Custodial wallet / SaaS in Eswatini
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Eswatini with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register or obtain a license with the FIU or FSRA as a VASP (custody provider) under the Prevention of Organised Crime Act and FIU Act — Eswatini is an ESAAMLG member applying FATF standards to VASPs (sz.aml.amlcft-registration-eswatini-as-a, sz.aml.prevention-of-organised-crime-act)
- Conduct customer due diligence (CDD) and Know Your Customer (KYC) on end users of the custodial wallet service (sz.aml.prevention-of-organised-crime-act)
- Implement sanctions screening against UN Security Council Resolutions (ISIL/Al-Qaida, Taliban, country-specific regimes) and any applicable OFAC obligations if processing USD transactions (sz.aml.united-nations-un-sanctions, sz.aml.us-sanctions-ofac)
- Comply with FATF Recommendation 15 obligations for VASPs, including transaction monitoring and suspicious transaction reporting (STRs) to the FIU (sz.aml.fatf-recommendations-eswatini-through-its, sz.aml.recommendation-15-new-technologies-specifically)
- Maintain records of transactions and customer information per POCA/FIU Act requirements; comply with targeted financial sanctions (freeze assets) obligations under UNSCRs (sz.aml.legal-basis-in-eswatini-eswatinis, sz.aml.recommendation-6-targeted-financial-sanctions)
- If offering custody of tokens that qualify as securities (equity, debt, asset-backed, profit-sharing, or certain utility tokens/NFTs), full securities law compliance (prospectus, licensing as financial services provider, ongoing disclosure) also attaches (sz.aml.licensing-issuers-promoters-or-financial, sz.licensing.prospectus-requirements-for-public-offerings)
Key Restrictions
- If any tokens held in custody are classified as securities (equity tokens, debt tokens, asset-backed tokens, profit-sharing tokens, certain utility tokens with speculative investment characteristics, or certain NFTs with fractional-ownership/profit-expectation characteristics), the operator must comply with FSRA securities laws including prospectus requirements, licensed trading platform obligations, and financial services provider licensing (sz.licensing.security-tokens-these-are-tokens, sz.licensing.licensed-trading-platforms-trading-would)
- The CBE has stated that virtual assets are not legal tender and financial institutions are advised to exercise extreme caution — this may restrict or complicate banking relationships and fiat on/off ramps (sz.enforcement.central-bank-of-eswatini-cbe)
- No specific digital-asset custody regime exists yet; the operator must rely on general financial services licensing pathways which are still being developed (sz.enforcement.ongoing-discussions-and-regulatory-development)
- SaaS white-label model creates ambiguity — the licensed/registered entity (the SaaS provider) bears primary AML obligations, but the white-label client may also face CDD/reporting duties depending on how custody is structured contractually
Key Risks
- Regulatory ambiguity: Eswatini has not yet enacted a comprehensive VASP licensing framework; the CBE historically warned against crypto and the FSRA framework is under development — this creates uncertainty for custodial wallet operators (sz.enforcement.general-reference-to-their-policystance, sz.enforcement.ongoing-discussions-and-regulatory-development)
- Securities reclassification risk: Many tokens held in custody (utility tokens with speculative value, fractional NFTs, profit-sharing tokens) could be retroactively classified as securities, triggering unlicensed securities-dealing exposure (sz.licensing.certain-utility-tokens-while-typically, sz.licensing.certain-nfts-non-fungible-tokens-while)
- Banking access risk: CBE's cautious stance and advisories to financial institutions may make it difficult for a custody provider to open and maintain bank accounts in Eswatini (sz.enforcement.central-bank-of-eswatini-cbe-public-statement-on-virtual-assets-cryptocurrencies)
- FATF grey-list / compliance risk: As an ESAAMLG member, Eswatini is under pressure to implement FATF Recommendation 15; regulatory changes could impose new requirements retroactively (sz.aml.fatf-recommendations-eswatini-through-its)
- Lack of insurance/Proof-of-Reserves regulation: No specific segregation, insurance, or proof-of-reserves rules exist yet for custodial wallets — this is both a flexibility and a risk (absence of cited rules on these topics)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Eswatini operates no virtual-asset licensing regime: neither the Central Bank of Eswatini nor the Financial Services Regulatory Authority licenses virtual asset service providers, and the only hook is AML-side, created by the Anti-Money Laundering, Counter-Financing of Terrorism and Counter-Proliferation Financing (Miscellaneous Amendments) Act 2024, which directs supervisory authorities to establish a framework to regulate VASPs and under which VASPs are treated as accountable institutions registering with the Eswatini Financial Intelligence Centre.
Eswatini's primary AML/CFT statute is the Money Laundering and Financing of Terrorism (Prevention) Act, 2011 (Act 6 of 2011), as amended by Act 5 of 2016, whose section 19 establishes the financial intelligence body first named the Swaziland Financial Intelligence Unit and now operating as the Eswatini Financial Intelligence Centre; Eswatini has no Financial Intelligence Unit Act, the Prevention of Organised Crime Act 2018 deals with organised crime and confiscation rather than accountable-institution duties, and the 2011 Act as consolidated carries no definition of virtual assets, VASPs, cryptocurrency or digital currency.
FATF Recommendations: Eswatini, through its membership in ESAAMLG, is expected to continue enhancing its legal framework to fully comply with FATF Recommendation 15 on new technologies and Virtual Asset Service Providers (VASPs). This implies that future amendments or new regulations could introduce more specific requirements for VASPs, which might eventually encompass more detailed aspects of custody.
Recommendation 15 (New Technologies): Specifically applies AML/CFT obligations to VASPs, including the obligation to implement sanctions screening.
Recommendation 6 (Targeted Financial Sanctions): Requires countries to implement targeted financial sanctions related to terrorism and WMD proliferation without delay.
Evidence fact sz.aml.united-nations-un-sanctions not found (may have been renamed).
U.S. Sanctions (OFAC):
Eswatini's AML statute is the Money Laundering and Financing of Terrorism (Prevention) Act, 2011 (Act 6 of 2011), amended by Act 5 of 2016, and the Prevention of Organised Crime Act, 2018 supplies asset-recovery powers, but United Nations Security Council targeted financial sanctions are given domestic effect by the Anti-Money Laundering (United Nations Security Council Resolutions) Regulations, 2016 together with the Suppression of Terrorism Act as amended by Act No. 11 of 2017, with the Ministry of Foreign Affairs and International Cooperation acting as the gateway for UNSC 1267 and 1373 listings; section 19 of the 2011 Act establishes the financial intelligence unit as the Swaziland Financial Intelligence Unit, the single body that now operates as the Eswatini Financial Intelligence Centre, and Eswatini was rated Non-Compliant on Recommendations 6 and 7 in the June 2022 ESAAMLG mutual evaluation.
Security Tokens: These are tokens explicitly designed to represent traditional financial instruments.
Eswatini's Financial Services Regulatory Authority licenses no virtual-asset trading platform and operates no securities-exchange licence class that reaches crypto-asset trading; the Central Bank of Eswatini's 2023 notice records that cryptocurrencies are not legal tender in Eswatini and that crypto investments or assets are currently unregulated there, so no Eswatini instrument makes crypto trading either licensable or unlawful. A digital-asset regulatory framework administered by a body called the FSRA belongs to the Abu Dhabi Global Market, not to Eswatini.
Prospectus Requirements: For public offerings of securities, a comprehensive prospectus must be prepared and registered with the FSRA. This prospectus must disclose all material information relevant to the investment, risks, and the issuer.
Licensing: Issuers, promoters, or financial intermediaries involved in offering or distributing securities may need to be licensed by the FSRA as financial services providers (e.g., investment advisors, brokers, collective investment scheme managers).
Certain Utility Tokens: While typically designed to provide access to a product or service, a utility token can be reclassified as a security if:
Certain NFTs (Non-Fungible Tokens): While most NFTs are unique digital assets, they can be considered securities if:
Central Bank of Eswatini (CBE) Public Statement on Virtual Assets (Cryptocurrencies)
Evidence fact sz.enforcement.central-bank-of-eswatini-cbe-public-statement-on-virtual-assets-cryptocurrencies not found (may have been renamed).
Ongoing Discussions and Regulatory Development
General reference to their policy/stance: While not a direct enforcement action, the CBE's consistently cautious stance is reiterated in various publications. For instance, their financial stability reports or governor's statements would reflect this. A common search result for their crypto stance points to articles referencing their long-standing cautionary approach.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators may operate in Eswatini subject to AML/CFT registration (likely with FIU/FSRA) and securities law compliance for any tokens classified as securities, but the regime lacks a dedicated digital-asset custody framework; the CBE's cautious stance and ongoing regulatory development create material uncertainty.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?