← Regulations / Kazakhstan / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Kazakhstan

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Kazakhstan with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Must adhere to AIFC AML Rules (aligned with FATF recommendations) — mandatory for all regulated firms (kz.custody.aifc-anti-money-laundering-and-counter-terrorist, kz.licensing.adherence-to-aifc-aml-rules).
  • Must comply with Kazakhstan national AML/CFT Law (No. 191-IV dated Aug 28, 2009) administered by the Financial Monitoring Agency (FMA) (kz.aml.law-of-the-republic-of, kz.aml.financial-monitoring-agency-fma-the).
  • Must comply with the AIFC Digital Asset Business Rules (DABR) AML provisions (kz.custody.aifc-digital-asset-business-rules).
  • Must screen customers and transactions against UN Security Council Consolidated List (kz.aml.compliance-vasps-must-screen-customers).
  • Must screen against OFAC SDN List if dealing with U.S. persons, USD transactions, or using U.S. technology/services (kz.aml.compliance-vasps-must-screen-against).
  • Must screen against EU Consolidated Financial Sanctions List if serving EU persons or using EU financial infrastructure (kz.aml.compliance-vasps-must-screen-against).
  • Must maintain robust AML/KYC policies and procedures as part of license application (kz.custody.robust-anti-money-laundering-aml-and).
  • SaaS provider must implement AML controls on behalf of or in coordination with white-label clients; the regulated entity (license holder) bears ultimate statutory AML responsibility.

Key Restrictions

  • Must be incorporated or established as a legal entity within the AIFC and maintain a physical office presence there (kz.licensing.must-be-incorporated-or-established, kz.licensing.maintain-a-physical-office-presence).
  • Key personnel (CEO, Compliance Officer) must be primarily based in the AIFC (kz.licensing.have-key-personnel-eg-ceo).
  • Must hold a 'Providing Custodian (Digital Assets)' license under the AIFC Digital Asset Business Rules (kz.licensing.license-type-providing-custodian-digital, kz.custody.license-type-firms-typically-seek).
  • Minimum capital requirement: typically USD 300,000 (or KZT equivalent) for custodians (kz.licensing.custodian-digital-assets-typically-usd).
  • Client digital assets must be segregated from the firm's proprietary assets and held in trust/safekeeping arrangements (kz.custody.mandatory-segregation-licensed-custodians-are, kz.custody.trust-accountssafeguarding-assets-must-be).
  • Private keys must be managed under detailed policies including cold storage for significant portions of assets (kz.custody.private-key-management-detailed-policies).
  • Robust cybersecurity frameworks, multi-factor authentication, encryption, and secure network protocols required (kz.custody.robust-cybersecurity-firms-must-implement).
  • SaaS/white-label arrangement: the licensed custodian remains the regulated entity; white-label clients cannot be unregulated intermediaries dealing with AIFC residents without their own licensing.

Key Risks

  • Significant enforcement precedent against unregistered crypto operators — over 50 illegal mining farms shut down, websites blocked, criminal investigations launched (kz.enforcement.afm-kazakhstan-clamps-down-on, kz.enforcement.entity-targeted-numerous-unregistered-cryptocurrency, kz.enforcement.entity-targeted-operators-and-websites).
  • Strict enforcement against unregistered crypto exchanges and P2P platforms, with website blocking and criminal cases (kz.enforcement.kazinform-financial-monitoring-agency-blocks).
  • Crypto-related pyramid scheme and fraud enforcement actions signal high consumer-protection scrutiny (kz.enforcement.entity-targeted-individuals-and-organized, kz.enforcement.afm-financial-monitoring-agency-prevented).
  • Regulatory ambiguity on how SaaS/white-label responsibilities split between custodian and client — AFSA may treat the white-label client as carrying on regulated activity by extension.
  • Tax and transfer-pricing exposure for cross-border SaaS fee arrangements between AIFC entity and foreign affiliates.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 95% confidence

License Type: Firms typically seek a license for "Providing Digital Asset Custody Services" under the AIFC Digital Asset Business Rules. This falls under the broader category of "Digital Asset Business."

custody 100% confidence

AIFC Digital Asset Business Rules (DABR): Contains specific requirements for firms involved in digital asset activities.

custody 100% confidence

AIFC Conduct of Business Rules (COB): General rules for how firms must conduct business with clients.

custody 100% confidence

AIFC Prudential Rules (PRU): Rules related to capital, risk management, and financial soundness.

custody 100% confidence

AIFC Anti-Money Laundering and Counter-Terrorist Financing Rules (AML): Mandatory for all regulated firms.

custody 95% confidence

Mandatory Segregation: Licensed custodians are required to segregate client digital assets from their own proprietary assets. These assets must be clearly identifiable as client assets.

custody 90% confidence

Trust Accounts/Safeguarding: Assets must be held in a manner that protects clients' interests, typically implying a trust or fiduciary arrangement where client assets are not subject to the custodian's creditors in case of insolvency.

custody 95% confidence

Private Key Management: Detailed policies and procedures for the generation, storage, backup, and recovery of private keys are mandatory. This strongly implies the use of offline (cold) storage for a significant portion of client assets, especially those not actively traded.

custody 95% confidence

Robust Cybersecurity: Firms must implement and maintain robust cybersecurity frameworks to protect client digital assets from theft, loss, or unauthorized access. This includes multi-factor authentication, encryption, and secure network protocols.

custody 95% confidence

Capital Requirements: Licensed firms must meet specific minimum capital requirements (financial resources) based on the nature and scale of their business, as detailed in the Prudential Rules. This serves as a buffer against operational losses.

custody 95% confidence

Regulatory Reference: AIFC Digital Asset Business Rules 2020 (DABR), specifically Part 3 (General Requirements for Digital Asset Business) and other relevant sections detailing specific activities.

licensing 60% confidence

AIFC Financial Services Authority (AFSA): The independent regulator of the AIFC, responsible for licensing, supervision, and enforcement of financial services, including virtual asset activities.

licensing 60% confidence

License Type: Providing Custodian (Digital Assets) services.

licensing 60% confidence

Must be incorporated or established as a legal entity within the AIFC.

licensing 60% confidence

Maintain a physical office presence in the AIFC.

licensing 60% confidence

Have key personnel (e.g., CEO, Compliance Officer) primarily based in the AIFC.

licensing 60% confidence

Custodian (Digital Assets): Typically USD 300,000 (or KZT equivalent).

licensing 60% confidence

Adherence to AIFC AML Rules, which are aligned with FATF (Financial Action Task Force) recommendations.

aml 60% confidence

Law of the Republic of Kazakhstan "On Counteracting Legalization (Laundering) of Criminal Proceeds and Financing of Terrorism" (No. 191-IV dated August 28, 2009, as amended): This is the primary AML/CFT law. It designates the Financial Monitoring Agency (FMA) as the competent authority and outlines the obligations of "financial organizations" and other reporting entities (which, under FATF standards, includes VASPs). It requires reporting entities to identify customers, monitor transactions, and report suspicious activities, including those related to terrorism financing and proliferation, which often involves sanctions screening.

aml 60% confidence

Financial Monitoring Agency (FMA): The FMA is Kazakhstan's Financial Intelligence Unit (FIU) and the primary body responsible for enforcing AML/CFT laws, including monitoring compliance with international sanctions.

aml 60% confidence

Compliance: VASPs must screen customers and transactions against the UN Security Council Consolidated List (individuals and entities associated with terrorism and proliferation of weapons of mass destruction, and other sanction programs).

aml 60% confidence

Compliance: VASPs must screen against OFAC's Specially Designated Nationals And Blocked Persons List (SDN List) and other relevant sanctions lists specific to programs (e.g., Russia/Ukraine, Iran, North Korea).

enforcement 60% confidence

AFM: Kazakhstan clamps down on illegal crypto mining farms (This link provides context on various AFM actions, including illegal crypto-related activities.)

enforcement 60% confidence

Entity Targeted: Numerous unregistered cryptocurrency mining farms operated by various individuals and organizations across the country. Violation Type: Unlicensed business activity, illegal electricity consumption, tax evasion, sometimes money laundering, and operating outside the legal framework for crypto mining. Outcome: Shut down of operations, seizure of equipment (hundreds of thousands of mining devices), criminal charges against operators, and significant administrative fines. While individual penalty amounts for each entity are not publicly disclosed, the total economic impact and asset seizures were substantial. For instance, in 2022 alone, the AFM reported stopping 51 illegal mining farms and confiscating equipment worth billions of tenge.

enforcement 60% confidence

Entity Targeted: Operators and websites of unregistered cryptocurrency exchanges and peer-to-peer trading platforms. Violation Type: Unlicensed financial activity, facilitation of illegal financial operations (e.g., fraud, money laundering), violation of financial regulations. Penalty Amount: Not specified as a direct fine in publicly available reports. Outcome: Blocking of website access, criminal charges against individuals involved, seizure of funds (if traceable).

enforcement 60% confidence

Kazinform: Financial Monitoring Agency blocks 138 websites for illegal online casinos, cryptocurrencies (This article from Jan 2024 highlights ongoing efforts against illegal online platforms, including those related to cryptocurrencies, demonstrating continuous enforcement.)

enforcement 60% confidence

Entity Targeted: Individuals and organized groups operating pyramid schemes and financial frauds that solicited investments in cryptocurrencies. Violation Type: Financial fraud, creation and promotion of financial pyramids, illegal attraction of funds, money laundering. Penalty Amount: Not specified as a single fine, but involves restitution to victims, asset forfeiture, and criminal sentences (imprisonment).

enforcement 60% confidence

AFM: Financial Monitoring Agency prevented a financial pyramid scheme using crypto currency (This example from Nov 2022 details a specific case of a pyramid scheme involving cryptocurrency.)

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers may operate in Kazakhstan only through an AIFC-licensed entity holding a "Providing Custodian (Digital Assets)" license, with a local office, minimum USD 300,000 capital, mandatory client asset segregation, and full AML/CTF obligations under both AIFC rules and national law; white-label clients' AML responsibilities are not fully defined.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?