DeFi protocol frontend in Burkina Faso
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Burkina Faso without local incorporation, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- General AML/CFT Law N°024-2016/AN applies to any entity dealing with funds or assets, including virtual assets — this could extend to DeFi frontends if they are deemed to handle funds or assets on behalf of users (bf.licensing.amlkyc-burkina-faso-is-a, bf.aml.law-n024-2016an-of-20-may)
- Identification and verification requirements: full name, date of birth, address, nationality, official ID document number(s) for natural persons; name, legal form, registration number, constitutional documents, and BO identification for legal entities (bf.aml.identification-and-verification-of-identity, bf.aml.for-natural-persons-full-name, bf.aml.for-legal-entities-name-legal)
- Beneficial ownership identification required — understand ownership and control structure (bf.aml.beneficial-ownership-identification-identify-and)
- Purpose-and-intended-nature-of-business-relationship documentation required (bf.aml.purpose-and-intended-nature-of)
- Ongoing monitoring and transaction scrutiny to ensure consistency with customer risk profile (bf.aml.ongoing-monitoring-conduct-ongoing-due)
- Risk-based approach: EDD for high-risk customers/PEPs; SDD only in low-risk scenarios (bf.aml.risk-based-approach-apply-enhanced-due)
- Suspicious transaction reporting (STR) to CENTIF (Burkina Faso's FIU) — mandatory for any suspected ML/TF activity, regardless of amount, with whistleblower protections and anti-tipping-off rules (bf.aml.vasps-like-other-financial-institutions, bf.aml.the-report-must-be-made, bf.aml.the-vasp-and-its-employees, bf.aml.tipping-off-informing-the-customer)
- Record-keeping: transaction records, CDD documents, STR records must be retained (bf.aml.all-necessary-records-of-transactions, bf.aml.records-of-the-information-obtained, bf.aml.records-pertaining-to-suspicious-transaction)
- CENTIF is the supervising FIU; BCEAO oversees financial institutions regionally (bf.aml.centrale-nationale-de-traitement-des, bf.aml.banque-centrale-des-tats-de)
Key Restrictions
- No specific regulatory framework exists for VASPs or DeFi frontends — operating is a legal grey area with no clear licensing pathway (bf.licensing.no-specific-regulatory-framework-for, bf.licensing.neither-exists-for-crypto-specific-activities)
- BCEAO maintains that cryptocurrencies are not legal tender in the UEMOA zone and has issued public warnings against their use (bf.licensing.the-bceao-has-on-several, bf.enforcement.bceaos-stance-the-bceao-has)
- Fiat-to-crypto on-ramps/off-ramps through regulated banking channels are effectively impossible: BCEAO-supervised institutions will reject crypto-related banking services (bf.licensing.implication-for-vasps-this-means, bf.licensing.exchanges-fiat-to-crypto-crypto-to-crypto-no-specific)
- If fee-taking involves receiving or transacting in CFA Francs (XOF), existing payment services regulations may apply and require a payment institution license — but such a license would likely be denied for crypto-related activities (bf.licensing.payment-processors-facilitating-crypto-payments)
- New BCEAO external financial relations regulations (15 Instructions) effective August 1, 2025 may further restrict cross-border crypto flows (bf.licensing.bceao-circulars-and-communications)
Key Risks
- Extreme regulatory ambiguity: DeFi frontends have no defined legal status — what is not prohibited is not permitted either, creating unpredictability (bf.licensing.entities-operating-in-this-space, bf.enforcement.lack-of-specific-national-framework)
- Banking access risk: inability to open or maintain bank accounts in Burkina Faso/UEMOA due to BCEAO's prohibition stance (bf.licensing.implication-for-vasps-this-means)
- Enforcement risk is low probability but high impact: lack of specific crypto enforcement today does not preclude future retroactive or politically motivated enforcement, especially given the military junta's censorship environment (bf.enforcement.while-not-specific-to-burkina, bf.enforcement.you-might-find-news-articles)
- Fraud/ponzi-scheme association risk: any crypto-related operation may be publicly conflated with scams by BCEAO warnings, creating PR and consumer-protection exposure (bf.enforcement.nature-of-reported-incidents-any, bf.enforcement.general-warnings-as-mentioned-public)
- No consumer protection framework exists for crypto — operator bears full liability for user losses (bf.licensing.entities-operating-in-this-space)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific regulatory framework for VASPs.
A statutory licensing requirement for VASPs does exist in Burkina Faso: art. 58 of Loi n°046-2024/ALT du 30 décembre 2024 prohibits carrying on the professional activity of prestataire de services d'actifs virtuels without prior agrément or autorisation from the competent authority, and art. 3 lists PSAV among the assujettis. What is true is that the regime is not yet operational: art. 59 defers all PSAV-specific requirements to 'les autorités compétentes' and no competent authority has been designated in Burkina Faso, so no agrément can currently be applied for or granted.
GIABA membership and FSRB status are correct: FATF lists GIABA as a FATF-Style Regional Body and Burkina Faso among its members. But it is no longer accurate that there is 'no specific crypto AML/KYC framework': Loi n°046-2024/ALT du 30 décembre 2024 names prestataires de services d'actifs virtuels among the assujettis at art. 3, so the full CDD/record-keeping/STR obligations of that law apply to VASPs by name, not merely 'by expectation'. Note Burkina Faso is a GIABA member, not a FATF member.
Burkina Faso DOES have a national legislative framework covering virtual assets: Loi n°046-2024/ALT du 30 décembre 2024 defines 'actif virtuel' (art. 2-2) and 'prestataire de services d'actifs virtuels' (art. 2-51), makes PSAV assujettis (art. 3), and provides at art. 58 that 'Nul ne peut se livrer à l'activité professionnelle de prestataire de services d'actifs virtuels s'il n'a pas obtenu l'agrément ou l'autorisation préalable de l'autorité compétente.' It is however not operational: no autorité compétente has been designated and no implementing text exists. Separately, no BCEAO instrument imposing a 'blanket prohibition' on regulated institutions facilitating virtual assets could be located, so there was no ban to 'evolve' from; BCEAO's position is that crypto-assets are not currency, not legal tender and not regulated (Governor Kassi Brou, 22 July 2026), and it created a crypto-asset regulatory drafting committee announced 8 May 2026.
BCEAO's 15 New Instructions on External Financial Relations (implementing Regulation No. 06/2024/CM/UEMOA), effective August 1, 2025
Implication for VASPs: This means that entities wishing to operate as crypto exchanges, custody providers, or payment processors in Burkina Faso (or any UEMOA country) will face significant challenges, primarily the inability to obtain banking services from regulated financial institutions within the UEMOA zone. This effectively makes it extremely difficult, if not impossible, to operate legally and effectively.
Both fiat-to-crypto and crypto-to-crypto exchange are within the art. 2-51 definition of prestataire de services d'actifs virtuels in Loi n°046-2024/ALT, and art. 58 requires prior agrément/autorisation from the competent authority — so a VASP-specific licensing obligation exists on paper (though no competent authority has been designated). There is no separate BCEAO instrument prohibiting supervised banks or payment institutions from serving crypto businesses; BCEAO's published position is that crypto-assets are not currency, not legal tender and not regulated, and it is drafting a framework.
Correct that XOF payment processing falls under the UEMOA payment-services regime (Instruction n°001-01-2024 for payment institutions; Instruction n°008-05-2015 for e-money). Incorrect that no crypto-specific licence exists: transfer of virtual assets and services relating to their transfer are enumerated PSAV activities under art. 2-51 of Loi n°046-2024/ALT and require prior agrément under art. 58, albeit from a competent authority not yet designated. The assertion that such payments 'would be prohibited from using regulated financial infrastructure' is not supported by any BCEAO instrument.
Entities operating in this space do so in a legal grey area, exposed to regulatory risks, potential legal challenges, and lack of consumer protection.
Local Presence: Any legally registered business in Burkina Faso would require a local presence and incorporation under Burkinabe law.
No 'Loi n° 024-2016/AN du 20 mai 2016' exists. Burkina Faso's 2016 AML/CFT statute is Loi n° 016-2016/AN du 3 mai 2016 relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme (cited throughout the 2023 GIABA follow-up report), and it transposed UEMOA Directive n° 02/2015/CM/UEMOA rather than FATF/GIABA recommendations directly. That regime has since been replaced: Loi n° 046-2024/ALT du 30 décembre 2024 transposes the UMOA loi uniforme LBC/FT/FP of 31 March 2023 and covers virtual assets expressly, so VASP coverage no longer depends on interpreting 'financial institution' — art. 2 point 2 defines 'actif virtuel', art. 2 point 51 defines 'prestataire de services d'actifs virtuels (PSAV)', art. 3 makes PSAV assujettis, and art. 58 forbids professional PSAV activity without prior agrément or autorisation from the competent authority (no such authority has yet been designated in Burkina Faso).
AML-related identification and verification of identity generally requires collecting and verifying key personal data (such as full name, date of birth, and address) and confirming it through reliable sources, which may include a single government‑issued photo ID or a mix of documentary and electronic methods; a rigid requirement for two physical forms of identification is not a universal or current standard.
For natural persons in the US: Full name, date of birth, place of birth, address, nationality, and official identification document number(s) from reliable, independent sources (such as state-issued driver's license, passport, or Social Security number). Verification must use reliable, independent source documents. Note: The US has no national ID card; verification relies on a decentralized system of state and federal documents. Validity period requirements vary by document type and regulatory context.
For legal entities: Name, legal form, address (registered office and current operational address if different), registered office, official registration number, constitutional documents (e.g., articles of incorporation, bylaws, memorandum and articles of association), and identification of individuals authorized to act on behalf of the entity.
Beneficial Ownership Identification: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer. This includes understanding the ownership and control structure of legal persons and arrangements.
Purpose and Intended Nature of the Business Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conduct ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Apply enhanced due diligence (EDD) for high-risk customers or transactions (e.g., Politically Exposed Persons - PEPs, complex transactions, transactions from high-risk jurisdictions). Simplified due diligence (SDD) may be applied in low-risk scenarios, but not to the extent of foregoing identification entirely.
VASPs are obligated to report any transaction or activity that they suspect to be related to money laundering or terrorist financing, regardless of the amount.
The report must be made promptly to the Financial Intelligence Unit (FIU) of Burkina Faso.
Loi n° 001-2021/AN du 30 mars 2021 is Burkina Faso's personal-data-protection law (portant protection des personnes à l'égard du traitement des données à caractère personnel, which created the CIL); it is not the instrument governing AML disclosure offences and it does not create the offence described. The applicable instrument is Loi n° 046-2024/ALT du 30 décembre 2024, whose art. 63 prohibits an assujetti from disclosing to the owner of the funds or the author of the operation the existence or content of a declaration made to CENTIF — i.e. it penalises tipping-off, which is the opposite of penalising a good-faith report.
"Tipping off" (informing the customer or a third party that an STR has been filed or that an investigation is underway) is strictly prohibited.
All necessary records of transactions, both domestic and international, to enable their reconstruction.
Records of the information obtained through CDD measures (copies of identification documents, account files, business correspondence).
Records pertaining to suspicious transaction reports filed.
The name is wrong: CENTIF stands for 'Cellule Nationale de Traitement des Informations Financières', not 'Centrale Nationale' (spelled out at art. 2 point 18 of Loi n° 046-2024/ALT). The functional description is otherwise correct — CENTIF is Burkina Faso's FIU, receives declarations de soupçon (art. 60), analyses them and disseminates to law enforcement. But the last sentence overstates its role: supervisory compliance enforcement and administrative sanctions sit with each sector's 'autorité de contrôle' (art. 182 of the uniform law scheme), not with CENTIF.
BCEAO is the common central bank of the eight UMOA states (Benin, Burkina Faso, Côte d'Ivoire, Guinea-Bissau, Mali, Niger, Senegal, Togo), but prudential supervision of banks and financial institutions is exercised by the Commission Bancaire de l'UMOA (created 24 April 1990, chaired by the BCEAO Governor), not by BCEAO itself; BCEAO's own instruments regulate e-money issuers (Instruction n° 008-05-2015) and payment institutions (Instruction n° 001-01-2024). Neither BCEAO nor the Commission Bancaire currently supervises PSAV: Loi n° 046-2024/ALT art. 59 defers PSAV requirements to an 'autorité compétente' that Burkina Faso has not designated. A VASP is therefore not brought under BCEAO by resemblance to payment services; it would fall under BCEAO's payment/e-money regimes only if it actually issued e-money or provided a listed payment service.
BCEAO's public position is confirmed as of July 2026 — Governor Jean-Claude Kassi Brou: 'Ce n'est pas une monnaie. Ce n'est pas réglementé. Donc soyez prudents' — and BCEAO has taken no entity-specific enforcement action in Burkina Faso. But 'not regulated' now needs qualification: since 30 December 2024, Loi n° 046-2024/ALT art. 58 makes it unlawful to carry on professional PSAV activity in Burkina Faso without prior agrément or autorisation, and PSAV are assujettis to the full AML/CFT regime (art. 3). What does not exist is an operational regime: no competent authority has been designated under art. 59, so no licence can actually be obtained. BCEAO created the C-CRYPTO drafting committee and held its international crypto-assets conference in Dakar on 8 May 2026; a framework is in preparation with no published timeline.
Correct that Burkina Faso has no operational crypto framework — no licensing regime, no designated crypto regulator, no prudential or conduct rules — but no longer correct that crypto entities are undefined in national law. Loi n° 046-2024/ALT du 30 décembre 2024 defines 'actif virtuel' (art. 2 point 2) and 'prestataire de services d'actifs virtuels' (art. 2 point 51, expressly including custody), makes PSAV assujettis (art. 3), and by art. 58 prohibits professional PSAV activity without prior agrément or autorisation from the competent authority. Art. 59 defers all PSAV-specific requirements to that competent authority, which Burkina Faso has not designated — so a criminal/administrative prohibition exists on paper with no route to compliance and no supervisor to enforce it.
Nature of Reported Incidents: Any incidents related to cryptocurrencies in Burkina Faso are more likely to be:
While not specific to Burkina Faso alone, the BCEAO's position applies to all WAEMU member states: https://www.bceao.int/fr/actualites/mise-en-garde-du-public-relativement-lutilisation-des-monnaies-virtuelles (This specific link refers to a 2020 warning, but the stance remains consistent).
Given the junta's crackdown on media and secret detention of journalists in Burkina Faso, local outlets like LeFaso.net and Sidwaya may not be able to freely publish BCEAO warnings without government censorship or reprisal.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — operating a DeFi protocol frontend in/from Burkina Faso is legally ambiguous with no specific framework; general AML obligations likely apply if the operator handles funds/assets, but fiat on/off-ramps are effectively blocked by BCEAO policy, and no licensing pathway exists.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?