Custodial wallet / SaaS in Seychelles
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Seychelles with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP must conduct CDD for all customers: natural persons (name, address, DOB, nationality, official ID) and legal persons (name, legal form, directors, registered address) — sc.aml.identification-and-verification-of-customers, sc.aml.natural-persons-obtain-and-verify, sc.aml.legal-personsarrangements-obtain-and-verify
- Beneficial ownership identification required (≥25% threshold) — sc.aml.beneficial-ownership-identification-identify-and
- Ongoing transaction monitoring for consistency with customer risk profile — sc.aml.ongoing-monitoring-continuously-monitor-the
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions (FATF-listed), complex/unusual transactions, and high-risk virtual asset activities — sc.aml.enhanced-due-diligence-edd-apply, sc.aml.transactions-with-politically-exposed-persons, sc.aml.business-relationships-or-transactions-with, sc.aml.complex-unusually-large-transactions-and, sc.aml.specific-virtual-asset-activities-deemed
- Immediate reporting to the FIU of suspicious transactions (STRs) — sc.aml.reporting-obligation-a-vasp-must
- No-tipping-off prohibition — sc.aml.no-tipping-off-vasps-and-their
- CDD and transaction records must be retained — sc.aml.cdd-records-all-records-obtained, sc.aml.transaction-records-records-of-all
- SaaS provider (as the licensed VASP) bears the AML obligations directly; white-label clients are customers of the VASP and subject to the VASP's CDD, not independently licensed unless they also provide virtual asset services — derived from sc.custody.requirement-for-license-any-person and sc.aml.safekeeping-andor-administration-of-virtual
Key Restrictions
- Must obtain a VASP license from the FSA to provide 'custody or administration of virtual assets or instruments enabling control over virtual assets' as a business — sc.custody.requirement-for-license-any-person
- Must maintain a physical presence or designated local resident in Seychelles — sc.custody.local-presence-generally-theres-a
- Mandatory segregation: client virtual assets must be kept separate from the VASP's own assets — sc.custody.mandatory-segregation-a-licensed-vasp
- Minimum capital requirements apply (details in subsidiary regulations/FSA directives) — sc.custody.minimum-capital-meeting-prescribed-minimum
- Directors and senior management must pass a fit-and-proper test — sc.custody.fit-and-proper-test-the
- Adequate cybersecurity and data protection measures required; industry-standard hot/cold storage expected — sc.custody.cybersecurity-strong-cybersecurity-and-data, sc.custody.appropriate-cybersecurity-and-data-protection, sc.custody.while-not-explicitly-named-the
- No standalone insurance or bonding mandate, but FSA may require professional indemnity insurance as part of ongoing risk assessment — sc.custody.however-the-act-does-require
Key Risks
- No explicit proof-of-reserves or attestation requirement, creating ambiguity on best practices for demonstrating solvency — sc.custody.similar-to-insurance-the-act, sc.custody.adequate-internal-control-systems-accounting
- No distinct 'qualified custodian' category — the same VASP license covers all custody, so differentiation is not recognized in regulation — sc.custody.the-seychelles-vasp-act-does, sc.custody.instead-any-entity-that-provides
- FSA enforcement track record includes public warnings and license revocations for unlicensed or non-compliant operators; high risk of enforcement action if operating without license or with inadequate compliance — sc.licensing.issuing-public-warnings-against-entities, sc.licensing.cease-and-desist-orders-mandating, sc.licensing.license-revocationssuspensions-for-non-compliance-within
- If white-label clients serve end users, the SaaS provider could be exposed to liability for downstream AML failures given the VASP license is held by the SaaS provider, not the client
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Requirement for License: Any person providing "custody or administration of virtual assets or instruments enabling control over virtual assets" as a business in or from Seychelles must obtain a VASP license from the FSA.
Regulatory Reference: Virtual Assets Service Providers Act, 2022, Section 5(1).
Application Requirements: To obtain a VASP license for custodial services, applicants must satisfy stringent criteria, including:
Fit and Proper Test: The applicant, its directors, and senior management must meet "fit and proper" criteria.
Business Plan: Submission of a comprehensive business plan detailing operations, strategies, and internal controls.
Internal Controls: Adequate internal control systems, accounting systems, and systems for safeguarding virtual assets.
AML/CFT Compliance: Robust anti-money laundering (AML) and combating the financing of terrorism (CFT) policies and procedures, in compliance with Seychelles' AML/CFT framework and international standards.
Risk Management: Adequate risk management frameworks and internal audit functions.
Cybersecurity: Strong cybersecurity and data protection measures.
Minimum Capital: Meeting prescribed minimum capital requirements (details usually in subsidiary regulations or FSA directives).
Local Presence: Generally, there's a requirement for a physical presence or designated local resident.
Application Process: The application process is detailed in the Virtual Assets Service Providers (Application) Regulations, 2023.
Fees: Fees for application and annual licensing are prescribed in the Virtual Assets Service Providers (Fees) Regulations, 2023.
Mandatory Segregation: A licensed VASP offering custodial services is explicitly required to maintain a clear segregation between the virtual assets of its clients and its own virtual assets. This is a fundamental principle to protect client funds in case of insolvency or operational issues of the VASP.
Record Keeping: VASPs must keep proper records for all clients' virtual assets held by them.
The Virtual Assets Service Providers Act, 2022 does not explicitly mandate specific insurance or bonding requirements for custodians in a standalone section.
However, the Act does require VASPs to have "adequate risk management frameworks and internal audit functions" (Section 7(g)). The FSA, as part of its supervisory powers, may require a VASP to hold professional indemnity insurance or other forms of financial guarantees as part of its ongoing assessment of risk management or "fit and proper" criteria. It is common practice for financial service providers, including custodians, to carry robust insurance coverage to protect against operational risks, cyber risks, and potential losses. The absence of an explicit mandate in the primary Act does not preclude such requirements from being imposed through FSA directives, guidelines, or as part of the licensing conditions based on the nature and scale of operations.
Similar to insurance, the Act focuses on broader principles, requiring VASPs to have:
"appropriate cybersecurity and data protection measures" (Section 7(g)).
"adequate internal control systems, accounting systems and systems for safeguarding virtual assets" (Section 7(d)).
While not explicitly named, the best practice for safeguarding virtual assets, especially large amounts, typically involves a combination of hot and cold storage solutions. The FSA would expect a VASP to implement industry-standard security measures, which would likely include cold storage for a significant portion of client assets, as part of its compliance with the general cybersecurity and asset safeguarding requirements.
The Seychelles VASP Act does not define a separate category of "qualified custodian" distinct from a general VASP that offers custody services.
Instead, any entity that provides "custody or administration of virtual assets or instruments enabling control over virtual assets" as a business is considered a Virtual Asset Service Provider (VASP) and must be licensed as such by the FSA. Therefore, a "qualified custodian" in Seychelles' context is effectively a VASP that holds the necessary license and complies with all the requirements of the VASP Act for providing custody services.
Virtual Asset Service Providers Act, 2022 (VASP Act 2022): This is the cornerstone legislation specifically regulating VASPs. It mandates licensing, registration, and compliance with AML/CFT obligations for entities engaged in virtual asset services.
Anti-Money Laundering and Countering the Financing of Terrorism Act, 2020 (AML/CFT Act 2020): This is the overarching AML/CFT legislation in Seychelles, applying to all designated non-financial businesses and professions (DNFBPs) and financial institutions, which now explicitly includes VASPs. The VASP Act builds upon and references the requirements of this broader AML/CFT Act.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Identification and Verification of Customers:
Natural Persons: Obtain and verify identity through reliable, independent source documents, such as name, residential address, date of birth, nationality, and official identification numbers.
Legal Persons/Arrangements: Obtain and verify identity information such as name, legal form, proof of existence, powers that regulate the legal person, names of directors/partners, and the address of the registered office or place of business.
Beneficial Ownership Identification: Identify and verify the identity of the beneficial owner(s) of the customer. For legal persons, this typically involves identifying individuals who ultimately own or control more than 25% of the entity.
Purpose and Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of the relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk scenarios, including:
Transactions with Politically Exposed Persons (PEPs).
Business relationships or transactions with persons from high-risk jurisdictions identified by FATF or the domestic AML/CFT framework.
Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
Specific virtual asset activities deemed higher risk.
Reporting Obligation: A VASP must immediately report to the FIU when it knows, suspects, or has reasonable grounds to suspect that funds or other assets are proceeds of a criminal activity, or are related to terrorist financing, or other money laundering activities.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be made.
CDD Records: All records obtained through CDD procedures (e.g., copies of identification documents, account files, business correspondence).
Transaction Records: Records of all domestic and international transactions, including the amount, currency, and type of virtual asset, transaction dates, and parties involved.
Issuing Public Warnings: Against entities operating without a license or misrepresenting their licensing status in Seychelles, often encompassing investment schemes, forex, and implicitly, crypto-related activities.
Cease and Desist Orders: Mandating unauthorized entities to stop operations.
License Revocations/Suspensions: For non-compliance within the broader financial services sector, which can indirectly affect entities dealing with virtual assets.
Entity Targeted: Numerous entities falsely claiming to be licensed or operating without proper authorization. While not always explicitly "crypto," many involve fraudulent investment schemes, forex trading, or brokerage services that often interact with digital assets. Violation Type: Operating without a license, misrepresentation of licensing status, unauthorized financial services activities, potential fraud. Penalty Amount: N/A (no monetary fine typically disclosed for these warnings, but the entity is ordered to cease operations and public is warned). Outcome: Public awareness, cessation of unauthorized activities (if complied), potential further legal action if non-compliant.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS provider may operate in Seychelles only by obtaining a VASP license from the FSA (high burden), maintaining a local presence, segregating client assets, and complying with comprehensive AML/CFT obligations; no distinct "qualified custodian" category or explicit proof-of-reserves/insurance mandate exists, creating some regulatory ambiguity.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?