DeFi protocol frontend in Mauritania
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Mauritania with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- CDD obligations under Law N° 2013-030 — identify and verify natural persons (name, DOB, address, nationality via reliable documents) and legal entities (name, form, incorporation proof, directors, binding powers).
- Beneficial ownership identification — identify and verify individuals who ultimately own or control >25% (standard threshold) of the customer entity.
- Purpose and intended nature of business relationship must be documented.
- Ongoing transaction monitoring for consistency with customer risk profile, including screening for unusual activity.
- Screen customers against national and international sanctions lists (UN Security Council resolutions).
- Suspicious Transaction Reports (STRs) to CENTRIF (Mauritania's FIU) — mandatory if funds are suspected to be proceeds of crime or linked to terrorist financing, irrespective of amount.
- No-tipping-off prohibition — cannot disclose STR filing to customers or third parties.
- Record-keeping of CDD data, transaction records (amount, currency, dates, parties, originator/beneficiary info per FATF Travel Rule principles), and STR correspondence.
- Risk-based approach — apply Enhanced Due Diligence (EDD) for higher-risk customers (PEPs, etc.).
- BCM Circular N° 004/R/2019 prohibits banks and regulated financial institutions from any involvement with crypto, meaning the frontend cannot rely on local banking partners for fiat on/off ramps.
Key Restrictions
- The BCM Circular N° 004/R/2019 prohibits all banks, financial institutions, and payment service providers supervised by the BCM from buying, selling, holding, or facilitating crypto transactions — this effectively cuts off local fiat on/off ramps and banking relationships.
- No specific legal framework exists for virtual assets — the frontend operates in a legal vacuum with no protections for contracts, consumer rights, or tax treatment.
- Any business must comply with general Mauritanian commercial law: local incorporation and standard business permits are required.
- Fee-taking (e.g., frontend fees, swap commissions) could recharacterize the operator as a financial intermediary, potentially triggering BCM financial services rules or falling under the general prohibition on regulated entities dealing with crypto.
Key Risks
- Legal uncertainty — no clear framework means the frontend could be deemed illegal at any time, with potential retroactive enforcement.
- BCM Circular N° 004/R/2019 creates a de facto prohibition on any crypto-related activity touching the regulated financial system, making it practically impossible to bank or process fiat locally.
- Risk of future regulation or ban — Mauritania could introduce a licensing regime, registration requirement, or outright ban at any time, potentially with retroactive effect.
- AML obligations are based on general law (Law N° 2013-030) whose applicability to unregulated VASPs is contested — operators may be held to FATF standards without clear implementing guidance.
- No crypto-specific supervisory clarity — CENTRIF and BCM have not issued crypto-specific AML guidance, creating compliance gap risk.
- Enforcement precedent is absent but so is legal protection — first-mover operators may face disproportionate scrutiny or penalties.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Absence of Specific Legislation: Mauritania has not enacted specific laws or decrees to regulate virtual assets, blockchain technology, or cryptocurrency service providers. Unlike many countries that have adopted or are in the process of adopting bespoke crypto regulations, Mauritania has not yet done so.
Central Bank Stance: The Banque Centrale de Mauritanie (BCM) – the country's central bank and primary financial regulator – has generally taken a cautious stance. While there hasn't been an outright ban, the BCM has historically issued warnings regarding the risks associated with cryptocurrencies, including their volatility, potential for fraud, and use in illicit activities. These warnings serve to inform the public and financial institutions of the risks rather than establishing a regulatory framework.
No Specific Licenses: Consequently, there are no specific licenses or registration requirements for cryptocurrency exchanges, custody providers, or payment processors.
Neither a dedicated licensing nor a registration regime for virtual assets exists.
Entities wishing to operate a business in Mauritania would, however, need to comply with general Mauritanian commercial law for company registration and obtain standard business permits, which are distinct from financial service licenses.
Local Presence: While no specific local presence requirement exists for crypto entities, any business operating in Mauritania would generally need to establish a legal entity and physical presence in accordance with Mauritanian commercial law.
Legal Uncertainty: Operating a virtual asset business in a jurisdiction without clear regulations carries significant legal and operational risks. There is no legal certainty regarding the status of contracts, consumer protection, tax implications, or the legality of operations.
Risk of Future Regulation: The absence of regulation does not mean permissibility. Mauritania could, at any time, introduce new laws, including bans, strict licensing requirements, or even retroactive measures.
Law N° 2013-030 of 17 July 2013 on Combating Money Laundering and Terrorist Financing (Loi n° 2013-030 du 17 juillet 2013 relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme).
Beneficial Ownership Identification: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements (e.g., trusts). This typically involves identifying individuals who ultimately own or control more than a specified percentage (e.g., 25%) of the entity.
Purpose and Intended Nature of Business Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing transactions for unusual patterns.
Screening: Screen customers against national and international sanctions lists (e.g., UN Security Council resolutions).
Obligation to Report: If a VASP knows, suspects, or has reasonable grounds to suspect that funds or other assets, regardless of their amount, are proceeds of a criminal activity or are linked to terrorist financing, it must promptly report this to the Financial Intelligence Unit (FIU).
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that a suspicious transaction report has been or will be submitted.
Records of transactions, including the amount, currency (virtual and fiat, where applicable), dates, and parties involved (originator and beneficiary information, as per FATF Travel Rule principles).
Risk-Based Approach: Apply CDD measures on a risk-sensitive basis. VASPs must have policies and procedures for assessing and managing risks associated with different customers, products, services, and geographic areas. Enhanced Due Diligence (EDD) must be applied for higher-risk customers (e.g., Politically Exposed Persons - PEPs), complex or unusually large transactions, and situations identified as high-risk. Simplified Due Diligence (SDD) may be permitted for lower-risk situations, but the VASP must be able to demonstrate that the risk is genuinely low.
Ban on Financial Institutions Dealing with Cryptocurrencies:
Legal Reference: Circular N° 004/R/2019 issued by the Banque Centrale de Mauritanie (BCM) (Central Bank of Mauritania).
Cellule Nationale de Traitement du Renseignement Financier (CENTRIF) - The Financial Intelligence Unit (FIU):
Communiqué from the Banque Centrale de Mauritanie (BCM):
What this means: The BCM's stance implies that any activity related to cryptocurrencies, including custody services, falls outside the legal and regulated financial sector and would likely be viewed as non-compliant or illegal.
Legal Basis (Indirect): The relevant legislation would be Loi N° 2013-057 portant sur les systèmes et moyens de paiement en République Islamique de Mauritanie (Law N° 2013-057 on payment systems and means in the Islamic Republic of Mauritania), and subsequent implementing regulations or circulars from the BCM regarding payment service providers and e-money. This law defines and regulates various payment instruments and services.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend may operate in Mauritania only as a locally-incorporated entity under general commercial law, with no specific crypto licensing path, but faces a de facto prohibition on banking relationships due to BCM Circular N° 004/R/2019, must comply with general AML/CFT obligations under Law N° 2013-030 (CDD, screening, STRs to CENTRIF), and operates in a high-risk legal vacuum with no regulatory clarity or protections.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?