AML Compliance for Africa's Fintechs as Crypto Rules Tighten
Global AML Regulatory Updates - VASP & Crypto AML

AML Compliance for Africa’s Fintechs as Crypto Rules Tighten

Africa’s mobile payments market is set to reach $198.8 billion in 2026. The continent accounts for roughly 74% of global mobile-money transaction volume, according to BCG. Fintech revenues across the region could hit $65 billion by 2030, according to a BCG report published earlier this year. That growth is attracting global investors, new customers and regulatory attention in equal measure. For fintechs operating in this environment, AML compliance is no longer a post-launch box-ticking exercise. It is increasingly central to sustainable growth and access to regulated financial services.

Nigeria, Kenya and Ghana have introduced significant new virtual-asset regulatory frameworks in the past twelve months. South Africa took a different path. It continues to operate its crypto asset service provider (CASP) licensing regime under the Financial Advisory and Intermediary Services Act, 2002 (FAIS Act). At the same time, Nigeria and South Africa left the FATF grey list in October 2025 after completing their action plans. Both countries must now sustain and show that their AML/CFT reforms are working. The rules vary by business model. Not every fintech is a VASP. VASP and CASP rules differ by country and by the type of activity. This article explains what these changes mean for fintechs and VASPs in Africa. It also covers what steps firms should take now.

Notably, the examples below focus on selected African markets where significant virtual-asset regulatory developments have occurred recently; requirements in other African jurisdictions may differ.

Key AML compliance areas for African fintechs

Compliance area Key requirement Why it matters
VASP licensing Licensing or registration with the relevant national regulator, based on the firm’s activities and country Firms that operate without a licence risk enforcement action and may face difficulties maintaining access to banking services
KYC and CDD Risk-based customer checks at onboarding and throughout the relationship Weak KYC/CDD controls remain a recurring supervisory concern
Travel Rule Sender and receiver details must be collected, held and shared in line with FATF standards and local rules FATF continues to push for effective implementation and reports significant gaps across jurisdictions
Transaction monitoring Risk-based transaction monitoring using automated or manual controls suited to the firm’s volumes and risk Controls must match the firm’s risk level and transaction volumes
Independent AML assurance Independent review or testing of AML/CFT controls, where appropriate or required. Independent assurance can provide documented evidence of control effectiveness and support management oversight and regulatory engagement

Why AML compliance for Africa’s fintechs can no longer wait

Africa’s fintech sector is entering what BCG calls its “second wave.” The first wave was dominated by mobile money and payments. The second is expanding into lending, insurance, wealth management and cross-border transfers, among other areas. As a result, these areas can bring new and more complex AML risks than payments alone. AML controls at African fintechs must keep pace.

Growth has outpaced the compliance systems at many firms. Many fast-growing fintechs struggle to scale their compliance teams and controls as their customer base grows. As a result, that gap is becoming harder to ignore. Regulators in several African markets are now pushing for formal licensing and enforcement. International bodies such as the FATF continue to watch closely.

In its most recent targeted update on virtual assets and VASPs, the FATF called for the closing of regulatory gaps. It also noted that illicit finance risks in the sector are becoming more complex. For African fintechs, the message is clear. Build compliance into your growth plan now or risk facing increased regulatory scrutiny and difficulties maintaining access to financial services later.

Nigeria’s cross-sectoral virtual asset regulatory framework

Nigeria has moved aggressively to regulate virtual assets after exiting the FATF grey list in October 2025. President Tinubu signed an Executive Order on Virtual Assets. This established the Virtual Asset Council and Virtual Asset Office. The Council is chaired by the CBN, with the Nigeria Revenue Service and the Securities and Exchange Commission (SEC) as vice-chairs. This coordination body brings together multiple agencies including the CBN, SEC and the Nigerian Financial Intelligence Unit (NFIU).

The framework requires virtual asset businesses to comply with the licensing and AML/CFT rules that apply to their activities under existing laws. These rules can include customer checks, transaction monitoring, suspicious activity reporting and record-keeping. The SEC still runs its VASP framework, including the Accelerated Regulatory Incubation Programme (ARIP). The broader 2026 framework brings these agencies into closer working.

For fintechs, the practical effect is significant. Firms that previously operated in a grey area between the CBN’s earlier crypto restrictions and the SEC’s licensing regime now work within a more coordinated system. However, the existing duties of the SEC, CBN and other agencies remain in place. In addition, firms must run KYC/CDD at onboarding, ongoing monitoring and regular reporting. Firms without the right licence may face enforcement action and difficulties maintaining access to banking services.

Kenya, South Africa and Ghana reshape the VASP regulatory landscape

Kenya gazetted its Virtual Asset Service Providers Regulations 2026 (Legal Notice No. 134 of 2026) in July, putting the licensing framework under the VASP Act 2025 into practice. The regulations cover a range of virtual asset activities, including exchange services, transfer services, custody and wallet provision. VASPs must be licensed and supervised by the right regulator. In particular, the Central Bank of Kenya (CBK) oversees payment-facing activities and the Capital Markets Authority (CMA) covers investment and capital-market activities. AML/CFT controls must meet Kenyan rules, which are based on FATF standards. The rules also apply to offshore platforms that target Kenyan users or earn revenue from them.

South Africa took a different route. The Financial Sector Conduct Authority (FSCA) brought crypto assets under its existing financial services licensing framework under the FAIS Act. As a result, CASPs must obtain the right FSP licence from the FSCA. South Africa’s removal from FATF increased monitoring in October 2025 was followed by its removal from the EU’s corresponding high-risk third-country list in January 2026. The FATF has stressed that countries removed from increased monitoring should sustain and continue strengthening their AML/CFT regimes.

Ghana established a statutory framework for virtual asset regulation through the Virtual Asset Service Providers Act, 2025. During 2026, the SEC and Bank of Ghana have been putting the framework into practice. This includes sandbox testing and the development of activity-specific licensing rules.

Similarly, Mauritius continues to operate its FSC-administered VASP licensing regime under the Virtual Asset and Initial Token Offering Services Act 2021.

Across these countries, regulatory frameworks increasingly provide for formal licensing, AML/CFT controls, customer due diligence and regulatory reporting, although the specific requirements vary by country and activity.

The Travel Rule challenge for African VASPs

The FATF’s Travel Rule (Recommendation 16) applies to VASPs conducting virtual asset transfers. It requires VASPs to obtain, hold and transmit required originator and beneficiary information for applicable virtual asset transfers. In practice, this is hard to do. Smaller VASPs working across borders face particular implementation challenges.

The challenge comes from three directions. First, smaller VASPs may face particular challenges in integrating Travel Rule messaging protocols and maintaining interoperable systems. Second, counterparty identification is difficult when the receiving VASP operates in a jurisdiction without a Travel Rule framework. Third, cross-border mobile-money activity is significant in parts of East and West Africa, while some informal value-transfer channels may operate outside formal regulatory frameworks.

The compliance challenge also varies by transfer type. VASP-to-VASP transactions can leverage emerging messaging protocols. Transfers involving unhosted wallets raise different identification obligations. Mobile money transfers may fall under separate payment system regulations rather than VASP frameworks. Informal value-transfer services can present particular challenges because they may operate outside formal regulatory frameworks.

The FATF’s best practices guidance on Travel Rule supervision makes clear that regulators should take a risk-based approach to enforcement. However, that does not exempt firms from building the systems needed to comply. VASPs that wait for enforcement action before investing in Travel Rule solutions may face increased regulatory scrutiny and difficulties maintaining cross-border financial relationships.

Fortunately, solutions are available. Several Travel Rule technology providers now offer integration options designed for emerging market VASPs, with lower cost structures and API-first architectures. Compliance7 has worked with VASPs on Travel Rule implementation strategies that balance regulatory expectations with operational realities.

Building an AML program that scales with fintech growth

A common mistake among fast-growing African fintechs is treating AML compliance as a static project rather than a living program. A KYC process designed for 10,000 customers may become difficult to operate effectively as the customer base grows to hundreds of thousands. Transaction monitoring rules calibrated for a payments-only business will miss risks when the firm adds lending or cross-border transfers.

Scalable AML programs share several features. These programs use risk-based customer segmentation rather than applying the same level of due diligence to every customer. Monitoring is automated with rules and thresholds that adjust as the business grows. Staff training ensures that compliance is understood across the organisation, not just within the compliance team. Reporting workflows are also built to handle rising SAR volumes without bottlenecks.

AI-powered compliance tools are increasingly relevant here. AI and machine-learning techniques can complement traditional rules-based monitoring by identifying patterns and relationships that may be difficult to capture through static rules alone. Their use, however, requires appropriate governance, validation, monitoring and human oversight. For example, automated screening tools can check customers against sanctions lists, PEP databases and adverse media sources at the speed that fintech onboarding demands. For firms considering these tools, an independent AI AML assurance review can be valuable. It helps assess whether AI-enabled AML controls are appropriately governed, validated and aligned with applicable regulatory obligations.

The key point is that compliance infrastructure must grow alongside the business. Regulators in Nigeria, Kenya and South Africa are moving toward risk-based supervision. Firms with a mature, proportionate AML program are better placed to respond to supervisory reviews. By contrast, firms addressing material control gaps only after an inspection face a much harder conversation.

The role of independent AML assurance in a changing regulatory environment

Nigeria and South Africa were removed from FATF’s increased monitoring list after completing action plans that required significant AML/CFT reforms. Maintaining the effectiveness of those reforms over time is an ongoing challenge. In particular, staff turnover, product expansion and growing transaction volumes can all affect how well controls perform in practice.

An independent AML assurance provides an objective assessment of whether a firm’s AML/CFT controls are working as designed. It can help identify control gaps before they become the subject of regulatory findings. For fintechs operating under new VASP licensing regimes, an independent review may be particularly relevant. It can provide documented evidence of management oversight, control testing and remediation activity that may be relevant during licence renewals and supervisory reviews.

Regulatory expectations increasingly emphasise effective AML/CFT controls, risk-based supervision and demonstrable control effectiveness. In some sectors and jurisdictions, independent testing or review may form part of the broader control framework. The appropriate scope and frequency of independent assurance should therefore be determined by applicable regulatory requirements, the firm’s risk profile and the nature and scale of its activities.

For fintechs and VASPs, the practical step is to schedule independent AML assurance at an appropriate frequency. That frequency should reflect regulatory requirements, risk profile, business complexity and the pace of material changes. Firms that approach independent assurance as an investment in compliance maturity can derive value beyond the immediate compliance assessment, including clearer remediation priorities and stronger management oversight.

What comes next for African fintech compliance

Africa’s fintech sector continues to expand rapidly. In response, regulators are developing frameworks that bring the sector into the formal financial system. For fintechs and VASPs, this shift is ultimately positive. Clearer rules create a more predictable business environment and can support access to banking relationships and global partnerships.

The AML compliance challenge for African fintechs is real, but it is manageable. Firms that invest in scalable AML programs, implement Travel Rule solutions, maintain appropriate independent assurance and stay current with licensing requirements will be well positioned. Those that delay may face enforcement action, increased regulatory scrutiny, difficulties maintaining banking relationships and challenges supporting cross-border activity.

If your fintech or VASP needs help building a compliance program that meets African and global regulatory expectations, book a free consultation with Compliance7.

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Ajith Abraham is a Financial Crime Compliance professional with 12+ years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.