Custodial wallet / SaaS in Mexico
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Mexico without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- AML/KYC mandatory for all providers serving Mexican residents under the Federal AML Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita)
- Virtual asset operations by non-financial entities classified as 'vulnerable activities', requiring KYC, internal policies, transaction monitoring, and reporting to the Financial Intelligence Unit (FIU)
- Reporting of transactions above thresholds to FIU and Ministry of Finance (SHCP)
- SaaS provider and white-label client must each assess their own AML/CTF obligations; the SaaS provider may be subject to AML obligations as a non-financial entity offering custody services to Mexican residents
Key Restrictions
- No specific custody license or qualified-custodian regime exists for non-financial custodial wallet providers
- No license or registration needed for non-financial entities offering custody services to the public
- Banxico prohibits financial institutions (banks, fintechs) from offering client-facing custody services — only internal operations allowed with prior authorization
- No Banxico approvals have been granted since the 2019 secondary rules, with fines up to $47,000 for violations
- Security tokens (tokenized securities) fall under Securities Market Law, adding a separate regulatory layer
- Certain stablecoins may fall under the Fintech Law if the issuer receives, manages, and safeguards public funds with redemption/transfer capabilities
Key Risks
- Regulatory ambiguity — no formal classification of custodial wallet providers or dedicated custody rules creates uncertainty for both SaaS providers and white-label clients
- Enforcement risk — Mexico has seen U.S./international enforcement actions for cryptocurrency-based money laundering linked to cartels, raising AML compliance scrutiny
- Banxico has not granted any approvals since 2019 secondary rules, signaling a potentially restrictive enforcement posture even where licensing frameworks exist
- Non-financial custody providers operate in a gap: not subject to fintech/banking licensing but still bound by AML vulnerable-activity obligations without clear regulatory guidance
- White-label client AML responsibility allocation is unclear — both the SaaS provider and the client could face obligations, increasing compliance complexity
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges, Custody Providers, Payment Processors (Non-Financial Entities): No license or registration needed; services can be offered to the public if not reserved for regulated entities.
AML/CTF Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita): Classifies virtual asset operations by non-financial entities as vulnerable activities, requiring KYC, internal policies, transaction monitoring, and reporting to the Financial Intelligence Unit (FIU) for transactions over ~$58,000 MXN (645 UMAs) per client in six months.
AML/KYC: Mandatory for all providers serving Mexican residents, including:
Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera): Defines virtual assets and grants Banxico regulatory powers but excludes non-financial custody from licensing.
Banxico: Regulates virtual assets for financial institutions; authorizes internal operations but bans client-facing custody.
Circular 4/2019 (Banxico): Limits financial entities to internal virtual asset operations with prior approval; bans public-facing services.
No approvals granted by Banxico post-2019 secondary rules, with fines up to $47,000 for violations.
Security tokens: Those representing or underlying securities (e.g., tokenized stocks or bonds) fall under Securities Market Law scope.
Certain stablecoins: If issuers receive, manage, safeguard public funds, and enable redemption/transfer, they may fall under the Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera, March 2018).
Financial Intelligence Unit (FIU) and Ministry of Finance and Public Credit (SHCP): Enforce AML/CTF reporting for transactions above thresholds; SHCP oversees broader AML/CTF implementation.
Federal AML Law (as amended 2018): Covers virtual asset transactions. https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPIORPI_180818.pdf
No public process details for non-financial VASPs, as none required.
Local Presence: No explicit requirement, but company setup (if incorporating) needs Mexican notary, share certificates, corporate books, tax registry (RFC), e-signature, foreign investment registry (if applicable), and bank account. Office rental may aid compliance.
Capital: No specific minimum capital mandates in search results for virtual asset providers.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — non-financial custodial wallet/SaaS providers may serve Mexican residents without a specific custody license, but must comply with AML/KYC obligations as vulnerable-activity reporters to the FIU, and face regulatory ambiguity around segregation, insurance, and proof-of-reserves requirements.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?