← Regulations / Micronesia / Operating Models / DeFi frontend

DeFi protocol frontend in Micronesia

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Micronesia with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Registration with the FSM Financial Intelligence Unit (FIU) is required for VASPs under the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020).
  • Customer Due Diligence (CDD): identification and verification of natural persons (government-issued ID), legal entities (proof of existence, ownership structure), and beneficial owners.
  • Ongoing monitoring of business relationships and transaction scrutiny consistent with customer risk profile.
  • Risk-based approach: Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions.
  • Travel Rule obligations: For cross-border transfers, collect and transmit originator/beneficiary information for transactions ≥ USD 1,000. For domestic transfers, threshold is USD 3,000.
  • Suspicious Transaction Reporting (STR): report any transaction giving rise to reasonable suspicion of ML/TF, regardless of amount or asset type.
  • No tipping-off: prohibitions against informing customers or third parties that an STR has been filed.
  • Record-keeping obligations: maintain customer identification records, transaction records (amounts, asset types, addresses, timestamps), and business correspondence.

Key Restrictions

  • Fee-taking (e.g., frontend fees, swap fees) may elevate the risk that the operator is classified as a VASP or financial intermediary under FSM law, attracting AML/CFT obligations.
  • The FSM lacks a comprehensive crypto framework — there is no explicit licensing path for DeFi frontends, creating legal uncertainty.
  • Any frontend that handles fiat currency or custody-like functions may fall under the FSM Banking Act 1980.
  • Given the lack of domestic VASP registrations to date, there is no established precedent or administrative process for registering a DeFi frontend.

Key Risks

  • Regulatory vacuum: The FSM has no specific crypto laws — operating a DeFi frontend exists in a grey area, with no clear guidance on whether it constitutes regulated activity.
  • International pressure (FATF/APG): APG recommendations push FSM toward stricter VASP regulation — future rule changes could impose retroactive obligations or enforcement.
  • Limited supervisory capacity: FSM FIU has acknowledged limited understanding of virtual asset risks, leading to unpredictable enforcement or sudden policy shifts.
  • No enforcement precedent: zero known enforcement cases means any regulatory action would set precedent, creating first-mover risk.
  • Reputational risk: operating in a jurisdiction with low regulatory maturity may be perceived negatively by partners, users, or other regulators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

No Specific Crypto Requirements: There are no specific registration or exemption requirements published by the FSM for token issuers.

licensing 60% confidence

Application of General Securities Law (if applicable): If a token were classified as a security under existing FSM law, then the issuer would theoretically be subject to any existing general securities registration and disclosure requirements. Given the nascent nature of crypto regulation in the FSM, it is highly improbable that existing securities laws would be practically adaptable to digital asset offerings without explicit guidance or amendments. Issuers would likely find themselves in a regulatory vacuum or an unworkable compliance scenario.

licensing 60% confidence

Undefined/Indirect: The FSM currently lacks a comprehensive and explicit regulatory framework specifically for cryptocurrencies and virtual assets. The approach can be characterized as largely undefined or operating in a "grey area."

licensing 60% confidence

Partial/Indirect Application: While there's no dedicated crypto law, existing anti-money laundering (AML) and combating the financing of terrorism (CFT) legislation and regulatory bodies would likely apply to virtual asset activities, especially for entities operating within the FSM or facilitating transactions involving FSM residents. This aligns with global standards set by the Financial Action Task Force (FATF), which requires countries to regulate Virtual Asset Service Providers (VASPs).

aml 40% confidence

Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27 of the FSM Code): This act establishes the general framework for combating money laundering and terrorist financing, including obligations for financial institutions and designated non-financial businesses and professions (DNFBPs). While it may not explicitly mention "virtual assets" or "VASPs" as distinct regulated entities, the FSM, as an APG member, is expected to apply these requirements to VASPs in line with FATF Recommendation 15 (now Recommendation 16 in the context of the FATF's June 2019 Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers).

aml 40% confidence

Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.

aml 40% confidence

FSM Banking Act 1980 (Title 29 of the FSM Code): This act provides the general legal framework for banking and financial services. While it does not specifically regulate VASPs, any VASP that offers services resembling traditional financial services (e.g., custody of fiat currency, remittances) might fall under the purview or interpretation of this act or require specific licensing.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Beneficial Ownership: Identifying and verifying the identity of the beneficial owner(s) of the customer, and taking reasonable measures to understand the ownership and control structure of legal persons and arrangements.

aml 40% confidence

Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or transaction.

aml 40% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 40% confidence

Risk-Based Approach: Applying a risk-based approach to CDD, meaning enhanced CDD (EDD) measures must be applied to higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, or where the customer's identity verification poses higher risk) and simplified CDD (SCDD) may be applied to lower-risk customers.

aml 40% confidence

Reporting any transaction (or attempted transaction) that gives rise to a reasonable suspicion that it may be related to money laundering, terrorist financing, or other criminal activity.

aml 40% confidence

No Tipping-Off: Prohibitions against informing the customer or any third party that an STR has been filed or that an investigation is being conducted.

aml 40% confidence

Customer Identification Records: All records obtained through CDD measures (e.g., copies of identification documents, verification data).

aml 40% confidence

Transaction Records: Records of all transactions, including amounts, types of virtual assets, sending and receiving addresses/accounts, timestamps, and any other relevant transaction data.

aml 40% confidence

Business Correspondence: All relevant business correspondence, including records of analysis performed.

aml 100% confidence

For cross-border transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 1,000 or more.

aml 100% confidence

For domestic transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 3,000 or more.

enforcement 40% confidence

Lack of a Dedicated Regulatory Framework: The FSM currently lacks a comprehensive legal and regulatory framework specifically addressing virtual assets (VAs) and virtual asset service providers (VASPs).

enforcement 40% confidence

No Registered or Licensed VASPs: As of the latest assessments, there are no known or registered VASPs operating within the FSM that would fall under a regulatory scope (if one existed).

enforcement 40% confidence

Limited Capacity and Awareness: International assessments indicate that the FSM's financial authorities are still developing their understanding and capacity to monitor and regulate the virtual asset sector.

enforcement 40% confidence

No specific legislation: The FSM had not yet enacted specific legislation or regulations to address virtual assets or virtual asset service providers (VASPs).

enforcement 40% confidence

No VASPs identified: The authorities had not identified any VASPs operating within the jurisdiction.

enforcement 40% confidence

Lack of understanding and capacity: The report highlighted a lack of understanding by supervisory authorities regarding the risks associated with virtual assets and a need to develop supervisory capacity in this area.

enforcement 40% confidence

Recommendations: The APG recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations, and ensure appropriate supervision and enforcement capabilities.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend operating in/from the FSM would likely be treated as a VASP under AML/CFT law (requiring FIU registration and compliance with CDD, Travel Rule, and STR obligations), but the jurisdiction lacks a dedicated crypto framework, licensed VASPs, or any enforcement precedent, creating significant legal uncertainty.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?