Remote VASP serving residents in Iceland
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Iceland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration required with Central Bank of Iceland under Act No. 140/2018 (transposing AMLD5) for any entity providing virtual asset services to residents
- CDD/KYC obligations under the Act on Measures Against Money Laundering and Terrorist Financing No. 140/2018
- Ongoing transaction monitoring and record-keeping requirements
- Beneficial ownership identification and record-keeping
- Suspicious Transaction Report (STR) filing obligations to the Central Bank
- Under MiCA (Regulation EU 2023/1114), once implemented: full CASP authorization required with prudential safeguards — own funds (capital requirements) or an insurance policy per Annex IV thresholds (Article 66, point 10 and Article 67, point 7)
- Under MiCA: strict segregation of client crypto-assets from own assets (Article 67, point 1)
- Under MiCA: robust security policies and procedures for private key management, asset protection (Article 67, point 2)
Key Restrictions
- Cross-border remote service (no local entity) is not permissible — any entity serving residents must register as a VASP with the Central Bank of Iceland
- A local entity (or at minimum a VASP registration with Icelandic nexus) is required to lawfully serve residents
- Under MiCA (taking effect): full CASP authorization required — a full financial services license, not merely AML registration
- No specific exemption for foreign-incorporated entities providing services from abroad without local presence
Key Risks
- Enforcement risk for unlicensed remote operators: while Iceland has not publicly announced major enforcement actions against crypto firms in recent years, the legal framework (Act No. 140/2018) criminalizes unregistered VASP activity
- Regulatory ambiguity remains around the precise territorial scope — whether foreign entities need to be incorporated in Iceland or merely registered; facts are not explicit on this point
- MiCA transition: obligations will shift from AML-registration to full CASP authorization with heightened capital and prudential requirements, creating compliance timeline risk
- No specific insurance or bonding requirements under current AML framework, but general business insurance expectations apply — risk of underinsurance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulator: The primary financial regulator is now the Seðlabanki Íslands (Central Bank of Iceland), which absorbed the functions of the former Financial Supervisory Authority (Fjármálaeftirlitið, FME) in January 2020. It is responsible for supervising financial undertakings, including those dealing with virtual assets, primarily from an AML/CFT perspective.
Focus: The Central Bank's focus has been on implementing AML/CFT regulations for Virtual Asset Service Providers (VASPs), aligning with FATF recommendations and EU directives. They require VASPs to register and comply with the AML/CFT Act.
VASP Registration: Any entity providing services related to virtual assets, including the safekeeping and/or administration of virtual assets on behalf of customers (i.e., custody), is required to register as a Virtual Asset Service Provider (VASP) with the Central Bank of Iceland. This is not a "license" in the traditional sense of financial services but rather an AML/CFT registration that imposes significant obligations.
The registration is mandated by the Act on measures to combat money laundering and terrorist financing No. 140/2018, which transposes EU AML Directives (AMLD5, soon AMLD6) into Icelandic law.
Scope: This typically covers situations where the custodian holds private keys and has control over clients' virtual assets.
Act on measures to combat money laundering and terrorist financing No. 140/2018: https://www.althingi.is/lagas/nuna/2018140.html (Icelandic original)
Central Bank of Iceland - AML/CFT: https://www.cb.is/financial-supervision/aml-cft/
The AML Act requires VASPs to keep records of transactions and to identify beneficial owners, indirectly supporting the need for clear asset ownership distinctions.
MiCA Authorization: Under MiCA, "custody and administration of crypto-assets on behalf of clients" is explicitly defined as a crypto-asset service (Article 3, point 16). Providers of this service will be required to obtain authorization from their competent national authority (in Iceland, likely the Central Bank of Iceland) to operate as a Crypto-Asset Service Provider (CASP) (Article 59).
This authorization is a full financial services license, distinct from the current AML registration.
Mandatory Segregation: MiCA explicitly mandates strict segregation of client assets.
Article 67 (Obligations of crypto-asset service providers providing custody and administration of crypto-assets on behalf of clients), point 1: "A crypto-asset service provider providing custody and administration of crypto-assets on behalf of clients shall ensure that the crypto-assets of its clients are segregated from its own assets and from the assets of other clients."
Prudential Safeguards: MiCA (Article 66, point 10 and Article 67, point 7) requires CASPs to have robust prudential safeguards. These safeguards can take the form of:
Own funds (capital requirements).
An insurance policy.
Article 67, point 2: "A crypto-asset service provider providing custody and administration of crypto-assets on behalf of clients shall establish, implement and maintain robust security policies and procedures regarding the access to, and the protection of, the crypto-assets, private cryptographic keys and, where applicable, the means of access to the crypto-assets of its clients."
No Publicly Announced Major Actions: Unlike larger countries where regulatory bodies regularly announce fines or other penalties against specific crypto firms for violations, Iceland has not had such public announcements in the last three years. This doesn't mean there are no regulatory activities, but rather that any actions taken may be less "significant" in the public domain (e.g., private warnings, compliance orders, or smaller, non-public fines) or against individuals rather than companies, or relate to older cases outside the requested timeframe.
Criminal Cases: While there haven't been public administrative actions from the financial regulator, criminal cases involving cryptocurrency fraud or theft can occur, handled by the police and prosecutors. However, such cases are typically against individuals for criminal offenses rather than administrative enforcement against a regulated entity, and no major, widely publicized criminal actions against a crypto company have emerged in the last 3 years that would fit "enforcement action" in the regulatory sense. The prominent "Cloud Mining" Ponzi scheme was investigated and prosecuted years ago, outside the specified 3-year window.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign remote VASP cannot serve Icelandic residents from abroad without registering as a VASP with the Central Bank of Iceland under Act No. 140/2018; a local entity or at minimum a formal registration nexus is required, and once MiCA is fully effective, a full CASP license (capital-intensive) will be mandatory.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?