← Regulations / Isle of Man / Operating Models / Remote VASP

Remote VASP serving residents in Isle of Man

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Isle of Man with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the IOMFSA under the Designated Business (Registration and Oversight) Act 2015 (DBROA) is mandatory for any entity carrying on a 'designated business' activity involving virtual assets.
  • Must implement robust AML/CFT policies and procedures under the AML/CFT Code (2015/2019) and IOM FSA AML/CFT Handbook.
  • Conduct risk-based Customer Due Diligence (CDD): identify and verify identity of customers and beneficial owners, understand purpose and intended nature of business relationships.
  • Ongoing monitoring of business relationships required.
  • Maintain separate accounts or records clearly distinguishing client virtual assets from firm assets.
  • Implement internal controls to prevent misuse or misappropriation of client assets.
  • Establish clear procedures for return of client assets in case of business failure or cessation.
  • Fit and proper persons (directors, beneficial owners, key personnel) must be demonstrated.
  • Adequate financial resources, robust governance arrangements, and operational resilience/risk management frameworks required.
  • Record-keeping and risk management systems required under AML/CFT Code 2019.

Key Restrictions

  • Foreign-incorporated entity cannot serve Isle of Man residents remotely without first registering as a Designated Business with the IOMFSA.
  • Requires a local business presence/registration — registration under DBROA effectively requires the operator to be subject to IOMFSA oversight.
  • Must demonstrate fit and proper persons (directors, beneficial owners) — likely requiring local substance or at least local directors.
  • VASP activities covered include exchange (fiat-crypto and crypto-crypto), custody/safekeeping, payment processing/transfer services, and participation in offers/sales of virtual assets — all require registration.

Key Risks

  • IOMFSA frequently issues public warnings against entities operating without a license or targeting Isle of Man residents without proper authorisation — enforcement risk for unregistered remote operators is high.
  • Regulatory ambiguity remains around whether purely remote (no physical presence) service can ever satisfy IOMFSA's fit-and-proper and governance expectations.
  • No specific publicly documented enforcement cases were found matching this exact model, but IOMFSA takes a proactive supervisory approach and issues warnings against unlicensed operators.
  • Cross-border service without registration could lead to public warning, potential fines, or being named on IOMFSA warnings list.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

The Designated Business (Registration and Oversight) Act 2015 (DBROA): This Act provides the framework for the registration and oversight of businesses engaged in certain activities, including those involving virtual assets.

licensing 60% confidence

DBROA 2015: https://www.legislation.gov.im/cms/images/LEGISLATION/PRINCIPAL/2015/2015-0027/DesignatedBusinessRegistrationandOversightAct2015_1.pdf

licensing 60% confidence

Anti-Money Laundering and Countering the Financing of Terrorism Code 2015 (AML/CFT Code): This Code sets out the specific AML/CFT obligations for Designated Businesses.

licensing 60% confidence

AML/CFT Code 2015: https://www.legislation.gov.im/cms/images/LEGISLATION/PRINCIPAL/2015/2015-0029/Anti-MoneyLaunderingandCounteringtheFinancingofTerrorismCode2015_1.pdf

licensing 60% confidence

AML/CFT Handbook: The IOM FSA publishes a comprehensive handbook that provides guidance on how Designated Businesses should comply with their AML/CFT obligations.

licensing 60% confidence

Virtual Asset Service Providers (VASPs): A person carrying on the business of providing any of the following services to, or on behalf of, another person:

licensing 60% confidence

Exchanges: Exchanging virtual assets for fiat currencies, or one or more forms of virtual assets. This covers both fiat-to-crypto and crypto-to-crypto exchanges.

licensing 60% confidence

Custody Providers: Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets. This includes businesses that hold private keys on behalf of clients.

licensing 60% confidence

Payment Processors: Services related to the transfer of virtual assets. This covers facilitating payments in crypto, or services that move virtual assets from one address or account to another.

licensing 60% confidence

AML/KYC Compliance: This is the cornerstone of the IOM's regulatory approach. Registered businesses must implement robust AML/CFT policies and procedures, including:

licensing 60% confidence

Warnings Against Unlicensed Activity: The IOMFSA frequently issues public warnings against entities operating without a license or targeting Isle of Man residents without proper authorisation. These are a form of enforcement but are directed at unregistered entities rather than penalties for registered DLT firms.

licensing 60% confidence

Preventative and Supervisory Approach: The IOMFSA often emphasizes a proactive supervisory approach, working with licensed entities to rectify issues before they escalate to formal public enforcement actions with substantial fines. This approach may result in fewer public "headline" enforcement actions.

licensing 60% confidence

Regulator: Isle of Man Financial Services Authority (IOMFSA)

aml 60% confidence

Designated Business Registration: Any entity carrying on a "designated business" activity involving virtual assets must register with the IOM FSA. This explicitly includes providing safe custody or storage of virtual assets.

aml 60% confidence

Issuing, transmitting, transferring, providing safe custody or storage, administering, managing, lending, buying, selling, or otherwise dealing with virtual assets.

aml 60% confidence

Designated Businesses (Registration and Oversight) Act 2015: https://www.legislation.gov.im/cms/images/stories/Acts/2015/Designated_Businesses_(Registration_and_Oversight)_Act_2015.pdf_Act_2015.pdf)

aml 60% confidence

IOM FSA AML/CFT Handbook (specifically Section 4.5 Virtual Asset Businesses): https://www.iomfsa.im/media/1908/amlcft-handbook-december-2023-version-8.pdf (Refer to the latest version available on the FSA website)

aml 60% confidence

AML/CFT Code 2019: Requires designated businesses to have robust internal controls, record-keeping, and risk management systems. This implicitly demands a clear distinction and proper accounting for client assets versus firm assets to prevent commingling and facilitate accurate reporting.

enforcement 60% confidence

Outcome: No specific, publicly documented cases matching all criteria were found within the specified timeframe.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a foreign-incorporated remote VASP may serve Isle of Man residents only if it registers as a Designated Business under DBROA 2015 with the IOMFSA, establishes robust AML/CFT compliance, satisfies fit-and-proper and governance requirements, and submits to IOMFSA oversight; unlicensed remote servicing carries material enforcement risk (public warnings, potential fines).

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?