Custodial wallet / SaaS in Djibouti
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Djibouti without local incorporation, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- CDD/EDD obligations under Law No. 128/AN/18/8ème L — identify and verify customers (individuals: name, address, date of birth, nationality, unique ID; legal entities: legal name, form, proof of existence, authorized persons)
- UBO identification — reasonable measures to identify natural persons who own or control the customer (25%+ ownership trigger)
- Risk-based approach to assess and mitigate ML/TF risks associated with virtual asset products, services, customers, and delivery channels
- FATF Travel Rule compliance — obtain and transmit originator and beneficiary information for virtual asset transfers above a threshold
- Ongoing transaction monitoring to ensure consistency with customer risk profile
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions, and customers in new anonymity-favoring technologies
- Suspicious Transaction Reporting — submit STRs promptly to the Cellule de Traitement des Renseignements Financiers (CTRF/FIU) and refrain from tipping off
- Record-keeping: identity/CDD records for at least 5 years after business relationship ends; transaction records for at least 5 years; STR documentation for a similar period
- Simplified Due Diligence (SDD) permitted for lower-risk scenarios as per VASP's risk assessment
- Supervised by Banque Centrale de Djibouti (BCD) for prudential AML/CFT compliance; CTRF as FIU for STR intake
Key Restrictions
- No specific custodial license or qualified-custodian framework exists for digital assets — the operator cannot obtain a crypto-custody license and must operate under the general financial services umbrella regulated by the Central Bank
- No explicit segregation-of-client-assets rules exist for digital assets — any segregation is voluntary best practice from traditional finance
- No mandated insurance/bonding requirements for digital asset custodians
- No cold-storage mandates or technical asset-storage requirements in legislation
- No publicly announced pending custody legislation — the regime is entirely undeveloped
Key Risks
- Regulatory vacuum — no specific license pathway creates legal uncertainty for custodial wallet operators; any operation could face retroactive regulation or enforcement
- AML obligations under general law apply to VASPs but the law was written for traditional finance — interpretation and application to custodial wallet SaaS models is untested
- No FATF-aligned VASP registration or supervision framework has been publicly operationalized, creating ambiguity on who must register and with whom
- Low crypto adoption and lack of enforcement precedent means the regulator's actual stance toward custodial wallets is unknown
- If future custody-specific regulation is enacted (e.g., capital requirements, proof-of-reserves, insurance mandates), existing operators may face costly compliance retrofits or grandfathering uncertainty
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific custodial license for digital assets currently exists. Djibouti does not have a dedicated regulatory regime that requires entities providing crypto custody services to obtain a specific license.
Any entity wishing to operate in the financial sector would generally need to comply with the broader banking and financial services laws regulated by the Central Bank. However, these laws typically do not explicitly cover digital asset custody.
No specific rules for the segregation of client digital assets are in place. In the absence of a dedicated regulatory framework for digital asset custody, there are no explicit legal mandates requiring custodians to segregate client digital assets from their proprietary assets.
No specific insurance or bonding requirements for digital asset custodians exist. Given the lack of a specific licensing regime, there are no mandated insurance or bonding coverages for crypto custody services.
No specific cold storage mandates. The technical specifics of how digital assets should be stored (e.g., the percentage to be held in cold storage versus hot storage) are not addressed in any current Djiboutian legislation.
No specific definition of a "qualified custodian" for digital assets. This concept, common in jurisdictions with mature crypto regulations (like the U.S. SEC's definition), does not exist in Djibouti's current legal framework.
There is no publicly announced or readily available information regarding pending specific custody legislation for digital assets in Djibouti.
Law No. 128/AN/18/8ème L of July 18, 2018, modifying and completing Law No. 136/AN/07/5ème L on Money Laundering, Terrorist Financing and Proliferation Financing.
Be subject to the same AML/CFT obligations as traditional financial institutions. This means adhering to the principles outlined in Law No. 128/AN/18/8ème L.
Implement a risk-based approach to identify, assess, and mitigate money laundering and terrorist financing risks associated with their virtual asset products, services, customers, and delivery channels.
Comply with the FATF Travel Rule, which requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers above a certain threshold.
For individuals: Obtaining name, address, date of birth, nationality, and a unique identification number (e.g., national ID card, passport). Verification typically requires official, independent documents.
For legal entities (companies, trusts, foundations): Obtaining legal name, legal form, proof of existence, powers that regulate the entity and bind it, address of registered office, and names of individuals who are authorized to act on behalf of the entity. Verification requires official registration documents.
Identifying and Verifying the Ultimate Beneficial Owner (UBO): Taking reasonable measures to understand the ownership and control structure of the customer and identify the natural persons who ultimately own or control the customer. This often applies for entities where control is 25% or more.
Understanding the Purpose and Intended Nature of the Business Relationship: Collecting information about the customer's anticipated activity, source of funds, and source of wealth (especially for high-risk customers or large transactions).
Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Required for higher-risk scenarios, including:
Customers from high-risk jurisdictions (as identified by FATF or national authorities)
Customers involved in new technologies or products that favor anonymity.
Simplified Due Diligence (SDD): Permitted for lower-risk scenarios, as defined by the VASP's risk assessment and regulator's guidance.
Report any suspicious transaction (including attempted transactions) where they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of a criminal activity or are related to terrorist financing.
Submit STRs promptly to the Financial Intelligence Unit (FIU).
Refrain from "tipping off" the customer or any third party that an STR has been filed.
Identity records: All records obtained through CDD procedures (copies of identification documents, account files, business correspondence) for at least five (5) years after the business relationship is terminated.
Transaction records: Records of transactions, including the amounts, currencies, and names/addresses of participants, for at least five (5) years from the date of the transaction.
STRs and related internal documentation: Must also be kept for a similar period.
Banque Centrale de Djibouti (BCD) - The Central Bank of Djibouti:
The BCD is the main prudential regulator for financial institutions and is responsible for supervising their adherence to AML/CFT requirements. It issues regulations and guidance for the financial sector.
Cellule de Traitement des Renseignements Financiers (CTRF) - The Financial Intelligence Unit (FIU):
Absence of Specific Laws: As of my last update, Djibouti lacks a dedicated legal and regulatory framework for cryptocurrencies. This means there are no specific crypto laws to enforce.
Limited Crypto Adoption: The overall adoption and usage of cryptocurrencies in Djibouti are relatively low compared to more developed economies.
Regulatory Focus: The BCD's regulatory priorities may be focused on traditional financial sectors and broader financial stability, rather than active enforcement in an unregulated crypto space.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators can technically operate in Djibouti but in a complete regulatory vacuum: no specific custody license, segregation, insurance, cold-storage, or qualified-custodian rules exist, while general AML/CFT obligations under Law No. 128/AN/18/8ème L (CDD, Travel Rule, STRs to CTRF) apply to VASPs, supervised by the Banque Centrale de Djibouti.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?