[codicts-css-switcher id=”346″]

Global Law Experts Logo
ghana establishes five-agency

Ghana Establishes Five-agency Virtual Assets Coordinating Committee Before Any VASP Licence Is Issued

By Global Law Experts
– posted 2 hours ago

Ghana is establishing five-agency virtual assets coordinating machinery ahead of granting virtual asset service provider (VASP) licences, signalling a deliberate, supervision-first approach to crypto regulation in one of West Africa’s fastest-moving fintech markets. The Virtual Assets Coordinating Committee (VACC) is understood to bring together the Bank of Ghana as chair, the Securities and Exchange Commission, the Ministry of Finance, the Cyber Security Authority and the Financial Intelligence Centre to coordinate policy, licensing and anti-money-laundering oversight before the market is formally opened. This sequencing is notable: the regulatory scaffolding is being raised before applications are processed, giving firms both a warning and a window.

This article explains who is expected to sit on the committee, how supervisory responsibilities are likely to be split, what AML and beneficial-ownership documentation applicants should assemble, and how operators already active in Ghana without authorisation might manage their compliance exposure.

Who should read this: corporate counsel, compliance officers, money-laundering reporting officers (MLROs), fintech founders, custodial and exchange operators, investors and consultants preparing for VASP authorisation in Ghana.

What the Virtual Assets Coordinating Committee is and why it matters

The Virtual Assets Coordinating Committee is an administrative coordination body designed to align the mandates of Ghana’s principal financial and technical regulators around a single objective: the safe, supervised introduction of licensed virtual asset activity. Rather than allowing one agency to regulate in isolation, the committee model recognises that virtual assets touch monetary policy, capital markets, fiscal policy, cybersecurity and financial crime simultaneously.

The fact that Ghana is establishing five-agency virtual assets coordinating structures before licences are issued matters for a practical reason. It tells the market that authorisation will be conditioned on a mature, cross-agency supervisory framework, not a light-touch registration. For applicants, that means the bar for governance, AML controls and technical resilience is likely to be set collectively, and no single approval will suffice in isolation.

Legal basis and the central-bank-led coordination model

The Bank of Ghana is understood to chair the committee, consistent with its statutory role over the payment system under the Payment Systems and Services Act, 2019 (Act 987) and its broader oversight of monetary stability under the Bank of Ghana Act, 2002 (Act 612), as amended. Ghana’s central bank has consistently signalled caution on unregulated crypto activity while working toward a supervised framework, and in 2024 published draft guidelines on digital assets for public consultation. The committee’s remit is expected to cover four broad functions: policy coordination, licensing coordination, AML and financial-crime oversight, and technical guidance on cybersecurity and operational resilience.

Because the committee is standing up before licensing begins, its early outputs, draft regulations, consultation papers and joint guidance, will help define the compliance baseline. Practitioners should treat every published notice from the member agencies as authoritative signalling and monitor the Bank of Ghana, SEC, Ministry of Finance, Financial Intelligence Centre and Cyber Security Authority websites for the formal instruments that follow.

Who sits on the committee, the five agencies and their mandates

Understanding the individual mandates of each member is essential to preparing a credible application. Each agency brings a distinct supervisory lens, and applicants will likely need to satisfy all five perspectives rather than a single reviewer.

Bank of Ghana, chair and prudential lead

As chair, the Bank of Ghana anchors the committee. Its focus for VASPs will centre on payment-system integrity, prudential soundness and the boundary between virtual assets and regulated payment activity. Where a virtual asset business connects to Ghana’s payment rails, for example, fiat on-ramps and off-ramps, the Bank of Ghana’s authorisation and oversight functions come directly into play. The central bank is likely to lead on licensing coordination and prudential expectations such as capital adequacy and safeguarding of client assets.

Securities and Exchange Commission, market conduct and investor protection

The Securities and Exchange Commission (SEC) will focus on market integrity and investor protection under the Securities Industry Act, 2016 (Act 929). Where virtual assets take on the characteristics of securities, token offerings, investment schemes or custodial arrangements marketed to the public, the SEC’s mandate over disclosure, market conduct and investor safeguards is engaged. Firms offering token sales, staking-as-a-service, or pooled investment products should expect the SEC to scrutinise marketing materials, custody arrangements and conflict-of-interest controls.

Ministry of Finance, policy and fiscal framework

The Ministry of Finance provides the policy and fiscal backbone. Its role is to help set the legislative direction, sponsor enabling regulations and align virtual asset policy with Ghana’s broader financial-sector strategy and tax framework. Ministerial statements and draft legislation from the Ministry will typically precede the operational rules issued by the technical regulators, so counsel should watch Ministry of Finance publications for early indications of the statutory shape of the regime.

Cyber Security Authority, technical resilience and incident reporting

The Cyber Security Authority (CSA), established under the Cybersecurity Act, 2020 (Act 1038), addresses the technical and operational-resilience dimension. Virtual asset businesses hold private keys, process high-value transactions and present attractive targets for attackers. The CSA is expected to set expectations around technical resilience, secure custody, incident reporting and the protection of critical financial infrastructure. Applicants should anticipate requirements around penetration testing, secure key management, business-continuity planning and reporting of security incidents.

Financial Intelligence Centre, AML and financial-crime supervision

The Financial Intelligence Centre (FIC) is Ghana’s national financial-intelligence unit, established under the Anti-Money Laundering Act, 2020 (Act 1044), and the natural recipient of suspicious transaction reports from VASPs. Its focus is anti-money-laundering (AML) and countering the financing of terrorism (CFT): customer due diligence, beneficial-ownership transparency, transaction monitoring and reporting obligations. Given the elevated money-laundering risk associated with virtual assets, the FIC’s expectations are likely to be among the most demanding elements of any application.

How multi-agency supervision may allocate responsibilities

Because Ghana is adopting a five-agency virtual assets coordinating approach rather than a single-regulator model, applicants should understand which agency is likely to lead on which function, and how the agencies will coordinate. The table below sets out a likely allocation of responsibilities. It reflects each agency’s core statutory mandate and should be read as practitioner interpretation pending the committee’s published rules.

Agency Primary remit for VASPs Typical supervisory actions Key compliance focus
Bank of Ghana (chair) Licensing coordination; prudential and payment-system oversight Authorisation review; capital and safeguarding checks; payment-system integration approval Capital adequacy; client-asset safeguarding; fit-and-proper governance
Securities and Exchange Commission Market conduct; investor protection; token-offering oversight Review of offerings and custody; conduct examinations; disclosure scrutiny Investor disclosures; custody controls; conflicts of interest
Ministry of Finance Policy, legislation and fiscal framework Issuing regulations; consultation windows; tax and policy alignment Statutory compliance; fiscal/tax treatment
Cyber Security Authority Technical resilience and incident reporting Security standard-setting; incident-response review; infrastructure assessments Key management; penetration testing; incident reporting
Financial Intelligence Centre AML/CFT supervision and intelligence Receiving STRs/CTRs; AML examinations; beneficial-ownership scrutiny CDD/KYC; beneficial ownership; suspicious transaction reporting

Practical coordination mechanisms

Multi-agency regimes typically rely on formal coordination tools to avoid duplication and gaps. In practice, the committee is likely to operate through memoranda of understanding between agencies, information-sharing arrangements and, where appropriate, joint inspections. For applicants, this means information disclosed to one regulator may be shared across the committee, so consistency across submissions is critical.

Consider a practical scenario: a licensed exchange detects a series of structured transactions that suggest layering. The AML function files a suspicious transaction report with the FIC. If the same activity reveals a security breach, for example, compromised accounts, the operator would also owe an incident report to the Cyber Security Authority. Where the transactions touch a token that behaves like a security, the SEC’s conduct interest is engaged. A single event can therefore trigger parallel obligations to multiple committee members, and applicants should design internal escalation flows that route incidents to the correct regulator promptly.

The AML and financial-crime limb, FIC expectations and KYC, BO and SOF guidance

The AML and financial-crime dimension is the heart of the regime. International standards make clear that virtual asset service providers must apply the same core AML/CFT obligations as other financial institutions. The Financial Action Task Force (FATF), the intergovernmental body that sets global AML/CFT standards, has issued detailed risk-based guidance for virtual assets and VASPs, and Ghana’s framework is expected to reflect those standards, including customer due diligence, beneficial-ownership transparency and the so-called travel rule for transfers.

VASPs in Ghana should expect a full suite of obligations: customer due diligence (CDD) and know-your-customer (KYC) checks at onboarding, ongoing transaction monitoring, enhanced due diligence for higher-risk customers and jurisdictions, record-keeping, and the filing of suspicious transaction reports (STRs) and, where applicable, currency transaction reports with the FIC, consistent with the Anti-Money Laundering Act, 2020 (Act 1044) and its Regulations.

Beneficial ownership, what documentation to prepare

Beneficial-ownership transparency is a central plank of both FATF standards and Ghana’s corporate and AML framework, reinforced by the beneficial-ownership disclosure requirements of the Companies Act, 2019 (Act 992) and the central beneficial-ownership register maintained by the Office of the Registrar of Companies. Applicants should be able to identify and verify the natural persons who ultimately own or control the applicant entity and its customers where relevant. Documentation to assemble includes:

  • Ownership structure charts. A clear diagram tracing ownership from the applicant through any holding companies to ultimate beneficial owners.
  • Identity verification. Government-issued identification and proof of address for each beneficial owner above the applicable control threshold.
  • Beneficial-ownership register. An up-to-date register consistent with Ghana’s corporate registration requirements under the Companies Act, 2019.
  • Control documentation. Shareholder agreements, voting arrangements and nominee disclosures that reveal effective control beyond nominal shareholding.

Source-of-funds evidence, best practice and examples

Regulators and the FIC will expect VASPs to understand and document the source of funds and source of wealth for higher-risk customers and for the applicant’s own capital. Good practice includes retaining evidence such as bank statements, audited financial statements, sale-of-asset documentation, employment or business income records, and clear narratives explaining the economic rationale for large or unusual flows. For example, a customer funding a substantial purchase should be able to demonstrate a traceable, legitimate origin, proceeds of a documented property sale or business distribution, rather than unexplained cash.

Suspicious transaction reporting and engagement with the FIC

The FIC is the reporting destination for suspicious activity. VASPs should build reporting workflows that allow an MLRO to escalate, assess and file STRs without tipping off the customer. Effective transaction-monitoring rules should flag structuring, rapid movement of funds, transactions with high-risk jurisdictions, and mismatches between customer profile and activity. Record-keeping obligations require firms to retain CDD records and transaction data for the periods prescribed under Ghana’s AML framework, so data-retention architecture must be built in from day one.

What applicants should prepare now, governance, technology and documentation checklist

Because Ghana is building five-agency virtual assets coordinating supervision, a credible application will likely need to satisfy prudential, conduct, AML, cyber and policy expectations at once. Preparation should begin now, well ahead of any application process opening. The checklist below groups the key workstreams.

  • Corporate structure and beneficial-ownership records. Incorporate in the appropriate form, maintain a current beneficial-ownership register, and prepare ownership charts and control disclosures.
  • Compliance officer and MLRO appointment. Appoint a qualified compliance officer and money-laundering reporting officer with clear authority and board access.
  • AML/CFT policies and procedures. Draft a risk-based AML programme covering CDD, EDD, sanctions screening, PEP handling and reporting.
  • Sanctions and screening. Implement sanctions and watchlist screening at onboarding and on an ongoing basis.
  • KYC onboarding flows. Design digital onboarding with identity verification, liveness checks and risk scoring.
  • Transaction monitoring. Deploy monitoring tuned to virtual-asset typologies, including travel-rule data collection for transfers.
  • Cybersecurity controls. Establish secure key management, access controls, encryption and segregation of hot and cold storage.
  • Penetration testing and incident response. Commission independent penetration testing and maintain a documented incident-response and breach-notification plan aligned to Cyber Security Authority expectations.
  • External audit and independent testing. Arrange independent assurance over financial statements and AML controls.
  • Capital and reserve considerations. Prepare for prudential expectations around capital adequacy and client-asset safeguarding.
  • Consumer complaints handling. Establish a documented complaints and dispute-resolution process.

Example application file structure

Section Contents
1. Corporate Incorporation documents, ownership charts, beneficial-ownership register, group structure
2. Governance Board composition, fit-and-proper declarations, compliance officer and MLRO appointments
3. AML/CFT AML policy, CDD/EDD procedures, sanctions screening, STR/CTR reporting procedures
4. Technology and cyber Architecture overview, key management, penetration-test results, incident-response plan
5. Financial Audited financials, capital plan, client-asset safeguarding arrangements
6. Conduct and consumer Marketing controls, disclosures, complaints handling, custody terms

Applicants should also prepare a vendor checklist, identity-verification providers, transaction-monitoring platforms, custody technology and independent testers, and allow realistic lead times to procure, integrate and test each before submission. For firms weighing whether to build internal capability or engage external advisers, guidance on choosing local versus international counsel for Ghana investments can help structure the decision.

Sequencing risk, operators currently active in Ghana without a licence

A key practical issue is sequencing risk. Because the committee is standing up before any licence is issued, firms already offering virtual asset services in Ghana are, in effect, operating ahead of the formal regime. This creates potential enforcement exposure and a compressed remediation window once rules crystallise.

The principal risks include enforcement action, retrospective scrutiny of past onboarding and transactions, potential penalties, and reputational damage that can jeopardise future authorisation. A firm that has onboarded customers without adequate CDD, for example, may face a costly remediation exercise, re-verifying its customer base, before it can credibly apply.

Options for existing operators

  • Halt or ring-fence higher-risk services. Where a product line presents clear regulatory risk, consider suspending it pending authorisation rather than compounding exposure.
  • Partial compliance and remediation. Begin remediating onboarding gaps, backfilling KYC and beneficial-ownership records, and standing up transaction monitoring.
  • Voluntary engagement. Consider proactive, counsel-led engagement with the relevant regulator and, where appropriate, voluntary disclosure, which can demonstrate good faith.
  • Accelerated application preparation. Assemble the application file now so the firm can move quickly once the process opens, converting readiness into competitive advantage.

The prudent posture is to assume that supervision will be rigorous and that the committee will expect operators to have prepared during this pre-licensing window rather than waited for enforcement.

Practical timeline and next steps, what to watch for from regulators

Because the framework is emerging, the exact sequence of milestones is subject to regulator guidance. Firms should nonetheless watch for a predictable pattern of outputs: committee meetings and terms of reference; draft regulations and enabling legislation; consultation windows inviting industry comment; detailed licensing rules and application criteria; and, finally, the opening of an application process. Monitoring the Bank of Ghana, SEC, Ministry of Finance, FIC and Cyber Security Authority pages for these publications is the single most reliable way to stay ahead.

A practical action timeline for applicants:

  • 0–30 days. Conduct a gap assessment against the checklist above; appoint or confirm your MLRO and compliance officer; begin remediation of any onboarding gaps.
  • 31–90 days. Finalise AML policies, procure and integrate KYC and transaction-monitoring vendors, commission penetration testing, and draft the application file.
  • 90+ days. Complete independent testing and external audit, refine the file in light of published draft rules, and prepare for submission when the process opens.

Where to find official notices and regulator contact points

Practitioners should rely on primary sources for definitive guidance. The Bank of Ghana, Securities and Exchange Commission, Ministry of Finance, Financial Intelligence Centre and Cyber Security Authority each publish notices, guidance and contact details on their official websites, and the FATF publishes the international standards that underpin Ghana’s AML expectations. Where a regulator issues a specific press release on committee formation or licensing rules, that release should be treated as the controlling reference.

Conclusion, key takeaways and recommended action

The decision to establish five-agency virtual assets coordinating oversight before issuing VASP licences is a clear signal: authorisation is likely to be earned through demonstrable prudential, conduct, AML and cyber readiness, not granted on registration alone. Firms that treat this pre-licensing window as preparation time will be best placed when applications open. The five immediate actions are: run a gap assessment against the checklist; appoint a qualified MLRO and compliance officer; remediate onboarding and beneficial-ownership records; build AML and cyber controls aligned to FIC and Cyber Security Authority expectations; and, for existing operators, address sequencing risk through counsel-led engagement and, where necessary, suspension of higher-risk services.

This article is general guidance and not legal advice. Virtual asset regulation in Ghana is evolving, and specific obligations are subject to regulator guidance. Firms should obtain bespoke advice before acting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Oliver Barker-Vormawor at MERTON & EVERETT LLP, a member of the Global Law Experts network.

Sources

  1. Bank of Ghana
  2. Securities and Exchange Commission, Ghana
  3. Ministry of Finance, Ghana
  4. Financial Intelligence Centre, Ghana
  5. Cyber Security Authority, Ghana
  6. Financial Action Task Force (FATF), guidance on virtual assets and VASPs

FAQs

What is the Virtual Assets Coordinating Committee that Ghana is establishing?
It is understood to be a five-agency committee chaired by the Bank of Ghana that coordinates licensing, supervision and AML/CFT oversight for virtual assets in Ghana. The establishment of five-agency virtual assets coordinating oversight before VASP licences are issued signals a supervision-first approach to the market.
The Bank of Ghana (chair), the Securities and Exchange Commission, the Ministry of Finance, the Cyber Security Authority and the Financial Intelligence Centre. Each brings a distinct mandate covering prudential, conduct, policy, cyber and AML supervision respectively.
Key items are likely to include company incorporation and beneficial-ownership records, AML policies, KYC procedures, source-of-funds documentation, cybersecurity controls, a compliance officer and MLRO appointment, penetration-test results and audited financial statements assembled into a structured application file. Final requirements will be confirmed by the regulators’ published rules.
VASPs should expect full CDD and KYC obligations, beneficial-ownership screening and reporting, suspicious transaction and currency transaction reporting to the FIC, ongoing transaction monitoring, and enhanced due diligence for higher-risk customers and jurisdictions, consistent with the Anti-Money Laundering Act, 2020 (Act 1044) and FATF standards.
There is sequencing risk. Firms should assess compliance gaps, consider voluntary disclosure to the relevant regulator, halt higher-risk product lines if necessary, and prepare an accelerated application and remediation plan before enforcement activity intensifies.
mediation act 2023
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Ghana Establishes Five-agency Virtual Assets Coordinating Committee Before Any VASP Licence Is Issued

Send welcome message

Custom Message