DeFi protocol frontend in Marshall Islands
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Marshall Islands with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full CDD/EDD on all users (mh.licensing.customer-due-diligence-cdd-and)
- Ongoing transaction monitoring (mh.licensing.ongoing-monitoring-of-transactions)
- Reporting suspicious transactions (STRs) to the FIU (mh.licensing.reporting-of-suspicious-transactions-strs)
- Appointment of a qualified Compliance Officer and MLRO (mh.licensing.appointment-of-a-qualified-compliance)
- Sanctions screening against UN Consolidated List, OFAC SDN List, and EU Consolidated List at minimum (mh.aml.screen-against-the-following-lists, mh.aml.un-security-council-consolidated-list, mh.aml.ofac-specially-designated-nationals-and, mh.aml.eu-consolidated-list-of-persons)
- Freeze and report assets of sanctioned individuals/entities (mh.aml.vasps-must-freeze-assets-of)
- Risk-based sanctions screening program at onboarding and ongoing (mh.aml.develop-and-implement-a-risk-based)
- Maintain robust cybersecurity frameworks, data protection, audit trails, disaster recovery (mh.licensing.technology-security-robust-cybersecurity-frameworks)
Key Restrictions
- Must be a properly incorporated legal entity in the Marshall Islands (e.g., IBC or similar) (mh.licensing.legal-entity-the-applicant-must)
- Must hold a VASP license from MIIFSA — a DeFi frontend facilitating transfers, exchanges, or asset issuance falls under the VASP definition (mh.licensing.establish-a-licensing-regime-for, mh.licensing.exchanges-virtual-asset-trading-platforms, mh.licensing.transferring-virtual-assets, mh.licensing.participation-in-and-provision-of)
- Must maintain adequate capital commensurate with operations; specific minimum capital thresholds set by MIIFSA regulations (mh.licensing.the-digital-assets-act-generally, mh.licensing.specific-minimum-capital-thresholds-are)
- Directors, senior management, shareholders must pass fit-and-proper assessment (mh.licensing.fit-and-proper-persons-all)
- Requires a registered office and registered agent in the Marshall Islands, and potentially local management/key personnel (mh.licensing.a-registered-office-in-the, mh.licensing.a-registered-agent-who-is, mh.licensing.potentially-a-requirement-for-local)
- Fee-taking (e.g., trading fees, swap fees) would constitute VASP activity (exchanging/transferring for value) and clearly triggers licensing (mh.licensing.payment-processors-virtual-asset-transfers)
Key Risks
- Limited public enforcement record — uncertain how MIIFSA would treat a DeFi frontend specifically (mh.enforcement.limited-public-enforcement-record-the)
- Practical oversight often occurs where primary operations are located, not in MH (mh.enforcement.role-as-a-corporate-registry)
- OFAC secondary sanctions risk if frontend serves US persons or processes USD (mh.aml.practical-necessity-any-vasp-transacting)
- Regulatory ambiguity around whether a fully permissionless/immutable frontend without custody or fee-taking would be a VASP — MH law defines VASP broadly and likely captures the activity (mh.licensing.define-digital-assets-and-virtual, mh.licensing.transferring-virtual-assets)
- Heavy licensing burden for what is often a lightweight web frontend — capital adequacy, local entity, fit-and-proper requirements are disproportionate for a non-custodial UI
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Define "digital assets" and "virtual asset service providers" (VASPs).
Impose Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) obligations on VASPs.
Empower the MIIFSA to regulate and supervise the virtual asset sector.
Exchanges (Virtual Asset Trading Platforms): Providing services for the exchange between virtual assets and fiat currencies, or between one or more forms of virtual assets.
Participation in and provision of financial services related to an issuer's offer or sale of a virtual asset.
Payment Processors (Virtual Asset Transfers): Performing services that involve the transfer of virtual assets, whether for value, or facilitating the transfer for others. This covers activities such as:
Legal Entity: The applicant must be a properly incorporated legal entity in the Marshall Islands (e.g., an International Business Company or similar).
The Digital Assets Act generally requires VASPs to maintain adequate capital commensurate with the nature, scale, and complexity of their operations and the risks they undertake.
Specific minimum capital thresholds are typically set out in subsidiary regulations issued by the MIIFSA. These are designed to ensure financial stability and protect consumers. You would need to consult the latest MIIFSA guidance for exact figures.
This is a cornerstone requirement. VASPs must implement robust Anti-Money Laundering (AML) and Know Your Customer (KYC) policies and procedures.
Customer due diligence (CDD) and enhanced CDD (EDD) for higher-risk clients.
Reporting of suspicious transactions (STRs) to the Financial Intelligence Unit (FIU).
Appointment of a qualified Compliance Officer and a Money Laundering Reporting Officer (MLRO).
A registered agent who is authorized to act on behalf of the company.
Potentially, a requirement for local management or key personnel, or at least clear lines of communication and control demonstrable to MIIFSA. The degree of local operational presence can depend on the scale and nature of the proposed activities.
Fit and Proper Persons: All directors, senior management, shareholders, and beneficial owners must undergo a "fit and proper" assessment. This includes background checks for criminal records, financial solvency, and professional competence.
Technology & Security: Robust cybersecurity frameworks, data protection measures, and secure operational procedures are essential to protect virtual assets and customer data. This includes audit trails, disaster recovery plans, and business continuity plans.
Anti-Money Laundering and Counter-Terrorism Financing Act 2018 (AML/CTF Act 2018): This Act forms the cornerstone of the RMI's regulatory regime. It mandates financial institutions, including VASPs, to implement robust AML/CTF programs, which explicitly cover sanctions compliance.
UN Sanctions Compliance:
As a member state of the United Nations, the RMI is obligated to implement sanctions resolutions passed by the UN Security Council (UNSC).
The AML/CTF Act 2018 explicitly mandates compliance with UN sanctions. This means VASPs must screen against the UNSC Consolidated List, which includes individuals and entities designated under various UN sanctions regimes (e.g., related to terrorism, proliferation, specific countries like North Korea, Iran, etc.).
VASPs must freeze assets of sanctioned individuals/entities and report such findings to the FIU.
OFAC Sanctions Compliance:
Practical Necessity: Any VASP transacting in USD, dealing with US persons or entities, or having any nexus to the US financial system (e.g., through correspondent banking relationships, cloud providers, software vendors) must comply with OFAC sanctions to avoid secondary sanctions or blocking by US financial institutions.
EU Sanctions Compliance:
Develop and implement a risk-based sanctions screening program. This involves screening all customers (at onboarding and ongoing), beneficial owners, and transactions against relevant sanctions lists.
Screen against the following lists at a minimum:
UN Security Council Consolidated List: This list includes individuals and entities subject to asset freezes, travel bans, and arms embargoes imposed by the UN.
OFAC Specially Designated Nationals and Blocked Persons (SDN) List: This is the primary list for US sanctions. VASPs should also be aware of other OFAC lists (e.g., Sectoral Sanctions Identifications List, Foreign Sanctions Evaders List).
EU Consolidated List of persons, groups and entities subject to EU financial sanctions:
Limited Public Enforcement Record: The Marshall Islands is a smaller jurisdiction. While it has laws related to financial activities and anti-money laundering (AML) / combating the financing of terrorism (CFT), and has even explored innovative digital asset legislation (like the controversial Digital Assets Act of 2018 to create a sovereign digital currency, the SOV, which has largely stalled due to international pressure), its financial regulatory bodies do not have a robust public record of enforcement actions, particularly for complex and high-profile cryptocurrency cases, in the same way major financial hubs (like the US, UK, or EU) do.
Role as a Corporate Registry: Many cryptocurrency companies choose to incorporate in the Marshall Islands due to its flexible corporate registry (the Marshall Islands Trust Company Complex, or RMI-TCC). However, their primary operations and therefore primary regulatory oversight and enforcement actions often come from the jurisdictions where they primarily conduct business or where their customers are located, rather than from the RMI itself. For example, a company registered in RMI might face enforcement from the U.S. SEC or DOJ for activities impacting U.S. persons.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operated from or serving the Marshall Islands would likely constitute a VASP under the Digital Assets Act (covering exchanges, transfers, and participation in financial services related to virtual assets) and requires a MIIFSA-issued VASP license, local incorporation, fit-and-proper assessments, capital adequacy, and full AML/CTF/KYC obligations; however, enforcement precedent is thin and it is unclear how MIIFSA would treat a non-custodial, permissionless frontend in practice.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?