Custodial wallet / SaaS in Yemen
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is not permitted in Yemen.
Verdict Details
- Permitted
- no
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification under Law No. 1 of 2010 on Combating Money Laundering and Terrorism Financing (the primary AML/CFT law)
- Beneficial ownership identification and verification for legal entity customers
- Understanding the purpose and intended nature of the business relationship
- Ongoing due diligence and transaction monitoring throughout the business relationship
- Enhanced Due Diligence (EDD) for higher-risk customers including PEPs — any crypto involvement would inherently be high-risk
- Reporting suspicious transactions to the Financial Information Unit (FIU) — any virtual asset transaction is inherently suspicious under the de facto ban
- Record-keeping of customer identification and transaction data for at least 5 years after business relationship ends
- Records must be maintained for rapid retrieval by competent authorities upon request
- AML/KYC obligations arise for any financial activity — operating without explicit AML/KYC protocols would be a significant red flag under general AML/CFT principles and FATF standards
Key Restrictions
- Cryptocurrency custody services are not recognized or permitted — no licenses are issued for such activities
- Central Bank of Yemen (both Sana'a and Aden branches) has warned against dealing with cryptocurrencies, deeming them illegal and speculative
- Any entity attempting to operate a VASP falls into a grey area of legality or risks being interpreted under broader financial laws, or being outright prohibited
- Custody providers might be interpreted as holding funds/assets on behalf of others, which could require a banking or trust license under existing financial laws
- No segregation of client assets rules, no insurance/bonding requirements, no cold storage mandates exist because the framework does not acknowledge crypto custody providers
- No definition exists for a 'qualified custodian' for digital assets
Key Risks
- De facto prohibition: operating without a clear legal framework carries significant legal risk including potential penalties, asset confiscation, or criminal charges for unlicensed financial services
- Ongoing civil conflict makes official government and central bank websites unstable, inaccessible, or subject to control by different factions — regulatory uncertainty is extreme
- Lack of transparency from regulatory bodies in conflict zones; no incentive to publish detailed regulatory frameworks for prohibited activities
- Any transaction involving virtual assets would inherently be considered suspicious and a potential predicate offense under the AML/CFT law
- Two competing Central Banks (Aden-based, internationally recognized; Sana'a-based, Houthi-controlled) create jurisdictional confusion and compliance risk
- No pending legislation to regulate crypto custody — focus if any regulatory action occurs would likely be on reinforcing the ban, not creating a framework for legitimate operations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial License Requirements: No licenses are issued for cryptocurrency custody services as such activities are not recognized or permitted.
Segregation of Client Assets Rules: There are no rules for segregating client assets for crypto custody, as regulated custody services are not established.
Insurance/Bonding Requirements: No insurance or bonding requirements exist for crypto custodians.
Cold Storage Mandates: There are no mandates for cold storage, as the regulatory framework does not acknowledge the existence of crypto custody providers.
Qualified Custodian Definitions: There is no definition for a "qualified custodian" for digital assets in Yemen.
Any Pending Custody Legislation: There is no known pending legislation to regulate cryptocurrency custody. The focus, if any regulatory action were to be taken, would likely be on reinforcing the ban or addressing illicit uses rather than creating a framework for legitimate operations.
Central Bank of Yemen (Sana'a Branch): In 2018-2019, the CBY in Sana'a reportedly issued warnings against dealing with cryptocurrencies, deeming them illegal and speculative.
Central Bank of Yemen (Aden Branch): Similarly, the CBY in Aden has also warned against cryptocurrencies.
Yemen does not have dedicated laws or regulations specifically addressing virtual assets, cryptocurrencies, or Virtual Asset Service Providers (VASPs).
In the absence of specific crypto regulations, any entity attempting to operate a cryptocurrency exchange, provide custody services, or process payments using virtual assets would fall into a grey area of legality or risk being interpreted under existing, broader financial laws, or even being outright prohibited.
Custody Providers: Might be interpreted as holding funds or assets on behalf of others, which in a traditional context could require a banking or trust license.
De Facto Prohibition/High Risk: Without a clear legal framework, engaging in such activities carries significant legal risk, including potential penalties for operating an unlicensed financial service, confiscation of assets, or criminal charges, depending on how authorities might interpret activities. It is more likely to be viewed with suspicion than to be regulated.
AML/KYC (Anti-Money Laundering/Know Your Customer): Yemen has general AML/CFT (Combating the Financing of Terrorism) laws, even if their enforcement is challenging and fragmented.
Operating without explicit AML/KYC protocols would be a significant red flag and expose operators to severe legal and reputational risks.
Law No. 1 of 2010 on Combating Money Laundering and Terrorism Financing: This is the primary AML/CFT law in Yemen. It establishes the legal framework for identifying, freezing, and confiscating illicit funds, and mandates reporting obligations for financial institutions.
Identification and Verification: Obtaining and verifying the identity of customers (individuals and legal entities) using reliable, independent source documents, data, or information. This includes name, address, date of birth/incorporation, nationality, identification numbers.
Beneficial Ownership: Identifying and verifying the beneficial owner(s) of legal entities.
Purpose and Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile.
Enhanced Due Diligence (EDD): For higher-risk customers, politically exposed persons (PEPs), or complex transactions, more rigorous checks would be required. Given the illegal status of crypto, any involvement would inherently be high-risk.
Obligation to Report: Financial institutions and designated non-financial businesses and professions (DNFBPs) are legally obliged to report any suspicious transactions or activities to the Financial Information Unit (FIU).
Virtual Assets: Given the outright ban, any transaction involving virtual assets would inherently be considered suspicious and a potential predicate offense under the AML/CFT law.
Duration: Financial institutions are required to maintain records of customer identification data, account files, business correspondence, and transaction data for a period of at least five (5) years after the business relationship has ended or the transaction has been completed.
Accessibility: Records must be maintained in a way that allows for rapid retrieval by competent authorities upon request.
Political Instability: The ongoing civil conflict makes official government and central bank websites unstable, inaccessible, or subject to control by different factions.
Lack of Transparency: Regulatory bodies in conflict zones often lack the resources or political will to maintain comprehensive, publicly accessible digital archives of all their directives.
Prohibitive Stance: When an activity is prohibited, there's less incentive to publish detailed regulatory frameworks for it; rather, the focus is on blanket warnings or bans.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Not permitted — custodial wallet / SaaS operations in Yemen face a de facto prohibition, as both branches of the Central Bank of Yemen have declared cryptocurrencies illegal and speculative, no custody licensing framework exists, and any entity attempting such activity risks criminal penalties for operating unlicensed financial services under existing law.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?