← Regulations / Rwanda / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Rwanda

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Rwanda with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • VASPs (including custodial wallet providers) are classified as 'reporting persons' under Law N° 060/2021 and must register with / report to the Financial Intelligence Centre (FIC) of Rwanda.
  • Conduct Customer Due Diligence on all customers including name, address, date of birth, nationality, national ID (for individuals) and entity name, legal form, registration number, beneficial ownership (for legal entities) — see rw.licensing.identification-and-verification-of-customers through rw.licensing.for-legal-entities-companies-corporations.
  • Apply a risk-based approach — Enhanced Due Diligence for higher-risk customers (PEPs, high-risk jurisdictions, complex transactions); Simplified Due Diligence for lower-risk — see rw.licensing.risk-based-approach-applying-cdd-measures.
  • Suspicious Transaction Reporting: No minimum monetary threshold; any suspicion of ML/TF must be reported promptly to the FIC within 2–5 business days — see rw.licensing.reporting-threshold and rw.licensing.timing.
  • Maintain records for at least 5 years: CDD documents, transaction records, business relationship records, and copies of all STRs — see rw.licensing.duration.
  • Screen all customers, beneficial owners, and counterparties against UN sanctions lists (UN Security Council Consolidated List) and OFAC SDN list if using U.S. services or USD — see rw.aml.screen-all-customers-beneficial-owners (both instances).
  • Immediately freeze assets of designated individuals/entities and report hits to FIC without delay — see rw.aml.immediately-freeze-funds-and-other and rw.aml.report-any-hits-or-frozen.
  • No-tipping-off prohibition: cannot disclose STR filing to the customer or third parties — see rw.licensing.no-tipping-off-vasps-and-their.
  • Ongoing monitoring of business relationships and transactions for consistency with customer risk profile — see rw.licensing.ongoing-monitoring-continuously-monitoring-the.

Key Restrictions

  • No formal VASP/custody licensing regime currently exists; operators fall under general AML/CFT obligations as 'reporting persons' under the FIC framework, with potential future licensing under Law 008/2021 on Payment Systems (BNR oversight).
  • Cryptocurrencies are not legal tender in Rwanda and the BNR has issued ongoing public warnings about their risks, creating an ambiguous operating environment.
  • Local incorporation is effectively required given that reporting-person obligations and recordkeeping (5-year minimum) apply to entities operating in/with Rwanda.
  • Segregation, insurance, and proof-of-reserves rules for custodial wallets are not currently codified in Rwandan law — these would need to be contractually arranged.

Key Risks

  • Regulatory ambiguity: No comprehensive crypto-specific licensing framework — BNR warnings create uncertainty about future enforcement and potential retroactive compliance requirements.
  • Enforcement risk: Lack of formal regime means any adverse action could fall under general financial laws (AML, fraud, criminal code) handled by law enforcement rather than a specialist regulator.
  • Market size and limited precedent: Very few enforcement actions to date; limited guidance on how custodial wallet models will be treated.
  • OFAC / sanctions exposure: Use of U.S. services (blockchain analytics, USD rails) creates secondary sanctions risk requiring OFAC screening even without local mandate.
  • Reputational risk: BNR's public stance discouraging crypto use could create friction with banking partners and the broader financial ecosystem.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Law N° 060/2021 of 14/10/2021 on Preventing and Combating Money Laundering and Financing of Terrorism: This is the overarching AML/CFT law in Rwanda. It establishes the legal framework for identifying, reporting, and preventing money laundering and terrorist financing. It defines "reporting persons" broadly to include any person or entity that, by virtue of their activities, may be exposed to ML/TF risks, which can encompass VASPs even if not explicitly named.

licensing 60% confidence

Ministerial Order N° 001/2022 of 28/01/2022 determining requirements for combating money laundering and financing of terrorism: This order specifies the general AML/CFT compliance requirements for reporting persons.

licensing 60% confidence

Ministerial Order N° 002/2022 of 28/01/2022 determining procedures for combating money laundering and financing of terrorism: This order details the procedural aspects of AML/CFT compliance.

licensing 60% confidence

National Bank of Rwanda (BNR) Circulars and Guidelines: The BNR, as the central bank and financial regulator, has issued warnings regarding the risks associated with cryptocurrencies, underscoring the need for AML/CFT compliance should they operate within Rwanda's financial ecosystem. While not specific VASP licensing, these reinforce the general AML/CFT obligations.

licensing 60% confidence

Identification and Verification of Customers:

licensing 60% confidence

For Individuals: Obtaining and verifying name, address, date of birth, nationality, national identification number (e.g., Rwandan ID card, passport number), and any other unique identifiers. This typically involves documentary verification (e.g., valid ID document) and, where appropriate, non-documentary methods.

licensing 60% confidence

For Legal Entities (Companies, Corporations, Trusts): Obtaining and verifying the entity's name, legal form, address, registration number, articles of incorporation, bylaws, and proof of existence. Identifying and verifying the identity of beneficial owners (individuals who ultimately own or control the entity, typically 25% ownership threshold or control through other means), as well as persons acting on behalf of the entity (e.g., directors, authorized signatories).

licensing 60% confidence

Understanding the Purpose and Intended Nature of the Business Relationship: VASPs must understand why the customer wants to use their services and the anticipated level and type of activity.

licensing 60% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by customers to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information up-to-date.

licensing 60% confidence

Risk-Based Approach: Applying CDD measures based on a risk assessment. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex or unusually large transactions) and simplified due diligence (SDD) for lower-risk customers (if permitted and justified). Due to the inherent risks of virtual assets, most VASP activities would generally require standard or enhanced CDD.

licensing 60% confidence

Reporting Threshold: There is no minimum monetary threshold for reporting suspicious transactions. Any transaction, regardless of amount, where there are reasonable grounds to suspect that it may be related to money laundering or terrorist financing, must be reported.

licensing 60% confidence

Content of Report: STRs must contain comprehensive details about the customer, the transaction(s), and the reasons for the suspicion.

licensing 60% confidence

Timing: Reports must be made promptly, typically within a specified number of business days (e.g., 2-5 working days) of forming the suspicion.

licensing 60% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.

licensing 60% confidence

Customer Identification Records: All documents and information obtained during the CDD process (e.g., copies of identification documents, beneficial ownership information).

licensing 60% confidence

Transaction Records: Records of all transactions undertaken, sufficient to permit reconstruction of individual transactions (e.g., sender and receiver details, amounts, type of virtual asset, transaction hash/ID, date and time).

licensing 60% confidence

Business Relationship Records: Records pertaining to the business relationship, correspondence, and decisions made regarding the customer's risk profile.

licensing 60% confidence

Suspicious Transaction Reports (STRs): Copies of all STRs filed and any internal documentation supporting the decision to file (or not to file).

licensing 60% confidence

Duration: Records must generally be kept for a period of at least five (5) years after the end of the business relationship or the date of the transaction.

licensing 60% confidence

Financial Intelligence Centre (FIC) of Rwanda

licensing 60% confidence

National Bank of Rwanda (BNR) Circulars and Guidelines: The BNR, as the central bank and financial regulator, has issued warnings regarding the risks associated with cryptocurrencies, underscoring the need for AML/CFT compliance should they operate within Rwanda's financial ecosystem. While not specific VASP licensing, these reinforce the general AML/CFT obligations.

licensing 40% confidence

Central Bank of Rwanda (BNR) - Official Website: The BNR is the primary financial regulator. Their official statements and publications are the most authoritative source.

aml 60% confidence

Law No. 008/2020 of 08/07/2020 on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation (AML/CFT-P): This is the cornerstone legislation. It establishes the Financial Intelligence Centre (FIC) as the primary body for receiving and analyzing suspicious transaction reports (STRs) and provides the framework for identifying and sanctioning financial crimes. This law explicitly mandates compliance with international sanctions, particularly those issued by the United Nations Security Council (UNSC).

aml 60% confidence

Law No. 008/2021 of 16/02/2021 Governing Payment Systems: This law provides a framework for licensing and oversight of payment service providers. While not specific to crypto, it lays the groundwork for how VASPs might be regulated and licensed, extending AML/CFT obligations to them. The National Bank of Rwanda (BNR) is the primary regulator for payment systems and is actively working on a comprehensive framework for digital assets.

aml 60% confidence

Requirements for VASPs: Once formally regulated, VASPs in Rwanda (or those dealing with Rwandan entities) must:

aml 60% confidence

Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).

aml 60% confidence

Refrain from making funds or economic resources available, directly or indirectly, to sanctioned parties.

aml 60% confidence

Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).

aml 60% confidence

Refrain from engaging in any activity that could be considered a violation or circumvention of OFAC sanctions.

enforcement 60% confidence

Evolving Regulatory Framework: Rwanda's regulatory framework for virtual assets is still developing. While the National Bank of Rwanda (BNR) has issued warnings and statements regarding the risks of cryptocurrencies, comprehensive legislation specifically targeting Virtual Asset Service Providers (VASPs) and detailing licensing requirements and specific enforcement mechanisms is still in progress.

enforcement 60% confidence

Focus on Warnings and Consumer Protection: The BNR's primary approach has been to issue public warnings about the unregulated nature of cryptocurrencies, their volatility, and the risks of fraud and money laundering. This is a preventative measure rather than reactive enforcement against specific licensed entities (as there are few, if any, formally licensed crypto businesses operating under a specific crypto regulatory regime in Rwanda currently).

enforcement 60% confidence

Lack of Formal Licensing Regime: Without a well-established licensing regime for crypto businesses, enforcement actions would more likely fall under general financial laws (e.g., anti-money laundering, fraud) rather than specific crypto regulatory breaches. Any related cases might be handled by criminal law enforcement rather than financial regulators as "enforcement actions" against a specific crypto business.

enforcement 60% confidence

Limited Market Size: The cryptocurrency market in Rwanda may not yet be large enough to attract the scale of illicit activity or the number of unregulated operators that would trigger frequent, large-scale, and publicly reported enforcement actions seen in more mature or permissive crypto jurisdictions.

enforcement 60% confidence

National Bank of Rwanda (BNR) on Virtual Currencies: The BNR has consistently stated that virtual currencies are not legal tender in Rwanda and has warned against their risks.

enforcement 60% confidence

General Stance/Violation Type: Public warnings against the use of cryptocurrencies due to their unregulated nature, high volatility, lack of legal tender status, and potential for fraud and money laundering. This can be broadly seen as a "pre-emptive enforcement" or "risk mitigation" strategy.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators can operate in Rwanda under the general AML/CFT framework as reporting persons to the FIC, but a formal crypto-custody licensing regime does not yet exist, the BNR maintains a cautionary stance on crypto, and segregation/insurance/proof-of-reserves rules are not codified, creating medium regulatory ambiguity.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?