← Regulations / Zimbabwe / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Zimbabwe

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Zimbabwe with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASPs are designated as 'financial institutions' under the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) and must comply as reporting entities.
  • Customer Due Diligence (CDD) / KYC procedures for all users.
  • Ongoing monitoring of transactions for suspicious activities.
  • Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FIU).
  • Appointment of a dedicated AML/CFT Compliance Officer.
  • Robust internal AML/CFT policies and controls.
  • Record-keeping of transactions and customer data.
  • Risk-based assessment and management of AML/CTF risks.
  • Currency transaction reporting (CTR) thresholds apply as per the Money Laundering and Proceeds of Crime Act.
  • FATF Travel Rule has not been specifically implemented — no specific threshold or technical implementation requirements yet.

Key Restrictions

  • No specific custodial license or qualified-custodian regime exists — a VASP license covering custody is the expected path.
  • No legally mandated segregation of client digital assets; no specific insurance/bonding or cold-storage requirements exist.
  • The regulatory framework for VASPs is nascent — operated via the Money Laundering and Proceeds of Crime Amendment Act (2022) and the RBZ National Fintech Sandbox, but no comprehensive digital-asset custody rules have been enacted.
  • Local incorporation in Zimbabwe is highly probable (if not required) for licensing.
  • Physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer) may be required.

Key Risks

  • Regulatory ambiguity: no dedicated custody/qualified-custodian framework exists — reliance on future regulations from RBZ and FIU creates operational uncertainty.
  • Enforcement risk: VASPs are already designated as financial institutions under AML law, but the broader licensing and custody-specific rules are not yet in force, creating a gap for operators.
  • No segregation or insurance mandates mean client asset protection is purely contractual — high exposure in the event of insolvency or hack.
  • Travel Rule not implemented, but FATF mutual evaluation may force rapid adoption, creating retroactive compliance risk.
  • The RBZ is studying crypto/CBDC — a future regulatory shift could materially change the operating environment.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 60% confidence

No Specific Rules: As there are no specific custodial licenses or regulatory frameworks, there are no explicit rules mandating the segregation of client digital assets from a custodian's proprietary assets. Best practices in traditional finance would suggest segregation, but this is not legally mandated for crypto custody in Zimbabwe.

custody 60% confidence

No Specific Requirements: There are no specific insurance or bonding requirements for digital asset custodians.

custody 60% confidence

No Specific Mandates: While cold storage is a widely recognized security best practice for managing digital assets, there are no specific legal mandates or requirements for its use by custodians in Zimbabwe.

custody 60% confidence

No Specific Definition: The term "qualified custodian" and its associated definitions, commonly found in more mature regulatory jurisdictions (like the US under SEC rules), do not exist within Zimbabwe's current regulatory landscape for digital assets.

custody 60% confidence

National Financial Technology Sandbox (2021): This is the most significant development pointing towards future regulation. Launched by the RBZ, the sandbox allows innovative fintech solutions, including those involving digital assets, to be tested in a controlled environment. While not legislation itself, insights gained from the sandbox are expected to inform the development of future laws and regulations.

licensing 60% confidence

Regulatory Sandbox: This is anticipated to be a controlled environment where approved entities can test innovative financial products, services, or business models (including those involving VAs) with real customers, but within defined parameters and under the close supervision of the RBZ, for a limited period. Successful participants in the sandbox may then be eligible for full licensing once the broader framework is established.

licensing 60% confidence

Virtual Asset Service Provider (VASP) License: This is the most common umbrella term. It would likely cover:

licensing 60% confidence

Custody Providers: Entities providing services to safeguard virtual assets or instruments enabling control over virtual assets on behalf of others.

licensing 60% confidence

Registration: In some regimes, registration might be a simpler, less rigorous process for lower-risk activities or for certain types of market participants (e.g., basic disclosures).

licensing 60% confidence

Licensing: This typically involves a comprehensive application, detailed due diligence, meeting stringent capital, operational, and compliance requirements, and ongoing supervision. Zimbabwe is expected to adopt a full licensing regime for commercial VA operations to ensure financial stability, consumer protection, and AML/CFT compliance.

licensing 60% confidence

Likely to be prescribed minimum capital thresholds, which may vary depending on the type and scale of VA services offered, reflecting the inherent risks. This ensures financial stability and ability to absorb operational shocks.

licensing 60% confidence

This will be a paramount requirement. Virtual asset service providers will be designated as "reporting entities" and will be subject to the provisions of Zimbabwe's Money Laundering and Proceeds of Crime Act (Chapter 9:24) and regulations issued by the Financial Intelligence Unit (FIU).

licensing 60% confidence

It is highly probable that licensed entities will need to be domiciled in Zimbabwe (i.e., incorporated locally).

licensing 60% confidence

Requirements may include a physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer).

aml 60% confidence

Partially (Framework for VASPs): Zimbabwe, as an FATF member, is committed to implementing FATF Recommendations. In October 2022, Zimbabwe promulgated the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022), which for the first time designated VASPs as "financial institutions" for AML/CFT purposes. This means VASPs are now subject to general AML/CFT obligations such as customer due diligence (CDD), record-keeping, and suspicious transaction reporting (STR).

aml 60% confidence

Not Adopted (Travel Rule Specifics): While VASPs are regulated, the specific requirements of the FATF Travel Rule – mandating the collection and sharing of originator and beneficiary information for virtual asset transfers – have not yet been specifically legislated or enforced. The FATF's Mutual Evaluation Report for Zimbabwe (October 2022) highlighted this as an area needing improvement, stating that measures to implement the Travel Rule were not yet in place.

aml 60% confidence

General VASP Regulation: The Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) became effective upon its gazetting in October 2022. This is the effective date for VASPs to be considered reporting entities under Zimbabwe's AML/CFT framework.

aml 60% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

Essentially, any entity in Zimbabwe that performs these services professionally and for financial gain is considered a VASP and falls under the purview of the AML/CFT Act.

aml 60% confidence

For General AML/CFT: VASPs, as regulated financial institutions, are generally required to have internal systems and controls for:

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators are covered as VASPs under Zimbabwe's AML framework (2022 Act) and a comprehensive licensing regime is expected from RBZ, but no dedicated custody or qualified-custodian rules exist yet; operators must comply with AML obligations (KYC, STRs, CDD, AML officer) and likely local incorporation, and may test via the RBZ Fintech Sandbox in the interim.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?