Custodial wallet / SaaS in San Marino
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in San Marino with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Register as an ODLT (Operator in Distributed Ledger Technologies) / VASP with Banca Centrale della Repubblica di San Marino (BCRSM/BCSM) — Law 171/2019 and BCRA Circular 64/2020.
- Implement Customer Due Diligence (CDD) per Decree 120/2019 and AML Law No. 200/2023 — identify and verify natural persons (name, DOB, address, nationality, ID), and legal persons (legal name, form, address, proof of existence, authorized individuals).
- Identify and verify beneficial owners (natural persons holding >25% shares/voting rights or exercising control through other means).
- Conduct risk-based AML/CFT assessments (RBA) and apply proportionate CDD measures; apply Enhanced Due Diligence (EDD) for PEPs, cross-border correspondent relationships, complex/large/unusual transactions, high-risk jurisdictions, and anonymity-favoring technologies.
- Appoint an AML Officer and a Board-level AML Compliance Officer.
- Establish and operate a Suspicious Transaction Reporting (STR) mechanism, reporting to the Financial Intelligence Agency (AIF).
- Conduct ongoing monitoring of business relationships and transactions, and keep CDD records up-to-date.
- ODLTs are considered 'financial intermediaries' under Decree 120/2019, carrying full AML/CFT obligations including comprehensive internal controls, policies, and procedures.
Key Restrictions
- Must be incorporated in San Marino as a joint-stock company (S.p.A.) or limited liability company (S.r.l.) with registered office and effective management in San Marino.
- Minimum share capital: €300,000 for ODLTs providing services directly to the public and holding client funds/virtual assets (custodial wallet/SaaS). The BCRA may require higher capital based on complexity/risk.
- Capital must be fully paid up.
- Must obtain ODLT/VASP authorization from BCRA/BCSM — custodial wallet providers are explicitly listed as 'Custody Providers (Virtual Asset Custody Providers)' requiring authorization.
- BCSM Regulation No. 2023-01 specifically governs VASPs and applies to this operating model.
Key Risks
- As of the July 2022 MONEYVAL report, no licensed DLT service providers were recorded, indicating the licensing path may still be nascent, untested, or slow.
- Regulatory framework has been evolving rapidly (new laws in 2019, 2020, 2023 and circulars in 2020, 2021, 2023), creating potential for shifting requirements or interpretation gaps.
- Small jurisdiction: limited enforcement precedent and potentially limited regulatory capacity for complex custodial/SaaS models.
- The white-label SaaS structure creates ambiguity as to whether the licensor (ODLT/VASP) or the white-label client bears primary AML obligations — both may be captured as VASPs depending on fact pattern.
- No proof-of-reserves, segregation, or insurance rules explicitly identified in supplied facts — these would need to be confirmed or negotiated with the regulator.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 171 of December 17, 2019, "Regulations for Distributed Ledger Technologies and Blockchain for Business" (Legge 171/2019): This law defines DLT, virtual assets, and establishes the framework for Operators in Distributed Ledger Technologies (ODLTs).
BCRA Circular No. 64 of 15 September 2020, "Disciplining the activities of Operators in Distributed Ledger Technologies": This circular provides detailed implementation rules for Law 171/2019, specifying the requirements for obtaining authorization (registration) as an ODLT.
BCRA Circular No. 67 of 11 May 2021, "Amendments and additions to Circular No. 64 of 15 September 2020": This circular introduced updates and clarifications to the initial implementing regulations.
Decree No. 120 of 21 August 2019, "Provisions against money laundering and terrorist financing": This AML/CFT law is applicable to ODLTs and virtual asset service providers (VASPs).
Custody Providers (Virtual Asset Custody Providers): Entities that provide services for the safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of natural or legal persons. This also requires ODLT/VASP authorization.
Legal Form & Establishment:
Must be a joint-stock company (Società per Azioni - S.p.A.) or a limited liability company (Società a responsabilità limitata - S.r.l.) established in San Marino.
Must have its registered office and effective management in San Marino.
Minimum Share Capital:
€300,000 for ODLTs providing services directly to the public (including VASPs like exchanges and custody providers) and holding client funds or virtual assets.
The BCRA may require a higher capital amount based on the complexity, scale, and risk profile of the proposed activities.
Capital must be fully paid up.
ODLTs are considered "financial intermediaries" under San Marino's AML/CFT legislation (Decree 120/2019) and are subject to all related obligations.
Implementing robust Customer Due Diligence (CDD) procedures for all clients (identifying and verifying identity, beneficial ownership).
Conducting risk assessments for business relationships and transactions.
Implementing comprehensive internal controls, policies, and procedures for AML/CFT.
Appointing an AML Officer and a Board-level AML Compliance Officer.
Establishing a Suspicious Transaction Reporting (STR) mechanism and reporting to the Financial Intelligence Agency (AIF).
Banca Centrale della Repubblica di San Marino (BCRSM) - The Central Bank of the Republic of San Marino. It is the primary financial regulator responsible for licensing, supervision, and ongoing oversight of virtual asset service providers.
Regolamento della Banca Centrale della Repubblica di San Marino n. 2023-01 – "Regolamento in materia di prestatori di servizi relativi ad attività virtuali (VASP)."
Natural Persons: Obtain and verify identity using reliable, independent source documents, data, or information (e.g., name, date of birth, place of birth, address, nationality, official identification number/document type).
Legal Persons/Arrangements: Obtain and verify legal name, legal form, address, proof of existence, powers that regulate and bind the legal person/arrangement, and names of individuals authorized to act on its behalf.
Identify the beneficial owner(s) (natural person(s) who ultimately own or control the customer and/or the natural person on whose behalf a transaction is being conducted).
Verify the identity of the beneficial owner(s) using relevant information and data.
For legal persons, this typically involves identifying natural persons holding more than 25% of shares or voting rights, or exercising control through other means.
Purpose and Intended Nature of Business Relationship: Obtain information on the purpose and intended nature of the business relationship or occasional transaction.
Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of that relationship.
Ensure that the documents, data, or information collected under the CDD process are kept up-to-date.
Risk-Based Approach (RBA): VASPs must implement a risk-based approach to AML/CFT, meaning they should:
Assess their ML/TF risks, considering factors such as customer type, services offered, virtual asset types, geographic areas, and delivery channels.
Apply CDD measures proportionate to the identified risks.
Enhanced Due Diligence (EDD): Apply EDD in higher-risk situations, including but not limited to:
Relationships with Politically Exposed Persons (PEPs).
Complex, unusual, large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
Transactions involving high-risk jurisdictions.
Use of new technologies or products that favor anonymity.
No Licensed DLT Service Providers (as of last major assessment): A key finding from the MONEYVAL (Council of Europe anti-money laundering body) "Fifth Round Mutual Evaluation Report on San Marino" published in July 2022 stated:
MONEYVAL Report (July 2022):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are authorized as ODLT/VASP custody providers in San Marino, requiring a locally incorporated S.p.A. or S.r.l. with €300,000 minimum capital, full AML/CFT registration and compliance under BCSM oversight, though the licensing path appears nascent (no licensed DLT providers as of 2022 MONEYVAL) and specific proof-of-reserves/insurance/segregation rules are not detailed in the supplied facts.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?