DeFi protocol frontend in Mauritius
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Mauritius with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification (CDD) for all customers (mu.aml.identification-and-verification-of-customers, mu.aml.obtain-reliable-identifying-information-for)
- Beneficial ownership identification for any legal entity customers (25%+ ownership threshold) (mu.aml.beneficial-ownership-identification, mu.aml.identify-and-take-reasonable-measures, mu.aml.for-legal-entities-this-means)
- Understand purpose and intended nature of business relationship including source of funds and source of wealth (mu.aml.purpose-and-nature-of-business, mu.aml.understand-the-purpose-and-intended)
- Ongoing transaction monitoring and regular updates to customer information (mu.aml.continuously-monitor-the-business-relationship, mu.aml.regularly-update-customer-information-and)
- Enhanced Due Diligence (EDD) for PEPs, high-risk geographies, anonymous technologies, and complex/unusual transactions (mu.aml.enhanced-due-diligence-edd, mu.aml.edd-measures-include-obtaining-senior)
- Simplified Due Diligence (SDD) permitted for low-risk situations subject to regulatory guidance (mu.aml.simplified-due-diligence-sdd)
- Reporting entity obligations under FIAMLA 2002 and VAITOS Act 2021, including suspicious transaction reporting to the Financial Intelligence Unit (mu.aml.the-financial-intelligence-and-anti-money, mu.aml.the-virtual-asset-and-initial)
- Compliance with FSC Rules (VAITOS) 2022 specific AML/CFT requirements for VASPs (mu.aml.fsc-rules-for-virtual-asset)
Key Restrictions
- Any entity providing virtual asset services (including a frontend that facilitates transactions on behalf of users) must obtain a license under the VAITOS Act 2021 (mu.licensing.virtual-asset-and-initial-token)
- A local entity incorporated in Mauritius is required as the licensee (mu.licensing.licensing-process-applicants-must-submit)
- License application requires minimum stated capital of MUR 1,500,000 (~USD 37,500) (mu.licensing.minimum-stated-capital-schedule-1)
- Client virtual assets and money must be segregated from the licensee's own assets (mu.licensing.vaitos-act-2021-section-131g, mu.licensing.fsc-rules-vaitos-2022-rule)
- Robust risk management framework covering operational, technology, and financial risks mandatory (mu.licensing.risk-management-framework-section-131b)
- Adequate systems and controls for safeguarding cryptographic keys required (mu.licensing.vaitos-act-2021-section-131d)
- Cybersecurity policies and procedures for protecting against unauthorized access mandatory (mu.licensing.fsc-rules-vaitos-2022-rule)
- If the frontend takes fees (e.g., trading commissions, swap fees), it would likely be classified as providing a virtual asset service and fall squarely under VAITOS licensing requirements
Key Risks
- Regulatory ambiguity: Whether a non-custodial, non-fee-taking frontend that merely routes users to permissionless smart contracts qualifies as a 'virtual asset service' under the broad VAITOS Act definitions has not been definitively tested — this could result in enforcement action if the FSC takes a broad interpretation
- Enforcement risk: The FSC regularly issues public warnings against unregulated virtual asset services and has signaled that operating without a license is illegal (mu.enforcement.issuing-warnings-against-unregulated-activities, mu.enforcement.outcome-increased-public-awareness-discouragement)
- Mauritius exited FATF grey-listing in 2021 and maintains heightened AML/CFT scrutiny — non-compliance could damage reputation and attract severe regulatory sanctions (mu.enforcement.outcome-enhanced-amlcft-measures-across)
- Fee-taking (e.g., frontend swap fees, routing commissions) would almost certainly trigger full VAITOS licensing obligations, creating capital and operational burdens for what may be a thin-margin operation
- Small market size means limited regulatory precedent and potentially less sophisticated regulator understanding of DeFi-specific structures
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This Act defines various virtual asset services and mandates licensing for providers.
FSC Rules (Virtual Asset and Initial Token Offering Services) 2022: These rules provide specific details and requirements for implementing the VAITOS Act.
Definition of Custodian Wallet Service (Section 2, VAITOS Act 2021): "a service to safeguard virtual assets or instruments enabling control over virtual assets, on behalf of natural or legal persons."
Licensing Process: Applicants must submit a detailed application to the FSC, including:
Minimum Stated Capital (Schedule 1, FSC Rules (VAITOS) 2022):
A licensee providing "Custodian Wallet Service" must maintain a minimum stated capital of MUR 1,500,000 (approximately USD 37,500, subject to exchange rate fluctuations).
VAITOS Act 2021 (Section 13(1)(g)): A VASP shall "manage client virtual assets and money received from clients in a manner that protects the interests of clients, and, in particular, ensures that they are segregated from the assets of the VASP."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Mandates that a licensee must maintain separate accounts for client virtual assets and money received from clients, distinct from its own assets.
Prohibits the use of client virtual assets or money for the licensee’s own benefit or for the benefit of any third party without explicit client consent and where permitted by law.
Risk Management Framework (Section 13(1)(b) of VAITOS Act and Rule 9 of FSC Rules (VAITOS) 2022): Licensees are required to have "robust risk management policies and procedures" covering operational risks, technology risks, and financial risks. This implies that firms should consider professional indemnity insurance or other risk transfer mechanisms as part of their overall risk mitigation strategy, especially given the high-value nature of custodial services.
VAITOS Act 2021 (Section 13(1)(d)): A VASP shall "implement adequate systems and controls for safeguarding client virtual assets, including cryptographic keys."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Cybersecurity Policies: Procedures for protecting against unauthorized access, use, disclosure, disruption, modification, or destruction of information.
The Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This is the cornerstone legislation specifically regulating virtual assets and VASPs. It designates VASPs as "reporting entities" and brings them under the scope of AML/CFT obligations. It provides for the licensing, regulation, and supervision of VASPs by the Financial Services Commission (FSC).
The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002) (as amended): This is the overarching AML/CFT legislation in Mauritius. It establishes the general AML/CFT framework, defines "money laundering," sets out the obligations of reporting entities (including VASPs by virtue of the VAITOS Act), and empowers the Financial Intelligence Unit (FIU).
The Prevention of Terrorism Act 2002 (POTA 2002) (as amended): This Act provides the legal framework for combating the financing of terrorism and related offenses.
FSC Rules for Virtual Asset and Initial Token Offering Services 2022: These rules, issued by the FSC under the VAITOS Act, provide detailed requirements for VASPs, including specific AML/CFT obligations.
Identification and Verification of Customers:
Obtain reliable identifying information for all customers (natural persons and legal entities).
Beneficial Ownership Identification:
Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer.
For legal entities, this means identifying the natural person(s) who ultimately own or control 25% or more of the entity, or who otherwise exercise control through other means.
Purpose and Nature of Business Relationship:
Understand the purpose and intended nature of the business relationship or occasional transaction (e.g., source of funds, source of wealth, intended types of virtual asset transactions).
Continuously monitor the business relationship to ensure that transactions being conducted are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.
Regularly update customer information and beneficial ownership data.
Enhanced Due Diligence (EDD):
Evidence fact mu.aml.edd-measures-obtain-senior not found (may have been renamed).
Simplified Due Diligence (SDD):
Issuing warnings against unregulated activities.
Outcome: Increased public awareness, discouragement of participation in fraudulent schemes, and a clear signal that the FSC is monitoring the space. The warnings emphasize that entities operating without a license are illegal.
Outcome: Enhanced AML/CFT measures across the financial sector, including more stringent requirements for VASPs. This means proactive enforcement through regulation and licensing to prevent future violations. Entities that fail to meet these high standards face license denial or revocation.
Focus on Licensing & Prevention: Mauritius's strategy for virtual assets is heavily focused on comprehensive licensing and strong AML/CFT compliance before an entity can operate. This means many non-compliant entities are prevented from entering the market or have their applications rejected, rather than being fined after operating illegally.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend operating in/from Mauritius likely requires a VAITOS Act license as a virtual asset service provider, with associated high licensing burden, local incorporation, MUR 1.5M minimum capital, and full AML/CFT obligations; whether a purely non-custodial, non-fee-taking frontend triggers licensure is not definitively settled, creating ambiguity risk.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?