← Regulations / Democratic Republic of the Congo / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Democratic Republic of the Congo

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Democratic Republic of the Congo with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • AML/CFT obligations under Law No. 04/016 of July 19, 2004 (as amended) apply to any entity processing transactions (likely including custodial wallet providers), requiring KYC procedures, transaction monitoring, and suspicious transaction reporting.
  • Suspicious Transaction Reports must be filed with the Cellule Nationale de Renseignements Financiers (CENAREF), the DRC's financial intelligence unit.
  • FATF international best practices, including robust KYC and travel-rule considerations, are recommended even though not codified in crypto-specific regulation.
  • The AML/KYC obligations under Law No. 04/016 apply to financial institutions and DNFBPs; a custodial wallet provider processing fiat or facilitating financial transactions could be captured.

Key Restrictions

  • No specific crypto custody framework exists — the activity operates in a legal grey area with no dedicated license or qualified-custodian status.
  • The BCC has publicly warned against cryptocurrency use, stating cryptocurrencies are not legal tender and are unregulated; this creates operational and reputational risk.
  • No segregation, insurance, cold-storage, or proof-of-reserves rules exist for crypto custodians; client asset protection is legally undefined.
  • If the SaaS provider handles fiat-crypto conversions or fiat payments, it may be deemed a payment service under Law No. 20/017, triggering BCC authorization requirements and capital requirements.
  • General business registration (Ministry of Commerce, tax ID, GUCE registration, local office, local directors) is mandatory for any entity operating in the DRC.

Key Risks

  • High regulatory ambiguity — the BCC's 2021 public warning actively discourages cryptocurrency use, and enforcement against unregulated financial activities is a material risk.
  • No legal recognition or protection for custodial relationships — client funds and digital assets have no defined legal status or segregation framework.
  • Tax exposure — a 15-15% crypto tax exists (noted in facts), but its application to custodial services is unclear.
  • Potential retroactive application of future regulation — the BCC has indicated ongoing study of digital financial innovations, which could lead to sudden regulatory changes.
  • White-label clients face AML ambiguity — it is unclear where AML obligations fall between the SaaS custody provider and the white-label client under Law No. 04/016.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 80% confidence

The Democratic Republic of the Congo licenses no cryptocurrency custodian because Article 22 bis of Loi n° 25/048 du 1er juillet 2025, amending Loi n° 22/068 du 27 décembre 2022, prohibits virtual-asset activities and virtual-asset service providers outright, so no custody licence category can arise under BCC-supervised financial-sector law.

custody 80% confidence

Reference: The general position of the BCC can be found in various communiques and statements. For instance, the Communiqué of the Banque Centrale du Congo (BCC) dated December 14, 2021, warned the public against the use of cryptocurrencies, highlighting their lack of legal framework and associated risks. While a direct, stable URL to the specific communiqué can be elusive on the BCC's dynamic site, its content is widely reported and reflects the official position.

custody 80% confidence

No Democratic Republic of the Congo instrument imposes a 15% or any other crypto-asset tax, and none imposes insurance or bonding requirements on cryptocurrency custodians; Article 22 bis of Loi n° 25/048 du 1er juillet 2025 instead prohibits virtual-asset activities and virtual-asset service providers throughout the DRC.

Evidence fact cd.custody.cold-storage-mandates not found (may have been renamed).

custody 80% confidence

Congolese law defines no qualified custodian for digital assets, and Article 22 bis of Loi n° 25/048 du 1er juillet 2025 forecloses the question by prohibiting virtual-asset activities and virtual-asset service providers in the Democratic Republic of the Congo.

licensing 80% confidence

Virtual-asset activity in the Democratic Republic of the Congo is prohibited, not unregulated: article 22 bis of Loi n° 25/048 du 1er juillet 2025, amending Loi n° 22/068 du 27 décembre 2022, bans virtual-asset activities and virtual-asset service providers outright, so operating a cryptocurrency exchange or a crypto custody business in the country is unlawful rather than merely unlicensed.

licensing 80% confidence

General Business Registration: Any entity operating in the DRC, regardless of its specific activity, would need to comply with general business registration requirements (e.g., registering with the Ministry of Commerce, obtaining a tax ID, etc.), but these are not specific to financial services or virtual assets.

licensing 80% confidence

Crypto-only exchanges and custody businesses have no registration or licensing route in the Democratic Republic of the Congo because article 22 bis of Loi n° 25/048 du 1er juillet 2025 prohibits virtual-asset activities and virtual-asset service providers; the Banque Centrale du Congo is the authority competent to detect and sanction providers operating in breach of that prohibition.

licensing 80% confidence

Local Presence: General business laws would require any company operating in the DRC to have a registered local presence (e.g., a local office, local directors, registration with the relevant commercial registries).

licensing 80% confidence

The general AML/CFT framework of the Democratic Republic of the Congo is Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016 du 19 juillet 2004, as amended by Loi n° 25/048 du 1er juillet 2025; the amending law is crypto-specific, since its article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the country.

licensing 80% confidence

The Cellule Nationale des Renseignements Financiers (CENAREF) is the Congolese financial intelligence unit responsible for receiving, analysing and transmitting suspicious transaction reports on money laundering, terrorist financing and proliferation financing, and it is the central and sole structure for that purpose under Loi n° 22/068 du 27 décembre 2022.

licensing 80% confidence

Even in the absence of specific crypto regulations, any legitimate financial operation (or one seeking future legitimacy) should adhere to international AML/CFT best practices (e.g., FATF recommendations), including robust KYC procedures, transaction monitoring, and suspicious activity reporting. Failure to do so could lead to future legal issues or blacklisting.

custody 80% confidence

Loi n° 04/016 du 19 juillet 2004 was replaced by Loi n° 22/068 du 27 décembre 2022 and amended by Loi n° 25/048 du 1er juillet 2025, which is the operative Congolese AML/CFT/CPF statute; instead of extending FATF virtual-asset obligations to VASPs, its Article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the DRC.

custody 80% confidence

The Conseil des ministres adopted the bill amending Loi n° 04/016 du 19 juillet 2004 on 24 December 2021; it was enacted as Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016, and was itself amended by Loi n° 25/048 du 1er juillet 2025.

enforcement 90% confidence

Entity Targeted: General Public, financial institutions (indirectly). Violation Type: N/A (This was a public warning, not an enforcement action against a specific violator.) The warning addressed the risks of using unregulated financial instruments like cryptocurrencies and clarified that they are not legal tender in the DRC. Penalty Amount: N/A.

enforcement 90% confidence

Outcome: To inform the public of the risks and to clarify that cryptocurrencies are not recognized as legal tender, aiming to deter their use within the formal financial system. The outcome is public awareness rather than a specific legal penalty.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS services exist in a legal grey area with no specific crypto custody framework; a local entity is required for general business registration, and AML/CFT obligations under Law No. 04/016 apply, but the BCC has publicly warned against cryptocurrency activity, creating significant operational risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?