Custodial wallet / SaaS in Burundi
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is not permitted in Burundi.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- No lawful crypto operations exist, but if hypothetically permitted, general AML/CFT Law N°1/01 of 04 January 2011 would apply, requiring customer identification and verification
- Ongoing monitoring and scrutiny of transactions throughout the business relationship
- Suspicious Transaction Reporting (STR) to the Financial Intelligence Unit (FIU) — no de minimis threshold; any suspicious transaction must be reported
- No-tipping-off prohibition
- Record-keeping of identification documents, account files, and transaction data
- Risk-based CDD with simplified (SCDD) and enhanced (ECDD) measures available
- Screening against sanctions lists and PEPs
- Travel Rule equivalent expectations under FATF Recommendation 15 would apply if VASP framework existed
Key Restrictions
- Cryptocurrency-related activities are explicitly prohibited for financial institutions under BRB Communiqué N° BRB/DGD/2021-002 (Dec 2021)
- Providing crypto custody services is prohibited
- Cryptocurrencies are not recognized as legal tender and are not regulated by the BRB — no legal protection for users
- No regulatory framework exists for licensed crypto custodians, qualified custodians, or custodial wallet providers
- No segregation, insurance, bonding, cold storage, or proof-of-reserves requirements exist or can be complied with, as the activity itself is banned
Key Risks
- Complete prohibition of crypto custody services means any operation would be unlawful
- Potential enforcement under existing financial market laws (Law No. 1/01 of Jan 20, 2011) and AML laws for unauthorized financial activities
- No path to legal compliance — no licensing regime exists for crypto custodians
- Low market adoption and limited public reporting on enforcement, but risk of action by BRB and FIU is real
- Operators could face penalties, asset seizures, or criminal charges under general AML and financial regulation statutes
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Cryptocurrency custody in Burundi is prohibited by law, thus no specific insurance or bonding requirements are mandated for cryptocurrency custodians.
None Specified: Given the lack of specific crypto regulation, there are no explicit rules or mandates for the segregation of client digital assets from the custodian's own assets. In traditional finance, this is a cornerstone of investor protection, but it has not been extended to digital assets in Burundi's legal framework.
Cryptocurrency custody in Burundi is prohibited by law, thus no specific insurance or bonding requirements are mandated for cryptocurrency custodians.
Cryptocurrencies are not recognized as legal tender in Burundi.
They are not regulated by the BRB, meaning there is no legal protection for users or investors.
Financial institutions are explicitly prohibited from engaging in cryptocurrency-related activities.
Custody Providers: Providing crypto custody services is prohibited.
Communiqué N° BRB/DGD/2021-002 du 16 Décembre 2021 de la Banque de la République du Burundi (Bank of the Republic of Burundi Communiqué No. BRB/DGD/2021-002 of December 16, 2021).
Bank of the Republic of Burundi Communiqué (March 2019): This is the most significant regulatory action. The BRB issued a communiqué warning the public against the use and trading of virtual currencies, highlighting the risks of fraud, money laundering, terrorist financing, and market manipulation. It explicitly stated that cryptocurrencies are not recognized as legal tender or a regulated financial product in Burundi and that local banks and financial institutions are prohibited from facilitating transactions involving them. This communal acts as a de facto ban within the formal financial system.
Law N°1/01 of 04 January 2011 on Anti-Money Laundering and Combating the Financing of Terrorism. This law, along with its implementing decrees and ordinances, establishes the general framework for identifying, reporting, and prosecuting money laundering and terrorist financing activities.
Subsequent Amendments and Regulations: The law is subject to updates and specific regulations issued by relevant authorities, primarily the Financial Intelligence Unit (FIU) and the Central Bank.
Identification and verification of beneficial owners under FinCEN’s CDD Rule is risk‑based and may be limited by covered financial institutions, rather than being an unconditional, blanket requirement for all federal business relationships.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying a risk-based approach, meaning:
Reporting Thresholds: While specific thresholds might exist for certain fiat transactions, the primary obligation is to report any transaction (regardless of amount) that is suspected of being related to money laundering or terrorist financing.
No Tipping-Off: Obliged entities, their directors, officers, and employees are prohibited from disclosing to the customer or any third party that a STR has been or will be submitted.
Under FATF Recommendation 15 and its interpretive note, virtual asset service providers (VASPs) are expected to be explicitly licensed or registered and directly subject to full AML/CFT requirements—including customer due diligence (CDD), record‑keeping, ongoing monitoring, suspicious transaction reporting, and Travel Rule obligations—on the same footing as other regulated financial institutions, rather than having CDD applied only hypothetically or merely ‘by analogy’ if they were formally regulated.
Emerging Regulatory Landscape: Many developing nations, including Burundi, are still in the early stages of establishing comprehensive regulatory frameworks for cryptocurrencies. The focus often remains on issuing warnings and advisories rather than direct, targeted enforcement actions against specific entities.
Central Bank Stance: The primary financial regulator in Burundi is the Banque de la République du Burundi (BRB). Like many central banks in Africa, the BRB has generally adopted a cautious stance towards cryptocurrencies, often stating that they are not recognized as legal tender and advising citizens of the associated risks (volatility, scams, lack of consumer protection). These are regulatory statements but not enforcement actions against specific entities.
Lack of Public Reporting: Even if smaller, localized enforcement actions against individuals or informal crypto operations have occurred (e.g., related to fraud or unlicensed financial activities), they are often not widely reported by international or even national news outlets, especially without significant financial or legal implications.
Law No. 1/01 of January 20, 2011, on the Regulation of the Financial Market: This law (and any subsequent amendments) governs the financial market in Burundi and establishes the Financial Market Authority (AMF). While it doesn't mention crypto, it would be the foundational legal text if crypto assets were ever to be formally regulated as securities.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
No — custodial wallet/SaaS operation is prohibited in Burundi; the BRB has explicitly banned cryptocurrency custody services, financial institutions from dealing in crypto, and no licensing framework exists for digital asset custodians.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?