← Regulations / Cabo Verde / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Cabo Verde

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Cabo Verde with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD/KYC) required under Lei n.º 1/IX/2021 for all customers, including name, address, date of birth, national ID (cv.licensing.customer-due-diligence-cddkyc-implementing)
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusual transactions, cross-border correspondent relationships, and new technologies favoring anonymity (cv.aml.enhanced-due-diligence-edd-required, cv.aml.politically-exposed-persons-peps, cv.aml.customers-from-high-risk-jurisdictions-as, cv.aml.transactions-involving-new-technologies-or)
  • Suspicious Transaction Reporting (STR) to UIF (Unidade de Informação Financeira) without delay, regardless of amount (cv.licensing.suspicious-transaction-reporting-str-reporting, cv.aml.reporting-obligation-immediately-report-any)
  • Record-keeping of customer identification data and transaction details for at least 5 years after the business relationship ends (cv.licensing.record-keeping-maintaining-records-of-customer, cv.aml.retention-period-records-must-be)
  • Conduct risk assessments of ML/TF risks associated with business operations, customers, products, and services (cv.licensing.risk-assessments-conducting-a-thorough)
  • Establish internal controls, appoint an AML compliance officer, and provide staff training (cv.licensing.internal-controls-establishing-and-maintaining)
  • Ongoing monitoring of business relationships and transactions for consistency with customer risk profile (cv.aml.ongoing-monitoring-continuously-monitor-the)
  • No tipping-off prohibition — cannot disclose to customer or third party that an STR has been made (cv.aml.no-tipping-off-prohibit-the-disclosure)
  • Simplified Due Diligence (SDD) may be permitted for lower-risk customers on a risk-sensitive basis (cv.aml.simplified-due-diligence-sdd-may)

Key Restrictions

  • No specific crypto custody license exists — operator cannot obtain a bespoke custody license and must operate under general financial services law (cv.custody.no-specific-crypto-custody-license, cv.licensing.there-are-no-specific-laws)
  • BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, creating regulatory uncertainty for standalone custodial wallet operators (cv.licensing.it-has-clarified-that-cryptocurrencies, cv.licensing.crucially-the-bcv-has-stated)
  • If the operator handles fiat currency exchange or payment processing related to digital assets, it falls under a dedicated legal framework classifying crypto-assets as 'payment tokens' and may require a financial services license (cv.custody.entities-offering-services-involving-fiat)
  • General company registration in Cabo Verde is required, separate from any financial services licensing (cv.licensing.entities-wishing-to-operate-a)
  • No specific segregation of client asset rules for crypto — general financial prudency principles apply, referencing general banking and financial system laws (cv.custody.while-there-are-no-specific, cv.custody.references-would-be-found-in)
  • No specific insurance/bonding mandates for crypto custody; no cold storage mandates (cv.custody.no-specific-insurance-or-bonding, cv.custody.there-are-no-specific-mandates)
  • If digital assets are treated akin to financial instruments, a 'qualified custodian' would be a BCV-licensed bank, trust company, or investment firm — the custodial wallet SaaS provider would likely need to become or partner with such an entity (cv.custody.in-the-absence-of-dedicated)

Key Risks

  • Regulatory ambiguity — no dedicated crypto custody or VASP licensing regime exists, creating legal uncertainty for the operating model (cv.licensing.lack-of-dedicated-licensing-regime)
  • BCV has issued public warnings against cryptocurrencies and does not authorize/license virtual asset entities, increasing enforcement risk for unregulated operators (cv.enforcement.regulatory-stance-and-warnings-general, cv.enforcement.issuing-warnings-to-the-public)
  • General criminal law may apply to fraud cases involving crypto, handled by police/judicial system rather than a specialist financial regulator (cv.enforcement.any-cases-of-fraud-involving)
  • Pending legislation may bring VASPs under a future AML framework aligned with FATF — operators may face retroactive compliance burdens (cv.custody.the-most-likely-initial-regulatory, cv.licensing.cabo-verde-has-updated-its)
  • SaaS provider vs white-label client AML allocation is undefined — the facts do not distinguish AML obligations between the custody provider and downstream clients, creating gaps in compliance responsibility

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 40% confidence

No specific "crypto custody license" currently exists.

custody 40% confidence

However, any entity providing services that involve holding or managing financial assets, even digital ones, could potentially be deemed to be operating within the scope of existing financial services laws and regulations. This might necessitate obtaining a general financial services license or authorization from the Banco de Cabo Verde (BCV) if their activities are interpreted to fall under the definition of banking, investment services, or payment services.

custody 85% confidence

Entities offering services involving fiat currency exchange or payment processing related to digital assets in Cape Verde are subject to a dedicated legal framework that classifies crypto-assets under existing financial categories including 'payment tokens,' rather than merely falling under general payment services regulations by likelihood.

custody 40% confidence

While there are no specific crypto-custody segregation rules, the general principles of financial prudency and client protection applicable to traditional financial institutions in Cabo Verde would likely require segregation of client funds/assets from the operational capital of the service provider. This is a fundamental principle to prevent misuse of client assets and protect them in case of insolvency.

custody 85% confidence

References would be found in the general banking and financial system laws and prudential regulations issued by the BCV.

custody 40% confidence

No specific insurance or bonding requirements for crypto custody.

custody 40% confidence

There are no specific mandates for cold storage of digital assets.

custody 40% confidence

In the absence of dedicated crypto regulations, if digital assets were to be treated akin to other financial instruments, a "qualified custodian" would likely refer to an entity already licensed and regulated by the BCV as a bank, trust company, or investment firm authorized to hold client assets.

custody 40% confidence

The most likely initial regulatory step would be the inclusion of Virtual Asset Service Providers (VASPs) within the scope of the country's Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) framework, aligning with recommendations from the Financial Action Task Force (FATF). This would impose registration, KYC/CDD, transaction monitoring, and reporting obligations on entities dealing with virtual assets.

licensing 95% confidence

There are no specific laws or regulations that define a licensing framework for crypto exchanges, custody providers, or payment processors as distinct categories of financial institutions.

licensing 95% confidence

It has clarified that cryptocurrencies are not legal tender in Cabo Verde.

licensing 85% confidence

The BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, but it has actively issued public warnings and interventions (e.g., regarding OPTCOIN), indicating some regulatory oversight through public communications and evolving legal frameworks for digital currency.

licensing 90% confidence

Entities wishing to operate a business (including a crypto-related one) would need to comply with general company registration laws in Cabo Verde, but this is distinct from obtaining a financial services license.

licensing 95% confidence

Cabo Verde has updated its AML/CFT laws to align with FATF recommendations, which include virtual assets and VASPs.

licensing 60% confidence

Lei n.º 1/IX/2021, de 16 de março (AML/CFT Law): You would typically find this on the official gazette (Boletim Oficial) of Cabo Verde or through legal databases. A direct public URL from the government might be specific to a legislative portal. You can search for "Lei n.º 1/IX/2021 Cabo Verde branqueamento de capitais" to find official publications.

licensing 95% confidence

Customer Due Diligence (CDD/KYC): Implementing robust KYC procedures to identify and verify the identity of customers, including beneficial owners. This means collecting name, address, date of birth, national ID, etc.

licensing 95% confidence

Enhanced Due Diligence (EDD): For higher-risk customers or transactions.

licensing 95% confidence

Record-Keeping: Maintaining records of customer identification data and transaction details for a specified period (typically 5-7 years).

licensing 95% confidence

Suspicious Transaction Reporting (STR): Reporting any suspicious transactions or activities to the UIF without delay.

licensing 95% confidence

Risk Assessments: Conducting a thorough assessment of money laundering and terrorist financing risks associated with their business operations, customers, products, and services.

licensing 95% confidence

Internal Controls: Establishing and maintaining appropriate internal policies, procedures, and controls to mitigate ML/TF risks, including the appointment of an AML compliance officer and staff training.

aml 90% confidence

Enhanced Due Diligence (EDD): Required for higher-risk customers or transactions, including:

aml 90% confidence

Politically Exposed Persons (PEPs)

aml 85% confidence

Customers from high-risk jurisdictions (as identified by FATF or local authorities)

aml 85% confidence

Transactions involving new technologies or products that favor anonymity.

aml 90% confidence

Reporting Obligation: Immediately report any transaction (or attempted transaction), regardless of the amount, that the VASP suspects to be related to money laundering, terrorist financing, or proliferation financing.

aml 90% confidence

No Tipping-Off: Prohibit the disclosure to the customer or any third party that a suspicious transaction report is being or has been made, or that an AML/CFT investigation is being conducted.

aml 100% confidence

Retention Period: Records must be retained for at least five (5) years after the business relationship ends or after the date of an occasional transaction. These records must be readily available to competent authorities upon request.

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing customer records and updating information as needed.

aml 85% confidence

Simplified Due Diligence (SDD): May be permitted for lower-risk customers or transactions, provided the VASP can demonstrate the lower risk.

enforcement 95% confidence

Issuing warnings to the public about the risks of unregulated virtual assets.

enforcement 75% confidence

Any cases of fraud involving cryptocurrencies would likely be handled under general criminal law by the police and judicial system, rather than specific crypto-related enforcement by a financial regulator, especially if dedicated virtual asset laws are still nascent. These types of criminal cases are often not widely reported internationally with the specific details requested.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers may operate in Cape Verde only by registering as a general company and complying with AML/CFT obligations under Lei n.º 1/IX/2021 (which defines VASPs), but face significant regulatory uncertainty because no dedicated crypto custody license exists, BCV does not license virtual-asset-only entities, and the allocation of AML duties between the SaaS provider and white-label clients is undefined.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?