← Regulations / Mexico / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Mexico

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Mexico without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • AML/KYC mandatory for all providers serving Mexican residents under the Federal AML Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita)
  • Virtual asset operations by non-financial entities classified as 'vulnerable activities', requiring KYC, internal policies, transaction monitoring, and reporting to the Financial Intelligence Unit (FIU)
  • Reporting of transactions above thresholds to FIU and Ministry of Finance (SHCP)
  • SaaS provider and white-label client must each assess their own AML/CTF obligations; the SaaS provider may be subject to AML obligations as a non-financial entity offering custody services to Mexican residents

Key Restrictions

  • No specific custody license or qualified-custodian regime exists for non-financial custodial wallet providers
  • No license or registration needed for non-financial entities offering custody services to the public
  • Banxico prohibits financial institutions (banks, fintechs) from offering client-facing custody services — only internal operations allowed with prior authorization
  • No Banxico approvals have been granted since the 2019 secondary rules, with fines up to $47,000 for violations
  • Security tokens (tokenized securities) fall under Securities Market Law, adding a separate regulatory layer
  • Certain stablecoins may fall under the Fintech Law if the issuer receives, manages, and safeguards public funds with redemption/transfer capabilities

Key Risks

  • Regulatory ambiguity — no formal classification of custodial wallet providers or dedicated custody rules creates uncertainty for both SaaS providers and white-label clients
  • Enforcement risk — Mexico has seen U.S./international enforcement actions for cryptocurrency-based money laundering linked to cartels, raising AML compliance scrutiny
  • Banxico has not granted any approvals since 2019 secondary rules, signaling a potentially restrictive enforcement posture even where licensing frameworks exist
  • Non-financial custody providers operate in a gap: not subject to fintech/banking licensing but still bound by AML vulnerable-activity obligations without clear regulatory guidance
  • White-label client AML responsibility allocation is unclear — both the SaaS provider and the client could face obligations, increasing compliance complexity

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Exchanges, Custody Providers, Payment Processors (Non-Financial Entities): No license or registration needed; services can be offered to the public if not reserved for regulated entities.

licensing 20% confidence

AML/CTF Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita): Classifies virtual asset operations by non-financial entities as vulnerable activities, requiring KYC, internal policies, transaction monitoring, and reporting to the Financial Intelligence Unit (FIU) for transactions over ~$58,000 MXN (645 UMAs) per client in six months.

licensing 20% confidence

AML/KYC: Mandatory for all providers serving Mexican residents, including:

licensing 20% confidence

Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera): Defines virtual assets and grants Banxico regulatory powers but excludes non-financial custody from licensing.

licensing 20% confidence

Banxico: Regulates virtual assets for financial institutions; authorizes internal operations but bans client-facing custody.

licensing 20% confidence

Circular 4/2019 (Banxico): Limits financial entities to internal virtual asset operations with prior approval; bans public-facing services.

licensing 20% confidence

No approvals granted by Banxico post-2019 secondary rules, with fines up to $47,000 for violations.

licensing 60% confidence

Security tokens: Those representing or underlying securities (e.g., tokenized stocks or bonds) fall under Securities Market Law scope.

licensing 60% confidence

Certain stablecoins: If issuers receive, manage, safeguard public funds, and enable redemption/transfer, they may fall under the Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera, March 2018).

licensing 20% confidence

Financial Intelligence Unit (FIU) and Ministry of Finance and Public Credit (SHCP): Enforce AML/CTF reporting for transactions above thresholds; SHCP oversees broader AML/CTF implementation.

licensing 60% confidence

Federal AML Law (as amended 2018): Covers virtual asset transactions. https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPIORPI_180818.pdf

licensing 20% confidence

No public process details for non-financial VASPs, as none required.

licensing 20% confidence

Local Presence: No explicit requirement, but company setup (if incorporating) needs Mexican notary, share certificates, corporate books, tax registry (RFC), e-signature, foreign investment registry (if applicable), and bank account. Office rental may aid compliance.

licensing 20% confidence

Capital: No specific minimum capital mandates in search results for virtual asset providers.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — non-financial custodial wallet/SaaS providers may serve Mexican residents without a specific custody license, but must comply with AML/KYC obligations as vulnerable-activity reporters to the FIU, and face regulatory ambiguity around segregation, insurance, and proof-of-reserves requirements.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?