Custodial wallet / SaaS in Botswana
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Botswana with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must appoint a qualified AML/CFT Compliance Officer approved by NBFIRA (bw.licensing.amlcft-compliance-officer-appointment-of)
- Implement customer due diligence (CDD) for all customers: verify identity (national ID/passport), residential address, source of funds/wealth (bw.aml.identification-and-verification-of-customers, bw.aml.national-identity-number-eg-omang, bw.aml.source-of-funds-and-source)
- For legal entity customers: verify registration number, legal form, directors, constitutive documents, and beneficial owners owning ≥25% (bw.aml.legal-entitiesarrangements-eg-companies-trusts, bw.aml.beneficial-ownership-identification, bw.aml.for-legal-persons-this-typically)
- Apply Enhanced Due Diligence (EDD) for higher-risk customers or transactions (bw.licensing.enhanced-due-diligence-edd-applying)
- Maintain records of customer identification, transactions, and business correspondence for at least 5 years (bw.licensing.record-keeping-maintaining-records-of)
- Monitor transactions throughout the business relationship consistently with customer risk profile (bw.aml.ongoing-due-diligence-and-monitoring, bw.aml.monitoring-the-business-relationship-and)
- Report suspicious transactions to the Financial Intelligence Agency (FIA) under the Financial Intelligence Act No. 17 of 2019 (bw.aml.financial-intelligence-act-fia-no)
- Comply with NBFIRA's Guidance Notes on AML/CFT for VASPs and the Proceeds of Serious Crime Act (POCA) (bw.aml.nbfiras-virtual-assets-business-regulatory, bw.aml.proceeds-of-serious-crime-act)
- Sanctions screening obligations enforced through the FIA Act and Ministry regulations giving effect to international obligations (bw.enforcement.legal-basis-this-obligation-is)
Key Restrictions
- Must be incorporated in Botswana as a company under the Companies Act and maintain a physical office in Botswana (bw.licensing.legal-entity-and-local-presence, bw.licensing.applicants-must-be-a-company, bw.licensing.they-must-maintain-a-physical)
- Senior management and key personnel must be based in Botswana or demonstrate sufficient local oversight (bw.licensing.senior-management-and-key-personnel)
- Minimum unimpaired capital: BWP 500,000 for a Principal VASP License (full range of activities); BWP 200,000 for a Limited VASP License (narrower scope) (bw.licensing.principal-vasp-license-bwp-500000, bw.licensing.limited-vasp-license-bwp-200000)
- NBFIRA may require a security deposit or other financial guarantees in addition to capital (bw.licensing.in-addition-to-capital-nbfira)
- Must implement measures to safeguard virtual assets under custody against theft, loss, or damage (bw.custody.section-151a-requires-a-licensed)
- Must maintain adequate and appropriate systems of control and procedures for proper administration — broad enough to require client asset segregation (bw.custody.section-15-requires-a-licensed)
- Must implement a robust IT framework managing cybersecurity and operational resilience — may include cold storage ratios (bw.custody.section-151b-requires-a-vasp)
- Detailed operational requirements (security measures for private keys, segregation, capital adequacy, insurance) are expected via future NBFIRA directives and practice notes (bw.custody.section-18-grants-nbfira-the, bw.custody.nbfira-directives-regulations-and-guidelines, bw.custody.detailed-operational-requirements-eg-specific, bw.custody.further-clarification-on-client-asset)
- The Botswana Cybersecurity Bill, 2025 establishes legally enforceable risk management (cybersecurity and disaster recovery) requirements for financial services and critical infrastructure (bw.custody.specific-requirements-for-risk-management)
Key Risks
- AML/CFT framework is still being reformed to address identified weaknesses — regulatory expectations may shift during the licensing process (bw.licensing.amlcft-anti-money-laundering-counter-financing-of)
- Detailed custody rules (cold storage ratios, insurance mandates, specific segregation mechanics) are not yet in finalised subsidiary legislation — operators face implementation uncertainty until NBFIRA issues directives (bw.custody.nbfira-directives-regulations-and-guidelines)
- NBFIRA has a track record of public warnings against unregistered VASPs — operating without a license carries significant enforcement exposure (bw.enforcement.nbfira-advisory-on-virtual-assets)
- The Botswana Cybersecurity Bill, 2025 introduces new legally binding obligations that may overlap with or extend beyond VASP-specific custody rules, creating compliance complexity (bw.custody.specific-requirements-for-risk-management)
- White-label SaaS structure creates ambiguity around which party (SaaS provider vs. white-label client) bears primary CDD/AML obligations — the VASP license sits on the custodian, but client-facing obligations may flow through contractual allocation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Section 5: Prohibits any person from carrying on a virtual asset business or virtual assets service without a license issued by NBFIRA.
Section 3 (Definitions): Defines a "virtual asset service provider" (VASP) to include any person who, as a business, "provides custody or administration of virtual assets or instruments enabling control over virtual assets."
Sections 6-10: Outline the application process for a license, including requirements such as:
Section 15: Requires a licensed VASP to "at all times maintain adequate and appropriate systems of control and procedures for the proper administration of its affairs." This provision is broad enough to encompass requirements for client asset segregation to prevent co-mingling and protect client funds in case of VASP insolvency.
Section 15(1)(a): Requires a licensed VASP to "implement appropriate measures to safeguard the virtual assets under its custody or control against theft, loss, or damage."
Section 15(1)(b): Requires a VASP to "implement a robust information technology framework to manage risks, including cybersecurity and operational resilience."
Section 15(1)(d): Requires a VASP to "at all times maintain adequate financial resources for the proper performance of its functions." While not directly mandating insurance, adequate financial resources could implicitly cover potential liabilities.
Section 18: Grants NBFIRA the power to issue directives and practice notes to VASPs concerning various matters, which would include detailed operational requirements like asset segregation.
NBFIRA Directives, Regulations, and Guidelines: NBFIRA is mandated by the Act to develop and issue subsidiary legislation, directives, and guidelines to fully implement its provisions. These future instruments are expected to provide the granular detail for aspects like:
Detailed operational requirements (e.g., specific security measures for private keys, possibly including cold storage ratios).
Further clarification on client asset protection and segregation.
Specific capital adequacy or insurance requirements.
The Botswana Cybersecurity Bill, 2025, establishes specific, legally enforceable requirements for risk management in custody, including cybersecurity and disaster recovery, for financial services and critical infrastructure.
Legal Entity and Local Presence:
Applicants must be a company incorporated in Botswana under the Companies Act.
They must maintain a physical office in Botswana.
Senior management and key personnel are expected to be based in Botswana or demonstrate sufficient local oversight.
Principal VASP License: BWP 500,000 (Botswana Pula) in unimpaired capital. This typically covers the full range of VASP activities.
Limited VASP License: BWP 200,000 in unimpaired capital. This may be for VASPs with a narrower scope of activities or those determined by NBFIRA to pose lower risk.
In addition to capital, NBFIRA may require a security deposit or other financial guarantees to protect clients.
AML/CFT Compliance Officer: Appointment of a qualified and experienced AML/CFT Compliance Officer, approved by NBFIRA, who reports to senior management and the Board.
Customer Due Diligence (CDD): Implementing strong CDD measures for all customers, including identifying and verifying the identity of natural and legal persons, and beneficial owners.
Enhanced Due Diligence (EDD): Applying EDD for higher-risk customers or transactions.
Record Keeping: Maintaining records of customer identification data, transaction data, and business correspondence for at least 5 years.
Botswana is actively tightening its AML/CFT financial sanctions regime to address identified weaknesses, indicating the framework is being reformed rather than remaining a stable cornerstone already fully aligned with FATF standards.
Financial Intelligence Act (FIA), No. 17 of 2019: This Act establishes the Financial Intelligence Agency (FIA) and outlines the obligations of accountable institutions (which now explicitly include VASPs) regarding customer due diligence, record-keeping, and suspicious transaction reporting. It replaced the 2009 Act.
Proceeds of Serious Crime Act (POCA), Cap 08:06: This is the overarching legislation that criminalizes money laundering and terrorist financing, and provides for the confiscation of proceeds of crime.
NBFIRA's Virtual Assets Business Regulatory Framework and Guidance Notes: NBFIRA has issued a comprehensive framework and specific guidance notes, such as the "Guidance Notes on Anti-Money Laundering and Combating the Financing of Terrorism for Virtual Asset Service Providers" (e.g., published in November 2022), which directly detail AML/CFT obligations for VASPs. These are crucial for specific requirements.
Identification and Verification of Customers:
National identity number (e.g., Omang for citizens), passport number, or other official identification document number.
Source of funds and source of wealth (especially for high-risk customers or large transactions).
Legal Entities/Arrangements (e.g., companies, trusts):
Beneficial Ownership Identification:
For legal persons, this typically means identifying individuals who ultimately own or control 25% or more of the shares or voting rights, or otherwise exercise control over the entity.
Ongoing Due Diligence and Monitoring:
Monitoring the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, risk profile, and, where necessary, the source of funds.
NBFIRA Advisory on Virtual Assets and Virtual Asset Service Providers (July 2021): https://www.nbfira.org.bw/news-media/media-releases/advisory-virtual-assets-and-virtual-asset-service-providers
Legal Basis: This obligation is implicitly enforced through the FIA Act (mandating AML/CFT compliance) and the various regulations issued by the Ministry responsible for foreign affairs, which give effect to international obligations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are classified as VASPs under Botswana's Virtual Assets Act 2025 and must obtain a NBFIRA VASP license (Principal: BWP 500,000 capital, or Limited: BWP 200,000), incorporate locally with a physical office, comply with comprehensive AML/CFT obligations under the FIA and POCA, and meet asset-safeguarding requirements, though detailed custody-specific rules (segregation, insurance, cold storage ratios) await future NBFIRA directives.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?