DeFi protocol frontend in Cabo Verde
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Cabo Verde without local incorporation, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD/KYC): Must implement robust KYC procedures to identify and verify customers, including beneficial owners (name, address, date of birth, national ID, etc.) — see cv.licensing.customer-due-diligence-cddkyc-implementing
- Enhanced Due Diligence (EDD): Required for higher-risk customers (PEPs, high-risk jurisdictions, complex/unusually large transactions, transactions involving new technologies favoring anonymity) — see cv.aml.enhanced-due-diligence-edd-required, cv.aml.politically-exposed-persons-peps, cv.aml.customers-from-high-risk-jurisdictions-as, cv.aml.complex-unusually-large-transactions-or, cv.aml.transactions-involving-new-technologies-or
- Suspicious Transaction Reporting (STR): Must immediately report any suspicious transaction (or attempted transaction), regardless of amount, to the Unidade de Informação Financeira (UIF) without delay — see cv.licensing.suspicious-transaction-reporting-str-reporting, cv.aml.reporting-obligation-immediately-report-any
- Record-Keeping: Maintain all transaction records, customer identification data, and CDD analysis for at least 5 years after business relationship ends or after an occasional transaction — see cv.licensing.record-keeping-maintaining-records-of-customer, cv.aml.retention-period-records-must-be
- Risk Assessment: Must conduct a thorough ML/TF risk assessment of the business operations, customers, products, and services — see cv.licensing.risk-assessments-conducting-a-thorough
- Internal Controls: Must establish and maintain internal policies, procedures, and controls including appointment of an AML compliance officer and staff training — see cv.licensing.internal-controls-establishing-and-maintaining
- No Tipping-Off: Prohibition on disclosing to customers or third parties that an STR has been or is being made — see cv.aml.no-tipping-off-prohibit-the-disclosure
- Risk-Based Approach: CDD measures must be applied on a risk-sensitive basis (SDD for lower risk, EDD for higher risk) — see cv.aml.risk-based-approach-apply-cdd-measures, cv.aml.simplified-due-diligence-sdd-may
Key Restrictions
- No specific crypto licensing framework exists — the operator must be structured to fall outside traditional financial services licensing (e.g., avoid fiat on-ramp/off-ramp or remittance services) to avoid triggering BCV licensing requirements for financial institutions — see cv.licensing.if-a-company-were-to, cv.licensing.there-are-no-specific-laws
- If the frontend takes fees in fiat currency or processes fiat payments, it may trigger existing BCV licensing for payment processing or remittances — see cv.licensing.if-a-company-were-to
- The BCV has issued repeated public warnings against cryptocurrencies and does not authorize/supervise/license entities dealing exclusively with virtual assets — operating in a public-facing manner carries reputational/regulatory attention risk — see cv.licensing.the-banco-de-cabo-verde, cv.licensing.crucially-the-bcv-has-stated
- No dedicated VASP registration regime exists — general company registration is required for any business operating in Cabo Verde, but this is distinct from a financial license — see cv.licensing.neither-a-specific-licensing-nor, cv.licensing.entities-wishing-to-operate-a
Key Risks
- Regulatory ambiguity: The BCV's stance is hostile and warnings are frequent, but the legal framework for VASPs is nascent and AML-only — no clear 'permission to operate' path exists for crypto-native businesses
- Enforcement risk for fee-taking: If the frontend charges fees (e.g., swap fees, routing fees), it could be reclassified as a financial service requiring BCV licensing, with potential for enforcement action or public warning
- No safe harbor for 'decentralized' claim: The BCV has not distinguished between decentralized protocol frontends and centralized VASPs — the operator could be treated as a VASP under Lei n.º 1/IX/2021 solely by operating the frontend
- AML compliance burden without clear supervisory guidance: The UIF expects STRs and CDD from VASPs but there is no tailored guidance for DeFi frontends, creating compliance uncertainty
- FATF alignment creates obligations: Cabo Verde has updated AML/CFT laws per FATF recommendations that include virtual assets and VASPs, meaning the frontend operator likely has obligations even if the BCV refuses to license them — see cv.licensing.cabo-verde-has-updated-its
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Banco de Cabo Verde (BCV), the central bank, has repeatedly issued public warnings regarding the risks associated with cryptocurrencies.
The BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, but it has actively issued public warnings and interventions (e.g., regarding OPTCOIN), indicating some regulatory oversight through public communications and evolving legal frameworks for digital currency.
There are no specific laws or regulations that define a licensing framework for crypto exchanges, custody providers, or payment processors as distinct categories of financial institutions.
Neither a specific licensing nor a dedicated registration regime for Virtual Asset Service Providers (VASPs) exists in Cabo Verde.
Entities wishing to operate a business (including a crypto-related one) would need to comply with general company registration laws in Cabo Verde, but this is distinct from obtaining a financial services license.
If a company were to deal with fiat currency in a way that constitutes a traditional financial service (e.g., remittances, payment processing of traditional money), then those specific activities would fall under the BCV's existing licensing requirements for financial institutions, which are separate from crypto activities.
Cabo Verde has updated its AML/CFT laws to align with FATF recommendations, which include virtual assets and VASPs.
Key Law: Lei n.º 1/IX/2021, de 16 de março, on the Prevention and Combat of Money Laundering and the Financing of Terrorism, explicitly defines "Ativo Virtual" (Virtual Asset) and "Prestador de Serviços de Ativos Virtuais" (Virtual Asset Service Provider) and subjects them to AML/CFT obligations.
Customer Due Diligence (CDD/KYC): Implementing robust KYC procedures to identify and verify the identity of customers, including beneficial owners. This means collecting name, address, date of birth, national ID, etc.
Enhanced Due Diligence (EDD): For higher-risk customers or transactions.
Suspicious Transaction Reporting (STR): Reporting any suspicious transactions or activities to the UIF without delay.
Record-Keeping: Maintaining records of customer identification data and transaction details for a specified period (typically 5-7 years).
Risk Assessments: Conducting a thorough assessment of money laundering and terrorist financing risks associated with their business operations, customers, products, and services.
Internal Controls: Establishing and maintaining appropriate internal policies, procedures, and controls to mitigate ML/TF risks, including the appointment of an AML compliance officer and staff training.
Reporting Obligation: Immediately report any transaction (or attempted transaction), regardless of the amount, that the VASP suspects to be related to money laundering, terrorist financing, or proliferation financing.
No Tipping-Off: Prohibit the disclosure to the customer or any third party that a suspicious transaction report is being or has been made, or that an AML/CFT investigation is being conducted.
Retention Period: Records must be retained for at least five (5) years after the business relationship ends or after the date of an occasional transaction. These records must be readily available to competent authorities upon request.
Enhanced Due Diligence (EDD): Required for higher-risk customers or transactions, including:
Customers from high-risk jurisdictions (as identified by FATF or local authorities)
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
Transactions involving new technologies or products that favor anonymity.
Risk-Based Approach: Apply CDD measures on a risk-sensitive basis:
Simplified Due Diligence (SDD): May be permitted for lower-risk customers or transactions, provided the VASP can demonstrate the lower risk.
Regulatory Stance and Warnings (General "Actions"):
Issuing warnings to the public about the risks of unregulated virtual assets.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend may be operated in Cabo Verde but falls into a regulatory grey zone: no dedicated licensing regime exists, the central bank (BCV) has a hostile stance and issues public warnings, and the operator is deemed a VASP subject to AML/CFT obligations under Lei n.º 1/IX/2021 (including KYC, STR to UIF, and record-keeping), with heightened risk if it takes fees in fiat (triggering traditional financial services licensing).
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?