Custodial wallet / SaaS in Ireland
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Ireland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full CDD/KYC under Part 4 of the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010–2021 — identify customers, verify identities, understand transaction purpose, assess risk.
- Suspicious Transaction Reporting (STR) — monitor transactions and report ML/TF suspicious activity to authorities, with enhanced mechanisms under WCTR empowering FIUs to suspend suspicious crypto transfers.
- Record-keeping obligations — maintain records of transactions, CDD, and monitoring to demonstrate AML/CFT compliance.
- Registration with CBI: VASPs (fiat-to-crypto exchanges and custodian wallet providers) must register with the Central Bank of Ireland under 5AMLD transposition; 15 VASPs listed as of July 2024.
- Post-30 December 2024: Full MiCA CASP authorization regime applies, including CBI supervision under the European Union (Markets in Crypto-Assets) Regulations 2024 (S.I. No. 607/2024).
- AML supervision by Central Bank of Ireland as Designated National Competent Authority under MiCAR.
Key Restrictions
- Custody of crypto-assets is a licensed MiCA activity — CASP authorization required from CBI.
- Local entity incorporation is required to obtain CBI CASP authorization.
- Individual Accountability Framework applies to senior management personnel.
- Detailed outsourcing and operational resilience documentation must be submitted to CBI for authorization.
- Pre-MiCA VASP AML registration (under 5AMLD) currently in effect; full CASP authorization under MiCA mandatory from 30 December 2024.
Key Risks
- CBI is known for rigorous, lengthy authorization process (6–12 months); operators face significant timeline risk.
- Regulatory ambiguity around how custody-as-a-service / white-label arrangements allocate AML obligations between the SaaS provider and the white-label client — both may need separate authorizations.
- Short window between MiCAR applicability (30 Dec 2024) and the original CBI timeline; operators still under pre-MiCA transitional registration face uncertainty.
- Sanctions compliance risk: Irish/ EU sanctions regimes apply (including EU restrictive measures and OFAC extraterritorial reach for USD-linked activity).
- Insurance and proof-of-reserves requirements not explicitly detailed in cited sources — unclear whether CBI will impose specific prudential rules for custodians beyond MiCA baseline.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CBI — CASP authorization, VASP registration, AML supervision. Coinbase and Gemini chose Ireland as EU base.
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (amended) (2021) — Pre-MiCA VASP AML registration
VASP: CASP authorization under MiCA via Central Bank of Ireland. 6-12 months (CBI rigorous). Individual Accountability Framework applies to senior management.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization with EU-wide passporting — CBI requires detailed outsourcing and operational resilience documentation
Customer Due Diligence (CDD/KYC): VASPs must conduct CDD, including identifying customers, verifying identities, understanding transaction purposes, and assessing risks, as outlined in Part 4 of the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010 to 2021. This involves stricter KYC obligations like user identity verification and real-time monitoring, with no anonymous crypto transactions allowed.
Suspicious Transaction Reporting: VASPs must monitor transactions for suspicious activity related to money laundering or terrorist financing and report to the relevant authorities, with enhanced mechanisms under WCTR empowering financial intelligence units to suspend suspicious crypto transfers.
Record-Keeping Obligations: VASPs must maintain records of transactions, CDD, and monitoring to demonstrate compliance with AML/CFT rules.
Central Bank of Ireland (CBI): Designated National Competent Authority (NCA) under MiCAR for authorizing/supervising Crypto-Asset Service Providers (CASPs), enforcing AML/CFT for VASPs, and issuing consumer warnings.
EU Fifth Anti-Money Laundering Directive (5AMLD): Transposed via Irish law requiring VASPs (fiat-to-crypto exchanges, custodian wallets) to register with CBI, apply KYC/due diligence, and report suspicious activities. Registration ongoing; 15 VASPs listed as of July 2024.
Markets in Crypto-Assets Regulation (MiCAR): EU Regulation published 9 June 2023; applicable to ARTs/EMTs from 30 June 2024 and CASPs from 30 December 2024. Irish implementation: S.I. No. 607/2024 - European Union (Markets in Crypto-Assets) Regulations 2024 (published 12 November 2024), designating CBI as NCA for issuance, custody, trading platforms/exchanges.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers may operate in Ireland only after obtaining CASP authorization from the Central Bank of Ireland (6–12 month rigorous process), with mandatory local incorporation, full AML/CDD obligations, and a licensing burden assessed as high under MiCA.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?