Crypto ATM / kiosk operator in Luxembourg
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as a VASP with the CSSF under the Law of 12 November 2004 (AML Law), which transposes the 5th AML Directive and brings crypto-to-fiat exchange services under AML/CFT supervision
- Conduct customer due diligence (CDD): obtain and verify customer name, residential address, date/place of birth, nationality, and unique identification number from a government-issued ID
- Identify and verify beneficial ownership (UBO) for any natural person owning/controlling 25%+ of a legal entity; consult the Luxembourg Register of Beneficial Owners (RBE)
- Understand the purpose and intended nature of the business relationship
- Perform ongoing transaction monitoring — scrutinize transactions throughout the relationship to ensure consistency with customer risk profile
- Apply Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex or unusually large transactions, and unusual transaction patterns with no apparent lawful purpose
- Report suspicious transactions to the CSSF (and Cellule de Renseignement Financier — CRF) under the AML Law
- Maintain a robust AML/CFT internal control framework as detailed in CSSF Circular 22/811 (and predecessor Circular 20/747)
- Comply with CSSF Regulation N° 12-02 on AML/CFT professional obligations
- No specific cash-transaction reporting threshold identified in the provided facts — cash-in/cash-out at kiosks would trigger standard EDD for large/unusual transactions
Key Restrictions
- Must be incorporated or have a legal presence in Luxembourg to register as a VASP with the CSSF
- Must register as a VASP with the CSSF before commencing operations — operating without registration is a violation subject to cease-and-desist orders
- Must implement robust IT security measures and internal controls to protect customer virtual assets (per CSSF Circular 22/811 guidance)
- No explicit cold-storage mandate, but sound risk management and CSSF guidance implicitly require industry best practices for secure storage
- MiCA (Regulation EU 2023/1114) will require a full authorization (not just AML registration) for custody and administration of crypto-assets, including segregation of client crypto-assets on separate blockchain addresses and client funds from own funds
- The CSSF expects adequate financial resources and risk management — professional indemnity insurance may be expected though not explicitly mandated under current VASP AML registration regime
Key Risks
- High-cash AML risk profile of kiosks attracts enhanced regulatory scrutiny — CSSF may apply more intensive supervisory engagement for cash-intensive VASPs
- No publicly known enforcement fines against named crypto entities in Luxembourg, but the CSSF actively issues warnings and can order non-compliant entities to cease operations; actions may be resolved through non-public administrative measures
- Cash transactions at kiosks may be considered high-risk under AML Law, triggering mandatory EDD — unclear whether cash-transaction reporting thresholds (e.g. €10K) apply directly to crypto kiosks as they do to traditional financial institutions
- Transition to MiCA full authorization regime will impose additional prudential requirements (capital or professional indemnity insurance) and explicit asset segregation rules — operators must plan for this regulatory upgrade
- No explicit licensing category for 'crypto ATM/kiosk' — the operator must fit within the existing VASP registration framework, creating some structural ambiguity
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.
The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.
Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.
CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.
Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
Keep separate the crypto-assets of their clients from their own crypto-assets and ensure that this is achieved by using different blockchain addresses or distributed ledgers.
Keep separate the funds of their clients from their own funds, in accordance with national law.
However, the CSSF generally expects regulated entities to have adequate financial resources and robust risk management, which may include appropriate professional indemnity insurance to cover potential liabilities arising from operational failures, security breaches, or errors.
Prudential Requirements and Professional Indemnity Insurance: MiCA introduces specific prudential requirements for crypto-asset service providers. For custodians, it requires them to:
There are no explicit mandates for "cold storage" in Luxembourg's current regulations.
However, CSSF Circular 22/811 and the general principles of sound risk management dictate that VASPs must implement robust IT security measures and internal controls to protect virtual assets. This implicitly requires firms to adopt industry best practices for secure storage, which often involves a combination of hot, warm, and cold storage solutions, multi-signature wallets, Hardware Security Modules (HSMs), and comprehensive key management policies. The CSSF assesses the adequacy of these measures as part of the VASP registration and ongoing supervision.
Directive (EU) 2018/843 (5th AML Directive): Critically, this directive extended the scope of AML/CFT rules to include virtual asset service providers, bringing them under the regulatory purview.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.
CSSF Regulation N° 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing: This regulation, though predating the full VASP inclusion, sets out general professional obligations and is complemented by specific CSSF guidance.
CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.
Exchange services: Exchanging virtual assets for fiat currencies or other virtual assets.
Identification and Verification:
Verify identity using reliable, independent source documents, data, or information (e.g., government-issued photo ID, proof of address utility bill).
Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.
Consult relevant registers (e.g., the Luxembourg Register of Beneficial Owners - RBE).
Purpose and Intended Nature of the Business Relationship: Understand the rationale behind the customer's use of virtual asset services.
Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:
Politically Exposed Persons (PEPs), their family members, and close associates.
Transactions involving high-risk jurisdictions.
Complex or unusually large transactions, and all unusual patterns of transactions, that have no apparent economic or lawful purpose.
Focus on Registration and AML/CFT Compliance:
The CSSF maintains a public register of VASPs operating in Luxembourg. This registration process is a crucial form of regulation and "pre-enforcement." Entities must demonstrate robust AML/CFT frameworks to be registered.
Failure to register or comply with AML/CFT obligations is a violation, and the CSSF's primary "enforcement" in such cases often involves:
Ordering non-compliant entities to cease operations.
Regulator: Commission de Surveillance du Secteur Financier (CSSF)
CSSF Circular 20/747: Revised prudential requirements for VASPs.
CSSF Circular 23/843: Updated guidance for VASPs on AML/CFT, reflecting new recommendations from the Financial Action Task Force (FATF).
Violation Type (General Focus): Non-compliance with AML/CFT obligations, operating without proper registration as a VASP, market abuse, consumer protection issues. Outcome (General): Refusal of VASP registration, official warnings, cease-and-desist orders, enhanced supervisory measures.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto ATM/kiosk operator may operate in Luxembourg by registering as a VASP with the CSSF under the AML Law and complying with full EU-standard AML/CFT obligations (CDD, EDD, ongoing monitoring, suspicious transaction reporting), with no dedicated kiosk-specific license and no explicit cash-transaction reporting threshold identified, but must also prepare for the upcoming MiCA full-authorization regime.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?