Remote VASP serving residents in Isle of Man
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Isle of Man with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the IOMFSA under the Designated Business (Registration and Oversight) Act 2015 (DBROA) is mandatory for any entity carrying on a 'designated business' activity involving virtual assets.
- Must implement robust AML/CFT policies and procedures under the AML/CFT Code (2015/2019) and IOM FSA AML/CFT Handbook.
- Conduct risk-based Customer Due Diligence (CDD): identify and verify identity of customers and beneficial owners, understand purpose and intended nature of business relationships.
- Ongoing monitoring of business relationships required.
- Maintain separate accounts or records clearly distinguishing client virtual assets from firm assets.
- Implement internal controls to prevent misuse or misappropriation of client assets.
- Establish clear procedures for return of client assets in case of business failure or cessation.
- Fit and proper persons (directors, beneficial owners, key personnel) must be demonstrated.
- Adequate financial resources, robust governance arrangements, and operational resilience/risk management frameworks required.
- Record-keeping and risk management systems required under AML/CFT Code 2019.
Key Restrictions
- Foreign-incorporated entity cannot serve Isle of Man residents remotely without first registering as a Designated Business with the IOMFSA.
- Requires a local business presence/registration — registration under DBROA effectively requires the operator to be subject to IOMFSA oversight.
- Must demonstrate fit and proper persons (directors, beneficial owners) — likely requiring local substance or at least local directors.
- VASP activities covered include exchange (fiat-crypto and crypto-crypto), custody/safekeeping, payment processing/transfer services, and participation in offers/sales of virtual assets — all require registration.
Key Risks
- IOMFSA frequently issues public warnings against entities operating without a license or targeting Isle of Man residents without proper authorisation — enforcement risk for unregistered remote operators is high.
- Regulatory ambiguity remains around whether purely remote (no physical presence) service can ever satisfy IOMFSA's fit-and-proper and governance expectations.
- No specific publicly documented enforcement cases were found matching this exact model, but IOMFSA takes a proactive supervisory approach and issues warnings against unlicensed operators.
- Cross-border service without registration could lead to public warning, potential fines, or being named on IOMFSA warnings list.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Designated Business (Registration and Oversight) Act 2015 (DBROA): This Act provides the framework for the registration and oversight of businesses engaged in certain activities, including those involving virtual assets.
DBROA 2015: https://www.legislation.gov.im/cms/images/LEGISLATION/PRINCIPAL/2015/2015-0027/DesignatedBusinessRegistrationandOversightAct2015_1.pdf
Anti-Money Laundering and Countering the Financing of Terrorism Code 2015 (AML/CFT Code): This Code sets out the specific AML/CFT obligations for Designated Businesses.
AML/CFT Code 2015: https://www.legislation.gov.im/cms/images/LEGISLATION/PRINCIPAL/2015/2015-0029/Anti-MoneyLaunderingandCounteringtheFinancingofTerrorismCode2015_1.pdf
AML/CFT Handbook: The IOM FSA publishes a comprehensive handbook that provides guidance on how Designated Businesses should comply with their AML/CFT obligations.
Virtual Asset Service Providers (VASPs): A person carrying on the business of providing any of the following services to, or on behalf of, another person:
Exchanges: Exchanging virtual assets for fiat currencies, or one or more forms of virtual assets. This covers both fiat-to-crypto and crypto-to-crypto exchanges.
Custody Providers: Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets. This includes businesses that hold private keys on behalf of clients.
Payment Processors: Services related to the transfer of virtual assets. This covers facilitating payments in crypto, or services that move virtual assets from one address or account to another.
AML/KYC Compliance: This is the cornerstone of the IOM's regulatory approach. Registered businesses must implement robust AML/CFT policies and procedures, including:
Risk-Based Approach: Identifying, assessing, and understanding money laundering and terrorist financing risks.
Customer Due Diligence (CDD):
Identifying and verifying the identity of customers and beneficial owners.
Ongoing monitoring of business relationships.
Warnings Against Unlicensed Activity: The IOMFSA frequently issues public warnings against entities operating without a license or targeting Isle of Man residents without proper authorisation. These are a form of enforcement but are directed at unregistered entities rather than penalties for registered DLT firms.
Preventative and Supervisory Approach: The IOMFSA often emphasizes a proactive supervisory approach, working with licensed entities to rectify issues before they escalate to formal public enforcement actions with substantial fines. This approach may result in fewer public "headline" enforcement actions.
Regulator: Isle of Man Financial Services Authority (IOMFSA)
Designated Business Registration: Any entity carrying on a "designated business" activity involving virtual assets must register with the IOM FSA. This explicitly includes providing safe custody or storage of virtual assets.
Virtual Asset Activities Covered: The definition of "virtual assets" and the activities that constitute "designated business" are broad and cover:
Exchanging, or arranging or making arrangements for the exchange of, virtual assets for fiat currencies or other virtual assets.
Issuing, transmitting, transferring, providing safe custody or storage, administering, managing, lending, buying, selling, or otherwise dealing with virtual assets.
Application Process: Applicants must demonstrate:
Fit and proper persons (directors, beneficial owners, key personnel).
Robust governance arrangements.
Adequate financial resources.
Comprehensive AML/CFT policies, procedures, and controls.
Operational resilience and risk management frameworks.
Designated Businesses (Registration and Oversight) Act 2015: https://www.legislation.gov.im/cms/images/stories/Acts/2015/Designated_Businesses_(Registration_and_Oversight)_Act_2015.pdf_Act_2015.pdf)
IOM FSA AML/CFT Handbook (specifically Section 4.5 Virtual Asset Businesses): https://www.iomfsa.im/media/1908/amlcft-handbook-december-2023-version-8.pdf (Refer to the latest version available on the FSA website)
AML/CFT Code 2019: Requires designated businesses to have robust internal controls, record-keeping, and risk management systems. This implicitly demands a clear distinction and proper accounting for client assets versus firm assets to prevent commingling and facilitate accurate reporting.
General Principles: The IOM FSA expects firms to protect client assets. This means:
Maintaining separate accounts or records that clearly distinguish client virtual assets from the firm's own assets.
Implementing internal controls to prevent the misuse or misappropriation of client assets.
Ensuring that client assets are not used to satisfy the firm's debts or liabilities.
Having clear procedures for the return of client assets in case of business failure or cessation.
Outcome: No specific, publicly documented cases matching all criteria were found within the specified timeframe.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign-incorporated remote VASP may serve Isle of Man residents only if it registers as a Designated Business under DBROA 2015 with the IOMFSA, establishes robust AML/CFT compliance, satisfies fit-and-proper and governance requirements, and submits to IOMFSA oversight; unlicensed remote servicing carries material enforcement risk (public warnings, potential fines).
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?