DeFi protocol frontend in Burkina Faso
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Burkina Faso without local incorporation, subject to AML obligations and none licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- None
- Last updated
- 2026-07-13
AML Obligations
- General AML/CFT Law N°024-2016/AN applies to any entity dealing with funds or assets, including virtual assets — this could extend to DeFi frontends if they are deemed to handle funds or assets on behalf of users (bf.licensing.amlkyc-burkina-faso-is-a, bf.aml.law-n024-2016an-of-20-may)
- Identification and verification requirements: full name, date of birth, address, nationality, official ID document number(s) for natural persons; name, legal form, registration number, constitutional documents, and BO identification for legal entities (bf.aml.identification-and-verification-of-identity, bf.aml.for-natural-persons-full-name, bf.aml.for-legal-entities-name-legal)
- Beneficial ownership identification required — understand ownership and control structure (bf.aml.beneficial-ownership-identification-identify-and)
- Purpose-and-intended-nature-of-business-relationship documentation required (bf.aml.purpose-and-intended-nature-of)
- Ongoing monitoring and transaction scrutiny to ensure consistency with customer risk profile (bf.aml.ongoing-monitoring-conduct-ongoing-due)
- Risk-based approach: EDD for high-risk customers/PEPs; SDD only in low-risk scenarios (bf.aml.risk-based-approach-apply-enhanced-due)
- Suspicious transaction reporting (STR) to CENTIF (Burkina Faso's FIU) — mandatory for any suspected ML/TF activity, regardless of amount, with whistleblower protections and anti-tipping-off rules (bf.aml.vasps-like-other-financial-institutions, bf.aml.the-report-must-be-made, bf.aml.the-vasp-and-its-employees, bf.aml.tipping-off-informing-the-customer)
- Record-keeping: transaction records, CDD documents, STR records must be retained (bf.aml.all-necessary-records-of-transactions, bf.aml.records-of-the-information-obtained, bf.aml.records-pertaining-to-suspicious-transaction)
- CENTIF is the supervising FIU; BCEAO oversees financial institutions regionally (bf.aml.centrale-nationale-de-traitement-des, bf.aml.banque-centrale-des-tats-de)
Key Restrictions
- No specific regulatory framework exists for VASPs or DeFi frontends — operating is a legal grey area with no clear licensing pathway (bf.licensing.no-specific-regulatory-framework-for, bf.licensing.neither-exists-for-crypto-specific-activities)
- BCEAO maintains that cryptocurrencies are not legal tender in the UEMOA zone and has issued public warnings against their use (bf.licensing.the-bceao-has-on-several, bf.enforcement.bceaos-stance-the-bceao-has)
- Fiat-to-crypto on-ramps/off-ramps through regulated banking channels are effectively impossible: BCEAO-supervised institutions will reject crypto-related banking services (bf.licensing.implication-for-vasps-this-means, bf.licensing.exchanges-fiat-to-crypto-crypto-to-crypto-no-specific)
- If fee-taking involves receiving or transacting in CFA Francs (XOF), existing payment services regulations may apply and require a payment institution license — but such a license would likely be denied for crypto-related activities (bf.licensing.payment-processors-facilitating-crypto-payments)
- New BCEAO external financial relations regulations (15 Instructions) effective August 1, 2025 may further restrict cross-border crypto flows (bf.licensing.bceao-circulars-and-communications)
Key Risks
- Extreme regulatory ambiguity: DeFi frontends have no defined legal status — what is not prohibited is not permitted either, creating unpredictability (bf.licensing.entities-operating-in-this-space, bf.enforcement.lack-of-specific-national-framework)
- Banking access risk: inability to open or maintain bank accounts in Burkina Faso/UEMOA due to BCEAO's prohibition stance (bf.licensing.implication-for-vasps-this-means)
- Enforcement risk is low probability but high impact: lack of specific crypto enforcement today does not preclude future retroactive or politically motivated enforcement, especially given the military junta's censorship environment (bf.enforcement.while-not-specific-to-burkina, bf.enforcement.you-might-find-news-articles)
- Fraud/ponzi-scheme association risk: any crypto-related operation may be publicly conflated with scams by BCEAO warnings, creating PR and consumer-protection exposure (bf.enforcement.nature-of-reported-incidents-any, bf.enforcement.general-warnings-as-mentioned-public)
- No consumer protection framework exists for crypto — operator bears full liability for user losses (bf.licensing.entities-operating-in-this-space)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific regulatory framework for VASPs.
Neither exists for crypto-specific activities. There is no framework for either registration or licensing of VASPs in Burkina Faso. Entities operating in this space are therefore in a legal grey area, highly exposed to risks, and generally lack regulatory recognition.
AML/KYC: Burkina Faso is a member of the Intergovernmental Action Group against Money Laundering in West Africa (GIABA), a FATF-style regional body. Thus, it is committed to implementing FATF recommendations. While there's no specific crypto AML/KYC framework, any entity dealing with funds or assets would be expected to comply with general AML/CFT obligations.
The BCEAO has, on several occasions, issued communications (e.g., in 2018 and subsequent updates) warning the public and financial institutions about the risks associated with cryptocurrencies. These communications generally declare that cryptocurrencies are not legal tender in the UEMOA zone and prohibit regulated financial institutions (banks, microfinance institutions, payment service providers) from engaging in transactions related to, or facilitating, the use of virtual assets.
BCEAO's 15 New Instructions on External Financial Relations (implementing Regulation No. 06/2024/CM/UEMOA), effective August 1, 2025
Implication for VASPs: This means that entities wishing to operate as crypto exchanges, custody providers, or payment processors in Burkina Faso (or any UEMOA country) will face significant challenges, primarily the inability to obtain banking services from regulated financial institutions within the UEMOA zone. This effectively makes it extremely difficult, if not impossible, to operate legally and effectively.
Exchanges (Fiat-to-Crypto, Crypto-to-Crypto): No specific license exists. Any attempt to operate a fiat-to-crypto exchange would necessitate a payment institution or banking license, which would then be rejected by BCEAO-supervised entities due to their crypto prohibition. Crypto-to-crypto exchanges, while not directly touching fiat, would still face banking access issues for operational needs and are considered unregulated.
Payment Processors (facilitating crypto payments): No specific license exists. If these activities involve traditional payment processing in CFA Francs (XOF), they would fall under existing payment services regulations. However, if the payments are in crypto or facilitated by crypto, they would again be prohibited from using regulated financial infrastructure.
Entities operating in this space do so in a legal grey area, exposed to regulatory risks, potential legal challenges, and lack of consumer protection.
Local Presence: Any legally registered business in Burkina Faso would require a local presence and incorporation under Burkinabe law.
Law N°024-2016/AN of 20 May 2016 on the fight against money laundering and financing of terrorism. This law transposed the recommendations of the FATF and GIABA into national law. While it predates explicit FATF guidance on VASPs, its broad scope regarding "financial institutions" and "designated non-financial businesses and professions (DNFBPs)" is often interpreted to cover entities dealing with virtual assets if they perform similar functions to traditional financial services.
AML-related identification and verification of identity generally requires collecting and verifying key personal data (such as full name, date of birth, and address) and confirming it through reliable sources, which may include a single government‑issued photo ID or a mix of documentary and electronic methods; a rigid requirement for two physical forms of identification is not a universal or current standard.
For natural persons in the US: Full name, date of birth, place of birth, address, nationality, and official identification document number(s) from reliable, independent sources (such as state-issued driver's license, passport, or Social Security number). Verification must use reliable, independent source documents. Note: The US has no national ID card; verification relies on a decentralized system of state and federal documents. Validity period requirements vary by document type and regulatory context.
For legal entities: Name, legal form, address (registered office and current operational address if different), registered office, official registration number, constitutional documents (e.g., articles of incorporation, bylaws, memorandum and articles of association), and identification of individuals authorized to act on behalf of the entity.
Beneficial Ownership Identification: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer. This includes understanding the ownership and control structure of legal persons and arrangements.
Purpose and Intended Nature of the Business Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or occasional transaction.
Ongoing Monitoring: Conduct ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Apply enhanced due diligence (EDD) for high-risk customers or transactions (e.g., Politically Exposed Persons - PEPs, complex transactions, transactions from high-risk jurisdictions). Simplified due diligence (SDD) may be applied in low-risk scenarios, but not to the extent of foregoing identification entirely.
VASPs are obligated to report any transaction or activity that they suspect to be related to money laundering or terrorist financing, regardless of the amount.
The report must be made promptly to the Financial Intelligence Unit (FIU) of Burkina Faso.
In Burkina Faso, VASP employees are not shielded from liability for breaching disclosure restrictions, even when reporting suspicions in good faith; unauthorized disclosures remain punishable under Law No. 001-2021.
"Tipping off" (informing the customer or a third party that an STR has been filed or that an investigation is underway) is strictly prohibited.
All necessary records of transactions, both domestic and international, to enable their reconstruction.
Records of the information obtained through CDD measures (copies of identification documents, account files, business correspondence).
Records pertaining to suspicious transaction reports filed.
Centrale Nationale de Traitement des Informations Financières (CENTIF): This is Burkina Faso's Financial Intelligence Unit (FIU). CENTIF is the body to which all suspicious transaction reports are submitted, and it is responsible for analyzing these reports and disseminating intelligence to law enforcement agencies. CENTIF also plays a key role in ensuring compliance with AML/CFT obligations across various sectors.
Banque Centrale des États de l'Afrique de l'Ouest (BCEAO): As the regional central bank, the BCEAO supervises financial institutions within the WAEMU zone. While it primarily oversees traditional banks and payment service providers, its directives and policy stances on digital finance and payment systems are highly relevant. If VASPs offer services resembling traditional payment or financial services, they may fall under the extended purview or influence of the BCEAO.
BCEAO's Stance: The BCEAO has consistently issued warnings to the public about the risks associated with cryptocurrencies, stating that they are not recognized as legal tender and are not regulated by the central bank or other financial authorities in the region. These are general advisories, not specific enforcement actions against particular entities within Burkina Faso.
Lack of Specific National Framework: Burkina Faso, like many countries in the region, has not yet established a comprehensive national regulatory framework specifically for cryptocurrencies. Without clear laws defining crypto entities, licensing requirements, and prohibited activities, it's challenging for regulators to conduct formal enforcement actions with specific penalties.
Nature of Reported Incidents: Any incidents related to cryptocurrencies in Burkina Faso are more likely to be:
While not specific to Burkina Faso alone, the BCEAO's position applies to all WAEMU member states: https://www.bceao.int/fr/actualites/mise-en-garde-du-public-relativement-lutilisation-des-monnaies-virtuelles (This specific link refers to a 2020 warning, but the stance remains consistent).
Given the junta's crackdown on media and secret detention of journalists in Burkina Faso, local outlets like LeFaso.net and Sidwaya may not be able to freely publish BCEAO warnings without government censorship or reprisal.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — operating a DeFi protocol frontend in/from Burkina Faso is legally ambiguous with no specific framework; general AML obligations likely apply if the operator handles funds/assets, but fiat on/off-ramps are effectively blocked by BCEAO policy, and no licensing pathway exists.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?