On-shore VASP in Isle of Man
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Isle of Man with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as a Designated Business under the Designated Business (Registration and Oversight) Act 2015 (DBROA) with the IOM FSA.
- Implement a risk-based approach identifying, assessing, and understanding ML/TF risks.
- Conduct Customer Due Diligence (CDD): identify and verify identity of customers and beneficial owners, understand purpose and intended nature of the business relationship.
- Conduct ongoing monitoring of business relationships.
- Maintain robust internal controls, record-keeping, and risk management systems per the AML/CFT Code 2019.
- Maintain separate accounts/records clearly distinguishing client virtual assets from firm assets; prevent commingling.
- Ensure client assets are not used to satisfy the firm's debts or liabilities.
- Have clear procedures for return of client assets in case of business failure or cessation.
- Implement appropriate technical and organisational measures for security, integrity, and availability of virtual assets and associated systems.
- Obtain appropriate insurance coverage (cyber, crime, professional indemnity) as part of risk mitigation for custody services.
- Submit to supervision by the Isle of Man Financial Services Authority (IOMFSA).
- Follow guidance in the IOM FSA AML/CFT Handbook (specifically Section 4.5 on Virtual Asset Businesses).
Key Restrictions
- Must be locally incorporated and registered with the IOM FSA as a Designated Business.
- Directors, beneficial owners, and key personnel must be 'fit and proper' persons.
- Must demonstrate adequate financial resources, robust governance, operational resilience, and comprehensive AML/CFT policies as part of the application.
- Corporate income tax at 0% applies to most trading income, but if the VASP's primary business involves crypto (e.g. exchange, custody, active trading), profits are subject to corporate income tax; banking/insurance/retail income above £500k is taxed at 10%.
- Standard VAT of 20% applies to fees charged for exchange services and wallet services.
Key Risks
- Stringent AML/CFT expectations — IOMFSA takes a proactive supervisory approach and public enforcement actions are common for AML/CFT deficiencies.
- No specific publicly documented enforcement cases found for on-shore VASPs, but IOMFSA regularly issues warnings against unlicensed activity.
- Capital gains tax not applicable, but trading income and corporate income tax obligations can create complexity around characterisation of crypto gains.
- Operational risk around custody of virtual assets — cyber theft, loss of private keys, and professional indemnity risks are high on FSA's radar.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulator: Isle of Man Financial Services Authority (IOMFSA)
The Designated Business (Registration and Oversight) Act 2015 (DBROA): This Act provides the framework for the registration and oversight of businesses engaged in certain activities, including those involving virtual assets.
AML/CFT Code 2015: https://www.legislation.gov.im/cms/images/LEGISLATION/PRINCIPAL/2015/2015-0029/Anti-MoneyLaunderingandCounteringtheFinancingofTerrorismCode2015_1.pdf
AML/CFT Handbook: The IOM FSA publishes a comprehensive handbook that provides guidance on how Designated Businesses should comply with their AML/CFT obligations.
Virtual Asset Service Providers (VASPs): A person carrying on the business of providing any of the following services to, or on behalf of, another person:
AML/KYC Compliance: This is the cornerstone of the IOM's regulatory approach. Registered businesses must implement robust AML/CFT policies and procedures, including:
Risk-Based Approach: Identifying, assessing, and understanding money laundering and terrorist financing risks.
Customer Due Diligence (CDD):
Identifying and verifying the identity of customers and beneficial owners.
Understanding the purpose and intended nature of the business relationship.
Ongoing monitoring of business relationships.
Designated Business Registration: Any entity carrying on a "designated business" activity involving virtual assets must register with the IOM FSA. This explicitly includes providing safe custody or storage of virtual assets.
Fit and proper persons (directors, beneficial owners, key personnel).
Robust governance arrangements.
Adequate financial resources.
Comprehensive AML/CFT policies, procedures, and controls.
Operational resilience and risk management frameworks.
AML/CFT Code 2019: Requires designated businesses to have robust internal controls, record-keeping, and risk management systems. This implicitly demands a clear distinction and proper accounting for client assets versus firm assets to prevent commingling and facilitate accurate reporting.
General Principles: The IOM FSA expects firms to protect client assets. This means:
Maintaining separate accounts or records that clearly distinguish client virtual assets from the firm's own assets.
Implementing internal controls to prevent the misuse or misappropriation of client assets.
Ensuring that client assets are not used to satisfy the firm's debts or liabilities.
Having clear procedures for the return of client assets in case of business failure or cessation.
FSA's Expectations on Operational Risk: The FSA emphasizes that firms must have adequate systems and controls to manage operational risks, including those related to the safekeeping of client assets.
FSA's View: While not explicitly mandated, the FSA would expect a prudent firm providing custody services for valuable digital assets to seriously consider and obtain appropriate insurance coverage (e.g., cyber insurance, crime insurance, professional indemnity) as part of its overall risk mitigation strategy. The absence of such consideration would likely be viewed negatively during supervision.
Security and Operational Resilience: The FSA expects firms to implement "appropriate technical and organisational measures" to ensure the security, integrity, and availability of virtual assets and associated systems. This includes:
Trading Profits: Companies whose primary business activities involve cryptocurrency (e.g., exchanges, custodial services, development of crypto projects, professional mining operations, active crypto trading) will have their profits from these activities subject to corporate income tax.
Corporate Income Tax Rates (2023/24):
Supply of Cryptocurrencies (e.g., Bitcoin, Ether): The actual buying and selling of cryptocurrencies that function as a means of payment or exchange are generally exempt from VAT. This aligns with the EU and UK position, treating them similarly to currency or securities for VAT purposes.
Exchange Services: Fees charged by cryptocurrency exchanges for facilitating trades or converting crypto to fiat (and vice versa) are generally considered taxable services and are subject to the standard rate of VAT (currently 20%).
Wallet Services: If a fee is charged for wallet services, this would typically be subject to VAT.
Preventative and Supervisory Approach: The IOMFSA often emphasizes a proactive supervisory approach, working with licensed entities to rectify issues before they escalate to formal public enforcement actions with substantial fines. This approach may result in fewer public "headline" enforcement actions.
Outcome: No specific, publicly documented cases matching all criteria were found within the specified timeframe.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A locally-incorporated on-shore VASP is permitted in the Isle of Man, subject to Designated Business registration with the IOM FSA under the DBROA 2015, demonstrating fit-and-proper persons, adequate financial resources, robust governance, and comprehensive AML/CFT compliance under the AML/CFT Code 2019 and IOM FSA AML/CFT Handbook.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?