DeFi protocol frontend in San Marino
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in San Marino with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Implementing robust Customer Due Diligence (CDD) procedures for all clients (identifying and verifying identity, beneficial ownership) under Decree 120/2019 and BCSM Regulation 2023-01
- Conducting risk assessments for business relationships and transactions under a risk-based approach (RBA)
- Implementing comprehensive internal controls, policies, and procedures for AML/CFT
- Appointing an AML Officer and a Board-level AML Compliance Officer
- Establishing a Suspicious Transaction Reporting (STR) mechanism and reporting to the Financial Intelligence Agency (AIF)
- Applying Enhanced Due Diligence (EDD) for higher-risk situations including PEPs, cross-border correspondent relationships, complex/unusual/large transactions, high-risk jurisdictions, and new technologies that favor anonymity
- Conduct ongoing monitoring of business relationships and transactions, keeping CDD data up to date
- Identifying beneficial owners (natural persons holding >25% shares/voting rights for legal persons)
Key Restrictions
- Must be established as a joint-stock company (S.p.A.) or limited liability company (S.r.l.) in San Marino with registered office and effective management in San Marino
- Minimum share capital of €300,000 if providing services directly to the public and/or holding client funds/virtual assets; BCRA may require higher capital based on risk profile
- Capital must be fully paid up
- Fee-taking (e.g., swap fees, frontend fees) likely constitutes providing financial services related to virtual assets, triggering full ODLT/VASP authorization
- ODLTs are considered 'financial intermediaries' under San Marino AML/CFT law (Decree 120/2019)
- Geofencing alone is insufficient — full KYC/CDD obligations apply to any entity classified as an ODLT/VASP
Key Risks
- Regulatory ambiguity: unclear whether a frontend that solely interfaces with permissionless smart contracts without custody or order-matching falls under the ODLT/VASP definition, creating potential classification risk
- No licensed DLT service providers as of MONEYVAL's July 2022 assessment — regulatory process is still developing with limited precedent
- Small jurisdiction with discretionary enforcement; the BCRA/BCSM may take an expansive view of what constitutes 'providing other services related to virtual assets'
- Frontend operators taking fees (swap fees, referral fees) face higher risk of being classified as financial intermediaries subject to full regulation
- MONEYVAL scrutiny on San Marino's AML/CFT framework may drive aggressive enforcement against unlicensed VASPs including frontend operators
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 171 of December 17, 2019, "Regulations for Distributed Ledger Technologies and Blockchain for Business" (Legge 171/2019): This law defines DLT, virtual assets, and establishes the framework for Operators in Distributed Ledger Technologies (ODLTs).
BCRA Circular No. 64 of 15 September 2020, "Disciplining the activities of Operators in Distributed Ledger Technologies": This circular provides detailed implementation rules for Law 171/2019, specifying the requirements for obtaining authorization (registration) as an ODLT.
BCRA Circular No. 67 of 11 May 2021, "Amendments and additions to Circular No. 64 of 15 September 2020": This circular introduced updates and clarifications to the initial implementing regulations.
Decree No. 120 of 21 August 2019, "Provisions against money laundering and terrorist financing": This AML/CFT law is applicable to ODLTs and virtual asset service providers (VASPs).
Providing other services related to virtual assets.
Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.
Transferring virtual assets.
Must be a joint-stock company (Società per Azioni - S.p.A.) or a limited liability company (Società a responsabilità limitata - S.r.l.) established in San Marino.
Must have its registered office and effective management in San Marino.
€300,000 for ODLTs providing services directly to the public (including VASPs like exchanges and custody providers) and holding client funds or virtual assets.
Minimum Share Capital:
Capital must be fully paid up.
ODLTs are considered "financial intermediaries" under San Marino's AML/CFT legislation (Decree 120/2019) and are subject to all related obligations.
Implementing robust Customer Due Diligence (CDD) procedures for all clients (identifying and verifying identity, beneficial ownership).
Conducting risk assessments for business relationships and transactions.
Implementing comprehensive internal controls, policies, and procedures for AML/CFT.
Appointing an AML Officer and a Board-level AML Compliance Officer.
Establishing a Suspicious Transaction Reporting (STR) mechanism and reporting to the Financial Intelligence Agency (AIF).
Regolamento della Banca Centrale della Repubblica di San Marino n. 2023-01 – "Regolamento in materia di prestatori di servizi relativi ad attività virtuali (VASP)."
Risk-Based Approach (RBA): VASPs must implement a risk-based approach to AML/CFT, meaning they should:
Enhanced Due Diligence (EDD): Apply EDD in higher-risk situations, including but not limited to:
Identify the beneficial owner(s) (natural person(s) who ultimately own or control the customer and/or the natural person on whose behalf a transaction is being conducted).
No Licensed DLT Service Providers (as of last major assessment): A key finding from the MONEYVAL (Council of Europe anti-money laundering body) "Fifth Round Mutual Evaluation Report on San Marino" published in July 2022 stated:
MONEYVAL Report (July 2022):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving San Marino residents would likely be classified as an ODLT/VASP requiring full authorization as a San Marino-incorporated S.p.A. or S.r.l. with minimum €300,000 capital, comprehensive AML/CDD obligations, and BCRA/BCSM supervision, but regulatory classification of non-custodial frontends remains somewhat ambiguous with no licensed precedent as of 2022.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?