How CASP Licensing Works in South Africa
4-step guide to CASP licensing in South Africa: FSCA & FIC requirements, AML/custody controls, and a 6–12 month approval timeline.

If I want to offer crypto services in South Africa, I should expect a licensing path that often takes 6–12 months, not a few days. In most cases, I need FSCA authorization under FAIS and separate FIC registration for AML/CFT. I also should not go live until my license is issued, my filing conditions are cleared, and my AML controls work in testing.
Here’s the short version:
- Crypto is treated as a financial product in South Africa for FAIS purposes.
- I may fall into scope if I give crypto advice, run brokerage or order execution, operate an exchange, or hold client crypto or keys.
- I usually deal with two regulators:
- FSCA for licensing as an FSP
- FIC for AML/CFT registration and reporting
- I need to settle my service scope, custody model, and governance roles before filing.
- My application can slow down if I do not explain my business model, AML setup, or custody flows in plain detail.
- I should plan for at least one regulator query round.
- After approval, I still need KYC, sanctions screening, Travel Rule, recordkeeping, and reporting in place before launch.
A simple way to think about it: scope first, filings next, review after that, then launch checks.
| Step | What I need to do | What matters most |
|---|---|---|
| 1 | Confirm whether my crypto service is in scope | Advice, exchange, brokerage, custody, fiat on-ramp |
| 2 | Build the filing pack | KI documents, business plan, AML files, company records |
| 3 | Submit and answer regulator questions | Missing forms and weak explanations often cause delays |
| 4 | Finish go-live checks | No launch before written approval and cleared conditions |
If my model touches South African clients, a foreign license alone will not cover me. The safe path is to treat licensing, AML registration, and launch controls as one connected project from day one.
South Africa CASP Licensing Process: 4 Steps to Approval
Step 1: Confirm Scope and Set Up the Business
Step 1 is where you lock in your scope and governance before you file. That scope shapes the filings, controls, and people the regulators will look at.
Define Your Services and License Scope
Start by listing every service you plan to offer: exchange, OTC dealing, custody, advice, and transfers. Then map each one to its FAIS category. In most cases, that means Category I or Category II permissions under Subcategory 1.28. Category I covers advice and intermediary services. Category II covers investment management.
Your business plan should walk through the full customer journey, from signup to fiat movement, key control, and withdrawals.
You also need to settle your custody model early. A broker that never touches client wallets presents a different risk picture from a full-service exchange that holds client assets or uses pooled wallets and cold storage. That one call affects the controls you’ll need to spell out in the application.
At the same time, decide whether you’ll give investment advice or stay execution-only. That choice changes your license category and the competency standard for staff.
Set Up Governance and Fit-and-Proper Roles
Once the scope is clear, build the governance structure around it. You’ll need a formal legal entity, usually a South African company, with a clear shareholding register and identifiable beneficial owners. The ownership chain should be easy for the FSCA and FIC to review so they can identify beneficial owners and screen them for integrity and AML risk.
Every CASP must appoint at least one Key Individual (KI). This is the person responsible for overseeing and managing the licensed crypto activities, and the FSCA assesses that person directly. If the KI is under-qualified, the application can slow down or lose strength fast, so this is not a role to fill at the last minute.
Your KI should be able to show:
- Relevant qualifications
- RE1 regulatory exam results
- Hands-on experience in both financial services and crypto
- A full document pack, including ID, a detailed CV, proof of qualifications, RE1 results, and declarations on criminal, regulatory, and financial history
Beyond the KI, assign clear responsibility for compliance, risk management, and AML/CFT. Put the reporting lines in writing. The FSCA wants to see oversight shared across a capable team, not piled onto one person. A role matrix is the simplest way to show who reports to whom.
Once those roles are set, moving into the FSCA and FIC document pack gets much easier. With scope and accountability fixed, the filing process becomes far more direct.
sbb-itb-0796ce6
Step 2: Prepare the Filings and Compliance Documents
With your governance structure and key roles set, the next job is putting together the application file. This is where many teams get stuck. In a lot of cases, delays happen because the business model, custody setup, product flow, or tech stack isn't explained clearly enough.
Documents for the FSCA Application

The FSCA application follows the standard FAIS FSP process. That means using the usual FAIS FSP forms - FSP 2, 4C, 4D, and 5 - along with CASP declarations. The FSCA has said that the CASP licensing process is basically the same as a standard FSP application, with a CASP declaration and crypto-specific conditions added.
Your application file should deal with five main areas:
| Document Area | What to Include |
|---|---|
| Business plan | Crypto services, customer segments, revenue model, full customer journey, tech stack, custody model, risk controls |
| Corporate records | CIPC registration, share register, beneficial ownership structure |
| Governance pack | Board structure, representative registers, fit-and-proper evidence |
| Financial soundness | Capital position, financial statements or forecasts, solvency calculations |
| Compliance framework | FAIS conduct policies, conflicts of interest, complaints handling, outsourcing oversight |
The FSCA has noted that early CASP applications were often delayed or queried because the business model was not described in enough detail, or because the application did not clearly explain operational controls for crypto-asset product flows, custody arrangements, and technology setup.
A complete file helps move the review along, but you should still expect follow-up from the regulator.
AML and Risk Files for FIC Compliance

FIC registration and a Risk Management and Compliance Programme (RMCP) are mandatory. And the RMCP needs to be built around crypto risk, not copied from a generic template.
It should spell out your customer risk rating method, customer due diligence (CDD) and enhanced due diligence (EDD) steps, transaction monitoring rules, sanctions screening, and suspicious transaction reporting (STR) workflows.
For transaction monitoring, your rules should flag crypto-specific patterns such as:
- rapid in-and-out fiat flows
- small structured deposits just below reporting thresholds
- use of privacy coins or mixers
- sudden volume spikes
FICA requires CDD and transaction records to be kept for at least five years after the end of a business relationship or the conclusion of a transaction.
Your STR process also needs to work in practice. A policy on its own won't cut it. You need runbooks, escalation steps, and report templates that include wallet addresses, transaction hashes, and a clear narrative the FIC can act on.
Once the RMCP and reporting process are documented, the next move is submission planning and query handling.
Contact Points and Submission Planning
Before submitting, pin down the right contact channel for each regulator. For FSCA licensing questions - including forms, fees, subcategory points, and application status - use the FSCA's dedicated FSP licensing portal under the FAIS Registrations path. For FIC questions, use the Compliance Contact Centre.
Keep your questions short and specific. Point to the exact FSCA notice or FIC guidance document you're working from, give a brief summary of your business model, and ask one focused question. It saves time and cuts back on back-and-forth.
It also helps to build a submission calendar that maps:
- document finalization
- board approval dates
- internal reviews
- target submission window
- any regulatory deadlines that apply
This should line up with the timing points set by your team and any filing deadlines in play. Also, log every regulator contact - date, topic, and outcome. Keep that contact log ready for the review stage.
Once the file is submitted, expect regulator queries before approval.
Step 3: Submit, Respond, and Wait for Approval
Submitting your application starts the review. It does not mean a decision is close.
The FSCA reviews applications in stages, and it helps to know how that process works. If you understand what the regulator is checking at each point, you're less likely to get stuck in back-and-forth delays.
What Happens After Submission
Once your file is in, the FSCA checks whether your scope, governance, and controls line up with what you said in the application. It starts with a completeness check. At this stage, the regulator confirms that the required forms, attachments, and fees are all there before the main review begins.
If anything is missing, the FSCA sends a request for further information (RFI) and puts the review on hold until you fix the gaps. That pause can drag things out, so the first pass matters more than many firms expect.
Common reasons for an RFI include:
- Missing RE1 evidence for key individuals
- A business plan that doesn't clearly explain the crypto service model
- An AML framework that isn't specific enough to South African law
After that, the FSCA reviews governance, capital adequacy, technology and custody controls, and the fit and proper status of key people. In practice, you should plan for at least one RFI round before a decision.
| Stage | What the FSCA Does | What You Should Expect |
|---|---|---|
| Submission received | Intake and completeness screening | File must be complete and well organized |
| Substantive review | Checks business model, documents, and fit-and-proper issues | Possible RFIs on governance, AML, or custody |
| Remediation rounds | Requests updated policies or additional evidence | Respond quickly with documented changes |
| Decision | Application advanced, declined, or left pending | Possible conditional approval or withdrawal |
| License issued | License issued and firm listed publicly | Start only after all conditions are met |
Approval Conditions and Timing
Approval isn't always clean and open-ended. The FSCA can attach conditions linked to scope, controls, or reporting.
For example, it may limit a CASP to non-custodial brokerage activity until a custody risk assessment and technology audit are submitted and accepted. It can also require the firm to appoint a dedicated compliance officer, put specific IT security measures in place, or file conduct reports more often during an early period.
The review phase usually takes 6–12 months from submission to license issuance, depending on how complex the application is and how many RFI rounds come up. That's a long runway, but it's normal.
Do not launch until every condition has been met and the FSCA has confirmed that in writing.
Once the approval is on paper and all conditions are cleared, move to launch checks and ongoing reporting.
Step 4: Complete Launch Checks and Ongoing Duties
License approval doesn't end your compliance work. It just changes the job. At that point, you move from documents and sign-offs to live controls that have to work in practice.
Pre-Launch Checks Before Serving Customers
Before you launch, test your AML/CFT workflows, KYC onboarding, complaints handling, and risk disclosures from start to finish.
Your board or key individual should sign a go-live memo that confirms scope, conditions, fit-and-proper roles, approved governance policies, and an operational RMCP. If dry-run sanctions screening shows false negatives, pause the launch, even if your FSCA license letter has already been issued.
A simple go-live checklist helps here. Tie each item to evidence, such as:
- License letter
- Cleared conditions
- FIC registration
- Board minutes
- Training logs
- UAT sign-off on AML and conduct controls
That way, you're not relying on memory or verbal confirmation. After launch, these same controls don't disappear. They shift into day-to-day monitoring and reporting.
Post-License Supervision and Reporting
Once you're live, supervision continues. The FSCA and FIC still monitor firms through inspections, reporting, and enforcement.
FIC Directive 9, known as the Travel Rule, took effect on April 30, 2025. It requires CASPs to send originator and beneficiary data with crypto transfers. If you fail to comply, the FIC can impose administrative sanctions under section 45C of the FIC Act. Your RMCP also needs regular updates to reflect new typologies and transfer patterns.
You should also keep a reporting calendar that covers FSCA returns, FIC suspicious transaction reports, cash-threshold reports, and sector questionnaires. Assign one responsible person to each reporting line, with clear escalation to your compliance officer.
This is where discipline matters most. Prompt replies to supervisory requests and open incident reporting can make dealings with regulators much smoother over time.
Key Takeaways for a Smooth Licensing Path
The path is pretty direct: confirm scope, build governance, submit complete FSCA and AML/CFT documents, and launch only when every condition and control is live.
Licensing is the start of a continuing compliance function, not the finish line. The controls you put in place now - governance, recordkeeping, transaction monitoring, and staff training - are the same controls regulators will review after go-live. Build them to hold up under day-to-day supervision, not just to get initial approval.
FAQs
Do foreign crypto firms need South African licensing?
Yes - if a foreign crypto firm serves South African customers, it should expect to meet South Africa’s CASP-related licensing rules as enforcement picks up.
Kryptonim’s South Africa overview says the country has moved from planning to active enforcement under Directive 9, introduced in April 2025. That means firms should get ready for licensing and compliance instead of operating without local regulatory approval.
What usually causes CASP license delays?
CASP license delays often come down to one simple issue: the application isn’t complete.
The biggest hold-ups usually show up in AML/KYC paperwork and in the proof that your controls work in practice. It’s not enough to say the process exists on paper. Review teams usually want clear records that back it up. If those records are missing, thin, or hard to follow, the review can slow down fast.
Timing also plays a big part. This gets more sensitive around major transition dates, especially full MiCA compliance by 07/01/2026. When many firms are filing, updating, or fixing submissions at the same time, delays can stack up.
Cross-border issues can add another layer. If counterparties sit outside places with compatible Travel Rule implementation, firms may need enhanced due diligence and extra checks. That means more documents, more review steps, and more time before the license process moves ahead.
What must be ready before launch?
Before you launch under South Africa’s CASP licensing path, get your AML/KYC program in place. That means having clear checks for counterparty risk, enhanced due diligence, and the originator and beneficiary details required for compliant transfers.
Your filings and supporting documents should be complete and match the regulator’s step-by-step requirements. Before starting operations, be prepared to confirm licensing status through official regulatory contact points or registries.