Centralized exchange in Slovenia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Slovenia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register with FURS (Financial Administration) as a VASP under ZPPML-1 before commencing operations.
- Implement robust internal AML/CFT policies, procedures, and controls.
- Conduct risk assessment frameworks (customer, product, geographical risks).
- Perform Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) measures.
- Maintain record-keeping of transactions and customer data.
- Report suspicious transactions to the Office for Money Laundering Prevention (UPPD).
- Appoint an AML officer (fit and proper).
- Provide AML/CFT training for relevant employees.
- Undergo fit and proper assessment for management and beneficial owners.
- Under MiCA (future regime): comply with travel rule obligations for crypto-asset transfers (TFR), including obtaining, holding, and transmitting originator and beneficiary information on withdrawals.
- Under MiCA: initial capital requirement or professional indemnity insurance (minimum capital for CASP custody services).
Key Restrictions
- Currently operates under ZPPML-1 registration regime (AML-focused), not a full prudential license — no explicit custody segregation rules exist under current law for crypto assets.
- If processing fiat payments (EUR deposits/withdrawals), a separate Payment Institution (PI) or Electronic Money Institution (EMI) license from the Bank of Slovenia may be required under ZPlaS-1 (PSD2 transposition).
- Under MiCA (full effect mid-2025), a CASP license from a designated national competent authority (likely ATVP or Bank of Slovenia) will be mandatory, replacing the current registration regime.
- No explicit statutory requirement under current law to hold professional indemnity insurance or maintain minimum own funds for asset protection (MiCA will change this).
- No statutory mandate for cold storage of crypto assets under current Slovenian law, though robust technical/organizational security measures are expected.
Key Risks
- Regulatory ambiguity around custody segregation: current ZPPDFT-2 does not explicitly mandate insolvency-remote segregation of client crypto assets from the custodian's own assets, creating risk in the event of insolvency.
- Transition risk: MiCA will introduce a full CASP licensing regime with capital requirements, governance standards, and enhanced custody rules—operators must be prepared for the regulatory upgrade.
- Fiat payment processing may trigger dual regulation (FURS for VASP + Bank of Slovenia for payment services), increasing compliance complexity.
- Enforcement activity is primarily AML-focused and not highly public; limited precedent makes it difficult to gauge regulatory intensity beyond annual UPPD reports.
- Travel rule obligations under MiCA/TFR will require technical implementation for all crypto-asset transfers on withdrawals.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Act on the Prevention of Money Laundering and Terrorist Financing (ZPPML-1):
Competent Authority: The Financial Administration of the Republic of Slovenia (FURS) (Finančna uprava Republike Slovenije) is the primary supervisory authority for AML/CTF compliance, including the registration and supervision of VASPs.
Current Regime (ZPPML-1): Registration. Slovenia currently requires VASPs to register with FURS before they can operate. This is a registration for AML/CTF purposes, focusing on preventing illicit financial activities, rather than a full operational license that would typically cover aspects like prudential requirements, consumer protection, or market integrity comprehensively.
Future Regime (MiCA): Licensing. The EU's Markets in Crypto-Assets (MiCA) Regulation (Regulation (EU) 2023/1114) will introduce a comprehensive, harmonized licensing framework for crypto-asset service providers (CASPs) across all EU member states. MiCA will come into full effect for most crypto-assets by December 30, 2024 (stablecoin rules apply from June 30, 2024). Once MiCA is fully implemented, it will largely supersede the national AML-driven registration requirements for the activities it covers, introducing a full licensing regime with passporting rights across the EU.
Requirement: Registration with FURS under ZPPML-1.
Activities Covered: Providing platforms or services where users can buy/sell virtual currencies with fiat currencies (e.g., EUR, USD) or exchange one virtual currency for another (e.g., BTC for ETH).
Future under MiCA: Will require a CASP license from a competent authority (which Slovenia will designate, likely Bank of Slovenia or ATVP) for operating an exchange platform.
If processing fiat payments for crypto transactions (e.g., enabling users to deposit/withdraw EUR to/from an exchange account):
This could require a Payment Institution (PI) license or Electronic Money Institution (EMI) license from the Bank of Slovenia (Banka Slovenije). This is separate from VASP registration and is generally a more robust licensing process.
VASP Registration: Entities providing services of safeguarding private cryptographic keys on behalf of clients, or holding, storing, and transferring virtual currencies, are classified as "virtual asset service providers" (VASPs) under ZPPDFT-2.
Obligation to Register: VASPs must register with the Office for Money Laundering Prevention (UPPD). This is a registration requirement, not a full prudential licensing regime akin to banks or investment firms, but it entails strict AML/CFT compliance obligations.
Implementation of robust internal AML/CFT policies, procedures, and controls.
Risk assessment frameworks (customer, product, geographical risks).
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) measures.
Record-keeping of transactions and customer data.
Reporting of suspicious transactions to UPPD.
Appointment of an AML officer.
Training for relevant employees.
Fit and proper assessment for management and beneficial owners (though not as extensive as for licensed financial institutions).
Currently (Pre-MiCA): ZPPDFT-2 primarily focuses on AML/CFT compliance, ensuring the identification of asset ownership and preventing illicit finance. It does not explicitly mandate insolvency-remote segregation of client crypto assets from the custodian's own assets in the same way traditional financial regulations (e.g., MiFID II for investment firms, CRD for banks) do.
Currently (Pre-MiCA): There are no specific statutory requirements under ZPPDFT-2 for VASPs (including custodians) to hold professional indemnity insurance or maintain a minimum level of own funds for asset protection, unlike for traditional financial institutions.
Currently (Pre-MiCA): Slovenian law does not explicitly mandate the use of cold storage for crypto assets. However, VASPs are expected to implement robust technical and organizational security measures to protect client assets from loss, theft, or unauthorized access. Good practice dictates that a significant portion of client assets should be held in cold storage. Regulators would assess the overall security framework rather than dictating specific technological solutions.
Authorization: CASPs offering custody services will require authorization from a national competent authority (e.g., ATVP in Slovenia). This is a much more stringent licensing process than the current AML registration.
Key Requirements (MiCA Articles 59-64, and specific for custody Articles 65-68):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange with custody can operate in Slovenia under current AML registration (FURS/ZPPML-1), but fiat on/off-ramp services may require a separate payment license (Bank of Slovenia), and MiCA (mid-2025) will introduce a full CASP licensing regime with capital, governance, custody segregation, and travel-rule requirements.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?