Custodial wallet / SaaS in Sweden
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Sweden with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CASP must register/authorize with Finansinspektionen (FI) as a crypto-asset service provider under MiCA (EU Reg 2023/1114) with effect from June 30, 2024; pre-MiCA registrants have a transition period until June 30, 2026.
- Conduct KYC by obtaining customer information before any transactions (Swedish AML Act SFS 2017:630).
- Perform risk assessments of products, services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.
- Apply enhanced due diligence where risks are higher.
- Comply with EU sanctions regimes integrated via FI and the Certain International Sanctions Act (1996:95).
Key Restrictions
- Must be authorized by Finansinspektionen (FI) as a CASP under MiCA; custody of crypto assets is a regulated crypto-asset service requiring a licence.
- A local entity (Swedish incorporation) is required to apply for and maintain the FI authorization.
- Safeguarding/custody rules under MiCA apply — client assets must be segregated from the operator's own assets (no commingling), with strict custody and safekeeping obligations.
- White-label SaaS model likely means both the SaaS operator (custodian) and the white-label client may each have independent regulatory obligations — the SaaS provider as the registered CASP, and the client potentially as a distributor or onward service provider depending on activity.
Key Risks
- Regulatory ambiguity on allocation of AML obligations between the SaaS custodian platform and the white-label client — unclear whether the white-label client also requires its own CASP registration or can rely on the SaaS provider's licence.
- Pre-MiCA registrants face a hard transition deadline (June 30, 2026), creating risk for operators who have not yet obtained full MiCA authorization.
- FI has enforcement discretion; operating without a full MiCA licence (even with a pending application) carries material enforcement risk.
- Tax treatment by Skatteverket (classifying crypto as taxable financial instruments) imposes reporting obligations and capital gains tax burdens on end users, creating operational complexity for SaaS providers handling tax reporting for white-label clients.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
FI crypto-asset services page: https://www.fi.se/en/payments/apply-for-authorisation/crypto-assets-and-crypto-asset-services/cryptoasset-services/
Lag (2024:1159) (Swedish Parliament, Nov 27, 2024): Search official gazette (Svensk författningssamling) for full text.
MiCA (EU Regulation 2023/1114): Direct effect in Sweden.
Swedish Financial Supervisory Authority (Finansinspektionen / SFSA): Primary regulator for supervising CASPs, licensing issuers of e-money/asset-referenced tokens, enforcing MiCA, AML/KYC, and consumer protection; appointed national competent authority via act effective June 30, 2024.
Primary laws: Swedish Anti-Money Laundering and Terrorist Financing Law (AML Act, SFS 2017:630); Money Laundering Crimes Criminal Code; former Currency Exchange Act (SCEA, 1996:1006, now amended/reduced post-MiCA); Lag med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar (2024:1159, effective 30 Dec 2024).
EU alignment: MiCA directly effective; CASPs now under direct AML Act regulation; prior SCEA expansions (effective 1 Jan 2020) imposed stricter-than-EU AML on virtual currency exchanges and custodians.
Registration/authorization required with FI; transition for pre-MiCA registrants until 30 Jun 2026.
Conduct KYC by obtaining customer information before transactions.
Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.
Apply enhanced due diligence where risks are higher.
Certain International Sanctions Act (1996:95): riksagen.se (via FI link)
EU sanctions: Integrated via FI; OFAC SDN: https://sanctionssearch.ofac.treas.gov
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers must obtain a MiCA CASP authorization from Finansinspektionen (FI) as a locally-incorporated entity, comply with full AML obligations under SFS 2017:630, and must segregate client crypto assets; allocation of AML duties between the SaaS platform and white-label clients remains an area of regulatory uncertainty.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?