← Regulations / Luxembourg / Operating Models / Remote VASP

Remote VASP serving residents in Luxembourg

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Luxembourg with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the CSSF (Commission de Surveillance du Secteur Financier) for AML/CFT purposes is mandatory for any entity providing virtual asset services (custody, exchange, transfer) — cross-border services to Luxembourg residents trigger this obligation.
  • Customer Due Diligence (CDD) under the Law of 12 November 2004 (AML Law) and CSSF Circular 22/811: obtain and verify customer name, address, date/place of birth, nationality, and a unique ID number from reliable independent sources.
  • Beneficial ownership identification: identify and verify any natural person owning or controlling ≥25% of shares/voting rights; consult the Luxembourg Register of Beneficial Owners (RBE).
  • Ongoing transaction monitoring: scrutinize transactions throughout the relationship to ensure consistency with customer knowledge and risk profile.
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, and unusual transaction patterns.
  • Suspicious Transaction Reporting (STR) obligations to the CSSF.
  • Internal control frameworks and robust IT security measures as per CSSF Circular 22/811 and general sound risk management expectations.
  • Under MiCA (Regulation (EU) 2023/1114), applicable from 2025 onward: full authorization required from CSSF, with capital requirements or professional indemnity insurance, mandatory segregation of client crypto-assets (separate blockchain addresses) and client funds.

Key Restrictions

  • Foreign-incorporated entity must register as a VASP with the CSSF before providing virtual asset services to Luxembourg residents — no exemption for cross-border/remote service without local presence.
  • Under current AML Law (pre-MiCA), registration is AML/CFT-focused; under MiCA (effective ~2025), full authorization is required with more stringent prudential requirements (capital/insurance, client asset segregation, governance).
  • Commingling of client and proprietary crypto-assets is discouraged by the CSSF; MiCA explicitly mandates separate blockchain addresses for client assets.
  • No explicit cold-storage mandate, but CSSF expects robust IT security and internal controls which implicitly require industry best practices for secure storage.
  • While no publicly documented fines for unlicensed remote VASPs have been issued, the CSSF actively issues warnings against unlicensed entities and can order cessation of operations.

Key Risks

  • Enforcement risk: CSSF actively monitors for unregistered VASP activity and issues public warnings; while large public fines have not been announced, regulatory actions may be resolved via non-public administrative measures, cease-and-desist orders, or enhanced supervision.
  • Regulatory ambiguity under current regime: the AML Law registration is less burdensome than MiCA authorization, creating a transition risk as MiCA's stricter requirements (capital, insurance, segregation) will apply fully from 2025.
  • Reputational and operational risk of being publicly named in a CSSF warning to the public, which could affect banking relationships and correspondent access.
  • Lack of public enforcement precedent against crypto firms means the CSSF's actual enforcement posture toward unlicensed remote operators is untested in court but likely aggressive given the EU-wide push for registration compliance.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration as a VASP: Entities providing "custodian wallet services" (which includes custody of virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs) under Luxembourg law. These VASPs are subject to registration with the CSSF for AML/CFT purposes.

licensing 60% confidence

The registration is governed by the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"), which incorporated the EU's 5th AML Directive.

licensing 60% confidence

Registration requires the entity to comply with AML/CFT obligations, including customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting, and internal control frameworks.

aml 60% confidence

Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the "AML Law"): This is the cornerstone legislation. It was significantly amended by the Law of 25 March 2020 to transpose the 5th AML Directive, explicitly including virtual asset service providers as "professionals" subject to AML/CFT obligations.

aml 60% confidence

CSSF Circular 20/747 (as amended by Circular 22/815): This circular is crucial for VASPs as it consolidates and specifies the AML/CFT professional obligations under the amended AML Law for all entities subject to CSSF supervision, including VASPs. It provides detailed guidance on risk assessment, customer due diligence, internal organisation, and reporting requirements.

aml 60% confidence

Beneficial Ownership (UBO): Identify and take reasonable measures to verify the identity of the beneficial owner(s) (any natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or otherwise exercises control over the entity). For trusts or similar legal arrangements, identify the settlors, trustees, beneficiaries, and any other person exercising ultimate control.

aml 60% confidence

Enhanced Due Diligence (EDD): Required for situations posing a higher ML/TF risk, including:

licensing 60% confidence

CSSF Circular 22/811 (and previous versions like 20/747 and 21/769 which it consolidates/replaces): This circular provides detailed guidance on AML/CFT obligations for VASPs.

enforcement 60% confidence

CSSF Warnings for Unlicensed Entities: The CSSF frequently issues warnings against entities that purport to offer financial services in Luxembourg without proper authorization, including those related to crypto. These are general warnings rather than specific enforcement actions against a regulated VASP.

licensing 60% confidence

Authorization, not just Registration: MiCA will require firms providing "custody and administration of crypto-assets on behalf of third parties" to obtain a full authorization from a national competent authority (the CSSF in Luxembourg) to operate across the EU. This is a more stringent licensing regime than the current AML registration.

licensing 60% confidence

Keep separate the crypto-assets of their clients from their own crypto-assets and ensure that this is achieved by using different blockchain addresses or distributed ledgers.

licensing 60% confidence

Keep separate the funds of their clients from their own funds, in accordance with national law.

licensing 60% confidence

Prudential Requirements and Professional Indemnity Insurance: MiCA introduces specific prudential requirements for crypto-asset service providers. For custodians, it requires them to:

licensing 60% confidence

Hold own funds (capital requirements) or a professional indemnity insurance to cover liability risks from their operations. The amount will depend on the type of service and associated risks.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a foreign-incorporated remote VASP serving Luxembourg residents must register with the CSSF for AML/CFT purposes (with no exemption for cross-border-only service), comply with the full suite of EU-derived AML/CFT obligations (CDD, EDD, STR, transaction monitoring), and, under MiCA from ~2025, obtain a full authorization from the CSSF with capital/insurance and client asset segregation requirements; operating without registration carries risk of CSSF warnings, cease-and-desist orders, and potentially non-public administrative enforcement actions.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?