Centralized exchange in Serbia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Serbia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer due diligence (CDD) required under the Law on Prevention of Money Laundering and Financing of Terrorism — identify and verify identity of customers (natural persons: official ID docs; legal entities: company register excerpts).
- Beneficial owner identification required (25% ownership threshold for legal entities); consult Central Register of Beneficial Owners.
- Obtain information on purpose and intended nature of business relationship.
- Perform ongoing monitoring of business relationships — scrutinize transactions, regularly update customer info and risk assessments.
- Enhanced due diligence for PEPs, their family members/close associates, and customers from high-risk jurisdictions.
- Suspicious transaction reporting (STR) obligations under the AML/CFT law.
- Record-keeping for 5 years as required by AML/CFT laws.
- Travel Rule obligations apply: For cross-border and domestic transfers of digital assets ≥ EUR 1,000, collect and transmit originator info (name, address, official personal document number or customer ID, account/transaction ID) and beneficiary info (name, account/transaction ID) to the beneficiary VASP.
- Screen transactions and involved parties against sanctions lists.
Key Restrictions
- Only legal entities registered in Serbia can apply for a VASP license — foreign entities cannot directly provide services without establishing a Serbian legal entity.
- Must obtain a license from the National Bank of Serbia (NBS) or the Securities Commission (SC) depending on the nature of the digital asset; if providing services for both types of digital assets, may require licenses from both regulators.
- Client digital assets must be segregated from the VASP's own assets (Article 28(2) of the Law on Digital Assets).
- Minimum capital requirements (as specified in regulations by NBS/SC).
- Fit and proper test for management and significant shareholders.
- Robust internal controls, risk management systems, IT security, and business continuity plans required.
Key Risks
- Enforcement risk: NBS actively monitors for unlicensed VASP activity; several entities have faced administrative proceedings or been forced to cease operations.
- Criminal enforcement risk: Individuals and groups involved in unlicensed crypto services face arrest, asset seizure, and prosecution for fraud/money laundering (e.g., Infinity Economics scheme).
- Tax enforcement risk: Tax authorities actively pursue crypto-related income and capital gains non-compliance; audits and enforcement actions are conducted.
- Regulatory ambiguity: AML/CFT supervision is described as 'partial' rather than fully effective; secondary legislation details may still be developing.
- Revocation of license is a possible penalty for non-compliance with AML/CFT obligations including the Travel Rule.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law on Digital Assets (Zakon o digitalnoj imovini):
This law defines digital assets, regulates their issuance and trading, and explicitly designates Virtual Asset Service Providers (VASPs) as obliged entities under the general AML/CFT law. It also sets out the licensing requirements for VASPs.
Law on the Prevention of Money Laundering and Terrorist Financing (Zakon o sprečavanju pranja novca i finansiranja terorizma)
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Custody and/or administration of virtual assets or instruments enabling control over virtual assets.
Eligible Entities: Only legal entities registered in Serbia can apply for a VASP license. Foreign entities cannot directly provide services without establishing a Serbian legal entity.
The Law on Digital Assets mandates the segregation of client assets.
Article 28(2) of the Law on Digital Assets states that a virtual asset service provider must "take all necessary measures for the safekeeping of digital assets of its clients, including the segregation of clients' digital assets from its own digital assets."
The Securities Commission (SC) supervises digital assets that qualify as financial instruments (e.g., security tokens, certain stablecoins).
The National Bank of Serbia (NBS) supervises banks and financial institutions, but the regulation of virtual assets as means of payment is governed by the Law on Digital Assets, which establishes a separate regulatory framework from the NBS’s traditional supervision of payment systems.
Key Licensing Requirements: Applicants must meet stringent conditions, including:
Minimum Capital: Specified in regulations issued by the NBS or SC (e.g., minimum share capital requirements).
Management & Ownership: Fit and proper test for management and significant shareholders, demonstrating professional competence, reputation, and absence of criminal records.
Internal Controls: Robust internal procedures, risk management systems, IT security, and business continuity plans.
Whether Adopted: Yes, adopted. Serbia incorporated the FATF Travel Rule principles into its national legislation, primarily through the Law on Digital Assets (Zakon o digitalnoj imovini). This law specifically designates the National Bank of Serbia (NBS) as the supervisory authority for virtual asset service providers (VASPs) concerning AML/CFT compliance.
Threshold Amounts: Serbia generally follows the FATF Recommendation 16 for the Travel Rule. This means:
For cross-border transfers of digital assets: The Travel Rule applies to transactions with a value of EUR 1,000 or more.
For domestic transfers of digital assets: The Travel Rule also applies to transactions with a value of EUR 1,000 or more.
Originator information: Name, address, official personal document number or customer identification number (if applicable), virtual asset account number (or transaction ID if no account), and sometimes the purpose of the transaction.
Beneficiary information: Name, virtual asset account number (or transaction ID).
Secure Storage: VASPs must establish robust systems for the secure storage of collected data for a period of 5 years, as required by AML/CFT laws.
Entity Targeted: Various domestic entities and individuals operating crypto asset exchange or custody services without the required licenses. While specific names are not always publicly disclosed with detailed penalties, the NBS has consistently emphasized its licensing requirements and taken steps against non-compliant entities. Violation Type: Operating a virtual asset service provider (VASP) without obtaining the necessary operating license from the NBS, as mandated by the Digital Assets Law. This includes facilitating the exchange of virtual assets for fiat currency or other virtual assets, or providing custody services. Penalty Amount: Administrative fines, cessation of operations. The Digital Assets Law (Article 109, Paragraph 1, Point 1 and 2) prescribes fines ranging from RSD 100,000 to RSD 5,000,000 for legal entities and RSD 10,000 to RSD 500,000 for responsible persons within the legal entity, along with potential protective measures like a ban on conducting business. Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Entity Targeted: Individuals and organized criminal groups involved in large-scale crypto Ponzi schemes, investment fraud, and money laundering using virtual assets. Examples include actions related to the "Infinity Economics" scheme and connections to other global crypto scams like "Finiko.". Violation Type: Fraud, money laundering, unauthorized organization of games of chance (depending on the nature of the scheme), cybercrime. These often fall under general criminal statutes rather than specific "crypto violations.". Penalty Amount: Arrests, pre-trial detention, asset freezes (including virtual assets), criminal charges leading to potential prison sentences if convicted. Specific final conviction penalties (amounts/sentences) are rarely publicly detailed for each individual case by Serbian authorities, especially if investigations are ongoing or multi-jurisdictional. Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Entity Targeted: Individuals and legal entities earning income from digital assets (e.g., capital gains from crypto trading, income from mining, staking, or providing crypto services). Violation Type: Tax evasion related to income or capital gains derived from digital assets. Penalty Amount: Varies significantly based on the amount of unpaid tax, plus interest and potential fines as per tax laws. Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Identify and Verify the Identity of the Customer:
Evidence fact rs.licensing.identify-and-verify-the-identity-1 not found (may have been renamed).
Obtain Information on the Purpose and Intended Nature of the Business Relationship: Understand why the customer wants to use the VASP's services.
Perform Ongoing Monitoring of the Business Relationship:
Politically Exposed Persons (PEPs): For customers who are PEPs, their family members, or close associates.
High-risk jurisdictions: Customers from countries identified by FATF or other credible sources as having weak AML/CFT regimes.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Serbia only after obtaining a VASP license from the NBS or SC (depending on asset type), establishing a locally-incorporated entity, segregating client assets, and complying with full AML/CFT obligations including the FATF Travel Rule (EUR 1,000 threshold).
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?