Tanzania -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
Tanzania's regulatory framework for cryptocurrency and virtual asset service providers (VASPs) is still developing and largely relies on the application of existing general Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) legislation to entities that engage in financial activities, even if those activities involve virtual assets.
While Tanzania has historically taken a cautious stance towards cryptocurrencies, the global push for VASP regulation (driven by the Financial Action Task Force - FATF) means that VASPs operating in or serving Tanzanian customers are expected to comply with robust AML/CFT requirements. The regulatory landscape is evolving, and specific VASP licensing frameworks may emerge.
Here's a breakdown based on the current understanding:
AML/CFT Requirements for Cryptocurrency/Virtual Asset Service Providers in Tanzania
1. AML/CFT Legislation:
The primary legislation governing AML/CFT in Tanzania that would apply to VASPs (by interpretation, in the absence of specific VASP laws) includes:
- The Anti-Money Laundering Act (AMLA), 2006 (as amended): This is the principal legislation establishing the legal framework for combating money laundering. It defines "financial institutions" and "other reporting institutions" and imposes obligations on them. While VASPs may not be explicitly listed, their activities are likely to be interpreted as falling under the scope of financial services or other reporting obligations.
- The Anti-Money Laundering Regulations, 2012 (as amended): These regulations provide detailed rules and procedures for implementing the AMLA, including customer due diligence, suspicious transaction reporting, and record-keeping.
- The Anti-Terrorism Act, 2002 (as amended): This act provides the legal framework for combating terrorism financing.
2. Customer Due Diligence (CDD) Requirements:
VASPs are expected to implement robust CDD measures, similar to traditional financial institutions. These include:
- Identification and Verification of Customers:
- Natural Persons: Collecting and verifying full legal name, date of birth, residential address, nationality, national identification number (e.g., National ID, passport, driver's license). Verification should be done using reliable, independent source documents, data, or information.
- Legal Entities (Companies, Partnerships, etc.): Collecting and verifying official name, registration number, address of registered office, names of directors/partners, legal form, proof of existence (e.g., certificate of incorporation).
- Beneficial Ownership: Identifying and verifying the identity of the ultimate beneficial owner(s) of the virtual assets or the entity, ensuring that the VASP knows who ultimately owns or controls the funds/assets.
- Purpose and Intended Nature of the Business Relationship: Understanding the purpose and intended nature of the customer's virtual asset activities and the business relationship.
- Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by the customer to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
- Enhanced Due Diligence (EDD): Applying EDD for higher-risk situations, which may include:
- Transactions involving Politically Exposed Persons (PEPs).
- Customers from high-risk jurisdictions (as identified by FATF or local authorities).
- Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
- New technologies or products that favor anonymity, which is often a characteristic of some virtual asset transactions.
- Cross-border virtual asset transfers.
3. Suspicious Transaction Reporting (STR):
VASPs have a legal obligation to report suspicious transactions to the Financial Intelligence Unit (FIU Tanzania).
- Obligation to Report: Any VASP, or its employees, that knows or suspects that a transaction (or attempted transaction) involves funds or virtual assets derived from illegal activity, or is related to money laundering or terrorism financing, must report it.
- What Constitutes Suspicion: Suspicion can arise from various factors, including unusual transaction patterns, inconsistent customer information, lack of clear economic purpose, or involvement of high-risk jurisdictions.
- Reporting Mechanism: Reports must be submitted to the FIU Tanzania promptly and without delay, typically through a prescribed format (e.g., an online portal or specific form).
- No Tipping-Off: VASPs and their employees are prohibited from "tipping-off" customers or third parties that an STR has been or will be submitted.
4. Record-Keeping Obligations:
VASPs are required to maintain comprehensive records related to their customers and transactions.
- Duration: All records must be kept for a minimum period of five (5) years after the business relationship has ended or after the date of the transaction.
- Types of Records:
- All customer identification and verification data.
- Business correspondence related to the customer relationship.
- Records of all virtual asset transactions, including transaction dates, amounts, types of virtual assets, sending and receiving addresses (if applicable), and originating/beneficiary information.
- Records of all suspicious transaction reports filed.
- Records of internal policies and procedures for AML/CFT compliance.
- Accessibility: Records must be maintained in a manner that allows for easy retrieval by competent authorities upon request.
5. Overseeing Authority:
- Financial Intelligence Unit (FIU Tanzania): This is the primary body responsible for receiving, analyzing, and disseminating suspicious transaction reports and financial intelligence related to money laundering and terrorism financing. The FIU also provides guidance on AML/CFT compliance.
- Website: https://www.fiu.go.tz/
- Bank of Tanzania (BoT): As the central bank, BoT is the primary regulator for financial institutions and is responsible for overall financial sector stability and supervision. While they have historically been cautious regarding crypto, any future formal licensing or prudential regulation of VASPs would likely fall under their purview. They have also indicated an openness to exploring virtual assets, which may lead to a more defined regulatory stance.
- Website: https://www.bot.go.tz/
Important Considerations for VASPs in Tanzania:
- Evolving Landscape: The regulatory environment for virtual assets is dynamic globally and locally. VASPs should continuously monitor for new laws, regulations, or guidance from Tanzanian authorities.
- Risk-Based Approach: VASPs are expected to implement a risk-based approach to AML/CFT, meaning they should assess their specific risks (customer type, products, services, delivery channels, geographical areas) and apply controls commensurate with those risks.
- FATF Standards: Tanzania is expected to align with the recommendations of the Financial Action Task Force (FATF), particularly FATF Recommendation 15 on New Technologies and its Interpretive Note on Virtual Assets and VASPs. This means adhering to the "travel rule" (which requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers) and having a robust internal compliance program.
- Legal Counsel: Given the evolving nature and the lack of highly specific VASP legislation, it is highly advisable for any VASP operating or intending to operate in Tanzania to seek local legal counsel specializing in financial regulation and AML/CFT to ensure full compliance.
This information provides a general overview based on the current legislative framework and international standards. Specific interpretation and application may vary, and direct official guidance for VASPs in Tanzania is still developing.
Source Data
Tanzania's principal AML statute is the Anti-Money Laundering Act, Cap. 423 (Act No. 12 of 2006, R.E. 2023, commenced 1 July 2007), which imposes obligations on the class of 'reporting person' defined in section 3 paragraphs (a) to (j); the Anti-Money Laundering (Amendment) Act, 2022 (Act No. 2 of 2022, in force 8 March 2022) inserted definitions of 'virtual asset' and 'virtual asset service provider' into section 3 but left virtual asset service providers outside that class, which only a notice published in the Gazette by the Minister under paragraph (j) can extend.
Tanzania's operative AML subsidiary legislation is the Anti-Money Laundering Regulations, 2022 (Government Notice No. 397 of 3 June 2022), amended by the Anti-Money Laundering (Amendment) Regulations, 2023 (Government Notice No. 853E of 22 November 2023); regulation 30 of GN No. 397 revoked the Anti-Money Laundering and Counter Terrorist Financing Regulations, 2012 (GN No. 289 of 2012), and neither the 2022 regulations nor the 2023 amendment mentions virtual assets or virtual asset service providers.
Tanzania's counter-terrorism statute is the Prevention of Terrorism Act, Act No. 21 of 2002, consolidated as Cap. 19 R.E. 2023 and in force from 15 June 2003, with terrorist financing offences at sections 16 and 17 and proliferation financing at section 13, supplemented by the POTA Regulations 2022; Tanzania has no statute titled the Anti-Terrorism Act, and the Prevention of Terrorism Act mentions no virtual assets.
Natural Persons: Collecting and verifying full legal name, date of birth, residential address, nationality, national identification number (e.g., National ID, passport, driver's license). Verification should be done using reliable, independent source documents, data, or information.
Legal Entities (Companies, Partnerships, etc.): Collecting and verifying official name, registration number, address of registered office, names of directors/partners, legal form, proof of existence (e.g., certificate of incorporation).
Beneficial Ownership: Identifying and verifying the identity of the ultimate beneficial owner(s) of the virtual assets or the entity, ensuring that the VASP knows who ultimately owns or controls the funds/assets.
Purpose and Intended Nature of the Business Relationship: Understanding the purpose and intended nature of the customer's virtual asset activities and the business relationship.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by the customer to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious activities.
Enhanced Due Diligence (EDD): Applying EDD for higher-risk situations, which may include:
Transactions involving Politically Exposed Persons (PEPs).
Customers from high-risk jurisdictions (as identified by FATF or local authorities).
Complex, unusually large transactions, or unusual patterns of transactions that have no apparent economic or lawful purpose.
New technologies or products that favor anonymity, which is often a characteristic of some virtual asset transactions.
Tanzania imposes no suspicious-transaction reporting duty on virtual asset service providers: section 18 of the Anti-Money Laundering Act, Cap. 423 R.E. 2023 (section 17 in the R.E. 2022 numbering) binds only a "reporting person", and the section 3 definition of reporting person, at paragraphs (a) to (j), names banks and financial institutions, cash dealers, accountants, real estate agents, auditors, tax advisers, dealers in precious stones, works of art or metals, trust and company service providers, motor vehicle dealers, clearing and forwarding agents, advocates and notaries, pension fund managers, securities market intermediaries, financial leasing entities, microfinance service providers and auctioneers, but no virtual asset service provider, even though section 3 has defined both "virtual asset" and "virtual asset service provider" since the Anti-Money Laundering (Amendment) Act, 2022 (Act No. 2 of 2022) came into force on 8 March 2022.
What Constitutes Suspicion: Suspicion can arise from various factors, including unusual transaction patterns, inconsistent customer information, lack of clear economic purpose, or involvement of high-risk jurisdictions.
Suspicious transaction reports in Tanzania are submitted to the Financial Intelligence Unit under section 18 of the Anti-Money Laundering Act, Cap. 423 R.E. 2023 by any secure means the Unit specifies, and the Unit operates a goAML portal for that purpose, but the duty falls only on a "reporting person" as defined in section 3, and virtual asset service providers are outside that definition, so no Tanzanian virtual asset service provider owes a reporting obligation to the Unit.
Tanzania's tipping-off prohibition in section 22 of the Anti-Money Laundering Act, Cap. 423 R.E. 2023 (section 20 in the R.E. 2022 numbering) is drafted to bind "a person" rather than only a reporting person, so it reaches anyone, including the staff of a virtual asset business, who discloses or warns a person involved in a transaction, or an unauthorised third party, that a suspicious transaction report under section 18 may be prepared, is being prepared or has been sent to the Financial Intelligence Unit; the prohibition attaches to reports made by reporting persons, and virtual asset service providers owe no reporting duty of their own because section 3 omits them from the reporting-person list.
Tanzania's anti-money-laundering record-retention period is ten years, not five: section 17(1)(b) of the Anti-Money Laundering Act, Cap. 423 R.E. 2023 (section 16 in the R.E. 2022 numbering) requires every reporting person to retain records for a minimum period of ten years from the date the transaction is completed, the business relationship ends or the risk assessment is completed, and the duty binds only the reporting persons listed at paragraphs (a) to (j) of section 3, a list that omits virtual asset service providers.
All customer identification and verification data.
Business correspondence related to the customer relationship.
Records of all virtual asset transactions, including transaction dates, amounts, types of virtual assets, sending and receiving addresses (if applicable), and originating/beneficiary information.
Records of all suspicious transaction reports filed.
Records of internal policies and procedures for AML/CFT compliance.
Accessibility: Records must be maintained in a manner that allows for easy retrieval by competent authorities upon request.
The Financial Intelligence Unit of Tanzania is established as an extra-ministerial department under the Ministry responsible for finance by section 4 of the Anti-Money Laundering Act, Cap. 423 R.E. 2023, and section 6 gives it power to receive suspicious transaction reports, currency transaction reports, cross-border currency reports and electronic funds transfer reports from reporting persons, to analyse them and disseminate the results to law enforcement agencies, supervisory authorities and other competent authorities, and to supervise reporting persons for compliance with anti-money-laundering, counter-terrorist-financing and counter-proliferation-financing obligations.
The Bank of Tanzania supervises banks and financial institutions under the Bank of Tanzania Act, 2006 (Act No. 4 of 2006, Cap. 197) and has issued the only Tanzanian official positions on cryptocurrency, the public notice of 12 November 2019 and the press release of 29 November 2019, both invoking sections 26 and 27 of that Act and the Foreign Exchange Act, 1992, yet it licenses and supervises no virtual asset service provider; on 30 July 2026 Governor Emmanuel Tutuba said the Bank had "completed the assessment and developed a concept on the regulation and supervision of virtual assets" and had submitted that concept to the Ministry of Finance, which is a policy document awaiting legislation rather than a supervisory perimeter.
Evolving Landscape: The regulatory environment for virtual assets is dynamic globally and locally. VASPs should continuously monitor for new laws, regulations, or guidance from Tanzanian authorities.
Risk-Based Approach: VASPs are expected to implement a risk-based approach to AML/CFT, meaning they should assess their specific risks (customer type, products, services, delivery channels, geographical areas) and apply controls commensurate with those risks.
FATF Standards: Tanzania is expected to align with the recommendations of the Financial Action Task Force (FATF), particularly FATF Recommendation 15 on New Technologies and its Interpretive Note on Virtual Assets and VASPs. This means adhering to the "travel rule" (which requires VASPs to obtain and transmit originator and beneficiary information for virtual asset transfers) and having a robust internal compliance program.
Legal Counsel: Given the evolving nature and the lack of highly specific VASP legislation, it is highly advisable for any VASP operating or intending to operate in Tanzania to seek local legal counsel specializing in financial regulation and AML/CFT to ensure full compliance.
Tanzania's principal anti-money-laundering statute is the Anti-Money Laundering Act, Act No. 12 of 2006, consolidated as Cap. 423 and now in Revised Edition 2023, which imposes customer due diligence (section 16), record-keeping for a minimum of ten years (section 17), suspicious transaction reporting to the Financial Intelligence Unit (section 18) and internal compliance programmes (sections 19 and 20) on "reporting persons" as defined in section 3; the Anti-Money Laundering (Amendment) Act, 2022 (Act No. 2 of 2022), in force 8 March 2022, inserted definitions of "virtual asset" and "virtual asset service provider" into section 3 but did not add virtual asset service providers to the reporting-person list at paragraphs (a) to (j), so a Tanzanian virtual asset service provider falls inside the perimeter only if the Minister specifies the category by notice published in the Gazette under paragraph (j), and no such notice has been made.
Tanzania's counter-terrorism statute is the Prevention of Terrorism Act, Act No. 21 of 2002, consolidated as Cap. 19 in Revised Edition 2023 and amended most recently by the Anti-Money Laundering (Amendment) Act, 2022; the Minister declares suspected international terrorists and international terrorist groups under section 14 and designates suspected domestic terrorists under section 15, property used in the commission of terrorist acts is seized under section 38, and seizure, restraint and forfeiture orders are made under sections 48 and 49; the Act makes no reference to virtual assets, cryptocurrency or digital assets, so targeted financial sanctions in Tanzania reach virtual assets only through the general definition of property.
The Bank of Tanzania issued two cryptocurrency warnings in November 2019, the Public Notice on Cryptocurrencies of 12 November 2019 and the press release "Bank of Tanzania Not Involved in Cryptocurrency" of 29 November 2019, each citing sections 26 and 27 of the Bank of Tanzania Act, 2006 and the Foreign Exchange Act, 1992, and each stating that the Tanzanian shilling is the only legal tender and that the foreign exchange regulatory framework does not extend to trading or use of any virtual currency; the Bank's only subsequent published work on the subject is central bank digital currency research, described in its public notice of 14 January 2023 as a "phased, cautious and risk-based approach" with a way forward to be announced on conclusion of the research phase, which is neither a pilot nor a decision against issuance.
Financial Intelligence Unit (FIU): The national center for receiving, analyzing, and disseminating suspicious transaction reports (STRs) and other financial information related to money laundering and terrorist financing.
The Bank of Tanzania's published position rests on the two November 2019 warnings and on a central bank digital currency research notice of 14 January 2023 that adopts a "phased, cautious and risk-based approach" and promises information on the way forward once research concludes; President Samia Suluhu Hassan's June 2021 remarks urging the Bank to prepare for cryptocurrency are recorded in press reporting and in no Bank of Tanzania or State House document, and Tanzania as at 21 August 2026 still has no virtual asset service provider licence, register or designated supervisor, the Bank having submitted a regulation-and-supervision concept to the Ministry of Finance on 30 July 2026.
Implication for Crypto (if permitted/regulated): If VASPs were to operate under a formal regulatory framework in Tanzania, they would be designated as "reporting persons" and would be subject to:
Customer Due Diligence (CDD) and Know Your Customer (KYC): Identifying and verifying the identity of customers and beneficial owners.
Ongoing Transaction Monitoring: Scrutinizing transactions for suspicious activity.
Sanctions Screening: Screening customers and transactions against national and international sanctions lists.
Suspicious Transaction Reporting (STR): Reporting any suspicious activities or transactions to the FIU.
Record-Keeping: Maintaining records for a prescribed period.
The Anti-Money Laundering Act, 2006 (and amendments): Available through Tanzania's Parliament website or legal databases. (Example via National Assembly: http://www.parliament.go.tz/polis/uploads/bills/1474278458-Bill%20No.3%20of%202019%20The%20Anti-Money%20Laundering%20(Amendment)%20Act,%202019.pdf%20Act,%202019.pdf) - Note: always check for the latest consolidated version)
The Prevention of Terrorism Act, 2002 (and amendments): (Similarly, via Parliament website)
Bank of Tanzania Website: https://www.bot.go.tz/
Tanzania Financial Intelligence Unit (FIU) Website: http://www.fiu.go.tz/
1 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by SearXNG+LLM .
Primary Sources
fiu.go.tz. (n.d.). fiu.go.tz. Retrieved April 22, 2026, from https://www.fiu.go.tz/
bot.go.tz. (n.d.). bot.go.tz. Retrieved April 22, 2026, from https://www.bot.go.tz/
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →