DeFi protocol frontend in Guernsey
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Standard CDD: must identify customer (passport, national ID) and verify identity using reliable independent source documents (gg.aml.identify-the-customer-obtain-proof, gg.aml.verify-the-customers-identity-use)
- Identify beneficial owner (25% ownership threshold) for legal persons (gg.aml.identify-the-beneficial-owner-bo)
- Understand purpose and intended nature of business relationship (gg.aml.understand-the-purpose-and-intended)
- Collect source of funds/wealth information (gg.aml.collect-source-of-fundswealth-information)
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and specific high-risk virtual asset activities (gg.aml.enhanced-due-diligence-edd-edd, gg.aml.politically-exposed-persons-peps, gg.aml.customers-from-high-risk-jurisdictions, gg.aml.complex-or-unusually-large-transactions, gg.aml.non-face-to-face-business-relationships-without-additional)
- Ongoing monitoring of customer relationships and transactions; review CDD on significant changes (gg.aml.ongoing-monitoring-vasps-must-continuously)
- Sanctions screening against UN, UK, EU, and Guernsey sanctions lists (gg.aml.sanctions-screening-all-customers-and)
- Obligation to report suspicion of ML/TF to the FIU; no tipping-off (gg.aml.obligation-to-report-vasps-have, gg.aml.no-tipping-off-it-is-an)
- Internal reporting procedures with designated MLRO/DMLRO (gg.aml.internal-reporting-vasps-must-have)
- Risk-based approach (RBA) required; virtual assets considered higher risk (gg.aml.risk-based-approach-rba-vasps-must)
Key Restrictions
- Must be licensed as a VASP (Virtual Asset Service Provider) by the GFSC — operating a DeFi frontend that intermediates between users and smart contracts likely constitutes a regulated VASP activity (gg.enforcement.unlicensed-activity-the-gfsc-has)
- Local incorporation required — prospective licensees must submit a comprehensive application demonstrating governance, financial resources, fit-and-proper management, and AML/CFT frameworks (gg.custody.application-process-prospective-licensees-must)
- If the frontend takes fees or has any custody/control of user assets, it triggers fiduciary-level regulation under The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000 (gg.custody.the-regulation-of-fiduciaries-administration)
- Geofencing required — cannot serve users without full CDD onboarding as per VASP AML/CFT obligations; permissionless, unrestricted access is incompatible with the regulatory framework
- Non-face-to-face business relationships require EDD with additional safeguards (gg.aml.non-face-to-face-business-relationships-without-additional)
Key Risks
- High enforcement risk for operating without a VASP licence — unlicensed activity is a recognized enforcement trigger (gg.enforcement.unlicensed-activity-the-gfsc-has)
- Regulatory ambiguity: the boundary between a 'frontend to a decentralized protocol' and a 'VASP' is not clearly defined in GFSC guidance; fee-taking or any control over transactions increases the likelihood of classification as regulated activity
- AML/CFT compliance is resource-intensive; small DeFi frontends may struggle with capital requirements, MLRO appointment, and ongoing supervisory obligations
- Risk that the GFSC takes a broad view of VASP definition to encompass any interface that facilitates virtual asset transfers for users, even if the underlying protocol is permissionless
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.
Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:
VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.
The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law
Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.
Standard CDD: For all customers, VASPs must:
Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).
Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.
Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.
Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.
Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:
Non-face-to-face business relationships without additional safeguards.
Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.
Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).
Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.
No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.
Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.
Sound governance arrangements.
Adequate financial resources (capital requirements vary based on the nature and scale of the business).
Experienced and fit and proper directors and senior management.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — operating a DeFi protocol frontend in/from Guernsey requires a VASP licence from the GFSC with full AML/CFT obligations (CDD, EDD, ongoing monitoring, sanctions screening, FIU reporting), local incorporation, and a comprehensive licensing process; fee-taking or custody of user assets further triggers fiduciary regulation; permissionless, unrestricted access is incompatible with the regime.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?