Custodial wallet / SaaS in Mongolia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Mongolia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Licensed VASPs must conduct KYC on all customers (individuals: full name, DOB, nationality, address, national ID/passport; legal entities: name, form, registration, directors, ownership structure)
- Beneficial ownership identification required for legal entity customers (25% or more ownership threshold)
- Purpose-and-nature-of-business-relationship assessment required for each customer
- Ongoing transaction monitoring — scrutinize for unusual/suspicious patterns, keep CDD data up-to-date
- Risk-based approach: policies and procedures for assessing ML/TF risks by customer, product, service, transaction channel
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex structures
- Screening against UN Security Council sanctions lists and internal watchlists
- Suspicious Transaction Reports (STRs) to the Financial Information Unit (FIU) — must be filed promptly without undue delay (no monetary threshold; any suspicious transaction)
- No tipping-off prohibition on VASPs and employees
- Record-keeping: CDD records, transaction records (amounts, asset types, sender/receiver addresses, timestamps), analysis records, STRs and communications with authorities
- AML obligations attach to the licensed VASP (the SaaS/custody provider); white-label clients may be customers of the VASP and subject to the VASP's KYC program, but the licensed entity bears regulatory responsibility
- The VASP Law integrates VASPs into Mongolia's existing AML/CFT framework (Law on Combating Money Laundering and Terrorism Financing)
Key Restrictions
- Must obtain a VASP license from the Financial Regulatory Commission (FRC) — custodial wallet/SaaS falls under 'safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets'
- Must be a legally established entity in Mongolia (local entity required)
- Must comply with capital adequacy requirements set by the FRC (specific amounts not detailed in provided facts)
- Must implement risk management systems and cybersecurity measures required by FRC
- Customer funds (virtual assets) segregation, insurance, and proof-of-reserves rules are not explicitly detailed in the provided facts — this represents a regulatory gap that must be clarified with the FRC
- The SaaS operator (licensed VASP) bears primary regulatory responsibility; white-label clients cannot independently rely on the operator's license to avoid their own obligations if they also qualify as VASPs
Key Risks
- Regulatory ambiguity on specific custody rules — segregation, insurance, and proof-of-reserves requirements are not clearly defined in the available facts; operators must seek FRC guidance or interpretive rulings
- Evolving regulatory framework (law effective Jan 2022) — enforcement patterns and supervisory expectations are still developing, creating uncertainty
- English-language legal sources are limited — operators may need Mongolian-language legal counsel to navigate licensing applications and compliance
- If white-label clients are themselves engaging in VASP activities (e.g., exchange, transfer), they may require separate licensing, creating a complex dual-licensing structure
- Sanctions screening obligations exist but scope of Mongolia's implementation of UNSC resolutions for virtual assets specifically is not fully detailed
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Partial but Evolving: Mongolia has moved from an unregulated state to establishing a foundational legal framework for virtual assets, specifically targeting Virtual Asset Service Providers (VASPs). The focus is heavily on AML/CFT compliance, risk management, and consumer protection through licensing. It's considered "partial" as it primarily regulates the service providers rather than attempting to regulate every facet of virtual assets or underlying technologies comprehensively at this stage.
Financial Regulatory Commission (FRC) of Mongolia:
Law on Regulation of Virtual Asset Service Providers (VASPs)
Date: Enacted on December 17, 2021 (effective from January 1, 2022).
Purpose: This law establishes the legal framework for the regulation of virtual assets and VASPs in Mongolia. Key provisions include:
Definition of VASP Activities: Outlines the services requiring a license, such as exchange between virtual assets and fiat currencies, exchange between one or more forms of virtual assets, transfer of virtual assets, safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets, and participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Licensing Requirements: Mandates that all entities providing VASP services must obtain a license from the FRC.
AML/CFT Compliance: Imposes strict AML/CFT obligations on licensed VASPs, including Know Your Customer (KYC) procedures, transaction monitoring, record-keeping, and suspicious transaction reporting to the FIU.
Risk Management: Requires VASPs to implement robust risk management systems, cybersecurity measures, and capital adequacy requirements.
Permitted but Regulated: Crypto trading and the operation of cryptocurrency exchanges are legal in Mongolia, provided they are conducted by entities that have obtained a license from the Financial Regulatory Commission (FRC).
Licensing is Mandatory: Any entity wishing to operate as a Virtual Asset Service Provider (VASP) – including crypto exchanges, custodial services, or providers facilitating virtual asset transfers – must go through a rigorous licensing process with the FRC.
Strict AML/CFT Compliance: Licensed exchanges and VASPs are subject to strict AML/CFT requirements, including:
Law on Combating Money Laundering and Terrorism Financing (LMLCFT): This is the main AML/CFT law in Mongolia, originally adopted in 2013 and subsequently amended (e.g., in 2018 and 2021) to incorporate FATF recommendations, including those related to virtual assets. It establishes the legal framework for identifying, freezing, and confiscating assets obtained from criminal activities, as well as preventing the financing of terrorism.
Financial Regulatory Commission (FRC) Resolutions and Regulations: The FRC is the primary regulator for non-banking financial services, including VASPs. They issue specific regulations, resolutions, and licensing requirements that detail how the LMLCFT applies to virtual asset businesses.
For Individuals: Obtain and verify the client's full name, date of birth, place of birth, nationality, permanent address, and unique identification number (e.g., national ID card number, passport number). Verification must be done using reliable, independent source documents, data, or information.
For Legal Entities: Obtain and verify the entity's legal name, legal form, registration number, address of registered office, and names of directors/partners. Understand the entity's ownership and control structure.
Beneficial Ownership (BO): Identify and verify the identity of the natural persons who ultimately own or control the customer, as well as the natural persons on whose behalf a transaction is being conducted. For legal entities, this typically involves identifying individuals owning 25% or more of the shares or voting rights, or otherwise exercising control.
Purpose and Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or transaction. This helps assess the risk profile of the customer.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes:
Scrutinizing transactions for unusual or suspicious patterns.
Keeping customer due diligence data up-to-date.
Risk-Based Approach: Implement policies and procedures to identify, assess, and understand the money laundering and terrorism financing (ML/TF) risks posed by customers, products, services, transactions, and delivery channels.
Enhanced Due Diligence (EDD): Apply EDD measures for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, complex structures) and transactions. This may involve obtaining additional information on the customer, sources of funds/wealth, and the reasons for the intended transactions.
Screening: Screen customers against national and international sanctions lists (e.g., UN Security Council sanctions) and internal watchlists.
Reporting Threshold: Report any transaction (regardless of amount) or attempted transaction that the VASP knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorism financing.
Reporting Body: All STRs must be submitted to the Financial Information Unit (FIU) of Mongolia.
Timing: Reports must be filed promptly, without undue delay, typically within a few working days of forming a suspicion.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a report has been or will be made (i.e., "tipping-off").
CDD Records: All documents and data obtained through the CDD process (e.g., copies of identification documents, beneficial ownership information).
Transaction Records: Records of all virtual asset transactions, including amounts, types of virtual assets, sender and receiver addresses, timestamps, and any relevant metadata.
Analysis Records: Records of any internal inquiries, risk assessments, and the rationale behind decisions regarding customer risk categorization or suspicious activity.
STRs and Communications: Copies of all submitted STRs and any related communications with the FIU or other authorities.
Legal Basis: The implementation of UNSC resolutions is typically embedded in a country's national Anti-Money Laundering/Combating the Financing of Terrorism (AML/CFT) laws.
Legal Basis: Penalties would be outlined in the Law on Combating Money Laundering and Terrorism Financing and the Mongolian Criminal Code.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers are permitted in Mongolia as licensed VASPs under the FRC, requiring a local entity, a high-burden licensing process, and strict AML/CFT compliance, though specific custody rules (segregation, insurance, proof-of-reserves) are not clearly detailed in available sources.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?