← Regulations / Uzbekistan / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Uzbekistan

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Uzbekistan with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • All custodial wallet / SaaS providers must be licensed as a VASP by NAPP under Cabinet Resolution No. 445.
  • Must implement and maintain internal AML/CFT policies and procedures per NAPP's August 2023 AML Regulation.
  • Mandatory KYC/ CDD for all clients — identity verification via reliable, independent sources (passport, national ID).
  • For legal-entity clients: verify legal name, form, address, registration number, directors, and beneficial owners (>25% threshold).
  • Ongoing transaction monitoring — scrutinize transactions for consistency with client profile and risk category.
  • Risk categorization (low/medium/high) with simplified CDD for low-risk and Enhanced Due Diligence (EDD) for high-risk clients, PEPs, high-risk geographies, and complex/anonymous transactions.
  • Source of funds/wealth verification for high-risk clients or above-threshold transactions.
  • Suspicious transaction reporting to NAPP and relevant authorities.
  • Beneficial ownership identification — reasonable measures to verify individuals who own/control >25% of a client entity.
  • Regular review of existing customer information, especially for high-risk clients.
  • AML obligations apply at the SaaS provider level (licensed VASP); white-label clients are also likely obliged entities if they touch end-user assets or interface with customers directly.

Key Restrictions

  • Must be a legal entity registered in the Republic of Uzbekistan (local incorporation required).
  • All data related to virtual asset turnover and client data must be stored on servers located within Uzbekistan.
  • Must integrate information systems with NAPP's unified information system for monitoring and supervision.
  • Must obtain an information security certificate (e.g., ISO 27001) and conduct regular penetration testing and security audits.
  • Minimum authorized capital requirements apply as set by NAPP (similar to exchange-level capital requirements).
  • Directors and key personnel must meet qualification requirements and have a clean criminal record.
  • Must develop clear and transparent client terms of service, fee structures, and complaint resolution procedures.
  • White-label/BaaS model must ensure both the SaaS provider and the white-label client each satisfy licensing obligations — NAPP's licensing framework likely requires each entity dealing with virtual assets to hold its own license.

Key Risks

  • No publicly available detailed custody-specific rules on asset segregation, insurance requirements, or proof-of-reserves — regulatory gap or unpublished guidance may exist.
  • SaaS provider bears primary AML/licensing liability; unclear whether white-label clients can rely on the SaaS provider's license or must obtain their own separate license.
  • Data localization and government system integration create operational complexity and potential latency/availability risks.
  • Regulatory framework is young and undergoing continuous refinement — NAPP regularly issues clarifications and amendments, creating uncertainty for long-term planning.
  • Uzbekistan is a FATF/EAG member — future FATF-driven changes (e.g., Travel Rule implementation) could impose new obligations on custodians.
  • Enforcement precedents are limited; compliance gaps in the evolving framework carry high regulatory risk.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Resolution of the Cabinet of Ministers No. 445 "On approval of the Regulation on the procedure for licensing the activities of service providers in the field of circulation of crypto-assets" dated August 22, 2022. This is the most critical document detailing licensing and operational requirements.

licensing 60% confidence

Presidential Decree No. UP-106 "On measures for further development of the digital economy in the Republic of Uzbekistan" dated March 16, 2022. This decree established NAPP as the regulator and laid out the general principles.

licensing 60% confidence

Legal Entity Status: The applicant must be a legal entity registered in the Republic of Uzbekistan.

licensing 60% confidence

Authorized Capital: Compliance with the minimum authorized capital requirements as stipulated by NAPP (e.g., for crypto exchanges, it's often set at a significant amount in USD equivalent, which usually applies to other VASPs like custodians as well).

licensing 60% confidence

AML/CFT Compliance: Strict adherence to international Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) standards, including FATF recommendations. This involves:

licensing 60% confidence

Data Storage: All information related to virtual asset turnover and client data must be stored on servers located within the territory of the Republic of Uzbekistan.

licensing 60% confidence

Integration with NAPP Systems: Service providers must integrate their information systems with NAPP's unified information system for monitoring and supervision.

licensing 60% confidence

Qualified Personnel: Directors and key personnel must meet qualification requirements, including relevant experience and a clean criminal record.

licensing 60% confidence

Internal Control System: Establishment of an effective internal control system to manage operational risks.

licensing 60% confidence

Clear Rules: Development of clear and transparent rules for interaction with clients, including terms of service, fee structures, and complaint resolution procedures.

aml 60% confidence

Regulation on the Procedure for Carrying Out Anti-Money Laundering and Counter-Terrorism Financing Measures for Virtual Asset Market Participants (Registered by the Ministry of Justice on August 9, 2023, No. 3456).

aml 60% confidence

Identification and Verification:

aml 60% confidence

Individuals: Obtain and verify identity through reliable, independent sources (e.g., passport, national ID card). This includes name, date of birth, place of birth, address, nationality, and ID document details.

aml 60% confidence

Legal Entities: Obtain and verify legal name, legal form, address, registration number, articles of incorporation, names of directors and senior management, and proof of legal existence.

aml 60% confidence

Source of Funds/Wealth: For high-risk clients or transactions exceeding a certain threshold, VASPs must identify and verify the source of funds or wealth involved.

aml 60% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the client. For legal entities, this typically means identifying individuals who own or control more than a specified percentage (e.g., 25%) of the company, or who otherwise exercise control through other means.

aml 60% confidence

Regularly review existing customer information to ensure it is up-to-date and relevant, especially for high-risk clients.

aml 60% confidence

Scrutinize transactions undertaken by clients to ensure they are consistent with the VASP's knowledge of the client, their business, and risk profile.

aml 60% confidence

Categorize clients based on their ML/TF risk (e.g., low, medium, high).

aml 60% confidence

Apply simplified CDD for low-risk clients/transactions where appropriate.

aml 60% confidence

Apply Enhanced Due Diligence (EDD) for high-risk clients, transactions, or business relationships. This includes:

aml 60% confidence

Politically Exposed Persons (PEPs) and their family members/close associates.

aml 60% confidence

Clients from high-risk geographic areas (as identified by FATF or NAPP).

aml 60% confidence

Transactions involving new or complex technologies that may favor anonymity.

aml 60% confidence

Unusual or complex transactions without an apparent economic or lawful purpose.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers can operate in Uzbekistan only as locally incorporated, NAPP-licensed VASPs with mandatory data localization, government system integration, IT security certification, and full AML/CFT obligations (KYC, EDD, STR, beneficial ownership); however, asset segregation, insurance, and proof-of-reserves rules specific to custody are not clearly defined in public regulations, and the white-label/BaaS allocation of licensing responsibility remains ambiguous.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?