← Regulations / Slovenia / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Slovenia

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Slovenia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • VASPs must register with the Office for Money Laundering Prevention (UPPD) before operating (si.aml.obligation-to-register-vasps-must, si.aml.vasp-registration-entities-providing-services)
  • Implementation of robust internal AML/CFT policies, procedures, and controls (si.aml.implementation-of-robust-internal-amlcft)
  • Risk assessment frameworks covering customer, product, and geographical risks (si.aml.risk-assessment-frameworks-customer-product)
  • Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) measures (si.aml.customer-due-diligence-cdd-and)
  • Record-keeping of transactions and customer data (si.aml.record-keeping-of-transactions-and-customer)
  • Reporting of suspicious transactions to UPPD (si.aml.reporting-of-suspicious-transactions-to)
  • Appointment of an AML officer (si.aml.appointment-of-an-aml-officer)
  • Training for relevant employees (si.aml.training-for-relevant-employees)
  • Fit and proper assessment for management and beneficial owners (si.aml.fit-and-proper-assessment-for)
  • Under MiCA (future): CASPs offering custody services will require authorization from ATVP with initial capital requirements, governance arrangements, and professional indemnity insurance (si.aml.authorization-casps-offering-custody-services, si.aml.initial-capital-requirement-for-minimum)

Key Restrictions

  • Slovenia currently applies an AML/CTF registration regime under ZPPML-1 / ZPPDFT-2 — no separate 'custody license' or qualified-custodian status exists for pure crypto custodians (si.licensing.current-regime-zppml-1-registration-slovenia, si.aml.currently-pre-mica-slovenian-law-zppdft-2)
  • There is no statutory requirement currently for segregation of client crypto assets from the custodian's own assets (insolvency-remote) under ZPPDFT-2 (si.aml.currently-pre-mica-zppdft-2-primarily-focuses)
  • There are currently no specific statutory requirements to carry professional indemnity insurance or maintain minimum own funds for asset protection (si.aml.currently-pre-mica-there-are-no)
  • Cold storage is not explicitly mandated, but VASPs must implement robust technical and organizational security measures (si.aml.currently-pre-mica-slovenian-law-does)
  • Under MiCA (future), CASPs will need a full authorization from the national competent authority (likely ATVP), must be a legal person established in the EU, and must meet initial capital requirements (si.aml.authorization-casps-offering-custody-services, si.aml.legal-form-casps-must-be, si.aml.initial-capital-requirement-for-minimum)
  • If the custodial wallet/SaaS provider also processes fiat payments (EUR deposits/withdrawals), it may require a Payment Institution or EMI license from the Bank of Slovenia under ZPlaS-1 (si.licensing.if-processing-fiat-payments-for, si.licensing.this-could-require-a-payment)

Key Risks

  • Regulatory ambiguity: current ZPPDFT-2 regime lacks specific prudential or custody rules (segregation, insurance, proof-of-reserves) creating legal uncertainty for institutional clients (si.aml.currently-pre-mica-zppdft-2-primarily-focuses)
  • Transition risk: the shift from AML registration (FURS/UPPD) to MiCA CASP licensing (ATVP) in 2024-2025 means operators face dual regimes and potential re-authorization (si.licensing.future-regime-mica-licensing-the)
  • Enforcement is low-visibility: UPPD conducts supervision but does not routinely publish named enforcement actions, creating compliance uncertainty (si.enforcement.amlcft-supervisory-activities-general)
  • If the SaaS provider is the regulated VASP while white-label clients are not regulated, the SaaS provider bears full AML/CTF liability for end users — unclear allocation of obligations under the current framework
  • No official recognition of 'qualified custodian' status means custodial wallet operators may struggle to meet institutional counterparty requirements

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Current Regime (ZPPML-1): Registration. Slovenia currently requires VASPs to register with FURS before they can operate. This is a registration for AML/CTF purposes, focusing on preventing illicit financial activities, rather than a full operational license that would typically cover aspects like prudential requirements, consumer protection, or market integrity comprehensively.

licensing 20% confidence

Requirement: Registration with FURS under ZPPML-1.

aml 60% confidence

VASP Registration: Entities providing services of safeguarding private cryptographic keys on behalf of clients, or holding, storing, and transferring virtual currencies, are classified as "virtual asset service providers" (VASPs) under ZPPDFT-2.

aml 60% confidence

Obligation to Register: VASPs must register with the Office for Money Laundering Prevention (UPPD). This is a registration requirement, not a full prudential licensing regime akin to banks or investment firms, but it entails strict AML/CFT compliance obligations.

aml 100% confidence

Fit and proper assessment for management and beneficial owners (though not as extensive as for licensed financial institutions).

licensing 20% confidence

Activities Covered: Services that hold or administer virtual currencies on behalf of third parties, or provide safekeeping services for private cryptographic keys on behalf of clients to hold, store, and transfer virtual currencies.

licensing 20% confidence

If processing fiat payments for crypto transactions (e.g., enabling users to deposit/withdraw EUR to/from an exchange account):

licensing 20% confidence

This could require a Payment Institution (PI) license or Electronic Money Institution (EMI) license from the Bank of Slovenia (Banka Slovenije). This is separate from VASP registration and is generally a more robust licensing process.

licensing 20% confidence

Future Regime (MiCA): Licensing. The EU's Markets in Crypto-Assets (MiCA) Regulation (Regulation (EU) 2023/1114) will introduce a comprehensive, harmonized licensing framework for crypto-asset service providers (CASPs) across all EU member states. MiCA will come into full effect for most crypto-assets by December 30, 2024 (stablecoin rules apply from June 30, 2024). Once MiCA is fully implemented, it will largely supersede the national AML-driven registration requirements for the activities it covers, introducing a full licensing regime with passporting rights across the EU.

aml 60% confidence

Authorization: CASPs offering custody services will require authorization from a national competent authority (e.g., ATVP in Slovenia). This is a much more stringent licensing process than the current AML registration.

aml 60% confidence

Initial capital: Requirement for minimum initial capital or professional indemnity insurance (see below).

aml 60% confidence

Currently (Pre-MiCA): ZPPDFT-2 primarily focuses on AML/CFT compliance, ensuring the identification of asset ownership and preventing illicit finance. It does not explicitly mandate insolvency-remote segregation of client crypto assets from the custodian's own assets in the same way traditional financial regulations (e.g., MiFID II for investment firms, CRD for banks) do.

aml 60% confidence

Currently (Pre-MiCA): There are no specific statutory requirements under ZPPDFT-2 for VASPs (including custodians) to hold professional indemnity insurance or maintain a minimum level of own funds for asset protection, unlike for traditional financial institutions.

aml 60% confidence

Currently (Pre-MiCA): Slovenian law does not explicitly mandate the use of cold storage for crypto assets. However, VASPs are expected to implement robust technical and organizational security measures to protect client assets from loss, theft, or unauthorized access. Good practice dictates that a significant portion of client assets should be held in cold storage. Regulators would assess the overall security framework rather than dictating specific technological solutions.

aml 60% confidence

Currently (Pre-MiCA): Slovenian law (ZPPDFT-2) defines the service of safeguarding private cryptographic keys and the provider as a VASP. There isn't a separate legal definition of a "qualified custodian" that implies a higher prudential standard beyond AML compliance for pure crypto firms. Any VASP registered with UPPD and adhering to AML/CFT rules is currently considered a legitimate provider.

enforcement 60% confidence

Entity Targeted: Virtual Asset Service Providers (VASPs) operating in Slovenia. Violation Type: Non-compliance with AML/CFT obligations (e.g., inadequate customer due diligence, suspicious transaction reporting failures, internal control deficiencies). Penalty Amount: Details are not typically made public for individual administrative measures, but can range from warnings to fines.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are permitted in Slovenia as registered VASPs under ZPPML-1/ZPPDFT-2, but the current regime lacks specific custody prudential rules (segregation, insurance, capital); full MiCA CASP licensing will apply from 2024-2025, and fiat payment processing may trigger an additional PI/EMI license from the Bank of Slovenia.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?