← Regulations / Croatia / Operating Models / Remote VASP

Remote VASP serving residents in Croatia

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Croatia with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Registration with the Ministry of Finance – Financial Intelligence Office (USPN) as a VASP under the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma)
  • Implement robust KYC/CDD procedures including identity verification and beneficial ownership identification
  • Appoint an AML Officer
  • Establish and maintain AML/CFT internal policies, procedures, and controls
  • Conduct and maintain a risk assessment methodology for money laundering and terrorist financing risks
  • Report suspicious transactions to the Financial Intelligence Office (USPN)
  • Ongoing monitoring of customer transactions and activity
  • Maintain records for at least 5 years (extendable to 10 years by national law)
  • Comply with the EU Transfer of Funds Regulation (EU 2023/1113) — obtain and transmit originator and beneficiary information for all crypto-asset transfers (EUR 1,000 de minimis exception for self-hosted wallet counterparty information)
  • Segregation of client assets and sound financial management practices (best practice, soon mandatory under MiCA)

Key Restrictions

  • A legal entity incorporated in Croatia with a registered office in Croatia is required to register — pure cross-border remote service without local entity is not permitted under current regime
  • Must register with the USPN (Office for Anti-Money Laundering) under the current AML/CFT registration regime — this is not a simple notification; it requires full AML programme implementation
  • From 30 December 2025, MiCA (Regulation EU 2023/1114) will introduce a full licensing regime for CASPs, requiring authorization from a competent national authority (likely HANFA in coordination with USPN)
  • Cannot offer services to Croatian residents without meeting VASP registration obligations — operating without registration carries enforcement risk
  • Travel Rule obligations apply from 30 December 2024 under Regulation (EU) 2023/1113

Key Risks

  • Unlicensed remote operation without Croatian entity/registration carries significant enforcement risk — USPN and HANFA may take action against unregistered foreign VASPs serving Croatian residents
  • Regulatory ambiguity during the transition period (pre-MiCA to post-MiCA) — the current regime is light on details for segregation, insurance, and cold storage requirements, creating compliance uncertainty
  • MiCA implementation from December 2025 will raise the compliance bar significantly — operators who register under current regime will need to transition to full CASP licensing
  • HANFA may interpret certain crypto-assets as financial instruments under securities laws, creating dual regulatory exposure
  • The EUR 1,000 de minimis threshold for self-hosted wallet transfers is limited — most commercial transfers will require full Travel Rule compliance

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Office for Anti-Money Laundering (Ured za sprječavanje pranja novca – USPN): This is the primary authority responsible for supervising the implementation of AML/CFT measures by obliged entities, including VASPs. They maintain the register of VASPs.

licensing 60% confidence

Current Regime (Pre-MiCA): Croatia operates a registration regime for VASPs, primarily for AML/CFT supervision. This means entities providing virtual asset services must register with the USPN and comply with AML obligations. It is not a full financial services license in the traditional sense, but an AML registration.

licensing 60% confidence

Future Regime (Post-MiCA): From December 30, 2025, MiCA will introduce a harmonized licensing regime across the EU. Entities providing "crypto-asset services" (as defined by MiCA) will require a license from a competent national authority (likely HANFA in Croatia, in coordination with USPN for AML aspects) in one EU member state, which will then allow them to operate across the entire EU ("passporting"). This will replace the national AML registrations for the services covered by MiCA.

licensing 60% confidence

Generally, a legal entity incorporated in Croatia is required to apply for registration.

licensing 60% confidence

A registered office in Croatia is necessary.

licensing 60% confidence

AML/KYC Framework: This is the most critical aspect:

licensing 60% confidence

Risk Assessment: A robust risk assessment methodology for identifying and mitigating money laundering and terrorist financing risks associated with the VASP's operations, customers, products, and geographies.

aml 60% confidence

VASPs are required to register with the Ministry of Finance – Financial Intelligence Office (Ured za sprječavanje pranja novca) as part of their AML/CTF obligations.

aml 60% confidence

This registration requires compliance with the Croatian Anti-Money Laundering and Terrorist Financing Act (Zakon o sprječavanju pranja novca i financiranja terorizma), which transposes EU AML Directives (specifically AMLD5).

aml 60% confidence

Implementing robust KYC/CDD (Know Your Customer/Customer Due Diligence) procedures.

aml 60% confidence

Reporting suspicious activities to the Financial Intelligence Office.

aml 60% confidence

Establishing internal AML policies and procedures.

aml 60% confidence

Segregation of Client Assets Rules (Current):

travel-rule 60% confidence

Adopted: Yes, through Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (commonly known as the revised Transfer of Funds Regulation - TFR). As an EU Regulation, it is directly applicable in Croatia and does not require separate national transposition legislation for its core provisions.

travel-rule 60% confidence

Effective Date: The provisions of Regulation (EU) 2023/1113 concerning crypto-asset transfers will apply from 30 December 2024.

travel-rule 60% confidence

Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114 (Note: MiCA has a phased implementation, with most provisions for CASPs applying from 30 December 2025).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a non-resident entity cannot serve Croatian residents from abroad remotely; a locally incorporated entity with a registered office in Croatia is required, must register with the USPN (Office for Anti-Money Laundering) under the current AML/CFT regime, and will need a full MiCA CASP license from December 2025.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?