Centralized exchange in Mongolia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Mongolia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Obtain and verify customer identity (full name, date of birth, nationality, permanent address, national ID/passport number) under the Law on Combating Money Laundering and Terrorism Financing (LMLCFT)
- Identify beneficial owners — natural persons owning 25% or more of legal entity customers
- Understand purpose and intended nature of the business relationship
- Implement ongoing transaction monitoring to detect unusual or suspicious patterns
- Apply risk-based approach with Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, and complex structures
- Screen customers against UN Security Council sanctions and internal watchlists
- Report suspicious transactions (any amount) to the Financial Information Unit (FIU) of Mongolia — promptly, without undue delay
- Maintain CDD records, transaction records (amounts, asset types, sender/receiver addresses, timestamps), analysis records, and STR copies
- Comply with 'no tipping-off' prohibition — cannot disclose to customer or third party that a report has been made
- Keep CDD data up-to-date and refresh as necessary
Key Restrictions
- Must obtain a VASP license from the Financial Regulatory Commission (FRC) under the Law on Regulation of Virtual Asset Service Providers (enacted Dec 17, 2021, effective Jan 1, 2022)
- Must be a legal entity incorporated in Mongolia — licensing is mandatory and only available to registered entities
- Must implement robust risk management systems, cybersecurity measures, and capital adequacy requirements per FRC licensing conditions
- Exchange between fiat and virtual assets, exchange between virtual assets, transfer of virtual assets, and safekeeping/administration of virtual assets all fall within the licensed VASP scope
- Must comply with FRC Resolution No. 278 (2021) detailing VASP licensing requirements and AML/KYC frameworks
Key Risks
- Enforcement precedent is thin — the VASP law is relatively new (effective 2022) and the FRC's enforcement track record is still developing
- English-language guidance from the FRC may be limited, creating operational ambiguity for foreign compliance teams
- Travel rule implementation is not explicitly detailed in the provided facts — the scope of virtual asset transfer obligations (including originator/beneficiary information requirements) may be clarified in unpublished FRC guidance
- Sanctions screening and UNSC resolution compliance obligations exist under the broader AML/CFT framework but specific VASP-related sanctions guidance may be unclear
- Potential regulatory overlap between the FRC, Bank of Mongolia, and the FIU could create coordination risk
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Partial but Evolving: Mongolia has moved from an unregulated state to establishing a foundational legal framework for virtual assets, specifically targeting Virtual Asset Service Providers (VASPs). The focus is heavily on AML/CFT compliance, risk management, and consumer protection through licensing. It's considered "partial" as it primarily regulates the service providers rather than attempting to regulate every facet of virtual assets or underlying technologies comprehensively at this stage.
Financial Regulatory Commission (FRC) of Mongolia:
Law on Regulation of Virtual Asset Service Providers (VASPs)
Date: Enacted on December 17, 2021 (effective from January 1, 2022).
Licensing Requirements: Mandates that all entities providing VASP services must obtain a license from the FRC.
Definition of VASP Activities: Outlines the services requiring a license, such as exchange between virtual assets and fiat currencies, exchange between one or more forms of virtual assets, transfer of virtual assets, safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets, and participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
AML/CFT Compliance: Imposes strict AML/CFT obligations on licensed VASPs, including Know Your Customer (KYC) procedures, transaction monitoring, record-keeping, and suspicious transaction reporting to the FIU.
Risk Management: Requires VASPs to implement robust risk management systems, cybersecurity measures, and capital adequacy requirements.
Permitted but Regulated: Crypto trading and the operation of cryptocurrency exchanges are legal in Mongolia, provided they are conducted by entities that have obtained a license from the Financial Regulatory Commission (FRC).
Licensing is Mandatory: Any entity wishing to operate as a Virtual Asset Service Provider (VASP) – including crypto exchanges, custodial services, or providers facilitating virtual asset transfers – must go through a rigorous licensing process with the FRC.
Strict AML/CFT Compliance: Licensed exchanges and VASPs are subject to strict AML/CFT requirements, including:
Law on Combating Money Laundering and Terrorism Financing (LMLCFT): This is the main AML/CFT law in Mongolia, originally adopted in 2013 and subsequently amended (e.g., in 2018 and 2021) to incorporate FATF recommendations, including those related to virtual assets. It establishes the legal framework for identifying, freezing, and confiscating assets obtained from criminal activities, as well as preventing the financing of terrorism.
For Individuals: Obtain and verify the client's full name, date of birth, place of birth, nationality, permanent address, and unique identification number (e.g., national ID card number, passport number). Verification must be done using reliable, independent source documents, data, or information.
For Legal Entities: Obtain and verify the entity's legal name, legal form, registration number, address of registered office, and names of directors/partners. Understand the entity's ownership and control structure.
Beneficial Ownership (BO): Identify and verify the identity of the natural persons who ultimately own or control the customer, as well as the natural persons on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals owning 25% or more of the shares or voting rights, or otherwise exercising control.
Purpose and Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or transaction. This helps assess the risk profile of the customer.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes:
Risk-Based Approach: Implement policies and procedures to identify, assess, and understand the money laundering and terrorism financing (ML/TF) risks posed by customers, products, services, transactions, and delivery channels.
Enhanced Due Diligence (EDD): Apply EDD measures for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, complex structures) and transactions. This may involve obtaining additional information on the customer, sources of funds/wealth, and the reasons for the intended transactions.
Screening: Screen customers against national and international sanctions lists (e.g., UN Security Council sanctions) and internal watchlists.
Reporting Threshold: Report any transaction (regardless of amount) or attempted transaction that the VASP knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorism financing.
Reporting Body: All STRs must be submitted to the Financial Information Unit (FIU) of Mongolia.
Timing: Reports must be filed promptly, without undue delay, typically within a few working days of forming a suspicion.
Contents: STRs must contain comprehensive details of the parties involved, the transaction(s), the reasons for suspicion, and any supporting documentation.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a report has been or will be made (i.e., "tipping-off").
CDD Records: All documents and data obtained through the CDD process (e.g., copies of identification documents, beneficial ownership information).
Transaction Records: Records of all virtual asset transactions, including amounts, types of virtual assets, sender and receiver addresses, timestamps, and any relevant metadata.
Analysis Records: Records of any internal inquiries, risk assessments, and the rationale behind decisions regarding customer risk categorization or suspicious activity.
STRs and Communications: Copies of all submitted STRs and any related communications with the FIU or other authorities.
For instance, the FRC Resolution No. 278 (2021) outlines detailed VASP licensing requirements, including robust AML/KYC frameworks.
Legal Basis: The implementation of UNSC resolutions is typically embedded in a country's national Anti-Money Laundering/Combating the Financing of Terrorism (AML/CFT) laws.
Legal Basis: Penalties would be outlined in the Law on Combating Money Laundering and Terrorism Financing and the Mongolian Criminal Code.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Mongolia only after obtaining a VASP license from the Financial Regulatory Commission (FRC) under the 2021 VASP Law, incorporating locally, and complying with strict AML/CFT obligations (KYC, EDD, transaction monitoring, STR filing to the FIU, sanctions screening, record-keeping).
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?