Custodial wallet / SaaS in Belize
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Belize with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Must obtain and verify customer identity (full name, DOB, nationality, address, government-issued ID) under MLTPA and VASA — bz.aml.identification-and-verification
- For legal persons, must verify legal name, form, proof of existence, ownership structure, and beneficial owners (any natural person with >25% ownership/control) — bz.aml.legal-personsarrangements-eg-companies-trusts
- Must apply risk-based CDD including Simplified CDD for low-risk and Enhanced CDD for high-risk (PEPs, high-risk jurisdictions, complex transactions) — bz.aml.risk-based-approach-vasps-must-apply
- Must conduct ongoing transaction monitoring and regularly update customer information — bz.aml.continuously-monitor-the-business-relationship
- Must report suspicious transactions to the Financial Intelligence Unit (FIU) under MLTPA — bz.aml.financial-intelligence-unit-fiu-of, bz.aml.role-the-fiu-is-the
- Record-keeping obligations: detailed and accurate records of all client virtual assets with clear ownership identification — bz.custody.record-keeping-detailed-and-accurate-records
- Must establish AML/CFT policies compliant with MLTPA, VASA, and FATF standards — bz.custody.amlcft-compliance-robust-anti-money-laundering
- Source of funds/wealth must be established for higher-risk customers or transactions — bz.aml.source-of-fundswealth-for-higher-risk
Key Restrictions
- Must be licensed under the Digital Asset Services Licensing Regulations, 2025 and VASA 2024 by the Financial Services Commission (FSC) — bz.custody.virtual-assets-services-act-2024, bz.custody.application-process-submission-of-a
- Must meet minimum paid-up capital requirements that vary based on services offered — bz.custody.minimum-capital-requirements-vasps-must
- Client virtual assets must be held in trust/fiduciary capacity, in accounts separate from proprietary assets, with no commingling — bz.custody.separate-accounts-a-licensed-vasp, bz.custody.no-commingling-client-assets-must, bz.custody.trustee-capacity-the-vasp-must
- Directors, senior management, and significant shareholders must pass fit and proper assessment — bz.custody.fit-and-proper-test-directors
- Must submit comprehensive business plan including organizational structure, internal controls, risk management, technology infrastructure, and security measures — bz.custody.business-plan-submission-of-a
- Must implement robust IT/cybersecurity measures to protect virtual assets, client data, and operational integrity — bz.custody.information-technology-it-cybersecurity-implementation
Key Risks
- Regulatory ambiguity: The transition from IFSC to FSC and the supplementation of VASA 2024 by the 2025 Regulations creates uncertainty about which provisions are fully in force — bz.custody.virtual-assets-services-act-2024
- FSC has discretion to impose additional insurance/bonding requirements on individual licensees based on business model and risk profile, creating unpredictability — bz.custody.ifsc-discretion-the-ifsc-may
- Information asymmetry: Facts note that FSC/IFSC website should host latest guidance, but old links may still point to superseded acts — bz.custody.current-public-information-page-check
- AML obligations for the SaaS provider vs white-label client are not clearly delineated in provided facts; risk of regulatory overlap and dual liability
- Enforcement precedent is thin given the recency of the 2024/2025 regulatory framework — confidence reduced
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Belize's Virtual Assets Services Act, 2024 remains in force, but its security, operational resilience, and risk management sections are now supplemented and partially superseded by the Digital Asset Services Licensing Regulations, 2025, which imposes a new licensing framework that overrides earlier provisions.
International Financial Services Commission (Virtual Assets) Regulations, 2024
Application Process: Submission of a detailed application to the Financial Services Commission (FSC), formerly the IFSC.
Fit and Proper Test: Directors, senior management, and significant shareholders must undergo a "fit and proper" assessment, considering their competence, integrity, and financial soundness.
Minimum Capital Requirements: VASPs must meet prescribed minimum paid-up capital requirements, which are stipulated in the Regulations and vary depending on the services offered.
Business Plan: Submission of a comprehensive business plan detailing operations, organizational structure, internal controls, risk management framework, technology infrastructure, and security measures.
AML/CFT Compliance: Robust Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) policies and procedures must be in place, compliant with Belizean laws (e.g., Money Laundering and Terrorism (Prevention) Act) and international FATF standards. This includes customer due diligence (CDD), record-keeping, suspicious transaction reporting, and internal controls.
Risk Management Framework: Detailed policies for identifying, assessing, monitoring, and mitigating risks associated with virtual asset services, including technological, operational, cybersecurity, and market risks.
Corporate Governance: Establishment of sound corporate governance arrangements, including clear lines of responsibility, oversight by the board, and internal audit functions.
Information Technology (IT) & Cybersecurity: Implementation of robust IT systems and cybersecurity measures to protect virtual assets, client data, and operational integrity.
Separate Accounts: A licensed VASP providing custody services must hold client virtual assets in accounts separate from its own assets.
No Commingling: Client assets must not be commingled with the VASP's proprietary assets.
Trustee Capacity: The VASP must hold client virtual assets in trust or a similar fiduciary capacity, ensuring they are protected in the event of the VASP's insolvency or bankruptcy.
Record-Keeping: Detailed and accurate records of all client virtual assets must be maintained, clearly identifying ownership.
Financial Resources: VASPs are expected to maintain adequate financial resources, including sufficient capital, to cover operational risks and potential liabilities.
Risk Management: The comprehensive risk management framework required will likely necessitate considerations for covering potential losses due to cyber-attacks, operational failures, or misconduct. This often implies the need for appropriate insurance coverage (e.g., cybersecurity insurance, professional indemnity insurance), even if not explicitly mandated for a specific amount in the law.
IFSC Discretion: The IFSC may, at its discretion, impose specific insurance or bonding requirements on individual licensees based on their business model, scale of operations, and risk profile.
Robust Security Measures: Licensed VASPs must implement stringent security measures to protect virtual assets from theft, loss, or unauthorized access. This includes cybersecurity protocols, cryptographic security, access controls, and data integrity.
Financial Intelligence Unit (FIU) of Belize
Role: The FIU is the central national agency responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs) to law enforcement agencies.
Virtual Asset Services Act, 2023 (VASA)
Money Laundering and Terrorism (Prevention) Act (MLTPA) [Revised Edition 2011 & subsequent amendments]:
Legal Persons/Arrangements (e.g., companies, trusts):
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship (e.g., why the customer wants to use the VASP's services, expected transaction volumes and types).
Source of Funds/Wealth: For higher-risk customers or transactions, VASPs must take reasonable measures to establish the source of funds or source of wealth.
Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: VASPs must apply a risk-based approach to CDD, meaning that the intensity and nature of CDD measures should be commensurate with the money laundering and terrorism financing risks identified. This involves:
Simplified CDD (SCDD): For lower-risk situations, if permitted by regulations.
Enhanced CDD (ECDD): For higher-risk situations, such as customers from high-risk jurisdictions, Politically Exposed Persons (PEPs), or complex transactions. This includes obtaining additional information, increased frequency of monitoring, and requiring senior management approval for establishing or continuing relationships.
The primary regulator for financial services in Belize, including licensing and oversight of investment businesses, securities dealing, and collective investment schemes, is now the Financial Services Commission (FSC), which replaced the International Financial Services Commission (IFSC).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers can operate in Belize but must obtain a VASP license from the FSC under the VASA 2024 / 2025 Regulations, establish a local entity, meet minimum capital requirements, implement full AML/CFT programs with CDD/STR obligations to the FIU, and hold client assets in segregated trust accounts with no commingling.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?