Centralized exchange in Rwanda
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Rwanda with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Obtain and verify identity for individuals (name, address, date of birth, nationality, national ID/passport) and legal entities (name, legal form, registration, beneficial owners) per Ministerial Orders N° 001/2022 and N° 002/2022 and Law N° 060/2021.
- Risk-Based Approach: Apply enhanced due diligence (EDD) for PEPs, high-risk jurisdictions, and unusually large transactions; simplified due diligence for lower-risk customers.
- Ongoing Monitoring: Continuously monitor transactions and business relationships; keep customer information up to date.
- Suspicious Transaction Reporting (STRs): Report any suspicious transaction — no minimum threshold — to the Financial Intelligence Centre (FIC) of Rwanda promptly (within 2–5 working days of suspicion). No tipping-off is permitted.
- Record-Keeping: Retain customer identification, transaction, business relationship, and STR records for at least 5 years after the end of the business relationship or transaction date.
- Sanctions Screening: Screen all customers, beneficial owners, and counterparties against UN Security Council sanctions lists. Immediately freeze assets of designated persons and report to FIC without delay.
- Travel Rule: As a VASP handling transfers, obligations analogous to the FATF Recommendation 16 travel rule would apply — collect, transmit, and maintain originator and beneficiary information for virtual asset transfers. (Implied by the AML/CFT framework and Rwanda's FATF membership.)
- OFAC Sanctions Risk: Prudent operators should also screen against OFAC SDN lists and block transactions/ freeze assets of designated persons to mitigate secondary sanctions risk, given use of USD or US-based services.
Key Restrictions
- No comprehensive VASP-specific licensing regime exists yet; operator would need to comply with the general AML/CFT framework under Law N° 008/2020 and Law N° 060/2021, plus potentially seek recognition under the Payment Systems Law (N° 008/2021) for payment-related crypto services.
- BNR has issued repeated public warnings that virtual currencies are not legal tender, are unregulated, and carry high risks — creating regulatory uncertainty for exchange operations.
- Local entity incorporation is required to be a 'reporting person' subject to FIC oversight and to meet record-keeping and CDD obligations under Rwandan law.
- No formal licensing pathway for crypto exchanges currently exists; operator would need to comply as a reporting person under AML/CFT law while the regulatory framework remains developing.
- Custody segregation rules are not explicitly codified for virtual assets in Rwanda; operator must follow general AML/CFT record-keeping and customer asset protection principles.
Key Risks
- Regulatory Ambiguity: No comprehensive VASP/crypto-exchange licensing regime exists. The BNR has not formally authorized crypto exchanges, creating legal uncertainty for active operations.
- Enforcement Risk: While BNR's current posture is warnings and consumer protection, operating without explicit regulatory authorization could expose the exchange to enforcement under general financial laws or AML/CFT non-compliance.
- Market & Reputational Risk: Rwanda's crypto market is small; BNR public warnings discourage public participation, limiting the addressable market and creating PR exposure.
- Secondary Sanctions Risk: If the exchange deals in USD, uses US-based blockchain analytics, or touches US persons, it must comply with OFAC sanctions to avoid secondary sanctions risk.
- No Explicit Travel Rule Guidance: While FATF Recommendation 16 applies, Rwanda has not issued specific VASP travel rule guidance, creating compliance ambiguity for withdrawal/transfer obligations.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Rwanda's anti-money-laundering statute is Law nº 001/2025 of 22/01/2025 on the prevention and punishment of money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction, Official Gazette nº Special Bis of 22/01/2025, which superseded Law nº 028/2023 of 19/05/2023, itself the successor to Law nº 75/2019. No Rwandan anti-money-laundering statute carries the number 060/2021. Reporting persons on the Financial Intelligence Centre's published list are 435 financial institutions and 3,128 designated non-financial businesses and professions, a class that excludes virtual asset service providers, whose anti-money-laundering duty arises instead as a licensing condition under Article 10(2)(g) of Law nº 023/2026 of 25/05/2026, supervised by the Capital Market Authority of Rwanda under Article 6.
Rwanda's general anti-money-laundering compliance requirements for reporting persons are set by Regulations nº 002/FIC/2026 of 22/06/2026, Official Gazette nº 25 Bis of 22/06/2026, issued by the Director General of the Financial Intelligence Centre, whose Article 45 repeals Regulations nº 002/FIC/2023 of 26/06/2023, and the matching sanctions instrument is Regulations nº 001/FIC/2026 of 22/06/2026 of the same date and gazette. Both are Financial Intelligence Centre regulations rather than ministerial orders, and neither mentions virtual assets or virtual asset service providers.
Ministerial Order N° 002/2022 of 28/01/2022 determining procedures for combating money laundering and financing of terrorism: This order details the procedural aspects of AML/CFT compliance.
The National Bank of Rwanda has published no virtual-asset circular or guideline; ESAAMLG's July 2024 mutual evaluation of Rwanda records that the central bank issued a public notice in 2023 warning against crypto-asset activity until a regulatory framework was in place, and since Law nº 023/2026 of 25/05/2026 regulating virtual asset business the licensing of virtual asset service providers belongs to the Capital Market Authority of Rwanda, with the National Bank of Rwanda confined by Article 8 to cooperation with that Authority and to directives on matters falling under its own purview.
Evidence fact rw.licensing.identification-and-verification-of-customers not found (may have been renamed).
For Individuals: Obtaining and verifying name, address, date of birth, nationality, national identification number (e.g., Rwandan ID card, passport number), and any other unique identifiers. This typically involves documentary verification (e.g., valid ID document) and, where appropriate, non-documentary methods.
For Legal Entities (Companies, Corporations, Trusts): Obtaining and verifying the entity's name, legal form, address, registration number, articles of incorporation, bylaws, and proof of existence. Identifying and verifying the identity of beneficial owners (individuals who ultimately own or control the entity, typically 25% ownership threshold or control through other means), as well as persons acting on behalf of the entity (e.g., directors, authorized signatories).
Understanding the Purpose and Intended Nature of the Business Relationship: VASPs must understand why the customer wants to use their services and the anticipated level and type of activity.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by customers to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information up-to-date.
Risk-Based Approach: Applying CDD measures based on a risk assessment. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex or unusually large transactions) and simplified due diligence (SDD) for lower-risk customers (if permitted and justified). Due to the inherent risks of virtual assets, most VASP activities would generally require standard or enhanced CDD.
Reporting Threshold: There is no minimum monetary threshold for reporting suspicious transactions. Any transaction, regardless of amount, where there are reasonable grounds to suspect that it may be related to money laundering or terrorist financing, must be reported.
Content of Report: STRs must contain comprehensive details about the customer, the transaction(s), and the reasons for the suspicion.
Timing: Reports must be made promptly, typically within a specified number of business days (e.g., 2-5 working days) of forming the suspicion.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.
Customer Identification Records: All documents and information obtained during the CDD process (e.g., copies of identification documents, beneficial ownership information).
Transaction Records: Records of all transactions undertaken, sufficient to permit reconstruction of individual transactions (e.g., sender and receiver details, amounts, type of virtual asset, transaction hash/ID, date and time).
Business Relationship Records: Records pertaining to the business relationship, correspondence, and decisions made regarding the customer's risk profile.
Suspicious Transaction Reports (STRs): Copies of all STRs filed and any internal documentation supporting the decision to file (or not to file).
Duration: Records must generally be kept for a period of at least five (5) years after the end of the business relationship or the date of the transaction.
Financial Intelligence Centre (FIC) of Rwanda
The National Bank of Rwanda has published no virtual-asset circular or guideline; ESAAMLG's July 2024 mutual evaluation of Rwanda records that the central bank issued a public notice in 2023 warning against crypto-asset activity until a regulatory framework was in place, and since Law nº 023/2026 of 25/05/2026 regulating virtual asset business the licensing of virtual asset service providers belongs to the Capital Market Authority of Rwanda, with the National Bank of Rwanda confined by Article 8 to cooperation with that Authority and to directives on matters falling under its own purview.
Rwanda's operative anti-money-laundering statute is Law nº 001/2025 of 22/01/2025 on the prevention and punishment of money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction, which replaced Law nº 028/2023 of 19/05/2023, itself the repeal of Law nº 75/2019 of 29/01/2020; no Rwandan anti-money-laundering law is numbered 008/2020, and the Financial Intelligence Centre is governed by Law nº 045/2021 of 18/08/2021 as amended by Law nº 002/2025 of 22/01/2025.
Rwanda's anti-money-laundering obligations rest on Law nº 001/2025 of 22/01/2025, not on any law numbered 008/2020; Law nº 028/2023, which it replaced, contains no reference to virtual assets or virtual asset service providers, and preventive duties for virtual asset businesses were created only by Law nº 023/2026 of 25/05/2026 regulating virtual asset business.
Law nº 008/2021 of 16/02/2021 governs partnerships, not payment systems; Rwanda's payment-system statute is Law nº 061/2021 of 14/10/2021, which makes no reference to virtual assets, and virtual asset business is licensed by the Capital Market Authority of Rwanda under Law nº 023/2026 of 25/05/2026, the National Bank of Rwanda being confined to monetary and financial-stability oversight and cooperation rather than licensing.
Requirements for VASPs: Once formally regulated, VASPs in Rwanda (or those dealing with Rwandan entities) must:
Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).
Immediately freeze funds and other assets of designated individuals and entities.
Articles 6 and 7 of Rwanda's Regulations on Targeted Financial Sanctions of 26/08/2021 require a reporting person to report to the Financial Intelligence Centre without delay whether funds or other assets of a designated person were identified and to notify attempted dealings with frozen assets, but virtual asset service providers are not among Rwanda's reporting persons, their obligations arising instead under Law nº 023/2026.
Refrain from making funds or economic resources available, directly or indirectly, to sanctioned parties.
Legal Reference: UN Security Council Sanctions Committees (Lists and Resolutions): https://www.un.org/securitycouncil/sanctions/information
Dealing with U.S. persons (citizens, residents, entities, branches globally).
Using U.S. dollar-denominated transactions.
Utilizing U.S.-based blockchain analytics tools or other U.S. services.
Operating in whole or in part within the U.S.
Requirements for VASPs: Due to the risk of secondary sanctions and disruption of international financial services, prudent VASPs operating in Rwanda should:
Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).
Block transactions and freeze assets of designated individuals and entities.
Refrain from engaging in any activity that could be considered a violation or circumvention of OFAC sanctions.
Legal Reference: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC): https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information
Rwanda enacted a comprehensive virtual-asset statute on 25 May 2026: Law nº 023/2026 of 25/05/2026 regulating virtual asset business, Official Gazette nº Special of 28/05/2026, which sets licensing conditions at Article 10, suspension and revocation at Article 11, a regulatory sandbox at Article 13, the virtual-asset service list at Article 14, administrative sanctions at Article 32 and offences at Articles 33 to 38, and makes the Capital Market Authority of Rwanda the licensing and supervisory authority. The implementing regulations remain unmade, so the licensing regime is in force yet not operable. No National Bank of Rwanda virtual-asset warning exists as a published central-bank instrument.
Rwanda's virtual-asset investor-protection rules are statutory and belong to the Capital Market Authority of Rwanda, at Articles 25 to 27 of Law nº 023/2026 of 25/05/2026 on investor protection, market conduct and data and asset protection, with technology and information security at Article 28 and inspections at Article 29. No National Bank of Rwanda cryptocurrency warning exists as a published central-bank instrument, and the Capital Market Authority's licensee register carries ten categories, from exchanges to investment advisers, with no virtual-asset category and no licensed virtual asset service provider.
Rwanda has a statutory virtual-asset licensing regime at Article 10 of Law nº 023/2026 of 25/05/2026, and enforcement runs through that statute rather than through general financial law: Article 6(b) directs the Capital Market Authority of Rwanda to identify a virtual asset service provider that contravenes the Law, Article 29 provides for inspections, Article 30 for freezing of virtual assets, Article 32 for administrative sanctions and Articles 33 to 38 for offences. Because the implementing regulations are unmade, no licence has been issued and no enforcement action has been published.
Limited Market Size: The cryptocurrency market in Rwanda may not yet be large enough to attract the scale of illicit activity or the number of unregulated operators that would trigger frequent, large-scale, and publicly reported enforcement actions seen in more mature or permissive crypto jurisdictions.
Rwanda's virtual-asset regulator is the Capital Market Authority of Rwanda: Articles 5 to 7 of Law nº 023/2026 of 25/05/2026 establish it as the Regulatory Authority, Article 6 charges it with supervising virtual asset service providers and with ensuring their anti-money-laundering compliance, and Article 14 makes it the licensing authority for virtual asset services. Article 8 gives the National Bank of Rwanda a cooperation role together with power to issue directives on matters falling under its own purview, which is a directive power rather than a licensing power.
Rwanda's official position on virtual assets is set by statute rather than by warning. Article 15 of Law nº 023/2026 of 25/05/2026 bars natural persons from carrying on virtual asset business, provides that virtual assets are not legal tender and cannot be used as a direct means of payment unless the National Bank of Rwanda authorises it, requires approval for mining facilities, virtual-asset automated teller machines and mixer or tumbler services, and restricts marketing to licensed providers. Article 4(3) excludes algorithmic stablecoins, non-fungible tokens and central bank digital currency from the Law's scope.
Virtual assets are not legal tender in Rwanda, and the rule is statutory rather than declaratory: Article 15 of Law nº 023/2026 of 25/05/2026 provides that virtual assets are not legal tender and cannot be used as a direct means of payment unless the National Bank of Rwanda authorises it. The National Bank of Rwanda has published no instrument of its own stating that position.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Rwanda only by complying with the general AML/CFT framework as a reporting person (Law N° 008/2020, Law N° 060/2021, Ministerial Orders), incorporating locally, and facing significant regulatory uncertainty due to the lack of a formal VASP licensing regime and BNR's cautionary stance on cryptocurrencies.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?