DeFi protocol frontend in Belize
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Belize with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs are 'reporting entities' under the Money Laundering and Terrorism (Prevention) Act (MLTPA) — must perform CDD including verifying full name, date of birth, nationality, physical address, and government-issued ID
- Enhanced CDD for higher-risk situations (PEPs, high-risk jurisdictions, complex transactions) including source of funds/wealth checks
- Continuous monitoring of business relationships and transactions to ensure consistency with customer risk profile
- Suspicious Transaction Reporting (STR) to the Financial Intelligence Unit (FIU) of Belize
- Risk-based approach required — Simplified CDD (SCDD) for low-risk; Enhanced CDD (ECDD) for high-risk
- Regularly update customer information, especially for high-risk customers
- Record-keeping obligations under MLTPA and VASA
- Beneficial ownership identification — identify any natural person owning >25% or otherwise controlling the entity
Key Restrictions
- Must be licensed as a VASP under the Virtual Assets Services Act, 2023 (VASA) and the Digital Asset Services Licensing Regulations, 2025
- Must have a local entity (incorporation in Belize) to apply for a VASP license
- Directors, senior management, and significant shareholders must pass a 'fit and proper' test
- Minimum paid-up capital requirements apply (vary by services offered)
- Must submit a detailed business plan, AML/CFT policies, risk management framework, and IT/cybersecurity plan
- Fee-taking (e.g., frontend fees on swaps) likely triggers VASP classification — the frontend operator is providing a virtual asset service by facilitating exchange
- If the protocol's tokens are classified as 'investment contracts' (securities), additional securities registration obligations or exemptions may apply under the SIA 2021
- Geofencing US persons may be required per FATF Travel Rule and sanctions compliance obligations
Key Risks
- Regulatory ambiguity: Belize has not issued specific guidance on whether a pure frontend interacting with permissionless smart contracts is itself a VASP, creating legal uncertainty
- Enforcement risk: If the FSC/Belize FIU determines the frontend is facilitating unlicensed VASP activity, operators could face penalties, shutdown orders, or criminal liability
- The 2025 regulations introduce a new licensing framework that supersedes prior regimes — operators must ensure compliance with the latest framework, not just VASA 2024
- Security token classification risk: Any protocol tokens with investment characteristics could be deemed 'investment contracts' under Belizean law, triggering securities registration requirements
- Sanctions exposure: Failure to adequately geofence sanctioned jurisdictions or US persons could result in international enforcement action (OFAC, FATF)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The primary regulator for financial services in Belize, including licensing and oversight of investment businesses, securities dealing, and collective investment schemes, is now the Financial Services Commission (FSC), which replaced the International Financial Services Commission (IFSC).
Financial Intelligence Unit (FIU): Responsible for anti-money laundering (AML) and countering the financing of terrorism (CFT) supervision, including for entities dealing with virtual assets.
Virtual Asset Services Act, 2023 (VASA)
Money Laundering and Terrorism (Prevention) Act (MLTPA) [Revised Edition 2011 & subsequent amendments]:
Legal Persons/Arrangements (e.g., companies, trusts):
Source of Funds/Wealth: For higher-risk customers or transactions, VASPs must take reasonable measures to establish the source of funds or source of wealth.
Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Regularly update customer information, especially for high-risk customers.
Risk-Based Approach: VASPs must apply a risk-based approach to CDD, meaning that the intensity and nature of CDD measures should be commensurate with the money laundering and terrorism financing risks identified. This involves:
Simplified CDD (SCDD): For lower-risk situations, if permitted by regulations.
Enhanced CDD (ECDD): For higher-risk situations, such as customers from high-risk jurisdictions, Politically Exposed Persons (PEPs), or complex transactions. This includes obtaining additional information, increased frequency of monitoring, and requiring senior management approval for establishing or continuing relationships.
Belize's Virtual Assets Services Act, 2024 remains in force, but its security, operational resilience, and risk management sections are now supplemented and partially superseded by the Digital Asset Services Licensing Regulations, 2025, which imposes a new licensing framework that overrides earlier provisions.
International Financial Services Commission (Virtual Assets) Regulations, 2024
Application Process: Submission of a detailed application to the Financial Services Commission (FSC), formerly the IFSC.
Fit and Proper Test: Directors, senior management, and significant shareholders must undergo a "fit and proper" assessment, considering their competence, integrity, and financial soundness.
Minimum Capital Requirements: VASPs must meet prescribed minimum paid-up capital requirements, which are stipulated in the Regulations and vary depending on the services offered.
Business Plan: Submission of a comprehensive business plan detailing operations, organizational structure, internal controls, risk management framework, technology infrastructure, and security measures.
AML/CFT Compliance: Robust Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) policies and procedures must be in place, compliant with Belizean laws (e.g., Money Laundering and Terrorism (Prevention) Act) and international FATF standards. This includes customer due diligence (CDD), record-keeping, suspicious transaction reporting, and internal controls.
Risk Management Framework: Detailed policies for identifying, assessing, monitoring, and mitigating risks associated with virtual asset services, including technological, operational, cybersecurity, and market risks.
Corporate Governance: Establishment of sound corporate governance arrangements, including clear lines of responsibility, oversight by the board, and internal audit functions.
Information Technology (IT) & Cybersecurity: Implementation of robust IT systems and cybersecurity measures to protect virtual assets, client data, and operational integrity.
Investment Tokens (Security Tokens): Tokens explicitly designed to represent a share in a company, a right to dividends, a portion of profits, or an interest in a collective investment scheme or fund. This includes asset-backed tokens (e.g., representing real estate, commodities, or revenue streams).
An investment contract: This is the most crucial category for many crypto tokens. While not explicitly defined further in the context of crypto, an investment contract generally implies:
Registration of Securities: The issuer would typically be required to register the securities with the IFSC, which involves filing a prospectus or offering memorandum that provides detailed disclosure about the issuer, the token, the project, and the risks involved.
Exemptions: Certain exemptions from registration may apply, such as:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend operating in/from Belize must obtain a VASP license under VASA 2023/the 2025 Regulations, incorporate locally, satisfy AML/CDD obligations, and may face securities classification risks depending on token characteristics; Belize has not issued specific guidance on whether a pure non-custodial frontend is a VASP, creating moderate regulatory ambiguity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?