Remote VASP serving residents in Ireland
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Ireland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must register with the Central Bank of Ireland (CBI) and obtain CASP authorization under MiCA — rigorous 6–12 month application process
- Customer Due Diligence (CDD/KYC) required under Part 4 of the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010–2021 — identify and verify customers, assess risk, understand transaction purpose
- Suspicious Transaction Reporting (STR) — monitor for money laundering/terrorist financing and report to authorities; enhanced mechanisms under WCTR for suspending suspicious crypto transfers
- Record-keeping obligations — maintain records of transactions, CDD, and monitoring to demonstrate AML/CFT compliance
- Travel Rule adopted (EUR 0 threshold under TFR recast) — full originator/beneficiary data required on all virtual asset transfers
- EU Fifth Anti-Money Laundering Directive (5AMLD) transposed — fiat-to-crypto exchanges and custodian wallets must register with CBI, apply KYC, and report suspicious activities
- Sanctions screening — CBI enforces EU/UN sanctions; operators must comply with International Financial Sanctions regimes
Key Restrictions
- Must be authorized as a CASP under MiCA via the Central Bank of Ireland — no exemption for non-resident, foreign-incorporated entities serving Irish residents cross-border
- Local entity required — CASP authorization necessitates an Irish (or EU) incorporated entity with physical presence; remote cross-border service without authorization is unlawful
- Individual Accountability Framework applies to senior management of CASPs
- Detailed outsourcing and operational resilience documentation required by CBI
- No 'no-action' or lighter-touch regime for foreign VASPs — CBI treats unlicensed cross-border activity as illegal
Key Risks
- High enforcement risk — CBI has issued consumer warnings against unlicensed crypto firms operating cross-border into Ireland; Binance-type fact patterns face regulatory action
- No grandfathering for pre-MiCA operators; all VASPs must transition to full CASP authorization by December 2024
- Sanctions compliance risk — CBI enforces EU sanctions rigorously; OFAC reach may also apply given USD involvement
- Operational resilience and outsourcing scrutiny by CBI is high — foreign-entity setups without local substance are unlikely to pass authorization
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CBI — CASP authorization, VASP registration, AML supervision. Coinbase and Gemini chose Ireland as EU base.
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (amended) (2021) — Pre-MiCA VASP AML registration
VASP: CASP authorization under MiCA via Central Bank of Ireland. 6-12 months (CBI rigorous). Individual Accountability Framework applies to senior management.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
EXCHANGE: CASP authorization with EU-wide passporting — CBI requires detailed outsourcing and operational resilience documentation
Customer Due Diligence (CDD/KYC): VASPs must conduct CDD, including identifying customers, verifying identities, understanding transaction purposes, and assessing risks, as outlined in Part 4 of the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010 to 2021. This involves stricter KYC obligations like user identity verification and real-time monitoring, with no anonymous crypto transactions allowed.
Suspicious Transaction Reporting: VASPs must monitor transactions for suspicious activity related to money laundering or terrorist financing and report to the relevant authorities, with enhanced mechanisms under WCTR empowering financial intelligence units to suspend suspicious crypto transfers.
Record-Keeping Obligations: VASPs must maintain records of transactions, CDD, and monitoring to demonstrate compliance with AML/CFT rules.
Central Bank of Ireland (CBI): Designated National Competent Authority (NCA) under MiCAR for authorizing/supervising Crypto-Asset Service Providers (CASPs), enforcing AML/CFT for VASPs, and issuing consumer warnings.
EU Fifth Anti-Money Laundering Directive (5AMLD): Transposed via Irish law requiring VASPs (fiat-to-crypto exchanges, custodian wallets) to register with CBI, apply KYC/due diligence, and report suspicious activities. Registration ongoing; 15 VASPs listed as of July 2024.
Markets in Crypto-Assets Regulation (MiCAR): EU Regulation published 9 June 2023; applicable to ARTs/EMTs from 30 June 2024 and CASPs from 30 December 2024. Irish implementation: S.I. No. 607/2024 - European Union (Markets in Crypto-Assets) Regulations 2024 (published 12 November 2024), designating CBI as NCA for issuance, custody, trading platforms/exchanges.
Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)
Adoption and Effective Date: Adopted via the EU recast FTR, effective December 2024. Ireland, as an EU member, implements this uniformly, with the Central Bank of Ireland overseeing supervision.
Threshold Amounts: Follows the FATF-recommended €1,000 (or USD 1,000 equivalent) de minimis threshold for virtual asset transfers, above which full Travel Rule data must be shared; requirements may vary below this per EU rules.
VASPs Covered: All VASPs, including those handling crypto transactions, must comply for both originating and beneficiary roles in transfers.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-resident remote VASP may not serve Irish residents from abroad without establishing a locally authorized CASP entity; cross-border service triggers mandatory CASP authorization under MiCA (6–12 months, high burden), AML registration, KYC/CDD, Travel Rule compliance, and CBI supervision, with significant enforcement risk for unlicensed operators.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?