Remote VASP serving residents in Kyrgyzstan
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Kyrgyzstan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Law No. 200 'On the Turnover of Virtual Assets' (Aug 2022) designates VASPs as obliged entities — remote operators serving residents are captured.
- Customer Due Diligence (CDD) mandatory: full name, DOB, citizenship, address, ID documents for individuals; legal form, registration, TIN, beneficial owners for legal entities (kg.licensing.identification-and-verification, kg.licensing.for-individuals-full-name-date, kg.licensing.for-legal-entities-full-name)
- Beneficial ownership identification required at 25% or other threshold (kg.licensing.beneficial-ownership-identification-vasps-must)
- Risk-based approach: EDD for PEPs, high-risk jurisdictions; SDD permitted for low risk (kg.licensing.risk-based-approach-vasps-must-adopt)
- Ongoing monitoring of transactions and business relationships (kg.licensing.ongoing-monitoring-continuously-monitoring-the)
- Suspicious transaction reporting — must report immediately without delay if suspicion arises, regardless of amount; no tipping-off (kg.licensing.obligation-to-report-if-a, kg.licensing.no-tipping-off-vasps-and-their, kg.licensing.timelines-reports-should-typically-be)
- FATF Travel Rule applies: originator name, account/identifier, address or ID number; beneficiary name and account/identifier for transfers above threshold (expected ~USD/EUR 1,000) (kg.aml.core-requirement-vasps-in-kyrgyzstan, kg.aml.originator-information-name-account-number, kg.aml.beneficiary-information-name-account-number, kg.aml.fatf-standard-threshold-the-fatf)
- Record-keeping for minimum 5 years from transaction or account closure (kg.licensing.retention-period-records-must-generally)
- Supervised by the State Service for Financial Intelligence (SSFI) under the Ministry of Finance (kg.licensing.the-state-service-for-financial, kg.licensing.role-the-ssfi-acts-as)
Key Restrictions
- VASP is defined as a legal entity — foreign-incorporated firms with no Kyrgyz entity may not be recognized as a lawful operator; a local legal entity is effectively required (kg.aml.the-law-no-200-on)
- No specific licensing law for remote cross-border VASPs exists yet — the framework contemplates licensed domestic entities, not unregistered foreign ones (kg.aml.key-legislation-the-primary-law, kg.licensing.evolving-landscape-the-regulatory-landscape)
- The NBKR has issued repeated public warnings that cryptocurrencies are not legal tender and carry risks — operating without a license would be contrary to these warnings (kg.enforcement.regulator-name-national-bank-of, kg.enforcement.entity-targeted-the-general-public)
- FATF Travel Rule compliance requires technical integration (e.g., TRISA, Sygna) — cannot be satisfied by simply ignoring cross-border transfer obligations (kg.aml.implementation-vasps-are-expected-to)
Key Risks
- No established licensing pathway for a foreign-entity remote VASP — legal basis exists under Law No. 200 but implementing regulations for foreign operators may be incomplete or absent (kg.licensing.evolving-landscape-the-regulatory-landscape)
- Enforcement risk: SCNS and MVD aggressively pursue unlicensed crypto operations (mining farm seizures, criminal proceedings) — analogous risk for unregistered VASPs (kg.enforcement.regulatorenforcing-agency-state-committee-for, kg.enforcement.december-2023-scns-reported-neutralizing)
- Pyramid-scheme enforcement precedent (S-Group) shows authorities will pursue fraud-related crypto activities aggressively (kg.enforcement.entity-targeted-organizers-and-promoters)
- Ambiguity on licensing authority: unclear which body will issue VASP licenses (SSFI vs. NBKR vs. a future regulator) (kg.licensing.national-bank-of-the-kyrgyz, kg.licensing.evolving-landscape-the-regulatory-landscape)
- Potential penalties include significant fines, license suspension/revocation, and criminal proceedings (kg.aml.administrative-fines-significant-monetary-penalties, kg.aml.suspension-or-revocation-of-licenses)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law of the Kyrgyz Republic on Combating the Financing of Terrorism and Legalization (Laundering) of Criminal Proceeds (No. 87, dated July 25, 2011, with subsequent amendments). This law establishes the legal and organizational framework for AML/CFT, defines the obligations of reporting entities, and outlines the role of the financial intelligence unit.
Key Legislation: The primary law is the Law of the Kyrgyz Republic No. 200 "On the Turnover of Virtual Assets" dated August 10, 2022. This law provides the legal basis for the regulation of virtual assets and designates VASPs as obliged entities for AML/CFT purposes.
Effective Date: The Law No. 200 became effective shortly after its promulgation in August 2022. This integration means VASPs are now subject to the broader AML/CFT legislation of Kyrgyzstan, including reporting requirements.
The Law No. 200 "On the Turnover of Virtual Assets" broadly defines and covers entities engaged in activities related to virtual assets. It defines a "Virtual Asset Service Provider" (VASP) as a legal entity carrying out one or more of the following activities for or on behalf of another natural or legal person:
The State Service for Financial Intelligence (SSFI) under the Ministry of Finance of the Kyrgyz Republic.
Role: The SSFI acts as Kyrgyzstan's Financial Intelligence Unit (FIU). It is responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies, as well as for developing and implementing AML/CFT policies and overseeing compliance by reporting entities.
Evolving Landscape: The regulatory landscape for virtual assets is constantly evolving globally and in Kyrgyzstan. VASPs should monitor for any new specific laws, regulations, or guidance related to cryptocurrencies issued by the SSFI or the National Bank of the Kyrgyz Republic.
National Bank of the Kyrgyz Republic (NBKR): While the SSFI is the primary AML/CFT supervisor, the NBKR also plays a crucial role in maintaining financial stability and overseeing the financial sector. The NBKR has historically issued warnings regarding the risks of cryptocurrencies. Any future comprehensive regulatory framework for VASPs might involve the NBKR, especially if virtual assets are classified as financial instruments or securities.
Core Requirement: VASPs in Kyrgyzstan are required to obtain, hold, and transmit required originator (sender) and beneficiary (receiver) information for virtual asset transfers that meet the specified thresholds.
FATF Standard Threshold: The FATF Travel Rule generally applies to virtual asset transfers (transactions) exceeding USD/EUR 1,000 (or its equivalent in virtual assets) for cross-border transfers and USD/EUR 1,000 (or its equivalent) if the transaction is domestic and not part of a pre-existing business relationship where the customer has been verified. For unhosted wallets, the guidance usually suggests due diligence for transactions above a certain threshold (e.g., USD/EUR 1,000), but the Travel Rule itself focuses on VASP-to-VASP transfers.
Originator Information: Name, account number (or unique transaction identifier), physical address, national identity number, customer identification number, or date and place of birth.
Beneficiary Information: Name, account number (or unique transaction identifier).
For individuals: Full name, date and place of birth, citizenship, residential address, identification document details (e.g., passport, national ID number). Verification through reliable, independent sources (e.g., government-issued documents, utility bills).
For legal entities: Full name, legal form, registration number, legal address, tax identification number (TIN), details of beneficial owners, directors, and authorized signatories. Verification through company registration documents, articles of association, and public registries.
Beneficial Ownership Identification: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including those who ultimately own or control the customer, or the person on whose behalf a transaction is being conducted. Thresholds (e.g., 25% ownership or control) typically apply.
Risk-Based Approach: VASPs must adopt a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex structures, large transactions) and simplified due diligence (SDD) for lower-risk scenarios where permitted.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Obligation to Report: If a VASP has grounds to suspect that funds or other property, regardless of the amount, are related to the financing of terrorism or legalization (laundering) of criminal proceeds, it must immediately report such suspicions.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report (STR) has been filed, or that an investigation into money laundering or terrorist financing is being conducted.
Timelines: Reports should typically be filed "without delay" after the suspicion arises.
Retention Period: Records must generally be kept for a minimum period of five years from the date of the transaction or the termination of the business relationship.
Regulator/Enforcing Agency: State Committee for National Security (SCNS, known as GKNB in Russian), Ministry of Internal Affairs (MVD), in cooperation with national energy companies (e.g., National Energy Holding).
December 2023: SCNS reported neutralizing a large illegal crypto mining farm in Bishkek operating in an abandoned factory.
Entity Targeted: Organizers and promoters of the "S-Group" financial pyramid scheme. Violation Type: Fraud, establishment of a financial pyramid, illegal enrichment. The scheme falsely promised high returns from investments in various "projects," including crypto trading. Penalty Amount: No single "fine" amount specified as it's a criminal case. The goal is asset seizure and restitution to victims. The estimated damage to victims was substantial, reaching billions of KGS. Organizers face criminal charges, which can lead to imprisonment.
Regulator Name: National Bank of the Kyrgyz Republic (NBKR)
Entity Targeted: The general public, financial institutions, and potential investors. Violation Type: N/A (warnings are preventative, not punitive). The NBKR warns against the risks associated with cryptocurrency, including high volatility, fraud, and the lack of legal tender status. They also emphasize that transactions using crypto are not regulated under Kyrgyz law, except for a specific license requirement for crypto-exchange activities. Penalty Amount: N/A (no direct penalty for warnings).
Administrative Fines: Significant monetary penalties for legal entities and responsible officials.
Suspension or Revocation of Licenses: The licensing authority (which is expected to be the State Service for Regulation and Supervision of the Financial Market under the Government of the Kyrgyz Republic or a similar body) can suspend or revoke a VASP's operating license.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Kyrgyz residents must establish a local legal entity, obtain a VASP license under Law No. 200 "On the Turnover of Virtual Assets," and comply with comprehensive Kyrgyz AML/CFT obligations (CDD, ongoing monitoring, STR filing, Travel Rule, 5-year record-keeping) supervised by the SSFI, with significant enforcement risk for unregistered operators including criminal prosecution.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?