← Regulations / Djibouti / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Djibouti

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Djibouti without local incorporation, subject to AML obligations and none licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
None
Last updated
2026-07-13

AML Obligations

  • CDD/EDD obligations under Law No. 128/AN/18/8ème L — identify and verify customers (individuals: name, address, date of birth, nationality, unique ID; legal entities: legal name, form, proof of existence, authorized persons)
  • UBO identification — reasonable measures to identify natural persons who own or control the customer (25%+ ownership trigger)
  • Risk-based approach to assess and mitigate ML/TF risks associated with virtual asset products, services, customers, and delivery channels
  • FATF Travel Rule compliance — obtain and transmit originator and beneficiary information for virtual asset transfers above a threshold
  • Ongoing transaction monitoring to ensure consistency with customer risk profile
  • Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions, and customers in new anonymity-favoring technologies
  • Suspicious Transaction Reporting — submit STRs promptly to the Cellule de Traitement des Renseignements Financiers (CTRF/FIU) and refrain from tipping off
  • Record-keeping: identity/CDD records for at least 5 years after business relationship ends; transaction records for at least 5 years; STR documentation for a similar period
  • Simplified Due Diligence (SDD) permitted for lower-risk scenarios as per VASP's risk assessment
  • Supervised by Banque Centrale de Djibouti (BCD) for prudential AML/CFT compliance; CTRF as FIU for STR intake

Key Restrictions

  • No specific custodial license or qualified-custodian framework exists for digital assets — the operator cannot obtain a crypto-custody license and must operate under the general financial services umbrella regulated by the Central Bank
  • No explicit segregation-of-client-assets rules exist for digital assets — any segregation is voluntary best practice from traditional finance
  • No mandated insurance/bonding requirements for digital asset custodians
  • No cold-storage mandates or technical asset-storage requirements in legislation
  • No publicly announced pending custody legislation — the regime is entirely undeveloped

Key Risks

  • Regulatory vacuum — no specific license pathway creates legal uncertainty for custodial wallet operators; any operation could face retroactive regulation or enforcement
  • AML obligations under general law apply to VASPs but the law was written for traditional finance — interpretation and application to custodial wallet SaaS models is untested
  • No FATF-aligned VASP registration or supervision framework has been publicly operationalized, creating ambiguity on who must register and with whom
  • Low crypto adoption and lack of enforcement precedent means the regulator's actual stance toward custodial wallets is unknown
  • If future custody-specific regulation is enacted (e.g., capital requirements, proof-of-reserves, insurance mandates), existing operators may face costly compliance retrofits or grandfathering uncertainty

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 40% confidence

No specific custodial license for digital assets currently exists. Djibouti does not have a dedicated regulatory regime that requires entities providing crypto custody services to obtain a specific license.

custody 40% confidence

Any entity wishing to operate in the financial sector would generally need to comply with the broader banking and financial services laws regulated by the Central Bank. However, these laws typically do not explicitly cover digital asset custody.

custody 40% confidence

No specific rules for the segregation of client digital assets are in place. In the absence of a dedicated regulatory framework for digital asset custody, there are no explicit legal mandates requiring custodians to segregate client digital assets from their proprietary assets.

custody 40% confidence

No specific insurance or bonding requirements for digital asset custodians exist. Given the lack of a specific licensing regime, there are no mandated insurance or bonding coverages for crypto custody services.

custody 40% confidence

No specific cold storage mandates. The technical specifics of how digital assets should be stored (e.g., the percentage to be held in cold storage versus hot storage) are not addressed in any current Djiboutian legislation.

custody 40% confidence

No specific definition of a "qualified custodian" for digital assets. This concept, common in jurisdictions with mature crypto regulations (like the U.S. SEC's definition), does not exist in Djibouti's current legal framework.

custody 40% confidence

There is no publicly announced or readily available information regarding pending specific custody legislation for digital assets in Djibouti.

aml 40% confidence

Law No. 128/AN/18/8ème L of July 18, 2018, modifying and completing Law No. 136/AN/07/5ème L on Money Laundering, Terrorist Financing and Proliferation Financing.

aml 40% confidence

Be subject to the same AML/CFT obligations as traditional financial institutions. This means adhering to the principles outlined in Law No. 128/AN/18/8ème L.

aml 40% confidence

Implement a risk-based approach to identify, assess, and mitigate money laundering and terrorist financing risks associated with their virtual asset products, services, customers, and delivery channels.

aml 40% confidence

Comply with the FATF Travel Rule, which requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers above a certain threshold.

aml 40% confidence

Identifying and Verifying the Identity of the Customer:

aml 40% confidence

For individuals: Obtaining name, address, date of birth, nationality, and a unique identification number (e.g., national ID card, passport). Verification typically requires official, independent documents.

aml 40% confidence

For legal entities (companies, trusts, foundations): Obtaining legal name, legal form, proof of existence, powers that regulate the entity and bind it, address of registered office, and names of individuals who are authorized to act on behalf of the entity. Verification requires official registration documents.

aml 40% confidence

Identifying and Verifying the Ultimate Beneficial Owner (UBO): Taking reasonable measures to understand the ownership and control structure of the customer and identify the natural persons who ultimately own or control the customer. This often applies for entities where control is 25% or more.

aml 40% confidence

Understanding the Purpose and Intended Nature of the Business Relationship: Collecting information about the customer's anticipated activity, source of funds, and source of wealth (especially for high-risk customers or large transactions).

aml 40% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 40% confidence

Enhanced Due Diligence (EDD): Required for higher-risk scenarios, including:

aml 40% confidence

Politically Exposed Persons (PEPs)

aml 40% confidence

Customers from high-risk jurisdictions (as identified by FATF or national authorities)

aml 40% confidence

Complex, unusually large, or unusual transaction patterns

aml 40% confidence

Customers involved in new technologies or products that favor anonymity.

aml 40% confidence

Simplified Due Diligence (SDD): Permitted for lower-risk scenarios, as defined by the VASP's risk assessment and regulator's guidance.

aml 40% confidence

Report any suspicious transaction (including attempted transactions) where they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of a criminal activity or are related to terrorist financing.

aml 40% confidence

Submit STRs promptly to the Financial Intelligence Unit (FIU).

aml 40% confidence

Refrain from "tipping off" the customer or any third party that an STR has been filed.

aml 40% confidence

Identity records: All records obtained through CDD procedures (copies of identification documents, account files, business correspondence) for at least five (5) years after the business relationship is terminated.

aml 40% confidence

Transaction records: Records of transactions, including the amounts, currencies, and names/addresses of participants, for at least five (5) years from the date of the transaction.

aml 40% confidence

STRs and related internal documentation: Must also be kept for a similar period.

aml 40% confidence

Banque Centrale de Djibouti (BCD) - The Central Bank of Djibouti:

aml 40% confidence

The BCD is the main prudential regulator for financial institutions and is responsible for supervising their adherence to AML/CFT requirements. It issues regulations and guidance for the financial sector.

aml 40% confidence

Cellule de Traitement des Renseignements Financiers (CTRF) - The Financial Intelligence Unit (FIU):

enforcement 60% confidence

Absence of Specific Laws: As of my last update, Djibouti lacks a dedicated legal and regulatory framework for cryptocurrencies. This means there are no specific crypto laws to enforce.

enforcement 60% confidence

Limited Crypto Adoption: The overall adoption and usage of cryptocurrencies in Djibouti are relatively low compared to more developed economies.

enforcement 60% confidence

Regulatory Focus: The BCD's regulatory priorities may be focused on traditional financial sectors and broader financial stability, rather than active enforcement in an unregulated crypto space.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators can technically operate in Djibouti but in a complete regulatory vacuum: no specific custody license, segregation, insurance, cold-storage, or qualified-custodian rules exist, while general AML/CFT obligations under Law No. 128/AN/18/8ème L (CDD, Travel Rule, STRs to CTRF) apply to VASPs, supervised by the Banque Centrale de Djibouti.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?