Custodial wallet / SaaS in Morocco
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is not permitted in Morocco.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- No formal AML framework for VASPs exists — the 2017 prohibition means crypto transactions are illegal under current foreign exchange regulations (Law No. 43-05 on AML/CFT exists but has no crypto-specific implementing provisions)
- If and when a framework materializes, expected obligations would include: Customer Due Diligence (CDD)/KYC, ongoing transaction monitoring, and Suspicious Activity Reporting (SAR) to the Financial Intelligence Unit (UTRF)
- Globally, OFAC sanctions compliance would apply to any operator with U.S. nexus (screening against SDN list, geographic restrictions, blocking/freezing, reporting to OFAC)
- Globally, EU sanctions compliance would apply to any operator with EU nexus (screening against EU consolidated list, asset freezing, prohibition on making funds available to designated persons)
Key Restrictions
- Crypto transactions are effectively illegal under current foreign exchange regulations (Office des Changes 2017 warning — using virtual currencies violates foreign exchange law)
- No legal recognition — cryptocurrencies are not legal tender and have no recognized status under Moroccan law
- No licensing pathway exists yet — no VASP, exchange, or custody license framework has been enacted
- Any future framework is expected to require local incorporation, physical presence, management and staff in Morocco
- Bank Al-Maghrib is actively exploring regulation and a CBDC but no law has been passed
Key Risks
- Operating custodial wallet services for Moroccan residents currently exposes the operator to legal risk under the 2017 foreign exchange prohibition
- No regulatory clarity — BAM has signaled a shift toward regulation but no law exists, creating enforcement uncertainty
- Regulatory reversal risk — the historical prohibition could be enforced at any time despite BAM's exploratory stance
- Reputational risk of operating in a jurisdiction with an official ban on crypto use and trading
- IF/WHEN regulation arrives, it is expected to be conservative with high capital requirements, strict AML, and mandatory local incorporation
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Historical Prohibition: An official ban on the use and trading of cryptocurrencies.
Lack of Legal Tender Status: Cryptocurrencies are not recognized as legal tender.
Ongoing Exploration: The central bank (Bank Al-Maghrib) is actively studying the sector with the intent to develop a comprehensive regulatory framework, including potential central bank digital currency (CBDC) initiatives.
Reference: Communiqué n°01/2017 du 20 novembre 2017 de l'Office des Changes.
2017 Warnings: Bank Al-Maghrib (BAM - Morocco's central bank) and the Moroccan Exchange Office issued strong warnings against the use of cryptocurrencies.
The Moroccan Exchange Office (Office des Changes) explicitly declared that engaging in cryptocurrency transactions constitutes a violation of the current foreign exchange regulations, which stipulate that foreign exchange transactions must be conducted through authorized intermediaries and in currencies listed by BAM.
Result: This effectively made the use of cryptocurrencies for transactions or business operations illegal in Morocco under existing laws, with no legal pathway for VASP operations.
Intention to Regulate: Recognizing the global rise of cryptocurrencies and the need to address them, Bank Al-Maghrib has publicly announced its intention to introduce a regulatory framework for virtual assets.
Ongoing Work: BAM has been working in consultation with international bodies like the International Monetary Fund (IMF) and the World Bank to draft a comprehensive bill. This work has been ongoing since at least late 2022 and throughout 2023.
No Enacted Law Yet: Despite these efforts, the proposed law has not yet been finalized, approved by the government, or published in the Official Bulletin. Therefore, the historical warnings remain the de facto regulatory environment.
No Specific Licenses: Because there is no specific virtual asset regulatory framework in place, there are no specific licenses required or available for:
Custody Providers: No specific license exists for virtual asset custody services.
Local Presence: Foreign entities wishing to operate in Morocco would almost certainly be required to establish a local legal entity (e.g., a subsidiary) and have a physical presence, management, and staff in Morocco.
AML/KYC Obligations: This is virtually guaranteed. Morocco already has robust anti-money laundering and combating the financing of terrorism (AML/CFT) laws (e.g., Law No. 43-05 as amended). Any regulated VASP would be subject to strict AML/CFT obligations, including:
Capital Requirements: Significant minimum capital requirements would likely be imposed to ensure the financial stability and credibility of VASPs, appropriate to the services offered (exchange, custody, etc.).
Prohibition/Lack of Legal Framework: BAM views cryptocurrencies as operating outside of the legal and regulatory framework for financial transactions in Morocco, exposing users to significant risks. This means that operating a Virtual Asset Service Provider (VASP) or conducting significant crypto-related business within Morocco itself could be deemed illegal or at least highly unregulated and risky.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Not permitted — custodial wallet / SaaS services for Moroccan residents are currently illegal under the 2017 foreign exchange prohibition by Bank Al-Maghrib and the Office des Changes; no VASP or custody licensing framework exists, though BAM has signaled intent to introduce one with expected high capital requirements, local entity mandate, and strict AML obligations.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?