A Be Relevant product

How to get a CASP (crypto) licence in South Africa

Crypto asset services in South Africa require FSCA authorisation. This is a question-led guide to CASP licensing — the requirements, the process, and the ongoing compliance a Crypto Asset Service Provider must maintain.

RegDesk prepares CASP applications and crypto compliance documents. See RegDesk pricing →

What is a CASP licence in South Africa?

A Crypto Asset Service Provider (CASP) licence authorises a business to provide crypto asset services in South Africa. Crypto assets were declared a financial product under the FAIS Act, which means CASPs must be authorised by the FSCA. Authorisation follows the FAIS framework with a CASP-specific declaration alongside the standard fit-and-proper, operational-ability and financial-soundness requirements.

Do crypto businesses need to be FSCA-authorised?

Yes. Because crypto assets are a financial product under the FAIS Act, businesses that give advice on, or provide intermediary services in, crypto assets generally require FSCA authorisation as a CASP. Operating without the required authorisation exposes the business to regulatory action. Confirm your specific activities against the current FSCA position.

How does the CASP application process work?

The CASP process mirrors a standard FSP application — a CIPC-registered entity in good standing, at least one approved Key Individual, fit-and-proper declarations, operational ability and financial soundness — with crypto-specific conditions and a CASP declaration added. If you already provide traditional financial services, the crypto activities are added under the same authorisation framework.

What compliance must a CASP maintain?

Beyond the standard FSP compliance set, CASPs address crypto-specific anti-money-laundering and counter-terrorist-financing risk: a Risk Management and Compliance Programme (RMCP) with a crypto-typology overlay, a Travel Rule policy giving effect to the applicable FIC directive on originator and beneficiary information, and controls for custody and client-asset safekeeping, alongside the usual FICA cash-threshold and suspicious-transaction reporting to the FIC.

What is the CASP Declaration (General Notice 1350 of 2022)?

General Notice 1350 of 2022 (Government Gazette 47334) is the FSCA declaration that brought crypto assets under the FAIS Act as a financial product. It defines a crypto asset for FSP purposes, identifies which crypto activities constitute financial services (advice and intermediary services), and set the transition timeline for existing crypto businesses to become authorised CASPs. The declaration sits alongside FIC Act Schedule 1 item 22, which lists CASPs as accountable institutions for AML/CFT purposes.

What custody and asset-segregation controls must a CASP have?

A CASP holding client crypto assets must have documented custody arrangements: how client assets are held (hot wallet, cold storage, third-party custodian); segregation from CASP own assets and other clients’ assets; withdrawal authorisation and approvals; key management and recovery; and insurance or protection arrangements against loss. The FSCA reads custody as an operational-ability question — the CASP must show it can actually protect the assets it holds on client behalf.

What does client KYC onboarding look like for a CASP?

Client onboarding for a CASP combines FICA CDD (identity verification, address, source of funds) with crypto-specific data (wallet-address attribution, expected transaction typology, jurisdictions of counterparties) and CDD enhancements for higher-risk clients (PEPs, sanctioned jurisdictions, large-value activity). The onboarding record retention is 5 years under FIC Act section 22. Travel Rule requirements (Directive 9 of 2024) add originator/beneficiary information capture at transaction time. See the Travel Rule guide for the specifics.

What is a CASP’s business-wide risk assessment (BWRA)?

The BWRA is the documented assessment of the CASP’s money-laundering, terrorist-financing and proliferation-financing risk arising from its products, services, clients, jurisdictions and delivery channels. It underpins the RMCP’s controls: higher-risk elements (e.g. privacy coins, non-custodial cross-border transfers, self-hosted wallets) drive stronger CDD, screening and monitoring. The BWRA is reviewed at least annually and after material business changes.

How does RegDesk help with CASP licensing?

RegDesk prepares CASP applications and generates the crypto compliance documents — the CASP declaration set, crypto-overlay RMCP, Travel Rule policy giving effect to FIC Directive 9 of 2024, custody and asset-segregation policy, business-wide risk assessment, and client KYC onboarding pack — auto-filled from your entity data, as a first draft for your Compliance Officer to review and approve. It is not legal or compliance advice; verify current CASP requirements against the FSCA before acting.