Custodial wallet / SaaS in Malaysia
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Malaysia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Must register as a Recognised Market Operator (RMO/DAX) with the Securities Commission Malaysia (SC) — custody is included under DAX registration (my.licensing.vasp, my.licensing.custody)
- Customer asset segregation required under DAX registration rules (my.licensing.custody)
- Must comply with AMLATFPUAA 2001 and BNM's AML/CFT and Targeted Financial Sanctions for Financial Institutions Policy Document (my.aml.anti-money-laundering-anti-terrorism-financing-and, my.aml.amlcft-and-targeted-financial-sanctions)
- Must comply with SC's Guidelines on Recognised Markets and Guidelines on Digital Assets for AML/CFT (my.aml.guidelines-on-recognised-markets-sc, my.aml.capital-markets-and-services-act)
- Customer Identification and Verification required: name, address, DOB, nationality, ID document, contact info for individuals (my.aml.customer-identification-and-verification, my.aml.obtain-and-verify-the-identity)
- For legal entity customers, obtain legal name, legal form, proof of existence, address, directors, shareholders, beneficial owners, governing documents (my.aml.for-legal-entitiescorporate-customers-obtain)
- Beneficial ownership identification required — look through to ultimate natural person(s) (my.aml.beneficial-ownership-identify-and-verify)
- Purpose and intended nature of business relationship must be documented (my.aml.purpose-and-intended-nature-of)
- Source of funds/wealth information required for higher-risk customers (my.aml.source-of-fundswealth-for-higher-risk)
- Ongoing monitoring of business relationships and transactions required with periodic CDD updates (my.aml.ongoing-monitoring-continuously-monitor-the)
- Enhanced Due Diligence for PEPs, high-risk jurisdictions, and customers using anonymity-enhancing products/services (my.aml.politically-exposed-persons-peps-implement, my.aml.high-risk-customers-peps-customers-from, my.aml.high-risk-productsservices-products-or-services)
- Non-face-to-face CDD measures required (multi-factor authentication, video verification, cross-referencing) (my.aml.non-face-to-face-nff-customers-given-the)
- Safekeeping/administration of digital currencies is a designated AML activity under AMLATFPUAA 2001 (my.aml.safekeeping-andor-administration-of-digital)
- Suspicious Transaction Reports (STRs) must be filed with BNM's FIU (my.aml.bank-negara-malaysia-bnm, my.aml.role-the-central-bank-of)
Key Restrictions
- Must obtain DAX (RMO) registration with SC — only 5 operators have been registered, process is strict and takes 6-12 months (my.licensing.vasp)
- Minimum MYR 5 million (~$1.1M USD) shareholders' funds required (my.licensing.exchange)
- Custody is not a standalone license — it is bundled within DAX registration (my.licensing.custody)
- Customer digital assets must be segregated from the operator's own assets (my.licensing.custody)
- Local incorporation in Malaysia is required — no remote foreign operation appears permitted without SC registration (my.licensing.vasp, my.enforcement.entity-targeted-binance-holdings-limited)
- White-label clients (SaaS customers) who are themselves VASPs may need separate AML/CDD obligations — unclear from facts how obligations split between SaaS provider and white-label client
Key Risks
- SC has an active enforcement record — Binance and CZ were issued cease-and-desist orders for operating without registration; unregistered platforms face similar action (my.enforcement.entity-targeted-binance-holdings-limited, my.enforcement.entity-targeted-various-unauthorized-digital)
- SC is described as 'strict and slow' on registrations — only 5 operators have been registered to date, creating a bottleneck risk (my.licensing.vasp)
- No dedicated custodial wallet/custody-as-a-service framework — custody is treated as part of DAX registration, which is designed for exchange operators, creating structural ambiguity for pure custody plays (my.licensing.custody, my.licensing.vasp)
- AML obligations for SaaS-model — unclear whether the SaaS provider or the white-label end-client bears CDD obligations for end users; regulatory gap risk (inferred from operating model vs. regulatory framework)
- Proof-of-reserves and insurance requirements not explicitly addressed in provided facts — may be unregulated or unclear
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
SC Malaysia — Digital asset exchange registration, IEO oversight, cease-and-desist enforcement
Capital Markets and Services (Prescription of Securities) Order 2019 (2019) — Digital currency and digital token as prescribed securities
Guidelines on Digital Assets (2020) — DAX operator requirements
VASP: Recognized Market Operator (RMO) — DAX registration with SC. Only 5 operators registered (Luno, Tokenize, MX Global, Sinegy, Hata). SC strict and slow on registrations. 6-12 months.
CUSTODY: Included under DAX registration; customer asset segregation required
EXCHANGE: DAX registration with SC — MYR 5M (~$1.1M USD) minimum shareholders' funds. SC issued cease-and-desist orders against unregistered operators (incl. Binance 2021). IEO framework requires separate SC approval.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLATFPUAA 2001)
AML/CFT and Targeted Financial Sanctions for Financial Institutions (AML/CFT TFS for FIs) Policy Document (BNM Policy Document): Issued by Bank Negara Malaysia, this comprehensive policy document provides detailed guidance and requirements for reporting institutions to comply with AMLATFPUAA 2001. This document has specific sections/appendices applicable to "Digital Currencies" or "Virtual Assets."
Capital Markets and Services Act 2007 (CMSA): For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.
Guidelines on Recognised Markets (SC Guidelines): Specifically for operators of recognised markets, including DAX, detailing operational, conduct, and AML/CFT requirements.
Role: The central bank of Malaysia and the primary regulator for AML/CFT compliance across all reporting institutions, including VASPs, under the AMLATFPUAA 2001. BNM also houses the Financial Intelligence Unit (FIU) responsible for receiving Suspicious Transaction Reports (STRs).
Role: Regulates the capital markets in Malaysia. The SC specifically licenses and oversees Digital Asset Exchanges (DAX) and other entities involved in the offering or trading of digital assets that are classified as securities. SC-regulated entities must comply with both SC-specific AML/CFT requirements and the broader BNM framework.
Safekeeping and/or administration of digital currencies or instruments enabling control over digital currencies.
Customer Identification and Verification:
Obtain and verify the identity of individual customers (name, address, date of birth, nationality, identification document details, contact information).
For legal entities/corporate customers, obtain and verify: legal name, legal form, proof of existence (e.g., certificate of incorporation), address of registered office, names of directors/partners/trustees, details of shareholders and beneficial owners, and constitution/governing documents.
Beneficial Ownership: Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.
Purpose and Intended Nature of Business Relationship: Understand the rationale behind the customer's request to use the VASP's services and the anticipated level and type of activity.
Source of Funds/Wealth: For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.
Non-Face-to-Face (NFF) Customers: Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.
Politically Exposed Persons (PEPs): Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.
High-Risk Customers: PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.
High-Risk Products/Services: Products or services that facilitate anonymity (e.g., privacy coins, mixing services).
Entity Targeted: Binance Holdings Limited and its CEO, Changpeng Zhao (CZ). Violation Type: Operating a Digital Asset Exchange (DAX) without registration/license, which is a violation under the Capital Markets and Services Act 2007. The SC considers digital assets as securities, and operating a platform for trading them requires authorization. Penalty Amount: No explicit monetary fine was announced at the time of the public reprimand. The penalties were operational: a public reprimand, an order to cease all operations in Malaysia, disable access to its website and mobile applications, and cease all media and marketing activities targeting Malaysian investors. Outcome: Binance was forced to shut down its direct operations in Malaysia. Malaysian users were advised to withdraw their funds. The action led Binance to later pursue a compliant pathway to re-enter the Malaysian market by acquiring a stake in and partnering with a licensed local Digital Asset Exchange (DAX), MX Global, demonstrating the effectiveness of the SC's enforcement in driving regulatory compliance.
Entity Targeted: Various unauthorized digital asset platforms, investment schemes involving crypto, and individuals promoting them. (Specific names are too numerous to list here, but are updated frequently). Violation Type: Operating or promoting unauthorized investment schemes, digital asset exchanges, or services without the necessary licenses or approvals from the SC Malaysia. Penalty Amount: Typically no specific monetary penalty is announced publicly for being added to the alert list. The "penalty" is a public warning, which often leads to the platform being unable to operate effectively in Malaysia and subsequent cessation of operations or blocking of access. Outcome: Public awareness is raised, and investors are warned against dealing with these entities. This often leads to reduced or ceased operations for the targeted entities within Malaysia.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators must obtain DAX (RMO) registration with the Securities Commission Malaysia, which bundles custody under the exchange framework; the operator must be locally incorporated, maintain MYR 5M in shareholders' funds, segregate customer assets, and comply with extensive AML/CFT obligations under AMLATFPUAA 2001 and BNM/SC guidelines, though the framework does not explicitly address custody-as-a-service or the SaaS/white-label split of AML duties.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?