Custodial wallet / SaaS in Lesotho
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Lesotho without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- Customer identification & verification under MLPCA 2008 (name, address, DOB, nationality, national ID/passport for individuals; company info, directors, beneficial ownership for legal entities)
- Ongoing transaction monitoring to ensure consistency with customer knowledge and risk profile
- Source of funds/wealth information required, especially for large transactions or high-risk customers
- Enhanced Due Diligence (EDD) for PEPs, high-risk geographies (FATF-listed), complex/unusual transactions, and new technology/products
- Suspicious Transaction Reporting (STR) to the FIU Lesotho for any transaction reasonably suspected of involving proceeds of crime, ML, or TF — including virtual asset activity
- No tipping-off prohibition (customer must not be informed that an STR has been made)
- Record-keeping for minimum 5 years post-relationship/transaction: customer ID data, transaction records, business correspondence, and analysis of complex/unusual transactions
- Compliance with FATF Recommendation 15 on VASPs, as Lesotho is an ESAAMLG member committed to FATF standards
Key Restrictions
- No dedicated VASP or crypto custody licensing regime exists — the operator cannot obtain a crypto-specific license
- If the custodial wallet service involves fiat currency (holding fiat, fiat-crypto conversion, remittance in fiat), it may fall under the Financial Institutions Act 2012 or National Payment Systems Act 2018, requiring a traditional financial-services license with high capital requirements
- Central Bank of Lesotho (CBL) has issued public warnings advising against dealing in cryptocurrencies — this creates reputational and regulatory risk for any crypto operator
- Virtual assets are not explicitly designated as 'securities' under Lesotho's securities laws (though ICO tokens resembling collective investment schemes may be)
- No specific segregation, insurance, cold-storage, or proof-of-reserves rules exist for digital asset custodians — fiduciary duties under common law may apply but are ambiguous
Key Risks
- Regulatory vacuum: absence of a dedicated VASP/custody regime means uncertainty about what obligations apply, with risk that existing laws are applied retroactively or expansively
- CBL's publicly stated anti-crypto stance increases enforcement risk — the regulator may treat any crypto activity as de facto unlawful even absent specific prohibitions
- The FIU expects VASPs to comply with AML/CFT obligations even though VASPs are not explicitly designated as reporting institutions — creates a compliance gap
- No local enforcement precedent exists, so the practical consequences of non-compliance are untested and unpredictable
- Insurance and asset-protection gaps: no mandated insurance or segregation means operator bears full risk of loss, theft, or hack with no regulatory backstop
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific cryptocurrency custody license currently exists in Lesotho.
Any entity seeking to offer services that could be interpreted as "financial services" or holding client funds would generally fall under the purview of the Financial Institutions Act 2012 or the Central Bank of Lesotho Act 2000. However, these acts are designed for traditional financial institutions (banks, insurers, etc.) and do not explicitly cover or provide licensing categories for digital asset custodians.
There are no specific rules in Lesotho mandating the segregation of client digital assets from the custodian's own assets.
No specific insurance or bonding requirements for digital asset custodians currently exist in Lesotho.
There are no specific mandates for digital asset custodians regarding cold storage or other specific security measures.
There is no specific definition of a "qualified custodian" for digital assets in Lesotho.
Money Laundering and Proceeds of Crime Act 2008 (as amended): This act and its regulations establish the AML/CFT framework in Lesotho. Entities dealing with virtual assets might be considered "designated non-financial businesses and professions" (DNFBPs) or be brought under the scope of "financial institutions" through future amendments or interpretations, thereby imposing KYC/CDD, record-keeping, and suspicious transaction reporting (STR) obligations.
No Dedicated VASP Regime: Lesotho has not yet enacted specific legislation to define, license, or regulate virtual assets or virtual asset service providers. There is no specific registration or licensing regime for crypto businesses.
Cautious Stance: The Central Bank of Lesotho (CBL), which is the primary financial regulator, has previously issued public notices warning the public about the risks associated with investing in and transacting with cryptocurrencies. This indicates a cautious "wait-and-see" or risk-averse approach rather than active promotion or regulation.
Indirect Application of Existing Laws (AML/CFT): While there's no specific VASP law, any entity operating within Lesotho that handles funds or facilitates financial transactions (even if virtual) could potentially fall under the scope of existing Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) legislation.
Custody Providers: Similarly, there are no specific licenses for "virtual asset custody providers." If the custody provider also provides traditional financial services (e.g., managing fiat bank accounts, lending fiat against crypto), then existing financial services licenses might be required.
AML/KYC: This is the most critical area. Lesotho is a member of the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), which means it is committed to implementing the Financial Action Task Force (FATF) recommendations. FATF Recommendation 15 specifically applies to VASPs, requiring them to be regulated for AML/CFT purposes and supervised.
While VASPs are not explicitly designated as "reporting institutions" under Lesotho's current AML law, the FIU would expect any entity involved in financial flows to conduct customer due diligence (KYC), monitor transactions, and report suspicious activities to prevent money laundering and terrorist financing. Failing to do so could lead to investigations and penalties, especially if illicit activities are facilitated.
Money Laundering and Proceeds of Crime Act (MLPCA) 2008 (as amended): This is the foundational legislation that defines money laundering offenses, establishes reporting obligations, and sets out the framework for combating financial crime. VASPs are expected to comply with the obligations outlined in this Act, particularly if they are classified as financial institutions or DNFBPs under its scope.
Financial Intelligence Act 2011 (as amended): This Act establishes the Financial Intelligence Unit (FIU) of Lesotho, defines its powers, and details the requirements for reporting suspicious transactions.
Identification and Verification:
Ongoing Monitoring: Continuously monitoring the business relationship, including scrutiny of transactions undertaken throughout the course of the relationship, to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Source of Funds/Wealth: Given the inherent risks of virtual assets, VASPs are expected to obtain information on the source of funds or source of wealth, especially for large transactions or high-risk customers.
Enhanced Due Diligence (EDD): Required for high-risk situations, which typically include:
Report Suspicious Transactions: Report to the FIU any transaction (or attempted transaction) where they have reasonable grounds to suspect that it may involve the proceeds of criminal activity, or relates to money laundering or terrorist financing. This includes suspicious activities in virtual assets.
Duration: Records must typically be kept for a minimum period of five (5) years after the business relationship is terminated or after an occasional transaction is completed.
Stance on Crypto: The CBL has consistently issued public warnings regarding the risks associated with cryptocurrencies. These warnings emphasize the lack of regulation, price volatility, potential for fraud, money laundering, and consumer protection issues. They have advised the public against dealing with unregulated crypto service providers.
Stance on Crypto: The FIU would be involved in monitoring for illicit financial activities involving cryptocurrencies as part of its broader anti-money laundering and combating the financing of terrorism (AML/CFT) mandate.
Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG): Lesotho is a member, and their publications relate to regional AML/CFT efforts and FATF recommendations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet / SaaS provider can operate in Lesotho only in the regulatory vacuum (no dedicated VASP or custody license exists), but must comply with general AML/CFT obligations under the MLPCA 2008 and FIU oversight, faces significant regulatory risk from the Central Bank of Lesotho's anti-crypto stance, and must avoid fiat-related activities that would trigger traditional financial-services licensing.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?