Centralized exchange in Luxembourg
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Register as a VASP with the CSSF under the Law of 12 November 2004 (AML Law) — this is mandatory for custodial wallet service providers.
- Conduct customer due diligence (CDD): obtain and verify customer name, residential address, date/place of birth, nationality, and unique ID number from a reliable source (e.g., passport, national ID).
- For legal entities: verify company name, legal form, registered address, articles of association, directors list, and proof of incorporation.
- Identify and verify beneficial owners (UBO — any natural person owning/controlling ≥25% of shares/voting rights or otherwise exercising control); consult the Luxembourg Register of Beneficial Owners (RBE).
- Understand the purpose and intended nature of the business relationship.
- Perform ongoing transaction monitoring — scrutinize transactions to ensure consistency with customer knowledge and risk profile; regularly review/update CDD data.
- Apply enhanced due diligence (EDD) for PEPs, family members and close associates, high-risk jurisdictions, and complex or unusually large transactions.
- Report suspicious transactions to the relevant authorities under the AML Law and CSSF Circular 22/811.
- Maintain a robust internal control framework and risk management systems per CSSF Circular 22/811 (consolidating 20/747 and 21/769) and CSSF Circular 23/843 (updated FATF-aligned guidance).
- Prepare for MiCA authorization (Regulation EU 2023/1114) — a full, more stringent licensing process by the CSSF replacing the current AML registration, with specific prudential and conduct requirements.
- Travel Rule obligations (FATF Recommendation 16) apply to withdrawals/transfers of virtual assets — VASPs must collect, share, and transmit originator and beneficiary information on virtual asset transfers.
Key Restrictions
- Must be registered as a VASP with the CSSF — operating without registration is a violation subject to warnings, cease-and-desist orders, or refusal of registration.
- Under MiCA (Regulation EU 2023/1114), the operator must obtain full authorization from the CSSF as a crypto-asset service provider (CASP) to continue operating across the EU; this is a more demanding licensing process than the current AML registration.
- Client crypto-assets must be kept separate from the VASP's own crypto-assets using different blockchain addresses or distributed ledgers (MiCA Article 67).
- Client fiat funds must be kept separate from the VASP's own funds in accordance with national law (MiCA Article 67).
- Must hold own funds (capital requirements) or professional indemnity insurance to cover liability risks from operations (MiCA Article 67(5) and Article 68).
- No explicit mandate for cold storage, but CSSF Circular 22/811 and sound risk management principles require robust IT security measures, which implicitly demand industry best practices including cold storage for a material portion of assets.
Key Risks
- Regulatory ambiguity during the transition from AML registration (current regime) to MiCA authorization — operators may face dual compliance burdens or uncertainty about timelines and grandfathering.
- No major public fines against named crypto entities to date, but the CSSF uses non-public administrative measures, enhanced supervision, and warnings — enforcement risk is real but opaque.
- Commingling of client and proprietary assets (even inadvertently) would violate MiCA segregation requirements and could trigger enforcement action or loss of authorization.
- Travel Rule compliance for virtual asset transfers is operationally complex and Luxembourg has not yet issued bespoke local guidance — firms must follow FATF standards as interpreted by CSSF Circular 23/843.
- As MiCA comes into force, firms relying solely on the current lighter AML registration may need to reapply for full CASP authorization, creating licensing timeline risk.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.
The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.
Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.
CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.
Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
Explicit Requirement: MiCA explicitly mandates crypto-asset service providers offering custody services to:
Keep separate the crypto-assets of their clients from their own crypto-assets and ensure that this is achieved by using different blockchain addresses or distributed ledgers.
Keep separate the funds of their clients from their own funds, in accordance with national law.
MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.
Prudential Requirements and Professional Indemnity Insurance: MiCA introduces specific prudential requirements for crypto-asset service providers. For custodians, it requires them to:
Hold own funds (capital requirements) or a professional indemnity insurance to cover liability risks from their operations. The amount will depend on the type of service and associated risks.
MiCA Regulation (EU) 2023/1114, Article 67 ("Custody and administration of crypto-assets on behalf of third parties"): Specifically, Article 67(1)(b) addresses segregation.
However, CSSF Circular 22/811 and the general principles of sound risk management dictate that VASPs must implement robust IT security measures and internal controls to protect virtual assets. This implicitly requires firms to adopt industry best practices for secure storage, which often involves a combination of hot, warm, and cold storage solutions, multi-signature wallets, Hardware Security Modules (HSMs), and comprehensive key management policies. The CSSF assesses the adequacy of these measures as part of the VASP registration and ongoing supervision.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.
CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.
Exchange services: Exchanging virtual assets for fiat currencies or other virtual assets.
Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.
Transfer of virtual assets: Services involving the movement of virtual assets between addresses or accounts.
Identification and Verification:
Obtain and verify the customer's name, residential address, date and place of birth, nationality, and a unique identification number (e.g., from a passport or national ID card).
Verify identity using reliable, independent source documents, data, or information (e.g., government-issued photo ID, proof of address utility bill).
Legal Entities (Companies, Foundations, etc.):
Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.
Consult relevant registers (e.g., the Luxembourg Register of Beneficial Owners - RBE).
Purpose and Intended Nature of the Business Relationship: Understand the rationale behind the customer's use of virtual asset services.
Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Regularly review and update customer identification data, especially for high-risk clients.
Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:
Politically Exposed Persons (PEPs), their family members, and close associates.
Transactions involving high-risk jurisdictions.
Complex or unusually large transactions, and all unusual patterns of transactions, that have no apparent economic or lawful purpose.
Focus on Registration and AML/CFT Compliance:
Violation Type (General Focus): Non-compliance with AML/CFT obligations, operating without proper registration as a VASP, market abuse, consumer protection issues. Outcome (General): Refusal of VASP registration, official warnings, cease-and-desist orders, enhanced supervisory measures.
CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.
CSSF Circular 23/843 (Relevant for AML/CFT for VASPs):
No Major Public Fines Against Specific Crypto Entities:
Potential for Non-Public Actions:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange taking custody of user assets may operate in Luxembourg but must register as a VASP with the CSSF under the AML Law, comply with comprehensive AML/CFT obligations, segregate client crypto-assets (per MiCA Article 67), and prepare for the transition to full MiCA authorization as a CASP.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?