South Africa's Financial Intelligence Centre Act (FICA) – the principal AML/CFT statute – and the country's designation of crypto asset service providers (CASPs) as accountable institutions place a demanding and enforceable compliance architecture on every digital-asset firm with a South African nexus. The Money Laundering and Terrorist Financing Control Regulations issued under FICA, together with the Financial Sector Conduct Authority (FSCA) licensing regime that took effect for CASPs in 2023, mean that the Money Laundering Reporting Officer (MLRO) and the broader compliance officer function are no longer optional roles – they are preconditions for operating lawfully. A firm that appoints the wrong person, documents inadequately, or misreads the scope of South Africa's Travel Rule obligation is exposed to licence suspension, transaction rails being frozen by correspondent banks, and potential criminal referral to the Financial Intelligence Centre (FIC).
This page sets out the regulated basis for the MLRO and compliance officer function in South Africa, the practical requirements that inbound and domestic CASPs must satisfy, the cross-border layer that applies when a firm serves users or holds banking outside the country, and the decision point at which external counsel materially reduces risk.
What is the regulated perimeter for CASPs in South Africa?
South Africa classifies CASPs as accountable institutions under FICA, a step that brings them inside the full AML/CFT supervisory perimeter operated by the Financial Intelligence Centre (FIC) and, for licensed entities, co-supervised by the FSCA. The FSCA formally designated crypto assets as financial products under the Financial Advisory and Intermediary Services Act (FAIS), and a general CASP licence under that regime became mandatory for firms buying, selling, exchanging or administering crypto assets as a business from June 2023 onward. The FIC designation under FICA covers a broader set of activities, including firms that facilitate transfers or provide custody, regardless of whether they hold an FSCA CASP licence.
The practical consequence is a two-layer obligation. First, FICA duties: customer due diligence, record-keeping, transaction monitoring, suspicious-transaction reporting to the FIC, and the appointment of a compliance officer. Second, FSCA duties: fit-and-proper requirements for key individuals, ongoing reporting, and conduct obligations tied to the FAIS framework. A firm that is only FICA-registered but not FSCA-licensed still carries FICA's full compliance architecture. A firm that is FSCA-licensed carries both layers simultaneously.
South Africa's position within the global FATF framework matters here. South Africa was grey-listed by FATF in February 2023, a designation that heightened correspondent-bank scrutiny of South African-linked payment flows and intensified the FIC's own supervisory posture toward newly designated accountable institutions including CASPs. That context is not background detail – it is the reason banks in London, Singapore, and Dubai apply elevated due-diligence checks to South African crypto-related accounts.
Who must act as MLRO, and what does the role require?
Every FICA-regulated accountable institution – including every CASP – must appoint a natural person as its compliance officer, a role functionally equivalent to the MLRO title used in other common-law jurisdictions. The appointment is not merely administrative. FICA sets out specific responsibilities: the compliance officer must ensure the institution complies with FICA, must train staff, must assess the adequacy of internal controls, and must report directly to senior management. The FIC expects that person to be sufficiently senior to exercise genuine oversight authority.
For FSCA-licensed CASPs, the fit-and-proper framework adds a competence threshold. The individual must demonstrate relevant qualifications or experience in AML/CFT, financial services regulation, or a cognate field. The FSCA retains the right to object to or remove a key individual who does not meet the standard. In our practice, we regularly see firms underestimate this requirement – an in-house accountant with no AML background, or a director who doubles as MLRO without dedicated time, will not satisfy the regulator on examination.
The MLRO must implement a written compliance programme that, at minimum, covers a risk assessment of the firm's business model, customer risk profiles, and geographic exposure; a customer identification and verification procedure (KYC); an ongoing monitoring process; a mechanism for staff to escalate suspicious activity internally; and a process for filing suspicious-transaction reports with the FIC within the FICA-prescribed period. Record-keeping obligations run to a minimum of five years from the date of the last transaction or the end of the business relationship, whichever is later – a figure that tracks FATF Recommendation 11 and is reflected in the FICA regulations.
The compliance officer must be physically reachable in South Africa for regulatory purposes, or the firm must demonstrate a governance structure that gives South African authorities equivalent access. Purely offshore nomination with no local presence is a structural deficiency the FIC has signalled it will treat as a breach.
What does the FICA KYC and monitoring programme require in practice?
FICA's customer due diligence requirements mirror the FATF standard: identify the customer, verify identity against reliable independent sources, understand the nature of the business relationship, identify beneficial owners, and apply enhanced due diligence to higher-risk customers. For CASPs, the FIC has clarified that wallet-to-wallet transfers from non-custodial sources must be treated as a risk signal that triggers additional verification, particularly where the on-chain history is unclear or the counterparty wallet is flagged by forensic tools.
Ongoing transaction monitoring is a core expectation. The FIC does not prescribe a specific technology solution, but the supervisory expectation is that the monitoring system is commensurate with the risk profile of the firm's customer base. A CASP serving institutional DeFi participants carries a different risk exposure than a retail exchange, and the monitoring programme must reflect that distinction. In our cross-border practice, we consistently advise that a monitoring framework designed for a single jurisdiction rarely survives unchanged when the same firm adds users in a second market – the risk typologies, threshold rules, and escalation paths need local tuning.
Suspicious-transaction reporting to the FIC is mandatory and non-discretionary once the threshold for a reasonable suspicion is met. The MLRO is the formal filing officer. South Africa maintains a dedicated goAML platform – the FIC's online reporting system – through which reports are filed. Failure to report, or deliberate delay, can trigger both regulatory and criminal consequences under FICA. The MLRO must also maintain a log of internal escalations that did not result in a formal FIC report, demonstrating that the decision not to file was considered and documented.
How does the Travel Rule apply to South African CASPs?
South Africa has implemented the FATF Travel Rule – the obligation to transmit originator and beneficiary data alongside virtual-asset transfers – through the amendments to the Money Laundering and Terrorist Financing Control Regulations under FICA. The rule applies to transfers of crypto assets between CASPs and between a CASP and another obliged entity. The practical de-minimis threshold and the precise data fields required track the FATF standard; however, firms should confirm the current regulatory guidance from the FIC rather than assuming a single global figure applies without qualification.
Implementing the Travel Rule in a South African CASP introduces two practical problems that the compliance officer must address. First, counterparty identification: the sending CASP must identify the receiving VASP and confirm it is a regulated entity before transmitting the data packet. Where the counterparty is in a jurisdiction with no formal VASP registry – or where the receiving address is a self-hosted wallet – the firm must apply its own risk procedures to decide whether to proceed with the transfer. Second, data security: the Travel Rule data packet contains personal data that is also subject to South Africa's Protection of Personal Information Act (POPIA), meaning the MLRO's procedures must integrate with the firm's POPIA compliance programme to avoid creating a new data-protection exposure while solving an AML obligation.
The cross-border dimension is acute. A South African CASP sending funds to a Singapore counterparty must satisfy both South African Travel Rule requirements and any requirements the receiving firm's MAS-regulated environment imposes. A sending CASP to a Dubai-based VARA-licensed firm must similarly align data fields with what VARA expects on the receipt side. The compliance officer who has mapped only the South African requirement has, in practice, mapped only half the obligation. We have seen correspondent-bank suspensions triggered precisely because the Travel Rule data packet was formatted for the South African side but not structured in a way the receiving firm's compliance system could process.
What is the cross-border interaction with banking and tax?
The cross-border layer compounds the domestic compliance obligation significantly. South Africa's grey-listing created a measurable chilling effect on correspondent-bank appetite for South African crypto-related accounts. Tier-1 banks in major financial centres apply enhanced due-diligence requirements, and in some cases refuse to open accounts for entities whose primary business is crypto asset services linked to the South African market. The compliance officer must therefore prepare a compliance package designed not only for the FIC but for the bank's own AML team – a separate audience with a different risk tolerance and a different documentary standard.
From a tax perspective, the South African Revenue Service (SARS) treats crypto assets as assets for income-tax purposes. Gains on disposal are subject either to income tax (where trading is frequent) or capital gains tax (where the holding is investment-grade), and SARS has issued guidance requiring disclosure of crypto-asset holdings and transactions on annual tax returns. The compliance officer is not a tax adviser, but the compliance programme must be structured to produce the transaction records – counterparty details, timestamps, values in South African rand at acquisition and disposal – that SARS expects to see on audit. A gap in the monitoring record is simultaneously an AML problem and a tax-evidence problem.
Exchange-control considerations under the Currency and Exchanges Act and the rules administered by the South African Reserve Bank (SARB) also interact with crypto activity. Transfers of value offshore via crypto assets raise currency-control questions that the compliance officer and the firm's legal advisers must assess. Where a CASP operates a remittance corridor, additional authorisations from the SARB may be required. In our practice, we map this stack – licence, FICA compliance, exchange-control posture and banking relationships – as an integrated unit before a client launches a South African operation, because a gap in any one layer will undermine the others.
For a scoped assessment of your South African CASP compliance structure, contact OBOLUS at info@oboluslaw.com. The compliance architecture and banking relationships for a South Africa-linked entity require coordinated legal and regulatory analysis. A one-jurisdiction view will not hold under scrutiny.
What is the process for an inbound operator setting up a compliant function?
An inbound operator – typically a firm licensed in a hub jurisdiction such as the UAE, Singapore, or an EU member state under MiCA – that wants to serve South African customers or establish a South African presence must complete several sequential steps before the compliance function is live.
First, determine whether the activity triggers FICA accountable-institution status, FSCA CASP licensing, or both. The analysis turns on the nature of the services, the location of the customer-facing entity, and where funds are held. A firm that routes South African customers through an offshore entity but performs customer onboarding from South Africa is almost certainly within scope. The offshore-entity structure does not, by itself, remove the South African regulatory exposure.
Second, appoint the MLRO or compliance officer before commencing activity. The FIC does not accept a retroactive appointment as a remediation step for a firm that has already been operating without one. In practice, the appointment must be documented, the role must be adequately resourced, and a written risk assessment specific to the South African business must exist from day one.
Third, register with the FIC on the goAML system. FICA-designated accountable institutions must formally register. For FSCA-licensed CASPs, the FSCA licence application triggers a parallel supervisory relationship, and the compliance officer's identity and credentials are submitted as part of the licence file.
Fourth, build the compliance manual and operational procedures to the FICA standard – covering customer due diligence, Travel Rule procedures, suspicious-transaction reporting, staff training, and the record-keeping architecture. This manual is a live document; the FIC and FSCA expect it to be updated when the firm's risk profile or product set changes.
Timelines for establishing this function vary by the firm's existing infrastructure. A firm that already has a MiCA-compliant compliance framework can adapt much of the substance; the South African specifics – FIC registration, POPIA integration, exchange-control mapping, rand-denominated record-keeping – require targeted work that typically runs to several weeks of legal and operational engagement.
A practical illustration
In a recent matter, a payments technology company operating under a major-payment-institution licence in Southeast Asia sought to extend its stablecoin transfer corridor to South African business customers. Initial advice from a single-jurisdiction adviser had suggested that the existing VASP compliance framework was sufficient. On review, we identified three gaps: the MLRO appointment had not been formalised for South African purposes under FICA, the Travel Rule data fields being transmitted did not align with FIC expectations, and the firm's banking relationships routed settlement through a correspondent that had implemented elevated screening for South African counterparties following the FATF grey-listing. We restructured the compliance function, documented the MLRO appointment with a South Africa-specific remit, revised the Travel Rule operational procedures to satisfy both MAS and FIC requirements, and prepared a compliance package for the correspondent bank. The corridor launched in the following quarter without a banking suspension.
What are the most common compliance mistakes South African CASPs make?
The most costly compliance failure is the appointment of a nominal MLRO – a director or CFO who carries the title but lacks the time, authority, or specialist knowledge to exercise genuine oversight. The FIC's examination process probes the compliance officer directly: what is the risk assessment methodology, how are suspicious transactions escalated, what training has been given, when was the compliance programme last reviewed? A nominal appointee will not survive that examination.
A second common error is treating the FICA obligation as separate from the FSCA licensing obligation and the POPIA data-governance framework. The three regimes operate on overlapping datasets and overlapping timelines. A compliance officer who manages them in separate silos creates inconsistency that regulators identify quickly – for example, a suspicious-transaction report that contains customer data the firm's POPIA programme designates as a restricted category, or a KYC record that is retained for FICA purposes but deleted under a POPIA retention schedule before the FICA five-year minimum has run.
A third error is failing to account for the grey-listing context in the firm's ongoing banking risk assessment. The compliance programme must not only satisfy South African regulators; it must be legible and credible to the AML teams of foreign correspondent banks. That requires a compliance dossier pitched at the international standard, not simply one that satisfies the minimum domestic requirement.
Does an offshore licence remove the need for South African FICA compliance?
A common assumption is that a VASP or CASP licence obtained in an offshore centre – Dubai, Cayman, BVI, or an EU member state – satisfies all compliance requirements globally and removes the need for separate South African registration. That assumption is incorrect and, where relied upon to avoid FICA compliance, potentially criminal.
FICA's accountable-institution designation follows the activity and the customer, not the corporate structure. If a firm provides crypto asset services to customers who are in South Africa, or processes transactions through South African infrastructure or banking, the FIC takes the position that FICA applies. An offshore entity structure changes the corporate form but does not change the underlying activity analysis. The FSCA takes a comparable position for CASP licensing: the question is whether a service is being provided in South Africa, not where the entity is incorporated.
For a firm operating a genuinely offshore model – where no South African customers are onboarded, no South African banking is used, and no South African operations are conducted – the analysis may differ. But the burden of demonstrating that clean separation sits with the firm, and the consequences of miscalibrating it are significant. We map that boundary as a specific legal question before any client relies on it.
If your compliance structure was built for a different jurisdiction and you now have South African exposure, a targeted review is the priority. Contact OBOLUS at info@oboluslaw.com or via t.me/oboluslaw to discuss a scoped assessment.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – end-to-end FICA, FATF and cross-border AML programme design for CASPs
- MLRO and compliance officer function in Japan under FSA and JVCEA – how Japan's self-regulatory AML layer interacts with cross-border obligations
- Legal counsel for NFT platforms – licensing, AML and FICA exposure for NFT-adjacent digital-asset businesses
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 and implemented in South Africa through FICA regulations – requires that a VASP transmit originator and beneficiary information alongside a virtual-asset transfer to a counterparty VASP. The required data typically includes the originator's name, account identifier and address, and the beneficiary's name and account identifier. The obligation applies to transfers above the applicable de-minimis threshold; below that threshold, reduced data requirements generally apply. The compliance officer is responsible for building and operating the operational process that captures, transmits, and receives this data at the point of transfer.
Who must act as MLRO for a crypto firm?
Under FICA, every accountable institution – including every CASP – must appoint a natural person as compliance officer, which is the functional equivalent of an MLRO. That person must be sufficiently senior to exercise genuine oversight, must have demonstrable AML/CFT competence, and must be accessible to the FIC. For FSCA-licensed CASPs, the individual is also subject to the FSCA's fit-and-proper assessment. The role cannot be outsourced in its entirety; a third-party compliance consultant may support the function, but a named internal individual must hold the appointment and carry the accountability.
How do regulators audit crypto AML programs?
The FIC conducts supervisory examinations of FICA accountable institutions, including CASPs, through a combination of desk-based document reviews and on-site inspections. Examiners typically request the firm's risk assessment, compliance manual, KYC records for a sample of customers, transaction-monitoring logs, and records of suspicious-transaction reports filed and internal escalations resolved without a report. The FSCA's supervisory process for licensed CASPs covers similar ground, with additional focus on key-individual competence and conduct obligations. A firm that cannot produce contemporaneous documentation for each element of its compliance programme will not satisfy either supervisor.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, compliance, and banking stack across operating, custody, and payment layers before you commit to a structure – so the architecture holds under supervisory scrutiny from day one. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme design and VASP compliance requirements across African and emerging digital-asset regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.