← Regulations / Yemen / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Yemen

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Not permitted AI-Generated · Unreviewed

Custodial SaaS is not permitted in Yemen.

Verdict Details

Permitted
no
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer identification and verification under Law No. 1 of 2010 on Combating Money Laundering and Terrorism Financing (the primary AML/CFT law)
  • Beneficial ownership identification and verification for legal entity customers
  • Understanding the purpose and intended nature of the business relationship
  • Ongoing due diligence and transaction monitoring throughout the business relationship
  • Enhanced Due Diligence (EDD) for higher-risk customers including PEPs — any crypto involvement would inherently be high-risk
  • Reporting suspicious transactions to the Financial Information Unit (FIU) — any virtual asset transaction is inherently suspicious under the de facto ban
  • Record-keeping of customer identification and transaction data for at least 5 years after business relationship ends
  • Records must be maintained for rapid retrieval by competent authorities upon request
  • AML/KYC obligations arise for any financial activity — operating without explicit AML/KYC protocols would be a significant red flag under general AML/CFT principles and FATF standards

Key Restrictions

  • Cryptocurrency custody services are not recognized or permitted — no licenses are issued for such activities
  • Central Bank of Yemen (both Sana'a and Aden branches) has warned against dealing with cryptocurrencies, deeming them illegal and speculative
  • Any entity attempting to operate a VASP falls into a grey area of legality or risks being interpreted under broader financial laws, or being outright prohibited
  • Custody providers might be interpreted as holding funds/assets on behalf of others, which could require a banking or trust license under existing financial laws
  • No segregation of client assets rules, no insurance/bonding requirements, no cold storage mandates exist because the framework does not acknowledge crypto custody providers
  • No definition exists for a 'qualified custodian' for digital assets

Key Risks

  • De facto prohibition: operating without a clear legal framework carries significant legal risk including potential penalties, asset confiscation, or criminal charges for unlicensed financial services
  • Ongoing civil conflict makes official government and central bank websites unstable, inaccessible, or subject to control by different factions — regulatory uncertainty is extreme
  • Lack of transparency from regulatory bodies in conflict zones; no incentive to publish detailed regulatory frameworks for prohibited activities
  • Any transaction involving virtual assets would inherently be considered suspicious and a potential predicate offense under the AML/CFT law
  • Two competing Central Banks (Aden-based, internationally recognized; Sana'a-based, Houthi-controlled) create jurisdictional confusion and compliance risk
  • No pending legislation to regulate crypto custody — focus if any regulatory action occurs would likely be on reinforcing the ban, not creating a framework for legitimate operations

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 20% confidence

Custodial License Requirements: No licenses are issued for cryptocurrency custody services as such activities are not recognized or permitted.

custody 20% confidence

Segregation of Client Assets Rules: There are no rules for segregating client assets for crypto custody, as regulated custody services are not established.

custody 20% confidence

Insurance/Bonding Requirements: No insurance or bonding requirements exist for crypto custodians.

custody 20% confidence

Cold Storage Mandates: There are no mandates for cold storage, as the regulatory framework does not acknowledge the existence of crypto custody providers.

custody 20% confidence

Qualified Custodian Definitions: There is no definition for a "qualified custodian" for digital assets in Yemen.

custody 20% confidence

Any Pending Custody Legislation: There is no known pending legislation to regulate cryptocurrency custody. The focus, if any regulatory action were to be taken, would likely be on reinforcing the ban or addressing illicit uses rather than creating a framework for legitimate operations.

custody 20% confidence

Central Bank of Yemen (Sana'a Branch): In 2018-2019, the CBY in Sana'a reportedly issued warnings against dealing with cryptocurrencies, deeming them illegal and speculative.

custody 20% confidence

Central Bank of Yemen (Aden Branch): Similarly, the CBY in Aden has also warned against cryptocurrencies.

licensing 40% confidence

Yemen does not have dedicated laws or regulations specifically addressing virtual assets, cryptocurrencies, or Virtual Asset Service Providers (VASPs).

licensing 40% confidence

In the absence of specific crypto regulations, any entity attempting to operate a cryptocurrency exchange, provide custody services, or process payments using virtual assets would fall into a grey area of legality or risk being interpreted under existing, broader financial laws, or even being outright prohibited.

licensing 40% confidence

Custody Providers: Might be interpreted as holding funds or assets on behalf of others, which in a traditional context could require a banking or trust license.

licensing 40% confidence

De Facto Prohibition/High Risk: Without a clear legal framework, engaging in such activities carries significant legal risk, including potential penalties for operating an unlicensed financial service, confiscation of assets, or criminal charges, depending on how authorities might interpret activities. It is more likely to be viewed with suspicion than to be regulated.

licensing 40% confidence

AML/KYC (Anti-Money Laundering/Know Your Customer): Yemen has general AML/CFT (Combating the Financing of Terrorism) laws, even if their enforcement is challenging and fragmented.

licensing 40% confidence

Operating without explicit AML/KYC protocols would be a significant red flag and expose operators to severe legal and reputational risks.

aml 40% confidence

Law No. 1 of 2010 on Combating Money Laundering and Terrorism Financing: This is the primary AML/CFT law in Yemen. It establishes the legal framework for identifying, freezing, and confiscating illicit funds, and mandates reporting obligations for financial institutions.

aml 40% confidence

Identification and Verification: Obtaining and verifying the identity of customers (individuals and legal entities) using reliable, independent source documents, data, or information. This includes name, address, date of birth/incorporation, nationality, identification numbers.

aml 40% confidence

Beneficial Ownership: Identifying and verifying the beneficial owner(s) of legal entities.

aml 40% confidence

Purpose and Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or occasional transaction.

aml 40% confidence

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity's knowledge of the customer, their business, and risk profile.

aml 40% confidence

Enhanced Due Diligence (EDD): For higher-risk customers, politically exposed persons (PEPs), or complex transactions, more rigorous checks would be required. Given the illegal status of crypto, any involvement would inherently be high-risk.

aml 40% confidence

Obligation to Report: Financial institutions and designated non-financial businesses and professions (DNFBPs) are legally obliged to report any suspicious transactions or activities to the Financial Information Unit (FIU).

aml 40% confidence

Virtual Assets: Given the outright ban, any transaction involving virtual assets would inherently be considered suspicious and a potential predicate offense under the AML/CFT law.

aml 40% confidence

Duration: Financial institutions are required to maintain records of customer identification data, account files, business correspondence, and transaction data for a period of at least five (5) years after the business relationship has ended or the transaction has been completed.

aml 40% confidence

Accessibility: Records must be maintained in a way that allows for rapid retrieval by competent authorities upon request.

custody 20% confidence

Political Instability: The ongoing civil conflict makes official government and central bank websites unstable, inaccessible, or subject to control by different factions.

custody 20% confidence

Lack of Transparency: Regulatory bodies in conflict zones often lack the resources or political will to maintain comprehensive, publicly accessible digital archives of all their directives.

custody 20% confidence

Prohibitive Stance: When an activity is prohibited, there's less incentive to publish detailed regulatory frameworks for it; rather, the focus is on blanket warnings or bans.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Not permitted — custodial wallet / SaaS operations in Yemen face a de facto prohibition, as both branches of the Central Bank of Yemen have declared cryptocurrencies illegal and speculative, no custody licensing framework exists, and any entity attempting such activity risks criminal penalties for operating unlicensed financial services under existing law.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?