Crypto ATM / kiosk operator in Mongolia
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Mongolia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full KYC/CDD required for all customers: name, date of birth, nationality, address, unique ID number verified from reliable source documents (mn.aml.identification-and-verification-idv, mn.aml.for-individuals-obtain-and-verify)
- Beneficial ownership identification required for legal entity customers (25%+ ownership threshold) (mn.aml.beneficial-ownership-bo-identify-and)
- Ongoing transaction monitoring for unusual/suspicious patterns with periodic CDD updates (mn.aml.ongoing-monitoring-continuously-monitor-the, mn.aml.scrutinizing-transactions-for-unusual-or, mn.aml.keeping-customer-due-diligence-data-up-to-date)
- Enhanced Due Diligence (EDD) required for higher-risk customers including PEPs, customers from high-risk jurisdictions, and complex structures (mn.aml.enhanced-due-diligence-edd-apply)
- Screening against UN Security Council sanctions lists and internal watchlists (mn.aml.screening-screen-customers-against-national)
- Suspicious Transaction Reporting (STR) to the Financial Information Unit (FIU) — no monetary threshold; file promptly upon suspicion, with no tipping-off (mn.aml.reporting-threshold-report-any-transaction, mn.aml.reporting-body-all-strs-must, mn.aml.timing-reports-must-be-filed, mn.aml.no-tipping-off-vasps-and-their)
- Record-keeping obligations: CDD records, transaction records (amounts, asset types, sender/receiver addresses, timestamps), analysis records, and STRs (mn.aml.cdd-records-all-documents-and, mn.aml.transaction-records-records-of-all, mn.aml.analysis-records-records-of-any, mn.aml.strs-and-communications-copies-of)
- Risk-based approach required: implement policies to assess ML/TF risks from customers, products, services, and delivery channels (mn.aml.risk-based-approach-implement-policies-and)
- Purpose and nature of business relationship must be understood and documented (mn.aml.purpose-and-nature-of-the)
Key Restrictions
- Physical crypto ATM/kiosk operator is a VASP under the Law on Regulation of Virtual Asset Service Providers (2021) and must obtain an FRC license (mn.licensing.licensing-requirements-mandates-that-all, mn.licensing.law-on-regulation-of-virtual)
- Kiosk operator must be a legal entity incorporated in Mongolia (no foreign entity can directly operate without local registration) (mn.licensing.licensing-is-mandatory-any-entity)
- Capital adequacy requirements must be satisfied as part of licensing (mn.licensing.risk-management-requires-vasps-to)
- Robust risk management and cybersecurity systems required for licensing (mn.licensing.risk-management-requires-vasps-to)
- Only cash-to-crypto (or crypto-to-cash) exchanges that comply with full AML/KYC framework are permitted — anonymous cash transactions are not allowed (mn.licensing.strict-amlcft-compliance-licensed-exchanges)
- No specific cash-transaction reporting threshold identified in provided facts; all transactions must be monitored and suspicious ones reported regardless of amount (mn.aml.reporting-threshold-report-any-transaction)
Key Risks
- High-cash AML risk profile of crypto ATMs may attract elevated scrutiny from FRC and FIU, given the regulatory focus on AML/CFT (mn.licensing.strict-amlcft-compliance-licensed-exchanges)
- Limited English-language documentation and guidance from FRC creates compliance interpretation risk (mn.licensing.url-financial-regulatory-commission-of)
- Enforcement penalties under AML law and Criminal Code for non-compliance could be severe (mn.enforcement.legal-basis-penalties-would-be)
- No explicit kiosk-specific regulation or cash threshold found — regulatory treatment of kiosks may be inferred from general VASP rules, creating ambiguity (mn.licensing.partial-but-evolving-mongolia-has)
- Consumer protection obligations under VASP law may impose additional operational requirements for kiosk operators (mn.licensing.consumer-protection-aims-to-protect)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Partial but Evolving: Mongolia has moved from an unregulated state to establishing a foundational legal framework for virtual assets, specifically targeting Virtual Asset Service Providers (VASPs). The focus is heavily on AML/CFT compliance, risk management, and consumer protection through licensing. It's considered "partial" as it primarily regulates the service providers rather than attempting to regulate every facet of virtual assets or underlying technologies comprehensively at this stage.
Financial Regulatory Commission (FRC) of Mongolia:
Law on Regulation of Virtual Asset Service Providers (VASPs)
Date: Enacted on December 17, 2021 (effective from January 1, 2022).
Definition of VASP Activities: Outlines the services requiring a license, such as exchange between virtual assets and fiat currencies, exchange between one or more forms of virtual assets, transfer of virtual assets, safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets, and participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Licensing Requirements: Mandates that all entities providing VASP services must obtain a license from the FRC.
AML/CFT Compliance: Imposes strict AML/CFT obligations on licensed VASPs, including Know Your Customer (KYC) procedures, transaction monitoring, record-keeping, and suspicious transaction reporting to the FIU.
Risk Management: Requires VASPs to implement robust risk management systems, cybersecurity measures, and capital adequacy requirements.
Consumer Protection: Aims to protect users of VASP services.
Strict AML/CFT Compliance: Licensed exchanges and VASPs are subject to strict AML/CFT requirements, including:
Licensing is Mandatory: Any entity wishing to operate as a Virtual Asset Service Provider (VASP) – including crypto exchanges, custodial services, or providers facilitating virtual asset transfers – must go through a rigorous licensing process with the FRC.
For Individuals: Obtain and verify the client's full name, date of birth, place of birth, nationality, permanent address, and unique identification number (e.g., national ID card number, passport number). Verification must be done using reliable, independent source documents, data, or information.
Beneficial Ownership (BO): Identify and verify the identity of the natural persons who ultimately own or control the customer, as well as the natural persons on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals owning 25% or more of the shares or voting rights, or otherwise exercising control.
Purpose and Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or transaction. This helps assess the risk profile of the customer.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes:
Scrutinizing transactions for unusual or suspicious patterns.
Evidence fact mn.aml.keeping-customer-due-diligence-data-up-to-date not found (may have been renamed).
Risk-Based Approach: Implement policies and procedures to identify, assess, and understand the money laundering and terrorism financing (ML/TF) risks posed by customers, products, services, transactions, and delivery channels.
Enhanced Due Diligence (EDD): Apply EDD measures for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, complex structures) and transactions. This may involve obtaining additional information on the customer, sources of funds/wealth, and the reasons for the intended transactions.
Screening: Screen customers against national and international sanctions lists (e.g., UN Security Council sanctions) and internal watchlists.
Reporting Threshold: Report any transaction (regardless of amount) or attempted transaction that the VASP knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorism financing.
Reporting Body: All STRs must be submitted to the Financial Information Unit (FIU) of Mongolia.
Timing: Reports must be filed promptly, without undue delay, typically within a few working days of forming a suspicion.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a report has been or will be made (i.e., "tipping-off").
CDD Records: All documents and data obtained through the CDD process (e.g., copies of identification documents, beneficial ownership information).
Transaction Records: Records of all virtual asset transactions, including amounts, types of virtual assets, sender and receiver addresses, timestamps, and any relevant metadata.
Analysis Records: Records of any internal inquiries, risk assessments, and the rationale behind decisions regarding customer risk categorization or suspicious activity.
STRs and Communications: Copies of all submitted STRs and any related communications with the FIU or other authorities.
Legal Basis: Penalties would be outlined in the Law on Combating Money Laundering and Terrorism Financing and the Mongolian Criminal Code.
URL: Financial Regulatory Commission of Mongolia (Note: English content might be limited for specific legal documents, but the overall institution and its role are outlined).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — crypto ATM/kiosk operation is legal in Mongolia only if the operator obtains a VASP license from the Financial Regulatory Commission (FRC) as a locally incorporated entity, implements full AML/KYC/CDD measures including ongoing monitoring and suspicious transaction reporting to the FIU, and satisfies capital adequacy and risk management requirements under the 2021 VASP Law.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?