← Regulations / Montenegro / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Montenegro

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Montenegro with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASP licensing from the Capital Market Authority (KAP) is required — custody of digital assets for third parties (Article 18(1)(2)) is a regulated virtual asset service requiring a license under Article 20
  • Minimum capital requirements and guarantees for coverage of potential liabilities (Article 21(1)(7)) — amounts to be specified in subordinate regulations from KAP/CBCG
  • Client asset protection measures (Article 21(1)(9)) — typically requiring segregation of client assets from the VASP's own assets
  • Professional indemnity insurance or similar financial instruments to cover cyber-attack, operational failure, or loss of client assets
  • Adequate technical and security measures for safekeeping and protection of digital assets (Article 21(1)(6))
  • Possession of a cybersecurity certificate (Article 21(1)(10))
  • AML/CFT compliance as an obligated entity under the Law on Prevention of Money Laundering and Terrorism Financing — including CDD, ongoing monitoring, STR reporting to the Financial Intelligence Unit (USPNFT), risk assessment, internal controls
  • Appointment of a designated AML Officer with regular staff training
  • Travel Rule obligations: collect originator and beneficiary information, transmit securely to beneficiary VASP, screen for sanctions and suspicious activity
  • If virtual assets held are deemed 'securities' under Montenegrin law, additional investment-services license from KHOV (Capital Market Commission) may be required
  • If custody involves fiat currency handling, payment services/e-money license from the Central Bank of Montenegro (CBCG) may be required (minimum capital €20,000–€125,000 depending on service type)

Key Restrictions

  • Must be a legal entity established in Montenegro (Article 21(1)(1))
  • Must have a registered office and local management/personnel including a local AML Officer
  • Must have adequate organizational structure, internal control mechanisms, and risk management systems (Article 21(1)(2))
  • Management and key personnel must have suitable professional qualifications and reputation (Article 21(1)(3))
  • Must possess a cybersecurity certificate (Article 21(1)(10))
  • White-label/client structure: the licensed VASP (SaaS provider) retains primary regulatory responsibility; white-label clients do not need separate VASP licenses if they operate under the SaaS provider's license, but AML obligations for the SaaS provider cannot be delegated — the provider must ensure its platform does not facilitate client non-compliance
  • If SaaS provider touches fiat currency (e.g., fiat on-ramp/off-ramp), additional CBCG payment-services licensing may apply

Key Risks

  • Regulatory framework is very new (Law No. 80/23) — subordinate regulations and KAP/CBCG guidance on capital amounts, guarantee forms, and cybersecurity certification standards are not yet published, creating implementation uncertainty
  • EU MiCA alignment is anticipated — the regime may change significantly as Montenegro harmonizes with EU law as a candidate country
  • Do Kwon case has created heightened scrutiny on crypto actors in Montenegro — enforcement risk for any perceived non-compliance is elevated
  • Official English translations of the Blockchain Law and AML Law are not readily available; reliance on the authoritative Montenegrin text creates compliance complexity
  • Ambiguity around how securities classification applies to various digital assets held in custody — case-by-case assessment by KHOV creates legal risk
  • Clarity on whether the SaaS provider or the white-label client bears primary AML responsibility for end users is not explicitly addressed in primary legislation

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

Definition of VASP: Article 2(1)(7) defines a "virtual asset service provider" as a legal entity that, as its regular business activity, provides one or more of the virtual asset services specified in Article 18.

custody 60% confidence

Custody Service: Article 18(1)(2) specifies "custody of digital assets for third parties" as a regulated virtual asset service.

custody 60% confidence

Licensing Authority: The Capital Market Authority (KAP) is responsible for issuing, supervising, and revoking licenses for VASPs (Article 20).

custody 60% confidence

Licensing Conditions (Article 21): Applicants for a VASP license must meet several conditions, including:

custody 60% confidence

Legal entity established in Montenegro.

custody 60% confidence

Adequate organizational structure, internal control mechanisms, and risk management systems.

custody 60% confidence

Suitable professional qualifications and reputation of management and key personnel.

custody 60% confidence

Adequate technical and security measures for the safekeeping and protection of digital assets.

custody 60% confidence

Minimum capital requirements and guarantees for covering potential liabilities.

custody 60% confidence

Measures for the protection of client assets.

custody 60% confidence

Compliance with AML/CFT regulations.

custody 60% confidence

Possession of a cybersecurity certificate.

custody 60% confidence

Law on Blockchain, Digital Assets and Individual Digital Identifiers (Zakon o blokčejnu, digitalnoj imovini i individualnim digitalnim identitetima) - Official publication in the "Official Gazette of Montenegro," No. 80/23.

custody 60% confidence

Article 21(1)(9) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers explicitly requires VASPs to implement "measures for the protection of client assets." This typically implies segregation, ensuring that client assets are identifiable and separate from the VASP's own assets, to prevent commingling and protect clients in case of VASP insolvency. While the law doesn't detail how assets must be segregated (e.g., separate wallets, omnibus accounts with clear ledgering), the requirement for "measures for the protection of client assets" is the legal basis.

custody 60% confidence

Article 21(1)(7) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers states that a VASP must meet "minimum capital requirements" and provide "guarantees for the coverage of potential liabilities arising from the provision of virtual asset services."

custody 60% confidence

These "guarantees" can take various forms, including professional indemnity insurance or other financial instruments designed to cover risks such as cyber-attacks, operational failures, or loss of client assets. The specific nature and amount of these guarantees are likely to be detailed in subordinate legislation or regulations issued by the Capital Market Authority.

custody 60% confidence

EU Alignment (MiCA): Montenegro is an EU candidate country. The European Union's comprehensive Markets in Crypto-Assets Regulation (MiCA) came into full effect in December 2024 for VASPs. While Montenegro has passed its own law, it will eventually need to harmonize its legislation with MiCA as part of its EU accession process. This could lead to amendments or further refinement of the Montenegrin framework to fully align with MiCA's robust requirements for crypto-asset service providers (CASPs), including those offering custody. MiCA sets very detailed requirements for operational resilience, governance, client asset segregation, and liability for custody providers.

licensing 60% confidence

Custody providers are subject to AML/CTF obligations as "obligated entities."

licensing 60% confidence

If the virtual assets held in custody are deemed to be "securities" under Montenegrin law, then a license from the Capital Market Commission (KHOV) for providing investment services (e.g., safekeeping of financial instruments) might be required. This is a case-by-case assessment.

licensing 60% confidence

AML/KYC (Anti-Money Laundering / Know Your Customer): This is the most critical requirement for any VASP operating in Montenegro.

licensing 60% confidence

AML Officer: Appointment of a designated AML Officer and providing regular training to staff.

licensing 60% confidence

An entity generally needs to be incorporated in Montenegro to conduct business activities and be subject to local regulation.

licensing 60% confidence

A registered office and local management/personnel, including a local AML Officer, would typically be expected for AML compliance.

licensing 60% confidence

Company Registration: Establish a legal entity (e.g., LLC) in Montenegro with the Central Registry of Commercial Entities (CRPS).

licensing 60% confidence

AML Framework Implementation: Develop and implement comprehensive AML/CTF policies, procedures, and controls, appoint an AML Officer, and conduct a risk assessment.

aml 60% confidence

Law on Prevention of Money Laundering and Terrorism Financing (Zakon o sprječavanju pranja novca i finansiranja terorizma): This is the primary legislation. While an official English translation with a direct URL might be hard to find, the official Montenegrin legal gazette (Službeni list Crne Gore) publishes it. The most relevant amendments were made in 2021 to address virtual assets.

aml 60% confidence

Custody and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

Collect required originator and beneficiary information.

aml 60% confidence

Transmit this information securely and reliably to the beneficiary VASP (or store it for non-VASP beneficiaries).

aml 60% confidence

Screen transactions for sanctions compliance and suspicious activity.

aml 60% confidence

Respond to requests for information from competent authorities.

aml 60% confidence

Administrative Fines: Significant monetary penalties for legal entities and responsible persons within those entities.

aml 60% confidence

Revocation of Licenses: Suspension or permanent revocation of operating licenses for VASPs.

aml 60% confidence

Criminal Charges: In cases of severe or intentional non-compliance, particularly where money laundering or terrorism financing is involved, criminal charges can be brought against individuals and corporate officers.

aml 60% confidence

Financial Intelligence Unit (FIU) of Montenegro (Uprava za sprečavanje pranja novca i finansiranja terorizma - USPNFT): This is the main supervisory body for AML/CFT compliance, including for VASPs. Their website may contain guidance.

aml 60% confidence

MONEYVAL Follow-Up Report (May 2023): This report by Moneyval (Council of Europe anti-money laundering body) provides a detailed assessment of Montenegro's compliance with FATF Recommendations. It explicitly states Montenegro's compliance with Recommendation 15 (Virtual Assets and VASPs) and the implementation of the Travel Rule.

enforcement 60% confidence

Entity Targeted: Do Kwon (and his associate Hon Chang Joon). Violation Type (Montenegro Specific): Forgery of documents (using fake Costa Rican and Belgian passports for illegal entry and travel).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are permitted in Montenegro only as licensed VASPs from the Capital Market Authority (KAP), requiring a local legal entity, minimum capital and guarantees, cybersecurity certification, client asset segregation, and full AML/CFT obligations, with significant regulatory uncertainty pending subordinate regulations and future MiCA alignment.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?