← Regulations / Slovakia / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Slovakia

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Slovakia without local incorporation, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration as an obliged entity under Act No. 297/2008 Coll. (AML Act) with the Slovak FIU / Ministry of Interior (currently no dedicated custody license).
  • Customer due diligence (CDD): identity verification of natural persons (full name, date of birth, address, nationality, ID document) and legal entities (company name, registered address, registration number, management, authority).
  • Identify and verify Ultimate Beneficial Owner (UBO) — individual(s) holding ≥25% shares/voting rights or otherwise controlling the customer.
  • Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and new/developing technologies including virtual assets.
  • Source of Funds (SoF) and Source of Wealth (SoW) measures for high-risk relationships or transactions.
  • Ongoing transaction monitoring and continuous scrutiny of business relationships; keep customer info up-to-date.
  • Suspicious Activity Reporting (SAR) — any transaction, attempted transaction, or activity suspected to be linked to criminal proceeds or terrorist financing must be reported promptly to the FIU.
  • Internal risk management systems, policies, and procedures for AML/CFT compliance.
  • From December 30, 2024: MiCA will require mandatory authorization as a CASP (Crypto-Asset Service Provider) by NBS (National Bank of Slovakia) for custody and administration of crypto-assets on behalf of clients (Article 68).
  • Under MiCA: strict segregation mandate — client crypto-assets must be held in custody separately from the CASP's own assets, and client agreement required specifying duties, responsibilities and ownership rights.

Key Restrictions

  • No dedicated 'crypto custody license' exists under current law; operators rely on AML registration as obliged entities.
  • No specific insurance/bonding mandates for crypto custody under current Slovak law.
  • No cold-storage mandate under current law — security measures expected but technology not prescribed.
  • 'Qualified custodian' status not explicitly defined for crypto under current Slovak law.
  • Under MiCA (from Dec 30, 2024): mandatory CASP authorization by NBS, strict client-asset segregation, and a written client agreement are required.
  • SaaS provider and white-label client may each have independent AML obligations as obliged entities under Act No. 297/2008 Coll. — the allocation of CDD/SAR responsibilities between them must be contractually clarified.

Key Risks

  • Regulatory ambiguity: current regime is AML-focused with no dedicated custody licensing framework, creating uncertainty on segregation and prudential standards.
  • Transition risk: MiCA will introduce mandatory CASP authorization, segregation mandates, and NBS supervision from Dec 30, 2024 — operators must prepare for a full licensing process.
  • Enforcement risk: NAKA (National Criminal Agency) has pursued major crypto-related fraud/money laundering cases with asset seizures up to €15M; NBS issues frequent warnings against unlicensed operators.
  • AML allocation risk: in a white-label SaaS model, both the platform provider and the client could be deemed 'obliged entities' — unclear which party performs CDD/SAR, creating dual-liability exposure.
  • No specific insurance mandate means client asset loss (e.g., from security breach) may not be covered, creating significant operational risk and potential consumer-harm exposure.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.

licensing 60% confidence

AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.

licensing 60% confidence

National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.

licensing 60% confidence

Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.

licensing 60% confidence

None specific to crypto custody: There are no national insurance or bonding mandates specifically for crypto custody providers under current Slovak law.

licensing 60% confidence

No specific mandate: Slovak law does not currently mandate the use of cold storage for crypto assets. Custodians are expected to implement robust security measures, but the specific technology is not prescribed.

licensing 60% confidence

Not explicitly defined for crypto: The concept of a "qualified custodian" as a specifically regulated entity for crypto assets does not exist under current Slovak law. Entities performing custody are primarily defined by their AML obligations.

licensing 60% confidence

Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).

licensing 60% confidence

Strict Segregation Mandate: MiCA explicitly requires CASPs providing custody services to:

licensing 60% confidence

"Enter into a client agreement to specify their duties and responsibilities, and to ensure that clients’ rights are clearly established, including those relating to the ownership of the crypto-assets." (Article 68(2)(b))

licensing 60% confidence

All other titles, including those related to CASPs and custody, will apply from December 30, 2024.

aml 60% confidence

Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.

aml 60% confidence

Custodian wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store, and transfer virtual assets.

aml 60% confidence

Identification of the Customer and Verification of Identity:

aml 60% confidence

Identification of the Ultimate Beneficial Owner (UBO):

aml 60% confidence

Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.

aml 60% confidence

Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.

enforcement 60% confidence

Entity Targeted: General public, but implicitly targets any unlicensed entities or scammers operating without proper authorization or misrepresenting their services. Violation Type: Operating without required licenses (e.g., for investment services or financial advisory), offering fraudulent investment opportunities, misrepresentation of crypto products, or not adhering to AML/CFT obligations (though the latter is harder for the NBS to enforce directly against unlicensed foreign entities). Penalty Amount: No direct monetary penalty specified for the warning itself. The "penalty" is more in the form of reputational damage for entities named (if any) and increased public awareness leading to fewer victims.

enforcement 60% confidence

Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers may operate in Slovakia currently as AML-registered obliged entities under Act No. 297/2008 Coll., but must prepare for mandatory MiCA CASP authorization by NBS (effective Dec 30, 2024) which will introduce strict asset segregation, client agreement, and prudential requirements.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?