Remote VASP serving residents in Slovakia
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Slovakia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration as an obliged entity under Act No. 297/2008 Coll. (AML Act) for virtual currency exchange services, custodian wallet providers, and related virtual asset services (sk.licensing.registration-not-a-dedicated-license)
- Customer due diligence (CDD) including identification and verification of identity for natural persons (full name, date of birth, place of birth, permanent address, nationality, ID document) and legal entities (company name, registered address, registration number, directors) (sk.aml.identification-of-the-customer-and, sk.aml.natural-persons-full-name-date, sk.aml.legal-entities-company-name-registered)
- Identification and verification of Ultimate Beneficial Owner (UBO) — natural persons holding 25%+ shares/voting rights or otherwise controlling the customer (sk.aml.identification-of-the-ultimate-beneficial)
- Ongoing transaction monitoring and keeping customer information up-to-date (sk.aml.continuously-scrutinize-transactions-throughout-the)
- Enhanced due diligence for PEPs, high-risk jurisdictions, complex/unusually large transactions, new technologies (virtual assets), and non-face-to-face business relationships (sk.aml.politically-exposed-persons-peps-customers, sk.aml.high-risk-jurisdictions-customers-or-transactions, sk.aml.complex-or-unusually-large-transactions, sk.aml.new-or-developing-technologies-including, sk.aml.non-face-to-face-business-relationships-where-there)
- Source of Funds (SoF) and Source of Wealth (SoW) measures for high-risk relationships (sk.aml.source-of-funds-sof-and)
- Suspicious Activity Reporting (SAR) — obligation to report any transaction, attempted transaction, or activity involving suspected proceeds of crime or terrorist financing, submitted promptly once suspicion arises (sk.aml.obligation-to-report-any-transaction, sk.aml.timing-reports-must-be-submitted)
- Supervised by FIU within Ministry of Interior for AML purposes; NBS may supervise if activities deemed financial services (sk.licensing.competent-authorities-for-aml-purposes)
- From December 30, 2024: MiCA will require full CASP authorization by NBS with mandatory authorization under MiCA Title V for custody services (sk.licensing.all-other-titles-including-those, sk.licensing.mandatory-authorization-under-mica-title)
Key Restrictions
- Must register as an obliged entity under Act No. 297/2008 Coll. (AML Act) to lawfully serve Slovak residents — no 'remote VASP without local presence' exemption exists
- Local establishment is effectively required to meet AML registration and supervision obligations; cross-border service without registration exposes the operator to criminal liability
- No specific crypto custody license currently exists, but AML obligations apply regardless (sk.licensing.registration-not-a-dedicated-license)
- From December 30, 2024, MiCA will apply — any CASP serving Slovak residents must be authorized in an EU Member State, requiring a local entity in an EU jurisdiction (sk.licensing.mandatory-authorization-under-mica-title)
- No cold storage mandates, no insurance/bonding mandates, and no qualified custodian definitions specific to crypto under current law (sk.licensing.none-specific-to-crypto-custody, sk.licensing.no-specific-mandate-slovak-law, sk.licensing.not-explicitly-defined-for-crypto)
Key Risks
- Criminal enforcement risk: NAKA (National Criminal Agency) actively pursues unlicensed crypto operators, with asset seizures (up to €15 million in recent cases) and criminal charges for unauthorized business activities and money laundering (sk.enforcement.entity-targeted-an-organized-criminal, sk.enforcement.seizure-of-assets-during-the)
- NBS regularly issues public warnings against unlicensed entities offering crypto-related services, signaling active supervisory scrutiny (sk.enforcement.entity-targeted-general-public-but, sk.enforcement.date-nbs-has-issued-numerous)
- Broad interpretation of 'providers of other services related to virtual assets' under AML Act creates legal uncertainty for operators at the margins of the VASP definition (sk.aml.providers-of-other-services-related)
- MiCA transitional period creates ambiguity — current AML-only regime will shift to a full CASP authorization regime from December 30, 2024 (sk.licensing.all-other-titles-including-those)
- Enforcement actions often involve international cooperation (Europol, Eurojust), increasing cross-border enforcement risk for remote operators (sk.enforcement.europol-general-cooperation-for-cybercrime)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Registration, not a dedicated license: Currently, there isn't a specific "crypto custody license" in the traditional financial sense. However, entities providing services related to virtual assets, including custodian wallet providers, are considered "obliged entities" under Slovak AML law.
AML Obligations: This means they must comply with AML/CFT requirements, such as customer due diligence (CDD), transaction monitoring, suspicious activity reporting (SARs), and implementing internal risk management systems.
National Legislation: These obligations stem from Act No. 297/2008 Coll. on measures against the legalization of proceeds of crime and the financing of terrorism (Zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu). This Act has been amended multiple times to transpose the 4th, 5th, and 6th EU AML Directives.
Competent Authorities: For AML purposes, the Financial Intelligence Unit (FIU) within the Ministry of Interior is key, but the National Bank of Slovakia (Národná banka Slovenska - NBS) supervises financial institutions, which could include certain crypto-related activities if deemed financial services.
All other titles, including those related to CASPs and custody, will apply from December 30, 2024.
Mandatory Authorization: Under MiCA (Title V), any entity providing "custody and administration of crypto-assets on behalf of clients" (Article 68) will be considered a Crypto-Asset Service Provider (CASP) and will need to be authorized by the national competent authority. In Slovakia, this will most likely be the National Bank of Slovakia (NBS).
Act No. 297/2008 Coll. on Protection Against Legalisation of Proceeds of Crime and Against Financing of Terrorism (AML Act): This is the primary legislation in Slovakia governing AML/CFT. It has been amended multiple times, most notably by Act No. 397/2019 Coll., which transposed the 5AMLD and extended its scope to virtual assets and VASPs.
Virtual currency exchange services: Providers exchanging virtual currencies for fiat currencies, or vice versa, or between one or more forms of virtual assets.
Custodian wallet providers: Entities that provide services to safeguard private cryptographic keys on behalf of their customers, to hold, store, and transfer virtual assets.
Providers of other services related to virtual assets: This can be broadly interpreted to include other services like issuance, transfer, or administration of virtual assets.
Identification of the Customer and Verification of Identity:
Natural Persons: Full name, date of birth, place of birth, permanent address, nationality, type and number of identity document, and the issuing authority. Identity must be verified using reliable, independent sources (e.g., government-issued ID).
Legal Entities: Company name, registered address, registration number, identification of directors/management, and verification of their authority.
Identification of the Ultimate Beneficial Owner (UBO):
Continuously scrutinize transactions throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, or close associates.
High-risk jurisdictions: Customers or transactions involving countries identified as having strategic AML/CFT deficiencies by FATF or the European Commission.
Complex or unusually large transactions: Or transactions with an unusual pattern, without an apparent economic or lawful purpose.
New or developing technologies: Including virtual assets, where the risks may not be fully understood.
Non-face-to-face business relationships: Where there is no physical meeting with the customer.
Source of Funds (SoF) and Source of Wealth (SoW): VASPs must take reasonable measures to establish the source of funds and wealth involved in high-risk relationships or transactions.
Obligation to Report: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that funds are proceeds of criminal activity or are linked to terrorist financing.
Timing: Reports must be submitted promptly, usually immediately, once a suspicion arises.
Entity Targeted: An organized criminal group involving multiple individuals suspected of operating a sophisticated investment fraud scheme and subsequent money laundering using cryptocurrencies. Violation Type: Investment fraud, money laundering, unauthorized business activities, establishment, masterminding, and support of a criminal group. The scheme involved luring victims into fake crypto investment platforms.
Seizure of assets: During the operation, authorities seized financial assets, movable property, and real estate worth approximately €15 million. This includes accounts, cryptocurrencies, and other assets believed to be proceeds of crime.
Entity Targeted: General public, but implicitly targets any unlicensed entities or scammers operating without proper authorization or misrepresenting their services. Violation Type: Operating without required licenses (e.g., for investment services or financial advisory), offering fraudulent investment opportunities, misrepresentation of crypto products, or not adhering to AML/CFT obligations (though the latter is harder for the NBS to enforce directly against unlicensed foreign entities). Penalty Amount: No direct monetary penalty specified for the warning itself. The "penalty" is more in the form of reputational damage for entities named (if any) and increased public awareness leading to fewer victims.
Date: NBS has issued numerous warnings throughout the last 3 years, for example:
Europol (General cooperation for cybercrime, relevant to Slovak context): While not a specific Slovak action, Europol often assists NAKA in such international cases. https://www.europol.europa.eu/media-press/newsroom/news/romanian-criminal-gang-dismantled-involved-in-cryptocurrency-fraud-worth-eur-2-million (Example of a related Europol case in Romania from October 2023, illustrating the type of regional cooperation NAKA engages in).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Slovak residents must register as an obliged entity under the AML Act (Act No. 297/2008 Coll.), comply with full CDD/AML/CTF obligations supervised by the FIU, and from December 30, 2024 must obtain MiCA CASP authorization (via an EU-established entity); operating without registration carries criminal enforcement risk including asset seizures and prosecution by NAKA.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?