← Regulations / Kiribati / Operating Models / Remote VASP

Remote VASP serving residents in Kiribati

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Kiribati without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Registration with the FIU as an 'accountable institution' under the AML/CTF Act (interpreted as a VASP / money or value transfer service)
  • Customer Due Diligence (CDD): identify and verify identity of customers, including beneficial owners (name, residential address, DOB, ID number for individuals; legal name, form, proof of existence, senior management, beneficial ownership for legal entities)
  • Purpose and nature of business relationship understanding
  • Source of funds/wealth inquiry for high-risk customers or transactions
  • Ongoing monitoring of business relationships and transactions
  • Risk-based approach: Simplified Due Diligence (SDD) for low-risk (FIU-approved) and Enhanced Due Diligence (EDD) for high-risk (PEPs, cross-border, high-risk jurisdictions, complex/unusual transactions)
  • Suspicious Transaction Reporting (STR) to the Kiribati Financial Intelligence Unit (FIU) for any transaction or attempted transaction involving proceeds of crime or terrorist financing
  • No tipping-off prohibition
  • Record-keeping: customer identification records, transaction records, and correspondence for a specified period
  • FATF Travel Rule (Recommendation 16) — obtain and transmit originator/beneficiary info for VA transfers above threshold, per expected FATF alignment even if not explicitly codified

Key Restrictions

  • No specific VASP licensing regime exists — operator relies on AML/CTF Act interpretation as a 'money or value transfer service' or VASP
  • General business registration with the Registrar of Companies is still required
  • No specific minimum capital requirements for VASPs; only nominal general business capital requirements
  • No specific segregation of client assets, insurance, bonding, or cold storage mandates — operational discretion, but weak investor protection
  • Regulatory ambiguity: Kiribati has not explicitly defined virtual assets, stablecoins, or VASP categories in law — FATF alignment is expected but not codified

Key Risks

  • Regulatory ambiguity — lack of specific VASP legislation creates uncertainty around scope of obligations and legal classification
  • Enforcement risk is currently low due to nascent regulatory environment and limited crypto activity, but could increase if Kiribati adopts specific crypto legislation or FATF pressures alignment
  • No dedicated publicly accessible crypto guidance from FIU — operators must proactively engage with FIU Kiribati to confirm obligations
  • Bank of Kiribati could issue directives if virtual asset activity impacts financial stability or traditional banking
  • Travel Rule compliance is expected by FATF standards but not explicitly codified in domestic law — gap risk

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration, Not Licensing (for Crypto-specific activities): Kiribati currently operates on a de facto registration regime under its AML/CTF laws for virtual asset activities, rather than a specific licensing regime. This means that entities dealing with virtual assets are primarily required to comply with AML/CTF obligations and register with the FIU (if they fall under the definition of an "accountable institution"), rather than obtaining a bespoke crypto-specific license.

licensing 60% confidence

General Business Licensing: All businesses operating in Kiribati, regardless of their sector, must still undergo general business registration and licensing with the Registrar of Companies and comply with general business laws.

licensing 60% confidence

Kiribati Financial Intelligence Unit (FIU): Responsible for enforcing the AML/CTF Act, receiving suspicious transaction reports, and providing guidance on AML/CTF compliance.

licensing 60% confidence

Likely Treatment: Would most likely be considered a "money or value transfer service" or a "virtual asset service provider" (VASP) under the scope of the AML/CTF Act. This would trigger obligations as an "accountable institution."

licensing 60% confidence

Requirements: Compliance with AML/CTF Act, including registration with the FIU (if applicable), and general business registration.

licensing 60% confidence

Specific Crypto Capital: There are no specific minimum capital requirements defined for virtual asset service providers in Kiribati.

licensing 60% confidence

General Business Capital: General business registration may have nominal capital requirements, but nothing substantial for financial services.

licensing 60% confidence

Mandatory: Any entity falling under the scope of the AML/CTF Act (including VASPs by interpretation) would be obligated to implement robust AML/KYC procedures.

licensing 60% confidence

Customer Due Diligence (CDD): Identifying and verifying the identity of customers, including beneficial owners.

licensing 60% confidence

Ongoing Monitoring: Monitoring business relationships and transactions.

licensing 60% confidence

Record-Keeping: Maintaining records of transactions and customer data for a specified period.

licensing 60% confidence

Suspicious Transaction Reporting (STR): Reporting suspicious activities to the Kiribati FIU.

aml 60% confidence

Anti-Money Laundering and Counter-Terrorist Financing Act 2018 (as amended): This is the core AML/CFT legislation. While it might not explicitly mention "virtual assets" or "stablecoins," financial institutions and designated non-financial businesses and professions (DNFBPs) are expected to report suspicious transactions. If stablecoin activities were deemed to fall under "financial services" broadly, they could be captured.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Individuals: Obtain and verify the customer's name, residential address, date of birth, and an identification number (e.g., passport, national ID card). Verification typically requires reliable, independent source documents or data.

aml 40% confidence

Legal Entities (Companies, Trusts): Obtain and verify the legal name, legal form, proof of existence, powers that regulate and bind the legal person or arrangement, and the names of relevant persons holding senior management positions. Identification and verification of beneficial owners (those ultimately owning or controlling 25% or more of the entity) are mandatory.

aml 40% confidence

Purpose and Nature of Business Relationship: Understanding the intended purpose and nature of the business relationship or occasional transaction.

aml 40% confidence

Source of Funds/Wealth: For high-risk customers or transactions, obtaining information on the source of funds or wealth involved in the relationship or transaction.

aml 40% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.

aml 40% confidence

Risk-Based Approach: VASPs must apply a risk-based approach, meaning:

aml 40% confidence

Simplified Due Diligence (SDD): May be applied in lower-risk situations, where specific conditions are met and approved by the FIU.

aml 40% confidence

Enhanced Due Diligence (EDD): Must be applied in higher-risk situations, such as relationships with politically exposed persons (PEPs), cross-border correspondent relationships, or transactions involving high-risk jurisdictions or complex, unusual transactions. EDD includes more intensive verification, increased monitoring, and senior management approval.

aml 40% confidence

Obligation to Report: VASPs must report any transaction (or attempted transaction) where they know, suspect, or have reasonable grounds to suspect that the transaction involves proceeds of criminal activity or relates to terrorist financing.

aml 40% confidence

Reporting Authority: All STRs must be submitted to the Financial Intelligence Unit of Kiribati (FIU Kiribati).

aml 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.

aml 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process (identification documents, beneficial ownership information, business relationship details).

aml 40% confidence

Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).

aml 40% confidence

Correspondence: Records of all correspondence and analyses related to CDD, business relationships, and transactions.

aml 40% confidence

Financial Intelligence Unit of Kiribati (FIU Kiribati)

aml 40% confidence

Travel Rule: While not explicitly mentioned in Kiribati's 2017 Act, the FATF "Travel Rule" (Recommendation 16 for wire transfers, extended to virtual asset transfers) requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers above a certain threshold. VASPs should be prepared to implement this.

aml 60% confidence

No specific classification exists. Kiribati's current laws do not define or classify stablecoins as e-money, payment tokens, securities, or any other distinct category.

custody 40% confidence

No specific rules. Given the absence of a dedicated framework, there are no explicit mandates for the segregation of client digital assets from a custodian's proprietary assets. In traditional finance, this is a cornerstone of investor protection, but it has not been extended to digital assets through specific legislation in Kiribati.

custody 40% confidence

No specific mandates. Kiribati's regulatory environment does not impose technical requirements such as the use of cold storage for digital assets. Decisions regarding storage methods (hot, warm, cold) would be left to the operational discretion of the service provider.

custody 40% confidence

No specific definition. Kiribati law does not provide a specific definition for a "qualified custodian" in the context of digital assets.

enforcement 20% confidence

Nascent Regulatory Environment: Kiribati is a small island nation with a developing financial sector. Its regulatory frameworks for emerging technologies like cryptocurrency are either nascent or non-existent. There is no specific legislation or dedicated body for crypto regulation in place.

enforcement 20% confidence

Limited Crypto Activity: The level of cryptocurrency adoption and activity within Kiribati is generally very low compared to larger economies, meaning fewer potential targets for enforcement.

enforcement 20% confidence

The Bank of Kiribati (BoK): The central bank responsible for monetary policy and financial system stability.

enforcement 20% confidence

The Kiribati Financial Intelligence Unit (KFIU): Deals with anti-money laundering (AML) and countering the financing of terrorism (CFT).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a foreign-incorporated VASP may remotely serve Kiribati residents, subject to general business registration and AML/CTF compliance (registration as an accountable institution, CDD, ongoing monitoring, STR filing to the FIU), but operates under significant regulatory ambiguity due to the absence of specific VASP legislation.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?