← Regulations / Luxembourg / Operating Models / CEX

Centralized exchange in Luxembourg

Order-book exchange that takes custody of user assets and matches trades between users.

Conditional AI-Generated · Unreviewed

CEX is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Register as a VASP with the CSSF under the Law of 12 November 2004 (AML Law) — this is mandatory for custodial wallet service providers.
  • Conduct customer due diligence (CDD): obtain and verify customer name, residential address, date/place of birth, nationality, and unique ID number from a reliable source (e.g., passport, national ID).
  • For legal entities: verify company name, legal form, registered address, articles of association, directors list, and proof of incorporation.
  • Identify and verify beneficial owners (UBO — any natural person owning/controlling ≥25% of shares/voting rights or otherwise exercising control); consult the Luxembourg Register of Beneficial Owners (RBE).
  • Understand the purpose and intended nature of the business relationship.
  • Perform ongoing transaction monitoring — scrutinize transactions to ensure consistency with customer knowledge and risk profile; regularly review/update CDD data.
  • Apply enhanced due diligence (EDD) for PEPs, family members and close associates, high-risk jurisdictions, and complex or unusually large transactions.
  • Report suspicious transactions to the relevant authorities under the AML Law and CSSF Circular 22/811.
  • Maintain a robust internal control framework and risk management systems per CSSF Circular 22/811 (consolidating 20/747 and 21/769) and CSSF Circular 23/843 (updated FATF-aligned guidance).
  • Prepare for MiCA authorization (Regulation EU 2023/1114) — a full, more stringent licensing process by the CSSF replacing the current AML registration, with specific prudential and conduct requirements.
  • Travel Rule obligations (FATF Recommendation 16) apply to withdrawals/transfers of virtual assets — VASPs must collect, share, and transmit originator and beneficiary information on virtual asset transfers.

Key Restrictions

  • Must be registered as a VASP with the CSSF — operating without registration is a violation subject to warnings, cease-and-desist orders, or refusal of registration.
  • Under MiCA (Regulation EU 2023/1114), the operator must obtain full authorization from the CSSF as a crypto-asset service provider (CASP) to continue operating across the EU; this is a more demanding licensing process than the current AML registration.
  • Client crypto-assets must be kept separate from the VASP's own crypto-assets using different blockchain addresses or distributed ledgers (MiCA Article 67).
  • Client fiat funds must be kept separate from the VASP's own funds in accordance with national law (MiCA Article 67).
  • Must hold own funds (capital requirements) or professional indemnity insurance to cover liability risks from operations (MiCA Article 67(5) and Article 68).
  • No explicit mandate for cold storage, but CSSF Circular 22/811 and sound risk management principles require robust IT security measures, which implicitly demand industry best practices including cold storage for a material portion of assets.

Key Risks

  • Regulatory ambiguity during the transition from AML registration (current regime) to MiCA authorization — operators may face dual compliance burdens or uncertainty about timelines and grandfathering.
  • No major public fines against named crypto entities to date, but the CSSF uses non-public administrative measures, enhanced supervision, and warnings — enforcement risk is real but opaque.
  • Commingling of client and proprietary assets (even inadvertently) would violate MiCA segregation requirements and could trigger enforcement action or loss of authorization.
  • Travel Rule compliance for virtual asset transfers is operationally complex and Luxembourg has not yet issued bespoke local guidance — firms must follow FATF standards as interpreted by CSSF Circular 23/843.
  • As MiCA comes into force, firms relying solely on the current lighter AML registration may need to reapply for full CASP authorization, creating licensing timeline risk.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.

licensing 60% confidence

The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.

licensing 60% confidence

Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.

licensing 60% confidence

CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.

licensing 60% confidence

Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.

licensing 60% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):

licensing 60% confidence

Explicit Requirement: MiCA explicitly mandates crypto-asset service providers offering custody services to:

licensing 60% confidence

Keep separate the crypto-assets of their clients from their own crypto-assets and ensure that this is achieved by using different blockchain addresses or distributed ledgers.

licensing 60% confidence

Keep separate the funds of their clients from their own funds, in accordance with national law.

licensing 60% confidence

MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.

licensing 60% confidence

Prudential Requirements and Professional Indemnity Insurance: MiCA introduces specific prudential requirements for crypto-asset service providers. For custodians, it requires them to:

licensing 60% confidence

Hold own funds (capital requirements) or a professional indemnity insurance to cover liability risks from their operations. The amount will depend on the type of service and associated risks.

licensing 60% confidence

MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.

licensing 60% confidence

However, CSSF Circular 22/811 and the general principles of sound risk management dictate that VASPs must implement robust IT security measures and internal controls to protect virtual assets. This implicitly requires firms to adopt industry best practices for secure storage, which often involves a combination of hot, warm, and cold storage solutions, multi-signature wallets, Hardware Security Modules (HSMs), and comprehensive key management policies. The CSSF assesses the adequacy of these measures as part of the VASP registration and ongoing supervision.

aml 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.

aml 60% confidence

CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.

aml 60% confidence

Exchange services: Exchanging virtual assets for fiat currencies or other virtual assets.

aml 60% confidence

Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.

aml 60% confidence

Transfer of virtual assets: Services involving the movement of virtual assets between addresses or accounts.

aml 60% confidence

Obtain and verify the customer's name, residential address, date and place of birth, nationality, and a unique identification number (e.g., from a passport or national ID card).

aml 60% confidence

Verify identity using reliable, independent source documents, data, or information (e.g., government-issued photo ID, proof of address utility bill).

aml 60% confidence

Legal Entities (Companies, Foundations, etc.):

aml 60% confidence

Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.

aml 60% confidence

Consult relevant registers (e.g., the Luxembourg Register of Beneficial Owners - RBE).

aml 60% confidence

Purpose and Intended Nature of the Business Relationship: Understand the rationale behind the customer's use of virtual asset services.

aml 60% confidence

Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 60% confidence

Regularly review and update customer identification data, especially for high-risk clients.

aml 60% confidence

Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:

aml 60% confidence

Politically Exposed Persons (PEPs), their family members, and close associates.

aml 60% confidence

Transactions involving high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions, and all unusual patterns of transactions, that have no apparent economic or lawful purpose.

enforcement 60% confidence

Violation Type (General Focus): Non-compliance with AML/CFT obligations, operating without proper registration as a VASP, market abuse, consumer protection issues. Outcome (General): Refusal of VASP registration, official warnings, cease-and-desist orders, enhanced supervisory measures.

enforcement 60% confidence

CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a centralized exchange taking custody of user assets may operate in Luxembourg but must register as a VASP with the CSSF under the AML Law, comply with comprehensive AML/CFT obligations, segregate client crypto-assets (per MiCA Article 67), and prepare for the transition to full MiCA authorization as a CASP.

Questions this verdict aims to answer

  • What exchange / VASP license applies?
  • What custody segregation rules apply to user assets?
  • What market-conduct and listing rules apply?
  • What travel-rule obligations apply on withdrawals?