Costa Rica KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Costa Rica.

Direct answer
What does the Costa Rica compliance checklist cover?
The Costa Rica checklist translates primary KYC, KYB and AML rules into 11 control areas and 33 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Inteligencia Financiera (UIF) within the Instituto Costarricense sobre Drogas
- Core AML framework
- Law 7786, reformed by Laws 8204, 8719, 9387 and 9449, plus sector regulations
- Financial-sector rule
- CONASSIF 12-21 for Article 14 entities
- Articles 15 and 15-bis rule
- SUGEF 13-19 registration and risk-based controls for covered activities
- Suspicious reports
- Directly, immediately and confidentially to UIF, including attempts and regardless of amount
- US$10,000 controls
- Special identification and reporting/data duties apply to defined cash operations and international electronic transfers; this is not a ROS threshold
- AML record retention
- At least 5 years from the applicable transaction or relationship trigger
- RTBF beneficial ownership
- 15% or more participation under the current decree, plus control by other means and senior-manager fallback
- Sanctions timing
- Freeze without delay and communicate a positive match to UIF within no more than 24 hours
- Privacy authority
- Agencia de Proteccion de Datos de los Habitantes (PRODHAB)
- FATF status
- GAFILAT member; not named on the FATF public lists reviewed 1 August 2026
Implementation detail
Costa Rica compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingClassify the entity under Article 14, Article 15, Article 15-bis or outside those categories before choosing the rulebook.3 items+
Article 14 financial institutions are supervised under CONASSIF 12-21 by the competent financial superintendency.
- Implementation action
- Map the legal entity and each product to SUGEF, SUGEVAL, SUPEN or SUGESE and capture market-specific lineamientos as well as the common rule.
- Evidence to retain
- Perimeter memo, authorization, supervisor register, rule inventory and launch approval.
- Primary citation
- Law 7786 art. 14; CONASSIF 12-21 arts. 1-4
Covered activities under Articles 15 and 15-bis must register with SUGEF and comply with SUGEF 13-19.
- Implementation action
- Test money transfer, third-party fund management, exchange, credit and listed non-financial activities; obtain registration before using products or accounts for the registered activity.
- Evidence to retain
- Activity analysis, application, SUGEF registration, registered accounts, conditions and renewals.
- Primary citation
- Law 7786 arts. 15, 15-bis and 15-ter; SUGEF 13-19
Only legally authorized entities may conduct financial intermediation.
- Implementation action
- Assess whether the model habitually takes public funds for lending or investment at its own risk; obtain SUGEF authorization where required and do not rely on AML registration alone.
- Evidence to retain
- Funds-flow diagram, Law 7558 analysis, SUGEF correspondence and authorization.
- Primary citation
- Organic Law of the BCCR, Law 7558 arts. 116 and 119
02Governance and risk assessmentThe control framework must be approved, risk-based and appropriate to the applicable supervisory category.3 items+
Obliged entities must identify and assess customer, product, channel and geographic LC/FT/FPADM risks.
- Implementation action
- Approve an enterprise assessment and translate it into risk appetite, customer scoring, due-diligence levels, scenarios and review frequency.
- Evidence to retain
- Methodology, data, national-risk inputs, approval, validation and change log.
- Primary citation
- CONASSIF 12-21 arts. 5-13; SUGEF 13-19
The compliance function must have suitable authority, independence, resources and reporting access.
- Implementation action
- Appoint the required officer or liaison for the entity category, document deputies and conflicts, and provide direct escalation to the governing body.
- Evidence to retain
- Appointment, fit-and-proper evidence, role profile, minutes, budget, training and escalation log.
- Primary citation
- Law 7786 arts. 14-15-bis; CONASSIF 12-21 arts. 14-22; SUGEF 13-19
Controls must be tested and deficiencies remediated under the applicable audit and review rules.
- Implementation action
- Schedule independent, internal or external review as required, assign accountable owners and validate closure with evidence.
- Evidence to retain
- Audit plan, reports, management responses, remediation tracker and closure tests.
- Primary citation
- CONASSIF 12-21 arts. 23-27; SUGEF 13-19
03Natural-person KYC and representativesCDD must establish identity, authority, purpose, source and expected behaviour using reliable evidence.3 items+
Customers must be identified and verified, especially at relationship opening and for cash transactions above US$10,000.
- Implementation action
- Capture official identity, domicile, occupation, purpose, expected activity and source of funds; authenticate evidence and resolve inconsistencies before activation.
- Evidence to retain
- Identity record, verification result, profile, source evidence, reviewer and exceptions.
- Primary citation
- Law 7786 art. 16; CONASSIF 12-21 arts. 28-36
Representatives and signatories must be identified and their authority validated.
- Implementation action
- Verify the natural person, obtain the current mandate or power, confirm its scope and link it to the represented customer and beneficial owners.
- Evidence to retain
- Representative KYC, power, National Registry check, scope analysis and expiry control.
- Primary citation
- Law 7786 art. 16(c); CONASSIF 12-21 arts. 28-36
CDD must continue throughout the relationship and activity must remain consistent with the known customer and risk profile.
- Implementation action
- Set risk-based refresh and event triggers, update source and beneficial-owner information and investigate material deviations.
- Evidence to retain
- Review schedule, event alerts, updated file, discrepancy resolution and approval.
- Primary citation
- CONASSIF 12-21 arts. 28-38; SUGEF 13-19
04KYB, RTBF and beneficial ownershipAML beneficial-owner CDD and the entity's own RTBF filing are related but distinct obligations.3 items+
CDD must identify the natural persons who ultimately own or control the customer or receive the benefit.
- Implementation action
- Verify legal existence, purpose and authority; trace direct and indirect ownership, voting and control by other means to natural persons.
- Evidence to retain
- Registry certificate, constitutional documents, ownership chart, voting analysis, declarations and corroboration.
- Primary citation
- CONASSIF 12-21 arts. 3 and 29; Law 7786 art. 16
RTBF identifies 15% or greater direct or indirect participation and also requires control-by-other-means and senior-manager fallback analysis.
- Implementation action
- Do not treat 15% as the sole test; calculate holdings and voting rights, assess appointment and other control and document the exceptional fallback.
- Evidence to retain
- Cap table, indirect calculation, control memo, fallback rationale and reviewer sign-off.
- Primary citation
- Law 9416 art. 5; Executive Decree 44390-H arts. 8-10
Covered legal persons and structures must file accurate RTBF declarations annually and on applicable changes under the current schedule.
- Implementation action
- Use Central Directo, track the current joint-resolution filing period, submit event-driven updates and reconcile declarations with corporate and AML records.
- Evidence to retain
- RTBF declaration, BCCR receipt, source documents, change log and reconciliation.
- Primary citation
- Law 9416 arts. 5-7; Executive Decree 44390-H; Joint Resolution MH-DGT-ICD-RES-0020-2024
05PEPs, EDD and remote onboardingPEPs and higher-risk customers require management attention, source analysis and intensified monitoring.3 items+
Systems must determine whether a customer or beneficial owner is a PEP and cover relevant family members and close associates.
- Implementation action
- Screen at onboarding and continuously, research the public function and relationship, and document the classification and review period.
- Evidence to retain
- Screening, role research, relationship map, disposition and review date.
- Primary citation
- CONASSIF 12-21 arts. 3 and 39-41; General Regulation to Law 7786
PEP and other high-risk relationships require enhanced measures.
- Implementation action
- Obtain senior approval, establish source of wealth and funds, set intensified monitoring and refresh and document why the relationship is accepted or continued.
- Evidence to retain
- Approval, wealth and funds evidence, monitoring plan, reviews and exceptions.
- Primary citation
- CONASSIF 12-21 arts. 39-43; SUGEF 13-19
Remote onboarding must meet the same identification and accountable risk outcomes as other channels.
- Implementation action
- Use permitted reliable sources, bind identity to the session, test impersonation and presentation attacks and govern vendors and fallback.
- Evidence to retain
- Method approval, vendor due diligence, device and liveness evidence where used, tests and exceptions.
- Primary citation
- CONASSIF 12-21 arts. 32-36 and applicable superintendency lineamientos
06Monitoring, ROS and confidentialitySuspicion and attempts must be reported immediately, confidentially and independently of threshold-data reports.3 items+
Reasonable suspicion must be reported directly, immediately and confidentially to UIF, including attempted operations and regardless of amount.
- Implementation action
- Escalate promptly, record the knowledge time and grounds, submit through the secure current channel and preserve the receipt and supplements.
- Evidence to retain
- Alert, analysis, decision timeline, ROS, UIF receipt, supplement and access log.
- Primary citation
- Law 7786 art. 25; Executive Decree 40018 arts. 1-4
Unusual activity must be analysed against the customer's known profile before a documented ROS decision.
- Implementation action
- Deploy risk-based scenarios, collect available facts without delaying an immediate report, document the conclusion and keep monitoring after filing.
- Evidence to retain
- Scenario inventory, alerts, case file, rationale, tuning and quality assurance.
- Primary citation
- CONASSIF 12-21 arts. 46-52; SUGEF 13-19
Customers and unauthorised persons must not be informed of a ROS or related analysis.
- Implementation action
- Restrict case access, separate servicing communications from reporting decisions and train staff on confidentiality and lawful supervisor access.
- Evidence to retain
- Access roles, confidentiality acknowledgements, training, communications and incident log.
- Primary citation
- Law 7786 art. 25; Executive Decree 40018
07Threshold data, wires, payments and agentsUS$10,000 transaction data, payment-system participation and suspicious reporting are separate controls.3 items+
Defined cash operations and electronic transfers from or to another country at US$10,000 or more require the applicable record and information reporting treatment.
- Implementation action
- Implement exact category and aggregation logic, submit through the applicable supervisor format and keep the process separate from ROS assessment.
- Evidence to retain
- Rules, transaction extract, report file, receipt, exception and reconciliation.
- Primary citation
- Law 7786 arts. 20-24; CONASSIF 12-21 arts. 53-55
SINPE participation and payment services must comply with the BCCR Payment System Regulation and technical admission requirements.
- Implementation action
- Classify the participant type, obtain affiliation or authorization, meet security and operating requirements and reconcile settlement and customer records.
- Evidence to retain
- BCCR approval, participant agreement, technical certification, settlement controls and incidents.
- Primary citation
- BCCR Payment System Regulation, edition 24, effective 12 December 2025
Agents, correspondents and vendors operate under the accountable entity's responsibility.
- Implementation action
- Contract for CDD, monitoring, evidence access, audit, incident notice and exit; test samples and prohibit use outside authorized activities.
- Evidence to retain
- Due diligence, contract, training, monitoring, sample tests, incidents and exit plan.
- Primary citation
- CONASSIF 12-21; BCCR Payment System Regulation; applicable correspondent rules
08Targeted financial sanctionsCosta Rica requires direct list monitoring, freezing without delay and rapid UIF communication.3 items+
All relevant persons must monitor applicable UN lists and freeze or immobilize funds or assets without delay on a positive match.
- Implementation action
- Screen customers, beneficial owners, representatives, counterparties and assets on list updates and before relevant activity; freeze without prior notice.
- Evidence to retain
- List source, screening timestamp, match packet, freeze record and access controls.
- Primary citation
- Law 7786 art. 33-bis; Executive Decree 40018 arts. 6-7
A positive match and the freeze must be communicated to UIF within no more than 24 hours.
- Implementation action
- Use the secure UIF platform, preserve the exact detection and freeze time and follow judicial or authority instructions for continuation or release.
- Evidence to retain
- UIF communication, timestamp, receipt, authority correspondence and release approval.
- Primary citation
- Executive Decree 40018 arts. 6-7
Sanctions controls must include owned, controlled and acting-on-behalf relationships, not only exact customer-name matches.
- Implementation action
- Map ownership and control, use multiple identifiers, investigate potential matches and document false-positive decisions.
- Evidence to retain
- Ownership analysis, identifiers, screening result, escalation and reviewer approval.
- Primary citation
- Law 7786 art. 33-bis; Executive Decree 40018
09Records and regulator accessRecords must remain complete, secure and rapidly retrievable for the legally defined period.3 items+
Identity, account, correspondence and transaction records must be retained for at least five years from the applicable trigger.
- Implementation action
- Define triggers by record class, suspend deletion for investigations and authority requests and document any longer sector period.
- Evidence to retain
- Retention schedule, system rules, legal holds, deletion log and tested retrieval.
- Primary citation
- Law 7786 arts. 16(d)-(e) and 22
Records must permit reconstruction of transactions and the basis for CDD, risk and reporting decisions.
- Implementation action
- Preserve source documents, versions, approvals, screening, alerts, communications and reports in an auditable sequence.
- Evidence to retain
- Complete sample file, immutable audit trail, version history and reconstruction test.
- Primary citation
- Law 7786 arts. 16-22; CONASSIF 12-21
Information must be available to UIF and competent supervisors through lawful and secure channels.
- Implementation action
- Maintain current credentials, verify authority, index each production and preserve secure delivery and legal-hold evidence.
- Evidence to retain
- Request, authority check, production index, delivery receipt and hold.
- Primary citation
- Law 7786 arts. 17-19 and 123; applicable supervisor rules
10Privacy, biometrics and transfersAML duties coexist with informed processing, security, confidentiality and transfer controls under Law 8968.3 items+
Personal-data collection generally requires clear prior information and informed, express consent unless a legal exception applies.
- Implementation action
- Map each KYC field to purpose and legal basis, provide the article 5 information, minimise optional data and keep ROS processing confidential.
- Evidence to retain
- Data inventory, legal-basis record, notice, consent where used and rights log.
- Primary citation
- Law 8968 arts. 4-7; Executive Decree 37554-JP
Sensitive and biometric information requires strict necessity, lawful grounds and proportionate security.
- Implementation action
- Document necessity, limit collection, test accuracy and bias, encrypt templates, restrict access and implement a lawful fallback.
- Evidence to retain
- Necessity assessment, consent or exception, security design, testing, access and deletion logs.
- Primary citation
- Law 8968 arts. 9-11; Executive Decree 37554-JP arts. 35-37
Transfers to processors or third parties require valid authorization or another lawful basis and must preserve confidentiality and security.
- Implementation action
- Map locations and subprocessors, contract for purpose limits, security, incident handling, deletion and regulator access, and assess each transfer.
- Evidence to retain
- Data-flow map, transfer assessment, contracts, subprocessor register and incident plan.
- Primary citation
- Law 8968 arts. 11 and 14; Executive Decree 37554-JP
11Fintech, virtual assets and practical evidence packsFintech and virtual-asset models must be classified by function rather than marketing label.3 items+
Payment, stored-value, remittance and customer-fund models may trigger BCCR, SUGEF and Law 7786 requirements.
- Implementation action
- Analyse custody, settlement, redemption, cross-border transfer, public-fund taking and third-party fund control; obtain each required approval before launch.
- Evidence to retain
- Product and funds flows, legal opinions, regulator correspondence, approvals and conditions.
- Primary citation
- Law 7558 arts. 116 and 119; Law 7786 arts. 14-15-bis; BCCR Payment System Regulation
No blanket conclusion should be drawn from using virtual assets; the exact activity and legal perimeter control.
- Implementation action
- Test exchange, transfer, custody, administration, investment and payment functions against Articles 14-15-bis, securities, payments, consumer, tax and sanctions rules and record any regulatory uncertainty.
- Evidence to retain
- Dated perimeter memo, authority checks, risk assessment, customer restrictions and monitoring plan.
- Primary citation
- Law 7786; SUGEF 13-19; current BCCR and superintendency rules reviewed 1 August 2026
Every implemented control should have a compact and reviewable evidence pack.
- Implementation action
- Assign an owner, applicability decision, procedure, system control, test, exception route and remediation date to every checklist row.
- Evidence to retain
- Control matrix, RACI, evidence links, test results, gaps, remediation and approval.
- Primary citation
- Recommended implementation control supporting Law 7786 and sector-rule compliance
Primary-source register
16 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law 7786 - current legal textSistema Costarricense de Informacion Juridica · Primary legislation
- CONASSIF 12-21 - Article 14 AML/CFT/CPF regulationSuperintendencia General de Entidades Financieras · Primary sector regulation
- SUGEF 13-19 - Articles 15 and 15-bis regulationSuperintendencia General de Entidades Financieras · Primary sector regulation
- Current SUGEF transversal regulations registerSuperintendencia General de Entidades Financieras · Official regulation register
- Executive Decree 40018 - ROS and targeted financial sanctionsSistema Costarricense de Informacion Juridica · Primary regulation
- Law 9416 - Tax Fraud Law and RTBFSistema Costarricense de Informacion Juridica · Primary legislation
- Executive Decree 44390-H - RTBF regulationSistema Costarricense de Informacion Juridica · Primary regulation
- Joint Resolution MH-DGT-ICD-RES-0020-2024 - RTBF filing rulesSistema Costarricense de Informacion Juridica · Primary administrative resolution
- RTBF 2025 official guideMinisterio de Hacienda · Official filing guidance
- Law 8968 - personal-data protectionSistema Costarricense de Informacion Juridica · Primary legislation
- Costa Rica data-protection legislation registerAgencia de Proteccion de Datos de los Habitantes · Official legislation register
- BCCR Payment System Regulation - edition 24Banco Central de Costa Rica · Primary payment regulation
- SUGEF warning and authorization guidance for unauthorised financial activitySuperintendencia General de Entidades Financieras · Official licensing guidance
- FATF Costa Rica country pageFinancial Action Task Force · Official country and follow-up source
- FATF black and grey listsFinancial Action Task Force · Official current-status source
- FATF Latin America regional body pageFinancial Action Task Force · Official GAFILAT membership source
Direct answers
Costa Rica KYC, KYB and AML questions
Who receives suspicious-operation reports in Costa Rica?+
The UIF of the Instituto Costarricense sobre Drogas. Reports must be sent directly, immediately and confidentially through the current secure channel.
Are attempted suspicious operations reportable?+
Yes. Executive Decree 40018 expressly covers attempts, regardless of amount.
Is US$10,000 the Costa Rica ROS threshold?+
No. Suspicion has no monetary threshold. US$10,000 is relevant to defined cash and international-transfer identification and information-reporting controls.
What is the Costa Rica beneficial-owner threshold?+
The current RTBF regulation uses 15% or more participation, but control by other means and an exceptional senior-manager fallback must also be assessed.
How long must AML records be kept?+
At least five years from the applicable end-of-transaction or relationship trigger, subject to legal holds and any longer sector rule.
What is the sanctions reporting deadline?+
Freeze or immobilize without delay and communicate a positive match to UIF within no more than 24 hours under Executive Decree 40018.
Does SUGEF AML registration authorize financial intermediation?+
No. Article 15 or 15-bis registration is distinct from prudential authorization. Public-fund-taking and other regulated financial activities require separate analysis and approval.
How are fintech and virtual-asset businesses treated?+
Classification follows the activity, not the label. Test custody, exchange, transfer, payments, remittance, customer-fund management and investment functions against Law 7786, BCCR, SUGEF, securities and other rules.
Is Costa Rica on a FATF public list?+
Costa Rica was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026, but remains subject to GAFILAT follow-up and risk-based controls still apply.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, a licence decision or a substitute for the operative Spanish text, SUGEF/UIF instructions or regulator confirmation. Reviewed 1 August 2026. Confirm entity, activity, customer, transaction, reporting format, RTBF filing period, sanctions route, privacy role and later developments with qualified Costa Rican counsel and the competent authority before launch.