DeFi protocol frontend in Bhutan
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is not permitted in Bhutan.
Verdict Details
- Permitted
- no
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD: must collect name, date of birth, nationality, unique ID number (citizenship ID), residential address for individuals (bt.aml.identification-and-verification, bt.aml.individuals-collecting-and-verifying-the)
- CDD: for legal persons, collect legal name, legal form, proof of existence, governing powers, registered address, directors/senior management (bt.aml.legal-personsentities-eg-companies-collecting)
- Beneficial ownership identification and verification required (bt.aml.beneficial-ownership-identifying-and-verifying)
- Purpose and intended nature of business relationship must be understood (bt.aml.purpose-and-intended-nature-of)
- Ongoing due diligence and transaction monitoring required (bt.aml.ongoing-due-diligence-conducting-ongoing)
- Risk-based approach: Simplified CDD, Standard CDD, and Enhanced CDD (EDD) for PEPs/high-risk situations (bt.aml.risk-based-approach-applying-cdd-measures, bt.aml.simplified-cdd-for-lower-risk-situations, bt.aml.standard-cdd-for-typical-relationships, bt.aml.enhanced-cdd-edd-for-higher-risk)
- STR obligation: any transaction with reasonable grounds to suspect ML/TF must be reported to the FIU (bt.aml.obligation-to-report-any-transaction)
- No tipping-off rule applies (bt.aml.no-tipping-off-reporting-entities-and)
- Recordkeeping: 5-year minimum retention for customer ID data, transaction records, and correspondence (bt.aml.customer-identification-data-records-of, bt.aml.transaction-data-records-of-all, bt.aml.correspondence-records-of-business-correspondence, bt.aml.duration-records-must-generally-be)
- FATF Travel Rule likely expected for virtual asset transfers (bt.aml.fatf-travel-rule-the-fatfs)
Key Restrictions
- Crypto trading for the general public is heavily restricted and effectively prohibited through the formal financial system (bt.licensing.crypto-trading-for-the-general)
- No licensed or regulated crypto exchanges operate for the public within Bhutan; any involvement is outside the formal financial system (bt.licensing.crypto-exchanges-there-are-no)
- The RMA has issued circulars effectively prohibiting licensed financial institutions from processing virtual-asset transactions (bt.licensing.rma-circulars-and-public-notices)
- No distinct regulatory framework exists for private crypto/VASP activities for the general public — the RMA stance is prohibitive (bt.licensing.for-the-public-and-licensed)
- A frontend taking fees could be characterized as providing financial services requiring licensing under the Financial Institutions Act / Financial Services Amendment Bill (bt.aml.licensing-as-of-current-public)
- Even a non-custodial frontend that does not hold user funds likely falls within the broad prohibition on facilitating virtual asset access for the public
Key Risks
- Operating a DeFi frontend for Bhutanese residents without explicit permission carries significant risk of operating outside the formal financial system (bt.licensing.crypto-exchanges-there-are-no)
- The RMA's prohibitive stance means any facilitation of crypto for the public may be treated as unlicensed financial activity
- Enforcement action or compelled shutdown by the RMA is possible given the absence of any licensing pathway for public-facing crypto services
- The government's own involvement in crypto (via DHI mining) creates a selective, state-controlled environment — private operators face a different, restrictive regime (bt.licensing.for-state-owned-entities-in-contrast)
- Fee-taking increases the likelihood the activity is characterized as a regulated financial service
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
For the Public and Licensed Financial Institutions: The Royal Monetary Authority of Bhutan (RMA) has adopted a cautious and prohibitive stance. There is no legal framework to permit or regulate private crypto trading, exchanges, or virtual asset service providers (VASPs) for the general public. Licensed financial institutions (banks, non-bank financial institutions) are generally prohibited from dealing with virtual assets, processing transactions related to them, or providing services to crypto businesses. This effectively acts as a de facto ban on public participation in the unregulated crypto market.
For State-Owned Entities: In contrast, Bhutan has strategically engaged with cryptocurrency through Druk Holdings & Investments (DHI), the sovereign wealth fund. DHI has been involved in Bitcoin mining and holds significant crypto assets, indicating a state-controlled, strategic adoption rather than an open market approach.
Royal Monetary Authority of Bhutan (RMA):
RMA Circulars and Public Notices: The RMA has issued warnings and advisories to the public and financial institutions concerning the risks of cryptocurrencies, highlighting their unregulated nature, volatility, and potential for fraud and money laundering. These directives effectively prohibit licensed financial institutions from facilitating crypto-related transactions. Specific circular numbers and dates are often for internal circulation or specific institutions, but the general public advisories are consistent.
Crypto Trading: For the general public in Bhutan, crypto trading is heavily restricted and effectively prohibited through the formal financial system. The RMA's stance discourages and prevents licensed financial institutions from processing transactions related to virtual assets. This means individuals cannot easily buy or sell cryptocurrencies via traditional banking channels within Bhutan.
Crypto Exchanges: There are no licensed or regulated cryptocurrency exchanges operating for the public within Bhutan. The regulatory environment does not support their establishment or operation for public access. Any involvement would be considered operating outside the formal financial system and could carry significant risks for participants.
Identification and Verification:
Individuals: Collecting and verifying the customer's name, date of birth, nationality, unique identification number (e.g., citizenship ID), residential address. This typically involves using reliable, independent source documents, data, or information.
Legal Persons/Entities (e.g., companies): Collecting and verifying the legal name, legal form, proof of existence, powers governing the entity, address of registered office, and names of directors and senior management.
Beneficial Ownership: Identifying and verifying the natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.
Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.
Ongoing Due Diligence: Conducting ongoing monitoring of the business relationship and transactions to ensure they are consistent with the entity's knowledge of the customer, their business, and risk profile, including the source of funds.
Risk-Based Approach: Applying CDD measures based on the risk associated with the customer, product, service, or jurisdiction. This means:
Simplified CDD: For lower-risk situations.
Standard CDD: For typical relationships.
Enhanced CDD (EDD): For higher-risk situations, such as customers from high-risk jurisdictions, Politically Exposed Persons (PEPs), or complex transactions. EDD would involve obtaining additional information, increasing transaction monitoring, and obtaining senior management approval.
Obligation to Report: Any transaction (regardless of amount) where there are reasonable grounds to suspect that it may be linked to money laundering, terrorist financing, or other criminal activity must be reported.
No Tipping-Off: Reporting entities and their employees are prohibited from disclosing to the customer or any third party that an STR has been or will be filed.
Customer Identification Data: Records of all customer identification and verification documents (e.g., copies of ID, beneficial ownership information).
On-chain data shows Bhutan's government has conducted regular Bitcoin transactions (e.g., 90 BTC transfers) with total outflows exceeding $237 million in 2026, but the government has stated it does not recall selling any bitcoin, indicating a lack of comprehensive, reconstructable transaction records.
Correspondence: Records of business correspondence relating to customers.
Duration: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.
FATF "Travel Rule": The FATF's Interpretive Note 15 (Recommendation 16) requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers. While not explicitly codified in Bhutanese law for VASPs, the RMA would likely expect VASPs to comply with this as part of their broader AML/CFT obligations, consistent with international standards.
Licensing: As of current public information, Bhutan does not have a distinct licensing framework specifically for VASPs. However, depending on the nature of their activities (e.g., if they provide services similar to traditional financial institutions), they may be required to obtain a license under the Financial Institutions Act or operate under specific regulatory guidance from the RMA.
Royal Monetary Authority of Bhutan (RMA): The central bank and primary financial regulator.
No specific "digital asset custody license" currently exists.
Public information exists on specific pending digital asset custody legislation in Bhutan, as BTSE Bhutan received in-principle approval for a digital asset trading and custody services license in May 2026.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
No — operating a DeFi protocol frontend accessible to the general public in Bhutan is effectively prohibited; the RMA has no licensing pathway for private VASP activities, formal financial institutions are barred from processing crypto transactions, and any such operation would be outside the formal financial system with significant enforcement risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?