DeFi protocol frontend in Bahrain
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Bahrain with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CASP licensing required — a DeFi frontend that takes fees, screens users, or aggregates/executes transactions on behalf of users would likely be classified as a Category 1 (Exchange) or Category 2 (Brokerage) CASP under CBB Rulebook Volume 6 — Crypto-Asset Module, requiring BHD 25,000–100,000 minimum capital + BHD 50,000 reserve for Category 1.
- Full CDD/EDD obligations apply — must obtain name, permanent address, date of birth, nationality, official ID number (CPR/National ID, passport) for individuals; legal name, legal form, proof of existence, BO identification (≥10% threshold), ownership and control structure for legal entities.
- Ongoing risk-based CDD — must assess and reassess customer risk profile using collected information, including beneficial ownership information (bh.licensing.assess-the-customers-risk-profile).
- Source of Funds / Source of Wealth obligations apply for higher-risk relationships.
- Mandatory sanctions screening against UN Consolidated Lists (UNSC 1267/1989/2253 ISIL & Al-Qaida, UNSC 1988 Taliban), and Bahrain national sanctions lists (bh.aml.mandatory-screening-licensed-vasps-must).
- Travel Rule compliance required — must obtain and transmit originator/beneficiary information for crypto transfers above threshold (bh.aml.travel-rule-the-cbb-has).
- Ongoing transaction monitoring and periodic screening of existing clients against sanctions lists (bh.aml.ongoing-monitoring-screening-is-not).
- Suspicious Transaction Reports (STRs) must be filed with the CBB's Financial Crime unit as per CBB Law No. 64 of 2006 and Law No. 4 of 2001.
- Penalties for non-compliance: substantial fines, license conditions, suspension/revocation, imprisonment, asset confiscation (bh.aml.fines-can-be-substantial through bh.aml.confiscation-of-assets).
Key Restrictions
- Must be licensed as a CASP (Category 1–4) under CBB Rulebook Volume 6 — Crypto-Asset Module (CRA) before operating any frontend that services Bahrain residents.
- Local entity required — must be incorporated in Bahrain and meet fit-and-proper criteria for directors and senior management (bh.custody.legal-entity-must-be-incorporated).
- If the frontend involves custody or control of user assets (e.g., aggregating swaps via a proxy contract), Category 3 (Custodian) license may apply, requiring BHD 100,000 capital + BHD 50,000 reserve, segregation of client assets in trust, cold storage mandates, and minimum insurance.
- Geofencing / IP blocking likely required for unlicensed operation to exclude Bahrain residents; even a non-custodial frontend that routes transactions on behalf of users likely triggers CASP licensing if it takes fees or screens users.
Key Risks
- Regulatory ambiguity — the CBB framework was designed for centralized VASPs (exchanges, custodians, brokerages) and does not clearly address 'fully decentralized' protocols with a non-custodial, no-fee frontend. A regulator could classify the frontend operator as a CASP regardless of protocol decentralization.
- Enforcement exposure — operating without a CASP license while serving Bahrain residents could trigger CBB enforcement (substantial fines, license conditions, criminal referral). The first licensed exchange (Rain Financial) shows the CBB actively supervises.
- Fee-taking risk — if the frontend takes fees (e.g., routing fees, interface fees), the CBB is far more likely to classify the operator as a Category 1 or 2 CASP, triggering the full licensing burden.
- Sanctions overlap risk — while Bahrain law does not mandate OFAC/EU compliance, practical necessity of USD clearing and international counterparty relations means many VASPs screen OFAC/EU lists anyway; non-compliance carries secondary sanctions risk for international transactions.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CBB — Crypto-Asset Service Provider licensing (4 categories), prudential supervision — first MENA jurisdiction with comprehensive crypto framework (2019)
CBB Rulebook Volume 6 — Crypto-Asset Module (2019) — Comprehensive crypto exchange, custody, brokerage, advisory licensing. Shariah-compliant crypto product guidance available.
VASP: CASP License from CBB: Category 1 (Exchange): BHD 100,000 (~$265K USD) + BHD 50,000 reserve. Category 2 (Brokerage): BHD 25,000. Category 3 (Custodian): BHD 100,000 + BHD 50,000 reserve. Category 4 (Advisory): BHD 25,000. 3-6 months. CBB pragmatic and accessible.
Central Bank of Bahrain (CBB) Official Website: https://www.cbb.gov.bh/
Virtual asset service providers in Bahrain are regulated under the Central Bank of Bahrain Rulebook, specifically through the Crypto-Asset (CRA) Module in Volume 6 (Capital Markets), which sets out licensing categories, prudential, conduct, technology, and ongoing compliance requirements for crypto-asset service providers operating in or from Bahrain, alongside cross‑referenced modules (e.g., AML/CFT, outsourcing, conduct) in the wider CBB Rulebook.
Module RA (Risk Management Module) - Specifically, RA-6 Virtual Asset Regulatory Framework: This module (introduced in 2019) is the cornerstone of VA regulation in Bahrain. It provides specific licensing requirements, operational standards, technological governance, and crucial AML/CFT measures tailored for VASPs. It categorizes virtual assets and defines various VASP activities (e.g., exchange, custody, portfolio management, advisory).
Module FC (Financial Crime) sets out core AML/CFT requirements for specific categories of CBB licensees, with separate FC Modules issued in different CBB Volumes (e.g., for conventional banks, Islamic banks, insurance licensees). VASPs, where regulated by the CBB, must comply with those FC provisions expressly applicable to their licensee category, including requirements on CDD, EDD, suspicious transaction reporting, record‑keeping, and internal controls, rather than a single generic FC module covering all CBB licensees uniformly.
Identification and Verification:
Obtain name, permanent address, date of birth, nationality, and an official identification number (e.g., CPR/National ID, passport number).
Verify identity using reliable, independent source documents (e.g., government-issued photo ID, passport) and proof of address (e.g., utility bill).
Legal Entities (Companies, Partnerships, etc.):
Obtain legal name, legal form, proof of existence (e.g., certificate of incorporation), names of directors and authorized signatories, registered address, and details of principal business activity.
Identify and verify the identity of the beneficial owner(s) (any natural person owning or controlling 10% or more of shares/voting rights, or otherwise exercising control).
Understand the ownership and control structure.
Assess and, on an ongoing risk‑based and event‑driven basis, reassess the customer’s risk profile using collected and updated customer information, including beneficial ownership information, as part of the institution’s customer due diligence obligations.
Bahraini law and Central Bank of Bahrain (CBB) regulations require financial institutions, including VASPs, to comply with UN Security Council sanctions and with Bahrain’s own AML/CFT and terrorism‑financing measures, which include domestic designations and restrictions. This framework obliges institutions to freeze assets and prohibit transactions involving individuals and entities designated under applicable UN resolutions and corresponding Bahraini laws, ministerial orders, and CBB directives, not just UN lists alone.
Mandatory Screening: Licensed VASPs must screen all customers (initial onboarding and ongoing), beneficial owners, and transactions against:
UN Sanctions Lists: Specifically the Consolidated List maintained by the UNSC 1267/1989/2253 ISIL (Da'esh) & Al-Qaida Sanctions Committee and the UNSC 1988 Taliban Sanctions Committee List, as well as other relevant UN sanctions lists.
National Sanctions Lists of Bahrain: This includes lists of designated terrorists and terrorist organizations issued by the Kingdom of Bahrain's competent authorities.
Ongoing Monitoring: Screening is not a one-time event. VASPs must conduct ongoing monitoring to identify if existing clients or parties to transactions subsequently appear on sanctions lists.
Travel Rule: The CBB has implemented the FATF's "Travel Rule," requiring VASPs to obtain and transmit originator and beneficiary information for crypto transfers above a certain threshold. This enhances the ability to identify cross-border transactions involving high-risk jurisdictions or sanctioned entities.
Fines (can be substantial).
Suspension or revocation of the VASP's license.
Legal Entity: Must be incorporated in Bahrain.
Minimum Capital: Maintain adequate financial resources. For a Class 4 (Custody) license, the minimum paid-up capital is BD 50,000 (approx. USD 132,600), plus additional operational risk capital requirements based on a risk assessment (CR-1.3.1).
Authorization: Obtain a license from the CBB.
Absolute Segregation: Crypto-asset platform operators must ensure that client crypto-assets are held separate from their own crypto-assets and are clearly identifiable as client assets (CRY-5.1.1).
Robust Security: Operators must implement robust security measures for the custody of crypto-assets (CRY-4.2.1).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend that services Bahrain residents is likely regulated as a CASP under CBB Rulebook Volume 6, requiring a full CASP license (Category 1–4 depending on fee-taking and custody), local incorporation, comprehensive CDD/KYC, sanctions screening, Travel Rule compliance, and geofencing for unlicensed operations; however, the CBB framework does not have explicit guidance for 'fully non-custodial, no-fee' DeFi frontends, creating moderate regulatory ambiguity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?