← Regulations / Mali / Operating Models / Remote VASP

Remote VASP serving residents in Mali

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Not permitted AI-Generated · Unreviewed

Remote VASP is not permitted in Mali.

Verdict Details

Permitted
no
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD: identify and verify natural persons (name, address, DOB, nationality, official ID) and legal entities (name, registered address, legal form, proof of incorporation, directors, beneficial owners) per Law N°2018-024 and UEMOA Directive No. 02/2015/CM/UEMOA
  • Beneficial ownership identification required
  • Understand purpose and intended nature of business relationship
  • Ongoing transaction monitoring for consistency with customer profile
  • Risk-based approach: EDD for PEPs, high-risk jurisdictions, complex transactions; SDD for low-risk
  • STR reporting: any transaction suspected of ML/TF must be reported to CENTIF (Cellule Nationale de Traitement des Informations Financières) — Mali's FIU
  • No tipping-off prohibition
  • Record-keeping: transaction records and CDD documents retained for at least 5 years after relationship ends
  • Even though crypto is de facto banned, AML obligations would apply if operating in the fiat periphery (e.g. payment processing) — enforced by BCEAO for financial institutions

Key Restrictions

  • Cryptocurrencies are not recognized as legal tender in the UEMOA zone
  • BCEAO has issued explicit prohibitions (Circular N°0000000001/M/DG/2021, December 2021) barring all supervised financial institutions from engaging in any virtual asset activities
  • No crypto-specific licensing or registration regime exists — no legal pathway to operate a compliant VASP
  • Financial institutions (banks, microfinance, payment processors) cannot integrate crypto under BCEAO directives
  • Operating as a remote VASP serving residents would fall outside any recognized regulatory framework, creating a de facto prohibition

Key Risks

  • High enforcement risk: BCEAO has repeatedly warned and reiterated its prohibition (April 2022, July 2023), and Malian judicial police and public prosecutors have pursued arrests and investigations related to crypto fraud (May 2023 arrests, late 2022-2023 scam warnings)
  • No regulatory sandbox or transitional pathway — any crypto operation is operating in an unregulated space that BCEAO has publicly warned against
  • Reputational and consumer-protection risk: BCEAO public warnings frame crypto as high-risk and unregulated, likely deterring local banking partners
  • AML/CFT compliance is impossible in practice for a remote VASP since no supervised financial institution can lawfully process fiat on/off ramps for crypto in Mali
  • Possible criminal liability for unlicensed financial operations disguised as crypto services

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

December 2021: The BCEAO issued a directive (Circular N°0000000001/M/DG/2021) explicitly prohibiting financial institutions under its purview from engaging in any activities related to virtual assets.

licensing 60% confidence

They are not recognized as legal tender within the UEMOA zone.

licensing 60% confidence

They are not regulated or supervised by the BCEAO or any national financial authority in the region.

licensing 60% confidence

Financial institutions supervised by the BCEAO (banks, microfinance institutions) are generally prohibited or strongly discouraged from engaging in activities related to virtual assets due to the associated risks (money laundering, terrorist financing, consumer protection, financial stability).

licensing 60% confidence

Neither a registration nor a specific licensing regime currently exists for VASPs in Mali.

licensing 60% confidence

Entities operating in this space are doing so outside of a recognized regulatory framework. This is not a "light touch" approach; rather, it indicates a lack of formal permission or supervision, which can be interpreted as implicitly disallowed for formal financial sector participation.

custody 40% confidence

The BCEAO issued a press release on May 19, 2021, warning the public about the risks associated with cryptocurrencies. It reiterated that cryptocurrencies are not recognized as legal tender in the UEMOA zone and are not subject to the supervision of the BCEAO or national financial authorities. The bank strongly discouraged financial institutions from engaging in activities related to cryptocurrencies.

custody 40% confidence

There are no specific custodial license requirements for digital asset service providers in Mali, as there is no established regulatory framework for cryptocurrencies. Given the BCEAO's warnings, attempting to operate such a licensed service would likely face significant challenges or be deemed unauthorized.

aml 40% confidence

Law N°2018-024 of August 21, 2018, amending Ordinance N°2015-032/P-RM of June 19, 2015, relating to the fight against money laundering and terrorist financing.

aml 60% confidence

Cellule Nationale de Traitement des Informations Financières (CENTIF): Mali's FIU, responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs).

enforcement 60% confidence

Entity Targeted: All regulated financial institutions (banks, microfinance institutions, payment service providers, etc.) within the UEMOA zone, including those operating in Mali. Also serves as a warning to the general public. Violation Type: Engaging in any activity related to cryptocurrencies (issuance, exchange, holding, investment, facilitation of transactions, etc.). The BCEAO considers these activities to be unauthorized and high-risk. Penalty Amount: Not a specific monetary penalty for a single action, but non-compliance by regulated entities could lead to severe administrative sanctions, including fines, withdrawal of operating licenses, and other regulatory penalties imposed by the BCEAO or national banking commissions. Outcome: A de facto ban on formal cryptocurrency operations within Mali's regulated financial sector. Financial institutions are prohibited from offering crypto services, and the public is warned about the risks and lack of regulatory protection.

enforcement 60% confidence

Entity Targeted: Individuals or informal groups promoting and operating cryptocurrency-based investment scams or pyramid schemes. Violation Type: Fraud, swindling (escroquerie), illegal financial operations, often disguised as crypto investment opportunities. Penalty Amount: Varies depending on the scale of the fraud; can include prison sentences and financial reparations to victims. Specific public records of these amounts for crypto-specific cases in Mali are difficult to pinpoint from international sources. Outcome: Arrests, investigations, and potential prosecutions of individuals involved in scams. Public awareness campaigns to warn citizens against unregulated crypto investment opportunities.

enforcement 50% confidence

Outcome: A de facto ban on formal cryptocurrency operations within Mali's regulated financial sector. Financial institutions are prohibited from offering crypto services, and the public is warned about the risks and lack of regulatory protection.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

No — a remote VASP serving Malian residents is not permitted; the BCEAO has imposed a de facto ban on crypto activity by supervised financial institutions, no licensing or registration pathway exists for VASPs, and unlicensed operators face enforcement risk from Malian judicial police including arrest and prosecution for fraud.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?