Custodial wallet / SaaS in Serbia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Serbia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including custodial wallet providers) are obliged entities under the Law on Prevention of Money Laundering and Terrorist Financing (Official Gazette RS No. 113/2017, 91/2019, 153/2020).
- Must identify and verify identity of customers (natural persons: name, surname, address, date/place of birth, unique identification number from passport or national ID card).
- Must identify and verify identity of legal entity customers (name, registered address, registration number, legal form, statutory representatives, ownership structure).
- Must identify and verify beneficial owners (natural persons owning/controlling ≥25% of the customer or on whose behalf a transaction is conducted).
- Must obtain information on purpose and intended nature of the business relationship.
- Must perform ongoing transaction monitoring and regularly update customer information and risk assessments.
- Enhanced due diligence required for Politically Exposed Persons (PEPs), their family members, and close associates.
- Enhanced due diligence required for customers from high-risk jurisdictions identified by FATF or other credible sources.
- Must report suspicious transactions to the relevant authorities.
- Record-keeping and internal AML/CFT controls required under the general AML/CFT law.
Key Restrictions
- Only legal entities registered in Serbia may apply for a VASP license; foreign entities cannot directly provide services without establishing a Serbian legal entity.
- Must obtain a VASP license from the National Bank of Serbia (NBS) and/or the Securities Commission (SC), depending on whether the digital assets qualify as virtual assets (NBS) or financial instruments/securities (SC). If both types are involved, licenses from both regulators — or a combined license — may be required.
- Client digital assets must be segregated from the VASP's own assets (mandated by Article 28(2) of the Law on Digital Assets).
- Minimum capital requirements specified in regulations by NBS or SC must be met.
- Management and significant shareholders must pass fit-and-proper tests (professional competence, reputation, no criminal record).
- Robust internal procedures, risk management systems, IT security, and business continuity plans required.
- Secondary legislation may prescribe additional financial guarantees, insurance, or higher capital requirements depending on the nature and scale of services.
Key Risks
- ["Enforcement risk: NBS actively monitors for unlicensed VASP activities and has taken steps against unlicensed custody/exchange operators.", "Criminal/investment-fraud enforcement risk: Authorities have pursued large-scale crypto Ponzi schemes (e.g., 'Infinity Economics') with arrests and asset seizures — reputational and legal exposure for custodians linked to such schemes.", "Tax enforcement risk: Tax authorities increasingly audit and enforce compliance on crypto income and capital gains; custodial wallet providers may face scrutiny regarding user tax reporting obligations.", "Regulatory ambiguity: AML/CFT supervision is described as having partial rather than strict adherence; further steps needed in supervision and effective use of financial intelligence creates uncertainty for compliance standards.", "SaaS/white-label split risk: The law does not clearly differentiate between the SaaS platform operator and the white-label client — both may be treated as VASPs requiring separate licenses, creating dual licensing exposure."]
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Licensing Authority: The Law on Digital Assets designates two main regulators, depending on the nature of the digital asset:
The National Bank of Serbia (NBS) supervises banks and financial institutions, but the regulation of virtual assets as means of payment is governed by the Law on Digital Assets, which establishes a separate regulatory framework from the NBS’s traditional supervision of payment systems.
The Securities Commission (SC) supervises digital assets that qualify as financial instruments (e.g., security tokens, certain stablecoins).
A legal entity providing services related to digital assets must obtain a license from the relevant authority. If a VASP intends to provide services for both types of digital assets, it might require licenses from both regulators or a combined license if stipulated.
Eligible Entities: Only legal entities registered in Serbia can apply for a VASP license. Foreign entities cannot directly provide services without establishing a Serbian legal entity.
Licensable Activities (including custody): The law defines "virtual asset services" that require a license, including:
Safekeeping and administration of digital assets on behalf of clients (custody).
Key Licensing Requirements: Applicants must meet stringent conditions, including:
Minimum Capital: Specified in regulations issued by the NBS or SC (e.g., minimum share capital requirements).
Management & Ownership: Fit and proper test for management and significant shareholders, demonstrating professional competence, reputation, and absence of criminal records.
Internal Controls: Robust internal procedures, risk management systems, IT security, and business continuity plans.
Serbia has made strides in risk assessment and prosecution under its AML/CFT framework, but further steps are needed in supervision and effective use of financial intelligence, indicating partial rather than strict adherence to all AML/CFT regulations.
Operational Requirements: Technical and organizational capabilities to securely provide the services.
The Law on Digital Assets mandates the segregation of client assets.
Article 28(2) of the Law on Digital Assets states that a virtual asset service provider must "take all necessary measures for the safekeeping of digital assets of its clients, including the segregation of clients' digital assets from its own digital assets."
This means that client digital assets must be held in separate accounts or wallets distinct from the VASP's proprietary assets to protect clients in case of the VASP's insolvency or bankruptcy.
The Law on Digital Assets mandates the segregation of client assets.
While the primary law doesn't explicitly mandate professional indemnity insurance or specific bonding requirements in detail, it empowers the NBS and SC to prescribe more specific conditions through secondary legislation.
Article 16 of the Law gives the regulators the power to prescribe "detailed conditions and method of obtaining and revoking licenses" which can include financial guarantees, insurance, or higher capital requirements depending on the nature and scale of the services.
Law on Digital Assets (Zakon o digitalnoj imovini):
Official Name: Закон о дигиталној имовини
This law defines digital assets, regulates their issuance and trading, and explicitly designates Virtual Asset Service Providers (VASPs) as obliged entities under the general AML/CFT law. It also sets out the licensing requirements for VASPs.
Law on the Prevention of Money Laundering and Terrorist Financing (Zakon o sprečavanju pranja novca i finansiranja terorizma)
This is the overarching AML/CFT law in Serbia, applying to all obliged entities, including VASPs. It sets out the general rules for customer due diligence, suspicious transaction reporting, record-keeping, and internal controls.
Custody and/or administration of virtual assets or instruments enabling control over virtual assets.
Identify and Verify the Identity of the Customer:
For natural persons: Obtain and verify identity based on official documents (e.g., passport, national ID card) including name, surname, address, date and place of birth, and unique identification number.
For legal entities: Obtain and verify identity based on official documents (e.g., excerpt from the company register) including name, registered address, registration number, legal form, details of statutory representatives, and information on the ownership and control structure.
Identify and Verify the Identity of the Customer:
Identify the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold for legal entities) or on whose behalf a transaction is being conducted.
Verify their identity using reliable, independent sources, as per natural person requirements. Serbia also has a Central Register of Beneficial Owners that obliged entities can consult.
Obtain Information on the Purpose and Intended Nature of the Business Relationship: Understand why the customer wants to use the VASP's services.
Perform Ongoing Monitoring of the Business Relationship:
Scrutinize transactions throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regularly update customer information and risk assessments.
Politically Exposed Persons (PEPs): For customers who are PEPs, their family members, or close associates.
High-risk jurisdictions: Customers from countries identified by FATF or other credible sources as having weak AML/CFT regimes.
Entity Targeted: Various domestic entities and individuals operating crypto asset exchange or custody services without the required licenses. While specific names are not always publicly disclosed with detailed penalties, the NBS has consistently emphasized its licensing requirements and taken steps against non-compliant entities. Violation Type: Operating a virtual asset service provider (VASP) without obtaining the necessary operating license from the NBS, as mandated by the Digital Assets Law. This includes facilitating the exchange of virtual assets for fiat currency or other virtual assets, or providing custody services. Penalty Amount: Administrative fines, cessation of operations. The Digital Assets Law (Article 109, Paragraph 1, Point 1 and 2) prescribes fines ranging from RSD 100,000 to RSD 5,000,000 for legal entities and RSD 10,000 to RSD 500,000 for responsible persons within the legal entity, along with potential protective measures like a ban on conducting business. Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Entity Targeted: Individuals and organized criminal groups involved in large-scale crypto Ponzi schemes, investment fraud, and money laundering using virtual assets. Examples include actions related to the "Infinity Economics" scheme and connections to other global crypto scams like "Finiko.". Violation Type: Fraud, money laundering, unauthorized organization of games of chance (depending on the nature of the scheme), cybercrime. These often fall under general criminal statutes rather than specific "crypto violations.". Penalty Amount: Arrests, pre-trial detention, asset freezes (including virtual assets), criminal charges leading to potential prison sentences if convicted. Specific final conviction penalties (amounts/sentences) are rarely publicly detailed for each individual case by Serbian authorities, especially if investigations are ongoing or multi-jurisdictional. Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Entity Targeted: Individuals and legal entities earning income from digital assets (e.g., capital gains from crypto trading, income from mining, staking, or providing crypto services). Violation Type: Tax evasion related to income or capital gains derived from digital assets. Penalty Amount: Varies significantly based on the amount of unpaid tax, plus interest and potential fines as per tax laws. Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers may operate in Serbia only if they establish a locally-incorporated entity, obtain a VASP license from the NBS and/or SC (depending on asset type), meet minimum capital and fit-and-proper requirements, segregate client digital assets, and comply with full CDD/AML obligations under Serbian law.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?