← Regulations / Sweden / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Sweden

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Sweden with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CASP must register/authorize with Finansinspektionen (FI) as a crypto-asset service provider under MiCA (EU Reg 2023/1114) with effect from June 30, 2024; pre-MiCA registrants have a transition period until June 30, 2026.
  • Conduct KYC by obtaining customer information before any transactions (Swedish AML Act SFS 2017:630).
  • Perform risk assessments of products, services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.
  • Apply enhanced due diligence where risks are higher.
  • Comply with EU sanctions regimes integrated via FI and the Certain International Sanctions Act (1996:95).

Key Restrictions

  • Must be authorized by Finansinspektionen (FI) as a CASP under MiCA; custody of crypto assets is a regulated crypto-asset service requiring a licence.
  • A local entity (Swedish incorporation) is required to apply for and maintain the FI authorization.
  • Safeguarding/custody rules under MiCA apply — client assets must be segregated from the operator's own assets (no commingling), with strict custody and safekeeping obligations.
  • White-label SaaS model likely means both the SaaS operator (custodian) and the white-label client may each have independent regulatory obligations — the SaaS provider as the registered CASP, and the client potentially as a distributor or onward service provider depending on activity.

Key Risks

  • Regulatory ambiguity on allocation of AML obligations between the SaaS custodian platform and the white-label client — unclear whether the white-label client also requires its own CASP registration or can rely on the SaaS provider's licence.
  • Pre-MiCA registrants face a hard transition deadline (June 30, 2026), creating risk for operators who have not yet obtained full MiCA authorization.
  • FI has enforcement discretion; operating without a full MiCA licence (even with a pending application) carries material enforcement risk.
  • Tax treatment by Skatteverket (classifying crypto as taxable financial instruments) imposes reporting obligations and capital gains tax burdens on end users, creating operational complexity for SaaS providers handling tax reporting for white-label clients.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 50% confidence

FI crypto-asset services page: https://www.fi.se/en/payments/apply-for-authorisation/crypto-assets-and-crypto-asset-services/cryptoasset-services/

custody 40% confidence

Lag (2024:1159) (Swedish Parliament, Nov 27, 2024): Search official gazette (Svensk författningssamling) for full text.

custody 40% confidence

MiCA (EU Regulation 2023/1114): Direct effect in Sweden.

licensing 60% confidence

Swedish Financial Supervisory Authority (Finansinspektionen / SFSA): Primary regulator for supervising CASPs, licensing issuers of e-money/asset-referenced tokens, enforcing MiCA, AML/KYC, and consumer protection; appointed national competent authority via act effective June 30, 2024.

aml 100% confidence

Primary laws: Swedish Anti-Money Laundering and Terrorist Financing Law (AML Act, SFS 2017:630); Money Laundering Crimes Criminal Code; former Currency Exchange Act (SCEA, 1996:1006, now amended/reduced post-MiCA); Lag med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar (2024:1159, effective 30 Dec 2024).

aml 100% confidence

EU alignment: MiCA directly effective; CASPs now under direct AML Act regulation; prior SCEA expansions (effective 1 Jan 2020) imposed stricter-than-EU AML on virtual currency exchanges and custodians.

aml 100% confidence

Registration/authorization required with FI; transition for pre-MiCA registrants until 30 Jun 2026.

aml 100% confidence

Conduct KYC by obtaining customer information before transactions.

aml 100% confidence

Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.

aml 100% confidence

Apply enhanced due diligence where risks are higher.

aml 60% confidence

Certain International Sanctions Act (1996:95): riksagen.se (via FI link)

aml 60% confidence

EU sanctions: Integrated via FI; OFAC SDN: https://sanctionssearch.ofac.treas.gov

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers must obtain a MiCA CASP authorization from Finansinspektionen (FI) as a locally-incorporated entity, comply with full AML obligations under SFS 2017:630, and must segregate client crypto assets; allocation of AML duties between the SaaS platform and white-label clients remains an area of regulatory uncertainty.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?