← Regulations / North Korea / Operating Models / Remote VASP

Remote VASP serving residents in North Korea

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Not permitted AI-Generated · Unreviewed

Remote VASP is not permitted in North Korea.

Verdict Details

Permitted
no
Local entity required
No
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Any foreign VASP serving North Korean residents would be facilitating transactions with a jurisdiction that is on the FATF 'Call for Action' (high-risk) list, triggering enhanced due diligence and counter-measures under FATF recommendations globally.
  • UN Security Council sanctions (UNSC 1718 Sanctions Committee) prohibit or severely restrict financial transactions with North Korea, making any AML/KYC compliance effectively impossible to perform lawfully.
  • U.S. OFAC sanctions against North Korea impose strict liability — any virtual asset transaction involving North Korean residents or entities risks asset freezing and criminal penalties.
  • Foreign VASPs must implement robust sanctions screening and geofencing to prevent any transactions with North Korean IPs, residents, or wallets linked to DPRK entities.

Key Restrictions

  • No legitimate legal pathway exists for a foreign-incorporated VASP to openly serve North Korean residents due to comprehensive UN and national sanctions regimes.
  • Any transaction involving North Korea or its residents carries severe sanctions evasion risk (UNSC sanctions, OFAC sanctions, EU sanctions).
  • North Korea is designated by FATF as a high-risk jurisdiction subject to a 'Call for Action' — all countries must apply counter-measures to transactions involving the DPRK.
  • State-sponsored hacking groups (Lazarus Group, Kimsuky, Andariel) are the primary actors in DPRK's virtual asset space — private remote VASP services are not a recognized market.

Key Risks

  • Extreme sanctions enforcement risk: OFAC and other authorities have demonstrated willingness to shut down and sanction entities facilitating DPRK transactions (e.g., Sinbad.io mixer in 2023, Tornado Cash in 2022).
  • Criminal enforcement risk: U.S. and allied authorities have indicted individuals and seized cryptocurrency linked to DPRK hacking groups; any unlicensed remote service could be treated as complicity in money laundering or sanctions evasion.
  • Reputational and counter-party risk: Any VASP found to serve North Korean residents will lose access to the international banking system and be blacklisted by correspondent banks.
  • Regulatory ambiguity: North Korea has no public licensing framework for private VASPs — the only crypto activity is state-controlled and illicit, creating an impossible compliance environment.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Sanctions Evasion: Bypassing international sanctions to fund the regime's weapons programs and luxury goods for the elite.

licensing 60% confidence

Exchanges, Custody Providers, Payment Processors: There are no publicly known or established licensing regimes or requirements for these types of entities to operate legally and openly within North Korea for a domestic market. Any virtual asset activity occurring within the DPRK is either:

licensing 60% confidence

Directly managed by state-affiliated entities (e.g., intelligence agencies, state-owned banks, research institutions).

licensing 60% confidence

Highly controlled and isolated, serving specific state objectives rather than a private market.

licensing 60% confidence

Registration vs. Licensing Regime: The distinction between registration and licensing regimes, as understood in conventional financial regulation, does not apply to virtual asset service providers (VASPs) within North Korea. There is no public body for registration or licensing of private crypto businesses.

licensing 60% confidence

United Nations Security Council (UNSC) Panel of Experts Reports on the DPRK: These annual reports frequently detail North Korea's use of cyber means, including virtual asset theft and exploitation, for sanctions evasion.

licensing 60% confidence

Financial Action Task Force (FATF) Statements and Reports: The FATF has repeatedly flagged North Korea as a high-risk jurisdiction for money laundering and terrorist financing, highlighting its severe deficiencies in AML/CFT.

aml 60% confidence

FATF Blacklisting: As mentioned, it remains on the FATF's "Call for Action" list, signaling to all countries to apply enhanced due diligence and counter-measures to transactions involving North Korea.

aml 60% confidence

UN Sanctions: North Korea is subject to extensive sanctions imposed by the United Nations Security Council (UNSC) due to its nuclear and ballistic missile programs. These sanctions severely restrict its access to the international financial system.

aml 60% confidence

National Sanctions: Countries like the United States (through OFAC), the European Union, and others implement their own robust sanctions regimes against North Korea, targeting individuals, entities, and financial institutions involved in supporting the DPRK regime's illicit activities.

aml 60% confidence

Financial Exclusion: Due to these sanctions and the high-risk designation, North Korea is largely cut off from the legitimate global financial system. Any entities attempting to transact with North Korea, especially concerning virtual assets, face significant risks of violating sanctions and being subject to severe penalties themselves in other jurisdictions.

custody 60% confidence

No Public Market for Private Services: There is no known legitimate or public market for private cryptocurrency custodial services, exchanges, or investment funds within North Korea. The concept of "client assets" or "private custodians" as distinct from the state's own operations is fundamentally alien to its economic and political structure.

enforcement 60% confidence

Entity Targeted: Cryptocurrency Mixers (e.g., Sinbad.io). Violation Type: Facilitating money laundering for sanctioned entities, including North Korea's Lazarus Group, for proceeds from major cryptocurrency heists. Penalty Amount: Assets frozen, U.S. persons prohibited from transacting with the entity, effective shutdown of the service. (No specific fine amount against the mixer, but the economic impact is a cessation of operations).

enforcement 60% confidence

Entity Targeted: Individuals and associated cryptocurrency addresses linked to North Korean state-sponsored hacking groups (e.g., Lazarus Group/APT38). Violation Type: Conspiracy to commit money laundering, international money laundering, conspiracy to commit computer fraud, theft of cryptocurrency. Penalty Amount: Indictment of individuals, seizure of tens of millions of dollars in stolen cryptocurrency.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Not permitted — no legitimate legal pathway exists for a foreign-incorporated remote VASP to serve North Korean residents due to comprehensive UN and national sanctions regimes, FATF high-risk counter-measures, and the absence of any public licensing framework; any such activity would constitute sanctions evasion and expose the operator to severe enforcement actions including asset freezing, criminal prosecution, and international blacklisting.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?