← Regulations / Mali / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Mali

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Not permitted AI-Generated · Unreviewed

Custodial SaaS is not permitted in Mali.

Verdict Details

Permitted
no
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer identification and verification (name, address, ID numbers for natural persons; legal name, incorporation docs, beneficial ownership for legal entities) — per Malian AML Law N°2018-024 and UEMOA Directive No. 02/2015/CM/UEMOA
  • Beneficial ownership identification required for all legal-person customers
  • Ongoing monitoring of transactions throughout the business relationship
  • Risk-based approach: Enhanced Due Diligence for PEPs, high-risk jurisdictions, and unusual transactions; Simplified Due Diligence allowed for low-risk scenarios
  • Suspicious Transaction Reporting (STR) obligation to CENTIF (Mali's FIU) — any transaction the entity suspects relates to ML/TF, regardless of amount
  • No tipping-off prohibition
  • Record retention: at least 5 years after relationship ends or transaction date (CDD records, transaction data, correspondence)
  • AML/CFT obligations would theoretically fall on both the SaaS custodian (as the regulated entity holding keys) and the white-label client (as the entity with the customer relationship); however, no crypto-specific AML guidance exists

Key Restrictions

  • BCEAO Circular N°0000000001/M/DG/2021 (Dec 2021) explicitly prohibits financial institutions supervised by the BCEAO from engaging in any activities related to virtual assets — this effectively bans formal custodial wallet/SaaS operations from interacting with the regulated banking system
  • Cryptocurrencies are not recognized as legal tender in the UEMOA zone and are not subject to supervision by the BCEAO or any national financial authority
  • No specific custodial license, qualified-custodian framework, segregation rules, insurance requirements, or cold-storage mandates exist — meaning the activity operates in a complete legal vacuum
  • No VASP registration or licensing regime exists in Mali; entities operating in this space do so outside any recognized regulatory framework

Key Risks

  • Enforcement risk is high — BCEAO has repeatedly warned against crypto (2018, 2021, 2022, 2023) and financial institutions face a de facto ban; unregulated operators risk being treated as operating illegally
  • Criminal enforcement precedent exists — arrests and investigations for crypto-related fraud/scams have occurred (reported May 2023, late 2022/early 2023), and unlicensed custodial services may be conflated with illegal financial operations
  • No legal recognition of digital assets means no property-law protection for custodial client assets; no segregation rules leaves clients unsecured in case of insolvency
  • Inability to integrate with the formal banking sector (banks prohibited from servicing crypto businesses) creates severe operational friction for fiat on/off ramps
  • Regulatory ambiguity — absence of a framework means no clear path to compliance, making any operation vulnerable to sudden enforcement action or policy change
  • Reputational risk from association with the pervasive crypto scam environment in the region

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 40% confidence

General Regulatory Stance:

custody 40% confidence

The BCEAO issued a press release on May 19, 2021, warning the public about the risks associated with cryptocurrencies. It reiterated that cryptocurrencies are not recognized as legal tender in the UEMOA zone and are not subject to the supervision of the BCEAO or national financial authorities. The bank strongly discouraged financial institutions from engaging in activities related to cryptocurrencies.

custody 40% confidence

This implies that any entity offering crypto custody services would be operating in an unregulated space, potentially contravening the spirit of the BCEAO's warnings.

custody 40% confidence

Custodial License Requirements:

custody 40% confidence

There are no specific custodial license requirements for digital asset service providers in Mali, as there is no established regulatory framework for cryptocurrencies. Given the BCEAO's warnings, attempting to operate such a licensed service would likely face significant challenges or be deemed unauthorized.

custody 40% confidence

Segregation of Client Assets Rules:

custody 40% confidence

No specific rules exist for the segregation of client assets for cryptocurrency custodians. This is due to the absence of a dedicated regulatory framework for crypto custody.

custody 40% confidence

No specific insurance or bonding requirements are mandated for digital asset custodians.

custody 40% confidence

Cold Storage Mandates:

custody 40% confidence

No specific cold storage mandates or any other operational security requirements are legally defined for cryptocurrency custody in Mali.

custody 40% confidence

Qualified Custodian Definitions:

custody 40% confidence

No legal definition of a "qualified custodian" exists within the Malian or UEMOA financial regulatory framework concerning digital assets.

custody 40% confidence

Pending Custody Legislation:

custody 40% confidence

There is no publicly available information indicating any specific pending legislation in Mali or at the UEMOA regional level directly addressing digital asset custody. The focus remains largely on cautioning against and monitoring cryptocurrencies, rather than integrating them into a regulated financial system. Discussions within the UEMOA might involve the possibility of a Central Bank Digital Currency (eCFA), but this is distinct from regulating private cryptocurrency custody services.

licensing 60% confidence

December 2021: The BCEAO issued a directive (Circular N°0000000001/M/DG/2021) explicitly prohibiting financial institutions under its purview from engaging in any activities related to virtual assets.

licensing 60% confidence

None specifically for crypto. Since there is no dedicated crypto regulatory framework, there are no specific licenses for these activities.

licensing 60% confidence

Neither a registration nor a specific licensing regime currently exists for VASPs in Mali.

licensing 60% confidence

Entities operating in this space are doing so outside of a recognized regulatory framework. This is not a "light touch" approach; rather, it indicates a lack of formal permission or supervision, which can be interpreted as implicitly disallowed for formal financial sector participation.

licensing 60% confidence

They are not recognized as legal tender within the UEMOA zone.

licensing 60% confidence

They are not regulated or supervised by the BCEAO or any national financial authority in the region.

licensing 60% confidence

Financial institutions supervised by the BCEAO (banks, microfinance institutions) are generally prohibited or strongly discouraged from engaging in activities related to virtual assets due to the associated risks (money laundering, terrorist financing, consumer protection, financial stability).

aml 40% confidence

Law N°2018-024 of August 21, 2018, amending Ordinance N°2015-032/P-RM of June 19, 2015, relating to the fight against money laundering and terrorist financing.

aml 40% confidence

UEMOA Directive No. 02/2015/CM/UEMOA

aml 40% confidence

Customer Identification and Verification:

aml 40% confidence

Beneficial Ownership Identification: Identifying and verifying the natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.

aml 40% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of that relationship to ensure consistency with the institution’s knowledge of the customer, their business, and risk profile.

aml 40% confidence

Risk-Based Approach: Applying enhanced due diligence (EDD) for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, or those engaged in complex/unusual transactions) and simplified due diligence (SDD) for lower-risk scenarios.

aml 40% confidence

Obligation: Any transaction (regardless of amount) that an institution knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorist financing must be reported.

aml 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that an STR has been filed or that a money laundering or terrorist financing investigation is being conducted.

aml 40% confidence

Transaction Records: All transaction data, including the amount, currency, date, and details of the parties involved (originator and beneficiary), should be kept.

aml 40% confidence

Customer Identification Records: Records obtained through CDD measures (copies of identification documents, account files, business correspondence) must be retained.

aml 40% confidence

Retention Period: Generally, these records must be kept for at least five (5) years after the business relationship ends or after the date of an occasional transaction.

aml 60% confidence

Cellule Nationale de Traitement des Informations Financières (CENTIF): Mali's FIU, responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs).

enforcement 60% confidence

Entity Targeted: All regulated financial institutions (banks, microfinance institutions, payment service providers, etc.) within the UEMOA zone, including those operating in Mali. Also serves as a warning to the general public. Violation Type: Engaging in any activity related to cryptocurrencies (issuance, exchange, holding, investment, facilitation of transactions, etc.). The BCEAO considers these activities to be unauthorized and high-risk. Penalty Amount: Not a specific monetary penalty for a single action, but non-compliance by regulated entities could lead to severe administrative sanctions, including fines, withdrawal of operating licenses, and other regulatory penalties imposed by the BCEAO or national banking commissions. Outcome: A de facto ban on formal cryptocurrency operations within Mali's regulated financial sector. Financial institutions are prohibited from offering crypto services, and the public is warned about the risks and lack of regulatory protection.

enforcement 50% confidence

Outcome: A de facto ban on formal cryptocurrency operations within Mali's regulated financial sector. Financial institutions are prohibited from offering crypto services, and the public is warned about the risks and lack of regulatory protection.

enforcement 60% confidence

Entity Targeted: Individuals or informal groups promoting and operating cryptocurrency-based investment scams or pyramid schemes. Violation Type: Fraud, swindling (escroquerie), illegal financial operations, often disguised as crypto investment opportunities. Penalty Amount: Varies depending on the scale of the fraud; can include prison sentences and financial reparations to victims. Specific public records of these amounts for crypto-specific cases in Mali are difficult to pinpoint from international sources. Outcome: Arrests, investigations, and potential prosecutions of individuals involved in scams. Public awareness campaigns to warn citizens against unregulated crypto investment opportunities.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Not permitted — custodial wallet/SaaS operations in Mali face a de facto ban: the BCEAO has prohibited all regulated financial institutions from dealing in virtual assets, no crypto-specific licensing or custody framework exists, and operating outside the formal system carries significant criminal enforcement risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?