← Regulations / Peru / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Peru

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Peru with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • VASPs (including custodial wallet providers) are designated obliged entities under Resolución SBS N° 893-2019 and must implement a full AML/CFT compliance program.
  • Mandatory Customer Due Diligence (CDD): identify and verify customers (individuals: national ID, name, DOB, address; legal entities: incorporation docs, directors, legal representative).
  • Beneficial ownership identification and verification required for all customers.
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, high-value virtual asset transactions, and unusual patterns.
  • Ongoing transaction monitoring to detect unusual or suspicious patterns.
  • Suspicious Transaction Reports (ROS) must be filed with UIF-Perú.
  • Record-keeping obligations: maintain transaction and customer records.
  • Must appoint a compliance officer and conduct a comprehensive ML/TF risk assessment.
  • Must establish internal policies, procedures, and training programs.
  • Simplified CDD permitted for lower-risk situations only.

Key Restrictions

  • No specific crypto custody license exists — the operator registers as a regular company under general commercial law.
  • If custody services evolve to offer interest-bearing accounts, lending, or other financial products, they may trigger SBS scrutiny and traditional financial licensing requirements.
  • If fiat conversion or money transmission services are bundled with the custodial wallet offering, the operator may need to comply with EEDE (Electronic Money Issuing Company) regulations under the SBS.
  • No specific capital requirements for VASPs beyond general company formation capital (e.g., S.A.C., S.A.A.).
  • While VASPs are recognized as obliged entities for AML purposes, no qualified-custodian regime, segregation, insurance, or proof-of-reserves rules exist for crypto custody under Peruvian law.

Key Risks

  • Regulatory ambiguity: no dedicated VASP/custody licensing framework means enforcement posture could shift rapidly, especially if FATF pushes for tighter supervision.
  • SBS reclassification risk: custodial services offering yield, lending, or fiat on/off ramps could be retroactively deemed financial intermediation, triggering high capital requirements and SBS licensing.
  • No segregation or insurance requirements create operational risk — client funds are not legally protected in insolvency scenarios.
  • The white-label SaaS model creates shared AML liability risk: unclear whether the SaaS provider, the white-label client, or both must file ROS and maintain CDD records.
  • UIF-Perú has limited public enforcement precedent specifically against custodial wallet providers, creating uncertainty about inspection cadence and penalty severity.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

No specific Licensing Regime for VASPs: There is no dedicated law requiring crypto exchanges, custody providers, or crypto-focused payment processors to obtain a specific "virtual asset license" from a regulatory body like the Superintendencia de Banca, Seguros y AFP (SBS) or the Banco Central de Reserva del Perú (BCRP).

licensing 60% confidence

AML/CTF Obligations for Existing "Obligated Subjects": The primary regulatory interaction for entities dealing with virtual assets comes from the Unidad de Inteligencia Financiera del Perú (UIF-Perú), which oversees AML/CTF compliance. Existing "obligated subjects" (sujetos obligados) under the AML/CTF framework (like banks, financial institutions, payment service providers dealing with fiat, and money transmitters) are expected to manage risks associated with virtual assets if they engage with them.

licensing 60% confidence

They typically operate under general commercial law, registering as a regular company in Peru.

licensing 60% confidence

If custody services evolve to offer interest-bearing accounts, lending, or other financial products using virtual assets, they could potentially attract scrutiny from the SBS and might be deemed to require traditional financial licenses.

licensing 60% confidence

If they facilitate crypto-to-fiat or fiat-to-crypto payments, or if their services resemble traditional payment services (e.g., money transfers in fiat), they might be subject to the regulations applicable to Electronic Money Issuing Companies (Empresas Emisoras de Dinero Electrónico - EEDEs) or other payment service providers, which are regulated by the SBS. However, the direct application to pure-play crypto firms is often unclear.

licensing 60% confidence

No specific capital requirements for VASPs. General company formation capital requirements apply based on the chosen legal entity type (e.g., S.A.C., S.A.A.).

licensing 60% confidence

If a VASP were to be deemed a traditional financial institution (e.g., an EEDE), then significant capital requirements mandated by the SBS would apply.

aml 40% confidence

Resolución SBS N° 893-2019 (and its preceding/subsequent modifications):

aml 40% confidence

What it means for VASPs: VASPs are now required to implement an AML/CFT compliance program, appoint a compliance officer, and report to the UIF-Perú.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Individuals: Obtain and verify identity using reliable independent source documents (e.g., national ID, passport). This includes full name, date of birth, place of birth, nationality, address, and national identification number.

aml 40% confidence

Legal Entities: Obtain and verify legal name, legal form, address of main place of business, names of directors/partners, legal representative, and evidence of legal existence (e.g., articles of incorporation, business registration).

aml 40% confidence

Beneficial Ownership: Identify and verify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.

aml 40% confidence

Purpose and Intended Nature of Business Relationship: Understand the customer's activities and the intended purpose and nature of the business relationship or transaction.

aml 40% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious transaction patterns.

aml 40% confidence

Simplified CDD: May be applied in situations of lower risk, provided the VASP has sufficient information to determine that the risk is low.

aml 40% confidence

Enhanced Due Diligence (EDD): Required for higher-risk customers, business relationships, or transactions. This includes:

aml 40% confidence

Customers from high-risk jurisdictions.

aml 40% confidence

Politically Exposed Persons (PEPs) and their family members/close associates.

aml 40% confidence

Transactions involving significant amounts of virtual assets.

aml 40% confidence

Transactions with unusual patterns or no apparent economic or lawful purpose.

aml 40% confidence

Collecting additional information on the customer, beneficial owner, source of funds/wealth, and the reasons for the intended transactions.

aml 40% confidence

Obtaining senior management approval for establishing or continuing relationships with such customers.

Evidence fact pe.aml.reporting-suspicious-transactions-ros-reporting not found (may have been renamed).

Evidence fact pe.aml.record-keeping-maintaining-records-of-transactions not found (may have been renamed).

Evidence fact pe.aml.risk-assessment-conducting-a-comprehensive not found (may have been renamed).

Evidence fact pe.aml.internal-controls-establishing-internal-policies not found (may have been renamed).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are permitted in Peru under general commercial law with no specific custody license, but must register as a local company and comply with AML/CFT obligations as obliged entities under Resolución SBS N° 893-2019, including CDD, EDD, transaction monitoring, and SAR filing with UIF-Perú.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?