Custodial wallet / SaaS in Costa Rica
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Costa Rica with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Register as an obligated subject with SUGEF under the AML framework (Law 7786 as amended by Law 10.363) — the VASP registration system under SUGEF 2-2024 is the applicable path.
- Implement a full AML/KYC program: customer identification and verification (KYC), including physical residential address, national ID/passport, contact info, and for legal entities: corporate structure, registered office, tax ID, directors/partners, beneficial owners (>25% threshold).
- Implement ongoing transaction monitoring to ensure consistency with customer risk profile, and periodically review risk categorizations.
- Apply a Risk-Based Approach (RBA): enhanced due diligence (EDD) for high-risk customers (PEPs, cross-border relationships, complex/unusual transactions), including source-of-funds/wealth verification.
- Appoint a designated AML Compliance Officer.
- Report suspicious transactions (STRs/SARs) to the Unidad de Inteligencia Financiera (UIAD / FIU) — any transaction or attempted transaction where funds are suspected to be proceeds of crime or linked to terrorist financing.
- Maintain records of transactions and client data (record-keeping obligations governed by electronic invoicing and monthly tax reporting to the General Directorate of Taxation).
- No-tipping-off prohibition: cannot disclose to customers that an STR has been or will be filed.
- Conduct a comprehensive money laundering risk assessment.
- Establish internal controls, policies, procedures, and employee training programs.
Key Restrictions
- Custodial wallet/SaaS providers that control private keys on behalf of clients are highly likely to be classified as 'obligated subjects' under Law 7786 (via Law 10.363 and SUGEF 2-2024), but no specific VASP license exists — registration is under the AML framework, not a dedicated custody/capital-adequacy regime.
- No specific segregation, insurance, or proof-of-reserves rules exist for crypto custodians in Costa Rica; these are not addressed in existing regulations.
- If the operator processes fiat currency payments (even crypto-adjacent), it may fall under existing payment service provider regulations requiring SUGEF licensing with higher capital and operational requirements.
- Purely crypto-to-crypto custody (no fiat conversion) remains in a grey area; classification depends on whether the service involves value transfer that could be used for money laundering.
- Local incorporation and a local legal representative (registered office, local presence) are required under general Costa Rican corporate law for any company operating and generating income in the jurisdiction.
- No specific capital requirements for crypto custodians exist; if the activity is interpreted as a financial institution activity (e.g., holding client funds in fiat), traditional financial institution capital requirements may apply.
- Virtual assets are not legal tender in Costa Rica (BCCR position), and SUGEF has warned financial institutions about dealing with unregulated crypto entities.
Key Risks
- Regulatory ambiguity: Law 10.363 established the VASP framework and SUGEF 2-2024 provides registration rules, but the operational regulations remain pending/in development — enforcement posture is still evolving.
- Expediente 22.837 (the proposed amendment explicitly classifying VASPs) has faced procedural setbacks, creating uncertainty about the scope of obligations.
- No dedicated custody/capital adequacy/segregation/insurance rules for crypto custodians — operators cannot rely on a clear asset protection framework.
- SUGEF and BCCR have consistently warned that virtual assets are unregulated and carry significant risks — enforcement action may be unpredictable against entities operating in grey areas.
- Criminal enforcement risk: OIJ has investigated and prosecuted individuals for money laundering and fraud using crypto; custody providers could face scrutiny if used by bad actors, especially without robust AML controls.
- If holding both fiat and crypto, the operator may inadvertently fall under full financial institution regulation with significantly higher capital and compliance burdens.
- SaaS white-label model creates ambiguity about where AML obligations sit — the SaaS provider may bear direct obligations as the obligated subject, not just the white-label client.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Superintendencia General de Entidades Financieras (SUGEF): The General Superintendency of Financial Institutions. SUGEF is responsible for supervising financial entities and enforcing AML/CFT regulations for many obligated subjects.
Virtual asset service providers in Costa Rica are not yet explicitly classified as 'obligated subjects' under Law 7786; the proposed amendment (Expediente 22.837) that would explicitly include them remains pending and has faced procedural setbacks.
Registration: With SUGEF as an "obligated subject" (if the activity falls under their scope) or potentially with the Financial Intelligence Unit (Unidad de Inteligencia Financiera - UIF) depending on the exact classification.
Full AML/KYC Program: Implementation of robust Know Your Customer (KYC), Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), and Transaction Monitoring policies and procedures.
AML Officer: Appointment of a designated AML Compliance Officer.
Reporting: Obligation to report suspicious transactions (SARs/STRs) to the UIF.
Maintenance of transaction and client records for a specified period is now predominantly governed by electronic invoicing systems and specific monthly reporting obligations to the General Directorate of Taxation, fundamentally altering the methods and specific requirements for record-keeping in Costa Rica.
Conduct a comprehensive money laundering risk assessment.
Status: If the custody provider holds virtual assets on behalf of clients and/or provides services that enable the transfer or exchange of these assets, they would likely also fall under the "obligated subject" category, especially if they control the private keys for clients.
If processing fiat currency payments (even if crypto-related): They would likely fall under existing payment service provider regulations and certainly under AML/CFT laws as obligated subjects.
If purely crypto-to-crypto transactions (e.g., facilitating payments in crypto without fiat conversion): This remains a grey area in many jurisdictions without specific VASP licensing. However, the global trend is to bring such services under AML/CFT scrutiny if they involve value transfer and could be used for illicit purposes. SUGEF's interpretation would be key.
Capital Requirements: There are no specific capital requirements for crypto-specific licenses as such licenses don't exist. However:
If an entity's operations are interpreted as falling under the scope of existing financial institution activities (e.g., holding client funds, providing certain payment services in fiat), then the capital requirements applicable to traditional financial institutions or payment service providers regulated by SUGEF would apply. These can vary significantly depending on the type of financial service.
For entities purely operating as "obligated subjects" under AML without being a licensed financial institution, there isn't a direct prescribed minimum capital, but demonstrating financial soundness and having adequate resources to implement AML controls is implicitly expected.
Local Presence: Generally, any company operating and generating income in Costa Rica needs to be incorporated locally and have a local registered office and local representation (e.g., a local legal representative). This is standard corporate law, not crypto-specific. For AML purposes, having a local AML officer is also typical.
Law No. 7786, "Law on Narcotics, Psychotropic Substances, Drugs of Unauthorized Use, Related Activities, Money Laundering and Financing of Terrorism" (Ley sobre Estupefacientes, Sustancias Psicotrópicas, Drogas de Uso No Autorizado, Actividades Conexas, Legitimación de Capitales y Financiamiento al Terrorismo), as amended. This is Costa Rica's foundational AML/CFT law.
Law No. 10.363, "Law on the Regulation of Virtual Asset Service Providers" (Ley de Regulación de Proveedores de Servicios de Activos Virtuales). This law established the legal framework for VASPs, bringing them under Law 7786's AML/CFT scope. However, the operational AML/CFT obligations and registration mandate became enforceable only after SUGEF's implementing regulation (SUGEF 2-2024) came into effect on November 16, 2024.
Regulations issued by SUGEF: While Law 10.363 sets the legal framework, the Superintendent General of Financial Entities (SUGEF) is responsible for developing specific regulations. The key implementing regulation, SUGEF 2-2024 ("Reglamento para la Inscripción y Supervisión de los Proveedores de Servicios de Activos Virtuales"), was issued and became effective on November 16, 2024. It details registration, CDD, transaction monitoring, STR, and record-keeping requirements for VASPs.
Identification and Verification of Customer Identity:
Physical residential address
Identification number (e.g., national ID card, passport number)
Contact information (e.g., phone number, email address)
Source of funds/wealth (as part of Enhanced Due Diligence (EDD) for high-risk clients, which may include scrutiny of large transactions as a contributing factor to the risk assessment).
Verification through reliable, independent source documents, data, or information (e.g., government-issued ID, utility bills).
Legal name, legal nature or type of entity (naturaleza jurídica), and proof of incorporation/registration (copia certificada de la personería jurídica).
Registered office address (domicilio o dirección física de la sede social).
Corporate identification number (número de identificación), which in Costa Rica commonly serves as the tax identification number (cédula jurídica / Número de Identificación Tributaria).
Names of directors, partners, and senior management.
Identification of Beneficial Owners (BOs): VASPs must identify and verify the identity of all natural persons who ultimately own or control the legal entity (typically those holding 25% or more of shares or voting rights, or otherwise exercising control).
Nature of business and purpose of the business relationship.
Purpose and Intended Nature of the Business Relationship: Understanding why the customer wants to use the VASP's services.
Ongoing Due Diligence:
Regularly monitoring transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Keeping customer information, documents, and data up-to-date.
Periodically reviewing the risk categorization of customers.
Risk-Based Approach (RBA): VASPs must apply CDD measures on a risk-sensitive basis. This means applying enhanced due diligence (EDD) for higher-risk customers, transactions, or business relationships (e.g., Politically Exposed Persons (PEPs), cross-border correspondent relationships, complex/unusual transactions). Simplified due diligence (SDD) may be applied in specific lower-risk scenarios.
Trigger: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that the funds or assets are proceeds of criminal activity (including money laundering) or are related to terrorist financing.
Reporting Body: The report must be submitted to the Unidad de Inteligencia Financiera del Instituto Costarricense sobre Drogas (UIAD), which is Costa Rica's FIU.
No Tipping Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been, or will be, filed.
Regulator Name: Superintendencia General de Entidades Financieras (SUGEF)
September 2021: SUGEF Circular SGF-0036-2021 reiterates that virtual assets are not legal tender and are not regulated by SUGEF unless they fall under existing regulated activities.
January 2022: SUGEF continues to issue warnings regarding the risks of virtual assets.
Outcome: SUGEF maintains that virtual assets are not regulated financial products or services under its supervision. Financial institutions are advised to exercise extreme caution when dealing with virtual assets and to ensure compliance with existing AML/CFT regulations if handling any related transactions. This means that if a bank facilitates transactions involving crypto, it must still comply with its existing AML obligations.
Regulator Name: Banco Central de Costa Rica (BCCR)
November 2021: BCCR reiterates that cryptocurrencies are not legal tender in Costa Rica and highlights risks associated with their use.
Costa Rica's regulatory stance on cryptocurrencies has evolved from mere cautionary statements to active legislative development, with Bill No. 22.837 on virtual assets advancing in the legislative assembly.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers controlling private keys on behalf of clients are likely classified as obligated subjects under Costa Rica's AML framework (Law 7786 via Law 10.363 and SUGEF 2-2024) and must register with SUGEF, implement a full AML/KYC program, appoint a compliance officer, and report suspicious transactions to the FIU, but the regulatory framework is still evolving with no specific custody license, capital adequacy, segregation, insurance, or proof-of-reserves requirements.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?