Custodial wallet / SaaS in Ukraine
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Ukraine with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including custodial wallet providers) are designated as 'reporting entities' (subjects of primary financial monitoring) under the AML/CFT Law No. 361-IX.
- Mandatory customer identification and verification (KYC) for individuals: full name, date of birth, place of birth, address, identification number, and identity document details based on reliable, independent sources.
- Mandatory customer identification and verification for legal entities: name, registration number, legal form, legal address, contact details, and management structure.
- Beneficial Ownership (UBO) identification: must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer.
- Purpose and intended nature of the business relationship must be understood and documented.
- Ongoing transaction monitoring required to ensure consistency with customer knowledge, business, and risk profile, including monitoring source of funds and destination of virtual assets.
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and transactions above thresholds (e.g., equivalent of UAH 400,000 for certain operations).
- Suspicious transaction reporting obligation — suspicion triggers reporting regardless of amount.
- Simplified Due Diligence (SDD) is limited in scope given the inherent risks of virtual assets.
- State Financial Monitoring Service (SFMS) is the AML/CFT supervisor and financial intelligence unit.
Key Restrictions
- Must be a legal entity incorporated in Ukraine to obtain a VASP permit.
- The full licensing mechanism is not yet operational — secondary legislation (resolutions, procedures, detailed requirements) from NSSMC/NBU/MinDigital has not been fully adopted as of late 2023/early 2024 due to wartime priorities.
- Custodial wallet providers require a VASP permit covering 'safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets'.
- Separate accounting required: VASPs must maintain separate accounting records for their own virtual assets and those of clients (Article 12, Part 2, Point 2 of the VA Law).
- Indicative capital requirement for custody activities: approximately UAH 5 million (~$125k-$150k) — pending finalization in secondary legislation.
- Insurance/bonding requirements are not yet explicit in the Law but are highly probable in future secondary legislation.
- No explicit cold storage mandate yet in the Law, but reliable and safe storage is required.
Key Risks
- Regulatory limbo: The VASP licensing regime is legally enacted but not practically operational — secondary legislation is pending, meaning a custodial wallet provider cannot currently obtain a full license.
- Wartime disruption: Government focus on wartime priorities means licensing implementation could remain stalled for an extended period.
- Ambiguity on segregation: The Law requires separate accounting but does not explicitly require separate on-chain wallet segregation — secondary legislation may clarify this.
- Uncertain capital requirements: Indicative figures (UAH 5M for custody) come from drafts and may change when final regulations are published.
- Insurance/proof-of-reserves rules are absent from primary law but may appear in secondary legislation — operators face uncertainty on future compliance costs.
- Enforcement risk: SFMS and NSSMC may take enforcement action against unlicensed VASPs operating without a permit, even if the permit process is not fully operational.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Mandate: The Law "On Virtual Assets" mandates that any entity providing virtual asset services, including custody services, must obtain a permit (дозвіл). This permit functions similarly to a license.
Definition of VASP: Article 1 of the Law defines a "Virtual Asset Service Provider" (VASP) as a legal entity that, as part of its business activities, performs one or more of the following services for or on behalf of another natural or legal person:
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets. (This directly covers custody).
Issuing Authority: The NSSMC is generally responsible for issuing these permits. For virtual assets secured by monetary values, the NBU would be the responsible authority.
Specific Conditions: While the Law mandates permits, the specific conditions and procedures for obtaining these permits (e.g., capital requirements, personnel qualifications, technical requirements) are to be established by normative legal acts of the NSSMC and NBU. These specific acts are still largely in development or pending full implementation.
Separate Accounting: Article 12, Part 2, Point 2 requires VASPs to maintain separate accounting records for their own virtual assets and those of their clients. This is a foundational step towards ensuring client assets are not commingled with the VASP's proprietary assets.
The Law "On Virtual Assets" (Article 16, Part 2, Point 2) requires VASPs to ensure the reliable and safe storage of virtual assets and/or instruments enabling control over them. While the law doesn't explicitly use the term "segregation" in the same way traditional finance does for client funds (e.g., separate bank accounts), the underlying principle of protecting client assets is implied through:
The Law "On Virtual Assets" (Article 16, Part 2, Point 2) requires VASPs to ensure the reliable and safe storage of virtual assets and/or instruments enabling control over them. While the law doesn't explicitly use the term "segregation" in the same way traditional finance does for client funds (e.g., separate bank accounts), the underlying principle of protecting client assets is implied through:
However, it is a common regulatory practice in other jurisdictions for financial service providers, especially custodians, to have sufficient capital, insurance, or bonding to cover potential losses due to cyber-attacks, operational failures, or fraud.
AML/CFT Compliance: Obtaining a permit is intrinsically linked to strict adherence to the AML/CFT Law, including KYC procedures, transaction monitoring, and reporting suspicious activities.
While the VA Law is in force, its full implementation, particularly the practical licensing mechanism, depends on the adoption of secondary legislation (resolutions, procedures, and detailed requirements) by the NBU and MinDigital.
As of late 2023/early 2024, this secondary legislation has not yet been fully adopted, meaning the actual process for obtaining a license is largely suspended or not fully operational. The focus of the government has been on wartime priorities.
Custody Providers: Will require a VASP license covering "custody and/or administration services."
Currently, the exact, officially finalized capital requirements are pending the adoption of secondary legislation.
For other VASP activities (e.g., custody, transfer): Potentially around UAH 5 million (approx. $125,000 - $150,000).
These are indicative figures from drafts and should be verified once official regulations are published.
This is a cornerstone of the VA Law and is largely aligned with international standards (FATF recommendations).
VASPs will be subject to the Law of Ukraine "On Preventing and Countering Legalization (Laundering) of Criminal Proceeds, Terrorist Financing and Financing the Proliferation of Weapons of Mass Destruction."
Law of Ukraine No. 361-IX "On Preventing and Counteracting Legalization (Laundering) of Criminal Proceeds, Terrorist Financing and Financing the Proliferation of Weapons of Mass Destruction" (dated December 6, 2019, with subsequent amendments).
This is the foundational AML/CFT law in Ukraine, bringing the country's framework closer to FATF recommendations and the EU's 4th and 5th AML Directives. It designates "virtual asset service providers" as "reporting entities" (subjects of primary financial monitoring).
Identification and Verification:
For Individuals: Obtain and verify the customer's identity, including full name, date of birth, place of birth, address, identification number (where applicable), and details of the identity document (series, number, date of issue, issuing authority). Verification must be based on reliable, independent source documents, data, or information.
For Legal Entities: Obtain and verify the legal entity's name, registration number, legal form, legal address, contact details, and identify the management structure.
Beneficial Owner (UBO) Identification: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer. This is crucial for both individuals (e.g., if acting on behalf of another) and legal entities.
Understanding the Business Relationship:
Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of that relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring the source of funds and the destination of virtual assets.
Enhanced Due Diligence (EDD):
Transactions above specific thresholds (e.g., equivalent of UAH 400,000 for certain types of operations, though suspicion requires reporting even below this).
Simplified Due Diligence (SDD):
State Financial Monitoring Service of Ukraine (SFMS - Держфінмоніторинг): Responsible for AML/CFT oversight and financial intelligence.
National Securities and Stock Market Commission (NSSMC - НКЦПФР): The primary regulator for virtual assets, especially those secured by currency, valuables, or property rights, and for most VASP activities.
National Bank of Ukraine (NBU - НБУ): Regulates virtual assets secured by monetary values.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are legally required to obtain a VASP permit (license) in Ukraine, but the licensing regime is not yet fully operational due to pending secondary legislation, leaving operators in regulatory uncertainty with AML obligations already in force.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?