Jurisdiction guide

Compliance in South Africa: what you must do, and in what order.

Regulatory infrastructure for South African fintechs, digital asset businesses, and the international companies entering the market.

Regulatory map

Who regulates what in South Africa

Key regulators
SARB, FSCA, the Information Regulator, FIC
Central bank
the South African Reserve Bank
Securities regulator
the FSCA
Financial intelligence unit
the Financial Intelligence Centre
Data protection authority
the Information Regulator
Privacy law
POPIA
Payment licence categories
SARB payment system participation and FSCA financial services provider licences
Digital asset framework
CASP licensing under the FAIS Act

Licensing

The licensing route

SARB and FSCA authorisation, CASP licensing under the FAIS Act, POPIA compliance, and AML/CFT programmes that survive an FIC inspection.

Why now

CASP licensing under the FAIS Act, FIC Act amendments after greylisting, and POPIA enforcement have all reshaped what supervisors expect.

Entering from abroad

Entering South Africa means FSCA authorisation, SARB exchange control considerations, POPIA compliance, and FIC Act obligations.

Where to start

For policy tracking and analysis of regulatory change in South Africa, read Legum Dialogue. This guide is a practical summary, not legal advice.

Legum provides regulatory and compliance advisory services. Where a matter requires licensed legal representation, we will say so clearly before work begins.