EST · MMXXVI
Home/Jurisdictions/South Africa/KYC and onboarding framework in South Africa
Compliance, AML & Travel Rule

KYC and onboarding framework in South Africa

Kyc and onboarding framework in South Africa. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

South Africa's Financial Intelligence Centre Act (FICA) and the Financial Sector Conduct Authority's CASP (crypto asset service provider) licensing regime together define the KYC and onboarding obligations every digital-asset business touching South African clients or infrastructure must satisfy. FICA imposes customer due diligence, beneficial-ownership verification and ongoing monitoring obligations on accountable institutions, a category that now expressly includes crypto asset service providers. For any business operating across borders – with an offshore entity serving South African users, or a South African entity accepting funds from international rails – the interaction between FICA, the FSCA's CASP regime and the FATF Travel Rule creates a compliance stack that cannot be addressed by a single offshore licence.

This page sets out the regulated basis for KYC and onboarding in South Africa, the practical steps to build a compliant program, and the cross-border issues most commonly encountered by inbound operators. Each section opens with a direct answer to the question it addresses.

What is the regulated basis for KYC in South Africa?

The primary legal basis for KYC obligations in South Africa is FICA (the Financial Intelligence Centre Act), administered by the Financial Intelligence Centre (FIC). Crypto asset service providers were designated as accountable institutions under FICA following amendments that aligned South Africa's AML regime with FATF Recommendation 15. This designation means that any entity operating as a CASP in the South African market must register with the FIC, appoint a compliance officer, conduct customer due diligence, keep records and file suspicious transaction reports.

The Financial Sector Conduct Authority (FSCA) holds the licensing mandate for CASPs under the Financial Advisory and Intermediary Services Act (FAIS), as extended to crypto asset activities. The FSCA published CASP licensing requirements and has moved through an initial authorisation window. A CASP operating without authorisation is now exposed to enforcement action directly from the FSCA, quite apart from any FIC sanction for KYC failures.

In our cross-border practice, the most common gap we see is a business that holds a European or Caribbean licence and assumes FSCA authorisation is unnecessary because it has no South African legal entity. The FSCA's position turns on where the service is offered and where clients are located, not only on where the entity is incorporated. An operator serving South African residents through a website or app is, in the FSCA's view, conducting regulated activity in South Africa.

Who needs a CASP licence and KYC framework in South Africa?

Any person or entity that as a regular feature of their business buys, sells, exchanges, administers, manages, safeguards or otherwise deals in crypto assets for or on behalf of another person in South Africa will generally require CASP authorisation from the FSCA. This captures centralised exchanges, OTC desks, custodians, portfolio managers and crypto-lending platforms. It is not limited to South African-incorporated entities.

The FSCA has indicated that the category of services that trigger authorisation is deliberately broad, mirroring the FATF virtual asset service provider definition. For an inbound business, the trigger analysis should ask: is the service marketed to South African residents? Are transaction flows settled through South African banking rails? Are South African institutional counterparties involved? A positive answer to any one of these questions is a strong indicator that CASP authorisation is required.

Once CASP status is confirmed, the entity becomes an accountable institution under FICA regardless of its domicile. The KYC and onboarding program must then satisfy the FIC's standard methodology: risk-based customer due diligence, enhanced due diligence for high-risk customers and politically exposed persons, record-keeping obligations, and transaction monitoring.

For a scoped assessment of whether your business model triggers CASP authorisation in South Africa, contact OBOLUS at info@oboluslaw.com. The process above describes the standard regulatory path. Your facts – the entity location, the user base, the banking rails – change the analysis. Map your options.

How does the KYC onboarding process work under FICA?

A compliant FICA onboarding program for a South African CASP follows five sequential steps: client risk assessment, identity verification, beneficial-ownership determination, source-of-funds examination and ongoing monitoring.

The risk-based approach is mandatory, not discretionary. The FIC expects each accountable institution to produce a documented risk management and compliance program (RMCP) that maps client risk categories – retail versus institutional, domestic versus cross-border, fiat-entry versus crypto-native – to corresponding due diligence intensity. Regulators audit the RMCP as the primary document; a shallow or generic policy will attract adverse findings regardless of how well the front-end onboarding screens work in practice.

Identity verification for natural persons requires a South African ID number or, for foreign nationals, a passport and proof of address. For legal entities, the requirement extends to the certificate of incorporation, constitutional documents, and identification of all beneficial owners holding above the relevant threshold set by FICA – which aligns broadly with the FATF 25% beneficial ownership standard, though operators should verify the current threshold in the applicable FIC guidance rather than relying on any single published figure.

Source-of-funds documentation is a persistent pain point. In our practice, we regularly advise CASPs that their onboarding questionnaires are collecting declarations but not evidence. The FIC's expectation is that a CASP can demonstrate, at the time of account opening and periodically thereafter, the plausible economic basis for the client's asset profile. For institutional clients, that means audited accounts or a fund mandate. For high-net-worth individuals, it typically means documentary evidence of the wealth event.

Ongoing monitoring must be capable of flagging unusual transaction patterns against the client's established risk profile. A crypto-native business that relies solely on blockchain analytics without integrating traditional fiat monitoring will have gaps – particularly for clients who bridge between fiat deposits and on-chain activity across multiple wallets.

Does the Travel Rule apply to South African CASPs?

The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary data with virtual asset transfers – applies to South African CASPs by virtue of FICA's alignment with FATF standards and the FIC's guidance on virtual asset transfers. South Africa's Grey Listing by FATF in 2023, and its subsequent work toward removal from that list, has placed Travel Rule compliance under heightened scrutiny by the FIC and international correspondent banks.

Practically, Travel Rule compliance requires a CASP to collect and transmit – or receive and verify – the originator's name, account number, physical address or national identity number, date of birth, and the beneficiary's name and account number, whenever a transfer meets or exceeds the applicable threshold. The precise threshold is set by FIC guidance and should be verified against current published rules rather than relied upon as a static figure.

The technology layer matters. South Africa does not mandate a single Travel Rule solution provider. A CASP must implement a protocol – whether that is TRP, TRISA, Sygna or a bilateral arrangement – that is compatible with its counterparties. In our practice, we have seen onboarding programs that fully satisfy the identity-verification requirements of FICA but fail Travel Rule obligations because the back-end transfer infrastructure has no counterparty-data transmission capability. The two layers must be built and tested together.

For cross-border transfers involving the South African rand or South African-resident counterparties, there is a second layer: South Africa Exchange Control regulations administered by the South African Reserve Bank (SARB). SARB has issued guidance on the treatment of crypto asset transfers under exchange control, and a CASP routing cross-border value through South African banking rails needs to satisfy both FICA's Travel Rule-equivalent requirements and SARB's capital-flow reporting obligations simultaneously.

How does South African KYC interact with cross-border tax and banking?

For a business structured outside South Africa but serving South African clients, the compliance interaction runs in three directions: FICA KYC obligations, SARB exchange control, and the tax obligations of clients under the South African Revenue Service (SARS) regime. None of these layers can be addressed in isolation.

South African banks have, in recent years, taken a cautious approach to correspondent relationships with crypto businesses. The FATF Grey Listing exacerbated this: international correspondent banks applied enhanced due diligence to all South African counterparties, which in practice meant that South African-domiciled CASPs faced heightened banking scrutiny on top of the structural reluctance many banks already showed toward crypto clients. An inbound CASP that has not addressed its transaction monitoring, Travel Rule and RMCP documentation before approaching a South African banking partner will encounter a closed door.

From a tax perspective, SARS treats crypto assets as assets of an intangible nature. Gains are taxable – either as capital gains or revenue income depending on the nature of the trading – and SARS has issued guidance clarifying that crypto receipts must be disclosed. For an offshore CASP whose clients are South African tax residents, there is a practical risk that SARS will seek information about client balances and transaction histories through exchange-of-information mechanisms. An operator whose KYC and records do not support a compliant response to such a request is exposed on two fronts simultaneously.

The banking angle also affects onboarding directly. South African-domiciled clients will typically fund accounts through the domestic banking system, which means the CASP will receive Rand-denominated deposits subject to SARB's financial surveillance rules. The FICA onboarding program must be capable of verifying whether the source of funds is consistent with the client's exchange control allowances – particularly the single discretionary allowance and the foreign investment allowance available to South African residents.

What did South Africa's FATF Grey Listing mean for CASPs?

South Africa's placement on the FATF Grey List in February 2023 signaled that its AML/CFT regime had material deficiencies, with virtual asset supervision among the identified gaps. The practical effect on operating CASPs was immediate and multi-layered.

International correspondent banks applied enhanced due diligence to South African entities across the financial sector, including crypto businesses. For CASPs trying to maintain USD, EUR or GBP settlement accounts through South African entities, the cost and friction of banking relationships increased materially. Several operators we are aware of moved operational entities to alternative jurisdictions while retaining client-facing infrastructure in South Africa – a structure that itself creates layered compliance obligations rather than eliminating them.

The Grey Listing also accelerated the FSCA's timeline for CASP licensing and the FIC's scrutiny of RMCP quality. Operators who had operated in a registration-only regime under earlier FICA provisions faced an effective compliance upgrade requirement: move to CASP authorisation, produce a robust RMCP, appoint a qualified MLRO and demonstrate Travel Rule capability. Businesses that did not move quickly found their banking relationships under review.

South Africa subsequently made significant legislative and supervisory reforms to address the identified deficiencies. Progress was acknowledged by FATF, and observers anticipated potential removal from the Grey List contingent on sustained implementation. Operators should verify the current status of South Africa's FATF standing through FATF's published documentation before relying on any description of the current position.

In a recent compliance matter, a digital-asset payments company with a South African client base had allowed its FIC registration to lapse during the period of transition to CASP authorisation. We worked with allied counsel in South Africa to regularize the FIC status, reconstruct the RMCP to FSCA standard and negotiate a corrective undertaking before the banking relationship was formally terminated. The outcome was the retention of the account and a fully documented compliance program – completed within a matter of weeks once the correct sequence was followed.

If a prior application stalled, a licence lapsed or a banking relationship came under pressure, a structured review can identify the root cause. Write to OBOLUS at info@oboluslaw.com or reach us at t.me/oboluslaw. Map your options.

Who must act as MLRO for a South African CASP?

Every CASP that is an accountable institution under FICA must designate a compliance officer responsible for the RMCP, AML/CFT obligations and FIC reporting functions – a role that in international practice corresponds to the Money Laundering Reporting Officer (MLRO). The FIC requires that this person holds sufficient seniority, independence and technical competence to discharge the function.

For an internationally structured business with no South African entity, the MLRO question is more complex. The FSCA will want to understand who is responsible for the South African compliance function, and a generic group compliance officer based offshore who has no South African qualification or experience is unlikely to satisfy the regulator's expectations in practice. In our practice, we regularly advise inbound operators to appoint a local compliance officer or to retain South African counsel with the necessary expertise on a managed-service basis until the business has sufficient scale to justify a dedicated headcount.

The MLRO is also responsible for filing suspicious transaction reports (STRs) and cash threshold reports (CTRs) with the FIC. The thresholds and filing mechanics are set by FIC guidance and should be verified against current rules. An MLRO who does not have access to real-time transaction data from the CASP's platform cannot discharge this function effectively – which is why the RMCP, the transaction monitoring system and the MLRO appointment must be integrated from the start of the onboarding program build, not layered on afterward.

How should an inbound operator build a compliant KYC program for South Africa?

Building a compliant KYC and onboarding program for the South African market requires five elements working together: a current-state regulatory mapping, a documented RMCP, a technology stack that covers identity verification and Travel Rule transmission, an appointed MLRO with appropriate competence, and a testing and audit protocol.

The regulatory mapping must address whether the operator requires CASP authorisation from the FSCA, FIC registration as an accountable institution, SARB exchange control compliance for cross-border flows, and any SARS-driven client information obligations. These are separate, parallel requirements – satisfying one does not discharge the others.

The RMCP is the document that ties the program together. It describes the business, identifies the client risk categories, sets out the due diligence procedures for each category, defines escalation and STR filing triggers, and documents the governance and oversight structure. The FSCA and FIC both treat the RMCP as the primary audit document. A technology-first operator that has invested in strong KYC tooling but has not produced a written RMCP will fail the first regulatory inspection.

Technology selection should be driven by the operator's client base. A primarily retail exchange needs a consumer-grade identity verification system integrated with South African ID document formats and real-time FICA screening. An institutional-facing custodian or OTC desk needs a corporate due diligence workflow capable of handling complex beneficial-ownership structures across multiple jurisdictions. In both cases, the Travel Rule layer must be implemented before the first qualifying transfer is processed – not as a subsequent upgrade.

Testing and audit should occur before the first client is onboarded, not only in response to a regulatory inquiry. A pre-launch compliance audit conducted by counsel familiar with the FSCA's current examination priorities will identify gaps at the lowest possible cost. Operators we advise routinely find that the gap is not in the KYC tooling itself but in the linkage between the tool's output and the RMCP's documented risk thresholds – a structural issue that only a legal review of the whole system can surface.

Which operator profile should build which KYC structure for South Africa?

Different operator profiles face different South African compliance obligations, and the structure should follow the profile.

A retail exchange with South African resident clients is likely the highest-friction profile. It requires CASP authorisation from the FSCA, full FIC registration as an accountable institution, a consumer-grade KYC onboarding flow with South African ID verification capability, Travel Rule infrastructure for all qualifying outbound transfers, and an MLRO capable of managing daily STR and CTR obligations. The timeline to build this program from scratch – assuming all documentation, technology and personnel decisions are made promptly – is typically measured in months, not weeks. A business in this category that is not already compliant is operating at material regulatory risk.

An institutional OTC desk or custodian with South African corporate clients faces a somewhat different profile. KYC obligations are corporate due diligence rather than consumer identity verification, beneficial-ownership tracing is more complex, and transaction volumes may be lower but values higher. The Travel Rule obligation is identical in kind, and the MLRO function is more demanding in terms of the technical sophistication required. The cross-border interaction with SARB exchange control and SARS is more acute for this profile because the individual transactions are larger and more visible to both regulators.

An offshore entity with incidental South African clients is the profile most likely to underestimate its exposure. If the entity does not actively market into South Africa, does not accept Rand deposits and does not hold South African client assets, there is an arguable case that FSCA authorisation is not required – but that case must be documented and defensible, not simply assumed. The FIC's accountable-institution designation follows the client base, and a non-South African entity with a material South African client segment is at risk of being treated as an unregistered accountable institution if it has not taken a position and maintained records to support it.

A common assumption is that a single offshore VASP or CASP licence covers all markets globally. It does not. The FSCA's regulatory perimeter is defined by the location of clients and the nature of the service, not by the entity's home jurisdiction. An operator with a MiCA-compliant structure in the EU, a Singapore Payment Services Act licence and a BVI legal entity may still require CASP authorisation in South Africa if it actively serves South African clients. Managing the interaction between those regimes is where experienced cross-border counsel adds the most value.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, drawn from FATF Recommendation 16, requires a virtual asset service provider to collect and transmit – or receive and verify – identifying information about the originator and beneficiary of a virtual asset transfer whenever the transfer meets or exceeds the applicable threshold. Required data typically includes the originator's name, account identifier, address or national identity number, and date of birth, together with the beneficiary's name and account identifier. In South Africa, the FIC's guidance on virtual asset transfers implements this requirement, and CASPs must have technical infrastructure in place to transmit and receive the data rather than simply collecting it at onboarding. The precise threshold and technical requirements should be verified against current FIC published rules.

Who must act as MLRO for a crypto firm?

Under FICA, every accountable institution – including a CASP – must designate a compliance officer with sufficient seniority, technical competence and independence to manage the AML/CFT function, file suspicious and cash-threshold reports with the FIC, and maintain the risk management and compliance program. In international practice this role is equivalent to the MLRO. The FSCA expects the CASP to identify this person as part of the authorisation process. For an internationally structured operator, a group compliance officer based offshore is unlikely to satisfy the FSCA's expectations without South African experience or local supporting counsel. The compliance officer must have real-time access to transaction data to discharge reporting obligations effectively.

How do regulators audit crypto AML programs?

Both the FSCA and the FIC conduct examinations of CASPs that focus primarily on the documented risk management and compliance program, the quality of customer due diligence records, the effectiveness of transaction monitoring, and the timeliness and completeness of suspicious transaction reports. Regulators typically request the RMCP, a sample of client files across different risk categories, transaction monitoring logs and escalation records, and evidence that the Travel Rule infrastructure is operational. A CASP whose onboarding technology is sound but whose RMCP is generic or underdocumented will receive adverse findings. The surest preparation for a regulatory examination is a pre-examination legal review that stress-tests the RMCP against the regulator's current examination priorities.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, KYC and Travel Rule compliance programs that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so structural gaps surface before they become enforcement events. Our disputes team also coordinates freezing relief and on-chain tracing across leading common-law forums when assets are at risk. Digital assets are the whole of our practice. To discuss your South African compliance position, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, Travel Rule implementation and VASP/CASP licensing across African and European regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours