Remote VASP serving residents in Sao Tome and Principe
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Sao Tome and Principe with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) under Lei n.º 10/2012 (as amended by Lei n.º 7/2020) — obtain and verify name, address, date of birth, nationality, identification number for individuals; legal form, proof of existence, governance for entities.
- Beneficial ownership identification and verification for all customers.
- Ongoing monitoring of business relationships and transactions to ensure consistency with risk profile.
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, and transactions with no apparent lawful purpose.
- Suspicious Transaction Reporting (STR) to the Unidade de Informação Financeira (UIF/FIU) — reports must be made promptly for any suspected ML/TF activity regardless of amount.
- No tipping-off prohibition — cannot disclose to customer or third parties that an STR is being submitted.
- Record-keeping: customer identification data and transaction records must be retained.
- Internal AML/CFT policies, controls, and training programs required.
- Travel Rule (FATF Recommendation 16) — not explicitly adopted; no specific VASP travel-rule obligations currently enforceable.
Key Restrictions
- No specific VASP licensing regime exists — operators exist in a regulatory grey area.
- If the remote VASP facilitates fiat-to-crypto or crypto-to-fiat exchange (STN Dobra), it likely triggers existing banking or payment-service licensing requirements under BCSTP supervision.
- Local entity incorporation, physical office, local management/compliance officer, and fit-and-proper assessment required for any traditional financial license — a remote-only structure with no local presence is unlikely to satisfy these requirements.
- Pure crypto-to-crypto exchange may avoid specific licensing but still triggers AML/CFT obligations.
- Cryptocurrencies are not legal tender in STP (BCSTP Comunicado n.º 001/2022) — the central bank has issued public warnings discouraging crypto use.
Key Risks
- Enforcement risk is low in practice due to the small financial market and limited crypto adoption, but the absence of a clear VASP framework creates regulatory ambiguity.
- FATF/GIABA pressure may lead to future VASP legislation — operators could face sudden compliance obligations or enforcement if laws are enacted retroactively.
- Operating without a fiat-related license while facilitating fiat-crypto conversion carries risk of being deemed an unlicensed financial institution by the BCSTP.
- Public warnings from BCSTP (Comunicado n.º 001/2022) signal a cautious/discouraging posture toward crypto, creating reputational and regulatory tail risk.
- Low public reporting of enforcement actions means operators may not receive clear advance warning of changing regulatory stance.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Neither a dedicated Registration nor Licensing Regime for VASPs: As of the latest information, STP does not have a specific regime for registering or licensing virtual asset service providers.
Implication: Companies operating solely with crypto-to-crypto transactions might operate in a regulatory grey area from a specific licensing perspective. However, any interaction with traditional fiat currency or the broader financial system would likely bring them under the purview of existing financial regulations.
If an exchange facilitates the exchange of virtual assets for fiat currency (e.g., STN - Sao Tome Dobra) or vice versa, and offers services akin to traditional banking or money remittance, it might be deemed to be conducting activities that require a banking license or a payment service provider license from the Banco Central de São Tomé e Príncipe (BCSTP).
Pure crypto-to-crypto exchanges might not require a specific license yet, but they would still be subject to AML/CFT obligations if they deal with "funds" or "assets" in a broad sense.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most crucial and universally applicable requirement, even in the absence of specific crypto licensing. STP has AML/CFT legislation in line with international standards (FATF recommendations). Any entity dealing with funds, regardless of their nature (fiat or virtual assets), would be subject to:
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures.
Suspicious Transaction Reporting (STR) to the Financial Information Unit (FIU) of Sao Tome and Principe.
Local Presence: For any traditional financial license, a significant local presence is typically required, including:
Local management and staff, including a compliance officer.
Lei n.º 10/2012, de 23 de Agosto (Law No. 10/2012, of August 23): This is the foundational law for the Prevention and Combat of Money Laundering and Terrorism Financing. It establishes the general framework for AML/CFT obligations for financial and non-financial institutions.
Lei n.º 7/2020, de 16 de Julho (Law No. 7/2020, of July 16): This law amended and republished Law No. 10/2012. Amendments typically reflect updated FATF recommendations and often broaden the scope of obliged entities or strengthen specific requirements (like beneficial ownership or risk-based approaches), which would implicitly apply to emerging sectors like virtual assets.
Identification and Verification of Customers:
Beneficial Ownership: Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) of the customer, including natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.
Purpose and Intended Nature of the Business Relationship: Understanding the purpose and intended nature of the business relationship.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Applying enhanced measures for higher-risk customers, relationships, or transactions, such as:
Customers from high-risk jurisdictions identified by FATF or national authorities.
Complex or unusually large transactions.
Transactions with no apparent economic or lawful purpose.
Simplified Due Diligence (SDD): Permitted in specific, low-risk circumstances, provided that the obliged entity has determined the relationship or transaction presents a low risk of money laundering or terrorist financing.
Report Suspicious Transactions: Report to the Financial Intelligence Unit (UIF) any transaction, attempted transaction, or activity that they know, suspect, or have reasonable grounds to suspect involves funds derived from criminal activity or is related to terrorism financing, regardless of the amount.
Timeliness: Reports must be made promptly.
No Tipping-Off: Obliged entities, their directors, officers, and employees are prohibited from disclosing to the customer or to third parties that an STR is being or has been submitted.
Customer Identification Data: All records obtained through CDD procedures (e.g., copies of identification documents, verification data).
Transaction Records: Details of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).
Unidade de Informação Financeira (UIF) – Financial Intelligence Unit:
Banco Central de São Tomé e Príncipe (BCSTP) – Central Bank of São Tomé and Príncipe:
No specific legislation or regulatory guidance explicitly implementing the FATF Travel Rule for VASPs has been publicly identified.
Not applicable, as the Travel Rule has not been explicitly adopted or implemented.
Small Financial Market: Sao Tome and Principe has a very small economy and financial sector. The adoption and prevalence of complex cryptocurrency operations that would warrant significant enforcement actions (like those seen in major financial hubs) are extremely limited.
Developing Regulatory Framework: Many smaller nations are still in the early stages of developing specific regulations for cryptocurrencies. Their primary focus tends to be on general financial stability, anti-money laundering (AML), and countering the financing of terrorism (CFT) within traditional banking.
Primary Regulator: The main financial regulator in Sao Tome and Principe is the Banco Central de São Tomé e Príncipe (BCSTP). Their pronouncements on digital currencies typically revolve around issuing warnings to the public about the risks associated with cryptocurrencies, rather than specific enforcement actions against entities. They often emphasize that cryptocurrencies are not legal tender.
Lack of Public Reporting: Even if smaller, localized enforcement actions (e.g., against a very small local operation or individual) were to occur, they are rarely reported beyond national borders or in a manner that is easily accessible internationally.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving residents from abroad faces a regulatory grey area: pure crypto-to-crypto operations may avoid specific licensing but trigger AML/CFT obligations under Lei n.º 10/2012, while any fiat interaction likely requires a traditional financial license (banking/payment) that demands local incorporation, physical presence, and BCSTP supervision, making a purely remote fiat-touching structure effectively impermissible.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?