Custodial wallet / SaaS in Bulgaria
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Bulgaria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with the National Revenue Agency (NRA) as a VASP for AML/CFT purposes (bg.aml.national-revenue-agency-nra--)
- Customer Due Diligence (CDD) under MAMLA, including identity verification (name, DOB, nationality, address, national ID number for natural persons; company name, legal form, registration number, address for legal entities) (bg.aml.natural-persons-name-date-and, bg.aml.legal-entities-company-name-legal)
- Beneficial Owner identification (25%+1 share threshold or control) and verification (bg.aml.identification-and-verification-of-the, bg.aml.for-legal-entities-vasps-must)
- Understanding purpose and intended nature of business relationship and source of funds/wealth (bg.aml.understanding-the-purpose-and-intended)
- Ongoing transaction monitoring throughout the business relationship (bg.aml.regular-scrutiny-of-transactions-undertaken)
- Suspicious Transaction Reports (STRs) to SANS Financial Intelligence Directorate (bg.aml.state-agency-for-national-security, bg.aml.role-this-is-bulgarias-financial)
- Record-keeping obligations under MAMLA (bg.aml.keeping-customer-documents-data-and)
- Enhanced due diligence for PEPs and high-risk third countries (bg.aml.politically-exposed-persons-peps-customers, bg.aml.high-risk-third-countries-transactions-involving)
- Reporting of complex, unusual, large transactions or unusual patterns (bg.aml.complex-unusual-large-transactions-or)
- Ongoing internal control rules and compliance program (bg.aml.identification-and-verification-of-the)
Key Restrictions
- Must register as a VASP with the National Revenue Agency (NRA) before offering custodial wallet services (bg.aml.national-revenue-agency-nra--)
- Must comply with MAMLA defining virtual asset safekeeping/administration as a regulated activity (bg.aml.safekeeping-andor-administration-of-virtual)
- The SaaS provider (custodian) is the obliged entity — not just the white-label client — because the provider holds the keys and performs safekeeping (bg.aml.safekeeping-andor-administration-of-virtual)
- No specific custody license / qualified-custodian framework identified in the facts — VASP registration under AML law appears to be the primary gateway
Key Risks
- No dedicated custody license regime (capital/reserve/segregation rules) described in the provided facts — regulatory gaps around proof-of-reserves and insurance requirements are unaddressed and create uncertainty
- AML obligations attach to the custodial SaaS provider as the obliged entity performing safekeeping, but the facts do not clarify how obligations split between provider and white-label client in a SaaS model
- Enforcement exposure: administrative fines, cessation orders, and potential criminal investigation for non-compliance with MAMLA (bg.enforcement.violation-type-non-compliance-with-the)
- EU sanctions directly applicable — custodians must implement sanctions screening without national transposition gap (bg.enforcement.legal-basis-eu-sanctions-are)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
While MAMLA historically served as the primary domestic AML/CFT law for VASPs in Bulgaria, the current regulatory framework is transitioning to the EU's MiCA regime. The 'Bulgarian MiCA Act' is being introduced as the new governing law, and VASPs/CASPs now face dual compliance obligations under both MiCA and MAMLA-derived AML/CFT rules (such as CDD), though MAMLA no longer solely dictates the requirements and penalties for VASPs.
This act defines "virtual assets" and "virtual asset service providers" and brings them within the scope of obliged entities. It outlines the specific requirements for customer due diligence, reporting, and record-keeping.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
In Bulgaria, the State Agency for National Security (SANS) is the primary AML/CFT regulatory body, overseeing VASPs centrally; the Financial Intelligence Directorate under DANS no longer serves as the sole key entity.
National Revenue Agency (NRA) (Национална агенция за приходите - НАП)
In Bulgaria, the identification and verification of the beneficial owner is required under the AML Act, but if no individual beneficial owner can be identified through ownership or control criteria, the law provides that members of senior management are treated as the beneficial owner for registration purposes, so the process is not absolute but includes a fallback.
Natural Persons: Name, date and place of birth, nationality, permanent address, unique identification number (e.g., national ID card, passport number). Identity must be verified using reliable, independent source documents or data (e.g., valid official identification document).
Legal Entities: Company name, legal form, registration number, registered address, and the names of the individuals authorized to represent the company. Verification involves obtaining extracts from commercial registers or similar official documents.
For legal entities, VASPs must identify the natural person(s) who ultimately own or control the customer, typically defined as holding 25% plus one share or more of the voting rights or exercising control via other means. This information must also be verified.
Evidence fact bg.aml.understanding-the-purpose-and-intended not found (may have been renamed).
Regular scrutiny of transactions undertaken throughout the course of the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer documents, data, and information up-to-date.
Politically Exposed Persons (PEPs): Customers who hold or have held prominent public functions, their family members, or close associates.
High-Risk Third Countries: Transactions involving customers or beneficial owners from countries identified by the EU or FATF as having strategic AML/CFT deficiencies.
Complex, Unusual, Large Transactions, or Unusual Patterns: Transactions that have no apparent economic or lawful purpose.
Violation Type: Non-compliance with the Measures Against Money Laundering Act (MAMLA), specifically regarding VASP registration, customer due diligence (CDD), ongoing monitoring, suspicious transaction reporting (STR), record-keeping, internal control rules, etc. Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Outcome: Administrative fines, cessation of non-compliant activities, and potential criminal investigations in severe cases of money laundering.
Legal Basis: EU sanctions are typically imposed through Council Decisions and implemented via Council Regulations. These Regulations are directly applicable in all EU Member States without the need for national transposition.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are permitted in Bulgaria as VASPs but must register with the National Revenue Agency for AML/CFT purposes under MAMLA; no dedicated custody-license framework (capital, segregation, insurance, proof-of-reserves rules) is apparent from the provided facts, creating regulatory uncertainty for this operating model.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?