DeFi protocol frontend in Comoros
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Comoros with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Verify identity of all clients using reliable independent source documents (full name, address, DOB, nationality, official ID number for natural persons; name, legal form, address, directors, beneficial owners, proof of incorporation for legal entities) per km.aml.identification-and-verification and km.aml.for-natural-persons-obtain-and and km.aml.for-legal-entities-obtain-and
- Beneficial Ownership: Identify and take reasonable measures to verify beneficial owner(s) of all customers per km.aml.beneficial-ownership-identify-and-take
- Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of each business relationship per km.aml.purpose-and-intended-nature-of
- Ongoing Monitoring: Conduct ongoing due diligence and scrutinize transactions throughout the relationship to ensure consistency with customer risk profile per km.aml.ongoing-monitoring-conduct-ongoing-due
- Enhanced Due Diligence (EDD): Apply EDD to PEPs, customers from high-risk jurisdictions, complex/unusually large transactions, non-face-to-face relationships, and transactions involving new technologies (including certain virtual assets) per km.aml.enhanced-due-diligence-edd-apply through km.aml.transactions-involving-new-technologies-and
- Source of Funds/Wealth: For high-risk clients or transactions, take reasonable measures to establish source of funds or source of wealth per km.aml.source-of-fundswealth-for-high-risk
- Suspicious Transaction Reporting (STR): Report any transaction (regardless of amount) where there are reasonable grounds to suspect proceeds of crime or terrorist financing to the CNTIF (Comoros FIU) per km.aml.obligation-to-report-vasps-are and km.aml.reporting-authority-all-strs-must
- No Tipping-Off: Prohibited from disclosing to customers or third parties that an STR has been filed per km.aml.no-tipping-off-vasps-and-their
- Record Keeping: Maintain customer identification data, account files, business correspondence, transaction records (date, type, amount, currency, parties, wallet addresses, transaction hashes), and copies of STRs for prescribed period per km.aml.customer-identification-data-all-documents through km.aml.strs-and-internal-reports-copies
- Appointment of a qualified AML/CFT Compliance Officer per km.licensing.compliance-officer-appointment-of-a
Key Restrictions
- Must obtain an AOFA Financial Services License or MSB license, adapted to cover crypto-related activities — no dedicated crypto licensing framework exists per km.licensing.instead-virtual-asset-businesses-seeking and km.licensing.required-licenses-for-specific-providers
- Must maintain a registered office address in Anjouan per km.licensing.registered-office-all-licensed-entities
- Must appoint a local registered agent or representative as liaison with AOFA per km.licensing.local-agentrepresentative-its-common-to
- Minimum paid-up capital of approximately USD 10,000–50,000 required, typically deposited in a local bank account per km.licensing.the-capital-requirement-is-typically
- Operational substance plan recommended for reputational/compliance purposes per km.licensing.physical-presencestaff-while-a-full
- Must comply with AOFA licensing criteria and undergo due diligence per km.licensing.they-must-meet-specific-criteria
- FATF grey-list status (jurisdictions under increased monitoring) imposes additional compliance pressure and reputational risk per km.licensing.comoros-is-currently-on-the
- No specific legal definition or framework for DeFi, crypto custody, or smart contract-based activities — significant regulatory ambiguity per km.custody.none-specific-there-are-no and km.enforcement.developing-regulatory-landscape-comoros-is
Key Risks
- Regulatory ambiguity: No dedicated crypto/DeFi legislation means the applicability of existing financial services licensing to a DeFi frontend is untested and subject to interpretation per km.licensing.specific-crypto-law-vs-general and km.licensing.the-union-of-the-comoros
- FATF grey-list status creates increased scrutiny of all financial services licensed out of Comoros, potentially affecting correspondent banking relationships and international reputation per km.licensing.comoros-is-currently-on-the
- Enforcement risk is low-probability but high-context: regulator focus has historically been on public warnings rather than active enforcement against crypto operators per km.enforcement.focus-on-warnings-not-enforcement, but lack of specific frameworks means non-compliance could trigger broader financial services penalties
- Limited scale of crypto activity in Comoros means there is little regulatory precedent or guidance to rely on per km.enforcement.limited-scale-of-crypto-activity
- Fee-taking by the frontend (e.g., trading fees, swap fees) could push classification toward a payment processor or exchange licensing category (MSB license), increasing obligations per km.licensing.payment-processors-fiat-to-crypto-crypto-to-fiat-crypto-only and km.licensing.exchanges-spot-derivatives-would-typically
- No segregation or insurance requirements for client assets, creating operational and trust risks per km.custody.none-specific-for-digital-assets and km.custody.none-specific-there-are-no (insurance/bonding)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Anjouan Offshore Finance Authority (AOFA): This is the primary authority responsible for licensing offshore financial services, including what are often adapted for cryptocurrency businesses.
Specific Crypto Law vs. General Financial Services License:
The Union of the Comoros does not have a dedicated, comprehensive law specifically for virtual assets or cryptocurrencies akin to those in major financial hubs.
Instead, virtual asset businesses seeking to operate from Comoros (via Anjouan) typically apply for a general financial services license or a Money Service Business (MSB) license under the AOFA framework. These licenses are then interpreted and adapted to cover crypto-related activities.
Required Licenses for Specific Providers (via AOFA):
Exchanges (Spot, Derivatives): Would typically require an AOFA Financial Services License or MSB license. This allows for the facilitation of transactions, trading, and conversion of virtual assets.
Payment Processors (Fiat-to-Crypto, Crypto-to-Fiat, Crypto-only): An MSB license is the most common route for these entities, as they facilitate money transfers and currency exchange, which crypto payments are increasingly seen to represent.
Businesses must formally apply for a license.
They must meet specific criteria and undergo due diligence by the AOFA.
The capital requirement is typically modest compared to many other jurisdictions. For a general Financial Services or MSB license from AOFA, the minimum paid-up capital requirement can be around USD 10,000 to USD 50,000, though this can vary. It's often required to be deposited in a local bank account or an account approved by the AOFA.
Comoros is currently on the FATF (Financial Action Task Force) "grey list" (Jurisdictions under increased monitoring). This means it is actively working with the FATF to address strategic deficiencies in its AML/CFT regimes.
Registered Office: All licensed entities must have a registered office address in Anjouan.
Local Agent/Representative: It's common to require a local registered agent or representative who acts as a liaison with the AOFA.
Physical Presence/Staff: While a full physical office with local staff isn't always strictly mandated for the offshore structures, having an operational substance plan is increasingly important for reputational and compliance purposes.
Compliance Officer: Appointment of a qualified AML/CFT Compliance Officer.
Ordinance No. 19-001/PR of 26 July 2019 on the Fight Against Money Laundering and Terrorist Financing: This is the most recent foundational AML/CFT law in Comoros. It replaced previous legislation (like Law No. 11-002/AF of 29 March 2011) and aims to align the Comorian framework with international standards set by FATF.
Note: While this Ordinance may not explicitly name "virtual assets" or "cryptocurrency," the broad definitions of "financial activity," "financial institutions," and "designated non-financial businesses and professions (DNFBPs)" are generally interpreted to encompass activities related to virtual assets and VASPs, especially given FATF Recommendation 15.
Be subject to licensing or registration: Depending on the specific interpretation and future regulations, VASPs are expected to be licensed or registered by the relevant authorities (e.g., the Central Bank).
Implement AML/CFT requirements: VASPs must comply with all AML/CFT obligations applicable to financial institutions, including customer due diligence, record-keeping, and suspicious transaction reporting.
For natural persons: Obtain and verify the customer's identity using reliable, independent source documents, data, or information (e.g., full name, address, date and place of birth, nationality, unique identification number from an official document like a passport or national ID card).
For legal entities: Obtain and verify the identity of the legal entity (e.g., name, legal form, address, directors, beneficial owners, proof of incorporation). Understand the ownership and control structure.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons and arrangements.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conduct ongoing due diligence on the business relationship and scrutinize transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Apply EDD measures to higher-risk situations, which may include:
Transactions involving complex or unusually large amounts.
Transactions involving new technologies and products (e.g., certain virtual assets).
Source of Funds/Wealth: For high-risk clients or transactions, VASPs should take reasonable measures to establish the source of funds or source of wealth.
Obligation to Report: VASPs are obligated to report any transaction (or attempted transaction), regardless of the amount, where there are reasonable grounds to suspect that the funds are the proceeds of a crime or are related to terrorist financing.
Reporting Authority: All STRs must be submitted to the National Financial Information Processing Unit (Cellule Nationale de Traitement des Informations Financières - CNTIF), which is Comoros' Financial Intelligence Unit (FIU).
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that an STR has been filed or that an investigation is underway.
Customer Identification Data: All documents and information used for CDD, including verification records.
Account Files: Records related to customer accounts and business relationships.
Business Correspondence: Relevant correspondence with customers.
Transaction Records: Records of all transactions (date, type, amount, currency, parties involved, payment methods, digital wallet addresses, transaction hashes).
STRs and Internal Reports: Copies of all STRs filed and any internal reports related to suspicious activities.
Developing Regulatory Landscape: Comoros is a small, developing island nation. Its financial regulatory framework is still maturing, and specific legislation or dedicated enforcement mechanisms for complex digital assets like cryptocurrencies are likely not yet robust or fully established.
Focus on Warnings, Not Enforcement: Like many emerging economies, the primary approach of its financial regulator (the Central Bank of Comoros – Banque Centrale des Comores, BCC) regarding cryptocurrencies has typically been to issue general warnings to the public about the risks associated with volatile and unregulated assets, rather than to conduct formal enforcement actions against specific entities. Such warnings are often generic and do not name specific actors or impose penalties.
Limited Scale of Crypto Activity: It's also possible that the scale of cryptocurrency operations or significant violations within Comoros has not yet reached a level that would trigger major, publicly reported enforcement actions.
None Specific: There are no specific licensing requirements for cryptocurrency custodians in Comoros as there is no specific legal definition or framework for such entities. Entities operating in the crypto space would likely fall into an unregulated category or might be subject to existing general financial services laws if their activities could be broadly interpreted as such (though this is unlikely for pure crypto custody without specific legal amendments).
None Specific for Digital Assets: Since there are no specific custody laws, there are no explicit rules mandating the segregation of client digital assets from a custodian's proprietary assets. Traditional financial institutions under BCC oversight are subject to segregation rules for fiat currencies and securities, but these do not extend to digital assets without specific legislation.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi frontend operating from Comoros (Anjouan) would likely need to obtain an AOFA Financial Services or MSB license and comply with full AML/CFT obligations, but the framework is untested for DeFi, lacks specific crypto/DeFi legislation, and the jurisdiction carries FATF grey-list risk and significant regulatory ambiguity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?