On-shore VASP in Cabo Verde
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Cabo Verde with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD/KYC): Implement procedures to identify and verify customers and beneficial owners under Lei n.º 1/IX/2021 and Law No. 10/VIII/2011.
- Enhanced Due Diligence (EDD): Required for PEPs, high-risk jurisdictions, complex or unusually large transactions, and transactions involving new technologies favoring anonymity.
- Record-Keeping: Maintain customer identification data and transaction records for at least 5 years, per AML/CFT legislation (Lei n.º 1/IX/2021 and Law No. 10/VIII/2011).
- Suspicious Transaction Reporting (STR): Report any suspicious transactions to the Unidade de Informação Financeira (UIF) without delay, regardless of amount.
- Risk Assessments: Conduct ML/TF risk assessments covering business operations, customers, products, and services.
- Internal Controls: Appoint an AML compliance officer, establish internal policies/procedures, and conduct staff training.
- Travel Rule Compliance: Collect, retain, and transmit originator and beneficiary information for all virtual asset transfers (zero threshold for custodial transfers; EUR 1,000 threshold for certain detailed data points) per Instruction No. 3/2021.
- Secure transmission of Travel Rule data required; no specific technical solution mandated (e.g., TRISA, OpenVASP, SYGNA).
- No Tipping-Off: Prohibited from disclosing to customers or third parties that an STR has been or will be filed.
Key Restrictions
- No dedicated crypto licensing regime exists — VASPs must comply with general company registration laws and cannot obtain a specific financial services license for VASP activities from BCV.
- BCV has publicly stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, creating legal uncertainty.
- If dealing with fiat currency in a way that constitutes traditional financial services (e.g., remittances, payment processing), those activities fall under separate BCV licensing requirements.
- Cryptocurrencies are not legal tender in Cabo Verde per BCV statements.
- Decree-Law No. 5/2020 brings VASPs under BCV supervision and subjects them to AML/CFT obligations, but no implementing licensing or registration mechanism has been fully operationalized for VASPs.
- No specific crypto custody license, segregation rules, cold storage mandates, or insurance requirements exist for digital assets.
Key Risks
- Regulatory ambiguity — BCV has warned against crypto risks but not established a clear path to licensure, creating material legal risk for on-shore operation.
- Enforcement exposure — BCV has intervened publicly (e.g., regarding OPTCOIN) and could take action against unlicensed operators under general financial laws.
- No dedicated crypto custody framework means client asset protection is legally uncertain; general prudential standards for traditional financial institutions may apply by analogy.
- AML/CFT compliance obligations are well-defined (Lei n.º 1/IX/2021), but the lack of a licensing gateway means an operator may be regulated without being formally authorized.
- Criminal liability risk — non-compliance with AML/CFT obligations can lead to criminal charges, imprisonment, asset forfeiture under Law No. 37/VIII/2011.
- Significant administrative fines for data protection non-compliance (CVE 1M–100M for first offense, up to CVE 300M for repeat) under Law 133/V.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Banco de Cabo Verde (BCV), the central bank, has repeatedly issued public warnings regarding the risks associated with cryptocurrencies.
It has clarified that cryptocurrencies are not legal tender in Cabo Verde.
The BCV has stated it does not authorize, supervise, or license entities that deal exclusively with virtual assets, but it has actively issued public warnings and interventions (e.g., regarding OPTCOIN), indicating some regulatory oversight through public communications and evolving legal frameworks for digital currency.
There are no specific laws or regulations that define a licensing framework for crypto exchanges, custody providers, or payment processors as distinct categories of financial institutions.
Neither a specific licensing nor a dedicated registration regime for Virtual Asset Service Providers (VASPs) exists in Cabo Verde.
Entities wishing to operate a business (including a crypto-related one) would need to comply with general company registration laws in Cabo Verde, but this is distinct from obtaining a financial services license.
If a company were to deal with fiat currency in a way that constitutes a traditional financial service (e.g., remittances, payment processing of traditional money), then those specific activities would fall under the BCV's existing licensing requirements for financial institutions, which are separate from crypto activities.
Key Law: Lei n.º 1/IX/2021, de 16 de março, on the Prevention and Combat of Money Laundering and the Financing of Terrorism, explicitly defines "Ativo Virtual" (Virtual Asset) and "Prestador de Serviços de Ativos Virtuais" (Virtual Asset Service Provider) and subjects them to AML/CFT obligations.
Specific AML/CFT Requirements for VASPs (as "Reporting Entities"):
Customer Due Diligence (CDD/KYC): Implementing robust KYC procedures to identify and verify the identity of customers, including beneficial owners. This means collecting name, address, date of birth, national ID, etc.
Enhanced Due Diligence (EDD): For higher-risk customers or transactions.
Record-Keeping: Maintaining records of customer identification data and transaction details for a specified period (typically 5-7 years).
Suspicious Transaction Reporting (STR): Reporting any suspicious transactions or activities to the UIF without delay.
Risk Assessments: Conducting a thorough assessment of money laundering and terrorist financing risks associated with their business operations, customers, products, and services.
Internal Controls: Establishing and maintaining appropriate internal policies, procedures, and controls to mitigate ML/TF risks, including the appointment of an AML compliance officer and staff training.
Law No. 10/VIII/2011, of 23 May: This is the foundational law on the Prevention and Combat of Money Laundering, Financing of Terrorism and Proliferation of Weapons of Mass Destruction. It establishes the general framework for AML/CFT obligations, including customer due diligence, suspicious transaction reporting, and record-keeping.
Decree-Law No. 4/2015, of 19 January: This decree-law approves the Regulation for the Implementation of Law No. 10/VIII/2011, providing more detailed guidance on how the AML/CFT obligations are to be met.
Enhanced Due Diligence (EDD): Required for higher-risk customers or transactions, including:
Customers from high-risk jurisdictions (as identified by FATF or local authorities)
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
Transactions involving new technologies or products that favor anonymity.
Reporting Obligation: Immediately report any transaction (or attempted transaction), regardless of the amount, that the VASP suspects to be related to money laundering, terrorist financing, or proliferation financing.
No Tipping-Off: Prohibit the disclosure to the customer or any third party that a suspicious transaction report is being or has been made, or that an AML/CFT investigation is being conducted.
Retention Period: Records must be retained for at least five (5) years after the business relationship ends or after the date of an occasional transaction. These records must be readily available to competent authorities upon request.
Unidade de Informação Financeira (UIF) – Financial Intelligence Unit:
Foundational Law: The legal framework for virtual assets (VAs) and Virtual Asset Service Providers (VASPs) in Cabo Verde was established by Decree-Law No. 5/2020 of January 27, 2020. This law defines VAs and VASPs, brings them under the supervision of the Banco de Cabo Verde (BCV), and subjects them to anti-money laundering and combating the financing of terrorism (AML/CFT) obligations.
Travel Rule Implementation: The specific requirements for the FATF Travel Rule, including the collection and transmission of originator and beneficiary information, are detailed in Instruction No. 3/2021 of January 28, 2021, of the Banco de Cabo Verde. This instruction operationalizes the AML/CFT obligations for VASPs, including those related to the Travel Rule.
Zero Threshold for Custodial Transfers: For transfers between VASPs (or from a VASP to a non-custodial wallet when initiated by a VASP customer), the full Travel Rule information is generally required for all transactions, regardless of amount.
Threshold for Specific Data Points: While information is required for all transfers, certain detailed information requirements (e.g., full address of the originator/beneficiary) may have a threshold. Based on standard FATF implementation, this typically aligns with the EUR 1,000 (or equivalent) threshold. For transactions below this amount, VASPs might be allowed to collect less granular information, provided they can still identify the originator and beneficiary and reconstruct the transaction. However, the core obligation to obtain some identifying information remains for all transfers.
Collect and Retain Information: Obtain and retain the required originator and beneficiary information for all virtual asset transfers.
Transmit Information: Ensure that transfers of virtual assets are accompanied by the necessary originator and beneficiary information to the beneficiary VASP (or to the non-custodial wallet owner, if applicable).
Secure Transmission: The information must be transmitted securely and reliably. The instruction does not prescribe a specific technical solution (e.g., TRISA, OpenVASP, SYGNA), but requires the capability and execution of transmitting this data.
Risk-Based Approach: VASPs must implement a risk-based approach to monitor transactions and report suspicious activities to the Financial Information Unit (FIU) of Cabo Verde.
Administrative fines under Cape Verde Law 133/V (Data Protection) range from CVE 1 million to CVE 100 million for first offenses and from CVE 100 million to CVE 300 million for repeat violations, with the specific amounts varying by severity and recurrence.
Criminal Charges: Depending on the nature of the non-compliance (e.g., involvement in money laundering or terrorist financing), individuals and legal entities could face criminal prosecution, imprisonment, and asset forfeiture, as defined by Cabo Verde's general AML/CFT laws (e.g., Law No. 37/VIII/2013 and its subsequent amendments).
Primary Regulator: The Banco de Cabo Verde (BCV) is the central bank and the main authority responsible for overseeing financial institutions and monetary policy. It is also the most likely body to address issues related to virtual assets and cryptocurrencies from a financial stability and consumer protection perspective.
Regulatory Stance and Warnings (General "Actions"):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — An on-shore VASP can operate in Cabo Verde only by complying with general company registration laws and AML/CFT obligations under Lei n.º 1/IX/2021 and Decree-Law No. 5/2020 (including full Travel Rule), but there is no dedicated VASP licensing pathway, the BCV has stated it does not license entities dealing exclusively with virtual assets, and the regulatory framework remains ambiguous, creating material legal risk.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?