Custodial wallet / SaaS in Zimbabwe
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Zimbabwe with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs are designated as 'financial institutions' under the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) and must comply as reporting entities.
- Customer Due Diligence (CDD) / KYC procedures for all users.
- Ongoing monitoring of transactions for suspicious activities.
- Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FIU).
- Appointment of a dedicated AML/CFT Compliance Officer.
- Robust internal AML/CFT policies and controls.
- Record-keeping of transactions and customer data.
- Risk-based assessment and management of AML/CTF risks.
- Currency transaction reporting (CTR) thresholds apply as per the Money Laundering and Proceeds of Crime Act.
- FATF Travel Rule has not been specifically implemented — no specific threshold or technical implementation requirements yet.
Key Restrictions
- No specific custodial license or qualified-custodian regime exists — a VASP license covering custody is the expected path.
- No legally mandated segregation of client digital assets; no specific insurance/bonding or cold-storage requirements exist.
- The regulatory framework for VASPs is nascent — operated via the Money Laundering and Proceeds of Crime Amendment Act (2022) and the RBZ National Fintech Sandbox, but no comprehensive digital-asset custody rules have been enacted.
- Local incorporation in Zimbabwe is highly probable (if not required) for licensing.
- Physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer) may be required.
Key Risks
- Regulatory ambiguity: no dedicated custody/qualified-custodian framework exists — reliance on future regulations from RBZ and FIU creates operational uncertainty.
- Enforcement risk: VASPs are already designated as financial institutions under AML law, but the broader licensing and custody-specific rules are not yet in force, creating a gap for operators.
- No segregation or insurance mandates mean client asset protection is purely contractual — high exposure in the event of insolvency or hack.
- Travel Rule not implemented, but FATF mutual evaluation may force rapid adoption, creating retroactive compliance risk.
- The RBZ is studying crypto/CBDC — a future regulatory shift could materially change the operating environment.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Custodial License Requirements:
Segregation of Client Assets Rules:
No Specific Rules: As there are no specific custodial licenses or regulatory frameworks, there are no explicit rules mandating the segregation of client digital assets from a custodian's proprietary assets. Best practices in traditional finance would suggest segregation, but this is not legally mandated for crypto custody in Zimbabwe.
No Specific Requirements: There are no specific insurance or bonding requirements for digital asset custodians.
No Specific Mandates: While cold storage is a widely recognized security best practice for managing digital assets, there are no specific legal mandates or requirements for its use by custodians in Zimbabwe.
No Specific Definition: The term "qualified custodian" and its associated definitions, commonly found in more mature regulatory jurisdictions (like the US under SEC rules), do not exist within Zimbabwe's current regulatory landscape for digital assets.
National Financial Technology Sandbox (2021): This is the most significant development pointing towards future regulation. Launched by the RBZ, the sandbox allows innovative fintech solutions, including those involving digital assets, to be tested in a controlled environment. While not legislation itself, insights gained from the sandbox are expected to inform the development of future laws and regulations.
Regulatory Sandbox: This is anticipated to be a controlled environment where approved entities can test innovative financial products, services, or business models (including those involving VAs) with real customers, but within defined parameters and under the close supervision of the RBZ, for a limited period. Successful participants in the sandbox may then be eligible for full licensing once the broader framework is established.
Virtual Asset Service Provider (VASP) License: This is the most common umbrella term. It would likely cover:
Custody Providers: Entities providing services to safeguard virtual assets or instruments enabling control over virtual assets on behalf of others.
Registration: In some regimes, registration might be a simpler, less rigorous process for lower-risk activities or for certain types of market participants (e.g., basic disclosures).
Licensing: This typically involves a comprehensive application, detailed due diligence, meeting stringent capital, operational, and compliance requirements, and ongoing supervision. Zimbabwe is expected to adopt a full licensing regime for commercial VA operations to ensure financial stability, consumer protection, and AML/CFT compliance.
Likely to be prescribed minimum capital thresholds, which may vary depending on the type and scale of VA services offered, reflecting the inherent risks. This ensures financial stability and ability to absorb operational shocks.
AML/KYC (Anti-Money Laundering / Know Your Customer):
This will be a paramount requirement. Virtual asset service providers will be designated as "reporting entities" and will be subject to the provisions of Zimbabwe's Money Laundering and Proceeds of Crime Act (Chapter 9:24) and regulations issued by the Financial Intelligence Unit (FIU).
It is highly probable that licensed entities will need to be domiciled in Zimbabwe (i.e., incorporated locally).
Requirements may include a physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer).
Partially (Framework for VASPs): Zimbabwe, as an FATF member, is committed to implementing FATF Recommendations. In October 2022, Zimbabwe promulgated the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022), which for the first time designated VASPs as "financial institutions" for AML/CFT purposes. This means VASPs are now subject to general AML/CFT obligations such as customer due diligence (CDD), record-keeping, and suspicious transaction reporting (STR).
Not Adopted (Travel Rule Specifics): While VASPs are regulated, the specific requirements of the FATF Travel Rule – mandating the collection and sharing of originator and beneficiary information for virtual asset transfers – have not yet been specifically legislated or enforced. The FATF's Mutual Evaluation Report for Zimbabwe (October 2022) highlighted this as an area needing improvement, stating that measures to implement the Travel Rule were not yet in place.
General VASP Regulation: The Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) became effective upon its gazetting in October 2022. This is the effective date for VASPs to be considered reporting entities under Zimbabwe's AML/CFT framework.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Essentially, any entity in Zimbabwe that performs these services professionally and for financial gain is considered a VASP and falls under the purview of the AML/CFT Act.
For General AML/CFT: VASPs, as regulated financial institutions, are generally required to have internal systems and controls for:
Customer Due Diligence (KYC processes).
Risk-based assessment and management.
Record-keeping of transactions and customer data.
Monitoring transactions for suspicious activities.
Reporting suspicious transactions to the Financial Intelligence Unit (FIU).
Having an appointed AML/CFT Compliance Officer.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators are covered as VASPs under Zimbabwe's AML framework (2022 Act) and a comprehensive licensing regime is expected from RBZ, but no dedicated custody or qualified-custodian rules exist yet; operators must comply with AML obligations (KYC, STRs, CDD, AML officer) and likely local incorporation, and may test via the RBZ Fintech Sandbox in the interim.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?