Remote VASP serving residents in Gibraltar
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Gibraltar with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full AML/CFT/CPF obligations under the Proceeds of Crime Act 2015 (POCA), including customer due diligence (CDD), transaction monitoring, risk assessments, staff training, and appointment of a compliance officer (MLRO)
- GFSC AML/CFT/CPF guidance compliance — policies and manuals must be submitted during the licensing application
- Travel Rule obligations under the Proceeds of Crime Act 2015 (Transfer of Virtual Assets) Regulations 2021 for transfers ≥ €1,000 — originator VASPs must collect and transmit originator and beneficiary information (names, wallet details)
- Registration of Money Laundering Reporting Officer (MLRO) with GFSC
- Sanctions Act 2019 compliance for counter-proliferation
Key Restrictions
- Must obtain a DLT Provider Licence from GFSC — there is no separate registration-only path for remote VASPs
- Must maintain 'mind and management' in Gibraltar: local office, local hires (including a manager), and proof of domestic operations
- Must be incorporated under the Companies Act 2014 (updated 2022) in Gibraltar — no pure remote/cross-border licensing path exists
- Authorized capital is not fixed but must demonstrate financial stability and resources for substance requirements
- The DLT provider licence requires demonstrating compliance with 10 principles covering governance, risk management, financial stability, data security, and customer protection
Key Risks
- Operating without a DLT Provider Licence while serving Gibraltar residents would constitute unlicensed activity, exposing the operator to GFSC enforcement action
- GFSC mandates physical substance in Gibraltar — a fully remote, non-resident structure is incompatible with licensing requirements
- No separate 'crypto-only' or lighter registration regime for remote VASPs; the DLT licence is the only pathway and requires incorporation and local presence
- Enforcement risk for unlicensed cross-border servicing includes potential sanctions, reputational damage, and potential liability under POCA for failure to comply with AML obligations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Services Act 2018 – establishes the 10 key principles for DLT business operations
The DLT Regulations – govern distributed ledger technology providers
Requirements include physical presence, qualified management, transparent ownership, and annual fees (e.g., £50,000 for exchanges).
GFSC supervision ensures market integrity, but stablecoin-specific rules (e.g., 1:1 reserves) are absent from sources.
Gibraltar Financial Services Commission (GFSC): The main authority, responsible for licensing, supervising, and enforcing rules on DLT firms, virtual asset service providers (VASPs), crypto exchanges, custody services, and trading platforms. It ensures compliance with international standards like FATF, including customer verification and risk management.
Financial Services Act 2019 (FSA): Oversees virtual/digital asset activities, ensuring GFSC compliance for transfers, storage, and management.
Proceeds of Crime Act 2015 – addresses AML/CFT/CPF requirements
The regime is principles-based, with 10 core principles covering governance, risk management, financial stability, data security, and customer protection; applicants must demonstrate compliance, including "mind and management" in Gibraltar (e.g., local office and employees).1 2 6
Post-licensing, firms must adhere to AML/CFT/CPF under the Proceeds of Crime Act 2015 ("POCA") and subsidiary rules, including customer due diligence (CDD), transaction monitoring, risk assessments, staff training, and appointing a compliance officer.1 2 6
No separate "crypto-only" license exists; the DLT license covers broader blockchain activities.2
The DLT Provider Licence is mandatory for any business using blockchain or DLT to store, transmit, or trade digital assets, including crypto exchanges, wallet providers, trading platforms, and custodial services; it falls under Section 8 of the FSA and ensures compliance with 9-10 DLT principles focused on transparency, risk management, AML/CFT, and governance.
No separate registration regime exists beyond this licensing; firms must be incorporated under the Companies Act 2014 (updated 2022) and comply with Proceeds of Crime Act 2015 (POCA) for AML/CFT/CPF, plus consumer protection and intellectual property rules.
Substance mandates: Local office, local hires (including a manager), and proof of domestic operations; GFSC verifies the firm is genuinely run from Gibraltar.
Approval: GFSC grants license if criteria met, including AML/CFT protocols and financial soundness; ongoing supervision follows.
Stage 1 (Initial Application): Submit form, business plan (detailing name, services, address, contact, founders/key persons), and pay non-refundable assessment fee; GFSC reviews viability against DLT principles.
Stage 2 (Full Application): Pay full fee, submit pack with policy manuals on risk management, IT/security, governance, financial crime (AML/CFT), and compliance procedures.
Stage 3 (Final Submissions): Provide conduct-of-business policies, non-financial resources info, and individual application forms for directors, shareholders, and key personnel; GFSC assesses business model, security, and substance.
Proceeds of Crime Act 2015 (POCA): Core law mandating AML/CFT/CPF obligations for DLT Firms and VASPs, including registration of the Money Laundering Reporting Officer (MLRO) with GFSC.
Financial Services Act 2019 (FSA): Regulates DLT activities (e.g., storing/transmitting value via DLT) as requiring GFSC authorization; non-DLT crypto activities fall under POCA AML regime.
GFSC issues comprehensive AML/CFT/CPF guidance; VASPs must submit policies/manuals during application.
Threshold Amount: The rule applies to transfers of virtual assets valued at €1,000 or more (equivalent to EUR 1000).
Covered VASPs: All activities matching the FATF definition of Virtual Asset Service Providers (VASPs)—including exchanges, digital wallet providers, OTC trading desks, safekeeping/administration of virtual assets, and participation in virtual asset issuance/sales—are regulated and supervised by the GFSC. This covers DLT Providers authorised since 1 January 2018 under the Financial Services (DLT Providers and VAA Providers) Regulations 2020.
Technical Implementation Requirements: Originator VASPs must collect and securely transmit (before or alongside the transaction) originator and beneficiary information—such as names and account/wallet details—for transactions over the threshold involving another VASP or relevant financial business. Beneficiary VASPs must obtain and hold this data. Virtual assets are defined in the amended POCA as digital representations of value for payment/investment, excluding fiat digital representations and certain financial instruments.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign-incorporated remote VASP cannot serve Gibraltar residents without first obtaining a GFSC DLT Provider Licence, which requires Gibraltar incorporation, physical office, local management, and full AML/CFT/CPF compliance, making a truly 'remote, no-local-entity' model impermissible.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?