Custodial wallet / SaaS in Nauru
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Nauru with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) under AML/CTF Act 2019 — identify and verify identity of individuals (govt-issued ID, proof of address) and legal entities (name, legal form, proof of existence, senior management identity).
- Beneficial ownership identification — identify and verify beneficial owner(s) of customers, including understanding ownership and control structure of legal persons.
- Ongoing due diligence — monitor transactions throughout the business relationship to ensure consistency with customer risk profile.
- Enhanced Due Diligence (EDD) — required for high-risk customers including PEPs, cross-border relationships, and complex transactions.
- Suspicious Transaction Reporting (STR) — immediately report any transaction suspected of ML/TF to the Nauru Financial Intelligence Unit (NFIU).
- No tipping-off — prohibition on disclosing STR filings to customers or third parties.
- Record-keeping — retain CDD records, transaction records, and STR copies for at least 5 years after relationship ends or transaction date.
- Employee training — provide regular training on STR obligations and suspicious activity identification.
- These obligations apply to the custodial wallet SaaS operator as a VASP. The operator cannot delegate AML/CFT compliance to white-label clients — the SaaS provider must implement its own CDD and monitoring.
Key Restrictions
- No dedicated custody-license or qualified-custodian framework identified for digital assets — the NFSA regulates securities under pre-existing securities law, and if custody tokens are deemed securities, the operator may need licensing as a financial service provider (broker/dealer/investment adviser) under NFSA.
- If the custodial wallet involves holding tokens that are classified as securities (e.g., profit-sharing, governance, asset-backed tokens, or investment-contract tokens), the platform may need to be licensed as a securities exchange or trading facility, and the operator may need to comply with prospectus/registration requirements.
- No statutory segregation, insurance, or proof-of-reserves rules specifically for digital asset custody identified in Nauru law — these would need to be contractually arranged.
- The AML/CTF Act 2017 and AML/CTF Act 2019 apply to VASPs including custodial wallet providers; compliance is mandatory regardless of the nature of the assets held.
Key Risks
- Regulatory ambiguity — Nauru has not enacted a bespoke digital-asset custody framework; the application of securities law to custodial wallets is untested and uncertain.
- Small-jurisdiction risk — Nauru has very limited regulatory capacity and enforcement resources, creating uncertainty about supervisory expectations and practical compliance assistance.
- Limited public disclosure — enforcement actions are unlikely to be publicly reported, making it difficult to gauge regulatory posture.
- APG/AML scrutiny — Nauru is under APG mutual evaluation; any perceived AML/CFT deficiencies in the VASP sector could trigger international reputational or correspondent-banking risks.
- No insurance/segregation rules — operators have no statutory safe harbor for custodial assets; client loss or bankruptcy could expose the operator to civil liability.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Nauru Financial Services Authority Act 2017: Establishes the NFSA.
Securities Act (e.g., Securities Act 1974): Defines what constitutes a "security." Finding a publicly accessible, definitive current version of Nauru's Securities Act is challenging, but its existence is implied by the NFSA's mandate.
Security Tokens: Any token that explicitly represents a traditional security (e.g., equity in a company, debt, real estate ownership, shares in an investment fund).
Licensing: Individuals or entities involved in the issuance, distribution, or advising on securities (including security tokens) may need to be licensed by the NFSA as financial service providers (e.g., brokers, dealers, investment advisers).
AML/CTF Compliance: All token issuers and Virtual Asset Service Providers (VASPs) would be subject to Nauru's AML/CTF Act 2017. This includes customer due diligence (CDD), transaction monitoring, and suspicious transaction reporting.
Licensed Platforms: Platforms (exchanges) facilitating the trading of security tokens would likely need to be licensed by the NFSA as securities exchanges or trading facilities.
Anti-Money Laundering and Counter-Terrorist Financing Act 2019: This Act sets out the preventive measures for financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs), including customer due diligence, suspicious transaction reporting, and record-keeping. It is the most direct piece of legislation for prudential AML/CFT obligations.
Identification and Verification:
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of customers, including understanding the ownership and control structure of legal persons.
Ongoing Due Diligence: Conduct ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions (e.g., politically exposed persons (PEPs), cross-border correspondent relationships, complex transactions).
Reporting Obligation: Immediately report any transaction (or attempted transaction) that is suspected to be related to money laundering, terrorist financing, or other criminal activity.
No Tipping-Off: Prohibit the VASP, its directors, officers, or employees from disclosing to the customer or third parties that an STR has been filed (tipping-off).
Training: Provide regular training to employees on their STR obligations and how to identify suspicious activities.
Customer Records: All records obtained through CDD, including identification data, beneficial ownership information, and account files.
Transaction Records: Records of all domestic and international transactions, sufficient to reconstruct individual transactions.
STRs: Copies of all suspicious transaction reports filed.
Retention Period: Records must typically be retained for at least five (5) years after the business relationship has ended or after the date of an occasional transaction.
Nauru Financial Intelligence Unit (NFIU): The NFIU is the central agency responsible for receiving, analyzing, and disseminating financial intelligence reports, including STRs, and for overseeing compliance with AML/CFT obligations across relevant sectors.
Small Jurisdiction: Nauru is one of the world's smallest nations. Its financial sector is very limited, and the scale of cryptocurrency activity and the potential for "significant" violations (in terms of public reporting) is extremely low compared to larger economies.
Limited Public Disclosure: Even if minor enforcement actions occurred, small island nations often do not have robust public disclosure frameworks for financial enforcement to the same extent as major financial hubs.
Regulatory Capacity: While Nauru has a financial intelligence unit (FIU) and participates in global anti-money laundering (AML) and combating the financing of terrorism (CFT) efforts (e.g., through the Asia/Pacific Group on Money Laundering - APG), its regulatory capacity and enforcement resources are constrained.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators may serve Nauru residents subject to AML/CFT registration and obligations under the AML/CTF Act 2017 & 2019, but the jurisdiction lacks a dedicated digital-asset custody framework, and if held tokens constitute securities under Nauru's Securities Act, additional NFSA licensing, prospectus, and exchange-trading requirements may apply.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?