Custodial wallet / SaaS in Kiribati
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Kiribati without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) — identify and verify identity of customers including beneficial owners (ki.aml.identification-and-verification, ki.aml.legal-entities-companies-trusts-obtain)
- Ongoing monitoring of business relationships and transactions (ki.aml.ongoing-monitoring-continuously-monitoring-the)
- Record-keeping — maintain records of transactions, CDD information, and correspondence for a specified period (ki.aml.record-keeping-maintaining-records-of, ki.aml.customer-identification-records-all-documents, ki.aml.transaction-records-records-of-all)
- Suspicious Transaction Reporting (STR) — report any suspected money-laundering or terrorist-financing transactions to the Kiribati FIU (ki.aml.obligation-to-report-vasps-must, ki.aml.reporting-authority-all-strs-must)
- No tipping-off — prohibited from disclosing to customers that an STR has been filed (ki.aml.no-tipping-off-vasps-and-their)
- Risk-based approach — apply Simplified Due Diligence (SDD) in low-risk scenarios and Enhanced Due Diligence (EDD) for PEPs, cross-border relationships, and high-risk situations (ki.aml.risk-based-approach-vasps-must-apply, ki.aml.simplified-due-diligence-sdd-may, ki.aml.enhanced-due-diligence-edd-must)
- Travel Rule — while not explicitly codified in Kiribati law, FATF-aligned VASPs should obtain and transmit originator/beneficiary information for virtual asset transfers (ki.aml.travel-rule-while-not-explicitly)
- Source of Funds/Wealth — obtain for high-risk customers or transactions (ki.aml.source-of-fundswealth-for-high-risk)
Key Restrictions
- No specific crypto custody license exists — a custodial wallet SaaS would likely be treated as a VASP under the AML/CTF Act, requiring AML registration with the FIU rather than a dedicated license (ki.licensing.registration-not-licensing-for-crypto-specific, ki.licensing.custody-providers-holding-virtual-assets)
- No specific segregation, insurance, cold-storage, or proof-of-reserves rules exist for digital asset custody — provider discretion applies (ki.custody.no-specific-rules-given-the, ki.custody.no-specific-requirements-there-are, ki.custody.no-specific-mandates-kiribatis-regulatory)
- No specific qualified-custodian definition exists in Kiribati law (ki.custody.no-specific-definition-kiribati-law)
- General business registration with the Registrar of Companies is required for any entity operating in Kiribati (ki.licensing.general-business-licensing-all-businesses)
- No specific minimum capital requirements for VASPs exist (ki.licensing.specific-crypto-capital-there-are)
Key Risks
- Regulatory ambiguity — the absence of a dedicated crypto framework creates uncertainty about how custodial wallet services will be classified and supervised (ki.enforcement.nascent-regulatory-environment-kiribati-is)
- AML/CTF obligations fall on the VASP itself; the (white-label) client-vs-SaaS allocation of CDD obligations is not addressed in local law, creating compliance gap risk for the SaaS provider (ki.aml.regulatory-ambiguity-the-lack-of)
- Low enforcement precedent does not mean no enforcement — the FIU could take action under the AML/CTF Act if it determines the operator is an accountable institution (ki.enforcement.limited-crypto-activity-the-level)
- Travel Rule compliance burden may be expected as Kiribati aligns with FATF standards even absent local codification (ki.aml.travel-rule-while-not-explicitly)
- Banking access risk — the Bank of Kiribati could issue directives if VA activities affect financial stability; local banking relationships may be fragile (ki.licensing.bank-of-kiribati-the-central)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial License Requirements:
None specifically for crypto custody. There is no public record of a licensing regime exclusively for digital asset custodians in Kiribati. General financial services licenses might exist, but these typically cover traditional banking, insurance, or investment services and would not explicitly apply to crypto custody unless specifically amended.
Segregation of Client Assets Rules:
No specific rules. Given the absence of a dedicated framework, there are no explicit mandates for the segregation of client digital assets from a custodian's proprietary assets. In traditional finance, this is a cornerstone of investor protection, but it has not been extended to digital assets through specific legislation in Kiribati.
No specific requirements. There are no known legislative or regulatory requirements mandating insurance or bonding for digital asset custodians operating in Kiribati.
No specific mandates. Kiribati's regulatory environment does not impose technical requirements such as the use of cold storage for digital assets. Decisions regarding storage methods (hot, warm, cold) would be left to the operational discretion of the service provider.
No specific definition. Kiribati law does not provide a specific definition for a "qualified custodian" in the context of digital assets.
Customer Due Diligence (CDD): Identifying and verifying the identity of customers.
Record Keeping: Maintaining records of transactions and CDD information.
Suspicious Transaction Reporting (STR): Reporting transactions suspected of being linked to money laundering or terrorist financing to the Financial Intelligence Unit (FIU).
Financial Intelligence Unit (FIU) of Kiribati:
Registration, Not Licensing (for Crypto-specific activities): Kiribati currently operates on a de facto registration regime under its AML/CTF laws for virtual asset activities, rather than a specific licensing regime. This means that entities dealing with virtual assets are primarily required to comply with AML/CTF obligations and register with the FIU (if they fall under the definition of an "accountable institution"), rather than obtaining a bespoke crypto-specific license.
General Business Licensing: All businesses operating in Kiribati, regardless of their sector, must still undergo general business registration and licensing with the Registrar of Companies and comply with general business laws.
Custody Providers (holding virtual assets on behalf of others):
Specific Crypto Capital: There are no specific minimum capital requirements defined for virtual asset service providers in Kiribati.
AML/KYC Requirements: This is the most crucial aspect.
Customer Due Diligence (CDD): Identifying and verifying the identity of customers, including beneficial owners.
Ongoing Monitoring: Monitoring business relationships and transactions.
Record-Keeping: Maintaining records of transactions and customer data for a specified period.
Suspicious Transaction Reporting (STR): Reporting suspicious activities to the Kiribati FIU.
Anti-Money Laundering and Counter-Terrorist Financing Act 2018 (as amended): This is the core AML/CFT legislation. While it might not explicitly mention "virtual assets" or "stablecoins," financial institutions and designated non-financial businesses and professions (DNFBPs) are expected to report suspicious transactions. If stablecoin activities were deemed to fall under "financial services" broadly, they could be captured.
Legal Entities (Companies, Trusts): Obtain and verify the legal name, legal form, proof of existence, powers that regulate and bind the legal person or arrangement, and the names of relevant persons holding senior management positions. Identification and verification of beneficial owners (those ultimately owning or controlling 25% or more of the entity) are mandatory.
Purpose and Nature of Business Relationship: Understanding the intended purpose and nature of the business relationship or occasional transaction.
Source of Funds/Wealth: For high-risk customers or transactions, obtaining information on the source of funds or wealth involved in the relationship or transaction.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.
Risk-Based Approach: VASPs must apply a risk-based approach, meaning:
Simplified Due Diligence (SDD): May be applied in lower-risk situations, where specific conditions are met and approved by the FIU.
Enhanced Due Diligence (EDD): Must be applied in higher-risk situations, such as relationships with politically exposed persons (PEPs), cross-border correspondent relationships, or transactions involving high-risk jurisdictions or complex, unusual transactions. EDD includes more intensive verification, increased monitoring, and senior management approval.
Obligation to Report: VASPs must report any transaction (or attempted transaction) where they know, suspect, or have reasonable grounds to suspect that the transaction involves proceeds of criminal activity or relates to terrorist financing.
Reporting Authority: All STRs must be submitted to the Financial Intelligence Unit of Kiribati (FIU Kiribati).
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.
Customer Identification Records: All documents and information obtained during the CDD process (identification documents, beneficial ownership information, business relationship details).
Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).
Travel Rule: While not explicitly mentioned in Kiribati's 2017 Act, the FATF "Travel Rule" (Recommendation 16 for wire transfers, extended to virtual asset transfers) requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers above a certain threshold. VASPs should be prepared to implement this.
Regulatory Ambiguity: The lack of specific VASP legislation means there can be ambiguity. VASPs should proactively engage with the FIU Kiribati to seek clarification on their obligations and how the existing framework applies to their specific business model.
Nascent Regulatory Environment: Kiribati is a small island nation with a developing financial sector. Its regulatory frameworks for emerging technologies like cryptocurrency are either nascent or non-existent. There is no specific legislation or dedicated body for crypto regulation in place.
Limited Crypto Activity: The level of cryptocurrency adoption and activity within Kiribati is generally very low compared to larger economies, meaning fewer potential targets for enforcement.
Regulatory Bodies: The primary financial authorities in Kiribati are:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS is permitted in Kiribati under a de facto AML/CTF registration regime (not a dedicated custody license), with no specific segregation, insurance, cold-storage, or qualified-custodian rules, but requiring FIU registration, full AML/KYC/CDD/STR obligations under the AML/CTF Act 2018, and general business registration; significant regulatory ambiguity exists due to the complete absence of a crypto-specific framework.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?