← Regulations / Mauritius / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Mauritius

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Mauritius with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Full CDD on all customers: obtain name, date of birth, nationality, address, unique ID for natural persons; legal name, proof of incorporation, address, director/beneficial-owner details for legal entities (mu.aml.identification-and-verification-of-customers).
  • Beneficial ownership identification: identify natural persons owning or controlling ≥25% of a customer entity (mu.aml.beneficial-ownership-identification, mu.aml.for-legal-entities-this-means).
  • Ongoing transaction monitoring and regular updating of customer/KYC information (mu.aml.continuously-monitor-the-business-relationship, mu.aml.regularly-update-customer-information-and).
  • Enhanced Due Diligence (EDD) for PEPs, high-risk geographies, anonymous-technology transactions, and large/complex/unusual transactions (mu.aml.enhanced-due-diligence-edd, mu.aml.edd-measures-include-obtaining-senior).
  • Simplified Due Diligence (SDD) permitted for low-risk situations, subject to documented risk assessment (mu.aml.simplified-due-diligence-sdd, mu.aml.sdd-applied-in-lower-risk).
  • Reporting entity obligations under FIAMLA 2002 and VAITOS Act 2021 – VASP must file suspicious transaction reports (STRs) with the Financial Intelligence Unit (FIU) (mu.aml.the-financial-intelligence-and-anti-money, mu.aml.suspicious-transaction-reports-strs, mu.aml.filing-threshold-for-strs).
  • Record-keeping: maintain all transaction and identification records for at least 7 years (mu.aml.record-keeping-duration).
  • The SaaS VASP licensee bears primary AML/CFT responsibility as the reporting entity; white-label clients are customers of the licensee, not separate VASPs, unless they independently qualify as VASPs.

Key Restrictions

  • Licensing required: Custodian Wallet Service is a defined licensable activity under the VAITOS Act 2021 (Section 2) (mu.licensing.definition-of-custodian-wallet-service).
  • Applicant must be incorporated in Mauritius or a registered foreign company (mu.licensing.licensing-process-applicants-must-submit).
  • Minimum stated capital of MUR 1,500,000 (~USD 37,500) required specifically for custodian wallet licensees (mu.licensing.a-licensee-providing-custodian-wallet).
  • Client virtual assets and money must be segregated from the VASP's own assets; no use for own benefit without explicit client consent (mu.licensing.vaitos-act-2021-section-131g, mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.prohibits-the-use-of-client).
  • Must implement adequate systems and controls for safeguarding cryptographic keys (mu.licensing.vaitos-act-2021-section-131d).
  • Robust cybersecurity and risk management framework required covering operational, technology, and financial risks (mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.cybersecurity-policies-procedures-for-protecting).
  • Insurance may be required by the FSC on a case-by-case basis; no standing mandatory insurance requirement specified (mu.licensing.the-fsc-may-on-a).
  • Proof-of-reserves / disclosure requirements: no specific mandatory public proof-of-reserves rule found in the provided facts, though segregation and record-keeping rules apply (mu.licensing.requires-the-licensee-to-clearly).

Key Risks

  • Regulatory ambiguity on whether white-label SaaS clients of the licensee require their own VASP license or are covered under the licensee's license — the licensee bears ultimate responsibility as the reporting entity, but client activity may independently trigger VASP status.
  • No mandatory insurance requirement codified; FSC may impose on a case-by-case basis, creating uncertainty for risk modeling.
  • Mauritius exited the FATF grey list in 2021 but remains under close scrutiny; non-compliance could trigger reputational damage and renewed grey-listing risk (mu.enforcement.date-october-2021-mauritius-officially).
  • FSC actively issues warnings against unlicensed virtual asset activities; operating without a license carries legal and reputational risk (mu.enforcement.issuing-warnings-against-unregulated-activities).
  • Small market size may limit local business-to-business SaaS opportunity; cross-border servicing may be constrained by the local entity requirement.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Definition of Custodian Wallet Service (Section 2, VAITOS Act 2021): "a service to safeguard virtual assets or instruments enabling control over virtual assets, on behalf of natural or legal persons."

licensing 60% confidence

VAITOS Act 2021 (Section 13(1)(g)): A VASP shall "manage client virtual assets and money received from clients in a manner that protects the interests of clients, and, in particular, ensures that they are segregated from the assets of the VASP."

licensing 60% confidence

Prohibits the use of client virtual assets or money for the licensee’s own benefit or for the benefit of any third party without explicit client consent and where permitted by law.

aml 60% confidence

The Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This is the cornerstone legislation specifically regulating virtual assets and VASPs. It designates VASPs as "reporting entities" and brings them under the scope of AML/CFT obligations. It provides for the licensing, regulation, and supervision of VASPs by the Financial Services Commission (FSC).

aml 60% confidence

The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002) (as amended): This is the overarching AML/CFT legislation in Mauritius. It establishes the general AML/CFT framework, defines "money laundering," sets out the obligations of reporting entities (including VASPs by virtue of the VAITOS Act), and empowers the Financial Intelligence Unit (FIU).

aml 60% confidence

Identification and Verification of Customers:

aml 60% confidence

Beneficial Ownership Identification:

aml 60% confidence

For legal entities, this means identifying the natural person(s) who ultimately own or control 25% or more of the entity, or who otherwise exercise control through other means.

aml 60% confidence

Continuously monitor the business relationship to ensure that transactions being conducted are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.

aml 60% confidence

Enhanced Due Diligence (EDD):

aml 60% confidence

EDD measures include obtaining senior management approval, taking reasonable measures to establish the source of wealth and source of funds, and conducting enhanced ongoing monitoring.

aml 60% confidence

Simplified Due Diligence (SDD):

enforcement 60% confidence

Date: October 2021 (Mauritius officially exited the FATF grey list). Ongoing since then with continuous monitoring and updates to AML/CFT frameworks.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators may serve Mauritian residents only after obtaining a Custodian Wallet Service license under the VAITOS Act 2021 from the FSC, requiring a local entity, MUR 1.5M minimum capital, full segregation of client assets, robust key-safeguarding and cybersecurity controls, and comprehensive AML/CFT obligations as a reporting entity, with the licensee bearing primary responsibility over its white-label clients.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?