INTELLIGENCE BRIEF
firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session
vol VII . ISSUE 24 . 24 JUN 2026
The Travel Rule's African Frontier
Breaking . AML

The Travel Rule's African Frontier

Insight . Intelligence . Accountability

32 Views
0 Comments
News & Analysis 24 Jul, 2026

A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.

The Travel Rule's African Frontier

Closing the Sub-Regional Compliance Gap in Virtual Asset AML Regulation

From : Dr. Foluso Amusa, PhD  |  Founder & President, IGRCFP  |  July 2026

A NOTE FROM DR. AMUSA

Africa's virtual asset markets are growing faster than our supervisory infrastructure can currently follow. This briefing is written for IGRCFP members, regulators, and compliance officers who need a clear-eyed, technical view of where the Travel Rule stands across our region today — not just which laws have passed, but whether they actually work together across borders. I hope it sharpens the conversation.

Abstract

Sub-Saharan Africa now sits among the fastest-growing virtual asset markets in the world, yet its Travel Rule infrastructure — the mechanism by which originator and beneficiary data move with a transaction, in line with FATF Recommendation 16 — remains fragmented across a dozen distinct regulatory tracks. This briefing sets out the current state of Recommendation 15 implementation globally following the FATF's Seventh Targeted Update of July 2026, maps the African regulatory landscape jurisdiction by jurisdiction, and identifies the specific technical and supervisory gaps that create arbitrage corridors for illicit value movement. It closes with a practical, risk-based interoperability agenda for regulators, VASPs, and compliance officers operating across African borders.

1. A Continent Building the Runway While the Aircraft Is Already Airborne

Africa's virtual asset adoption curve has consistently outpaced its regulatory infrastructure. On-chain value received across Sub-Saharan Africa grew sharply in the twelve months to mid-2025, driven by remittance substitution, stablecoin-denominated trade settlement, and retail speculation in markets with volatile local currencies. Regulators across the continent have responded in the past eighteen months with a wave of primary legislation: Kenya's Virtual Asset Service Providers Act, Nigeria's rewritten Investments and Securities Act, Ghana's forthcoming VASP Bill, and South Africa's maturing licensing regime under the Financial Sector Conduct Authority all moved from consultation to force within a compressed window.

What has not moved at the same pace is the plumbing beneath the law: the technical capability of licensed VASPs to actually execute the FATF Travel Rule, collecting, verifying, and transmitting originator and beneficiary information in real time, across borders, between counterparties that may sit in entirely different legal and technical regimes. Licensing a VASP is a necessary condition for AML compliance. It is not sufficient. This briefing focuses on that second, harder problem: the operational mechanics of cross-border data transmission and the sub-regional gaps that persist even where domestic law now looks complete on paper.

2. The Global Baseline: What the FATF's July 2026 Update Actually Shows

The FATF's Seventh Targeted Update on the implementation of Recommendation 15, published on 16 July 2026, gives the clearest picture yet of where global Travel Rule adoption stands. Eighty-three percent of surveyed jurisdictions have now passed Travel Rule legislation, up from seventy-three percent a year earlier, with a further eleven jurisdictions reporting implementation underway. That is genuine progress. But the same report is candid about the gap between legislating and operating: among jurisdictions that permit VASPs to operate legally, only seventy-six have completed actual licensing or registration, a figure unchanged from 2025, and regulators continue to struggle to identify the natural or legal persons who actually control virtual asset businesses operating within their borders.

Three structural weaknesses recur throughout the FATF's findings, and each has a distinct African expression, discussed below: the offshore VASP problem, where more than a third of jurisdictions with licensing frameworks have had to broaden scope to capture foreign-incorporated providers serving local customers; persistent blind spots around decentralised finance, where the overwhelming majority of surveyed authorities cannot yet identify which domestic DeFi arrangements meet the legal definition of a VASP; and uneven Travel Rule execution even where legislation exists, particularly for unhosted wallets and emerging stablecoin rails.

A licence is a legal event. Interoperable data transmission is an engineering event. African markets are currently strong on the first and structurally weak on the second.

3. The African Regulatory Map, Mid-2026

The table below summarizes the state of play across the jurisdictions of greatest relevance to IGRCFP's Africa Desk membership. The picture is one of rapid convergence toward the FATF template licensing, a designated supervisor, and a stated intention to implement the Travel Rule but with meaningfully different timelines, thresholds, and enforcement capacity..

Jurisdiction

Primary Regulator(s)

Legal Basis

Status, mid-2026

Nigeria

SEC (securities); CBN (banking nexus)

Investments and Securities Act 2025

Digital assets classified as securities; dedicated VASP Regulation Bill 2026 under Senate review to consolidate exchange, wallet and platform licensing.

Kenya

Central Bank of Kenya; Capital Markets Authority

Virtual Asset Service Providers Act, 2025

Dual-regulator model in force since November 2025; draft 2026 regulations concluded public consultation; licensing transition runs through late 2026.

South Africa

Financial Sector Conduct Authority

FAIS Act (crypto assets classified as financial products, 2022)

Established licensing regime; enforcement and supervision maturing rather than newly built.

Ghana

Bank of Ghana, via Virtual Assets Regulatory Office

VASP Bill (in passage)

VARO established to centralise supervision; registration precedes full licensing, expected within 2026.

Mauritius

Financial Services Commission

VAITOS Act, 2021

One of the continent's earliest comprehensive frameworks, with defined VASP categories and strong AML/CFT conditions.

Rwanda / Uganda

Frameworks in development

Pending

AML obligations may apply indirectly; no dedicated licensing regime yet.

Tanzania

N/A (no dedicated regime)

General AML/CFT law

Virtual-asset activity brought within AML/CFT scope without a standalone VASP licence.

Ethiopia

N/A

Prohibition

Maintains a prohibitionist stance on virtual asset service provision.

Table 1. Selected African VASP regulatory frameworks, compiled from primary legislation, regulator publications and independent legal analysis current to July 2026.

Two patterns are worth drawing out. First, the region has largely converged on a dual-regulator or FSP-extension model rather than building a single stand-alone crypto authority: Kenya splits oversight between its central bank and capital markets regulator; Nigeria routes digital assets through securities law with a banking-system nexus; South Africa folded crypto assets into its existing financial-products framework rather than legislating afresh. Second, physical presence and capital requirements vary sharply. Nigeria requires local incorporation and office presence, while several other jurisdictions do not—which itself creates an incentive for VASPs to domicile in the lightest-touch jurisdiction available while continuing to serve customers across the whole sub-region.

4. The Technical Compliance Gap Beneath the Legal Layer

4.1 What Travel Rule compliance actually requires

Recommendation 16, extended to virtual assets through Recommendation 15, obliges a VASP to attach originator name, account number or wallet identifier, and, above the applicable threshold, physical address or national identifier, together with equivalent beneficiary data, to every qualifying transfer and to transmit that data to the receiving institution securely and, in practice, near-instantaneously. This is not a reporting obligation that can be satisfied after the fact through a suspicious transaction report; it is a real-time data-exchange requirement that sits inside the transaction flow itself.

For a bank-to-bank wire, this problem was solved decades ago through SWIFT messaging standards. Virtual assets have no equivalent single rail. Compliant VASPs must instead adopt one of several competing message-exchange protocols and a common data schema, typically based on the InterVASP Messaging Standard (IVMS 101), and must be able to counterparty-verify that the receiving VASP is itself licensed and technically capable of receiving structured data before the transfer executes the so-called VASP-to-VASP due diligence step. Where the counterparty is an unhosted wallet rather than another regulated VASP, the originating institution must apply enhanced due diligence in lieu of a compliant counterparty, a category the FATF's July 2026 update flags as a continuing global weak point.

4.2 The African-specific frictions

  • Sunrise asymmetry: A Kenyan VASP now operating under a live licensing regime may route a transfer to a Nigerian or Ghanaian counterparty whose own licensing transition is not yet complete, creating a period in which one leg of the transaction is supervised and the other is not.

  • Protocol fragmentation: Without a shared regional message-exchange standard, cross-border VASPs are integrating multiple proprietary Travel Rule solutions bilaterally, which is costly for smaller African VASPs and creates gaps precisely where smaller, higher-risk providers operate.

  • Mobile-money-to-crypto interfaces: High mobile money penetration, most visibly through platforms such as M-Pesa, means a meaningful share of on/off-ramp activity crosses between a heavily supervised payments rail and a newly regulated virtual asset rail. Travel Rule data captured on the crypto leg does not automatically map onto the KYC data held by the mobile money operator, leaving a reconciliation gap at exactly the point regulators most need visibility.

  • Registry opacity: No African jurisdiction yet publishes a real-time, machine-readable public registry of licensed VASPs equivalent to those maintained by some European regulators, which slows the counterparty due diligence step described above and increases reliance on manual verification.

  • Threshold and definition drift: Differing transaction thresholds, currency conversion practices, and definitions of what counts as a reportable transfer between Nigeria, Kenya, Ghana and South Africa create room for structuring across borders that would not be possible within a single harmonised regime.

5. Sub-Regional Fragmentation as an Arbitrage Corridor

None of the frictions above are unique to Africa; every multi-jurisdictional Travel Rule environment faces them. What makes the African case distinctive is the combination of high genuine transaction volume, a wide spread of supervisory maturity within a single trading and remittance corridor, and limited formal cooperation mechanisms between the relevant regulators. A transaction structured to route through the least-supervised leg of an ECOWAS or EAC corridor is materially harder for any single national regulator to detect than the equivalent structuring within a jurisdiction operating a single, mature regime.

This is the same dynamic that has historically driven correspondent banking de-risking and trade-based money laundering across African corridors, now reproduced in a faster-moving, harder-to-trace medium. The FATF's own emphasis on offshore VASPs and unhosted wallets in its July 2026 update is a direct acknowledgement that regulatory perimeter gaps, wherever they sit, become the preferred routing path for illicit actors rather than an evenly distributed background risk.

6. A Practical Interoperability Agenda

IGRCFP's Africa Desk proposes the following priorities for regulators, VASPs, and in-house compliance functions operating across more than one African jurisdiction:

  • Regulator-to-regulator: pursue a shared, minimum-viable data schema (aligned to IVMS 101) and a mutual-recognition understanding between the Central Bank of Kenya, Nigeria's SEC, South Africa's FSCA, and the Bank of Ghana's Virtual Assets Regulatory Office, so that a licence issued in one jurisdiction carries a known, auditable standard of Travel Rule capability in the others.

  • Public VASP registries: prioritise publication of machine-readable, API-accessible licensed-VASP registries, reducing reliance on manual counterparty verification and closing the window in which unlicensed offshore VASPs can present as compliant.

  • Mobile-money-to-crypto reconciliation: require licensed VASPs that accept mobile money on/off-ramps to map originator identity data captured at the payments layer directly into Travel Rule payloads, rather than treating the two KYC records as independent.

  • Threshold harmonisation: align reportable-transfer thresholds and structuring definitions across the region's principal VASP regimes as a near-term technical priority, ahead of full licensing convergence.

  • Institutional capacity building: extend structured AML/CFT and Travel Rule technical training to supervisory staff and MLROs at licensed VASPs, mirroring the sectoral capacity gap the FATF identifies globally in DeFi supervision — a gap that a compliance function cannot close through policy alone.

  • Enhanced due diligence defaults: until counterparty verification infrastructure matures, VASPs operating cross-border should default to enhanced due diligence on any transfer to a counterparty that cannot be positively confirmed as a licensed, Travel-Rule-capable VASP, treating unhosted-wallet-equivalent uncertainty as the working assumption rather than the exception.

7. Conclusion

Africa's virtual asset regulators have, in a remarkably short period, closed most of the legislative gap that separated the continent from the FATF standard. What remains is the harder, less visible work of interoperability: ensuring that a Travel Rule obligation written into law in Nairobi, Lagos, Accra, or Pretoria actually produces a structured, verifiable data packet that a counterparty VASP in a neighboring jurisdiction can receive, trust, and act on in real time. Closing that gap is now the principal determinant of whether the region's virtual asset sector becomes a supervised extension of the formal financial system or a persistent seam through which financial crime risk migrates to wherever the enforcement is thinnest.

References & Further Reading

Financial Action Task Force, Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, Paris, 16 July 2026.

Kenya, Virtual Asset Service Providers Act, 2025 (in force 4 November 2025); Draft VASP Regulations 2026.

Nigeria, Investments and Securities Act 2025; Virtual Asset Service Providers Regulation Bill 2026 (Senate, second reading).

South Africa, Financial Sector Conduct Authority classification of crypto assets as financial products under the FAIS Act, October 2022.

Ghana, Bank of Ghana Virtual Assets Regulatory Office (VARO); Virtual Asset Service Providers Bill (in passage, 2026).

Mauritius, Virtual Asset and Initial Token Offering Services Act, 2021.

Leave a comment

Your email address will not be published. Required fields are marked with *

Similar Articles
A network that laundered more than four million euros from scams by sending the money to Nigeria falls

A network that laundered more than four million euros from scams by sending the money to Nigeria falls

Spanish Police Bust €4 Million International Money Laundering Ring Bound for Nigeria. The Spanish Civil Guard has dismantled a criminal network responsible for laundering over €4 million generated through cyber fraud, CEO scams, and identity theft across Europe. The organization utilized "smurfing"—splitting large illicit funds into more than 9,200 small-wire transfers using falsified passports and stolen identities—to bypass anti-money laundering controls and funnel cash into Nigeria. The two-phase operation led to 20 arrests, investigations into 11 others, and raids targeting key leaders in Bilbao as well as several complicit money transfer agencies.

Read Full Brief
07 Aug 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish.

Read Full Brief
04 Aug 2026
FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

The Financial Action Task Force closed its June 2026 plenary by removing Algeria and Namibia from its list of jurisdictions under increased monitoring, while adding Bosnia and Herzegovina and Iraq. For African compliance functions, the headline delisting matters less than what it confirms about the direction of travel.

Read Full Brief
04 Aug 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

Read Full Brief
04 Aug 2026
The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

High-risk AI obligations for financial services have been pushed back sixteen months. Transparency rules for chatbots and synthetic media have not moved at all — and enforcement power against general-purpose AI providers switches on this week.

Read Full Brief
04 Aug 2026
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.

Read Full Brief
04 Aug 2026
Recommended Articles
See all

No recommended articles found.