Crypto ATM / kiosk operator in Mauritius
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in Mauritius with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including crypto ATM operators) are designated 'reporting entities' under the VAITOS Act 2021 and FIAMLA 2002, subjecting them to full AML/CFT obligations.
- Customer identification and verification is required for all customers — natural persons (full name, date of birth, nationality, residential address, unique ID number verified from independent source documents) and legal entities (legal name, form, incorporation proof, directors, beneficial owners).
- Beneficial ownership identification required — identify and verify natural persons who ultimately own or control 25% or more of the entity.
- Ongoing transaction monitoring required — continuously monitor the business relationship to ensure transactions are consistent with customer knowledge, risk profile, and source of funds.
- Enhanced Due Diligence (EDD) applies in higher-risk situations including: PEPs, customers from high-risk geographic areas, transactions involving new/anonymity-favouring technologies, and complex/unusually large transactions.
- EDD measures include obtaining senior management approval, establishing source of wealth and source of funds, and conducting enhanced ongoing monitoring.
- Record-keeping and suspicious transaction reporting obligations apply under FIAMLA 2002 (specific cash transaction reporting thresholds not explicitly stated in provided facts).
- VASPs must comply with FSC Rules (VAITOS) 2022 for AML/CFT and the FSC Guide to AML/CFT for Licensed Institutions.
Key Restrictions
- Must be licensed under the VAITOS Act 2021 as a Virtual Asset Service Provider (VASP) before operating any crypto ATM/kiosk.
- A licensee providing 'Custodian Wallet Service' (which includes safeguarding virtual assets or instruments enabling control over virtual assets) must maintain minimum stated capital of MUR 1,500,000 (~USD 37,500).
- Client virtual assets and money must be segregated from the VASP's own assets — separate accounts, no use for the licensee's own benefit without explicit client consent.
- Must implement robust governance arrangements, risk management systems (operational, financial, IT, cybersecurity), independent audit function, and cybersecurity policies.
- Must have adequate systems and controls for safeguarding client virtual assets, including cryptographic keys.
- FSC may require specific insurance coverage on a case-by-case basis.
- A comprehensive business plan, evidence of fit-and-proper persons, and full AML/CFT compliance program must be submitted as part of the licensing application.
Key Risks
- Cash-intensive nature of crypto ATMs creates inherently higher AML/CFT risk profile, triggering EDD obligations and greater scrutiny from FSC.
- Mauritius was previously FATF grey-listed (exited October 2021) — regulators remain vigilant and enforcement posture is proactive; non-compliant operators face license denial or revocation rather than fines.
- Small market size means fewer operators, potentially higher scrutiny per operator.
- Specific cash-transaction reporting thresholds (e.g., for cash-in/cash-out at kiosks) are not clearly identified in the provided facts — ambiguity in granular operational requirements.
- FSC enforcement actions may not always detail financial penalties; risks include public warnings, license revocation, or reputational harm.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This Act defines various virtual asset services and mandates licensing for providers.
FSC Rules (Virtual Asset and Initial Token Offering Services) 2022: These rules provide specific details and requirements for implementing the VAITOS Act.
Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002)
Guidance Notes on Anti-Money Laundering and Combating the Financing of Terrorism for Virtual Assets and Virtual Asset Service Providers (VASPs)
Definition of Custodian Wallet Service (Section 2, VAITOS Act 2021): "a service to safeguard virtual assets or instruments enabling control over virtual assets, on behalf of natural or legal persons."
Licensing Process: Applicants must submit a detailed application to the FSC, including:
A comprehensive business plan.
Evidence of "fit and proper" persons for directors, beneficial owners, and senior management.
Robust governance arrangements, including internal controls, risk management systems (operational, financial, IT, cybersecurity).
Adequate financial resources.
An independent audit function.
Compliance with AML/CFT obligations.
Minimum Stated Capital (Schedule 1, FSC Rules (VAITOS) 2022):
A licensee providing "Custodian Wallet Service" must maintain a minimum stated capital of MUR 1,500,000 (approximately USD 37,500, subject to exchange rate fluctuations).
VAITOS Act 2021 (Section 13(1)(g)): A VASP shall "manage client virtual assets and money received from clients in a manner that protects the interests of clients, and, in particular, ensures that they are segregated from the assets of the VASP."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Mandates that a licensee must maintain separate accounts for client virtual assets and money received from clients, distinct from its own assets.
Requires the licensee to clearly identify and account for client virtual assets and money, and to maintain proper records.
Prohibits the use of client virtual assets or money for the licensee’s own benefit or for the benefit of any third party without explicit client consent and where permitted by law.
Minimum Stated Capital: The requirement for minimum stated capital (MUR 1.5 million) serves as a financial buffer.
Risk Management Framework (Section 13(1)(b) of VAITOS Act and Rule 9 of FSC Rules (VAITOS) 2022): Licensees are required to have "robust risk management policies and procedures" covering operational risks, technology risks, and financial risks. This implies that firms should consider professional indemnity insurance or other risk transfer mechanisms as part of their overall risk mitigation strategy, especially given the high-value nature of custodial services.
The FSC may, on a case-by-case basis or through further guidance, require specific insurance coverage if deemed necessary for the protection of clients.
VAITOS Act 2021 (Section 13(1)(d)): A VASP shall "implement adequate systems and controls for safeguarding client virtual assets, including cryptographic keys."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Cybersecurity Policies: Procedures for protecting against unauthorized access, use, disclosure, disruption, modification, or destruction of information.
The Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This is the cornerstone legislation specifically regulating virtual assets and VASPs. It designates VASPs as "reporting entities" and brings them under the scope of AML/CFT obligations. It provides for the licensing, regulation, and supervision of VASPs by the Financial Services Commission (FSC).
The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002) (as amended): This is the overarching AML/CFT legislation in Mauritius. It establishes the general AML/CFT framework, defines "money laundering," sets out the obligations of reporting entities (including VASPs by virtue of the VAITOS Act), and empowers the Financial Intelligence Unit (FIU).
The Prevention of Terrorism Act 2002 (POTA 2002) (as amended): This Act provides the legal framework for combating the financing of terrorism and related offenses.
FSC Rules for Virtual Asset and Initial Token Offering Services 2022: These rules, issued by the FSC under the VAITOS Act, provide detailed requirements for VASPs, including specific AML/CFT obligations.
FSC Guide to Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) for Licensed Institutions: While a general guide, it applies to all licensed entities, including VASPs, providing guidance on implementing AML/CFT programs.
Identification and Verification of Customers:
Obtain reliable identifying information for all customers (natural persons and legal entities).
Natural Persons: Full name, date of birth, place of birth, nationality, residential address, unique identification number (e.g., passport, national ID card). Verification requires independent, reliable source documents (e.g., certified copies of ID, utility bills).
Legal Entities: Legal name, legal form, proof of incorporation/registration, address of registered office and principal place of business, names of directors/partners/trustees, and identification of individuals authorized to act on behalf of the entity. Verification typically involves corporate documents.
Beneficial Ownership Identification:
Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer.
For legal entities, this means identifying the natural person(s) who ultimately own or control 25% or more of the entity, or who otherwise exercise control through other means.
Understand the ownership and control structure of the customer.
Purpose and Nature of Business Relationship:
Understand the purpose and intended nature of the business relationship or occasional transaction (e.g., source of funds, source of wealth, intended types of virtual asset transactions).
Continuously monitor the business relationship to ensure that transactions being conducted are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.
Regularly update customer information and beneficial ownership data.
Enhanced Due Diligence (EDD):
Applied in higher-risk situations, including:
Customers who are Politically Exposed Persons (PEPs), their family members, or close associates.
Customers from high-risk geographic areas (as identified by FATF or local regulators).
Transactions involving new or developing technologies or products that favour anonymity.
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
EDD measures include obtaining senior management approval, taking reasonable measures to establish the source of wealth and source of funds, and conducting enhanced ongoing monitoring.
Issuing warnings against unregulated activities.
Refusing or revoking licenses for non-compliance.
Providing guidelines and directives.
Regulator Name: Financial Services Commission (FSC) Mauritius
Focus on Licensing & Prevention: Mauritius's strategy for virtual assets is heavily focused on comprehensive licensing and strong AML/CFT compliance before an entity can operate. This means many non-compliant entities are prevented from entering the market or have their applications rejected, rather than being fined after operating illegally.
Smaller Market: Compared to major global financial centers, the number of large-scale crypto operations (and thus potential high-profile violations) in Mauritius is smaller.
Enforcement Action Publication Policy: While the FSC publishes enforcement actions, they might not always detail specific financial penalties for every type of breach, especially if it leads to license revocation or denial rather than a fine for a fully licensed entity. Public notices are more likely to cover broad warnings or general licensing updates.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto ATM/kiosk operator may operate in Mauritius only after obtaining a VASP license under the VAITOS Act 2021, meeting minimum capital of MUR 1.5 million (if custodian wallet services are provided), establishing a local entity, and implementing full AML/CFT compliance including customer KYC, beneficial ownership identification, EDD for higher-risk transactions, segregation of client assets, and robust governance/cybersecurity frameworks.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?