Centralized exchange in Trinidad and Tobago
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Trinidad and Tobago with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP must obtain a license under the Virtual Asset Business Act, 2022 (VABA, 2022) and comply with the AML/CFT obligations in the Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13
- Customer Due Diligence: Identify and verify customers (individuals: full name, DOB, address, nationality, ID number; legal persons: name, registration, constitutional documents)
- Beneficial Ownership: Identify and verify beneficial owners of legal persons/arrangements
- PEP Screening: Enhanced scrutiny for domestic and foreign PEPs, their family members, and close associates; require senior management approval for relationships
- Enhanced Due Diligence (EDD): Required for high-risk situations — PEPs, cross-border correspondent relationships, complex/unusually large transactions, high-risk FATF jurisdictions, anonymity-enhancing virtual assets
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile
- Suspicious Transaction Reports (STRs): File with the Financial Intelligence Unit (FIU) of Trinidad and Tobago promptly upon suspicion of ML/TF
- No tipping-off prohibition: Cannot disclose to customer or third party that an STR has been filed
- Record-keeping: Maintain CDD records, transaction records (amount, type, date, addresses), analysis records, and STR copies for at least 5 years
- Travel Rule: For cross-border virtual asset transfers ≥ US$1,000/€1,000 — collect and transmit originator name, VA address, physical address or ID number, DOB; and beneficiary name, VA address, physical address or ID number; transmit securely in real/near-real time
- Travel Rule: For domestic transfers ≥ US$3,000/€3,000 — same information requirements as cross-border
- Travel Rule: Collect and retain originator and beneficiary info for ALL transfers regardless of threshold; provide to authorities upon request
- Screen customers and transactions against UN Consolidated Sanctions List (legally binding), OFAC SDN List, EU Sanctions Lists, and domestic lists under the Anti-Terrorism Act
- Sanctions screening obligations: Implement robust KYC/CDD, screen against sanctions lists regularly, conduct ongoing monitoring for red flags and sanctions evasion
Key Restrictions
- Must obtain a VASP license from the Central Bank of Trinidad and Tobago (CBTT) which began accepting applications in September 2023, with full enforcement from May 2024
- Must be licensed as a VASP — operating without a license carries penalties: for individuals — fine of TTD $500,000 and five years imprisonment; for body corporate — fine of TTD $2,000,000
- Cryptocurrencies are NOT legal tender in Trinidad and Tobago and the CBTT has stated they are generally unregulated under existing financial services laws absent VASP licensing
- Must implement travel-rule compliance solutions (technology-agnostic but must enable secure, verifiable data transfer — TRISA, Shyft, OpenVASP, etc.)
- Must comply with mandatory UN Security Council sanctions obligations as a UN member state
- Must implement sanctions screening against UN, OFAC, and EU lists given the global nature of virtual asset transactions and USD/EUR dependency for fiat on/off ramps
Key Risks
- Enforcement exposure under Anti-Terrorism Act (up to 25 years imprisonment for terrorism financing) and Proceeds of Crime Act (asset forfeiture including virtual assets)
- Secondary sanctions risk from OFAC/EU due to inherently cross-border nature of virtual asset transactions and reliance on international correspondent banking
- Regulatory ambiguity: CBTT has historically stated crypto is unregulated — the VASP Act framework is still relatively new (effective May 2024), creating uncertainty in interpretation and enforcement
- FATF grey/black list jurisdiction risk: Enhanced due diligence from foreign counterparties if T&T is identified as having strategic AML/CFT deficiencies
- High operational burden: Must simultaneously comply with VABA, Anti-Terrorism Act, Proceeds of Crime Act, FIU Act, and travel-rule obligations with significant criminal penalties for non-compliance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Business Act, 2022 (VABA, 2022): This is the foundational law for virtual assets and VASPs, defining what constitutes a "virtual asset" and "virtual asset business" and establishing the regulatory framework. It mandates licensing and compliance with AML/CFT obligations for VASPs.
Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13: This is the overarching AML/CFT legislation that applies to all financial institutions, including VASPs under the VABA. It sets out the general requirements for AML/CFT compliance, including CDD, STRs, and record-keeping.
Proceeds of Crime Act, Chap 11:27: This Act criminalizes money laundering and the financing of terrorism, providing the legal basis for prosecuting such offenses and seizing assets.
Financial Intelligence Unit Act, Chap 72:01: This Act establishes the Financial Intelligence Unit (FIU) as the central national agency for receiving, analyzing, and disseminating suspicious transaction reports and other financial intelligence.
Identification and Verification of Customers:
For Individuals: Obtain and verify the customer's full legal name, date of birth, residential address, nationality, and a unique identification number (e.g., passport number, national ID card number). Verification must be done using reliable, independent source documents, data or information.
For Legal Persons/Arrangements (e.g., companies, trusts): Obtain and verify the legal name, principal place of business, registration number, articles of incorporation, bylaws, and other relevant constitutional documents.
Beneficial Ownership: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons and arrangements. This involves understanding the ownership and control structure of the customer.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or transaction (e.g., why is the customer using VASP services, what types of virtual assets will be involved, expected transaction volumes).
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information and beneficial ownership up-to-date.
Politically Exposed Persons (PEPs): Implement enhanced scrutiny for customers who are PEPs (domestic or foreign) or their family members or close associates. This includes obtaining senior management approval for establishing business relationships with PEPs and taking reasonable measures to establish the source of wealth and source of funds.
Enhanced Due Diligence (EDD): Apply EDD in situations identified as high-risk, such as:
Relationships with PEPs.
Cross-border correspondent relationships.
Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
Customers residing in or transactions involving high-risk jurisdictions identified by the FATF or other relevant bodies.
Transactions involving anonymity-enhancing virtual assets.
Trigger: Any VASP that knows, suspects, or has reasonable grounds to suspect that a transaction (attempted or completed), virtual asset, or funds are linked to money laundering, terrorist financing, or other criminal activity, must file an STR.
Reporting Body: Financial Intelligence Unit (FIU) of Trinidad and Tobago.
Timeline: Reports must be submitted promptly, typically within a few working days of forming the suspicion, and in accordance with FIU guidelines.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been or will be filed, or that an investigation is being conducted.
Customer Records: All records obtained during CDD, including identification documents, verification data, beneficial ownership information, and the assessment of the purpose and nature of the business relationship.
Transaction Records: Detailed records of all virtual asset transactions, including the amount, type of virtual asset, date, time, originating and beneficiary addresses (or equivalent identifiers), and any other relevant transaction data. These records must be sufficient to reconstruct individual transactions.
Analysis Records: Records of any analysis undertaken concerning complex, unusual, or large transactions, and the findings of such analysis.
STRs: Copies of all suspicious transaction reports filed, along with supporting documentation.
For cross-border virtual asset transfers: Information must accompany the transfer for transactions equal to or exceeding US$1,000 or €1,000 (or the equivalent in other currencies).
For domestic virtual asset transfers: Information must accompany the transfer for transactions equal to or exceeding US$3,000 or €3,000 (or the equivalent in other currencies).
Important Note: Regardless of the threshold, VASPs are required to collect and retain originator and beneficiary information for all virtual asset transfers, including those below the thresholds, and provide it to competent authorities upon request.
Collect and Transmit Required Information:
For Originator: Name, Virtual Asset Address (or unique transaction identifier), physical address or national identification number or customer identification number, date and place of birth (if applicable).
For Beneficiary: Name, Virtual Asset Address (or unique transaction identifier), physical address or national identification number or customer identification number, date and place of birth (if applicable).
Secure Transmission: Ensure that the required information is transmitted securely and reliably with the virtual asset transfer.
Real-time or Near Real-time Availability: The information should be made available to the beneficiary VASP and competent authorities in a timely manner.
Record Keeping: Maintain records of all collected information for at least five years from the date of the transaction.
Interoperability: While no specific technology standard is mandated (e.g., TRISA, Shyft, OpenVASP), VASPs must implement solutions that allow them to fulfill the data transfer and record-keeping requirements in a secure and verifiable manner. They are expected to have robust systems for identity verification (KYC) and transaction monitoring (AML/CFT).
For an individual: A fine of TTD $500,000 and imprisonment for five years.
For a body corporate: A fine of TTD $2,000,000.
Regulator Name: Central Bank of Trinidad and Tobago (CBTT)
Statements on Regulatory Stance: Clarifying that cryptocurrencies are not legal tender and are generally unregulated under existing financial services laws, which limits the scope for traditional "enforcement actions" against entities operating solely in this space unless they infringe on other laws (e.g., fraud, money laundering, unregistered securities offerings).
Anti-Terrorism Act, Chap. 12:07: This act provides for measures against terrorism and includes provisions for implementing UN Security Council Resolutions related to terrorism and its financing, including the freezing of assets of designated terrorist entities and individuals.
Proceeds of Crime Act, Chap. 11:27: This act deals with money laundering offences, confiscation of criminal proceeds, and related matters, which can indirectly support sanctions enforcement by targeting illicit financial flows.
Financial Intelligence Unit of Trinidad and Tobago Act, Chap. 72:01: Establishes the FIU, which plays a crucial role in receiving, analyzing, and disseminating suspicious transaction reports (STRs) and suspicious activity reports (SARs) related to ML, TF, and other financial crimes, including sanctions violations.
Implement Robust Know Your Customer (KYC) and Customer Due Diligence (CDD) procedures: This includes identifying and verifying the identity of customers and beneficial owners.
Screen against Sanctions Lists: Regularly screen customers, counterparties, and transactions against:
UN Consolidated Sanctions List: This is legally binding for T&T.
OFAC Specially Designated Nationals (SDN) List and other OFAC lists: Essential due to the dominance of the USD in global finance and the extraterritorial reach of OFAC.
EU Sanctions Lists: Important for similar reasons if dealing with EU counterparties or currencies.
Domestic Lists: Any individuals or entities designated under T&T's Anti-Terrorism Act or similar legislation.
Ongoing Monitoring: Continuously monitor transactions for red flags indicative of sanctions evasion or illicit activity.
Politically Exposed Persons (PEPs) Screening: Identify and apply enhanced due diligence to PEPs, their family members, and close associates, as PEPs often present a higher risk for corruption and sanctions evasion.
Countries subject to comprehensive UN, OFAC, or EU sanctions: E.g., Iran, North Korea, Syria, Cuba (OFAC), and specific regions or entities related to ongoing conflicts (e.g., Russia/Ukraine related sanctions).
High-Risk Jurisdictions: Jurisdictions identified by FATF as having strategic AML/CFT deficiencies (e.g., those on the FATF "grey list" or "black list") warrant enhanced due diligence and potentially restrictions.
Imprisonment: Individuals found guilty of offences under the Anti-Terrorism Act or Proceeds of Crime Act can face significant prison sentences. For example, terrorism financing offences carry terms of imprisonment of up to 25 years.
Fines: Substantial monetary penalties can be imposed on both individuals and corporate entities.
Asset Forfeiture: Proceeds of crime, including virtual assets, can be confiscated.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange may operate in Trinidad and Tobago but must obtain a VASP license from the CBTT under the VABA 2022, comply with full AML/CFT obligations including CDD, PEP screening, STR filing with the FIU, travel-rule data transmission (US$1,000/€1,000 cross-border, US$3,000/€3,000 domestic), and sanctions screening against UN, OFAC, and EU lists, with severe criminal penalties for non-compliance.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?