ملاوي KYC, KYB & AML compliance checklist
قائمة عملية وموثقة بالمصادر لتنفيذ متطلبات KYC وKYB وAML في ملاوي.
- تاريخ آخر مراجعة
- تاريخ آخر مراجعة:
- الإصدار
- الإصدار 1.0

إجابة مباشرة
ما الذي تغطيه قائمة الامتثال الخاصة بـ ملاوي؟
تحوّل قائمة ملاوي قواعد KYC وKYB وAML الأساسية إلى 11 مجالات رقابية و37 فحوص تنفيذ، وتشمل الجهات المختصة وواجبات الإبلاغ والأدلة الواجب الاحتفاظ بها.
حقائق تنظيمية أساسية
- Primary AML/CFT law
- Financial Crimes Act (Chapter 7:07), commenced 17 February 2017
- Financial intelligence unit
- Financial Intelligence Authority (FIA)
- STR timing
- As soon as possible and no later than three days after suspicion; attempts and any amount are covered
- Large transaction reporting
- MWK 5,000,000 transaction or aggregate under the 2020 Regulations; current FIA direction controls submission timing
- Local mobile-money transfer reporting
- Each transfer above MWK 300,000 under regulation 21
- Casino CDD trigger
- MWK 2,000,000 within 24 hours for specified gaming transactions, plus entry/access identification duties
- Core AML retention
- Seven years, with the start event determined by record class
- Beneficial ownership
- Natural-person ownership/control, other control, then senior-management fallback; no universal percentage stated in the Act
- Data protection
- Data Protection Act 2024, commenced 31 May 2024; confirm live registration and incident procedures with MACRA
- FATF public lists
- Not named in FATF statements dated 19 June 2026; ESAAMLG follow-up continues
تفاصيل التنفيذ
متطلبات وإجراءات الامتثال في ملاوي
افتح كل مجال لمراجعة المتطلب وإجراء التنفيذ المقترح والأدلة الواجب الاحتفاظ بها والمصدر الأساسي.
01Scope, authorities and regulated activitiesResolve entity, product, profession and supervisor scope before configuring controls.3 عناصر+
Financial institutions and designated non-financial businesses and professions within the statutory definition are reporting institutions.
- إجراء التنفيذ
- Map each entity, product, branch, profession, agent and outsourced activity to the Act and its supervisor.
- الأدلة الواجب الاحتفاظ بها
- Perimeter memorandum, entity-product matrix, licences and authority map.
- المصدر الأساسي
- Financial Crimes Act (FCA), s.2 and Second Schedule
The FIA receives and analyses reports, issues guidance and supervises compliance within its mandate.
- إجراء التنفيذ
- Register required contacts and reporting access, appoint alternates and maintain a regulatory calendar.
- الأدلة الواجب الاحتفاظ بها
- FIA registration, channel access, contact register and calendar.
- المصدر الأساسي
- FCA, ss.3-6 and 23, 33
Deposit-taking, payments, remittance, e-money and other financial services require the applicable RBM authority before launch.
- إجراء التنفيذ
- Obtain a written perimeter and every required RBM licence or approval before pilot or production operation.
- الأدلة الواجب الاحتفاظ بها
- RBM classification, licence, conditions, approved product map and renewal register.
- المصدر الأساسي
- Financial Services Act 2010; National Payment Systems Act; RBM licensing framework
02Governance, risk assessment and control ownershipBuild accountable controls from documented customer, product, delivery, geography and transaction risk.3 عناصر+
Reporting institutions identify, assess, document and keep current their ML/TF risks and apply proportionate mitigation.
- إجراء التنفيذ
- Approve enterprise and customer-risk methodologies, document inputs and overrides and review material change.
- الأدلة الواجب الاحتفاظ بها
- Risk assessments, methodology, ratings, approvals and remediation plan.
- المصدر الأساسي
- FCA, s.21(1)-(4); 2020 Regulations, reg.3
A written customer-acceptance policy is updated annually or on new developments and approved by the board.
- إجراء التنفيذ
- Define acceptance, escalation, prohibition and exception rules and obtain annual board approval.
- الأدلة الواجب الاحتفاظ بها
- Policy, board minutes, change record and staff guidance.
- المصدر الأساسي
- 2020 Regulations, reg.18
The AML programme includes internal rules, training, compliance oversight and independent testing.
- إجراء التنفيذ
- Appoint an authorised compliance officer, provide information access and test the complete lifecycle independently.
- الأدلة الواجب الاحتفاظ بها
- Appointment, charter, training, audit reports and issue tracker.
- المصدر الأساسي
- FCA, ss.27-28; 2020 Regulations, regs.30-35
03Natural-person identification and CDDIdentify and verify customers at relationship, prescribed transaction, wire, suspicion and identity-doubt triggers.4 عناصر+
CDD is required for a relationship, prescribed occasional or wire transaction, suspicion, and doubt about earlier evidence.
- إجراء التنفيذ
- Configure all five triggers and linked-transaction detection; never let a monetary threshold suppress suspicion-driven CDD.
- الأدلة الواجب الاحتفاظ بها
- Trigger matrix, aggregation logic, test cases and exceptions.
- المصدر الأساسي
- FCA, s.16(1); 2020 Regulations, reg.4
A natural person is identified through official documentation and verified using reliable, independent sources.
- إجراء التنفيذ
- Capture name, address, occupation and official identity evidence; validate authenticity and screen the person.
- الأدلة الواجب الاحتفاظ بها
- Identity record, authenticity result, independent verification and screening decision.
- المصدر الأساسي
- FCA, s.16(1)-(2)(b); 2020 Regulations, regs.5-6, 10-12
Purpose, intended nature and risk-relevant source information must be understood.
- إجراء التنفيذ
- Record intended products, expected activity, counterparties, geography and corroborated source information proportionate to risk.
- الأدلة الواجب الاحتفاظ بها
- Customer profile, purpose statement, expected-activity baseline and source evidence.
- المصدر الأساسي
- FCA, s.16(2)(a)-(b); 2020 Regulations, reg.11
Deferred verification is exceptional and allowed only where prompt completion and effective risk management are assured.
- إجراء التنفيذ
- Apply restrictions, a short completion deadline and escalation; do not treat deferral as routine onboarding.
- الأدلة الواجب الاحتفاظ بها
- Exception approval, rationale, restrictions and completion timestamp.
- المصدر الأساسي
- FCA, s.16(7); 2020 Regulations, reg.10(2)-(3)
04KYB, authority and beneficial ownershipVerify legal existence, representatives and the natural persons who ultimately own or control the customer.4 عناصر+
Legal-person CDD covers name, legal form, existence, binding powers, senior management, registered office, ownership and control.
- إجراء التنفيذ
- Obtain current CRIPC evidence and constitutive documents and reconcile directors, addresses, mandates and ownership.
- الأدلة الواجب الاحتفاظ بها
- Registry extract, constitution, directors, address, licence and discrepancy log.
- المصدر الأساسي
- FCA, s.16(2)(c); 2020 Regulations, regs.8-9, 13-15
A person acting for another customer must have verified authority and identity.
- إجراء التنفيذ
- Verify each representative separately and validate the mandate before permitting activity.
- الأدلة الواجب الاحتفاظ بها
- Identity file, mandate, board authority and verification result.
- المصدر الأساسي
- FCA, s.16(9)(b); 2020 Regulations, reg.16
Beneficial-owner analysis follows natural-person controlling ownership, control through other means and senior-management fallback.
- إجراء التنفيذ
- Trace every ownership layer, test non-ownership control and document why any senior-manager fallback was necessary.
- الأدلة الواجب الاحتفاظ بها
- Ownership chart, registry evidence, control analysis, BO KYC and fallback rationale.
- المصدر الأساسي
- FCA, ss.2 and 16(3)-(4)
Trust CDD identifies the settlor, trustee, protector if any, beneficiaries or class and every other natural person exercising ultimate effective control.
- إجراء التنفيذ
- Verify the trust instrument, roles, powers, control chain and relevant natural persons.
- الأدلة الواجب الاحتفاظ بها
- Trust deed, role register, powers analysis and verified identity files.
- المصدر الأساسي
- FCA, s.16(5)-(6); 2020 Regulations, regs.8, 13
05PEPs, enhanced due diligence and remote onboardingHigher-risk and politically exposed relationships require accountable approval and stronger evidence.4 عناصر+
Systems determine whether a customer or beneficial owner is a PEP and extend reasonable measures to family and close associates.
- إجراء التنفيذ
- Screen before activation and continuously, resolve matches and preserve reliable role and relationship evidence.
- الأدلة الواجب الاحتفاظ بها
- Screening, match decision, role evidence and relationship analysis.
- المصدر الأساسي
- FCA, ss.2 and 16(2)(d); 2020 Regulations, reg.7
PEP relationships require senior-management approval, source-of-wealth and source-of-funds measures and enhanced ongoing monitoring.
- إجراء التنفيذ
- Corroborate source evidence, record approval before starting or continuing and configure enhanced monitoring.
- الأدلة الواجب الاحتفاظ بها
- Source file, approval, monitoring plan and reviews.
- المصدر الأساسي
- FCA, s.16(2)(d)
High risk receives enhanced CDD; simplified measures require substantiated lower risk.
- إجراء التنفيذ
- Define standard, enhanced and simplified control sets with eligibility rules and prohibited overrides.
- الأدلة الواجب الاحتفاظ بها
- Risk-control matrix, rationale, approvals and override log.
- المصدر الأساسي
- FCA, s.21(5)-(6); 2020 Regulations, regs.3-4
Non-face-to-face relationships receive the same identification, verification and monitoring standards as face-to-face relationships; the Act's non-resident limitation must be assessed.
- إجراء التنفيذ
- Confirm legal eligibility, then use document-integrity, presence, independent-data, device and fraud checks proportionate to risk.
- الأدلة الواجب الاحتفاظ بها
- Eligibility memo, remote standard, test results, fraud logs and exceptions.
- المصدر الأساسي
- FCA, s.16(8)
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity, monitor continuously and report suspicion promptly and confidentially.5 عناصر+
If satisfactory identity evidence is unavailable, do not open, start or transact; submit an STR within three days and do not proceed unless FIA directs.
- إجراء التنفيذ
- Route failed CDD to block and confidential reporting review without alerting the customer.
- الأدلة الواجب الاحتفاظ بها
- Failure reason, block, STR, submission receipt and FIA direction if any.
- المصدر الأساسي
- FCA, s.19; 2020 Regulations, reg.4(3)-(4)
Ongoing monitoring tests activity against customer knowledge, business, risk and source information and keeps records current.
- إجراء التنفيذ
- Configure risk-based refresh, event triggers and transaction monitoring; investigate deviations.
- الأدلة الواجب الاحتفاظ بها
- Refresh schedule, triggers, scenarios, alerts, cases and updated CDD.
- المصدر الأساسي
- FCA, s.29; 2020 Regulations, regs.19(5), 24
Suspected or confirmed transactions and attempted transactions connected to an offence are reportable regardless of amount.
- إجراء التنفيذ
- Escalate immediately, preserve the suspicion timestamp and submit a complete STR to FIA.
- الأدلة الواجب الاحتفاظ بها
- Internal report, analysis, STR, receipt and case timeline.
- المصدر الأساسي
- FCA, s.23(1)-(2); 2020 Regulations, reg.29
An STR is due as soon as possible and no later than three days after suspicion, wherever possible before execution.
- إجراء التنفيذ
- Use a shorter internal SLA measured from the documented formation of suspicion.
- الأدلة الواجب الاحتفاظ بها
- Suspicion timestamp, approval, submission timestamp and SLA monitoring.
- المصدر الأساسي
- FCA, s.23(1)
Tipping off and unauthorised disclosure of reports or suspicion are prohibited; reporting overrides inconsistent secrecy duties subject to legal privilege.
- إجراء التنفيذ
- Restrict case access, control customer communications and train staff on permitted disclosures.
- الأدلة الواجب الاحتفاظ بها
- Access logs, communication plan, training and disclosure register.
- المصدر الأساسي
- FCA, ss.24-26 and 32
07Threshold reports, wires and sector triggersKeep CDD, STR and prescribed threshold-reporting duties separate.4 عناصر+
Transactions or aggregate transactions of at least MWK 5,000,000 require the prescribed large-currency or electronic-transfer report, with timing guided by FIA.
- إجراء التنفيذ
- Aggregate accurately, apply current FIA formats and timing and submit an STR separately where suspicion exists.
- الأدلة الواجب الاحتفاظ بها
- Threshold configuration, aggregation tests, report, FIA receipt and linked STR decision.
- المصدر الأساسي
- FCA, s.33; 2020 Regulations, reg.28
Local mobile-money or similar local transfer reporting applies to each transfer above MWK 300,000; domestic and international electronic transfers also fall within regulation 21.
- إجراء التنفيذ
- Confirm current FIA file specifications and configure the correct transfer populations without treating the threshold as a CDD safe harbour.
- الأدلة الواجب الاحتفاظ بها
- Scope memo, transfer rules, test cases, submissions and receipts.
- المصدر الأساسي
- 2020 Regulations, reg.21
Electronic transfers carry complete originator and beneficiary information; deficient transfers require risk-based execution, rejection or suspension and reporting controls.
- إجراء التنفيذ
- Validate required fields through the chain, hold deficient messages and monitor persistent counterpart failures.
- الأدلة الواجب الاحتفاظ بها
- Field matrix, validation, repair/reject queue, monitoring and samples.
- المصدر الأساسي
- FCA, s.28; 2020 Regulations, reg.20
Casinos identify customers at entry or remote access and apply the MWK 2,000,000 24-hour transaction triggers specified in regulation 17.
- إجراء التنفيذ
- Aggregate chips, gaming-machine and remote-gaming activity per customer over 24 hours and retain identification records.
- الأدلة الواجب الاحتفاظ بها
- Access record, aggregation, identity file and test results.
- المصدر الأساسي
- 2020 Regulations, reg.17
08Targeted financial sanctionsImplement current UN and domestic designations without delay and without prior notice.2 عناصر+
Reporting institutions screen against current domestic and United Nations designation lists and must not make funds or services available to designated persons.
- إجراء التنفيذ
- Screen customers, beneficial owners, representatives, counterparties and transactions at onboarding and on list change.
- الأدلة الواجب الاحتفاظ بها
- List provenance, screening logs, population reconciliation and match decisions.
- المصدر الأساسي
- Financial Crimes (Suppression of Terrorist Financing and Proliferation) Regulations 2017, regs.8-12
Property of a designated person is frozen without delay and the competent authority is notified using the current procedure.
- إجراء التنفيذ
- Maintain a 24/7 escalation path, validate matches, block access without notice and contact FIA for the live reporting route.
- الأدلة الواجب الاحتفاظ بها
- Match analysis, freeze timestamp, asset inventory, report and receipt.
- المصدر الأساسي
- 2017 TFS Regulations, regs.11-12
09Records, access and assuranceRetain reconstructable evidence for the correct seven-year clock and make it promptly available.3 عناصر+
Identity, transaction, correspondence, FIA reports, unreported investigations and FIA enquiries are retained for at least seven years under class-specific clocks.
- إجراء التنفيذ
- Map each record class to its statutory start event, legal hold and deletion control.
- الأدلة الواجب الاحتفاظ بها
- Retention schedule, system configuration, samples, legal holds and deletion tests.
- المصدر الأساسي
- FCA, s.22; 2020 Regulations, reg.19
Records must reconstruct transactions and be immediately available to FIA and competent authorities.
- إجراء التنفيذ
- Index linked CDD, transaction, investigation and report evidence and test retrieval.
- الأدلة الواجب الاحتفاظ بها
- Request register, retrieval tests, access control and response package.
- المصدر الأساسي
- FCA, s.22(3)-(5)
Reliance on a third party does not transfer ultimate CDD responsibility.
- إجراء التنفيذ
- Assess supervision and country risk, obtain core information immediately and contract for documents without delay.
- الأدلة الواجب الاحتفاظ بها
- Due diligence, agreement, document tests, monitoring and exit plan.
- المصدر الأساسي
- FCA, s.17
10Privacy, biometrics and transfersApply the Data Protection Act 2024 alongside AML retention and disclosure duties.3 عناصر+
Personal data needs a documented lawful basis, specified purpose, proportionate collection, accuracy, security and governed retention.
- إجراء التنفيذ
- Maintain a data inventory and notices, minimise onboarding fields and reconcile AML retention with privacy deletion rules.
- الأدلة الواجب الاحتفاظ بها
- Inventory, lawful-basis record, notices, retention map, access and deletion logs.
- المصدر الأساسي
- Data Protection Act 2024
Biometric and other sensitive verification data require heightened necessity, access, security and vendor controls.
- إجراء التنفيذ
- Complete a documented privacy and security assessment before biometric processing and preserve consent or another applicable legal condition.
- الأدلة الواجب الاحتفاظ بها
- Assessment, legal condition, template controls, access logs and vendor assurance.
- المصدر الأساسي
- Data Protection Act 2024
Security incidents and international transfers must follow the Act and current MACRA procedures.
- إجراء التنفيذ
- Confirm live notification, registration and transfer mechanics with MACRA; maintain incident and transfer playbooks without inventing deadlines not verified in the official text.
- الأدلة الواجب الاحتفاظ بها
- MACRA confirmation, incident register, transfer map, contracts and assessments.
- المصدر الأساسي
- Data Protection Act 2024; Government Notice 40 of 2024
11Practical evidence packs and change controlMake every decision reconstructable and keep time-sensitive rules current.2 عناصر+
A complete customer file links identity, KYB, ownership, screening, risk, approval, monitoring and reporting decisions.
- إجراء التنفيذ
- Block activation when mandatory evidence or approval is missing and preserve the release decision.
- الأدلة الواجب الاحتفاظ بها
- Control checklist, linked case file, approvals and release log.
- المصدر الأساسي
- FCA, ss.16-23; 2020 Regulations
Thresholds, report channels, sanctions lists, FATF status, licensing conditions and privacy procedures require ongoing legal monitoring.
- إجراء التنفيذ
- Assign owners and review FIA, RBM, CRIPC, MACRA, Gazette, FATF and ESAAMLG sources on a governed schedule.
- الأدلة الواجب الاحتفاظ بها
- Legal inventory, source log, change assessments and implementation tickets.
- المصدر الأساسي
- Official sources listed below
سجل المصادر الأساسية
13 مصدرًا مستخدمًا في هذه القائمة
استخدم هذه الروابط للتحقق من التشريعات وإرشادات الجهات الرقابية وإجراءات الإبلاغ والبيانات الدولية.
- Financial Crimes Act (Chapter 7:07)Malawi Gazette text via MalawiLII · Primary legislation reproduction
- Financial Crimes (Money Laundering) Regulations, 2020Malawi Gazette text via MalawiLII · Primary regulations reproduction
- Financial Crimes (Money Laundering) (Amendment) Regulations, 2020Malawi Gazette text via MalawiLII · Primary regulations reproduction
- Financial Crimes (Suppression of Terrorist Financing and Proliferation) Regulations, 2017Malawi Gazette text via MalawiLII · Primary regulations reproduction
- Financial Services ActMalawi Gazette text via MalawiLII · Primary legislation reproduction
- Reserve Bank of MalawiReserve Bank of Malawi · Official regulator
- Companies Registrations and Intellectual Property CentreCRIPC · Official company registry
- CRIPC services and beneficial-ownership updatesCRIPC · Official registry guidance
- MACRA confirmation of the Data Protection Act, 2024MACRA · Official regulator confirmation
- Data Protection Act, 2024: CommencementMalawi Gazette text via MalawiLII · Primary commencement notice reproduction
- Malawi fourth enhanced follow-up report, April 2024ESAAMLG · Authoritative regional assessment
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
إجابات مباشرة
أسئلة KYC وKYB وAML في ملاوي
Who receives suspicious transaction reports in Malawi?+
The Financial Intelligence Authority. Use the current FIA-prescribed form and channel.
When is an STR due?+
As soon as possible and no later than three days after suspicion is formed, wherever possible before the transaction; attempts and any amount are covered.
What is the general large-transaction reporting threshold?+
The 2020 Regulations specify MWK 5,000,000 per transaction or aggregate for prescribed large-currency and electronic-transfer reports. Confirm current FIA formats and filing timing.
Does Malawi use one beneficial-ownership percentage for AML CDD?+
No universal percentage is stated in the cited Act. Identify natural persons through controlling ownership, other control and, only when necessary, senior-management fallback.
How long are core AML records kept?+
At least seven years, with the start event depending on the record class and relationship or transaction event.
Are financial services automatically permitted after company registration?+
No. Company registration does not replace RBM or other sector licensing and approval.
How should sanctions matches be handled?+
Validate urgently, freeze designated property without delay and use the current competent-authority reporting procedure without tipping off the affected party.
Does the Data Protection Act apply to identity verification?+
Yes where personal data is processed. Document purpose and lawful basis, minimise data, secure it, govern retention and confirm sensitive-data and transfer procedures with MACRA.
Is Malawi on a FATF public list?+
Malawi was not named in FATF's public statements dated 19 June 2026. ESAAMLG follow-up is a separate peer-review process.
منهجية البحث والمراجعة
تحدد VOVE ID Compliance Research النطاق التنظيمي، وتحول الالتزامات إلى ضوابط تشغيلية، وتربط الادعاءات الجوهرية بالمصادر، وتسجل تاريخ وإصدار كل مراجعة.
This checklist is general regulatory information, not legal advice or a licence determination. It reflects sources reviewed on 17 July 2026. Confirm current Gazette amendments, FIA directives and report channels, RBM licensing conditions, CRIPC filing mechanics and MACRA data-protection procedures with Malawian counsel and the competent authority before launch. Monetary reporting thresholds, AML beneficial-ownership analysis and company-registry disclosures are distinct. VOVE ID supports evidence collection and audit trails; the reporting institution remains responsible for acceptance, reporting, freezing and compliance decisions.