Custodial wallet / SaaS in Fiji
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Fiji with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Must register as a 'reporting institution' under the Financial Transactions Reporting Act 2004 (FTRA) — crypto custodial operations likely fall under the definition of a financial institution or DNFBP.
- Customer Due Diligence (CDD): Obtain and verify identity for individual customers (national ID, passport, driver's license — full name, DOB, address, nationality) and legal entities (name, legal form, proof of existence, registered address, directors).
- Beneficial ownership identification: Identify ultimate natural persons with 25% or more ownership/control of legal-entity customers.
- Ongoing monitoring: Continuously monitor business relationships and transactions for consistency with customer risk profile; flag unusual/suspicious activity.
- Suspicious Transaction Reporting (STR): No monetary threshold — any suspected ML/TF transaction (including attempted) must be reported promptly to the Fiji FIU.
- Enhanced Due Diligence (EDD): Required for PEPs, high-risk jurisdictions, complex/unusual transactions, non-face-to-face relationships, and customers in high-risk sectors (virtual assets are treated as higher risk).
- Record-keeping: Maintain all CDD data, transaction records, and STR-related documentation per FTRA requirements.
- No tipping-off: Prohibited from informing customers or third parties that an STR has been filed.
- AML Compliance Officer: Must appoint a designated AML Compliance Officer responsible for internal reporting and STR filing with the FIU.
- No explicit exemption for white-label/SaaS arrangements — both the SaaS platform and the white-label client likely carry independent AML obligations if each is a reporting institution.
Key Restrictions
- No specific crypto custody license exists — the operation cannot qualify as a 'qualified custodian' under Fijian law, creating structural legal uncertainty.
- If custodial services extend into exchange, lending, brokerage, or other financial services, appropriate licenses under the Banking Act 1995 or other financial services legislation would be required.
- Cryptocurrencies are not recognized as legal tender by the RBF and are subject to repeated public warnings — operating a crypto business carries an elevated reputational and regulatory risk.
- Any offering of tokens that could be classified as securities (investment tokens, security tokens, certain stablecoins) would trigger prospectus requirements under the Companies Act 2015 and potential RBF licensing for the platform.
- No cold storage, insurance, or segregation mandates exist — but lack of a defined framework means best-practice compliance is self-imposed and untested by regulators.
Key Risks
- Regulatory vacuum: No specific crypto custody framework means the model operates in a grey zone — the RBF may issue retroactive restrictions or enforcement actions.
- Repeated RBF public warnings against crypto (2021, 2022, 2023) signal regulatory hostility and potential future prohibition.
- FATF Mutual Evaluation Report (2022) highlighted Fiji's VA framework gaps — pressure to align with FATF standards could result in sudden new obligations or licensing requirements.
- No insurance or segregation requirements means custodial risk (hack, fraud, operational failure) sits entirely on the operator with no regulatory safety net.
- AML/CFT obligations apply but are designed for traditional financial institutions — compliance for a crypto custodial SaaS model is untested and may attract FIU scrutiny.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific license for cryptocurrency custody exists. As cryptocurrencies are not recognized as regulated financial products under the current RBF framework, there is no specific "crypto custodian license."
If an entity's operations extend beyond pure custody into other financial services (e.g., exchange, lending, brokerage) and those services fall under existing definitions within the Banking Act 1995 or other financial services legislation, then appropriate licenses for those activities would be required. However, such legislation does not currently explicitly include digital assets.
No specific rules for cryptocurrency asset segregation exist. Since there is no specific regulatory framework for crypto custody, there are no mandates for how client digital assets should be segregated from the custodian's proprietary assets.
No specific insurance or bonding requirements for cryptocurrency custodians exist. Given the absence of a dedicated framework, there are no mandates for custodians to carry specific insurance policies or bonding to cover potential losses due to hacks, fraud, or operational failures.
No specific cold storage mandates exist. There are no regulatory requirements dictating the use or proportion of cold storage (offline storage) for digital assets held in custody. Industry best practices, again, would guide custodians to use a combination of hot, warm, and cold storage for security.
No specific definition of a "qualified custodian" for digital assets exists. The RBF has not introduced any regulatory definitions or criteria for what constitutes a qualified custodian in the context of cryptocurrencies.
Financial Transactions Reporting Act 2004 (FTRA):
Banking Act 1995:
Security Tokens: These are tokens that explicitly represent traditional securities, such as shares in a company, bonds, units in a collective investment scheme, or other financial instruments. Examples include tokens representing equity, debt, or profit-sharing rights.
Prospectus Requirement: Generally, an offer of securities to the public in Fiji requires the preparation and registration of a prospectus with the Registrar of Companies. This prospectus must contain all material information necessary for investors to make an informed decision.
AML/CFT Compliance: Any entity (exchange, broker, OTC desk) involved in the secondary trading of virtual assets (whether securities or not) is considered a "financial institution" or "designated non-financial business and profession" under Fiji's Anti-Money Laundering and Counter-Financing of Terrorism Act 2017. They would be subject to stringent AML/CFT obligations, including customer due diligence (KYC), suspicious transaction reporting, and record-keeping.
Financial Transactions Reporting Act 2004 (FTRA 2004): This is the foundational AML/CFT law in Fiji. It establishes the framework for reporting institutions, customer due diligence, suspicious transaction reporting, and the powers of the Financial Intelligence Unit (FIU).
Customer Identification and Verification:
Individual Customers: Obtain and verify identity using reliable, independent sources (e.g., national ID cards, passports, driver's licenses). This includes full name, date of birth, residential address, and nationality.
Legal Entities (Companies, Trusts, etc.): Obtain and verify the entity's name, legal form, proof of existence, registered address, and the names of directors/partners/trustees.
Beneficial Ownership: Identify and verify the ultimate natural person(s) who own or control the customer, or on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals with 25% or more ownership/control.
Purpose and Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or transaction to assess potential risks.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Enhanced CDD (EDD): Must be applied in higher-risk situations, which typically include:
Politically Exposed Persons (PEPs) and their family members/close associates.
Customers from high-risk jurisdictions.
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
Non-face-to-face business relationships.
Reporting Threshold: There is no monetary threshold for reporting. Any transaction (including attempted transactions), regardless of value, where the VASP suspects or has reasonable grounds to suspect involves money laundering, terrorism financing, or any other criminal activity, must be reported.
Content of Report: STRs must contain comprehensive information about the customer, the transaction, the grounds for suspicion, and any other relevant details.
Timing: STRs must be submitted promptly to the FIU, typically within a few days of forming the suspicion.
No Tipping-Off: VASPs and their employees are strictly prohibited from "tipping off" or informing the customer or any other third party that an STR has been filed or that an investigation is underway.
Internal Reporting: VASPs must establish internal procedures for reporting suspicious activities to a designated AML Compliance Officer, who is then responsible for filing the STR with the FIU.
Regulator Name: Reserve Bank of Fiji (RBF)
Entity Targeted: General Public / Potential Investors. Violation Type: N/A (Preventative advisory, not an enforcement action). Penalty Amount: N/A.
RBF Statement (2023) - Warning on Virtual Assets and Cryptocurrency: While a specific press release for 2023 isn't easily found, the RBF's general stance is reiterated in public speeches and financial stability reports. Their 2022 Annual Report mentions ongoing monitoring and collaboration with FIU.
RBF Statement (2021) - Warning on Virtual Assets and Cryptocurrency (example of consistent messaging):
FATF Mutual Evaluation Report for Fiji (2022) - discussing Fiji's VA framework:
FIU Typology Reports (various years, discussing virtual asset risks):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operations in Fiji are legally possible but operate in a regulatory vacuum: no specific crypto custody license exists, AML/CFT obligations under the FTRA 2004 clearly apply (requiring registration as a reporting institution and full CDD/STR compliance), and the RBF's hostile public stance combined with FATF pressure creates significant risk of future regulatory change or enforcement.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?