← Regulations / Guinea-Bissau / Operating Models / DeFi frontend

DeFi protocol frontend in Guinea-Bissau

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Guinea-Bissau with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) — identification and verification of identity (natural persons: name, address, date of birth, nationality, unique identification number; legal persons: name, legal form, address, directors, beneficial owners) — required under Law No. 7/2014 and UEMOA Directive No. 003/2021/CM/UEMOA
  • Beneficial ownership identification — for legal persons, understanding ownership and control structure, identifying the ultimate beneficial owner (UBO)
  • Purpose-and-nature assessment — understanding the purpose and intended nature of the business relationship or transaction
  • Ongoing transaction monitoring — scrutiny of transactions throughout the business relationship to ensure consistency with the customer's profile
  • Record-keeping — maintain customer identification data, transaction records (including travel-rule information), analysis of complex/unusual transactions, and copies of STRs for applicable retention periods
  • Risk-based approach — apply Simplified CDD (SCDD) for lower-risk situations and Enhanced CDD (EDD) for higher-risk situations (PEPs, high-risk jurisdictions, complex/unusual transactions, new technologies)
  • Suspicious Transaction Reporting (STR) — report any suspicious or attempted transaction, regardless of amount, to the Unidade de Informação Financeira (UIF — Financial Intelligence Unit of Guinea-Bissau)
  • No tipping-off — prohibition on disclosing to the customer or any third party that an STR has been or will be filed
  • Travel Rule obligations — sender and recipient information must be recorded for virtual asset transfers, per FATF Recommendation 15 as transposed via UEMOA Directive No. 003/2021/CM/UEMOA

Key Restrictions

  • No specific crypto or VASP licensing framework exists — the operator cannot obtain a license tailored to DeFi frontend activities
  • BCEAO has issued public warnings against cryptocurrencies and generally prohibits unauthorized payment/crypto services by non-licensed entities
  • If the frontend involves fee-taking, it may be reclassified as a financial service requiring a traditional financial license (e.g., e-money, payment services, financial intermediation) from the BCEAO — this is a significant grey-area risk
  • Any entity operating in Guinea-Bissau must incorporate locally with a registered office under general business registration laws
  • UEMOA Directive No. 003/2021/CM/UEMOA transposes FATF Recommendation 15 on virtual assets — VASPs (potentially including DeFi frontends) must comply with AML/CFT obligations even absent specific crypto licensing
  • The BCEAO's stance that cryptocurrencies are not recognized as legal tender or regulated financial instruments creates an ambiguous legal environment for any crypto-touching service

Key Risks

  • Regulatory uncertainty — no specific crypto laws exist but BCEAO warnings suggest active hostility; future regulation (possibly retroactive) is a material risk
  • Fee-taking risk — if the frontend charges fees (swap fees, routing fees), it risks being classified as an unauthorized financial or payment service under BCEAO rules, carrying enforcement exposure
  • Enforcement risk — the FIU (UIF) and Central Bank could scrutinize any entity handling financial flows under general AML/CFT provisions, even without specific VASP rules
  • Travel Rule compliance ambiguity — FATF Recommendation 15 transposed via UEMOA Directive applies to VASPs, but it is unclear how it applies to non-custodial DeFi frontends; compliance expectations are unclear
  • GIABA mutual evaluation risk — Guinea-Bissau's AML/CFT framework deficiencies regarding virtual assets may lead to increased enforcement pressure or sudden regulatory changes
  • Operational grey area — operating a DeFi frontend without explicit legal clarity exposes the operator to potential shutdown orders or reputational damage

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Absence of Specific Crypto Laws: There are no explicit laws or regulations defining virtual assets, outlining VASP licensing categories, setting specific capital requirements for crypto firms, or mandating a particular application process for crypto businesses.

licensing 60% confidence

Central Bank Stance: Like many central banks in the absence of specific legislation, the Banco Central da Guiné-Bissau (Central Bank of Guinea-Bissau) is more likely to have issued warnings regarding the risks associated with cryptocurrencies rather than establishing a regulatory framework for them. These warnings typically highlight price volatility, lack of consumer protection, and potential for illicit use. (Unfortunately, direct links to specific public warnings are often hard to find without deep local search capabilities in Portuguese).

licensing 60% confidence

General Business Registration: Any entity wishing to operate in Guinea-Bissau, including a business that might involve virtual assets, would still need to comply with general company registration laws and obtain standard business licenses from the relevant government ministries (e.g., Ministry of Economy and Finance, Ministry of Justice) for its operational activities, irrespective of whether those activities involve virtual assets.

licensing 60% confidence

Neither (for Crypto-Specific Activities): Since there's no specific regulatory framework for virtual assets, there is no designated "registration regime" or "licensing regime" for crypto activities.

licensing 60% confidence

None Specifically for Crypto: There are no specific "Virtual Asset Exchange License," "Crypto Custody License," or "Crypto Payment Processor License" available or required in Guinea-Bissau.

licensing 60% confidence

Traditional Financial Licenses (Potential Overlap/Future): If a VASP's activities were deemed to fall under the scope of traditional financial services (e.g., money remittance, e-money issuance, or general financial intermediation), then relevant licenses for those traditional activities might be required. However, without specific legal clarity on how virtual assets are classified in relation to existing financial laws, this remains ambiguous. It's more likely that traditional financial services licenses would not implicitly cover virtual asset activities without explicit legislative amendment.

licensing 60% confidence

AML/KYC: This is the most likely area where some implicit obligation might arise. Guinea-Bissau is a member of the Inter-Governmental Action Group against Money Laundering in West Africa (GIABA), an FATF-style regional body. This means it is committed to implementing FATF Recommendations, including Recommendation 15 on New Technologies, which requires countries to regulate Virtual Asset Service Providers (VASPs) for AML/CFT purposes.

licensing 60% confidence

Current Situation: While Guinea-Bissau has general Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) laws, it's not clear whether these laws explicitly designate VASPs as "reporting entities" or "financial institutions" that must adhere to AML/KYC obligations (e.g., customer due diligence, suspicious transaction reporting).

licensing 60% confidence

Financial Intelligence Unit (FIU): Guinea-Bissau has an FIU (Unidade de Informação Financeira - UIF). If a virtual asset business were identified as conducting financial activities that could facilitate money laundering, it might eventually fall under the purview of the general AML/CFT law and the FIU's supervision.

licensing 60% confidence

Local Presence: Any company operating in Guinea-Bissau would generally require a registered local office and compliance with local business registration requirements.

licensing 60% confidence

General AML/CFT Law: Guinea-Bissau is expected to have legislation aligned with international AML/CFT standards. The most recent comprehensive law would be:

licensing 60% confidence

Law No. 5/2023 of April 28, 2023, on the Prevention and Combat of Money Laundering, Terrorist Financing, and Proliferation Financing.

licensing 60% confidence

Central Bank of Guinea-Bissau (Banco Central da Guiné-Bissau): This is the primary financial regulator. Any future crypto-related regulations would likely emanate from here.

aml 40% confidence

Law No. 7/2014 of 30th May 2014 on the Prevention and Combat of Money Laundering and Terrorist Financing: This is the overarching national AML/CFT law. It defines reporting entities, establishes the Financial Intelligence Unit (FIU), and outlines general obligations.

aml 40% confidence

UEMOA Directive No. 003/2021/CM/UEMOA relating to the fight against money laundering and terrorist financing in the UEMOA Member States: This critical regional directive, adopted in 2021, incorporates the revised FATF Recommendations, including specific provisions for virtual assets (FATF Recommendation 15). It mandates member states (including Guinea-Bissau) to apply AML/CFT measures to VASPs and to supervise or monitor them. National legislation and regulations are expected to be updated to reflect this directive.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Purpose and Nature of the Business Relationship: Understanding the purpose and intended nature of the business relationship or transaction.

aml 40% confidence

Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 40% confidence

Risk-Based Approach: Applying CDD measures based on a risk assessment. This means:

aml 40% confidence

Report Suspicious Transactions: Report any transaction (or attempted transaction), regardless of its amount, that they suspect may involve money laundering or terrorist financing. This includes transactions related to virtual assets.

aml 40% confidence

Reporting Body: Reports must be submitted to the national Financial Intelligence Unit (FIU).

aml 40% confidence

Unidade de Informação Financeira (UIF) - Financial Intelligence Unit of Guinea-Bissau:

custody 60% confidence

Implication of BCEAO Stance: Any entity seeking to offer financial services, including what might be construed as digital asset custody, would generally need a license from the BCEAO and/or national financial authorities. However, the BCEAO's stance against recognizing cryptocurrencies means that such a license specifically for crypto custody is not available or granted. Unlicensed provision of financial services is generally illegal.

custody 60% confidence

Central Bank of West African States (BCEAO) Official Website:

custody 60% confidence

BCEAO Communiqués on Cryptocurrencies (Example - French):

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend can operate in Guinea-Bissau only in a high-risk grey area: no specific crypto licensing exists, but general AML/CFT obligations (including FATF Recommendation 15 via UEMOA Directive) may apply; fee-taking risks reclassification as an unauthorized financial service under BCEAO rules; local incorporation is required for any entity presence, and the BCEAO's anti-crypto stance creates material enforcement exposure.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?