← Regulations / Guernsey / Operating Models / DeFi frontend

DeFi protocol frontend in Guernsey

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Guernsey with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Standard CDD: must identify customer (passport, national ID) and verify identity using reliable independent source documents (gg.aml.identify-the-customer-obtain-proof, gg.aml.verify-the-customers-identity-use)
  • Identify beneficial owner (25% ownership threshold) for legal persons (gg.aml.identify-the-beneficial-owner-bo)
  • Understand purpose and intended nature of business relationship (gg.aml.understand-the-purpose-and-intended)
  • Collect source of funds/wealth information (gg.aml.collect-source-of-fundswealth-information)
  • Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and specific high-risk virtual asset activities (gg.aml.enhanced-due-diligence-edd-edd, gg.aml.politically-exposed-persons-peps, gg.aml.customers-from-high-risk-jurisdictions, gg.aml.complex-or-unusually-large-transactions, gg.aml.non-face-to-face-business-relationships-without-additional)
  • Ongoing monitoring of customer relationships and transactions; review CDD on significant changes (gg.aml.ongoing-monitoring-vasps-must-continuously)
  • Sanctions screening against UN, UK, EU, and Guernsey sanctions lists (gg.aml.sanctions-screening-all-customers-and)
  • Obligation to report suspicion of ML/TF to the FIU; no tipping-off (gg.aml.obligation-to-report-vasps-have, gg.aml.no-tipping-off-it-is-an)
  • Internal reporting procedures with designated MLRO/DMLRO (gg.aml.internal-reporting-vasps-must-have)
  • Risk-based approach (RBA) required; virtual assets considered higher risk (gg.aml.risk-based-approach-rba-vasps-must)

Key Restrictions

  • Must be licensed as a VASP (Virtual Asset Service Provider) by the GFSC — operating a DeFi frontend that intermediates between users and smart contracts likely constitutes a regulated VASP activity (gg.enforcement.unlicensed-activity-the-gfsc-has)
  • Local incorporation required — prospective licensees must submit a comprehensive application demonstrating governance, financial resources, fit-and-proper management, and AML/CFT frameworks (gg.custody.application-process-prospective-licensees-must)
  • If the frontend takes fees or has any custody/control of user assets, it triggers fiduciary-level regulation under The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000 (gg.custody.the-regulation-of-fiduciaries-administration)
  • Geofencing required — cannot serve users without full CDD onboarding as per VASP AML/CFT obligations; permissionless, unrestricted access is incompatible with the regulatory framework
  • Non-face-to-face business relationships require EDD with additional safeguards (gg.aml.non-face-to-face-business-relationships-without-additional)

Key Risks

  • High enforcement risk for operating without a VASP licence — unlicensed activity is a recognized enforcement trigger (gg.enforcement.unlicensed-activity-the-gfsc-has)
  • Regulatory ambiguity: the boundary between a 'frontend to a decentralized protocol' and a 'VASP' is not clearly defined in GFSC guidance; fee-taking or any control over transactions increases the likelihood of classification as regulated activity
  • AML/CFT compliance is resource-intensive; small DeFi frontends may struggle with capital requirements, MLRO appointment, and ongoing supervisory obligations
  • Risk that the GFSC takes a broad view of VASP definition to encompass any interface that facilitates virtual asset transfers for users, even if the underlying protocol is permissionless

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

enforcement 60% confidence

Unlicensed activity: The GFSC has a licensing regime for Virtual Asset Service Providers (VASPs). Enforcement might occur for operating without a license, but public records don't typically detail large fines specifically for this in recent years.

custody 60% confidence

Application Process: Prospective licensees must submit a comprehensive application to the GFSC, demonstrating:

custody 60% confidence

VASP Definition: The GFSC recognizes "virtual asset custody wallet providers" as a type of VASP. Providing such services falls within the scope of regulated activities.

custody 60% confidence

The Regulation of Fiduciaries, Administration Businesses and Company Directors, etc. (Bailiwick of Guernsey) Law, 2000: https://www.gfsc.gg/commission/laws-regulations/fiduciaries-law

aml 60% confidence

Risk-Based Approach (RBA): VASPs must assess the money laundering and terrorist financing risks associated with their business, customers, products, services, and geographic areas. This assessment dictates the level of CDD applied. Virtual assets and related services are generally considered to carry higher inherent risks.

aml 60% confidence

Standard CDD: For all customers, VASPs must:

aml 60% confidence

Identify the Customer: Obtain proof of identity (e.g., passport, national ID card for individuals; incorporation documents, registers for legal entities).

aml 60% confidence

Verify the Customer's Identity: Use reliable, independent source documents, data, or information. For individuals, this often involves documentary evidence and potentially non-documentary methods. For legal entities, verification of existence and legal form.

aml 60% confidence

Identify the Beneficial Owner (BO): For legal persons or arrangements, identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% ownership threshold, or control via other means).

aml 60% confidence

Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer wants to use the VASP's services and the expected activity levels.

aml 60% confidence

Collect Source of Funds/Wealth Information: Understand where the customer's funds/virtual assets originate from.

aml 60% confidence

Enhanced Due Diligence (EDD): EDD is required in situations where there is a higher risk of ML/TF. This includes, but is not limited to:

aml 60% confidence

Politically Exposed Persons (PEPs).

aml 60% confidence

Customers from high-risk jurisdictions.

aml 60% confidence

Complex or unusually large transactions.

aml 60% confidence

Non-face-to-face business relationships without additional safeguards.

aml 60% confidence

Ongoing Monitoring: VASPs must continuously monitor customer relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. Any significant changes in customer behaviour or circumstances must trigger a review of CDD.

aml 60% confidence

Sanctions Screening: All customers and transactions must be screened against applicable sanctions lists (e.g., UN, UK, EU, Guernsey).

aml 60% confidence

Obligation to Report: VASPs have a legal obligation to report any knowledge, suspicion, or reasonable grounds for suspicion of money laundering or terrorist financing to the Financial Intelligence Unit (FIU). This includes attempts to launder money or finance terrorism.

aml 60% confidence

No Tipping-Off: It is an offence to "tip-off" a customer or any third party that a suspicious transaction report has been or will be made.

aml 60% confidence

Internal Reporting: VASPs must have internal procedures for employees to report suspicions to a designated Money Laundering Reporting Officer (MLRO) or Deputy MLRO. The MLRO is then responsible for evaluating the internal report and deciding whether to file an STR with the FIU.

custody 60% confidence

Adequate financial resources (capital requirements vary based on the nature and scale of the business).

custody 60% confidence

Experienced and fit and proper directors and senior management.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — operating a DeFi protocol frontend in/from Guernsey requires a VASP licence from the GFSC with full AML/CFT obligations (CDD, EDD, ongoing monitoring, sanctions screening, FIU reporting), local incorporation, and a comprehensive licensing process; fee-taking or custody of user assets further triggers fiduciary regulation; permissionless, unrestricted access is incompatible with the regime.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?