Financial Intelligence Centre Act 38 of 2001

AML, CFT and KYC policy

What an accountable institution under Item 22 of Schedule 1 to the FIC Act is actually required to do, what that means for the documents we ask you for, and the two occasions on which the law prevents us from explaining ourselves to you. Conexus is an over-the-counter desk that settles in whichever currency is confirmed for a client; the framework set out here is the South African one, and it governs every client onboarded through this office.

Version 2.0 · Effective 18 August 2026 · Last reviewed 18 August 2026 · Owned by the compliance officer, compliance officer — to be confirmed

One thing to know before you read the rest

Section 29(3) of the FIC Act makes it an offence for us to tell you that a report has been filed with the Financial Intelligence Centre, or that one is being considered. If a transaction is delayed and the explanation we give you is thin, that may be the reason. We will say that we cannot explain rather than invent something that sounds better.

What this document is, and what it is not

This is the public summary of how Conexus Crypto meets its obligations under the Financial Intelligence Centre Act 38 of 2001 (the FIC Act) and the anti-money-laundering and counter-terrorist-financing duties that come with being a crypto asset service provider in South Africa. It is written for clients, not for auditors, and it exists so that nothing we ask you for at onboarding is a surprise.

It is not our Risk Management and Compliance Programme. The RMCP is an internal document approved by the board, and it is not published — a document that tells the public exactly which patterns trigger a review is a document that tells the wrong people how to avoid triggering one. What is published here is the shape of the programme, the statutory basis for each duty, and what each duty means for you in practice.

Nothing in this document is legal advice, and it does not restate the whole of South African anti-money-laundering law. Where a section names a statute, read the statute if the point matters to you.

Our status: accountable institution under Item 22

Crypto asset service providers were added to Schedule 1 of the FIC Act as Item 22 with effect from 19 December 2022. From that date, a business that exchanges crypto assets for fiat currency, exchanges one crypto asset for another, transfers crypto assets, or safeguards them for a client, is an accountable institution in the same statutory category as a bank, an attorney holding client funds, or a foreign-exchange trader.

Being an accountable institution is not a badge. It is a list of duties, each with its own section number and its own penalty for failure:

  • Register with the Financial Intelligence Centre and report through the goAML platform.
  • Develop, document, maintain and implement a Risk Management and Compliance Programme under section 42.
  • Establish and verify the identity of every client under section 21, and apply enhanced measures under section 21A where the risk is higher.
  • Understand the beneficial ownership of legal persons and trusts.
  • Conduct ongoing due diligence and monitor transactions under section 21C.
  • Keep records for five years under sections 22 and 23.
  • File cash threshold reports under section 28, terrorist property reports under section 28A, and suspicious and unusual transaction reports under section 29.
  • Appoint a person responsible for compliance and train staff under section 42A.
  • Apply the Travel Rule set out in FIC Directive 9 of 2024.

Our registration with the Financial Intelligence Centre and our goAML reporting credentials are held in the name of registered company name — to be confirmed. The regulatory status page sets out the licences and registration numbers, with links to the public registers where you can check them without asking us for anything: see compliance and regulatory status.

The Risk Management and Compliance Programme (section 42)

Section 42 requires every accountable institution to have a written RMCP that has been approved by the board of directors or the most senior governing body. It is not a policy that a compliance officer writes alone and files. It has to describe, in enough detail to be tested, how the institution identifies and rates money-laundering and terrorist-financing risk, and what it does at each rating.

Ours rates risk across four dimensions:

  • Client risk — natural person or legal person, complexity of the ownership structure, whether the client is a politically exposed person or connected to one, adverse media, and how much of the client's story we can independently corroborate.
  • Geographic risk — the client's residence and tax residence, the jurisdictions the funds have touched, and whether any of those jurisdictions are subject to a FATF call for action or increased monitoring.
  • Product and transaction risk — the asset, the direction, the size relative to the client's declared profile, the number of counterparties involved, and whether the crypto leg involves a self-hosted wallet or a regulated counterparty.
  • Delivery channel risk — whether the client was onboarded face to face at our Cape Town office or remotely, and how the documents reached us.

The rating decides the depth of due diligence, whether senior management has to approve the relationship, how often the file is refreshed, and what a trader is allowed to execute without escalating. The programme is reviewed at least annually, and whenever the law, a directive, or our own experience says it should be reviewed sooner. Changes are minuted.

Customer due diligence (section 21)

Section 21 prohibits us from establishing a business relationship or concluding a single transaction with a client until we have established and verified their identity. There is no discretion in this and no client-relations exception to it. A desk that offers to skip it is either breaking the law or is not what it says it is.

For a natural person, the baseline is full name, date of birth, South African identity number or passport number, nationality, residential address, contact details, income tax number where one exists, and the purpose and intended nature of the relationship. Identity is verified against the document itself and, where available, against independent data. Address is verified against a document that is not the same document that proved identity.

For a legal person, the baseline adds the registered name, registration number, registered address, trading address, nature of business, the identity of every person authorised to act on the entity's behalf, and the identity of every person exercising executive control. For a trust, it adds the trust deed, the trustees, the founder, and the named or ascertainable beneficiaries.

Source of funds is part of standard due diligence, not an extra. We ask where the rand or the crypto asset in this particular transaction came from, and we ask for something that shows it: a payslip, a sale agreement, a company resolution, an exchange statement, a wallet history. The answer has to be consistent with everything else on the file.

The practical version of all of this — which documents to have ready, in which format, and how long the checks usually take — is on the onboarding and KYC page.

Enhanced due diligence (section 21A)

Section 21A requires additional measures where the risk of money laundering or terrorist financing is higher than the ordinary case. We apply enhanced due diligence when, among other triggers:

  • the client, a beneficial owner, or a close associate is a politically exposed person — see sanctions and politically exposed persons;
  • the ownership structure is opaque, layered across several jurisdictions, or uses nominees;
  • the client, the counterparty or the funds are connected to a jurisdiction under FATF increased monitoring or a call for action;
  • the transaction is materially larger, faster or differently shaped than the client's declared profile;
  • blockchain analytics attribute the incoming funds, directly or at one remove, to a darknet market, a ransomware address, a sanctioned entity, a known fraud cluster or a mixing service;
  • the client was onboarded remotely and something in the file could not be corroborated independently;
  • adverse media or an open-source check raises a question the client has not already answered.

Enhanced measures mean, in practice: source of wealth as well as source of funds, documentary corroboration rather than a statement, senior management approval before the relationship starts or continues, tighter transaction limits, and a shorter review cycle. It is slower. It is meant to be.

Beneficial ownership

Where a client is a legal person, a partnership or a trust, we are required to look through the entity to the natural persons who ultimately own or control it. We follow the ownership chain until we reach natural persons, and we record each layer.

Where no natural person meets the ownership test, we identify the persons who exercise control by other means, and failing that, the persons holding the senior management positions. We do not accept "the company owns itself" or a chain that terminates in an entity in a jurisdiction that publishes nothing.

Since April 2023, companies and close corporations have had to file beneficial ownership registers with the CIPC, and trustees with the Master of the High Court. We will ask to see what you filed, and we will compare it with what you tell us. Where the two do not match, we will ask why before we do anything else.

Ongoing due diligence and monitoring (section 21C)

Due diligence is not a gate you pass once. Section 21C requires an accountable institution to conduct ongoing due diligence on a business relationship, which includes monitoring transactions to make sure they are consistent with what the institution knows about the client, their business and their risk profile.

For this desk that means three things. First, transactions are reviewed against the profile the client gave us at onboarding, and a material departure from it is a question, not an exception. Second, client files are refreshed on a cycle set by risk rating, and sooner if something changes — a new controller, a new banking arrangement, a new jurisdiction. Third, screening against sanctions and PEP data is continuous rather than a single check at onboarding, because a client who was clear in March may not be clear in September.

If your circumstances change in a way that affects any of this — a change of address, of tax residence, of the controlling mind of a company, of the source of the funds you trade — tell us. It is faster to update a file than to unblock a transaction.

Record keeping: five years (sections 22 and 23)

Sections 22 and 23 require an accountable institution to keep, for at least five years, the records obtained through customer due diligence and the records of every transaction concluded. The five years run from the date the business relationship ends, or from the date the single transaction was concluded.

What we keep includes the identity and verification documents, the source-of-funds and source-of-wealth material, the correspondence in which a quote was given and accepted, the amount, the asset, the rate, the fees, the settlement instructions, the bank references and the on-chain transaction identifiers.

Two consequences worth stating plainly. You cannot ask us to delete a transaction record — the FIC Act requires us to keep it, and section 14 of the Protection of Personal Information Act allows retention where another law requires it. And where a report has been made to the Financial Intelligence Centre, the record must be retained and may be requested by the Centre or by a law-enforcement authority acting under a lawful instrument. How this interacts with your data protection rights is set out on the privacy policy.

Cash threshold reports (section 28)

Section 28 requires an accountable institution to report to the Financial Intelligence Centre any cash transaction, or series of apparently linked cash transactions, above the prescribed threshold. The threshold is R49 999.99 — meaning that a cash amount of R50 000 or more, in a single transaction or in linked transactions, is reportable.

The report is factual. It is not an allegation about you, it does not mean anything has gone wrong, and it does not require your consent. It is filed regardless of how ordinary the transaction is.

In practice this rarely arises here, because this desk does not settle in cash. Rand moves by EFT, RTC or PayShap between bank accounts in the client's own name. That is a deliberate design choice: it produces a clean audit trail for both sides, and it removes an entire category of risk. Where a cash element does arise, the reporting duty applies and we will tell you it applies.

Suspicious and unusual transaction reports (section 29)

Section 29 is the duty that clients understand least and should understand best. It requires any person who carries on a business — not only accountable institutions — to report to the Financial Intelligence Centre where they know or suspect that property is the proceeds of unlawful activities, that a transaction has no apparent business or lawful purpose, that it may be relevant to the investigation of a tax offence, or that it relates to terrorist financing.

There is no monetary threshold. A small transaction is as reportable as a large one. The report must be filed within 15 days of the suspicion arising, excluding Saturdays, Sundays and public holidays.

Section 29 reports do not require proof, only a reasonable suspicion, and filing one is not an accusation. Section 38 protects a person who reports in good faith from civil or criminal liability for having done so.

The part that affects you directly is the prohibition on tipping off. Section 29(3) makes it an offence to disclose that a report has been made or is contemplated, or to disclose information that could prejudice an investigation. So:

  • we cannot tell you whether a report has been filed;
  • we cannot tell you that one is being considered;
  • if a transaction is delayed or declined, we may not be able to give you the real reason;
  • a vague answer from us is sometimes a legal requirement and not evasiveness.

We would rather say this on a public page than have you discover it mid-transaction and read it as bad faith.

The Travel Rule (Directive 9 of 2024)

FIC Directive 9 of 2024 implements the FATF travel rule for crypto asset transfers in South Africa and has been in force since 30 April 2025. It requires originator and beneficiary information to accompany a transfer between crypto asset service providers, and it has no minimum threshold. Every transfer is in scope, whatever its size.

What that means at this desk. When we send a crypto asset to another service provider on your instruction, we transmit the required originator and beneficiary information to that provider. When we receive one, we expect the same information to arrive with it. This is why a trader will ask who controls the destination address, and why "send it to my friend, he will settle with me later" turns into a conversation rather than an instruction.

Below R5 000 a reduced information set applies and the ordering institution is not required to verify it. Read that carefully: it is relief from the verification step, not anonymity. The information still travels, it is still recorded, and it is still kept for five years. Anyone selling a sub-R5 000 transfer to you as private has either not read the directive or is relying on you not having read it.

Transfers to and from self-hosted wallets are not prohibited. Where one is involved we take reasonable measures to establish that the wallet is controlled by our client, and we apply additional measures where the risk is higher. If a counterparty provider does not meet the directive, or the information arrives incomplete, we have three options in this order: request what is missing, hold the transfer, or decline it.

Training, screening and the compliance function

Section 42A requires an accountable institution to provide ongoing training to its employees so that they can comply with the Act and with the RMCP, and to appoint a person with the authority to enforce compliance.

Everyone on this desk who speaks to a client, sees a document, or touches a settlement is trained before they do so and re-trained at least annually. Training covers the FIC Act duties, the RMCP, sanctions and PEP screening, the travel rule, red-flag typologies specific to crypto asset conversion in South Africa, the tipping-off prohibition, and the internal escalation route. Attendance and assessment are recorded. Staff are screened before appointment.

The compliance officer is compliance officer — to be confirmed, who reports to the board on compliance matters, owns the RMCP, approves higher-risk relationships, and is the person who decides whether a report is filed. A trader cannot overrule a compliance decision, and commercial pressure is not a consideration in one.

Regulatory queries: support@conexus-crypto.com or +27 76 560 1228. If you want to raise something formally rather than ask a question, use the complaints procedure.

When we delay, decline or terminate

We will delay a transaction where due diligence is incomplete, where a screening hit needs to be resolved, or where information required by the travel rule has not arrived. We will decline a transaction, or end a relationship, where due diligence cannot be completed, where the explanation given does not hold together, where the funds or counterparty fall within our prohibited use policy, or where continuing would put us in breach of the law.

A declined transaction is not a judgment about you as a person, and it is frequently the product of a rule rather than of an opinion. Where we may lawfully explain, we will. Where section 29(3) prevents us, we will say that we cannot explain rather than invent a reason.

If a crypto asset has already been received when a transaction is declined, we will not simply keep it. Subject to any legal restriction, it is returned to the verified source of origin, in the same asset, net of the network cost of the return. It is never sent to a different address or a different person on request. The mechanics are set out under cancellation, reversal and refunds.

Review of this document

This document is reviewed at least annually and whenever the FIC Act, a directive, a public compliance communication or our own risk assessment changes in a way that affects it. The version number, effective date and last-reviewed date are at the top of the page. Dated changes in South African crypto asset regulation are tracked separately on the regulatory updates page.

If you believe something on this page is wrong, write to support@conexus-crypto.com with the instrument and the correction, and we will check it.

Read next

Ask before you send, not after.

A question answered at the start costs a minute. The same question after funds have moved costs a great deal more.

Investing in crypto assets may result in the loss of capital, as the value is variable and can go up as well as down. A crypto asset is not legal tender and does not fall within the National Payment System Act. Conexus Crypto provides an exchange service only and does not provide financial, investment, legal or tax advice.
WhatsApp Request a quote
ДизайнНовыйПрежний