← Regulations / Bulgaria / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Bulgaria

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes (bg.aml.national-revenue-agency-nra--)
  • Customer Due Diligence (CDD) under MAMLA, including identity verification (name, DOB, nationality, address, national ID number for natural persons; company name, legal form, registration number, address for legal entities) (bg.aml.natural-persons-name-date-and, bg.aml.legal-entities-company-name-legal)
  • Beneficial Owner identification (25%+1 share threshold or control) and verification (bg.aml.identification-and-verification-of-the, bg.aml.for-legal-entities-vasps-must)
  • Understanding purpose and intended nature of business relationship and source of funds/wealth (bg.aml.understanding-the-purpose-and-intended)
  • Ongoing transaction monitoring throughout the business relationship (bg.aml.regular-scrutiny-of-transactions-undertaken)
  • Suspicious Transaction Reports (STRs) to SANS Financial Intelligence Directorate (bg.aml.state-agency-for-national-security, bg.aml.role-this-is-bulgarias-financial)
  • Record-keeping obligations under MAMLA (bg.aml.keeping-customer-documents-data-and)
  • Enhanced due diligence for PEPs and high-risk third countries (bg.aml.politically-exposed-persons-peps-customers, bg.aml.high-risk-third-countries-transactions-involving)
  • Reporting of complex, unusual, large transactions or unusual patterns (bg.aml.complex-unusual-large-transactions-or)
  • Ongoing internal control rules and compliance program (bg.aml.identification-and-verification-of-the)

Key Restrictions

  • Must register as a VASP with the National Revenue Agency (NRA) before offering custodial wallet services (bg.aml.national-revenue-agency-nra--)
  • Must comply with MAMLA defining virtual asset safekeeping/administration as a regulated activity (bg.aml.safekeeping-andor-administration-of-virtual)
  • The SaaS provider (custodian) is the obliged entity — not just the white-label client — because the provider holds the keys and performs safekeeping (bg.aml.safekeeping-andor-administration-of-virtual)
  • No specific custody license / qualified-custodian framework identified in the facts — VASP registration under AML law appears to be the primary gateway

Key Risks

  • No dedicated custody license regime (capital/reserve/segregation rules) described in the provided facts — regulatory gaps around proof-of-reserves and insurance requirements are unaddressed and create uncertainty
  • AML obligations attach to the custodial SaaS provider as the obliged entity performing safekeeping, but the facts do not clarify how obligations split between provider and white-label client in a SaaS model
  • Enforcement exposure: administrative fines, cessation orders, and potential criminal investigation for non-compliance with MAMLA (bg.enforcement.violation-type-non-compliance-with-the)
  • EU sanctions directly applicable — custodians must implement sanctions screening without national transposition gap (bg.enforcement.legal-basis-eu-sanctions-are)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 100% confidence

While MAMLA historically served as the primary domestic AML/CFT law for VASPs in Bulgaria, the current regulatory framework is transitioning to the EU's MiCA regime. The 'Bulgarian MiCA Act' is being introduced as the new governing law, and VASPs/CASPs now face dual compliance obligations under both MiCA and MAMLA-derived AML/CFT rules (such as CDD), though MAMLA no longer solely dictates the requirements and penalties for VASPs.

aml 95% confidence

This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.

aml 90% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 100% confidence

In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.

aml 90% confidence

National Revenue Agency (NRA) (Национална агенция за приходите - НАП)

aml 100% confidence

In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.

aml 80% confidence

Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).

aml 80% confidence

Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.

aml 95% confidence

For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.

Evidence fact bg.aml.understanding-the-purpose-and-intended not found (may have been renamed).

aml 83% confidence

Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Keeping customer documents, data, and information up-to-date.

aml 95% confidence

Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.

aml 95% confidence

High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.

aml 95% confidence

Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.

enforcement 80% confidence

Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.

enforcement 80% confidence

Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers are permitted in Bulgaria as VASPs but must register with the National Revenue Agency for AML/CFT purposes under MAMLA; no dedicated custody-license framework (capital, segregation, insurance, proof-of-reserves rules) is apparent from the provided facts, creating regulatory uncertainty for this operating model.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?