Custodial wallet / SaaS in Democratic Republic of the Congo
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Democratic Republic of the Congo with a local entity, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- AML/CFT obligations under Law No. 04/016 of July 19, 2004 (as amended) apply to any entity processing transactions (likely including custodial wallet providers), requiring KYC procedures, transaction monitoring, and suspicious transaction reporting.
- Suspicious Transaction Reports must be filed with the Cellule Nationale de Renseignements Financiers (CENAREF), the DRC's financial intelligence unit.
- FATF international best practices, including robust KYC and travel-rule considerations, are recommended even though not codified in crypto-specific regulation.
- The AML/KYC obligations under Law No. 04/016 apply to financial institutions and DNFBPs; a custodial wallet provider processing fiat or facilitating financial transactions could be captured.
Key Restrictions
- No specific crypto custody framework exists — the activity operates in a legal grey area with no dedicated license or qualified-custodian status.
- The BCC has publicly warned against cryptocurrency use, stating cryptocurrencies are not legal tender and are unregulated; this creates operational and reputational risk.
- No segregation, insurance, cold-storage, or proof-of-reserves rules exist for crypto custodians; client asset protection is legally undefined.
- If the SaaS provider handles fiat-crypto conversions or fiat payments, it may be deemed a payment service under Law No. 20/017, triggering BCC authorization requirements and capital requirements.
- General business registration (Ministry of Commerce, tax ID, GUCE registration, local office, local directors) is mandatory for any entity operating in the DRC.
Key Risks
- High regulatory ambiguity — the BCC's 2021 public warning actively discourages cryptocurrency use, and enforcement against unregulated financial activities is a material risk.
- No legal recognition or protection for custodial relationships — client funds and digital assets have no defined legal status or segregation framework.
- Tax exposure — a 15-15% crypto tax exists (noted in facts), but its application to custodial services is unclear.
- Potential retroactive application of future regulation — the BCC has indicated ongoing study of digital financial innovations, which could lead to sudden regulatory changes.
- White-label clients face AML ambiguity — it is unclear where AML obligations fall between the SaaS custody provider and the white-label client under Law No. 04/016.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Democratic Republic of the Congo licenses no cryptocurrency custodian because Article 22 bis of Loi n° 25/048 du 1er juillet 2025, amending Loi n° 22/068 du 27 décembre 2022, prohibits virtual-asset activities and virtual-asset service providers outright, so no custody licence category can arise under BCC-supervised financial-sector law.
Reference: The general position of the BCC can be found in various communiques and statements. For instance, the Communiqué of the Banque Centrale du Congo (BCC) dated December 14, 2021, warned the public against the use of cryptocurrencies, highlighting their lack of legal framework and associated risks. While a direct, stable URL to the specific communiqué can be elusive on the BCC's dynamic site, its content is widely reported and reflects the official position.
No Democratic Republic of the Congo instrument imposes a 15% or any other crypto-asset tax, and none imposes insurance or bonding requirements on cryptocurrency custodians; Article 22 bis of Loi n° 25/048 du 1er juillet 2025 instead prohibits virtual-asset activities and virtual-asset service providers throughout the DRC.
Evidence fact cd.custody.cold-storage-mandates not found (may have been renamed).
Congolese law defines no qualified custodian for digital assets, and Article 22 bis of Loi n° 25/048 du 1er juillet 2025 forecloses the question by prohibiting virtual-asset activities and virtual-asset service providers in the Democratic Republic of the Congo.
Virtual-asset activity in the Democratic Republic of the Congo is prohibited, not unregulated: article 22 bis of Loi n° 25/048 du 1er juillet 2025, amending Loi n° 22/068 du 27 décembre 2022, bans virtual-asset activities and virtual-asset service providers outright, so operating a cryptocurrency exchange or a crypto custody business in the country is unlawful rather than merely unlicensed.
General Business Registration: Any entity operating in the DRC, regardless of its specific activity, would need to comply with general business registration requirements (e.g., registering with the Ministry of Commerce, obtaining a tax ID, etc.), but these are not specific to financial services or virtual assets.
Crypto-only exchanges and custody businesses have no registration or licensing route in the Democratic Republic of the Congo because article 22 bis of Loi n° 25/048 du 1er juillet 2025 prohibits virtual-asset activities and virtual-asset service providers; the Banque Centrale du Congo is the authority competent to detect and sanction providers operating in breach of that prohibition.
Local Presence: General business laws would require any company operating in the DRC to have a registered local presence (e.g., a local office, local directors, registration with the relevant commercial registries).
The general AML/CFT framework of the Democratic Republic of the Congo is Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016 du 19 juillet 2004, as amended by Loi n° 25/048 du 1er juillet 2025; the amending law is crypto-specific, since its article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the country.
The Cellule Nationale des Renseignements Financiers (CENAREF) is the Congolese financial intelligence unit responsible for receiving, analysing and transmitting suspicious transaction reports on money laundering, terrorist financing and proliferation financing, and it is the central and sole structure for that purpose under Loi n° 22/068 du 27 décembre 2022.
Even in the absence of specific crypto regulations, any legitimate financial operation (or one seeking future legitimacy) should adhere to international AML/CFT best practices (e.g., FATF recommendations), including robust KYC procedures, transaction monitoring, and suspicious activity reporting. Failure to do so could lead to future legal issues or blacklisting.
Loi n° 04/016 du 19 juillet 2004 was replaced by Loi n° 22/068 du 27 décembre 2022 and amended by Loi n° 25/048 du 1er juillet 2025, which is the operative Congolese AML/CFT/CPF statute; instead of extending FATF virtual-asset obligations to VASPs, its Article 22 bis prohibits virtual-asset activities and virtual-asset service providers in the DRC.
The Conseil des ministres adopted the bill amending Loi n° 04/016 du 19 juillet 2004 on 24 December 2021; it was enacted as Loi n° 22/068 du 27 décembre 2022, which replaced Loi n° 04/016, and was itself amended by Loi n° 25/048 du 1er juillet 2025.
Regulator Name: Banque Centrale du Congo (BCC)
Entity Targeted: General Public, financial institutions (indirectly). Violation Type: N/A (This was a public warning, not an enforcement action against a specific violator.) The warning addressed the risks of using unregulated financial instruments like cryptocurrencies and clarified that they are not legal tender in the DRC. Penalty Amount: N/A.
Outcome: To inform the public of the risks and to clarify that cryptocurrencies are not recognized as legal tender, aiming to deter their use within the formal financial system. The outcome is public awareness rather than a specific legal penalty.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS services exist in a legal grey area with no specific crypto custody framework; a local entity is required for general business registration, and AML/CFT obligations under Law No. 04/016 apply, but the BCC has publicly warned against cryptocurrency activity, creating significant operational risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?