Custodial wallet / SaaS in Israel
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Israel with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must screen customers, counterparties, wallets, and transactions against sanctions lists using integrated KYC, transaction monitoring, and blockchain analytics; OFAC SDN-listed crypto addresses require asset blocking.
- Crypto Travel Rule compliance under FATF standards adopted in Israel — VASPs must verify counterparty sanctions for transfers; EU Regulation 2023/1113 (MiCA-related) influences cross-border operations.
- AML/CFT compliance is overseen by the Israel Money Laundering Prohibition Authority (IMPA).
Key Restrictions
- FASP license (Financial Asset Service Provider) required from ISA/CMISA for custody of crypto assets — covers the SaaS operator directly.
- Customer asset segregation required under the FASP custody framework.
- Transactions must route through licensed entities in the 'closed garden' model — no unlicensed counterparties.
- Israeli Trust Act provisions may also apply to custody arrangements.
- Capital requirement: ILS 300,000–1,000,000 (~$80K–$270K USD) depending on activity type.
- Licensing process takes 6–12 months with 8–14 weeks review after submission.
- ISA proposed amendments to Securities Law (Howey-like token categorisation) may impose additional obligations if hosted assets are classified as securities.
- Banking access historically challenging, though improving after landmark court cases and Bank of Israel guidance.
Key Risks
- Regulatory framework is still maturing (FASP law finalised 2023–2024); ongoing parliamentary review and 2026 legislative steps could shift obligations.
- Stablecoin and tokenised asset regulation still under development — BOI may introduce additional custody/settlement requirements.
- ISA committee evaluating decentralised offerings — could affect custody of certain tokens.
- No explicit 'proof of reserves' or insurance rules found in the provided facts; this may be an unregulated gap or left to contractual terms.
- AML obligations apply to the VASP (SaaS provider), but the white-label client relationship may create ambiguous allocation of KYC/Travel Rule duties between provider and client.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Israel Money Laundering Prohibition Authority — AML/CFT compliance
Financial Asset Service Providers Regulation Law (2023) — FASP licensing covering crypto exchange, custody, portfolio management. Framework matured 2023-2024 after years of uncertainty.
VASP: Financial Asset Service Provider (FASP) License from ISA/CMISA. ILS 300,000-1,000,000 (~$80K-$270K USD) depending on activity type. 6-12 months. Banking sector gradually opening after landmark court cases and Bank of Israel guidance.
CUSTODY: Included under FASP license; customer asset segregation required
EXCHANGE: FASP license. Strong crypto startup ecosystem but banking access historically challenging.
CMSA/ISA/BOI/IMPA oversight (no direct URLs).
Exchanges: Require a license as a "service provided in a financial asset" under the Supervision of Financial Services Law from the CMA. Recent ISA amendments (August 2024) allow non-bank Tel Aviv Stock Exchange (TASE) members (e.g., brokerages) to offer trading in approved cryptocurrencies like Bitcoin and Ethereum via licensed exchanges.
Custody Providers: Need the same CMA financial asset service license for management or custody of virtual currencies; Israeli Trust Act provisions may also apply. Transactions must route through licensed entities in the "closed garden" model.
Prepare documents: company registration, business plan, proof of capital, directors' details, compliance handbook, IT/security policies, risk models.
Submit to CMA (or relevant authority for VASPs/exchanges/custody).
Undergo verification/review (8-14 weeks, depending on completeness).
Receive decision; ongoing obligations include real-time monitoring and regulator engagement.
ISA proposed amendments to the Israeli Securities Law to categorize tokens (e.g., security vs. utility, using Howey-like tests) and regulate offerings, potentially impacting custody.
National Crypto Strategy Committee interim report proposes a unified regulator, token issuance rules, and banking integration; parliamentary review and 2026 legislative steps expected.
Regulatory guidance sought on stablecoins and tokenized assets, covering custody, settlement, and protections; Bank of Israel (BOI) principles for stablecoin risk management.
ISA committee evaluating decentralized offerings; ongoing stablecoin regulation likely under BOI.
Screening Obligations: VASPs must screen customers, counterparties, wallets, and transactions against these lists using integrated KYC, transaction monitoring, and blockchain analytics; OFAC may list specific crypto addresses on the SDN List, requiring blocking of associated assets.
Crypto Travel Rule Alignment: Under FATF standards adopted in Israel, VASPs comply with Travel Rule-like requirements for transfers, including counterparty sanctions verification; EU's Regulation (EU) 2023/1113 (MiCA-related) influences via cross-border operations, applying to all qualifying crypto transfers without thresholds since December 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS provider may operate in Israel but must obtain a FASP license from ISA/CMISA (ILS 300K–1M capital, 6–12 months), comply with asset segregation rules, screen customers under IMPA AML/CFT oversight, adhere to the Crypto Travel Rule, and route transactions through licensed entities in the closed-garden model; no explicit proof-of-reserves or insurance rules were found in the facts, and the regulatory framework continues to mature with 2026 legislative steps expected.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?