Crypto-funded debit card in Mongolia
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Mongolia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Licensed VASPs must implement full KYC/CDD per LMLCFT — obtain and verify full name, DOB, nationality, permanent address, unique ID (national ID/passport) for individuals
- For legal entities: obtain legal name, form, registration number, address, directors/partners, and beneficial ownership structure (25%+ ownership threshold)
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, and complex structures
- Ongoing transaction monitoring to detect unusual or suspicious patterns, with CDD data kept up-to-date
- Screen all customers against UN sanctions lists and internal watchlists
- Suspicious Transaction Reports (STRs) must be filed promptly (within a few working days) to the Financial Information Unit (FIU) of Mongolia for any transaction where ML/TF is suspected — no monetary threshold
- No tipping-off prohibition applies to VASPs and employees
- Record-keeping: CDD documents, transaction records (amounts, asset types, addresses, timestamps), analysis records, and STRs must be maintained
- Risk-based approach required — implement policies to identify and assess ML/TF risks of customers, products, and delivery channels
Key Restrictions
- Must obtain a VASP license from the Financial Regulatory Commission (FRC) under the Law on Regulation of Virtual Asset Service Providers (2021) — this covers exchange between virtual assets and fiat, which crypto-to-fiat conversion at point-of-sale would constitute
- A separate e-money or payment-institution license regime is not yet clearly articulated in the facts; the crypto-to-fiat leg falls under the VASP licensing framework handled by the FRC, not the Bank of Mongolia's payment systems regime
- Local entity incorporation in Mongolia is required — the VASP licensing process mandates a licensed entity in Mongolia
- Partner-bank or BIN-sponsor arrangements are not explicitly addressed by the facts; any partner financial institution in Mongolia would need to be a regulated entity under the Bank of Mongolia's supervision, creating dependency risk
- Capital adequacy requirements apply per the VASP Law
Key Risks
- Regulatory framework is nascent (VASP Law effective Jan 2022) — interpretation and enforcement of how crypto debit cards fit under 'exchange between virtual assets and fiat' is evolving and untested
- No specific e-money or payment services legislation clearly mapped to debit card issuance — card issuance itself may fall outside the VASP Law scope and lack a clear licensing pathway
- BIN sponsorship and card scheme membership (Mastercard/Visa) may require a regulated financial institution partner in Mongolia, but the facts do not detail whether the FRC or Bank of Mongolia has issued guidance on such arrangements for VASPs
- AML enforcement precedent is limited — penalties are outlined in the Criminal Code and LMLCFT but no specific enforcement cases against VASP debit card operators are documented in the provided facts
- Tax treatment of the conversion (10% PIT on capital gains under MNT 60M; progressive above) creates compliance complexity for a high-volume card product
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Partial but Evolving: Mongolia has moved from an unregulated state to establishing a foundational legal framework for virtual assets, specifically targeting Virtual Asset Service Providers (VASPs). The focus is heavily on AML/CFT compliance, risk management, and consumer protection through licensing. It's considered "partial" as it primarily regulates the service providers rather than attempting to regulate every facet of virtual assets or underlying technologies comprehensively at this stage.
Financial Regulatory Commission (FRC) of Mongolia:
Bank of Mongolia (Central Bank):
Financial Information Unit (FIU) of Mongolia (under the General Intelligence Agency):
Law on Regulation of Virtual Asset Service Providers (VASPs)
Date: Enacted on December 17, 2021 (effective from January 1, 2022).
Definition of VASP Activities: Outlines the services requiring a license, such as exchange between virtual assets and fiat currencies, exchange between one or more forms of virtual assets, transfer of virtual assets, safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets, and participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Licensing Requirements: Mandates that all entities providing VASP services must obtain a license from the FRC.
AML/CFT Compliance: Imposes strict AML/CFT obligations on licensed VASPs, including Know Your Customer (KYC) procedures, transaction monitoring, record-keeping, and suspicious transaction reporting to the FIU.
Risk Management: Requires VASPs to implement robust risk management systems, cybersecurity measures, and capital adequacy requirements.
Permitted but Regulated: Crypto trading and the operation of cryptocurrency exchanges are legal in Mongolia, provided they are conducted by entities that have obtained a license from the Financial Regulatory Commission (FRC).
Strict AML/CFT Compliance: Licensed exchanges and VASPs are subject to strict AML/CFT requirements, including:
Law on Combating Money Laundering and Terrorism Financing (LMLCFT): This is the main AML/CFT law in Mongolia, originally adopted in 2013 and subsequently amended (e.g., in 2018 and 2021) to incorporate FATF recommendations, including those related to virtual assets. It establishes the legal framework for identifying, freezing, and confiscating assets obtained from criminal activities, as well as preventing the financing of terrorism.
For Individuals: Obtain and verify the client's full name, date of birth, place of birth, nationality, permanent address, and unique identification number (e.g., national ID card number, passport number). Verification must be done using reliable, independent source documents, data, or information.
For Legal Entities: Obtain and verify the entity's legal name, legal form, registration number, address of registered office, and names of directors/partners. Understand the entity's ownership and control structure.
Beneficial Ownership (BO): Identify and verify the identity of the natural persons who ultimately own or control the customer, as well as the natural persons on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals owning 25% or more of the shares or voting rights, or otherwise exercising control.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes:
Enhanced Due Diligence (EDD): Apply EDD measures for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, complex structures) and transactions. This may involve obtaining additional information on the customer, sources of funds/wealth, and the reasons for the intended transactions.
Screening: Screen customers against national and international sanctions lists (e.g., UN Security Council sanctions) and internal watchlists.
Reporting Threshold: Report any transaction (regardless of amount) or attempted transaction that the VASP knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorism financing.
Reporting Body: All STRs must be submitted to the Financial Information Unit (FIU) of Mongolia.
Timing: Reports must be filed promptly, without undue delay, typically within a few working days of forming a suspicion.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a report has been or will be made (i.e., "tipping-off").
CDD Records: All documents and data obtained through the CDD process (e.g., copies of identification documents, beneficial ownership information).
Transaction Records: Records of all virtual asset transactions, including amounts, types of virtual assets, sender and receiver addresses, timestamps, and any relevant metadata.
Applicability: Profits derived from the sale, exchange, or disposal of virtual assets by individuals or businesses are generally subject to capital gains tax.
The standard PIT rate on capital gains from the sale of property (including virtual assets, by analogy) is 10% if the gains are less than MNT 60 million within a tax year. If the total annual taxable income (including capital gains) exceeds MNT 60 million, a progressive rate applies (10% on the first MNT 60 million, and 20% on the amount exceeding MNT 60 million).
Legal Basis: Penalties would be outlined in the Law on Combating Money Laundering and Terrorism Financing and the Mongolian Criminal Code.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto-funded debit card program in Mongolia would require a local entity licensed as a VASP by the FRC to conduct the crypto-to-fiat conversion, but card issuance (BIN sponsorship, payment scheme membership) lacks a clear, dedicated regulatory pathway under the facts provided, and no distinct e-money/payment-institution license framework is identified.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?