- What crypto AML compliance means, and what it doesn't
- Why this became your problem
- What the CBN's VASP pilot signals for your business
- The AML obligations that apply to your business
- The choice no one names: build it, or inherit it
- How Breet builds AML compliance into the payment rail
- A quick compliance checklist before your next crypto payment
- Compliance is infrastructure, not paperwork
If crypto already moves through your business, AML compliance stopped being optional. Nigeria’s Money Laundering (Prevention and Prohibition) Act 2022 pulled crypto operators into the financial-institution net, and the CBN’s 2026 VASP supervision pilot made the direction official.
So the question is not whether you are on the hook. It is how much you must build yourself. Most guides here either define AML and sell you a screening tool, or list regulations and stop.Â
This one maps which obligations actually apply to a business like yours, not a licensed exchange, then shows the faster path: letting a compliant rail carry most of them.
What crypto AML compliance means, and what it doesn’t
Crypto AML compliance is the set of controls that verify who you deal with, screen and monitor transactions, and report what looks suspicious, so your business does not become a laundering channel.Â
The principles match traditional banking. Crypto just adds blockchain-specific steps.
One distinction trips up most African operators: AML and KYC are not the same thing. KYC, verifying your customers’ identities, is one input to AML.Â
AML is the whole program: ongoing monitoring, sanctions screening, and reporting. A business that verifies users at signup and does nothing after is not AML-compliant.
One myth also worth killing fast: crypto is not anonymous. Blockchain transactions sit permanently on a public ledger. That traceability is exactly why regulators expect more monitoring, not less.
Why this became your problem
African crypto regulation has moved from silence to active supervision. “Unregulated by default” is over in the markets most readers here operate in.
In Nigeria, the 2022 Money Laundering Act extended AML duties to crypto, the SEC’s digital-asset rules created VASP and custodian registration, and the Investments and Securities Act 2025 put VASPs formally under SEC oversight.Â
In Ghana, Parliament passed a Virtual Asset Service Providers law in late 2025, with the Bank of Ghana and SEC running a regulatory sandbox from early 2026.Â
South Africa already supervises crypto businesses under its financial-intelligence laws, Mauritius positions itself as a regulated hub, and Kenya is tightening oversight as adoption grows.
The message is the same across the continent: regulation is replacing uncertainty. Ignoring AML today invites penalties, damaged banking relationships, frozen accounts, and lost customer trust.Â
Businesses that can show KYC records, ongoing screening, and a clean settlement audit trail find the opposite: banks stay, enterprise clients sign, and investors get comfortable, because the operation can prove it meets expectations.
What the CBN’s VASP pilot signals for your business
On March 31, 2026, the Central Bank of Nigeria launched its AML/CFT/CPF Supervision Pilot Scheme for a select group of Virtual Asset Service Providers, naming six participants: cNGN, Flutterwave, Juicyway, KoinKoin, KuCoin, and Paystack.
The pilot requires participating VASPs to submit monthly AML/CFT/CPF performance reports on a prescribed CBN template, engage directly with the CBN and the Nigerian Financial Intelligence Unit (NFIU), and undergo reviews of governance, customer onboarding, sanctions screening, transaction monitoring, and cross-border activity.Â
Each must also show a credible plan for the FATF Travel Rule. Participation is closed to the selected cohort.
Here is why it matters even if you are not one of the six. The CBN has described the pilot as a preview of where supervision is heading.Â
Any fintech building a dollar product, a stablecoin rail, a cross-border wallet, or a crypto-settled remittance platform should treat these as the standard being set, not a rule for six named companies.Â
Onboarding, sanctions screening, transaction monitoring, Travel Rule readiness, these are the controls every crypto-adjacent business should already be building toward.
The AML obligations that apply to your business
Here are the obligations regulators expect, mapped to what they mean for an operator rather than a compliance textbook.
| Obligation | What it means in practice | Who usually carries it |
| KYC and customer due diligence | Verify customer identity before transactions | You or your payment rail |
| Transaction monitoring | Watch fund flows for suspicious activity continuously | Usually the payment rail |
| Sanctions and PEP screening | Screen customers against global and local watchlists | Usually the payment rail |
| Travel Rule | Share sender and receiver data for qualifying transfers | Usually licensed VASPs or payment rails |
| Recordkeeping | Keep customer and transaction records for years | Shared responsibility |
1. Verify identity before transactions
Use government-issued ID and biometrics where required. For business customers, identify the ultimate beneficial owner, not just whoever opened the account.Â
Apply Enhanced Due Diligence to higher-risk cases: politically exposed persons (PEPs), high-risk jurisdictions, and large transactions.Â
Tier KYC to risk so low-risk users are not over-frictioned, and high-risk ones get real scrutiny.
2. Monitor transactions continuously
Screening fund flows is an ongoing job, not a one-time onboarding check.Â
The red flags regulators look for include structuring and round-number transfers, rapid wallet-hopping, privacy coins or mixers, geographic outliers, and sudden volume spikes on a previously quiet account.
3. Screen against watchlists on an ongoing basis
Check every customer and counterparty against OFAC, UN, EU, and local Nigerian and Ghanaian sanctions and PEP lists, and re-screen over time, not just at signup.Â
This is the obligation most often flagged in audits and the one where non-compliance carries the sharpest enforcement risk.
4. Satisfy the Travel Rule for qualifying transfers
For transfers above the FATF-recommended $1,000 threshold, originator and beneficiary information must travel with the transaction between VASPs.Â
This is the obligation businesses least expect and the one most impossible to satisfy alone, since it requires VASP-to-VASP data sharing you do not control.
5. Keep records and file reports
Retain KYC documents and transaction records, typically for five to seven years, and file Suspicious Activity Reports (SARs) when transactions trip red flags.Â
Be ready for periodic audits. Regulators treat undocumented controls the same as absent ones: if it is not documented, it did not happen.
Every obligation above is real. The question every competing guide skips is who builds it.
The choice no one names: build it, or inherit it
You have two ways to meet these obligations. Stand up an AML program yourself, or run your payments on infrastructure that already carries most of them.
The catch with building in-house is the step everyone forgets. An in-house stack screens the user, but you still have to convert and settle the crypto somewhere.Â
If that “somewhere” is a P2P channel or an informal OTC contact, you have just reintroduced the exact exposure you were trying to remove: no screening, no audit trail, and an unexplained lump sum hitting your bank account.Â
Converting crypto to fiat cleanly means the conversion and the compliance run together, not in separate places.Â
And when you hold your own wallets and keys, custody risk lands on you too. Whoever controls the wallet owns the compliance obligation attached to what is inside it.
| Obligation | Build in-house (what it takes) | Inherit from a compliant rail |
| KYC and identity verification | Integrate identity providers and maintain onboarding flows | Handled on every transaction |
| Transaction monitoring | Deploy monitoring software and build alert workflows | Runs automatically during every transaction |
| Sanctions and PEP screening | Subscribe to and continuously update sanctions databases | Handled automatically by the rail |
| Travel Rule | Build or integrate Travel Rule messaging systems | Managed by the compliant rail where applicable |
| SAR filing | Create reporting processes and assign staff | Rail keeps a screened audit trail; your team files SARs with the NFIU using those records |
| Recordkeeping and audits | Store records securely and prepare for audits | Records retained for years and retrievable on request |
| Compliance officer | Hire or assign internal compliance personnel | Licensed partners carry KYC, screening, and recordkeeping functions |
| Crypto-to-fiat settlement | Find an exchange, OTC desk, or P2P buyer and manage it yourself | Screened, converted, and settled in one compliant flow |
Note the last row. Filing SARs stays with you no matter what, but the screening, monitoring, and settlement that feed those reports can be carried out for you.
How Breet builds AML compliance into the payment rail
Breet Business is crypto payment infrastructure for African businesses. Accept crypto, settle in naira, cedis, or USD, and move large volumes through an API, a business dashboard, or an OTC desk.Â
More than 100 verified businesses across Africa run on it, with over 3 million transactions settled programmatically, 99.9% uptime, and sign-up to first live transaction in under a day.
This is not another compliance tool to bolt onto your stack. It is the rail your payments run on, with compliance built into the flow. Here is how each obligation gets carried.
Screening on every transaction, not just at onboarding
Breet runs KYC and AML screening automatically on every transaction. Wallet generation, key management, on-chain confirmation, screening, and reconciliation all happen inside the payment flow.Â
Where point tools verify a user once and stop, the rail screens the fund flow continuously, which is what ongoing monitoring actually requires.
Compliance and settlement in one flow
The same flow that screens the transaction converts it and settles it. There is no unscreened, unexplained crypto inflow arriving at your bank.Â
Every payment converts to naira, cedis, or USD and lands in a local bank account, mobile-money wallet, or stablecoin address in minutes, with screening applied and an audit trail behind it.Â
When your bank or auditor asks how funds were screened and where they came from, you have an answer. A P2P or informal off-ramp cannot give one.Â
Here is how the crypto and stablecoin API handles this end-to-end.
A documented posture you can show your bank
When asked, you point to a posture, not a promise. Breet is PCI DSS compliant, processes data under the Nigeria Data Protection Act 2023, and delivers crypto and banking services through licensed partners, with a 99.9% uptime SLA.Â
The API documentation lays out the technical side.
See how screening runs on your own transactions. Book a walkthrough.
A quick compliance checklist before your next crypto payment
Pressure-test where you stand right now:
- Do you verify identity and identify beneficial owners for business customers before transacting?
- Are transactions screened and monitored on an ongoing basis, not just at signup?
- Do you screen against sanctions and PEP lists, including OFAC, UN, EU, and local Nigerian and Ghanaian lists?
- Can you satisfy the Travel Rule for transfers above the threshold, transmitting originator and beneficiary data between VASPs?
- Do you keep KYC and transaction records and have a SAR process?
- Does your crypto-to-fiat settlement carry the same screening and audit trail, or does it happen off a compliant rail?
If you answered “no” or “not sure” to two or more, especially the last one, you are carrying AML risk you do not need to. The build-versus-inherit choice applies to exactly the gaps this list surfaces.
Compliance is infrastructure, not paperwork
Crypto AML compliance for an African business comes down to a handful of real obligations: KYC, transaction monitoring, sanctions and PEP screening, the Travel Rule, and recordkeeping.Â
The only strategic decision is whether you build those controls yourself or inherit them from the rail your payments run on.
The obligation competitors never map, settlement, is where most AML risk actually concentrates.Â
A screened onboarding flow that ends in an unscreened P2P or informal off-ramp is not compliant at all, and businesses usually discover that gap the hard way: a frozen account, or an auditor’s question they cannot answer.Â
The operators treating compliance as infrastructure rather than paperwork are the ones banks and enterprise clients keep saying yes to.
Ready to put your crypto payments on a compliant rail? Talk to sales.




