Self-custodial wallet / non-custodial software in Ireland
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Ireland without local incorporation, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- No AML obligations attach to the publisher of non-custodial/self-custodial wallet software because the publisher never holds, controls, or has access to user funds, and therefore does not qualify as a VASP/CASP under Irish law or MiCA.
- The EU Fifth Anti-Money Laundering Directive (5AMLD) and Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010-2021 impose KYC/CDD, record-keeping, and suspicious transaction reporting obligations on VASPs that provide 'custodian wallet' services — defined as services where the provider holds, stores, or transfers private keys on behalf of users. Pure non-custodial software does not trigger this definition.
- AML obligations (CDD/KYC, suspicious transaction reporting, record-keeping) apply only if the software publisher also provides an ancillary service that crosses into custody (e.g., key recovery infrastructure, hosted wallet features).
Key Restrictions
- The software publisher must not hold, store, or transmit private keys on behalf of users, nor operate any infrastructure that constitutes 'custody' under MiCA Article 3(1)(17) definitions.
- Any feature that allows the publisher to regenerate, escrow, or recover user private keys would reclassify the service as custody and trigger MiCA CASP authorization requirements.
- The wallet software must not facilitate fiat-to-crypto or crypto-to-fiat exchange services on its own (i.e., embedded on-ramp/off-ramp features provided by the publisher directly would require a separate CASP license).
- Marketing or representing the software as a financial service product could trigger consumer-protection disclosure obligations under Irish consumer law.
Key Risks
- Regulatory reclassification risk: If CBI or ESMA expands the interpretation of 'custody' to include certain non-custodial models (e.g., threshold signature schemes, DKG setups where the publisher operates nodes), the publisher could be retroactively deemed an unlicensed CASP.
- Consumer-protection enforcement risk: CBI has issued consumer warnings about unregulated crypto services; a non-custodial wallet publisher suffering a major security incident could face consumer-harm scrutiny even absent a license.
- Sanctions screening expectations: OFAC and EU sanctions frameworks may expect wallet publishers to implement geoblocking for sanctioned jurisdictions (e.g., via IP-blocking), even if the publisher has no AML statutory obligation.
- MiCA's phased application (CASPs from 30 December 2024) may lead to divergent member-state interpretations of what constitutes 'custody' for software-only wallet providers.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CUSTODY: CASP authorization — custody is a licensed MiCA activity
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (amended) (2021) — Pre-MiCA VASP AML registration
EU Fifth Anti-Money Laundering Directive (5AMLD): Transposed via Irish law requiring VASPs (fiat-to-crypto exchanges, custodian wallets) to register with CBI, apply KYC/due diligence, and report suspicious activities. Registration ongoing; 15 VASPs listed as of July 2024.
Customer Due Diligence (CDD/KYC): VASPs must conduct CDD, including identifying customers, verifying identities, understanding transaction purposes, and assessing risks, as outlined in Part 4 of the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010 to 2021. This involves stricter KYC obligations like user identity verification and real-time monitoring, with no anonymous crypto transactions allowed.
Suspicious Transaction Reporting: VASPs must monitor transactions for suspicious activity related to money laundering or terrorist financing and report to the relevant authorities, with enhanced mechanisms under WCTR empowering financial intelligence units to suspend suspicious crypto transfers.
Record-Keeping Obligations: VASPs must maintain records of transactions, CDD, and monitoring to demonstrate compliance with AML/CFT rules.
Central Bank of Ireland (CBI): Designated National Competent Authority (NCA) under MiCAR for authorizing/supervising Crypto-Asset Service Providers (CASPs), enforcing AML/CFT for VASPs, and issuing consumer warnings.
VASP: CASP authorization under MiCA via Central Bank of Ireland. 6-12 months (CBI rigorous). Individual Accountability Framework applies to senior management.
CBI — CASP authorization, VASP registration, AML supervision. Coinbase and Gemini chose Ireland as EU base.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a pure software publisher of a self-custodial wallet is not a VASP/CASP under Irish law or MiCA because it never holds private keys or user funds, so no license or AML obligations attach; however, any feature that crosses into custody (key recovery, hosted infrastructure) would trigger full MiCA CASP authorization and AML compliance obligations.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?