Custodial wallet / SaaS in Congo
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Congo without local incorporation, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Safekeeping and/or administration of virtual assets (including custodial wallets) is a regulated VASP activity under Instruction n°001/GRT/2022 (cg.aml.safekeeping-andor-administration-of-virtual).
- Customer identification and verification using reliable, independent source documents (cg.aml.identification-and-verification, cg.aml.identify-the-customer-natural-or).
- For legal-person clients: identify ownership/control structure and beneficial owners (cg.aml.for-legal-persons-understand-the).
- Ongoing transaction monitoring to ensure consistency with customer and risk profile (cg.aml.ongoing-due-diligence, cg.aml.conduct-ongoing-monitoring-of-the).
- Enhanced Due Diligence for PEPs, cross-border relationships, complex/large transactions, high-risk countries (cg.aml.enhanced-due-diligence-edd, cg.aml.apply-edd-measures-for-higher-risk).
- Report suspicious transactions immediately to the national FIU; prohibition on tipping-off (cg.aml.reporting-obligation-immediately-report-to, cg.aml.no-tipping-off-vasps-and-their).
- Maintain CDD records and transaction records for at least 5 years after business relationship ends or transaction date (cg.aml.customer-records-maintain-all-records, cg.aml.transaction-records-maintain-records-of, cg.aml.availability-records-must-be-sufficient).
- Records must permit reconstruction of individual transactions and be promptly available to competent authorities (cg.aml.availability-records-must-be-sufficient).
- The regional AML framework (Regulation No. 01/18/CEMAC/UMAC/CM of 21 December 2018) applies to CEMAC members including Congo (cg.aml.regulation-no-0118cemacumaccm-of-21).
Key Restrictions
- BEAC Circular N° 001/GR/2022 (Dec 21, 2022) prohibits ALL financial institutions from engaging in, facilitating, or being exposed to cryptocurrencies — this includes holding, buying/selling, offering services, facilitating transactions, and opening accounts for crypto service providers (cg.licensing.circular-n-001gr2022-of-beac, cg.licensing.content-this-circular-explicitly-prohibits, cg.licensing.holding-buying-or-selling-cryptocurrencies, cg.licensing.offering-services-related-to-cryptocurrencies, cg.licensing.facilitating-cryptocurrency-transactions-for-clients, cg.licensing.opening-accounts-for-cryptocurrency-service).
- Any custodial wallet/SaaS operator would need a banking partner to handle fiat on/off-ramps — BEAC's ban on banks dealing with crypto effectively cuts off access to the formal financial system (cg.licensing.banks-and-other-financial-institutions, cg.licensing.it-is-extremely-difficult-and).
- No licensed or regulated crypto operators can legally operate within the formal financial system in Congo or any CEMAC country (cg.licensing.no-licensed-or-regulated-crypto).
- While Instruction n°001/GRT/2022 technically creates a VASP licensing/registration framework, the BEAC's de facto ban on financial institution involvement creates an operational contradiction — a licensee may exist on paper but cannot obtain banking services (cg.licensing.regulatory-approach-highly-restrictive-de, cg.aml.instruction-n001grt2022-relative-la-prvention).
- A draft law approving exchange between virtual assets and fiat was passed by the Lower Chamber on May 5, but BEAC's circular still governs the financial system — regulatory landscape is in flux (cg.aml.exchange-between-virtual-assets-and).
Key Risks
- Severe enforcement risk: BEAC circular is a formal prohibition with force on all financial institutions; operating without banking access is practically impossible for a custodial wallet requiring fiat rails (cg.licensing.financial-institutions-are-explicitly-prohibited).
- Regulatory contradiction between the VASP AML instruction (which implies legal VASP activity) and the BEAC circular (which bans crypto facilitation by financial institutions) creates legal uncertainty (cg.licensing.content-this-circular-explicitly-prohibits vs cg.aml.instruction-n001grt2022-relative-la-prvention).
- Any platform operating in Congo would be doing so illicitly and without regulatory oversight, exposing users to fraud and scams (cg.licensing.any-platforms-claiming-to-operate).
- No consumer protection for individuals engaging in crypto activities in the jurisdiction (cg.licensing.there-is-no-consumer-protection).
- If the draft law permitting fiat-to-virtual-asset exchange passes, the landscape could shift, but currently the ban is in effect.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The prohibition applicable in the Republic of the Congo is Décision COBAC D-2022/071 du 6 mai 2022, issued by the Commission Bancaire de l'Afrique Centrale and not by BEAC; it bars COBAC-supervised institutions — credit institutions, microfinance establishments and payment institutions — from acquiring, holding, transferring, converting or booking crypto-assets, and requires them to detect such operations and report them to COBAC and BEAC, while leaving private holding of crypto by the public lawful and leaving the COSUMAF PSAN licensing regime in force.
No BEAC circular of 21 December 2022 bans crypto-assets; the cited PDF at beac.int returns HTTP 404, beac.int indexes no crypto content, and the real CEMAC measure is Décision COBAC D-2022/071 du 6 mai 2022 restricting COBAC-supervised institutions.
The prohibition binding financial institutions in the Republic of the Congo comes from Décision COBAC D-2022/071 du 6 mai 2022, which forbids COBAC-supervised establishments from acquiring, holding, transferring, converting or booking crypto-assets and obliges them to detect and report such operations to COBAC and BEAC; no BEAC circular of December 2022 exists.
Holding, buying, or selling cryptocurrencies.
Offering services related to cryptocurrencies.
Facilitating cryptocurrency transactions for clients.
Opening accounts for cryptocurrency service providers.
Décision COBAC D-2022/071 du 6 mai 2022 forbids credit institutions, microfinance establishments and payment institutions supervised by COBAC in the Republic of the Congo from acquiring, holding, transferring, converting or booking crypto-assets, and requires them to detect crypto-related operations and report them to COBAC and BEAC.
It is extremely difficult and risky for individuals to convert fiat currency into crypto or vice-versa through legitimate channels.
A community licensing route for crypto exchanges exists in the Republic of the Congo: Règlement n° 01/22/CEMAC/UMAC/CM/COSUMAF du 21 juillet 2022 and the Règlement Général COSUMAF du 23 mai 2023 require COSUMAF agrément as prestataire de services sur actifs numériques, covering custody, buy-sell against legal tender, platform operation, reception-transmission of orders, portfolio management, advice and placement, although COSUMAF has granted no PSAN agrément to date.
COSUMAF is the designated competent authority for virtual-asset service providers in the Republic of the Congo and may grant PSAN agrément under the Règlement Général du 23 mai 2023, so an exchange platform can hold a lawful community licence, and articles 91 to 93 of that règlement place virtual-asset risks inside COSUMAF's risk-based AML/CFT supervision.
There is no consumer protection for individuals engaged in crypto trading.
No Instruction n° 001/GRT/2022 exists; BEAC numbers its instructions n° 00X/GR/YYYY and has issued no virtual-asset instrument. Virtual-asset obligations in the CEMAC zone, including the Republic of the Congo, rest on Décision COBAC D-2022/071 du 6 mai 2022, Règlement n° 01/22/CEMAC/UMAC/CM/COSUMAF du 21 juillet 2022, the Règlement Général de la COSUMAF du 23 mai 2023 and Règlement n° 02/24/CEMAC/UMAC/CM du 20 décembre 2024, whose article 6(e) makes virtual-asset service providers assujettis.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Evidence fact cg.aml.identification-and-verification not found (may have been renamed).
Identify the customer (natural or legal person) and verify their identity using reliable, independent source documents, data, or information.
For legal persons: understand the ownership and control structure, and identify and verify the identity of beneficial owners.
Evidence fact cg.aml.ongoing-due-diligence not found (may have been renamed).
Conduct ongoing monitoring of the business relationship and transactions undertaken throughout the course of that relationship to ensure that transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Evidence fact cg.aml.enhanced-due-diligence-edd not found (may have been renamed).
Apply EDD measures for higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), cross-border correspondent relationships, complex or unusually large transactions, high-risk countries). This includes obtaining additional information on the customer, beneficial owner, source of funds/wealth, and enhanced ongoing monitoring.
Reporting Obligation: Immediately report to the national Financial Intelligence Unit (FIU) any suspicious transactions, including attempted transactions, where they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorist financing, regardless of the amount.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that a suspicious transaction report has been or will be submitted.
Article 39 of Règlement n° 02/24/CEMAC/UMAC/CM du 20 décembre 2024, directly applicable in the Republic of the Congo, requires assujettis including virtual-asset service providers to keep identification, account and transaction records for a minimum of ten years after the account is closed or the business relationship ends, not five years.
Article 39 of Règlement n° 02/24/CEMAC/UMAC/CM du 20 décembre 2024, directly applicable in the Republic of the Congo, requires assujettis including virtual-asset service providers to keep identification, account and transaction records for a minimum of ten years after the account is closed or the business relationship ends, not five years.
Availability: Records must be sufficient to permit the reconstruction of individual transactions and to provide evidence for prosecution of criminal activity. They must be made available promptly to the competent authorities upon request.
The CEMAC AML/CFT instrument binding the Republic of the Congo is Règlement n° 02/24/CEMAC/UMAC/CM du 20 décembre 2024, which replaced Règlement n° 01/CEMAC/UMAC/CM du 11 avril 2016; no Règlement n° 01/18/CEMAC/UMAC/CM exists, and the 21 December 2018 CEMAC instruments are Règlement n° 02/18/CEMAC/UMAC/CM on exchange control and Règlement n° 04/18/CEMAC/UMAC/COBAC on payment services and electronic money. CEMAC règlements are directly applicable in Congo without national transposition.
The Republic of the Congo has adopted no national virtual-asset statute; exchange between virtual assets and legal tender is governed regionally, requiring a COSUMAF agrément as PSAN under the Règlement Général de la COSUMAF du 23 mai 2023 and prior agrément under article 42 of Règlement n° 02/24/CEMAC/UMAC/CM du 20 décembre 2024, while Décision COBAC D-2022/071 du 6 mai 2022 bars COBAC-supervised institutions from handling crypto-assets.
Décision COBAC D-2022/071 du 6 mai 2022 bars COBAC-supervised institutions in the Republic of the Congo from every crypto-asset operation and obliges them to detect and report crypto-related flows to COBAC and BEAC, which closes banking relationships with crypto exchange platforms as a consequence of the general prohibition rather than through a separate account-opening clause.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet/SaaS operator is theoretically captured by the CEMAC VASP AML/CFT instruction (which would require licensing and AML compliance), but in practice the BEAC's December 2022 circular prohibits all financial institutions from facilitating crypto, cutting off banking access and making a lawful, banked operation infeasible in the Republic of the Congo.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?