Custodial wallet / SaaS in Micronesia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Micronesia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD obligations under the Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27): identify and verify natural persons (government-issued ID) and legal entities (proof of existence, ownership structure, senior management).
- Beneficial ownership identification required for all customers.
- Ongoing transaction monitoring to ensure consistency with customer risk profile.
- Risk-based approach: Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions.
- Suspicious Transaction Reporting (STR) to the FSM FIU — any transaction or attempted transaction giving rise to suspicion, regardless of amount or asset type.
- Travel Rule obligations under 2020 AML/CFT amendments: collect and transmit originator/beneficiary info for cross-border VA transfers ≥ USD 1,000 and domestic VA transfers ≥ USD 3,000.
- Record-keeping: customer identification records, transaction records (amounts, VA types, addresses, timestamps), business correspondence.
- No-tipping-off prohibitions — cannot inform customer or third party about an STR filing.
- Registration/licensing requirement under the 2020 AML/CFT amendments for VASPs, with AML/CFT program obligations including independent audit and training.
Key Restrictions
- No specific crypto custody or qualified-custodian regime exists — custody must be structured under general AML/CFT registration as a VASP.
- No segregation, insurance, or proof-of-reserves rules have been published specifically for VASPs.
- The 2020 AML/CFT amendments require VASPs to register, be licensed, and comply with FATF-style obligations including Travel Rule — but no implementing regulations or supervisory processes have been publicly detailed.
- Local entity likely required: the VASP registration/licensing obligation under FSM law implies incorporation or registered presence in the FSM.
- As of the latest APG assessment (July 2022), no VASPs had been identified or registered — the regime is nascent and largely untested.
Key Risks
- Regulatory vacuum risk: no dedicated crypto custody/custodian framework means rules are implicit and unpredictable; regulator may later interpret custody as requiring a banking license under the FSM Banking Act 1980.
- Enforcement ambiguity: no publicly available enforcement examples or legal cases for crypto securities violations in the FSM — compliance posture is uncertain.
- Limited supervisory capacity: the FSM FIU and financial authorities are still developing understanding and capacity for virtual asset oversight.
- International pressure risk: FATF/APG recommendations may drive sudden rule changes that could render an existing operating model non-compliant.
- Travel Rule compliance burden: collecting and transmitting originator/beneficiary information for VA transfers across a custody/SaaS architecture is operationally complex and untested in this jurisdiction.
- No clarity on whether the SaaS operator or the white-label client bears primary AML obligations — likely both would be VASPs under FATF guidance, doubling compliance exposure.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No Specific Crypto Requirements: There are no specific registration or exemption requirements published by the FSM for token issuers.
Undefined/Indirect: The FSM currently lacks a comprehensive and explicit regulatory framework specifically for cryptocurrencies and virtual assets. The approach can be characterized as largely undefined or operating in a "grey area."
Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27 of the FSM Code): This act establishes the general framework for combating money laundering and terrorist financing, including obligations for financial institutions and designated non-financial businesses and professions (DNFBPs). While it may not explicitly mention "virtual assets" or "VASPs" as distinct regulated entities, the FSM, as an APG member, is expected to apply these requirements to VASPs in line with FATF Recommendation 15 (now Recommendation 16 in the context of the FATF's June 2019 Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers).
FSM Banking Act 1980 (Title 29 of the FSM Code): This act provides the general legal framework for banking and financial services. While it does not specifically regulate VASPs, any VASP that offers services resembling traditional financial services (e.g., custody of fiat currency, remittances) might fall under the purview or interpretation of this act or require specific licensing.
Beneficial Ownership: Identifying and verifying the identity of the beneficial owner(s) of the customer, and taking reasonable measures to understand the ownership and control structure of legal persons and arrangements.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying a risk-based approach to CDD, meaning enhanced CDD (EDD) measures must be applied to higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, or where the customer's identity verification poses higher risk) and simplified CDD (SCDD) may be applied to lower-risk customers.
Reporting any transaction (or attempted transaction) that gives rise to a reasonable suspicion that it may be related to money laundering, terrorist financing, or other criminal activity.
No Tipping-Off: Prohibitions against informing the customer or any third party that an STR has been filed or that an investigation is being conducted.
Customer Identification Records: All records obtained through CDD measures (e.g., copies of identification documents, verification data).
Transaction Records: Records of all transactions, including amounts, types of virtual assets, sending and receiving addresses/accounts, timestamps, and any other relevant transaction data.
Financial Intelligence Unit (FIU) of the Federated States of Micronesia (FSM FIU)
Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.
Asia/Pacific Group on Money Laundering (APG) Enhanced Follow-Up Report & Technical Compliance Re-Rating - Federated States of Micronesia (July 2022). Specifically, pages 21-23 regarding Recommendations 15 (New Technologies) and 16 (Wire Transfers).
For cross-border transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 1,000 or more.
For domestic transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 3,000 or more.
Lack of a Dedicated Regulatory Framework: The FSM currently lacks a comprehensive legal and regulatory framework specifically addressing virtual assets (VAs) and virtual asset service providers (VASPs).
No Registered or Licensed VASPs: As of the latest assessments, there are no known or registered VASPs operating within the FSM that would fall under a regulatory scope (if one existed).
Limited Capacity and Awareness: International assessments indicate that the FSM's financial authorities are still developing their understanding and capacity to monitor and regulate the virtual asset sector.
No specific legislation: The FSM had not yet enacted specific legislation or regulations to address virtual assets or virtual asset service providers (VASPs).
No VASPs identified: The authorities had not identified any VASPs operating within the jurisdiction.
Lack of understanding and capacity: The report highlighted a lack of understanding by supervisory authorities regarding the risks associated with virtual assets and a need to develop supervisory capacity in this area.
Recommendations: The APG recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations, and ensure appropriate supervision and enforcement capabilities.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operation is theoretically permissible under the FSM's general AML/CFT registration framework for VASPs (2020 amendments to the Anti-Money Laundering and Counter-Terrorist Financing Act), but the jurisdiction lacks a dedicated custody/custodian licensing regime, has no registered VASPs to date, and faces significant regulatory ambiguity, limited supervisory capacity, and undefined segregation/insurance/proof-of-reserves requirements.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?