DeFi protocol frontend in Togo
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Togo without local incorporation, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Screen customers (KYC) and transactions against the UN Consolidated Sanctions List (tg.aml.vasp-obligations-vasps-must-screen)
- Implement sanctions screening against OFAC SDN List and other OFAC-administered lists where the frontend deals with U.S. persons, transacts in USD, or uses U.S.-based infrastructure (tg.aml.vasp-obligations-vasps-should-implement)
- Screen customers and transactions against the EU Consolidated Financial Sanctions List if dealing with EU persons or transacting within the EU financial system (tg.aml.vasp-obligations-vasps-should-screen)
- Implement customer due diligence (CDD/KYC) — identify and verify customers and beneficial owners under Loi n° 2018-009 (tg.aml.implement-cddkyc-identify-and-verify)
- Conduct ongoing monitoring of customer transactions for suspicious activity (tg.aml.conduct-ongoing-monitoring-monitor-customer)
- Report suspicious transactions (STRs) to CENTIF, Togo's FIU (tg.aml.report-suspicious-transactions-strs-report)
- Maintain records of customer identification and transactions for a specified period (tg.aml.maintain-records-keep-records-of)
- Adhere to FATF Recommendation 15 principles including Travel Rule obligations if the frontend qualifies as a VASP (tg.aml.compliance-requirement-fatf-recommendation-15)
Key Restrictions
- BCEAO Circular No. 00000002/RB/2020 prohibits financial institutions (banks, microfinance, payment service providers) from engaging in crypto activities — the frontend cannot use formal banking channels in WAEMU (tg.licensing.bceao-circular-no-00000002rb2020-on)
- No crypto-specific regulatory framework exists — operating the frontend would be unlicensed and unregulated in Togo, operating outside the formal financial system (tg.licensing.exchanges-any-cryptocurrency-exchange-operating)
- Regulated financial institutions cannot facilitate crypto transactions — the frontend cannot integrate with local banks or payment providers (tg.licensing.for-financial-institutions-the-bceao)
- Difficulties converting crypto to fiat and integrating with the formal banking system — bank accounts may be flagged or closed (tg.licensing.difficulty-interfacing-with-traditional-finance)
Key Risks
- BCEAO has consistently warned that virtual assets are not legal tender and are unregulated — operating a frontend carries reputational and enforcement risk even if not formally banned (tg.enforcement.central-bank-of-west-african)
- No specific crypto enforcement actions have been taken yet, but the BCEAO's stance creates material enforcement exposure for any publicly identifiable operator (tg.enforcement.lack-of-specific-crypto-legislation)
- BCT (national BCEAO agency) could enforce regional directives against entities facilitating crypto transactions (tg.licensing.note-the-bct-is-not)
- Fee-taking model (e.g. frontend swap fees) could bring the operator within scope of financial services regulation or AML law, increasing enforcement risk (implied by tg.licensing.existing-amlcft-legislation-while-not)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
'BCEAO Circular No. 00000002/RB/2020 on the Prohibition of the Use of Cryptocurrencies and other Digital Assets in WAEMU Member States' does not exist. No BCEAO instrument prohibits cryptocurrency in UEMOA. The numbering format is also wrong: BCEAO instructions are numbered nnn-mm-yyyy (e.g. Instruction n° 008-05-2015), never with an /RB/ segment. The BCEAO's exhaustive published index of payment-system instruments 2002-2024 contains no such circular, and bceao.int returns nothing on crypto-actifs beyond the 8 May 2026 Dakar conference. The real constraint is art. 58 of the Loi uniforme of 31 March 2023: professional PSAV activity requires prior agrement from a competent authority which no member state has designated.
No BCEAO directive prohibits banks, microfinance institutions or payment service providers in Togo from crypto activity — no such instrument exists. The BCEAO's own exhaustive payment-systems register lists 12 instruments from 2002 to 2024 and contains nothing on crypto-actifs or stablecoins; a full-text fetch of Instruction n° 008-05-2015 (e-money) returns zero occurrences of 'crypto', 'actif virtuel', 'stablecoin' or 'blockchain'. As of the 8 May 2026 Dakar conference the BCEAO had only just created the C-CRYPTO drafting committee, and as of July 2026 was still drafting a roadmap. The real constraint is national and different in kind: art. 58 of Loi n° 2026-001 makes professional PSAV activity conditional on a prior agrément from an 'autorité compétente' that art. 59 leaves undesignated — so no agrément can be obtained. That Togolese banks decline crypto counterparties is commercial de-risking, not compliance with a prohibition. The claim's practical conclusion ('you cannot legally buy or sell crypto through traditional banks') therefore lands near the right outcome via a fabricated cause.
Correct on the narrow point: Togolese law contains no prohibition on an individual owning or trading virtual assets. Loi n° 2026-001 regulates prestataires, not holders, and imposes no restriction on natural persons holding actifs virtuels. But 'there isn't a direct law' is no longer accurate as a general statement — since 2 March 2026 there is a direct law: art. 2 defines 'actif virtuel', art. 3 makes PSAV assujettis, art. 58 forbids anyone from carrying on PSAV activity professionally without a prior agrément. And the qualifier 'or through unregulated, foreign platforms' overreaches: the individual user is outside art. 58, but a foreign platform providing exchange, transfer or custody services in Togo on a commercial basis is within it, and cannot lawfully do so because no competent authority has been designated under art. 59 to issue the agrément.
'Unlicensed' is right; 'unregulated' is wrong. Art. 58 of Loi n° 2026-001 du 2 mars 2026 provides that 'Nul ne peut se livrer à l'activité professionnelle de prestataire de services d'actifs virtuels s'il n'a pas obtenu l'agrément ou l'autorisation préalable de l'autorité compétente', and art. 59 defers the specific requirements and sanctions to 'les autorités compétentes' — which Togo has not designated. So any exchange operating in Togo is necessarily unlicensed, and indeed in breach of art. 58, since no licence can be issued. But it is not outside regulation: a PSAV is an assujetti under art. 3, owes customer due diligence and suspicious-transaction reporting to CENTIF-Togo under art. 60, and must retain records for 10 years under art. 23. 'Operating outside the formal financial system' is a description of banking practice, not a legal status.
The premise is false and everything is derived from it. Togolese financial institutions are not 'prohibited from dealing with crypto' — no BCEAO or Togolese instrument imposes such a prohibition, as the BCEAO's own payment-systems register and the full text of Instruction n° 008-05-2015 confirm. Fiat on/off-ramp friction in Togo is real, but its causes are (a) bank de-risking, a commercial choice, and (b) art. 58 of Loi n° 2026-001, which makes professional PSAV activity conditional on an agrément that cannot currently be issued because art. 59 leaves the competent authority undesignated. The AML/CFT-scrutiny sentence is right for the wrong reason: scrutiny arises because PSAV are themselves assujettis under art. 3, must report suspicions to CENTIF-Togo under art. 60 and retain records 10 years under art. 23 — not because converting crypto is forbidden.
High Risk and Unregulated: However, the environment is highly risky. There is no consumer protection, no regulatory oversight for exchanges operating in the grey area, and no legal recourse if funds are lost.
Superseded on 2 March 2026. Togo's AML/CFT law IS now crypto-specific. Loi n° 2026-001 du 2 mars 2026 — Togo's transposition of the UMOA Loi uniforme LBC/FT/FP du 31 mars 2023 (itself giving effect to Directive n° 01/2023/CM/UEMOA) — defines 'actif virtuel' at art. 2 as 'la représentation numérique d'une valeur qui peut être échangée ou transférée par un procédé numérique', defines the prestataire de services d'actifs virtuels (PSAV) including custody/administration, lists PSAV among the assujettis at art. 3, and at art. 58 prohibits professional PSAV activity without prior agrément. The bill was adopted in first reading 29 December 2025 and finally on 2 March 2026, replacing the framework built on Loi n° 2018-004 du 4 mai 2018, under which the 'not crypto-specific' description was accurate. Separately: Togo is NOT a FATF member — it is a GIABA member — though its law does follow the FATF Recommendations. And the laws do more than 'could potentially be invoked': PSAV are directly assujettis with CDD, STR (art. 60, to CENTIF-Togo) and 10-year record-retention (art. 23) duties.
VASP Obligations: VASPs must screen their customers (KYC) and transactions against the UN Consolidated Sanctions List.
VASP Obligations: VASPs should implement robust sanctions screening programs to ensure they are not directly or indirectly facilitating transactions with individuals, entities, or jurisdictions on the SDN list or other OFAC-administered lists. This includes screening against wallet addresses known to be associated with sanctioned entities where possible.
VASP Obligations: VASPs should screen customers and transactions against the EU Consolidated Financial Sanctions List.
Implement CDD/KYC: Identify and verify the identity of customers and beneficial owners.
Conduct Ongoing Monitoring: Monitor customer transactions for suspicious activity.
Report Suspicious Transactions (STRs): Report any suspected money laundering or terrorist financing activities to the Cellule Nationale de Traitement des Informations Financières (CENTIF), Togo's Financial Intelligence Unit (FIU).
Maintain Records: Keep records of customer identification and transactions for a specified period.
Compliance Requirement: FATF Recommendation 15 specifically addresses virtual assets and VASPs, requiring countries to regulate VASPs for AML/CFT purposes, license/register them, and apply the "Travel Rule" (requiring VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers).
Togo is a UEMOA/UMOA member and the BCEAO is the common central bank for the eight member states. However, the BCEAO has issued no formal public communique warning about virtual currencies at the cited URL, which redirects silently to the BCEAO homepage. The BCEAO's documented position as of August 2026 rests on (i) Governor Kassi Brou's July 2026 statement ('Ce n'est pas une monnaie. Ce n'est pas reglementee. Donc soyez prudents.') and (ii) the 8 May 2026 Dakar crypto-asset conference launching the C-CRYPTO drafting committee. The substance of the claim (not legal tender, not regulated by the BCEAO, users bear the risk) is correct; the evidentiary basis ('consistently issued warnings', with a specific communique) is not.
Lack of Specific Crypto Legislation: Like many countries in the region, Togo has not yet enacted comprehensive, standalone legislation specifically regulating virtual assets or cryptocurrency service providers. Discussions are ongoing at the UEMOA level, but concrete national laws and enforcement frameworks are still developing.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend targeting Togolese residents faces a hostile regulatory environment: BCEAO directives prohibit regulated financial institutions from facilitating crypto, there is no VASP licensing pathway, and the frontend would be unlicensed/unregulated, though individuals are not explicitly banned from using foreign platforms; fee-taking increases the risk of being treated as an unlicensed financial services operator under existing AML law.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?