Remote VASP serving residents in Zimbabwe
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Zimbabwe with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs are designated as 'financial institutions' under the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) and must comply with AML/CFT obligations as reporting entities.
- Customer Due Diligence (CDD/KYC) procedures for all users.
- Ongoing monitoring of transactions.
- Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FIU).
- Appointment of a dedicated AML Compliance Officer.
- Robust internal AML/CFT policies and controls.
- Record-keeping of transactions and customer data.
- Risk-based assessment and management.
- Currency transaction reporting (CTR) and suspicious transaction reporting (STR) under existing thresholds per the Money Laundering and Proceeds of Crime Act.
- Travel Rule not yet adopted — no specific threshold or technical implementation requirements for VA transfer information sharing currently.
Key Restrictions
- Local incorporation is highly probable — licensed entities will need to be domiciled in Zimbabwe.
- Physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer) may be required.
- No specific custodial license framework yet — only possible through the RBZ National Fintech Sandbox for testing.
- No specific segregation, insurance, bonding, or cold storage mandates exist yet for custodial services.
- No Travel Rule specifics adopted — FATF Mutual Evaluation expected to address compliance gaps.
Key Risks
- Enforcement risk for unlicensed remote VASPs is high — the AML Act designates VASPs as financial institutions and requires licensing; operating without a license likely constitutes illegal financial activity.
- Regulatory framework is still under development (sandbox phase) — significant ambiguity on final licensing criteria, capital thresholds, and operational requirements.
- FATF mutual evaluation will likely push Zimbabwe to tighten enforcement and adopt Travel Rule, creating compliance catch-up risk for early movers.
- No clear grandfathering or transitional pathway for existing remote operators servicing Zimbabwe residents.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Virtual Asset Service Provider (VASP) License: This is the most common umbrella term. It would likely cover:
Licensing: This typically involves a comprehensive application, detailed due diligence, meeting stringent capital, operational, and compliance requirements, and ongoing supervision. Zimbabwe is expected to adopt a full licensing regime for commercial VA operations to ensure financial stability, consumer protection, and AML/CFT compliance.
Likely to be prescribed minimum capital thresholds, which may vary depending on the type and scale of VA services offered, reflecting the inherent risks. This ensures financial stability and ability to absorb operational shocks.
It is highly probable that licensed entities will need to be domiciled in Zimbabwe (i.e., incorporated locally).
Requirements may include a physical office, local directors, and locally-based key personnel (e.g., CEO, Compliance Officer).
Partially (Framework for VASPs): Zimbabwe, as an FATF member, is committed to implementing FATF Recommendations. In October 2022, Zimbabwe promulgated the Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022), which for the first time designated VASPs as "financial institutions" for AML/CFT purposes. This means VASPs are now subject to general AML/CFT obligations such as customer due diligence (CDD), record-keeping, and suspicious transaction reporting (STR).
General VASP Regulation: The Money Laundering and Proceeds of Crime Amendment Act (No. 6 of 2022) became effective upon its gazetting in October 2022. This is the effective date for VASPs to be considered reporting entities under Zimbabwe's AML/CFT framework.
Which VASPs are Covered:
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Essentially, any entity in Zimbabwe that performs these services professionally and for financial gain is considered a VASP and falls under the purview of the AML/CFT Act.
Customer Due Diligence (KYC processes).
Risk-based assessment and management.
Record-keeping of transactions and customer data.
Monitoring transactions for suspicious activities.
Reporting suspicious transactions to the Financial Intelligence Unit (FIU).
Having an appointed AML/CFT Compliance Officer.
For General AML Reporting (as Financial Institutions): VASPs, like other financial institutions, are subject to existing thresholds for currency transaction reporting (CTR) and suspicious transaction reporting (STR) as stipulated by the Money Laundering and Proceeds of Crime Act. These thresholds typically apply to fiat currency transactions but would extend to the fiat equivalent of virtual asset transactions if deemed suspicious or exceeding certain reportable limits in the context of their general AML obligations. The standard FATF Travel Rule threshold for VASP-to-VASP transfers is USD/EUR 1,000, but this is not currently enforced in Zimbabwe.
Not Adopted (Travel Rule Specifics): While VASPs are regulated, the specific requirements of the FATF Travel Rule – mandating the collection and sharing of originator and beneficiary information for virtual asset transfers – have not yet been specifically legislated or enforced. The FATF's Mutual Evaluation Report for Zimbabwe (October 2022) highlighted this as an area needing improvement, stating that measures to implement the Travel Rule were not yet in place.
Travel Rule: There is no effective date for the Travel Rule in Zimbabwe, as the specific legislative and regulatory measures for its implementation are still pending.
For Travel Rule: Since the Travel Rule is not specifically implemented, there are no specific threshold amounts for the collection and transmission of originator and beneficiary information on VA transfers.
For Travel Rule: As the Travel Rule is not specifically implemented, there are no specific technical implementation requirements for the secure sharing of originator and beneficiary information for VA transfers.
Technical Implementation Requirements:
Financial Intelligence Unit (FIU): Responsible for combating money laundering and terrorist financing (AML/CFT). Any future VA framework will heavily rely on FIU guidance for compliance.
AML/KYC (Anti-Money Laundering / Know Your Customer):
This will be a paramount requirement. Virtual asset service providers will be designated as "reporting entities" and will be subject to the provisions of Zimbabwe's Money Laundering and Proceeds of Crime Act (Chapter 9:24) and regulations issued by the Financial Intelligence Unit (FIU).
Requirements will include:
Customer due diligence (CDD) procedures for all users.
Ongoing monitoring of transactions.
Reporting suspicious transactions (STRs) to the FIU.
Appointment of a dedicated AML Compliance Officer.
Robust internal AML/CFT policies and controls.
FATF (Financial Action Task Force) standards, which Zimbabwe is expected to comply with, will heavily influence these requirements.
Reserve Bank of Zimbabwe (RBZ): The central bank, responsible for monetary policy, financial sector stability, and licensing of financial institutions. It is the primary body driving the VA regulatory development.
National Financial Technology Sandbox (2021): This is the most significant development pointing towards future regulation. Launched by the RBZ, the sandbox allows innovative fintech solutions, including those involving digital assets, to be tested in a controlled environment. While not legislation itself, insights gained from the sandbox are expected to inform the development of future laws and regulations.
Fintech Sandbox Participants: Entities participating in the RBZ's National Fintech Sandbox might be allowed to test innovative solutions that could involve elements of custody, but this is an experimental phase and not a full licensing regime.
No Specific Rules: As there are no specific custodial licenses or regulatory frameworks, there are no explicit rules mandating the segregation of client digital assets from a custodian's proprietary assets. Best practices in traditional finance would suggest segregation, but this is not legally mandated for crypto custody in Zimbabwe.
No Specific Requirements: There are no specific insurance or bonding requirements for digital asset custodians.
No Specific Mandates: While cold storage is a widely recognized security best practice for managing digital assets, there are no specific legal mandates or requirements for its use by custodians in Zimbabwe.
No Specific Definition: The term "qualified custodian" and its associated definitions, commonly found in more mature regulatory jurisdictions (like the US under SEC rules), do not exist within Zimbabwe's current regulatory landscape for digital assets.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Zimbabwe residents would need to be locally incorporated, licensed under the forthcoming VASP regime (expected to be a full, capital-intensive licensing process), and comply with AML/CFT obligations under the Money Laundering and Proceeds of Crime Amendment Act (2022), though the framework is still in development and the Travel Rule has not yet been adopted.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?