Custodial wallet / SaaS in Trinidad and Tobago
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Trinidad and Tobago with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Licensing under the Virtual Asset Business Act, 2022 (VABA, 2022) is mandatory — this defines a 'virtual asset business' and imposes AML/CFT compliance obligations on all VASPs.
- AML/CFT obligations are underpinned by the Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13, which applies to all financial institutions including VASPs.
- Customer Due Diligence (CDD): obtain and verify identity for individuals (full legal name, DOB, residential address, nationality, unique ID number) and legal persons (name, business address, registration number, constitutional documents).
- Beneficial Ownership: identify and verify the beneficial owner(s) of legal persons/arrangements, understanding ownership and control structure.
- Purpose and intended nature of business relationship must be documented.
- Ongoing monitoring of transactions to ensure consistency with customer risk profile.
- PEP screening: enhanced scrutiny for domestic/foreign PEPs, family members, and close associates; senior management approval required for establishing relationships with PEPs.
- Enhanced Due Diligence (EDD) required for: PEPs, cross-border correspondent relationships, complex/unusually large transactions, high-risk jurisdictions (FATF grey/black list), and transactions involving anonymity-enhancing virtual assets.
- Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Unit (FIU) of Trinidad and Tobago promptly (within a few working days) when ML/TF is suspected.
- No tipping-off: VASPs and employees cannot disclose to customers that an STR has been filed.
- Record-keeping: customer records, transaction records (sufficient to reconstruct individual transactions), analysis records, and copies of STRs must be retained.
- Sanctions screening obligations: screen against UN Consolidated Sanctions List (legally binding), OFAC SDN List, EU sanctions lists, and domestic lists under the Anti-Terrorism Act.
- Ongoing monitoring for sanctions evasion and illicit activity, including screening for countries under comprehensive UN/OFAC/EU sanctions (Iran, North Korea, Syria, etc.) and high-risk jurisdictions.
- AML obligations apply to the SaaS operator (licensed VASP) — the white-label client's obligations depend on whether they also meet the definition of a VASP; the licensed operator retains regulatory responsibility.
Key Restrictions
- Must obtain a VASP license under the Virtual Asset Business Act, 2022 (VABA, 2022) — no exemption for custodial wallet / SaaS providers.
- Must be incorporated or registered locally (local entity required) to meet licensing and supervisory requirements under the CBTT and FIU.
- Cryptocurrencies are not legal tender in Trinidad and Tobago; the Central Bank has consistently warned they are not regulated under traditional financial services laws.
- The SaaS operator, as the licensed VASP, bears primary regulatory liability for AML/CFT compliance even when services are white-labeled — segregation of duties with white-label clients must be contractually defined but does not transfer regulatory accountability.
- Geographic restrictions may apply for transactions involving sanctioned jurisdictions or high-risk FATF-listed countries.
- Must comply with sanctions screening against UN, OFAC, and EU lists due to global nature of virtual asset transactions and bank correspondent relationships.
Key Risks
- Regulatory ambiguity: though VABA 2022 exists, the CBTT has publicly stated that crypto assets are not legal tender and are 'generally unregulated' under traditional financial services laws, creating uncertainty about the scope of current enforcement.
- Enforcement precedent is thin — public advisories and warnings have been the primary regulatory tool, with no publicly reported major enforcement actions against VASPs, meaning the practical application of VABA is not yet tested.
- Secondary sanctions risk: failure to screen adequately against OFAC/EU sanctions lists could expose the operator to enforcement by US/EU authorities or loss of correspondent banking relationships.
- The combination of white-label/custody-as-a-service model with unclear regulatory delineation between the SaaS provider and its clients creates ML/TF compliance gaps if not carefully structured.
- Financial institutions providing fiat on-ramps/off-ramps may refuse to bank VASPs due to perceived AML/sanctions risk, causing operational disruption.
- Potential classification by the TTSEC of certain virtual assets or services as securities could subject the operator to additional securities law compliance.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Business Act, 2022 (VABA, 2022): This is the foundational law for virtual assets and VASPs, defining what constitutes a "virtual asset" and "virtual asset business" and establishing the regulatory framework. It mandates licensing and compliance with AML/CFT obligations for VASPs.
Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13: This is the overarching AML/CFT legislation that applies to all financial institutions, including VASPs under the VABA. It sets out the general requirements for AML/CFT compliance, including CDD, STRs, and record-keeping.
Proceeds of Crime Act, Chap 11:27: This Act criminalizes money laundering and the financing of terrorism, providing the legal basis for prosecuting such offenses and seizing assets.
Financial Intelligence Unit Act, Chap 72:01: This Act establishes the Financial Intelligence Unit (FIU) as the central national agency for receiving, analyzing, and disseminating suspicious transaction reports and other financial intelligence.
Identification and Verification of Customers:
For Individuals: Obtain and verify the customer's full legal name, date of birth, residential address, nationality, and a unique identification number (e.g., passport number, national ID card number). Verification must be done using reliable, independent source documents, data or information.
For Legal Persons/Arrangements (e.g., companies, trusts): Obtain and verify the legal name, principal place of business, registration number, articles of incorporation, bylaws, and other relevant constitutional documents.
Beneficial Ownership: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons and arrangements. This involves understanding the ownership and control structure of the customer.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or transaction (e.g., why is the customer using VASP services, what types of virtual assets will be involved, expected transaction volumes).
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information and beneficial ownership up-to-date.
Politically Exposed Persons (PEPs): Implement enhanced scrutiny for customers who are PEPs (domestic or foreign) or their family members or close associates. This includes obtaining senior management approval for establishing business relationships with PEPs and taking reasonable measures to establish the source of wealth and source of funds.
Enhanced Due Diligence (EDD): Apply EDD in situations identified as high-risk, such as:
Relationships with PEPs.
Cross-border correspondent relationships.
Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
Customers residing in or transactions involving high-risk jurisdictions identified by the FATF or other relevant bodies.
Transactions involving anonymity-enhancing virtual assets.
Trigger: Any VASP that knows, suspects, or has reasonable grounds to suspect that a transaction (attempted or completed), virtual asset, or funds are linked to money laundering, terrorist financing, or other criminal activity, must file an STR.
Reporting Body: Financial Intelligence Unit (FIU) of Trinidad and Tobago.
Timeline: Reports must be submitted promptly, typically within a few working days of forming the suspicion, and in accordance with FIU guidelines.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been or will be filed, or that an investigation is being conducted.
Customer Records: All records obtained during CDD, including identification documents, verification data, beneficial ownership information, and the assessment of the purpose and nature of the business relationship.
Transaction Records: Detailed records of all virtual asset transactions, including the amount, type of virtual asset, date, time, originating and beneficiary addresses (or equivalent identifiers), and any other relevant transaction data. These records must be sufficient to reconstruct individual transactions.
Analysis Records: Records of any analysis undertaken concerning complex, unusual, or large transactions, and the findings of such analysis.
STRs: Copies of all suspicious transaction reports filed, along with supporting documentation.
Sanctioned Entity Screening Obligations:
Implement Robust Know Your Customer (KYC) and Customer Due Diligence (CDD) procedures: This includes identifying and verifying the identity of customers and beneficial owners.
Screen against Sanctions Lists: Regularly screen customers, counterparties, and transactions against:
UN Consolidated Sanctions List: This is legally binding for T&T.
OFAC Specially Designated Nationals (SDN) List and other OFAC lists: Essential due to the dominance of the USD in global finance and the extraterritorial reach of OFAC.
EU Sanctions Lists: Important for similar reasons if dealing with EU counterparties or currencies.
Domestic Lists: Any individuals or entities designated under T&T's Anti-Terrorism Act or similar legislation.
Ongoing Monitoring: Continuously monitor transactions for red flags indicative of sanctions evasion or illicit activity.
Politically Exposed Persons (PEPs) Screening: Identify and apply enhanced due diligence to PEPs, their family members, and close associates, as PEPs often present a higher risk for corruption and sanctions evasion.
Countries subject to comprehensive UN, OFAC, or EU sanctions: E.g., Iran, North Korea, Syria, Cuba (OFAC), and specific regions or entities related to ongoing conflicts (e.g., Russia/Ukraine related sanctions).
High-Risk Jurisdictions: Jurisdictions identified by FATF as having strategic AML/CFT deficiencies (e.g., those on the FATF "grey list" or "black list") warrant enhanced due diligence and potentially restrictions.
FATF Standards: The FATF recommends that countries ensure VASPs are subject to AML/CFT obligations, including sanctions screening. Non-compliance with OFAC/EU sanctions, even by entities outside those jurisdictions, is often viewed negatively by international regulators and financial institutions.
Global Reach of Virtual Assets: Virtual asset transactions are inherently global. A VASP in T&T could inadvertently facilitate transactions with individuals or entities sanctioned by the US or EU, leading to secondary sanctions risks or enforcement actions by these foreign authorities if there's a nexus to their jurisdiction (e.g., a US person involved, US-domiciled technology, or USD stablecoins).
International Correspondent Banking: VASPs often rely on traditional financial institutions (banks) for fiat on-ramps/off-ramps, payroll, etc. These banks are almost universally subject to OFAC and EU sanctions due to their international operations, especially their dealings in USD or EUR. Non-compliance by a VASP could lead to banks de-risking or terminating services.
OFAC/EU Sanctions Compliance Requirements for VASPs:
Regulator Name: Central Bank of Trinidad and Tobago (CBTT)
Key Points: The CBTT has consistently warned against the use of cryptocurrencies due to high volatility, potential for fraud, money laundering, lack of consumer protection, and the absence of regulatory oversight. They maintain that crypto assets are not legal tender in Trinidad and Tobago.
Statements on Regulatory Stance: Clarifying that cryptocurrencies are not legal tender and are generally unregulated under existing financial services laws, which limits the scope for traditional "enforcement actions" against entities operating solely in this space unless they infringe on other laws (e.g., fraud, money laundering, unregistered securities offerings).
Regulator Name: Financial Intelligence Unit of Trinidad and Tobago (FIUTT)
Regulator Name: Trinidad and Tobago Securities and Exchange Commission (TTSEC)
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers in Trinidad and Tobago must obtain a VASP license under the Virtual Asset Business Act, 2022, incorporate locally, and comply with a full suite of AML/CFT obligations (CDD, EDD, PEP screening, STR filing to the FIU, sanctions screening against UN/OFAC/EU lists), though enforcement precedent is thin and the practical application of the 2022 Act remains untested.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?