Self-custodial wallet / non-custodial software in Kyrgyzstan
Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.
Self-custodial wallet is conditionally permitted in Kyrgyzstan with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- CDD obligation under Law No. 200 'On the Turnover of Virtual Assets' (Aug 2022) — but only triggered if the publisher is classified as a VASP (i.e., engages in safekeeping/administration of virtual assets or instruments enabling control over them). Non-custodial wallet publishers that never hold keys likely fall outside this scope.
- If classified as a VASP: must identify and verify customers (full name, date/place of birth, citizenship, address, ID document details for individuals; full name, legal form, registration number, legal address, TIN, beneficial owners for legal entities).
- If classified as a VASP: beneficial ownership identification required (25%+ threshold).
- If classified as a VASP: ongoing transaction monitoring, risk-based approach, EDD for PEPs/high-risk customers, SDD where permitted.
- If classified as a VASP: suspicious transaction reporting to the State Service for Financial Intelligence (SSFI) 'without delay' upon suspicion, no tipping-off.
- If classified as a VASP: Travel Rule obligations for transfers above FATF thresholds (USD/EUR 1,000 equivalent) — must obtain, hold, and transmit originator/beneficiary information.
- If classified as a VASP: record-keeping for minimum 5 years (CDD documents, transaction records, analysis of unusual transactions).
- Non-compliance penalties: administrative fines, suspension or revocation of license.
Key Restrictions
- Publisher must assess whether it qualifies as a VASP under Law No. 200. The definition includes 'safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets' — non-custodial wallet software that does not hold or control private keys likely falls outside this scope, but the law is broadly drafted and FATF guidance could be interpreted to cover wallet software.
- If the software facilitates transfers on behalf of users (e.g., built-in swapping or bridging features), the publisher may be deemed to be 'transferring virtual assets', triggering VASP classification.
- If classified as a VASP: must be a legal entity (local entity required).
- If classified as a VASP: must register with the SSFI and comply with the full AML/CFT framework under Law No. 87 (AML/CFT Law).
- The NBKR has issued warnings about crypto risks and does not recognize crypto as legal tender — consumer protection disclosures are advisable.
Key Risks
- Regulatory ambiguity: Kyrgyzstan's Law No. 200 uses broad VASP language (e.g., 'instruments enabling control over virtual assets') that could be interpreted to cover non-custodial wallet publishers, despite the publisher never holding keys.
- Enforcement precedent is focused on illegal mining and financial pyramid schemes — there is no clear enforcement guidance or court precedent specifically addressing non-custodial wallet software publishers.
- The SSFI has not yet issued specific guidance or thresholds for VASP classification of software-only wallet providers, creating uncertainty around whether registration is required.
- NBKR's cautious public stance on crypto could lead to sudden regulatory changes or restrictive interpretations that capture wallet software.
- Risk of being treated as an unregistered VASP if the SSFI interprets 'instruments enabling control' broadly — penalties include fines and license revocation.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law of the Kyrgyz Republic on Combating the Financing of Terrorism and Legalization (Laundering) of Criminal Proceeds (No. 87, dated July 25, 2011, with subsequent amendments). This law establishes the legal and organizational framework for AML/CFT, defines the obligations of reporting entities, and outlines the role of the financial intelligence unit.
The State Service for Financial Intelligence (SSFI) under the Ministry of Finance of the Kyrgyz Republic.
Adopted: Yes, Kyrgyzstan adopted legislation to regulate virtual assets and include VASPs within its AML/CFT framework.
Key Legislation: The primary law is the Law of the Kyrgyz Republic No. 200 "On the Turnover of Virtual Assets" dated August 10, 2022. This law provides the legal basis for the regulation of virtual assets and designates VASPs as obliged entities for AML/CFT purposes.
While Law No. 200 designates VASPs as obliged entities, the specific threshold amounts for the FATF Travel Rule (i.e., the requirement to transmit originator and beneficiary information) are typically set by the overarching AML/CFT law or secondary regulations/guidance from the Financial Intelligence Unit (FIU).
The Law No. 200 "On the Turnover of Virtual Assets" broadly defines and covers entities engaged in activities related to virtual assets. It defines a "Virtual Asset Service Provider" (VASP) as a legal entity carrying out one or more of the following activities for or on behalf of another natural or legal person:
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Transfer of virtual assets.
Exchange between one or more forms of virtual assets.
This comprehensive definition aligns with FATF recommendations, ensuring that most relevant crypto businesses are covered.
Core Requirement: VASPs in Kyrgyzstan are required to obtain, hold, and transmit required originator (sender) and beneficiary (receiver) information for virtual asset transfers that meet the specified thresholds.
For individuals: Full name, date and place of birth, citizenship, residential address, identification document details (e.g., passport, national ID number). Verification through reliable, independent sources (e.g., government-issued documents, utility bills).
For legal entities: Full name, legal form, registration number, legal address, tax identification number (TIN), details of beneficial owners, directors, and authorized signatories. Verification through company registration documents, articles of association, and public registries.
Beneficial Ownership Identification: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including those who ultimately own or control the customer, or the person on whose behalf a transaction is being conducted. Thresholds (e.g., 25% ownership or control) typically apply.
Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship (e.g., why the customer is using virtual assets, expected transaction volumes and types).
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Risk-Based Approach: VASPs must adopt a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex structures, large transactions) and simplified due diligence (SDD) for lower-risk scenarios where permitted.
Obligation to Report: If a VASP has grounds to suspect that funds or other property, regardless of the amount, are related to the financing of terrorism or legalization (laundering) of criminal proceeds, it must immediately report such suspicions.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report (STR) has been filed, or that an investigation into money laundering or terrorist financing is being conducted.
Customer Identification Data: Records of all documents obtained during CDD, including identification and verification information, beneficial ownership details, and account details.
Transaction Records: Records of all transactions conducted, including amounts, types of virtual assets, dates, sender and recipient information, and any associated messages or instructions.
Analysis of Complex/Unusual Transactions: Records of any internal findings, analysis, or documentation related to complex, unusual, large, or high-risk transactions.
Retention Period: Records must generally be kept for a minimum period of five years from the date of the transaction or the termination of the business relationship.
National Bank of the Kyrgyz Republic (NBKR): While the SSFI is the primary AML/CFT supervisor, the NBKR also plays a crucial role in maintaining financial stability and overseeing the financial sector. The NBKR has historically issued warnings regarding the risks of cryptocurrencies. Any future comprehensive regulatory framework for VASPs might involve the NBKR, especially if virtual assets are classified as financial instruments or securities.
Regulator Name: National Bank of the Kyrgyz Republic (NBKR)
FATF Standard Threshold: The FATF Travel Rule generally applies to virtual asset transfers (transactions) exceeding USD/EUR 1,000 (or its equivalent in virtual assets) for cross-border transfers and USD/EUR 1,000 (or its equivalent) if the transaction is domestic and not part of a pre-existing business relationship where the customer has been verified. For unhosted wallets, the guidance usually suggests due diligence for transactions above a certain threshold (e.g., USD/EUR 1,000), but the Travel Rule itself focuses on VASP-to-VASP transfers.
Information Required (FATF Standard):
Non-compliance with AML/CFT obligations, including those related to the Travel Rule, generally falls under the existing national legislation on combating the legalization (laundering) of criminal proceeds and the financing of terrorism.
Administrative Fines: Significant monetary penalties for legal entities and responsible officials.
Suspension or Revocation of Licenses: The licensing authority (which is expected to be the State Service for Regulation and Supervision of the Financial Market under the Government of the Kyrgyz Republic or a similar body) can suspend or revoke a VASP's operating license.
Evolving Landscape: The regulatory landscape for virtual assets is constantly evolving globally and in Kyrgyzstan. VASPs should monitor for any new specific laws, regulations, or guidance related to cryptocurrencies issued by the SSFI or the National Bank of the Kyrgyz Republic.
FATF Standards: Adherence to FATF recommendations is paramount. VASPs should ensure their compliance programs are aligned with the latest FATF guidance on virtual assets.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-custodial wallet software publisher that never holds or controls private keys likely falls outside Kyrgyzstan's VASP definition under Law No. 200, but the broad term 'instruments enabling control over virtual assets' creates regulatory ambiguity; if classified as a VASP, local incorporation, AML/CFT registration with the SSFI, and full CDD/Travel Rule obligations apply.
Questions this verdict aims to answer
- Does software publishing trigger VASP / MSB classification?
- Do AML obligations attach when no custody exists?
- What disclosure or consumer-protection rules apply?