← Regulations / Fiji / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Fiji

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Fiji with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Must register as a 'reporting institution' under the Financial Transactions Reporting Act 2004 (FTRA) — crypto custodial operations likely fall under the definition of a financial institution or DNFBP.
  • Customer Due Diligence (CDD): Obtain and verify identity for individual customers (national ID, passport, driver's license — full name, DOB, address, nationality) and legal entities (name, legal form, proof of existence, registered address, directors).
  • Beneficial ownership identification: Identify ultimate natural persons with 25% or more ownership/control of legal-entity customers.
  • Ongoing monitoring: Continuously monitor business relationships and transactions for consistency with customer risk profile; flag unusual/suspicious activity.
  • Suspicious Transaction Reporting (STR): No monetary threshold — any suspected ML/TF transaction (including attempted) must be reported promptly to the Fiji FIU.
  • Enhanced Due Diligence (EDD): Required for PEPs, high-risk jurisdictions, complex/unusual transactions, non-face-to-face relationships, and customers in high-risk sectors (virtual assets are treated as higher risk).
  • Record-keeping: Maintain all CDD data, transaction records, and STR-related documentation per FTRA requirements.
  • No tipping-off: Prohibited from informing customers or third parties that an STR has been filed.
  • AML Compliance Officer: Must appoint a designated AML Compliance Officer responsible for internal reporting and STR filing with the FIU.
  • No explicit exemption for white-label/SaaS arrangements — both the SaaS platform and the white-label client likely carry independent AML obligations if each is a reporting institution.

Key Restrictions

  • No specific crypto custody license exists — the operation cannot qualify as a 'qualified custodian' under Fijian law, creating structural legal uncertainty.
  • If custodial services extend into exchange, lending, brokerage, or other financial services, appropriate licenses under the Banking Act 1995 or other financial services legislation would be required.
  • Cryptocurrencies are not recognized as legal tender by the RBF and are subject to repeated public warnings — operating a crypto business carries an elevated reputational and regulatory risk.
  • Any offering of tokens that could be classified as securities (investment tokens, security tokens, certain stablecoins) would trigger prospectus requirements under the Companies Act 2015 and potential RBF licensing for the platform.
  • No cold storage, insurance, or segregation mandates exist — but lack of a defined framework means best-practice compliance is self-imposed and untested by regulators.

Key Risks

  • Regulatory vacuum: No specific crypto custody framework means the model operates in a grey zone — the RBF may issue retroactive restrictions or enforcement actions.
  • Repeated RBF public warnings against crypto (2021, 2022, 2023) signal regulatory hostility and potential future prohibition.
  • FATF Mutual Evaluation Report (2022) highlighted Fiji's VA framework gaps — pressure to align with FATF standards could result in sudden new obligations or licensing requirements.
  • No insurance or segregation requirements means custodial risk (hack, fraud, operational failure) sits entirely on the operator with no regulatory safety net.
  • AML/CFT obligations apply but are designed for traditional financial institutions — compliance for a crypto custodial SaaS model is untested and may attract FIU scrutiny.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

No specific license for cryptocurrency custody exists. As cryptocurrencies are not recognized as regulated financial products under the current RBF framework, there is no specific "crypto custodian license."

custody 60% confidence

If an entity's operations extend beyond pure custody into other financial services (e.g., exchange, lending, brokerage) and those services fall under existing definitions within the Banking Act 1995 or other financial services legislation, then appropriate licenses for those activities would be required. However, such legislation does not currently explicitly include digital assets.

custody 60% confidence

No specific rules for cryptocurrency asset segregation exist. Since there is no specific regulatory framework for crypto custody, there are no mandates for how client digital assets should be segregated from the custodian's proprietary assets.

custody 60% confidence

No specific insurance or bonding requirements for cryptocurrency custodians exist. Given the absence of a dedicated framework, there are no mandates for custodians to carry specific insurance policies or bonding to cover potential losses due to hacks, fraud, or operational failures.

custody 60% confidence

No specific cold storage mandates exist. There are no regulatory requirements dictating the use or proportion of cold storage (offline storage) for digital assets held in custody. Industry best practices, again, would guide custodians to use a combination of hot, warm, and cold storage for security.

custody 60% confidence

No specific definition of a "qualified custodian" for digital assets exists. The RBF has not introduced any regulatory definitions or criteria for what constitutes a qualified custodian in the context of cryptocurrencies.

custody 60% confidence

Financial Transactions Reporting Act 2004 (FTRA):

licensing 60% confidence

Security Tokens: These are tokens that explicitly represent traditional securities, such as shares in a company, bonds, units in a collective investment scheme, or other financial instruments. Examples include tokens representing equity, debt, or profit-sharing rights.

licensing 60% confidence

Prospectus Requirement: Generally, an offer of securities to the public in Fiji requires the preparation and registration of a prospectus with the Registrar of Companies. This prospectus must contain all material information necessary for investors to make an informed decision.

licensing 60% confidence

AML/CFT Compliance: Any entity (exchange, broker, OTC desk) involved in the secondary trading of virtual assets (whether securities or not) is considered a "financial institution" or "designated non-financial business and profession" under Fiji's Anti-Money Laundering and Counter-Financing of Terrorism Act 2017. They would be subject to stringent AML/CFT obligations, including customer due diligence (KYC), suspicious transaction reporting, and record-keeping.

aml 60% confidence

Financial Transactions Reporting Act 2004 (FTRA 2004): This is the foundational AML/CFT law in Fiji. It establishes the framework for reporting institutions, customer due diligence, suspicious transaction reporting, and the powers of the Financial Intelligence Unit (FIU).

aml 60% confidence

Customer Identification and Verification:

aml 60% confidence

Individual Customers: Obtain and verify identity using reliable, independent sources (e.g., national ID cards, passports, driver's licenses). This includes full name, date of birth, residential address, and nationality.

aml 60% confidence

Legal Entities (Companies, Trusts, etc.): Obtain and verify the entity's name, legal form, proof of existence, registered address, and the names of directors/partners/trustees.

aml 60% confidence

Beneficial Ownership: Identify and verify the ultimate natural person(s) who own or control the customer, or on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals with 25% or more ownership/control.

aml 60% confidence

Purpose and Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or transaction to assess potential risks.

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.

aml 60% confidence

Enhanced CDD (EDD): Must be applied in higher-risk situations, which typically include:

aml 60% confidence

Politically Exposed Persons (PEPs) and their family members/close associates.

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.

aml 60% confidence

Non-face-to-face business relationships.

aml 60% confidence

Reporting Threshold: There is no monetary threshold for reporting. Any transaction (including attempted transactions), regardless of value, where the VASP suspects or has reasonable grounds to suspect involves money laundering, terrorism financing, or any other criminal activity, must be reported.

aml 60% confidence

Content of Report: STRs must contain comprehensive information about the customer, the transaction, the grounds for suspicion, and any other relevant details.

aml 60% confidence

Timing: STRs must be submitted promptly to the FIU, typically within a few days of forming the suspicion.

aml 60% confidence

No Tipping-Off: VASPs and their employees are strictly prohibited from "tipping off" or informing the customer or any other third party that an STR has been filed or that an investigation is underway.

aml 60% confidence

Internal Reporting: VASPs must establish internal procedures for reporting suspicious activities to a designated AML Compliance Officer, who is then responsible for filing the STR with the FIU.

aml 60% confidence

Types of Records:

enforcement 60% confidence

Entity Targeted: General Public / Potential Investors. Violation Type: N/A (Preventative advisory, not an enforcement action). Penalty Amount: N/A.

enforcement 60% confidence

RBF Statement (2023) - Warning on Virtual Assets and Cryptocurrency: While a specific press release for 2023 isn't easily found, the RBF's general stance is reiterated in public speeches and financial stability reports. Their 2022 Annual Report mentions ongoing monitoring and collaboration with FIU.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS operations in Fiji are legally possible but operate in a regulatory vacuum: no specific crypto custody license exists, AML/CFT obligations under the FTRA 2004 clearly apply (requiring registration as a reporting institution and full CDD/STR compliance), and the RBF's hostile public stance combined with FATF pressure creates significant risk of future regulatory change or enforcement.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?