Crypto Investment

You're on the Register. Now You're an Obliged Entity — What That Actually Costs

Entry in the register makes you an obliged entity. Your AML officer must pass a Montenegrin exam, hold a licence, and be your employee.

Rohat Kahraman· 20 August 2026Updated · 20 August 2026
Cover illustration: the AML obligations that begin once a crypto provider is registered

The previous piece ended where most coverage of Montenegro's crypto regime ends: with entry in the register of crypto-asset service providers, the first of which happened on 31 July 2026.

That is the wrong place to stop, because of where the register lives. Montenegro did not pass a standalone crypto statute. It put crypto-asset services inside the anti-money-laundering law — the Zakon o sprječavanju pranja novca i finansiranja terorizma, amended by "Sl. list CG" 024/25 of 12 March 2025.

The consequence is structural rather than technical. Registration is not a permission you obtain and file away. It is your entry into a compliance perimeter that carries continuing, dated, personal obligations — and the first of them will surprise most foreign founders.

The obligation nobody prices in: your AML officer

Article 69 requires an obliged entity, within 60 days of establishment or of starting the activity, to appoint an AML compliance officer and at least one deputy. Within three working days of that appointment, the FIU must be notified.

The notification is prescriptive. It contains the officer's name, personal identification number, the number, expiry date and issuing state of their identity document, the number and expiry of their residence permit if they are a foreigner, job title and contact telephone — plus the entity's name, tax number and registered address. Changes must be reported within three days, with an explanation of the reasons. Notifications go to the FIU electronically, signed with a qualified electronic signature.

So far, administrative. Then comes Article 70, and this is the provision that reshapes hiring plans.

A person may be appointed as AML officer or deputy only if they:

  1. have completed the training and passed the professional examination for the role;
  2. hold the licence to perform the role;
  3. have not been finally convicted of a criminal offence carrying a prison sentence of more than six months; and
  4. are in an employment relationship with the obliged entity.

Read conditions 2 and 4 together as a foreign crypto business. Your group's head of compliance in Tallinn or Dubai — however senior, however experienced — cannot be your Montenegrin AML officer unless they hold the Montenegrin licence and are employed by the Montenegrin entity. Neither can an external consultancy on a retainer. The role is not outsourceable by design.

Article 70(2) tightens it further: one person may be the AML officer or deputy at only one obliged entity. There is no shared-officer model across a group.

Article 71 confirms the training is not a formality delivered in-house: it is conducted by an adult-education organiser holding a licence under the adult-education regulations.

There is also a transition with teeth. Officers and deputies who do not obtain the licence in accordance with the law lose that status — the appointment simply ceases.

The relief for small entities, and its limits

The law does recognise that not every obliged entity is a bank.

Where an obliged entity has four or fewer employees, it is not required to appoint a deputy. And in that case the director may perform the AML officer role personally, provided the director meets the Article 70 conditions — with the FIU notified accordingly.

Article 70(3) adds a narrow exception to the one-entity rule: where the director performs the role under Article 69(5), that director may be the AML officer at several obliged entities in which they are both the director and the only employee.

That is genuinely useful for a lean structure. But note what it does not do. It does not waive the training, the examination or the licence. A two-person crypto startup still needs someone who has sat the Montenegrin exam and holds the licence — it simply may be the founder rather than a separate hire.

Which obliged entity you are, precisely — and why it decides your supervisor

"Obliged entity" is not one category. Article 4(2) lists them, and the position of crypto-asset service providers on that list is not cosmetic.

Crypto-asset service providers are point 12. Their neighbours are instructive: point 10 is gambling operators, point 11 is pawnshops, point 13 covers auditors, accountants and tax advisers. Points 5, 6 and 7 are investment fund management companies, pension fund management companies and investment firms.

That numbering feeds directly into supervision. Article 131(1)(3) assigns the Capital Market Commission supervision over obliged entities under points 5, 6, 7 and 12 — which is why the crypto register sits with that authority rather than with the Central Bank. The Central Bank supervises points 1, 2 and 3, the credit institutions and the lending and exchange businesses it licenses.

For a firm arriving from another market, that placement is worth absorbing. You are not being supervised as a payments business by a central bank. You are supervised by the capital-market regulator, alongside investment firms and fund managers — an authority whose examination culture, expectations and vocabulary come from securities regulation.

It also explains the shape of the application file described in the previous piece: a business plan setting out intended services and how they will be marketed, repute requirements reaching the beneficial owner, data on all directors. Those are securities-supervisor instincts, and they are a reasonable guide to how the relationship is likely to run after registration as well.

The threshold that is specific to crypto

Customer due diligence obligations attach at different points for different obliged entities. The crypto-specific trigger is materially lower than most.

The law requires due diligence measures on every occasional transaction constituting a transfer of crypto-assets of €1,000 or more. For comparison, traders in goods are caught at €10,000.

For a business whose ordinary transaction size sits above a thousand euro, "occasional transaction" screening is not an edge case. It is the default posture, and it has to be built into onboarding and monitoring rather than bolted on afterwards.

Due diligence is also not a one-off event at onboarding. The law requires an obliged entity to apply customer knowledge and monitoring measures periodically to clients with whom a business relationship already exists — on the basis of its money-laundering and terrorist-financing risk assessment, when circumstances relating to the client change, or where the entity is under any legal obligation during the relevant calendar year to contact the client to verify information connected with the client's beneficial owner.

In practice that means the file you build at onboarding is a file you are expected to keep alive, and the trigger for refreshing it is your own risk assessment rather than a fixed anniversary.

ObligationTrigger / deadlineSource
Appoint AML officer and deputywithin 60 days of establishment or starting activityArt. 69
Notify the FIU of the appointmentwithin 3 working days, electronically, qualified e-signatureArt. 69
Notify a change of officerwithin 3 days, with reasonsArt. 69
Officer eligibilitytraining + exam + licence + employment with the entityArt. 70
One officer, one entityno shared officer across a groupArt. 70(2)
Deputy not requiredobliged entity with ≤4 employeesArt. 69
CDD on crypto transfersoccasional transaction of €1,000 or moreAML law, CDD triggers
Align internal acts and organisation6 months from entry into forceArt. 146

Internal acts, and what applies in the meantime

Article 146 requires obliged entities to bring their internal acts and internal organisation into line with the law within six months of its entry into force.

There is a sensible bridge: until the new internal acts under Articles 77, 78 and 80 are adopted, the existing rulebook applies — the Pravilnik on the manner of work of the authorised person, internal control, data retention and protection, record-keeping and staff training, published in "Službeni list CG" 71/20.

For a firm building its Montenegrin compliance stack now, that rulebook is the document to work from rather than a generic group policy translated into Montenegrin.

One provision that is waiting for EU accession

A detail worth knowing because it recurs across Montenegrin legislation: Article 146a defers the application of Article 108(2) and Article 134(8) and (9) until the day Montenegro accedes to the European Union.

This is the same drafting pattern found elsewhere — obligations written into the statute now, switched on by accession later. It matters for planning because a provision that is in the text is not necessarily in force, and reading a consolidated law without checking the deferral clauses produces confident wrong answers.

What I could not resolve

Three gaps, stated rather than papered over.

I found no penalty provision keyed specifically to the crypto registration article. General AML supervisory powers and sanctions exist and the Capital Market Commission is the supervisor, but I am not going to attach figures to an offence I could not tie to the text.

The practical route to the officer licence — how often the exam runs, which organisers are licensed, what the training costs and how long the cycle takes — is administrative practice rather than statute. It is the first thing to establish for a live timetable, and it should come from the authority rather than from an article.

The six-month and sixty-day clocks run from different events. Article 146 runs from the law's entry into force; Article 69 runs from the entity's establishment or the start of activity. For a company registering now, the second is the live one — but confirm which applies to your facts rather than assuming.

The arithmetic

The registration file is the visible cost. The officer is the real one, and it is a hiring problem before it is a legal one.

A licensed, examined AML officer who must be your employee and cannot serve another obliged entity is a permanent seat on your payroll in Montenegro — for a business that may have imagined a light local presence. Whether the founder can occupy that seat under the four-or-fewer-employees route is a question with a concrete answer, and the answer changes the shape of the entire local structure.

Establishing that before incorporation costs a conversation. Discovering it after the entity exists, the register application is drafted and the launch date is announced costs a rebuild.

What to send, and when

If you are planning to register, send your intended Montenegrin structure — how many employees, who would hold the compliance role, whether that person is or can be employed locally, and whether any of them holds a Montenegrin AML officer licence already. That is enough to say whether Article 70 is satisfied or whether the plan needs a person it does not currently have.

RoNa Legal advises foreign clients on Montenegrin law; representation before Montenegrin authorities and courts is conducted together with advocates entered in the register of the Bar Association of Montenegro. See our fintech and crypto practice or reach us through contact. The registration obligation itself — who is caught, including EU-licensed providers — is set out in Montenegro's crypto register. Related: AML and KYC harmonisation for Montenegrin companies.

Frequently asked questions

Does registering as a crypto service provider create ongoing obligations?

Yes. The register sits inside the Law on the Prevention of Money Laundering and Terrorism Financing, so entry places you within the AML compliance perimeter with continuing duties.

When must I appoint an AML compliance officer?

Within 60 days of establishment or of starting the activity, under Article 69, together with at least one deputy.

How quickly must the appointment be reported?

Within three working days, to the financial intelligence unit, electronically and signed with a qualified electronic signature. Changes are reported within three days with an explanation.

Can our existing group compliance officer take the role?

Only if they satisfy Article 70 — which requires the Montenegrin training and professional examination, the licence, no conviction carrying more than six months' imprisonment, and an employment relationship with the Montenegrin obliged entity.

Can we outsource the role to a consultant?

No. Condition four requires an employment relationship with the obliged entity, which an external retainer does not create.

Can one person cover several of our entities?

No. Article 70(2) permits a person to act as officer or deputy at only one obliged entity, with a narrow exception where a director performs the role and is the only employee.

We will be very small. Is there any relief?

Yes. An obliged entity with four or fewer employees need not appoint a deputy, and the director may perform the role personally — but the director must still meet the Article 70 conditions, including the licence.

What happens to an officer who does not obtain the licence?

Their status as officer or deputy ceases.

At what transaction size does customer due diligence bite for crypto?

On every occasional transaction that constitutes a transfer of crypto-assets of €1,000 or more — considerably lower than the €10,000 threshold applying to traders in goods.

How long do we have to align internal policies?

Article 146 gives obliged entities six months from the law's entry into force to align internal acts and internal organisation. Until new internal acts under Articles 77, 78 and 80 are adopted, the Pravilnik published in "Sl. list CG" 71/20 applies.

Is everything in the law already in force?

No. Article 146a defers Article 108(2) and Article 134(8) and (9) until Montenegro accedes to the EU. Reading a consolidated text without checking deferral clauses is a common source of wrong answers.