Mali -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
The regulatory landscape for cryptocurrency and virtual asset service providers (VASPs) in Mali, like in many West African nations, is still evolving. While there isn't yet a dedicated, comprehensive law specifically for VASPs, they are generally expected to comply with existing Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) legislation applicable to financial institutions, often relying on interpretations and international standards set by the Financial Action Task Force (FATF).
Mali is a member state of the West African Economic and Monetary Union (UEMOA/WAEMU), and its financial regulations are heavily influenced by UEMOA directives and the Central Bank of West African States (BCEAO).
Here's a breakdown based on available information:
AML/CFT Legislation
Mali's primary AML/CFT legal framework is derived from UEMOA directives transposed into national law.
UEMOA Directive No. 02/2015/CM/UEMOA
- Full Name: Directive relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme dans les États membres de l’UEMOA. (Directive on the fight against money laundering and terrorist financing in UEMOA member states).
- Purpose: This regional directive sets the foundational AML/CFT standards for all UEMOA member states, including Mali, aligning with FATF recommendations.
Malian National Law:
- Law N°2018-024 of August 21, 2018, amending Ordinance N°2015-032/P-RM of June 19, 2015, relating to the fight against money laundering and terrorist financing.
- Purpose: This is Mali's national legislation implementing the UEMOA directives. While it doesn't explicitly mention "virtual assets" or "VASPs" (as it largely predates comprehensive FATF VASP guidance), the broad definitions of "financial institutions," "financial activities," and "transfer of funds" could potentially be interpreted to include certain VASP activities.
- Note: The BCEAO issued Communiqué N°18/2021 in 2021, reiterating that virtual assets are not legal tender in the UEMOA zone and warning financial institutions against their involvement in certain virtual asset activities, pending a specific regulatory framework. This indicates a cautious approach and an acknowledgment of the sector, but not yet a full regulatory embrace for VASPs.
Customer Due Diligence (CDD) Requirements
Based on the general AML/CFT law, VASPs in Mali (if recognized and regulated) would be expected to apply CDD measures consistent with FATF standards, which typically include:
- Customer Identification and Verification:
- For natural persons: Collecting and verifying identity (e.g., name, address, date of birth, nationality, unique identification number via official documents like passport or national ID card).
- For legal entities: Collecting and verifying legal name, registered address, legal form, proof of incorporation, names of directors/authorized signatories, and identification of beneficial owners.
- Beneficial Ownership Identification: Identifying and verifying the natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.
- Purpose and Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or occasional transaction.
- Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of that relationship to ensure consistency with the institution’s knowledge of the customer, their business, and risk profile.
- Risk-Based Approach: Applying enhanced due diligence (EDD) for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, or those engaged in complex/unusual transactions) and simplified due diligence (SDD) for lower-risk scenarios.
Suspicious Transaction Reporting (STR)
VASPs operating in Mali would be obligated to report suspicious transactions to the Financial Intelligence Unit (FIU).
- Obligation: Any transaction (regardless of amount) that an institution knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorist financing must be reported.
- No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that an STR has been filed or that a money laundering or terrorist financing investigation is being conducted.
Record-Keeping Obligations
Mali's AML/CFT law typically requires financial institutions to retain records for a minimum period.
- Transaction Records: All transaction data, including the amount, currency, date, and details of the parties involved (originator and beneficiary), should be kept.
- Customer Identification Records: Records obtained through CDD measures (copies of identification documents, account files, business correspondence) must be retained.
- Retention Period: Generally, these records must be kept for at least five (5) years after the business relationship ends or after the date of an occasional transaction.
Authority Overseeing Compliance
The oversight for AML/CFT compliance in Mali involves several key institutions:
Cellule Nationale de Traitement des Informations Financières (CENAREF) du Mali:
- Role: This is Mali's Financial Intelligence Unit (FIU). It is the primary body responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies. CENAREF plays a central role in the fight against money laundering and terrorist financing.
- URL: Official government websites often link to CENAREF. While a dedicated, stable public website specifically for CENAREF Mali can be elusive, its information is typically found through the Ministry of Economy and Finance or the UEMOA regional bodies. A direct, stable public URL specifically for CENAREF Mali is not consistently available, but information may be found via the Ministry of Economy and Finance of Mali.
Central Bank of West African States (BCEAO):
- Role: The BCEAO is the central bank for the eight UEMOA member states, including Mali. It is the primary regulator and supervisor for banks and traditional financial institutions. While it has expressed caution regarding virtual assets (as per Communiqué N°18/2021), it would likely play a significant role in any future licensing or prudential supervision of VASPs in the UEMOA zone.
- URL: www.bceao.int
Ministry of Economy and Finance (Mali):
- Role: Responsible for overall economic and financial policy, including the transposition and enforcement of AML/CFT legislation.
Current State and Future Outlook for VASPs in Mali:
- Lack of Specific VASP Licensing: Currently, there is no explicit licensing regime for VASPs in Mali. This means that while they might be implicitly covered by general AML/CFT laws, the specifics of their operation, authorization, and prudential regulation remain largely undefined.
- FATF Standards: As a country within a region subject to FATF scrutiny, Mali is under pressure to implement FATF Recommendation 15 (which specifically addresses virtual assets and VASPs) and its interpretive note, including the "Travel Rule" (FATF Recommendation 16 for wire transfers, extended to VASPs). This means that even without explicit national VASP legislation, VASPs are generally expected to adhere to these international best practices.
- Risk and Uncertainty: Operating as a VASP in Mali carries regulatory uncertainty due to the evolving framework. It is crucial for any entity considering VASP activities to seek specific legal counsel in Mali to understand the current interpretations of existing laws and any new directives that may emerge.
Disclaimer: This information is for general guidance and informational purposes only, and does not constitute legal advice. The regulatory landscape for virtual assets is rapidly changing. It is highly recommended to consult with local legal and regulatory experts in Mali for specific advice tailored to your VASP operations.
Source Data
Directive n.02/2015/CM/UEMOA du 2 juillet 2015 is a real instrument but is no longer the operative AML/CFT framework. At the regional level it has been replaced by Directive n.01/2023/CM/UEMOA du 16 juin 2023 relative a la lutte contre le blanchiment de capitaux, le financement du terrorisme et de la proliferation des armes de destruction massive, and by the UMOA loi uniforme LBC/FT/FP du 31 mars 2023. For Mali specifically the operative instrument is Ordonnance n.2024-011/PT-RM du 30 aout 2024, which transposes the 2023 uniform law and is what Malian decrees have cited since.
Full Name: Directive relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme dans les États membres de l’UEMOA. (Directive on the fight against money laundering and terrorist financing in UEMOA member states).
The 2015 directive no longer sets the foundational standard. Since 16 June 2023 the regional instrument is Directive n.01/2023/CM/UEMOA, implemented through the UMOA loi uniforme LBC/FT/FP du 31 mars 2023, and Mali transposed it by Ordonnance n.2024-011/PT-RM du 30 aout 2024. Mali's own AML statute now covers proliferation financing and virtual assets, neither of which is in the 2015 directive. Note also that Mali is a member of GIABA, the FATF-style regional body, not of the FATF itself.
No such instrument sits in Mali's AML/CFT chain. Mali's predecessor uniform law is Loi n.2016-008 du 17 mars 2016 portant Loi uniforme relative a la lutte contre le blanchiment de capitaux et le financement du terrorisme - cited verbatim in the visas of Arrete n.2024-3011/MEF-SG du 26 aout 2024, i.e. still the operative AML basis days before the new ordinance. Mali's current AML statute is Ordonnance n.2024-011/PT-RM du 30 aout 2024 portant lutte contre le blanchiment de capitaux, le financement du terrorisme et de la proliferation des armes de destruction massive (JO n. special 17 du 2 septembre 2024). Independently, the cited number/date pairing is internally impossible: Malian laws are numbered sequentially by adoption date within the year, and Loi n.2018-043 was adopted on 27 juin 2018, so a 'Loi n.2018-024' cannot bear the date 21 aout 2018. Neither 'Loi n.2018-024' nor 'Ordonnance n.2015-032/P-RM du 19 juin 2015' appears in the visas of any Malian LBC/FT instrument located.
False since 30 August 2024. Ordonnance n.2024-011/PT-RM defines 'actif virtuel' expressly at art. 2(2) ('La representation numerique d'une valeur qui peut etre echangee ou transferee par un procede numerique') and 'prestataire de services d'actifs virtuels' at art. 2(51), covering exchange fiat/VA, VA-to-VA exchange, transfer, custody and administration of virtual assets, and participation in/provision of financial services related to virtual-asset offerings. Art. 3(c) makes PSAV assujettis in their own right, and arts. 58-59 address them directly. No interpretive stretch of 'financial institution' is needed or appropriate - art. 2 defines institutions financieres separately from PSAV. The claim was accurate of the predecessor Loi n.2016-008 du 17 mars 2016 only.
For natural persons: Collecting and verifying identity (e.g., name, address, date of birth, nationality, unique identification number via official documents like passport or national ID card).
For legal entities: Collecting and verifying legal name, registered address, legal form, proof of incorporation, names of directors/authorized signatories, and identification of beneficial owners.
Beneficial Ownership Identification: Identifying and verifying the natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.
Purpose and Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of that relationship to ensure consistency with the institution’s knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying enhanced due diligence (EDD) for higher-risk customers (e.g., politically exposed persons - PEPs, customers from high-risk jurisdictions, or those engaged in complex/unusual transactions) and simplified due diligence (SDD) for lower-risk scenarios.
Obligation: Any transaction (regardless of amount) that an institution knows, suspects, or has reasonable grounds to suspect is related to money laundering or terrorist financing must be reported.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that an STR has been filed or that a money laundering or terrorist financing investigation is being conducted.
Transaction Records: All transaction data, including the amount, currency, date, and details of the parties involved (originator and beneficiary), should be kept.
Customer Identification Records: Records obtained through CDD measures (copies of identification documents, account files, business correspondence) must be retained.
The retention period in Mali is ten (10) years, not five. Art. 23 of Ordonnance n.2024-011/PT-RM du 30 aout 2024 requires the assujettis to keep client-identification and transaction records 'pendant une duree de dix ans'. This mirrors art. 23 of the UMOA loi uniforme du 31 mars 2023. The five-year figure is the FATF Recommendation 11 international minimum imported in place of reading the local text.
Cellule Nationale de Traitement des Informations Financières (CENTIF): Mali's FIU, responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs).
Mali's FIU is not CENAREF. It is the CENTIF (Cellule nationale de Traitement des Informations financieres), the standard UEMOA/francophone designation, to which art. 60 of Ordonnance n.2024-011/PT-RM du 30 aout 2024 directs suspicious-transaction declarations, and whose members are appointed by presidential decree (e.g. Decret n.2025-0006/PT-RM du 9 janvier 2025). CENAREF (Cellule Nationale des Renseignements Financiers) is the Democratic Republic of the Congo's FIU and has no role in Mali. The description of the FIU's functions is otherwise accurate; only the institution's name is wrong.
Built on the same non-existent institution: there is no 'CENAREF Mali'. Mali's FIU is the CENTIF. The record's secondary point - that no stable public website exists - happens to hold (centif.ml, centif.gouv.ml and centif-mali.org do not resolve), but the authoritative publication channel is not the Ministry of Economy and Finance or 'the UEMOA regional bodies': Malian LBC/FT instruments, including the appointment decrees of CENTIF members and the AML statute itself, are published by the Secretariat General du Gouvernement in the Journal officiel de la Republique du Mali at sgg-mali.ml.
Correct that the BCEAO is the regional central bank supervising financial institutions in the eight UMOA states including Mali, and that it has publicly urged caution on crypto-assets (it created the C-CRYPTO drafting committee in May 2026 and held the Dakar crypto-assets conference of 8 May 2026). Wrong that it has issued crypto 'guidelines': the BCEAO's own LBC/FT and payment-system registers contain no crypto-asset instrument of any kind, and there is no BCEAO prohibition either. The final proposition is correct for the right reason only since 30 August 2024: AML/CFT obligations bind virtual-asset actors in Mali because Ordonnance n.2024-011/PT-RM makes PSAV assujettis at art. 3(c) and defines them at art. 2(51) - not because of anything the BCEAO issued.
'Communique N.18/2021' does not exist. The BCEAO's own LBC/FT register lists twelve instruments - Instructions n.001-03-2025 to 003-03-2025, the loi uniforme, Decisions n.021 (21 dec. 2023) and n.003 (28 mars 2024) on thresholds, Instructions n.007 to 010-09-2017, and Directives n.02/2015 and 04/2007 - and contains no 2021 communique and no crypto-asset item at all. This is a new fabrication in the same family as the previously identified BCEAO 'Communique N.004/2020/RB' and the /RB-suffixed instructions; the BCEAO's numbering format is nnn-mm-yyyy. The claim that the BCEAO would supervise VASPs is also unfounded: art. 59 of Ordonnance n.2024-011/PT-RM defers PSAV requirements to 'les autorites competentes' without naming any, and Mali has designated none.
Role: Responsible for overall economic and financial policy, including the transposition and enforcement of AML/CFT legislation.
The symmetric art. 58 error. Correct that no VASP licence is obtainable in Mali and that operational, authorisation and prudential detail is undefined. Wrong that VASPs are merely 'implicitly covered' and that there is no explicit requirement: art. 58 of Ordonnance n.2024-011/PT-RM du 30 aout 2024 provides 'Nul ne peut se livrer a l'activite professionnelle de prestataire de services d'actifs virtuels s'il n'a pas obtenu l'agrement ou l'autorisation prealable de l'autorite competente', and PSAV are named assujettis at art. 3(c) with a dedicated definition at art. 2(51) including custody and administration of virtual assets. The accurate position: a statutory prohibition on unlicensed PSAV activity is in force in Mali, but art. 59 leaves every PSAV-specific requirement and sanction to 'les autorites competentes' and Mali has designated none, so no licence can in fact be obtained and no supervisor is operational.
Mali does have explicit national VASP legislation: Ordonnance n.2024-011/PT-RM du 30 aout 2024 defines actifs virtuels (art. 2(2)) and PSAV (art. 2(51)), makes PSAV assujettis (art. 3(c)) and imposes a prior-agrement requirement (art. 58), which is the substance of FATF Recommendation 15. The travel-rule half remains wrong in the other direction: the originator/beneficiary provisions are arts. 39-47 and are drafted for 'institutions financieres', a category art. 2 defines separately from PSAV, so no crypto travel rule is in force in Mali. Mali is a member of GIABA, the FATF-style regional body for West Africa, not of the FATF; the framing 'expected to adhere to international best practices' has no domestic legal force either way.
Risk and Uncertainty: Operating as a VASP in Mali carries regulatory uncertainty due to the evolving framework. It is crucial for any entity considering VASP activities to seek specific legal counsel in Mali to understand the current interpretations of existing laws and any new directives that may emerge.
Requirements: VASPs operating in Mali must screen their customers (KYC/CDD) and transactions against the consolidated UN Security Council Sanctions List. This list includes individuals and entities designated under various regimes, such as:
Al-Qaeda and ISIL (Da'esh) Sanctions Committee
DPRK (North Korea) Sanctions Committee
Other country-specific sanctions (e.g., related to Libya, Somalia, Sudan, Yemen, etc.)
Obligations: If a VASP identifies a match (a customer or transaction linked to a sanctioned individual/entity), it must:
Immediately freeze all virtual assets and funds associated with the designated person/entity.
Prohibit making any virtual assets, funds, or economic resources available to, or for the benefit of, the designated person/entity.
Report the hit to Mali's Financial Intelligence Unit (FIU), the Cellule Nationale de Traitement des Informations Financières (CENTIF).
UN Security Council Resolutions: Various resolutions mandate sanctions.
UN Security Council Sanctions Committees
Requirements: VASPs in Mali should consider screening against the EU Sanctions Map/Database, especially if they have any operational nexus, customer base, or transaction flow involving EU jurisdictions or entities. This includes:
Freezing of funds and economic resources of designated persons/entities.
Prohibition on making funds or economic resources available to them.
Half right. Asset freezing plus reporting to CENTIF is the correct mechanism for persons and entities designated under UN Security Council resolutions (uniform law of 31 March 2023, art. 41 and arts. 89-92 / 175-181; art. 177 provides for publication of freezing decisions on the CRF website). But EU restrictive measures are NOT the equivalent of UN sanctions in Mali: EU Council Regulations and Decisions have no autonomous legal force in Mali and create no Malian freezing or reporting duty. An EU-list hit with no UN-list counterpart triggers no statutory obligation in Mali - at most a commercial/correspondent-banking risk decision. The claim also presupposes a functioning VASP regime that does not exist (art. 58 prohibition, art. 59 authority never designated).
Council Regulations and Decisions: Implement EU sanctions.
EU Sanctions Map (External Action Service)
Consolidated list of persons, groups and entities subject to EU financial sanctions (Council of the EU)
They process transactions through the U.S. financial system.
Their activities involve U.S. persons or U.S.-origin goods/services.
They facilitate transactions for OFAC-sanctioned entities or individuals.
They operate in a manner that "causes" a U.S. person to violate sanctions.
No Malian or UEMOA/BCEAO instrument requires screening against OFAC's SDN List, the Sectoral Sanctions Identifications List or the Non-SDN Palestinian Legislative Council List. Those are US Treasury programmes binding on US persons and on transactions with a US nexus; they are not law in Mali. The lists that carry legal force in Mali are those derived from UN Security Council resolutions, via the UMOA uniform LBC/FT/FP law of 31 March 2023 (art. 41; arts. 89-92 and 175-181). The BCEAO's own exhaustive LBC/FT register - Instructions n. 007-09-2017 to 010-09-2017, Decisions n. 021 du 21/12/2023/CM/UMOA and n. 003 du 28/03/2024/CM, Instructions n. 001-03-2025 to 003-03-2025 - contains no OFAC-screening obligation. Separately, there are no licensed VASPs in Mali on which such a duty could bite: art. 58 prohibits unlicensed PSAV activity and art. 59 defers the rules to a competent authority that has never been designated.
Obligations: If a VASP identifies a match (a customer or transaction linked to a sanctioned individual/entity), it must:
It must block (freeze) the funds and assets.
It must prohibit all dealings with the sanctioned party.
It must report the blocked property and rejected transactions to OFAC within specific timeframes.
OFAC Sanctions Programs and Information
OFAC Specially Designated Nationals (SDN) List
Correct that the BCEAO is the regional central bank supervising financial institutions in the eight UMOA states including Mali, and that it has publicly urged caution on crypto-assets (it created the C-CRYPTO drafting committee in May 2026 and held the Dakar crypto-assets conference of 8 May 2026). Wrong that it has issued crypto 'guidelines': the BCEAO's own LBC/FT and payment-system registers contain no crypto-asset instrument of any kind, and there is no BCEAO prohibition either. The final proposition is correct for the right reason only since 30 August 2024: AML/CFT obligations bind virtual-asset actors in Mali because Ordonnance n.2024-011/PT-RM makes PSAV assujettis at art. 3(c) and defines them at art. 2(51) - not because of anything the BCEAO issued.
There is no 'Law N°2014-047/AN-RM of 16 October 2014' operating as Mali's AML/CFT statute. Mali's AML/CFT statute was Loi n°2016-008/RM du 17 mars 2016 portant loi uniforme relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme (JO n°2016-20 du 13 mai 2016, p.762), which transposed Directive n°02/2015/CM/UEMOA. It has been replaced by Ordonnance n°2024-011/PT-RM du 30 août 2024 (JO Spécial n°17 du 2 septembre 2024), Mali's transposition of the UMOA loi uniforme du 31 mars 2023. The sub-claim that VASPs are covered 'under FATF guidance' as financial institutions is also wrong for the 2016 text: Loi n°2016-008 contains no reference to actifs virtuels, monnaies virtuelles or PSAV anywhere; its assujettis are enumerated in art. 5. VASP coverage in Mali dates only from the 2024 ordonnance.
While a direct online link to this specific law in English is challenging to find, it is consistently cited as the main AML/CFT law in Mali by international bodies like GIABA.
FATF Recommendations: Mali, through its membership in GIABA, is expected to implement FATF standards, including Recommendation 15 on New Technologies, which specifically covers virtual assets and VASPs.
Customer Due Diligence (CDD): Identify and verify the identity of all customers (KYC) and beneficial owners. This includes collecting names, addresses, dates of birth, etc.
Sanctions Screening: Screen customer names, addresses, and other identifiers against the UN, EU, and OFAC sanctions lists at onboarding and on an ongoing basis. For crypto, this can extend to screening associated wallet addresses using blockchain analytics tools against lists of addresses known to be associated with sanctioned entities.
Transaction Screening: Monitor transactions in real-time or near real-time for links to sanctioned entities, high-risk jurisdictions, or suspicious patterns.
Source of Funds/Wealth: For high-risk customers or large transactions, inquire about the source of funds and source of wealth to ensure they are legitimate and not from sanctioned sources.
OFAC-Sanctioned Jurisdictions: Countries like Cuba, Iran, North Korea, Syria, and specific regions (e.g., Crimea, Donetsk, Luhansk regions of Ukraine).
High-Risk Jurisdictions: Countries identified by FATF or GIABA as having strategic AML/CFT deficiencies (e.g., those on the FATF 'grey list' or 'black list'). Transactions with such jurisdictions often require enhanced due diligence.
Countries under UN/EU Embargoes: Depending on the specific sanctions regime, certain transactions with or involving individuals/entities from embargoed countries may be prohibited.
Financial Penalties: Significant fines for institutions and individuals.
Imprisonment: For individuals found guilty of money laundering, terrorist financing, or serious breaches of compliance obligations.
License Revocation/Suspension: VASPs (if licensed or registered) could lose their operating authorization.
Reputational Damage: Significant harm to the business's standing and trust.
Asset Forfeiture: Proceeds of illicit activities may be confiscated.
Mali's general AML/CFT statute is not 'Loi n°2019-005 du 25 février 2019'. The backbone was Loi n°2016-008/RM du 17 mars 2016 portant loi uniforme relative à la lutte contre le blanchiment de capitaux et le financement du terrorisme (JO n°2016-20 du 13 mai 2016, p.762), and since 30 August 2024 it is Ordonnance n°2024-011/PT-RM du 30 août 2024 portant lutte contre le blanchiment de capitaux, le financement du terrorisme et de la prolifération des armes de destruction massive (JO Spécial n°17 du 2 septembre 2024), Mali's transposition of the UMOA loi uniforme du 31 mars 2023.
The premise is wrong (there is no Malian 2019 AML law) and the conclusion is superseded. Since Ordonnance n°2024-011/PT-RM du 30 août 2024, Malian law does contain specific virtual-asset provisions: art. 2(2) defines 'actif virtuel' as 'la représentation numérique d'une valeur qui peut être échangée ou transférée par un procédé numérique'; art. 2(51) defines the prestataire de services d'actifs virtuels, expressly including 'conservation et/ou administration d'actifs virtuels ou d'instruments permettant le contrôle d'actifs virtuels'; art. 3(c) makes PSAV assujettis; art. 58 prohibits unlicensed PSAV activity. What remains true is that no competent authority has been designated under art. 59, so no licensing regime is operational and no VASP-specific Travel Rule obligation exists.
Therefore, the FATF Travel Rule has not been specifically adopted or implemented for VASPs in Mali through dedicated legislation.
The first limb is right — no VASP/Travel-Rule-specific regime has an effective date in Mali because none is operational. The second limb is wrong: the general AML/CFT instrument is not a February 2019 law. Loi n°2016-008/RM du 17 mars 2016 (JO n°2016-20 du 13 mai 2016) governed until it was replaced by Ordonnance n°2024-011/PT-RM du 30 août 2024, published in JO Spécial n°17 du 2 septembre 2024 and in force from that publication.
The conclusion is correct — no threshold triggers a virtual-asset travel-rule obligation in Mali, because no such obligation exists. The premise is wrong: VASPs are specifically regulated on paper. Ordonnance n°2024-011/PT-RM art. 2(51) defines the PSAV, art. 3(c) makes them assujettis and art. 58 forbids unlicensed PSAV activity. The reason no threshold exists is not absence of regulation but art. 59's deferral to a competent authority Mali has never designated.
The figures and the legal source are both wrong. Thresholds in Mali are not fixed by Malian decrees but by UMOA/BCEAO instruments applying directly across the Union. The cash-transaction reporting threshold to CENTIF is fifteen million (15 000 000) FCFA — Instruction n°010-09-2017, art. 1: 'Est fixé à quinze millions de francs CFA le seuil pour la déclaration des transactions en espèces'. Under the 31 March 2023 uniform law the thresholds are set by Décision n°021 du 21 décembre 2023 and Décision n°003 du 28 mars 2024 of the UMOA Council of Ministers, supplemented by BCEAO Instructions n°001-03-2025 to n°003-03-2025. There is in any event no 2019 Malian AML law from which decrees could flow.
Ordonnance n°2024-011/PT-RM du 30 août 2024, art. 3, lists among the persons subject to the ordonnance: 'c) les Prestataires de Services d'Actifs Virtuels'. Exchanges and custodial wallet providers are therefore assujettis in Mali on exactly the same statutory footing as financial institutions, and owe the full preventive obligations including the ten-year record retention of art. 23 and suspicious-transaction reporting to CENTIF under art. 60. What is absent is supervision, not designation.
Incorrect. Under Ordonnance n°2024-011/PT-RM art. 3(c), a prestataire de services d'actifs virtuels is assujetti in its own right, with no requirement that it also hold a banking or financial-institution licence. Art. 58 goes further and makes the professional exercise of PSAV activity itself conditional on a prior agrément or authorisation from the competent authority. The genuine gap is that art. 59 leaves the specific PSAV requirements and sanctions to a competent authority Mali has not designated, so the obligations are unsupervised rather than inapplicable.
Mali has no crypto travel rule and therefore no technical implementation requirements for VASPs: Ordonnance n° 2024-011/PT-RM du 30 août 2024 reproduces the UMOA uniform law's originator/beneficiary articles (arts. 39-47), which are drafted for 'institutions financières' — a category art. 2 defines separately from 'prestataire de services d'actifs virtuels'. The premise that there is 'no specific regulatory framework' for VASPs is wrong: PSAV are expressly listed among the personnes assujetties at art. 3, and are subject to CDD, 10-year record retention (art. 23) and STR obligations (art. 60).
For traditional financial institutions, the requirements typically involve maintaining records of transactions, conducting customer due diligence (CDD), and reporting suspicious transactions to the Cellule Nationale de Traitement des Informations Financières (CENTIF) – Mali's Financial Intelligence Unit.
Mali's operative AML/CFT statute is no longer any 2019 law: it is Ordonnance n° 2024-011/PT-RM du 30 août 2024 portant lutte contre le blanchiment de capitaux, le financement du terrorisme et de la prolifération des armes de destruction massive, published in JO n°2024-17 spécial du 2 septembre 2024 and taken under the habilitation of Loi n°2024-016 du 11 juillet 2024. It transposes Directive n°01/2023/CM/UEMOA du 31 mars 2023 and Décision n°04/31/03/2023/CM/UMOA. Administrative sanctions under this framework are imposed by the autorité de contrôle, not by CENTIF.
VASPs ARE explicitly designated reporting entities in Mali. Art. 3 of Ordonnance n° 2024-011/PT-RM du 30 août 2024 lists 'Prestataires de Services d'Actifs Virtuels' among the personnes assujetties alongside institutions financières and EPNFD, and art. 2(51) defines PSAV to include exchange, transfer and 'la conservation et l'administration d'actifs virtuels'. The AML obligations (CDD, 10-year retention, STRs to CENTIF) and their associated sanctions therefore apply to PSAV directly, with no need for 'loose interpretation'. What is genuinely absent is a crypto-specific travel rule and a designated competent authority under art. 59.
This law can be found on the website of CENTIF Mali (Malian Financial Intelligence Unit).
URL (example, GIABA hosts these reports): You would typically find this on the GIABA website under "Mutual Evaluations" or "Follow-Up Reports."
No BCEAO 'Communiqué N°18/2021' exists. BCEAO does not number its press releases in an N°nn/yyyy series, its communiqués-de-presse index contains no 2021 item on monnaies virtuelles or crypto-actifs, and its LBC/FT regulation index contains no virtual-asset instrument. The only crypto-related item BCEAO publishes is the Conférence internationale sur les crypto-actifs et innovations numériques of 8 May 2026. The substantive point that FCFA is the only legal tender is correct, but it rests on monetary law, not on this non-existent communiqué.
10 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by SearXNG+LLM .
Primary Sources
Consolidated list of persons, groups and entities subject to EU financial sanctions (Council of the EU). (n.d.). Consolidated list of persons, groups and entities subject to EU financial sanctions (Council of the EU). Retrieved April 21, 2026, from https://data.europa.eu/data/datasets/consolidated-list-of-persons-groups-and-entities-subject-to-eu-financial-sanctions?locale=en
OFAC Sanctions Programs and Information. (n.d.). OFAC Sanctions Programs and Information. Retrieved April 21, 2026, from https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information
OFAC Specially Designated Nationals (SDN) List. (n.d.). OFAC Specially Designated Nationals (SDN) List. Retrieved April 21, 2026, from https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information/specially-designated-nationals-and-blocked-persons-list-sdn-human-readable-list
Secondary Sources
bceao.int. (n.d.). www.bceao.int. Retrieved April 22, 2026, from https://www.bceao.int/
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →