Custodial wallet / SaaS in Luxembourg
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Must register as a VASP with the CSSF (AML registration) under the Law of 12 November 2004, as amended by the Law of 25 March 2020 implementing AMLD5
- Perform customer due diligence (CDD): verify identity (name, address, DOB, nationality, ID number) for natural persons
- For legal entity clients: verify company name, legal form, registered address, articles, directors, proof of incorporation
- Identify and verify beneficial owners (UBO threshold: 25% ownership or control), consulting the Luxembourg Register of Beneficial Owners (RBE)
- Determine purpose and intended nature of the business relationship
- Ongoing transaction monitoring to ensure consistency with customer risk profile
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, and complex/unusually large transactions
- Report suspicious transactions to the CSSF under the AML Law
- Maintain internal control frameworks, risk assessments, and AML/CFT policies per CSSF Circular 22/811 (consolidating 20/747, 21/769)
- Comply with CSSF Circular 23/843 reflecting updated FATF recommendations
- Consult CSSF Regulation N° 12-02 on general AML professional obligations
Key Restrictions
- Must be registered as a VASP with the CSSF before offering custodial wallet services to Luxembourg residents
- Under current AML Law, no explicit mandate for segregation of client crypto assets from proprietary assets, but CSSF expects adequate arrangements to protect client virtual assets
- MiCA (Regulation EU 2023/1114) will impose a full authorization regime (not just AML registration) for custody and administration of crypto-assets on behalf of third parties, with mandatory segregation of client crypto-assets into different blockchain addresses
- MiCA will require own funds or professional indemnity insurance to cover liability risks (Article 67(5) and Article 68)
- No explicit cold-storage mandate, but CSSF expects robust IT security measures and industry best practices for secure storage
- White-label SaaS structure means both the platform provider (as VASP) and potentially the white-label client may have independent AML obligations — the provider retains responsibility for custody and key safeguarding
Key Risks
- Transition risk: MiCA will replace the current AML registration regime with a full authorization regime — operators face licensing upgrade requirements and potential gaps during the transition
- Ambiguity in allocation of AML obligations between the SaaS custody provider and white-label client under current regime
- No major public enforcement fines against crypto entities to date, but CSSF may use non-public administrative measures; the absence of fines does not indicate absence of scrutiny
- No explicit insurance/bonding requirements currently, but CSSF expects adequate financial resources — firms may under-insure relative to CSSF expectations
- Commingling of client and proprietary crypto assets is a risk under current rules — MiCA will mandate blockchain-level segregation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.
The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.
Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (Loi du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme, telle que modifiée): While a specific URL to the consolidated law is hard to pinpoint, it's the primary legal basis. The key amendments are from 2018 and later.
CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.
Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.
While the current AML Law itself doesn't explicitly mandate segregation of client crypto assets in the same way traditional financial services are regulated (e.g., MiFID), the CSSF expects VASPs to have robust internal controls, governance, and risk management frameworks. Commingling client and proprietary assets would generally be viewed as poor practice and a significant risk to clients, potentially leading to CSSF intervention based on general prudential expectations.
Firms offering custody services must demonstrate adequate arrangements to protect clients' virtual assets.
Explicit Requirement: MiCA explicitly mandates crypto-asset service providers offering custody services to:
Keep separate the crypto-assets of their clients from their own crypto-assets and ensure that this is achieved by using different blockchain addresses or distributed ledgers.
Keep separate the funds of their clients from their own funds, in accordance with national law.
Luxembourg's current VASP AML registration does not explicitly mandate specific insurance or bonding requirements for pure crypto custody services.
However, the CSSF generally expects regulated entities to have adequate financial resources and robust risk management, which may include appropriate professional indemnity insurance to cover potential liabilities arising from operational failures, security breaches, or errors.
Prudential Requirements and Professional Indemnity Insurance: MiCA introduces specific prudential requirements for crypto-asset service providers. For custodians, it requires them to:
Hold own funds (capital requirements) or a professional indemnity insurance to cover liability risks from their operations. The amount will depend on the type of service and associated risks.
There are no explicit mandates for "cold storage" in Luxembourg's current regulations.
However, CSSF Circular 22/811 and the general principles of sound risk management dictate that VASPs must implement robust IT security measures and internal controls to protect virtual assets. This implicitly requires firms to adopt industry best practices for secure storage, which often involves a combination of hot, warm, and cold storage solutions, multi-signature wallets, Hardware Security Modules (HSMs), and comprehensive key management policies. The CSSF assesses the adequacy of these measures as part of the VASP registration and ongoing supervision.
MiCA does not explicitly mandate "cold storage" either, but it does require crypto-asset service providers to:
Directive (EU) 2015/849 (4th AML Directive): Laid the groundwork for strengthening AML/CFT rules across the EU.
Directive (EU) 2018/843 (5th AML Directive): Critically, this directive extended the scope of AML/CFT rules to include virtual asset service providers, bringing them under the regulatory purview.
Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.
CSSF Regulation N° 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing: This regulation, though predating the full VASP inclusion, sets out general professional obligations and is complemented by specific CSSF guidance.
CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.
Custodial wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store and transfer virtual assets.
Identification and Verification:
Obtain and verify the customer's name, residential address, date and place of birth, nationality, and a unique identification number (e.g., from a passport or national ID card).
Legal Entities (Companies, Foundations, etc.):
Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.
Purpose and Intended Nature of the Business Relationship: Understand the rationale behind the customer's use of virtual asset services.
Scrutinize transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:
Focus on Registration and AML/CFT Compliance:
CSSF VASP Register (Information Page): This page explains the registration requirements and provides access to the list of registered VASPs.
Law of 25 March 2020: Establishing a register for VASPs, transposing parts of the 5th Anti-Money Laundering Directive (AMLD5).
CSSF Circular 23/843: Updated guidance for VASPs on AML/CFT, reflecting new recommendations from the Financial Action Task Force (FATF).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers must register as VASPs with the CSSF under the AML Law, comply with CSSF AML/CFT obligations (CDD, monitoring, EDD, reporting), and should prepare for the transition to MiCA's full authorization regime with mandatory asset segregation and capital/insurance requirements.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?