Custodial wallet / SaaS in Uganda
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Uganda with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- AML obligations under the Anti-Money Laundering Act, 2013 (as amended) apply to any entity conducting financial transactions — custodial wallet operators handling fiat on/off-ramps would likely need to register as reporting persons.
- Customer Due Diligence (CDD) required under the Anti-Money Laundering Regulations, 2015: obtain and verify full name, permanent address, date of birth, national ID for individuals; for legal entities obtain registered name, proof of incorporation, business registration, tax ID, directors, beneficial owners.
- Beneficial ownership identification and verification required for all legal entity customers.
- Ongoing monitoring of business relationships and transactions to ensure consistency with customer risk profile.
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk FATF-listed jurisdictions, and large/complex transactions.
- Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Authority (FIA) within 48 hours of forming suspicion.
- No tipping-off — must not disclose STR filings to the customer or third parties.
- Record retention: all records (CDD, transactions, business correspondence) must be kept for a minimum of 5 years after the business relationship ends.
- For virtual asset transactions, records must include wallet addresses, transaction hashes, and amounts.
- If the custodial wallet service involves fiat-to-crypto or crypto-to-fiat conversion, the operator may also fall under the National Payment Systems Act, 2020 licensing regime as a PSP, with additional AML obligations.
Key Restrictions
- Regulated financial institutions (banks, payment service providers) are prohibited from dealing in, facilitating, or holding cryptocurrencies — a custodial wallet operator cannot partner with or use regulated banks for on/off-ramp services.
- No specific license exists for digital asset custody — operators exist in a regulatory grey area with no formal recognition or protection.
- Any custody service tied to a payment system or fiat conversion may be deemed a Payment Service Provider (PSP) under the National Payment Systems Act, 2020, requiring a PSP license.
- The Bank of Uganda has issued circulars (e.g., Circular N. 3 of 2021) warning supervised entities against crypto dealings, effectively cutting crypto businesses off from the formal banking system.
- No segregation of client digital assets rules exist — the activity is not formally recognized for regulated entities.
- No insurance, bonding, or proof-of-reserves requirements exist for crypto custodians.
Key Risks
- Regulatory ambiguity: no formal VASP framework exists; any custodial wallet operation exists in a legal grey area and could be subject to sudden enforcement action or policy change.
- Banking access risk: regulated financial institutions are prohibited from dealing in crypto — operators will struggle to maintain fiat on/off-ramp banking relationships.
- Enforcement exposure: BoU public warnings and circulars demonstrate hostility; while no fines against unregulated VASPs have been issued yet, the risk of future enforcement (including potential closure or criminal liability) is high.
- AML compliance complexity: the AML Act applies to 'reporting persons' but does not explicitly name VASPs — uncertainty exists as to whether the FIA would treat a custodial wallet provider as a reporting person, creating legal risk.
- No qualified custodian status exists: no legal framework for custody standards, capital adequacy, or client asset protection — operator bears full liability for loss/theft/hacks.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Cryptocurrencies are not legal tender in Uganda.
The BoU does not regulate, license, or supervise virtual assets or virtual asset service providers (VASPs).
Regulated financial institutions (banks, payment service providers, etc.) are prohibited from dealing in cryptocurrencies, facilitating crypto transactions, or holding crypto on behalf of clients.
There are no specific licenses for cryptocurrency/digital asset custody in Uganda.
This is because regulated financial institutions are currently prohibited from engaging in these activities. Any entity attempting to provide such services would operate in an unregulated space, with potential legal and operational risks.
General licenses under the National Payment Systems Act, 2020 or the Financial Institutions Act, 2004 (as amended) do not cover cryptocurrency custody.
There are no specific rules for the segregation of client digital assets, as the activity itself is not formally recognized or permitted for regulated entities.
There are no specific insurance or bonding requirements for cryptocurrency/digital asset custodians.
There are no specific mandates or requirements for cold storage (offline storage) of digital assets.
There is no official definition of a "qualified custodian" specific to digital assets in Uganda's regulatory framework. This term typically emerges in jurisdictions that have established specific licensing and oversight for crypto custodians.
A comprehensive legal and regulatory framework for the licensing and supervision of Virtual Asset Service Providers (VASPs) is still largely absent.
Bank of Uganda (BOU) Stance: The BOU has repeatedly issued advisories clarifying that cryptocurrencies are not recognized as legal tender in Uganda and that the central bank does not regulate or license any cryptocurrency businesses.
Current Situation: No specific license. Many operate in a grey area.
Potential Interpretation: Unless the custody service is directly tied to a payment system or involves managing traditional financial assets alongside virtual assets, it is highly unlikely to fall under any existing financial services licensing regime. These entities currently operate without specific oversight.
The Anti-Money Laundering Act, 2013 (as amended): This is the primary AML legislation in Uganda. It defines money laundering, establishes the Financial Intelligence Authority (FIA), and outlines obligations for "reporting persons." While it doesn't explicitly mention "cryptocurrency" or "VASP," the broad definitions of "financial institution," "transaction," and "funds" can be interpreted to encompass activities involving virtual assets.
The Anti-Money Laundering Regulations, 2015: These regulations provide more specific details on the implementation of the Act, including customer due diligence, record-keeping, and suspicious transaction reporting.
The Financial Intelligence Authority Act, 2013: This Act establishes the FIA as the central national agency responsible for receiving, analyzing, and disseminating financial intelligence related to money laundering, terrorist financing, and proliferation financing.
Individual Customers: Obtain and verify the customer's full name, permanent address, date of birth, national identification number (e.g., National ID, passport), and other relevant identification documents.
Legal Entities (Companies, etc.): Obtain and verify the company's registered name, legal form, proof of incorporation, physical address, business registration number, tax identification number, and details of directors, beneficial owners, and authorized signatories.
Beneficial Ownership: Identify and verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds where necessary.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers, transactions, or business relationships. This includes:
Report Suspicious Transactions: Report any transaction (attempted or completed) where there is a reasonable suspicion that the funds involved are proceeds of crime, or are linked to money laundering, terrorist financing, or proliferation financing.
Report to the FIA: Such reports must be made to the Financial Intelligence Authority (FIA) promptly, and generally within 48 hours of forming the suspicion.
No Tipping-Off: Not disclose to the customer or any third party that a suspicious transaction report has been made or that a money laundering investigation is being conducted.
Retention Period: Records must be retained for a minimum period of five (5) years after the business relationship has ended or after the date of an occasional transaction.
Entity Targeted: All Regulated Financial Institutions (e.g., Commercial Banks, Payment Service Providers, Microfinance Deposit-taking Institutions). Violation Type: N/A (this was a pre-emptive prohibition, not an action against a prior violation by a crypto firm). Penalty Amount: N/A (the circular itself did not impose a fine on a crypto entity, but implied penalties for regulated entities that failed to comply with the directive). Outcome: The BoU issued a circular directing all supervised financial institutions to cease facilitating transactions related to virtual currencies. This effectively cut off cryptocurrency exchanges and related businesses from accessing formal banking services in Uganda. The BoU cited concerns over consumer protection, money laundering, terrorism financing, and the lack of specific regulations. This directive has made it extremely challenging, if not impossible, for crypto businesses to operate formally within the Ugandan financial system.
Entity Targeted: The general public and unregulated virtual asset service providers (implicitly). Violation Type: N/A (warnings about risks, not specific violations). Penalty Amount: N/A. Outcome: These warnings emphasize that cryptocurrencies are not legal tender, are not regulated by the BoU, and carry high risks of fraud, money laundering, and loss of funds. The FIA has also highlighted AML/CFT risks. The lack of a specific licensing and regulatory framework for VASPs means that any entity operating with virtual assets does so without official recognition or oversight, increasing their operational risk and exposure to potential future actions should a framework be introduced. This environment largely prevents formal enforcement actions against VASPs for regulatory non-compliance because there aren't specific VASP regulations to violate yet, other than general financial laws (e.g., fraud).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operation is technically possible in a regulatory grey area without a specific license, but it faces severe structural constraints: no access to the regulated banking system (BoU prohibition on regulated financial institutions), no formal custody or segregation framework, and must comply with Uganda's general AML Act obligations if deemed a reporting person, while operating under material enforcement risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?