Custodial wallet / SaaS in Jersey
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Jersey with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration as a Designated Business under the Designated Business (Registration and Oversight) (Jersey) Law 2019 is required for the custodial wallet/SaaS provider as a VASP.
- Full CDD on all customers — obtain reliable independent evidence of identity (government-issued photo ID, proof of address) for natural persons.
- For legal-entity customers, obtain details of legal status, constitution, and powers; identify and verify UBOs (typically 25%+ ownership or control).
- Ongoing transaction monitoring — continuously scrutinize transactions to ensure consistency with customer knowledge, business, and risk profile.
- Ongoing due diligence — keep customer identity data up-to-date; periodic review of existing relationships, especially for high-risk clients.
- Enhanced due diligence for PEPs (senior foreign/domestic public officials, family, close associates) — mandatory enhanced scrutiny of transactions and source of wealth/funds.
- Enhanced due diligence for customers/transactions involving high-risk jurisdictions identified by FATF or JFSC.
- Suspicious Activity Reporting (SAR) obligations under the Proceeds of Crime (Jersey) Law 1999 and the Money Laundering (Jersey) Order 2008.
- Record-keeping obligations under the Money Laundering (Prevention and Detection of Money Laundering) (Jersey) Order 2008.
- AML/CFT Handbook compliance — VASPs must refer to JFSC AML/CFT Handbook for practical compliance interpretations.
- The white-label client (if itself a VASP or financial services business) also bears its own AML obligations; the SaaS provider may have obligations as a correspondent/servicer depending on the contractual allocation.
Key Restrictions
- Must register as a Designated Business with JFSC under the Designated Business (Registration and Oversight) (Jersey) Law 2019.
- If the custodial arrangement or the token held constitutes an 'investment product' (e.g., security tokens representing equity/debt, units in a collective investment fund), a traditional financial services licence under the Financial Services (Jersey) Law 1998 may also be required.
- The JFSC Guidance Notes for VASPs must be followed; compliance is assessed based on the economic reality of the arrangement, not merely the label.
- Local entity incorporation is required — Jersey registration as a Designated Business necessitates a Jersey-incorporated or registered entity.
- SaaS provider must have adequate governance, risk management, and AML/CFT systems and controls in place; failures can result in civil penalties and public statements (as seen in Volopa enforcement).
Key Risks
- JFSC enforcement is active and carries real penalties — Volopa (Jersey) Ltd received a civil financial penalty for AML/CFT systems breaches, demonstrating that weak controls will be sanctioned.
- Personal liability risk for MLROs and compliance officers — Ms Kateryna Sazonova was disqualified and publicly named for SAR failure.
- If the hosted tokens are classified as 'investment tokens' (security tokens), the operator may face dual regulation (Designated Business registration + FSJL licence), increasing complexity and cost.
- Ambiguity around whether the white-label client or the SaaS platform is primarily responsible for customer-facing AML obligations could create regulatory exposure for the SaaS provider if contracts are not clearly structured.
- No specific proof-of-reserves, segregation, or insurance requirements were identified in the provided facts — this regulatory gap creates uncertainty about prudential expectations for custodial wallet operators.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Proceeds of Crime (Jersey) Law 1999 (PCL): Defines money laundering and terrorist financing offences.
Money Laundering (Jersey) Order 2008 (MLO): Sets out the specific AML/CFT obligations for "financial services businesses" and "designated businesses."
Designated Business (Registration and Oversight) (Jersey) Law 2019: https://www.jerseylaw.je/laws/enacted/Pages/designated-business-(registration-and-oversight)-(jersey)-law-2019.aspx-(jersey)-law-2019.aspx)
Financial Services (Jersey) Law 1998 (FSJL): This law regulates traditional financial services. Certain virtual asset activities could, in specific circumstances, also fall under its scope, requiring a traditional licence (e.g., if a crypto offering constitutes a collective investment fund or an investment product).
JFSC Guidance Notes for Virtual Asset Service Providers (VASPs): (Crucial document!)
The Proceeds of Crime (Jersey) Law 1999 (as amended): This is the principal law creating offences related to money laundering and the financing of terrorism. It defines criminal conduct and the various money laundering offences.
The Money Laundering (Jersey) Law 2008 (as amended): This law establishes the preventative measures that financial services businesses (including VASPs) must take to combat money laundering and terrorist financing. It mandates compliance with the requirements set out in the Money Laundering Order.
The Money Laundering (Prevention and Detection of Money Laundering) (Jersey) Order 2008 (as amended) (the "ML Order"): This is the core regulatory instrument that specifies the detailed AML/CFT requirements for financial services businesses, including customer due diligence, reporting, record-keeping, and internal controls.
The Terrorism (Jersey) Law 2011 (as amended): This law creates offences related to terrorist financing and provides for asset freezing and other measures to combat terrorism.
JFSC AML/CFT Handbook: While not primary legislation, the JFSC's AML/CFT Handbook is a critical guidance document that provides practical advice and interpretations of the statutory requirements, demonstrating how businesses should comply. VASPs must refer to the relevant sections of this handbook.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Obtain reliable independent evidence of the customer's identity (e.g., government-issued photo ID, proof of address).
For legal entities, obtain details of the company's legal status, constitution, and powers.
Identify the ultimate beneficial owner (UBO) of the customer, including natural persons who ultimately own or control the customer (typically holding 25% or more of shares or voting rights, or exercising control through other means).
Understanding the Purpose and Nature of the Business Relationship:
Obtain information about the customer's business activities, the source of funds and source of wealth (particularly for high-risk customers or high-value transactions), and the intended purpose and nature of the VASP relationship.
Continuously scrutinize transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keep customer information, including identity data, up-to-date and relevant.
Review existing customer relationships periodically, especially for high-risk clients.
Politically Exposed Persons (PEPs): Senior foreign and domestic public officials, their family members, and close associates. Enhanced scrutiny of transactions and source of wealth/funds is mandatory.
High-Risk Jurisdictions: Customers or transactions involving countries identified by FATF or the JFSC as having inadequate AML/CFT regimes.
Regulator Name: Jersey Financial Services Commission (JFSC)
Entity Targeted: Volopa (Jersey) Limited (an e-money institution). Violation Type: Significant and systemic breaches of the Money Laundering (Jersey) Order 2008 concerning its AML/CFT systems and controls. This included failures in client due diligence, transaction monitoring, and governance. While not explicitly stated as crypto-specific, e-money institutions often facilitate transactions that can involve virtual assets, making robust AML controls crucial in this space. Penalty Amount: £395,097 (civil financial penalty).
Outcome: Imposition of a civil financial penalty and requirement to implement remediation measures.
Entity Targeted: Ms Kateryna Sazonova (former Money Laundering Reporting Officer (MLRO) and Compliance Officer for a licensed trust company). Violation Type: Failure to make a Suspicious Activity Report (SAR) regarding a client whose funds were identified as proceeds of a cyber fraud. Cyber fraud frequently involves the use of virtual assets for the movement and concealment of illicit funds, making this action highly relevant to the crypto space indirectly. Penalty Amount: Prohibited from performing any function as a Money Laundering Reporting Officer, Compliance Officer, or Principal Person for any person registered under regulatory laws in Jersey. No specific financial penalty was imposed on her in this public statement.
Outcome: Public statement issued, disqualification from holding key positions in regulated entities in Jersey.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS provider in Jersey must register as a Designated Business with the JFSC under the Designated Business (Registration and Oversight) (Jersey) Law 2019 and comply with the full ML Order AML/CFT framework; may also require a traditional FSJL licence if the hosted assets constitute investment products; local entity required and regulatory enforcement is active.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?