Custodial wallet / SaaS in Senegal
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Senegal with a local entity, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- No specific AML framework exists for VASPs, but general AML/CFT obligations apply under FATF membership — including customer due diligence (identity verification), ongoing transaction monitoring, suspicious transaction reporting to CENTIF (Senegal's FIU), and a risk-based AML approach.
- These obligations would attach directly to the SaaS operator as the entity engaging in the regulated activity, not to the white-label client (though contracts would typically allocate compliance responsibility).
- If the operator also handles fiat currency (e.g., on/off ramps), it would need to comply with BCEAO e-money / payment institution AML rules, which are more detailed and enforced.
Key Restrictions
- No dedicated custodial or VASP license exists — pure crypto custody operates in a regulatory grey area and is viewed as unauthorized by BCEAO authorities.
- If the service involves fiat handling, it may fall under BCEAO's Payment Institution or Electronic Money Institution framework, requiring a full license, significant capital, and local incorporation.
- Local entity and physical presence within Senegal (or another UEMOA state with passporting) is required if the service touches fiat; for pure crypto custody this is a practical risk rather than a codified requirement.
Key Risks
- Regulatory ambiguity — BCEAO has repeatedly warned that cryptocurrencies are not recognized as legal tender and has provided no safe harbor for VASPs, creating enforcement risk.
- No segregation, insurance, or proof-of-reserves requirements exist, leaving client assets legally unprotected in insolvency or hack scenarios.
- Operating a custodial wallet without a license could be deemed an unauthorized financial activity, exposing the operator to enforcement actions or penalties.
- FATF recommendations (Travel Rule, VASP registration) are expected to be adopted regionally, which may retroactively impose requirements on operators currently in the grey area.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Status: There are no specific mandates or requirements for the use of cold storage for digital assets.
Not legal tender within the UEMOA zone.
Crypto-assets are not recognised as currency and there is still no BCEAO prudential or market-conduct framework for them (a drafting committee, C-CRYPTO, was set up in May 2026 with AMF-UMOA). However, virtual assets and virtual asset service providers ARE legally defined and regulated for AML/CFT purposes: the UMOA Loi uniforme LBC/FT/FP of 31 March 2023 defines 'actif virtuel' (art. 2) and 'prestataire de services d'actifs virtuels' (art. 2), lists PSAV among the assujettis (art. 3) and requires an agrement or prior authorisation to carry on that activity (art. 58); Senegal transposed it by Loi n° 2024-08 du 14 fevrier 2024.
Subject to significant risks, including money laundering, terrorist financing, fraud, and financial instability.
The premise is wrong: virtual assets and VASPs are legally defined in Senegal (Loi n° 2024-08 du 14 fevrier 2024, transposing the UMOA Loi uniforme LBC/FT/FP of 31 March 2023), custody of virtual assets falls within the PSAV definition, and art. 58 requires an agrement or prior authorisation. A crypto custodian in Senegal is therefore an AML/CFT-regulated, licence-requiring activity, not one outside all oversight - even though no dedicated prudential/custody framework has been issued yet.
Evidence fact sn.custody.status-there-are-no-specific:1 not found (may have been renamed).
There is indeed no rule in Senegalese or UEMOA law requiring crypto custodians to segregate client digital assets from their own. But the stated premise - that no regulatory framework at all exists - is inaccurate: since the Loi uniforme LBC/FT/FP of 31 March 2023 (transposed by Loi n° 2024-08 du 14 fevrier 2024), VASPs including custodians are assujettis to AML/CFT obligations and need an agrement or prior authorisation (art. 58). What is absent is a prudential/conduct framework, not any framework.
Evidence fact sn.custody.status-there-are-no-specific:2 not found (may have been renamed).
Correct that no insurance or bonding obligation is imposed on crypto custodians, but the premise is wrong: a licensing obligation does exist - art. 58 of the UMOA Loi uniforme LBC/FT/FP of 31 March 2023 (in force in Senegal via Loi n° 2024-08 du 14 fevrier 2024) requires an agrement or prior authorisation for any professional VASP activity, including custody of virtual assets. What is missing is the prudential content of that regime.
Status: There are no official definitions of a "qualified custodian" specifically for digital assets.
Since the UMOA loi uniforme LBC/FT/FP of 31 March 2023 — transposed in Senegal by Loi n° 2024-08 du 14 février 2024 — VASP activity is no longer unaddressed: art. 58 provides that 'Nul ne peut se livrer à l'activité professionnelle de prestataire de services d'actifs virtuels s'il n'a pas obtenu l'agrément ou l'autorisation préalable de l'autorité compétente', and art. 3(c) makes PSAV assujettis to AML/CFT obligations. What is still missing is an operative licensing regime: the law does not name the competent authority and the BCEAO's crypto-asset regulatory framework remained in preparation as of mid-2026.
No dedicated custody licence exists yet, but custody/administration of virtual assets is within the definition of prestataire de services d'actifs virtuels at art. 2(51) of the UMOA loi uniforme of 31 March 2023, and art. 58 makes it unlawful to carry on that activity without agrément or prior authorisation from the competent authority (transposed in Senegal by Loi n° 2024-08 du 14 février 2024).
Correct that the BCEAO's payment framework — Instruction n° 001-01-2024 on payment services and Instruction n° 008-05-2015 on electronic money issuers — contains no virtual-asset provisions, so a fiat payment leg is licensable while the crypto leg is not covered by those instruments. But the crypto leg is not simply 'unregulated': it falls under the AML/CFT authorisation requirement of art. 58 of the UMOA loi uniforme of 31 March 2023, transposed by Loi n° 2024-08.
Senegal is not a member of the FATF (whose membership is 39 jurisdictions); it is a member of GIABA, the FATF-style regional body for West Africa, and was subject to FATF increased monitoring (grey list) until October 2024. AML/KYC obligations on virtual asset activity are also not merely prospective: the UMOA loi uniforme of 31 March 2023, transposed in Senegal by Loi n° 2024-08 du 14 février 2024, already makes PSAV assujettis (art. 3(c)) with customer due diligence, authorisation (art. 58) and CENTIF reporting (art. 60) duties.
Local Presence: For any licensed financial institution, a physical presence, management, and operational infrastructure within Senegal (or another UEMOA member state, with appropriate passporting) would be required.
Pre-application discussions with the BCEAO.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators face no specific licensing regime but must operate in a regulatory grey area; if fiat handling is involved, BCEAO e-money/payment institution licensing applies, requiring local incorporation and significant capital; pure crypto custody is legally ambiguous with enforcement risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?