Custodial wallet / SaaS in Oman
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Oman with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) under Royal Decree No. 30/2016 and Ministerial Decision No. 63/2016 — identify and verify all customers (name, address, date of birth, nationality, unique ID), including obtaining company name, legal form, address, proof of incorporation, and directors for legal-entity clients.
- Beneficial ownership identification — identify and verify natural persons who ultimately own or control the customer (typically 25%+ ownership threshold).
- Purpose and intended nature of the business relationship — gather information on anticipated activity, source of funds, and purpose of virtual asset transactions.
- Ongoing transaction monitoring — scrutinize transactions throughout the business relationship for consistency with customer risk profile.
- PEP screening — implement procedures to determine if customer or beneficial owner is a Politically Exposed Person; apply Enhanced Due Diligence (EDD) including senior management approval for PEP relationships.
- Sanctions screening — screen customers and transactions against national and international sanctions lists (e.g., UN, OFAC).
- Enhanced Due Diligence (EDD) for higher-risk categories (non-face-to-face, complex ownership structures, high-value transactions, cross-border correspondent virtual asset relationships, high-risk jurisdictions).
- Suspicious Transaction Report (STR) filing — obligation to promptly file STRs with the Oman Financial Intelligence Unit (OMAFIU) when funds are suspected to be proceeds of crime or related to terrorism financing.
- No tipping-off — prohibition on disclosing to customers or third parties that an STR has been filed or an investigation is underway.
- Recordkeeping — maintain transaction records (origin/destination, amount, date, type) and CDD records for the legally prescribed retention period.
- Appointment of a Compliance Officer and AML/CFT internal policies, procedures, and controls (risk-based approach, independent audit function, employee training, and screening).
Key Restrictions
- Must operate under the CMA Virtual Assets Regulatory Framework (issued November 2023) and obtain a license from the Capital Market Authority to act as a VASP in Oman.
- Custodial wallet/SaaS providers are effectively acting as VASPs under the CMA framework — no specific 'custody license' exists; the general VASP license applies.
- CBO-supervised financial institutions (banks, payment service providers) are prohibited from engaging in or facilitating cryptocurrency transactions under the CBO's ongoing advisories — the SaaS operator cannot rely on a local bank partner for crypto-related banking activity.
- No specific segregation-of-client-assets, insurance/bonding, proof-of-reserves, cold-storage mandates, or qualified-custodian definitions exist under current Omani law — the operator must define its own safeguard framework.
- Local entity required — the CMA framework implies a licensed Omani entity with physical presence to operate as a VASP.
- If the SaaS operator's tokens or arrangements constitute 'investment contracts' or securities-like rights, the CMA's Capital Market Law may impose additional securities-level requirements.
Key Risks
- Regulatory ambiguity — the CMA framework is newly issued (Nov 2023) and its interpretation for custodial wallet/SaaS models is untested; no licensing precedents or guidance exist yet for this specific operating model.
- CBO vs CMA tension — CBO advisories prohibit regulated financial institutions from engaging with crypto, while the CMA framework permits VASPs. A custodial wallet operator may struggle to access banking services.
- No asset segregation or insurance rules — in the absence of prescribed custody safeguards, the operator bears full design risk and may face heightened scrutiny from the CMA for consumer/investor protection gaps.
- SaaS liability chain — the white-label client is the direct customer-facing entity, but the SaaS operator handles keys. Under AML/CFT law, both parties could be treated as VASPs with joint AML obligations, creating compliance coordination risk.
- FATF-driven enforcement risk — Oman is a MENAFATF member subject to FATF Recommendation 15; any gaps in VASP regulation could trigger accelerated enforcement or remedial actions against unlicensed operators.
- No publicly known pending legislation for digital asset custody specifically — the framework landscape may shift rapidly without clear transitional provisions.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
CMA Announcement: CMA Oman News - Issuance of Virtual Assets Regulatory Framework (This link might change or be archived; search CMA Oman for "Virtual Assets Regulatory Framework 2023")
Capital Market Authority (CMA) Virtual Assets Regulatory Framework (2023): The CMA issued a comprehensive regulatory framework for virtual assets in July 2023. This framework aims to regulate the activities of VASPs, including issuance, listing, and trading of virtual assets, ensuring compliance with international AML/CFT standards. It covers licensing requirements, corporate governance, market conduct, and crucial for this discussion, AML/CFT obligations.
Central Bank of Oman (CBO): The CBO has previously issued warnings regarding the risks of virtual currencies. However, in parallel with the CMA, it has also been working on developing its own regulatory framework for digital assets, particularly concerning digital currencies and payments.
Central Bank of Oman Official Website: https://www.cbo.gov.om/ - While specific crypto regulation is absent, the site provides information on regulated financial activities, none of which currently include virtual asset custody. Public warnings have been widely reported by news outlets referencing the CBO's stance.
No specific license exists. Oman does not currently have a licensing regime for digital asset custody providers. Financial institutions operating under CBO licenses are generally advised against involvement with virtual currencies.
Not applicable. Since there is no framework for licensing crypto custodians, there are no specific rules regarding the segregation of client assets for such services.
Not applicable. Similarly, in the absence of a licensing regime, there are no specific insurance or bonding requirements for crypto custody providers.
Not applicable. There are no specific mandates for cold storage, as the regulatory framework for crypto custody does not exist.
No definition exists. Oman's regulatory landscape does not currently define "qualified custodians" in the context of digital assets.
Represents an Investment Contract: The primary purpose of the token issuance is to raise capital from investors who contribute funds with the expectation of generating profit or return.
Royal Decree No. 30/2016 on Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT Law), amended by Royal Decree No. 112/2020: This is the foundational law for AML/CFT in Oman. While it predates explicit crypto regulations, its broad definitions of "funds," "financial institutions," and "financial activities" are intended to encompass new technologies and virtual assets once they fall under a regulated scope. VASPs, once licensed, will be designated as financial institutions or designated non-financial businesses and professions (DNFBPs) under this law.
Oman's Adherence to FATF Standards: Oman is a member of the Middle East and North Africa Financial Action Task Force (MENAFATF) and is committed to implementing the recommendations of the Financial Action Task Force (FATF). FATF Recommendation 15 specifically addresses new technologies, urging countries to regulate and supervise VASPs for AML/CFT purposes, including sanctions compliance.
Royal Decree No. 30/2016 (Law on Combating Money Laundering and Terrorism Financing): This is the foundational AML/CFT law in Oman, outlining the obligations for financial institutions and designated non-financial businesses and professions (DNFBPs).
Ministerial Decision No. 63/2016 (Implementing Regulations of the Law on Combating Money Laundering and Terrorism Financing): This decision provides detailed regulations and guidelines for implementing Royal Decree 30/2016.
Identification and Verification (ID&V) of Customers:
Beneficial Ownership Identification:
Understanding the Purpose and Intended Nature of the Business Relationship:
Conducting ongoing scrutiny of transactions undertaken throughout the course of the business relationship to ensure consistency with the VASP's knowledge of the customer, their business, and risk profile.
Politically Exposed Persons (PEPs):
Screening customers and transactions against national and international sanctions lists (e.g., UN, OFAC).
Enhanced Due Diligence (EDD):
Obligation to Report: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are proceeds of a criminal activity or are related to terrorism financing, it must promptly file a Suspicious Transaction Report (STR) with the Oman Financial Intelligence Unit (OMAFIU).
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR is being, or has been, submitted, or that an investigation is being conducted.
Transaction Records: All records of domestic and international transactions, including information on the origin and destination of the funds/virtual assets, transaction amount, date, and type.
CDD Records: Records of all information obtained through the CDD process (identification data, beneficial ownership information, business relationship purpose, etc.).
CBO Warnings against Crypto (Ongoing/Recurring)
CMA Issuance of Virtual Asset Regulatory Framework
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers may operate in Oman only by obtaining a VASP license under the CMA's November 2023 Virtual Assets Regulatory Framework, with no specific custody license, asset segregation, or insurance rules existing; the operator faces the tension of CBO prohibitions on crypto facilitation by regulated financial institutions, and AML obligations under Royal Decree No. 30/2016 attach to both the SaaS provider and its white-label clients as VASPs.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?