Remote VASP serving residents in Italy
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Italy without local incorporation, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Mandatory AML/KYC compliance under Legislative Decree No. 231/2007 and Legislative Decree No. 204/2024 (formally includes CASPs)
- Registration with OAM (Organismo per la gestione degli elenchi di Agenti e Mediatori) required — mandatory under Ministerial Decree January 17, 2022 for virtual currency services
- Travel Rule compliance required under MiCA aligning with EU/AMLD5
- Transaction monitoring and Suspicious Activity Reporting (SAR) mandatory
- CASP authorization (post-MiCA from June 30, 2025) from Bank of Italy (custody/ARTs/EMTs) or CONSOB (exchanges/platforms) with fit-and-proper, governance, AML policies
- Sanctions screening against EU Consolidated Financial Sanctions List, OFAC SDN List (extraterritorial), and UN lists; must block and report
- Capital requirement: €50,000–€150,000 minimum scaled by services/risks
- Asset segregation and consumer protection obligations under MiCA
Key Restrictions
- Cross-border remote service without a local entity is permissible only via EU-wide MiCA passporting — the operator must be authorized as a CASP in one EU member state and then passported into Italy
- Pre-MiCA (until ~June 30, 2025): OAM registration is mandatory; no full license but the foreign entity must register with OAM to serve Italian residents
- Post-MiCA (from June 30, 2025): Full CASP authorization required; transitional grace for existing OAM-registered operators until December 30, 2025
- No explicit requirement for a local branch/entity due to passporting regime, but Italian authorities oversee and require governance/board transparency
- Existing OAM-registered VASPs must transition by applying before June 30, 2025 (new ops) or December 30, 2025 (extension)
Key Risks
- Unlicensed remote operation serving Italian residents without OAM registration (pre-MiCA) or CASP authorization (post-MiCA) carries fines up to €5 million or 3% of annual turnover for companies, and up to €700,000 for individuals
- Risk of suspension or revocation of business authorization for non-compliance
- OFAC extraterritorial enforcement applies regardless of Italian/EU licensing status — strict liability for SDN-linked crypto
- Transition period ambiguity: operators must track deadlines (June 30, 2025 and December 30, 2025) precisely to avoid enforcement gap
- Regulatory overlap between Bank of Italy and CONSOB may create complexity in determining which authority to apply to
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
MiCA Regulation (EU) 2023/1114: https://www.boccadutri.com/micar-european-regulation-on-crypto-assets/
Legislative Decree No. 129/2024: https://www.lightspark.com/knowledge/is-crypto-legal-in-italy ; https://cms.law/en/int/expert-guides/cms-expert-guide-to-crypto-regulation/italy
Decree No. 218/2024 (effective Jan 1, 2025): https://www.binance.com/en/square/post/33345454531865
Pre-MiCA (until ~June 2025): Registration-only with OAM for VASPs (exchanges, custody); no full license needed but mandatory AML/KYC compliance. Investors urged to use registered firms.
Post-MiCA (from June 30, 2025): Licensing regime via CASP authorization; single EU passporting allows operation across member states without per-country re-licensing. Transitional grace until Dec 30, 2025, for existing operators.
Capital: €50,000–€150,000 minimum, scaled by services/risks.
AML/KYC: Strict compliance mandatory (Travel Rule, transaction monitoring, suspicious activity reporting); aligns with AMLD5 and GDPR for data protection.
Local Presence/Governance: Transparent ownership; board with finance/compliance experience; risk management systems; independent compliance/audit functions. No explicit branch required due to passporting, but Italian authorities oversee.
Other: Asset segregation, consumer protection, market abuse prevention.
Prepare documentation: Governance plans, fit-and-proper assessments for management/owners, capital proof, AML policies, risk systems.
Lodge with competent authority (Bank of Italy for custody/ARTs/EMTs; Consob for exchanges/platforms).
Undergo review for compliance; authorization grants EU-wide passporting.
Existing OAM-registered VASPs transition by applying before deadlines (June 30, 2025, for new ops; Dec 30, 2025, extension).
Primary Legislation: Regulation (EU) 2023/1114 — Markets in Crypto-Assets (MiCA)
Italian Implementation: Legislative Decree 2024 (approved to adapt national legislation to MiCA requirements); Law Decree 95/2025 (extending VASP registration deadlines)
Primary Supervisory Authority: Bank of Italy (financial stability, systemic risk, cross-border issuance)
Secondary Authority: CONSOB (securities-related aspects, investor protection, MiCAR disclosure compliance)
Consob (Commissione Nazionale per le Società e la Borsa): Oversees investor protection and market integrity; authorizes crypto-asset service providers (CASPs) for most crypto-assets (excluding asset-referenced tokens (ARTs) and e-money tokens (EMTs)).
Bank of Italy (Banca d'Italia): Authorizes issuance of ARTs and EMTs; handles prudential supervision, financial stability, and AML compliance for CASPs.
Legislative Decree No. 129 (effective September 2024): Transposes EU MiCA into Italian law, regulating issuance and trading of crypto-assets, including ARTs and EMTs, with requirements for authorization, asset segregation, and consumer protection.
CONSOB: Oversees securities-related aspects and ensures investor protection compliance with MiCAR disclosure rules.
Primary national law: Legislative Decree No. 231/2007, the core Italian AML/CFT framework, transposed from EU AML Directives (e.g., 2015/849 as amended by 2018/843), covering prevention of money laundering and terrorist financing via the financial system.
Legislative Decree No. 129/2024 (effective September 2024), aligning with EU MiCAR for CASP authorization and operations.
Legislative Decree No. 204/2024 (December 2024), amending AML Law to formally include CASPs.
Ministerial Decree (January 17, 2022), requiring registration with OAM for virtual currency services (e.g., exchanges, e-wallets) operating in Italy, implementing EU rules on virtual assets.
EU alignments: 5th AMLD (2018/843) and TFR recast extend rules to virtual assets and wallet providers.
OFAC: Applies to all U.S. persons and has extraterritorial reach; VASPs must block cryptoassets linked to SDN-listed persons/entities (including wallet addresses) and report to OFAC. Strict liability applies, with no crypto exceptions.
EU/UN: Integrated into MiCA and Italian AML rules; screening prevents dealings with sanctioned parties, with Travel Rule enhancing controls for crypto transfers.
EU Consolidated Financial Sanctions List
MiCA Regulation: EU Regulation 2023/1114 – https://eur-lex.europa.eu/eli/reg/2023/1114/oj
Italian MiCA Decree: Legislative Decree no. 129/2024 – https://www.gazzettaufficiale.it/ (search decree)
OAM VASP Register: https://www.organismo-am.it/
OFAC SDN: https://sanctionssearch.ofac.treasury.gov/
Fines up to €5 million or 3% of annual turnover for companies
Suspension or revocation of business authorization
Up to €700,000 for individuals
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign-incorporated remote VASP may serve Italian residents either through pre-MiCA OAM registration (until June 30, 2025) or post-MiCA CASP authorization with EU-wide passporting (from June 30, 2025), with no explicit local entity requirement but full AML/KYC, Travel Rule, sanctions screening, and capital adequacy obligations applying in both regimes.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?