← Regulations / Micronesia / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Micronesia

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Micronesia with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD obligations under the Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27): identify and verify natural persons (government-issued ID) and legal entities (proof of existence, ownership structure, senior management).
  • Beneficial ownership identification required for all customers.
  • Ongoing transaction monitoring to ensure consistency with customer risk profile.
  • Risk-based approach: Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions.
  • Suspicious Transaction Reporting (STR) to the FSM FIU — any transaction or attempted transaction giving rise to suspicion, regardless of amount or asset type.
  • Travel Rule obligations under 2020 AML/CFT amendments: collect and transmit originator/beneficiary info for cross-border VA transfers ≥ USD 1,000 and domestic VA transfers ≥ USD 3,000.
  • Record-keeping: customer identification records, transaction records (amounts, VA types, addresses, timestamps), business correspondence.
  • No-tipping-off prohibitions — cannot inform customer or third party about an STR filing.
  • Registration/licensing requirement under the 2020 AML/CFT amendments for VASPs, with AML/CFT program obligations including independent audit and training.

Key Restrictions

  • No specific crypto custody or qualified-custodian regime exists — custody must be structured under general AML/CFT registration as a VASP.
  • No segregation, insurance, or proof-of-reserves rules have been published specifically for VASPs.
  • The 2020 AML/CFT amendments require VASPs to register, be licensed, and comply with FATF-style obligations including Travel Rule — but no implementing regulations or supervisory processes have been publicly detailed.
  • Local entity likely required: the VASP registration/licensing obligation under FSM law implies incorporation or registered presence in the FSM.
  • As of the latest APG assessment (July 2022), no VASPs had been identified or registered — the regime is nascent and largely untested.

Key Risks

  • Regulatory vacuum risk: no dedicated crypto custody/custodian framework means rules are implicit and unpredictable; regulator may later interpret custody as requiring a banking license under the FSM Banking Act 1980.
  • Enforcement ambiguity: no publicly available enforcement examples or legal cases for crypto securities violations in the FSM — compliance posture is uncertain.
  • Limited supervisory capacity: the FSM FIU and financial authorities are still developing understanding and capacity for virtual asset oversight.
  • International pressure risk: FATF/APG recommendations may drive sudden rule changes that could render an existing operating model non-compliant.
  • Travel Rule compliance burden: collecting and transmitting originator/beneficiary information for VA transfers across a custody/SaaS architecture is operationally complex and untested in this jurisdiction.
  • No clarity on whether the SaaS operator or the white-label client bears primary AML obligations — likely both would be VASPs under FATF guidance, doubling compliance exposure.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

No Specific Crypto Requirements: There are no specific registration or exemption requirements published by the FSM for token issuers.

licensing 60% confidence

Undefined/Indirect: The FSM currently lacks a comprehensive and explicit regulatory framework specifically for cryptocurrencies and virtual assets. The approach can be characterized as largely undefined or operating in a "grey area."

aml 40% confidence

Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27 of the FSM Code): This act establishes the general framework for combating money laundering and terrorist financing, including obligations for financial institutions and designated non-financial businesses and professions (DNFBPs). While it may not explicitly mention "virtual assets" or "VASPs" as distinct regulated entities, the FSM, as an APG member, is expected to apply these requirements to VASPs in line with FATF Recommendation 15 (now Recommendation 16 in the context of the FATF's June 2019 Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers).

aml 40% confidence

FSM Banking Act 1980 (Title 29 of the FSM Code): This act provides the general legal framework for banking and financial services. While it does not specifically regulate VASPs, any VASP that offers services resembling traditional financial services (e.g., custody of fiat currency, remittances) might fall under the purview or interpretation of this act or require specific licensing.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Beneficial Ownership: Identifying and verifying the identity of the beneficial owner(s) of the customer, and taking reasonable measures to understand the ownership and control structure of legal persons and arrangements.

aml 40% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 40% confidence

Risk-Based Approach: Applying a risk-based approach to CDD, meaning enhanced CDD (EDD) measures must be applied to higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, or where the customer's identity verification poses higher risk) and simplified CDD (SCDD) may be applied to lower-risk customers.

aml 40% confidence

Reporting any transaction (or attempted transaction) that gives rise to a reasonable suspicion that it may be related to money laundering, terrorist financing, or other criminal activity.

aml 40% confidence

No Tipping-Off: Prohibitions against informing the customer or any third party that an STR has been filed or that an investigation is being conducted.

aml 40% confidence

Customer Identification Records: All records obtained through CDD measures (e.g., copies of identification documents, verification data).

aml 40% confidence

Transaction Records: Records of all transactions, including amounts, types of virtual assets, sending and receiving addresses/accounts, timestamps, and any other relevant transaction data.

aml 40% confidence

Financial Intelligence Unit (FIU) of the Federated States of Micronesia (FSM FIU)

aml 40% confidence

Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.

aml 40% confidence

Asia/Pacific Group on Money Laundering (APG) Enhanced Follow-Up Report & Technical Compliance Re-Rating - Federated States of Micronesia (July 2022). Specifically, pages 21-23 regarding Recommendations 15 (New Technologies) and 16 (Wire Transfers).

aml 100% confidence

For cross-border transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 1,000 or more.

aml 100% confidence

For domestic transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 3,000 or more.

enforcement 40% confidence

Lack of a Dedicated Regulatory Framework: The FSM currently lacks a comprehensive legal and regulatory framework specifically addressing virtual assets (VAs) and virtual asset service providers (VASPs).

enforcement 40% confidence

No Registered or Licensed VASPs: As of the latest assessments, there are no known or registered VASPs operating within the FSM that would fall under a regulatory scope (if one existed).

enforcement 40% confidence

Limited Capacity and Awareness: International assessments indicate that the FSM's financial authorities are still developing their understanding and capacity to monitor and regulate the virtual asset sector.

enforcement 40% confidence

No specific legislation: The FSM had not yet enacted specific legislation or regulations to address virtual assets or virtual asset service providers (VASPs).

enforcement 40% confidence

No VASPs identified: The authorities had not identified any VASPs operating within the jurisdiction.

enforcement 40% confidence

Lack of understanding and capacity: The report highlighted a lack of understanding by supervisory authorities regarding the risks associated with virtual assets and a need to develop supervisory capacity in this area.

enforcement 40% confidence

Recommendations: The APG recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations, and ensure appropriate supervision and enforcement capabilities.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS operation is theoretically permissible under the FSM's general AML/CFT registration framework for VASPs (2020 amendments to the Anti-Money Laundering and Counter-Terrorist Financing Act), but the jurisdiction lacks a dedicated custody/custodian licensing regime, has no registered VASPs to date, and faces significant regulatory ambiguity, limited supervisory capacity, and undefined segregation/insurance/proof-of-reserves requirements.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?