Custodial wallet / SaaS in Cameroon
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Cameroon with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- KYC: Identify and verify customers (natural persons: full name, date of birth, nationality, address, ID number, source of funds/wealth) before establishing a relationship or for transactions above ~EUR 1,000 threshold.
- Beneficial Ownership: Identify and verify natural persons who own or control ≥25% of legal entity customers.
- Risk Assessment: Understand the purpose and intended nature of the business relationship; assess customer risk profile.
- Ongoing Monitoring: Continuously monitor transactions against customer knowledge and risk profile; update customer documentation regularly.
- Enhanced Due Diligence (EDD): Required for high-risk situations (PEPs, high-risk jurisdictions per FATF, complex/unusually large transactions, non-face-to-face customers).
- Suspicious Transaction Reporting: File STRs with ANIF (Cameroon's FIU) 'without delay' for any transaction or attempted transaction suspected of ML/TF, regardless of amount.
- Record-Keeping: Maintain all KYC, transaction, and reporting records per CEMAC Regulation No. 02/CEMAC/UMAC/CM/22 and Law No. 2016/007.
- The SaaS provider bears primary AML obligations as the VASP; white-label clients may have shared obligations depending on contractual allocation, but the licensed entity remains responsible before regulators.
Key Restrictions
- CEMAC-wide BEAC ban (May 2022) prohibits all crypto-asset activities by regulated financial institutions; crypto is not recognized as legal tender.
- No specific license exists for custodial wallet / custody providers — the framework is effectively prohibition for regulated entities without a regime for independent crypto businesses.
- Local corporate entity and physical presence in Cameroon are mandatory, as this extends from general requirements for regulated financial activities.
- Access to banking services is extremely challenging or impossible, as banks are prohibited from dealing with crypto-related businesses.
- White-label arrangement: The custody-as-a-service provider must itself be the licensed/regulated entity; the model cannot operate through a mere technology/service contract without the provider being the obligated VASP under CEMAC AML rules.
Key Risks
- Regulatory illegality risk: The May 2022 CEMAC-wide BEAC ban on crypto-asset activities is still formally in force; operating any custodial wallet service carries risk of enforcement despite observed market adoption.
- Enforcement precedent: The GIT (Global Investment Trading) Ponzi scheme case shows that Cameroonian authorities actively prosecute crypto-adjacent unlicensed financial activities with arrests, asset seizures, and criminal charges.
- No banking access: Without a legally recognized framework for VASPs, custodial wallet providers cannot obtain or maintain bank accounts, creating a structural operational barrier.
- Regulatory ambiguity: The gap between the de jure ban and de facto market activity creates uncertainty; a future licensing framework may impose retroactive compliance obligations.
- AML liability concentration: Under CEMAC regulations, the VASP (custodial wallet provider) bears direct AML obligations; white-label clients create additional KYC/onboarding risk for which the provider remains accountable.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Second half is correct: COBAC-supervised institutions (banks, microfinance, payment institutions, bureaux de change) are prohibited by Decision COBAC D-2022/071 from holding, exchanging or converting crypto-assets, so regulated-sector custody is indeed impossible. First half is wrong as of 2026: 'conservation d'actifs numeriques pour le compte de tiers' is an enumerated PSAN service under the COSUMAF Reglement general du 23 mai 2023 and requires COSUMAF agrement, and the CEMAC VASP definition in Reglement n° 02/24/CEMAC/UMAC/CM expressly covers safekeeping of virtual assets.
A VASP/PSAN authorisation regime does exist and covers Cameroon, at CEMAC level. (i) The COSUMAF Reglement general du 23 mai 2023 (in force 24 May 2023) creates the prestataire de services sur actifs numeriques status, defines jetons numeriques functionally (art. 336: 'tout bien incorporel representant, sous forme numerique, un ou plusieurs droits'), reserves digital-token placement to PSAN, and requires COSUMAF agrement for buying/selling digital assets against legal currency, third-party custody, operating a trading platform, order reception/transmission, portfolio management, advice and placement. (ii) Reglement n° 02/24/CEMAC/UMAC/CM du 20 decembre 2024 defines 'actifs virtuels' and 'prestataires de services d'actifs virtuels', makes them assujettis, and at art. 42(1) provides that no one may carry on VASP activity professionally without prior approval or authorisation from the competent authority (art. 39: 10-year record retention; art. 42(5)(a): originator/beneficiary travel-rule information). The record's practical conclusion is nevertheless close to reality: no implementing instructions have been published, no PSAN agrement is publicly known, and COBAC D-2022/071 continues to prohibit supervised institutions from any crypto dealing. The accurate framing is 'a regime exists in law but is not operational', not 'no regime exists'.
Entities seeking to operate in the crypto space would likely face a lack of legal recognition and significant operational hurdles, particularly concerning banking relationships.
Local Presence: For most regulated financial activities in Cameroon, a local corporate entity and physical presence are mandatory. This would likely extend to any future crypto licensing.
Evidence fact cm.licensing.beac-communiqu-on-cryptocurrencies-december not found (may have been renamed).
Lack of Legal Tender Status: Cryptocurrencies are not recognized as legal tender within the CEMAC zone.
The substantive claim is right but the instrument identity is wrong. There is no "Regulation No. 02/CEMAC/UMAC/CM/22" and no 2022 CEMAC AML regulation. The instrument is Reglement n° 02/24/CEMAC/UMAC/CM, signed at Libreville on 20 December 2024 (CEMAC/UMAC Ministerial Committee, extraordinary session), effective on signature and abrogating all contrary provisions of Reglement n° 01/CEMAC/UMAC/CM du 11 avril 2016. It does define virtual assets - art. 2(72): "Digital representation of a value that can be digitally traded, transferred or used for payment or investment purposes... does not include digital representations of fiat currencies, securities and other financial assets already covered by specific regulatory provisions" - and defines prestataires de services d'actifs virtuels; art. 6(e) lists "virtual or digital asset service providers" among the assujettis, so VASPs carry the same AML/CFT obligations as financial institutions. It is a FATF-aligned revision (approved by GABAC Plenary Resolution No. 10 of 28 September 2024). The 2022 CEMAC instrument that touches digital assets is a different one: Reglement n° 01/22/CEMAC/UMAC/CM/COSUMAF du 21 juillet 2022 on the regional financial market.
Loi n° 2016/007 du 12 juillet 2016 is Cameroon's Code Penal, not an AML/CFT law, and it did not create ANIF. Cameroon has no standalone national AML/CFT statute: the framework is the directly applicable CEMAC regulation - today Reglement n° 02/24/CEMAC/UMAC/CM du 20 decembre 2024, previously Reglement n° 01/CEMAC/UMAC/CM du 11 avril 2016 and before that Reglement n° 01/03-CEMAC-UMAC-CM du 4 avril 2003 - supplemented for supervised financial institutions by Reglement COBAC R-2023/01 on LBC/FT diligences (in force 1 July 2024). ANIF was created by Decret n° 2005/187 du 31 mai 2005 (organisation and functioning of the Agence Nationale d'Investigation Financiere), operational since January 2006 and attached to the Ministere des Finances; its regional legal basis is art. 25 of Reglement n° 01/03-CEMAC-UMAC-CM, which instituted an ANIF in every Central African state.
Evidence fact cm.aml.identification-and-verification-of-customers not found (may have been renamed).
Identifying the natural person(s) who ultimately own or control the customer (typically 25% ownership or more, or effective control).
Assessing the risk profile of the customer based on this information.
Continuously monitoring business relationships and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and their risk profile, including, where necessary, the source of funds.
Evidence fact cm.aml.applying-edd-measures-for-high-risk not found (may have been renamed).
Reporting Obligation: VASPs must report any transaction (or attempted transaction) that they suspect, or have reasonable grounds to suspect, is related to money laundering or terrorist financing, regardless of the amount.
Reporting Body: Reports must be made to the Agence Nationale d'Investigation Financière (ANIF), Cameroon's FIU.
Timing: Reports must be submitted "without delay" once suspicion is formed.
Il n'existe aucune interdiction générale des crypto-actifs en zone CEMAC et la BEAC n'a émis aucun texte d'interdiction. La mesure de 2022 est la Décision COBAC D-2022/071 du 6 mai 2022, prise par la COBAC (superviseur bancaire), qui interdit aux seuls établissements assujettis à la COBAC de détenir, utiliser, échanger ou convertir des cryptoactifs pour compte propre ou pour compte de clients, de les comptabiliser au bilan, et leur impose un dispositif de détection et une remontée d'information à la COBAC et à la BEAC. Les personnes physiques et les entreprises non assujetties ne sont pas visées. À l'inverse, le Règlement n° 01/22/CEMAC/UMAC/CM du 21 juillet 2022 (en vigueur le 1er août 2022) admet les 'actifs numériques' et 'jetons numériques' sur le marché financier d'Afrique centrale et soumet les prestataires de services sur actifs numériques à l'agrément de la COSUMAF.
Enforcement against crypto-related Ponzi schemes/fraudulent operations.
Date: May 6, 2022
Aucune prohibition générale des activités liées aux crypto-actifs n'a été établie en zone CEMAC. L'exploitation d'une plateforme d'échange n'est pas 'hautement illégale' : elle constitue au contraire un service sur actifs numériques soumis à l'agrément de la COSUMAF depuis le Règlement n° 01/22/CEMAC/UMAC/CM du 21 juillet 2022 et le Règlement Général COSUMAF du 23 mai 2023. Le minage n'est visé par aucun texte CEMAC. Seuls les établissements assujettis à la COBAC sont soumis à une interdiction, en vertu de la Décision COBAC D-2022/071.
Le fondateur de Global Investment Trading (GIT), promoteur de la plateforme Liyeplimal, est Émile Parfait SIMB — et non 'Emile Parfait Mbori', qui n'existe pas. Le jeton était le Limo / Limo dollar (commercialisé aussi sous le nom LimoCoin) — et non un 'Mofor Coin'. Les faits reprochés sont l'escroquerie et la collecte illégale de fonds : le MINFI avait mis en demeure GIT, parmi 17 entités, de cesser ses collectes illégales de fonds (communiqué d'octobre 2020) et la COSUMAF avait publié des mises en garde en octobre 2020 et juin 2021 pour exercice sans agrément.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS is not expressly prohibited for non-regulated entities but faces a de facto ban on banking access, no licensing framework, and a CEMAC-wide BEAC directive prohibiting crypto activities by financial institutions, with the only viable path being a local entity holding a future VASP license under developing CEMAC AML rules.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?