On-shore VASP in Montenegro
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Montenegro with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Implement robust KYC procedures for all clients under the Law on Prevention of Money Laundering and Terrorism Financing (Official Gazette No. 042/2015, 052/2016, 080/2017, 070/2019, 014/2021).
- Ongoing monitoring: Monitor transactions and client relationships for suspicious activities.
- Reporting: Report suspicious transactions (STRs) to the Financial Intelligence Unit (FIU/USPNFT).
- Conduct a comprehensive money laundering / terrorist financing risk assessment.
- Establish internal AML/CTF policies, procedures, and controls.
- Appoint a designated AML Officer with regular staff training.
- Sanctions screening: Screen transactions for sanctions compliance.
- Travel Rule compliance: Collect and transmit originator and beneficiary information for transfers of virtual assets.
- Respond to information requests from competent authorities.
Key Restrictions
- Must be a legal entity incorporated in Montenegro in the Central Registry of Commercial Entities (CRPS).
- Must obtain a VASP license from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers (Official Gazette No. 80/23).
- Minimum capital requirements and guarantees for covering potential liabilities apply (amounts to be detailed in subordinate regulations).
- Must have adequate organizational structure, internal control mechanisms, and risk management systems.
- Must meet fit-and-proper requirements for management and key personnel.
- Must have adequate technical and security measures for digital asset safekeeping, including cybersecurity certification.
- Client assets must be segregated and protected under segregation rules.
- If handling fiat currency, may need a separate payment services/e-money license from the Central Bank of Montenegro (CBCG) under the Law on Payment Services.
- If virtual assets held are deemed securities, a license from the Capital Market Commission (KHOV) for investment services may also be required (case-by-case).
Key Risks
- Regulatory ambiguity: Subordinate legislation and KAP guidance clarifying capital/guarantee amounts, cybersecurity specifics, and other detailed requirements are not yet fully published.
- MiCA alignment risk: Montenegro is an EU candidate country and will need to harmonize with MiCA regulations, potentially causing a future regulatory shift and re-licensing.
- Do Kwon enforcement precedent signals heightened scrutiny on crypto actors in Montenegro; document forgery and related charges were aggressively pursued.
- Extradition proceedings for Do Kwon remain ongoing, creating political and reputational exposure for the crypto sector in Montenegro.
- Tax compliance complexity: Crypto gains, staking, airdrops, and mining have ambiguous tax treatment (PIT/CIT/VAT), requiring careful record-keeping and professional advice.
- The FIU (USPNFT) and Tax Administration require filings in Montenegrin language, creating an administrative burden for non-local operators.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Cryptocurrency Exchanges (Fiat-to-Crypto/Crypto-to-Fiat):
There is no specific "crypto exchange license".
However, if the exchange handles fiat currency deposits and withdrawals, it might be deemed to provide payment services or electronic money services. In such cases, a license from the Central Bank of Montenegro (CBCG) under the Law on Payment Services (Zakon o platnom prometu) may be required. This would be a license for a payment institution or electronic money institution, not a crypto-specific one.
All exchanges, regardless of fiat handling, are considered "obligated entities" under AML laws and must comply with those provisions.
Custody Providers (of Virtual Assets):
There is no specific "crypto exchange license".
Custody providers are subject to AML/CTF obligations as "obligated entities."
If the virtual assets held in custody are deemed to be "securities" under Montenegrin law, then a license from the Capital Market Commission (KHOV) for providing investment services (e.g., safekeeping of financial instruments) might be required. This is a case-by-case assessment.
Payment Processors (Crypto-native/Crypto-to-Crypto):
There is no specific "crypto exchange license".
If the processing involves fiat currency (e.g., converting crypto payments into fiat for merchants), it could fall under the Law on Payment Services and require a license from the CBCG as a payment institution.
If the processing is purely crypto-to-crypto and does not touch fiat or traditional payment rails, the primary obligation would be AML/CTF compliance.
AML/KYC (Anti-Money Laundering / Know Your Customer): This is the most critical requirement for any VASP operating in Montenegro.
Customer Due Diligence (CDD): Implementing robust KYC procedures for all clients.
Ongoing Monitoring: Monitoring transactions and client relationships for suspicious activities.
Reporting: Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FZPCG).
Risk Assessment: Conducting a comprehensive risk assessment of ML/TF risks.
Internal Controls: Establishing internal policies, procedures, and controls for AML/CTF.
AML Officer: Appointment of a designated AML Officer and providing regular training to staff.
There are no specific capital requirements for being a VASP solely under AML obligations.
However, if a license from the CBCG (for payment services/e-money) or KHOV (for investment services) is required, then specific capital requirements would apply based on those respective laws. For instance, payment institutions have minimum capital requirements (e.g., €20,000 to €125,000 depending on services).
An entity generally needs to be incorporated in Montenegro to conduct business activities and be subject to local regulation.
A registered office and local management/personnel, including a local AML Officer, would typically be expected for AML compliance.
Company Registration: Establish a legal entity (e.g., LLC) in Montenegro with the Central Registry of Commercial Entities (CRPS).
AML Framework Implementation: Develop and implement comprehensive AML/CTF policies, procedures, and controls, appoint an AML Officer, and conduct a risk assessment.
Definition of VASP: Article 2(1)(7) defines a "virtual asset service provider" as a legal entity that, as its regular business activity, provides one or more of the virtual asset services specified in Article 18.
Custody Service: Article 18(1)(2) specifies "custody of digital assets for third parties" as a regulated virtual asset service.
Licensing Authority: The Capital Market Authority (KAP) is responsible for issuing, supervising, and revoking licenses for VASPs (Article 20).
Licensing Conditions (Article 21): Applicants for a VASP license must meet several conditions, including:
Legal entity established in Montenegro.
Adequate organizational structure, internal control mechanisms, and risk management systems.
Suitable professional qualifications and reputation of management and key personnel.
Adequate technical and security measures for the safekeeping and protection of digital assets.
Minimum capital requirements and guarantees for covering potential liabilities.
Measures for the protection of client assets.
Compliance with AML/CFT regulations.
Possession of a cybersecurity certificate.
Law on Blockchain, Digital Assets and Individual Digital Identifiers (Zakon o blokčejnu, digitalnoj imovini i individualnim digitalnim identitetima) - Official publication in the "Official Gazette of Montenegro," No. 80/23.
Capital Market Authority (KAP) website: https://www.kap.co.me/ (For official announcements and forms related to licensing)
Article 21(1)(9) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers explicitly requires VASPs to implement "measures for the protection of client assets." This typically implies segregation, ensuring that client assets are identifiable and separate from the VASP's own assets, to prevent commingling and protect clients in case of VASP insolvency. While the law doesn't detail how assets must be segregated (e.g., separate wallets, omnibus accounts with clear ledgering), the requirement for "measures for the protection of client assets" is the legal basis.
Article 21(1)(7) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers states that a VASP must meet "minimum capital requirements" and provide "guarantees for the coverage of potential liabilities arising from the provision of virtual asset services."
These "guarantees" can take various forms, including professional indemnity insurance or other financial instruments designed to cover risks such as cyber-attacks, operational failures, or loss of client assets. The specific nature and amount of these guarantees are likely to be detailed in subordinate legislation or regulations issued by the Capital Market Authority.
Subordinate Legislation and Guidance: The Capital Market Authority (KAP) and the Central Bank of Montenegro (CBCG) are expected to issue detailed bylaws, regulations, and guidance to clarify the implementation of the Blockchain Law, including specific requirements for capital, guarantees, risk management, and cybersecurity for VASPs providing custody services. These will provide the practical details for compliance.
EU Alignment (MiCA): Montenegro is an EU candidate country. The European Union's comprehensive Markets in Crypto-Assets Regulation (MiCA) came into full effect in December 2024 for VASPs. While Montenegro has passed its own law, it will eventually need to harmonize its legislation with MiCA as part of its EU accession process. This could lead to amendments or further refinement of the Montenegrin framework to fully align with MiCA's robust requirements for crypto-asset service providers (CASPs), including those offering custody. MiCA sets very detailed requirements for operational resilience, governance, client asset segregation, and liability for custody providers.
Law on Prevention of Money Laundering and Terrorism Financing (Zakon o sprječavanju pranja novca i finansiranja terorizma): This is the primary legislation. While an official English translation with a direct URL might be hard to find, the official Montenegrin legal gazette (Službeni list Crne Gore) publishes it. The most relevant amendments were made in 2021 to address virtual assets.
Official Gazette of Montenegro, No. 042/2015, 052/2016, 080/2017, 070/2019, 014/2021 (and subsequent amendments if any).
This law defines "obliged entities" and outlines their AML/CFT responsibilities. With the latest amendments, VASPs are explicitly included or fall under broader categories that capture their activities. The law is designed to transpose EU AML Directives into Montenegrin national law.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Custody and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.
Exchanges between virtual assets and fiat currencies.
Exchanges between one or more forms of virtual assets.
Transfer of virtual assets.
Collect required originator and beneficiary information.
Transmit this information securely and reliably to the beneficiary VASP (or store it for non-VASP beneficiaries).
Screen transactions for sanctions compliance and suspicious activity.
Respond to requests for information from competent authorities.
Administrative Fines: Significant monetary penalties for legal entities and responsible persons within those entities.
Revocation of Licenses: Suspension or permanent revocation of operating licenses for VASPs.
Criminal Charges: In cases of severe or intentional non-compliance, particularly where money laundering or terrorism financing is involved, criminal charges can be brought against individuals and corporate officers.
The penalties are designed to be proportionate and dissuasive, reflecting the severity of the violation.
Financial Intelligence Unit (FIU) of Montenegro (Uprava za sprečavanje pranja novca i finansiranja terorizma - USPNFT): This is the main supervisory body for AML/CFT compliance, including for VASPs. Their website may contain guidance.
MONEYVAL Follow-Up Report (May 2023): This report by Moneyval (Council of Europe anti-money laundering body) provides a detailed assessment of Montenegro's compliance with FATF Recommendations. It explicitly states Montenegro's compliance with Recommendation 15 (Virtual Assets and VASPs) and the implementation of the Travel Rule.
Relevant excerpt from the May 2023 Moneyval report (page 14): "Montenegro has addressed the deficiencies identified in its AML/CFT Law and bylaws regarding FATF R.15 (virtual assets and VASPs) and it has been re-rated from PC to C. The AML/CFT law has been amended in 2021 by transposing EU 5AMLD, which now includes a comprehensive framework for VASPs. The requirements for obliged entities (VASPs) are fully incorporated into the AML/CFT Law and bylaws. They include customer due diligence, reporting suspicious transactions, and requirements for record-keeping and travel rule."
Sale/Purchase of Cryptocurrency: Generally, the sale or purchase of cryptocurrency itself is likely to be exempt from VAT, similar to how traditional currencies or other financial instruments are treated. This is based on EU VAT directives, which many countries implicitly or explicitly follow.
Services Related to Cryptocurrency: Services provided by crypto businesses (e.g., fees charged by cryptocurrency exchanges for trading, custodial services, advisory services) would likely be subject to the standard 21% VAT.
Individuals realizing gains from cryptocurrency transactions (treated as "other income") or receiving other forms of crypto income are generally required to declare these amounts in their annual Personal Income Tax Return (Godišnja prijava poreza na dohodak fizičkih lica).
Companies involved in crypto activities must report their income and profits in their Corporate Income Tax Return (Poreska prijava za porez na dobit pravnih lica).
VAT-registered businesses providing crypto-related services must file regular VAT Returns (PDV prijava).
Entity Targeted: Do Kwon (and his associate Hon Chang Joon). Violation Type (Montenegro Specific): Forgery of documents (using fake Costa Rican and Belgian passports for illegal entry and travel).
Do Kwon: Sentenced to four months in prison.
Hon Chang Joon: Sentenced to four months in prison.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — an on-shore VASP is permitted in Montenegro, but must be locally incorporated, obtain a VASP license from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers (Official Gazette No. 80/23), meet minimum capital/guarantee requirements, implement full AML/CTF obligations, and may need additional payment services or securities licenses depending on activities; detailed subordinate regulations from KAP are still pending, creating some regulatory uncertainty.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?