Remote VASP serving residents in Tanzania
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Tanzania with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification (full name, DOB, residential address, nationality, national ID/passport) under the Anti-Money Laundering Act, 2006 (as amended)
- Beneficial ownership identification and verification for legal entities
- Purpose and intended nature of business relationship assessment
- Ongoing transaction monitoring for consistency with customer risk profile
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdiction customers, complex/unusually large transactions, cross-border virtual asset transfers, and anonymity-favoring technologies
- Suspicious Transaction Reporting (STR) to the Financial Intelligence Unit (FIU) Tanzania without delay, with no tipping-off
- Record-keeping for minimum 5 years after business relationship ends, covering all customer ID data, transaction records, business correspondence, and filed STRs
- AML/CFT compliance framework required by AMLA 2006 and Anti-Money Laundering Regulations 2012, as Tanzania follows FATF standards for VASPs
Key Restrictions
- Bank of Tanzania (BoT) maintains that cryptocurrencies are not recognized as legal tender and financial institutions are prohibited from facilitating crypto transactions
- No specific VASP licensing regime exists — operators must navigate undefined legal territory where crypto activities may fall under the National Payment Systems Act 2015 or financial institution rules
- Local entity incorporation and physical presence would almost certainly be required for any regulated financial service
- The BoT has issued public warnings against unlicensed crypto operations, creating legal uncertainty for cross-border service provision
- Any fiat-crypto exchange may be construed as unauthorized money transmission or payment processing, triggering existing financial services law
Key Risks
- High enforcement risk — BoT has repeatedly warned the public and financial institutions against crypto transactions, and operating without a license could be treated as an unauthorized financial service
- No known licensed crypto exchanges or VASPs exist in Tanzania, indicating de facto prohibition in practice despite no explicit statutory ban
- Regulatory ambiguity — the lack of a specific framework means operators face unpredictable legal treatment; future regulation may be retroactive or impose requirements that cannot be met from abroad
- Banking access risk — financial institutions are prohibited from facilitating crypto, making fiat on/off ramps difficult if not impossible
- Reputational exposure — operating in a jurisdiction where the central bank has publicly discouraged crypto activity may attract negative attention from regulators and the public
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Lack of Specific Licensing Regime: There is no specific law or regulation in Tanzania that explicitly defines, regulates, and provides for the licensing of cryptocurrency exchanges, custody providers, or payment processors as virtual asset businesses.
Current Stance (Implied): While formal prohibition may not be explicit in specific crypto legislation, the lack of a regulatory framework and the BOT's historical cautious stance on unregulated financial activities mean that operating an unlicensed crypto business could face significant legal uncertainty and potential challenges under existing general financial laws.
Exchanges: If an exchange facilitates the exchange of fiat currency for cryptocurrencies, or vice versa, it might be seen as engaging in money transmission or payment processing activities.
Custody Providers: If a provider holds significant assets on behalf of clients, it could potentially be viewed through the lens of trust services or asset management, which are typically regulated.
Payment Processors: Companies facilitating payments using virtual assets, especially if they involve conversions to/from fiat currency, might be subject to the existing National Payment Systems Act, 2015 (and its regulations) administered by the Bank of Tanzania, depending on the interpretation of "payment system" and "electronic money."
HIGHLY LIKELY & CRITICAL: Even without a specific crypto licensing regime, Tanzania has a robust Anti-Money Laundering Act, 2006 (and subsequent amendments/regulations) and a Financial Intelligence Unit (FIU). Financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) are obligated to comply with AML/CFT (Anti-Money Laundering and Combating the Financing of Terrorism) requirements.
Virtual asset service providers, if operating, would be expected to implement robust KYC (Know Your Customer) and AML procedures, including customer due diligence, transaction monitoring, record-keeping, and suspicious transaction reporting to the FIU. This aligns with FATF (Financial Action Task Force) recommendations, which Tanzania adheres to.
Highly Likely: For any regulated financial service, a local presence (e.g., a locally incorporated entity, physical office, local management) is typically a prerequisite in Tanzania. This would almost certainly be a requirement for any future crypto licensing.
The Anti-Money Laundering Act (AMLA), 2006 (as amended): This is the principal legislation establishing the legal framework for combating money laundering. It defines "financial institutions" and "other reporting institutions" and imposes obligations on them. While VASPs may not be explicitly listed, their activities are likely to be interpreted as falling under the scope of financial services or other reporting obligations.
The Anti-Money Laundering Regulations, 2012 (as amended): These regulations provide detailed rules and procedures for implementing the AMLA, including customer due diligence, suspicious transaction reporting, and record-keeping.
Identification and Verification of Customers:
Beneficial Ownership: Identifying and verifying the identity of the ultimate beneficial owner(s) of the virtual assets or the entity, ensuring that the VASP knows who ultimately owns or controls the funds/assets.
Purpose and Intended Nature of the Business Relationship: Understanding the purpose and intended nature of the customer's virtual asset activities and the business relationship.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by the customer to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Enhanced Due Diligence (EDD): Applying EDD for higher-risk situations, which may include:
Obligation to Report: Any VASP, or its employees, that knows or suspects that a transaction (or attempted transaction) involves funds or virtual assets derived from illegal activity, or is related to money laundering or terrorism financing, must report it.
Reporting Mechanism: Reports must be submitted to the FIU Tanzania promptly and without delay, typically through a prescribed format (e.g., an online portal or specific form).
No Tipping-Off: VASPs and their employees are prohibited from "tipping-off" customers or third parties that an STR has been or will be submitted.
Duration: All records must be kept for a minimum period of five (5) years after the business relationship has ended or after the date of the transaction.
There is no specific "crypto custodian license" currently established in Tanzania. Any entity wishing to offer such services would operate in a largely unregulated space, though they might fall under general financial service provider rules if their activities are deemed to align with existing licensed financial services.
Entity Targeted: The general public, financial institutions, and any individuals or entities attempting to deal in, facilitate, or operate businesses involving cryptocurrencies. Violation Type: Dealing in, facilitating, or promoting instruments not recognized as legal tender; operating unauthorized financial services. Penalty Amount: Not a specific fine amount applied in a single action, but the outcome implies potential prosecution under existing financial laws for unauthorized activities.
Outcome: Cryptocurrencies are not recognized as legal tender in Tanzania. Financial institutions are prohibited from facilitating crypto transactions. This creates a high-risk environment for anyone operating a crypto business, as they would be operating outside the legal framework and subject to potential criminal charges rather than regulatory fines.
Bank of Tanzania's Stance (via news report):
PwC Global Crypto Regulation Report (2022/2023 versions would reflect this): While not a single URL for an enforcement action, these reports consistently classify Tanzania as having a highly restrictive/prohibitive crypto regulatory environment, underscoring the lack of licensed operations. (A direct BoT statement on licensing would be ideal, but is unlikely to exist as they don't license them).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Tanzanian residents faces a high-risk regulatory environment: no specific crypto licensing regime exists, the Bank of Tanzania has publicly maintained that crypto is not legal tender and prohibited financial institutions from facilitating crypto, and any cross-border service would likely be treated as unauthorized financial activity, though existing AML obligations under the AMLA 2006 would still attach if the operator is deemed a reporting institution.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?