Self-custodial wallet / non-custodial software in Guinea-Bissau
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Guinea-Bissau with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) — identify and verify natural persons (name, address, date of birth, nationality, unique ID) and legal persons (name, legal form, registered office, directors, beneficial owners, incorporation proof) under Law No. 7/2014 and Presidential Decree No. 17/2015 (gw.aml.law-no-72014-of-30th, gw.aml.presidential-decree-no-172015-of, gw.aml.obtaining-and-verifying-the-identity)
- Understand ownership/control structure and identify Ultimate Beneficial Owner (UBO) for legal persons (gw.aml.for-legal-persons-understanding-the)
- Understand purpose and intended nature of the business relationship (gw.aml.purpose-and-nature-of-the)
- Ongoing monitoring of business relationships, including transaction scrutiny consistent with customer knowledge and risk profile (gw.aml.conducting-ongoing-monitoring-of-the)
- Keep CDD documents, data, and information up to date (gw.aml.ensuring-that-documents-data-or)
- Apply risk-based approach: Simplified CDD (SCDD) for low risk; Enhanced CDD (EDD) required for PEPs, high-risk jurisdictions, complex/large transactions, and new technologies with unknown risks (gw.aml.risk-based-approach, gw.aml.simplified-cdd-scdd-permitted-in, gw.aml.enhanced-cdd-edd-required-for)
- Report suspicious transactions (STRs) to the FIU (Unidade de Informação Financeira) regardless of amount, including virtual-asset-related transactions (gw.aml.report-suspicious-transactions-report-any, gw.aml.reporting-body-reports-must-be, gw.aml.unidade-de-informao-financeira-uif)
- Prohibition on tipping-off about STR filings (gw.aml.no-tipping-off-prohibit-the-disclosure)
- Record-keeping: retain customer identification data, transaction records (including Travel Rule sender/receiver info), analysis of complex/unusual transactions, and copies of STRs (gw.aml.customer-identification-data-copies-of, gw.aml.transaction-data-all-records-necessary, gw.aml.analysis-of-complex-transactions-records, gw.aml.strs-copies-of-all-suspicious)
- Adherence to UEMOA Directive No. 003/2021/CM/UEMOA which incorporates FATF Recommendations including virtual-asset provisions (gw.aml.uemoa-directive-no-0032021cmuemoa-relating)
- Potential BCEAO instructions applicable to financial activities, including any digital-asset-related services (gw.aml.instructions-from-the-central-bank)
Key Restrictions
- No specific crypto licensing framework exists — operator cannot obtain a crypto-specific license, creating legal uncertainty (gw.licensing.none-specifically-for-crypto-there)
- BCEAO has issued warnings against cryptocurrencies and generally prohibits unauthorized payment services; software publishing may risk being classified as an unlicensed financial activity if it enables payments (gw.custody.bceao-communiqus-on-cryptocurrencies-example, gw.licensing.traditional-financial-licenses-potential-overlapfuture)
- If the wallet facilitates on-chain transfers, FATF Travel Rule information requirements could apply under general AML law, but no specific VASP designation framework clarifies exactly how (gw.aml.transaction-data-all-records-necessary)
- General business registration and a local office in Guinea-Bissau are required for any operating entity (gw.licensing.general-business-registration-any-entity, gw.licensing.local-presence-any-company-operating)
- No explicit safe harbor for non-custodial software publishers — classification as a 'reporting entity' under AML law is ambiguous (gw.licensing.current-situation-while-guinea-bissau-has, gw.licensing.amlkyc-this-is-the-most)
Key Risks
- ["Regulatory uncertainty is high — absence of specific crypto laws means a non-custodial wallet publisher could be retroactively captured by future regulation or by expansive interpretation of existing AML/financial-services law (gw.licensing.regulatory-uncertainty-high-risk-of)", "BCEAO's anti-cryptocurrency stance creates risk that even non-custodial software could be deemed facilitating unlicensed financial services, leading to enforcement action (gw.custody.implication-of-bceao-stance-any)", "Cross-border financial flows associated with the wallet software could attract FIU scrutiny under general AML/CFT provisions even without a formal VASP designation (gw.licensing.increased-scrutiny-any-business-involving)", "No public guidance on whether non-custodial software publishers are 'reporting entities' — compliance obligations are ambiguous, creating a gap between theoretical AML duties and practical implementation (gw.licensing.current-situation-while-guinea-bissau-has)", "FATF mutual evaluations (GIABA) may pressure Guinea-Bissau to adopt VASP regulation — operators face regulatory pivot risk (gw.licensing.giaba-inter-governmental-action-group-against)"]
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Absence of Specific Crypto Laws: There are no explicit laws or regulations defining virtual assets, outlining VASP licensing categories, setting specific capital requirements for crypto firms, or mandating a particular application process for crypto businesses.
Central Bank Stance: Like many central banks in the absence of specific legislation, the Banco Central da Guiné-Bissau (Central Bank of Guinea-Bissau) is more likely to have issued warnings regarding the risks associated with cryptocurrencies rather than establishing a regulatory framework for them. These warnings typically highlight price volatility, lack of consumer protection, and potential for illicit use. (Unfortunately, direct links to specific public warnings are often hard to find without deep local search capabilities in Portuguese).
General Business Registration: Any entity wishing to operate in Guinea-Bissau, including a business that might involve virtual assets, would still need to comply with general company registration laws and obtain standard business licenses from the relevant government ministries (e.g., Ministry of Economy and Finance, Ministry of Justice) for its operational activities, irrespective of whether those activities involve virtual assets.
Neither (for Crypto-Specific Activities): Since there's no specific regulatory framework for virtual assets, there is no designated "registration regime" or "licensing regime" for crypto activities.
None Specifically for Crypto: There are no specific "Virtual Asset Exchange License," "Crypto Custody License," or "Crypto Payment Processor License" available or required in Guinea-Bissau.
Traditional Financial Licenses (Potential Overlap/Future): If a VASP's activities were deemed to fall under the scope of traditional financial services (e.g., money remittance, e-money issuance, or general financial intermediation), then relevant licenses for those traditional activities might be required. However, without specific legal clarity on how virtual assets are classified in relation to existing financial laws, this remains ambiguous. It's more likely that traditional financial services licenses would not implicitly cover virtual asset activities without explicit legislative amendment.
AML/KYC: This is the most likely area where some implicit obligation might arise. Guinea-Bissau is a member of the Inter-Governmental Action Group against Money Laundering in West Africa (GIABA), an FATF-style regional body. This means it is committed to implementing FATF Recommendations, including Recommendation 15 on New Technologies, which requires countries to regulate Virtual Asset Service Providers (VASPs) for AML/CFT purposes.
Current Situation: While Guinea-Bissau has general Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) laws, it's not clear whether these laws explicitly designate VASPs as "reporting entities" or "financial institutions" that must adhere to AML/KYC obligations (e.g., customer due diligence, suspicious transaction reporting).
Financial Intelligence Unit (FIU): Guinea-Bissau has an FIU (Unidade de Informação Financeira - UIF). If a virtual asset business were identified as conducting financial activities that could facilitate money laundering, it might eventually fall under the purview of the general AML/CFT law and the FIU's supervision.
Local Presence: Any company operating in Guinea-Bissau would generally require a registered local office and compliance with local business registration requirements.
General AML/CFT Law: Guinea-Bissau is expected to have legislation aligned with international AML/CFT standards. The most recent comprehensive law would be:
Law No. 5/2023 of April 28, 2023, on the Prevention and Combat of Money Laundering, Terrorist Financing, and Proliferation Financing.
Law No. 7/2014 of 30th May 2014 on the Prevention and Combat of Money Laundering and Terrorist Financing: This is the overarching national AML/CFT law. It defines reporting entities, establishes the Financial Intelligence Unit (FIU), and outlines general obligations.
Presidential Decree No. 17/2015 of 27th May 2015: This decree further regulates and implements Law No. 7/2014, providing more detailed provisions for its application.
UEMOA Directive No. 003/2021/CM/UEMOA relating to the fight against money laundering and terrorist financing in the UEMOA Member States: This critical regional directive, adopted in 2021, incorporates the revised FATF Recommendations, including specific provisions for virtual assets (FATF Recommendation 15). It mandates member states (including Guinea-Bissau) to apply AML/CFT measures to VASPs and to supervise or monitor them. National legislation and regulations are expected to be updated to reflect this directive.
Instructions from the Central Bank of West African States (Banque Centrale des États de l'Afrique de l'Ouest - BCEAO): As the common central bank for UEMOA member states, the BCEAO issues regulations and instructions that financial institutions (and by extension, potentially VASPs) must adhere to, particularly concerning electronic money and other financial services. These often implement the UEMOA directives at an operational level.
Obtaining and verifying the identity of the customer (natural persons: name, address, date of birth, nationality, unique identification number; legal persons: name, legal form, address of registered office, directors, beneficial owners, proof of incorporation).
For legal persons, understanding the ownership and control structure, and identifying the ultimate beneficial owner (UBO).
Purpose and Nature of the Business Relationship: Understanding the purpose and intended nature of the business relationship or transaction.
Conducting ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Ensuring that documents, data, or information collected under the CDD process are kept up-to-date.
Evidence fact gw.aml.risk-based-approach not found (may have been renamed).
Enhanced CDD (EDD): Required for higher-risk situations, such as transactions with Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex or unusually large transactions, or situations involving new technologies where the risks are not yet known.
Report Suspicious Transactions: Report any transaction (or attempted transaction), regardless of its amount, that they suspect may involve money laundering or terrorist financing. This includes transactions related to virtual assets.
Reporting Body: Reports must be submitted to the national Financial Intelligence Unit (FIU).
No Tipping-Off: Prohibit the disclosure to the customer or any third party that an STR has been or will be filed.
Customer Identification Data: Copies of identity documents, account files, and business correspondence.
Transaction Data: All records necessary to reconstruct individual transactions, including amounts, currencies, dates, and parties involved. This includes sender and recipient information for virtual asset transfers (often referred to as the "Travel Rule" information, even if specific VASP regulations are still developing).
Analysis of Complex Transactions: Records of the background and purpose of complex, unusual large transactions, and all unusual patterns of transactions.
Unidade de Informação Financeira (UIF) - Financial Intelligence Unit of Guinea-Bissau:
No Specific Requirements: There are no specific laws or regulations in Guinea-Bissau that define or require a "cryptocurrency custodial license."
Implication of BCEAO Stance: Any entity seeking to offer financial services, including what might be construed as digital asset custody, would generally need a license from the BCEAO and/or national financial authorities. However, the BCEAO's stance against recognizing cryptocurrencies means that such a license specifically for crypto custody is not available or granted. Unlicensed provision of financial services is generally illegal.
BCEAO Communiqués on Cryptocurrencies (Example - French):
Lack of Regulatory Recognition: This absence is directly linked to the lack of a defined regulatory category for such services.
Regulatory Uncertainty: High risk of future, potentially retroactive, regulation.
Increased Scrutiny: Any business involving significant financial flows, especially cross-border, could attract attention from the Central Bank or the FIU under general AML/CFT provisions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a self-custodial wallet publisher can operate in Guinea-Bissau without a crypto-specific license (none exists), but must register a local entity, comply with general AML/CFT obligations under Law No. 7/2014 and UEMOA Directive 003/2021 (including CDD, STR filing, Travel Rule record-keeping), and faces material ambiguity risk because the BCEAO's anti-crypto stance could lead to unlicensed financial-activity enforcement and because non-custodial software publishers are not clearly excluded from reporting-entity definitions.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?