DeFi protocol frontend in Vanuatu
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Vanuatu with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration with VFSC as a VASP under the Virtual Asset Providers Act No. 27 of 2023 (VAPA 2023).
- Full AML/CTF program requirements under the Anti-Money Laundering and Counter-Terrorism Financing Act No. 13 of 2017 [CAP 264], including suspicious transaction reporting to the Vanuatu Financial Intelligence Unit (FIU).
- Customer due diligence (CDD) and KYC on all users — no explicit exemption for decentralized frontends or non-custodial interfaces.
- Ongoing transaction monitoring obligations.
- Record-keeping requirements (identity of each client's virtual assets per Section 22 VAPA 2023).
- Reporting obligations to VFSC and FIU as determined by the AML/CTF framework.
- Fit and proper person requirements for directors and senior management (Section 14 VAPA 2023).
Key Restrictions
- Any operation that meets the VASP definition (including fee-taking frontends interacting with users' assets) requires a VASP license under VAPA 2023.
- Client virtual assets must be segregated from the operator's own assets (Section 20 VAPA 2023), which poses structural challenges for non-custodial frontends.
- Operator cannot use, deal with, or dispose of client virtual assets without explicit consent (Section 21 VAPA 2023).
- Minimum unimpaired paid-up capital required (Section 18 VAPA 2023), though specific thresholds are not yet prescribed by regulation.
- Local incorporation in Vanuatu is implicitly required to obtain a VASP license from VFSC.
- Geofencing of prohibited jurisdictions (e.g., US persons) likely necessary to comply with licensing scope and regulatory risk appetite.
Key Risks
- Regulatory ambiguity: VAPA 2023 was designed primarily for custodial VASPs (exchanges, custody providers) and it is unclear how its custody/asset-segregation provisions apply to non-custodial DeFi frontends.
- Lack of specific enforcement precedent in Vanuatu against DeFi operators — regulatory interpretation of 'virtual asset service' may expand to cover any frontend that facilitates transactions.
- Fee-taking (e.g., frontend fees, swap fees) likely crosses the line into providing a 'service' and triggers VASP licensing; aggregators without fees may still be caught if they exercise control or screening.
- Minimal market size and offshore financial centre profile may create reputational risk for operators targeting global users from a Vanuatu entity.
- Capital requirements (Section 18) may be set at levels impractical for early-stage DeFi frontends once the Minister prescribes thresholds.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Providers Act No. 27 of 2023 (VAPA 2023): This is the cornerstone legislation for virtual assets, including custody services. It defines "virtual assets," "virtual asset service providers" (VASPs), and sets out licensing and operational requirements.
Vanuatu Financial Services Commission - Virtual Asset Providers Act No. 27 of 2023 (PDF link on VFSC website)
Application Requirements (Section 12, VAPA 2023): An applicant for a VASP license must submit to the VFSC:
Capital Requirements (Section 18, VAPA 2023): A VASP must at all times maintain a minimum unimpaired paid-up capital as prescribed by the Minister through regulation. This regulation is yet to be fully detailed.
Fit and Proper Persons (Section 14, VAPA 2023): Directors and senior management must meet "fit and proper" criteria established by the VFSC, demonstrating competence, integrity, and financial soundness.
Client Assets (Sections 20, 21, 22, VAPA 2023):
A VASP must hold a client’s virtual assets separate from its own assets and the assets of other clients (Section 20(1)).
Virtual assets held by a VASP on behalf of a client are not to be used to satisfy any liability of the VASP or form part of its assets (Section 20(2)).
A VASP is prohibited from using, dealing with, or otherwise disposing of a client's virtual assets without the client's explicit consent, except as authorized by law or a court order (Section 21).
A VASP must maintain adequate records that clearly identify the ownership of each client's virtual assets (Section 22).
Risk Management and Internal Controls (Section 19, VAPA 2023): A licensed VASP must implement robust risk management systems and internal controls designed to ensure the security, integrity, and operational resilience of its services, which could implicitly encourage or require consideration of insurance.
Financial Soundness and Capital Requirements (Section 18, VAPA 2023): The requirement for adequate capital is intended to provide a buffer against operational risks, though it's not a direct substitute for insurance.
Virtual Assets: The most likely general classification is "Virtual Assets" or "Digital Assets" under the Anti-Money Laundering and Counter-Terrorism Financing Act (AML/CTF Act) [CAP 264]. This act defines "virtual asset" broadly and mandates AML/CTF obligations for Virtual Asset Service Providers (VASPs).
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act [CAP 264] (accessible via PacLII: http://www.paclii.org/vu/legis/consol_act/a-mlact2019318/ - Note: This link points to the 2019 version which often incorporates previous amendments.)
Virtual Asset Service Provider (VASP) Obligations: The AML/CTF Act [CAP 264] mandates that entities providing "virtual asset services" (which would include stablecoin exchanges, transfers, custody, etc.) are considered VASPs and must comply with AML/CTF obligations, including registration with the Vanuatu Financial Intelligence Unit (FIU) and implementing robust KYC/CDD procedures.
Reference: Vanuatu Financial Intelligence Unit (FIU) website: http://www.fiu.gov.vu/
General Regulatory Stance and Warnings:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend would likely be classified as a VASP under VAPA 2023 (especially if fee-taking), requiring a full VASP license from VFSC, local incorporation, AML/CTF obligations including CDD/KYC, capital requirements, and asset segregation rules that are poorly suited to non-custodial models, with significant regulatory ambiguity due to lack of enforcement precedent and unclear applicability of custody-focused provisions.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?