Custodial wallet / SaaS in Congo
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Congo without local incorporation, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Safekeeping and/or administration of virtual assets (including custodial wallets) is a regulated VASP activity under Instruction n°001/GRT/2022 (cg.aml.safekeeping-andor-administration-of-virtual).
- Customer identification and verification using reliable, independent source documents (cg.aml.identification-and-verification, cg.aml.identify-the-customer-natural-or).
- For legal-person clients: identify ownership/control structure and beneficial owners (cg.aml.for-legal-persons-understand-the).
- Ongoing transaction monitoring to ensure consistency with customer and risk profile (cg.aml.ongoing-due-diligence, cg.aml.conduct-ongoing-monitoring-of-the).
- Enhanced Due Diligence for PEPs, cross-border relationships, complex/large transactions, high-risk countries (cg.aml.enhanced-due-diligence-edd, cg.aml.apply-edd-measures-for-higher-risk).
- Report suspicious transactions immediately to the national FIU; prohibition on tipping-off (cg.aml.reporting-obligation-immediately-report-to, cg.aml.no-tipping-off-vasps-and-their).
- Maintain CDD records and transaction records for at least 5 years after business relationship ends or transaction date (cg.aml.customer-records-maintain-all-records, cg.aml.transaction-records-maintain-records-of, cg.aml.availability-records-must-be-sufficient).
- Records must permit reconstruction of individual transactions and be promptly available to competent authorities (cg.aml.availability-records-must-be-sufficient).
- The regional AML framework (Regulation No. 01/18/CEMAC/UMAC/CM of 21 December 2018) applies to CEMAC members including Congo (cg.aml.regulation-no-0118cemacumaccm-of-21).
Key Restrictions
- BEAC Circular N° 001/GR/2022 (Dec 21, 2022) prohibits ALL financial institutions from engaging in, facilitating, or being exposed to cryptocurrencies — this includes holding, buying/selling, offering services, facilitating transactions, and opening accounts for crypto service providers (cg.licensing.circular-n-001gr2022-of-beac, cg.licensing.content-this-circular-explicitly-prohibits, cg.licensing.holding-buying-or-selling-cryptocurrencies, cg.licensing.offering-services-related-to-cryptocurrencies, cg.licensing.facilitating-cryptocurrency-transactions-for-clients, cg.licensing.opening-accounts-for-cryptocurrency-service).
- Any custodial wallet/SaaS operator would need a banking partner to handle fiat on/off-ramps — BEAC's ban on banks dealing with crypto effectively cuts off access to the formal financial system (cg.licensing.banks-and-other-financial-institutions, cg.licensing.it-is-extremely-difficult-and).
- No licensed or regulated crypto operators can legally operate within the formal financial system in Congo or any CEMAC country (cg.licensing.no-licensed-or-regulated-crypto).
- While Instruction n°001/GRT/2022 technically creates a VASP licensing/registration framework, the BEAC's de facto ban on financial institution involvement creates an operational contradiction — a licensee may exist on paper but cannot obtain banking services (cg.licensing.regulatory-approach-highly-restrictive-de, cg.aml.instruction-n001grt2022-relative-la-prvention).
- A draft law approving exchange between virtual assets and fiat was passed by the Lower Chamber on May 5, but BEAC's circular still governs the financial system — regulatory landscape is in flux (cg.aml.exchange-between-virtual-assets-and).
Key Risks
- Severe enforcement risk: BEAC circular is a formal prohibition with force on all financial institutions; operating without banking access is practically impossible for a custodial wallet requiring fiat rails (cg.licensing.financial-institutions-are-explicitly-prohibited).
- Regulatory contradiction between the VASP AML instruction (which implies legal VASP activity) and the BEAC circular (which bans crypto facilitation by financial institutions) creates legal uncertainty (cg.licensing.content-this-circular-explicitly-prohibits vs cg.aml.instruction-n001grt2022-relative-la-prvention).
- Any platform operating in Congo would be doing so illicitly and without regulatory oversight, exposing users to fraud and scams (cg.licensing.any-platforms-claiming-to-operate).
- No consumer protection for individuals engaging in crypto activities in the jurisdiction (cg.licensing.there-is-no-consumer-protection).
- If the draft law permitting fiat-to-virtual-asset exchange passes, the landscape could shift, but currently the ban is in effect.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulatory Approach: Highly Restrictive / De Facto Ban within the formal financial system. The BEAC has issued a directive effectively prohibiting financial institutions from engaging in any activities related to cryptocurrencies.
Circular N° 001/GR/2022 of BEAC concerning the ban on cryptocurrencies and crypto assets, dated December 21, 2022.
Content: This circular explicitly prohibits all financial institutions under its jurisdiction (which includes all banks and financial institutions in the Republic of the Congo) from engaging in, facilitating, or being exposed to cryptocurrencies and related activities. This includes:
Holding, buying, or selling cryptocurrencies.
Offering services related to cryptocurrencies.
Facilitating cryptocurrency transactions for clients.
Opening accounts for cryptocurrency service providers.
Banks and other financial institutions in Congo are forbidden from facilitating any transactions related to buying, selling, or cashing out cryptocurrencies.
It is extremely difficult and risky for individuals to convert fiat currency into crypto or vice-versa through legitimate channels.
No licensed or regulated crypto exchanges can legally operate within the formal financial system in the Republic of the Congo (or any CEMAC country).
Any platforms claiming to operate as exchanges within Congo would be doing so illicitly and without regulatory oversight, posing significant risks to users.
There is no consumer protection for individuals engaged in crypto trading.
Instruction n°001/GRT/2022 relative à la prévention et à la lutte contre le blanchiment des capitaux et le financement du terrorisme dans le secteur des actifs virtuels au sein de la CEMAC (Instruction No. 001/GRT/2022 on the prevention and fight against money laundering and terrorist financing in the virtual assets sector within CEMAC). This instruction, issued by the CEMAC regulatory body (likely the BEAC, in coordination with GABAC), specifically extends AML/CFT obligations to VASPs within the CEMAC zone, including Congo. It operationalizes FATF Recommendation 15 for virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Identify the customer (natural or legal person) and verify their identity using reliable, independent source documents, data, or information.
For legal persons: understand the ownership and control structure, and identify and verify the identity of beneficial owners.
Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of that relationship to ensure that transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Apply EDD measures for higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), cross-border correspondent relationships, complex or unusually large transactions, high-risk countries). This includes obtaining additional information on the customer, beneficial owner, source of funds/wealth, and enhanced ongoing monitoring.
Reporting Obligation: Immediately report to the national Financial Intelligence Unit (FIU) any suspicious transactions, including attempted transactions, where they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorist financing, regardless of the amount.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that a suspicious transaction report has been or will be submitted.
Customer Records: Maintain all records obtained through CDD measures (identification data, account files, business correspondence) for at least five (5) years after the business relationship ends.
Transaction Records: Maintain records of all transactions (both domestic and international) for at least five (5) years following the date of the transaction.
Availability: Records must be sufficient to permit the reconstruction of individual transactions and to provide evidence for prosecution of criminal activity. They must be made available promptly to the competent authorities upon request.
Regulation No. 01/18/CEMAC/UMAC/CM of 21 December 2018 on the prevention and suppression of money laundering and terrorist financing in CEMAC. This is the foundational regional AML/CFT law that Congo, as a member, is obliged to implement. It aligns with FATF recommendations and sets out the general obligations for reporting entities.
Exchange between virtual assets and fiat currencies is being formally regulated and permitted under a draft law approved by the Lower Chamber of Parliament on May 5.
Financial institutions are explicitly prohibited from opening accounts for or dealing with crypto exchange platforms.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator is theoretically captured by the CEMAC VASP AML/CFT instruction (which would require licensing and AML compliance), but in practice the BEAC's December 2022 circular prohibits all financial institutions from facilitating crypto, cutting off banking access and making a lawful, banked operation infeasible in the Republic of the Congo.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?