← Regulations / Isle of Man / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Isle of Man

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Isle of Man with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration as a Designated Business under the Designated Business (Registration and Oversight) Act 2015 (DBROA) — explicitly required for providers of safe custody or storage of virtual assets (im.aml.designated-business-registration-any-entity).
  • Comprehensive AML/CFT policies, procedures and controls under the AML/CFT Code 2015 (im.licensing.anti-money-laundering-and-countering-the) and AML/CFT Code 2019 (im.aml.amlcft-code-2019-requires-designated).
  • Customer Due Diligence (CDD) — identify and verify identity of customers and beneficial owners; understand purpose and intended nature of business relationship; ongoing monitoring (im.licensing.customer-due-diligence-cdd, im.licensing.identifying-and-verifying-the-identity, im.licensing.understanding-the-purpose-and-intended, im.licensing.ongoing-monitoring-of-business-relationships).
  • Risk-based approach to identifying, assessing and understanding ML/TF risks (im.licensing.risk-based-approach-identifying-assessing-and).
  • Fit and proper persons requirement for directors, beneficial owners and key personnel (im.aml.fit-and-proper-persons-directors).
  • Robust governance arrangements, adequate financial resources, operational resilience and risk management frameworks (im.aml.robust-governance-arrangements, im.aml.adequate-financial-resources, im.aml.operational-resilience-and-risk-management).
  • Internal controls, record-keeping and risk management systems — including clear distinction and proper accounting for client assets vs firm assets to prevent commingling (im.aml.amlcft-code-2019-requires-designated).
  • Maintaining separate accounts or records that clearly distinguish client virtual assets from firm's own assets (im.aml.maintaining-separate-accounts-or-records).
  • Implementing internal controls to prevent misuse or misappropriation of client assets (im.aml.implementing-internal-controls-to-prevent).
  • Clear procedures for return of client assets in case of business failure or cessation (im.aml.having-clear-procedures-for-the).
  • Appropriate technical and organisational measures for security, integrity and availability of virtual assets and associated systems (im.aml.security-and-operational-resilience-the).
  • Supervised by the Isle of Man Financial Services Authority (IOMFSA) (im.licensing.regulator-isle-of-man-financial).

Key Restrictions

  • Must register as a Designated Business with the IOMFSA under DBROA 2015 — custody of virtual assets is explicitly covered (im.licensing.custody-providers-safekeeping-andor-administration, im.aml.designated-business-registration-any-entity).
  • Must maintain separate accounts/records distinguishing client virtual assets from firm assets; commingling is prohibited (im.aml.maintaining-separate-accounts-or-records).
  • Client assets must not be used to satisfy the firm's debts or liabilities (im.aml.ensuring-that-client-assets-are).
  • SaaS provider (holding keys) is the regulated VASP — the white-label client may or may not need separate registration depending on whether the client itself conducts VASP activities (im.licensing.virtual-asset-service-providers-vasps).
  • While not explicitly mandated, the IOMFSA expects prudent custody firms to seriously consider obtaining appropriate insurance (cyber, crime, professional indemnity) as part of risk mitigation (im.aml.fsas-view-while-not-explicitly).

Key Risks

  • No specific publicly documented enforcement cases found for custody-related violations in the jurisdiction, creating some ambiguity around enforcement posture (im.enforcement.outcome-no-specific-publicly-documented).
  • AML/CFT obligations fall on the registered VASP (the SaaS provider holding keys) — unclear allocation of responsibility between SaaS provider and white-label client where client interfaces with end users.
  • Insurance expectations (cyber/crime/PI) are not statutorily mandated but are expected by the regulator — non-insured firms may face heightened supervisory criticism.
  • The IOMFSA frequently issues public warnings against unlicensed entities — operating without registration carries significant enforcement exposure (im.licensing.warnings-against-unlicensed-activity-the).

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Regulator: Isle of Man Financial Services Authority (IOMFSA)

licensing 60% confidence

The Designated Business (Registration and Oversight) Act 2015 (DBROA): This Act provides the framework for the registration and oversight of businesses engaged in certain activities, including those involving virtual assets.

licensing 60% confidence

Virtual Asset Service Providers (VASPs): A person carrying on the business of providing any of the following services to, or on behalf of, another person:

licensing 60% confidence

Custody Providers: Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets. This includes businesses that hold private keys on behalf of clients.

licensing 60% confidence

AML/KYC Compliance: This is the cornerstone of the IOM's regulatory approach. Registered businesses must implement robust AML/CFT policies and procedures, including:

aml 60% confidence

Designated Business Registration: Any entity carrying on a "designated business" activity involving virtual assets must register with the IOM FSA. This explicitly includes providing safe custody or storage of virtual assets.

aml 60% confidence

AML/CFT Code 2019: Requires designated businesses to have robust internal controls, record-keeping, and risk management systems. This implicitly demands a clear distinction and proper accounting for client assets versus firm assets to prevent commingling and facilitate accurate reporting.

aml 60% confidence

FSA's View: While not explicitly mandated, the FSA would expect a prudent firm providing custody services for valuable digital assets to seriously consider and obtain appropriate insurance coverage (e.g., cyber insurance, crime insurance, professional indemnity) as part of its overall risk mitigation strategy. The absence of such consideration would likely be viewed negatively during supervision.

aml 60% confidence

Security and Operational Resilience: The FSA expects firms to implement "appropriate technical and organisational measures" to ensure the security, integrity, and availability of virtual assets and associated systems. This includes:

enforcement 60% confidence

Outcome: No specific, publicly documented cases matching all criteria were found within the specified timeframe.

licensing 60% confidence

Warnings Against Unlicensed Activity: The IOMFSA frequently issues public warnings against entities operating without a license or targeting Isle of Man residents without proper authorisation. These are a form of enforcement but are directed at unregistered entities rather than penalties for registered DLT firms.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers holding keys on behalf of clients must register as Designated Businesses under DBROA 2015 with the IOMFSA, comply with comprehensive AML/CFT obligations including client asset segregation and record-keeping, and are expected by the regulator to carry appropriate insurance as part of operational risk management.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?