Centralized exchange in Holy See
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Holy See with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration/authorization with ASIF (Autorità di Supervisione e Informazione Finanziaria) before commencing operations (va.aml.licensingregistration-vasps-are-required-to)
- Customer Due Diligence (CDD): identify and verify identity of customers and beneficial owners using reliable source documents (va.licensing.conduct-customer-due-diligence-cdd, va.aml.identification-and-verification)
- Enhanced Due Diligence (EDD) for high-risk customers, PEPs, complex/unusual transactions (va.licensing.conduct-enhanced-due-diligence-edd, va.aml.politically-exposed-persons-peps-implement)
- Ongoing transaction monitoring to detect suspicious activity (va.licensing.monitor-transactions-identify-and-report, va.aml.ongoing-monitoring-conduct-ongoing-monitoring)
- Travel Rule: collect, store, and transmit originator and beneficiary information for VA transfers above EUR 1,000 equivalent threshold (va.aml.travel-rule-for-va-transfers, va.travel-rule.collect-the-required-originator-and, va.travel-rule.transmit-this-information-securely-and)
- Suspicious Transaction Reporting (STR) to ASIF without delay (va.aml.vasps-are-obligated-to-report)
- Record keeping of transactions and customer data for a specified period (va.licensing.record-keeping-maintain-records-of)
- Sanctions screening against international financial sanctions lists (va.licensing.sanctions-compliance-adhere-to-international)
- Internal AML/CFT policies, procedures, risk assessments, and staff training programs (va.licensing.internal-controls-establish-and-maintain)
- Source of funds/wealth inquiry for higher-risk situations (va.aml.source-of-fundswealth-for-higher-risk)
- Risk evaluation for new technologies/products that may favor anonymity (va.aml.new-technologiesproducts-evaluate-the-risks)
Key Restrictions
- Local entity required — any entity operating under the Holy See's jurisdiction must be locally present (e.g., Vatican banks or financial institutions incorporated in the Holy See) (va.licensing.local-presence-while-there-isnt)
- Must notify/register with ASIF of intent to engage in virtual asset activities and provide documentation demonstrating AML/CFT compliance (va.licensing.notificationregistration-with-asf-informing-the, va.licensing.demonstrating-compliance-providing-documentation-to)
- Must comply with ASIF's ongoing supervision, regular reporting, and audits (va.licensing.ongoing-supervision-remaining-subject-to)
- Subject to general prudential capital, liquidity, and risk management requirements as determined by ASIF for regulated financial institutions (va.licensing.capital-requirements-there-are-no)
- Must adhere to governance and risk management standards including cybersecurity, market volatility, and technological risk controls (va.licensing.governance-and-risk-management-regulated)
Key Risks
- Extremely small market — the Holy See is not a center for cryptocurrency activity, so operational viability is questionable (va.enforcement.low-cryptocurrency-activity-the-vatican)
- Very limited enforcement history — no specific enforcement actions against VASPs have occurred; regulatory preparedness exists but practical interpretation of rules is untested (va.enforcement.regulatory-preparedness-not-enforcement-while)
- Unique sovereign/jurisdictional context — the Holy See's financial system is specialized for Church assets and diplomatic missions, not commercial crypto services
- Regulatory framework is derived from FATF and EU standards but applied in a tiny jurisdiction, creating ambiguity about how rules apply in practice
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges: Entities facilitating the exchange between virtual assets and fiat currencies, or between different forms of virtual assets, would be classified as VASPs.
Custody Providers: Entities providing safekeeping or administration of virtual assets or instruments enabling control over virtual assets would be classified as VASPs.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the paramount requirement. VASPs are obligated to:
Conduct Customer Due Diligence (CDD): Identify and verify the identity of their customers (individuals and legal entities).
Conduct Enhanced Due Diligence (EDD): For high-risk customers, politically exposed persons (PEPs), or complex/unusual transactions.
Monitor Transactions: Identify and report suspicious transactions to the ASF.
Record Keeping: Maintain records of transactions and customer data for a specified period.
Internal Controls: Establish and maintain robust internal AML/CFT policies, procedures, risk assessments, and training programs for staff.
Sanctions Compliance: Adhere to international financial sanctions lists.
Local Presence: While there isn't a specific "local presence" requirement for external crypto businesses to set up shop (as this is not the Holy See's regulatory focus), any entity operating under its jurisdiction (e.g., Vatican banks or financial institutions) is, by definition, locally present. For foreign entities, the question of "local presence" is generally moot, as the Holy See is not seeking to attract such entities.
Capital Requirements: There are no specific capital requirements solely for cryptocurrency activities. However, regulated financial institutions within the Holy See are subject to general prudential requirements, including adequate capital, liquidity, and risk management frameworks as determined by the ASF. If a Vatican financial institution were to engage in VASP activities, it would need to ensure these activities are adequately capitalized and managed within its overall risk framework.
Governance and Risk Management: Regulated entities are expected to have sound governance structures and effective risk management systems in place to manage the specific risks associated with virtual assets (e.g., cyber security, market volatility, technological risks).
Notification/Registration with ASF: Informing the ASF of the intent to engage in virtual asset activities.
Demonstrating Compliance: Providing documentation to the ASF detailing how the institution will comply with all relevant AML/CFT obligations, including risk assessments, policies, procedures, and internal controls specific to virtual assets.
Ongoing Supervision: Remaining subject to ongoing supervision by the ASF, including regular reporting and audits.
Law No. CCXI (2018): On the prevention and countering of money laundering and terrorist financing.
Resolution No. 16/2022 on Virtual Assets:
Autorità di Supervisione e Informazione Finanziaria (ASF) / Supervisory and Financial Information Authority
Law No. CCXCVII (297) of 15 December 2018, concerning Measures for the Protection of the Financial System and Countering Money Laundering and the Financing of Terrorism: This is the foundational AML/CFT law that provides the general framework for financial institutions.
Decree No. CCCLVI (356) of 19 May 2021, issued by the Secretariat of State (amending Law No. CCXCVII and introducing specific provisions for Virtual Assets and Virtual Asset Service Providers): This crucial decree specifically brought virtual assets and VASPs under the Holy See's AML/CFT regulatory scope, implementing FATF Recommendation 15 and its Interpretive Note. It defines virtual assets and VASPs and subjects them to the same AML/CFT obligations as traditional financial institutions.
Licensing/Registration: VASPs are required to be authorized or registered by ASIF before commencing operations.
Natural Persons: Obtain and verify the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., passport, national ID card).
Legal Entities/Arrangements: Obtain and verify the legal entity's name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions. Identify and verify the identity of beneficial owners (those holding 25% or more of the shares/voting rights, or exercising control through other means).
Purpose and Nature of the Business Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutiny of transactions and the source of funds where necessary.
Source of Funds/Wealth: For higher-risk situations, VASPs must inquire about the source of funds and wealth of the customer.
Politically Exposed Persons (PEPs): Implement additional measures for customers who are PEPs, their family members, or close associates.
High-Risk Jurisdictions: Apply EDD to business relationships and transactions involving countries identified by FATF or ASIF as high-risk.
Complex or Unusual Transactions: Scrutinize transactions that are unusually large, complex, or have no apparent economic or lawful purpose.
New Technologies/Products: Evaluate the risks associated with new technologies or products, particularly those that might favor anonymity.
Non-Face-to-Face Relationships: Apply specific and adequate measures to compensate for the higher risk of non-face-to-face relationships.
"Travel Rule" for VA Transfers: Decree No. CCCLVI implements the FATF "Travel Rule," requiring VASPs to obtain, hold, and transmit originator and beneficiary information for VA transfers above a certain threshold (typically equivalent to EUR 1,000, but may be subject to specific ASIF instructions).
VASPs are obligated to report suspicious transactions to ASIF (acting as the FIU) without delay if they know, suspect, or have reasonable grounds to suspect that funds (including virtual assets) are proceeds of crime or are linked to terrorist financing.
Law No. CCCLI (351) of 1 October 2020: This law made significant amendments to the Holy See's AML/CFT framework, introducing definitions for virtual assets and virtual asset service providers and extending AML/CFT obligations to them. This law brought the Holy See's legislation in line with FATF standards for virtual assets.
Instruction No. 1 of the Financial Intelligence and Supervisory Authority (ASIF) of 19 March 2021 (Regulating VASPs): This instruction further details the obligations of VASPs operating in or from the Holy See, covering licensing, registration, customer due diligence, reporting, and information transfer requirements consistent with the Travel Rule.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Collect the required originator and beneficiary information accurately.
Store this information securely.
Transmit this information securely and reliably to the beneficiary VASP (or make it available upon request).
Screen for sanctions and suspicious activity.
Administrative Sanctions: Fines imposed by ASIF, revocation or suspension of licenses, and other supervisory measures.
Criminal Penalties: Imprisonment and significant monetary fines for serious violations, particularly those related to money laundering, terrorist financing, or other financial crimes. These are outlined in the Holy See's Criminal Code and specific AML/CFT laws.
Low Cryptocurrency Activity: The Vatican City State is a unique, extremely small sovereign entity with a highly specialized financial system primarily focused on managing the assets of the Catholic Church and its charitable works, as well as supporting its diplomatic missions. It is not a center for commercial cryptocurrency activity or innovation.
Robust AML/CTF Framework: The Holy See has significantly strengthened its anti-money laundering (AML) and counter-terrorist financing (CTF) framework in recent years, under the supervision of its financial intelligence and supervisory authority, the Autorità di Supervisione e Informazione Finanziaria (ASIF). This includes complying with international standards set by the Financial Action Task Force (FATF) and undergoing evaluations by MONEYVAL (the Council of Europe's AML body).
Regulatory Preparedness (Not Enforcement): While there haven't been enforcement actions, ASIF has issued guidance and regulations acknowledging the risks associated with virtual assets (cryptocurrencies). This indicates preparedness rather than a history of specific enforcement cases.
Regulator Name: Autorità di Supervisione e Informazione Finanziaria (ASIF)
Relevant Action: Issuance of regulatory frameworks for virtual assets.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange (custodial order-book exchange) is classified as a VASP under Holy See law (Decree No. CCCLVI/2021, Resolution 16/2022) and may operate only as a locally-incorporated entity registered with ASIF, subject to comprehensive AML/CFT obligations including the Travel Rule, but in practice this is a nearly theoretical path given the Holy See's extremely small market and lack of enforcement precedent.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?