← Regulations / Kiribati / Operating Models / Self-custodial wallet

Self-custodial wallet / non-custodial software in Kiribati

Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.

Conditional AI-Generated · Unreviewed

Self-custodial wallet is conditionally permitted in Kiribati without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD): identify and verify customers' name, residential address, date of birth, and identification number per AML/CTF Act 2018
  • Beneficial ownership identification for legal persons/arrangements
  • Ongoing monitoring of business relationships and transactions
  • Record-keeping of all transactions and CDD data
  • Suspicious Transaction Reporting (STR) to Kiribati FIU for any transaction suspected of involving criminal proceeds or terrorist financing
  • No tipping-off: prohibition on disclosing STR filing to customers or third parties
  • Risk-based approach: apply Simplified Due Diligence (SDD) in low-risk cases and Enhanced Due Diligence (EDD) for PEPs, cross-border relationships, and high-risk scenarios
  • Travel Rule considerations: FATF Recommendation 16 extended to VA transfers — obtain/transmit originator and beneficiary information for virtual asset transfers above threshold

Key Restrictions

  • Self-custodial wallet publishers that never hold, control, or have access to user funds may not fall under the AML/CTF Act's definition of a VASP or 'money or value transfer service', creating ambiguity
  • If the software publisher provides any ancillary services (e.g., integrated fiat on-ramp, swap functionality, or transaction routing), it could trigger VASP classification and full AML obligations
  • No specific crypto licensing regime exists — only general business registration with the Registrar of Companies is required for a pure software publisher
  • Kiribati has no specific consumer-protection, disclosure, or software-liability rules for non-custodial wallet software

Key Risks

  • Regulatory ambiguity: the absence of clear guidance means the FIU could retroactively interpret software publishing as a VASP activity under the broad AML/CTF Act
  • FATF expectations (Recommendation 15) may pressure Kiribati to expand VASP obligations to include wallet providers, creating future compliance risk
  • Limited local legal infrastructure makes it difficult to obtain a definitive legal opinion on classification
  • Bank of Kiribati could issue directives if virtual asset activity impacts financial stability, even absent specific crypto legislation
  • Reputational risk: operating in a jurisdiction with nascent AML frameworks may raise concerns for partners, auditors, or regulators in other jurisdictions

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Registration, Not Licensing (for Crypto-specific activities): Kiribati currently operates on a de facto registration regime under its AML/CTF laws for virtual asset activities, rather than a specific licensing regime. This means that entities dealing with virtual assets are primarily required to comply with AML/CTF obligations and register with the FIU (if they fall under the definition of an "accountable institution"), rather than obtaining a bespoke crypto-specific license.

licensing 60% confidence

General Business Licensing: All businesses operating in Kiribati, regardless of their sector, must still undergo general business registration and licensing with the Registrar of Companies and comply with general business laws.

licensing 60% confidence

Kiribati Financial Intelligence Unit (FIU): Responsible for enforcing the AML/CTF Act, receiving suspicious transaction reports, and providing guidance on AML/CTF compliance.

licensing 60% confidence

Likely Treatment: Would most likely be considered a "money or value transfer service" or a "virtual asset service provider" (VASP) under the scope of the AML/CTF Act. This would trigger obligations as an "accountable institution."

licensing 60% confidence

Requirements: Compliance with AML/CTF Act, including registration with the FIU (if applicable), and general business registration.

licensing 60% confidence

Mandatory: Any entity falling under the scope of the AML/CTF Act (including VASPs by interpretation) would be obligated to implement robust AML/KYC procedures.

licensing 60% confidence

Customer Due Diligence (CDD): Identifying and verifying the identity of customers, including beneficial owners.

licensing 60% confidence

Ongoing Monitoring: Monitoring business relationships and transactions.

licensing 60% confidence

Record-Keeping: Maintaining records of transactions and customer data for a specified period.

licensing 60% confidence

Suspicious Transaction Reporting (STR): Reporting suspicious activities to the Kiribati FIU.

aml 60% confidence

Anti-Money Laundering and Counter-Terrorist Financing Act 2018 (as amended): This is the core AML/CFT legislation. While it might not explicitly mention "virtual assets" or "stablecoins," financial institutions and designated non-financial businesses and professions (DNFBPs) are expected to report suspicious transactions. If stablecoin activities were deemed to fall under "financial services" broadly, they could be captured.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.

aml 40% confidence

Risk-Based Approach: VASPs must apply a risk-based approach, meaning:

aml 40% confidence

Obligation to Report: VASPs must report any transaction (or attempted transaction) where they know, suspect, or have reasonable grounds to suspect that the transaction involves proceeds of criminal activity or relates to terrorist financing.

aml 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.

aml 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process (identification documents, beneficial ownership information, business relationship details).

aml 40% confidence

Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).

aml 40% confidence

Financial Intelligence Unit of Kiribati (FIU Kiribati)

aml 40% confidence

Regulatory Ambiguity: The lack of specific VASP legislation means there can be ambiguity. VASPs should proactively engage with the FIU Kiribati to seek clarification on their obligations and how the existing framework applies to their specific business model.

aml 40% confidence

FATF Standards: Kiribati is expected to align with FATF standards. This means VASPs should design their AML/CFT programs based on the global best practices outlined in the FATF Recommendations and guidance for virtual assets, even if not explicitly codified in Kiribati law yet.

aml 40% confidence

Travel Rule: While not explicitly mentioned in Kiribati's 2017 Act, the FATF "Travel Rule" (Recommendation 16 for wire transfers, extended to virtual asset transfers) requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers above a certain threshold. VASPs should be prepared to implement this.

enforcement 20% confidence

Nascent Regulatory Environment: Kiribati is a small island nation with a developing financial sector. Its regulatory frameworks for emerging technologies like cryptocurrency are either nascent or non-existent. There is no specific legislation or dedicated body for crypto regulation in place.

enforcement 20% confidence

Limited Crypto Activity: The level of cryptocurrency adoption and activity within Kiribati is generally very low compared to larger economies, meaning fewer potential targets for enforcement.

custody 40% confidence

None specifically for crypto custody. There is no public record of a licensing regime exclusively for digital asset custodians in Kiribati. General financial services licenses might exist, but these typically cover traditional banking, insurance, or investment services and would not explicitly apply to crypto custody unless specifically amended.

custody 40% confidence

No specific rules. Given the absence of a dedicated framework, there are no explicit mandates for the segregation of client digital assets from a custodian's proprietary assets. In traditional finance, this is a cornerstone of investor protection, but it has not been extended to digital assets through specific legislation in Kiribati.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a pure self-custodial wallet publisher that never holds user keys or funds likely does not trigger VASP classification under Kiribati's AML/CTF Act, requiring only general business registration; however, any ancillary services (e.g., fiat on-ramps, swaps) could reclassify the operator as a VASP with full AML/CTF obligations (CDD, STR, record-keeping) under a highly ambiguous regulatory environment with no specific crypto legislation.

Questions this verdict aims to answer

  • Does software publishing trigger VASP / MSB classification?
  • Do AML obligations attach when no custody exists?
  • What disclosure or consumer-protection rules apply?