Remote VASP serving residents in Uganda
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Uganda with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- If the operator's activities involve fiat-to-crypto or crypto-to-fiat conversion (payment system touchpoints), they may be deemed a Payment Service Provider under the National Payment Systems Act, 2020, triggering full AML/CFT obligations under the Anti-Money Laundering Act, 2013 (as amended) and AML Regulations, 2015.
- Customer Due Diligence (CDD): must obtain and verify full name, permanent address, date of birth, national ID/passport for individuals; registered name, legal form, incorporation proof, address, business registration, tax ID, and beneficial owner details for legal entities.
- Beneficial Ownership identification and verification required.
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile, including source of funds.
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk FATF jurisdictions, large/complex transactions, and transactions with no apparent economic purpose.
- Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Authority (FIA) promptly, generally within 48 hours of forming suspicion.
- No-tipping-off prohibition: must not disclose STR filing to the customer or third parties.
- Record-keeping: retain CDD, transaction records (including wallet addresses, hashes, amounts), and business correspondence for a minimum of 5 years after relationship ends or occasional transaction date.
- Simplified Due Diligence (SDD) may apply only in low-risk circumstances as permitted by regulations.
Key Restrictions
- Remote VASP cannot operate from abroad without a local entity — any service touching fiat payments would likely require a Payment Service Provider (PSP) or Payment Service Operator (PSO) license under the National Payment Systems Act, 2020, which requires local incorporation.
- Regulated financial institutions (banks, PSPs) are prohibited from dealing in cryptocurrencies or facilitating crypto transactions. This cuts off banking access for unlicensed operators.
- Bank of Uganda has repeatedly warned that cryptocurrencies are not legal tender and that it does not regulate or license any crypto businesses.
- No specific VASP licensing framework exists — operators are in a regulatory grey area with no clear legal pathway.
- The current regulatory stance has effectively pushed crypto out of the formal financial system, making lawful operation via regulated channels extremely difficult.
Key Risks
- High enforcement risk: While enforcement to date has targeted regulated financial institutions (not crypto firms directly), the Bank of Uganda and FIA have issued repeated public warnings. Lack of a formal licensing pathway means any remote VASP serving residents operates in a clear regulatory grey area vulnerable to sudden enforcement action.
- Banking/commercial risk: The prohibition on regulated financial institutions dealing in crypto means remote VASPs will struggle to maintain fiat payment rails and banking relationships in Uganda.
- Regulatory ambiguity risk: The NPS Act could be interpreted to cover fiat-to-crypto gateways, creating retroactive enforcement exposure if the regulator later deems such activities as requiring a PSP/PSO license.
- AML/CFT compliance risk: Even without a formal licensing framework, the Anti-Money Laundering Act's broad definition of 'reporting persons' could be interpreted to cover entities facilitating financial transactions, creating parallel AML obligations without corresponding legal recognition.
- Reputational and PR exposure: Public warnings from the BoU and FIA label crypto as high-risk for fraud and money laundering, creating consumer wariness and potential civil liability.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Bank of Uganda Circular (N. 3 of 2021): While direct link to the circular might change, news articles widely reported on it and often link to scans of the original.
Bank of Uganda Warns Supervised Entities Against Dealing in Cryptocurrencies - Techweez (reporting on the circular)
Uganda's Central Bank Orders Financial Institutions to Cease All Crypto Transactions - Bitcoin.com News
Bank of Uganda reiterates its tough stance on cryptocurrency use - Africanews (2022)
A comprehensive legal and regulatory framework for the licensing and supervision of Virtual Asset Service Providers (VASPs) is still largely absent.
National Payment Systems Act, 2020 (NPS Act) and Regulations, 2021: This is the most relevant piece of legislation for payment services in Uganda.
National Payment Systems Regulations, 2021: (Often published as a statutory instrument, typically available via the Uganda Legal Information Institute or Ministry of Finance archives).
Current Situation: No specific license. Many operate in a grey area.
Potential Interpretation: If an exchange facilitates transactions between fiat currency and virtual assets (or vice versa), it could theoretically be deemed to be performing functions similar to a money remitter or payment service provider. In such a scenario, they might be required to obtain a Payment Service Provider (PSP) license or a Payment System Operator (PSO) license under the National Payment Systems Act, 2020, regulated by the Bank of Uganda.
The Anti-Money Laundering Act, 2013 (as amended): This is the primary AML legislation in Uganda. It defines money laundering, establishes the Financial Intelligence Authority (FIA), and outlines obligations for "reporting persons." While it doesn't explicitly mention "cryptocurrency" or "VASP," the broad definitions of "financial institution," "transaction," and "funds" can be interpreted to encompass activities involving virtual assets.
The Anti-Money Laundering Regulations, 2015: These regulations provide more specific details on the implementation of the Act, including customer due diligence, record-keeping, and suspicious transaction reporting.
The Financial Intelligence Authority Act, 2013: This Act establishes the FIA as the central national agency responsible for receiving, analyzing, and disseminating financial intelligence related to money laundering, terrorist financing, and proliferation financing.
Individual Customers: Obtain and verify the customer's full name, permanent address, date of birth, national identification number (e.g., National ID, passport), and other relevant identification documents.
Legal Entities (Companies, etc.): Obtain and verify the company's registered name, legal form, proof of incorporation, physical address, business registration number, tax identification number, and details of directors, beneficial owners, and authorized signatories.
Beneficial Ownership: Identify and verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.
Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or the transaction.
Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds where necessary.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers, transactions, or business relationships. This includes:
Customers from high-risk jurisdictions (identified by FATF or local authorities)
Transactions involving large amounts or complex structures
Transactions with no apparent economic or lawful purpose.
Simplified Due Diligence (SDD): May be applied in limited circumstances where the risk of money laundering or terrorist financing is lower, as permitted by the regulations.
Report Suspicious Transactions: Report any transaction (attempted or completed) where there is a reasonable suspicion that the funds involved are proceeds of crime, or are linked to money laundering, terrorist financing, or proliferation financing.
Report to the FIA: Such reports must be made to the Financial Intelligence Authority (FIA) promptly, and generally within 48 hours of forming the suspicion.
No Tipping-Off: Not disclose to the customer or any third party that a suspicious transaction report has been made or that a money laundering investigation is being conducted.
Customer Identification Records: All records obtained during CDD processes (identification documents, verification records, beneficial ownership information).
Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, type of transaction, and parties involved. For virtual assets, this would include wallet addresses, transaction hashes, and amounts.
Business Correspondence: Records of all relevant business correspondence with customers.
Retention Period: Records must be retained for a minimum period of five (5) years after the business relationship has ended or after the date of an occasional transaction.
Cryptocurrencies are not legal tender in Uganda.
The BoU does not regulate, license, or supervise virtual assets or virtual asset service providers (VASPs).
Regulated financial institutions (banks, payment service providers, etc.) are prohibited from dealing in cryptocurrencies, facilitating crypto transactions, or holding crypto on behalf of clients.
Entity Targeted: All Regulated Financial Institutions (e.g., Commercial Banks, Payment Service Providers, Microfinance Deposit-taking Institutions). Violation Type: N/A (this was a pre-emptive prohibition, not an action against a prior violation by a crypto firm). Penalty Amount: N/A (the circular itself did not impose a fine on a crypto entity, but implied penalties for regulated entities that failed to comply with the directive). Outcome: The BoU issued a circular directing all supervised financial institutions to cease facilitating transactions related to virtual currencies. This effectively cut off cryptocurrency exchanges and related businesses from accessing formal banking services in Uganda. The BoU cited concerns over consumer protection, money laundering, terrorism financing, and the lack of specific regulations. This directive has made it extremely challenging, if not impossible, for crypto businesses to operate formally within the Ugandan financial system.
Entity Targeted: The general public and unregulated virtual asset service providers (implicitly). Violation Type: N/A (warnings about risks, not specific violations). Penalty Amount: N/A. Outcome: These warnings emphasize that cryptocurrencies are not legal tender, are not regulated by the BoU, and carry high risks of fraud, money laundering, and loss of funds. The FIA has also highlighted AML/CFT risks. The lack of a specific licensing and regulatory framework for VASPs means that any entity operating with virtual assets does so without official recognition or oversight, increasing their operational risk and exposure to potential future actions should a framework be introduced. This environment largely prevents formal enforcement actions against VASPs for regulatory non-compliance because there aren't specific VASP regulations to violate yet, other than general financial laws (e.g., fraud).
Outcome: These warnings emphasize that cryptocurrencies are not legal tender, are not regulated by the BoU, and carry high risks of fraud, money laundering, and loss of funds. The FIA has also highlighted AML/CFT risks. The lack of a specific licensing and regulatory framework for VASPs means that any entity operating with virtual assets does so without official recognition or oversight, increasing their operational risk and exposure to potential future actions should a framework be introduced. This environment largely prevents formal enforcement actions against VASPs for regulatory non-compliance because there aren't specific VASP regulations to violate yet, other than general financial laws (e.g., fraud).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Ugandan residents faces a hostile regulatory environment: the Bank of Uganda and FIA have no VASP licensing framework, regulated financial institutions are prohibited from dealing in crypto, and any fiat-to-crypto gateway may be deemed an unlicensed payment service; legal operation would likely require local incorporation and a PSP/PSO license under the NPS Act, but the lack of a clear crypto-specific pathway means most operators exist in a grey area with high enforcement risk.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?