← Regulations / Norway / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Norway

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Norway with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • VASP registration with Finanstilsynet is required under the Anti-Money Laundering Act (Hvitvaskingsloven), which transposes AMLD5.
  • Implement robust KYC (Customer Due Diligence) procedures for all customers.
  • Establish and maintain robust internal control systems for AML/CTF.
  • Monitor transactions for suspicious activity.
  • Report suspicious transactions to Økokrim (National Authority for Investigation and Prosecution of Economic and Environmental Crime).
  • Ensure fit and proper management and ownership.
  • Upon MiCA implementation, CASP authorization (not just AML registration) will be required, with governance, internal controls, and specific custody rules.
  • If the custodial asset qualifies as a 'financial instrument' (e.g., security token), full financial institution licensing under the Financial Institutions Act applies, with strict asset segregation rules.

Key Restrictions

  • Local incorporation is required — only entities registered with Finanstilsynet as a VASP may provide custody services.
  • No specific legal mandate for insurance, bonding, or cold storage exists under current AML registration regime, though Finanstilsynet expects robust security measures.
  • If the digital asset qualifies as a 'financial instrument,' the entity must comply with the Financial Institutions Act (Finansforetaksloven) requiring strict segregation and full financial licensing.
  • No specific 'qualified custodian' regime exists for virtual assets — the closest is a registered VASP or, for financial instruments, a licensed financial institution.
  • MiCA adoption (expected mid-2024 to early 2025) will introduce a full CASP authorization regime with specific custody and administration requirements, replacing the current AML-only registration for custody services.

Key Risks

  • Regulatory ambiguity: The existing AML registration regime lacks specific custody standards (segregation, insurance, proof-of-reserves) — operators must rely on general sound management principles, creating uncertainty.
  • MiCA transition risk: As MiCA is incorporated (expected 2024-2025), operators will need to upgrade from AML registration to full CASP authorization, with higher capital and governance requirements.
  • Classification risk: If a custodial asset is reclassified as a financial instrument, the operator may become subject to the full Financial Institutions Act regime without having planned for it.
  • Enforcement precedent: Kryptobørs AS and Norges Kryptobørs AS were fined for AML compliance failures and operating without proper registration — demonstrating active enforcement by Finanstilsynet/Økokrim.
  • SaaS/white-label ambiguity: The AML obligations of the SaaS custodian vs. the white-label client are not clearly differentiated under current Norwegian law — both may need separate VASP registrations depending on who interfaces with the end customer.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Finanstilsynet (Financial Supervisory Authority of Norway): This is the primary regulator for financial services and virtual assets in Norway. It is responsible for overseeing compliance with the Anti-Money Laundering Act, including the registration of Virtual Asset Service Providers (VASPs).

licensing 60% confidence

This act transposes the EU's 5th Anti-Money Laundering Directive (AMLD5) into Norwegian law. It defines "virtual currency services" and mandates that entities providing such services (Virtual Asset Service Providers or VASPs) must register with Finanstilsynet.

licensing 60% confidence

Registered VASPs are subject to comprehensive AML/CTF obligations, including Know Your Customer (KYC) procedures, transaction monitoring, and suspicious activity reporting.

aml 60% confidence

VASP Registration: Companies that provide services for the exchange or custody of virtual assets are considered "virtual asset service providers" (VASPs) and must register with Finanstilsynet. This is an AML/CTF (Combatting the Financing of Terrorism) registration, not a full financial services license in the traditional sense, unless the specific virtual asset qualifies as a financial instrument under other legislation.

aml 60% confidence

Requirements for Registration: To register, companies must demonstrate compliance with the Money Laundering Act, which includes:

aml 60% confidence

Reporting suspicious transactions to Økokrim (National Authority for Investigation and Prosecution of Economic and Environmental Crime).

aml 60% confidence

If the Digital Asset is a Financial Instrument: If a digital asset is classified as a "financial instrument" (e.g., a security token) under the Securities Trading Act (Verdipapirhandelloven) or the Financial Institutions Act (finansforetaksloven), then offering custody services for such assets would fall under existing financial services licensing requirements, which are much more stringent than simple AML registration. Finanstilsynet conducts a case-by-case assessment.

aml 60% confidence

If classified as a Financial Instrument: If the virtual asset is deemed a financial instrument, then the rules under the Financial Institutions Act for safeguarding client funds/assets would apply, which mandates strict segregation from the firm's own assets.

aml 60% confidence

No Specific Mandate for VASPs: There are no specific legal mandates for insurance or bonding solely for virtual asset custodians under the current AML registration regime.

aml 60% confidence

No Explicit Legal Mandate: Norwegian law does not explicitly mandate the use of cold storage for virtual assets.

aml 60% confidence

Security Best Practice: However, Finanstilsynet expects companies providing virtual asset services to have robust security measures in place to protect client assets. Cold storage (offline storage of private keys) is widely recognized as a critical security best practice for managing the risks associated with holding cryptocurrencies and would be considered an essential component of a sound risk management framework by the regulator.

aml 60% confidence

No Specific Definition: Norway does not currently have a specific legal definition of a "qualified custodian" exclusively for virtual assets, akin to definitions found in some other jurisdictions (e.g., the U.S.).

aml 60% confidence

Registered VASP: The closest concept is a VASP that is registered with Finanstilsynet to provide custody services and complies with the Money Laundering Act. If the asset is a financial instrument, then a licensed financial institution providing custody services would be the "qualified custodian" under existing financial laws.

aml 60% confidence

MiCA's Scope: MiCA provides a comprehensive regulatory framework for crypto-asset markets and service providers (CASPs) not already covered by existing financial services legislation. It aims to harmonize rules across the EU/EEA, ensure consumer protection, market integrity, and financial stability.

aml 60% confidence

Impact on Custody: MiCA introduces specific and stringent requirements for "custody and administration of crypto-assets on behalf of clients" as a regulated crypto-asset service.

aml 60% confidence

Authorization, Not Just Registration: Under MiCA, entities wishing to provide custody services for crypto-assets (that are not financial instruments) will need to obtain authorization from their national competent authority (Finanstilsynet in Norway) as a Crypto-Asset Service Provider (CASP). This is a much more demanding process than the current AML registration.

licensing 60% confidence

Future Legislation: Markets in Crypto-Assets (MiCA) Regulation (EU Regulation 2023/1114) – Adopted by EU in May 2023:

enforcement 50% confidence

Entity Targeted: Kryptobørs AS (a Norwegian crypto exchange). Violation Type: Failure to comply with anti-money laundering (AML) regulations, inadequate internal controls, and operating without proper registration/licensing as a virtual asset service provider (VASP) for all services offered. Penalty Amount: Ordered to terminate its business. No specific monetary fine was publicized in connection with this specific order, but the cessation of operations is a severe penalty. Outcome: Finanstilsynet ordered Kryptobørs AS to terminate its business as a virtual asset service provider due to significant and persistent breaches of the Anti-Money Laundering Act and related regulations. This was a decisive action to remove a non-compliant entity from the market.

enforcement 50% confidence

Entity Targeted: Norges Kryptobørs AS (a Norwegian crypto exchange). Violation Type: Failure to comply with anti-money laundering (AML) regulations, specifically regarding inadequate risk assessment, customer due diligence (CDD) procedures, and not being properly registered for all types of currency exchange services offered. Penalty Amount: Ordered to cease providing currency exchange services involving fiat currency. No specific monetary fine was publicized in connection with this order, but the restriction on services is a significant penalty. Outcome: Finanstilsynet ordered Norges Kryptobørs AS to stop offering services involving the exchange between virtual and fiat currencies due to serious deficiencies in its AML compliance framework. The firm was permitted to continue offering exchange services between virtual assets.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers may operate in Norway as registered VASPs under the AML Act, but face a transitional regime moving toward MiCA CASP authorization, with no specific custody standards (segregation, insurance, proof-of-reserves) currently mandated beyond general AML obligations, and with material ambiguity regarding the allocation of AML duties between the SaaS provider and its white-label clients.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?