← Regulations / Tajikistan / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Tajikistan

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Tajikistan without local incorporation, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD) required under Law No. 659 (28.08.2010) — must obtain and verify identity of natural persons (full name, date of birth, address, national ID) and legal entities (name, legal form, address, registration number)
  • Beneficial ownership identification — must identify individuals owning 25% or more of shares/voting rights or exercising control
  • Purpose and intended nature of business relationship must be understood and documented
  • Ongoing transaction monitoring for consistency with customer risk profile
  • Risk-sensitive CDD — Enhanced Due Diligence (EDD) for high-risk customers/products, Simplified CDD (SCDD) only for genuinely low-risk scenarios
  • Suspicious Transaction Reporting (STR) — must report any transaction (no minimum threshold) with reasonable grounds to suspect ML/TF, submitted promptly to the Financial Monitoring Department (FMD) of the National Bank of Tajikistan
  • No tipping-off prohibition — cannot disclose STR filings to customers or third parties
  • Record-keeping: CDD documents, transaction records (including wallet addresses), and STR copies must be retained for at least 5 years after business relationship ends or transaction completed
  • Designate a management-level AML/CFT Officer responsible for compliance oversight
  • No specific crypto-AML framework exists — obligations derive from general AML law and would apply only if VASPs are formally recognized; currently high legal uncertainty on how these attach to custodial wallet/SaaS operators

Key Restrictions

  • No licensing framework for crypto custody or VASP services exists in Tajikistan — cannot obtain a formal 'crypto license' or 'qualified custodian' status
  • National Bank of Tajikistan (NBT) has explicitly stated cryptocurrencies are not legal tender and has warned citizens against use, trading, or investment in virtual assets
  • Implicit prohibition in practice — the lack of any legal framework combined with NBT warnings creates an effectively hostile operating environment
  • Traditional banking channels for fiat on/off-ramps would likely be blocked or denied by NBT-regulated banks
  • No legal basis exists for providing institutional-grade custody services for virtual assets
  • Payment processing via crypto is explicitly contradicted by NBT stance — existing NBT payment licenses cover only fiat currency
  • No specific capital requirements exist, but also no license to apply for — operators face structural legal uncertainty

Key Risks

  • High enforcement risk — NBT may issue cease-and-desist orders or refer matters to law enforcement for operating without authorization
  • Regulatory ambiguity — no formal VASP recognition means AML obligations (Law No. 659) may technically apply but without clear supervisory guidance for crypto custodians
  • Banking access risk — inability to maintain correspondent or operational banking relationships due to NBT hostility toward crypto
  • FATF/EAG mutual evaluation risk — Tajikistan is an EAG member; future FATF-driven regulation could retroactively penalize unregistered operators
  • No segregation, insurance, or proof-of-reserves rules exist for crypto custody — zero consumer/institutional asset protection framework

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

No Specific Licensing Regime: There are no specific licenses for cryptocurrency exchanges, custody providers, or payment processors designed for virtual assets in Tajikistan. This means you cannot apply for a "crypto license" as you would in, say, Singapore or Malta.

licensing 60% confidence

National Bank of Tajikistan (NBT) Stance: The NBT has repeatedly issued warnings and statements clarifying that cryptocurrencies are not legal tender in Tajikistan. They have cautioned citizens against the use, trading, or investment in virtual assets, citing risks such as financial fraud, money laundering, and the financing of terrorism.

licensing 60% confidence

Implicit Prohibition: The lack of a legal framework for operation, coupled with explicit warnings and the non-recognition of virtual assets as legal tender or regulated financial instruments, effectively creates an environment where most virtual asset activities are either unregulated and high-risk, or implicitly prohibited.

licensing 60% confidence

No Registration Regime: Similarly, there is no specific registration regime for VASPs like in some other jurisdictions (e.g., AML registration).

licensing 60% confidence

Cryptocurrency Exchanges: Would likely be operating in an unregulated space, with significant legal uncertainty and risk of enforcement action from the NBT or other state bodies. Any attempt to use traditional banking channels for fiat on/off-ramps would likely be flagged and potentially denied by banks adhering to the NBT's warnings.

licensing 60% confidence

Custody Providers: Similar to exchanges, there's no legal basis for providing institutional-grade custody services for virtual assets.

licensing 60% confidence

Payment Processors: Any entity attempting to process payments using cryptocurrencies would be in direct conflict with the NBT's stance that cryptocurrencies are not legal tender and are not permitted for payments. Existing payment processor licenses issued by the NBT are for traditional fiat currency services and would not extend to virtual assets.

licensing 60% confidence

Capital Requirements: No specific capital mandates for crypto-related businesses.

licensing 60% confidence

AML/KYC Requirements (Specific to Crypto): While Tajikistan has general Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) laws (aligned with FATF standards), these do not specifically detail obligations for virtual asset service providers because such providers are not formally recognized or regulated. Any financial institution that does operate must comply with general AML/CFT laws.

licensing 60% confidence

Local Presence: No specific requirements for local presence for a crypto business, as there's no license to obtain that would necessitate it.

licensing 60% confidence

National Bank of Tajikistan (NBT) Stance: The NBT has repeatedly issued warnings and statements clarifying that cryptocurrencies are not legal tender in Tajikistan. They have cautioned citizens against the use, trading, or investment in virtual assets, citing risks such as financial fraud, money laundering, and the financing of terrorism.

licensing 60% confidence

Relevance: The NBT is the central financial regulator in Tajikistan. While specific direct links to English-language laws or detailed regulatory acts on crypto may not be readily available, their official statements, press releases, and general regulatory framework consistently reflect a cautious to prohibitive stance on virtual assets. You would typically find statements regarding the non-recognition of crypto as legal tender and warnings against its use in the "News" or "Official Statements" sections (though likely in Tajik or Russian).

licensing 60% confidence

FATF (Financial Action Task Force) Mutual Evaluation Reports: Tajikistan is a member of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), a FATF-style regional body. FATF mutual evaluation reports often assess a country's compliance with Recommendation 15 on virtual assets and VASPs. While Tajikistan's full mutual evaluation report might not have an extensive section on its VASP framework because one doesn't exist, it would comment on its general AML/CFT regime.

aml 40% confidence

Law of the Republic of Tajikistan "On Combating Legalization (Laundering) of Proceeds from Crime and Financing of Terrorism" (No. 659, dated 28.08.2010, with subsequent amendments). This law sets out the fundamental obligations for financial institutions and other designated non-financial businesses and professions (DNFBPs) regarding AML/CFT.

aml 40% confidence

The National Bank of Tajikistan (NBT):

aml 40% confidence

The Financial Monitoring Department (FMD) of the National Bank of Tajikistan:

aml 40% confidence

Identification and Verification:

aml 40% confidence

Obtain and record reliable identification data for both natural persons (e.g., full name, date of birth, address, national identification number) and legal entities (e.g., name, legal form, address, registration number, articles of incorporation).

aml 40% confidence

Verify this information using independent and reliable source documents, data, or information (e.g., government-issued ID, utility bills, company registration documents).

aml 40% confidence

Identify and verify the identity of the beneficial owner(s) of the customer, ensuring that those who ultimately own or control the customer are known.

aml 40% confidence

For legal entities, this includes identifying individuals who own or control a certain percentage (e.g., 25% or more) of shares or voting rights, or otherwise exercise control through other means.

aml 40% confidence

Purpose and Nature of Business Relationship:

aml 40% confidence

Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for changes in beneficial ownership.

aml 40% confidence

Apply CDD measures on a risk-sensitive basis. Higher-risk customers, products, services, or geographical areas require enhanced CDD (EDD), while lower-risk situations may allow for simplified CDD (SCDD), provided the risks are genuinely low.

aml 40% confidence

Timing of CDD: CDD must be performed when establishing a business relationship, carrying out occasional transactions above a specified threshold, when there is a suspicion of ML/TF, or when there are doubts about the veracity or adequacy of previously obtained customer identification data.

aml 40% confidence

Obligation to Report: VASPs, once recognized under the AML/CFT framework, must report any transaction or attempted transaction, regardless of the amount, where there are reasonable grounds to suspect that it may be linked to money laundering or terrorist financing.

aml 40% confidence

Reporting Authority: All STRs must be submitted promptly to the Financial Monitoring Department (FMD) of the National Bank of Tajikistan.

aml 40% confidence

Indicators of Suspicion: VASPs should develop internal guidelines and train staff to recognize red flags and indicators of suspicious activity specific to virtual assets (e.g., unusual transaction patterns, structuring of transactions below reporting thresholds, use of privacy-enhancing coins without legitimate reason, attempts to obscure source of funds).

aml 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR has been filed or that an investigation is underway.

aml 40% confidence

CDD Records: All documents and information obtained during the CDD process (identification documents, beneficial ownership information, analysis of business purpose).

aml 40% confidence

Transaction Records: Details of all financial transactions, including the amount, currency, date, and parties involved (including wallet addresses if applicable).

aml 40% confidence

STR Records: Copies of all suspicious transaction reports filed.

aml 40% confidence

Retention Period: Records must generally be kept for a period of at least five (5) years after the business relationship ends or after an occasional transaction is completed.

aml 40% confidence

Designate an AML/CFT Officer: Appoint a qualified individual at the management level responsible for overseeing AML/CFT compliance.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS operation is not formally prohibited by statute but exists in a legal vacuum with no licensing pathway, explicit NBT hostility, and implicit prohibition in practice; technically possible only by relying on general AML law (Law No. 659) with extreme enforcement risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?