Crypto ATM / kiosk operator in Bulgaria
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- CDD on all customers: name, date/place of birth, nationality, permanent address, unique ID (national ID/passport) – verified from reliable independent documents (bg.aml.natural-persons-name-date-and)
- Beneficial owner identification: for legal entity customers, identify natural persons holding ≥25%+1 share or exercising control (bg.aml.for-legal-entities-vasps-must)
- Ongoing transaction monitoring: regular scrutiny to ensure consistency with customer risk profile (bg.aml.regular-scrutiny-of-transactions-undertaken)
- Enhanced due diligence (EDD) required for PEPs, high-risk third countries, and complex/unusual/large transactions (bg.aml.politically-exposed-persons-peps-customers, bg.aml.high-risk-third-countries-transactions-involving, bg.aml.complex-unusual-large-transactions-or)
- Record-keeping of customer documents, data, and information, kept up-to-date (bg.aml.keeping-customer-documents-data-and)
- Suspicious Transaction Reports (STRs) to SANS – Financial Intelligence Directorate (bg.aml.state-agency-for-national-security, bg.aml.role-this-is-bulgarias-financial)
- Registration with the National Revenue Agency (NRA) for AML/CFT compliance (bg.aml.national-revenue-agency-nra--, bg.aml.role-the-nra-is-responsible)
Key Restrictions
- Must register as a VASP with the National Revenue Agency (NRA) before commencing operations
- Must comply with all MAMLA obligations: CDD, ongoing monitoring, STR reporting, record-keeping, and internal control rules
- Physical kiosks must implement identity verification using reliable, independent source documents (no anonymous cash-in/cash-out above threshold)
- Cannot serve customers without verifying identity using valid official identification documents
- Must identify beneficial owners for legal entity customers at 25%+1 shareholding threshold
Key Risks
- Non-compliance with MAMLA (VASP registration, CDD, ongoing monitoring, STR, record-keeping) carries administrative fines, cessation of non-compliant activities, and potential criminal investigation for severe money laundering cases (bg.enforcement.violation-type-non-compliance-with-the)
- High-cash ATM/kiosk model attracts elevated AML scrutiny – cash-intensive operations are inherently high-risk for money laundering
- Regulatory guidance on specific kiosk cash thresholds (e.g., cash transaction reports) may not be explicitly codified – risk of ambiguity on exact reporting triggers
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
While MAMLA historically served as the primary domestic AML/CFT law for VASPs in Bulgaria, the current regulatory framework is transitioning to the EU's MiCA regime. The 'Bulgarian MiCA Act' is being introduced as the new governing law, and VASPs/CASPs now face dual compliance obligations under both MiCA and MAMLA-derived AML/CFT rules (such as CDD), though MAMLA no longer solely dictates the requirements and penalties for VASPs.
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
Role: This is Bulgaria's Financial Intelligence Unit (FIU). It is the primary recipient of Suspicious Transaction Reports (STRs) and other AML-related information from obliged entities. SANS is responsible for analyzing suspicious activities and disseminating intelligence to law enforcement.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
Role: The NRA is responsible for the registration and general supervision of VASPs for AML/CFT purposes. VASPs in Bulgaria are typically required to register with the NRA and demonstrate compliance with AML obligations. The NRA may conduct inspections and impose administrative sanctions for non-compliance.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators are permitted in Bulgaria as VASPs regulated under MAMLA, but must register with the National Revenue Agency, implement full CDD/KYC (no anonymous cash transactions), identify beneficial owners, report STRs to SANS, and face administrative penalties for non-compliance.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?