← Regulations / Holy See / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Holy See

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Holy See with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Registration/authorization with ASIF (Autorità di Supervisione e Informazione Finanziaria) required before commencing operations (va.aml.licensingregistration-vasps-are-required-to)
  • Conduct Customer Due Diligence (CDD) — identify and verify identity of customers and beneficial owners using reliable, independent source documents (va.aml.identification-and-verification, va.aml.natural-persons-obtain-and-verify, va.aml.legal-entitiesarrangements-obtain-and-verify)
  • Conduct Enhanced Due Diligence (EDD) for high-risk customers, PEPs, complex/unusual transactions, non-face-to-face relationships, and high-risk jurisdictions (va.aml.politically-exposed-persons-peps-implement, va.aml.high-risk-jurisdictions-apply-edd-to, va.aml.complex-or-unusual-transactions-scrutinize, va.aml.non-face-to-face-relationships-apply-specific-and)
  • Ongoing monitoring of business relationships and transactions — scrutiny to ensure consistency with customer knowledge and risk profile (va.aml.ongoing-monitoring-conduct-ongoing-monitoring)
  • Travel Rule compliance — obtain, hold, and transmit originator and beneficiary information for VA transfers above threshold (typically EUR 1,000 equivalent) (va.aml.travel-rule-for-va-transfers)
  • Report suspicious transactions to ASIF (acting as FIU) without delay (va.aml.vasps-are-obligated-to-report)
  • Record keeping — maintain transaction and customer data for a specified period (va.licensing.record-keeping-maintain-records-of)
  • Sanctions compliance — adhere to international financial sanctions lists (va.licensing.sanctions-compliance-adhere-to-international)
  • Establish and maintain internal AML/CFT policies, procedures, risk assessments, and staff training programs (va.licensing.internal-controls-establish-and-maintain)
  • Evaluate risks of new technologies/products, particularly those favoring anonymity (va.aml.new-technologiesproducts-evaluate-the-risks)
  • Determine source of funds/wealth for higher-risk situations (va.aml.source-of-fundswealth-for-higher-risk)

Key Restrictions

  • Must be authorized/registered by ASIF as a VASP before commencing operations — this applies to the custodial wallet/SaaS operator directly (va.aml.licensingregistration-vasps-are-required-to)
  • Local presence required — any entity operating under Holy See jurisdiction must be locally present (va.licensing.local-presence-while-there-isnt)
  • Must demonstrate AML/CFT compliance documentation to ASIF including risk assessments, policies, procedures, and internal controls specific to virtual assets (va.licensing.demonstrating-compliance-providing-documentation-to)
  • Subject to ongoing supervision by ASIF including regular reporting and audits (va.licensing.ongoing-supervision-remaining-subject-to)
  • Safekeeping/administration of VAs or instruments enabling control over VAs is expressly captured as a VASP activity under Decree No. CCCLVI (356) of 2021 (va.aml.safekeeping-andor-administration-of-vas)
  • No specific crypto capital requirements, but regulated entities subject to general prudential requirements including adequate capital, liquidity, and risk management (va.licensing.capital-requirements-there-are-no)

Key Risks

  • Extremely limited market — Vatican City is not a center for cryptocurrency activity; business volume would likely be negligible (va.enforcement.low-cryptocurrency-activity-the-vatican)
  • No enforcement precedent for virtual asset activities — regulatory preparedness exists but zero enforcement track record creates uncertainty (va.enforcement.regulatory-preparedness-not-enforcement-while)
  • Ambiguity on how SaaS/custody-as-a-service model interacts with white-label clients' own AML obligations — unclear where obligations for end-user CDD sit between the SaaS operator and the client
  • Regulatory framework derived from EU AML Directives and FATF standards may impose obligations disproportionate to the jurisdiction's actual market size
  • The Holy See's financial system is specialized (Church assets, charitable works, diplomatic missions) — non-aligned commercial crypto activity may face political/PR headwinds

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Custody Providers: Entities providing safekeeping or administration of virtual assets or instruments enabling control over virtual assets would be classified as VASPs.

licensing 60% confidence

Notification/Registration with ASF: Informing the ASF of the intent to engage in virtual asset activities.

licensing 60% confidence

Demonstrating Compliance: Providing documentation to the ASF detailing how the institution will comply with all relevant AML/CFT obligations, including risk assessments, policies, procedures, and internal controls specific to virtual assets.

licensing 60% confidence

Ongoing Supervision: Remaining subject to ongoing supervision by the ASF, including regular reporting and audits.

licensing 60% confidence

Local Presence: While there isn't a specific "local presence" requirement for external crypto businesses to set up shop (as this is not the Holy See's regulatory focus), any entity operating under its jurisdiction (e.g., Vatican banks or financial institutions) is, by definition, locally present. For foreign entities, the question of "local presence" is generally moot, as the Holy See is not seeking to attract such entities.

licensing 60% confidence

Capital Requirements: There are no specific capital requirements solely for cryptocurrency activities. However, regulated financial institutions within the Holy See are subject to general prudential requirements, including adequate capital, liquidity, and risk management frameworks as determined by the ASF. If a Vatican financial institution were to engage in VASP activities, it would need to ensure these activities are adequately capitalized and managed within its overall risk framework.

licensing 60% confidence

Conduct Customer Due Diligence (CDD): Identify and verify the identity of their customers (individuals and legal entities).

licensing 60% confidence

Conduct Enhanced Due Diligence (EDD): For high-risk customers, politically exposed persons (PEPs), or complex/unusual transactions.

licensing 60% confidence

Monitor Transactions: Identify and report suspicious transactions to the ASF.

licensing 60% confidence

Record Keeping: Maintain records of transactions and customer data for a specified period.

licensing 60% confidence

Internal Controls: Establish and maintain robust internal AML/CFT policies, procedures, risk assessments, and training programs for staff.

aml 40% confidence

Licensing/Registration: VASPs are required to be authorized or registered by ASIF before commencing operations.

aml 40% confidence

Safekeeping and/or administration of VAs or instruments enabling control over VAs.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Natural Persons: Obtain and verify the identity of the customer and any beneficial owner using reliable, independent source documents, data, or information (e.g., passport, national ID card).

aml 40% confidence

Legal Entities/Arrangements: Obtain and verify the legal entity's name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions. Identify and verify the identity of beneficial owners (those holding 25% or more of the shares/voting rights, or exercising control through other means).

aml 40% confidence

Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutiny of transactions and the source of funds where necessary.

aml 40% confidence

Politically Exposed Persons (PEPs): Implement additional measures for customers who are PEPs, their family members, or close associates.

aml 40% confidence

High-Risk Jurisdictions: Apply EDD to business relationships and transactions involving countries identified by FATF or ASIF as high-risk.

aml 40% confidence

Complex or Unusual Transactions: Scrutinize transactions that are unusually large, complex, or have no apparent economic or lawful purpose.

aml 40% confidence

Non-Face-to-Face Relationships: Apply specific and adequate measures to compensate for the higher risk of non-face-to-face relationships.

aml 40% confidence

New Technologies/Products: Evaluate the risks associated with new technologies or products, particularly those that might favor anonymity.

aml 40% confidence

"Travel Rule" for VA Transfers: Decree No. CCCLVI implements the FATF "Travel Rule," requiring VASPs to obtain, hold, and transmit originator and beneficiary information for VA transfers above a certain threshold (typically equivalent to EUR 1,000, but may be subject to specific ASIF instructions).

aml 40% confidence

Source of Funds/Wealth: For higher-risk situations, VASPs must inquire about the source of funds and wealth of the customer.

aml 40% confidence

VASPs are obligated to report suspicious transactions to ASIF (acting as the FIU) without delay if they know, suspect, or have reasonable grounds to suspect that funds (including virtual assets) are proceeds of crime or are linked to terrorist financing.

enforcement 60% confidence

Low Cryptocurrency Activity: The Vatican City State is a unique, extremely small sovereign entity with a highly specialized financial system primarily focused on managing the assets of the Catholic Church and its charitable works, as well as supporting its diplomatic missions. It is not a center for commercial cryptocurrency activity or innovation.

enforcement 60% confidence

Regulatory Preparedness (Not Enforcement): While there haven't been enforcement actions, ASIF has issued guidance and regulations acknowledging the risks associated with virtual assets (cryptocurrencies). This indicates preparedness rather than a history of specific enforcement cases.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet/SaaS operator is classified as a VASP under Decree No. CCCLVI (2021) and may operate only if locally incorporated, pre-registered/authorized with ASIF, and compliant with the full FATF-aligned AML/CFT framework (CDD, EDD, Travel Rule, suspicious reporting, ongoing supervision), though the market is practically negligible and enforcement history is non-existent.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?