← Regulations / Cote d'Ivoire / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Cote d'Ivoire

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Cote d'Ivoire with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD required under Loi n°2014-393 (as modified by Ordonnance n°2019-1089): verify identity for individuals (name, DOB, nationality, address, national ID) and legal persons (name, legal form, registration, directors, authorized representatives).
  • Beneficial ownership identification and verification required for all clients (legal persons).
  • Ongoing transaction monitoring required to ensure transactions are consistent with customer profile and risk.
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk countries, complex/unusual/large transactions, non-face-to-face relationships, and transactions involving new technologies (including virtual assets).
  • Suspicious Transaction Reports (STRs) must be filed with the FIU (CELLIF) for any suspected ML/TF transactions, with no-tipping-off obligations.
  • Record-keeping: all customer identification data, account files, and business correspondence must be retained for the statutory period under the AML law.
  • If the custodial wallet service touches fiat (on/off ramps), AML obligations may require Payment Institution or Electronic Money Issuer licensing under BCEAO directives (Directive 03/2018/CM/UEMOA, Instruction 002/2019/RB/UEMOA).
  • Regional AML framework applies via Règlement n°07/2002/CM/UEMOA du 19 septembre 2002.

Key Restrictions

  • Cryptocurrencies are not recognized as legal tender by the BCEAO and are not regulated by the central bank; BCEAO has consistently warned financial institutions and the public against engaging with crypto.
  • No specific crypto custody licensing framework exists — custody of crypto assets has no dedicated regulatory status under BCEAO.
  • If the service involves fiat currency handling, on/off-ramp, or payment initiation, it requires approval as a Payment Institution or Electronic Money Issuer (EME) from the BCEAO with significant capital requirements, local presence, and management.
  • No segregation-of-assets rules, insurance mandates, or cold-storage mandates exist specifically for crypto assets — the traditional financial segregation rules do not cover crypto.
  • Local incorporation (RCCM registration) and tax registration in Côte d'Ivoire are required.
  • No 'qualified custodian' definition exists for digital assets in this jurisdiction.

Key Risks

  • Regulatory ambiguity: no specific VASP or custody framework exists, leaving operators exposed to BCEAO enforcement based on its anti-crypto communiqués.
  • Banking friction: Regulated banks (under BCEAO) are discouraged from servicing crypto businesses, creating operational difficulties for fiat on/off ramps.
  • FATF monitoring exposure: Côte d'Ivoire is under increased FATF monitoring (October 2025), which may result in rapidly evolving regulatory obligations with limited transition periods.
  • Enforcement risk from BCEAO: BCEAO has publicly warned against crypto and may treat custodial wallet services as facilitating unregulated financial activity, potentially triggering administrative or criminal liability.
  • No asset segregation or insurance requirements for crypto means customer funds may be at risk in the event of insolvency or hack, creating consumer protection / PR exposure.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 80% confidence

The BCEAO's official website (https://www.bceao.int/) designates its "Publications" and "News" sections, primarily in French, as the official channels for updates on its stance regarding digital currencies. No direct "custody regulation" document exists on the site as of this date.

custody 85% confidence

There are no specific BCEAO licensing requirements for crypto custody, as cryptocurrencies are not recognized or regulated by the BCEAO. However, entities engaged in activities that intersect with traditional financial services (e.g., handling fiat currency, money transfers, or operating as a bank or payment institution) are subject to existing WAEMU financial licensing requirements, including AML/KYC obligations under the BCEAO's regulatory framework. National-level business licensing (e.g., registration with the Commercial Court in Côte d'Ivoire) also applies.

custody 80% confidence

The BCEAO's regulatory framework does not include specific rules for the segregation of cryptocurrency assets. While BCEAO regulations mandate segregation for fiduciaires in the traditional financial system (e.g., for securities maintained by investment service providers), these regulations explicitly exclude digital assets not recognized as financial instruments. Entities holding crypto assets may still be subject to general consumer protection or business contract laws at the national level in Côte d'Ivoire, but no specific segregation mandate from the BCEAO exists.

custody 85% confidence

The BCEAO has not issued any mandates requiring insurance or bonding for digital asset custodians. This is consistent with the broader lack of regulation for crypto assets. However, entities that also operate as traditional financial institutions may be subject to existing insurance/bonding requirements for their licensed activities (e.g., operational risk insurance for banks), but these do not specifically cover crypto custody. The absence of such protections increases risk for users in the event of loss, theft, or custodian insolvency.

custody 85% confidence

The BCEAO has not issued any specific mandates for cold storage or any other method of storing digital assets. This reflects the broader absence of a regulated crypto custody framework. In contrast, traditional financial institutions are subject to BCEAO prudential rules for the safekeeping of physical assets (e.g., cash in vaults, securities held by depositories), but no equivalent exists for unregulated digital assets.

custody 90% confidence

No specific definition for crypto assets. The concept of a "qualified custodian" as defined in jurisdictions like the US (e.g., under the Advisers Act) does not exist for digital assets in Cote d'Ivoire, as there's no framework to define or regulate such entities.

licensing 80% confidence

Côte d’Ivoire, as a member of WAEMU, is subject to Regulation 06/2024/CM/WAEMU of December 20, 2024, which establishes dedicated exchange control rules for virtual assets, effectively creating a regulatory framework for virtual assets in the WAEMU zone.

licensing 95% confidence

Required Licenses: Approval as a Payment Institution or Electronic Money Issuer (EME) from the BCEAO.

licensing 90% confidence

Directive No. 03/2018/CM/UEMOA on the harmonization of the regulation of payment services in the UEMOA region.

licensing 90% confidence

Instruction No. 002/2019/RB/UEMOA relating to the approval of payment institutions and electronic money institutions.

licensing 90% confidence

Required Compliance: Entities, even if not explicitly licensed for crypto, should adhere to general AML/CFT obligations if they deal with financial transactions. Once a specific VASP framework is established, these will be mandatory.

licensing 90% confidence

Directive No. 02/2015/CM/UEMOA on the fight against money laundering and terrorist financing in the UEMOA region.

licensing 90% confidence

Required Registration: Registration with the commercial registry (RCCM - Registre du Commerce et du Crédit Mobilier) and relevant tax authorities in Cote d'Ivoire.

licensing 60% confidence

Capital requirements (significant).

licensing 90% confidence

Local presence and management.

aml 60% confidence

Ordonnance n°2019-1089 du 18 décembre 2019 portant modification de la Loi n°2014-393 du 20 juin 2014 relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme.

aml 60% confidence

This law defines "obliged entities" (assujettis) which include financial institutions, and potentially DNFBPs. While VASPs are not explicitly named, depending on the services offered, they could fall under these broad categories, particularly if they facilitate exchanges, transfers, or safekeeping of assets.

aml 60% confidence

Règlement n°07/2002/CM/UEMOA du 19 septembre 2002 relatif à la lutte contre le blanchiment de capitaux dans les États membres de l'UEMOA.

aml 100% confidence

Identification and Verification of Identity:

aml 100% confidence

For Legal Persons/Entities (e.g., businesses): Obtaining and verifying the company's name, legal form, address of registered office, registration number, articles of incorporation, bylaws, and identifying the directors and persons authorized to represent the legal person.

aml 100% confidence

Beneficial Ownership: Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) (i.e., the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted). For legal persons, this typically involves identifying individuals holding 25% or more of the shares or voting rights, or otherwise exercising control.

aml 100% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Enhanced Due Diligence (EDD): Applying EDD measures in higher-risk situations, including:

aml 100% confidence

Obligation to Report: Obliged entities must report any transaction (or attempted transaction) that they suspect is linked to money laundering or terrorist financing to the Financial Intelligence Unit (FIU).

aml 100% confidence

No Tipping-Off: Obliged entities and their employees are prohibited from disclosing to the customer or to third parties that an STR has been filed or that an investigation is underway.

enforcement 50% confidence

Entity Targeted: General public and financial institutions operating within the UEMOA zone (including Côte d'Ivoire). Violation Type: While not a "violation" in the traditional sense, the BCEAO's consistent stance warns against the use, holding, or facilitation of transactions involving cryptocurrencies, emphasizing their speculative nature, lack of regulatory oversight, and potential for fraud and money laundering. It effectively "enforces" a non-recognition policy. Penalty Amount: Not applicable, as this is a general regulatory stance and warning, not a specific penalty against an entity. Outcome: A clear declaration that cryptocurrencies are not legal tender, are not regulated, and pose significant risks. Financial institutions are generally dissuaded from engaging with them. This discourages formal crypto operations.

enforcement 50% confidence

Outcome: A clear declaration that cryptocurrencies are not legal tender, are not regulated, and pose significant risks. Financial institutions are generally dissuaded from engaging with them. This discourages formal crypto operations.

licensing 90% confidence

Côte d’Ivoire is subject to FATF recommendations and was assessed in an IMF-led 2023 report for compliance with FATF AML/CFT standards. It is also listed as a jurisdiction under increased FATF monitoring as of October 2025, indicating that FATF influence is already driving concrete actions to address strategic AML/CFT deficiencies, including for the regulation of VASPs.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS operations are possible in Côte d'Ivoire only if structured to avoid pure crypto-custody (which has no framework) and instead licensed as a Payment Institution or Electronic Money Issuer under BCEAO directives if the service touches fiat; general AML/CFT obligations under Ordonnance n°2019-1089 apply, but no specific crypto custody licensing, segregation, insurance, or qualified-custodian rules exist, creating significant regulatory ambiguity and enforcement risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?