DeFi protocol frontend in Kyrgyzstan
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Kyrgyzstan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP must register as a legal entity and comply with the Law No. 200 'On the Turnover of Virtual Assets' (August 2022), which designates VASPs as obliged entities under AML/CFT framework.
- Full CDD required: name, date/place of birth, citizenship, residential address, ID document details for individuals; full legal name, registration number, legal address, TIN, beneficial owners for legal entities. Verification via independent sources.
- Beneficial ownership identification required (25% ownership or control threshold).
- Risk-based approach: EDD for PEPs, high-risk jurisdictions, complex/large transactions; SDD permitted for lower-risk scenarios.
- Suspicious Transaction Report (STR) required immediately ('without delay') upon any suspicion, regardless of amount — report to the State Service for Financial Intelligence (SSFI/FIU).
- No tipping-off: VASPs and employees must not disclose STR filings or related investigations to customers/third parties.
- Travel Rule obligations apply for virtual asset transfers: obtain, hold, and transmit originator info (name, account/transaction ID, physical address, national ID or DOB) and beneficiary info (name, account/transaction ID) for cross-border transfers exceeding USD/EUR 1,000 and domestic transfers exceeding USD/EUR 1,000 (per FATF standard).
- Record-keeping: all CDD documents, transaction records, and STR analysis must be retained for minimum 5 years.
- Ongoing monitoring of business relationships and transactions required to ensure consistency with customer risk profile.
Key Restrictions
- Frontend operator must be a registered legal entity in Kyrgyzstan, carrying out regulated VASP activities as defined by Law No. 200 (including safekeeping/administration, exchange, and transfer of virtual assets).
- If the frontend merely provides an interface to permissionless smart contracts without custody, exchange, or transfer of virtual assets on behalf of users, its classification as a VASP is ambiguous — Kyrgyz law defines VASP activities broadly and may still capture the operator under 'participation in and provision of financial services related to virtual assets'.
- Fee-taking from users (e.g., frontend fees, swap fees) likely triggers classification as a VASP under the exchange/transfer definitions, making licensing mandatory.
- Geofencing/regional restrictions are not explicitly mandated by law but would be necessary in practice to avoid serving prohibited or higher-risk persons; KYC screening is effectively mandatory if the operator is a VASP.
- Any mining-related activity is separately restricted by enforcement actions against unauthorized mining operations (electricity theft, illegal entrepreneurship).
Key Risks
- Regulatory ambiguity around whether non-custodial DeFi frontends without direct fiat on/off ramps qualify as VASPs — Law No. 200's broad definitions could capture them, but no explicit guidance on decentralized protocols exists.
- Enforcement risk is moderate to high: SSFI and NBKR have shown willingness to investigate crypto-related activity, and the NBKR has issued multiple public warnings about crypto risks.
- Travel Rule compliance is technically challenging for a frontend aggregator interacting with multiple blockchains and protocols — no regulatory accommodation for the 'unhosted wallet' problem is evident.
- Reputational risk from association with financial pyramid schemes (e.g., S-Group) — the regulator has actively pursued fraudsters using crypto marketing; any DeFi frontend perceived as promotional could attract scrutiny.
- Evolving landscape: regulatory guidance on virtual assets is still developing; new NBKR or SSFI rules could change obligations with little notice.
- Penalties for non-compliance include significant administrative fines, suspension or revocation of license, and potential criminal proceedings.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law of the Kyrgyz Republic on Combating the Financing of Terrorism and Legalization (Laundering) of Criminal Proceeds (No. 87, dated July 25, 2011, with subsequent amendments). This law establishes the legal and organizational framework for AML/CFT, defines the obligations of reporting entities, and outlines the role of the financial intelligence unit.
For individuals: Full name, date and place of birth, citizenship, residential address, identification document details (e.g., passport, national ID number). Verification through reliable, independent sources (e.g., government-issued documents, utility bills).
For legal entities: Full name, legal form, registration number, legal address, tax identification number (TIN), details of beneficial owners, directors, and authorized signatories. Verification through company registration documents, articles of association, and public registries.
Beneficial Ownership Identification: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including those who ultimately own or control the customer, or the person on whose behalf a transaction is being conducted. Thresholds (e.g., 25% ownership or control) typically apply.
Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship (e.g., why the customer is using virtual assets, expected transaction volumes and types).
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Risk-Based Approach: VASPs must adopt a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex structures, large transactions) and simplified due diligence (SDD) for lower-risk scenarios where permitted.
Obligation to Report: If a VASP has grounds to suspect that funds or other property, regardless of the amount, are related to the financing of terrorism or legalization (laundering) of criminal proceeds, it must immediately report such suspicions.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report (STR) has been filed, or that an investigation into money laundering or terrorist financing is being conducted.
Timelines: Reports should typically be filed "without delay" after the suspicion arises.
Customer Identification Data: Records of all documents obtained during CDD, including identification and verification information, beneficial ownership details, and account details.
Transaction Records: Records of all transactions conducted, including amounts, types of virtual assets, dates, sender and recipient information, and any associated messages or instructions.
Analysis of Complex/Unusual Transactions: Records of any internal findings, analysis, or documentation related to complex, unusual, large, or high-risk transactions.
Retention Period: Records must generally be kept for a minimum period of five years from the date of the transaction or the termination of the business relationship.
The State Service for Financial Intelligence (SSFI) under the Ministry of Finance of the Kyrgyz Republic.
Role: The SSFI acts as Kyrgyzstan's Financial Intelligence Unit (FIU). It is responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies, as well as for developing and implementing AML/CFT policies and overseeing compliance by reporting entities.
Evolving Landscape: The regulatory landscape for virtual assets is constantly evolving globally and in Kyrgyzstan. VASPs should monitor for any new specific laws, regulations, or guidance related to cryptocurrencies issued by the SSFI or the National Bank of the Kyrgyz Republic.
National Bank of the Kyrgyz Republic (NBKR): While the SSFI is the primary AML/CFT supervisor, the NBKR also plays a crucial role in maintaining financial stability and overseeing the financial sector. The NBKR has historically issued warnings regarding the risks of cryptocurrencies. Any future comprehensive regulatory framework for VASPs might involve the NBKR, especially if virtual assets are classified as financial instruments or securities.
FATF Standards: Adherence to FATF recommendations is paramount. VASPs should ensure their compliance programs are aligned with the latest FATF guidance on virtual assets.
Adopted: Yes, Kyrgyzstan adopted legislation to regulate virtual assets and include VASPs within its AML/CFT framework.
Key Legislation: The primary law is the Law of the Kyrgyz Republic No. 200 "On the Turnover of Virtual Assets" dated August 10, 2022. This law provides the legal basis for the regulation of virtual assets and designates VASPs as obliged entities for AML/CFT purposes.
Effective Date: The Law No. 200 became effective shortly after its promulgation in August 2022. This integration means VASPs are now subject to the broader AML/CFT legislation of Kyrgyzstan, including reporting requirements.
While Law No. 200 designates VASPs as obliged entities, the specific threshold amounts for the FATF Travel Rule (i.e., the requirement to transmit originator and beneficiary information) are typically set by the overarching AML/CFT law or secondary regulations/guidance from the Financial Intelligence Unit (FIU).
FATF Standard Threshold: The FATF Travel Rule generally applies to virtual asset transfers (transactions) exceeding USD/EUR 1,000 (or its equivalent in virtual assets) for cross-border transfers and USD/EUR 1,000 (or its equivalent) if the transaction is domestic and not part of a pre-existing business relationship where the customer has been verified. For unhosted wallets, the guidance usually suggests due diligence for transactions above a certain threshold (e.g., USD/EUR 1,000), but the Travel Rule itself focuses on VASP-to-VASP transfers.
Local Application: It is expected that Kyrgyzstan's FIU (the State Financial Intelligence Service under the Government of the Kyrgyz Republic - ГСФР при Правительстве Кыргызской Республики) will issue specific guidance or regulations that either explicitly adopt these FATF thresholds or define their own equivalent based on the national AML/CFT law.
The Law No. 200 "On the Turnover of Virtual Assets" broadly defines and covers entities engaged in activities related to virtual assets. It defines a "Virtual Asset Service Provider" (VASP) as a legal entity carrying out one or more of the following activities for or on behalf of another natural or legal person:
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Evidence fact kg.aml.safekeepingandor-administration-of-virtual not found (may have been renamed).
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
This comprehensive definition aligns with FATF recommendations, ensuring that most relevant crypto businesses are covered.
The Law No. 200 and the broader AML/CFT framework primarily mandate the outcome (transmission of required information) rather than specifying a particular technical solution.
Core Requirement: VASPs in Kyrgyzstan are required to obtain, hold, and transmit required originator (sender) and beneficiary (receiver) information for virtual asset transfers that meet the specified thresholds.
Information Required (FATF Standard):
Originator Information: Name, account number (or unique transaction identifier), physical address, national identity number, customer identification number, or date and place of birth.
Beneficiary Information: Name, account number (or unique transaction identifier).
Implementation: VASPs are expected to adopt robust technical solutions and protocols (e.g., using Travel Rule solution providers like TRISA, Sygna, Veriscope, etc.) to securely transmit this information to other VASPs involved in a transaction.
Data Security and Privacy: Implementation must comply with data protection and privacy laws in Kyrgyzstan, ensuring secure handling and storage of sensitive customer data.
Record-keeping: VASPs must maintain records of all required information for a period specified by national AML/CFT laws (typically 5-7 years).
Non-compliance with AML/CFT obligations, including those related to the Travel Rule, generally falls under the existing national legislation on combating the legalization (laundering) of criminal proceeds and the financing of terrorism.
Potential Penalties: These typically include:
Administrative Fines: Significant monetary penalties for legal entities and responsible officials.
Suspension or Revocation of Licenses: The licensing authority (which is expected to be the State Service for Regulation and Supervision of the Financial Market under the Government of the Kyrgyz Republic or a similar body) can suspend or revoke a VASP's operating license.
Regulator Name: National Bank of the Kyrgyz Republic (NBKR)
Entity Targeted: The general public, financial institutions, and potential investors. Violation Type: N/A (warnings are preventative, not punitive). The NBKR warns against the risks associated with cryptocurrency, including high volatility, fraud, and the lack of legal tender status. They also emphasize that transactions using crypto are not regulated under Kyrgyz law, except for a specific license requirement for crypto-exchange activities. Penalty Amount: N/A (no direct penalty for warnings).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operator serving Kyrgyz residents would likely be classified as a VASP under Law No. 200 if it takes fees, facilitates exchange/transfer of virtual assets, or provides safekeeping/administration, requiring registration as a local legal entity, full AML/CFT compliance including CDD, Travel Rule, STR reporting to the SSFI, and 5-year recordkeeping, with regulatory ambiguity around non-custodial, non-fee-taking interfaces.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?