Crypto ATM / kiosk operator in Holy See
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Holy See with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration/authorization with ASIF (Autorità di Supervisione e Informazione Finanziaria) before commencing operations (va.aml.licensingregistration-vasps-are-required-to)
- Customer Due Diligence (CDD): identify and verify identity of customers and beneficial owners using reliable, independent source documents (va.aml.identification-and-verification, va.aml.natural-persons-obtain-and-verify, va.aml.legal-entitiesarrangements-obtain-and-verify)
- Enhanced Due Diligence (EDD) for high-risk customers, PEPs, complex/unusual transactions, and high-risk jurisdictions (va.licensing.conduct-enhanced-due-diligence-edd, va.aml.politically-exposed-persons-peps-implement, va.aml.high-risk-jurisdictions-apply-edd-to)
- Travel Rule compliance: obtain, hold, and transmit originator and beneficiary information for VA transfers above threshold (typically EUR 1,000 equivalent) (va.aml.travel-rule-for-va-transfers)
- Suspicious Transaction Reporting (STR) to ASIF (acting as FIU) without delay (va.aml.vasps-are-obligated-to-report)
- Ongoing transaction monitoring to ensure transactions are consistent with customer knowledge and risk profile (va.licensing.monitor-transactions-identify-and-report, va.aml.ongoing-monitoring-conduct-ongoing-monitoring)
- Record-keeping: maintain records of transactions and customer data for a specified period (va.licensing.record-keeping-maintain-records-of)
- Internal AML/CFT policies, procedures, risk assessments, and staff training programs (va.licensing.internal-controls-establish-and-maintain)
- Sanctions compliance — adhere to international financial sanctions lists (va.licensing.sanctions-compliance-adhere-to-international)
- Evaluate risks of new technologies/products, especially those favoring anonymity — relevant for cash-to-crypto kiosks (va.aml.new-technologiesproducts-evaluate-the-risks)
- Non-face-to-face relationship measures: apply specific measures to compensate for higher risk (va.aml.non-face-to-face-relationships-apply-specific-and)
Key Restrictions
- Must be authorized or registered by ASIF before commencing any virtual asset service operations (va.aml.licensingregistration-vasps-are-required-to)
- Must submit documentation to ASIF detailing compliance with AML/CFT obligations including risk assessments, policies, and internal controls specific to virtual assets (va.licensing.demonstrating-compliance-providing-documentation-to)
- Entity is, by definition, locally present in Vatican City State if operating under its jurisdiction — the jurisdiction's financial system is tiny and primarily serves Church and charitable functions, not commercial crypto activity (va.licensing.local-presence-while-there-isnt, va.enforcement.low-cryptocurrency-activity-the-vatican)
- Capital requirements: general prudential requirements apply if regulated as a financial institution, but no specific capital requirements solely for crypto activities (va.licensing.capital-requirements-there-are-no)
- Subject to ongoing supervision by ASIF including regular reporting and audits (va.licensing.ongoing-supervision-remaining-subject-to)
Key Risks
- Extremely small and specialized jurisdiction — Vatican City is not a commercial crypto hub; regulatory framework exists primarily for preparedness, not active operator licensing, creating ambiguity about practical application to commercial ATM operators (va.enforcement.low-cryptocurrency-activity-the-vatican)
- No enforcement history for crypto activities — no precedent exists for how ASIF would handle a physical crypto kiosk operation (va.enforcement.regulatory-preparedness-not-enforcement-while)
- High-cash AML risk profile of crypto ATMs would trigger stringent EDD obligations and scrutiny under the anonymity-favoring products provisions (va.aml.new-technologiesproducts-evaluate-the-risks, va.aml.non-face-to-face-relationships-apply-specific-and)
- Travel Rule compliance for cash-in/cash-out transactions may create operational complexity for small-value kiosk transactions below the EUR 1,000 threshold
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges: Entities facilitating the exchange between virtual assets and fiat currencies, or between different forms of virtual assets, would be classified as VASPs.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the paramount requirement. VASPs are obligated to:
Conduct Customer Due Diligence (CDD): Identify and verify the identity of their customers (individuals and legal entities).
Conduct Enhanced Due Diligence (EDD): For high-risk customers, politically exposed persons (PEPs), or complex/unusual transactions.
Monitor Transactions: Identify and report suspicious transactions to the ASF.
Record Keeping: Maintain records of transactions and customer data for a specified period.
Internal Controls: Establish and maintain robust internal AML/CFT policies, procedures, risk assessments, and training programs for staff.
Sanctions Compliance: Adhere to international financial sanctions lists.
Local Presence: While there isn't a specific "local presence" requirement for external crypto businesses to set up shop (as this is not the Holy See's regulatory focus), any entity operating under its jurisdiction (e.g., Vatican banks or financial institutions) is, by definition, locally present. For foreign entities, the question of "local presence" is generally moot, as the Holy See is not seeking to attract such entities.
Capital Requirements: There are no specific capital requirements solely for cryptocurrency activities. However, regulated financial institutions within the Holy See are subject to general prudential requirements, including adequate capital, liquidity, and risk management frameworks as determined by the ASF. If a Vatican financial institution were to engage in VASP activities, it would need to ensure these activities are adequately capitalized and managed within its overall risk framework.
Demonstrating Compliance: Providing documentation to the ASF detailing how the institution will comply with all relevant AML/CFT obligations, including risk assessments, policies, procedures, and internal controls specific to virtual assets.
Ongoing Supervision: Remaining subject to ongoing supervision by the ASF, including regular reporting and audits.
Notification/Registration with ASF: Informing the ASF of the intent to engage in virtual asset activities.
Law No. CCXI (2018): On the prevention and countering of money laundering and terrorist financing.
Resolution No. 16/2022 on Virtual Assets:
Licensing/Registration: VASPs are required to be authorized or registered by ASIF before commencing operations.
Natural Persons: Obtain and verify the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., passport, national ID card).
Legal Entities/Arrangements: Obtain and verify the legal entity's name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions. Identify and verify the identity of beneficial owners (those holding 25% or more of the shares/voting rights, or exercising control through other means).
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutiny of transactions and the source of funds where necessary.
Politically Exposed Persons (PEPs): Implement additional measures for customers who are PEPs, their family members, or close associates.
High-Risk Jurisdictions: Apply EDD to business relationships and transactions involving countries identified by FATF or ASIF as high-risk.
Complex or Unusual Transactions: Scrutinize transactions that are unusually large, complex, or have no apparent economic or lawful purpose.
New Technologies/Products: Evaluate the risks associated with new technologies or products, particularly those that might favor anonymity.
Non-Face-to-Face Relationships: Apply specific and adequate measures to compensate for the higher risk of non-face-to-face relationships.
"Travel Rule" for VA Transfers: Decree No. CCCLVI implements the FATF "Travel Rule," requiring VASPs to obtain, hold, and transmit originator and beneficiary information for VA transfers above a certain threshold (typically equivalent to EUR 1,000, but may be subject to specific ASIF instructions).
VASPs are obligated to report suspicious transactions to ASIF (acting as the FIU) without delay if they know, suspect, or have reasonable grounds to suspect that funds (including virtual assets) are proceeds of crime or are linked to terrorist financing.
Low Cryptocurrency Activity: The Vatican City State is a unique, extremely small sovereign entity with a highly specialized financial system primarily focused on managing the assets of the Catholic Church and its charitable works, as well as supporting its diplomatic missions. It is not a center for commercial cryptocurrency activity or innovation.
Regulatory Preparedness (Not Enforcement): While there haven't been enforcement actions, ASIF has issued guidance and regulations acknowledging the risks associated with virtual assets (cryptocurrencies). This indicates preparedness rather than a history of specific enforcement cases.
Robust AML/CTF Framework: The Holy See has significantly strengthened its anti-money laundering (AML) and counter-terrorist financing (CTF) framework in recent years, under the supervision of its financial intelligence and supervisory authority, the Autorità di Supervisione e Informazione Finanziaria (ASIF). This includes complying with international standards set by the Financial Action Task Force (FATF) and undergoing evaluations by MONEYVAL (the Council of Europe's AML body).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto ATM/kiosk operator (classified as a VASP under Decree No. CCCLVI/2021 and Resolution No. 16/2022) may operate in Vatican City only after obtaining authorization/registration from ASIF and complying with a full suite of AML/CFT obligations, though the jurisdiction's tiny non-commercial financial system makes this a highly theoretical pathway with no enforcement precedent.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?