← Regulations / Timor-Leste / Operating Models / On-shore VASP

On-shore VASP in Timor-Leste

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in Timor-Leste with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • Implement customer due diligence (CDD): identify and verify individual customers (full legal name, date of birth, nationality, address, government-issued ID) and legal entities (name, legal form, proof of existence, beneficial owners >25%). — tl.licensing.customer-due-diligence-identifying-and, tl.aml.identification-and-verification, tl.aml.for-individuals-obtain-and-verify, tl.aml.for-legal-entities-companies-obtain
  • Conduct ongoing monitoring of transactions to ensure consistency with customer risk profile; scrutinize unusual or large transactions. — tl.licensing.monitoring-transactions-for-suspicious-activity, tl.aml.ongoing-monitoring-continuously-monitor-transactions
  • Report suspicious transactions (regardless of value) to the Unidade de Informação Financeira (UIF) / FIU when there are reasonable grounds to suspect money laundering or terrorist financing. — tl.licensing.reporting-suspicious-transactions-to-the, tl.aml.obligation-to-report-vasps-are, tl.aml.the-funds-are-the-proceeds, tl.aml.the-funds-are-linked-to
  • Apply Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, and non-face-to-face relationships. — tl.aml.enhanced-due-diligence-edd, tl.aml.apply-edd-measures-for-higher-risk, tl.aml.politically-exposed-persons-peps, tl.aml.customers-from-high-risk-geographic-locations, tl.aml.complex-unusually-large-transactions-or, tl.aml.business-relationships-and-transactions-with
  • Apply Simplified Due Diligence (SDD) only in clearly defined low-risk situations after a thorough risk assessment. — tl.aml.simplified-due-diligence-sdd, tl.aml.may-apply-sdd-in-clearly
  • Observe the 'No Tipping-Off' rule: do not disclose STR submissions to customers or third parties. — tl.aml.no-tipping-off-rule-vasps-their
  • Retain CDD records for at least 5 years after the business relationship ends, and transaction records for at least 5 years from the transaction date. — tl.aml.customer-identification-data-all-records, tl.aml.transaction-records-all-records-relating
  • Compliance is governed by Law No. 2/2011 (or Law No. 3/2011) on Prevention and Combat of Money Laundering and Financing of Terrorism, supervised by BCTL and the UIF. — tl.licensing.law-no-22011-on-the, tl.aml.law-no-32011-on-prevention, tl.aml.banco-central-de-timor-leste-bctl, tl.aml.the-bctl-is-responsible-for, tl.aml.unidade-de-informao-financeira-uif

Key Restrictions

  • No specific VASP license or registration exists — the operator cannot obtain a 'crypto license' and must instead comply with general business and financial laws. — tl.licensing.no-specific-licenses-are-currently, tl.licensing.neither-a-specific-registration-nor
  • If activities blur into traditional financial services (e.g., holding fiat deposits, fiat-to-fiat transfers, fiat lending backed by crypto), the operator may inadvertently fall under existing BCTL licensing for banks, payment service providers, or other financial institutions. — tl.licensing.if-a-service-providers-activities
  • General company registration and business licensing laws apply, typically requiring a registered office and local representation in Timor-Leste. — tl.licensing.local-presence-no-specific-local
  • No specific capital requirements for VASPs unless the operator seeks a traditional financial license, in which case significant BCTL capital requirements apply. — tl.licensing.capital-requirements-no-specific-capital

Key Risks

  • Regulatory ambiguity: lack of crypto-specific laws creates uncertainty about legal obligations for on-shore VASPs; the operator operates in a grey area. — tl.licensing.lack-of-specific-regulation-is
  • Enforcement risk: while BCTL has issued public warnings about crypto risks, enforcement may be limited but could escalate if the FATF pushes for VASP regulation or if the operator facilitates illicit activity. — tl.enforcement.issuing-warnings-and-advisories-the, tl.enforcement.prioritization-enforcement-efforts-in-smaller
  • AML/CFT compliance risk: failure to comply with general AML laws (Law No. 2/2011 or Law No. 3/2011) could lead to criminal charges if illicit activities are facilitated. — tl.licensing.the-general-amlcft-laws-of
  • Tax uncertainty: treatment of crypto services under the 2.5% Sales Tax is ambiguous; exchange fees, custodial fees, and consulting fees may be considered taxable services. — tl.tax.crypto-related-services-however-services-related
  • No segregation or custody rules exist: client digital assets lack the protection of mandated segregation, insurance, or cold storage requirements. — tl.custody.segregation-of-client-assets-rules, tl.custody.no-specific-rules-mandate-the, tl.custody.no-specific-insurance-or-bonding, tl.custody.cold-storage-mandates

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Lack of Specific Regulation is Not the Same as Legality or Full Freedom: While there are no crypto-specific licenses, any entity operating within Timor-Leste would still be subject to general business laws, tax laws, and potentially, if their activities could be interpreted as traditional financial services, existing financial sector legislation overseen by the Banco Central de Timor-Leste (BCTL).

licensing 40% confidence

AML/CFT Obligations: Even without specific VASP regulation, Timor-Leste, as a member of the international community, is subject to the recommendations of the Financial Action Task Force (FATF). Its existing Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) laws (such as Law No. 2/2011 on the Prevention and Combat of Money Laundering and Financing of Terrorism, and any subsequent updates) would apply to financial institutions and designated non-financial businesses and professions (DNFBPs). The BCTL and other relevant authorities would expect any entity involved in financial transactions, even those involving virtual assets, to have robust AML/KYC controls in place to prevent illicit activities.

licensing 40% confidence

No specific licenses are currently required for crypto-specific activities.

licensing 40% confidence

If a service provider's activities blur the lines with traditional financial services (e.g., holding fiat currency deposits, facilitating fiat-to-fiat transfers through crypto, or providing lending services in fiat backed by crypto), they might inadvertently fall under existing financial services laws and require a license as a financial institution, payment service provider, or money service business from the BCTL. However, for pure crypto-to-crypto activities or non-custodial wallets, there is no direct precedent or requirement.

licensing 40% confidence

Neither a specific registration nor a licensing regime exists for VASPs.

licensing 40% confidence

Capital Requirements: No specific capital requirements for VASPs as there are no specific licenses. If a business were to seek a traditional financial license (e.g., as a payment service provider), then the BCTL's requirements for that specific license would apply, which include significant capital.

licensing 40% confidence

Customer due diligence (identifying and verifying customers).

licensing 40% confidence

Monitoring transactions for suspicious activity.

licensing 40% confidence

Reporting suspicious transactions to the national Financial Intelligence Unit (FIU), likely housed within the Ministry of Finance or Central Bank.

licensing 40% confidence

Local Presence: No specific local presence requirements for VASPs given the lack of specific regulation. However, to operate any business in Timor-Leste, general company registration and business licensing laws would apply, which typically require a registered office and local representation.

licensing 40% confidence

The general AML/CFT laws of Timor-Leste (e.g., Law No. 2/2011) would be the guiding principles. Failure to comply with these general obligations could lead to criminal charges if illicit activities are facilitated.

licensing 40% confidence

Law No. 2/2011 on the Prevention and Combat of Money Laundering and Financing of Terrorism: This is Timor-Leste's primary AML/CFT law. While it likely does not explicitly mention "virtual assets" or "VASPs," its general provisions apply to entities engaged in financial activities and would be the basis for any enforcement action related to money laundering or terrorism financing through crypto. Finding the official, current version of this law online through a public government portal can be challenging for Timor-Leste. You may need to consult local legal resources.

aml 40% confidence

Law No. 3/2011 on Prevention and Combat of Money Laundering and Financing of Terrorism (Lei N.º 3/2011 de Prevenção e Combate ao Branqueamento de Capitais e ao Financiamento do Terrorismo): This is the foundational law that establishes the framework for AML/CFT in Timor-Leste. It defines money laundering and terrorist financing offenses, sets out reporting obligations for financial institutions and designated non-financial businesses and professions (DNFBPs), and establishes the Financial Intelligence Unit (FIU).

aml 40% confidence

Banco Central de Timor-Leste (BCTL - Central Bank of Timor-Leste):

aml 40% confidence

The BCTL is responsible for the overall supervision of financial institutions in Timor-Leste, including ensuring their compliance with AML/CFT requirements.

aml 40% confidence

Unidade de Informação Financeira (UIF) / Financial Intelligence Unit (FIU) of Timor-Leste:

aml 40% confidence

Identification and Verification:

aml 40% confidence

For individuals: Obtain and verify identity using reliable, independent source documents, data, or information (e.g., full legal name, date of birth, nationality, residential address, unique identification number from government-issued ID like passport or national ID card).

aml 40% confidence

For legal entities (companies): Obtain and verify the company's name, legal form, proof of existence, powers that regulate and bind the legal person, names of relevant persons holding senior management positions, and identify and verify beneficial owners (those who ultimately own or control more than a certain percentage, typically 25% or 10%).

aml 40% confidence

Ongoing Monitoring: Continuously monitor transactions and the business relationship to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes scrutinizing transactions to ensure they are not suspicious.

aml 40% confidence

Enhanced Due Diligence (EDD):

aml 40% confidence

Politically Exposed Persons (PEPs)

aml 40% confidence

Customers from high-risk geographic locations (as identified by FATF or national lists)

aml 40% confidence

Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.

aml 40% confidence

Business relationships and transactions with no face-to-face contact.

aml 40% confidence

Simplified Due Diligence (SDD):

aml 40% confidence

Obligation to Report: VASPs are obligated to report to the Unidade de Informação Financeira (UIF) any transaction, regardless of its value, where they have reasonable grounds to suspect that:

aml 40% confidence

The funds are the proceeds of criminal activity (money laundering).

aml 40% confidence

The funds are linked to terrorist financing.

aml 40% confidence

"No Tipping-Off" Rule: VASPs, their directors, officers, and employees are prohibited from disclosing to the customer or any third party that an STR has been or will be submitted to the UIF.

aml 40% confidence

Customer Identification Data: All records obtained through CDD procedures (e.g., copies of identification documents, verification data). These must be kept for at least five (5) years after the business relationship has ended.

aml 40% confidence

Transaction Records: All records relating to transactions (e.g., amounts, currencies, dates, parties involved, account numbers, virtual asset wallet addresses/transaction IDs). These must be kept for at least five (5) years from the date of the transaction.

custody 40% confidence

Segregation of Client Assets Rules:

custody 40% confidence

No specific rules mandate the segregation of client digital assets from a custodian's proprietary assets.

custody 40% confidence

No specific insurance or bonding requirements for cryptocurrency custodians are in place.

custody 40% confidence

Cold Storage Mandates:

tax 60% confidence

Crypto-Related Services: However, services related to cryptocurrency, such as exchange fees charged by a local service provider, custodial services, or consulting services, could potentially be subject to the 2.5% Sales Tax if they are deemed a taxable service provided in Timor-Leste. This area remains ambiguous due to the lack of specific guidance.

enforcement 20% confidence

Issuing Warnings and Advisories: The BCTL has previously issued statements cautioning the public about the risks associated with cryptocurrencies, highlighting their volatile nature, lack of regulatory oversight, and potential for use in illicit activities. These are general advisories rather than enforcement actions against specific entities.

enforcement 20% confidence

Prioritization: Enforcement efforts in smaller, developing economies often prioritize more traditional forms of financial crime due to limited resources and the nascent stage of crypto adoption.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — an on-shore VASP may operate in Timor-Leste under general business and AML laws (no specific crypto license exists), but must comply with Law No. 2/2011 or 3/2011 AML/CFT obligations, register as a local business, and avoid activities that trigger traditional financial services licensing.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?