Custodial wallet / SaaS in Mauritius
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Mauritius with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full CDD on all customers: obtain name, date of birth, nationality, address, unique ID for natural persons; legal name, proof of incorporation, address, director/beneficial-owner details for legal entities (mu.aml.identification-and-verification-of-customers).
- Beneficial ownership identification: identify natural persons owning or controlling ≥25% of a customer entity (mu.aml.beneficial-ownership-identification, mu.aml.for-legal-entities-this-means).
- Ongoing transaction monitoring and regular updating of customer/KYC information (mu.aml.continuously-monitor-the-business-relationship, mu.aml.regularly-update-customer-information-and).
- Enhanced Due Diligence (EDD) for PEPs, high-risk geographies, anonymous-technology transactions, and large/complex/unusual transactions (mu.aml.enhanced-due-diligence-edd, mu.aml.edd-measures-include-obtaining-senior).
- Simplified Due Diligence (SDD) permitted for low-risk situations, subject to documented risk assessment (mu.aml.simplified-due-diligence-sdd, mu.aml.sdd-applied-in-lower-risk).
- Reporting entity obligations under FIAMLA 2002 and VAITOS Act 2021 – VASP must file suspicious transaction reports (STRs) with the Financial Intelligence Unit (FIU) (mu.aml.the-financial-intelligence-and-anti-money, mu.aml.suspicious-transaction-reports-strs, mu.aml.filing-threshold-for-strs).
- Record-keeping: maintain all transaction and identification records for at least 7 years (mu.aml.record-keeping-duration).
- The SaaS VASP licensee bears primary AML/CFT responsibility as the reporting entity; white-label clients are customers of the licensee, not separate VASPs, unless they independently qualify as VASPs.
Key Restrictions
- Licensing required: Custodian Wallet Service is a defined licensable activity under the VAITOS Act 2021 (Section 2) (mu.licensing.definition-of-custodian-wallet-service).
- Applicant must be incorporated in Mauritius or a registered foreign company (mu.licensing.licensing-process-applicants-must-submit).
- Minimum stated capital of MUR 1,500,000 (~USD 37,500) required specifically for custodian wallet licensees (mu.licensing.a-licensee-providing-custodian-wallet).
- Client virtual assets and money must be segregated from the VASP's own assets; no use for own benefit without explicit client consent (mu.licensing.vaitos-act-2021-section-131g, mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.prohibits-the-use-of-client).
- Must implement adequate systems and controls for safeguarding cryptographic keys (mu.licensing.vaitos-act-2021-section-131d).
- Robust cybersecurity and risk management framework required covering operational, technology, and financial risks (mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.cybersecurity-policies-procedures-for-protecting).
- Insurance may be required by the FSC on a case-by-case basis; no standing mandatory insurance requirement specified (mu.licensing.the-fsc-may-on-a).
- Proof-of-reserves / disclosure requirements: no specific mandatory public proof-of-reserves rule found in the provided facts, though segregation and record-keeping rules apply (mu.licensing.requires-the-licensee-to-clearly).
Key Risks
- Regulatory ambiguity on whether white-label SaaS clients of the licensee require their own VASP license or are covered under the licensee's license — the licensee bears ultimate responsibility as the reporting entity, but client activity may independently trigger VASP status.
- No mandatory insurance requirement codified; FSC may impose on a case-by-case basis, creating uncertainty for risk modeling.
- Mauritius exited the FATF grey list in 2021 but remains under close scrutiny; non-compliance could trigger reputational damage and renewed grey-listing risk (mu.enforcement.date-october-2021-mauritius-officially).
- FSC actively issues warnings against unlicensed virtual asset activities; operating without a license carries legal and reputational risk (mu.enforcement.issuing-warnings-against-unregulated-activities).
- Small market size may limit local business-to-business SaaS opportunity; cross-border servicing may be constrained by the local entity requirement.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This Act defines various virtual asset services and mandates licensing for providers.
Definition of Custodian Wallet Service (Section 2, VAITOS Act 2021): "a service to safeguard virtual assets or instruments enabling control over virtual assets, on behalf of natural or legal persons."
Licensing Process: Applicants must submit a detailed application to the FSC, including:
Minimum Stated Capital (Schedule 1, FSC Rules (VAITOS) 2022):
A licensee providing "Custodian Wallet Service" must maintain a minimum stated capital of MUR 1,500,000 (approximately USD 37,500, subject to exchange rate fluctuations).
VAITOS Act 2021 (Section 13(1)(g)): A VASP shall "manage client virtual assets and money received from clients in a manner that protects the interests of clients, and, in particular, ensures that they are segregated from the assets of the VASP."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Mandates that a licensee must maintain separate accounts for client virtual assets and money received from clients, distinct from its own assets.
Prohibits the use of client virtual assets or money for the licensee’s own benefit or for the benefit of any third party without explicit client consent and where permitted by law.
VAITOS Act 2021 (Section 13(1)(d)): A VASP shall "implement adequate systems and controls for safeguarding client virtual assets, including cryptographic keys."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Cybersecurity Policies: Procedures for protecting against unauthorized access, use, disclosure, disruption, modification, or destruction of information.
The FSC may, on a case-by-case basis or through further guidance, require specific insurance coverage if deemed necessary for the protection of clients.
Adequate financial resources.
Evidence of "fit and proper" persons for directors, beneficial owners, and senior management.
Compliance with AML/CFT obligations.
The Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This is the cornerstone legislation specifically regulating virtual assets and VASPs. It designates VASPs as "reporting entities" and brings them under the scope of AML/CFT obligations. It provides for the licensing, regulation, and supervision of VASPs by the Financial Services Commission (FSC).
The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002) (as amended): This is the overarching AML/CFT legislation in Mauritius. It establishes the general AML/CFT framework, defines "money laundering," sets out the obligations of reporting entities (including VASPs by virtue of the VAITOS Act), and empowers the Financial Intelligence Unit (FIU).
Identification and Verification of Customers:
Beneficial Ownership Identification:
For legal entities, this means identifying the natural person(s) who ultimately own or control 25% or more of the entity, or who otherwise exercise control through other means.
Continuously monitor the business relationship to ensure that transactions being conducted are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD):
EDD measures include obtaining senior management approval, taking reasonable measures to establish the source of wealth and source of funds, and conducting enhanced ongoing monitoring.
Simplified Due Diligence (SDD):
Issuing warnings against unregulated activities.
Date: October 2021 (Mauritius officially exited the FATF grey list). Ongoing since then with continuous monitoring and updates to AML/CFT frameworks.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators may serve Mauritian residents only after obtaining a Custodian Wallet Service license under the VAITOS Act 2021 from the FSC, requiring a local entity, MUR 1.5M minimum capital, full segregation of client assets, robust key-safeguarding and cybersecurity controls, and comprehensive AML/CFT obligations as a reporting entity, with the licensee bearing primary responsibility over its white-label clients.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?