KYC, KYB & AML compliance checklist
Cabo Verde KYC, KYB & AML
An implementation-focused checklist for financial institutions, fintechs, virtual-asset service providers and designated non-financial businesses operating in Cabo Verde under the amended AML/CFT framework, sector rules, company-registration duties and personal-data law.
- Reviewed
- 28 July 2026
- Version
- 1.1
- control areas
- 11
- implementation checks
- 46
Direct answer
What does the Cabo Verde compliance checklist cover?
The Cabo Verde checklist translates primary KYC, KYB and AML rules into 11 control areas and 46 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML law
- Law No. 38/VII/2009, republished by Law No. 120/VIII/2016
- Financial intelligence unit
- Unidade de Informação Financeira (UIF)
- STR timing
- Immediately on knowledge, suspicion or sufficient grounds
- Cash threshold reports
- CVE 1,000,000 for listed cash operations, including linked operations
- General occasional CDD
- CVE 1,000,000, including apparently linked transactions
- Core AML retention
- At least 7 years under transaction- and relationship-specific clocks
- Beneficial ownership
- Identify the natural person who ultimately owns or controls, or on whose behalf activity occurs
- Financial supervisor
- Banco de Cabo Verde (BCV) for BCV-supervised financial entities
- Privacy authority
- Comissão Nacional de Proteção de Dados (CNPD)
- Data-breach notice
- Notify CNPD within 72 hours unless the breach is unlikely to create risk
- FATF public lists
- Not named in the 19 June 2026 public statements
Implementation detail
Cabo Verde compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve the entity, activity, supervisor and reporting perimeter before onboarding or launch.4 items+
The AML law applies to listed financial institutions and designated non-financial businesses and professions headquartered in Cabo Verde, including their branches, subsidiaries and other representations at home or abroad.
- Implementation action
- Map each entity, product, branch, agent, distributor and outsourced function to the statutory list and document the competent supervisor.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Primary citation
- Law No. 120/VIII/2016, arts. 4, 5 and 7
UIF is the national centre for receiving, requesting, analysing and disseminating information arising from suspicious-transaction reports.
- Implementation action
- Appoint an authorised reporting contact and obtain the current UIF form, channel, access and acknowledgement instructions before production reporting.
- Evidence to retain
- Appointment, access record, reporting procedure, test and acknowledgements.
- Primary citation
- Decree-Law No. 9/2012; Law No. 120/VIII/2016, arts. 5-6 and 34
BCV regulates and supervises financial institutions for compliance with the AML law and its sector notices.
- Implementation action
- Classify every financial service and obtain the required BCV authorisation and registration before launch.
- Evidence to retain
- Classification, authorisation, registration, conditions and service map.
- Primary citation
- Law No. 120/VIII/2016, arts. 5-7; Financial System Framework Law and LAIF
Professional virtual-asset activity in Cabo Verde requires prior registration with BCV and remains subject to AML/CFT obligations.
- Implementation action
- Do not provide exchange, transfer, custody, administration or related virtual-asset services until the BCV registration and any other required approval are effective.
- Evidence to retain
- Service analysis, application, BCV registration, conditions and control implementation.
- Primary citation
- Law No. 30/X/2023, arts. 2-3; BCV Notice No. 2/2024
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.4 items+
Reporting entities must identify, assess, understand, document and keep current their customer, geographic, product, transaction and delivery-channel ML risks.
- Implementation action
- Approve a methodology, assess risks before launch and on material change, and make the assessment available to the competent authorities.
- Evidence to retain
- Risk assessment, methodology, source data, change log and approvals.
- Primary citation
- Law No. 120/VIII/2016, art. 10(4)-(6)
Written policies, procedures and controls must be approved by senior management and proportionate to the entity's nature, size and activity.
- Implementation action
- Maintain a control framework covering CDD, BO, PEPs, sanctions, monitoring, reporting, records, training and group controls.
- Evidence to retain
- Policy suite, control library, approvals, testing and remediation.
- Primary citation
- Law No. 120/VIII/2016, arts. 10 and 28
Reporting entities must designate a management-level compliance owner and maintain independent internal control and audit arrangements.
- Implementation action
- Approve the mandate, authority, resources, access, escalation rights and independent assurance plan.
- Evidence to retain
- Appointment, mandate, board reporting, audit plan and reports.
- Primary citation
- Law No. 120/VIII/2016, art. 28
Employees and managers require continuous, role-appropriate AML training, and training records are retained for five years.
- Implementation action
- Deliver induction and periodic training, test understanding and retain attendance, content and results for the statutory period.
- Evidence to retain
- Training plan, materials, attendance, test results and five-year archive.
- Primary citation
- Law No. 120/VIII/2016, art. 29
03Natural-person identification and CDDIdentify and verify customers, representatives and ultimate actors using valid independent evidence.5 items+
Customers and beneficial owners must be identified and verified when opening an account or establishing a business relationship.
- Implementation action
- Capture the statutory natural-person attributes and verify them against a valid official document bearing photograph and signature.
- Evidence to retain
- CDD file, document provenance, verification result, purpose and risk decision.
- Primary citation
- Law No. 120/VIII/2016, arts. 12 and 14
CDD also applies to occasional transactions and domestic or international transfers at or above CVE 1,000,000, including apparently linked transactions.
- Implementation action
- Aggregate linked activity across channels and block completion until identification and verification are complete.
- Evidence to retain
- Aggregation logic, threshold tests, CDD file and release decision.
- Primary citation
- Law No. 120/VIII/2016, arts. 12(2) and 15(2)
Suspicion or doubt about previously obtained identification triggers CDD regardless of amount or exemption.
- Implementation action
- Refresh and independently verify the customer, representative and beneficial owner without applying a monetary floor.
- Evidence to retain
- Trigger record, refreshed evidence, investigation and decision.
- Primary citation
- Law No. 120/VIII/2016, arts. 12(2)(d)-(e) and 15(2)
Anonymous, numbered, coded, fictitious-name and otherwise unidentified relationships are prohibited.
- Implementation action
- Block activation and transaction capability until the required actors are identified and verified.
- Evidence to retain
- Account controls, test results and rejected-case log.
- Primary citation
- Law No. 120/VIII/2016, art. 12(3)
Representatives must be identified and their authority to act verified.
- Implementation action
- Verify the representative's identity, mandate, scope, validity and relationship to the customer before accepting instructions.
- Evidence to retain
- Identity file, mandate, authority check and expiry monitoring.
- Primary citation
- Law No. 120/VIII/2016, arts. 12(7), 14 and 15
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 items+
Legal-person identification includes name, nature and legal form, registered office, managers or directors and persons empowered to bind the entity.
- Implementation action
- Obtain a current commercial-registry certificate, constitutive documents, tax identifier, governing body and authority evidence; reconcile inconsistencies.
- Evidence to retain
- Registry certificate, statutes, NIF, officer list, mandates and discrepancy log.
- Primary citation
- Law No. 120/VIII/2016, art. 14(3)-(4); Commercial Registration Code
Reporting entities must understand the customer's ownership and control structure and determine the natural person who ultimately owns or controls it.
- Implementation action
- Trace every ownership and control layer to natural persons and document the statutory conclusion without substituting an unsupported universal percentage.
- Evidence to retain
- Ownership chart, control analysis, source records and verified BO files.
- Primary citation
- Law No. 120/VIII/2016, arts. 2, 12 and 15
Where the customer may be acting for another person, the entity must identify the person or entity on whose behalf the customer acts, including beneficial owners.
- Implementation action
- Investigate nominee, agency and third-party funding indicators and verify the ultimate actor before proceeding.
- Evidence to retain
- Agency analysis, declarations, source evidence and escalation record.
- Primary citation
- Law No. 120/VIII/2016, art. 12(6)
Commercial-register information must be kept updated, but the reviewed authoritative material does not establish a comprehensive public national BO register with a universal filing percentage.
- Implementation action
- Verify basic registry information and independently establish ownership and control; confirm current BO filing rules with DGRNI and counsel.
- Evidence to retain
- Registry extracts, customer ownership evidence, independent corroboration and update log.
- Primary citation
- Commercial Registration Code, art. 13; GIABA 2019 MER, Recommendation 24; controlled uncertainty
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.5 items+
The PEP framework covers domestic and foreign PEPs, relevant international-organisation functions, family members and recognised close associates.
- Implementation action
- Screen customers, beneficial owners, controllers and representatives at onboarding, list updates and periodic review.
- Evidence to retain
- Screening, match rationale, relationship mapping and review record.
- Primary citation
- Law No. 120/VIII/2016, art. 2 definitions and art. 24
PEP relationships require risk-based identification, senior-management approval, source-of-wealth and source-of-funds measures and enhanced continuous monitoring.
- Implementation action
- Obtain supported source evidence and senior approval before establishing or continuing the relationship.
- Evidence to retain
- Source file, approval, monitoring plan and alert reviews.
- Primary citation
- Law No. 120/VIII/2016, art. 24
Former PEP controls continue while the person's profile or activity presents increased ML risk; the law does not set a fixed exit period.
- Implementation action
- Document a risk-based decision before reducing controls and continue enhanced treatment while residual risk remains.
- Evidence to retain
- Former-PEP assessment, approval and periodic review.
- Primary citation
- Law No. 120/VIII/2016, art. 24(2)
Remote and anonymity-favouring activity requires enhanced measures and may be supplemented with additional documents or information.
- Implementation action
- Authenticate evidence, apply independent checks and escalate higher-risk remote cases without assuming one technology is legally sufficient.
- Evidence to retain
- Remote-onboarding standard, vendor review, tests and exceptions.
- Primary citation
- Law No. 120/VIII/2016, arts. 10(5) and 22(3)-(4)
Reliance on a third party does not transfer the reporting entity's responsibility.
- Implementation action
- Confirm equivalent obligations and supervision, obtain identity material immediately on request, contract for access and test retrieval.
- Evidence to retain
- Third-party due diligence, agreement, retrieval test and exceptions.
- Primary citation
- Law No. 120/VIII/2016, art. 20
06Failed CDD, monitoring and suspicious reportingStop unsafe activity, monitor continuously and report suspicion immediately and confidentially.5 items+
If required ownership, control, purpose, identity or source/destination information cannot be obtained, the relationship or operation must be refused or ended and an STR considered.
- Implementation action
- Operate a controlled block or exit and preserve the confidential STR decision.
- Evidence to retain
- Failure reason, block, closure, analysis, STR and acknowledgement.
- Primary citation
- Law No. 120/VIII/2016, arts. 15(3), 21 and 22(7)
Unusual, complex, high-volume, atypical or apparently purposeless activity requires careful examination and a written record.
- Implementation action
- Investigate the nature, purpose, frequency, actors, amount, source, destination and payment method and retain the analysis.
- Evidence to retain
- Alerts, cases, supporting evidence, written examination and approval.
- Primary citation
- Law No. 120/VIII/2016, arts. 22 and 26
An STR is sent to UIF immediately when the entity knows, suspects or has sufficient grounds to suspect completed, ongoing or attempted laundering activity.
- Implementation action
- Timestamp the trigger and submit through the current UIF route without waiting for proof or a completed transaction.
- Evidence to retain
- Internal report, analysis, STR, UIF receipt and timeline.
- Primary citation
- Law No. 120/VIII/2016, art. 34(1)
The entity must abstain from executing suspected activity and notify UIF, subject to the statutory exception where suspension is impossible or could prejudice prevention or investigation.
- Implementation action
- Govern holds, urgent consultation, lawful post-execution reporting and restricted communications.
- Evidence to retain
- Hold decision, exception rationale, UIF contact, receipt and access log.
- Primary citation
- Law No. 120/VIII/2016, art. 32
The existence of an STR, UIF request or investigation must not be disclosed to the customer or an unauthorised third party.
- Implementation action
- Restrict access, use neutral customer communications and log every disclosure and escalation.
- Evidence to retain
- Tipping-off policy, access controls, communications and testing.
- Primary citation
- Law No. 120/VIII/2016, art. 33
07Wires, thresholds, payments and agentsKeep CDD triggers, cash reports, wire information and product licensing distinct.5 items+
Listed cash operations at or above CVE 1,000,000 must be reported to UIF regardless of suspicion, including apparently linked operations and subject to the statutory activity-based exception.
- Implementation action
- Configure aggregation by customer and connected activity, apply the exact covered categories and retain report receipts and exception rationale.
- Evidence to retain
- Configuration, tests, reports, receipts and exception record.
- Primary citation
- Law No. 120/VIII/2016, art. 34(2)-(4)
Cross-border physical carriage of currency, bearer instruments or electronic money at or above CVE 1,000,000 requires a written customs declaration.
- Implementation action
- Do not treat the border declaration as an ordinary customer-reporting threshold; give travellers current customs instructions where relevant.
- Evidence to retain
- Procedure, declaration guidance and escalation record.
- Primary citation
- Law No. 120/VIII/2016, art. 11
Domestic wire transfers require specified originator and beneficiary names, account or unique reference data and alternative originator identity information.
- Implementation action
- Validate mandatory fields before release and preserve the complete payment-chain record.
- Evidence to retain
- Field matrix, validation, repair queue, samples and decisions.
- Primary citation
- Law No. 120/VIII/2016, art. 27(1)-(2)
Cross-border transfers at or above CVE 1,000,000 must carry the required originator information throughout the payment chain; deficient transfers require risk-based execute, reject or suspend decisions.
- Implementation action
- Implement field validation, repair, reject, suspend, beneficiary verification and follow-up rules.
- Evidence to retain
- Payment messages, repair requests, decisions, monitoring and tests.
- Primary citation
- Law No. 120/VIII/2016, art. 27(3)-(11)
Money or value transfer providers must maintain an up-to-date agent list and include agents within their AML programme and monitoring.
- Implementation action
- Maintain the regulator-ready agent register, due diligence, training, control testing and termination process.
- Evidence to retain
- Agent register, contracts, training, monitoring and remediation.
- Primary citation
- Law No. 120/VIII/2016, art. 18
08Targeted financial sanctions and proliferation riskScreen, freeze, restrict and report under the current UN and domestic implementation framework.3 items+
Relevant UN Security Council resolutions take effect in Cabo Verde's legal order, and terrorist-fund freezes require immediate implementation.
- Implementation action
- Maintain current UN lists, screen customers and transactions, prevent dealing and escalate true matches immediately.
- Evidence to retain
- List inventory, update logs, screening, match decision and freeze record.
- Primary citation
- Constitution of Cabo Verde, art. 12(3); Law No. 119/VIII/2016; BCV/AGMVM AML/CFT portal
Terrorist-financing and proliferation-financing targeted-sanctions implementation has documented technical-compliance gaps in GIABA assessments.
- Implementation action
- Obtain current BCV, UIF, prosecutor or other competent-authority instructions for the specific designation and do not invent a notification deadline or release route.
- Evidence to retain
- Legal update, authority correspondence, notification, direction and release decision.
- Primary citation
- GIABA 2019 MER and 2021 FUR, Recommendations 6-7; controlled procedure uncertainty
Virtual-asset service providers are subject to the communications, reporting and monitoring framework applicable to terrorist- and proliferation-related targeted sanctions.
- Implementation action
- Integrate UN-list screening, asset controls and authority escalation into the registered VASP control framework.
- Evidence to retain
- VASP policy, screening configuration, tests, escalation and reports.
- Primary citation
- Law No. 30/X/2023, art. 3; GIABA sixth enhanced FUR 2025, Recommendation 15
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.4 items+
Identity, beneficial-owner and transaction records and required written reports are retained for at least seven years after the transaction or end of the relationship, as applicable.
- Implementation action
- Map every record class to its transaction- or relationship-based clock and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, samples and deletion tests.
- Primary citation
- Law No. 120/VIII/2016, art. 25(1)
Financial institutions retain account-opening forms and related correspondence for at least seven years after account closure or the end of the relationship.
- Implementation action
- Link account records to the relationship closure event and test complete retrieval.
- Evidence to retain
- Archive configuration, closure trigger, sample and retrieval log.
- Primary citation
- Law No. 120/VIII/2016, art. 25(2)
Required records must be supplied to UIF and competent authorities on request.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Evidence to retain
- Request register, retrieval tests, access logs and response package.
- Primary citation
- Law No. 120/VIII/2016, arts. 25(3) and 31
Wire originator and beneficiary information is retained under the general seven-year rule.
- Implementation action
- Preserve complete payment messages, repairs, screening and disposition evidence for reconstructability.
- Evidence to retain
- Wire archive, reconstruction test and exception records.
- Primary citation
- Law No. 120/VIII/2016, arts. 25 and 27(11)
10Privacy, biometrics, breaches and transfersApply the amended personal-data framework alongside mandatory AML processing.5 items+
Personal-data processing must respect privacy and data-protection rights and have a lawful basis, specified purpose, proportionate scope, accuracy, security and retention controls.
- Implementation action
- Inventory KYC, BO, screening, monitoring and reporting data and document purpose, basis, recipients, access and retention.
- Evidence to retain
- Processing register, basis assessment, notices, access matrix and retention map.
- Primary citation
- Law No. 133/V/2001 as amended by Law No. 121/IX/2021, arts. 4, 6 and 7
Biometric data are special-category data and processing is prohibited unless a statutory exception or CNPD authorisation applies.
- Implementation action
- Before facial, fingerprint, liveness-template or comparable biometric use, document the exact exception, necessity, safeguards and notification or authorisation requirements.
- Evidence to retain
- Legal assessment, consent where applicable, CNPD filing, encryption and access tests.
- Primary citation
- Amended personal-data law, arts. 5 and 8
High-risk processing requires a DPIA before processing and before notification to CNPD, including large-scale special-data processing and qualifying automated profiling.
- Implementation action
- Complete the DPIA, obtain DPO advice where appointed, communicate the result with the required CNPD notification and track remediation.
- Evidence to retain
- DPIA, DPO opinion, CNPD submission and remediation.
- Primary citation
- Amended personal-data law, art. 29
A personal-data breach must be notified to CNPD within 72 hours after awareness unless it is unlikely to create risk; a high-risk breach is communicated to affected people without unjustified delay.
- Implementation action
- Run a documented breach-triage clock, preserve the risk analysis and issue required notices with consequences and mitigation.
- Evidence to retain
- Incident log, awareness time, risk assessment, notices, receipts and remediation.
- Primary citation
- Amended personal-data law, arts. 27-28
Foreign transfers require an adequate protection level determined by CNPD or a statutory derogation or CNPD-authorised safeguards.
- Implementation action
- Map hosting, support and vendor destinations and document the adequacy, derogation or authorised contractual safeguards before transfer.
- Evidence to retain
- Transfer map, adequacy decision, derogation analysis, safeguards and CNPD authorisation.
- Primary citation
- Amended personal-data law, arts. 35-36
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 items+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- Law No. 120/VIII/2016, arts. 8-34
Thresholds, UIF routes, sanctions directions, registers, licences and privacy procedures are time-sensitive.
- Implementation action
- Assign owners to monitor UIF, BCV, DGRNI, CNPD, the Official Gazette, FATF and GIABA on a documented schedule.
- Evidence to retain
- Legal inventory, source log, change assessment and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 46 implementation checks, with direct regulatory sources.
Download the Cape Verde KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Cape Verde implementation checklist. Regulatory review date: 28 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.1, reviewed 28 July 2026
Trusted by leading compliance teams
Primary-source register
15 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 120/VIII/2016 republishing the amended AML lawBanco de Cabo Verde · Primary legislation
- BCV anti-money-laundering framework and supervisory roleBanco de Cabo Verde · Official regulator guidance
- UIF official role and mandateMinistry of Justice, Cabo Verde · Official FIU guidance
- BCV Notice No. 5/2017 AML/CFT preventive controlsBanco de Cabo Verde · Primary regulator rule
- Law No. 119/VIII/2016 on terrorism and terrorist financingOfficial Gazette of Cabo Verde · Primary legislation
- UN sanctions and AML/CFT resourcesBanco de Cabo Verde / AGMVM · Official regulator guidance
- Law No. 30/X/2023 on virtual assets and digital banksBanco de Cabo Verde · Primary legislation
- BCV announcement of Notice No. 2/2024 for VASP registrationBanco de Cabo Verde · Official regulator guidance
- Company and registry services portalMinistry of Justice, Cabo Verde · Official registry portal
- Law No. 121/IX/2021 amending the personal-data regimeComissão Nacional de Proteção de Dados · Primary legislation
- CNPD legislation indexComissão Nacional de Proteção de Dados · Official authority index
- Cabo Verde sixth enhanced follow-up report - May 2025FATF / GIABA · Authoritative follow-up assessment
- Cabo Verde mutual evaluation report - 2019FATF / GIABA · Authoritative mutual evaluation
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Direct answers
Cabo Verde KYC, KYB and AML questions
Who receives suspicious transaction reports in Cabo Verde?+
The Unidade de Informação Financeira (UIF) receives reports through its current prescribed channel.
When is an STR due?+
Immediately when the reporting entity knows, suspects or has sufficient grounds to suspect that completed, ongoing or attempted activity may constitute money laundering.
What cash-reporting threshold applies?+
Listed cash operations at or above CVE 1,000,000, including apparently linked operations, are reported to UIF regardless of suspicion, subject to the exact statutory categories and exception.
When does general occasional-transaction CDD apply?+
At or above CVE 1,000,000 for one or apparently linked occasional transactions, and regardless of amount when suspicion or identification doubt exists.
What beneficial-ownership test applies?+
Identify the natural person who ultimately owns or controls the customer, or on whose behalf a transaction occurs. The reviewed primary AML law does not set a universal ownership percentage.
How long are AML records kept?+
Core identity, beneficial-owner, transaction and written-analysis records are kept for at least seven years under the applicable transaction or relationship clock.
Must virtual-asset service providers register?+
Yes. Professional virtual-asset activity in Cabo Verde requires prior BCV registration under Law No. 30/X/2023 and Notice No. 2/2024 and remains subject to AML/CFT duties.
What privacy breach deadline applies?+
Notify CNPD within 72 hours after awareness unless the breach is unlikely to create risk; communicate a high-risk breach to affected people without unjustified delay.
Is Cabo Verde on a FATF public list?+
No. Cabo Verde was not named in FATF's 19 June 2026 increased-monitoring or call-for-action statements, though GIABA kept it in enhanced follow-up in May 2025.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 28 July 2026 · Version 1.1
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 28 July 2026. Confirm the live UIF filing route and forms, BCV and sector instructions, targeted-financial-sanctions workflow, company and beneficial-ownership filing requirements, data-protection notifications, product licences and all later legal changes with the competent authority and qualified Cabo Verdean counsel before launch.