing, governance, and consumer protection; developed from the 2014 Cryptocurrency Working Group.
The regime is principles-based, with 10 core principles covering governance, risk management, financial stability, data security, and customer protection; applicants must demonstrate compliance, including "mind and management" in Gibraltar (e.g., local office and employees).1 2 6
Post-licensing, firms must adhere to AML/CFT/CPF under the Proceeds of Crime Act 2015 ("POCA") and subsidiary rules, including customer due diligence (CDD), transaction monitoring, risk assessments, staff training, and appointing a compliance officer.1 2 6
No separate "crypto-only" license exists; the DLT license covers broader blockchain activities.2
The DLT Provider Licence is mandatory for any business using blockchain or DLT to store, transmit, or trade digital assets, including crypto exchanges, wallet providers, trading platforms, and custodial services; it falls under Section 8 of the FSA and ensures compliance with 9-10 DLT principles focused on transparency, risk management, AML/CFT, and governance.
No separate registration regime exists beyond this licensing; firms must be incorporated under the Companies Act 2014 (updated 2022) and comply with Proceeds of Crime Act 2015 (POCA) for AML/CFT/CPF, plus consumer protection and intellectual property rules.
Activities like ICOs and non-security token sales may require additional Virtual Asset Service Provider (VASP) registration if applicable.
Authorized capital varies by project specifics and is not fixed; applicants must demonstrate financial stability, often via business plans showing sufficient resources for operations, risk management, and substance in Gibraltar (e.g., real office, local employees, manager).
Substance mandates: Local office, local hires (including a manager), and proof of domestic operations; GFSC verifies the firm is genuinely run from Gibraltar.
Stage 1 (Initial Application): Submit form, business plan (detailing name, services, address, contact, founders/key persons), and pay non-refundable assessment fee; GFSC reviews viability against DLT principles.
Stage 2 (Full Application): Pay full fee, submit pack with policy manuals on risk management, IT/security, governance, financial crime (AML/CFT), and compliance procedures.
Stage 3 (Final Submissions): Provide conduct-of-business policies, non-financial resources info, and individual application forms for directors, shareholders, and key personnel; GFSC assesses business model, security, and substance.
Approval: GFSC grants license if criteria met, including AML/CFT protocols and financial soundness; ongoing supervision follows.
Requirements include physical presence, qualified management, transparent ownership, and annual fees (e.g., £50,000 for exchanges).
They may qualify as investments under the Specialised Investment Business Act (SIBA) framework if facts indicate security-like features (e.g., offered to the public or tied to specific investors).
Proceeds of Crime Act 2015 (POCA): Core law mandating AML/CFT/CPF obligations for DLT Firms and VASPs, including registration of the Money Laundering Reporting Officer (MLRO) with GFSC.
Financial Services Act 2019 (FSA): Regulates DLT activities (e.g., storing/transmitting value via DLT) as requiring GFSC authorization; non-DLT crypto activities fall under POCA AML regime.
RFBR Regs 2021: Requires registration for AML/CFT supervision of VASPs not otherwise regulated.
Sanctions Act 2019: Expected compliance for counter-proliferation.
GFSC issues comprehensive AML/CFT/CPF guidance; VASPs must submit policies/manuals during application.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator must obtain a GFSC DLT Provider Licence (multi-stage, high-burden), maintain physical substance in Gibraltar, comply with POCA AML/CFT obligations including Travel Rule and MLRO appointment, but the provided facts lack specific segregation/insurance/proof-of-reserves rules, creating some regulatory ambiguity for the custody model.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?