Custodial wallet / SaaS in Solomon Islands
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Solomon Islands with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Must conduct Customer Due Diligence (CDD) including: identification and verification of identity for natural persons (full name, DOB, residential address, nationality, unique ID number) and legal persons (name, legal form, proof of existence, senior management), per sb.aml.identification-and-verification-of-identity, sb.aml.natural-persons-obtain-full-name, sb.aml.legal-personsentities-eg-companies-obtain
- Must identify and verify beneficial ownership (typically 25%+ ownership/control threshold for legal entities), per sb.aml.beneficial-ownership-identify-and-verify
- Must ascertain purpose and intended nature of the business relationship, per sb.aml.purpose-and-intended-nature-of
- Must conduct ongoing transaction monitoring to detect unusual or suspicious activity, per sb.aml.ongoing-monitoring-continuously-monitor-the
- Must apply Enhanced Due Diligence (EDD) for PEPs, cross-border correspondent relationships, high-risk jurisdictions, complex/unusually large transactions, and anonymity-enhancing virtual assets, per sb.aml.enhanced-due-diligence-edd-apply through sb.aml.anonymity-enhancing-virtual-assets-or-technologies
- Must submit Suspicious Transaction Reports (STRs) to the Solomon Islands Financial Intelligence Unit (SIFIU) promptly upon suspicion, per sb.aml.reporting-obligation-reports-must-be and sb.aml.content-of-report-strs-must
- Strict no-tipping-off prohibition regarding STR submissions, per sb.aml.no-tipping-off-vasps-and-their
- Record-keeping obligations: copies of CDD documents, all transaction records (including Travel Rule data if applicable), and business correspondence, per sb.aml.types-of-records, sb.aml.copies-of-documents-used-for, sb.aml.records-of-all-transactions-including
- The AML/CFT Act 2021 applies to financial institutions which may include VASPs, per sb.aml.anti-money-laundering-and-counter-terrorist-financing
- The Financial Transactions Reporting Act 2010 also imposes reporting requirements, per sb.aml.financial-transactions-reporting-act-2010
Key Restrictions
- No dedicated crypto custody license exists; the operator must determine whether its activities constitute 'banking business' or 'financial institution services' under the Financial Institutions Act 1998, which would require a traditional banking/finance license, per sb.custody.no-specific-crypto-custody-license and sb.custody.potential-application-of-existing-licenses
- No specific legal framework for segregation of client digital assets from proprietary assets exists; general fiduciary principles would apply only if the operator is a licensed financial institution, per sb.custody.no-specific-crypto-rules-there and sb.custody.general-fiduciary-principles-for-traditional
- No specific insurance or bonding requirements for digital asset custodians, per sb.custody.no-specific-crypto-requirements-there
- No cold storage mandates for digital assets under custody, per sb.custody.no-specific-mandates-there-are
- No legal definition of 'qualified custodian' for digital assets exists, per sb.custody.no-specific-definition-there-is
- The CBSI has warned the public against cryptocurrency risks and does not recognize crypto as legal tender, creating a hostile regulatory environment, per sb.licensing.pure-payment-tokenscryptocurrencies-tokens-intended and sb.licensing.the-cbsi-has-warned-the
- If the custody service involves tokens deemed investment contracts/securities (e.g., security tokens, fractionalized NFTs), prospectus requirements under the Companies Act 2009 may apply, per sb.licensing.prospectus-requirements-issuers-may-need
Key Risks
- Extreme regulatory ambiguity: no specific crypto custody or VASP framework exists, and the operator's activities could be re-interpreted as regulated banking/financial services at any time, per sb.custody.no-specific-crypto-custody-license
- Enforcement risk: the CBSI has taken a preventive anti-crypto posture with public warnings and no regulated exchanges, signaling regulatory hostility, per sb.licensing.focus-on-warnings-the-cbsis and sb.licensing.lack-of-specific-legislation-without
- Custody risk: no segregation, insurance, or proof-of-reserves rules mean client assets are legally unprotected in a bankruptcy or hack scenario
- Small market scale combined with significant compliance overhead (full AML program) makes the jurisdiction economically marginal for custodial wallet operators
- Pending legislation risk: while no draft laws are publicly available, the CBSI monitors international developments and could introduce retroactive or burdensome regulation, per sb.custody.there-is-no-publicly-available
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific crypto custody license: There is no dedicated license for virtual asset custodians.
Potential application of existing licenses: If an entity's activities involving digital assets were deemed to fall under the definition of banking business, financial institution services, or securities trading, it would likely require a license under the Financial Institutions Act 1998 or other relevant financial legislation administered by the CBSI. However, this would depend on how digital assets are legally characterized, which is currently ambiguous for custody.
No specific crypto rules: There are no explicit rules mandating the segregation of client digital assets from the custodian's proprietary assets.
General fiduciary principles: For traditional financial institutions, general principles of fiduciary duty and client asset protection would typically apply, implying segregation. However, without specific legislation for digital assets, the enforceability and interpretation for crypto assets would be unclear.
No specific crypto requirements: There are no specific insurance or bonding requirements for digital asset custodians.
General capital adequacy: Licensed financial institutions might be subject to capital adequacy requirements as part of their licensing conditions, but this typically does not extend to specific insurance for digital asset theft or loss.
No specific mandates: There are no legal mandates in the Solomon Islands for using cold storage or any particular security measures for digital assets under custody. This is an operational detail typically specified in advanced crypto regulatory frameworks.
No specific definition: There is no legal definition of a "qualified custodian" for digital assets in the Solomon Islands. This concept is usually part of robust regulatory regimes that define specific criteria for institutions entrusted with client assets (e.g., minimum capital, professional liability, security audits).
There is no publicly available information indicating any specific pending legislation for cryptocurrency or digital asset custody in the Solomon Islands. While the CBSI may be monitoring international developments or reviewing its financial sector laws, no draft laws or public consultations on this specific topic have been announced.
Central Bank of Solomon Islands (CBSI): The primary regulatory body.
Financial Institutions Act 1998: Regulates financial institutions and banking activities.
Anti-Money Laundering and Counter-Terrorist Financing Act 2002 (as amended): The key legislation for combating financial crime.
Anti-Money Laundering and Counter-Terrorist Financing Act 2021 (the AML/CFT Act): This comprehensive legislation aligns the Solomon Islands with international FATF standards, covering customer due diligence, reporting obligations, and broader AML/CFT requirements for financial institutions, which increasingly include VASPs.
Financial Transactions Reporting Act 2010: This Act also contributes to the framework, particularly regarding the reporting of certain transactions.
Solomon Islands Financial Intelligence Unit (SIFIU)
Identification and Verification of Identity:
Natural Persons: Obtain full name, date of birth, residential address, nationality, and unique identification number (e.g., passport, national ID). Verify this information using reliable, independent source documents, data, or information.
Legal Persons/Entities (e.g., Companies): Obtain name, legal form, proof of existence, powers that regulate and bind the legal person, and the names of relevant persons holding senior management positions.
Beneficial Ownership: Identify and verify the identity of the natural person(s) who ultimately own or control the customer (typically 25% or more ownership/control threshold for legal entities).
Purpose and Intended Nature of the Business Relationship: Understand the reason for the customer establishing the relationship and the expected nature of their virtual asset activities.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Enhanced Due Diligence (EDD): Apply EDD measures in higher-risk situations, including:
Reporting Obligation: Reports must be submitted to the SIFIU promptly. SIFIU guidance usually specifies a timeframe (e.g., within 24-48 hours of forming suspicion).
Content of Report: STRs must contain comprehensive information about the customer, the transaction(s), the grounds for suspicion, and any other relevant details.
No Tipping-Off: VASPs and their employees are strictly prohibited from informing the customer or any third party that an STR has been or will be submitted.
Copies of documents used for CDD (identification, verification).
Records of all transactions, including amounts, types of virtual assets, dates, and parties involved (including "Travel Rule" information if applicable).
Pure Payment Tokens/Cryptocurrencies: Tokens intended solely as a medium of exchange or store of value, and not offered or sold as part of an investment scheme. However, it's important to note that the CBSI does not recognize cryptocurrencies as legal tender and has warned against their use.
The CBSI has warned the public against the risks of trading cryptocurrencies due to their volatility, speculative nature, and lack of regulation.
Lack of Specific Legislation: Without a dedicated framework, enforcement actions are harder to initiate.
Focus on Warnings: The CBSI's primary approach has been preventive, issuing general public warnings about the risks of cryptocurrencies, scams, and their non-recognition as legal tender.
Prospectus Requirements: Issuers may need to prepare and register a prospectus or offer document with the Registrar of Companies, providing full disclosure of material information about the token, the project, the risks, and the issuer.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator could theoretically operate in Solomon Islands only if structured as (or deemed not to be) a licensed financial institution under the Financial Institutions Act 1998, and subject to full AML/CFT obligations under the AML/CFT Act 2021 and SIFIU supervision, but faces extreme regulatory ambiguity due to the complete absence of a dedicated crypto custody framework and a hostile CBSI posture toward digital assets.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?