← Regulations / Cameroon / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Cameroon

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Cameroon with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • KYC: Identify and verify customers (natural persons: full name, date of birth, nationality, address, ID number, source of funds/wealth) before establishing a relationship or for transactions above ~EUR 1,000 threshold.
  • Beneficial Ownership: Identify and verify natural persons who own or control ≥25% of legal entity customers.
  • Risk Assessment: Understand the purpose and intended nature of the business relationship; assess customer risk profile.
  • Ongoing Monitoring: Continuously monitor transactions against customer knowledge and risk profile; update customer documentation regularly.
  • Enhanced Due Diligence (EDD): Required for high-risk situations (PEPs, high-risk jurisdictions per FATF, complex/unusually large transactions, non-face-to-face customers).
  • Suspicious Transaction Reporting: File STRs with ANIF (Cameroon's FIU) 'without delay' for any transaction or attempted transaction suspected of ML/TF, regardless of amount.
  • Record-Keeping: Maintain all KYC, transaction, and reporting records per CEMAC Regulation No. 02/CEMAC/UMAC/CM/22 and Law No. 2016/007.
  • The SaaS provider bears primary AML obligations as the VASP; white-label clients may have shared obligations depending on contractual allocation, but the licensed entity remains responsible before regulators.

Key Restrictions

  • CEMAC-wide BEAC ban (May 2022) prohibits all crypto-asset activities by regulated financial institutions; crypto is not recognized as legal tender.
  • No specific license exists for custodial wallet / custody providers — the framework is effectively prohibition for regulated entities without a regime for independent crypto businesses.
  • Local corporate entity and physical presence in Cameroon are mandatory, as this extends from general requirements for regulated financial activities.
  • Access to banking services is extremely challenging or impossible, as banks are prohibited from dealing with crypto-related businesses.
  • White-label arrangement: The custody-as-a-service provider must itself be the licensed/regulated entity; the model cannot operate through a mere technology/service contract without the provider being the obligated VASP under CEMAC AML rules.

Key Risks

  • Regulatory illegality risk: The May 2022 CEMAC-wide BEAC ban on crypto-asset activities is still formally in force; operating any custodial wallet service carries risk of enforcement despite observed market adoption.
  • Enforcement precedent: The GIT (Global Investment Trading) Ponzi scheme case shows that Cameroonian authorities actively prosecute crypto-adjacent unlicensed financial activities with arrests, asset seizures, and criminal charges.
  • No banking access: Without a legally recognized framework for VASPs, custodial wallet providers cannot obtain or maintain bank accounts, creating a structural operational barrier.
  • Regulatory ambiguity: The gap between the de jure ban and de facto market activity creates uncertainty; a future licensing framework may impose retroactive compliance obligations.
  • AML liability concentration: Under CEMAC regulations, the VASP (custodial wallet provider) bears direct AML obligations; white-label clients create additional KYC/onboarding risk for which the provider remains accountable.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 100% confidence

Custody Providers: Similar to exchanges, no specific license exists. Financial institutions are prohibited from holding or facilitating virtual assets, making traditional custody services for crypto impossible within the regulated sector.

licensing 100% confidence

Neither a specific registration nor a licensing regime for VASPs exists in Cameroon. The current environment is effectively one of prohibition for regulated financial entities, without a corresponding framework for independent crypto businesses.

licensing 100% confidence

Entities seeking to operate in the crypto space would likely face a lack of legal recognition and significant operational hurdles, particularly concerning banking relationships.

licensing 100% confidence

Local Presence: For most regulated financial activities in Cameroon, a local corporate entity and physical presence are mandatory. This would likely extend to any future crypto licensing.

licensing 95% confidence

Lack of Legal Tender Status: Cryptocurrencies are not recognized as legal tender within the CEMAC zone.

aml 20% confidence

CEMAC Regulation No. 02/CEMAC/UMAC/CM/22 on the Fight Against Money Laundering and the Financing of Terrorism in the CEMAC Zone, with Specific Provisions for Virtual Assets: This is the most critical piece of legislation. Adopted in 2022, it explicitly defines "virtual assets" and "virtual asset service providers" and subjects VASPs to the same AML/CFT obligations as traditional financial institutions. It transposes the FATF Recommendations concerning virtual assets.

aml 20% confidence

Law No. 2016/007 of July 12, 2016, on the fight against money laundering and terrorist financing in Cameroon: This national law provides the general framework for AML/CFT in Cameroon, defining obliged entities, establishing the Financial Intelligence Unit (ANIF), and outlining sanctions. While it predates explicit VASP definitions, the CEMAC regulation extends its principles to VASPs.

aml 20% confidence

Identification and Verification of Customers:

aml 20% confidence

Identifying the natural person(s) who ultimately own or control the customer (typically 25% ownership or more, or effective control).

aml 20% confidence

Assessing the risk profile of the customer based on this information.

aml 20% confidence

Continuously monitoring business relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and their risk profile, including, where necessary, the source of funds.

aml 20% confidence

Applying EDD measures for high-risk situations, including:

aml 20% confidence

Reporting Obligation: VASPs must report any transaction (or attempted transaction) that they suspect, or have reasonable grounds to suspect, is related to money laundering or terrorist financing, regardless of the amount.

aml 20% confidence

Reporting Body: Reports must be made to the Agence Nationale d'Investigation Financière (ANIF), Cameroon's FIU.

aml 20% confidence

Timing: Reports must be submitted "without delay" once suspicion is formed.

enforcement 95% confidence

The CEMAC-wide Ban on Crypto-Assets by BEAC: This is a foundational regulatory action that makes all crypto-related activities illegal and provides the basis for enforcement.

enforcement 100% confidence

Outcome: Established a clear and comprehensive prohibition on all crypto-asset related activities across the CEMAC region. This makes any operation of a cryptocurrency exchange, mining operation, or widespread trading highly illegal and subject to enforcement by national authorities (police, judiciary, financial intelligence units) in each CEMAC member state, including Cameroon.

enforcement 100% confidence

Entity Targeted: Global Investment Trading (GIT) and its founder, Emile Parfait Mbori, along with several associates. Violation Type: Operating an illegal financial scheme (Ponzi scheme), fraud, illegal public offering of financial products, money laundering. Although often marketed as "crypto" (sometimes involving Mofor Coin), the core violation was operating an unregistered and fraudulent investment scheme. Penalty Amount: Not a final judicial penalty yet, as legal proceedings are ongoing. However, significant actions include:.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS is not expressly prohibited for non-regulated entities but faces a de facto ban on banking access, no licensing framework, and a CEMAC-wide BEAC directive prohibiting crypto activities by financial institutions, with the only viable path being a local entity holding a future VASP license under developing CEMAC AML rules.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?