Custodial wallet / SaaS in Holy See
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Holy See with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration/authorization with ASIF (Autorità di Supervisione e Informazione Finanziaria) required before commencing operations (va.aml.licensingregistration-vasps-are-required-to)
- Conduct Customer Due Diligence (CDD) — identify and verify identity of customers and beneficial owners using reliable, independent source documents (va.aml.identification-and-verification, va.aml.natural-persons-obtain-and-verify, va.aml.legal-entitiesarrangements-obtain-and-verify)
- Conduct Enhanced Due Diligence (EDD) for high-risk customers, PEPs, complex/unusual transactions, non-face-to-face relationships, and high-risk jurisdictions (va.aml.politically-exposed-persons-peps-implement, va.aml.high-risk-jurisdictions-apply-edd-to, va.aml.complex-or-unusual-transactions-scrutinize, va.aml.non-face-to-face-relationships-apply-specific-and)
- Ongoing monitoring of business relationships and transactions — scrutiny to ensure consistency with customer knowledge and risk profile (va.aml.ongoing-monitoring-conduct-ongoing-monitoring)
- Travel Rule compliance — obtain, hold, and transmit originator and beneficiary information for VA transfers above threshold (typically EUR 1,000 equivalent) (va.aml.travel-rule-for-va-transfers)
- Report suspicious transactions to ASIF (acting as FIU) without delay (va.aml.vasps-are-obligated-to-report)
- Record keeping — maintain transaction and customer data for a specified period (va.licensing.record-keeping-maintain-records-of)
- Sanctions compliance — adhere to international financial sanctions lists (va.licensing.sanctions-compliance-adhere-to-international)
- Establish and maintain internal AML/CFT policies, procedures, risk assessments, and staff training programs (va.licensing.internal-controls-establish-and-maintain)
- Evaluate risks of new technologies/products, particularly those favoring anonymity (va.aml.new-technologiesproducts-evaluate-the-risks)
- Determine source of funds/wealth for higher-risk situations (va.aml.source-of-fundswealth-for-higher-risk)
Key Restrictions
- Must be authorized/registered by ASIF as a VASP before commencing operations — this applies to the custodial wallet/SaaS operator directly (va.aml.licensingregistration-vasps-are-required-to)
- Local presence required — any entity operating under Holy See jurisdiction must be locally present (va.licensing.local-presence-while-there-isnt)
- Must demonstrate AML/CFT compliance documentation to ASIF including risk assessments, policies, procedures, and internal controls specific to virtual assets (va.licensing.demonstrating-compliance-providing-documentation-to)
- Subject to ongoing supervision by ASIF including regular reporting and audits (va.licensing.ongoing-supervision-remaining-subject-to)
- Safekeeping/administration of VAs or instruments enabling control over VAs is expressly captured as a VASP activity under Decree No. CCCLVI (356) of 2021 (va.aml.safekeeping-andor-administration-of-vas)
- No specific crypto capital requirements, but regulated entities subject to general prudential requirements including adequate capital, liquidity, and risk management (va.licensing.capital-requirements-there-are-no)
Key Risks
- Extremely limited market — Vatican City is not a center for cryptocurrency activity; business volume would likely be negligible (va.enforcement.low-cryptocurrency-activity-the-vatican)
- No enforcement precedent for virtual asset activities — regulatory preparedness exists but zero enforcement track record creates uncertainty (va.enforcement.regulatory-preparedness-not-enforcement-while)
- Ambiguity on how SaaS/custody-as-a-service model interacts with white-label clients' own AML obligations — unclear where obligations for end-user CDD sit between the SaaS operator and the client
- Regulatory framework derived from EU AML Directives and FATF standards may impose obligations disproportionate to the jurisdiction's actual market size
- The Holy See's financial system is specialized (Church assets, charitable works, diplomatic missions) — non-aligned commercial crypto activity may face political/PR headwinds
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custody Providers: Entities providing safekeeping or administration of virtual assets or instruments enabling control over virtual assets would be classified as VASPs.
Notification/Registration with ASF: Informing the ASF of the intent to engage in virtual asset activities.
Demonstrating Compliance: Providing documentation to the ASF detailing how the institution will comply with all relevant AML/CFT obligations, including risk assessments, policies, procedures, and internal controls specific to virtual assets.
Ongoing Supervision: Remaining subject to ongoing supervision by the ASF, including regular reporting and audits.
Local Presence: While there isn't a specific "local presence" requirement for external crypto businesses to set up shop (as this is not the Holy See's regulatory focus), any entity operating under its jurisdiction (e.g., Vatican banks or financial institutions) is, by definition, locally present. For foreign entities, the question of "local presence" is generally moot, as the Holy See is not seeking to attract such entities.
Capital Requirements: There are no specific capital requirements solely for cryptocurrency activities. However, regulated financial institutions within the Holy See are subject to general prudential requirements, including adequate capital, liquidity, and risk management frameworks as determined by the ASF. If a Vatican financial institution were to engage in VASP activities, it would need to ensure these activities are adequately capitalized and managed within its overall risk framework.
Conduct Customer Due Diligence (CDD): Identify and verify the identity of their customers (individuals and legal entities).
Conduct Enhanced Due Diligence (EDD): For high-risk customers, politically exposed persons (PEPs), or complex/unusual transactions.
Monitor Transactions: Identify and report suspicious transactions to the ASF.
Record Keeping: Maintain records of transactions and customer data for a specified period.
Internal Controls: Establish and maintain robust internal AML/CFT policies, procedures, risk assessments, and training programs for staff.
Sanctions Compliance: Adhere to international financial sanctions lists.
Licensing/Registration: VASPs are required to be authorized or registered by ASIF before commencing operations.
Safekeeping and/or administration of VAs or instruments enabling control over VAs.
Natural Persons: Obtain and verify the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., passport, national ID card).
Legal Entities/Arrangements: Obtain and verify the legal entity's name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions. Identify and verify the identity of beneficial owners (those holding 25% or more of the shares/voting rights, or exercising control through other means).
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutiny of transactions and the source of funds where necessary.
Politically Exposed Persons (PEPs): Implement additional measures for customers who are PEPs, their family members, or close associates.
High-Risk Jurisdictions: Apply EDD to business relationships and transactions involving countries identified by FATF or ASIF as high-risk.
Complex or Unusual Transactions: Scrutinize transactions that are unusually large, complex, or have no apparent economic or lawful purpose.
Non-Face-to-Face Relationships: Apply specific and adequate measures to compensate for the higher risk of non-face-to-face relationships.
New Technologies/Products: Evaluate the risks associated with new technologies or products, particularly those that might favor anonymity.
"Travel Rule" for VA Transfers: Decree No. CCCLVI implements the FATF "Travel Rule," requiring VASPs to obtain, hold, and transmit originator and beneficiary information for VA transfers above a certain threshold (typically equivalent to EUR 1,000, but may be subject to specific ASIF instructions).
Source of Funds/Wealth: For higher-risk situations, VASPs must inquire about the source of funds and wealth of the customer.
VASPs are obligated to report suspicious transactions to ASIF (acting as the FIU) without delay if they know, suspect, or have reasonable grounds to suspect that funds (including virtual assets) are proceeds of crime or are linked to terrorist financing.
Low Cryptocurrency Activity: The Vatican City State is a unique, extremely small sovereign entity with a highly specialized financial system primarily focused on managing the assets of the Catholic Church and its charitable works, as well as supporting its diplomatic missions. It is not a center for commercial cryptocurrency activity or innovation.
Regulatory Preparedness (Not Enforcement): While there haven't been enforcement actions, ASIF has issued guidance and regulations acknowledging the risks associated with virtual assets (cryptocurrencies). This indicates preparedness rather than a history of specific enforcement cases.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator is classified as a VASP under Decree No. CCCLVI (2021) and may operate only if locally incorporated, pre-registered/authorized with ASIF, and compliant with the full FATF-aligned AML/CFT framework (CDD, EDD, Travel Rule, suspicious reporting, ongoing supervision), though the market is practically negligible and enforcement history is non-existent.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?