DeFi protocol frontend in Serbia
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Serbia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD required for all customers (identify and verify identity of customer, beneficial owner, purpose of business relationship, ongoing monitoring) — see rs.licensing.identify-and-verify-the-identity: Identify and Verify the Identity of the Customer:
- For natural persons: obtain and verify identity based on official documents (name, surname, address, date/place of birth, unique ID) — rs.licensing.for-natural-persons-obtain-and
- For legal entities: obtain and verify identity based on official documents (company register excerpt) — rs.licensing.for-legal-entities-obtain-and
- Identify and verify beneficial owner (25% ownership threshold) via reliable, independent sources — rs.licensing.identify-and-verify-the-identity: Identify and Verify the Identity of the Beneficial Owner (BO): and rs.licensing.identify-the-natural-persons-who and rs.licensing.verify-their-identity-using-reliable
- Ongoing transaction monitoring and regular updating of customer information — rs.licensing.perform-ongoing-monitoring-of-the and rs.licensing.scrutinize-transactions-throughout-the-course and rs.licensing.regularly-update-customer-information-and
- Enhanced due diligence for PEPs and customers from high-risk FATF jurisdictions — rs.licensing.politically-exposed-persons-peps-for and rs.licensing.high-risk-jurisdictions-customers-from-countries
- Obliged entity status under the overarching AML/CFT Law (Law on Prevention of Money Laundering and Terrorist Financing) — rs.licensing.law-on-the-prevention-of
Key Restrictions
- Must obtain a VASP license from the NBS or SC (or both) before offering services — rs.custody.licensing-authority-the-law-on and rs.custody.a-legal-entity-providing-services
- Only legal entities registered in Serbia can apply — foreign entities must incorporate a Serbian entity — rs.custody.eligible-entities-only-legal-entities
- Fee-taking (commission, spread, or other revenue from users) likely qualifies as 'participation in and provision of financial services' or 'execution of orders', triggering full VASP licensing — rs.licensing.participation-in-and-provision-of and rs.custody.receipt-transfer-and-execution-of
- Client digital assets must be segregated (separate wallets/accounts) from proprietary assets — rs.custody.the-law-on-digital-assets: The Law on Digital Assets mandates the segregation of client assets. and rs.custody.article-282-of-the-law
- Minimum capital requirements must be met (specified by NBS/SC regulations) — rs.custody.minimum-capital-specified-in-regulations
- Management and significant shareholders subject to fit-and-proper test — rs.custody.management-ownership-fit-and-proper
- If the digital assets qualify as financial instruments (security tokens), the Securities Commission (SC) supervises — rs.custody.the-securities-commission-sc-supervises
Key Risks
- Regulatory classification risk: a purely non-custodial frontend with no fee-taking may argue it is not a VASP, but Serbian law casts a wide net over 'receipt, transfer, and execution of orders' and 'participation in financial services', creating ambiguity
- Enforcement risk: the NBS actively monitors for unlicensed activity and unlicensed operators face administrative proceedings — rs.enforcement.entity-targeted-various-domestic-entities and rs.enforcement.outcome-several-entities-have-either
- Criminal enforcement risk: individuals involved in crypto-related fraud/Ponzi schemes have been arrested and assets seized — rs.enforcement.entity-targeted-individuals-and-organized and rs.enforcement.outcome-numerous-arrests-have-been
- Tax compliance risk: income from providing crypto services is taxable and tax enforcement is increasing — rs.enforcement.entity-targeted-individuals-and-legal and rs.enforcement.outcome-increased-tax-compliance-with
- Dual regulator exposure: if operating across both virtual assets and security tokens, may need licenses from both NBS and SC
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law on Digital Assets (Zakon o digitalnoj imovini):
This law defines digital assets, regulates their issuance and trading, and explicitly designates Virtual Asset Service Providers (VASPs) as obliged entities under the general AML/CFT law. It also sets out the licensing requirements for VASPs.
Law on the Prevention of Money Laundering and Terrorist Financing (Zakon o sprečavanju pranja novca i finansiranja terorizma)
Participation in and provision of financial services related to the offer and/or sale of virtual assets (e.g., initial coin offerings - ICOs, initial exchange offerings - IEOs).
Evidence fact rs.licensing.identify-and-verify-the-identity: Identify and Verify the Identity of the Customer: not found (may have been renamed).
For natural persons: Obtain and verify identity based on official documents (e.g., passport, national ID card) including name, surname, address, date and place of birth, and unique identification number.
For legal entities: Obtain and verify identity based on official documents (e.g., excerpt from the company register) including name, registered address, registration number, legal form, details of statutory representatives, and information on the ownership and control structure.
Evidence fact rs.licensing.identify-and-verify-the-identity: Identify and Verify the Identity of the Beneficial Owner (BO): not found (may have been renamed).
Identify the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold for legal entities) or on whose behalf a transaction is being conducted.
Verify their identity using reliable, independent sources, as per natural person requirements. Serbia also has a Central Register of Beneficial Owners that obliged entities can consult.
Perform Ongoing Monitoring of the Business Relationship:
Scrutinize transactions throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Regularly update customer information and risk assessments.
Politically Exposed Persons (PEPs): For customers who are PEPs, their family members, or close associates.
High-risk jurisdictions: Customers from countries identified by FATF or other credible sources as having weak AML/CFT regimes.
Licensing Authority: The Law on Digital Assets designates two main regulators, depending on the nature of the digital asset:
A legal entity providing services related to digital assets must obtain a license from the relevant authority. If a VASP intends to provide services for both types of digital assets, it might require licenses from both regulators or a combined license if stipulated.
Eligible Entities: Only legal entities registered in Serbia can apply for a VASP license. Foreign entities cannot directly provide services without establishing a Serbian legal entity.
Receipt, transfer, and execution of orders related to digital assets.
Key Licensing Requirements: Applicants must meet stringent conditions, including:
Minimum Capital: Specified in regulations issued by the NBS or SC (e.g., minimum share capital requirements).
Management & Ownership: Fit and proper test for management and significant shareholders, demonstrating professional competence, reputation, and absence of criminal records.
Evidence fact rs.custody.the-law-on-digital-assets: The Law on Digital Assets mandates the segregation of client assets. not found (may have been renamed).
Article 28(2) of the Law on Digital Assets states that a virtual asset service provider must "take all necessary measures for the safekeeping of digital assets of its clients, including the segregation of clients' digital assets from its own digital assets."
The Securities Commission (SC) supervises digital assets that qualify as financial instruments (e.g., security tokens, certain stablecoins).
Entity Targeted: Various domestic entities and individuals operating crypto asset exchange or custody services without the required licenses. While specific names are not always publicly disclosed with detailed penalties, the NBS has consistently emphasized its licensing requirements and taken steps against non-compliant entities. Violation Type: Operating a virtual asset service provider (VASP) without obtaining the necessary operating license from the NBS, as mandated by the Digital Assets Law. This includes facilitating the exchange of virtual assets for fiat currency or other virtual assets, or providing custody services. Penalty Amount: Administrative fines, cessation of operations. The Digital Assets Law (Article 109, Paragraph 1, Point 1 and 2) prescribes fines ranging from RSD 100,000 to RSD 5,000,000 for legal entities and RSD 10,000 to RSD 500,000 for responsible persons within the legal entity, along with potential protective measures like a ban on conducting business. Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Outcome: Several entities have either ceased operations, come into compliance, or faced administrative proceedings. The NBS continues to monitor the market for unlicensed activity.
Entity Targeted: Individuals and organized criminal groups involved in large-scale crypto Ponzi schemes, investment fraud, and money laundering using virtual assets. Examples include actions related to the "Infinity Economics" scheme and connections to other global crypto scams like "Finiko.". Violation Type: Fraud, money laundering, unauthorized organization of games of chance (depending on the nature of the scheme), cybercrime. These often fall under general criminal statutes rather than specific "crypto violations.". Penalty Amount: Arrests, pre-trial detention, asset freezes (including virtual assets), criminal charges leading to potential prison sentences if convicted. Specific final conviction penalties (amounts/sentences) are rarely publicly detailed for each individual case by Serbian authorities, especially if investigations are ongoing or multi-jurisdictional. Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Outcome: Numerous arrests have been made, leading to ongoing investigations, indictments, and trials. Assets, including cryptocurrencies, have been seized. These cases are often complex and lengthy.
Entity Targeted: Individuals and legal entities earning income from digital assets (e.g., capital gains from crypto trading, income from mining, staking, or providing crypto services). Violation Type: Tax evasion related to income or capital gains derived from digital assets. Penalty Amount: Varies significantly based on the amount of unpaid tax, plus interest and potential fines as per tax laws. Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Outcome: Increased tax compliance, with individuals and entities reporting and paying taxes on their crypto gains. Audits and enforcement actions against non-compliant taxpayers are conducted, though details are private unless criminal charges are filed.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Operating a DeFi frontend targeting Serbian residents is likely a regulated VASP activity requiring a Serbian-entity VASP license; fee-taking almost certainly triggers licensing; a purely informational non-custodial frontend with zero revenue from Serbian users may argue against VASP classification, but the legal risk is high and the NBS actively enforces unlicensed activity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?