Lesotho -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
Lesotho, like many jurisdictions, is adapting its existing Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) framework to address the risks posed by virtual assets (cryptocurrencies) and Virtual Asset Service Providers (VASPs). The primary driver for these requirements is the international standards set by the Financial Action Task Force (FATF), of which Lesotho is a member through the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG).
While Lesotho may not have highly specific, stand-alone legislation solely for crypto/VASPs yet, they are generally brought under the ambit of existing AML/CFT laws that apply to financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs).
Here's a breakdown of the likely AML/KYC requirements:
AML/CFT Legislation
Lesotho's primary AML/CFT framework is built upon:
- Money Laundering and Proceeds of Crime Act (MLPCA) 2008 (as amended): This is the foundational legislation that defines money laundering offenses, establishes reporting obligations, and sets out the framework for combating financial crime. VASPs are expected to comply with the obligations outlined in this Act, particularly if they are classified as financial institutions or DNFBPs under its scope.
- Financial Intelligence Act 2011 (as amended): This Act establishes the Financial Intelligence Unit (FIU) of Lesotho, defines its powers, and details the requirements for reporting suspicious transactions.
Key Principle: Even without explicit "crypto law," the FATF Recommendations (particularly Recommendation 15 on Virtual Assets and VASPs) require countries to apply AML/CFT requirements to VASPs, including licensing/registration, CDD, record-keeping, and STRs. Lesotho, being a FATF-aligned jurisdiction, is expected to implement these.
Customer Due Diligence (CDD) Requirements
VASPs in Lesotho would be expected to implement robust CDD measures, typically including:
- Identification and Verification:
- For Individuals: Obtaining and verifying name, residential address, date of birth, nationality, and a unique identification number (e.g., national ID, passport). Verification should be done using reliable, independent source documents or data.
- For Legal Entities: Obtaining and verifying company name, legal form, proof of incorporation/registration, address of principal place of business, directors' names, and beneficial ownership information.
- Understanding the Nature of Business/Purpose of Relationship: VASPs must understand the nature and purpose of the business relationship or occasional transaction.
- Ongoing Monitoring: Continuously monitoring the business relationship, including scrutiny of transactions undertaken throughout the course of the relationship, to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
- Source of Funds/Wealth: Given the inherent risks of virtual assets, VASPs are expected to obtain information on the source of funds or source of wealth, especially for large transactions or high-risk customers.
- Enhanced Due Diligence (EDD): Required for high-risk situations, which typically include:
- Politically Exposed Persons (PEPs)
- Customers from high-risk geographic areas (as identified by FATF, national authorities, or the VASP's own risk assessment)
- Complex or unusual transactions
- Transactions involving new technologies or products where the risks have not been fully assessed (which can include certain crypto activities).
- Simplified Due Diligence (SDD): Permitted in strictly defined low-risk scenarios, but this is less common for VASP activities due to the inherent risks.
Suspicious Transaction Reporting (STR)
VASPs, like other financial institutions and DNFBPs, are obligated to:
- Report Suspicious Transactions: Report to the FIU any transaction (or attempted transaction) where they have reasonable grounds to suspect that it may involve the proceeds of criminal activity, or relates to money laundering or terrorist financing. This includes suspicious activities in virtual assets.
- No Tipping-Off: Prohibit informing the customer or third parties that an STR has been made (no "tipping-off").
- Prompt Reporting: Reports must be made promptly, usually within a few days of the suspicion arising.
Record-Keeping Obligations
VASPs are required to maintain records for a specified period to assist with investigations and provide an audit trail. This typically includes:
- Customer Identification Data: Copies of identity documents, verification records.
- Transaction Records: All transaction data, including dates, amounts, types of virtual assets, originators, beneficiaries, and payment methods.
- Business Correspondence: Relevant correspondence with customers regarding their transactions and relationships.
- Analysis of Complex/Unusual Transactions: Records of the background and purpose of any complex, unusual large transactions, and all unusual patterns of transactions.
- Duration: Records must typically be kept for a minimum period of five (5) years after the business relationship is terminated or after an occasional transaction is completed.
Authority Overseeing Compliance
The primary authority responsible for overseeing AML/CFT compliance for VASPs and other regulated entities in Lesotho is:
- Financial Intelligence Unit (FIU) of Lesotho: The FIU is the central national agency responsible for receiving, analysing, and disseminating suspicious transaction reports. It also provides guidance and exercises oversight on AML/CFT compliance across various sectors, including those that might encompass VASPs.
- FIU Lesotho Website: http://www.fiulesotho.org.ls/
While the FIU handles STRs and compliance oversight, the Central Bank of Lesotho (CBL) also plays a crucial role in regulating financial services and payment systems. If VASPs engage in activities that fall under the broader definition of financial services (e.g., issuing stablecoins, providing payment services), they might also fall under the CBL's purview, especially regarding licensing or registration requirements for such specific activities.
- Central Bank of Lesotho Website: https://www.centralbank.org.ls/
Important Note: The regulatory landscape for virtual assets is rapidly evolving. VASPs operating or intending to operate in Lesotho should consult directly with the FIU Lesotho and potentially the Central Bank of Lesotho to understand the most current and specific requirements applicable to their business model and operations. Seeking local legal counsel specializing in financial regulation is also highly recommended.
Source Data
The Money Laundering and Proceeds of Crime Act, 2008 (Act No. 4 of 2008) is Lesotho's foundational AML statute, but virtual asset service providers are not accountable institutions under its Schedule 1: the most recent Schedule amendment, Legal Notice No. 69 of 2024 published 25 June 2024 under section 112 of that Act, inserts only a person conducting safekeeping and administration of cash or liquid securities, and no virtual-asset category has ever been added.
Lesotho has no Financial Intelligence Act 2011: the Financial Intelligence Unit is established by section 14 of the Money Laundering and Proceeds of Crime Act, 2008 as a juristic person responsible to the Minister, suspicious transaction reporting arises under section 18 of that Act and the tipping-off prohibition under section 24(1).
Section 17(4) of the Money Laundering and Proceeds of Crime Act, 2008 requires records to be kept for at least five years from the date the relevant business or transaction was completed, but that duty binds only the accountable institutions listed in Schedule 1 of the Act, a list that contains no virtual asset service provider category after Legal Notice No. 69 of 2024.
Lesotho's Financial Intelligence Unit is established by section 14 of the Money Laundering and Proceeds of Crime Act, 2008 as a juristic person responsible to the Minister, and receives, analyses and disseminates suspicious transaction reports from the accountable institutions listed in Schedule 1 of that Act, which contains no virtual asset service provider category and gives the Unit no VASP oversight.
Lesotho has no virtual-asset statute, no VASP licence or registration regime and no prohibition on holding or trading cryptocurrency: the Central Bank of Lesotho's press statement of 20 May 2024 places cryptocurrencies outside its regulatory perimeter, the Bank's legislation index carries no virtual-asset, crypto-asset or fintech instrument, and the September 2023 ESAAMLG mutual evaluation rates Recommendation 15 Non-Compliant and records that Lesotho has no legal and institutional framework to allow VA and VASP activities.
The Central Bank of Lesotho has issued two public warnings on cryptocurrencies, on 9 November 2017 and on 20 May 2024; the 20 May 2024 press statement records that cryptocurrencies do not fall under the purview of the regulatory scope of the Central Bank of Lesotho and that there shall be no recourse to the Bank in the event of losses.
Lesotho's central bank is the Central Bank of Lesotho, and no institution named Bank of Lesotho or BOL exists; the Bank is the integrated regulator of banks, insurers, pension funds, capital markets and payment systems, licensing financial institutions under the Financial Institutions Act, 2012 (Act No. 3 of 2012), and its press statement of 20 May 2024 places cryptocurrencies outside its regulatory perimeter.
Lesotho's Financial Intelligence Unit is established by section 14 of the Money Laundering and Proceeds of Crime Act, 2008 (Act 4 of 2008) and receives, analyses and assesses reports of suspicious transactions under section 15, but its reporting perimeter reaches only accountable institutions listed in Schedule 1, and virtual asset service providers remain absent from that Schedule after Legal Notice No. 69 of 2024.
Lesotho has no Anti-Money Laundering and Combating of Financing of Terrorism Act, 2011; its anti-money-laundering statute is the Money Laundering and Proceeds of Crime Act, 2008 (Act 4 of 2008), amended by the Money Laundering and Proceeds of Crime (Amendment) Act No. 7 of 2016, and the 2011-dated regional AML statute belongs to Eswatini, whose Money Laundering and Financing of Terrorism (Prevention) Act is Act 6 of 2011.
The Central Bank of Lesotho Act 2000 constitutes and confers autonomy on the Central Bank of Lesotho and is listed in the Bank's own legislation index, but it carries no virtual-asset, crypto-asset or regulatory-sandbox provision, and the Bank's licensing statute for financial institutions is the separate Financial Institutions Act, 2012 (Act No. 3 of 2012).
Lesotho's Financial Institutions Act is Act No. 3 of 2012, published in the Gazette on 27 February 2012 and commencing on publication; it defines a financial institution as a deposit taking institution or a non-deposit taking institution carrying on financial activities as stipulated in its licence, and it contains no reference to virtual assets, crypto-assets, digital assets, electronic money or a regulatory sandbox.
Lesotho neither bans nor licenses cryptocurrency activity: it has no virtual-asset statute, no virtual-asset service provider licence and no VASP registration, and the September 2023 ESAAMLG mutual evaluation records that Lesotho does not have a legal and institutional framework to allow VAs and VASPs activities to be carried out.
Crypto businesses in Lesotho face no licensing, capital or conduct requirements, but the Central Bank of Lesotho's press statement of 20 May 2024 warns that offering cryptocurrencies as financial investment opportunities to the public exposes promoters to sections 27 and 28 of the Central Bank of Lesotho Capital Market Regulations of 2014, which require investment advisers to be licensed by the Bank.
Lesotho has not adopted the FATF travel rule for virtual assets and no Money Laundering and Proceeds of Crime (Amendment) Act, 2022 exists; the Financial Intelligence Unit's legislation index shows the only amending Act is No. 7 of 2016, the most recent Schedule amendment is Legal Notice No. 69 of 2024, and ESAAMLG rated Lesotho Non-Compliant on Recommendation 15 in September 2023.
The Central Bank of Lesotho licenses and supervises financial institutions under the Financial Institutions Act, 2012 (Act No. 3 of 2012), while anti-money-laundering compliance by accountable institutions is administered by the Financial Intelligence Unit under the Money Laundering and Proceeds of Crime Act, 2008; neither body supervises virtual asset service providers, which are not accountable institutions in Lesotho.
No Money Laundering and Proceeds of Crime (Amendment) Act was assented to in Lesotho on 14 July 2022 and no Lesotho instrument brings virtual assets or virtual asset service providers into law; Lesotho's most recent Schedule amendment, Legal Notice No. 69 of 2024 published on Tuesday 25 June 2024 under section 112 of the Money Laundering and Proceeds of Crime Act 2008, inserts only a person conducting safekeeping and administration of cash or liquid securities activities on behalf of other persons.
Lesotho's Money Laundering and Proceeds of Crime Act, 2008 requires accountable institutions to identify and verify customers under section 16, and requires an accountable institution which is a bank to include accurate originator information on electronic funds transfers under section 22 so that the information remains with the transfer, but virtual asset service providers are not accountable institutions in Lesotho and fall outside both duties.
Lesotho has no virtual-asset travel rule and no virtual-asset transfer threshold; section 22 of the Money Laundering and Proceeds of Crime Act, 2008 binds only an accountable institution which is a bank to carry accurate originator information on electronic funds transfers, and ESAAMLG rated Lesotho Non-Compliant on Recommendation 15 in its mutual evaluation adopted in September 2023.
No Lesotho legislation imposes systems-and-controls or travel-rule obligations on virtual asset service providers, because Schedule 1 to the Money Laundering and Proceeds of Crime Act, 2008, as last amended by Legal Notice No. 69 of 2024, contains no virtual-asset entry, and ESAAMLG found in September 2023 that Lesotho does not have a legal and institutional framework to allow VAs and VASPs activities to be carried out.
Lesotho requires accountable institutions to keep transaction and identification records for at least five years from the date the relevant business or transaction was completed, under section 17(4) of the Money Laundering and Proceeds of Crime Act 2008; no seven-year alternative exists, and no record-keeping duty attaches to virtual-asset activity because Schedule 1 lists no virtual-asset service provider.
Lesotho imposes no virtual-asset travel-rule obligation: the country has no virtual-asset statute and no VASP licence, virtual-asset service providers are absent from Schedule 1 of the Money Laundering and Proceeds of Crime Act 2008, and the ESAAMLG mutual evaluation adopted in September 2023 rated Recommendation 15 Non-Compliant on the finding that Lesotho lacks a legal and institutional framework for virtual assets.
Section 18(1) of the Money Laundering and Proceeds of Crime Act 2008 requires accountable institutions listed in Schedule 1 to report suspicious transactions to the Financial Intelligence Unit and the Authority; virtual-asset service providers are not accountable institutions in Lesotho, so no crypto-sector suspicious-transaction reporting duty arises.
Lesotho issues no virtual-asset service provider licence or operating permit, so no VASP licence or permit exists to revoke; under the Money Laundering and Proceeds of Crime Act 2008 a legal person faces a fine of not less than M250,000 for compliance failures under section 26(3) and not less than M500,000 for the money-laundering offence under section 25(2), figures well below the millions of maloti asserted.
50 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by SearXNG+LLM .
Primary Sources
fiulesotho.org.ls. (n.d.). fiulesotho.org.ls. Retrieved April 22, 2026, from http://www.fiulesotho.org.ls/
centralbank.org.ls. (n.d.). centralbank.org.ls. Retrieved April 22, 2026, from https://www.centralbank.org.ls/
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →