← Regulations / Sao Tome and Principe / Operating Models / DeFi frontend

DeFi protocol frontend in Sao Tome and Principe

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Sao Tome and Principe without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) — must identify and verify customer identity (name, address, date of birth, nationality, unique ID) under Lei n.º 10/2012 as amended by Lei n.º 7/2020.
  • Beneficial ownership identification and verification required for all customers.
  • Ongoing monitoring of business relationships and scrutiny of transactions.
  • Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, and transactions with no apparent economic purpose.
  • Suspicious Transaction Reporting (STR) to the Unidade de Informação Financeira (UIF) — must report any suspected ML/TF activity regardless of amount.
  • No tipping-off — prohibited from disclosing to customers or third parties that an STR is being submitted.
  • Record-keeping obligations: customer identification data, transaction records (amount, currency, date, parties), and business correspondence must be retained.
  • Internal AML/CFT policies, controls, and training required under Lei n.º 10/2012.

Key Restrictions

  • If the frontend facilitates exchange of virtual assets for fiat currency (STN), it may be deemed to require a banking license or payment service provider license from BCSTP.
  • If the frontend takes any form of custody of user assets, it enters a regulatory grey area and general financial services laws may apply.
  • Pure crypto-to-crypto frontends (no fiat on/off ramp, no custody) operate in a regulatory grey area with no specific licensing regime.
  • No specific geofencing or KYC obligations are codified for crypto frontends — obligations arise only under general AML law if the entity is deemed an obliged entity.

Key Risks

  • Regulatory ambiguity — STP has no dedicated VASP registration or licensing regime, creating uncertainty whether a DeFi frontend is a regulated entity at all.
  • Fee-taking (e.g., swap fees, frontend fees) may be recharacterized as a financial service activity, potentially triggering traditional financial license requirements.
  • BCSTP has issued public warnings discouraging crypto use and may take enforcement action against unlicensed entities perceived as engaging in financial intermediation.
  • Lack of specific crypto enforcement precedent makes it difficult to predict regulatory response.
  • FATF Recommendation 15 requires STP to regulate VASPs — future regulatory changes could impose retroactive obligations or licensing requirements.
  • Small market size and Portuguese-language regulatory environment create operational and compliance research challenges.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Neither a dedicated Registration nor Licensing Regime for VASPs: As of the latest information, STP does not have a specific regime for registering or licensing virtual asset service providers.

licensing 40% confidence

Implication: Companies operating solely with crypto-to-crypto transactions might operate in a regulatory grey area from a specific licensing perspective. However, any interaction with traditional fiat currency or the broader financial system would likely bring them under the purview of existing financial regulations.

licensing 40% confidence

If an exchange facilitates the exchange of virtual assets for fiat currency (e.g., STN - Sao Tome Dobra) or vice versa, and offers services akin to traditional banking or money remittance, it might be deemed to be conducting activities that require a banking license or a payment service provider license from the Banco Central de São Tomé e Príncipe (BCSTP).

licensing 40% confidence

Pure crypto-to-crypto exchanges might not require a specific license yet, but they would still be subject to AML/CFT obligations if they deal with "funds" or "assets" in a broad sense.

licensing 40% confidence

AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most crucial and universally applicable requirement, even in the absence of specific crypto licensing. STP has AML/CFT legislation in line with international standards (FATF recommendations). Any entity dealing with funds, regardless of their nature (fiat or virtual assets), would be subject to:

licensing 40% confidence

Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures.

licensing 40% confidence

Suspicious Transaction Reporting (STR) to the Financial Information Unit (FIU) of Sao Tome and Principe.

licensing 40% confidence

Internal AML/CFT policies, controls, and training.

aml 60% confidence

Lei n.º 10/2012, de 23 de Agosto (Law No. 10/2012, of August 23): This is the foundational law for the Prevention and Combat of Money Laundering and Terrorism Financing. It establishes the general framework for AML/CFT obligations for financial and non-financial institutions.

aml 60% confidence

Lei n.º 7/2020, de 16 de Julho (Law No. 7/2020, of July 16): This law amended and republished Law No. 10/2012. Amendments typically reflect updated FATF recommendations and often broaden the scope of obliged entities or strengthen specific requirements (like beneficial ownership or risk-based approaches), which would implicitly apply to emerging sectors like virtual assets.

aml 60% confidence

Identification and Verification of Customers:

aml 60% confidence

Beneficial Ownership: Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) of the customer, including natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.

aml 60% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 60% confidence

Enhanced Due Diligence (EDD): Applying enhanced measures for higher-risk customers, relationships, or transactions, such as:

aml 60% confidence

Report Suspicious Transactions: Report to the Financial Intelligence Unit (UIF) any transaction, attempted transaction, or activity that they know, suspect, or have reasonable grounds to suspect involves funds derived from criminal activity or is related to terrorism financing, regardless of the amount.

aml 60% confidence

No Tipping-Off: Obliged entities, their directors, officers, and employees are prohibited from disclosing to the customer or to third parties that an STR is being or has been submitted.

aml 60% confidence

Customer Identification Data: All records obtained through CDD procedures (e.g., copies of identification documents, verification data).

aml 60% confidence

Transaction Records: Details of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).

enforcement 20% confidence

Primary Regulator: The main financial regulator in Sao Tome and Principe is the Banco Central de São Tomé e Príncipe (BCSTP). Their pronouncements on digital currencies typically revolve around issuing warnings to the public about the risks associated with cryptocurrencies, rather than specific enforcement actions against entities. They often emphasize that cryptocurrencies are not legal tender.

enforcement 20% confidence

Entity Targeted: General public / Unlicensed entities (implicitly). Violation Type: Engaging with unregulated, volatile, and potentially fraudulent virtual assets; operating without proper licensing (though specific crypto licensing frameworks might not even exist). Penalty Amount: N/A (as these are warnings, not penalties).

custody 60% confidence

There are no specific licensing requirements for cryptocurrency custodians in Sao Tome and Principe.

custody 60% confidence

FATF Recommendation 15 specifically addresses new technologies and recommends that Virtual Asset Service Providers (VASPs), which would include custodians, be regulated for AML/CFT purposes, licensed or registered, and subject to effective systems for monitoring and supervision.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend operating in/from STP is not subject to a specific crypto licensing regime, but may face AML/CFT obligations under general law if deemed an obliged entity, and must avoid fiat conversion or custody to minimize the risk of triggering traditional financial services licensing requirements.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?