Custodial wallet / SaaS in Liechtenstein
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Liechtenstein with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Must register as a TT Custodian under the TVTG and obtain prior authorization from the FMA (Art. 4(1)(e), Art. 12-17 TVTG)
- Must comply with the Due Diligence Act (SPG) and Ordinance on Professional Due Diligence (SPV) for AML/CFT
- Identify and verify customers (natural persons: passport/ID, proof of address; legal entities: registration docs, UBO)
- Screen customers and UBOs against sanction lists (UN, EU, OFAC) and PEP lists
- Determine source of funds (SoF) and source of wealth (SoW) for higher-risk relationships
- Continuously monitor transactions and business relationships for suspicious activity
- Report suspicious transactions to the FMA (as the AML/CFT supervisor for TT Service Providers)
- Maintain robust AML/CFT compliance measures as per international FATF standards
Key Restrictions
- Must obtain a TT Custodian license from the FMA under the TVTG before offering custodial wallet/SaaS services
- Minimum capital of CHF 100,000 required (Art. 17 TVTG), with FMA discretion to require higher amounts
- Client tokens must be segregated from the custodian's own assets and from other clients' assets (implicit from Art. 23 TVTG's identification/return duty)
- Must implement state-of-the-art security measures including cold storage, multi-signature, HSMs, and robust key management policies (Art. 23 TVTG)
- Must take all necessary measures to protect tokens against loss, theft, or misuse (Art. 23 TVTG)
- Requires 'fit and proper' board/management, proper organization, IT security policy, and detailed business plan
- If offering fiat payment services alongside custody, may also need licensing under the Payment Services Act (Zahlungsdienstleistungsgesetz)
- White-label SaaS clients who are themselves TT Service Providers may need their own licensing/registration obligations
Key Risks
- FMA has active enforcement track record — issuing warnings against unauthorized operators, cease-and-desist orders, and license revocations for non-compliance
- MiCA implementation (applicable from Dec 30, 2024 for CASPs) will require transposition into Liechtenstein law, potentially altering current TVTG framework
- Capital requirement of CHF 100,000 may be deemed insufficient by FMA for larger operations, leading to ad hoc capital demands
- Ongoing supervision by FMA includes discretionary power to impose additional conditions on licensed entities
- AML/CFT obligations apply both to the SaaS provider (as a TT Custodian) and, in a white-label scenario, responsibilities for customer due diligence may need clear contractual allocation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Definition of TT Custodian: According to Art. 4 para. 1 lit. e TVTG, a TT Custodian is "a service provider who holds tokens in custody for third parties and provides services for the safeguarding of private keys or other means of access to tokens."
Licensing Process: Any entity wishing to act as a TT Custodian must obtain prior authorization from the FMA. The requirements for obtaining a license as a TT Service Provider are outlined in Articles 12-17 of the TVTG and include:
Proper Organization: The applicant must have an appropriate organizational structure, including robust internal controls, IT security, and risk management systems.
Qualified Management: The members of the board of directors and executive management must be "fit and proper," demonstrating professional qualifications, experience, and integrity.
Reliable Business Plan: A detailed business plan outlining the services, operational procedures, and risk assessments must be submitted.
Minimum Capital Requirements: As per Art. 17 TVTG, TT Service Providers, including TT Custodians, must have a minimum capital of CHF 100,000. The FMA may require higher capital based on the scope and risk of the services provided.
AML/CFT Compliance: Robust measures for combating money laundering and terrorist financing are mandatory, aligning with Liechtenstein's adherence to international standards (e.g., FATF recommendations).
Tokens and TT Service Providers Act (TVTG) - Art. 4(1)(e), Art. 12-17:
Duty of Care Regarding Third-Party Tokens: Art. 23 TVTG stipulates that a TT Custodian must take all necessary measures to protect the tokens against loss, theft, or misuse, and to ensure that they can always be identified and returned to the respective owner.
Identification and Return: This implicitly requires that the custodian must be able to clearly distinguish client assets from their own assets and from the assets of other clients. In practice, this leads to the implementation of technical and organizational measures for segregation, such as separate omnibus wallets per client or a sophisticated internal ledger system that tracks individual ownership within shared wallets, coupled with a robust reconciliation process.
Insolvency Protection: The segregation of client assets ensures that in the event of the custodian's insolvency, client assets are not part of the insolvency estate and can be returned to their rightful owners.
Security Measures: Art. 23 TVTG requires TT Custodians to implement "appropriate measures to protect the tokens against loss, theft or misuse." This broad requirement implies that custodians must employ state-of-the-art security practices suitable for the digital assets they hold.
Risk-Based Approach: For significant holdings, industry best practices for security almost universally involve some form of cold storage, multi-signature schemes, hardware security modules (HSMs), and robust key management policies. The FMA expects custodians to adopt a risk-based approach to security, meaning the higher the value and risk, the more stringent the security measures.
IT Security Policy: As part of the organizational requirements and risk management framework, custodians must have comprehensive IT security policies that address the entire lifecycle of private keys and access means.
FMA Authorization: A TT Custodian is "qualified" by virtue of having obtained the necessary authorization from the FMA. This licensing process ensures that the entity meets the rigorous standards set out in the TVTG regarding capital, management, organization, and operational integrity.
FMA Discretion: The FMA, during the licensing process or ongoing supervision, has the authority to impose additional conditions or requirements if deemed necessary to ensure the protection of clients and the stability of the financial market.
Minimum Capital Requirements: As mentioned, TT Custodians must hold a minimum capital of CHF 100,000, which acts as a buffer against operational risks.
Robust Risk Management: TT Service Providers are required to establish a sound risk management framework (Art. 13 para. 1 lit. c TVTG), which includes identifying, assessing, and mitigating risks associated with custody, including potential losses from cyber-attacks, operational errors, or theft. While not explicitly an insurance mandate, adequate risk management could lead a custodian to secure insurance coverage as a best practice to protect against certain risks.
Regulator Name: Financial Market Authority (FMA) Liechtenstein
Definition under TVTG: A "VT Exchange Service Provider" is a person who facilitates the exchange of VT Tokens against fiat currencies or other VT Tokens. This covers traditional cryptocurrency exchanges.
Token and VT Service Provider Act (TVTG) / Blockchain Act:
FMA Information on TVTG: https://www.fma-li.li/en/regulatory-sections/token-and-vt-service-provider-act-tvtg/
Due Diligence Act (DDA) (Sorgfaltspflichtgesetz):
Law on Professional Due Diligence for the Prevention of Money Laundering, Organised Crime and Terrorist Financing (Due Diligence Act, Sorgfaltspflichtgesetz - SPG): This is the overarching AML/CFT law that sets out the due diligence obligations for all financial intermediaries, including VASPs.
Ordinance on Professional Due Diligence (Sorgfaltspflichtverordnung - SPV): This ordinance provides detailed implementing provisions for the Due Diligence Act.
Law on Token and Trustworthy Technology Service Providers (Token and TT Service Provider Act, TVTG - commonly known as the "Blockchain Act"): This groundbreaking law defines and regulates various TT (Trustworthy Technology) service providers, which largely encompass VASPs. It explicitly brings these entities under the scope of the Due Diligence Act (SPG) for AML/CFT purposes.
FMA Guidelines: The Financial Market Authority (FMA) Liechtenstein issues various guidelines and circulars to provide practical guidance on the implementation of AML/CFT obligations, including specific guidance for TT Service Providers.
Token Custodians: Safely keep tokens or private keys for others.
Identification and Verification of the Customer and UBO:
Screening: Customers and their UBOs must be screened against national and international sanction lists (e.g., UN, EU, OFAC) and politically exposed persons (PEP) lists.
Understanding the Purpose and Intended Nature of the Business Relationship:
Source of Funds (SoF) / Source of Wealth (SoW):
VASPs must continuously monitor the business relationship, including transactions, to ensure that the activities are consistent with their knowledge of the customer, their business, and risk profile.
Entity Targeted: Licensed TVTG service providers or other financial institutions. (Specific names are not always publicly disclosed for every action, but the FMA's annual reports provide aggregated data). Violation Type: Non-compliance with the TVTG, Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) regulations, or other prudential requirements. Penalty Amount: Not a direct public monetary fine, but the severe penalty of loss of operating license, resulting in the inability to conduct regulated activities in Liechtenstein. This represents significant financial loss and reputational damage for the entity. Outcome: Withdrawal of authorization, cessation of regulated activities, safeguarding market integrity.
Entity Targeted: Various companies identified for unauthorized operation, often involving crypto/token offerings. (Specific company names are usually listed on the FMA's warning page, which is regularly updated). Violation Type: Operating financial services or token services without the necessary license under the TVTG or other relevant financial market laws, often coupled with allegations of scams or misleading information. Penalty Amount: Not a direct monetary fine imposed by the FMA in this context, but rather a public warning and expectation of cessation of activity. Failure to comply can lead to further legal action. Outcome: Public notification of unauthorized activity, demand for cessation of operations in Liechtenstein, consumer protection.
Outcome: Public notification of unauthorized activity, demand for cessation of operations in Liechtenstein, consumer protection.
Outcome: Withdrawal of authorization, cessation of regulated activities, safeguarding market integrity.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet / SaaS operator must obtain prior authorization from the FMA as a TT Custodian under the TVTG (Art. 4(1)(e), Art. 12-17), hold minimum capital of CHF 100,000, segregate client tokens, implement stringent security measures, and comply with comprehensive AML/CFT obligations under the SPG/SPV, with the FMA actively supervising and enforcing against unauthorized operations.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?