Custodial wallet / SaaS in Poland
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Poland with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with GIIF (Minister of Finance) under the Polish AML Act as a VASP for 'virtual currency safekeeping wallet service' (custody of private cryptographic keys).
- Appoint a designated AML Officer / Compliance Officer responsible for AML/CTF compliance.
- Implement Customer Due Diligence (CDD) procedures including identification and verification of clients, beneficial owners, and screening against sanctions lists.
- Conduct ongoing monitoring of client relationships and transactions to detect suspicious activities.
- Implement transaction monitoring systems to flag unusual patterns or threshold breaches.
- Report suspicious transactions and activities to GIIF.
- Maintain records of client identification data and transactions for at least 5 years.
- Provide regular AML/CTF training to relevant employees.
- Develop and maintain internal AML/CTF procedures including a business-specific risk assessment.
- Under MiCA (from 30 December 2024): meet capital requirements (€50k-€150k depending on services), implement segregation of client crypto-assets and funds, and obtain authorization from KNF (Polish Financial Supervision Authority) as a CASP.
Key Restrictions
- Operator must register as a VASP with GIIF under the Polish AML Act prior to commencing operations.
- The applicant must be a Polish legal entity (e.g., sp. z o.o. or S.A.) — a local entity is strictly required.
- At least one management board member must have residence in Poland or Polish citizenship.
- Management board members and beneficial owners must meet fit & proper criteria (no criminal record for intentional financial crimes).
- Under current Polish law, there are no specific asset segregation, insurance, or proof-of-reserves rules for custodians — this creates regulatory ambiguity.
- From 30 December 2024, MiCA will apply, requiring KNF authorization, mandatory segregation of client crypto-assets and funds, and minimum capital requirements.
- The Polish AML Act registration is AML/CTF-focused only — not a comprehensive prudential license; no current capital requirements under the AML Act.
Key Risks
- No specific segregation, insurance, or proof-of-reserves rules under current Polish law — operator has no clear regulatory guidance on how to structure client asset protection.
- No current definition of 'qualified custodian' for virtual assets in Poland — unclear what operational/prudential standards apply until MiCA takes full effect.
- Transition risk: MiCA will introduce a materially different regime (KNF authorization, capital requirements, mandatory segregation) from 30 December 2024 — operators must plan for a licensing upgrade.
- Unclear how AML obligations apply to the SaaS provider vs the white-label client — the VASP registration likely falls on the entity holding keys, but the white-label client may also have independent obligations if they facilitate transactions.
- Enforcement precedent is limited — GIIF has not yet published detailed examination findings or penalties specific to custodial wallet providers.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual currency safekeeping wallet service: This refers to the provision of services for safeguarding private cryptographic keys on behalf of clients, to hold, store, and transfer virtual currencies. This explicitly covers custody providers.
Current (Registration): Poland operates a registration regime for VASPs under its AML Act. This means entities must register their activities with GIIF and comply with AML/CTF obligations. It is not a full "licensing" regime in the sense of prudential supervision (e.g., capital adequacy, operational risk, consumer protection oversight by KNF) like banks or investment firms currently face. The focus is purely on preventing money laundering and terrorist financing.
The applicant must be a Polish legal entity (e.g., Spółka z ograniczoną odpowiedzialnością - limited liability company, or Spółka akcyjna - joint-stock company).
At least one individual from the management board of the Polish legal entity must have their residence in Poland or possess a Polish citizenship.
Under the current Polish AML Act, there are NO specific minimum capital requirements solely for VASP registration. This is a significant difference from traditional financial licenses.
Future (MiCA - Licensing): The EU's Markets in Crypto-Assets Regulation (MiCA) will introduce a comprehensive licensing regime for a broader range of crypto-asset services across the EU. MiCA will come into full effect in December 2024 for most provisions. Once MiCA is fully applicable, entities providing crypto-asset services (CASPs) as defined under MiCA will need to obtain a license from a national competent authority (in Poland, likely KNF) and will be subject to more extensive prudential, organisational, and consumer protection requirements, including capital requirements.
Future MiCA Impact: MiCA will introduce capital requirements for Crypto-Asset Service Providers (CASPs), ranging from €50,000 to €150,000 depending on the type of services provided.
Fit & Proper Criteria (Management/Owners):
Have no criminal record for intentional financial crimes (e.g., money laundering, terrorist financing, fraud, tax offenses).
Internal AML/CTF Procedures: Develop and implement robust internal anti-money laundering and counter-terrorist financing procedures, including a risk assessment specific to the business and its clients.
AML Officer: Appoint a designated individual responsible for AML/CTF compliance (AML Officer or Compliance Officer).
Customer Due Diligence (CDD): Implement procedures for identifying and verifying the identity of clients, including beneficial owners, and understanding the purpose and nature of business relationships. This involves collecting identity documents, verifying data, and screening against sanctions lists.
Ongoing Monitoring: Conduct ongoing monitoring of client relationships and transactions to detect suspicious activities.
Transaction Monitoring: Implement systems to monitor transactions for unusual patterns or thresholds.
Reporting: Report suspicious transactions and activities to GIIF.
Record-keeping: Maintain records of client identification data and transactions for at least 5 years.
Training: Provide regular AML/CTF training for relevant employees.
Requirement: Entities providing services related to virtual currencies, including "holding virtual currencies, including offering services to their users that consist of maintaining virtual currency instruments or access keys on their behalf," are considered Virtual Asset Service Providers (VASPs). These entities are obliged to register in the Register of Activities in the Field of Virtual Currencies (Rejestr Działalności w Zakresie Walut Wirtualnych).
Conditions for Registration:
Regulatory Body: The register is maintained by the Minister of Finance.
Current Status: The current Polish AML Act does not explicitly mandate specific rules for the segregation of client assets for virtual currency custodians. While good practice and general commercial law principles might suggest segregation, there is no direct regulatory requirement specific to crypto custody in the current AML framework.
Current Status: There is no specific definition of a "qualified custodian" for virtual assets within current Polish law. The AML Act focuses on identifying and registering VASPs for AML/CFT purposes, not on their operational qualifications or prudential standards as custodians.
Requirement: Under MiCA, entities wishing to provide custody and administration of crypto-assets will need to obtain an authorization from their competent national authority (likely the Polish Financial Supervision Authority – KNF). This authorization will be passportable across the EU.
Requirement: MiCA explicitly mandates the segregation of client crypto-assets and funds. Article 67 specifies that CASPs providing custody services must:
Conditions for Authorization: CASPs will need to meet stringent organizational, operational, and prudential requirements, including:
Having a minimum initial capital (Article 60).
Regulatory Body: The KNF will be the primary national competent authority for MiCA in Poland.
Titles II, V-XII (covering other crypto-assets and crypto-asset service providers, including custody) apply from 30 December 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers must register as VASPs with GIIF under the Polish AML Act (with a Polish legal entity requirement and AML obligations), currently operate with no specific custody/prudential rules, and face a transitional shift to KNF authorization and mandatory asset segregation under MiCA from 30 December 2024.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?