Remote VASP serving residents in Sweden
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Sweden with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Must register/authorize with Finansinspektionen (FI) as a CASP under MiCA (EU Regulation 2023/1114) and the Swedish AML Act (SFS 2017:630)
- Conduct KYC by obtaining customer information before any transactions (se.aml.conduct-kyc-by-obtaining-customer)
- Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing (se.aml.perform-risk-assessments-of-productsservices)
- Apply enhanced due diligence where risks are higher (se.aml.apply-enhanced-due-diligence-where)
- Screen against EU sanctions (integrated via FI) and Certain International Sanctions Act (1996:95) (se.aml.eu-sanctions-integrated-via-fi, se.aml.certain-international-sanctions-act-199695)
- Pre-MiCA registrants have transition period until 30 June 2026 to obtain full authorization (se.aml.registrationauthorization-required-with-fi-transition)
Key Restrictions
- Non-resident entity cannot serve Swedish residents without first obtaining authorization from Finansinspektionen as a CASP under MiCA
- Local incorporation or at least an EU establishment is required — a remote foreign-entity structure without EU presence is not permissible
- Authorization must be obtained from Finansinspektionen (FI) as the national competent authority under MiCA effective June 30, 2024 (se.licensing.swedish-financial-supervisory-authority-finansinspektionen)
- Transitional period for pre-MiCA registered entities ends June 30, 2026 — after that, full MiCA authorization is mandatory
Key Risks
- Enforcement risk is high for unlicensed remote operators — Binance-style enforcement actions under Swedish law are possible
- Sweden has historically imposed stricter-than-EU AML requirements on VASPs (pre-MiCA via SCEA expansions effective Jan 1, 2020), signaling an aggressive regulatory posture
- Tax reporting obligations to Skatteverket for Swedish residents' transactions create practical compliance complexity for remote operators
- Failure to obtain FI authorization could result in criminal liability under the Money Laundering Crimes Criminal Code and sanctions enforcement actions
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Swedish Financial Supervisory Authority (Finansinspektionen / SFSA): Primary regulator for supervising CASPs, licensing issuers of e-money/asset-referenced tokens, enforcing MiCA, AML/KYC, and consumer protection; appointed national competent authority via act effective June 30, 2024.
Primary laws: Swedish Anti-Money Laundering and Terrorist Financing Law (AML Act, SFS 2017:630); Money Laundering Crimes Criminal Code; former Currency Exchange Act (SCEA, 1996:1006, now amended/reduced post-MiCA); Lag med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar (2024:1159, effective 30 Dec 2024).
EU alignment: MiCA directly effective; CASPs now under direct AML Act regulation; prior SCEA expansions (effective 1 Jan 2020) imposed stricter-than-EU AML on virtual currency exchanges and custodians.
Registration/authorization required with FI; transition for pre-MiCA registrants until 30 Jun 2026.
Conduct KYC by obtaining customer information before transactions.
Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.
Apply enhanced due diligence where risks are higher.
EU sanctions: Integrated via FI; OFAC SDN: https://sanctionssearch.ofac.treas.gov
Certain International Sanctions Act (1996:95): riksagen.se (via FI link)
MiCA (EU Regulation 2023/1114): Direct effect in Sweden.
Lag (2024:1159) (Swedish Parliament, Nov 27, 2024): Search official gazette (Svensk författningssamling) for full text.
FI crypto-asset services page: https://www.fi.se/en/payments/apply-for-authorisation/crypto-assets-and-crypto-asset-services/cryptoasset-services/
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-resident remote VASP cannot serve Swedish residents from abroad without first obtaining MiCA authorization from Finansinspektionen, which requires an EU establishment and subjects the operator to full AML/KYC obligations under the Swedish AML Act (SFS 2017:630).
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?