Custodial wallet / SaaS in Italy
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Italy without local incorporation, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CASP authorization under MiCA (Regulation EU 2023/1114) — full application to Bank of Italy or CONSOB with governance plans, fit-and-proof assessments, capital proof, AML policies, and risk systems
- AML/KYC strict compliance under Legislative Decree No. 231/2007 as amended by Legislative Decree No. 204/2024 (formally includes CASPs)
- Travel Rule (TFR recast) — must accompany crypto transfers with originator/beneficiary information
- Suspicious transaction reporting to Italian Financial Intelligence Unit (UIF)
- Registration with OAM (Organismo Agenti e Mediatori) VASP Register — transitional regime until full MiCA authorization
- OFAC SDN screening (extraterritorial — U.S. sanctions apply with strict liability)
- EU Consolidated Financial Sanctions List screening
- UN sanctions list screening
- Consumer protection rules — asset segregation requirements under Legislative Decree No. 129/2024
Key Restrictions
- Must obtain CASP authorization from Bank of Italy or CONSOB (depending on asset type) by June 30, 2025, or transition existing OAM registration by Dec 30, 2025
- Minimum capital of €50,000–€150,000 scaled by services and risk profile
- Asset segregation required — customer crypto assets must be kept separate from operator's own assets
- Transparent ownership and governance: board with finance/compliance experience, independent compliance/audit functions
- White-label client (the SaaS customer) may itself be a regulated entity — AML obligations may attach at both the SaaS provider and the white-label client level depending on operational structure
- Proof-of-reserves and consumer protection requirements under MiCA and Italian implementation
- No explicit local incorporation required due to EU passporting, but Bank of Italy retains supervisory oversight over Italian operations
Key Risks
- Transition cliff: operators relying on pre-MiCA OAM registration must obtain full CASP authorization by Dec 30, 2025, or cease operations
- Regulatory ambiguity on allocation of AML obligations between custodial SaaS provider and white-label client — dual liability possible
- Fines up to €5 million or 3% of annual turnover (companies); up to €700,000 (individuals); suspension or revocation of authorization
- OFAC extraterritorial enforcement risk — strict liability for SDN-screened crypto addresses with no crypto exception
- Italian authorities (Bank of Italy/CONSOB) may impose additional national requirements beyond MiCA baseline during implementation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
MiCA Regulation (EU) 2023/1114: https://www.boccadutri.com/micar-european-regulation-on-crypto-assets/
Legislative Decree No. 129/2024: https://www.lightspark.com/knowledge/is-crypto-legal-in-italy ; https://cms.law/en/int/expert-guides/cms-expert-guide-to-crypto-regulation/italy
Decree No. 218/2024 (effective Jan 1, 2025): https://www.binance.com/en/square/post/33345454531865
Pre-MiCA (until ~June 2025): Registration-only with OAM for VASPs (exchanges, custody); no full license needed but mandatory AML/KYC compliance. Investors urged to use registered firms.
Post-MiCA (from June 30, 2025): Licensing regime via CASP authorization; single EU passporting allows operation across member states without per-country re-licensing. Transitional grace until Dec 30, 2025, for existing operators.
Capital: €50,000–€150,000 minimum, scaled by services/risks.
AML/KYC: Strict compliance mandatory (Travel Rule, transaction monitoring, suspicious activity reporting); aligns with AMLD5 and GDPR for data protection.
Local Presence/Governance: Transparent ownership; board with finance/compliance experience; risk management systems; independent compliance/audit functions. No explicit branch required due to passporting, but Italian authorities oversee.
Other: Asset segregation, consumer protection, market abuse prevention.
Prepare documentation: Governance plans, fit-and-proper assessments for management/owners, capital proof, AML policies, risk systems.
Lodge with competent authority (Bank of Italy for custody/ARTs/EMTs; Consob for exchanges/platforms).
Undergo review for compliance; authorization grants EU-wide passporting.
Existing OAM-registered VASPs transition by applying before deadlines (June 30, 2025, for new ops; Dec 30, 2025, extension).
Primary Legislation: Regulation (EU) 2023/1114 — Markets in Crypto-Assets (MiCA)
Italian Implementation: Legislative Decree 2024 (approved to adapt national legislation to MiCA requirements); Law Decree 95/2025 (extending VASP registration deadlines)
Primary Supervisory Authority: Bank of Italy (financial stability, systemic risk, cross-border issuance)
Secondary Authority: CONSOB (securities-related aspects, investor protection, MiCAR disclosure compliance)
Consob (Commissione Nazionale per le Società e la Borsa): Oversees investor protection and market integrity; authorizes crypto-asset service providers (CASPs) for most crypto-assets (excluding asset-referenced tokens (ARTs) and e-money tokens (EMTs)).
Bank of Italy (Banca d'Italia): Authorizes issuance of ARTs and EMTs; handles prudential supervision, financial stability, and AML compliance for CASPs.
Legislative Decree No. 129 (effective September 2024): Transposes EU MiCA into Italian law, regulating issuance and trading of crypto-assets, including ARTs and EMTs, with requirements for authorization, asset segregation, and consumer protection.
CONSOB: Oversees securities-related aspects and ensures investor protection compliance with MiCAR disclosure rules.
Primary national law: Legislative Decree No. 231/2007, the core Italian AML/CFT framework, transposed from EU AML Directives (e.g., 2015/849 as amended by 2018/843), covering prevention of money laundering and terrorist financing via the financial system.
Legislative Decree No. 129/2024 (effective September 2024), aligning with EU MiCAR for CASP authorization and operations.
Legislative Decree No. 204/2024 (December 2024), amending AML Law to formally include CASPs.
Ministerial Decree (January 17, 2022), requiring registration with OAM for virtual currency services (e.g., exchanges, e-wallets) operating in Italy, implementing EU rules on virtual assets.
EU alignments: 5th AMLD (2018/843) and TFR recast extend rules to virtual assets and wallet providers.
OFAC: Applies to all U.S. persons and has extraterritorial reach; VASPs must block cryptoassets linked to SDN-listed persons/entities (including wallet addresses) and report to OFAC. Strict liability applies, with no crypto exceptions.
EU/UN: Integrated into MiCA and Italian AML rules; screening prevents dealings with sanctioned parties, with Travel Rule enhancing controls for crypto transfers.
EU Consolidated Financial Sanctions List
OFAC SDN List (including crypto addresses)
MiCA Regulation: EU Regulation 2023/1114 – https://eur-lex.europa.eu/eli/reg/2023/1114/oj
Italian MiCA Decree: Legislative Decree no. 129/2024 – https://www.gazzettaufficiale.it/ (search decree)
OAM VASP Register: https://www.organismo-am.it/
Fines up to €5 million or 3% of annual turnover for companies
Suspension or revocation of business authorization
Up to €700,000 for individuals
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Custodial wallet/SaaS providers may operate in Italy under MiCA by obtaining CASP authorization (Bank of Italy or CONSOB) with minimum capital €50k–€150k, asset segregation, strict AML/KYC including Travel Rule, and OAM registration transition by Dec 30, 2025; EU passporting available, but AML obligations may attach at both the SaaS provider and white-label client level.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?