← Regulations / Guernsey / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Guernsey

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs must adopt a Risk-Based Approach (RBA) to assess ML/TF risk across customers, products, services, and geographies (gg.aml.risk-based-approach-rba-vasps-must)
  • Standard CDD required for all customers: identify and verify customer identity using reliable independent source documents (gg.aml.identify-the-customer-obtain-proof, gg.aml.verify-the-customers-identity-use)
  • Identify and verify Beneficial Owners (25%+ ownership threshold) for legal person customers (gg.aml.identify-the-beneficial-owner-bo)
  • Collect source of funds/wealth information (gg.aml.collect-source-of-fundswealth-information)
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusual transactions, non-face-to-face relationships, and higher-risk virtual asset activities (gg.aml.enhanced-due-diligence-edd-edd, gg.aml.politically-exposed-persons-peps, gg.aml.customers-from-high-risk-jurisdictions, gg.aml.non-face-to-face-business-relationships-without-additional)
  • Ongoing transaction monitoring to detect deviations from expected patterns (gg.aml.ongoing-monitoring-vasps-must-continuously)
  • Sanctions screening against UN, UK, EU, and Guernsey sanctions lists (gg.aml.sanctions-screening-all-customers-and)
  • Obligation to report suspicious activity to the FIU, with no-tipping-off prohibition (gg.aml.obligation-to-report-vasps-have, gg.aml.no-tipping-off-it-is-an)
  • Internal reporting procedures required, with designated MLRO/Deputy MLRO (gg.aml.internal-reporting-vasps-must-have)
  • Detailed record-keeping and CDD obligations under The Criminal Justice (Proceeds of Crime) Regulations 2017 (gg.aml.the-criminal-justice-proceeds-of)

Key Restrictions

  • The SaaS provider must be licensed as a VASP (virtual asset custody wallet provider) under the Fiduciaries Law (gg.custody.vasp-definition-the-gfsc-recognizes)
  • Must be incorporated in Guernsey as a licensed fiduciary/custodian — local entity required (gg.custody.the-regulation-of-fiduciaries-administration)
  • Client virtual assets must be clearly separated and identifiable from the firm's own assets — on-chain segregation preferred (gg.custody.core-principle-licensed-custodians-must, gg.custody.on-chain-segregation-ideally-client-assets)
  • If technical commingling occurs for operational reasons, impeccable internal records and accounting must delineate each client's beneficial ownership (gg.custody.robust-internal-accounting-where-technical)
  • Clients must retain beneficial ownership of their assets under the legal framework (gg.custody.legal-ownership-the-legal-framework)
  • A significant portion (ideally the vast majority) of assets should be held in cold storage / offline wallets (gg.custody.best-practice-expectation-while-not)
  • Firms must demonstrate secure key management including multi-signature schemes and geographically distributed backups (gg.custody.key-management-firms-must-demonstrate)
  • Capital requirements apply — based on nature and scale of business — in lieu of mandatory insurance (gg.custody.capital-requirements-instead-of-mandatory)
  • Insurance (crime, cyber, professional indemnity) is a best-practice expectation, not legally mandated, but commercially necessary (gg.custody.best-practice-carrying-adequate-insurance)

Key Risks

  • Enforcement risk for operating without a VASP license — GFSC actively supervises and can take action for unlicensed activity (gg.enforcement.unlicensed-activity-the-gfsc-has)
  • Regulatory ambiguity around allocation of AML obligations between the SaaS custodian and the white-label client — both may be considered VASPs requiring their own licensing
  • GFSC enforcement actions may involve confidential settlements, creating precedent uncertainty (gg.enforcement.enforcement-actions-might-involve-confidential)
  • Capital requirements are not flat — they vary based on business scale, creating uncertainty during application (gg.custody.adequate-financial-resources-capital-requirements)
  • No explicit mandatory insurance requirement creates a binding commitment gap that commercial counterparties may challenge

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.

custody 60% confidence

The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law

custody 60% confidence

Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:

custody 60% confidence

Adequate financial resources (capital requirements vary based on the nature and scale of the business).

custody 60% confidence

Core Principle: Licensed custodians must ensure that client virtual assets are clearly separated and identifiable from the firm's own assets. This is crucial for investor protection, particularly in the event of insolvency of the custodian.

custody 60% confidence

On-chain segregation: Ideally, client assets are held in distinct, segregated wallet addresses or accounts on the blockchain that are clearly identifiable as belonging to clients, not the firm.

custody 60% confidence

Robust internal accounting: Where technical commingling might occur for operational reasons (e.g., using shared liquidity pools in some complex scenarios), the firm must maintain impeccable internal records and accounting that clearly delineate each client's beneficial ownership and entitlements. However, direct on-chain segregation is generally preferred and expected for primary custody.

custody 60% confidence

Legal Ownership: The legal framework must ensure that clients retain beneficial ownership of their assets.

custody 60% confidence

Best Practice Expectation: While not explicitly mandated as "cold storage," GFSC's expectations regarding the safeguarding of client assets effectively necessitate the use of industry best practices. For digital assets, this means that a significant portion (and ideally the vast majority) of assets under custody should be held in "cold" (offline) storage environments to minimize exposure to online threats.

custody 60% confidence

Key Management: Firms must demonstrate highly secure key generation, storage, and recovery processes, often involving multi-signature schemes and geographically distributed backups.

custody 60% confidence

Capital Requirements: Instead of mandatory insurance, the GFSC imposes capital requirements designed to ensure that firms have sufficient financial resources to withstand operational shocks.

custody 60% confidence

Best Practice: Carrying adequate insurance coverage (such as crime insurance, cyber insurance, or professional indemnity insurance) is highly recommended and would be viewed favorably by the GFSC as part of demonstrating a sound and responsible business. It's often a commercial necessity for attracting clients.

custody 60% confidence

Risk Management Expectation: However, insurance and bonding are considered critical components of a robust risk management framework. The GFSC expects licensed custodians to assess their operational risks thoroughly, including those unique to digital assets (e.g., cyber theft, key loss, insider fraud), and to implement appropriate mitigation strategies.

aml 60% confidence

Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.

aml 60% confidence

Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).

aml 60% confidence

Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.

aml 60% confidence

Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).

aml 60% confidence

Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.

aml 60% confidence

Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:

aml 60% confidence

Politically Exposed Persons (PEPs).

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Non-face-to-face business relationships without additional safeguards.

aml 60% confidence

Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.

aml 60% confidence

Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).

aml 60% confidence

Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.

aml 60% confidence

No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.

aml 60% confidence

Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.

aml 60% confidence

The Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Regulations, 2017 (as amended): These Regulations provide the detailed requirements for financial services businesses (which include VASPs for AML/CFT purposes) concerning customer due diligence, record-keeping, and internal controls.

enforcement 60% confidence

Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.

enforcement 60% confidence

Enforcement actions might involve confidential settlements or outcomes that are not fully disclosed publicly, especially for smaller breaches.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers may operate in Guernsey only if licensed as a VASP under the Fiduciaries Law, with a local incorporated entity, client asset segregation (on-chain preferred), robust key management and cold storage practices, risk-based capital requirements, and full AML/CFT obligations including CDD, EDD, sanctions screening, and suspicious activity reporting to the FIU.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?