DeFi protocol frontend in North Macedonia
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in North Macedonia without local incorporation, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the Financial Intelligence Unit (FIU) as a VASP under the Law on Prevention of Money Laundering and Terrorist Financing (LPMALTF) is mandatory if the frontend facilitates exchange of virtual assets for fiat or other virtual assets.
- KYC/CDD obligations arise from VASP registration under the LPMALTF — must identify and verify users, monitor transactions, and report suspicious activity to the FIU.
- Suspicious transaction reporting (STR) obligations to the FIU apply under the AML/CTF framework.
- No explicit de minimis threshold for STR provided — standard AML principles apply regardless of transaction size if suspicious.
Key Restrictions
- Cannot rely on NBRSM-regulated financial institutions (banks, savings houses) for fiat on/off-ramps as they are prohibited from dealing in cryptocurrencies by NBRSM directive.
- If the frontend takes fees in any form (commission, spread, service fee), it likely triggers VASP classification and mandatory FIU registration.
- Geofencing of US and high-risk jurisdictions is advisable given the NBRSM's warnings and general anti-crypto stance, though not explicitly mandated by law.
- The NBRSM has stated that cryptocurrencies are not legal tender and do not fall under its regulatory supervision — leaving a regulatory gap that creates legal uncertainty for DeFi frontends.
Key Risks
- ["Regulatory ambiguity — NBRSM has not issued specific guidance on DeFi frontends or smart-contract-based services, creating enforcement risk.", "Reputational and operational risk from association with crypto: NBRSM's consistent public warnings discourage institutional engagement, making banking relationships difficult.", "Criminal enforcement risk from Ministry of Interior / Financial Police if the frontend is perceived as facilitating fraud, money laundering, or unregistered financial activity.", "Fee-taking without VASP registration creates direct exposure to criminal prosecution for operating without AML/CTF compliance.", "No precedent or safe harbor for 'truly decentralized' frontends — the regulator may view any user-facing interface as a VASP regardless of backend architecture."]
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulator Name: National Bank of the Republic of North Macedonia (Народна банка на Република Северна Македонија - NBRSM)
NBRSM Official Statement (November 2021): https://www.nbrm.mk/ns-newsarticle-soopstenie_za_javnost-23112021.nspx (Macedonian)
Law on Prevention of Money Laundering and Terrorist Financing
Regulating Authority: Financial Intelligence Unit (FIU) of North Macedonia (Управата за финансиско разузнавање - УФР) is the primary authority for VASP registration and AML/CTF supervision.
Exchanges (Virtual Asset Service Providers - VASP):
Requirement: Mandatory registration with the Financial Intelligence Unit (FIU) under the LPMALTF.
Scope: This applies to platforms facilitating the exchange of virtual assets for fiat currency, or virtual assets for other virtual assets.
Regulator Name: Ministry of Interior (Министерство за внатрешни работи - МВР), Public Prosecutor's Office (Јавно обвинителство на Република Северна Македонија), Financial Police (Управа за финансиска полиција).
Entity Targeted: General public, financial institutions under NBRSM supervision (banks, savings houses). Violation Type: While not a "violation" in the traditional sense, the NBRSM has consistently warned against the risks associated with cryptocurrencies and explicitly prohibited supervised financial institutions from dealing with them. This sets the regulatory boundary. Penalty Amount: N/A (This is a regulatory warning/stance, not a direct penalty for a specific breach by a regulated entity). Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Entity Targeted: Individuals and criminal groups involved in online fraud schemes often utilizing cryptocurrencies for payments or as the subject of the scam (e.g., fake investment platforms). Violation Type: Computer fraud, money laundering, organized crime. Penalty Amount: Seizure of assets, criminal charges, potential imprisonment, and restitution if convicted. Specific amounts are often under investigation or determined at conviction. Outcome: Arrests, ongoing investigations, disruption of fraudulent networks. The MVR regularly issues warnings about various online scams, many of which now involve cryptocurrency. While a single "major bust" focusing solely on crypto fraud with a public, finalized penalty within the last 3 years is hard to isolate from ongoing investigations, the MVR's continuous alerts and smaller-scale arrests demonstrate active enforcement.
Outcome: Arrests, ongoing investigations, disruption of fraudulent networks. The MVR regularly issues warnings about various online scams, many of which now involve cryptocurrency. While a single "major bust" focusing solely on crypto fraud with a public, finalized penalty within the last 3 years is hard to isolate from ongoing investigations, the MVR's continuous alerts and smaller-scale arrests demonstrate active enforcement.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operating in/to North Macedonia is permissible only as a registered VASP with the FIU if it facilitates any exchange or takes fees; the regulatory environment is highly cautious with active criminal enforcement, significant ambiguity around DeFi-specific structures, and no safe harbor for non-custodial frontends.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?