Custodial wallet / SaaS in Netherlands
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Netherlands with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CASP authorization under MiCA (via AFM) required for custody services — licensing burden includes full fit-and-proper tests, business plans, and policies
- WWFT (Wwft) AML/CTF compliance obligations: KYC/CDD on all customers, ongoing transaction monitoring, suspicious activity reporting (STR/SAFT) to FIU-Netherlands
- UBO integrity screening required as part of licensing process
- DNB oversees AML/CFT compliance under Wwft and maintains the register of crypto service providers
- Strict enforcement track record — prior unregistered operations (e.g., Binance, Coinbase) were fined by DNB
- Segregation of client crypto assets and custodial duties subject to MiCA CASP custody rules (safekeeping and administration of crypto assets on behalf of clients)
- Proof-of-reserves and insurance requirements for custodians may be imposed under MiCA implementing rules (Article 75 MiCA — safekeeping and segregation obligations for CASPs holding client crypto)
Key Restrictions
- Custody of crypto assets is a licensed MiCA activity — must obtain CASP authorization from AFM (with DNB AML input) before offering custodial wallet/SaaS services
- Transitional period ended June 30, 2025 — only MiCA-licensed CASPs may operate post-transition; existing DNB-registered entities required to upgrade
- Local entity incorporation in the Netherlands is required to obtain CASP authorization
- White-label / B2B custody-as-a-service arrangement: the CASP licensee (SaaS provider) bears primary regulatory responsibility; the white-label client may also trigger CASP obligations depending on whether they hold keys or direct customer relationships
Key Risks
- Pre-MiCA VASP registration with DNB had ~90% rejection rate — MiCA CASP process is rigorous with substantial UBO screening and integrity checks, creating risk of application failure or lengthy delays
- Several prominent exchanges withdrew from the Netherlands rather than comply — demonstrating high regulatory barrier to entry
- Ambiguity around allocation of AML obligations between custodial SaaS provider and white-label client (e.g., who performs KYC for end users) — this must be clearly contractually allocated and operationally demonstrated to DNB/AFM
- Strict enforcement posture by DNB (Binance fined €3.3M, Coinbase fined) — non-compliance risks significant fines and reputational damage
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
DNB — VASP registration (~90% rejection rate pre-MiCA), AML/CFT supervision
MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation
WWFT (Anti-Money Laundering and Anti-Terrorist Financing Act) (2018) — Pre-MiCA VASP AML registration with DNB — rigorous WWFT compliance
VASP: CASP authorization under MiCA via DNB/AFM. Pre-MiCA DNB registration had ~90% rejection rate. Substantial UBO integrity screening. Several exchanges withdrew from Netherlands.
CUSTODY: CASP authorization — custody is a licensed MiCA activity
AFM: Licenses and supervises crypto-asset service providers under MiCAR; opened its digital portal for MiCAR license applications as of April 22, 2024
DNB: Maintains the register of crypto service providers and oversees AML/CFT compliance under the Wwft
Applies to crypto exchanges, custodian wallet providers, and CASPs; stablecoins and unbacked cryptos (e.g., Bitcoin) have specific oversight.
Transitional period ended June 30, 2025: Existing CASPs could operate under prior rules while applying for MiCA licenses; only licensed entities allowed post-transition.
De Nederlandsche Bank (DNB): Central bank; handles AML/CTF registration for crypto service providers (exchanges, custodians), monitors compliance, supervises stablecoin issuers under MiCA, and enforces Wwft/Sanctions Act. Requires fit-and-proper tests, business plans, and policies for registration.
Dutch Authority for the Financial Markets (AFM): Supervises conduct, handles MiCA license applications/notifications for CASPs (opened portal April 22, 2024), and applies Financial Supervision Act (Wft) if crypto qualifies as financial instruments.
Wwft (Dutch Money Laundering and Anti-Terrorist Financing Act): Implements 5AMLD (effective May 21, 2020); mandates DNB registration for exchanges and custodian wallets, with KYC, transaction monitoring, and suspicious activity reporting. Non-compliance risks fines/imprisonment.
Markets in Crypto-Assets Regulation (MiCA/MiCAR): EU-wide (enacted 2024, licenses effective December 30, 2024); AFM processes applications, promotes transparency; DNB focuses on stablecoins.
Legal and encouraged with oversight: Trading/owning crypto permitted; providers must register with DNB (pre-MiCA) or obtain AFM MiCA licenses post-2025. AFM advises new providers to apply directly for MiCA rather than DNB registration.
Strict enforcement: Fines on unregistered platforms (e.g., Binance, Coinbase).
Comprehensive: Regulated via Dutch implementation of EU rules (e.g., 5AMLD and MiCA) rather than standalone national laws; covers AML/CTF, licensing, and supervision without prohibiting crypto.
AFM MiCA portal: Referenced in CMS guide (applications since April 2024).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers must obtain MiCA CASP authorization from AFM (with DNB AML oversight) and maintain a local entity, with rigorous licensing, AML obligations (KYC/STR under Wwft), and client asset segregation rules; the transitional period ended June 30, 2025, so only licensed operators may serve Dutch residents.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?