DeFi protocol frontend in Montenegro
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Montenegro with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Must register as an 'obligated entity' under the Law on Prevention of Money Laundering and Terrorism Financing (Official Gazette No. 042/2015, as amended through 014/2021), which transposes EU 5AMLD and covers VASPs (FATF R.15 compliant per MONEYVAL May 2023).
- Customer Due Diligence (CDD): Implement robust KYC procedures for all clients using the frontend — the law covers 'exchange between virtual assets and fiat currencies' and 'exchange between one or more forms of virtual assets'.
- Ongoing transaction monitoring for suspicious activity.
- Reporting: File Suspicious Transaction Reports (STRs) with the Financial Intelligence Unit (FIU/USPNFT).
- Sanctions screening of transactions — collect, transmit, and verify originator and beneficiary information for virtual asset transfers.
- Conduct a comprehensive ML/TF risk assessment.
- Appoint a designated local AML Officer and provide regular staff training.
- Establish internal policies, procedures, and controls for AML/CTF.
- No specific capital requirements for AML-only obligations, but if payment services/e-money licensing also triggered (if fiat is involved), minimum capital of €20,000–€125,000 applies depending on the service.
Key Restrictions
- A legal entity must be incorporated in Montenegro (registered with the Central Registry of Commercial Entities - CRPS) with a registered office and local management/personnel.
- A local AML Officer must be appointed.
- If the frontend handles fiat deposits/withdrawals (e.g., fiat on-ramp/off-ramp), it may trigger payment services or e-money licensing from the Central Bank of Montenegro (CBCG) under the Law on Payment Services.
- If frontend provides any form of custody (e.g., intermediary wallets), a VASP license is required from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers (Official Gazette No. 80/23), with conditions including minimum capital, cybersecurity certificate, organizational structure, and client asset protections.
- If frontend involves tokenized assets that qualify as 'securities', a license from the Capital Market Commission (KHOV) for investment services may be required (case-by-case).
- Fee-taking (e.g., trading fees, routing fees) likely classifies the operator as engaging in 'exchange between virtual assets' as a business, cementing regulated activity status.
Key Risks
- Regulatory ambiguity: No specific 'crypto exchange license' exists; classification depends on whether the frontend touches fiat, custody, or securities-like assets — each triggers a different regulator (CBCG, KAP, or KHOV).
- Enforcement precedent: Montenegro arrested and convicted Do Kwon (March 2023, four months imprisonment for document forgery); the high-profile nature of crypto enforcement signals active scrutiny.
- The DeFi frontend model is not explicitly addressed in the Blockchain Law or AML law — regulators may assert that any fee-collecting frontend interacting with users is a VASP engaging in exchange or transfer of virtual assets.
- Penalties for non-compliance include significant administrative fines, license revocation, and criminal charges for severe/intentional violations (per the AML law).
- EU alignment pressure: Montenegro will need to harmonize with MiCA as an EU candidate country, potentially changing the regulatory framework.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Cryptocurrency Exchanges (Fiat-to-Crypto/Crypto-to-Fiat):
There is no specific "crypto exchange license".
However, if the exchange handles fiat currency deposits and withdrawals, it might be deemed to provide payment services or electronic money services. In such cases, a license from the Central Bank of Montenegro (CBCG) under the Law on Payment Services (Zakon o platnom prometu) may be required. This would be a license for a payment institution or electronic money institution, not a crypto-specific one.
All exchanges, regardless of fiat handling, are considered "obligated entities" under AML laws and must comply with those provisions.
AML/KYC (Anti-Money Laundering / Know Your Customer): This is the most critical requirement for any VASP operating in Montenegro.
Customer Due Diligence (CDD): Implementing robust KYC procedures for all clients.
Ongoing Monitoring: Monitoring transactions and client relationships for suspicious activities.
Reporting: Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FZPCG).
Risk Assessment: Conducting a comprehensive risk assessment of ML/TF risks.
Internal Controls: Establishing internal policies, procedures, and controls for AML/CTF.
AML Officer: Appointment of a designated AML Officer and providing regular training to staff.
There are no specific capital requirements for being a VASP solely under AML obligations.
An entity generally needs to be incorporated in Montenegro to conduct business activities and be subject to local regulation.
A registered office and local management/personnel, including a local AML Officer, would typically be expected for AML compliance.
Company Registration: Establish a legal entity (e.g., LLC) in Montenegro with the Central Registry of Commercial Entities (CRPS).
Law on Prevention of Money Laundering and Terrorism Financing (Zakon o sprječavanju pranja novca i finansiranja terorizma): This is the primary legislation. While an official English translation with a direct URL might be hard to find, the official Montenegrin legal gazette (Službeni list Crne Gore) publishes it. The most relevant amendments were made in 2021 to address virtual assets.
Official Gazette of Montenegro, No. 042/2015, 052/2016, 080/2017, 070/2019, 014/2021 (and subsequent amendments if any).
This law defines "obliged entities" and outlines their AML/CFT responsibilities. With the latest amendments, VASPs are explicitly included or fall under broader categories that capture their activities. The law is designed to transpose EU AML Directives into Montenegrin national law.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Collect required originator and beneficiary information.
Transmit this information securely and reliably to the beneficiary VASP (or store it for non-VASP beneficiaries).
Screen transactions for sanctions compliance and suspicious activity.
Respond to requests for information from competent authorities.
Administrative Fines: Significant monetary penalties for legal entities and responsible persons within those entities.
Revocation of Licenses: Suspension or permanent revocation of operating licenses for VASPs.
Criminal Charges: In cases of severe or intentional non-compliance, particularly where money laundering or terrorism financing is involved, criminal charges can be brought against individuals and corporate officers.
MONEYVAL Follow-Up Report (May 2023): This report by Moneyval (Council of Europe anti-money laundering body) provides a detailed assessment of Montenegro's compliance with FATF Recommendations. It explicitly states Montenegro's compliance with Recommendation 15 (Virtual Assets and VASPs) and the implementation of the Travel Rule.
Relevant excerpt from the May 2023 Moneyval report (page 14): "Montenegro has addressed the deficiencies identified in its AML/CFT Law and bylaws regarding FATF R.15 (virtual assets and VASPs) and it has been re-rated from PC to C. The AML/CFT law has been amended in 2021 by transposing EU 5AMLD, which now includes a comprehensive framework for VASPs. The requirements for obliged entities (VASPs) are fully incorporated into the AML/CFT Law and bylaws. They include customer due diligence, reporting suspicious transactions, and requirements for record-keeping and travel rule."
Definition of VASP: Article 2(1)(7) defines a "virtual asset service provider" as a legal entity that, as its regular business activity, provides one or more of the virtual asset services specified in Article 18.
Licensing Authority: The Capital Market Authority (KAP) is responsible for issuing, supervising, and revoking licenses for VASPs (Article 20).
Legal entity established in Montenegro.
Law on Blockchain, Digital Assets and Individual Digital Identifiers (Zakon o blokčejnu, digitalnoj imovini i individualnim digitalnim identitetima) - Official publication in the "Official Gazette of Montenegro," No. 80/23.
Article 21(1)(9) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers explicitly requires VASPs to implement "measures for the protection of client assets." This typically implies segregation, ensuring that client assets are identifiable and separate from the VASP's own assets, to prevent commingling and protect clients in case of VASP insolvency. While the law doesn't detail how assets must be segregated (e.g., separate wallets, omnibus accounts with clear ledgering), the requirement for "measures for the protection of client assets" is the legal basis.
Article 21(1)(7) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers states that a VASP must meet "minimum capital requirements" and provide "guarantees for the coverage of potential liabilities arising from the provision of virtual asset services."
Do Kwon: Sentenced to four months in prison.
Arrest: March 23, 2023
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi frontend operator serving Montenegrin residents would be classified as a VASP/obligated entity subject to AML registration and compliance (including KYC, transaction monitoring, STR reporting, sanctions screening, and a local AML Officer), and must incorporate locally; if fee-taking with fiat on/off-ramp features, additional payment services or e-money licensing from the CBCG may be triggered, and if any custody is involved, a full VASP license from the KAP under the Blockchain Law is required.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?