← Regulations / Croatia / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Croatia

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Croatia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca – USPN) as a VASP under the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma).
  • Implement robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.
  • Perform ongoing monitoring of transactions and customer activity.
  • Report suspicious activities (STRs) to the Financial Intelligence Office (USPN).
  • Appoint an AML Officer responsible for AML/CFT compliance.
  • Establish and maintain comprehensive internal AML/CFT policies and procedures, including a risk assessment methodology covering customers, products, geographies, and delivery channels.
  • Maintain record-keeping obligations as per the AML Act (Narodne Novine No. 108/17, 39/19, 151/22).
  • From 30 December 2025, full MiCA CASP licensing will apply, adding prudential, governance, custody segregation and insurance requirements.

Key Restrictions

  • Must be a legal entity incorporated in Croatia with a registered office in Croatia to register as a VASP.
  • No specific qualified-custodian or dedicated custody license exists under current Croatian law — custody is regulated only through VASP AML registration.
  • No specific national rules on segregation of client crypto assets, insurance/bonding, or cold storage mandates currently exist (best practice only until MiCA applies).
  • From 30 December 2025, MiCA will introduce harmonised licensing for CASPs, including explicit custody and administration obligations (segregation, insurance/safeguarding, governance).

Key Risks

  • Regulatory ambiguity: current AML/CFT rules do not detail segregation, insurance, or proof-of-reserves requirements, creating legal uncertainty for custody providers.
  • MiCA transition risk: operating model must adapt to full CASP licensing by 30 Dec 2025, which will impose prudential, safeguarding, and governance requirements not currently detailed.
  • SaaS model ambiguity: unclear whether the SaaS platform provider (holding keys) or the white-label client (with customer relationship) is the VASP — both may owe AML obligations.
  • No specific consumer protection or recovery framework for lost/stolen client crypto assets under current regime.
  • Enforcement risk for failure to register as a VASP despite holding keys on behalf of Croatian residents.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Office for Anti-Money Laundering (Ured za sprječavanje pranja novca – USPN): This is the primary authority responsible for supervising the implementation of AML/CFT measures by obliged entities, including VASPs. They maintain the register of VASPs.

licensing 60% confidence

Current Regime (Pre-MiCA): Croatia operates a registration regime for VASPs, primarily for AML/CFT supervision. This means entities providing virtual asset services must register with the USPN and comply with AML obligations. It is not a full financial services license in the traditional sense, but an AML registration.

licensing 60% confidence

Future Regime (Post-MiCA): From December 30, 2025, MiCA will introduce a harmonized licensing regime across the EU. Entities providing "crypto-asset services" (as defined by MiCA) will require a license from a competent national authority (likely HANFA in Croatia, in coordination with USPN for AML aspects) in one EU member state, which will then allow them to operate across the entire EU ("passporting"). This will replace the national AML registrations for the services covered by MiCA.

licensing 60% confidence

Services related to the safekeeping and administration of virtual assets or instruments enabling control over virtual assets (e.g., private keys).

licensing 60% confidence

Generally, a legal entity incorporated in Croatia is required to apply for registration.

licensing 60% confidence

A registered office in Croatia is necessary.

aml 60% confidence

There is no specific "custody license" in Croatia dedicated solely to crypto assets.

aml 60% confidence

However, entities providing services related to virtual assets, including the safeguarding/custody of virtual assets, are considered VASPs.

aml 60% confidence

VASPs are required to register with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca) as part of their AML/CTF obligations.

aml 60% confidence

This registration requires compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma), which transposes EU AML Directives (specifically AMLD5).

aml 60% confidence

Implementing robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.

aml 60% confidence

Reporting suspicious activities to the Financial Intelligence Office.

aml 60% confidence

Establishing internal AML policies and procedures.

aml 60% confidence

Segregation of Client Assets Rules (Current):

aml 60% confidence

Explicit national rules for the segregation of client crypto assets from the firm's own assets are not specifically detailed within the current AML/CTF framework.

aml 60% confidence

There are no specific national insurance or bonding requirements explicitly mandated for crypto custody providers under the current AML/CTF framework.

aml 60% confidence

There are no explicit national mandates for cold storage of crypto assets. Operational security measures, including the use of cold storage, are generally considered best practices for secure custody but are not yet regulatory requirements.

aml 60% confidence

There is no specific definition of a "qualified custodian" for crypto assets within current Croatian national law. The concept of "qualified" custodian is more comprehensively introduced with the advent of MiCA.

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114 (Note: MiCA has a phased implementation, with most provisions for CASPs applying from 30 December 2025).

licensing 60% confidence

AML/KYC Framework: This is the most critical aspect:

licensing 60% confidence

AML/CFT Policies and Procedures: Comprehensive internal rules and procedures for customer due diligence (CDD), enhanced due diligence (EDD), ongoing monitoring, record-keeping, and reporting suspicious transactions.

licensing 60% confidence

Risk Assessment: A robust risk assessment methodology for identifying and mitigating money laundering and terrorist financing risks associated with the VASP's operations, customers, products, and geographies.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are permitted as registered VASPs under Croatia's current AML/CFT regime (no dedicated custody license), with a local entity required, but from 30 December 2025 MiCA will mandate full CASP licensing with detailed custody, segregation, and insurance obligations.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?