← Regulations / Laos / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Laos

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Laos with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Obtain and verify customer identity (full name, date of birth, nationality, residential address, official ID) under the Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA); CDD for legal entities includes legal name, registered address, registration number, articles of association, details of directors/senior management
  • Identify and verify beneficial owners of customers (including legal entities and arrangements)
  • Understand purpose and intended nature of the business relationship
  • Conduct ongoing monitoring of transactions for consistency with customer risk profile
  • Apply risk-based approach: Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions
  • Collect and transmit originator and beneficiary information for virtual asset transfers ('Travel Rule' — FATF Rec. 16); though detailed local regulations for VASPs may be further developed
  • Report any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves ML/TF — submit promptly to the FIU
  • Prohibition on tipping-off customers about STR submissions
  • Maintain records: CDD documents, transaction records, STR copies for minimum 5 years after business relationship ends or transaction date
  • Supervisor: Financial Intelligence Unit (FIU) under the Bank of Lao PDR for AML/CFT; BOL for licensing/supervision under the sandbox

Key Restrictions

  • Must obtain a license under the government's digital asset sandbox program (Prime Minister's Order No. 001/PMO) — no general license regime exists for custodial wallet services
  • Licensing issued by a joint committee of Ministry of Technology and Communications, Ministry of Finance, and Bank of Laos
  • Only a limited number of companies are permitted under the sandbox pilot; this is not an open licensing regime
  • No specific custodial license category exists — custodial wallets are covered under the sandbox license by application
  • For the general public, engaging in crypto financial services is largely prohibited or highly discouraged (BOL warnings); only sandbox participants are exempt
  • No explicit legal requirements for segregation of client assets, insurance/bonding, cold storage, or proof-of-reserves — though these would likely be reviewed during sandbox licensing
  • No definition of 'qualified custodian' exists in Laotian law for digital assets

Key Risks

  • Regulatory ambiguity — the sandbox is experimental and no comprehensive custody-specific regulations exist; any subsequent formalization could materially alter requirements
  • FATF has identified deficiencies in Laos's VA/VASP framework (APG 3rd Enhanced Follow-Up Report 2022); Travel Rule and comprehensive AML/CFT coverage for VASPs not yet operational
  • Enforcement risk — BOL has repeatedly warned the public against crypto use and financial institutions against facilitating crypto services outside authorized channels
  • Only a small number of companies were approved for the pilot; scale-down or cooling of the sandbox program is possible
  • No specific custodial insurance or bonding requirements — operators bear security risk without regulatory-mandated protections
  • Tax and corporate structure uncertainty given limited clarity from Ministry of Finance on digital asset taxation

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

A General Prohibition with Exceptions: Initial stances were restrictive. However, a significant development was the Prime Minister's Order No. 001/PMO, which allowed for a controlled experiment.

custody 60% confidence

The "Sandbox" Approach: The government initiated a pilot program or "sandbox" allowing a limited number of companies to mine and trade cryptocurrencies under strict supervision. This means that any entity engaging in activities that would involve custody must be part of this approved sandbox.

custody 60% confidence

Prime Minister's Order No. 001/PMO concerning the management of cryptocurrencies and digital assets (2021): This Order effectively lifted a prior ban on crypto activities, allowing the Ministry of Technology and Communications, the Bank of Laos, and the Ministry of Finance to permit and manage the mining and trading of digital assets by selected companies within a controlled environment.

custody 60% confidence

No specific "custodial license" exists. Instead, entities wishing to provide any form of digital asset service that involves holding client funds (even if implicitly, like an exchange) must apply for and obtain a license to participate in the government's digital asset sandbox program.

custody 60% confidence

This licensing is issued by a joint committee involving the Ministry of Technology and Communications, the Ministry of Finance, and the Bank of Laos. The criteria for obtaining such a license are likely stringent and include demonstrating technical capability, financial soundness, and compliance with general AML/CFT principles.

custody 60% confidence

No specific rules are publicly mandated. While financial best practices and general Anti-Money Laundering/Combating the Financing of Terrorism (AML/CFT) principles would strongly suggest the segregation of client assets from the firm's operational assets, there are no explicit legal requirements for this specifically for digital asset custodians in Laos at present. Any requirements would be ad-hoc conditions imposed during the sandbox licensing process.

custody 60% confidence

No specific insurance or bonding requirements for digital asset custody are publicly mandated. General business insurance would be expected for any licensed entity, but crypto-specific insurance or bonding is not a known regulatory requirement.

custody 60% confidence

No specific cold storage mandates are publicly known. While the use of cold storage for the majority of digital assets is a standard industry best practice for security, it is not a specific regulatory requirement in Laos. Security protocols would likely be reviewed as part of the sandbox licensing application, but without prescriptive mandates.

custody 60% confidence

No definition of a "qualified custodian" exists in Laotian law in the context of digital assets. This concept is typically found in more mature financial markets with established securities laws (e.g., the SEC in the U.S.).

licensing 40% confidence

Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA, dated 17 November 2022): This is the foundational AML/CFT law in Laos, superseding previous versions. It establishes the general obligations for reporting entities, including financial institutions, and covers key aspects of AML/CFT compliance.

licensing 40% confidence

Instruction on the Management and Supervision of Virtual Assets (Instruction No. 001/BOL, dated 28 January 2022): Issued by the Bank of Lao PDR, this instruction is highly specific to the pilot program for virtual assets. It outlines the regulatory framework, licensing requirements, and ongoing obligations (including AML/KYC) for entities authorized to engage in virtual asset activities (mining, trading platforms, exchanges, etc.). It designates authorized VASPs as reporting entities for AML/CFT purposes.

licensing 40% confidence

Obtain and verify the identity of the customer (individual or legal entity) using reliable, independent source documents, data, or information. For individuals, this includes full name, date of birth, nationality, residential address, and official identification document details (e.g., passport, national ID card).

licensing 40% confidence

For legal entities, this includes legal name, registered address, registration number, articles of association, and details of directors/senior management.

licensing 40% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements.

licensing 40% confidence

Purpose and Nature of Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or transaction.

licensing 40% confidence

Ongoing Monitoring: Conduct ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

licensing 40% confidence

Risk-Based Approach: Apply a risk-based approach to CDD, meaning enhanced due diligence (EDD) must be applied to higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), customers from high-risk jurisdictions, complex or unusual transactions, or transactions involving high-value virtual assets). Simplified due diligence (SDD) may be applied in lower-risk situations.

licensing 40% confidence

"Travel Rule" (FATF Recommendation 16): While specific detailed local regulations on the "Travel Rule" for VASPs may be further developed, authorized VASPs are generally expected to collect and transmit required originator and beneficiary information for virtual asset transfers above a certain threshold, in line with FATF recommendations, especially when transacting with other VASPs.

licensing 40% confidence

Reporting Obligation: Any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves money laundering, financing of terrorism, or other illicit activities, must be reported.

licensing 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted.

licensing 40% confidence

Timeliness: Reports must be submitted to the FIU promptly, as soon as the suspicion is formed.

licensing 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process, including copies of identification documents, beneficial ownership information, and risk assessments.

licensing 40% confidence

Transaction Records: Records of all transactions, including the amount, currency (both fiat and virtual asset), date, type of transaction, and the parties involved (originator and beneficiary information).

licensing 40% confidence

STR Records: Copies of all suspicious transaction reports submitted to the FIU and any internal analysis leading to those reports.

licensing 40% confidence

Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.

licensing 40% confidence

Bank of Lao PDR (BOL): The BOL is the central bank and the primary financial regulator in Laos. It is responsible for issuing licenses/authorizations for VASPs under the pilot program, developing specific regulations (like Instruction No. 001/BOL), and conducting ongoing supervision and examinations to ensure compliance with AML/CFT and other prudential requirements.

licensing 40% confidence

Financial Intelligence Unit (FIU) of Laos: Operating under the Bank of Lao PDR, the FIU is the central agency for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies.

licensing 40% confidence

Regulatory Approach: Restrictive / Partial Ban (for the public) with Controlled Exceptions.

licensing 40% confidence

For the general public and most businesses, engaging in cryptocurrency trading, exchanges, or financial services is largely prohibited or highly discouraged due to the Bank of the Lao PDR's warnings and notices.

aml 40% confidence

No, not comprehensively. While Laos has a general AML/CFT law, its framework for VAs and VASPs is still considered insufficient by international standards. The FATF Travel Rule (which stems from FATF Recommendation 15 and its Interpretive Note) requires countries to regulate VASPs for AML/CFT purposes, including implementing obligations to collect and transmit originator and beneficiary information for virtual asset transfers. Laos has yet to establish this comprehensive regulatory regime.

aml 40% confidence

As the comprehensive regulatory framework for VASPs and the Travel Rule is not yet in place, there is no specific effective date for its implementation in Laos. The initial steps involve defining VAs and VASPs, bringing them under the regulatory scope, and then prescribing the specific Travel Rule obligations.

aml 40% confidence

Which VASPs are Covered:

aml 40% confidence

The APG 3rd Enhanced Follow-Up Report on Lao PDR (2022), for instance, highlights the ongoing deficiencies in addressing Virtual Assets and VASPs, noting that the country still needs to revise its legal and regulatory framework to ensure VAs and VASPs are adequately covered.

aml 40% confidence

Law on Anti-Money Laundering and Counter-Terrorism Financing (No. 55/NA, dated 26 December 2014, amended): This is Laos's primary AML/CFT legislation. While it provides the general framework, its scope regarding virtual assets and VASPs is currently not comprehensive enough to implement the Travel Rule.

enforcement 60% confidence

Issuing Official Warnings and Prohibitions: The BOL has repeatedly reminded the public and financial institutions that cryptocurrencies are not legal tender and pose significant risks.

enforcement 60% confidence

A Brief Experiment with Authorized Mining (and subsequent cooling): There was a period in late 2021 where the Lao government approved a pilot project for a few companies to mine and trade cryptocurrencies, primarily to generate revenue for the state. However, this was a government initiative, not an enforcement action, and the enthusiasm seems to have significantly cooled since.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators may serve residents only if admitted to the government's digital asset sandbox pilot program (PMO Order No. 001/PMO), which is a restricted, high-burden licensing path with no specific custody license category, no mandated segregation/insurance/proof-of-reserves rules, and AML obligations under Law No. 67/NA with supervision by BOL and FIU.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?