← Regulations / Nauru / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Nauru

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Nauru with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) under AML/CTF Act 2019 — identify and verify identity of individuals (govt-issued ID, proof of address) and legal entities (name, legal form, proof of existence, senior management identity).
  • Beneficial ownership identification — identify and verify beneficial owner(s) of customers, including understanding ownership and control structure of legal persons.
  • Ongoing due diligence — monitor transactions throughout the business relationship to ensure consistency with customer risk profile.
  • Enhanced Due Diligence (EDD) — required for high-risk customers including PEPs, cross-border relationships, and complex transactions.
  • Suspicious Transaction Reporting (STR) — immediately report any transaction suspected of ML/TF to the Nauru Financial Intelligence Unit (NFIU).
  • No tipping-off — prohibition on disclosing STR filings to customers or third parties.
  • Record-keeping — retain CDD records, transaction records, and STR copies for at least 5 years after relationship ends or transaction date.
  • Employee training — provide regular training on STR obligations and suspicious activity identification.
  • These obligations apply to the custodial wallet SaaS operator as a VASP. The operator cannot delegate AML/CFT compliance to white-label clients — the SaaS provider must implement its own CDD and monitoring.

Key Restrictions

  • No dedicated custody-license or qualified-custodian framework identified for digital assets — the NFSA regulates securities under pre-existing securities law, and if custody tokens are deemed securities, the operator may need licensing as a financial service provider (broker/dealer/investment adviser) under NFSA.
  • If the custodial wallet involves holding tokens that are classified as securities (e.g., profit-sharing, governance, asset-backed tokens, or investment-contract tokens), the platform may need to be licensed as a securities exchange or trading facility, and the operator may need to comply with prospectus/registration requirements.
  • No statutory segregation, insurance, or proof-of-reserves rules specifically for digital asset custody identified in Nauru law — these would need to be contractually arranged.
  • The AML/CTF Act 2017 and AML/CTF Act 2019 apply to VASPs including custodial wallet providers; compliance is mandatory regardless of the nature of the assets held.

Key Risks

  • Regulatory ambiguity — Nauru has not enacted a bespoke digital-asset custody framework; the application of securities law to custodial wallets is untested and uncertain.
  • Small-jurisdiction risk — Nauru has very limited regulatory capacity and enforcement resources, creating uncertainty about supervisory expectations and practical compliance assistance.
  • Limited public disclosure — enforcement actions are unlikely to be publicly reported, making it difficult to gauge regulatory posture.
  • APG/AML scrutiny — Nauru is under APG mutual evaluation; any perceived AML/CFT deficiencies in the VASP sector could trigger international reputational or correspondent-banking risks.
  • No insurance/segregation rules — operators have no statutory safe harbor for custodial assets; client loss or bankruptcy could expose the operator to civil liability.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Nauru Financial Services Authority Act 2017: Establishes the NFSA.

licensing 40% confidence

Securities Act (e.g., Securities Act 1974): Defines what constitutes a "security." Finding a publicly accessible, definitive current version of Nauru's Securities Act is challenging, but its existence is implied by the NFSA's mandate.

licensing 40% confidence

Security Tokens: Any token that explicitly represents a traditional security (e.g., equity in a company, debt, real estate ownership, shares in an investment fund).

licensing 40% confidence

Licensing: Individuals or entities involved in the issuance, distribution, or advising on securities (including security tokens) may need to be licensed by the NFSA as financial service providers (e.g., brokers, dealers, investment advisers).

licensing 40% confidence

AML/CTF Compliance: All token issuers and Virtual Asset Service Providers (VASPs) would be subject to Nauru's AML/CTF Act 2017. This includes customer due diligence (CDD), transaction monitoring, and suspicious transaction reporting.

licensing 40% confidence

Licensed Platforms: Platforms (exchanges) facilitating the trading of security tokens would likely need to be licensed by the NFSA as securities exchanges or trading facilities.

aml 60% confidence

Anti-Money Laundering and Counter-Terrorist Financing Act 2019: This Act sets out the preventive measures for financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs), including customer due diligence, suspicious transaction reporting, and record-keeping. It is the most direct piece of legislation for prudential AML/CFT obligations.

aml 60% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of customers, including understanding the ownership and control structure of legal persons.

aml 60% confidence

Ongoing Due Diligence: Conduct ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile.

aml 60% confidence

Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions (e.g., politically exposed persons (PEPs), cross-border correspondent relationships, complex transactions).

aml 60% confidence

Reporting Obligation: Immediately report any transaction (or attempted transaction) that is suspected to be related to money laundering, terrorist financing, or other criminal activity.

aml 60% confidence

No Tipping-Off: Prohibit the VASP, its directors, officers, or employees from disclosing to the customer or third parties that an STR has been filed (tipping-off).

aml 60% confidence

Training: Provide regular training to employees on their STR obligations and how to identify suspicious activities.

aml 60% confidence

Customer Records: All records obtained through CDD, including identification data, beneficial ownership information, and account files.

aml 60% confidence

Transaction Records: Records of all domestic and international transactions, sufficient to reconstruct individual transactions.

aml 60% confidence

STRs: Copies of all suspicious transaction reports filed.

aml 60% confidence

Retention Period: Records must typically be retained for at least five (5) years after the business relationship has ended or after the date of an occasional transaction.

aml 60% confidence

Nauru Financial Intelligence Unit (NFIU): The NFIU is the central agency responsible for receiving, analyzing, and disseminating financial intelligence reports, including STRs, and for overseeing compliance with AML/CFT obligations across relevant sectors.

enforcement 20% confidence

Small Jurisdiction: Nauru is one of the world's smallest nations. Its financial sector is very limited, and the scale of cryptocurrency activity and the potential for "significant" violations (in terms of public reporting) is extremely low compared to larger economies.

enforcement 20% confidence

Limited Public Disclosure: Even if minor enforcement actions occurred, small island nations often do not have robust public disclosure frameworks for financial enforcement to the same extent as major financial hubs.

enforcement 20% confidence

Regulatory Capacity: While Nauru has a financial intelligence unit (FIU) and participates in global anti-money laundering (AML) and combating the financing of terrorism (CFT) efforts (e.g., through the Asia/Pacific Group on Money Laundering - APG), its regulatory capacity and enforcement resources are constrained.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators may serve Nauru residents subject to AML/CFT registration and obligations under the AML/CTF Act 2017 & 2019, but the jurisdiction lacks a dedicated digital-asset custody framework, and if held tokens constitute securities under Nauru's Securities Act, additional NFSA licensing, prospectus, and exchange-trading requirements may apply.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?