Custodial wallet / SaaS in Saint Vincent and the Grenadines
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Saint Vincent and the Grenadines with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer due diligence (CDD) required for all customers — natural persons: full name, residential address, date of birth, nationality, unique ID number verified via independent source documents.
- Legal person CDD: legal name, registered/business address, incorporation documents, beneficial ownership identification (25%+ threshold).
- Risk-based approach to CDD with enhanced due diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions.
- Ongoing transaction monitoring to ensure consistency with customer risk profile and source of funds where necessary.
- Obligation to file Suspicious Transaction Reports (STRs) to the Financial Intelligence Unit (FIU) 'without delay' upon reasonable grounds of suspicion.
- Recordkeeping: maintain CDD docs, transaction records, business correspondence, STRs and internal reports for minimum 5 years after relationship end or transaction date.
- No tipping-off prohibition — cannot disclose STR filing to customer or third parties.
Key Restrictions
- Must register as a Virtual Asset Service Provider (VASP) under the Virtual Asset Business Act, 2020 (VABA) — operating without registration is a violation.
- Must not falsely claim to be regulated by the SVG FSA; advertising without proper licensing is prohibited.
- Local entity likely required — the FSA and FIU oversight is territorially based, and entities operating in/from SVG must comply with VABA.
Key Risks
- No dedicated custody license / qualified-custodian framework exists in SVG for virtual asset custodians — regulatory classification of custodial wallets under VABA is ambiguous.
- The SVG FSA has publicly warned about unlicensed VASP activity and misrepresentation of regulatory status, creating enforcement risk for non-compliant operators.
- Thin regulatory infrastructure — the FSA does not specifically license VASPs, and segregation/insurance/proof-of-reserves rules for custodial wallets are not codified.
- AML obligations appear to fall on the registered VASP (the SaaS provider) as a reporting entity; unclear how obligations are allocated between white-label provider and client.
- Jurisdiction is a small offshore financial center — potential reputational risk and scrutiny from international FATF assessments.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Proceeds of Crime Act, 2013 (as amended): This act criminalizes money laundering and terrorist financing offenses and provides for the forfeiture of assets derived from criminal conduct.
The Anti-Money Laundering and Combating the Financing of Terrorism Act, 2017 (as amended): This is the principal legislation outlining the obligations for financial institutions and DNFBPs to prevent and detect money laundering and terrorist financing. It defines key terms, outlines reporting obligations, and sets out penalties for non-compliance.
The Financial Intelligence Unit Act, 2001 (as amended): This act establishes the Financial Intelligence Unit (FIU) and defines its powers and functions, including receiving and analyzing suspicious transaction reports.
Identify and Verify Customer Identity:
For natural persons: Obtain full name, residential address, date of birth, nationality, and a unique identification number (e.g., passport, national ID card). Verification typically requires independent, reliable source documents.
For legal persons/entities: Obtain legal name, address of registered office and principal place of business, incorporation details (e.g., certificate of incorporation, articles of association), and identify beneficial owners (those who ultimately own or control 25% or more of the entity).
Understand the Purpose and Intended Nature of the Business Relationship: Gather information about why the customer is seeking the services and how they intend to use them.
Conduct Ongoing Monitoring: Regularly review the business relationship and transactions undertaken to ensure they are consistent with the entity's knowledge of the customer, their business, and risk profile, including (where necessary) the source of funds.
Risk-Based Approach: Apply a risk-based approach to CDD.
Enhanced Due Diligence (EDD): Required for high-risk customers, such as Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or transactions involving complex structures or unusually large amounts. This involves more rigorous verification, deeper understanding of source of funds/wealth, and higher-level approval for establishing relationships.
Simplified Due Diligence (SDD): Permitted for low-risk customers, where sufficient information is available through public sources and the risk of ML/FT is assessed as low.
Obligation to Report: All reporting entities (which would include VASPs if their activities are considered relevant financial business) have a legal obligation to report any transaction (or attempted transaction) where there are reasonable grounds to suspect that funds are the proceeds of criminal activity or are linked to terrorist financing.
Recipient: Reports must be submitted to the Financial Intelligence Unit (FIU) of Saint Vincent and the Grenadines.
Timeliness: STRs must be filed promptly, "without delay," upon forming the suspicion.
No Tipping-Off: It is an offense to disclose to the customer or any third party that a suspicious transaction report has been or will be made.
Customer Identification Data: All documents used for CDD, including copies of identification documents and verification records.
Transaction Records: Details of all transactions, including amounts, types of currency/virtual assets, dates, and parties involved.
Business Correspondence: Records of communications with customers and third parties related to transactions and the business relationship.
STRs and Internal Reports: Copies of all suspicious transaction reports filed and any internal reports or analyses leading to such reports.
Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.
Financial Services Authority (FSA):
Financial Intelligence Unit (FIU):
Entity Targeted: General public and entities falsely claiming to be regulated by the SVG FSA for virtual asset business. Violation Type: Operating or advertising virtual asset business activities without proper licensing under the Virtual Asset Business Act, 2020 (VABA), or misrepresenting regulatory status. Penalty Amount: Not applicable to general warnings; specific penalties for unlicensed operation would be determined if an investigation led to a formal enforcement action, which typically isn't publicly detailed. Outcome: Increased public awareness, pressure on unlicensed entities to cease operations or comply, and a clear stance from the regulator.
Entity Targeted: All virtual asset service providers (VASPs) and the general public, including those considering operating in or from SVG. Violation Type: N/A (this is a regulatory clarification, not an enforcement action itself). However, entities failing to register or comply with VABA would be in violation. Penalty Amount: N/A. Outcome: Enhanced clarity on legal obligations for VASPs, driving compliance with registration requirements, AML/CFT measures, and consumer protection. This sets the stage for future enforcement by defining what constitutes a violation.
Outcome: Increased public awareness, pressure on unlicensed entities to cease operations or comply, and a clear stance from the regulator.
Outcome: Enhanced clarity on legal obligations for VASPs, driving compliance with registration requirements, AML/CFT measures, and consumer protection. This sets the stage for future enforcement by defining what constitutes a violation.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators may serve residents from SVG if registered as a VASP under the Virtual Asset Business Act 2020, but no dedicated custody-license framework exists, and AML obligations (CDD, ongoing monitoring, STR filing to FIU) apply to the registered entity, with significant regulatory ambiguity around segregation, insurance, and proof-of-reserves requirements.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?