Custodial wallet / SaaS in Croatia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Croatia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca – USPN) as a VASP under the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma).
- Implement robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.
- Perform ongoing monitoring of transactions and customer activity.
- Report suspicious activities (STRs) to the Financial Intelligence Office (USPN).
- Appoint an AML Officer responsible for AML/CFT compliance.
- Establish and maintain comprehensive internal AML/CFT policies and procedures, including a risk assessment methodology covering customers, products, geographies, and delivery channels.
- Maintain record-keeping obligations as per the AML Act (Narodne Novine No. 108/17, 39/19, 151/22).
- From 30 December 2025, full MiCA CASP licensing will apply, adding prudential, governance, custody segregation and insurance requirements.
Key Restrictions
- Must be a legal entity incorporated in Croatia with a registered office in Croatia to register as a VASP.
- No specific qualified-custodian or dedicated custody license exists under current Croatian law — custody is regulated only through VASP AML registration.
- No specific national rules on segregation of client crypto assets, insurance/bonding, or cold storage mandates currently exist (best practice only until MiCA applies).
- From 30 December 2025, MiCA will introduce harmonised licensing for CASPs, including explicit custody and administration obligations (segregation, insurance/safeguarding, governance).
Key Risks
- Regulatory ambiguity: current AML/CFT rules do not detail segregation, insurance, or proof-of-reserves requirements, creating legal uncertainty for custody providers.
- MiCA transition risk: operating model must adapt to full CASP licensing by 30 Dec 2025, which will impose prudential, safeguarding, and governance requirements not currently detailed.
- SaaS model ambiguity: unclear whether the SaaS platform provider (holding keys) or the white-label client (with customer relationship) is the VASP — both may owe AML obligations.
- No specific consumer protection or recovery framework for lost/stolen client crypto assets under current regime.
- Enforcement risk for failure to register as a VASP despite holding keys on behalf of Croatian residents.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Office for Anti-Money Laundering (Ured za sprječavanje pranja novca – USPN): This is the primary authority responsible for supervising the implementation of AML/CFT measures by obliged entities, including VASPs. They maintain the register of VASPs.
Current Regime (Pre-MiCA): Croatia operates a registration regime for VASPs, primarily for AML/CFT supervision. This means entities providing virtual asset services must register with the USPN and comply with AML obligations. It is not a full financial services license in the traditional sense, but an AML registration.
Future Regime (Post-MiCA): From December 30, 2025, MiCA will introduce a harmonized licensing regime across the EU. Entities providing "crypto-asset services" (as defined by MiCA) will require a license from a competent national authority (likely HANFA in Croatia, in coordination with USPN for AML aspects) in one EU member state, which will then allow them to operate across the entire EU ("passporting"). This will replace the national AML registrations for the services covered by MiCA.
Services related to the safekeeping and administration of virtual assets or instruments enabling control over virtual assets (e.g., private keys).
Generally, a legal entity incorporated in Croatia is required to apply for registration.
A registered office in Croatia is necessary.
There is no specific "custody license" in Croatia dedicated solely to crypto assets.
However, entities providing services related to virtual assets, including the safeguarding/custody of virtual assets, are considered VASPs.
VASPs are required to register with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca) as part of their AML/CTF obligations.
This registration requires compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma), which transposes EU AML Directives (specifically AMLD5).
Implementing robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.
Reporting suspicious activities to the Financial Intelligence Office.
Appointing an AML Officer.
Establishing internal AML policies and procedures.
Segregation of Client Assets Rules (Current):
Explicit national rules for the segregation of client crypto assets from the firm's own assets are not specifically detailed within the current AML/CTF framework.
Insurance/Bonding Requirements (Current):
There are no specific national insurance or bonding requirements explicitly mandated for crypto custody providers under the current AML/CTF framework.
Cold Storage Mandates (Current):
There are no explicit national mandates for cold storage of crypto assets. Operational security measures, including the use of cold storage, are generally considered best practices for secure custody but are not yet regulatory requirements.
Qualified Custodian Definitions (Current):
There is no specific definition of a "qualified custodian" for crypto assets within current Croatian national law. The concept of "qualified" custodian is more comprehensively introduced with the advent of MiCA.
Custodial License Requirements (Under MiCA):
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114 (Note: MiCA has a phased implementation, with most provisions for CASPs applying from 30 December 2025).
AML/KYC Framework: This is the most critical aspect:
AML/CFT Policies and Procedures: Comprehensive internal rules and procedures for customer due diligence (CDD), enhanced due diligence (EDD), ongoing monitoring, record-keeping, and reporting suspicious transactions.
Risk Assessment: A robust risk assessment methodology for identifying and mitigating money laundering and terrorist financing risks associated with the VASP's operations, customers, products, and geographies.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers are permitted as registered VASPs under Croatia's current AML/CFT regime (no dedicated custody license), with a local entity required, but from 30 December 2025 MiCA will mandate full CASP licensing with detailed custody, segregation, and insurance obligations.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?