Centralized exchange in Latvia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Latvia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register with the Financial Intelligence Unit (FIU) of Latvia under the AML/CTPF registration regime (current pre-MiCA regime).
- Establish and maintain a robust AML/CTPF Internal Control System (ICS) covering: risk assessment, CDD/EDD, transaction monitoring, suspicious transaction reporting, record-keeping (5 years), and employee training.
- Appoint an AML Officer (board member or senior employee reporting directly to the board) responsible for AML/CTPF compliance.
- Conduct ongoing customer due diligence (CDD) and enhanced due diligence (EDD) as required by the Law on the Prevention of Money Laundering and Terrorism Financing.
- Report suspicious transactions to the FIU of Latvia.
- Ensure fitness and propriety of management and beneficial owners.
- Post-MiCA (from December 2024): Transition from registration to full authorization (licensing) with the Bank of Latvia (Latvijas Banka), including prudential safeguards (capital requirements), specific safekeeping rules for client crypto-assets, and detailed IT/security arrangements.
- Travel Rule obligations apply on withdrawals — comply with FATF Recommendation 16 / wire transfer rule requirements for virtual asset transfers (identity information transmitted with transfers).
Key Restrictions
- Must be a legal entity registered in Latvia (typically an SIA — Limited Liability Company) with a registered office in Latvia.
- Under current (pre-MiCA) regime: No explicit mandatory segregation of client crypto assets for non-bank VASPs, though good practice and risk management strongly recommend it. Post-MiCA (Dec 2024): strict segregation of client crypto-assets is mandated.
- No explicit insurance or bonding requirements specifically for custodial VASPs under current AML registration regime, but FIU expects robust risk management.
- No specific legislative mandate for exclusive cold storage under current regime, but robust security measures (multi-sig, cold storage) expected.
- Under MiCA (from Dec 2024): full authorization (license) from Bank of Latvia required, with specific safekeeping rules, prudential safeguards, and organizational requirements.
- If the exchange touches fiat currency payment processing, those aspects must also comply with PSD2/EMD regulations overseen by the Bank of Latvia (FCMC).
Key Risks
- Regulatory transition risk: Current AML registration regime is being superseded by MiCA licensing (Dec 2024), creating uncertainty during the transition period and potential need for re-authorization.
- No explicit custody segregation rules under current regime creates ambiguity and counterparty risk exposure for users; enforcement expectations may shift rapidly.
- Publicly reported large fines against pure crypto businesses are scarce, making enforcement precedent and penalty calibration unclear.
- Language barrier: primary regulatory guidance is in Latvian, increasing compliance interpretation risk.
- General good practice and risk management expectations from FIU may be enforced more strictly than written law suggests.
- MiCA implementation may introduce new capital and operational requirements that existing registrants must meet by Dec 2024.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Current Regime (Pre-MiCA): Registration. Latvia requires entities engaged in virtual asset services to register with the FIU. This registration is primarily an AML/CTPF compliance obligation, meaning the focus is on preventing money laundering and terrorist financing, rather than prudential supervision (e.g., capital adequacy for consumer protection, market integrity, etc., which is typical of a full licensing regime).
Future Regime (Post-MiCA): Licensing. Once MiCA fully applies to VASPs (expected December 2024), Latvia will transition to a comprehensive licensing regime under MiCA. This will involve more stringent requirements, including prudential safeguards, operational resilience, and specific disclosures, and will likely be overseen by the Bank of Latvia (FCMC).
Financial Intelligence Unit (FIU) of Latvia (Finanšu izlūkošanas dienests - FID): The primary authority responsible for registering and supervising VASPs for AML/CTPF compliance.
The applicant must be a legal entity registered in Latvia (typically a Limited Liability Company – SIA).
The company must have its registered office in Latvia.
AML/CTPF Internal Control System (ICS):
This is the core requirement. The company must establish a robust internal control system for AML/CTPF compliance, including:
Risk Assessment: A comprehensive assessment of the company's money laundering and terrorism financing risks.
Client Due Diligence (CDD) and Enhanced Due Diligence (EDD): Procedures for identifying and verifying clients, beneficial owners, and monitoring business relationships.
Transaction Monitoring: Systems for monitoring transactions for suspicious activities.
Reporting: Procedures for reporting suspicious transactions to the FIU.
Record-keeping: Maintaining records for a specified period (typically 5 years).
Training: Regular AML/CTPF training for employees.
Appointed AML Officer:
The company must appoint a board member or an employee (who reports directly to the board) as the responsible person for AML/CTPF compliance (the AML Officer).
Requirement: Entities providing services of custodial wallet providers (which includes safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs). They are required to register with the Latvian Financial Intelligence Unit (FID).
Process: The registration involves demonstrating compliance with AML/CTF requirements, including:
Developing and implementing robust internal control systems.
Appointing a responsible person for AML/CTF compliance.
Conducting customer due diligence (CDD) and ongoing monitoring.
Reporting suspicious transactions.
Ensuring the fitness and propriety of management and beneficial owners.
Law on the Prevention of Money Laundering and Terrorism Financing (AML/CFT Law) (Nozagoto noziedzīgi iegūtu līdzekļu legalizācijas un terorisma finansēšanas novēršanas likums): This is the primary law regulating AML/CFT, which also covers sanctions compliance for obligated entities, including VASPs.
Current Status: Under the current AML framework, there are no explicit, specific rules mandating the segregation of client crypto assets for non-bank VASPs. However, general good practice, risk management principles, and the expectation of investor protection inherent in financial services would strongly suggest that reputable custodians segregate client assets from their own operational funds. For traditional financial institutions providing crypto services, existing segregation rules for client funds/assets would generally apply.
Current Status: There are no explicit insurance or bonding requirements specifically for custodial VASPs under the current AML registration regime in Latvia. However, the FID expects VASPs to have robust internal controls and risk management procedures, which may indirectly lead to considering insurance as a best practice for operational risks.
Evidence fact lv.aml.current-status-there-are-no_2 not found (may have been renamed).
Current Status: The Latvian AML law refers to "custodial wallet providers" as a type of VASP requiring registration. There isn't a specific definition of a "qualified custodian" that goes beyond meeting the VASP registration requirements and AML/CTF obligations.
Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from the competent authority in the home Member State – in Latvia, this will be the Bank of Latvia (Latvijas Banka).
Authorization Process: CASPs will need to meet stringent requirements, including:
Specific organizational requirements (e.g., robust governance arrangements, internal control mechanisms).
Prudential safeguards (capital requirements).
Specific rules on the safekeeping of client crypto-assets.
Detailed information technology and security arrangements.
Suitability of management and shareholders.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
Mandate: MiCA explicitly mandates strict segregation of client crypto-assets.
Penalty Amount: Varies depending on the severity of the violation, ranging from warnings and administrative measures to significant fines. However, publicly reported large fines against pure crypto businesses are scarce. Outcome: Remedial actions required, potential fines, or in severe cases, withdrawal of registration/license.
Outcome: Remedial actions required, potential fines, or in severe cases, withdrawal of registration/license.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange operating in Latvia must register as a VASP with the FIU under the current AML/CTPF regime (local entity required, no explicit custody segregation rules yet), and will need to transition to a full MiCA license from the Bank of Latvia by December 2024 with stringent custody, prudential, and organizational requirements.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?