Custodial wallet / SaaS in Latvia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Latvia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the FIU (Finanšu izlūkošanas dienests - FID) as a VASP under the AML/CTF Law (Nozagoto noziedzīgi iegūtu līdzekļu legalizācijas un terorisma finansēšanas novēršanas likums).
- Must develop and implement robust AML/CTPF Internal Control System (ICS) including: risk assessment, CDD/EDD procedures, transaction monitoring systems, suspicious transaction reporting procedures, record-keeping (minimum 5 years), and regular employee AML/CTPF training.
- Appointment of a board member or employee as the designated AML Officer responsible for AML/CTPF compliance.
- Fitness and propriety checks on management and beneficial owners.
- Reporting suspicious transactions to the FIU.
- Post-MiCA (from 30 December 2024): Full CASP authorization from the Bank of Latvia (Latvijas Banka) with prudential safeguards (capital requirements), specific rules on safekeeping of client crypto-assets, and detailed IT/security arrangements.
- MiCA mandates strict segregation of client crypto-assets (from 30 December 2024).
Key Restrictions
- Operator must be a legal entity registered in Latvia (typically an SIA) with registered office in Latvia.
- Current regime (pre-MiCA) is AML registration only — no specific segregation, insurance, or cold-storage rules, but FIU expects robust internal controls and risk management.
- Post-MiCA (from 30 December 2024): Full licensing required with prudential safeguards, client asset segregation rules, and authorization from the Bank of Latvia.
- White-label model: Both the SaaS provider and the white-label client may be VASPs depending on who has custody and control. The entity that safeguards/administers virtual assets on behalf of end users needs registration/licensing; careful allocation of AML obligations is required under a written agreement.
Key Risks
- Pre-MiCA gap: No explicit segregation, insurance, or proof-of-reserves rules for crypto custodians — creates investor protection risk and regulatory uncertainty.
- Post-MiCA transition: Operators must be prepared to upgrade from AML registration to full CASP licensing with significantly higher capital and operational requirements by 30 December 2024.
- White-label model ambiguity: Unclear allocation of AML obligations between SaaS provider and client under current regime — FIU may hold both jointly liable.
- Limited enforcement precedent: Publicly reported fines against pure crypto businesses are scarce, creating uncertainty about supervisory approach.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Intelligence Unit (FIU) of Latvia (Finanšu izlūkošanas dienests - FID): The primary authority responsible for registering and supervising VASPs for AML/CTPF compliance.
Current Regime (Pre-MiCA): Registration. Latvia requires entities engaged in virtual asset services to register with the FIU. This registration is primarily an AML/CTPF compliance obligation, meaning the focus is on preventing money laundering and terrorist financing, rather than prudential supervision (e.g., capital adequacy for consumer protection, market integrity, etc., which is typical of a full licensing regime).
Future Regime (Post-MiCA): Licensing. Once MiCA fully applies to VASPs (expected December 2024), Latvia will transition to a comprehensive licensing regime under MiCA. This will involve more stringent requirements, including prudential safeguards, operational resilience, and specific disclosures, and will likely be overseen by the Bank of Latvia (FCMC).
Custody Providers (Virtual Asset Wallet Service Providers):
Entities offering services to safeguard or administer virtual assets or instruments enabling control over virtual assets on behalf of third parties. This includes custodial wallet providers.
The applicant must be a legal entity registered in Latvia (typically a Limited Liability Company – SIA).
The company must have its registered office in Latvia.
Requirement: Entities providing services of custodial wallet providers (which includes safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of clients) are considered Virtual Asset Service Providers (VASPs). They are required to register with the Latvian Financial Intelligence Unit (FID).
Process: The registration involves demonstrating compliance with AML/CTF requirements, including:
Current Status: Under the current AML framework, there are no explicit, specific rules mandating the segregation of client crypto assets for non-bank VASPs. However, general good practice, risk management principles, and the expectation of investor protection inherent in financial services would strongly suggest that reputable custodians segregate client assets from their own operational funds. For traditional financial institutions providing crypto services, existing segregation rules for client funds/assets would generally apply.
Current Status: There are no explicit insurance or bonding requirements specifically for custodial VASPs under the current AML registration regime in Latvia. However, the FID expects VASPs to have robust internal controls and risk management procedures, which may indirectly lead to considering insurance as a best practice for operational risks.
Requirement: Under MiCA, providing "custody and administration of crypto-assets on behalf of clients" will require a full authorization (license) from the competent authority in the home Member State – in Latvia, this will be the Bank of Latvia (Latvijas Banka).
Authorization Process: CASPs will need to meet stringent requirements, including:
Mandate: MiCA explicitly mandates strict segregation of client crypto-assets.
Law on the Prevention of Money Laundering and Terrorism Financing (AML/CFT Law) (Nozagoto noziedzīgi iegūtu līdzekļu legalizācijas un terorisma finansēšanas novēršanas likums): This is the primary law regulating AML/CFT, which also covers sanctions compliance for obligated entities, including VASPs.
Penalty Amount: Varies depending on the severity of the violation, ranging from warnings and administrative measures to significant fines. However, publicly reported large fines against pure crypto businesses are scarce. Outcome: Remedial actions required, potential fines, or in severe cases, withdrawal of registration/license.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are permitted in Latvia as registered VASPs under the current AML regime (pre-MiCA) but must transition to full CASP licensing under MiCA by 30 December 2024, with a local Latvian entity required, AML obligations including registration with the FIU, and post-MiCA rules requiring strict client asset segregation and prudential safeguards.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?