From the journal

South Africa CASP Licensing

Under South African law: When must a crypto-asset service provider obtain authorisation from the Financial Sector Conduct Authority, or FSCA? What category and product authorisations are likely to be required? What transitional exemptions remain relevant? When must the provider register with the Financial Intelligence Centre, or FIC? What ongoing conduct, competence, operational, AML/CFT, payment, and cross-border requirements apply?

Illia ProkopievCo-Founder and CEO23 min read

Summary

South Africa does not presently use a single, freestanding statutory “CASP licence.” In legal form, the commonly described FSCA CASP licence is an authorisation as a financial services provider under the Financial Advisory and Intermediary Services Act 37 of 2002, or FAIS Act, with authorisation for financial services relating to crypto assets. The FSCA’s 2022 Declaration made a “crypto asset” a FAIS financial product.

A person must generally be authorised as an FSP, or act as a representative of an authorised FSP, where, as a regular feature of its business, it gives advice or renders an intermediary service concerning crypto assets. Intermediary service is broad enough to include transaction facilitation, buying or selling, administration, management, servicing, and safekeeping for or on behalf of a client or product supplier.

Authorisation is activity-, category-, and product-specific. It does not authorise every activity described commercially as “crypto.” The current FSCA application form includes crypto-asset product authorisations under Categories I, II, IIA, and III. A non-discretionary exchange, broker, platform, or custodian will commonly require Category I analysis; discretionary management ordinarily points to Category II; Category III applies only where the statutory administrative-FSP model is satisfied.

The special application window from 2023-06-01 to 2023-11-30 was transitional relief for qualifying existing operators. It is not a continuing grace period. A new entrant in 2026 should obtain the required FSCA authorisation before rendering the regulated service. A qualifying timely applicant may remain protected only while its application remains pending and while it complies with all exemption conditions.

FIC registration is a separate, activity-based AML/CFT obligation, not a substitute for FSCA authorisation. Schedule 1 Item 22 of the FIC Act covers five categories of crypto activity performed for or on behalf of a client: fiat/crypto exchange, crypto/crypto exchange, transfers, safekeeping or administration—including instruments enabling control—and financial services connected with an issuer’s offer or sale. Registration is generally required within 90 days after the accountable business commences. Directive 10, effective 2026-07-31, also requires Item 22 CASPs to provide and maintain specified geographic-location information.

The FAIS and FIC perimeters are not identical. A business may fall under both, only one, or neither. Personalised crypto advice can trigger FAIS without necessarily constituting Item 22 activity. Conversely, a person performing a listed Item 22 activity may have an FIC obligation even where the precise FAIS advice/intermediation test is disputed. Schedule 1 Item 12 must also be tested separately where an authorised FSP provides advice or intermediary services concerning the investment of a financial product.

FSCA authorisation requires ongoing honesty, integrity and good standing, competence, CPD, operational ability, and financial soundness. For crypto services, the special regulatory-examination exemption expired on 2025-06-30, and the FSCA has stated that there will be no further extension. The special crypto regime also requires at least six hours of crypto-related CPD per cycle, additional to generally applicable CPD where relevant.

Payment-type crypto intermediaries remain subject to FAIS where they provide advice or intermediary services. The SARB and FSCA currently state that the crypto activity is not, solely for that reason, an activity requiring authorisation under the National Payment System Act. Pure peer-to-peer transactions relying only on decentralised protocols and involving no intermediary or adviser do not currently require FSP authorisation under the regulators’ stated interpretation. Fiat payment rails, client-money flows, system-operator functions, and other payment activities must nevertheless be reviewed separately.

When does FAIS authorisation apply?

Conclusion

FAIS authorisation is required where a person, as a regular feature of its business, provides advice or an intermediary service concerning a crypto asset falling within General Notice 1350 of 2022. The entity must either hold its own FSP authorisation for the relevant category and crypto-asset product class or render the service as a duly appointed representative of an appropriately authorised FSP.

A commercial description such as “exchange,” “wallet,” “broker,” “protocol,” “payments company,” or “technology provider” is not determinative. The legal analysis follows the actual acts performed for clients or product suppliers.

Rule

The 2022 Declaration “declares a crypto asset as a financial product” for purposes of FAIS. Its definition covers a non-central-bank digital representation of value capable of electronic trading, transfer or storage for payment, investment, or other utility, using cryptography and distributed-ledger technology.

FAIS defines an FSP as a person who, as a regular feature of its business, gives advice, gives advice and renders an intermediary service, or renders an intermediary service. Section 7 provides that a person “may not act or offer to act as a financial services provider” without a licence.

“Intermediary service” is functional and broad. It includes acts for or on behalf of a client or product supplier resulting in a transaction, as well as buying, selling, otherwise dealing in, managing, administering, maintaining, servicing, or keeping a financial product in safe custody. Purely factual, objective, administrative, or promotional information without an express or implied recommendation can fall outside “advice,” but another component of the business may still constitute an intermediary service.

The 2026 SARB–FSCA communication confirms the regulators’ position that FAIS can cover administration, safekeeping, trading on behalf of a client, trading platforms, sales, marketing involving regulated advice, and payment-type facilitation where the statutory advice or intermediary-service test is met.

Limitations and counterarguments

A firm may argue that it provides only technical infrastructure or factual information. That position is materially stronger where it does not control keys, hold assets, route or approve transactions, set transaction parameters, receive transaction-linked remuneration, provide client support that influences transactions, or make recommendations. It weakens where the platform is the practical gateway through which the client enters, executes, settles, or manages the transaction.

A decentralised architecture does not itself establish an exemption. The 2026 joint communication addresses direct P2P transactions relying only on decentralised protocols and involving no intermediation or advice. It does not state that every DeFi front end, administrator, operator, foundation, developer, sequencer, validator, or fee recipient is outside FAIS.

A token that is also a security or derivative can trigger the Financial Markets Act or another product-specific regime. The FIC Item 22 definition expressly excludes a security as defined in the Financial Markets Act, while the FAIS analysis may still arise because the token is a different kind of financial product. Product classification must therefore precede reliance on the general crypto-asset rules.

Which FSP category and product authorisations are required?

Conclusion

The applicant must seek authorisation for each relevant FSP category, financial service, and crypto-asset product subcategory. There is no blanket authorisation to conduct all crypto business.

Rule

Board Notice 194 of 2017 establishes five FSP categories:

  • Category I: an FSP that is not Category II, IIA, III, or IV.
  • Category II: discretionary FSP.
  • Category IIA: hedge-fund FSP.
  • Category III: administrative FSP.
  • Category IV: assistance-business FSP.

The current FSCA Form FSP2 includes crypto assets in Categories I, II, IIA, and III. The presence of crypto assets in a form category does not itself establish that the applicant’s model meets that category’s substantive definition.

Application

A conventional exchange, broker, wallet custodian, order-routing platform, or payment-type intermediary ordinarily begins with Category I analysis because it performs non-discretionary advice or intermediary services.

Category II is required where the provider exercises discretion over acquisitions, disposals, portfolio composition, rebalancing, staking allocations, protocol allocation, or similar investment-management decisions for a client. Calling the functionality “automated,” “algorithmic,” “copy trading,” or “smart allocation” does not remove discretion if the provider or its system determines transactions under a client mandate.

Category III should not be selected merely because the business “administers” a platform in an ordinary commercial sense. It applies where the model satisfies the specialised administrative-FSP definition and requirements.

Category IIA is relevant only where the provider acts as a hedge-fund FSP. It is not an ordinary crypto-exchange category.

The licence should identify the actual service and product permissions. The provider should not represent to clients that FSCA authorisation approves tokens, guarantees solvency, validates custody arrangements beyond the licensed scope, or authorises payment-system or cross-border activities.

FAIS permits an application by a person not domiciled in South Africa, but that does not remove the need to satisfy South African governance, operational, key-individual, recordkeeping, supervision, and address requirements.

Limitations

The final category determination requires the client journey, terms of service, discretionary mandate, custody structure, transaction mechanics, and role of each group entity. A group-level conclusion is insufficient where different legal entities provide the interface, custody, execution, advice, market making, and fiat services.

Does the 2023 transitional exemption still permit operation?

Conclusion

Only a qualifying provider that came within the transitional exemption and submitted a complete application during 2023-06-01 through 2023-11-30 may potentially continue to operate under that exemption while its application remains undecided. A new entrant cannot commence regulated activity and then apply retrospectively.

Rule and application

FSCA FAIS Notice 90 of 2022 created a transitional framework for existing crypto financial-services businesses. The prescribed application window ran from 2023-06-01 to 2023-11-30. The FSCA’s current licensing page states that persons and entities must apply for and obtain authorisation before providing regulated financial services.

For a timely applicant, continued operation depends on the precise exemption conditions and continues only until the application is finally approved or declined. It is therefore necessary to verify:

  1. the legal entity that was operating and applied;
  2. the filing date and acknowledgement;
  3. whether the application covered the actual present-day services;
  4. whether any material business-model change occurred;
  5. whether all exemption conditions have been continuously satisfied; and
  6. whether the application has been withdrawn, rejected, declined, or otherwise finally determined.

A withdrawn or declined applicant may submit a new application, but the previous transitional position does not permit it to continue operating while the new application is considered. The ordinary section 7 prohibition applies.

Notice 90 also contains narrow exclusions or exemptions for specified mining and node-operator functions connected with distributed-ledger security or health, and for persons whose financial services relate only to NFTs. These provisions should be applied narrowly. A miner operating an exchange, or an NFT platform also facilitating fungible tokens, cannot treat the entire business as exempt merely because one function falls within the exemption.

Crypto-asset derivatives were already subject to existing financial-market and FAIS frameworks and were not brought wholesale within the transitional protection applicable to the newly declared product class.

Competence transition

The crypto-specific competence exemptions did not permanently waive the ordinary fit-and-proper regime. Notice 25 of 2023 and its amendment required applicable recognised qualifications and crypto-specific CPD. The temporary regulatory-examination relief was extended to 2025-06-30 and has expired. The FSCA’s 2026 update expressly states that no further extension is available.

The crypto CPD condition requires at least six hours per CPD cycle concerning crypto assets. It is additional to generally applicable CPD where the person is already subject to a higher or separate CPD requirement.

Notice 25’s relief concerning §13 of the General Code must be confined to its exact scope and the rendering of crypto-asset financial services. It should not be treated as a general exemption from client-asset, insurance, fidelity-cover, or other requirements applicable to the provider’s non-crypto services.

What must an FSCA application demonstrate?

Conclusion

A CASP application must establish both formal eligibility and a credible, implemented operating model. Policies that merely reproduce statutory language are unlikely to be sufficient. The applicant should demonstrate how governance, people, systems, custody, risk management, financial resources, compliance, and customer treatment function in practice.

Rule

Board Notice 194 requires honesty, integrity and good standing; competence; CPD; operational ability; and financial soundness.

Operationally, an FSP must have “adequate and appropriate human, technical and technological resources,” an effective governance framework, appropriate key individuals, record systems, banking arrangements, and—in applicable cases—separate arrangements for client funds.

Its governance framework must be proportionate to the nature, scale, risk, and complexity of the business and include a business plan, risk management, internal controls, compliance with the FIC Act, and corrective procedures.

Application

A defensible CASP application should ordinarily contain coherent evidence covering the following areas.

Corporate and ownership structure. The applicant should identify shareholders, ultimate beneficial owners, controllers, directors, group entities, related exchanges, liquidity providers, custodians, market makers, intellectual-property owners, and service companies. Intercompany contracts must correspond to the regulatory responsibility allocated to each entity.

Regulatory perimeter memorandum. Each service should be mapped to advice, intermediary service, discretion, custody, administration, payment facilitation, and each FIC Schedule activity. The memorandum should cover every token class and explain why securities, derivatives, deposits, collective-investment interests, or payment products are or are not implicated.

Key individuals and representatives. The application should demonstrate managerial responsibility, crypto knowledge, experience, recognised qualifications, regulatory examinations, class-of-business training, product-specific training, supervision arrangements, and CPD. Nominal appointment of an external key individual without demonstrable capacity to oversee the business is a material risk.

Business plan and financial soundness. The submission should reconcile projected volumes, spreads, fees, custody revenue, staking or yield revenue, outsourcing costs, compliance expenditure, insurance, capital resources, client liabilities, and operational runway. Forecasts should be consistent with the technical and customer model.

Governance and compliance. The applicant should establish decision rights, board oversight, compliance monitoring, complaints handling, conflicts management, product governance, marketing approval, incident escalation, breach reporting, and management information.

Custody and client assets. The application should document private-key generation, wallet architecture, hot/cold storage, signing authority, multi-signature or MPC arrangements, access controls, recovery, omnibus versus segregated wallets, reconciliation, proof of ownership, forks, airdrops, token migrations, lost-key events, insolvency treatment, and client withdrawal controls.

Technology and cyber resilience. Evidence should cover secure development, penetration testing, vulnerability management, change control, privileged access, logging, transaction monitoring, data integrity, backup, disaster recovery, business continuity, incident response, third-party dependency, cloud concentration, and recovery objectives.

Outsourcing. Contracts with custodians, cloud providers, blockchain-analytics vendors, KYC providers, payment processors, liquidity providers, and group companies should preserve access, audit, resilience, data, termination, transition, and regulatory-cooperation rights.

Conduct arrangements. The provider should evidence clear disclosures concerning volatility, custody, fees, spreads, execution methodology, conflicts, market making, token listing, delisting, staking, forks, withdrawal restrictions, insolvency risk, complaints, and the limited scope of FSCA authorisation.

AML/CFT integration. The FIC registration, institutional risk assessment, RMCP, client and beneficial-owner verification, sanctions screening, wallet-risk analytics, transaction monitoring, travel-rule workflow, reporting escalation, recordkeeping, and governance should correspond to the actual customer and transaction architecture.

The FSCA’s 2026 licensing update indicates that operational ability, business plans, frameworks, competence, and demonstrable crypto knowledge and experience were material issues in declined applications. That enforcement experience supports treating the application as a substantive operating-model assessment rather than a form-filing exercise.

Limitations

Exact forms, fees, submission channels, recognised-qualification lists, and documentary checklists are administrative matters capable of changing. They must be rechecked immediately before filing.

What conduct obligations apply after authorisation?

Conclusion

Authorisation initiates continuing supervision. A licensed CASP must remain fit and proper, comply with the General Code and licence conditions, restrict itself to its authorised services and products, supervise representatives, protect client assets, maintain records, and communicate the limits of its authorisation accurately.

Rule

Section 2 of the General Code requires the provider to render financial services “honestly, fairly, with due skill, care and diligence” and in the interests of clients and the integrity of the financial-services industry.

The Code also requires appropriate client information where advice is provided, a reasonable basis for recommendations, material disclosures, conflict controls, records, and safeguards where assets or funds are held.

Fit-and-proper requirements are continuing requirements, not only application-stage tests. Key individuals must remain able to manage and oversee the authorised services in light of their scale, range, and complexity.

Application

For CASPs, the general duties require particular attention to:

  • disclosure of the precise legal entity providing each service;
  • licence number, authorised category, product class, and limitations;
  • whether customer assets are held on-chain, off-chain, omnibus, or segregated;
  • ownership and insolvency treatment of client crypto assets;
  • execution venues, routing, spreads, slippage, and market-maker conflicts;
  • fees embedded in conversion rates, gas charges, staking rewards, or yield;
  • token-listing and delisting criteria;
  • withdrawal restrictions, settlement periods, and network outages;
  • risks of forks, bridges, smart contracts, stablecoin depegging, and protocol failure;
  • suitability where personalised advice is provided;
  • complaint and error-resolution procedures; and
  • accurate statements that FSCA authorisation does not make crypto legal tender, approve individual tokens, or provide a government guarantee.

Where the provider controls keys or instruments enabling control, client-asset governance should be operationally testable. Daily reconciliation, access logs, signing controls, withdrawal authorisation, incident response, and independent assurance are more persuasive than policy statements alone.

Counterarguments and limits

A provider that gives execution-only services may not owe the same suitability analysis as an adviser, but it remains subject to applicable fair-treatment, disclosure, conflict, record, custody, and licence-scope obligations.

A disclaimer that the provider gives “no advice” will not control if the interface, communications, ranking, nudges, portfolio suggestions, or sales process in substance make recommendations.

Is FIC registration a separate requirement?

Conclusion

Yes. A provider that carries on one or more Item 22 activities for or on behalf of clients is an accountable institution and must separately register with the FIC and comply with the FIC Act. FIC registration is not an operating licence and does not legalise conduct prohibited by FAIS.

Rule

Schedule 1 Item 22 covers a person carrying on, for or on behalf of a client:

  1. fiat-to-crypto or crypto-to-fiat exchange;
  2. crypto-to-crypto exchange;
  3. transfer of crypto from one address or account to another;
  4. safekeeping or administration of crypto or an instrument enabling control over it; or
  5. participation in or provision of financial services connected to an issuer’s offer or sale.

The Item 22 definition differs from the FAIS Declaration. Among other differences, it refers to perceived value used by an internet community as a medium of exchange, unit of account, or store of value for payment or investment, and excludes a digital representation of fiat currency and a security under the Financial Markets Act.

Section 43B requires registration of accountable institutions. FIC instructions state that a new accountable business must register within 90 days after commencement, electronically through goAML, and that registration is free.

Core FIC obligations

An Item 22 accountable institution must ordinarily establish and implement:

  • customer due diligence and identification;
  • beneficial-ownership identification and verification;
  • enhanced measures for higher-risk clients and relationships;
  • ongoing transaction monitoring;
  • scrutiny of complex, unusual, or apparently purposeless transactions;
  • targeted-financial-sanctions screening and controls;
  • suspicious and unusual transaction reporting;
  • recordkeeping;
  • governance, compliance responsibility, and training; and
  • a documented, maintained, and implemented RMCP.

Section 21C expressly requires ongoing due diligence and transaction monitoring consistent with the institution’s knowledge of the client, business, source of funds, and risk profile. Section 42 requires an AML/CFT and proliferation-financing RMCP capable of identifying, assessing, monitoring, mitigating, and managing institutional risks.

Section 29 requires reporting where the relevant person knows or ought reasonably to have known or suspected circumstances indicating unlawful proceeds, terrorist-financing connections, transactions without apparent lawful purpose, reporting avoidance, or relevant tax evasion.

Travel rule

Directive 9 of 2024, effective 2025-04-30, requires applicable originator and beneficiary information to accompany qualifying crypto-asset transfers. PCC 61, published on 2026-03-30, supplies current FIC implementation guidance. The workflow should address hosted and unhosted wallets, missing or incomplete information, intermediary CASPs, screening, data retention, exceptions, and rejection or escalation criteria.

Geographic-location information

Directive 10, effective 2026-07-31, requires Item 22 CASPs to provide the FIC with specified geographic-location information for their head offices, branches, subsidiaries, and subsidiary branches in and outside South Africa. Existing registered institutions must update their registration information within 90 days after the effective date, and later changes must be updated within 90 days.

2026 risk and compliance return

Directive 11 applied to Item 22 CASPs. Their return covered the period 2023-07-01 to 2026-03-31. A later FIC notice dated 2026-07-30 set the final submission deadline at 2026-07-31 at 17:00. As of the As-of Date, that deadline has passed. An in-scope CASP that did not file should treat the matter as a current compliance breach requiring immediate legal assessment and regulator-engagement strategy; the FIC states that failure to file may lead to administrative action.

Supervisory allocation

Schedule 2 of the FIC Act expressly names the FSCA as supervisory body for Items 4, 5, and 12—not Item 22. The FIC states that it oversees crypto-asset service providers and conducts inspections where no Schedule 2 supervisory body exists. At the same time, the FSCA supervises authorised FSPs and has reported FIC Act inspections involving licensed CASPs. The correct approach is therefore entity- and Schedule-item-specific: identify whether the business is registered under Item 22, Item 12, or both, and expect regulatory coordination rather than assuming exclusive supervision by one authority.

What is the position for crypto payments, P2P transactions, and DeFi?

Conclusion

A crypto transaction’s payment purpose does not remove it from FAIS. Where a business advises on or intermediates the crypto asset, FSCA authorisation is required. However, under the current joint SARB–FSCA position, the crypto activity does not require National Payment System Act authorisation solely because it resembles a payment transaction.

Rule and application

The joint communication states that the FAIS Declaration applies only to advice and intermediary services and was not intended to legitimise crypto as currency or acceptable tender. A provider must hold FSP authorisation or act as an authorised FSP’s representative where its regular business includes those services.

It further concludes that intermediaries facilitating crypto payment-type activities and persons advising on crypto must be authorised under FAIS, but that those activities are not presently considered payments under the National Payment System Act and therefore do not presently require authorisation under that Act on that basis alone.

That conclusion does not exempt the fiat side of the arrangement. A provider must separately analyse whether it:

  • receives or controls customer rand funds;
  • operates a payment account;
  • acts as a third-party payment provider;
  • supplies system-operator or clearing functionality;
  • uses a sponsoring bank or payment-system participant;
  • performs money or value transfer; or
  • conducts another activity regulated independently of the crypto leg.

For P2P and DeFi, the joint communication says that a direct transaction relying only on a decentralised protocol, with no intermediary or adviser, does not currently create an FSP obligation for the parties. The conclusion changes where an identifiable person provides a client-facing interface, routes or approves transactions, controls smart-contract parameters, holds administrative keys, safeguards assets, charges intermediation fees, provides transaction-specific assistance, or otherwise performs an intermediary service.

Are there current cross-border CASP requirements?

Conclusion

The “Authorised CASP” framework contained in the 2026 draft Crypto Assets Manual is not current binding law as of 2026-08-17. It must not be confused with an existing FAIS FSP authorisation.

Rule and application

National Treasury and the SARB published the draft Manual on 2026-08-03 to accompany the draft Capital Flow Management Regulations. It proposes an application and adjudication process for an “Authorised Crypto Asset Service Provider,” permissions for cross-border crypto activity, reporting to the SARB’s Financial Surveillance Department, and proposed treatment of transfers between domestic CASPs, offshore CASPs, and non-custodial wallets. Both the regulations and the Manual remain subject to consultation and refinement. Comments on the Manual are due by 2026-09-30.

Accordingly:

  • an FSCA FSP licence does not yet make a provider an “Authorised CASP” under the proposed cross-border framework;
  • a provider should not represent that the draft permissions are already available;
  • existing exchange-control and cross-border rules must be analysed under current law;
  • the proposed rules should nevertheless be incorporated into forward-looking architecture, reporting, wallet, and offshore-counterparty planning.

Cross-border activity also requires analysis of the location of clients, contracting entity, custody entity, offshore exchange or liquidity provider, wallet destination, marketing activity, data transfer, and settlement flows.

Enforcement and practical regulatory risk

Conclusion

CASP licensing is being substantively supervised and enforced. Operating without authorisation, relying on a withdrawn or declined transitional application, or treating licence approval as a formality carries material regulatory risk.

Application

The FSCA’s 2026-04-15 update reported that it had received 533 CASP applications: 310 had been approved, 17 declined, and 124 voluntarily withdrawn following regulatory engagement, with the balance still under consideration at that snapshot date. The identified decline issues included operational ability, business plans and control frameworks, competence, and inadequate crypto knowledge or experience. These figures are an administrative snapshot, not the current licensed-entity register as of 2026-08-17.

The FSCA also reported 81 investigations into potentially unlicensed CASP businesses, of which 30 had been closed and 51 remained ongoing at the relevant reporting point.

The same official materials reported AML/CFT inspection activity involving licensed CASPs and additional inspections planned for the 2026/27 financial year. This confirms that obtaining authorisation does not conclude the regulatory process; it moves the provider into continuing conduct and financial-crime supervision.

A declined or withdrawn applicant may reapply, but cannot rely on the former application to continue regulated operations. A material business-model change by a pending applicant may also require notification, amendment, or reconsideration of the scope of transitional protection.

Open Questions

The following items must be resolved before a final entity-specific licensing opinion or application strategy can be issued.

Regulatory perimeter

  1. Which legal entity contracts with the client?
  2. Which entity controls the website, application, protocol interface, order book, or execution logic?
  3. Does any entity give express or implied recommendations?
  4. Who receives, routes, approves, signs, or settles transactions?
  5. Who holds private keys, MPC shares, administrative keys, recovery credentials, or instruments enabling control?
  6. Is any investment or transaction discretion exercised?
  7. Does the provider earn transaction-linked spreads, routing fees, commissions, staking rewards, token incentives, or issuer payments?

Product classification

  1. Which tokens will be supported?
  2. Are any tokens securities, derivatives, stablecoins, tokenised deposits, collective-investment interests, NFTs, governance instruments, or issuer fundraising instruments?
  3. Does the provider list or distribute tokens in connection with an issuer’s offer or sale?

Existing regulatory status

  1. Does the entity hold an existing FSP licence?
  2. Which FSP categories, services, and product subcategories appear on that licence?
  3. Was a transitional CASP application submitted by 2023-11-30?
  4. Is it still pending, or has it been approved, withdrawn, rejected, or declined?
  5. Have the business model, group, ownership, key individuals, or services changed since filing?

FIC status

  1. Is the entity registered under Item 22, Item 12, or both?
  2. Was registration made within the prescribed period?
  3. Was the 2026 Item 22 risk and compliance return filed by 2026-07-31?
  4. Is Directive 9 implemented for all relevant transfer types?
  5. Has the entity completed or scheduled the Directive 10 geographic-location update within the applicable 90-day period?
  6. Does the RMCP match the actual wallet and transaction architecture?
  7. Which authority has inspected or corresponds with the entity concerning FIC compliance?

Client money and payments

  1. Does the provider receive or control rand or foreign currency?
  2. Are client fiat funds held in pooled or designated accounts?
  3. Does a bank, third-party payment provider, card acquirer, or payment-system participant sponsor the fiat leg?
  4. Does the business perform money or value transfer, clearing, settlement, or system-operator functions?

Cross-border and operations

  1. Where are clients, servers, custody providers, liquidity providers, and group companies located?
  2. Are transfers permitted to offshore exchanges or non-custodial wallets?
  3. How will the proposed cross-border “Authorised CASP” framework affect the target architecture?
  4. Are outsourcing, cloud, custody, insurance, incident-response, and insolvency arrangements fully documented?
  5. Do key individuals and representatives satisfy current qualification, examination, experience, training, and CPD requirements?
Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.

More from the journal

See all
Illia Prokopiev

EU Instant Euro Payments

Instant euro payments are now a central part of the EU payments framework, bringing faster execution, price parity, payee verification and new access rules for payment service providers. This article examines the binding requirements, key implementation deadlines and practical limits of the regime, while distinguishing the law itself from simplified public descriptions of how the system works.

FTC Issues Proposed Policy Statement on AI Accuracy and Output Steering in July 2026

On 1 July 2026, the Federal Trade Commission voted 2-0 to publish a proposed policy statement in the Federal Register describing how AI companies that configure their systems to suppress accuracy or steer outputs toward undisclosed objectives may violate Section 5 of the FTC Act. The statement applies established deceptive-practices doctrine to AI output manipulation. The public comment period closed 31 July 2026.

MiCA Transitional Period Expires 1 July 2026 as ESMA Orders Unauthorised CASPs to Wind Down

The Markets in Crypto-Assets Regulation transitional arrangement under Article 143 of Regulation (EU) 2023/1114 expired on 1 July 2026. Any entity providing crypto-asset services to EU clients without a MiCA authorisation is now in breach of EU law and must cease operations. ESMA issued a public statement on 23 June 2026 (ESMA75-113276571-1710) setting out expectations for how non-authorised providers must wind down activities and protect investors.