EST · MMXXVI
Home/Jurisdictions/Seychelles/KYC and onboarding framework in Seychelles
Compliance, AML & Travel Rule

KYC and onboarding framework in Seychelles

Kyc and onboarding framework in Seychelles. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business from Seychelles without a properly documented KYC (know-your-customer) program is one of the fastest ways to lose banking access and trigger regulator scrutiny simultaneously. Across the major correspondent-banking networks, AML deficiencies in an offshore entity are now treated as a systemic risk by the account-holding bank – not an administrative oversight. The Seychelles Financial Intelligence Unit (FIU) and the broader anti-money-laundering regime governed by the Proceeds of Crime Act and the Anti-Money Laundering and Countering the Financing of Terrorism Act impose obligations that have real teeth, and the international standard-setter FATF has placed Seychelles on its monitoring processes at various points, adding additional scrutiny from correspondent banks and liquidity partners worldwide.

This page sets out the regulated basis for KYC and customer onboarding in Seychelles for digital-asset businesses, the practical process and timeline an inbound operator should expect, the cross-border interaction with banking and tax, and the decision point at which engaging specialist counsel changes the outcome.

What is the legal basis for KYC obligations in Seychelles?

Seychelles imposes KYC obligations on virtual asset service providers through a combination of its anti-money laundering legislation, the Financial Intelligence Unit Act, and the Securities Act as administered by the Financial Services Authority (FSA). The FSA is the primary regulator for most corporate and financial services activity in Seychelles; VASPs and entities dealing in digital assets must register or licence with the FSA and then operate within its AML/CFT guidelines. The baseline is set by FATF Recommendation 15, which requires countries to apply the full FATF framework to virtual assets and VASPs – Seychelles has incorporated this into domestic supervisory expectations.

The practical consequence is that a Seychelles VASP cannot simply file a corporate registration and begin onboarding clients. The entity must implement a written AML/CFT program, appoint a qualified Money Laundering Reporting Officer (MLRO), conduct customer due diligence before a business relationship commences, apply enhanced due diligence to higher-risk customers, and maintain transaction monitoring systems capable of flagging unusual patterns. These are not aspirational standards – the FSA and FIU treat them as minimum entry conditions.

The process begins before the first customer is onboarded. Regulators in Seychelles increasingly review the AML/CFT program as part of the initial registration review, meaning a deficient program can delay or block market access entirely.

Which digital-asset businesses are required to maintain a KYC framework in Seychelles?

Any entity providing virtual asset services in or from Seychelles – including exchange, brokerage, custody, wallet provision, and token issuance with ongoing services – falls within the VASP perimeter and carries full KYC obligations. The test is functional: it is the activity performed, not the label applied to the company, that determines whether the AML/CFT regime applies.

This matters for two categories of inbound operator. First, a holding company that passively holds tokens or interests in other entities may sit outside the VASP definition, but the moment it begins executing trades, managing client assets, or routing transfers on behalf of third parties, the KYC obligations attach. Second, a company incorporated in Seychelles that directs its commercial activity entirely to users in another jurisdiction is not automatically exempt from Seychelles AML obligations – the FSA's supervisory reach covers the entity, not just the customer base.

In our practice, operators frequently underestimate the breadth of the "virtual asset service" definition. A Seychelles entity that administers a multi-sig arrangement for institutional clients, settles transactions between parties, or provides an interface through which customers execute trades is almost certainly a VASP. The safer analytical starting point is to assume the obligations apply and then build out the carve-outs, rather than the reverse.

CTA #1 – The analysis above describes the standard regulatory perimeter. Your entity structure, the services offered, and the countries from which you source clients all affect whether the Seychelles KYC regime applies to you in full, in part, or alongside a parallel regime in another jurisdiction. Map your options with OBOLUS before you commit to a structure.

What must a KYC and onboarding program contain under Seychelles AML law?

A compliant KYC and onboarding framework for a Seychelles VASP has several mandatory components, each traceable to the FSA's AML/CFT guidelines and to the FATF standard that underpins them.

Customer identification and verification is the first layer. Before accepting a client, the entity must collect identifying information – government-issued documentation, proof of address, and for corporate clients, beneficial ownership information to the ultimate natural-person level. Seychelles aligns with the FATF's recommended 25% ownership threshold for corporate beneficial-ownership disclosure, though the FSA retains discretion to require disclosure at lower thresholds where risk indicators are present.

Customer risk rating is the second layer. Every client must be assigned a risk tier – typically simplified, standard, or enhanced – at onboarding. The risk score determines the depth of due diligence, the frequency of periodic review, and the transaction-monitoring parameters applied to the account. High-risk categories include politically exposed persons (PEPs), clients resident in FATF-listed jurisdictions, and clients whose business model itself involves higher inherent risk (for example, a VASP onboarding another VASP as a client).

Ongoing monitoring is the third layer. A one-time onboarding check does not satisfy Seychelles AML obligations. The entity must monitor transactions in real time or near-real time, flag transactions that are inconsistent with the customer's declared profile, and conduct periodic reviews of the customer file. The monitoring obligation is not satisfied by a manual compliance review – the FSA expects technological systems capable of generating alerts at scale.

Suspicious Transaction Reporting (STR) to the FIU is the fourth layer. Where monitoring generates an alert that cannot be resolved through internal escalation, the MLRO must file an STR with the Seychelles FIU. The obligation to file is not discretionary once reasonable grounds for suspicion exist; tipping off the subject of an STR is a criminal offence.

Record retention – typically a minimum of five years from the end of the customer relationship – completes the core framework. Records must be retrievable and legible on request from the FSA or FIU.

How does the Travel Rule apply to Seychelles VASPs?

The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary identifying information alongside a virtual asset transfer – applies to Seychelles VASPs in line with the FATF standard. For transfers above the applicable threshold, the originating VASP must collect and transmit the sender's name, account identifier, and other specified data; the beneficiary VASP must collect and verify the corresponding beneficiary data.

In our cross-border practice, the Travel Rule generates two distinct operational challenges for Seychelles entities. The first is counterparty identification: a Seychelles VASP must verify that the VASPs it transacts with are themselves registered or licensed and operating a compliant Travel Rule solution. Sending a transfer to an unhosted wallet or to a counterparty VASP with no Travel Rule program creates a regulatory exposure that the FSA can treat as a systemic control failure, not just a one-off omission.

The second challenge is the sunrise problem: FATF member jurisdictions have adopted Travel Rule obligations on different timelines. A Seychelles VASP transacting with a counterparty in a jurisdiction that has not yet enacted a Travel Rule requirement faces a practical gap in data exchange. The FSA's expectation – consistent with FATF guidance – is that the Seychelles VASP maintains its own data-collection obligations regardless of whether the counterparty is able to reciprocate. This imposes an asymmetric compliance cost that operators must build into their systems architecture from day one.

How does the Seychelles KYC regime interact with banking and tax obligations cross-border?

The Seychelles KYC framework does not operate in isolation. For most digital-asset businesses, the Seychelles entity sits within a wider structure that includes operating entities, banking relationships, and tax registrations in multiple jurisdictions. Each layer carries its own compliance expectations, and they interact in ways that can create unexpected gaps.

On the banking side, a Seychelles VASP seeking a corporate bank account – whether in Seychelles itself, in a regional hub such as the UAE or Singapore, or in Europe – will be assessed partly on the strength of its AML/KYC documentation. Correspondent banks apply their own enhanced due diligence to VASPs as a category. A well-documented Seychelles KYC program, with an auditable MLRO appointment, a current risk assessment, and evidence of active transaction monitoring, materially improves the probability of account approval and reduces the time from application to opening.

On the tax side, Seychelles operates a territorial tax regime, but the operators we advise routinely have substance obligations, economic nexus considerations, or CRS/FATCA reporting requirements that flow from the structure as a whole – not from Seychelles tax law alone. The KYC data collected on customers often overlaps with the information required for CRS self-certification and tax residence reporting. Building the customer data model to serve both AML and tax reporting requirements simultaneously reduces cost and avoids the inconsistencies that arise when two separate teams manage the same underlying data.

A Seychelles entity that serves EU customers, for example, may need to consider whether MiCA's requirements – as administered by ESMA and the relevant national competent authority – impose a separate KYC or customer disclosure obligation at the point of service. The FSA's KYC regime and MiCA's requirements are not automatically co-extensive, and operating as though they are is a common structural error.

What does the onboarding compliance buildout look like in practice?

Operators we advise typically move through a sequenced buildout. The first stage is a gap analysis: mapping the current AML/CFT policies, if any, against the FSA's published expectations and the FATF standard. This produces a remediation list with prioritized items – the items that would fail an FSA inspection go to the top regardless of how operationally convenient they are to fix.

The second stage is policy drafting. A Seychelles VASP needs, at a minimum, an AML/CFT policy, a customer due diligence procedure, a PEP and sanctions screening procedure, a transaction monitoring procedure, and a suspicious transaction reporting procedure. These documents are not interchangeable with generic templates purchased from a compliance vendor; the FSA expects policies that reflect the entity's specific business model, customer types, and risk appetite.

The third stage is MLRO appointment. The MLRO must be a natural person with sufficient seniority and autonomy to make escalation decisions without commercial pressure. In our practice, placing the MLRO role inside the sales or revenue function – even where the individual is technically qualified – creates a governance structure the FSA is likely to question on inspection.

The fourth stage is systems integration. Transaction monitoring, wallet screening, and Travel Rule messaging solutions must be connected to the core platform before live trading begins. Retrofitting these systems after launch is significantly more expensive and operationally disruptive than building them into the initial architecture.

The timeline from gap analysis to a fully documented, systems-integrated compliance program varies by the complexity of the business model and the state of existing documentation. For a straightforward exchange or brokerage, the buildout typically runs over a period of weeks to a few months. For a custody or lending business with institutional clients, the timeline is longer, reflecting the greater complexity of the onboarding procedures and the higher scrutiny applied by the FSA to client-asset models.

Practical illustration: compliance buildout ahead of a banking application

In a recent matter, a digital-asset brokerage incorporated in Seychelles had been operating under a registration but had never formalized its AML/CFT program into auditable documentation. The entity was ready to approach a European correspondent bank for a settlement account. We conducted a structured gap analysis, identified that the transaction monitoring system was generating alerts but that no escalation procedure existed to route those alerts to the MLRO, and that the beneficial ownership records for two corporate clients were incomplete. We drafted the remediation policies, restructured the MLRO governance to ensure operational independence, and produced a compliance summary package for the bank's due diligence team. The bank's AML review completed within the expected timeline and the account was approved. The operator subsequently used the same documentation package when responding to an FSA request for information the following quarter.

What are the most common KYC failures that create enforcement exposure in Seychelles?

A common assumption is that registration with the FSA is the compliance endpoint – that once a VASP is on the register, ongoing supervisory scrutiny is minimal. That assumption is no longer accurate. The FSA has increased its thematic review activity, and FATF's assessments of Seychelles have fed directly into enhanced scrutiny of the digital-asset sector by correspondent banks and by regulators in other jurisdictions where Seychelles entities seek recognition.

The failures we see most frequently fall into three categories. The first is documentation that exists on paper but has never been operationalized: policies that describe procedures no one follows, and monitoring thresholds no one has connected to the actual transaction volumes of the business. The second is MLRO arrangements that are nominal: a director or external consultant named as MLRO who has no real visibility into transaction data and no escalation pathway to a board that takes AML risk seriously. The third is the Travel Rule gap: either no solution implemented at all, or a solution that covers outgoing transfers but fails to capture incoming transfers from counterparties with incomplete data sets.

Each of these failures is individually correctable. They become systemic problems when they exist together – and when a bank or regulator identifies all three in a single inspection, the remediation conversation moves from technical to existential.

CTA #2 – If a prior compliance review flagged deficiencies or a banking application stalled on AML grounds, a structured second read can identify the root cause and the remediation path. Map your options with the OBOLUS compliance desk.

When should a Seychelles VASP engage specialist counsel on its KYC framework?

The right moment to engage specialist counsel is before the compliance buildout begins – not after an FSA inspection request arrives or a bank account is declined. The reason is structural: the decisions made in the first weeks of a compliance program (the MLRO appointment, the risk appetite statement, the customer segmentation model) are expensive to reverse and visible in every subsequent regulatory interaction.

There are three operator profiles that present distinct decision points. The first is the startup VASP building its program from scratch: the priority is getting the architecture right the first time, including Travel Rule messaging and wallet screening from day one. The second is the established Seychelles entity that has grown beyond its original compliance design: the customer base has expanded, the product range has widened, and the original AML program no longer reflects the actual risk profile. A thematic review or a bank's due diligence request will expose this gap. The third is the inbound operator structuring a new entity in Seychelles as part of a multi-jurisdiction stack: the Seychelles compliance program must be designed in light of the obligations at every other layer of the structure – EU passporting under MiCA, MAS requirements in Singapore, or SFC expectations in Hong Kong will each impose requirements that interact with and sometimes exceed the FSA baseline.

We map the licence, compliance, banking, and tax stack across operating, custody, and payment layers before you commit. That single-mandate approach eliminates the gaps that appear when licensing, compliance, and banking are treated as separate workstreams with no common design logic.

Related at OBOLUS

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule, and compliance obligations that sit around every operational layer. We structure licensing, banking, and tax as one mandate rather than three disconnected workstreams – because the gaps between those workstreams are where enforcement exposure lives. To discuss your Seychelles KYC or compliance question, contact info@oboluslaw.com.

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – derived from FATF Recommendation 16 – requires a VASP initiating a virtual asset transfer to collect and transmit the originator's name, account identifier, and other specified data to the beneficiary VASP. The beneficiary VASP must in turn collect and verify the corresponding beneficiary information. The obligation applies to transfers above the applicable threshold set by each jurisdiction's implementing rules. Failure to comply is treated as a systemic AML control failure by most supervisors, not a technical omission.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) must be a natural person with sufficient seniority, autonomy, and access to transaction data to make independent escalation decisions. Most regulators – including the Seychelles FSA – expect the MLRO to sit at or near board level and to have a direct reporting line to the most senior governance body. External or nominee MLRO arrangements are scrutinized carefully; regulators assess whether the individual has real visibility into the business rather than nominal title.

How do regulators audit crypto AML programs?

Regulators typically audit crypto AML programs through a combination of document reviews, transaction sampling, and governance interviews. Supervisors request the written AML/CFT policies, the current risk assessment, the MLRO's activity log, a sample of customer due diligence files, and evidence of transaction monitoring alerts and their resolution. In Seychelles, the FSA may also request confirmation of Travel Rule implementation and counterparty VASP vetting procedures. An audit that reveals policies that exist on paper but are not operationalized is treated more severely than a gap that has been identified internally and is under active remediation.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design, Travel Rule implementation, and VASP supervisory compliance across offshore and emerging digital-asset jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours