Custodial wallet / SaaS in North Macedonia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in North Macedonia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Mandatory registration with the Financial Intelligence Unit (FIU) under the Law on Prevention of Money Laundering and Terrorist Financing (LPMALTF) — custody providers are classified as VASPs.
- Customer due diligence (CDD) obligations under the LPMALTF, including identity verification of end users.
- Ongoing transaction monitoring and suspicious transaction reporting (STR) to the FIU.
- Record-keeping obligations under AML/CTF registration requirements.
- The white-label SaaS provider (custodian) and the white-label client likely both carry independent VASP registration obligations under the FIU, as both parties facilitate custody/transfer of virtual assets.
Key Restrictions
- Crypto is explicitly not recognized as legal tender by NBRSM; supervised financial institutions (banks, savings houses) are prohibited from dealing in crypto, making banking integration difficult.
- A compliant custodial wallet/SaaS provider must register as a VASP with the FIU — no separate 'qualified custodian' license exists; the VASP registration is the sole pathway.
- No specific proof-of-reserves, segregation, or insurance rules for custodial wallets are codified — the regulatory framework is thin beyond AML registration.
- The NBRSM has issued public warnings against crypto use and disclaims regulatory supervision over crypto, creating legal uncertainty for formal custodial services.
Key Risks
- Regulatory ambiguity: NBRSM has explicitly stated crypto is not under its supervision, so no formal custody licence or asset safeguarding framework (segregation, insurance, PoR) exists — leaving custodians in a legal grey area.
- Enforcement risk from Ministry of Interior/Financial Police — criminal investigations have targeted crypto-related activity including fraud and money laundering, not just illegal mining.
- NBRSM prohibitions on supervised financial institutions from dealing in crypto create severe operational friction for any custodial service needing fiat on/off ramps via local banks.
- The absence of a bespoke custody framework means custodians must self-interpret their duties; a future regulatory crackdown or legislative change could retroactively create compliance gaps.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulator Name: National Bank of the Republic of North Macedonia (Народна банка на Република Северна Македонија - NBRSM)
NBRSM Official Statement (November 2021): https://www.nbrm.mk/ns-newsarticle-soopstenie_za_javnost-23112021.nspx (Macedonian)
Law on Prevention of Money Laundering and Terrorist Financing
Regulating Authority: Financial Intelligence Unit (FIU) of North Macedonia (Управата за финансиско разузнавање - УФР) is the primary authority for VASP registration and AML/CTF supervision.
Custody Providers (Virtual Asset Service Providers - VASP):
Requirement: Mandatory registration with the Financial Intelligence Unit (FIU) under the LPMALTF.
Law on Payment Services and Payment Systems: This law regulates traditional payment services.
Regulating Authority: National Bank of North Macedonia (NBNM) (Народна банка на Република Северна Македонија) is the authority for licensing and supervising payment institutions that handle fiat currency.
Entity Targeted: General public, financial institutions under NBRSM supervision (banks, savings houses). Violation Type: While not a "violation" in the traditional sense, the NBRSM has consistently warned against the risks associated with cryptocurrencies and explicitly prohibited supervised financial institutions from dealing with them. This sets the regulatory boundary. Penalty Amount: N/A (This is a regulatory warning/stance, not a direct penalty for a specific breach by a regulated entity). Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Entity Targeted: Individuals and organized groups operating illegal cryptocurrency mining farms. Violation Type: Theft of electricity, unauthorized connection to the electrical grid, potential charges for tax evasion, and sometimes organized crime. Penalty Amount: Seizure of expensive mining equipment (estimated value often in the hundreds of thousands of Euros), criminal charges, potential imprisonment, and financial penalties for stolen electricity. Specific penalty amounts vary per case and conviction. Outcome: Arrests of individuals, confiscation of mining hardware, disruption of illegal operations, and ongoing criminal proceedings. These actions highlight the MVR's focus on economic crime related to crypto.
Entity Targeted: Individuals and criminal groups involved in online fraud schemes often utilizing cryptocurrencies for payments or as the subject of the scam (e.g., fake investment platforms). Violation Type: Computer fraud, money laundering, organized crime. Penalty Amount: Seizure of assets, criminal charges, potential imprisonment, and restitution if convicted. Specific amounts are often under investigation or determined at conviction. Outcome: Arrests, ongoing investigations, disruption of fraudulent networks. The MVR regularly issues warnings about various online scams, many of which now involve cryptocurrency. While a single "major bust" focusing solely on crypto fraud with a public, finalized penalty within the last 3 years is hard to isolate from ongoing investigations, the MVR's continuous alerts and smaller-scale arrests demonstrate active enforcement.
Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Outcome: Arrests of individuals, confiscation of mining hardware, disruption of illegal operations, and ongoing criminal proceedings. These actions highlight the MVR's focus on economic crime related to crypto.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS provider may operate in North Macedonia only by registering as a VASP with the FIU under the AML/CTF law, but faces severe legal uncertainty because NBRSM has publicly disclaimed crypto supervision, no dedicated custody/segregation/insurance framework exists, and supervised financial institutions are barred from dealing in crypto, creating structural banking and regulatory risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?