← Regulations / Trinidad and Tobago / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Trinidad and Tobago

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Trinidad and Tobago with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Licensing under the Virtual Asset Business Act, 2022 (VABA, 2022) is mandatory — this defines a 'virtual asset business' and imposes AML/CFT compliance obligations on all VASPs.
  • AML/CFT obligations are underpinned by the Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13, which applies to all financial institutions including VASPs.
  • Customer Due Diligence (CDD): obtain and verify identity for individuals (full legal name, DOB, residential address, nationality, unique ID number) and legal persons (name, business address, registration number, constitutional documents).
  • Beneficial Ownership: identify and verify the beneficial owner(s) of legal persons/arrangements, understanding ownership and control structure.
  • Purpose and intended nature of business relationship must be documented.
  • Ongoing monitoring of transactions to ensure consistency with customer risk profile.
  • PEP screening: enhanced scrutiny for domestic/foreign PEPs, family members, and close associates; senior management approval required for establishing relationships with PEPs.
  • Enhanced Due Diligence (EDD) required for: PEPs, cross-border correspondent relationships, complex/unusually large transactions, high-risk jurisdictions (FATF grey/black list), and transactions involving anonymity-enhancing virtual assets.
  • Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Unit (FIU) of Trinidad and Tobago promptly (within a few working days) when ML/TF is suspected.
  • No tipping-off: VASPs and employees cannot disclose to customers that an STR has been filed.
  • Record-keeping: customer records, transaction records (sufficient to reconstruct individual transactions), analysis records, and copies of STRs must be retained.
  • Sanctions screening obligations: screen against UN Consolidated Sanctions List (legally binding), OFAC SDN List, EU sanctions lists, and domestic lists under the Anti-Terrorism Act.
  • Ongoing monitoring for sanctions evasion and illicit activity, including screening for countries under comprehensive UN/OFAC/EU sanctions (Iran, North Korea, Syria, etc.) and high-risk jurisdictions.
  • AML obligations apply to the SaaS operator (licensed VASP) — the white-label client's obligations depend on whether they also meet the definition of a VASP; the licensed operator retains regulatory responsibility.

Key Restrictions

  • Must obtain a VASP license under the Virtual Asset Business Act, 2022 (VABA, 2022) — no exemption for custodial wallet / SaaS providers.
  • Must be incorporated or registered locally (local entity required) to meet licensing and supervisory requirements under the CBTT and FIU.
  • Cryptocurrencies are not legal tender in Trinidad and Tobago; the Central Bank has consistently warned they are not regulated under traditional financial services laws.
  • The SaaS operator, as the licensed VASP, bears primary regulatory liability for AML/CFT compliance even when services are white-labeled — segregation of duties with white-label clients must be contractually defined but does not transfer regulatory accountability.
  • Geographic restrictions may apply for transactions involving sanctioned jurisdictions or high-risk FATF-listed countries.
  • Must comply with sanctions screening against UN, OFAC, and EU lists due to global nature of virtual asset transactions and bank correspondent relationships.

Key Risks

  • Regulatory ambiguity: though VABA 2022 exists, the CBTT has publicly stated that crypto assets are not legal tender and are 'generally unregulated' under traditional financial services laws, creating uncertainty about the scope of current enforcement.
  • Enforcement precedent is thin — public advisories and warnings have been the primary regulatory tool, with no publicly reported major enforcement actions against VASPs, meaning the practical application of VABA is not yet tested.
  • Secondary sanctions risk: failure to screen adequately against OFAC/EU sanctions lists could expose the operator to enforcement by US/EU authorities or loss of correspondent banking relationships.
  • The combination of white-label/custody-as-a-service model with unclear regulatory delineation between the SaaS provider and its clients creates ML/TF compliance gaps if not carefully structured.
  • Financial institutions providing fiat on-ramps/off-ramps may refuse to bank VASPs due to perceived AML/sanctions risk, causing operational disruption.
  • Potential classification by the TTSEC of certain virtual assets or services as securities could subject the operator to additional securities law compliance.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 60% confidence

Virtual Asset Business Act, 2022 (VABA, 2022): This is the foundational law for virtual assets and VASPs, defining what constitutes a "virtual asset" and "virtual asset business" and establishing the regulatory framework. It mandates licensing and compliance with AML/CFT obligations for VASPs.

aml 60% confidence

Anti-Money Laundering and Countering the Financing of Terrorism Act, Chap 11:13: This is the overarching AML/CFT legislation that applies to all financial institutions, including VASPs under the VABA. It sets out the general requirements for AML/CFT compliance, including CDD, STRs, and record-keeping.

aml 60% confidence

Proceeds of Crime Act, Chap 11:27: This Act criminalizes money laundering and the financing of terrorism, providing the legal basis for prosecuting such offenses and seizing assets.

aml 60% confidence

Financial Intelligence Unit Act, Chap 72:01: This Act establishes the Financial Intelligence Unit (FIU) as the central national agency for receiving, analyzing, and disseminating suspicious transaction reports and other financial intelligence.

aml 60% confidence

Identification and Verification of Customers:

aml 60% confidence

For Individuals: Obtain and verify the customer's full legal name, date of birth, residential address, nationality, and a unique identification number (e.g., passport number, national ID card number). Verification must be done using reliable, independent source documents, data or information.

aml 60% confidence

For Legal Persons/Arrangements (e.g., companies, trusts): Obtain and verify the legal name, principal place of business, registration number, articles of incorporation, bylaws, and other relevant constitutional documents.

aml 60% confidence

Beneficial Ownership: VASPs must identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons and arrangements. This involves understanding the ownership and control structure of the customer.

aml 60% confidence

Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or transaction (e.g., why is the customer using VASP services, what types of virtual assets will be involved, expected transaction volumes).

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information and beneficial ownership up-to-date.

aml 60% confidence

Politically Exposed Persons (PEPs): Implement enhanced scrutiny for customers who are PEPs (domestic or foreign) or their family members or close associates. This includes obtaining senior management approval for establishing business relationships with PEPs and taking reasonable measures to establish the source of wealth and source of funds.

aml 60% confidence

Enhanced Due Diligence (EDD): Apply EDD in situations identified as high-risk, such as:

aml 60% confidence

Cross-border correspondent relationships.

aml 60% confidence

Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.

aml 60% confidence

Customers residing in or transactions involving high-risk jurisdictions identified by the FATF or other relevant bodies.

aml 60% confidence

Transactions involving anonymity-enhancing virtual assets.

aml 60% confidence

Trigger: Any VASP that knows, suspects, or has reasonable grounds to suspect that a transaction (attempted or completed), virtual asset, or funds are linked to money laundering, terrorist financing, or other criminal activity, must file an STR.

aml 60% confidence

Reporting Body: Financial Intelligence Unit (FIU) of Trinidad and Tobago.

aml 60% confidence

Timeline: Reports must be submitted promptly, typically within a few working days of forming the suspicion, and in accordance with FIU guidelines.

aml 60% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been or will be filed, or that an investigation is being conducted.

aml 60% confidence

Customer Records: All records obtained during CDD, including identification documents, verification data, beneficial ownership information, and the assessment of the purpose and nature of the business relationship.

aml 60% confidence

Transaction Records: Detailed records of all virtual asset transactions, including the amount, type of virtual asset, date, time, originating and beneficiary addresses (or equivalent identifiers), and any other relevant transaction data. These records must be sufficient to reconstruct individual transactions.

aml 60% confidence

Analysis Records: Records of any analysis undertaken concerning complex, unusual, or large transactions, and the findings of such analysis.

aml 60% confidence

STRs: Copies of all suspicious transaction reports filed, along with supporting documentation.

licensing 60% confidence

Implement Robust Know Your Customer (KYC) and Customer Due Diligence (CDD) procedures: This includes identifying and verifying the identity of customers and beneficial owners.

licensing 60% confidence

Screen against Sanctions Lists: Regularly screen customers, counterparties, and transactions against:

licensing 60% confidence

OFAC Specially Designated Nationals (SDN) List and other OFAC lists: Essential due to the dominance of the USD in global finance and the extraterritorial reach of OFAC.

licensing 60% confidence

EU Sanctions Lists: Important for similar reasons if dealing with EU counterparties or currencies.

licensing 60% confidence

Domestic Lists: Any individuals or entities designated under T&T's Anti-Terrorism Act or similar legislation.

licensing 60% confidence

Ongoing Monitoring: Continuously monitor transactions for red flags indicative of sanctions evasion or illicit activity.

licensing 60% confidence

Politically Exposed Persons (PEPs) Screening: Identify and apply enhanced due diligence to PEPs, their family members, and close associates, as PEPs often present a higher risk for corruption and sanctions evasion.

licensing 60% confidence

Countries subject to comprehensive UN, OFAC, or EU sanctions: E.g., Iran, North Korea, Syria, Cuba (OFAC), and specific regions or entities related to ongoing conflicts (e.g., Russia/Ukraine related sanctions).

licensing 95% confidence

High-Risk Jurisdictions: Jurisdictions identified by FATF as having strategic AML/CFT deficiencies (e.g., those on the FATF "grey list" or "black list") warrant enhanced due diligence and potentially restrictions.

licensing 60% confidence

FATF Standards: The FATF recommends that countries ensure VASPs are subject to AML/CFT obligations, including sanctions screening. Non-compliance with OFAC/EU sanctions, even by entities outside those jurisdictions, is often viewed negatively by international regulators and financial institutions.

licensing 60% confidence

Global Reach of Virtual Assets: Virtual asset transactions are inherently global. A VASP in T&T could inadvertently facilitate transactions with individuals or entities sanctioned by the US or EU, leading to secondary sanctions risks or enforcement actions by these foreign authorities if there's a nexus to their jurisdiction (e.g., a US person involved, US-domiciled technology, or USD stablecoins).

licensing 60% confidence

International Correspondent Banking: VASPs often rely on traditional financial institutions (banks) for fiat on-ramps/off-ramps, payroll, etc. These banks are almost universally subject to OFAC and EU sanctions due to their international operations, especially their dealings in USD or EUR. Non-compliance by a VASP could lead to banks de-risking or terminating services.

enforcement 60% confidence

Key Points: The CBTT has consistently warned against the use of cryptocurrencies due to high volatility, potential for fraud, money laundering, lack of consumer protection, and the absence of regulatory oversight. They maintain that crypto assets are not legal tender in Trinidad and Tobago.

enforcement 60% confidence

Statements on Regulatory Stance: Clarifying that cryptocurrencies are not legal tender and are generally unregulated under existing financial services laws, which limits the scope for traditional "enforcement actions" against entities operating solely in this space unless they infringe on other laws (e.g., fraud, money laundering, unregistered securities offerings).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers in Trinidad and Tobago must obtain a VASP license under the Virtual Asset Business Act, 2022, incorporate locally, and comply with a full suite of AML/CFT obligations (CDD, EDD, PEP screening, STR filing to the FIU, sanctions screening against UN/OFAC/EU lists), though enforcement precedent is thin and the practical application of the 2022 Act remains untested.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?