← Regulations / Seychelles / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Seychelles

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Seychelles with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASP must conduct CDD for all customers: natural persons (name, address, DOB, nationality, official ID) and legal persons (name, legal form, directors, registered address) — sc.aml.identification-and-verification-of-customers, sc.aml.natural-persons-obtain-and-verify, sc.aml.legal-personsarrangements-obtain-and-verify
  • Beneficial ownership identification required (≥25% threshold) — sc.aml.beneficial-ownership-identification-identify-and
  • Ongoing transaction monitoring for consistency with customer risk profile — sc.aml.ongoing-monitoring-continuously-monitor-the
  • Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions (FATF-listed), complex/unusual transactions, and high-risk virtual asset activities — sc.aml.enhanced-due-diligence-edd-apply, sc.aml.transactions-with-politically-exposed-persons, sc.aml.business-relationships-or-transactions-with, sc.aml.complex-unusually-large-transactions-and, sc.aml.specific-virtual-asset-activities-deemed
  • Immediate reporting to the FIU of suspicious transactions (STRs) — sc.aml.reporting-obligation-a-vasp-must
  • No-tipping-off prohibition — sc.aml.no-tipping-off-vasps-and-their
  • CDD and transaction records must be retained — sc.aml.cdd-records-all-records-obtained, sc.aml.transaction-records-records-of-all
  • SaaS provider (as the licensed VASP) bears the AML obligations directly; white-label clients are customers of the VASP and subject to the VASP's CDD, not independently licensed unless they also provide virtual asset services — derived from sc.custody.requirement-for-license-any-person and sc.aml.safekeeping-andor-administration-of-virtual

Key Restrictions

  • Must obtain a VASP license from the FSA to provide 'custody or administration of virtual assets or instruments enabling control over virtual assets' as a business — sc.custody.requirement-for-license-any-person
  • Must maintain a physical presence or designated local resident in Seychelles — sc.custody.local-presence-generally-theres-a
  • Mandatory segregation: client virtual assets must be kept separate from the VASP's own assets — sc.custody.mandatory-segregation-a-licensed-vasp
  • Minimum capital requirements apply (details in subsidiary regulations/FSA directives) — sc.custody.minimum-capital-meeting-prescribed-minimum
  • Directors and senior management must pass a fit-and-proper test — sc.custody.fit-and-proper-test-the
  • Adequate cybersecurity and data protection measures required; industry-standard hot/cold storage expected — sc.custody.cybersecurity-strong-cybersecurity-and-data, sc.custody.appropriate-cybersecurity-and-data-protection, sc.custody.while-not-explicitly-named-the
  • No standalone insurance or bonding mandate, but FSA may require professional indemnity insurance as part of ongoing risk assessment — sc.custody.however-the-act-does-require

Key Risks

  • No explicit proof-of-reserves or attestation requirement, creating ambiguity on best practices for demonstrating solvency — sc.custody.similar-to-insurance-the-act, sc.custody.adequate-internal-control-systems-accounting
  • No distinct 'qualified custodian' category — the same VASP license covers all custody, so differentiation is not recognized in regulation — sc.custody.the-seychelles-vasp-act-does, sc.custody.instead-any-entity-that-provides
  • FSA enforcement track record includes public warnings and license revocations for unlicensed or non-compliant operators; high risk of enforcement action if operating without license or with inadequate compliance — sc.licensing.issuing-public-warnings-against-entities, sc.licensing.cease-and-desist-orders-mandating, sc.licensing.license-revocationssuspensions-for-non-compliance-within
  • If white-label clients serve end users, the SaaS provider could be exposed to liability for downstream AML failures given the VASP license is held by the SaaS provider, not the client

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

Requirement for License: Any person providing "custody or administration of virtual assets or instruments enabling control over virtual assets" as a business in or from Seychelles must obtain a VASP license from the FSA.

custody 60% confidence

AML/CFT Compliance: Robust anti-money laundering (AML) and combating the financing of terrorism (CFT) policies and procedures, in compliance with Seychelles' AML/CFT framework and international standards.

custody 60% confidence

Mandatory Segregation: A licensed VASP offering custodial services is explicitly required to maintain a clear segregation between the virtual assets of its clients and its own virtual assets. This is a fundamental principle to protect client funds in case of insolvency or operational issues of the VASP.

custody 60% confidence

The Virtual Assets Service Providers Act, 2022 does not explicitly mandate specific insurance or bonding requirements for custodians in a standalone section.

custody 60% confidence

However, the Act does require VASPs to have "adequate risk management frameworks and internal audit functions" (Section 7(g)). The FSA, as part of its supervisory powers, may require a VASP to hold professional indemnity insurance or other forms of financial guarantees as part of its ongoing assessment of risk management or "fit and proper" criteria. It is common practice for financial service providers, including custodians, to carry robust insurance coverage to protect against operational risks, cyber risks, and potential losses. The absence of an explicit mandate in the primary Act does not preclude such requirements from being imposed through FSA directives, guidelines, or as part of the licensing conditions based on the nature and scale of operations.

custody 60% confidence

While not explicitly named, the best practice for safeguarding virtual assets, especially large amounts, typically involves a combination of hot and cold storage solutions. The FSA would expect a VASP to implement industry-standard security measures, which would likely include cold storage for a significant portion of client assets, as part of its compliance with the general cybersecurity and asset safeguarding requirements.

custody 60% confidence

Instead, any entity that provides "custody or administration of virtual assets or instruments enabling control over virtual assets" as a business is considered a Virtual Asset Service Provider (VASP) and must be licensed as such by the FSA. Therefore, a "qualified custodian" in Seychelles' context is effectively a VASP that holds the necessary license and complies with all the requirements of the VASP Act for providing custody services.

aml 60% confidence

Virtual Asset Service Providers Act, 2022 (VASP Act 2022): This is the cornerstone legislation specifically regulating VASPs. It mandates licensing, registration, and compliance with AML/CFT obligations for entities engaged in virtual asset services.

aml 60% confidence

Anti-Money Laundering and Countering the Financing of Terrorism Act, 2020 (AML/CFT Act 2020): This is the overarching AML/CFT legislation in Seychelles, applying to all designated non-financial businesses and professions (DNFBPs) and financial institutions, which now explicitly includes VASPs. The VASP Act builds upon and references the requirements of this broader AML/CFT Act.

aml 60% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

Identification and Verification of Customers:

aml 60% confidence

Natural Persons: Obtain and verify identity through reliable, independent source documents, such as name, residential address, date of birth, nationality, and official identification numbers.

aml 60% confidence

Legal Persons/Arrangements: Obtain and verify identity information such as name, legal form, proof of existence, powers that regulate the legal person, names of directors/partners, and the address of the registered office or place of business.

aml 60% confidence

Beneficial Ownership Identification: Identify and verify the identity of the beneficial owner(s) of the customer. For legal persons, this typically involves identifying individuals who ultimately own or control more than 25% of the entity.

aml 60% confidence

Purpose and Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship, including scrutiny of transactions undertaken throughout the course of the relationship, to ensure that the transactions are consistent with the VASP’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 60% confidence

Enhanced Due Diligence (EDD): Apply EDD for higher-risk scenarios, including:

aml 60% confidence

Transactions with Politically Exposed Persons (PEPs).

aml 60% confidence

Business relationships or transactions with persons from high-risk jurisdictions identified by FATF or the domestic AML/CFT framework.

aml 60% confidence

Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.

aml 60% confidence

Specific virtual asset activities deemed higher risk.

aml 60% confidence

Reporting Obligation: A VASP must immediately report to the FIU when it knows, suspects, or has reasonable grounds to suspect that funds or other assets are proceeds of a criminal activity, or are related to terrorist financing, or other money laundering activities.

aml 60% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be made.

aml 60% confidence

CDD Records: All records obtained through CDD procedures (e.g., copies of identification documents, account files, business correspondence).

aml 60% confidence

Transaction Records: Records of all domestic and international transactions, including the amount, currency, and type of virtual asset, transaction dates, and parties involved.

licensing 60% confidence

Issuing Public Warnings: Against entities operating without a license or misrepresenting their licensing status in Seychelles, often encompassing investment schemes, forex, and implicitly, crypto-related activities.

licensing 60% confidence

License Revocations/Suspensions: For non-compliance within the broader financial services sector, which can indirectly affect entities dealing with virtual assets.

enforcement 60% confidence

Entity Targeted: Numerous entities falsely claiming to be licensed or operating without proper authorization. While not always explicitly "crypto," many involve fraudulent investment schemes, forex trading, or brokerage services that often interact with digital assets. Violation Type: Operating without a license, misrepresentation of licensing status, unauthorized financial services activities, potential fraud. Penalty Amount: N/A (no monetary fine typically disclosed for these warnings, but the entity is ordered to cease operations and public is warned). Outcome: Public awareness, cessation of unauthorized activities (if complied), potential further legal action if non-compliant.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet/SaaS provider may operate in Seychelles only by obtaining a VASP license from the FSA (high burden), maintaining a local presence, segregating client assets, and complying with comprehensive AML/CFT obligations; no distinct "qualified custodian" category or explicit proof-of-reserves/insurance mandate exists, creating some regulatory ambiguity.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?