Custodial wallet / SaaS in Cabo Verde
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Cabo Verde with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD/KYC) required under Lei n.º 1/IX/2021 for all customers, including name, address, date of birth, national ID (cv.licensing.customer-due-diligence-cddkyc-implementing)
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusual transactions, cross-border correspondent relationships, and new technologies favoring anonymity (cv.aml.enhanced-due-diligence-edd-required, cv.aml.politically-exposed-persons-peps, cv.aml.customers-from-high-risk-jurisdictions-as, cv.aml.transactions-involving-new-technologies-or)
- Suspicious Transaction Reporting (STR) to UIF (Unidade de Informação Financeira) without delay, regardless of amount (cv.licensing.suspicious-transaction-reporting-str-reporting, cv.aml.reporting-obligation-immediately-report-any)
- Record-keeping of customer identification data and transaction details for at least 5 years after the business relationship ends (cv.licensing.record-keeping-maintaining-records-of-customer, cv.aml.retention-period-records-must-be)
- Conduct risk assessments of ML/TF risks associated with business operations, customers, products, and services (cv.licensing.risk-assessments-conducting-a-thorough)
- Establish internal controls, appoint an AML compliance officer, and provide staff training (cv.licensing.internal-controls-establishing-and-maintaining)
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile (cv.aml.ongoing-monitoring-continuously-monitor-the)
- No tipping-off prohibition — cannot disclose to customer or third party that an STR has been made (cv.aml.no-tipping-off-prohibit-the-disclosure)
- Simplified Due Diligence (SDD) may be permitted for lower-risk customers on a risk-sensitive basis (cv.aml.simplified-due-diligence-sdd-may)
Key Restrictions
- No specific crypto custody license exists — operator cannot obtain a bespoke custody license and must operate under general financial services law (cv.custody.no-specific-crypto-custody-license, cv.licensing.there-are-no-specific-laws)
- BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, creating regulatory uncertainty for standalone custodial wallet operators (cv.licensing.it-has-clarified-that-cryptocurrencies, cv.licensing.crucially-the-bcv-has-stated)
- If the operator handles fiat currency exchange or payment processing related to digital assets, it falls under a dedicated legal framework classifying crypto-assets as 'payment tokens' and may require a financial services license (cv.custody.entities-offering-services-involving-fiat)
- General company registration in Cabo Verde is required, separate from any financial services licensing (cv.licensing.entities-wishing-to-operate-a)
- No specific segregation of client asset rules for crypto — general financial prudency principles apply, referencing general banking and financial system laws (cv.custody.while-there-are-no-specific, cv.custody.references-would-be-found-in)
- No specific insurance/bonding mandates for crypto custody; no cold storage mandates (cv.custody.no-specific-insurance-or-bonding, cv.custody.there-are-no-specific-mandates)
- If digital assets are treated akin to financial instruments, a 'qualified custodian' would be a BCV-licensed bank, trust company, or investment firm — the custodial wallet SaaS provider would likely need to become or partner with such an entity (cv.custody.in-the-absence-of-dedicated)
Key Risks
- Regulatory ambiguity — no dedicated crypto custody or VASP licensing regime exists, creating legal uncertainty for the operating model (cv.licensing.lack-of-dedicated-licensing-regime)
- BCV has issued public warnings against cryptocurrencies and does not authorize/license virtual asset entities, increasing enforcement risk for unregulated operators (cv.enforcement.regulatory-stance-and-warnings-general, cv.enforcement.issuing-warnings-to-the-public)
- General criminal law may apply to fraud cases involving crypto, handled by police/judicial system rather than a specialist financial regulator (cv.enforcement.any-cases-of-fraud-involving)
- Pending legislation may bring VASPs under a future AML framework aligned with FATF — operators may face retroactive compliance burdens (cv.custody.the-most-likely-initial-regulatory, cv.licensing.cabo-verde-has-updated-its)
- SaaS provider vs white-label client AML allocation is undefined — the facts do not distinguish AML obligations between the custody provider and downstream clients, creating gaps in compliance responsibility
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
However, any entity providing services that involve holding or managing financial assets, even digital ones, could potentially be deemed to be operating within the scope of existing financial services laws and regulations. This might necessitate obtaining a general financial services license or authorization from the Banco de Cabo Verde (BCV) if their activities are interpreted to fall under the definition of banking, investment services, or payment services.
Entities offering services involving fiat currency exchange or payment processing related to digital assets in Cape Verde are subject to a dedicated legal framework that classifies crypto-assets under existing financial categories including 'payment tokens,' rather than merely falling under general payment services regulations by likelihood.
While there are no specific crypto-custody segregation rules, the general principles of financial prudency and client protection applicable to traditional financial institutions in Cabo Verde would likely require segregation of client funds/assets from the operational capital of the service provider. This is a fundamental principle to prevent misuse of client assets and protect them in case of insolvency.
References would be found in the general banking and financial system laws and prudential regulations issued by the BCV.
No specific insurance or bonding requirements for crypto custody.
There are no specific mandates for cold storage of digital assets.
In the absence of dedicated crypto regulations, if digital assets were to be treated akin to other financial instruments, a "qualified custodian" would likely refer to an entity already licensed and regulated by the BCV as a bank, trust company, or investment firm authorized to hold client assets.
The most likely initial regulatory step would be the inclusion of Virtual Asset Service Providers (VASPs) within the scope of the country's Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) framework, aligning with recommendations from the Financial Action Task Force (FATF). This would impose registration, KYC/CDD, transaction monitoring, and reporting obligations on entities dealing with virtual assets.
There are no specific laws or regulations that define a licensing framework for crypto exchanges, custody providers, or payment processors as distinct categories of financial institutions.
It has clarified that cryptocurrencies are not legal tender in Cabo Verde.
The BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, but it has actively issued public warnings and interventions (e.g., regarding OPTCOIN), indicating some regulatory oversight through public communications and evolving legal frameworks for digital currency.
Entities wishing to operate a business (including a crypto-related one) would need to comply with general company registration laws in Cabo Verde, but this is distinct from obtaining a financial services license.
Cabo Verde has updated its AML/CFT laws to align with FATF recommendations, which include virtual assets and VASPs.
Lei n.º 1/IX/2021, de 16 de março (AML/CFT Law): You would typically find this on the official gazette (Boletim Oficial) of Cabo Verde or through legal databases. A direct public URL from the government might be specific to a legislative portal. You can search for "Lei n.º 1/IX/2021 Cabo Verde branqueamento de capitais" to find official publications.
Customer Due Diligence (CDD/KYC): Implementing robust KYC procedures to identify and verify the identity of customers, including beneficial owners. This means collecting name, address, date of birth, national ID, etc.
Enhanced Due Diligence (EDD): For higher-risk customers or transactions.
Record-Keeping: Maintaining records of customer identification data and transaction details for a specified period (typically 5-7 years).
Suspicious Transaction Reporting (STR): Reporting any suspicious transactions or activities to the UIF without delay.
Risk Assessments: Conducting a thorough assessment of money laundering and terrorist financing risks associated with their business operations, customers, products, and services.
Internal Controls: Establishing and maintaining appropriate internal policies, procedures, and controls to mitigate ML/TF risks, including the appointment of an AML compliance officer and staff training.
Enhanced Due Diligence (EDD): Required for higher-risk customers or transactions, including:
Customers from high-risk jurisdictions (as identified by FATF or local authorities)
Transactions involving new technologies or products that favor anonymity.
Reporting Obligation: Immediately report any transaction (or attempted transaction), regardless of the amount, that the VASP suspects to be related to money laundering, terrorist financing, or proliferation financing.
No Tipping-Off: Prohibit the disclosure to the customer or any third party that a suspicious transaction report is being or has been made, or that an AML/CFT investigation is being conducted.
Retention Period: Records must be retained for at least five (5) years after the business relationship ends or after the date of an occasional transaction. These records must be readily available to competent authorities upon request.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing customer records and updating information as needed.
Simplified Due Diligence (SDD): May be permitted for lower-risk customers or transactions, provided the VASP can demonstrate the lower risk.
Regulatory Stance and Warnings (General "Actions"):
Issuing warnings to the public about the risks of unregulated virtual assets.
Any cases of fraud involving cryptocurrencies would likely be handled under general criminal law by the police and judicial system, rather than specific crypto-related enforcement by a financial regulator, especially if dedicated virtual asset laws are still nascent. These types of criminal cases are often not widely reported internationally with the specific details requested.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers may operate in Cape Verde only by registering as a general company and complying with AML/CFT obligations under Lei n.º 1/IX/2021 (which defines VASPs), but face significant regulatory uncertainty because no dedicated crypto custody license exists, BCV does not license virtual-asset-only entities, and the allocation of AML duties between the SaaS provider and white-label clients is undefined.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?