← Regulations / Vietnam / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Vietnam

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Vietnam with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • KYC required for transactions equivalent to at least USD 1,000 (vn.licensing.vasps-must-conduct-updated-kyc)
  • VASPs must have detailed internal AML/KYC procedures integrated into IT systems with audit trails (vn.licensing.licensing-demands-detailed-internal-procedures)
  • Programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection (vn.licensing.platforms-require-programmed-amlkyc-processes)
  • 10-year data retention on Vietnam servers including transaction history, originator/beneficiary details (e.g. wallet addresses), IP/device logs, and account info (vn.licensing.vasps-must-retain-data-on)
  • AML/CTF policies imply STR reporting via MPS/SBV coordination; no explicit STR filing mechanism detailed in pilot docs (vn.licensing.no-explicit-str-filing-mechanism)
  • Systems must achieve Level 4 cybersecurity standard including encryption, intrusion detection, continuous monitoring to support CDD (vn.licensing.systems-must-achieve-level-4)
  • AML/CTF obligations enforced under Resolution No. 05/2025/NQ-CP, with MOF lead, SSC receiving applications, SBV financial integrity, MPS AML/cybersecurity oversight (vn.licensing.the-framework-mandates-vasps-to, vn.licensing.oversight-involves-mof-lead-ssc)

Key Restrictions

  • All customer funds/crypto must be held with a licensed VASP under the MOF/SSC licensing regime (vn.licensing.ministry-of-finance-mof-lead, vn.licensing.state-securities-commission-ssc-licensing)
  • Foreign investors require a single VND account at a licensed local bank; all transactions must use VND (vn.licensing.foreign-investors-require-a-single)
  • Data must be retained on Vietnam servers for 10 years (vn.licensing.vasps-must-retain-data-on)
  • Systems must achieve Level 4 cybersecurity (highest standard) (vn.licensing.systems-must-achieve-level-4)
  • No explicit custody-specific license (e.g. qualified custodian) exists — custodial wallet providers must obtain a general VASP license under the pilot program (vn.licensing.the-framework-mandates-vasps-to)
  • Pilot program is five-year duration (limited-term regime); prior to 2026, VASPs were not explicitly regulated (vn.licensing.prior-to-2026-vasps-were)

Key Risks

  • Enforcement precedent: ONUS case (March 2026) resulted in 7–9 arrests for fraud and money laundering via token price manipulation — demonstrates active MPS enforcement against crypto platforms (vn.enforcement.entity-targeted-onus-cryptocurrency-platform, vn.enforcement.outcome-at-least-79-arrests)
  • No explicit custody-specific rules for segregation, insurance, or proof-of-reserves — creates ambiguity for custodial wallet / SaaS providers (inference from absence in facts)
  • No explicit STR filing mechanism detailed in pilot docs — operational uncertainty around SAR/STR workflows (vn.licensing.no-explicit-str-filing-mechanism)
  • SaaS white-label model: unclear whether AML obligations attach to the SaaS provider (custodian) or the white-label client, and no fact directly addresses this split
  • Pilot program is temporary (five years); post-pilot regulatory certainty is unknown (vn.licensing.prior-to-2026-vasps-were)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Ministry of Finance (MOF) — Lead authority

licensing 20% confidence

State Securities Commission (SSC) — Licensing review and compliance monitoring

licensing 20% confidence

State Bank of Vietnam (SBV) — Financial oversight

licensing 20% confidence

Ministry of Public Security (MPS) — Cybersecurity and financial integrity

licensing 20% confidence

The framework mandates VASPs to apply AML/CTF obligations as part of licensing, treating crypto exchanges as market infrastructure akin to securities exchanges. This includes internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.

licensing 20% confidence

Oversight involves MOF (lead), SSC (receiving applications), SBV (financial integrity), and MPS (AML, cybersecurity).

licensing 20% confidence

Prior to 2026, VASPs were not explicitly regulated under AML laws, but the pilot program (five-year duration) now enforces compliance to prevent illicit flows.

licensing 20% confidence

Key reference: Resolution No. 05/2025/NQ-CP (September 9, 2025) establishes the licensing regime with AML/CTF as a core objective; Decision No. 96/QD-BTC details procedures, including AML appraisals.

licensing 20% confidence

VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.

licensing 20% confidence

Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.

licensing 20% confidence

Foreign investors require a single VND account at a licensed local bank; all transactions use VND.

licensing 20% confidence

Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.

licensing 20% confidence

VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.

licensing 20% confidence

Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.

licensing 20% confidence

No explicit STR filing mechanism is detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.

licensing 20% confidence

Custody and client protection rules reinforce STR through risk controls and complaint handling.

enforcement 60% confidence

Entity Targeted: ONUS cryptocurrency platform (including tokens VNDC, ONUS, and HNG), operated by Vương Lê Vĩnh Nhân (Eric Lê/Vuong Le Vinh Nhan) and associates. Violation Type: Fraud via token price manipulation, deceptive marketing, misleading promotions, artificial trading to control supply/demand, property appropriation, and money laundering using platform infrastructure. Penalty Amount: Not yet finalized; investigation targets billions of dollars in mobilized funds and investor losses (preliminary estimates in billions of USD).

enforcement 60% confidence

Outcome: At least 7–9 arrests (including Vương Lê Vĩnh Nhân and 6–8 accomplices); over 140 individuals summoned; platform operations dismantled; charges filed for fraud and money laundering.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS providers must obtain a VASP license under the MOF/SSC-led pilot regime (Resolution No. 05/2025/NQ-CP), with no dedicated qualified-custodian license category, and must comply with AML/KYC obligations (USD 1,000 threshold), Level 4 cybersecurity, 10-year local data retention, and VND-only banking; the ONUS enforcement case demonstrates active MPS risk, and the SaaS-model allocation of AML duties between provider and white-label client is not explicitly addressed in available facts.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?