Custodial wallet / SaaS in Labuan (Malaysia)
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Labuan (Malaysia) with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD)/KYC under AMLA 2001 and LFSA AML/CFT Guidelines — risk-based approach, verify identity of natural persons (gov-issued ID, proof of address) and legal entities (legal form, directors, beneficial owners).
- Beneficial ownership identification and verification — must identify and take reasonable measures to verify the natural persons who ultimately own or control the customer.
- Enhanced Due Diligence (EDD) for higher-risk customers — PEPs, customers from high-risk jurisdictions (FATF-identified), complex or unusually large transactions.
- Ongoing transaction monitoring — regularly scrutinize transactions for consistency with customer risk profile; periodic review of CDD information.
- Suspicious Transaction Reporting (STRs) — report suspicious transactions to the Financial Intelligence Unit (FIU) of Bank Negara Malaysia.
- Record-keeping obligations under AMLA 2001 — maintain CDD records and transaction records per regulatory requirements.
- AML/CFT compliance must be embedded in the operational framework under Section 5.4 of the Guidelines on Digital Asset Business (LFSA/GL/2020-002).
- For the SaaS model: the licensed Labuan entity (custodian) bears primary AML/CFT obligations under AMLA 2001 and LFSA guidelines, including CDD on its white-label clients and oversight of end-user onboarding procedures.
Key Restrictions
- Must be incorporated as a Labuan company under the Labuan Companies Act 1990 (lb.custody.entity-type-must-be-incorporated).
- Must have substantive physical presence in Labuan (lb.custody.physical-presence-must-have-a).
- Must maintain adequate paid-up capital and working capital as determined by LFSA based on nature, scale, and complexity of the business (lb.custody.capital-requirements-maintain-adequate-paid-up); potentially RM 500,000–RM 1,000,000+ for complex operations (lb.licensing.for-full-fledged-digital-asset-exchanges).
- Client digital assets must be segregated from the entity's proprietary assets in designated segregated accounts/wallets, with no commingling (lb.custody.section-531-e-the-entity).
- Must implement cold storage for a significant portion of digital assets, plus secure private key management and multi-signature wallets (lb.custody.section-531-g-the-entity, lb.custody.this-explicitly-mandates-the-use).
- Directors, controllers, and key management must meet LFSA fit-and-proper criteria (lb.custody.fit-and-proper-criteria-directors).
- Must submit a comprehensive business plan covering services, target market, operational procedures, risk management, and technology infrastructure (lb.custody.business-plan-submission-of-a).
- Custody services fall under the broader Labuan Digital Asset Business license; there is no standalone 'custody license,' but providing custody is a regulated activity under the DA Guidance Note (lb.licensing.for-custody-providers, lb.licensing.the-da-guidance-note-explicitly).
Key Risks
- Regulatory ambiguity — the DA Guidance Note does not prescribe a fixed minimum capital; LFSA determines it case-by-case, creating uncertainty during licensing.
- Enforcement risk — OFAC and EU sanctions are not directly enforceable as Malaysian law but are practically mandatory for Labuan VASPs; non-compliance can disrupt correspondent banking and cross-border operations (lb.enforcement.legal-basis-while-ofac-us).
- The line between a regulated 'custody provider' and an unregulated software/SaaS provider may be unclear until LFSA confirms applicability; pre-application consultation is critical.
- White-label clients may themselves need licensing if they hold keys or exercise control over assets — responsibility allocation between SaaS provider and client must be carefully structured.
- Insurance for digital asset custody (e.g., cyber theft coverage) is implied by the risk management framework requirement but not explicitly mandated — this may create gaps in practice.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Labuan Financial Services and Securities Act 2010 (LFSSA 2010)
Guidelines on Digital Asset Business (LFSA/GL/2020-002, last updated January 2023)
Entity Type: Must be incorporated or registered as a Labuan company under the Labuan Companies Act 1990.
Physical Presence: Must have a substantive presence in Labuan.
Capital Requirements: Maintain adequate paid-up capital and working capital, as determined by LFSA based on the nature, scale, and complexity of the business (Section 4.1.3 & 5.1).
Fit and Proper Criteria: Directors, controllers, and key management personnel must meet LFSA's "fit and proper" criteria (Section 4.1.5 & 4.1.6).
Business Plan: Submission of a comprehensive business plan detailing services offered, target market, operational procedures, risk management framework, and technology infrastructure.
Internal Controls & Risk Management: Robust internal control systems, governance framework, and risk management policies, particularly addressing cybersecurity, operational risks, and market risks (Section 5.3).
AML/CFT Compliance: Strict adherence to anti-money laundering and countering financing of terrorism (AML/CFT) requirements in line with the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and LFSA's relevant guidance (Section 5.4).
Technology & Security: Demonstrate robust IT systems, security protocols, and expertise in distributed ledger technology (DLT) and cybersecurity (Section 5.3).
Section 5.3.1 (e): "The entity shall establish robust internal controls and safeguards to segregate and protect clients' assets from its own assets. Client funds and digital assets must be held in designated segregated accounts or wallets and must not be commingled with the company's proprietary assets."
Section 5.3.1 (c): Requires the entity to "establish an adequate capital management framework to ensure sufficient capital is maintained to absorb potential losses arising from its business activities."
Section 5.3.1 (e): Implies the need for safeguards to protect client assets, which can include various risk mitigation strategies, potentially including insurance coverage for certain risks (e.g., cyber theft) as part of a comprehensive risk management framework.
Section 5.3.1 (g): "The entity shall implement appropriate and comprehensive cybersecurity measures and controls to safeguard clients' digital assets from theft, loss, and unauthorised access, which include, but are not limited to, the use of secure private key management, multi-signature wallets, and cold storage for a significant portion of digital assets."
This explicitly mandates the use of cold storage (offline storage) for a significant portion of digital assets, alongside other security measures like multi-signature wallets and robust private key management.
Labuan Financial Services and Securities Act 2010 (LFSSA 2010)
Guidance Note on the Offering and Trading of Digital Assets in Labuan IBFC (the DA Guidance Note): This is the most crucial document, specifically outlining the regulatory requirements for digital asset businesses. It was initially issued in 2019 and may undergo updates.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001): The national AML/CFT law applicable to Labuan entities.
For Custody Providers:
The DA Guidance Note explicitly covers aspects related to the custody of digital assets, requiring robust security, operational resilience, and client asset segregation. While there isn't a separate, specific "custody license" distinct from the "Digital Asset Business" umbrella, providing custody is a regulated activity within that framework.
For full-fledged digital asset exchanges or complex operations, LFSA will expect significantly higher capital, potentially in the range of RM 500,000 to RM 1,000,000 or more, depending on the business model and risk assessment.
Strict compliance with AMLA 2001 and LFSA's AML/CFT guidelines.
Implementation of comprehensive Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures.
Robust transaction monitoring systems.
Reporting of suspicious transactions (STRs) to the Financial Intelligence Unit (FIU) of Bank Negara Malaysia.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001): This is the cornerstone legislation. It imposes obligations on reporting institutions (which include VASPs) to detect, deter, and report suspicious transactions, and to implement robust AML/CFT measures, including sanctions screening.
Customer Due Diligence (CDD) / Know Your Customer (KYC)
Risk-Based Approach: VASPs must adopt a risk-based approach to CDD, meaning the intensity of verification should be commensurate with the assessed money laundering/terrorism financing risk of the customer, product, service, or transaction.
Identification and Verification:
Natural Persons: Obtain and verify identity through reliable, independent sources (e.g., government-issued ID, proof of address, date of birth, nationality).
Legal Entities: Obtain and verify legal name, legal form, proof of existence, powers that bind the entity, names of relevant persons (directors, senior management), and crucially, the beneficial owners.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted. This is particularly critical for VASPs dealing with potentially opaque structures.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Regularly scrutinize transactions undertaken throughout the course of the relationship to ensure consistency with the VASP’s knowledge of the customer, their business, and risk profile. This includes reviewing CDD information periodically.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers and transactions, including:
Politically Exposed Persons (PEPs)
Customers from high-risk jurisdictions (as identified by FATF or Labuan FSA)
Legal Basis: While OFAC (U.S.) and EU sanctions are not directly enforceable as Malaysian law, compliance is critical and practically mandatory for Labuan VASPs due to several factors:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers must be incorporated as a Labuan company with substantive physical presence in Labuan, obtain a Labuan Digital Asset Business license under the DA Guidance Note and LFSSA 2010, maintain segregated client assets with cold storage and robust cybersecurity, meet LFSA-determined capital requirements, and comply with full AMLA 2001 AML/CFT obligations including CDD, EDD, ongoing monitoring, and STR reporting to BNM's FIU.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?