Custodial wallet / SaaS in Comoros
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Comoros with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Apply for an AOFA Financial Services License (custody providers fall under this broader license) — minimum paid-up capital ~USD 10,000–50,000, deposited in a local bank account.
- Implement Customer Due Diligence (CDD) — verify identity for all clients using reliable, independent source documents (passport, national ID, etc.).
- For legal-entity clients: verify name, legal form, address, directors, beneficial owners, proof of incorporation; understand ownership and control structure.
- Identify and verify beneficial owners of customers.
- Understand the purpose and intended nature of the business relationship or occasional transaction.
- Conduct ongoing transaction monitoring to ensure transactions are consistent with the customer's risk profile.
- Apply Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and transactions involving new technologies/products (e.g., virtual assets).
- Report suspicious transactions (STRs) to the National Financial Information Processing Unit (CNTIF) — obligation applies regardless of the amount where there are reasonable grounds to suspect proceeds of crime or terrorist financing.
- No tipping-off: prohibited from disclosing to customers or third parties that an STR has been filed.
- Appoint a qualified AML/CFT Compliance Officer.
- Maintain records of transactions and client identification for the prescribed period (including CDD documents, account files, business correspondence, transaction records including digital wallet addresses and transaction hashes, and copies of STRs).
- Maintain a registered office address in Anjouan and appoint a local registered agent/representative as liaison with AOFA.
Key Restrictions
- Must be licensed under the Anjouan Offshore Finance Authority (AOFA) Financial Services License — no dedicated crypto custody law exists, so general financial services licensing is adapted to cover custody activities.
- Must have a registered office address in Anjouan.
- Must appoint a local registered agent or representative to act as liaison with AOFA.
- Comoros is on the FATF grey list — increased regulatory scrutiny and pressure to tighten AML/CFT regimes applies.
- No specific legal framework for digital asset custody — no defined 'qualified custodian' status, no mandated segregation of client digital assets, no cold-storage requirements, and no specific insurance/bonding rules for digital assets.
- The AML/CFT law (Ordinance No. 19-001/PR of 26 July 2019) does not explicitly name 'virtual assets' — coverage of VASPs relies on broad interpretation of 'financial activity' and 'financial institutions'.
Key Risks
- Regulatory ambiguity — no dedicated crypto/custody law means the operator relies on broad interpretations of existing financial services licensing, creating legal uncertainty.
- FATF grey-list jurisdiction — Comoros is under increased monitoring, which may lead to sudden regulatory changes, enhanced due diligence requirements by counterparties, and reputational risk for licensed entities.
- No segregation or insurance rules for digital assets — client assets lack the legal protections common in more developed custody regimes.
- Limited enforcement track record — no public enforcement actions mean uncertainty about how authorities would respond to non-compliance or disputes.
- Scrutiny challenge — the AML framework covers VASPs via broad definitions, but the absence of explicit VASP regulation creates gaps in how SaaS vs. white-label client obligations are allocated.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Overall Regulatory Landscape: The primary financial regulator in Comoros is the Banque Centrale des Comores (BCC), which oversees traditional banking and financial services. Comoros is also a member of the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), indicating a commitment to international AML/CFT standards. However, these standards typically recommend, rather than mandate, specific digital asset custody rules for individual member states unless adopted into national law.
None Specific: There are no specific licensing requirements for cryptocurrency custodians in Comoros as there is no specific legal definition or framework for such entities. Entities operating in the crypto space would likely fall into an unregulated category or might be subject to existing general financial services laws if their activities could be broadly interpreted as such (though this is unlikely for pure crypto custody without specific legal amendments).
None Specific for Digital Assets: Since there are no specific custody laws, there are no explicit rules mandating the segregation of client digital assets from a custodian's proprietary assets. Traditional financial institutions under BCC oversight are subject to segregation rules for fiat currencies and securities, but these do not extend to digital assets without specific legislation.
None Specific: There are no specific licensing requirements for cryptocurrency custodians in Comoros as there is no specific legal definition or framework for such entities. Entities operating in the crypto space would likely fall into an unregulated category or might be subject to existing general financial services laws if their activities could be broadly interpreted as such (though this is unlikely for pure crypto custody without specific legal amendments).
None: There are no specific mandates or requirements for the use of cold storage or any particular security measures for digital assets.
None: There is no legal definition of a "qualified custodian" in the context of digital assets within Comorian law.
Anjouan Offshore Finance Authority (AOFA): This is the primary authority responsible for licensing offshore financial services, including what are often adapted for cryptocurrency businesses.
Specific Crypto Law vs. General Financial Services License:
Instead, virtual asset businesses seeking to operate from Comoros (via Anjouan) typically apply for a general financial services license or a Money Service Business (MSB) license under the AOFA framework. These licenses are then interpreted and adapted to cover crypto-related activities.
Custody Providers: Would also fall under the broader Financial Services License, as they manage and secure virtual assets on behalf of clients. Specific conditions regarding security, insurance, and segregation of assets might be imposed.
The capital requirement is typically modest compared to many other jurisdictions. For a general Financial Services or MSB license from AOFA, the minimum paid-up capital requirement can be around USD 10,000 to USD 50,000, though this can vary. It's often required to be deposited in a local bank account or an account approved by the AOFA.
Comoros is currently on the FATF (Financial Action Task Force) "grey list" (Jurisdictions under increased monitoring). This means it is actively working with the FATF to address strategic deficiencies in its AML/CFT regimes.
Businesses must formally apply for a license.
They must meet specific criteria and undergo due diligence by the AOFA.
Registered Office: All licensed entities must have a registered office address in Anjouan.
Local Agent/Representative: It's common to require a local registered agent or representative who acts as a liaison with the AOFA.
Customer Due Diligence (CDD): Verification of identity for all clients (individuals and corporate).
Enhanced Due Diligence (EDD): For high-risk clients or transactions.
Monitoring: Ongoing monitoring of transactions for suspicious activities.
Reporting: Reporting of suspicious transactions (STRs) to the local Financial Intelligence Unit (FIU), which is likely the National Financial Intelligence Processing Unit (Unité Nationale de Traitement des Renseignements Financiers - UNTRF).
Compliance Officer: Appointment of a qualified AML/CFT Compliance Officer.
Record Keeping: Maintaining records of transactions and client identification for a prescribed period.
Ordinance No. 19-001/PR of 26 July 2019 on the Fight Against Money Laundering and Terrorist Financing: This is the most recent foundational AML/CFT law in Comoros. It replaced previous legislation (like Law No. 11-002/AF of 29 March 2011) and aims to align the Comorian framework with international standards set by FATF.
Note: While this Ordinance may not explicitly name "virtual assets" or "cryptocurrency," the broad definitions of "financial activity," "financial institutions," and "designated non-financial businesses and professions (DNFBPs)" are generally interpreted to encompass activities related to virtual assets and VASPs, especially given FATF Recommendation 15.
Be subject to licensing or registration: Depending on the specific interpretation and future regulations, VASPs are expected to be licensed or registered by the relevant authorities (e.g., the Central Bank).
Implement AML/CFT requirements: VASPs must comply with all AML/CFT obligations applicable to financial institutions, including customer due diligence, record-keeping, and suspicious transaction reporting.
For natural persons: Obtain and verify the customer's identity using reliable, independent source documents, data, or information (e.g., full name, address, date and place of birth, nationality, unique identification number from an official document like a passport or national ID card).
For legal entities: Obtain and verify the identity of the legal entity (e.g., name, legal form, address, directors, beneficial owners, proof of incorporation). Understand the ownership and control structure.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons and arrangements.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conduct ongoing due diligence on the business relationship and scrutinize transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Apply EDD measures to higher-risk situations, which may include:
Transactions involving complex or unusually large amounts.
Transactions involving new technologies and products (e.g., certain virtual assets).
Source of Funds/Wealth: For high-risk clients or transactions, VASPs should take reasonable measures to establish the source of funds or source of wealth.
Obligation to Report: VASPs are obligated to report any transaction (or attempted transaction), regardless of the amount, where there are reasonable grounds to suspect that the funds are the proceeds of a crime or are related to terrorist financing.
Reporting Authority: All STRs must be submitted to the National Financial Information Processing Unit (Cellule Nationale de Traitement des Informations Financières - CNTIF), which is Comoros' Financial Intelligence Unit (FIU).
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that an STR has been filed or that an investigation is underway.
Customer Identification Data: All documents and information used for CDD, including verification records.
Account Files: Records related to customer accounts and business relationships.
Business Correspondence: Relevant correspondence with customers.
Transaction Records: Records of all transactions (date, type, amount, currency, parties involved, payment methods, digital wallet addresses, transaction hashes).
STRs and Internal Reports: Copies of all STRs filed and any internal reports related to suspicious activities.
Developing Regulatory Landscape: Comoros is a small, developing island nation. Its financial regulatory framework is still maturing, and specific legislation or dedicated enforcement mechanisms for complex digital assets like cryptocurrencies are likely not yet robust or fully established.
Lack of Transparency/Public Disclosure: Even if minor enforcement actions or investigations were to occur, they are unlikely to be publicly disclosed with the level of detail requested (penalty amounts, specific dates, outcomes, public reports) in a country with less developed financial transparency standards compared to major global financial hubs.
Limited Scale of Crypto Activity: It's also possible that the scale of cryptocurrency operations or significant violations within Comoros has not yet reached a level that would trigger major, publicly reported enforcement actions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators may operate in Comoros by obtaining an AOFA Financial Services License under the Anjouan offshore framework, with no dedicated crypto custody law, no segregation/insurance/cold-storage mandates, and AML obligations under Ordinance No. 19-001/PR (interpreted to cover VASPs), but Comoros' FATF grey-list status and regulatory ambiguity create material risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?