← Regulations / Montenegro / Operating Models / CEX

Centralized exchange in Montenegro

Order-book exchange that takes custody of user assets and matches trades between users.

Conditional AI-Generated · Unreviewed

CEX is conditionally permitted in Montenegro with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) — robust KYC procedures for all clients under the Law on Prevention of Money Laundering and Terrorism Financing (me.aml.law-on-prevention-of-money, me.licensing.customer-due-diligence-cdd-implementing)
  • Ongoing transaction monitoring for suspicious activities (me.licensing.ongoing-monitoring-monitoring-transactions-and)
  • Suspicious Transaction Reporting (STRs) to the Financial Intelligence Unit (FZPCG/USPNFT) (me.licensing.reporting-reporting-suspicious-transactions-strs, me.aml.financial-intelligence-unit-fiu-of)
  • Comprehensive ML/TF risk assessment (me.licensing.risk-assessment-conducting-a-comprehensive)
  • Appointment of a designated AML Officer with regular staff training (me.licensing.aml-officer-appointment-of-a, me.licensing.internal-controls-establishing-internal-policies)
  • Travel Rule obligations: collect originator and beneficiary information, transmit securely to beneficiary VASP, screen for sanctions, respond to competent authority requests (me.aml.transfer-of-virtual-assets, me.aml.collect-required-originator-and-beneficiary, me.aml.transmit-this-information-securely-and, me.aml.screen-transactions-for-sanctions-compliance, me.aml.respond-to-requests-for-information)
  • Sanctions screening obligations (me.aml.screen-transactions-for-sanctions-compliance)

Key Restrictions

  • Must be incorporated as a legal entity in Montenegro (me.custody.legal-entity-established-in-montenegro, me.licensing.an-entity-generally-needs-to)
  • Must obtain a VASP license from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers (me.custody.licensing-authority-the-capital-market, me.custody.licensing-conditions-article-21-applicants)
  • Minimum capital requirements and guarantees for potential liability coverage must be met (me.custody.minimum-capital-requirements-and-guarantees, me.custody.article-2117-of-the-law)
  • If fiat handling is involved, a payment services or e-money license from the Central Bank of Montenegro (CBCG) may also be required, with capital requirements of €20,000–€125,000 depending on service type (me.licensing.however-if-the-exchange-handles, me.licensing.however-if-a-license-from)
  • Client asset segregation — measures for protection of client assets must be implemented (me.custody.article-2119-of-the-law, me.custody.measures-for-the-protection-of)
  • Must obtain a cybersecurity certificate (me.custody.possession-of-a-cybersecurity-certificate)
  • Adequate organizational structure, internal controls, risk management systems, and fit-and-proper management required (me.custody.adequate-organizational-structure-internal-control, me.custody.suitable-professional-qualifications-and-reputation)
  • If virtual assets held in custody are deemed securities, a license from the Capital Market Commission (KHOV) for investment services may also be required (me.licensing.if-the-virtual-assets-held)

Key Risks

  • Regulatory ambiguity — subordinate legislation (bylaws, guidance from KAP and CBCG) is still expected; precise capital amounts and guarantee forms not yet fully specified (me.custody.subordinate-legislation-and-guidance-the)
  • EU MiCA harmonisation risk — Montenegro as an EU candidate must align with MiCA, which could trigger significant regulatory changes mid-operation (me.custody.eu-alignment-mica-montenegro-is)
  • Enforcement precedent — the Do Kwon case shows active enforcement by Montenegrin authorities (forgery charges) and willingness to engage with international extradition requests, signalling heightened scrutiny on crypto operators (me.enforcement.entity-targeted-do-kwon-and, me.enforcement.do-kwon-sentenced-to-four)
  • Penalties for AML non-compliance include significant fines, license revocation, and criminal charges (me.aml.administrative-fines-significant-monetary-penalties, me.aml.revocation-of-licenses-suspension-or, me.aml.criminal-charges-in-cases-of)
  • Local management / AML Officer must be in-country, creating operational overhead (me.licensing.a-registered-office-and-local)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Cryptocurrency Exchanges (Fiat-to-Crypto/Crypto-to-Fiat):

licensing 60% confidence

There is no specific "crypto exchange license".

licensing 60% confidence

However, if the exchange handles fiat currency deposits and withdrawals, it might be deemed to provide payment services or electronic money services. In such cases, a license from the Central Bank of Montenegro (CBCG) under the Law on Payment Services (Zakon o platnom prometu) may be required. This would be a license for a payment institution or electronic money institution, not a crypto-specific one.

licensing 60% confidence

All exchanges, regardless of fiat handling, are considered "obligated entities" under AML laws and must comply with those provisions.

licensing 60% confidence

Customer Due Diligence (CDD): Implementing robust KYC procedures for all clients.

licensing 60% confidence

Ongoing Monitoring: Monitoring transactions and client relationships for suspicious activities.

licensing 60% confidence

Reporting: Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FZPCG).

licensing 60% confidence

Risk Assessment: Conducting a comprehensive risk assessment of ML/TF risks.

licensing 60% confidence

Internal Controls: Establishing internal policies, procedures, and controls for AML/CTF.

licensing 60% confidence

AML Officer: Appointment of a designated AML Officer and providing regular training to staff.

licensing 60% confidence

There are no specific capital requirements for being a VASP solely under AML obligations.

licensing 60% confidence

However, if a license from the CBCG (for payment services/e-money) or KHOV (for investment services) is required, then specific capital requirements would apply based on those respective laws. For instance, payment institutions have minimum capital requirements (e.g., €20,000 to €125,000 depending on services).

licensing 60% confidence

An entity generally needs to be incorporated in Montenegro to conduct business activities and be subject to local regulation.

licensing 60% confidence

A registered office and local management/personnel, including a local AML Officer, would typically be expected for AML compliance.

custody 60% confidence

Definition of VASP: Article 2(1)(7) defines a "virtual asset service provider" as a legal entity that, as its regular business activity, provides one or more of the virtual asset services specified in Article 18.

custody 60% confidence

Custody Service: Article 18(1)(2) specifies "custody of digital assets for third parties" as a regulated virtual asset service.

custody 60% confidence

Licensing Authority: The Capital Market Authority (KAP) is responsible for issuing, supervising, and revoking licenses for VASPs (Article 20).

custody 60% confidence

Licensing Conditions (Article 21): Applicants for a VASP license must meet several conditions, including:

custody 60% confidence

Legal entity established in Montenegro.

custody 60% confidence

Adequate organizational structure, internal control mechanisms, and risk management systems.

custody 60% confidence

Suitable professional qualifications and reputation of management and key personnel.

custody 60% confidence

Adequate technical and security measures for the safekeeping and protection of digital assets.

custody 60% confidence

Minimum capital requirements and guarantees for covering potential liabilities.

custody 60% confidence

Measures for the protection of client assets.

custody 60% confidence

Compliance with AML/CFT regulations.

custody 60% confidence

Possession of a cybersecurity certificate.

custody 60% confidence

Law on Blockchain, Digital Assets and Individual Digital Identifiers (Zakon o blokčejnu, digitalnoj imovini i individualnim digitalnim identitetima) - Official publication in the "Official Gazette of Montenegro," No. 80/23.

custody 60% confidence

Article 21(1)(9) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers explicitly requires VASPs to implement "measures for the protection of client assets." This typically implies segregation, ensuring that client assets are identifiable and separate from the VASP's own assets, to prevent commingling and protect clients in case of VASP insolvency. While the law doesn't detail how assets must be segregated (e.g., separate wallets, omnibus accounts with clear ledgering), the requirement for "measures for the protection of client assets" is the legal basis.

custody 60% confidence

Article 21(1)(7) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers states that a VASP must meet "minimum capital requirements" and provide "guarantees for the coverage of potential liabilities arising from the provision of virtual asset services."

custody 60% confidence

Subordinate Legislation and Guidance: The Capital Market Authority (KAP) and the Central Bank of Montenegro (CBCG) are expected to issue detailed bylaws, regulations, and guidance to clarify the implementation of the Blockchain Law, including specific requirements for capital, guarantees, risk management, and cybersecurity for VASPs providing custody services. These will provide the practical details for compliance.

custody 60% confidence

EU Alignment (MiCA): Montenegro is an EU candidate country. The European Union's comprehensive Markets in Crypto-Assets Regulation (MiCA) came into full effect in December 2024 for VASPs. While Montenegro has passed its own law, it will eventually need to harmonize its legislation with MiCA as part of its EU accession process. This could lead to amendments or further refinement of the Montenegrin framework to fully align with MiCA's robust requirements for crypto-asset service providers (CASPs), including those offering custody. MiCA sets very detailed requirements for operational resilience, governance, client asset segregation, and liability for custody providers.

aml 60% confidence

Law on Prevention of Money Laundering and Terrorism Financing (Zakon o sprječavanju pranja novca i finansiranja terorizma): This is the primary legislation. While an official English translation with a direct URL might be hard to find, the official Montenegrin legal gazette (Službeni list Crne Gore) publishes it. The most relevant amendments were made in 2021 to address virtual assets.

aml 20% confidence

Exchange between virtual assets and fiat currencies.

aml 20% confidence

Exchange between one or more forms of virtual assets.

aml 60% confidence

Custody and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

Transfer of virtual assets.

aml 60% confidence

Collect required originator and beneficiary information.

aml 60% confidence

Transmit this information securely and reliably to the beneficiary VASP (or store it for non-VASP beneficiaries).

aml 60% confidence

Screen transactions for sanctions compliance and suspicious activity.

aml 60% confidence

Respond to requests for information from competent authorities.

aml 60% confidence

Administrative Fines: Significant monetary penalties for legal entities and responsible persons within those entities.

aml 60% confidence

Revocation of Licenses: Suspension or permanent revocation of operating licenses for VASPs.

aml 60% confidence

Criminal Charges: In cases of severe or intentional non-compliance, particularly where money laundering or terrorism financing is involved, criminal charges can be brought against individuals and corporate officers.

aml 60% confidence

Financial Intelligence Unit (FIU) of Montenegro (Uprava za sprečavanje pranja novca i finansiranja terorizma - USPNFT): This is the main supervisory body for AML/CFT compliance, including for VASPs. Their website may contain guidance.

aml 60% confidence

MONEYVAL Follow-Up Report (May 2023): This report by Moneyval (Council of Europe anti-money laundering body) provides a detailed assessment of Montenegro's compliance with FATF Recommendations. It explicitly states Montenegro's compliance with Recommendation 15 (Virtual Assets and VASPs) and the implementation of the Travel Rule.

enforcement 60% confidence

Entity Targeted: Do Kwon (and his associate Hon Chang Joon). Violation Type (Montenegro Specific): Forgery of documents (using fake Costa Rican and Belgian passports for illegal entry and travel).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a centralized exchange with custody services is permitted in Montenegro but requires a VASP license from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers, local incorporation, significant AML/CTF obligations including the travel rule, and potentially a separate CBCG payment services license if fiat handling is involved; some subordinate regulations remain pending, creating moderate regulatory ambiguity.

Questions this verdict aims to answer

  • What exchange / VASP license applies?
  • What custody segregation rules apply to user assets?
  • What market-conduct and listing rules apply?
  • What travel-rule obligations apply on withdrawals?