EST · MMXXVI
Home/Jurisdictions/South Africa/EMI licence for crypto firms in South Africa
Licensing & Registration

EMI licence for crypto firms in South Africa

Emi licence for crypto firms in South Africa. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

EMI licence for crypto firms in South Africa

Operating a crypto payment or e-money product in South Africa without the correct authorisation is not a calculated risk – it is an enforcement event waiting to happen. The Financial Sector Conduct Authority (FSCA) formally designated crypto assets as a financial product under the Financial Advisory and Intermediary Services regime, and the South African Reserve Bank (SARB) regulates the payment layer that most crypto businesses ultimately depend on. For firms that hold customer funds, settle in fiat or issue a stored-value instrument, the relevant authorisation question is not purely a VASP registration question. It intersects the payment-services regime, and in some configurations it implicates an EMI-equivalent authorisation – the right to issue electronic money or operate a payment account – under the National Payment System Act and the rules administered by the SARB's Prudential Authority. This page maps that intersection and explains what inbound operators must resolve before they launch.

Why South Africa sits at the centre of the inbound operator's decision

South Africa has the largest and most liquid crypto market on the African continent, and the FSCA's move to bring crypto assets within the financial-product perimeter signals a maturing regulatory environment rather than a hostile one. For a cross-border operator – headquartered in Europe, the Gulf or Asia – the market is attractive precisely because the FSCA has chosen a disclosure and conduct-based licensing model, not a blanket prohibition. The regime does not yet replicate the granular activity-based licence categories of, say, VARA in Dubai or the MiCA CASP authorisation in the EU, but it creates a real compliance floor that enforcement authorities are beginning to test. Operators who treated South Africa as a grey-market opportunity are now facing FSCA inquiries and, in the payment layer, SARB scrutiny of their settlement arrangements.

In our cross-border practice, we regularly advise firms that arrive at the South African licensing question from two directions. Some are established VASPs in a recognised hub – Singapore, the UK, the DIFC – who want to add South African users without triggering local-establishment requirements. Others are locally incorporated businesses that grew quickly and never resolved the payment-layer authorisation question. Both groups face the same structural risk: a product that touches customer fiat, a South African bank account and stored value simultaneously may require engagement with two distinct regulators before it can operate safely.

What "EMI-equivalent authorisation" actually means in the South African context

South Africa does not use the EU term "electronic money institution" as a defined statutory category, but the National Payment System Act creates authorisation requirements that are functionally equivalent for firms that issue stored-value instruments or hold customer funds pending settlement. Under the applicable SARB payment-system provisions, any entity that wishes to issue a payment instrument, hold funds in a payment account or operate within a designated payment system must obtain the relevant approval or registration. For a crypto firm, this analysis turns on the product's economic substance, not its marketing label.

The critical classification questions are these. Does the firm hold rand-denominated customer balances at any point in the transaction chain? Does it issue a tokenised instrument that a South African customer can use to discharge a payment obligation? Does it settle cross-border crypto-to-fiat transactions through a South African correspondent bank? An affirmative answer to any one of these questions places the firm inside the payment-system regulatory perimeter, and it must then work through the SARB's registration or approval pathway independently of the FSCA's crypto-asset licence. The two authorisations are cumulative, not alternative.

This layering is a feature of the South African approach that operators trained on a single-licence model routinely underestimate. We have seen businesses obtain their FSCA crypto-asset VASP registration in good order and then discover, at the point of opening a South African bank settlement account, that the bank's compliance team requires evidence of a payment-system engagement with the SARB as well. The banking relationship and the regulatory authorisation are not independent questions.

The FSCA crypto-asset VASP registration: what it covers and what it does not

The FSCA's crypto-asset framework – built on the re-classification of crypto assets as financial products – requires any entity providing a financial service in relation to crypto assets to be licensed as a Financial Service Provider (FSP) or to be authorised under an equivalent regulatory permission. The FSP authorisation covers the conduct layer: advice, intermediary services, custody in the sense of managing crypto assets on behalf of clients. It does not, on its own, authorise the issuance of a stored-value payment instrument or the operation of a rand-denominated payment account.

The registration process involves submission to the FSCA of a detailed business plan, a fit-and-proper assessment of key individuals, an anti-money laundering compliance programme aligned with the Financial Intelligence Centre Act (FICA), and evidence of adequate capital and operational controls. The FSCA has published guidance on the expected standard, and its supervisory posture has tightened since the initial registration window opened. Processing timelines are not published as a fixed standard; in practice, the duration depends on the completeness of the initial submission and the complexity of the applicant's business model. Incomplete submissions are routinely returned, restarting the clock.

A firm offering staking, yield products or tokenised securities will face additional classification questions. The FSCA's financial-product perimeter is broad, and a product structured as a debt or equity instrument – even if denominated in crypto – may fall under the Collective Investment Schemes Control Act or the Financial Markets Act rather than, or in addition to, the crypto-asset provisions. Getting the classification right before submission is not a formality. It determines which regulatory queue the application enters and which disclosure obligations apply.

For a scoped assessment of your South African licensing position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the payment rails, the product – change the analysis materially.

How the SARB payment-system layer intersects the crypto product

The SARB's oversight of the payment system is the authorisation dimension most frequently overlooked by inbound operators, and it is where enforcement risk is highest for firms that move fiat as part of a crypto workflow. Under the National Payment System Act, the SARB has broad authority to designate payment systems, to set participation conditions and to approve the entities that operate within those systems. An operator that settles crypto-to-fiat transactions through a South African bank without the bank having confirmed that the settlement arrangement is within the firm's authorised scope is, in substance, relying on the bank's own payment-system participation – a position that most South African banks' compliance teams will not accept indefinitely.

For firms issuing a stored-value instrument – including a prepaid crypto card, a tokenised rand account or any instrument that stores monetary value for future use – the SARB's approval process is separate from and prior to the commercial launch of the product. The SARB evaluates the technical architecture of the instrument, the safeguarding of customer funds, the redemption mechanism and the systemic risk profile of the issuer. This is a substantive review, not an administrative registration. Timelines vary and are influenced by the novelty of the product structure and the quality of the technical documentation submitted.

In our practice, we regularly advise that the SARB engagement should begin before the FSCA application is finalised, not after. The two regulators operate independently, but the SARB's assessment of the payment instrument may affect the product's design – and a design change post-FSCA approval creates delay and expense. Sequential engagement is the default. Parallel engagement, where the product architecture is stable, saves time.

AML, FICA and the Travel Rule obligation

South Africa's anti-money laundering regime is anchored in FICA, which imposes customer due diligence, record-keeping and suspicious-transaction reporting obligations on all accountable institutions. Following the FSCA's designation of crypto assets as a financial product, crypto-asset service providers are expressly within the accountable-institution perimeter. The Financial Intelligence Centre supervises FICA compliance for the sector. Non-compliance is a strict-liability matter in terms of reporting obligations; the FIC publishes guidance that is updated periodically, and operators are expected to maintain a current compliance programme.

The Travel Rule – the obligation derived from FATF Recommendation 15 to pass originator and beneficiary data alongside a virtual-asset transfer – applies in South Africa to transfers above the applicable threshold. South Africa has committed to FATF standards and the FIC has issued guidance on implementation. The precise data threshold is subject to regulatory update and should be confirmed against current FIC guidance at the time of implementation. Importantly, the Travel Rule obligation is not satisfied by maintaining the data internally; it requires the technical capacity to transmit it to the receiving VASP, which in turn requires that both counterparties operate compatible systems. For firms transacting cross-border – whether sending to European exchanges subject to MiCA or to Singapore entities under the MAS Payment Services Act – the data-sharing obligation requires advance counterparty verification and, in some cases, bespoke documentation.

South Africa is also a FATF member, and its mutual evaluation outcomes have historically influenced the speed with which regulators act on gaps in the supervised population. Operators who are visible in the market but unregistered are a predictable enforcement target in the post-evaluation supervisory cycle.

The cross-border reality: banking, tax and exchange control

South Africa's exchange-control regime – administered by the SARB under the Currency and Exchanges Act – is a material constraint that operates independently of the licensing question. Residents and corporate entities are subject to annual allowances for cross-border capital flows, and crypto transactions that involve the offshore movement of value are scrutinised under these rules. For an inbound operator processing South African customer transactions, the exchange-control analysis determines whether the firm can accept rand deposits, convert to crypto, remit offshore and repatriate proceeds without triggering reporting obligations or approval requirements at the SARB's exchange-control division.

The tax treatment of crypto assets is determined by the South African Revenue Service (SARS). SARS has published guidance confirming that crypto assets are not currency for income-tax purposes; gains and losses are assessed under the general income or capital gains provisions depending on the holder's intention and the nature of the activity. For a business operating an exchange or a payment product, the normal receipts-and-accruals analysis applies to trading profits, and the VAT treatment of fees – whether they constitute exempt financial services or standard-rated supplies – requires careful structural analysis before launch. These are not questions that can be resolved by analogy to the EU or UK treatment; South African tax law applies on its own terms.

Banking access is a recurring operational challenge. South African banks have applied enhanced due diligence to crypto businesses, and a firm that cannot demonstrate a completed FSCA registration and a credible AML programme may find that account opening is refused or that accounts are closed with limited notice. The relationship between regulatory status and banking access is more direct in South Africa than in many other jurisdictions. Obtaining the FSCA authorisation is, in practice, a prerequisite to a stable banking relationship – not a parallel track.

A matter from our cross-border practice

In a recent engagement, an operator incorporated in a recognised EU member state sought to extend its MiCA-authorised CASP permissions to South African users via a locally incorporated subsidiary. The business had assumed that the EU authorisation, combined with a thin local entity, would satisfy the FSCA's requirements. On review, the product included a rand-denominated stored-value function – effectively a prepaid wallet – that placed it squarely within the SARB's payment-system regime as well as the FSCA's crypto-asset perimeter. We advised on the sequencing of the two regulatory engagements, assisted in redesigning the product's settlement flow to minimise the stored-value exposure, and mapped the exchange-control and tax treatment of the proposed cross-border settlement architecture. The client avoided a launch under an incomplete authorisation and entered the South African market on a properly structured basis several weeks later than originally planned, but without the enforcement exposure that a rushed launch would have created.

Decision framework: which authorisation path fits your profile

The right path depends on what the business actually does. Three operator profiles illustrate the decision branches most commonly encountered in practice.

Profile A – Pure crypto-to-crypto exchange with South African users. The FSCA crypto-asset FSP registration is the primary requirement. The SARB payment-system analysis is relevant only where the firm offers fiat on-ramp or off-ramp functionality, or holds rand balances for any period. The AML/FICA programme is mandatory. Timeline to a completed registration is subject to submission quality and FSCA queue position; qualitatively, well-prepared applications have concluded within a period of several months.

Profile B – Crypto payment product with fiat settlement. Both the FSCA crypto-asset authorisation and a SARB engagement on the payment instrument are required. The SARB review is substantive and product-specific. The exchange-control analysis is a third dimension. Tax structuring – particularly VAT treatment of payment fees – should be resolved before launch. This is the most complex profile and the one most likely to benefit from early parallel engagement with both regulators.

Profile C – Inbound operator licensing only locally to serve African markets from a South African hub. The full stack applies: FSCA registration, SARB payment-system engagement (if the product includes stored value or fiat settlement), FICA compliance, exchange-control analysis and SARS tax structuring. Allied counsel in the relevant neighbouring jurisdictions will be needed for any extension of service beyond the South African border, as each jurisdiction in the SADC region maintains its own VASP and payment regulatory regime.

If a prior application stalled or a banking relationship was lost, a second structural read can identify the underlying cause and the route forward. Write to OBOLUS at info@oboluslaw.com.

A common assumption that creates real risk

A common assumption among inbound operators is that a single offshore licence – held in Malta, the BVI or a similar hub – is sufficient to serve South African clients at scale. That assumption is incorrect, and the risk it creates is not theoretical. The FSCA's conduct-based jurisdiction extends to financial services provided to South African clients regardless of the provider's place of incorporation. An unlicensed foreign entity providing crypto financial services to South African residents is in breach of the applicable FSCA provisions, and the FSCA has the authority to publish public warnings, refer matters to the National Consumer Financial Education Committee and, in serious cases, refer to criminal prosecution authorities.

The offshore-licence assumption is doubly dangerous in the payment layer. South African banks that detect an unregistered foreign entity using their rails for fiat-crypto settlement have reported those arrangements to the SARB and closed the accounts involved. The loss of banking access is often more immediately damaging to the business than the regulatory enforcement itself. Operators we advise are told consistently: the question is not whether the South African regime will catch up to your product. It already has. The question is whether your structure is ready.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In South Africa, the FSCA does not publish a fixed processing timeline. Applications that are complete and well-structured typically conclude within a period of several months, but complex product configurations or incomplete submissions extend that materially. Where both FSCA and SARB engagement is required, the overall authorisation window is longer, since the two processes run independently. Early preparation – including a resolved AML programme and a finalised product design – is the principal variable within the applicant's control.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on the business model, the target user base, the banking requirements and the tax exposure. A firm serving South African clients needs South African authorisation regardless of where it is incorporated. For a holding or operational entity in a recognised hub – the EU under MiCA, Singapore under the MAS Payment Services Act, the UAE under VARA – the question is whether that hub authorisation covers the South African activity or whether a local presence and registration is separately required. We map the full stack before our clients commit to a structure.

Do I need a separate custody licence?

In South Africa, custody of crypto assets on behalf of clients falls within the FSCA's crypto-asset FSP perimeter and must be covered by the applicable authorisation. If the custody function is bundled with a payment or stored-value product, the SARB's payment-system requirements apply as well. In other jurisdictions – the EU under MiCA, Hong Kong under the SFC's VASP regime – custody is a separately licensed activity with its own capital and safeguarding requirements. Whether a single or layered authorisation applies to your custody service depends on the jurisdictions involved and the product's structure.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, payment and custody stack across operating layers before our clients commit to a structure – so that the banking relationship and the regulatory authorisation are resolved together, not in sequence. Digital assets are the whole of our practice. To discuss your South African licensing position or cross-border structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound licensing strategy for digital-asset businesses entering African and cross-border payment regulatory environments.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours