Custodial wallet / SaaS in Bahrain
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Bahrain with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Licensed VASPs must comply with CBB Module AML (Anti-Money Laundering & Combating of Financial Crime) in Volume 6 (Capital Markets), covering CDD, EDD, record-keeping, and reporting.
- Obtain and verify identity for all customers: name, permanent address, date of birth, nationality, and official ID number (e.g., CPR/National ID, passport) using reliable independent source documents.
- For legal entity clients: obtain legal name, legal form, proof of incorporation, directors/authorized signatories, registered address, principal business activity, and beneficial owner identification (10%+ ownership threshold).
- Understand the purpose and intended nature of the business relationship — assessed on a continuing, risk-based basis, not one-time.
- Assess and reassess customer risk profile using collected information including beneficial ownership data.
- Source of Funds and Source of Wealth (SoF/SoW) obligations apply under CDD requirements.
- Travel Rule: CBB has implemented FATF Travel Rule requiring VASPs to obtain and transmit originator and beneficiary information for crypto transfers above a certain threshold.
- Mandatory sanctions screening against UN Consolidated Lists (ISIL & Al-Qaida, Taliban), national Bahraini sanctions lists, and ongoing monitoring for existing clients.
- Risk-based approach per FATF recommendations — higher-risk jurisdictions trigger EDD; if risks cannot be mitigated, business must be declined.
- Substantial penalties for non-compliance: fines, license conditions, suspension/revocation, imprisonment, asset confiscation under CBB Law No. 64 of 2006 and Law No. 4 of 2001.
- While not legally mandated for purely domestic operations, prudent VASPs handling international transactions incorporate OFAC and EU sanctions lists into screening due to secondary sanctions risk and USD clearing access.
Key Restrictions
- Operator must hold a Category 3 (Custodian) license from the CBB — minimum paid-up capital of BHD 100,000 (~USD 265,000) plus BHD 50,000 reserve.
- Local entity required: must be incorporated in Bahrain.
- Client crypto-assets must be held in trust, absolutely segregated from operator's own assets, with no commingling (CRY-5.1.1 to CRY-5.1.3).
- Operators are prohibited from using client crypto-assets without explicit written client consent and regulatory approval (CRY-5.1.4).
- A significant proportion of client assets must be held in cold storage (offline), with documented policies determining the appropriate proportion based on asset type, liquidity needs, and risk profile (CRY-4.2.1, CRY-4.2.2).
- Regular reconciliation of client crypto-assets with internal records is mandated (CRY-5.1.5).
- Insurance or equivalent financial protections for client-asset safekeeping risks (cyber, theft, fraud, operational failures) must be maintained at levels commensurate with business scale and value of assets under custody — assessed on a case-by-case basis.
Key Risks
- While the CBB framework is mature and pragmatic, the rules distinguish between the SaaS operator (licensed custodian) and the white-label client — AML obligations for end-user onboarding may sit with the white-label client depending on how the relationship is structured, creating ambiguity.
- Insurance requirements are assessed case-by-case (not fixed amounts), creating uncertainty in compliance costs and adequacy.
- Cold-storage policies (proportion of assets) are left to operator discretion with documented justification — regulatory scrutiny of these policies may increase over time.
- Travel Rule implementation and cross-border data flows for hosted wallets present operational complexity.
- OFAC/EU sanctions screening is best practice for international operations but not explicitly mandated by Bahraini law for purely domestic flows — inconsistent application creates enforcement risk.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Authorization: Obtain a license from the CBB.
Legal Entity: Must be incorporated in Bahrain.
Minimum Capital: Maintain adequate financial resources. For a Class 4 (Custody) license, the minimum paid-up capital is BD 50,000 (approx. USD 132,600), plus additional operational risk capital requirements based on a risk assessment (CR-1.3.1).
Absolute Segregation: Crypto-asset platform operators must ensure that client crypto-assets are held separate from their own crypto-assets and are clearly identifiable as client assets (CRY-5.1.1).
No Commingling: Client crypto-assets must not be commingled with the operator's proprietary assets (CRY-5.1.2).
Trust Arrangement: Client crypto-assets must be held in trust for the clients (CRY-5.1.3).
Prohibition on Use: Operators are prohibited from using client crypto-assets for their own account or for the benefit of any other client without explicit, written client consent and regulatory approval (CRY-5.1.4).
Reconciliation: Regular reconciliation of client crypto-assets with internal records is mandated (CRY-5.1.5).
Robust Security: Operators must implement robust security measures for the custody of crypto-assets (CRY-4.2.1).
Significant Proportion in Cold Storage: This includes the use of cold storage (offline storage) for a significant proportion of client assets (CRY-4.2.1).
Policy & Procedures: Operators are required to have documented policies and procedures for determining the appropriate proportion of assets to be held in cold storage, taking into account factors such as asset type, liquidity needs, and the overall risk profile (CRY-4.2.2).
A crypto-asset platform operator should maintain appropriate risk management and, where required by its business model, adequate insurance or equivalent financial protections for client-asset safekeeping risks such as cyber incidents, theft, fraud, and operational failures; current U.S. regulatory guidance emphasizes safe-and-sound operations and broader risk controls rather than a universal standalone insurance mandate.
The CBB expects the coverage to be commensurate with the scale and nature of the operator's business and the value of assets under custody. Specific monetary amounts are not typically fixed in the rulebook but are assessed on a case-by-case, risk-based approach.
VASP: CASP License from CBB: Category 1 (Exchange): BHD 100,000 (~$265K USD) + BHD 50,000 reserve. Category 2 (Brokerage): BHD 25,000. Category 3 (Custodian): BHD 100,000 + BHD 50,000 reserve. Category 4 (Advisory): BHD 25,000. 3-6 months. CBB pragmatic and accessible.
CUSTODY: Category 3 Crypto Custodian license — BHD 100,000 minimum capital + BHD 50,000 reserve. Client asset segregation. Minimum insurance.
Bahrain’s primary AML/CFT statute is Decree‑Law No. (4) of 2001 on the Prohibition and Combating of Money Laundering and Terrorist Financing, as amended, most recently by Decree‑Law No. (36) of 2025.
Identification and Verification:
Obtain name, permanent address, date of birth, nationality, and an official identification number (e.g., CPR/National ID, passport number).
Verify identity using reliable, independent source documents (e.g., government-issued photo ID, passport) and proof of address (e.g., utility bill).
Legal Entities (Companies, Partnerships, etc.):
Identify and verify the identity of the beneficial owner(s) (any natural person owning or controlling 10% or more of shares/voting rights, or otherwise exercising control).
Understand the purpose and intended nature of the business relationship or the occasional transaction.
Assess and, on an ongoing risk‑based and event‑driven basis, reassess the customer’s risk profile using collected and updated customer information, including beneficial ownership information, as part of the institution’s customer due diligence obligations.
The regulation regarding 'Source of Funds and Source of Wealth (SoF/SoW)' in Bahrain has been updated, reflecting more robust risk assessment methodologies.
Bahraini law and Central Bank of Bahrain (CBB) regulations require financial institutions, including VASPs, to comply with UN Security Council sanctions and with Bahrain’s own AML/CFT and terrorism‑financing measures, which include domestic designations and restrictions. This framework obliges institutions to freeze assets and prohibit transactions involving individuals and entities designated under applicable UN resolutions and corresponding Bahraini laws, ministerial orders, and CBB directives, not just UN lists alone.
Under the Central Bank of Bahrain Rulebook, Volume 6 (Capital Markets), the relevant sanctions/terrorism‑financing obligation is contained in Module AML: Anti‑Money Laundering & Combating of Financial Crime, not in a separate Module FC. The Module AML imposes requirements on Capital Market Service Providers to implement effective AML/CFT measures in line with FATF recommendations, including compliance with applicable UN Security Council resolutions on terrorism, proliferation, and related asset freezing; however, there is no Section FC‑1.1.1 (UN Sanctions) in a Volume 6 'Module FC (Financial Crime)' as cited.
Mandatory Screening: Licensed VASPs must screen all customers (initial onboarding and ongoing), beneficial owners, and transactions against:
UN Sanctions Lists: Specifically the Consolidated List maintained by the UNSC 1267/1989/2253 ISIL (Da'esh) & Al-Qaida Sanctions Committee and the UNSC 1988 Taliban Sanctions Committee List, as well as other relevant UN sanctions lists.
National Sanctions Lists of Bahrain: This includes lists of designated terrorists and terrorist organizations issued by the Kingdom of Bahrain's competent authorities.
Ongoing Monitoring: Screening is not a one-time event. VASPs must conduct ongoing monitoring to identify if existing clients or parties to transactions subsequently appear on sanctions lists.
Risk-Based Approach (FATF Recommendations): VASPs must implement a risk-based approach to customer due diligence (CDD). Higher-risk jurisdictions (e.g., those identified by FATF as having strategic AML/CFT deficiencies) will trigger enhanced due diligence measures. If the risks cannot be mitigated, the VASP may choose to restrict or prohibit business relationships with customers or transactions originating from/destined for such regions.
Travel Rule: The CBB has implemented the FATF's "Travel Rule," requiring VASPs to obtain and transmit originator and beneficiary information for crypto transfers above a certain threshold. This enhances the ability to identify cross-border transactions involving high-risk jurisdictions or sanctioned entities.
Fines (can be substantial).
VASP Best Practice: Given the interconnectedness of the crypto ecosystem and the potential for severe penalties, prudent VASPs in Bahrain handling international transactions or onboarding international clients will incorporate OFAC, EU, and other major international sanctions lists into their screening processes.
Virtual asset service providers in Bahrain are regulated under the Central Bank of Bahrain Rulebook, specifically through the Crypto-Asset (CRA) Module in Volume 6 (Capital Markets), which sets out licensing categories, prudential, conduct, technology, and ongoing compliance requirements for crypto-asset service providers operating in or from Bahrain, alongside cross‑referenced modules (e.g., AML/CFT, outsourcing, conduct) in the wider CBB Rulebook.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators are permitted in Bahrain under a Category 3 (Custodian) Crypto-Asset Service Provider license from the CBB, requiring local incorporation, BHD 100,000 minimum capital plus BHD 50,000 reserve, strict client asset segregation and trust arrangements, cold-storage mandates, risk-based insurance, and comprehensive AML/CFT obligations including Travel Rule implementation.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?