KYC, KYB & AML compliance checklist
Burundi KYC, KYB & AML
An implementation-focused checklist for financial institutions, fintechs and designated non-financial businesses operating in Burundi under the amended AML/CFT law, BRB Regulation No. 02/2026, company-registration rules and the 2026 personal-data law.
- Reviewed
- 27 July 2026
- Version
- 1.0
- control areas
- 11
- implementation checks
- 40
Direct answer
What does the Burundi compliance checklist cover?
The Burundi checklist translates primary KYC, KYB and AML rules into 11 control areas and 40 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML/CFT law
- Law No. 1/08 of 27 March 2025 amending Law No. 1/02 of 4 February 2008
- Financial intelligence unit
- Cellule Nationale du Renseignement Financier (CNRF)
- STR timing
- Promptly; without delay after the statutory suspicion trigger
- Threshold reports
- CNRF or competent-authority thresholds - confirm the live instrument
- Core AML retention
- 10 years under relationship- and transaction-specific clocks
- Beneficial ownership
- Identify the natural person who ultimately owns or controls, or on whose behalf activity occurs
- Financial supervisor
- Banque de la Republique du Burundi (BRB) for BRB-supervised entities
- Privacy law
- Law No. 1/03 of 10 March 2026
- Data-breach notice
- Notify the protection body within 72 hours; high-risk individuals within 96 hours
- FATF public lists
- Not named in the June 2026 public statements
Implementation detail
Burundi compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve the entity, activity, supervisor and reporting perimeter before onboarding or launch.4 items+
The AML/CFT law applies to listed financial institutions, public and private licensing bodies, and designated non-financial businesses and professions.
- Implementation action
- Map each entity, product, branch, agent, distributor and outsourced function to the statutory list and document the responsible supervisor.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Primary citation
- Law No. 1/08 of 27 March 2025, arts. 1-3
CNRF is the national FIU and receives, analyses and disseminates suspicious transaction reports.
- Implementation action
- Appoint an authorised correspondent and obtain the current CNRF form, access, submission and acknowledgement instructions before production reporting.
- Evidence to retain
- Appointment, access record, reporting procedure and test evidence.
- Primary citation
- Law No. 1/08, arts. 4-6; Decree No. 100/009 of 9 February 2026
BRB Regulation No. 02/2026 applies to credit institutions, the National Postal Service, exchange bureaux, payment institutions, financing or guarantee funds and microfinance institutions.
- Implementation action
- Document whether each service is within a BRB-supervised category and obtain the required activity-specific approval before launch.
- Evidence to retain
- Classification, application, approval, conditions and service map.
- Primary citation
- BRB Regulation No. 02/2026, arts. 1-2
Virtual-asset services are within the AML law's defined regulated perimeter, but the reviewed sources did not establish a standalone live VASP licensing route.
- Implementation action
- Do not launch exchange, transfer, custody or other virtual-asset activity without a written perimeter and licensing decision from BRB and other competent authorities.
- Evidence to retain
- Legal analysis, authority correspondence, licence or written no-objection and product controls.
- Primary citation
- Law No. 1/08, art. 3 definitions; controlled licensing uncertainty
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.3 items+
Reporting institutions must establish AML/CFT policies, procedures, internal controls, employee screening, training and independent control arrangements.
- Implementation action
- Approve and periodically test a control framework covering CDD, BO, PEPs, sanctions, monitoring, reporting, records and training.
- Evidence to retain
- Policy suite, approvals, control library, training and assurance reports.
- Primary citation
- Law No. 1/08, arts. 75-76; BRB Regulation No. 02/2026, arts. 4 and 18-20
Institutions must identify and assess their ML/TF risks and apply controls proportionate to risk.
- Implementation action
- Assess customers, countries, products, services, transactions, delivery channels and new technologies before launch and on material change.
- Evidence to retain
- Risk assessment, methodology, source data, change log and approvals.
- Primary citation
- Law No. 1/08, arts. 23-38
BRB-supervised institutions must appoint an AML/CFT officer with adequate authority, independence and access and notify BRB and CNRF.
- Implementation action
- Approve the appointment, formal mandate, resources, escalation rights and group coverage; file required notifications.
- Evidence to retain
- Appointment, notifications, job mandate, access and board reporting.
- Primary citation
- BRB Regulation No. 02/2026, arts. 18-19
03Natural-person identification and CDDIdentify and verify customers, representatives and ultimate actors using reliable independent evidence.4 items+
Regular and occasional customers, and persons acting for them, must be identified and their authority verified through independent and reliable sources.
- Implementation action
- Capture identity attributes, verify evidence provenance, confirm mandates and establish the purpose and expected nature of activity.
- Evidence to retain
- CDD file, source provenance, verification result, authority and risk decision.
- Primary citation
- Law No. 1/08, art. 53; BRB Regulation No. 02/2026, arts. 5 and 10
Remote onboarding requires adapted identification measures and may use a reliable, independent digital-identification system.
- Implementation action
- Authenticate documents and apply risk-calibrated independent checks, supplementary evidence and escalation without assuming one technology is legally sufficient.
- Evidence to retain
- Remote-onboarding standard, vendor review, model tests, first-payment control and exceptions.
- Primary citation
- Law No. 1/08, art. 54; BRB Regulation No. 02/2026, art. 7
Anonymous and fictitious-name accounts are prohibited.
- Implementation action
- Block activation until the customer and required actors are identified and verified under the applicable rule.
- Evidence to retain
- Account controls, test results and rejected-case log.
- Primary citation
- Law No. 1/08, art. 52; BRB Regulation No. 02/2026, art. 5
CDD information must remain accurate and relevant during the relationship.
- Implementation action
- Use risk-based and event-driven refreshes for identity, purpose, expected activity, ownership and authority.
- Evidence to retain
- Refresh schedule, triggers, updated files and exception testing.
- Primary citation
- Law No. 1/08, art. 65; BRB Regulation No. 02/2026, art. 5
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 items+
Businesses and branches register through the ADB commercial register and maintain registrations for later changes.
- Implementation action
- Obtain current registry evidence, constitutive documents, tax number, registered address, managers and representative mandates; reconcile later changes.
- Evidence to retain
- Commercial-register certificate, NIF, statutes, change filings and discrepancy log.
- Primary citation
- Commercial Code 2015, arts. 34-37; ADB official creation and modification procedures
Institutions must discover and verify the natural person who ultimately owns or controls the customer or on whose behalf a transaction occurs.
- Implementation action
- Trace ownership and control through every layer and record the natural-person conclusion and evidence; do not substitute an undefined percentage.
- Evidence to retain
- Ownership chart, control analysis, source records and verified BO files.
- Primary citation
- Law No. 1/08, art. 3 definitions and arts. 51, 53 and 64; BRB Regulation No. 02/2026, arts. 3, 5-6
Trustees or equivalent managers must disclose that they act for others at relationship and prescribed occasional-transaction triggers.
- Implementation action
- Identify the arrangement, trustee or manager, settlor, beneficiaries and all persons exercising ultimate control; confirm any live threshold instrument.
- Evidence to retain
- Instrument, role register, identity files, control analysis and threshold check.
- Primary citation
- Law No. 1/08, art. 55
The 2026 national risk assessment reported that Burundi did not yet have a national BO register.
- Implementation action
- Do not represent ordinary commercial-register evidence as a verified national BO filing; monitor for a new register and reconcile when implemented.
- Evidence to retain
- Registry checks, customer-supplied ownership evidence, independent corroboration and change-monitoring log.
- Primary citation
- Burundi National Risk Assessment 2026, para. 161
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.4 items+
Domestic, foreign and international-organisation PEPs, close family and known associates fall within the statutory PEP framework.
- Implementation action
- Screen customers, beneficial owners, controllers and representatives at onboarding, list updates and periodic review.
- Evidence to retain
- Screening, match rationale, relationship mapping and review record.
- Primary citation
- Law No. 1/08, art. 3 definitions 35-38
BRB-supervised institutions apply enhanced control to PEP relationships; statutory PEP status continues for two years after the relevant function ends.
- Implementation action
- Require risk-based senior approval, source-of-wealth and source-of-funds evidence and enhanced monitoring, including after office where risk persists.
- Evidence to retain
- Source file, approval, monitoring plan and two-year status diary.
- Primary citation
- Law No. 1/08, art. 3 definition 38; BRB Regulation No. 02/2026, art. 5
Reliance on a third party does not remove the reporting institution's responsibility.
- Implementation action
- Confirm equivalent CDD and supervision, obtain identity material without delay, contract for access and test retrieval.
- Evidence to retain
- Due diligence, agreement, retrieval test and exceptions.
- Primary citation
- Law No. 1/08, arts. 46 and 58-60; BRB Regulation No. 02/2026, arts. 8-9
Simplified identification may be allowed only in circumstances defined by the competent authority and may not override suspicion.
- Implementation action
- Use simplified treatment only with the exact current instrument, documented lower-risk basis and a suspicion override.
- Evidence to retain
- Instrument, risk rationale, approval and monitoring.
- Primary citation
- Law No. 1/08, arts. 56 and 60
06Failed CDD, monitoring and suspicious reportingStop unsafe activity, monitor continuously and report suspicion promptly and confidentially.4 items+
If doubt about the true beneficial actor persists after verification, the operation or relationship must end and suspicion must be considered for reporting.
- Implementation action
- Operate a controlled block or exit and preserve the confidential STR decision.
- Evidence to retain
- Failure reason, block, closure, analysis, STR and acknowledgement.
- Primary citation
- Law No. 1/08, art. 64; BRB Regulation No. 02/2026, art. 6
Complex, abnormally large or unusual activity without apparent economic or lawful purpose requires examination and written documentation.
- Implementation action
- Investigate source, destination, purpose and actors, refresh CDD and retain the confidential written analysis.
- Evidence to retain
- Alerts, cases, source evidence, report and approval.
- Primary citation
- Law No. 1/08, arts. 66-67 and 72-73; BRB Regulation No. 02/2026, art. 12
Reporting entities that suspect or reasonably suspect criminal proceeds or terrorist-financing links must report promptly to CNRF.
- Implementation action
- Timestamp the trigger and submit using the current CNRF format and route without waiting for proof of an offence.
- Evidence to retain
- Internal report, analysis, STR, CNRF receipt and timeline.
- Primary citation
- Law No. 1/08, arts. 12-15; BRB Regulation No. 02/2026, art. 14
Suspected activity is withheld before reporting unless non-execution is impossible or would frustrate the investigation; tipping off is prohibited.
- Implementation action
- Govern transaction holds, lawful post-execution reporting and restricted communications; escalate urgent cases to CNRF.
- Evidence to retain
- Hold decision, exception rationale, access logs and communications record.
- Primary citation
- Law No. 1/08, arts. 16-18; BRB Regulation No. 02/2026, art. 15
07Wires, thresholds, payments and agentsKeep CDD triggers, special examination and threshold reports distinct.4 items+
Cash and other threshold reports apply at amounts set by CNRF or the competent authority, including apparently linked operations.
- Implementation action
- Obtain and version-control the live CNRF and BRB threshold instruments; configure aggregation and do not invent a value from the primary law.
- Evidence to retain
- Current instrument, configuration, tests, reports, receipts and exception record.
- Primary citation
- Law No. 1/08, arts. 41 and 48; BRB Regulation No. 02/2026, arts. 3 and 13
Electronic transfers require verified originator name, account and address or alternative identity information.
- Implementation action
- Validate required data through the chain and preserve originator and beneficiary records.
- Evidence to retain
- Field matrix, validation, repair queue, samples and decisions.
- Primary citation
- Law No. 1/08, arts. 69-70
Incoming transfers lacking complete originator information must be repaired and verified; if the information is not obtained, refuse and report to CNRF.
- Implementation action
- Define repair, reject, suspend, investigate and report rules with auditable timelines.
- Evidence to retain
- Repair requests, reject decisions, STRs and testing.
- Primary citation
- Law No. 1/08, art. 71
Payment services and exchange activity require the applicable BRB approval and AML controls.
- Implementation action
- Map the product, agent, outsourcing and settlement chain to the current payments and exchange rules and licence conditions.
- Evidence to retain
- Licence, conditions, agent register, oversight and audit results.
- Primary citation
- Law No. 1/07 of 11 May 2018; BRB Payment Regulation No. 002/2024; BRB Regulation No. 02/2026
08Targeted financial sanctions and proliferation riskScreen, freeze, restrict and report under the current designation framework.3 items+
Funds linked to UN-designated terrorists, terrorist financiers and terrorist organisations are subject to a court-defined freeze, and holders must freeze them immediately.
- Implementation action
- Maintain list-update, screening and rapid escalation controls and obtain competent-authority direction for the specific match.
- Evidence to retain
- List inventory, update logs, screening, match decision, freeze and legal direction.
- Primary citation
- Law No. 1/08, art. 88
Relevant designated-person funds must be reported promptly to CNRF or another competent authority.
- Implementation action
- Notify through the current route, preserve the receipt and do not release or deal without written authority.
- Evidence to retain
- Notification, receipt, direction and release decision.
- Primary citation
- Law No. 1/08, art. 89
The reviewed AML statute is framed principally around ML and TF; CPF implementation details require separate confirmation.
- Implementation action
- Screen applicable UN proliferation designations and obtain current Burundi implementation and reporting instructions before dealing.
- Evidence to retain
- Legal update, screening records, authority correspondence and escalation decision.
- Primary citation
- Controlled uncertainty; CNRF 2026 mutual-evaluation materials
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.3 items+
CDD, account, correspondence, identity, BO and analysis records are retained for 10 years after the business relationship ends.
- Implementation action
- Map every record class to the relationship-based clock and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, sample and deletion test.
- Primary citation
- Law No. 1/08, art. 47(1); BRB Regulation No. 02/2026, art. 11
Domestic and international transaction data sufficient to reconstruct each operation are retained for 10 years after execution.
- Implementation action
- Use transaction-based clocks and retain amount, currency, actors, accounts and supporting evidence.
- Evidence to retain
- Archive configuration, reconstruction test and retrieval log.
- Primary citation
- Law No. 1/08, art. 47(2)
Required information must be readily accessible to CNRF and other competent authorities.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Evidence to retain
- Request register, retrieval tests, access log and response package.
- Primary citation
- Law No. 1/08, arts. 47 and 74
10Privacy, biometrics, breaches and transfersApply Law No. 1/03 of 10 March 2026 alongside mandatory AML processing.5 items+
Personal-data processing must be lawful, fair, purpose-limited, proportionate, accurate, time-limited and secure.
- Implementation action
- Inventory KYC, BO, screening, monitoring and reporting data and document purpose, legal basis, access, recipients and retention.
- Evidence to retain
- Processing register, basis assessment, notices, access matrix and retention map.
- Primary citation
- Law No. 1/03 of 10 March 2026, arts. 5-8
Biometric identification and other sensitive-data processing are prohibited unless an Article 10 exception applies, with additional safeguards.
- Implementation action
- Before facial, fingerprint, liveness-template or comparable biometric use, document the exact exception, necessity, security and any required impact assessment and authorisation.
- Evidence to retain
- Legal assessment, explicit consent where applicable, DPIA, authorisation, encryption and access tests.
- Primary citation
- Law No. 1/03, arts. 9-10 and 40-41
High-risk processing requires a prior DPIA and submission to the protection body with an authorisation request.
- Implementation action
- Complete the legal and technical risk analysis, obtain DPO review and do not deploy until the prescribed authorisation process is complete.
- Evidence to retain
- DPIA, DPO opinion, application, authority decision and remediation.
- Primary citation
- Law No. 1/03, arts. 40-41
Transfers abroad require an adequate destination or safeguards approved by Burundi's personal-data protection body.
- Implementation action
- Map every hosting, support and vendor destination and obtain the required adequacy or safeguards decision before transfer.
- Evidence to retain
- Transfer map, adequacy analysis, safeguards, approval and access logs.
- Primary citation
- Law No. 1/03, arts. 15-16
A qualifying breach is notified to the protection body within 72 hours; affected individuals are notified within 96 hours where high risk arises.
- Implementation action
- Run a documented breach triage clock, preserve the risk analysis and issue clear notifications with consequences and mitigation.
- Evidence to retain
- Incident log, discovery time, risk assessment, notices, receipts and remediation.
- Primary citation
- Law No. 1/03, arts. 45-46
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 items+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- Law No. 1/08, arts. 47, 51-76
Thresholds, reporting routes, sanctions directions, registers, licences and privacy implementation are time-sensitive.
- Implementation action
- Assign owners to monitor CNRF, BRB, ADB, the personal-data protection body, FATF and ESAAMLG on a documented schedule.
- Evidence to retain
- Legal inventory, source log, change assessment and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 40 implementation checks, with direct regulatory sources.
Download the Burundi KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Burundi implementation checklist. Regulatory review date: 27 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.0, reviewed 27 July 2026
Trusted by leading compliance teams
Primary-source register
14 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 1/08 of 27 March 2025 amending the AML/CFT lawCNRF Burundi · Primary legislation
- CNRF official portalCNRF Burundi · Official FIU portal
- Decree No. 100/009 of 9 February 2026 on the CNRFMinistry of Finance, Burundi · Primary executive instrument
- BRB Regulation No. 02/2026 on AML/CFTBanque de la Republique du Burundi · Primary regulator rule
- BRB announcement of the 2026 AML/CFT frameworkBanque de la Republique du Burundi · Official regulator guidance
- Law No. 1/03 of 10 March 2026 on personal-data protectionARCT Burundi · Primary legislation
- Official publication page for the 2026 personal-data lawARCT Burundi · Official legal publication
- Burundi National Risk Assessment 2026CNRF Burundi · Official national risk assessment
- Official company-creation procedureAgence de Developpement du Burundi · Official registry procedure
- Burundi Commercial Code 2015Agence de Developpement du Burundi · Primary commercial legislation
- Burundi mutual-evaluation statusFATF · Authoritative assessment index
- Burundi draft mutual-evaluation report review - July 2026CNRF Burundi · Official evaluation status
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Direct answers
Burundi KYC, KYB and AML questions
Who receives suspicious transaction reports in Burundi?+
The Cellule Nationale du Renseignement Financier (CNRF) receives STRs using its current prescribed format and route.
When is an STR due?+
Promptly and without delay once the entity suspects or has reasonable grounds to suspect the statutory criminal-proceeds or terrorist-financing connection.
What transaction-reporting threshold applies?+
The AML law delegates cash and other reporting thresholds to CNRF or another competent authority. Obtain the current instrument and do not infer a universal value from the statute.
What beneficial-ownership test applies?+
Identify the natural person who ultimately owns or controls the customer, or on whose behalf a transaction occurs. The reviewed primary law does not provide a universal ownership percentage.
Does Burundi have a national beneficial-owner register?+
The official 2026 national risk assessment reported that a national BO register was not yet in place. Continue independent ownership and control verification and monitor implementation.
How long are AML records kept?+
CDD and relationship records are kept for 10 years after the relationship ends; reconstructable transaction data are kept for 10 years after execution.
Do remote onboarding and biometrics need extra controls?+
Yes. Remote onboarding requires adapted reliable identification. Biometric identification is sensitive processing and requires a supported exception, safeguards, and potentially a DPIA and authorisation.
What privacy breach deadlines apply?+
Notify the personal-data protection body within 72 hours of awareness of a qualifying breach, and notify affected individuals within 96 hours where the breach may create a high risk.
Is Burundi on a FATF public list?+
No. Burundi was not named in FATF's June 2026 increased-monitoring or call-for-action statements. Its ESAAMLG mutual evaluation was still being finalised as at 27 July 2026.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 27 July 2026 · Version 1.0
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 27 July 2026. Confirm current CNRF forms, access and threshold instruments; BRB circulars and licence conditions; sanctions directions; company and beneficial-ownership filing developments; personal-data agency implementation; and all sector overlays with the competent authority and qualified Burundian counsel before launch.