Remote VASP serving residents in North Macedonia
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in North Macedonia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Mandatory registration with the Financial Intelligence Unit (FIU) under the Law on Prevention of Money Laundering and Terrorist Financing (LPPMLTF) for any entity offering exchange, custody, transfer or administration of virtual assets to residents.
- FATF Travel Rule (Recommendation 16) adopted — VASPs must collect, transmit, and retain originator information (name, account number/unique identifier, physical address, national ID or customer ID, date/place of birth) and beneficiary information (name, account number/unique identifier) for all VASP-to-VASP transfers with no de minimis threshold.
- Enhanced due diligence may be triggered by transactions exceeding EUR 1,000 or EUR 15,000 for specific cash transactions or occasional transactions under LPPMLTF.
- VASPs must retain collected information for a prescribed period (typically 5-10 years) per general AML record-keeping rules.
- Supervision by the FIU (Управа за финансиско разузнавање - УФР) for AML/CTF compliance.
- Travel Rule information must be transmitted for VASP-to-unhosted-wallet transactions as well.
- Administrative fines, withdrawal of registration, public reprimands, and criminal charges for severe non-compliance.
Key Restrictions
- National Bank of the Republic of North Macedonia (NBRSM) has explicitly prohibited supervised financial institutions (banks, savings houses) from dealing in or facilitating cryptocurrency transactions — effectively cutting off fiat on/off-ramps through the regulated banking system.
- Cryptocurrencies are not recognized as legal tender in North Macedonia and do not fall under NBRSM regulatory supervision — creating legal ambiguity for any remote VASP operating without a local presence.
- Remote VASP serving residents must register with the FIU as a VASP under LPPMLTF — this appears to presume some form of local nexus (the law addresses 'obliged entities' operating in the jurisdiction).
- Criminal enforcement has targeted illegal mining (electricity theft) and online fraud involving crypto; unlicensed remote VASPs risk being treated as operating outside any legal framework.
Key Risks
- Banking access risk: NBRSM has prohibited supervised financial institutions from facilitating crypto transactions, making it extremely difficult to maintain fiat on/off-ramps for resident customers.
- Regulatory ambiguity: No clear licensing pathway for a foreign-incorporated entity with no local office to serve residents — the FIU VASP registration regime appears designed for locally established entities.
- Enforcement precedent: Police and prosecutors have actively targeted crypto-related economic crime (fraud, theft) and may view unlicensed cross-border VASP operations as illicit.
- MONEYVAL scrutiny: North Macedonia's AML/CFT framework is under MONEYVAL evaluation, increasing regulatory pressure on VASP compliance.
- Reputational and PR risk: NBRSM has publicly warned against crypto use, creating a hostile regulatory environment for any crypto service targeting residents.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
NBRSM Official Statement (November 2021): https://www.nbrm.mk/ns-newsarticle-soopstenie_za_javnost-23112021.nspx (Macedonian)
Regulator Name: National Bank of the Republic of North Macedonia (Народна банка на Република Северна Македонија - NBRSM)
Law on Prevention of Money Laundering and Terrorist Financing
Regulating Authority: Financial Intelligence Unit (FIU) of North Macedonia (Управата за финансиско разузнавање - УФР) is the primary authority for VASP registration and AML/CTF supervision.
Requirement: Mandatory registration with the Financial Intelligence Unit (FIU) under the LPMALTF.
Scope: This applies to platforms facilitating the exchange of virtual assets for fiat currency, or virtual assets for other virtual assets.
Adopted: Yes, the FATF Travel Rule (Recommendation 16, as applied to virtual assets) has been adopted in North Macedonia.
Legislation: The primary legislation is the Law on Prevention of Money Laundering and Terrorist Financing (LPPMLTF) (Закон за спречување перење пари и финансирање тероризам).
No De Minimis Threshold for VASP-to-VASP Transfers: Consistent with FATF guidance, for transfers of virtual assets between obliged entities (VASPs), there is generally no de minimis threshold for the required originator and beneficiary information to be transmitted. The full Travel Rule information must be collected and transmitted regardless of the amount.
Originator Information: Name, account number (or unique transaction identifier), physical address, national identity number (or customer identification number), date and place of birth (or legal entity registration number for corporate originators).
Beneficiary Information: Name, account number (or unique transaction identifier).
Retention: VASPs must retain the collected information for a prescribed period (typically 5-10 years, as per general AML record-keeping rules).
Administrative Fines: Substantial monetary fines can be imposed on the VASP (legal entity) and/or responsible individuals within the VASP's management. These fines can vary depending on the severity and recurrence of the breach.
Entity Targeted: General public, financial institutions under NBRSM supervision (banks, savings houses). Violation Type: While not a "violation" in the traditional sense, the NBRSM has consistently warned against the risks associated with cryptocurrencies and explicitly prohibited supervised financial institutions from dealing with them. This sets the regulatory boundary. Penalty Amount: N/A (This is a regulatory warning/stance, not a direct penalty for a specific breach by a regulated entity). Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Outcome: Heightened public awareness of crypto risks, reinforced prohibition for traditional financial institutions, setting a cautious regulatory tone. The NBRSM maintains that cryptocurrencies are not legal tender and do not fall under its regulatory supervision.
Entity Targeted: Individuals and organized groups operating illegal cryptocurrency mining farms. Violation Type: Theft of electricity, unauthorized connection to the electrical grid, potential charges for tax evasion, and sometimes organized crime. Penalty Amount: Seizure of expensive mining equipment (estimated value often in the hundreds of thousands of Euros), criminal charges, potential imprisonment, and financial penalties for stolen electricity. Specific penalty amounts vary per case and conviction. Outcome: Arrests of individuals, confiscation of mining hardware, disruption of illegal operations, and ongoing criminal proceedings. These actions highlight the MVR's focus on economic crime related to crypto.
Entity Targeted: Individuals and criminal groups involved in online fraud schemes often utilizing cryptocurrencies for payments or as the subject of the scam (e.g., fake investment platforms). Violation Type: Computer fraud, money laundering, organized crime. Penalty Amount: Seizure of assets, criminal charges, potential imprisonment, and restitution if convicted. Specific amounts are often under investigation or determined at conviction. Outcome: Arrests, ongoing investigations, disruption of fraudulent networks. The MVR regularly issues warnings about various online scams, many of which now involve cryptocurrency. While a single "major bust" focusing solely on crypto fraud with a public, finalized penalty within the last 3 years is hard to isolate from ongoing investigations, the MVR's continuous alerts and smaller-scale arrests demonstrate active enforcement.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign remote VASP serving North Macedonian residents must register with the FIU under the LPPMLTF as a VASP, comply with the FATF Travel Rule (no de minimis threshold), but faces severe banking-access barriers (NBRSM prohibition on banks facilitating crypto), no clear licensing pathway for non-resident entities, and active enforcement risk from police/prosecutors targeting crypto-related economic crime.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?