Centralized exchange in Uganda
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Uganda with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD under Anti-Money Laundering Act 2013 (as amended) and AML Regulations 2015: obtain/verify full name, permanent address, date of birth, national ID number for individuals; for legal entities — registered name, legal form, incorporation proof, tax ID, directors/beneficial owner details.
- Beneficial ownership identification and verification required.
- Ongoing monitoring of business relationships and transactions to ensure consistency with customer risk profile.
- Enhanced Due Diligence required for PEPs, customers from high-risk FATF jurisdictions, large/complex transactions, and transactions with no apparent economic purpose.
- Suspicious Transaction Reports must be filed with the Financial Intelligence Authority (FIA) promptly, generally within 48 hours of forming suspicion.
- No tipping-off: must not disclose to customer/third party that an STR has been filed.
- Record-keeping: customer identification records, transaction records (including wallet addresses, hashes, amounts for VAs), and business correspondence must be retained for a minimum of 5 years.
- If the exchange facilitates fiat-to-crypto or crypto-to-fiat transactions, it may fall within the scope of the National Payment Systems Act 2020 and require a Payment Service Provider (PSP) or Payment Service Operator (PSO) license from Bank of Uganda, bringing additional AML/CFT supervision.
Key Restrictions
- Regulated financial institutions (banks, PSPs, MDIs) are prohibited from dealing in cryptocurrencies or facilitating crypto transactions (BoU Circular N. 3 of 2021). This means no banking relationships for a centralized exchange are available through the formal financial system.
- Cryptocurrencies are not recognized as legal tender in Uganda; BoU does not license or supervise any VASPs.
- No specific VASP or crypto exchange license exists — any exchange would operate in a regulatory grey area outside the formal financial system.
- If the exchange is deemed to be performing payment services (fiat ramp), it may be required to obtain a PSP/PSO license under the National Payment Systems Act 2020 — a framework designed for traditional payments, not crypto.
- No specific custody segregation rules, cold-storage mandates, or qualified custodian definitions exist for digital assets.
Key Risks
- Bank of Uganda has repeatedly warned the public that unregulated crypto operations carry high risks of fraud, money laundering, and loss of funds — enforcement action against unlicensed operators is possible.
- Absence of banking relationships: BoU prohibits regulated financial institutions from facilitating crypto transactions, making fiat on/off ramps extremely difficult to maintain legally.
- Regulatory ambiguity: the NPS Act 2020 could be interpreted to require a PSP/PSO license for fiat-crypto exchange, but no crypto-specific guidance exists, creating legal uncertainty.
- No segregation or insolvency protection for user assets — users' crypto could be treated as general assets in the event of exchange insolvency.
- FATF travel-rule obligations for VASPs may technically apply under Uganda's AML framework, but there is no explicit crypto-specific travel-rule implementation, leaving compliance ambiguous.
- The existing regulatory stance has pushed crypto operations out of the formal financial system, making traditional regulatory enforcement challenging but also exposing operators to potential ad-hoc enforcement actions.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Bank of Uganda Circular (N. 3 of 2021): While direct link to the circular might change, news articles widely reported on it and often link to scans of the original.
Bank of Uganda Warns Supervised Entities Against Dealing in Cryptocurrencies - Techweez (reporting on the circular)
Uganda's Central Bank Orders Financial Institutions to Cease All Crypto Transactions - Bitcoin.com News
Bank of Uganda reiterates its tough stance on cryptocurrency use - Africanews (2022)
A comprehensive legal and regulatory framework for the licensing and supervision of Virtual Asset Service Providers (VASPs) is still largely absent.
The existing regulatory stance, exemplified by the 2021 circular, has effectively pushed crypto operations out of the formal financial system, making traditional regulatory enforcement challenging.
Bank of Uganda (BOU) Stance: The BOU has repeatedly issued advisories clarifying that cryptocurrencies are not recognized as legal tender in Uganda and that the central bank does not regulate or license any cryptocurrency businesses.
National Payment Systems Act, 2020 (NPS Act) and Regulations, 2021: This is the most relevant piece of legislation for payment services in Uganda.
National Payment Systems Regulations, 2021: (Often published as a statutory instrument, typically available via the Uganda Legal Information Institute or Ministry of Finance archives).
Relevance: The NPS Act and its regulations govern the operation of payment systems and the licensing of payment service providers (PSPs). While it does not explicitly mention cryptocurrencies, an argument could be made that any entity facilitating fiat-to-crypto or crypto-to-fiat transactions, or otherwise dealing with funds in a way that resembles traditional payment services, might fall under the purview of these laws. However, the BOU has not clarified how these laws apply to crypto-specific businesses.
Current Situation: No specific license. Many operate in a grey area.
Potential Interpretation: If an exchange facilitates transactions between fiat currency and virtual assets (or vice versa), it could theoretically be deemed to be performing functions similar to a money remitter or payment service provider. In such a scenario, they might be required to obtain a Payment Service Provider (PSP) license or a Payment System Operator (PSO) license under the National Payment Systems Act, 2020, regulated by the Bank of Uganda.
Requirement for a PSP/PSO License (General): This would entail meeting the requirements for traditional payment service providers.
Cryptocurrencies are not legal tender in Uganda.
The BoU does not regulate, license, or supervise virtual assets or virtual asset service providers (VASPs).
Regulated financial institutions (banks, payment service providers, etc.) are prohibited from dealing in cryptocurrencies, facilitating crypto transactions, or holding crypto on behalf of clients.
There are no specific licenses for cryptocurrency/digital asset custody in Uganda.
There are no specific rules for the segregation of client digital assets, as the activity itself is not formally recognized or permitted for regulated entities.
There are no specific mandates or requirements for cold storage (offline storage) of digital assets.
There is no official definition of a "qualified custodian" specific to digital assets in Uganda's regulatory framework. This term typically emerges in jurisdictions that have established specific licensing and oversight for crypto custodians.
The Anti-Money Laundering Act, 2013 (as amended): This is the primary AML legislation in Uganda. It defines money laundering, establishes the Financial Intelligence Authority (FIA), and outlines obligations for "reporting persons." While it doesn't explicitly mention "cryptocurrency" or "VASP," the broad definitions of "financial institution," "transaction," and "funds" can be interpreted to encompass activities involving virtual assets.
The Anti-Money Laundering Regulations, 2015: These regulations provide more specific details on the implementation of the Act, including customer due diligence, record-keeping, and suspicious transaction reporting.
The Financial Intelligence Authority Act, 2013: This Act establishes the FIA as the central national agency responsible for receiving, analyzing, and disseminating financial intelligence related to money laundering, terrorist financing, and proliferation financing.
Individual Customers: Obtain and verify the customer's full name, permanent address, date of birth, national identification number (e.g., National ID, passport), and other relevant identification documents.
Legal Entities (Companies, etc.): Obtain and verify the company's registered name, legal form, proof of incorporation, physical address, business registration number, tax identification number, and details of directors, beneficial owners, and authorized signatories.
Beneficial Ownership: Identify and verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or the transaction.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds where necessary.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers, transactions, or business relationships. This includes:
Customers from high-risk jurisdictions (identified by FATF or local authorities)
Transactions involving large amounts or complex structures
Report Suspicious Transactions: Report any transaction (attempted or completed) where there is a reasonable suspicion that the funds involved are proceeds of crime, or are linked to money laundering, terrorist financing, or proliferation financing.
Report to the FIA: Such reports must be made to the Financial Intelligence Authority (FIA) promptly, and generally within 48 hours of forming the suspicion.
No Tipping-Off: Not disclose to the customer or any third party that a suspicious transaction report has been made or that a money laundering investigation is being conducted.
Customer Identification Records: All records obtained during CDD processes (identification documents, verification records, beneficial ownership information).
Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, type of transaction, and parties involved. For virtual assets, this would include wallet addresses, transaction hashes, and amounts.
Business Correspondence: Records of all relevant business correspondence with customers.
Retention Period: Records must be retained for a minimum period of five (5) years after the business relationship has ended or after the date of an occasional transaction.
Entity Targeted: All Regulated Financial Institutions (e.g., Commercial Banks, Payment Service Providers, Microfinance Deposit-taking Institutions). Violation Type: N/A (this was a pre-emptive prohibition, not an action against a prior violation by a crypto firm). Penalty Amount: N/A (the circular itself did not impose a fine on a crypto entity, but implied penalties for regulated entities that failed to comply with the directive). Outcome: The BoU issued a circular directing all supervised financial institutions to cease facilitating transactions related to virtual currencies. This effectively cut off cryptocurrency exchanges and related businesses from accessing formal banking services in Uganda. The BoU cited concerns over consumer protection, money laundering, terrorism financing, and the lack of specific regulations. This directive has made it extremely challenging, if not impossible, for crypto businesses to operate formally within the Ugandan financial system.
Entity Targeted: The general public and unregulated virtual asset service providers (implicitly). Violation Type: N/A (warnings about risks, not specific violations). Penalty Amount: N/A. Outcome: These warnings emphasize that cryptocurrencies are not legal tender, are not regulated by the BoU, and carry high risks of fraud, money laundering, and loss of funds. The FIA has also highlighted AML/CFT risks. The lack of a specific licensing and regulatory framework for VASPs means that any entity operating with virtual assets does so without official recognition or oversight, increasing their operational risk and exposure to potential future actions should a framework be introduced. This environment largely prevents formal enforcement actions against VASPs for regulatory non-compliance because there aren't specific VASP regulations to violate yet, other than general financial laws (e.g., fraud).
Outcome: These warnings emphasize that cryptocurrencies are not legal tender, are not regulated by the BoU, and carry high risks of fraud, money laundering, and loss of funds. The FIA has also highlighted AML/CFT risks. The lack of a specific licensing and regulatory framework for VASPs means that any entity operating with virtual assets does so without official recognition or oversight, increasing their operational risk and exposure to potential future actions should a framework be introduced. This environment largely prevents formal enforcement actions against VASPs for regulatory non-compliance because there aren't specific VASP regulations to violate yet, other than general financial laws (e.g., fraud).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Uganda only outside the formal financial system (no banking relationships), without a specific VASP license, under general AML obligations supervised by the FIA, but with significant legal uncertainty and risk of regulatory action from the Bank of Uganda.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?