Custodial wallet / SaaS in Azerbaijan
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Azerbaijan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD)/KYC — verify full name, date of birth, address, national ID number for individuals; legal name, registration, beneficial owners (≥25%) for legal entities (az.aml.individuals-obtaining-and-verifying-the, az.aml.legal-entities-obtaining-and-verifying)
- Purpose and nature of business relationship documentation (az.aml.purpose-and-nature-of-business)
- Source of funds/wealth for high-risk customers or transactions (az.aml.source-of-fundswealth-for-high-risk)
- Ongoing transaction monitoring for unusual patterns consistent with customer risk profile (az.aml.ongoing-monitoring-continuously-monitoring-the)
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, cross-border virtual asset transfers to/from weak-AML jurisdictions (az.aml.enhanced-due-diligence-edd-required, az.aml.transactions-with-politically-exposed-persons, az.aml.customers-from-high-risk-jurisdictions-identified, az.aml.complex-unusually-large-transactions-or, az.aml.cross-border-virtual-asset-transfers-tofrom)
- Suspicious Transaction Reporting (STR) to the Financial Monitoring Service (FMS) (az.aml.reporting-mechanism-reports-are-typically, az.licensing.suspicious-transaction-reporting-str-reporting)
- Record-keeping of transactions and CDD documentation (az.licensing.record-keeping-maintaining-records-of)
- Simplified Due Diligence (SDD) may apply only in very limited low-risk circumstances per internal risk assessments (az.aml.simplified-due-diligence-sdd-may)
- Monitoring for red flags: structuring, privacy coins, addresses linked to illicit activity, rapid volume changes (az.aml.indicators-of-suspicion-vasps-must, az.aml.unusual-or-complex-transaction-patterns, az.aml.transactions-inconsistent-with-the-customers, az.aml.rapid-and-inexplicable-changes-in, az.aml.structuring-of-transactions-to-avoid, az.aml.transactions-involving-anonymity-enhancing-virtual-assets, az.aml.transactions-involving-addresses-linked-to)
Key Restrictions
- No dedicated custody or VASP license exists — any custodial wallet/SaaS operation would need to apply under a full traditional financial license (e.g., banking license or payment institution license), which is extremely difficult to obtain (az.licensing.no-dedicated-licensing-regime-there, az.licensing.custody-providers-there-is-no, az.licensing.regulatory-gap-de-facto-prohibition)
- Cryptocurrencies are not legal tender — processing payments in cryptocurrency is generally not permitted (az.licensing.processing-payments-in-cryptocurrency-this)
- Holding client assets (keys/funds) may trigger safekeeping, trust, or banking regulations, requiring a traditional license (az.licensing.custody-providers-there-is-no)
- Fiat payment processing for crypto services would require a traditional payment services license under the Law on Payment Services and Payment Systems, but regulatory approval is highly uncertain (az.licensing.processing-fiat-payments-for-cryptocurrency)
- Local physical presence and local management required — no remote-only operation (az.licensing.local-presence-any-regulated-financial)
- Fit and proper tests for directors/senior management, robust internal controls and risk management frameworks required (az.licensing.management-governance-fit-and-proper)
- AML/CTF amendments aligned with FATF recommendations for VASPs are enacted but not in force until 31 March 2026, creating legal uncertainty in the interim (az.aml.this-law-defines-the-scope)
- The CBA and financial authorities take a cautious/de facto prohibitory stance toward crypto activities (az.licensing.restrictive-interpretation-regulatory-silence-the)
Key Risks
- De facto prohibition risk — regulatory silence combined with CBA caution means operating in a legal grey zone with significant enforcement exposure (az.licensing.restrictive-interpretation-regulatory-silence-the, az.licensing.regulatory-gap-de-facto-prohibition)
- Criminal enforcement risk — most crypto-related enforcement actions in Azerbaijan target fraud/Ponzi/pyramid schemes, and a custodial wallet/SaaS provider could be swept into such investigations (az.enforcement.nature-of-violations-the-most, az.enforcement.entity-targeted-individuals-or-groups)
- No licensed precedent — no known entity has obtained a traditional financial license to operate custodial crypto services, so the application timeline, capital requirements, and likelihood of approval are untested (az.licensing.no-dedicated-licensing-regime-there, az.licensing.extensive-review-and-due-diligence, az.licensing.the-process-is-typically-lengthy)
- Capital burden — if a banking or payment license is required, minimum capital requirements are significant (az.licensing.capital-requirements-for-traditional-financial)
- Regulatory transition risk — AML/CFT amendments for VASPs effective 31 March 2026 may introduce new obligations or prohibitions, creating planning uncertainty (az.aml.this-law-defines-the-scope)
- White-label SaaS AML allocation risk — unclear whether AML obligations fall on the SaaS provider (as custodian/VASP) or the white-label client; the broad FATF VASP definition likely burdens both, but guidance is absent (az.licensing.the-fatfs-expanded-definition-of)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
A General Lack of Specific Legislation: There is no specific law or regulatory framework explicitly governing the licensing of crypto exchanges, custody providers, or dedicated crypto payment processors.
Restrictive Interpretation / Regulatory Silence: The prevailing approach by the Central Bank of Azerbaijan (CBA) and other financial authorities leans towards caution and, in many cases, a de facto prohibition or severe restriction on activities involving virtual assets, especially when they touch upon traditional financial services. Cryptocurrencies are not recognized as legal tender.
Application of General Financial Laws (Where Applicable): Certain activities might inadvertently fall under existing financial services laws (e.g., banking, payment services, securities), which are highly regulated and typically not easily granted for crypto-related businesses.
No Dedicated Licensing Regime: There is no "virtual asset license" you can apply for specifically to operate a crypto exchange, custody service, or crypto payment processing.
Regulatory Gap / De Facto Prohibition: The absence of a framework often means such activities are either not allowed, operate in a legal grey area with significant risk, or would require a full traditional financial license (e.g., a banking license or a payments institution license), which is extremely difficult to obtain and often not suitable for pure crypto businesses.
Custody Providers: There is no specific license for virtual asset custody. If a service involves holding client assets, especially if they are deemed to have monetary value, it could potentially fall under regulations for safekeeping, trust services, or even banking, requiring appropriate traditional licenses.
Processing payments in cryptocurrency: This is generally not permitted as cryptocurrencies are not legal tender in Azerbaijan.
Processing fiat payments for cryptocurrency services: An entity processing fiat payments on behalf of clients or other businesses for crypto-related transactions would typically require a traditional payment services license under the "Law on Payment Services and Payment Systems." However, the underlying crypto activity itself might still be problematic or prohibited.
Capital Requirements: For traditional financial institutions (banks, payment institutions), capital requirements are significant. For example, a bank would require a very high minimum capital. For a payment institution, it's lower but still substantial.
AML/KYC Requirements: This is the most crucial aspect that does apply. Azerbaijan is a member of the FATF (Financial Action Task Force) and has updated its AML/CTF framework to align with FATF recommendations. This means that entities dealing with virtual assets, if they operate, are expected to comply with:
Local Presence: Any regulated financial institution in Azerbaijan is required to have a physical local presence and often local management.
Management & Governance: Fit and proper tests for directors and senior management, robust internal controls, and risk management frameworks are standard for financial institutions.
The FATF's expanded definition of "Virtual Asset Service Providers (VASPs)" to include exchanges, custodians, etc., generally means these entities should be subject to AML/CTF obligations in Azerbaijan, even if a dedicated licensing regime is absent.
Submission of a comprehensive application to the Central Bank of Azerbaijan (CBA).
Proof of minimum capital.
Extensive review and due diligence by the CBA.
The process is typically lengthy, rigorous, and requires significant legal and financial expertise.
The AML/CTF framework defines the scope of reporting entities and their obligations, but amendments intended to align more fully with international standards—particularly in relation to new technologies and virtual assets—have been enacted but are not scheduled to commence until 31 March 2026, so those specific changes are not yet in force.
Key Principle: The law's definitions of "property" and "financial operations" are broad enough to encompass virtual assets and related services, thus bringing VASPs under its purview, even if they are not explicitly named in every article. FATF's guidance strongly recommends this approach for member countries.
Financial Monitoring Service of the Republic of Azerbaijan (FMS)
Individuals: Obtaining and verifying the customer's full legal name, date of birth, address, and unique identification number (e.g., passport number, national ID card number). Verification typically involves reliable, independent source documents or data.
Legal Entities: Obtaining and verifying the legal name, registration number, address, articles of incorporation, and identifying the natural persons who are the beneficial owners (typically those owning 25% or more of the entity's shares or voting rights, or exercising control through other means).
Purpose and Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.
Source of Funds/Wealth: For high-risk customers or transactions, obtaining information on the source of funds or wealth used in the virtual asset transactions.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual transaction patterns.
Enhanced Due Diligence (EDD): Required for higher-risk scenarios, such as:
Customers from high-risk jurisdictions identified by FATF or the FMS.
Complex, unusually large transactions or unusual patterns of transactions with no apparent economic or lawful purpose.
Cross-border virtual asset transfers to/from jurisdictions with weak AML/CFT regimes.
Simplified Due Diligence (SDD): May be applied in very limited, low-risk circumstances, as defined by internal risk assessments and regulatory guidelines.
Indicators of Suspicion: VASPs must develop systems and training to identify red flags indicative of money laundering, terrorist financing, or other illicit activities. These can include:
Reporting Mechanism: Reports are typically submitted electronically to the FMS.
Evidence fact az.aml.record-keeping-maintaining-records-of not found (may have been renamed).
Financial Monitoring Service (FMS): Responsible for AML/CFT oversight and financial intelligence.
Central Bank of Azerbaijan (CBAR): Regulates traditional financial institutions and payment systems, but direct crypto regulation is still being formalized.
Entity Targeted: Individuals or groups operating alleged fraudulent schemes (e.g., Ponzi schemes, pyramid schemes) using cryptocurrencies as an investment vehicle or payment method. Violation Type: Fraud, swindling, operating illegal financial schemes, potentially money laundering. Penalty Amount: This is not a "fine." Instead, it involves arrests, criminal investigations, pre-trial detention, potential prosecution leading to imprisonment, and asset forfeiture. Specific "penalty amounts" as regulatory fines are not applicable here.
Nature of Violations: The most common "violations" related to crypto in Azerbaijan that lead to law enforcement action are criminal in nature (fraud, pyramid schemes) rather than breaches of specific crypto-regulatory compliance.
Regulatory Maturity: Azerbaijan's specific regulatory framework for cryptocurrencies is still evolving. There isn't a dedicated crypto regulator actively issuing fines against licensed entities because the licensing regime is still nascent.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS is not explicitly prohibited but functionally very difficult to operate legally in Azerbaijan, requiring a traditional financial license (e.g., banking/payment institution license) that is extremely burdensome to obtain, with FATF-aligned AML/CTF obligations applying via broad statutory definitions but no dedicated VASP licensing framework, and key AML amendments not effective until 31 March 2026.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?