Crypto-funded debit card in Holy See
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Holy See with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD: Identify and verify identity of all customers (natural persons: passport/ID; legal entities: name, legal form, proof of existence, beneficial owners ≥25%) — Law No. CCXCVII & Decree CCCLVI.
- EDD: Enhanced due diligence for PEPs, high-risk jurisdictions (FATF/ASIF-listed), and complex/unusual transactions.
- Ongoing monitoring of business relationships and scrutiny of transactions to ensure consistency with customer risk profile.
- Source of funds/wealth inquiry required for higher-risk situations.
- Travel Rule: Obtain, hold, and transmit originator and beneficiary information for VA transfers ≥ EUR 1,000 threshold (per FATF Travel Rule implementation via Decree CCCLVI).
- Suspicious Transaction Reporting (STR): Report suspicious transactions to ASIF (acting as FIU) without delay.
- Record-keeping: Maintain transaction and customer data records for the period specified under Law CCXI/CCXCVII.
- Sanctions screening: Adhere to international financial sanctions lists.
- New technologies/products risk assessment: Evaluate risks of new products, especially those favoring anonymity.
- Non-face-to-face relationship measures: Apply specific controls to compensate for higher risk of remote onboarding.
- Internal AML/CFT controls: Establish policies, procedures, risk assessments, and staff training programs.
Key Restrictions
- VASP authorization/registration with ASIF is required before commencing any virtual asset activities (Decree CCCLVI).
- The operator must be a locally present regulated financial institution (or entity under ASIF jurisdiction); there is no framework for pure remote/foreign VASPs serving Vatican residents.
- Capital requirements are not specified solely for crypto, but regulated entities must meet general prudential requirements for adequate capital, liquidity, and risk management as determined by ASIF.
- No specific e-money or payment-institution license exists in Vatican law — the crypto-debit-card model would be regulated as a VASP activity (exchange + custody) under the ASIF framework.
- Crypto-to-fiat conversion at point of sale/ top-up constitutes 'exchange between VAs and fiat currencies' (a VASP activity under Decree CCCLVI).
- Safekeeping of user crypto prior to conversion constitutes 'safekeeping and/or administration of VAs' (also a VASP activity).
Key Risks
- Extremely small and specialized jurisdiction: Vatican City is not a crypto hub; there is virtually no market demand for a crypto-funded debit card targeting Vatican residents.
- No specific tax framework for crypto: Absence of income/capital gains tax legislation creates ambiguity for any tax obligations arising from the off-ramp/conversion event.
- No established enforcement history: While ASIF has a regulatory framework, there are no precedent enforcement actions to guide compliance expectations.
- Partner-bank/BIN-sponsor logistics: Vatican has no domestic banking infrastructure suitable for card program sponsorship; any BIN sponsorship would likely need to come from Italy or another EU member state, creating cross-jurisdictional complexity.
- MONEYVAL oversight: The Holy See is subject to MONEYVAL evaluations, and gaps in VASP supervision could trigger adverse findings or reputational risk.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges: Entities facilitating the exchange between virtual assets and fiat currencies, or between different forms of virtual assets, would be classified as VASPs.
Custody Providers: Entities providing safekeeping or administration of virtual assets or instruments enabling control over virtual assets would be classified as VASPs.
Payment Processors (dealing with VAs): Entities involved in the transfer of virtual assets or providing services related to the issuance/sale of virtual assets would also fall under the VASP definition.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the paramount requirement. VASPs are obligated to:
Conduct Customer Due Diligence (CDD): Identify and verify the identity of their customers (individuals and legal entities).
Conduct Enhanced Due Diligence (EDD): For high-risk customers, politically exposed persons (PEPs), or complex/unusual transactions.
Monitor Transactions: Identify and report suspicious transactions to the ASF.
Record Keeping: Maintain records of transactions and customer data for a specified period.
Internal Controls: Establish and maintain robust internal AML/CFT policies, procedures, risk assessments, and training programs for staff.
Sanctions Compliance: Adhere to international financial sanctions lists.
Local Presence: While there isn't a specific "local presence" requirement for external crypto businesses to set up shop (as this is not the Holy See's regulatory focus), any entity operating under its jurisdiction (e.g., Vatican banks or financial institutions) is, by definition, locally present. For foreign entities, the question of "local presence" is generally moot, as the Holy See is not seeking to attract such entities.
Capital Requirements: There are no specific capital requirements solely for cryptocurrency activities. However, regulated financial institutions within the Holy See are subject to general prudential requirements, including adequate capital, liquidity, and risk management frameworks as determined by the ASF. If a Vatican financial institution were to engage in VASP activities, it would need to ensure these activities are adequately capitalized and managed within its overall risk framework.
Notification/Registration with ASF: Informing the ASF of the intent to engage in virtual asset activities.
Demonstrating Compliance: Providing documentation to the ASF detailing how the institution will comply with all relevant AML/CFT obligations, including risk assessments, policies, procedures, and internal controls specific to virtual assets.
Ongoing Supervision: Remaining subject to ongoing supervision by the ASF, including regular reporting and audits.
Law No. CCXI (2018): On the prevention and countering of money laundering and terrorist financing.
Resolution No. 16/2022 on Virtual Assets:
Autorità di Supervisione e Informazione Finanziaria (ASF) / Supervisory and Financial Information Authority
Law No. CCXCVII (297) of 15 December 2018, concerning Measures for the Protection of the Financial System and Countering Money Laundering and the Financing of Terrorism: This is the foundational AML/CFT law that provides the general framework for financial institutions.
Decree No. CCCLVI (356) of 19 May 2021, issued by the Secretariat of State (amending Law No. CCXCVII and introducing specific provisions for Virtual Assets and Virtual Asset Service Providers): This crucial decree specifically brought virtual assets and VASPs under the Holy See's AML/CFT regulatory scope, implementing FATF Recommendation 15 and its Interpretive Note. It defines virtual assets and VASPs and subjects them to the same AML/CFT obligations as traditional financial institutions.
Defines "Virtual Assets" (VAs) as a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes.
Defines "Virtual Asset Service Provider" (VASP) as any natural or legal person who, as a business, conducts one or more of the following activities or operations for or on behalf of another natural or legal person:
Safekeeping and/or administration of VAs or instruments enabling control over VAs.
Subjects VASPs to the obligations specified in Law No. CCXCVII (2018) and subsequent regulations.
Licensing/Registration: VASPs are required to be authorized or registered by ASIF before commencing operations.
Natural Persons: Obtain and verify the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., passport, national ID card).
Legal Entities/Arrangements: Obtain and verify the legal entity's name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions. Identify and verify the identity of beneficial owners (those holding 25% or more of the shares/voting rights, or exercising control through other means).
Purpose and Nature of the Business Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutiny of transactions and the source of funds where necessary.
Source of Funds/Wealth: For higher-risk situations, VASPs must inquire about the source of funds and wealth of the customer.
Politically Exposed Persons (PEPs): Implement additional measures for customers who are PEPs, their family members, or close associates.
High-Risk Jurisdictions: Apply EDD to business relationships and transactions involving countries identified by FATF or ASIF as high-risk.
Complex or Unusual Transactions: Scrutinize transactions that are unusually large, complex, or have no apparent economic or lawful purpose.
New Technologies/Products: Evaluate the risks associated with new technologies or products, particularly those that might favor anonymity.
Non-Face-to-Face Relationships: Apply specific and adequate measures to compensate for the higher risk of non-face-to-face relationships.
"Travel Rule" for VA Transfers: Decree No. CCCLVI implements the FATF "Travel Rule," requiring VASPs to obtain, hold, and transmit originator and beneficiary information for VA transfers above a certain threshold (typically equivalent to EUR 1,000, but may be subject to specific ASIF instructions).
VASPs are obligated to report suspicious transactions to ASIF (acting as the FIU) without delay if they know, suspect, or have reasonable grounds to suspect that funds (including virtual assets) are proceeds of crime or are linked to terrorist financing.
No Known Specific Legislation: There is no known legislation or published tax rate in the Holy See that addresses capital gains specifically derived from cryptocurrency or virtual assets.
Low Cryptocurrency Activity: The Vatican City State is a unique, extremely small sovereign entity with a highly specialized financial system primarily focused on managing the assets of the Catholic Church and its charitable works, as well as supporting its diplomatic missions. It is not a center for commercial cryptocurrency activity or innovation.
Robust AML/CTF Framework: The Holy See has significantly strengthened its anti-money laundering (AML) and counter-terrorist financing (CTF) framework in recent years, under the supervision of its financial intelligence and supervisory authority, the Autorità di Supervisione e Informazione Finanziaria (ASIF). This includes complying with international standards set by the Financial Action Task Force (FATF) and undergoing evaluations by MONEYVAL (the Council of Europe's AML body).
Regulatory Preparedness (Not Enforcement): While there haven't been enforcement actions, ASIF has issued guidance and regulations acknowledging the risks associated with virtual assets (cryptocurrencies). This indicates preparedness rather than a history of specific enforcement cases.
Evidence fact va.enforcement.asif-circular-no-10 not found (may have been renamed).
MONEYVAL Reports: MONEYVAL evaluations of the Holy See often detail their progress in implementing FATF recommendations, including those related to virtual assets. These reports confirm the existence and scope of the Holy See's regulatory framework.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto-funded debit card program in the Holy See/Vatican City would be regulated as a VASP (covering both crypto-to-fiat exchange and safekeeping of virtual assets), requiring prior authorization from ASIF, a local regulated entity, comprehensive AML/CFT compliance under Law CCXCVII and Decree CCCLVI, and face major practical obstacles due to the absence of a domestic card/payment infrastructure and the jurisdiction's extremely small market.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?