KYC, KYB & AML compliance checklist
Benin KYC, KYB & AML
An implementation-focused checklist for financial institutions, fintechs and designated non-financial businesses operating in Benin under the 2024 AML/CFT/CPF law, UMOA rules, beneficial-ownership framework and Digital Code.
- Reviewed
- 23 July 2026
- Version
- 1.0
- control areas
- 11
- implementation checks
- 40
Direct answer
What does the Benin compliance checklist cover?
The Benin checklist translates primary KYC, KYB and AML rules into 11 control areas and 40 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML/CFT/CPF law
- Law No. 2024-01 of 20 February 2024
- Financial intelligence unit
- CENTIF Benin
- STR timing
- Immediately after suspicion or reasonable grounds arise
- Cash transaction report
- XOF 15 million or more, including apparently linked operations
- Core AML retention
- 10 years under record-class-specific clocks
- Beneficial ownership
- Controlling ownership, other control, then senior-manager fallback
- Payments authority
- BCEAO within the UMOA framework
- Privacy authority
- APDP Benin
- VASP perimeter
- Prior competent-authority approval or authorisation required
- FATF public lists
- Not named in the June 2026 statements
Implementation detail
Benin compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before onboarding or launch.4 items+
Financial institutions and listed designated non-financial businesses and professions are reporting persons.
- Implementation action
- Map each entity, product, profession, branch, distributor, agent and outsourced function to Law No. 2024-01 and document the responsible supervisor.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Primary citation
- Law No. 2024-01, arts. 2-4 and 107
CENTIF receives and analyses suspicious transaction reports and may request information.
- Implementation action
- Appoint an authorised correspondent and obtain the current CENTIF access, form and acknowledgement instructions before production reporting.
- Evidence to retain
- Appointment, access record, reporting procedure and test evidence.
- Primary citation
- Law No. 2024-01, arts. 60, 64 and 95-103
In-scope virtual-asset services require prior approval or authorisation from the competent authority.
- Implementation action
- Obtain a written perimeter assessment and the required approval before exchange, transfer, custody or other in-scope virtual-asset activity.
- Evidence to retain
- Classification, application, approval, conditions and service map.
- Primary citation
- Law No. 2024-01, arts. 58-59
Regulated payment services require the applicable BCEAO authorisation.
- Implementation action
- Map each payment, e-money, acquiring, transfer, remittance, initiation and agent function to the current UMOA payment-services framework.
- Evidence to retain
- Licence or exemption analysis, BCEAO register check and partner file.
- Primary citation
- BCEAO Instruction No. 001-01-2024 and current authorised-institution register
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.3 items+
Reporting persons must maintain internal organisation, controls and risk management proportionate to their activities.
- Implementation action
- Approve policies for CDD, BO, PEPs, sanctions, monitoring, reporting, recordkeeping, training, screening and independent testing.
- Evidence to retain
- Policy suite, approvals, control library, training and audit reports.
- Primary citation
- Law No. 2024-01, arts. 12-14
Money-laundering, terrorist-financing and proliferation-financing risks must be identified, assessed, documented and kept current.
- Implementation action
- Assess customers, geographies, products, services, transactions, channels, new products and technologies before launch and on material change.
- Evidence to retain
- Risk assessment, methodology, source data, change log and approvals.
- Primary citation
- Law No. 2024-01, art. 15
Institutions must be able to justify that customer controls are proportionate to risk.
- Implementation action
- Define risk-rating logic, control variants, approval levels and review cycles, then test their operation.
- Evidence to retain
- Risk model, decision records, samples and assurance results.
- Primary citation
- Law No. 2024-01, arts. 19-21 and 84-85
03Natural-person identification and CDDIdentify and verify customers, actors and beneficial owners at every statutory trigger.4 items+
Before a relationship or assisted transaction, collect and verify identity from reliable, independent sources and understand purpose and intended nature.
- Implementation action
- Capture identity attributes, verify evidence provenance, identify the beneficial owner and establish the expected activity profile.
- Evidence to retain
- CDD file, source provenance, verification result, purpose and risk decision.
- Primary citation
- Law No. 2024-01, arts. 16-17
CDD also applies to transfers, suspicion, identity doubt and applicable occasional or linked transactions.
- Implementation action
- Configure relationship, transfer, cash aggregation, suspicion and identity-quality triggers; do not treat a threshold as a safe harbour.
- Evidence to retain
- Trigger matrix, aggregation results, alerts and CDD timestamps.
- Primary citation
- Law No. 2024-01, arts. 17 and 49; UMOA Decision No. 021
Limited delayed verification must finish as soon as possible and before the first transaction, with effective risk controls.
- Implementation action
- Block transaction capability until verification is complete and document why each statutory condition is satisfied.
- Evidence to retain
- Deferral approval, restrictions, completion timestamp and exception testing.
- Primary citation
- Law No. 2024-01, art. 18
Remote relationships require particular and sufficient preventive measures.
- Implementation action
- Use risk-calibrated document, device, liveness, biometric or equivalent safeguards and manual escalation without assuming one technology is legally sufficient.
- Evidence to retain
- Remote-onboarding standard, vendor review, model tests and exceptions.
- Primary citation
- Law No. 2024-01, art. 22
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 items+
Legal-person and legal-arrangement CDD covers legal name, form, constitutive documents, powers, management and addresses.
- Implementation action
- Obtain current registry and constitutional evidence and verify every representative's identity and authority.
- Evidence to retain
- Registry extract, statutes, managers, addresses, mandate and discrepancy log.
- Primary citation
- Law No. 2024-01, arts. 17 and 26
The BO cascade tests controlling ownership, then control by other means, then the relevant senior managing official.
- Implementation action
- Trace every ownership layer and control right; document why each stage did or did not identify a natural person before using the fallback.
- Evidence to retain
- Ownership chart, control analysis, fallback rationale and verified BO files.
- Primary citation
- Law No. 2024-01, art. 26
Trusts and comparable arrangements use role-based BO tests.
- Implementation action
- Identify and verify the settlor, trustee, protector, beneficiaries or class and every other natural person exercising ultimate control.
- Evidence to retain
- Instrument, role register, identity files and control analysis.
- Primary citation
- Law No. 2024-01, art. 26
Companies must keep accurate, current shareholder, member and BO information; the national BO register is established by law.
- Implementation action
- Maintain event-driven updates, reconcile registry data and complete filings under the current 2025 implementation instrument.
- Evidence to retain
- Registers, update log, filing receipts, supporting documents and discrepancies.
- Primary citation
- Law No. 2024-01, arts. 76-79 and 122; Ministerial Order No. 1700-C/MEF (2025)
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.4 items+
PEP relationships require risk systems, senior-management approval, source-of-wealth and source-of-funds measures, and enhanced monitoring.
- Implementation action
- Screen customers and BOs for domestic, foreign and international-organisation PEP exposure and connected-person risk.
- Evidence to retain
- Screening, match rationale, source file, approval and monitoring plan.
- Primary citation
- Law No. 2024-01, art. 29
Institutions reassess identified PEP customer profiles every three years and retain risk-based treatment where warranted.
- Implementation action
- Schedule the statutory reassessment and document any change to status or controls.
- Evidence to retain
- Review diary, reassessment, decision and approval.
- Primary citation
- Law No. 2024-01, art. 29
Higher-risk relationships require enhanced measures; simplified treatment needs a demonstrated lower-risk basis and cannot override suspicion.
- Implementation action
- Document control changes, corroboration, approvals and monitoring intensity for each risk treatment.
- Evidence to retain
- EDD or SDD rationale, evidence, approval and review.
- Primary citation
- Law No. 2024-01, arts. 30 and 84-85
Reliance on a third party does not remove the institution's responsibility for CDD.
- Implementation action
- Assess eligibility, obtain required information immediately, contract for document access and test retrieval.
- Evidence to retain
- Due diligence, agreement, retrieval test and exceptions.
- Primary citation
- Law No. 2024-01, arts. 35-38
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity, monitor continuously and report suspicion immediately and confidentially.4 items+
If required CDD cannot be completed, do not open or execute, or terminate the relationship, and submit an STR.
- Implementation action
- Operate a controlled block or exit and preserve the confidential STR decision.
- Evidence to retain
- Failure reason, block, closure, STR and acknowledgement.
- Primary citation
- Law No. 2024-01, art. 25
Relationships and transactions require ongoing scrutiny, current CDD and written examination of complex, unusual or apparently purposeless activity.
- Implementation action
- Investigate source, destination, purpose and BO, refresh CDD and retain the confidential written analysis.
- Evidence to retain
- Alerts, cases, report, refreshed CDD and review.
- Primary citation
- Law No. 2024-01, arts. 19-21
Reporting persons must immediately report suspected sums, transactions and attempted transactions to CENTIF.
- Implementation action
- Timestamp when suspicion or reasonable grounds arose and file using the current prescribed route and model; send changes or supplements without delay.
- Evidence to retain
- Internal report, analysis, STR, CENTIF receipt and timeline.
- Primary citation
- Law No. 2024-01, art. 60
Suspicious activity is withheld before reporting unless the statutory post-execution conditions apply; tipping off is prohibited.
- Implementation action
- Govern holds, lawful release, post-execution reporting and restricted communications.
- Evidence to retain
- Hold decision, exception rationale, access logs and communications record.
- Primary citation
- Law No. 2024-01, arts. 61 and 63
07Wires, cash thresholds, payments and agentsKeep CDD triggers, special examination and threshold reports distinct.4 items+
Cash transactions of XOF 15 million or more, including apparently linked operations, are reported to CENTIF.
- Implementation action
- Aggregate linked activity, configure the exact in-scope entity and transaction logic, and obtain current CENTIF reporting instructions.
- Evidence to retain
- Threshold configuration, tests, reports, receipts and exception record.
- Primary citation
- Law No. 2024-01, art. 72; UMOA Decision No. 021, art. 8
Multiple cash transactions exceeding XOF 9 million in one day or at unusual frequency trigger identification and verification for financial institutions.
- Implementation action
- Aggregate by person and account across channels and apply CDD regardless of amount where suspicion exists.
- Evidence to retain
- Aggregation logic, customer match, CDD file and testing.
- Primary citation
- Law No. 2024-01, art. 17(i); UMOA Decision No. 021, art. 3
Payment in cash or bearer title at XOF 50 million or more, and unusual or unjustified operations at XOF 10 million or more, require special examination.
- Implementation action
- Investigate origin, destination, purpose and BO and retain a confidential report.
- Evidence to retain
- Scenario, investigation, source evidence, report and approval.
- Primary citation
- Law No. 2024-01, art. 21; UMOA Decision No. 021, art. 4
Wire transfers must carry required originator and beneficiary information and deficient transfers require governed handling.
- Implementation action
- Validate required data throughout the chain and define reject, suspend, execute, investigate and follow-up rules.
- Evidence to retain
- Field matrix, validation, repair queue, samples and decisions.
- Primary citation
- Law No. 2024-01, arts. 39-47
08Targeted financial sanctions and CPFScreen, freeze, restrict and report without delay under the current designation framework.3 items+
Reporting persons must implement internal procedures for targeted financial sanctions.
- Implementation action
- Screen customers, BOs, controllers, representatives and transactions at onboarding, list updates and before relevant activity.
- Evidence to retain
- List inventory, update logs, screening results and match files.
- Primary citation
- Law No. 2024-01, arts. 89 and 124
Property of a designated person or entity is frozen immediately after notification, without prior notice, and must not be made available.
- Implementation action
- Maintain a 24/7 freeze and escalation path covering direct, indirect, owned and controlled exposure.
- Evidence to retain
- Procedure, system test, match decision, freeze and audit trail.
- Primary citation
- Law No. 2024-01, art. 89
CENTIF and the competent authority are informed immediately of relevant funds, frozen assets, measures and attempted operations.
- Implementation action
- Use the current competent-authority route and obtain written direction before release or dealing.
- Evidence to retain
- Notifications, receipts, directions and release decision.
- Primary citation
- Law No. 2024-01, arts. 90-91
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.4 items+
Customer identity, profile and analysis records are kept for 10 years after account closure or relationship cessation.
- Implementation action
- Map every customer record class to the relationship-based clock and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, sample and deletion test.
- Primary citation
- Law No. 2024-01, art. 23
Transaction, accounting and business-correspondence records are kept for 10 years after execution.
- Implementation action
- Use transaction-based clocks and retain enough information to reconstruct individual operations.
- Evidence to retain
- Archive configuration, reconstruction test and retrieval log.
- Primary citation
- Law No. 2024-01, art. 23
Corporate and BO information is retained for at least 10 years after dissolution or the end of the relevant professional relationship.
- Implementation action
- Assign an archive owner and preserve current and historic ownership evidence.
- Evidence to retain
- Dissolution checklist, archive, access controls and retrieval test.
- Primary citation
- Law No. 2024-01, art. 79
Required records must be available to CENTIF, supervisors, judicial authorities and authorised investigators.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Evidence to retain
- Request register, retrieval tests, access log and response package.
- Primary citation
- Law No. 2024-01, arts. 24 and 103
10Privacy, biometrics and transfersApply the Digital Code alongside AML collection, retention and disclosure duties.4 items+
Personal-data processing requires a defined purpose, lawful treatment, proportionality, security and rights controls.
- Implementation action
- Inventory identity, BO, screening, monitoring and reporting data; document purpose, access, recipients, location and retention.
- Evidence to retain
- Processing register, basis assessment, notices, access matrix and retention map.
- Primary citation
- Digital Code, Law No. 2017-20 as amended, Book V
Applicable processing must complete the required APDP declaration, register or prior-authorisation formality before implementation.
- Implementation action
- Classify ordinary, sensitive, biometric, interconnected and cross-border processing with APDP or counsel before production use.
- Evidence to retain
- Formality matrix, filing, receipt or authorisation and change log.
- Primary citation
- Digital Code, art. 405; APDP compliance guidance
Biometric and other sensitive identity data require a specific lawful basis, necessity and stronger safeguards.
- Implementation action
- Document the applicable condition, minimise templates and raw images, test vendors and restrict access.
- Evidence to retain
- Legal assessment, necessity record, security design, tests and access logs.
- Primary citation
- Digital Code, Book V; controlled APDP implementation dependency
International transfers and security incidents require analysis under the current Digital Code and APDP procedures.
- Implementation action
- Document destinations and safeguards and maintain an incident escalation route; confirm current notification forms and deadlines rather than importing foreign rules.
- Evidence to retain
- Transfer assessment, contracts, incident log and APDP correspondence.
- Primary citation
- Digital Code, Book V; APDP official procedures
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 items+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- Law No. 2024-01, arts. 12-26
Time-sensitive thresholds, lists, reporting routes, registers and licences require governed change monitoring.
- Implementation action
- Assign owners to review SGG, CENTIF, BCEAO, UMOA, APIEx, APDP, FATF and GIABA sources on a documented schedule.
- Evidence to retain
- Legal inventory, source log, change assessment and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 40 implementation checks, with direct regulatory sources.
Download the Benin KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Benin implementation checklist. Regulatory review date: 23 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.0, reviewed 23 July 2026
Trusted by leading compliance teams
Primary-source register
15 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 2024-01 of 20 February 2024 on AML/CFT/CPFSecretariat General du Gouvernement, Republic of Benin · Primary legislation
- 2023 UMOA uniform AML/CFT/CPF lawBCEAO · Primary regional legal framework
- UMOA Decision No. 021 of 21 December 2023 setting implementation thresholdsBCEAO · Primary regional decision
- UMOA Decision No. 003 of 28 March 2024 setting complementary thresholdsBCEAO · Primary regional decision
- BCEAO Instruction No. 003-03-2025 on customer identification and knowledgeBCEAO · Primary regulator instruction
- BCEAO Instruction No. 001-03-2025 on AML/CFT/CPF organisation and controlBCEAO · Primary regulator instruction
- BCEAO Instruction No. 001-01-2024 on payment services in the UMOABCEAO · Primary regulator instruction
- CENTIF Benin annual report 2025CENTIF Benin · Official FIU report
- Beneficial-owner implementation materialsAPIEx / MonEntreprise.bj · Official registry and implementation portal
- Digital Code, Law No. 2017-20 of 20 April 2018Authority for the Protection of Personal Data · Primary legislation - official authority copy
- Law No. 2020-35 amending the Digital CodeSecretariat General du Gouvernement, Republic of Benin · Primary amending legislation
- Benin country assessment and follow-upFATF · Authoritative assessment index
- Benin 2026 fifth enhanced follow-up reportGIABA · Authoritative regional peer review
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Direct answers
Benin KYC, KYB and AML questions
Who receives suspicious transaction reports in Benin?+
CENTIF Benin receives reports using the current prescribed model and route.
When is an STR due?+
Immediately after suspicion or reasonable grounds arise. Attempted transactions are included, and relevant supplementary information is sent without delay.
What cash transaction report threshold applies?+
Institutions and designated non-financial businesses report cash transactions of XOF 15 million or more, whether a single operation or apparently linked operations.
What beneficial-ownership test applies?+
For legal persons, identify the natural person with controlling ownership, then control by other means, and only then the relevant senior managing official. Trusts and similar arrangements use role-based tests.
How long are AML records kept?+
Customer identity, profile and analysis records are kept for 10 years after relationship cessation; transaction and correspondence records are kept for 10 years after execution.
Do virtual-asset and payment services require authorisation?+
Yes, where the activity falls within the regulated perimeter. Obtain a current activity-specific decision from the competent authority before launch.
Does KYC processing require APDP formalities?+
Potentially. Article 405 establishes prior declaration or register requirements, while sensitive, biometric and transfer processing may need additional treatment. Confirm the current formality with APDP.
Is Benin on a FATF public list?+
Benin was not named in FATF's June 2026 increased-monitoring or call-for-action statements. GIABA enhanced follow-up is a separate peer-review process.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 23 July 2026 · Version 1.0
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 23 July 2026. Confirm the live CENTIF reporting route and forms, activity-specific licences, sanctions instructions, beneficial-owner filing workflow, APDP formalities and all sector overlays with the competent authority and qualified Beninese counsel before launch.