Crypto ATM / kiosk operator in Isle of Man
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Isle of Man with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with IOMFSA under the Designated Business (Registration and Oversight) Act 2015 (DBROA) as a Virtual Asset Service Provider (VASP)
- Customer Due Diligence (CDD) required: identify and verify identity of customers and beneficial owners before any transaction
- Risk-based approach: assess ML/TF risk of customer and transaction, with enhanced due diligence for cash-in/cash-out transactions given high-risk profile
- Ongoing monitoring of business relationships required under AML/CFT Code 2015
- Robust AML/CFT policies, procedures, and controls must be documented and implemented per AML/CFT Code 2015 and IOM FSA AML/CFT Handbook
- Fit and proper persons requirement for directors, beneficial owners, and key personnel
- Operational resilience and risk management frameworks required, including cyber theft and private-key loss risk mitigation
- Record-keeping and internal control obligations under AML/CFT Code 2019
- Cash-transaction reporting thresholds are not explicitly stated in provided facts, but standard CDD/STR obligations under AML/CFT Code apply to high-cash operations
Key Restrictions
- Must register as a Designated Business under DBROA 2015 before operating any crypto ATM/kiosk
- Must maintain separate accounts/records distinguishing client virtual assets from firm assets
- Must implement internal controls to prevent misuse or misappropriation of client assets
- Must have clear procedures for return of client assets in case of business failure
- Cash-in/cash-out at kiosks triggers highest AML risk tier — expect enhanced due diligence on all cash transactions
- Physical presence / incorporation in Isle of Man required for registration
Key Risks
- No specific publicly documented enforcement cases for crypto ATM/kiosk operators found — regulatory ambiguity on how existing VASP framework applies to unattended kiosks
- High-cash AML risk profile may attract enhanced supervisory scrutiny from IOMFSA
- No explicit cash-transaction reporting threshold (CTR-equivalent) mentioned in provided facts — operators must rely on general STR obligations which creates uncertainty
- Physical kiosk operations may raise additional operational resilience and security requirements (e.g., cyber theft, key management) not fully addressed in provided guidance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Designated Business (Registration and Oversight) Act 2015 (DBROA): This Act provides the framework for the registration and oversight of businesses engaged in certain activities, including those involving virtual assets.
Anti-Money Laundering and Countering the Financing of Terrorism Code 2015 (AML/CFT Code): This Code sets out the specific AML/CFT obligations for Designated Businesses.
Evidence fact im.licensing.amlcft-code-2015-httpswwwlegislationgovimcmsimageslegislationprincipal20152015-0027designatedbusinessregistrationandoversightact20151pdf not found (may have been renamed).
AML/CFT Handbook: The IOM FSA publishes a comprehensive handbook that provides guidance on how Designated Businesses should comply with their AML/CFT obligations.
Virtual Asset Service Providers (VASPs): A person carrying on the business of providing any of the following services to, or on behalf of, another person:
Exchanges: Exchanging virtual assets for fiat currencies, or one or more forms of virtual assets. This covers both fiat-to-crypto and crypto-to-crypto exchanges.
AML/KYC Compliance: This is the cornerstone of the IOM's regulatory approach. Registered businesses must implement robust AML/CFT policies and procedures, including:
Risk-Based Approach: Identifying, assessing, and understanding money laundering and terrorist financing risks.
Customer Due Diligence (CDD):
Identifying and verifying the identity of customers and beneficial owners.
Designated Business Registration: Any entity carrying on a "designated business" activity involving virtual assets must register with the IOM FSA. This explicitly includes providing safe custody or storage of virtual assets.
Virtual Asset Activities Covered: The definition of "virtual assets" and the activities that constitute "designated business" are broad and cover:
Exchanging, or arranging or making arrangements for the exchange of, virtual assets for fiat currencies or other virtual assets.
Issuing, transmitting, transferring, providing safe custody or storage, administering, managing, lending, buying, selling, or otherwise dealing with virtual assets.
Application Process: Applicants must demonstrate:
Fit and proper persons (directors, beneficial owners, key personnel).
Robust governance arrangements.
Adequate financial resources.
Comprehensive AML/CFT policies, procedures, and controls.
Operational resilience and risk management frameworks.
Designated Businesses (Registration and Oversight) Act 2015: https://www.legislation.gov.im/cms/images/stories/Acts/2015/Designated_Businesses_(Registration_and_Oversight)_Act_2015.pdf_Act_2015.pdf)
IOM FSA AML/CFT Handbook (specifically Section 4.5 Virtual Asset Businesses): https://www.iomfsa.im/media/1908/amlcft-handbook-december-2023-version-8.pdf (Refer to the latest version available on the FSA website)
AML/CFT Code 2019: Requires designated businesses to have robust internal controls, record-keeping, and risk management systems. This implicitly demands a clear distinction and proper accounting for client assets versus firm assets to prevent commingling and facilitate accurate reporting.
General Principles: The IOM FSA expects firms to protect client assets. This means:
Maintaining separate accounts or records that clearly distinguish client virtual assets from the firm's own assets.
Implementing internal controls to prevent the misuse or misappropriation of client assets.
Ensuring that client assets are not used to satisfy the firm's debts or liabilities.
Having clear procedures for the return of client assets in case of business failure or cessation.
FSA's Expectations on Operational Risk: The FSA emphasizes that firms must have adequate systems and controls to manage operational risks, including those related to the safekeeping of client assets.
Anti-Money Laundering and Countering the Financing of Terrorism Code 2019 (Parts related to Internal Controls, Record Keeping, and Risk Management): https://www.legislation.gov.im/cms/images/stories/Acts/2019/Anti-Money_Laundering_and_Countering_the_Financing_of_Terrorism_Code_2019.pdf
Risk Management Expectation: Firms are expected to have robust risk management frameworks. This includes identifying, assessing, mitigating, and monitoring all relevant risks, including operational risks like cyber theft, loss of private keys, and professional indemnity.
Security and Operational Resilience: The FSA expects firms to implement "appropriate technical and organisational measures" to ensure the security, integrity, and availability of virtual assets and associated systems. This includes:
Regulator: Isle of Man Financial Services Authority (IOMFSA)
Outcome: No specific, publicly documented cases matching all criteria were found within the specified timeframe.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators are permitted in the Isle of Man if they register as a Designated Business under DBROA 2015 (VASP category covering exchange of virtual assets for fiat), maintain local incorporation, implement full AML/CFT controls including CDD and a risk-based approach, but the facts lack explicit cash-transaction reporting thresholds or kiosk-specific licensing guidance, creating moderate uncertainty.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?