Operating a digital-asset business in South Africa without the correct VASP (virtual asset service provider) authorisation now exposes the business to enforcement action, banking termination and reputational damage that is difficult to reverse. The Financial Sector Conduct Authority (FSCA) formally declared crypto assets a financial product under the Financial Advisory and Intermediary Services Act – commonly called FAISA – with effect from late 2022, bringing exchanges, custodians and intermediaries inside the supervised perimeter for the first time. Any business operating in this space, whether incorporated in South Africa or serving South African clients from offshore, must understand what the regime now requires and where the structural exposure sits.
What Is the Legal Basis for VASP Licensing in South Africa?
South Africa's VASP licensing regime rests on the FSCA's declaration of crypto assets as a financial product under FAISA, obliging any entity that provides financial services in relation to crypto assets to hold a Financial Services Provider (FSP) licence. The declaration took effect in late 2022, and the FSCA subsequently issued guidance requiring existing crypto-asset businesses to apply for authorisation within a defined transition window. New entrants must be authorised before commencing regulated activity. Separately, the Financial Intelligence Centre (FIC) supervises crypto-asset businesses as accountable institutions under the Financial Intelligence Centre Act, imposing AML/CFT registration, customer due diligence and the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) across the industry.
The two pillars – FSP authorisation under FAISA and FIC registration under the FIC Act – operate in parallel. A business needs both. Holding one but not the other does not constitute compliance. In our practice, we have seen businesses that completed FIC registration in good faith while overlooking the FSP authorisation requirement; the gap was identified only when a banking partner conducted its own due-diligence review.
Which Businesses Need a Crypto-Asset FSP Licence?
Any person who, as a regular feature of business, provides financial services relating to crypto assets to South African clients must be licensed – regardless of where the entity is incorporated. The FSCA's jurisdiction attaches to the point of service delivery, not solely to the place of incorporation. Affected business models include crypto-asset exchange operators, over-the-counter (OTC) desks, custodians, portfolio managers, financial advisers and intermediaries dealing in crypto assets. White-label platforms that carry a South African user base inherit the same obligation as a locally incorporated operator.
Offshore entities that market to South African residents or direct them to a platform are not automatically exempt. The FSCA has signalled an expansive reading of what constitutes "financial services" in the South African market, consistent with the general FAISA extraterritorial enforcement posture. Businesses that route clients through an offshore entity to avoid local authorisation carry meaningful residual risk.
A practical note on category: under the FAISA regime, the FSP licence is segmented by category – the category relevant to most crypto-asset businesses covers intermediary services and advice in relation to a financial product. The applicable category must be identified precisely before the application is filed; an incorrect category leads to a defective authorisation that does not cover the actual activity.
For a scoped assessment of your entity's position under South African law, the analysis above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements – change the analysis. Map your options with the OBOLUS licensing desk before committing resources to a filing.
How Does the FSP Authorisation Process Work in Practice?
The FSP authorisation process is administered by the FSCA and proceeds in structured stages, each with documentary requirements that are more demanding than many applicants anticipate. The process begins with a fit-and-proper assessment of the key individual – the natural person responsible for the business who must meet qualifications, experience and honesty-and-integrity standards set out in the applicable conduct standard. The key individual must be identified and named in the application.
The application itself requires a detailed description of the business model, the financial products in relation to which services will be provided, the operational and compliance arrangements, and evidence of the financial soundness of the applicant. The FSCA has authority to request additional information, and incomplete submissions extend the review materially. Our experience is that applications filed without prior engagement with the regulator's expectations – and without a well-structured compliance manual – generate information requests that can add months to the timeline.
Once submitted, the FSCA reviews the application and either grants conditional authorisation, requests further information or declines. Conditional authorisation typically carries post-licensing obligations: the business must maintain ongoing compliance, submit periodic reports and notify the FSCA of material changes. The FIC registration process runs on a separate track and must be completed concurrently; it requires the business to identify its compliance officer, implement an AML/CFT programme and register on the FIC's goAML platform.
Timeline is an important operational variable. The FSCA does not publish a fixed statutory processing period for crypto-asset FSP applications at this stage of the regime's maturity. From initial filing to authorisation, the process typically spans a number of months and depends heavily on the quality of the initial submission and whether information requests arise. New-entrant applicants should plan for a runway that is longer than the minimum.
What Are the AML and Travel Rule Obligations for South African VASPs?
South African crypto-asset businesses registered with the FIC are accountable institutions subject to the full suite of AML/CFT obligations under the FIC Act, aligned with FATF Recommendations – including Recommendation 15, which extends the risk-based approach and Travel Rule requirements to virtual asset service providers. The Travel Rule requires that originator and beneficiary information accompany crypto-asset transfers above a defined threshold; in South Africa, the applicable threshold and technical implementation standards continue to be refined as the regime matures.
In practice, this means a VASP must implement a customer identification and verification programme, conduct ongoing monitoring, apply enhanced due diligence to higher-risk customers and counterparts, and have a documented process for filing suspicious transaction reports with the FIC. The Travel Rule imposes an additional data-collection and transmission obligation on the sending and receiving sides of a transaction. Businesses that rely on manual processes or legacy onboarding systems will find compliance burdensome at scale.
One area we monitor closely: the FIC's supervisory posture toward offshore VASPs receiving funds from South African residents. A transfer chain that touches a South African accountable institution at any point brings the Travel Rule data obligation into play, even if the originating platform operates outside the country. Cross-border transaction flows require compliance architecture that maps the accountable-institution status of each counterpart in the chain.
How Does South African Exchange Control Interact With a VASP Business?
South Africa operates a formal exchange control regime administered by the South African Reserve Bank (SARB). For a VASP business, this creates an additional compliance layer that has no direct parallel in most offshore crypto-licensing jurisdictions. Crypto-asset transactions that involve the movement of value across the South African border engage the exchange control framework. Residents moving funds offshore via a crypto-asset platform may require SARB approval or must operate within their annual discretionary and investment allowances. The VASP, as the facilitating platform, is expected to have controls that identify and flag cross-border flows.
The exchange control dimension directly affects banking relationships. South African banks assess VASP clients against both their own risk appetite and the exchange control compliance posture of the business. A VASP that cannot demonstrate a coherent exchange-control compliance programme is unlikely to open – or retain – a South African banking relationship. In our cross-border practice, the banking layer and the licensing layer must be structured together; a licensed VASP with no banking solution is operationally inert.
For an inbound operator – a business incorporated outside South Africa that seeks to serve the South African market – the cross-border structure involves decisions about whether to establish a local subsidiary, appoint a local representative and how to route the banking. Each path has different exchange-control, tax and regulatory implications. The decision cannot be made on the licensing variable alone.
What Is the Recommended Path for an Inbound Business Entering South Africa?
For a business incorporated in a well-regulated offshore jurisdiction – say, a MiCA-authorised CASP in an EU member state, or a MAS-licensed digital payment token service in Singapore – entering the South African market typically requires a local authorisation. The offshore licence does not passport into South Africa. The FAISA regime applies on the basis of where services are delivered to clients, not where the operator is supervised.
We have advised businesses in this position to consider three structural paths:
Path A – Local subsidiary: incorporate a South African company, apply for an FSP licence in the subsidiary's name, register the subsidiary as a FIC accountable institution and open a local banking relationship. This path gives the fullest operational footprint and the clearest regulatory standing. The key-individual requirement must be satisfied by a locally qualified individual. Timeline is driven by the FSP authorisation process.
Path B – Representative arrangement: engage a licensed South African FSP as an intermediary or representative to front the client relationship while the offshore entity provides the underlying service. This model reduces the direct regulatory burden on the offshore entity but introduces contractual, liability-allocation and ongoing supervision considerations that must be managed carefully.
Path C – Structured market withdrawal or limitation: for businesses that cannot satisfy the South African authorisation requirements in the near term, the most defensible position is to geo-block South African access, cease active marketing to South African residents and document the decision. This reduces enforcement risk while a proper licensing timeline is developed.
Profile matching matters. A business with a large existing South African user base should follow Path A or an accelerated version of it. A business testing market appetite with a small cohort has more room to consider Path B as a transitional arrangement. No single path is universally correct.
A Cross-Border Licensing Scenario in Practice
In a recent matter, a London-headquartered crypto-asset intermediary with a growing book of South African institutional clients engaged us after its banking partner flagged the absence of a local FSP authorisation. The business had operated under the reasonable – but incorrect – assumption that its FCA registration provided adequate regulatory cover for the South African portion of its business. We conducted a regulatory mapping exercise, identified the dual FSP/FIC gap, and structured a path that included establishing a local subsidiary, filing for FSP authorisation with a fully prepared compliance manual, and concurrently registering the entity as a FIC accountable institution. The banking relationship was preserved during the authorisation process through a documented transition plan shared with the bank. The authorisation was obtained in the subsequent quarter.
How Should a Business Decide Whether South Africa Fits Its Licensing Strategy?
South Africa is a significant market. It has one of the highest rates of crypto-asset adoption on the African continent, a maturing regulatory regime with FATF alignment, and a banking sector that – while cautious – is engaging with the VASP category more constructively as the authorisation regime matures. For a business with a genuine commercial footprint in the country, the cost of non-compliance is now asymmetric: enforcement action, banking termination and civil liability exposure all carry consequences that dwarf the cost of a proper licensing programme.
The decision framework we apply with clients turns on three axes: (1) the scale and nature of the South African user base – is it incidental or core to the business plan?; (2) the availability of a qualified key individual; and (3) the exchange-control and banking solution. If all three are workable, local authorisation is generally the right answer. If the key-individual requirement is a structural obstacle, the representative-arrangement path may serve as a bridge. If the banking solution is unavailable, the licensing decision should be deferred until that layer is resolved – a licence without a banking relationship does not constitute a viable operating entity.
A common assumption we encounter is that a single well-regulated offshore licence – a MiCA authorisation, a Singapore DPT licence – is sufficient to serve clients globally, including South African clients. That assumption is incorrect. The FAISA regime is territorial, and the FSCA enforces on the basis of service delivery. Allied counsel in the relevant jurisdiction can assist with local key-individual requirements and regulatory correspondence where that is needed.
If your South African exposure has grown beyond what your current licence covers, a prior structure may need reconsideration. A second-read engagement can surface the structural gap and the route forward. Map your options at info@oboluslaw.com.
Related Practices at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we map the full licence stack across operating, custody and payment layers for a multi-jurisdiction build
- VASP Licence Application in El Salvador – comparing El Salvador's Bitcoin-era regime for operators considering a Latin American entry point
- Tax Regime for Digital Assets in Cayman Islands – how the Cayman tax-neutral environment interacts with a multi-hub licensing structure
FAQ
How long does a crypto licence take to obtain?
In South Africa, the FSP authorisation process for crypto-asset businesses does not carry a fixed statutory timeline at the current stage of the regime's maturity. From initial filing to grant of authorisation, the process typically spans several months. Preparation quality is the largest variable: a well-structured application with a complete compliance manual and a qualified key individual generates fewer information requests and moves faster. Businesses should build a materially longer runway than the technical minimum into their operational plan.
Which jurisdiction is best for licensing my crypto business?
There is no single correct answer. The optimal jurisdiction depends on the operator's client base, product type, banking requirements and operational capacity. A business serving South African clients will generally need a South African FSP authorisation regardless of where it also holds an offshore licence. MiCA authorisation, a Singapore DPT licence or a VARA approval in Dubai each serve different market strategies. We map the full licence stack – not the licence in isolation – because the jurisdictional choice interacts with tax, exchange control and banking in ways that change the total cost and risk profile.
Do I need a separate custody licence?
In South Africa, custody of crypto assets on behalf of clients is treated as a regulated activity under the FAISA framework when it forms part of a broader financial services offering. Whether a separately scoped authorisation is required depends on how the custody activity is structured relative to the primary FSP licence category. In many major licensing jurisdictions – including Singapore under the Payment Services Act and Abu Dhabi under the FSRA regime – custody is a discrete regulated activity requiring its own authorisation. The answer is jurisdiction-specific and product-specific; businesses should confirm the custody question as part of the initial regulatory mapping, not as an afterthought.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is one you can operate, bank and defend. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound licensing strategy and regulatory mapping across African and Asia-Pacific digital-asset regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.