AML Compliance for Crypto Exchanges in Africa: What the CBN… | YouVerify
Anti-Money Laundering (AML)
AML Compliance for Crypto Exchanges in Africa: What the CBN Pilot and the FATF Grey List Exit Change in 2027
ByVictoria okere
•5mins Read
Key Takeaways
1. Nigeria's Central Bank began an AML/CFT supervision pilot in March 2026 covering six virtual asset service providers, requiring monthly compliance reporting and FATF Travel Rule implementation plans.
2. Nigeria and South Africa both exited the FATF grey list on 24 October 2025. This eases correspondent-banking friction but does not reduce underlying AML/CFT obligations for crypto exchanges.
3. A credible AML program for an African crypto exchange rests on five components: a written policy, a designated compliance officer, automated KYC and transaction monitoring, Travel Rule messaging, and staff training.
African crypto exchanges meet AML compliance obligations in 2027 by combining Know Your Customer (KYC) checks, on-chain transaction monitoring, sanctions screening, and FATF Travel Rule messaging with jurisdiction-specific reporting to regulators. In Nigeria, that means engaging with the Central Bank of Nigeria (CBN) and the Nigeria Financial Intelligence Unit (NFIU); in South Africa, the Financial Sector Conduct Authority (FSCA) and the Financial Intelligence Centre (FIC).
This is no longer a theoretical requirement. On 31 March 2026, the CBN commenced an AML/CFT/CPF supervision pilot involving six virtual asset service providers, requiring them to submit monthly compliance reports and present plans for implementing the FATF Travel Rule. The CBN was explicit that pilot participation does not amount to licensing, but it signals closer regulatory attention on how exchanges screen customers, monitor transactions, and report suspicious activity.
Why AML Compliance Matters for African Crypto Exchanges Right Now
A notable shift changes the compliance conversation this year: on 24 October 2025, the FATF removed Nigeria, South Africa, Mozambique, and Burkina Faso from its grey list of jurisdictions under increased monitoring. That's a meaningful improvement for correspondent banking relationships and cross-border settlement speed, but it is not a green light to relax controls. South Africa's Financial Intelligence Centre was explicit that delisting is a milestone, not a finish line, and that sustained AML/CFT enforcement is expected to continue. For crypto exchanges specifically, weaker screening remains the fastest route back onto a watchlist.
The CBN's AML/CFT Supervision Pilot for Virtual Asset Service Providers
What Participating VASPs Must Do
Under the pilot, participating firms submit monthly compliance reports, undergo assessment of their governance and transaction monitoring systems, and present a roadmap for FATF Travel Rule implementation. The CBN has indicated the pilot will roll out in phases, with the current cohort closed to new entrants for now, though the supervisory template is expected to extend more broadly across licensed VASPs over time.
FATF Recommendation 16, commonly called the Travel Rule, requires VASPs to collect and transmit originator and beneficiary information alongside virtual asset transfers. Exact de minimis thresholds vary by jurisdiction rather than following one fixed global figure, so exchanges should confirm the applicable threshold with their local regulator rather than assume a single number applies everywhere. Practically, compliance means integrating a Travel Rule messaging protocol, verifying that a receiving VASP is itself licensed before releasing customer data, and applying enhanced due diligence when a customer withdraws to a self-custody wallet.
Building an AML Programme: Five Core Components
1. A written AML/CFT policy, covering risk appetite, escalation procedures, and senior management sign-off, reviewed at least annually.
2. A designated compliance officer (MLRO) with authority to file suspicious transaction reports and interface directly with regulators.
3. Automated KYC and transaction monitoring capable of on-chain risk scoring, real-time alerting, and audit-trail generation.
4. Travel Rule messaging integration for secure originator and beneficiary data exchange between counterparty VASPs.
5. Documented annual AML/CFT training for all customer-facing and compliance staff.
AML Obligations Across Key African Markets
Market
Primary Regulator(s)
Reporting Channel
Nigeria
CBN (payments/banking) and SEC Nigeria (licensing)
NFIU (STR/SAR filing)
South Africa
FSCA (FSP licensing)
Financial Intelligence Centre (FIC)
Kenya
Capital Markets Authority (CMA) - verify current guidance
Financial Reporting Centre (FRC)
A Real-World Compliance Scenario
Consider a Lagos-based exchange that receives a large stablecoin deposit from a wallet with no prior transaction history, followed almost immediately by a request to withdraw to an unhosted wallet. Under CBN-aligned controls, this pattern (rapid in-and-out movement, an unverified counterparty, and a request to exit to self-custody) should trigger enhanced due diligence and, if unresolved, a suspicious transaction report to the NFIU within the required filing window, rather than automatic approval of the withdrawal.
Conclusion
AML compliance for African crypto exchanges in 2026 sits at the intersection of two real developments: closer CBN supervision through the AML/CFT pilot and an improved standing following Nigeria and South Africa's exit from the FATF grey list. Neither development reduces the underlying obligation to run KYC, transaction monitoring, sanctions screening, and Travel Rule messaging correctly. Exchanges that treat this as a durable compliance program, not a one-time filing exercise, will be better positioned for bank partnerships and institutional relationships going forward.