← Regulations / Kyrgyzstan / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Kyrgyzstan

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Kyrgyzstan with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • VASPs (including custodial wallet/SaaS providers) must adopt a risk-based approach to CDD, including EDD for higher-risk customers (PEPs, high-risk jurisdictions, complex structures) and SDD where permitted.
  • Identify and verify beneficial owners of legal entity customers (ownership threshold 25% or control).
  • Obtain purpose and intended nature of business relationship (expected transaction volumes/types).
  • Ongoing monitoring of business relationships and transactions for consistency with customer risk profile.
  • Obligation to report suspicious transactions 'without delay' to the State Service for Financial Intelligence (SSFI) — no monetary threshold.
  • No tipping-off: employees and VASPs must not disclose STR filings to customers or third parties.
  • Record-keeping for 5 years: customer identification data, transaction records, analysis of complex/unusual transactions.
  • Travel Rule compliance: obtain, hold, and transmit originator and beneficiary information for virtual asset transfers meeting FATF threshold (expected USD/EUR 1,000 for cross-border/domestic). Originator info: name, account number/transaction ID, address/national ID/DOB. Beneficiary info: name, account number/transaction ID.
  • VASPs must maintain records of Travel Rule information for the AML/CFT retention period (typically 5 years).
  • Compliance with data protection/privacy laws for handling of sensitive customer data.
  • The Law No. 200 'On the Turnover of Virtual Assets' (August 2022) designates custodial wallet services ('safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets') as a VASP activity subject to AML/CFT obligations.
  • SSFI is the FIU and AML/CFT supervisor; NBKR also plays a role in financial stability and may issue additional crypto regulations.

Key Restrictions

  • A local legal entity (incorporated in Kyrgyzstan) is required — the VASP definition under Law No. 200 applies to 'a legal entity carrying out' the covered activities.
  • Custodial wallet/safekeeping activities fall under the VASP definition in Law No. 200, triggering licensing and AML obligations.
  • The NBKR has historically warned against crypto risks and crypto is not legal tender, creating uncertainty for white-label arrangements.
  • No specific custody/segregation, insurance, or proof-of-reserves rules are evident in the provided sources — the framework appears to rely on general AML obligations rather than dedicated custodial-asset-protection regulation.
  • The regulatory landscape is evolving; VASPs must monitor for new guidance from SSFI or NBKR.

Key Risks

  • No dedicated custody license or qualified-custodian regime exists yet — the VASP framework under Law No. 200 is AML-centric, leaving asset segregation, insurance, and proof-of-reserves requirements ambiguous.
  • White-label SaaS arrangements create ambiguity around which party (SaaS provider vs. white-label client) bears primary AML/Travel Rule obligations; both may be VASPs under the broad definition.
  • Enforcement risk from SCNS/MVD for unlicensed operation; illegal mining and pyramid scheme precedents show active enforcement against unlicensed crypto activities.
  • NBKR has issued repeated warnings that crypto is not legal tender and carries risks, creating reputational and regulatory risk for operators.
  • The SSFI website is primarily in Russian/Kyrgyz with limited English content, creating practical compliance burdens for foreign operators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Law of the Kyrgyz Republic on Combating the Financing of Terrorism and Legalization (Laundering) of Criminal Proceeds (No. 87, dated July 25, 2011, with subsequent amendments). This law establishes the legal and organizational framework for AML/CFT, defines the obligations of reporting entities, and outlines the role of the financial intelligence unit.

licensing 40% confidence

Identification and Verification:

licensing 40% confidence

For legal entities: Full name, legal form, registration number, legal address, tax identification number (TIN), details of beneficial owners, directors, and authorized signatories. Verification through company registration documents, articles of association, and public registries.

licensing 40% confidence

Beneficial Ownership Identification: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including those who ultimately own or control the customer, or the person on whose behalf a transaction is being conducted. Thresholds (e.g., 25% ownership or control) typically apply.

licensing 40% confidence

Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship (e.g., why the customer is using virtual assets, expected transaction volumes and types).

licensing 40% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

licensing 40% confidence

Risk-Based Approach: VASPs must adopt a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex structures, large transactions) and simplified due diligence (SDD) for lower-risk scenarios where permitted.

licensing 40% confidence

Obligation to Report: If a VASP has grounds to suspect that funds or other property, regardless of the amount, are related to the financing of terrorism or legalization (laundering) of criminal proceeds, it must immediately report such suspicions.

licensing 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report (STR) has been filed, or that an investigation into money laundering or terrorist financing is being conducted.

licensing 40% confidence

Timelines: Reports should typically be filed "without delay" after the suspicion arises.

licensing 40% confidence

Customer Identification Data: Records of all documents obtained during CDD, including identification and verification information, beneficial ownership details, and account details.

licensing 40% confidence

Transaction Records: Records of all transactions conducted, including amounts, types of virtual assets, dates, sender and recipient information, and any associated messages or instructions.

licensing 40% confidence

Analysis of Complex/Unusual Transactions: Records of any internal findings, analysis, or documentation related to complex, unusual, large, or high-risk transactions.

licensing 40% confidence

Retention Period: Records must generally be kept for a minimum period of five years from the date of the transaction or the termination of the business relationship.

licensing 40% confidence

The State Service for Financial Intelligence (SSFI) under the Ministry of Finance of the Kyrgyz Republic.

licensing 40% confidence

Role: The SSFI acts as Kyrgyzstan's Financial Intelligence Unit (FIU). It is responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies, as well as for developing and implementing AML/CFT policies and overseeing compliance by reporting entities.

licensing 40% confidence

Evolving Landscape: The regulatory landscape for virtual assets is constantly evolving globally and in Kyrgyzstan. VASPs should monitor for any new specific laws, regulations, or guidance related to cryptocurrencies issued by the SSFI or the National Bank of the Kyrgyz Republic.

licensing 40% confidence

National Bank of the Kyrgyz Republic (NBKR): While the SSFI is the primary AML/CFT supervisor, the NBKR also plays a crucial role in maintaining financial stability and overseeing the financial sector. The NBKR has historically issued warnings regarding the risks of cryptocurrencies. Any future comprehensive regulatory framework for VASPs might involve the NBKR, especially if virtual assets are classified as financial instruments or securities.

licensing 40% confidence

FATF Standards: Adherence to FATF recommendations is paramount. VASPs should ensure their compliance programs are aligned with the latest FATF guidance on virtual assets.

aml 60% confidence

Adopted: Yes, Kyrgyzstan adopted legislation to regulate virtual assets and include VASPs within its AML/CFT framework.

aml 60% confidence

Key Legislation: The primary law is the Law of the Kyrgyz Republic No. 200 "On the Turnover of Virtual Assets" dated August 10, 2022. This law provides the legal basis for the regulation of virtual assets and designates VASPs as obliged entities for AML/CFT purposes.

aml 60% confidence

Effective Date: The Law No. 200 became effective shortly after its promulgation in August 2022. This integration means VASPs are now subject to the broader AML/CFT legislation of Kyrgyzstan, including reporting requirements.

aml 60% confidence

While Law No. 200 designates VASPs as obliged entities, the specific threshold amounts for the FATF Travel Rule (i.e., the requirement to transmit originator and beneficiary information) are typically set by the overarching AML/CFT law or secondary regulations/guidance from the Financial Intelligence Unit (FIU).

aml 60% confidence

FATF Standard Threshold: The FATF Travel Rule generally applies to virtual asset transfers (transactions) exceeding USD/EUR 1,000 (or its equivalent in virtual assets) for cross-border transfers and USD/EUR 1,000 (or its equivalent) if the transaction is domestic and not part of a pre-existing business relationship where the customer has been verified. For unhosted wallets, the guidance usually suggests due diligence for transactions above a certain threshold (e.g., USD/EUR 1,000), but the Travel Rule itself focuses on VASP-to-VASP transfers.

aml 60% confidence

Local Application: It is expected that Kyrgyzstan's FIU (the State Financial Intelligence Service under the Government of the Kyrgyz Republic - ГСФР при Правительстве Кыргызской Республики) will issue specific guidance or regulations that either explicitly adopt these FATF thresholds or define their own equivalent based on the national AML/CFT law.

aml 60% confidence

The Law No. 200 "On the Turnover of Virtual Assets" broadly defines and covers entities engaged in activities related to virtual assets. It defines a "Virtual Asset Service Provider" (VASP) as a legal entity carrying out one or more of the following activities for or on behalf of another natural or legal person:

aml 60% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

This comprehensive definition aligns with FATF recommendations, ensuring that most relevant crypto businesses are covered.

aml 60% confidence

Core Requirement: VASPs in Kyrgyzstan are required to obtain, hold, and transmit required originator (sender) and beneficiary (receiver) information for virtual asset transfers that meet the specified thresholds.

aml 60% confidence

Originator Information: Name, account number (or unique transaction identifier), physical address, national identity number, customer identification number, or date and place of birth.

aml 60% confidence

Beneficiary Information: Name, account number (or unique transaction identifier).

aml 60% confidence

Implementation: VASPs are expected to adopt robust technical solutions and protocols (e.g., using Travel Rule solution providers like TRISA, Sygna, Veriscope, etc.) to securely transmit this information to other VASPs involved in a transaction.

aml 60% confidence

Data Security and Privacy: Implementation must comply with data protection and privacy laws in Kyrgyzstan, ensuring secure handling and storage of sensitive customer data.

aml 60% confidence

Record-keeping: VASPs must maintain records of all required information for a period specified by national AML/CFT laws (typically 5-7 years).

aml 60% confidence

Non-compliance with AML/CFT obligations, including those related to the Travel Rule, generally falls under the existing national legislation on combating the legalization (laundering) of criminal proceeds and the financing of terrorism.

aml 60% confidence

Administrative Fines: Significant monetary penalties for legal entities and responsible officials.

aml 60% confidence

Suspension or Revocation of Licenses: The licensing authority (which is expected to be the State Service for Regulation and Supervision of the Financial Market under the Government of the Kyrgyz Republic or a similar body) can suspend or revoke a VASP's operating license.

enforcement 60% confidence

Entity Targeted: Organizers and promoters of the "S-Group" financial pyramid scheme. Violation Type: Fraud, establishment of a financial pyramid, illegal enrichment. The scheme falsely promised high returns from investments in various "projects," including crypto trading. Penalty Amount: No single "fine" amount specified as it's a criminal case. The goal is asset seizure and restitution to victims. The estimated damage to victims was substantial, reaching billions of KGS. Organizers face criminal charges, which can lead to imprisonment.

enforcement 95% confidence

Entity Targeted: The general public, financial institutions, and potential investors. Violation Type: N/A (warnings are preventative, not punitive). The NBKR warns against the risks associated with cryptocurrency, including high volatility, fraud, and the lack of legal tender status. They also emphasize that transactions using crypto are not regulated under Kyrgyz law, except for a specific license requirement for crypto-exchange activities. Penalty Amount: N/A (no direct penalty for warnings).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are treated as VASPs under Kyrgyzstan's Law No. 200 (August 2022) and may operate only as locally-incorporated legal entities subject to AML/CFT obligations (CDD, Travel Rule, STR, record-keeping) supervised by the SSFI, but no dedicated custody license, segregation, insurance, or proof-of-reserves rules exist in the provided framework, creating material regulatory ambiguity for the operating model.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?