DeFi protocol frontend in Cote d'Ivoire
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Cote d'Ivoire with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification (full name, date/place of birth, nationality, address, profession, national ID) — Obliged Entities under Loi n°2014-393 modifiée by Ordonnance n°2019-1089
- Beneficial ownership identification and verification for legal persons
- Understanding purpose and intended nature of business relationship
- Ongoing transaction monitoring to ensure consistency with customer risk profile
- Enhanced Due Diligence (EDD) for PEPs, high-risk countries, complex/unusual/large transactions, non-face-to-face situations, and transactions involving new technologies (including virtual assets)
- Suspicious Transaction Reporting (STR) to CELLIF (FIU) for any suspected ML/TF transactions
- Record-keeping: retain all customer identification data, account files, and business correspondence
- No tipping-off prohibition regarding STR filings
- Simplified Due Diligence (SDD) permitted only in low-risk situations as defined by regulation
Key Restrictions
- If the frontend facilitates fiat-to-crypto or crypto-to-fiat transactions, it likely requires BCEAO approval as a Payment Institution or Electronic Money Issuer under Directive 03/2018/CM/UEMOA and Instruction 002/2019/RB/UEMOA
- Cryptocurrencies are not recognized as legal tender by BCEAO — any operation involving crypto is not regulated by the central bank, creating legal uncertainty
- BCEAO communiqués (2013, 2017, 2018, 2021) have consistently warned against crypto and dissuaded financial institutions from engaging — practical banking access may be impossible
- Local incorporation (RCCM registration) and local management required
- Significant capital requirements if the model triggers payment institution / EME licensing
- No specific VASP licensing framework exists yet — Regulation 06/2024/CM/WAEMU promises a framework but its implementation and interpretation for DeFi frontends is untested
- Advanced cybersecurity, data protection (Law 2013-450), and consumer protection safeguards required if licensed
Key Risks
- BCEAO's hostile stance toward crypto means banks may refuse to serve DeFi frontends, cutting off fiat on/off ramps
- Regulatory ambiguity: DeFi frontends that do not handle fiat may fall into a grey area — not clearly regulated, but BCEAO warnings create reputational and enforcement risk
- FATF grey-list status (as of Oct 2025) increases scrutiny and may trigger enforcement actions even under ambiguous rules
- CELLIF AML/CFT obligations may apply indirectly if the frontend is deemed an 'obliged entity' under the broad categories in Ordonnance n°2019-1089
- Fee-taking (e.g., swap fees, routing fees) could increase the likelihood of the frontend being classified as a payment service requiring BCEAO licensing
- No specific crypto custody rules exist — if the frontend takes any custody of user funds, there is no regulatory safe harbor
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Côte d’Ivoire, as a member of WAEMU, is subject to Regulation 06/2024/CM/WAEMU of December 20, 2024, which establishes dedicated exchange control rules for virtual assets, effectively creating a regulatory framework for virtual assets in the WAEMU zone.
BCEAO's Cautious Stance: The BCEAO has historically adopted a cautious, and at times prohibitive, stance towards cryptocurrencies due to concerns about monetary stability, consumer protection, money laundering, and illicit financing. They have issued warnings to financial institutions and the public about the risks associated with cryptocurrencies.
Required Licenses: Approval as a Payment Institution or Electronic Money Issuer (EME) from the BCEAO.
Directive No. 03/2018/CM/UEMOA on the harmonization of the regulation of payment services in the UEMOA region.
Instruction No. 002/2019/RB/UEMOA relating to the approval of payment institutions and electronic money institutions.
Required Compliance: Entities, even if not explicitly licensed for crypto, should adhere to general AML/CFT obligations if they deal with financial transactions. Once a specific VASP framework is established, these will be mandatory.
Current Status: Largely unregulated for pure crypto-to-crypto exchanges. However, if they facilitate fiat-to-crypto or crypto-to-fiat transactions, they may face pressure from traditional banks (who are regulated by BCEAO) regarding AML/CFT compliance and potentially be required to obtain a Payment Institution license.
Capital requirements (significant).
Côte d’Ivoire has data protection obligations under Law 2013-450 and is actively strengthening cybersecurity through ARTCI and ANSSI, but implementation faces coordination challenges and security gaps, indicating measures are still being developed rather than already strong.
Ordonnance n°2019-1089 du 18 décembre 2019 portant modification de la Loi n°2014-393 du 20 juin 2014 relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme.
This Ordinance modified and strengthened the earlier Law n°2014-393, bringing it more in line with international standards set by FATF. It is the core legal text for AML/CFT.
This law defines "obliged entities" (assujettis) which include financial institutions, and potentially DNFBPs. While VASPs are not explicitly named, depending on the services offered, they could fall under these broad categories, particularly if they facilitate exchanges, transfers, or safekeeping of assets.
Identification and Verification of Identity:
Beneficial Ownership: Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) (i.e., the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted). For legal persons, this typically involves identifying individuals holding 25% or more of the shares or voting rights, or otherwise exercising control.
Purpose and Nature of the Business Relationship: Understanding the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Applying EDD measures in higher-risk situations, including:
Obligation to Report: Obliged entities must report any transaction (or attempted transaction) that they suspect is linked to money laundering or terrorist financing to the Financial Intelligence Unit (FIU).
Reporting Mechanism: Reports are made to CELLIF (see below).
No Tipping-Off: Obliged entities and their employees are prohibited from disclosing to the customer or to third parties that an STR has been filed or that an investigation is underway.
All customer identification data (e.g., copies of identification documents).
Entity Targeted: General public and financial institutions operating within the UEMOA zone (including Côte d'Ivoire). Violation Type: While not a "violation" in the traditional sense, the BCEAO's consistent stance warns against the use, holding, or facilitation of transactions involving cryptocurrencies, emphasizing their speculative nature, lack of regulatory oversight, and potential for fraud and money laundering. It effectively "enforces" a non-recognition policy. Penalty Amount: Not applicable, as this is a general regulatory stance and warning, not a specific penalty against an entity. Outcome: A clear declaration that cryptocurrencies are not legal tender, are not regulated, and pose significant risks. Financial institutions are generally dissuaded from engaging with them. This discourages formal crypto operations.
Outcome: A clear declaration that cryptocurrencies are not legal tender, are not regulated, and pose significant risks. Financial institutions are generally dissuaded from engaging with them. This discourages formal crypto operations.
A widely cited stance, though not a specific custody rule, is their consistent warning against crypto:
There are no specific BCEAO licensing requirements for crypto custody, as cryptocurrencies are not recognized or regulated by the BCEAO. However, entities engaged in activities that intersect with traditional financial services (e.g., handling fiat currency, money transfers, or operating as a bank or payment institution) are subject to existing WAEMU financial licensing requirements, including AML/KYC obligations under the BCEAO's regulatory framework. National-level business licensing (e.g., registration with the Commercial Court in Côte d'Ivoire) also applies.
Côte d’Ivoire is subject to FATF recommendations and was assessed in an IMF-led 2023 report for compliance with FATF AML/CFT standards. It is also listed as a jurisdiction under increased FATF monitoring as of October 2025, indicating that FATF influence is already driving concrete actions to address strategic AML/CFT deficiencies, including for the regulation of VASPs.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend may operate in Côte d'Ivoire only under high regulatory uncertainty: if it handles fiat on/off ramps, it likely requires costly BCEAO payment-institution licensing; if purely crypto-to-crypto, it falls in a grey area with BCEAO hostility and potential AML obligations, and any fee-taking raises classification risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?