Custodial wallet / SaaS in Central African Republic
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Central African Republic with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must comply with CEMAC Regulation No. 04/22/CM/UMAC/CM (Dec 2022) and COBAC Instruction No. 001/GR/2023 for AML/CFT obligations.
- Customer due diligence (CDD) required on all customers; enhanced due diligence (EDD) for high-risk categories (PEPs, cross-border relationships, high-risk jurisdictions).
- Identification and verification of natural persons (full name, DOB, nationality, physical address, ID numbers) and legal entities (legal form, name, address, directors, beneficial owners).
- Ultimate beneficial ownership (UBO) identification for legal persons.
- Ongoing transaction monitoring throughout the business relationship.
- Suspicious transaction reporting (STRs) to the national FIU (CENTIF) — must be made promptly when funds are suspected to be criminal proceeds or related to terrorist financing; tipping off prohibited.
- Travel Rule obligations apply to transactions exceeding EUR 1,000 (single or linked): collect & transmit originator info (name, physical address, national ID, DOB/POB, wallet address) and beneficiary info (name, physical address, wallet address) to the beneficiary VASP immediately and securely.
- Record-keeping for at least 5 years for all CDD documents, transaction records, and STRs.
- Risk-based procedures for identifying and verifying customers, especially for higher-risk transactions.
- Administrative sanctions (fines, injunctions, public reprimands), license suspension/withdrawal, and referral for criminal prosecution under national AML/CFT laws.
Key Restrictions
- The CEMAC regional regulatory framework (BEAC, COBAC) imposes VASP licensing/supervision requirements, but CAR's national implementation is incomplete — creating legal uncertainty for operators.
- Custodial wallet providers engaging in safekeeping/administration of virtual assets fall under the definition of VASP per Regulation No. 04/22/CM/UMAC/CM.
- The practical implementation of crypto regulation in CAR is deeply entangled with opaque state schemes (Sango Coin) that have drawn IMF and BEAC criticism, creating reputational and compliance risk.
- No clearly defined qualified-custodian or custody-license regime specific to digital assets has been functionally operationalized in CAR.
- Segregation, insurance, and proof-of-reserves rules for custodial wallets are not explicitly addressed in existing frameworks; any such obligations would derive from general VASP prudential requirements yet to be defined by COBAC/BEAC.
Key Risks
- BEAC/COBAC enforcement risk: BEAC has pressured CAR over its crypto law and continues to advise against cryptocurrency engagement, creating a risk of regional sanctions against VASPs operating out of CAR.
- IMF and FATF pressure: CAR's crypto initiatives have been flagged for governance, transparency, and illicit finance concerns, increasing the likelihood of future regulatory crackdown or blacklisting.
- Regulatory ambiguity: The gap between CAR's national law (which embraces crypto) and CEMAC regional regulation (which imposes stringent VASP requirements but is only partially transposed) creates legal uncertainty for custodial wallet operators.
- Sango Coin association risk: Any VASP licensed or operating in CAR risks being associated with the controversial Sango Coin project, deterring institutional clients and counterparties.
- Lack of operational infrastructure: CAR lacks the banking, telecom, and internet infrastructure to support reliable custodial wallet services, and BEAC has warned CEMAC financial institutions against engaging with crypto.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 22.006 of April 27, 2022, on the Regulation of Cryptocurrencies in the Central African Republic:
The 2022 law initially made Bitcoin legal tender in Central African Republic, but was later amended to revoke Bitcoin's legal tender status, while subsequent legislation enabled tokenization of land and natural resources.
Central African Republic has not established functional licensing or supervision of VASPs; rather, it has embraced opaque, unregulated cryptocurrency schemes that risk state asset capture by criminal organizations, with no effective AML/CFT compliance or VASP oversight.
While it creates the framework, it generally defers to further decrees or existing AML/CFT laws for specific requirements.
BEAC Regulation No. 01/17/CEMAC/UMAC/CM of March 30, 2017, on the Prevention and Suppression of Money Laundering and Terrorist Financing in the CEMAC Zone:
As a member of the Economic and Monetary Community of Central Africa (CEMAC), CAR is bound by regional regulations issued by the Banque des États de l'Afrique Centrale (BEAC).
This regulation provides the comprehensive AML/CFT framework for financial institutions within the CEMAC zone. While it predates the explicit regulation of VASPs, the CAR's 2022 crypto law implies that VASPs should adhere to the same stringent AML/CFT requirements as traditional financial institutions, as per FATF Recommendation 15.
This regulation covers customer due diligence, suspicious transaction reporting, and record-keeping obligations for all regulated entities.
Law No. 00-010 of May 8, 2000, on Money Laundering and Terrorist Financing:
Regulation No. 04/22/CM/UMAC/CM of 21 December 2022 concerning the regulation of Virtual Asset Service Providers (VASPs) in the CEMAC zone.
This regulation is further complemented by an instructional circular from the Banking Commission of Central Africa (COBAC), which is the primary supervisor for financial institutions in CEMAC:
Instruction No. 001/GR/2023 of 31 January 2023 from COBAC on the practical implementation of certain provisions of Regulation No. 04/22/CM/UMAC/CM.
Regulation No. 04/22/CM/UMAC/CM came into effect upon its publication on 21 December 2022.
The COBAC Instruction No. 001/GR/2023, providing implementation guidance, was effective from 31 January 2023.
While national transposition into CAR-specific law might still be ongoing or subject to internal processes, the regional directive and COBAC's instruction mandate compliance from VASPs operating in CAR as of these dates.
Exceeds EUR 1,000 (or its equivalent in XAF or other currency) for transactions conducted by VASPs.
This threshold applies to both single transactions and linked transactions.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Collect and retain the following information for transactions above the threshold:
Originator Information: Name, physical address, national identity number (or customer identification number), date and place of birth, and virtual asset wallet address (or unique transaction identifier).
Beneficiary Information: Name, physical address, virtual asset wallet address (or unique transaction identifier).
Transmit this information to the beneficiary VASP, where applicable, immediately and securely.
Maintain records of all collected information for at least five (5) years.
Implement risk-based procedures to identify and verify the identity of customers, especially for higher-risk transactions or relationships.
Administrative sanctions: Fines, injunctions, public reprimands.
Withdrawal or suspension of operating licenses for VASPs.
Referral to national judicial authorities for criminal prosecution under national AML/CFT laws, which can lead to imprisonment and substantial monetary fines for individuals and legal entities.
Regulator Name: Bank of Central African States (BEAC), the regional central bank for the six-nation Economic and Monetary Community of Central Africa (CEMAC), which includes CAR.
Entity Targeted: The Government of the Central African Republic (specifically its law adopting Bitcoin as legal tender).
The Central African Republic faces downside financing risks related to BEAC and has previously shown practices challenging regional monetary policy uniformity, suggesting potential for financial instability risks. While robust Anti-Money Laundering and Combating the Financing of Terrorism (AML-CFT) legal frameworks were noted in 2006, the provided evidence does not directly confirm that BEAC specifically argued a CAR law violated CEMAC conventions concerning unified monetary policy.
Outcome: CAR did not repeal its Bitcoin legal tender law, leading to a standoff with BEAC. However, the practical implementation of Bitcoin as legal tender has been largely ineffective, partly due to the lack of infrastructure and the regulatory friction with BEAC. BEAC continued to advise against the use of cryptocurrencies in the CEMAC zone.
Regulator Name: International Monetary Fund (IMF) – acting in an advisory and surveillance capacity, not a direct enforcement role but exerting significant policy pressure.
Violation Type: Concerns over governance issues, transparency, economic risks, financial stability, and potential for illicit finance associated with the Sango Coin project and the adoption of Bitcoin as legal tender. The IMF repeatedly warned that these initiatives could undermine economic stability and complicate aid efforts. Penalty Amount: No direct monetary penalty or fine. The "penalty" was the withholding of financial support, conditionalities on aid, and strong public statements that could deter foreign investment and lead to a lack of international financial sector integration.
Outcome: The Sango Coin project faced significant delays, lack of widespread adoption, and a de-facto scaling back of its ambitious initial vision. While CAR did not abandon its crypto plans, the IMF's warnings contributed to the project's difficulties in attracting investment and achieving its goals. The project appears largely dormant or significantly scaled back in 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS (VASP) is formally regulated under CEMAC's VASP framework (Regulation No. 04/22/CM/UMAC/CM and COBAC Instruction No. 001/GR/2023), but CAR's national transposition is incomplete, enforcement is uncertain, and the regulatory environment is clouded by the Sango Coin controversy and BEAC/IMF pressure, making this a high-risk jurisdiction for custodial wallet providers.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?