Custodial wallet / SaaS in Marshall Islands
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Marshall Islands with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Custodial wallet / SaaS VASPs must obtain a VASP license from MIIFSA as a 'Custody Provider (Virtual Asset Custody Wallets)' — defined as safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of others (mh.licensing.custody-providers-virtual-asset-custody)
- Must implement risk-based AML/CTF program under the AML/CTF Act 2018, aligned with FATF standards (mh.licensing.this-is-a-cornerstone-requirement, mh.licensing.these-must-align-with-the)
- Mandatory Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) for higher-risk clients (mh.licensing.customer-due-diligence-cdd-and)
- Ongoing transaction monitoring (mh.licensing.ongoing-monitoring-of-transactions)
- Reporting of Suspicious Transaction Reports (STRs) to the Financial Intelligence Unit (FIU) (mh.licensing.reporting-of-suspicious-transactions-strs)
- Appointment of a qualified Compliance Officer and Money Laundering Reporting Officer (MLRO) (mh.licensing.appointment-of-a-qualified-compliance)
- All directors, senior management, shareholders, and beneficial owners must pass a 'fit and proper' assessment (mh.licensing.fit-and-proper-persons-all)
- Sanctions screening against UN Security Council Consolidated List, OFAC SDN List, and EU Consolidated List — mandatory under the AML/CTF Act 2018 (mh.aml.un-sanctions-compliance, mh.aml.ofac-sanctions-compliance, mh.aml.eu-sanctions-compliance, mh.aml.screen-against-the-following-lists)
- Asset freezing obligations for sanctioned individuals/entities and reporting to FIU (mh.aml.vasps-must-freeze-assets-of)
- AML obligations attach to the licensed VASP entity (the SaaS provider); the white-label client's AML duties depend on whether the client itself is a VASP or the arrangement is structured accordingly (mh.licensing.establish-a-licensing-regime-for)
Key Restrictions
- Applicant must be a properly incorporated legal entity in the Marshall Islands (e.g., IBC or similar) (mh.licensing.legal-entity-the-applicant-must)
- Must maintain adequate capital commensurate with nature, scale, and complexity of operations (mh.licensing.the-digital-assets-act-generally); specific minimum capital thresholds set by MIIFSA subsidiary regulations (mh.licensing.specific-minimum-capital-thresholds-are)
- Requires a registered office in the Marshall Islands and a registered agent authorized to act on behalf of the company (mh.licensing.a-registered-office-in-the, mh.licensing.a-registered-agent-who-is)
- May require local management or key personnel depending on scale and nature of activities (mh.licensing.potentially-a-requirement-for-local)
- Must implement robust cybersecurity frameworks, data protection, audit trails, disaster recovery, and business continuity plans (mh.licensing.technology-security-robust-cybersecurity-frameworks)
- No specific segregation, insurance, or proof-of-reserves rules are explicitly detailed in the provided facts — these may be addressed in pending MIIFSA subsidiary regulations
Key Risks
- Limited public enforcement record — regulatory bodies exist but have little visible track record of crypto-specific enforcement (mh.enforcement.limited-public-enforcement-record-the)
- Many crypto companies incorporate in the Marshall Islands but operate elsewhere, meaning primary oversight often lies with other jurisdictions (mh.enforcement.role-as-a-corporate-registry)
- OFAC sanctions compliance is a practical necessity for any entity transacting in USD or dealing with US persons — secondary sanctions risk is real (mh.aml.practical-necessity-any-vasp-transacting)
- Specific capital thresholds, segregation requirements, insurance, and proof-of-reserves rules are not clearly detailed in available facts — regulatory ambiguity around custodian-specific obligations
- The white-label client's AML responsibilities relative to the SaaS provider's obligations are not clearly delineated in the provided regulatory facts — structuring risk
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Define "digital assets" and "virtual asset service providers" (VASPs).
Impose Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) obligations on VASPs.
Empower the MIIFSA to regulate and supervise the virtual asset sector.
Custody Providers (Virtual Asset Custody Wallets): Safekeeping or administration of virtual assets or instruments enabling control over virtual assets on behalf of others.
Legal Entity: The applicant must be a properly incorporated legal entity in the Marshall Islands (e.g., an International Business Company or similar).
The Digital Assets Act generally requires VASPs to maintain adequate capital commensurate with the nature, scale, and complexity of their operations and the risks they undertake.
Specific minimum capital thresholds are typically set out in subsidiary regulations issued by the MIIFSA. These are designed to ensure financial stability and protect consumers. You would need to consult the latest MIIFSA guidance for exact figures.
This is a cornerstone requirement. VASPs must implement robust Anti-Money Laundering (AML) and Know Your Customer (KYC) policies and procedures.
These must align with the Marshall Islands Anti-Money Laundering and Counter-Financing of Terrorism Act and international FATF standards.
Customer due diligence (CDD) and enhanced CDD (EDD) for higher-risk clients.
Reporting of suspicious transactions (STRs) to the Financial Intelligence Unit (FIU).
Appointment of a qualified Compliance Officer and a Money Laundering Reporting Officer (MLRO).
A registered agent who is authorized to act on behalf of the company.
Potentially, a requirement for local management or key personnel, or at least clear lines of communication and control demonstrable to MIIFSA. The degree of local operational presence can depend on the scale and nature of the proposed activities.
Fit and Proper Persons: All directors, senior management, shareholders, and beneficial owners must undergo a "fit and proper" assessment. This includes background checks for criminal records, financial solvency, and professional competence.
Technology & Security: Robust cybersecurity frameworks, data protection measures, and secure operational procedures are essential to protect virtual assets and customer data. This includes audit trails, disaster recovery plans, and business continuity plans.
Anti-Money Laundering and Counter-Terrorism Financing Act 2018 (AML/CTF Act 2018): This Act forms the cornerstone of the RMI's regulatory regime. It mandates financial institutions, including VASPs, to implement robust AML/CTF programs, which explicitly cover sanctions compliance.
Financial Intelligence Unit Act 2006 (as amended): Establishes the RMI Financial Intelligence Unit (FIU), which is the primary body responsible for receiving, analyzing, and disseminating financial intelligence related to money laundering, terrorism financing, and other serious offenses, including sanctions violations.
UN Sanctions Compliance:
As a member state of the United Nations, the RMI is obligated to implement sanctions resolutions passed by the UN Security Council (UNSC).
The AML/CTF Act 2018 explicitly mandates compliance with UN sanctions. This means VASPs must screen against the UNSC Consolidated List, which includes individuals and entities designated under various UN sanctions regimes (e.g., related to terrorism, proliferation, specific countries like North Korea, Iran, etc.).
VASPs must freeze assets of sanctioned individuals/entities and report such findings to the FIU.
OFAC Sanctions Compliance:
Practical Necessity: Any VASP transacting in USD, dealing with US persons or entities, or having any nexus to the US financial system (e.g., through correspondent banking relationships, cloud providers, software vendors) must comply with OFAC sanctions to avoid secondary sanctions or blocking by US financial institutions.
EU Sanctions Compliance:
Screen against the following lists at a minimum:
UN Security Council Consolidated List: This list includes individuals and entities subject to asset freezes, travel bans, and arms embargoes imposed by the UN.
OFAC Specially Designated Nationals and Blocked Persons (SDN) List: This is the primary list for US sanctions. VASPs should also be aware of other OFAC lists (e.g., Sectoral Sanctions Identifications List, Foreign Sanctions Evaders List).
EU Consolidated List of persons, groups and entities subject to EU financial sanctions:
Limited Public Enforcement Record: The Marshall Islands is a smaller jurisdiction. While it has laws related to financial activities and anti-money laundering (AML) / combating the financing of terrorism (CFT), and has even explored innovative digital asset legislation (like the controversial Digital Assets Act of 2018 to create a sovereign digital currency, the SOV, which has largely stalled due to international pressure), its financial regulatory bodies do not have a robust public record of enforcement actions, particularly for complex and high-profile cryptocurrency cases, in the same way major financial hubs (like the US, UK, or EU) do.
Role as a Corporate Registry: Many cryptocurrency companies choose to incorporate in the Marshall Islands due to its flexible corporate registry (the Marshall Islands Trust Company Complex, or RMI-TCC). However, their primary operations and therefore primary regulatory oversight and enforcement actions often come from the jurisdictions where they primarily conduct business or where their customers are located, rather than from the RMI itself. For example, a company registered in RMI might face enforcement from the U.S. SEC or DOJ for activities impacting U.S. persons.
Office of the Banking Commissioner (OBC): Responsible for regulating financial institutions.
Financial Intelligence Unit (FIU): Deals with AML/CFT matters and suspicious transaction reports. They would investigate financial crimes, but their enforcement actions are typically less public than those of a securities regulator.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are licensed as VASP 'Custody Providers' under MIIFSA, requiring a local Marshall Islands entity, a VASP license, AML/CTF compliance (including UN, OFAC, and EU sanctions screening), adequate capital, and a registered office/agent, though specific custodian-focused rules (segregation, insurance, proof-of-reserves) are not detailed in available regulations.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?