DeFi protocol frontend in Central African Republic
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Central African Republic with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) on all customers as per BEAC Regulation No. 01/17/CEMAC/UMAC/CM and Law No. 00-010 — collect identity, date of birth, nationality, physical address, identification numbers
- Transaction threshold of EUR 1,000 (or XAF equivalent) triggers enhanced information collection: originator name, physical address, national ID number, date/place of birth, wallet address; beneficiary name, address, wallet address
- Ongoing monitoring of business relationships and transaction consistency per BEAC Regulation
- Enhanced Due Diligence (EDD) for higher-risk categories (PEPs, cross-border, high-risk jurisdictions)
- Suspicious Transaction Reporting (STR) to CENTIF (the national FIU) — reports must be made promptly for any suspicion regardless of amount
- Record-keeping of all CDD documents, transaction records, and STR copies for at least 5 years
- Travel Rule compliance: transmit originator and beneficiary information to counterparty VASP immediately and securely for transactions above EUR 1,000
- Fee-taking from frontend operations likely classifies the operator as a VASP CEMAC Regulation No. 04/22/CM/UMAC/CM, triggering full AML/CFT obligations
Key Restrictions
- Must be registered/licensed as a VASP under CEMAC Regulation No. 04/22/CM/UMAC/CM, supervised by COBAC
- Regional BEAC/COBAC framework applies — CAR cannot unilaterally exempt DeFi frontends from regulation
- National AML/CFT law (Law No. 00-010) and BEAC Regulation No. 01/17/CEMAC/UMAC/CM apply — VASPs must adhere to same obligations as traditional financial institutions
- CEMAC has not issued specific DeFi exemptions; frontends interacting with permissionless contracts likely fall under VASP definitions if they facilitate exchange, transfer, or safekeeping of virtual assets
- Geofencing is not a substitute for licensing — operating a non-compliant frontend exposes operator to sanctions, fines, license suspension, or criminal referral
Key Risks
- Extreme regulatory ambiguity: CAR's own crypto law (Law No. 22.006) is contradictory — originally making BTC legal tender, later amended — and CAR is in open standoff with BEAC/COBAC over crypto regulation
- IMF and BEAC have exerted intense pressure on CAR regarding crypto initiatives (Sango Coin); operators face risk of being caught between national law and regional enforcement
- Practical enforcement capacity and infrastructure for VASP supervision in CAR is near-zero; however, COBAC has regional supervisory power and can impose sanctions
- The Sango Coin project demonstrates high political risk — crypto-friendly laws may be revoked or overridden by regional bodies
- Sanctions can include withdrawal of license, fines, public reprimands, and referral for criminal prosecution (imprisonment and fines) under national AML laws
- Fee-taking (charging users via frontend fees, spreads, or swap commissions) strengthens the argument that the operator is a VASP, not a passive software provider
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law No. 22.006 of April 27, 2022, on the Regulation of Cryptocurrencies in the Central African Republic:
The 2022 law initially made Bitcoin legal tender in Central African Republic, but was later amended to revoke Bitcoin's legal tender status, while subsequent legislation enabled tokenization of land and natural resources.
Central African Republic has not established functional licensing or supervision of VASPs; rather, it has embraced opaque, unregulated cryptocurrency schemes that risk state asset capture by criminal organizations, with no effective AML/CFT compliance or VASP oversight.
BEAC Regulation No. 01/17/CEMAC/UMAC/CM of March 30, 2017, on the Prevention and Suppression of Money Laundering and Terrorist Financing in the CEMAC Zone:
As a member of the Economic and Monetary Community of Central Africa (CEMAC), CAR is bound by regional regulations issued by the Banque des États de l'Afrique Centrale (BEAC).
This regulation provides the comprehensive AML/CFT framework for financial institutions within the CEMAC zone. While it predates the explicit regulation of VASPs, the CAR's 2022 crypto law implies that VASPs should adhere to the same stringent AML/CFT requirements as traditional financial institutions, as per FATF Recommendation 15.
Law No. 00-010 of May 8, 2000, on Money Laundering and Terrorist Financing:
Identification and Verification:
Ultimate Beneficial Ownership (UBO): Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) of customers, especially for legal persons and arrangements.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Applying enhanced measures for higher-risk categories, such as politically exposed persons (PEPs), cross-border correspondent relationships, or transactions involving high-risk jurisdictions or products.
Obligation to Report: VASPs are obligated to report any suspicious transactions, regardless of the amount involved, to the national Financial Intelligence Unit (FIU).
Reporting Body: The national FIU in the Central African Republic is the Cellule Nationale de Traitement des Informations Financières (CENTIF).
CDD Information: All documents and information obtained during the CDD process (identification documents, verification records).
Transaction Records: Records of all transactions, including sender and recipient information, amounts, dates, and types of virtual assets involved.
Regulation No. 04/22/CM/UMAC/CM of 21 December 2022 concerning the regulation of Virtual Asset Service Providers (VASPs) in the CEMAC zone.
This regulation is further complemented by an instructional circular from the Banking Commission of Central Africa (COBAC), which is the primary supervisor for financial institutions in CEMAC:
Instruction No. 001/GR/2023 of 31 January 2023 from COBAC on the practical implementation of certain provisions of Regulation No. 04/22/CM/UMAC/CM.
Exceeds EUR 1,000 (or its equivalent in XAF or other currency) for transactions conducted by VASPs.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.
Collect and retain the following information for transactions above the threshold:
Originator Information: Name, physical address, national identity number (or customer identification number), date and place of birth, and virtual asset wallet address (or unique transaction identifier).
Beneficiary Information: Name, physical address, virtual asset wallet address (or unique transaction identifier).
Transmit this information to the beneficiary VASP, where applicable, immediately and securely.
Maintain records of all collected information for at least five (5) years.
Implement risk-based procedures to identify and verify the identity of customers, especially for higher-risk transactions or relationships.
Administrative sanctions: Fines, injunctions, public reprimands.
Withdrawal or suspension of operating licenses for VASPs.
Referral to national judicial authorities for criminal prosecution under national AML/CFT laws, which can lead to imprisonment and substantial monetary fines for individuals and legal entities.
Regulator Name: Bank of Central African States (BEAC), the regional central bank for the six-nation Economic and Monetary Community of Central Africa (CEMAC), which includes CAR.
Entity Targeted: The Government of the Central African Republic (specifically its law adopting Bitcoin as legal tender).
Penalty Amount: No direct monetary penalty. The "penalty" was intense regulatory pressure, a demand for the law's repeal, and warnings to financial institutions within the CEMAC zone regarding engagement with cryptocurrencies. It represented significant political and economic pressure on CAR.
Outcome: CAR did not repeal its Bitcoin legal tender law, leading to a standoff with BEAC. However, the practical implementation of Bitcoin as legal tender has been largely ineffective, partly due to the lack of infrastructure and the regulatory friction with BEAC. BEAC continued to advise against the use of cryptocurrencies in the CEMAC zone.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — DeFi frontends that take fees, facilitate exchange/transfer of virtual assets, or interact with smart contracts on behalf of users are likely classified as VASPs under CEMAC Regulation No. 04/22/CM/UMAC/CM and must be licensed by COBAC, comply with full AML/CFT obligations (CDD, STR, Travel Rule above EUR 1,000), but CAR's regulatory environment is highly ambiguous, contested between national and regional authorities, and lacks functional supervisory infrastructure.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?