Custodial wallet / SaaS in Chile
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Chile with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including custodial wallet providers) are designated obligated entities under UAF Circular N° 57 and must comply with Ley N° 19.913 (main AML/CFT law).
- Customer Due Diligence (CDD): identify and verify individuals (full name, ID number, date of birth, nationality, address, contact info) and legal entities (legal form, name, address, representatives, beneficial ownership).
- Beneficial ownership identification and verification required.
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile.
- Enhanced Due Diligence (EDD) required for Politically Exposed Persons (PEPs) per UAF Circular N° 50.
- Risk-based approach: apply CDD commensurate with risk; higher-risk scenarios trigger EDD per UAF Circular N° 49 and N° 52.
- Suspicious activity reporting (ROS) — must report any unusual or suspicious transactions or attempts, regardless of amount, per UAF Circular N° 58.
- Compliance with international sanctions lists and TF reporting per UAF Circular N° 51.
- Designated compliance officer required (per UAF Circular N° 49).
- AML/CTF supervision by the Financial Analysis Unit (UAF) and CMF.
Key Restrictions
- Must register with the CMF (Financial Market Commission) via the Financial Services Register under the Fintech Law (Ley N° 21.521).
- Must obtain authorization and be registered as a VASP before offering custodial wallet services.
- Client assets must be segregated from the VASP's own assets — prohibition of commingling (Ley N° 21.521, Article 18).
- Client assets must be clearly identified as belonging to clients and separated from the VASP's balance sheet.
- Segregation aims to protect client assets in case of VASP insolvency or bankruptcy.
- Must maintain adequate own capital and provide guarantees as determined by CMF secondary regulations (Article 18).
- Must implement comprehensive risk management policies covering operational, technological, and cybersecurity risks.
- Must implement strong cybersecurity measures and IT infrastructure to protect client assets and data.
- Detailed operational segregation rules will be further specified in CMF secondary regulations.
Key Risks
- CMF has issued multiple warnings against unregistered entities and continues to name specific unregulated platforms in 2026 alerts — enforcement risk for operating without authorization.
- Criminal enforcement precedent exists: prosecutors have pursued fraud, pyramid scheme, and illegal financial operations charges against unregistered crypto operators (Mind Capital, Generación Zoe, IM Forex).
- Secondary regulations from CMF on capital, guarantees, and segregation specifics are still being developed — regulatory ambiguity on exact operational requirements.
- SaaS model creates ambiguity on whether AML obligations fall on the custodial wallet provider (the technology/white-label platform) or the white-label client — both may be deemed VASPs under Chilean law.
- Penalties for non-compliance include criminal sanctions (Article 161-A of the Penal Code: imprisonment and fines of 50–500 UTM) for operating outside the regulatory framework.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Any entity intending to provide virtual asset custody services in Chile must register with the Financial Market Commission (CMF) via the Financial Services Register, as established by the Fintech Law.
Authorization and Registration: Providers of virtual asset services, including custody, must obtain authorization and be registered with the CMF.
Requirements: The Ley Fintech explicitly mandates the segregation of client assets from the VASP's own assets.
Prohibition of Commingling: Entities providing custody services for virtual assets are prohibited from mixing client assets with their own proprietary assets.
Identification: Client assets must be clearly identified as belonging to clients and separated from the VASP's balance sheet.
Protection in Insolvency: This segregation aims to protect client assets in case of the VASP's insolvency or bankruptcy.
Specifics: The detailed operational rules for segregation will be further developed in the CMF's secondary regulations.
Capital and Guarantees: Regulated entities, including VASPs offering custody, must maintain adequate own capital and provide guarantees to back their operations and cover potential liabilities. These requirements are intended to protect clients and ensure the stability of the service provider.
Risk Mitigation: The amount and type of capital and guarantees will be determined by the CMF through secondary regulations, taking into account the specific risks associated with each service, including the custody of virtual assets.
Risk Management: Implement comprehensive risk management policies, including operational, technological, and cybersecurity risks.
Technology and Cybersecurity: Implement strong cybersecurity measures and IT infrastructure to protect client assets and data.
Anti-Money Laundering (AML) / Counter-Terrorist Financing (CTF): Comply with existing AML/CTF regulations, aligned with FATF recommendations, which are enforced by the Financial Analysis Unit (UAF) in Chile.
Ley N° 21.521 (Fintech Law):
Custody Providers: Entities providing safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of natural or legal persons.
Comisión para el Mercado Financiero (CMF):
UAF Circular N° 57 (Circular N°57 de la UAF): This is the most crucial piece of regulation for VASPs. Issued by the UAF, Circular N° 57 (published in October 2020) explicitly designates "Providers of Virtual Asset Services" (PSAV) as obligated entities under Law N° 19.913. This means VASPs must comply with all AML/CFT obligations applicable to other financial institutions.
Ley N° 19.913, que Crea la Unidad de Análisis Financiero y Modifica Diversas Disposiciones en Materia de Lavado y Blanqueo de Activos (Law N° 19.913, which Creates the Financial Analysis Unit and Modifies Various Provisions Regarding Asset Laundering and Blanqueo de Activos): This is the main AML/CFT law in Chile, establishing the UAF and defining the framework for preventing and prosecuting money laundering and terrorist financing.
Circular N° 49 de la UAF: Establishes general instructions on risk management and prevention of ML/FT for obligated entities, including policies, procedures, internal controls, and designated compliance officers.
Circular N° 50 de la UAF: Provides instructions for identifying Politically Exposed Persons (PEPs).
Circular N° 51 de la UAF: Establishes instructions regarding the detection and reporting of transactions related to terrorism financing and compliance with international sanctions lists.
Circular N° 52 de la UAF: Details instructions for conducting risk assessments for ML/FT.
Circular N° 58 de la UAF: Modifies and updates the instructions for reporting suspicious activities (ROS) and other information to the UAF.
Individuals: Obtain and verify identity (e.g., full name, ID number, date of birth, nationality, address, contact information) using reliable, independent source documents, data, or information.
Legal Entities: Obtain and verify legal form, name, address, contact information, legal representative(s), and information on beneficial ownership.
Beneficial Ownership: Identify and verify the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds.
Politically Exposed Persons (PEPs): Implement enhanced due diligence (EDD) measures for PEPs, including obtaining senior management approval for establishing business relationships and taking reasonable measures to establish the source of wealth and source of funds.
Risk-Based Approach: Apply CDD measures according to the level of risk associated with the customer, product, service, or geographic area. Higher risk scenarios require Enhanced Due Diligence (EDD).
Obligation to Report: VASPs are required to report any operation, transaction, business, or activity that they identify as unusual or suspicious, as well as any attempts to carry out such activities, regardless of the amount.
Entity Targeted: General public, and implicitly, unregulated entities operating in the crypto space. Specific warnings target individual unregistered platforms. Violation Type: Operating outside regulatory oversight, potential for fraud or financial instability. The warnings themselves are preventative, not punitive. Penalty Amount: No direct penalties attached to a warning. Penalties would come from future enforcement actions under the new FinTech Law, once fully implemented.
Entity Targeted: Individuals associated with "Mind Capital" in Chile, notably promoters and recruiters of the scheme. Violation Type: Alleged multi-level marketing scheme, fraud (estafa), swindling, and illegal banking activities, using cryptocurrencies as a facade. Outcome: Criminal proceedings are ongoing against several individuals involved in promoting and operating the scheme within Chile. The goal is to prosecute those responsible and recover funds for victims.
Entity Targeted: Chilean individuals and entities linked to the international "Generación Zoe" and "IM Forex" schemes. Violation Type: Alleged pyramid scheme, fraud (estafa), swindling, and illegal financial operations, misleading investors with promises of high, guaranteed returns using crypto as an investment vehicle. Penalty Amount: Criminal charges have been filed, leading to arrests and asset seizures. Specific penalties (prison sentences, restitution) are pending final judicial decisions. Outcome: Several individuals have been arrested and charged in Chile for their roles in promoting and operating the scheme. The primary operator of Generación Zoe, Leonardo Cositorto, was arrested in Argentina and is facing charges there. Chilean authorities continue to investigate and prosecute local affiliates. Penalty Amount: No direct penalties attached to a warning. Penalties would come from future enforcement actions under the new FinTech Law, once fully implemented. Outcome: Increased public awareness about crypto risks. The FinTech Law now requires Virtual Asset Service Providers (VASPs) to register with the CMF and comply with various regulations (e.g., AML/CFT, consumer protection). This will enable direct regulatory enforcement actions in the future against non-compliant entities.
Chile's regulatory framework under Resolution 79/2025 imposes strict oversight and reporting obligations on digital marketplaces and payment facilitators, with punitive enforcement measures (e.g., anti-avoidance rules) to combat non-compliance, tax evasion, and fraud—not merely preventative warnings.
For the relevant Chilean offense, Article 161-A of the Chilean Penal Code establishes a fixed statutory penalty range: imprisonment of reclusión menor in any of its degrees plus a fine of 50 to 500 UTM, increased to reclusión menor in its maximum degree plus a fine of 100 to 500 UTM if the same person both obtains and discloses the material; penalties are therefore not left open-ended to generic criminal charges, asset freezes, and restitution alone but are set by law within these ranges.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers may operate in Chile only if registered and authorized with the CMF as a VASP under the Fintech Law (Ley N° 21.521), with mandatory client asset segregation, capital/guarantee requirements, comprehensive AML/CTF obligations supervised by the UAF, and ongoing cybersecurity and risk management standards, though secondary regulations on capital and segregation specifics are still being finalized.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?