← Regulations / Sweden / Operating Models / Remote VASP

Remote VASP serving residents in Sweden

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Sweden with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Must register/authorize with Finansinspektionen (FI) as a CASP under MiCA (EU Regulation 2023/1114) and the Swedish AML Act (SFS 2017:630)
  • Conduct KYC by obtaining customer information before any transactions (se.aml.conduct-kyc-by-obtaining-customer)
  • Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing (se.aml.perform-risk-assessments-of-productsservices)
  • Apply enhanced due diligence where risks are higher (se.aml.apply-enhanced-due-diligence-where)
  • Screen against EU sanctions (integrated via FI) and Certain International Sanctions Act (1996:95) (se.aml.eu-sanctions-integrated-via-fi, se.aml.certain-international-sanctions-act-199695)
  • Pre-MiCA registrants have transition period until 30 June 2026 to obtain full authorization (se.aml.registrationauthorization-required-with-fi-transition)

Key Restrictions

  • Non-resident entity cannot serve Swedish residents without first obtaining authorization from Finansinspektionen as a CASP under MiCA
  • Local incorporation or at least an EU establishment is required — a remote foreign-entity structure without EU presence is not permissible
  • Authorization must be obtained from Finansinspektionen (FI) as the national competent authority under MiCA effective June 30, 2024 (se.licensing.swedish-financial-supervisory-authority-finansinspektionen)
  • Transitional period for pre-MiCA registered entities ends June 30, 2026 — after that, full MiCA authorization is mandatory

Key Risks

  • Enforcement risk is high for unlicensed remote operators — Binance-style enforcement actions under Swedish law are possible
  • Sweden has historically imposed stricter-than-EU AML requirements on VASPs (pre-MiCA via SCEA expansions effective Jan 1, 2020), signaling an aggressive regulatory posture
  • Tax reporting obligations to Skatteverket for Swedish residents' transactions create practical compliance complexity for remote operators
  • Failure to obtain FI authorization could result in criminal liability under the Money Laundering Crimes Criminal Code and sanctions enforcement actions

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Swedish Financial Supervisory Authority (Finansinspektionen / SFSA): Primary regulator for supervising CASPs, licensing issuers of e-money/asset-referenced tokens, enforcing MiCA, AML/KYC, and consumer protection; appointed national competent authority via act effective June 30, 2024.

aml 100% confidence

Primary laws: Swedish Anti-Money Laundering and Terrorist Financing Law (AML Act, SFS 2017:630); Money Laundering Crimes Criminal Code; former Currency Exchange Act (SCEA, 1996:1006, now amended/reduced post-MiCA); Lag med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar (2024:1159, effective 30 Dec 2024).

aml 100% confidence

EU alignment: MiCA directly effective; CASPs now under direct AML Act regulation; prior SCEA expansions (effective 1 Jan 2020) imposed stricter-than-EU AML on virtual currency exchanges and custodians.

aml 100% confidence

Registration/authorization required with FI; transition for pre-MiCA registrants until 30 Jun 2026.

aml 100% confidence

Conduct KYC by obtaining customer information before transactions.

aml 100% confidence

Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.

aml 100% confidence

Apply enhanced due diligence where risks are higher.

aml 60% confidence

EU sanctions: Integrated via FI; OFAC SDN: https://sanctionssearch.ofac.treas.gov

aml 60% confidence

Certain International Sanctions Act (1996:95): riksagen.se (via FI link)

custody 40% confidence

MiCA (EU Regulation 2023/1114): Direct effect in Sweden.

custody 40% confidence

Lag (2024:1159) (Swedish Parliament, Nov 27, 2024): Search official gazette (Svensk författningssamling) for full text.

custody 50% confidence

FI crypto-asset services page: https://www.fi.se/en/payments/apply-for-authorisation/crypto-assets-and-crypto-asset-services/cryptoasset-services/

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a non-resident remote VASP cannot serve Swedish residents from abroad without first obtaining MiCA authorization from Finansinspektionen, which requires an EU establishment and subjects the operator to full AML/KYC obligations under the Swedish AML Act (SFS 2017:630).

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?