Crypto ATM / kiosk operator in Saint Vincent and the Grenadines
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Saint Vincent and the Grenadines with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- CDD required for all customers: obtain full name, residential address, date of birth, nationality, and unique identification number (e.g. passport, national ID card) for natural persons
- For legal persons: obtain legal name, address of registered office/principal place of business, incorporation details, and identify beneficial owners owning/controlling 25%+ of the entity
- Understand the purpose and intended nature of the business relationship with each customer
- Conduct ongoing monitoring of transactions to ensure consistency with customer knowledge, business, and risk profile
- Enhanced Due Diligence (EDD) required for high-risk customers — PEPs, customers from high-risk jurisdictions, transactions involving complex structures or unusually large amounts
- Obligation to report suspicious transactions (STRs) to the Financial Intelligence Unit (FIU) promptly, 'without delay', upon forming suspicion
- No tipping-off: it is an offense to disclose to a customer or third party that an STR has been or will be made
- Record-keeping: maintain all CDD documents, transaction records, business correspondence, and STR copies for a minimum of 5 years after business relationship ends or transaction date
Key Restrictions
- Must register/license under the Virtual Asset Business Act, 2020 (VABA) — operating or advertising virtual asset business without proper licensing is a violation
- All CDD/AML/CFT obligations under the Anti-Money Laundering and Combating the Financing of Terrorism Act, 2017 apply to VASPs as reporting entities
- Enhanced DD required for cash-intensive operations given high-risk profile (cash-for-crypto transactions)
- Physical kiosk locations may need to comply with local business registration requirements and potentially financial services authority oversight
Key Risks
- The FSA has publicly targeted entities falsely claiming regulation or operating VASP business without VABA licensing — enforcement risk is active
- High cash-transaction volumes raise AML/CFT scrutiny risk; EDD obligations for unusually large or complex cash transactions
- No specific kiosk/money-transmitter licensing framework exists beyond VABA — regulatory treatment of cash-in/cash-out kiosks may involve some ambiguity
- FSA can take action against entities operating without proper authorization or in violation of financial laws
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Proceeds of Crime Act, 2013 (as amended): This act criminalizes money laundering and terrorist financing offenses and provides for the forfeiture of assets derived from criminal conduct.
The Anti-Money Laundering and Combating the Financing of Terrorism Act, 2017 (as amended): This is the principal legislation outlining the obligations for financial institutions and DNFBPs to prevent and detect money laundering and terrorist financing. It defines key terms, outlines reporting obligations, and sets out penalties for non-compliance.
The Financial Intelligence Unit Act, 2001 (as amended): This act establishes the Financial Intelligence Unit (FIU) and defines its powers and functions, including receiving and analyzing suspicious transaction reports.
Identify and Verify Customer Identity:
For natural persons: Obtain full name, residential address, date of birth, nationality, and a unique identification number (e.g., passport, national ID card). Verification typically requires independent, reliable source documents.
For legal persons/entities: Obtain legal name, address of registered office and principal place of business, incorporation details (e.g., certificate of incorporation, articles of association), and identify beneficial owners (those who ultimately own or control 25% or more of the entity).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer is seeking the services and how they intend to use them.
Conduct Ongoing Monitoring: Regularly review the business relationship and transactions undertaken to ensure they are consistent with the entity's knowledge of the customer, their business, and risk profile, including (where necessary) the source of funds.
Risk-Based Approach: Apply a risk-based approach to CDD.
Enhanced Due Diligence (EDD): Required for high-risk customers, such as Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or transactions involving complex structures or unusually large amounts. This involves more rigorous verification, deeper understanding of source of funds/wealth, and higher-level approval for establishing relationships.
Simplified Due Diligence (SDD): Permitted for low-risk customers, where sufficient information is available through public sources and the risk of ML/FT is assessed as low.
Obligation to Report: All reporting entities (which would include VASPs if their activities are considered relevant financial business) have a legal obligation to report any transaction (or attempted transaction) where there are reasonable grounds to suspect that funds are the proceeds of criminal activity or are linked to terrorist financing.
Recipient: Reports must be submitted to the Financial Intelligence Unit (FIU) of Saint Vincent and the Grenadines.
Timeliness: STRs must be filed promptly, "without delay," upon forming the suspicion.
No Tipping-Off: It is an offense to disclose to the customer or any third party that a suspicious transaction report has been or will be made.
Customer Identification Data: All documents used for CDD, including copies of identification documents and verification records.
Transaction Records: Details of all transactions, including amounts, types of currency/virtual assets, dates, and parties involved.
Business Correspondence: Records of communications with customers and third parties related to transactions and the business relationship.
STRs and Internal Reports: Copies of all suspicious transaction reports filed and any internal reports or analyses leading to such reports.
Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.
Financial Services Authority (FSA):
Financial Intelligence Unit (FIU):
Entity Targeted: General public and entities falsely claiming to be regulated by the SVG FSA for virtual asset business. Violation Type: Operating or advertising virtual asset business activities without proper licensing under the Virtual Asset Business Act, 2020 (VABA), or misrepresenting regulatory status. Penalty Amount: Not applicable to general warnings; specific penalties for unlicensed operation would be determined if an investigation led to a formal enforcement action, which typically isn't publicly detailed. Outcome: Increased public awareness, pressure on unlicensed entities to cease operations or comply, and a clear stance from the regulator.
Entity Targeted: All virtual asset service providers (VASPs) and the general public, including those considering operating in or from SVG. Violation Type: N/A (this is a regulatory clarification, not an enforcement action itself). However, entities failing to register or comply with VABA would be in violation. Penalty Amount: N/A. Outcome: Enhanced clarity on legal obligations for VASPs, driving compliance with registration requirements, AML/CFT measures, and consumer protection. This sets the stage for future enforcement by defining what constitutes a violation.
Outcome: Increased public awareness, pressure on unlicensed entities to cease operations or comply, and a clear stance from the regulator.
Evidence fact vc.enforcement.outcome-enhanced-clarity-on-legal-requirements not found (may have been renamed).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators must register under the Virtual Asset Business Act, 2020 (VABA) and comply with full AML/CFT obligations (CDD, EDD for high-risk cash transactions, STR filing to the FIU, 5-year record retention) under SVG law, with no specific kiosk-dedicated license but active enforcement against unlicensed VASPs.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?