Custodial wallet / SaaS in Palau
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Palau with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- AML/CFT obligations under the Money Laundering and Proceeds of Crime Act (Title 31) and the Anti-Money Laundering and Countering the Financing of Terrorism Act of 2017 apply to the custodian SaaS provider as the regulated entity (not just the white-label client).
- Customer Due Diligence (CDD): Obtain and verify full legal name, date of birth, residential address, and national ID/passport for individuals; legal name, form, proof of existence, registered address, directors/partners for legal entities.
- Beneficial ownership identification: Identify and verify natural persons owning or controlling 25% or more of the customer.
- Ongoing monitoring: Scrutinize transactions throughout the relationship, keep CDD data current, source of funds checks where necessary.
- Enhanced Due Diligence (EDD): Required for higher-risk customers (PEPs, high-risk jurisdictions, complex/unusually large transactions, new technologies).
- Suspicious Transaction Reporting (STR): No minimum threshold — any transaction with reasonable suspicion of ML/TF must be reported to the Palau Financial Intelligence Unit (FIU), with no tipping-off.
- Record-keeping: Maintain all CDD records and transaction records (amounts, virtual asset types, dates, parties, wallet addresses).
- Risk-based approach required for virtual asset transactions, assessing asset types, transaction volumes, counterparty wallets, and geographic locations.
- Oversight by Palau Financial Intelligence Unit (FIU) for AML/CFT; Financial Supervisory Commission (FSC) for financial institution-type activities.
Key Restrictions
- No specific digital asset custody license exists — operator must rely on general financial services licensing under the Financial Institutions Act (Title 30) if activities are interpreted as money transmission or financial services.
- No specific rules for digital asset segregation, insurance, bonding, cold storage, or qualified custodian status — reliance on general trust law, fiduciary principles, and industry best practices.
- Custodial wallet/SaaS model could be interpreted as a money services business, triggering a license under the Financial Institutions Act.
- White-label arrangement: the SaaS custodian (not the white-label client) likely bears the primary AML/CFT obligations as the licensed entity handling keys and transactions.
- No specific VASP licensing regime exists yet; Palau has not enacted legislation directly implementing FATF Recommendation 15 for VASP-specific licenses.
- The Digital Residency Act (2023) signals digital economy expansion but does not provide a custody framework.
Key Risks
- Regulatory ambiguity: No clear legal framework for digital asset custody — interpretation of existing law by PFIC/FIU could shift against custodial operators.
- Enforcement risk: Small financial sector with nascent oversight; future enforcement actions could apply existing law retroactively or broadly.
- Lack of segregation/insurance/cold-storage rules means no safe harbor — operators rely on general fiduciary principles with no clear standard of care.
- Stablecoin pilot (PSDC with Ripple) shows Palau is exploring digital assets but creates no custody precedent or regulatory clarity.
- Reliance on general trust law for client asset protection is fragile — no statutory safe harbor for digital asset custodians in bankruptcy or insolvency scenarios.
- Reputational risk: Operating under an ambiguous framework may deter institutional counterparties and auditors.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific digital asset custody license exists.
General financial services licenses under the Financial Institutions Act (Title 30 of the Palau National Code) could potentially apply if digital assets are interpreted to fall within the scope of "financial instruments" or "financial services." However, the Act was not designed with virtual assets in mind, and specific amendments or interpretations would be necessary.
Any entity performing functions akin to a traditional bank, trust company, or money services business with digital assets might be required to register or obtain a license under existing laws, but this would depend on interpretation by the Palau Financial Institutions Commission (PFIC) or other relevant authorities.
No specific rules for digital asset segregation.
In the absence of specific digital asset regulations, general principles of trust law and fiduciary duties, as applied to traditional financial services, would likely be the most relevant. These principles typically require the segregation of client funds/assets from the firm's operational assets to protect clients in case of insolvency. However, there is no explicit mandate tailored for virtual assets.
No specific insurance or bonding requirements for digital asset custodians.
Traditional financial institutions in Palau may have capital adequacy and insurance requirements, but these are not currently extended specifically to digital asset custodians.
No specific cold storage mandates.
Unlike jurisdictions that prescribe technical security measures for digital asset custodians, Palau has no explicit rules regarding the use of cold storage (offline storage) or other security protocols for safeguarding digital assets. Custodians operating in Palau would rely on industry best practices rather than regulatory mandates.
No specific definition of a "qualified custodian" for digital assets.
The concept of a "qualified custodian" as seen in U.S. securities law (e.g., under the Investment Advisers Act of 1940) does not have a direct equivalent in Palau's current legal framework for digital assets.
No specific custody legislation is publicly pending.
No Specific VASP License: As of the latest information, Palau has not enacted specific legislation for the licensing or registration of virtual asset service providers (VASPs) that directly implements FATF Recommendations regarding VASP-specific licenses.
Reliance on Existing Financial Institutions Act: Cryptocurrency businesses conducting activities that resemble traditional financial services (e.g., money transmission, payments, exchange of value) would likely fall under the purview of Palau's existing financial services legislation, primarily the Palau Financial Institutions Act (Title 27 of the Palau National Code).
AML/CFT Obligations: Regardless of specific licensing, all entities operating in Palau, especially those handling financial transactions, are subject to the country's AML/CFT framework. The Financial Supervisory Commission (FSC) is the primary regulator for financial institutions and oversees AML/CFT compliance.
Cryptocurrency Exchanges (Fiat-to-Crypto, Crypto-to-Fiat, Crypto-to-Crypto):
If interpreted as such, an exchange would need a license for "Money Services Business" or a similar category. This would typically apply if the exchange involves fiat currency or facilitates transfers of value between different parties.
Money Laundering and Proceeds of Crime Act (Title 31 of the Palau National Code): This act outlines AML/CFT obligations. As a member of the Asia/Pacific Group on Money Laundering (APG), Palau is committed to implementing the FATF Recommendations, which include virtual assets and virtual asset service providers (VASPs) within their scope. Any entity performing VASP functions (which can include custody) would be expected to comply with these general AML/CFT requirements.
Palau Financial Institutions Act (Title 30 of the Palau National Code): This act governs traditional financial institutions.
Anti-Money Laundering and Countering the Financing of Terrorism Act of 2017 (AML/CFT Act 2017): This is the overarching legislation that defines money laundering and terrorist financing offenses, establishes reporting obligations, and outlines customer due diligence requirements for financial institutions and DNFBPs. While it may not explicitly mention "virtual assets" in all its original definitions, the broad scope of "funds" or "property" and the country's commitment to FATF recommendations mean it's interpreted to cover virtual assets.
Financial Intelligence Unit Act, 2014: This Act establishes the Palau Financial Intelligence Unit (FIU) and outlines its powers and functions, including receiving and analyzing suspicious transaction reports.
National Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) Policy of the Republic of Palau: This policy document provides the overarching strategic framework for Palau's AML/CFT regime, emphasizing adherence to international standards.
Implementing FATF Recommendation 15 (New Technologies) and its Interpretive Note, which mandates countries to regulate and supervise VASPs for AML/CFT purposes, including licensing or registration.
Identification and Verification of Customers:
Individuals: Obtain and verify the customer's full legal name, date of birth, residential address, and national identification number or passport details. Verification usually involves reliable, independent source documents, data, or information.
Legal Persons/Entities: Obtain and verify the entity's legal name, legal form, proof of existence (e.g., certificate of incorporation), registered address, names of directors/partners, and proof of authority of persons acting on behalf of the entity.
Beneficial Ownership Identification and Verification:
Identify and take reasonable measures to verify the identity of the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted. This typically refers to individuals holding 25% or more of the shares or voting rights, or otherwise exercising control.
Purpose and Intended Nature of Business Relationship:
Ongoing Due Diligence:
Enhanced Due Diligence (EDD):
Risk-Based Approach to Virtual Asset Transactions:
Reporting Threshold: There is no minimum monetary threshold for reporting. Any transaction (or attempted transaction), regardless of amount, where the VASP has reasonable grounds to suspect it is linked to money laundering, terrorist financing, or other criminal activity, must be reported.
Content of Report: STRs must contain all relevant information, including the identity of the customer, details of the transaction, the grounds for suspicion, and any supporting documentation.
No Tipping-Off: VASPs and their employees are strictly prohibited from "tipping off" or disclosing to the customer or any third party that an STR is being or has been submitted.
Protection for Reporters: Employees who report suspicious transactions in good faith are protected from civil or criminal liability.
Customer Records: All records obtained through CDD procedures (identification documents, verification records, beneficial ownership information, business relationship purpose).
Transaction Records: Details of all transactions, including amounts, types of virtual assets, dates, and parties involved (including originating and beneficiary wallet addresses).
Small Financial Sector & Nascent Regulation: Palau is a small island nation with a relatively small financial sector. While it is exploring digital assets (e.g., its national stablecoin initiative with Ripple), its regulatory framework for cryptocurrencies is still evolving. The focus tends to be on establishing foundational Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) compliance rather than large-scale, public enforcement actions against crypto entities.
Primary Regulatory Body: The primary body responsible for financial intelligence and AML/CFT oversight in Palau is the Palau Financial Intelligence Unit (FIU). Their work often involves suspicious transaction reports (STRs) and cooperation with international bodies like the Asia/Pacific Group on Money Laundering (APG), but individual enforcement actions with public details like specific penalties against crypto entities are not commonly published.
Focus on Development, Not Enforcement (Yet): Palau has been notably proactive in exploring the adoption of digital assets, such as its "Root Name System" initiative and the Palau Stablecoin (PSC) pilot program. This indicates a forward-looking approach, but it also means the regulatory and enforcement infrastructure for complex crypto violations may still be under development.
Palau Financial Intelligence Unit (FIU): While their website primarily focuses on AML/CFT guidelines and STR reporting, it's the key agency for financial oversight.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator may operate in Palau subject to being licensed under general financial services laws (Financial Institutions Act) if activities are deemed money transmission, with full AML/CFT obligations (CDD, EDD, STRs, recordkeeping) supervised by the FIU, but no specific digital asset custody, segregation, insurance, or qualified-custodian framework exists, creating significant regulatory ambiguity.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?