Remote VASP serving residents in Mauritius
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Mauritius with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Mandatory licensing under VAITOS Act 2021 and FSC Rules (VAITOS) 2022 — cross-border service without a license is illegal (mu.licensing.virtual-asset-and-initial-token, mu.licensing.fsc-rules-virtual-asset-and)
- Designated as 'reporting entities' under FIAMLA 2002 and VAITOS Act 2021 with full AML/CFT obligations (mu.aml.the-virtual-asset-and-initial, mu.aml.the-financial-intelligence-and-anti-money)
- Customer identification and verification for all customers — natural persons (name, DOB, nationality, address, ID) and legal entities (incorporation docs, directors, authorized persons) (mu.aml.identification-and-verification-of-customers, mu.aml.natural-persons-full-name-date, mu.aml.legal-entities-legal-name-legal)
- Beneficial ownership identification — identify natural persons owning/controlling 25% or more (mu.aml.beneficial-ownership-identification, mu.aml.for-legal-entities-this-means)
- Ongoing monitoring of business relationships and regular updates to customer information (mu.aml.continuously-monitor-the-business-relationship, mu.aml.regularly-update-customer-information-and)
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, anonymous technologies, and complex/unusual transactions (mu.aml.enhanced-due-diligence-edd, mu.aml.customers-who-are-politically-exposed, mu.aml.customers-from-high-risk-geographic-areas)
- Travel Rule obligations for all virtual asset transfers exceeding EUR/USD 1,000 — must obtain, transmit, and hold originator and beneficiary information (mu.travel-rule.for-virtual-asset-transfers-where, mu.travel-rule.sending-vasp-originator-vasp-must, mu.travel-rule.receiving-vasp-beneficiary-vasp-must)
- Unhosted wallet/P2P transfers: must collect originator/beneficiary info from own customer; EDD may apply (mu.travel-rule.unhosted-walletsp2p-transfers-when-a)
- Record keeping of all collected information for at least 7 years under FIAMLA (mu.travel-rule.record-keeping-all-collected-information)
Key Restrictions
- Must incorporate a locally licensed entity in Mauritius — the VAITOS Act does not permit a foreign entity to serve residents cross-border without a local license (mu.licensing.virtual-asset-and-initial-token, mu.licensing.licensing-process-applicants-must-submit)
- Minimum stated capital of MUR 1,500,000 (~USD 37,500) for custodian wallet services; other service categories may have different capital requirements (mu.licensing.minimum-stated-capital-schedule-1, mu.licensing.a-licensee-providing-custodian-wallet)
- Client virtual assets and money must be segregated from the VASP's own assets; prohibited from using client assets without explicit consent (mu.licensing.vaitos-act-2021-section-131g, mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.prohibits-the-use-of-client)
- Must implement robust governance, risk management (operational, tech, financial), cybersecurity policies, and maintain an independent audit function (mu.licensing.robust-governance-arrangements-including-internal, mu.licensing.fsc-rules-vaitos-2022-rule, mu.licensing.cybersecurity-policies-procedures-for-protecting)
- Directors, beneficial owners, and senior management must be 'fit and proper' persons (mu.licensing.evidence-of-fit-and-proper)
- Travel Rule compliance requires technological solutions for secure and immediate transmission of originator/beneficiary info between VASPs (mu.travel-rule.interoperability-vasps-are-expected-to)
Key Risks
- High enforcement risk for unlicensed remote operators — FSC regularly issues public warnings against unregulated virtual asset activities and considers unlicensed operation illegal (mu.enforcement.issuing-warnings-against-unregulated-activities, mu.enforcement.outcome-increased-public-awareness-discouragement)
- Mauritius exited FATF grey list in October 2021; regulatory scrutiny and AML/CFT enforcement remain elevated to maintain compliance — failures trigger license denial or revocation (mu.enforcement.outcome-enhanced-amlcft-measures-across, mu.enforcement.focus-on-licensing-prevention-mauritiuss)
- The small market size means fewer precedent enforcement actions, creating some regulatory ambiguity on specific penalty amounts for unlicensed cross-border activity (mu.enforcement.smaller-market-compared-to-major, mu.enforcement.enforcement-action-publication-policy-while)
- Sanctions compliance risk: UN Sanctions Act 2019 mandates asset freezing and financial prohibitions; VASPs must screen against sanctions lists (mu.enforcement.legal-basis-the-united-nations)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This Act defines various virtual asset services and mandates licensing for providers.
FSC Rules (Virtual Asset and Initial Token Offering Services) 2022: These rules provide specific details and requirements for implementing the VAITOS Act.
Licensing Process: Applicants must submit a detailed application to the FSC, including:
Minimum Stated Capital (Schedule 1, FSC Rules (VAITOS) 2022):
A licensee providing "Custodian Wallet Service" must maintain a minimum stated capital of MUR 1,500,000 (approximately USD 37,500, subject to exchange rate fluctuations).
Evidence of "fit and proper" persons for directors, beneficial owners, and senior management.
Robust governance arrangements, including internal controls, risk management systems (operational, financial, IT, cybersecurity).
VAITOS Act 2021 (Section 13(1)(g)): A VASP shall "manage client virtual assets and money received from clients in a manner that protects the interests of clients, and, in particular, ensures that they are segregated from the assets of the VASP."
FSC Rules (VAITOS) 2022 (Rule 12 - Client Virtual Assets and Money):
Prohibits the use of client virtual assets or money for the licensee’s own benefit or for the benefit of any third party without explicit client consent and where permitted by law.
Cybersecurity Policies: Procedures for protecting against unauthorized access, use, disclosure, disruption, modification, or destruction of information.
The Virtual Asset and Initial Token Offering Services Act 2021 (VAITOS Act 2021): This is the cornerstone legislation specifically regulating virtual assets and VASPs. It designates VASPs as "reporting entities" and brings them under the scope of AML/CFT obligations. It provides for the licensing, regulation, and supervision of VASPs by the Financial Services Commission (FSC).
The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA 2002) (as amended): This is the overarching AML/CFT legislation in Mauritius. It establishes the general AML/CFT framework, defines "money laundering," sets out the obligations of reporting entities (including VASPs by virtue of the VAITOS Act), and empowers the Financial Intelligence Unit (FIU).
Identification and Verification of Customers:
Natural Persons: Full name, date of birth, place of birth, nationality, residential address, unique identification number (e.g., passport, national ID card). Verification requires independent, reliable source documents (e.g., certified copies of ID, utility bills).
Legal Entities: Legal name, legal form, proof of incorporation/registration, address of registered office and principal place of business, names of directors/partners/trustees, and identification of individuals authorized to act on behalf of the entity. Verification typically involves corporate documents.
Beneficial Ownership Identification:
For legal entities, this means identifying the natural person(s) who ultimately own or control 25% or more of the entity, or who otherwise exercise control through other means.
Continuously monitor the business relationship to ensure that transactions being conducted are consistent with the VASP's knowledge of the customer, their business and risk profile, including, where necessary, the source of funds.
Regularly update customer information and beneficial ownership data.
Enhanced Due Diligence (EDD):
Customers who are Politically Exposed Persons (PEPs), their family members, or close associates.
Customers from high-risk geographic areas (as identified by FATF or local regulators).
For virtual asset transfers where the value exceeds EUR/USD 1,000 (or its equivalent in any other currency or virtual asset).
Sending VASP (Originator VASP): Must obtain, hold, and transmit the required originator and beneficiary information to the Beneficiary VASP immediately and securely.
Receiving VASP (Beneficiary VASP): Must obtain and hold the required originator information from the Originator VASP. It must also verify the identity of the beneficiary when conducting a transaction above the threshold.
Unhosted Wallets/P2P Transfers: When a VASP's customer receives virtual assets from or sends virtual assets to a wallet not associated with a VASP (e.g., a self-hosted wallet), the VASP must still collect the required originator or beneficiary information from its own customer. Enhanced due diligence may be required.
Record Keeping: All collected information must be maintained for a period of at least seven years, as per the Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA).
Interoperability: VASPs are expected to adopt technological solutions that facilitate the secure and immediate transmission of the required information between VASPs, promoting interoperability.
Issuing warnings against unregulated activities.
Outcome: Increased public awareness, discouragement of participation in fraudulent schemes, and a clear signal that the FSC is monitoring the space. The warnings emphasize that entities operating without a license are illegal.
Outcome: Enhanced AML/CFT measures across the financial sector, including more stringent requirements for VASPs. This means proactive enforcement through regulation and licensing to prevent future violations. Entities that fail to meet these high standards face license denial or revocation.
Focus on Licensing & Prevention: Mauritius's strategy for virtual assets is heavily focused on comprehensive licensing and strong AML/CFT compliance before an entity can operate. This means many non-compliant entities are prevented from entering the market or have their applications rejected, rather than being fined after operating illegally.
Smaller Market: Compared to major global financial centers, the number of large-scale crypto operations (and thus potential high-profile violations) in Mauritius is smaller.
Enforcement Action Publication Policy: While the FSC publishes enforcement actions, they might not always detail specific financial penalties for every type of breach, especially if it leads to license revocation or denial rather than a fine for a fully licensed entity. Public notices are more likely to cover broad warnings or general licensing updates.
Legal Basis: The United Nations (Financial Prohibitions, Travel Bans and Arms Embargoes) Sanctions Act 2019 (often referred to as the UN Sanctions Act) provides the legal framework for the domestic implementation of UNSC sanctions. This Act mandates the freezing of assets, prohibition of financial services, and other restrictions against designated persons and entities listed by the UN.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign-incorporated entity may not serve Mauritius residents remotely without obtaining a VASP license from the FSC under the VAITOS Act 2021, which requires a locally incorporated entity, minimum stated capital, comprehensive AML/CFT programs, and full Travel Rule compliance.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?