Africa’s Crypto Travel Rule Tightens as Regulators Push Exchanges to Identify Users
Africa’s cryptocurrency market is entering a more demanding compliance phase as regulators across major financial centres move to make transaction traceability a condition of doing business. At the...
Africa’s cryptocurrency market is entering a more demanding compliance phase as regulators across major financial centres move to make transaction traceability a condition of doing business.
At the centre of the shift is the Financial Action Task Force’s Travel Rule, which applies FATF Recommendation 16 to virtual asset transfers. It requires virtual asset service providers, or VASPs, to collect and transmit identifying information about the originator and beneficiary of qualifying transactions. The aim is straightforward: make it harder for criminals to move illicit funds through crypto networks without leaving an identifiable trail.
But describing the rule as uniformly “strictly enforced” across South Africa, Kenya, Nigeria and Ghana would be too broad. The four markets are moving at different speeds, under different legal frameworks, and with different levels of implementation.
South Africa is currently the clearest example of the Travel Rule becoming an operational compliance requirement.
The Financial Intelligence Centre’s Directive 9 requires crypto asset service providers to implement Travel Rule controls. A March 2026 FIC communication confirmed that the rule applies at a zero threshold to crypto asset transfers conducted during a business relationship. In practical terms, that means CASPs cannot simply build their compliance system around large transactions and ignore smaller transfers.
The requirement goes beyond collecting a customer’s name when an account is opened.
CASPs must obtain, hold and transmit prescribed information concerning the originator and beneficiary. South African guidance also expects the information to accompany the transfer before or at the same time as the transaction. A post transaction data submission is not an acceptable substitute.
The FIC’s position effectively creates a “no data, no transfer” compliance problem for crypto businesses. Where required information is missing or incomplete, a CASP needs procedures for deciding whether the transaction should be executed, suspended, rejected or returned. That changes the compliance burden considerably.
An exchange now needs systems capable of identifying the counterparty, capturing the relevant customer information, transmitting it securely, screening the parties and retaining an auditable record of what happened.
The technology therefore becomes part of the compliance control.
South Africa is also moving on another front. In August 2026, the National Treasury and South African Reserve Bank released draft rules dealing with cross border crypto transfers. Under the proposed framework, transfers from authorised South African providers to offshore entities or non-custodial wallets would become reportable to the Reserve Bank’s Financial Surveillance Department. The proposal is aimed partly at preventing crypto from becoming a route around South Africa’s existing foreign exchange and capital flow controls.
Kenya is taking a broader legislative route.
The Virtual Asset Service Providers Act, 2025 establishes the legal framework for licensing and regulating VASPs. Kenya’s National Treasury has also published draft VASP Regulations for 2026, covering licensing, governance, AML and counter terrorist financing controls, risk management and cybersecurity.
That places Travel Rule compliance within a much wider regulatory architecture.
For Kenyan exchanges and other VASPs, the issue is no longer simply whether crypto transactions can be traced. It is whether the entire business has the governance, licensing, AML controls and technical infrastructure required to operate as a regulated financial service.
Nigeria presents a slightly different picture. FATF’s 2025 targeted update recorded Nigeria as having enacted a Travel Rule framework for VASPs. It also recorded that Nigeria had conducted virtual asset risk assessments and had VASPs within its regulatory and supervisory framework.
That is significant for Nigeria’s compliance industry because it has one of Africa’s largest and most active crypto markets. But implementation should not be confused with perfect enforcement.
The practical challenge is particularly difficult where transactions move between regulated exchanges, peer to peer platforms and self-hosted wallets. A Travel Rule framework is considerably easier to operate when both sides of a transaction are regulated VASPs. It becomes more complicated when one side of the transaction sits outside the regulated financial system.That is where customer identification, wallet attribution, sanctions screening, transaction monitoring and suspicious transaction reporting begin to overlap.
Ghana is also building out its virtual asset regime, but the legal position requires some care.
Ghana’s Virtual Asset Service Providers Act, 2025 provides a statutory foundation for regulating the sector, while the country’s broader policy framework is being developed around AML, consumer protection and financial stability concerns. Recent legal analysis notes that the Travel Rule was not previously directly binding under Ghana’s existing domestic law, even though VASPs were encouraged to follow it in line with FATF standards.
That means Ghana should not simply be placed in the same category as South Africa, where a specific FIC directive has already operationalised the Travel Rule.
The wider direction, however, is clear. African regulators are moving towards a financial system in which anonymity is becoming harder to maintain at the regulated exchange level.
For crypto businesses, this creates a new compliance workload. Know Your Customer procedures can no longer be treated as an onboarding exercise that ends when an account is approved. The information collected at onboarding has to connect with transaction monitoring and Travel Rule processes.
A compliant exchange needs to know who is sending the assets, who is receiving them, whether the receiving institution or wallet can be identified, whether the relevant information is complete, whether either party raises sanctions or financial crime concerns and what action should be taken when the required information is missing.
There is also a data protection problem.
The Travel Rule requires the movement of personal information between financial institutions. That creates a tension between financial transparency and privacy. Exchanges must transmit enough information to satisfy AML requirements without turning sensitive customer data into another security vulnerability.
For African crypto firms operating across borders, the problem becomes even harder.
One jurisdiction may apply a zero threshold. Another may apply a monetary threshold. Another may still be developing its implementation framework. A transaction involving customers and exchanges in several countries can therefore pass through multiple compliance regimes before it reaches its destination.
The FATF itself recognises that implementation remains uneven globally. Its 2025 assessment found significant differences between jurisdictions in legislation, supervision and enforcement of virtual asset controls
That unevenness is not a minor technical problem.
Criminal networks do not need every jurisdiction to be weak. They need to find the weakest point in a chain.
The regulatory response is therefore moving towards greater information sharing, stronger VASP supervision and better visibility of crypto transfers.
For exchanges, the message is becoming harder to ignore. The Travel Rule is not simply another KYC form.
It is a transaction level compliance obligation that reaches into customer identification, sanctions screening, transaction monitoring, data governance, cybersecurity, record keeping and regulatory reporting.
And across Africa, the direction of travel is increasingly clear. Crypto may still move at blockchain speed. Compliance is catching up.



No Comment! Be the first one.