Centralized exchange in North Macedonia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in North Macedonia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Mandatory registration with the Financial Intelligence Unit (FIU) under the Law on Prevention of Money Laundering and Terrorist Financing (LPPMLTF) — this is an AML/CTF registration, not a full prudential license.
- Travel Rule obligations adopted (FATF Recommendation 16): VASPs must collect and transmit originator information (name, account number/unique transaction identifier, physical address, national identity number, date/place of birth) and beneficiary information (name, account number/unique transaction identifier) for all VASP-to-VASP transfers with no de minimis threshold.
- Travel Rule applies to exchanges between virtual assets and fiat, exchanges between forms of virtual assets, transfers of virtual assets, and custody/administration of virtual assets.
- Enhanced due diligence may be triggered for transactions exceeding certain amounts (e.g., EUR 1,000 or EUR 15,000 for specific cash transactions or occasional transactions).
- VASPs must retain collected information for 5–10 years per general AML record-keeping rules.
- No specific technology mandate for Travel Rule compliance — VASPs may choose their own solution (e.g., TRISA, Sygna).
- Supervision by the FIU for AML/CTF compliance; National Bank of North Macedonia (NBNM) for payment services involving fiat.
Key Restrictions
- NBRSM has explicitly prohibited supervised financial institutions (banks, savings houses) from engaging in or facilitating crypto transactions — a centralized exchange cannot rely on local banking partners for fiat on/off-ramps.
- Cryptocurrencies are not recognized as legal tender and do not fall under NBRSM regulatory supervision, creating structural legal ambiguity for exchange operations.
- Local entity required — VASP registration with the FIU under LPPMLTF is mandatory for any entity facilitating exchange of virtual assets for fiat or other virtual assets.
- The NBRSM has issued repeated public warnings against crypto use (November 2021 and ongoing), reinforcing a hostile regulatory posture.
Key Risks
- High enforcement risk for unregistered operations — criminal investigations and prosecutions by the Ministry of Interior, Financial Police, and Public Prosecutor's Office for fraud, money laundering, and related crypto crimes have been actively pursued.
- Banking access risk — due to NBRSM prohibition on supervised financial institutions dealing in crypto, securing fiat banking partners is extremely difficult or impossible.
- Regulatory ambiguity — the NBRSM has explicitly stated crypto does not fall under its supervision, leaving the regulatory framework thin beyond AML/CTF registration; no dedicated exchange or custody licensing regime exists.
- Enforcement precedent includes raids on crypto mining operations (June 2022, Kumanovo) and ongoing focus on online fraud involving crypto payments, signaling active law enforcement attention.
- No de minimis threshold for Travel Rule means all VASP-to-VASP transfers require full originator/beneficiary data transmission, increasing operational burden.
- Potential for license/registration revocation or administrative fines for AML/CTF non-compliance.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law on Prevention of Money Laundering and Terrorist Financing
Regulating Authority: Financial Intelligence Unit (FIU) of North Macedonia (Управата за финансиско разузнавање - УФР) is the primary authority for VASP registration and AML/CTF supervision.
Exchanges (Virtual Asset Service Providers - VASP):
Requirement: Mandatory registration with the Financial Intelligence Unit (FIU) under the LPMALTF.
Scope: This applies to platforms facilitating the exchange of virtual assets for fiat currency, or virtual assets for other virtual assets.
Regulator Name: National Bank of the Republic of North Macedonia (Народна банка на Република Северна Македонија - NBRSM)
NBRSM Official Statement (November 2021): https://www.nbrm.mk/ns-newsarticle-soopstenie_za_javnost-23112021.nspx (Macedonian)
Date: Ongoing, with prominent statements in November 2021 and repeated subsequently.
Adopted: Yes, the FATF Travel Rule (Recommendation 16, as applied to virtual assets) has been adopted in North Macedonia.
Legislation: The primary legislation is the Law on Prevention of Money Laundering and Terrorist Financing (LPPMLTF) (Закон за спречување перење пари и финансирање тероризам).
No De Minimis Threshold for VASP-to-VASP Transfers: Consistent with FATF guidance, for transfers of virtual assets between obliged entities (VASPs), there is generally no de minimis threshold for the required originator and beneficiary information to be transmitted. The full Travel Rule information must be collected and transmitted regardless of the amount.
Originator Information: Name, account number (or unique transaction identifier), physical address, national identity number (or customer identification number), date and place of birth (or legal entity registration number for corporate originators).
Beneficiary Information: Name, account number (or unique transaction identifier).
Transmit Required Information: VASPs must obtain and transmit this information to the beneficiary VASP, or to the beneficiary itself if they are using an unhosted wallet.
Retention: VASPs must retain the collected information for a prescribed period (typically 5-10 years, as per general AML record-keeping rules).
No Specific Technology Mandate: Like most jurisdictions, North Macedonia's law does not mandate a specific technical solution (e.g., TRISA, TRAVELER, Sygna). VASPs are expected to choose and implement a solution that allows them to securely and effectively collect, transmit, and store the required information in a compliant manner. The emphasis is on what information needs to be transmitted, not how it is technically done, as long as it meets security and data protection standards.
Exchanges between virtual assets and fiat currencies.
Exchanges between one or more forms of virtual assets.
Transfers of virtual assets.
Custody and/or administration of virtual assets or instruments enabling control over virtual assets.
Administrative Fines: Substantial monetary fines can be imposed on the VASP (legal entity) and/or responsible individuals within the VASP's management. These fines can vary depending on the severity and recurrence of the breach.
Withdrawal of Licenses/Registrations: Supervisory authorities may suspend or revoke a VASP's license or registration if there are serious or repeated breaches of AML/CFT obligations.
Entity Targeted: General public, financial institutions under NBRSM supervision (banks, savings houses). Violation Type: While not a "violation" in the traditional sense, the NBRSM has consistently warned against the risks associated with cryptocurrencies and explicitly prohibited supervised financial institutions from dealing with them. This sets the regulatory boundary. Penalty Amount: N/A (This is a regulatory warning/stance, not a direct penalty for a specific breach by a regulated entity). Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Entity Targeted: Individuals and organized groups operating illegal cryptocurrency mining farms. Violation Type: Theft of electricity, unauthorized connection to the electrical grid, potential charges for tax evasion, and sometimes organized crime. Penalty Amount: Seizure of expensive mining equipment (estimated value often in the hundreds of thousands of Euros), criminal charges, potential imprisonment, and financial penalties for stolen electricity. Specific penalty amounts vary per case and conviction. Outcome: Arrests of individuals, confiscation of mining hardware, disruption of illegal operations, and ongoing criminal proceedings. These actions highlight the MVR's focus on economic crime related to crypto.
Entity Targeted: Individuals and criminal groups involved in online fraud schemes often utilizing cryptocurrencies for payments or as the subject of the scam (e.g., fake investment platforms). Violation Type: Computer fraud, money laundering, organized crime. Penalty Amount: Seizure of assets, criminal charges, potential imprisonment, and restitution if convicted. Specific amounts are often under investigation or determined at conviction. Outcome: Arrests, ongoing investigations, disruption of fraudulent networks. The MVR regularly issues warnings about various online scams, many of which now involve cryptocurrency. While a single "major bust" focusing solely on crypto fraud with a public, finalized penalty within the last 3 years is hard to isolate from ongoing investigations, the MVR's continuous alerts and smaller-scale arrests demonstrate active enforcement.
Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Outcome: Arrests of individuals, confiscation of mining hardware, disruption of illegal operations, and ongoing criminal proceedings. These actions highlight the MVR's focus on economic crime related to crypto.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in North Macedonia only as a registered VASP with the FIU under the AML/CTF framework, but faces a hostile regulatory environment where the central bank has prohibited all supervised financial institutions from handling crypto, making fiat on/off-ramps extremely difficult and creating structural legal ambiguity.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?