Cuba KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Cuba.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Cuba compliance checklist cover?
The Cuba checklist translates primary KYC, KYB and AML rules into 11 control areas and 34 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Dirección General de Investigación de Operaciones Financieras (DGIOF), within the Banco Central de Cuba
- Core preventive law
- Decree-Law 317 of 2013 and BCC Resolution 51 of 2013, supplemented by sector rules
- Suspicious reporting
- Report promptly to DGIOF when suspicion or reasonable grounds arise, regardless of amount
- CDD
- Identify every customer and verify identity data and documents; identify the beneficial owner
- Records
- Maintain identification and transaction records under the applicable BCC or sector rule; confirm the live sector retention period
- Company records
- The Central Commercial Registry and other competent registries evidence legal existence; access and beneficial-ownership availability require live confirmation
- Privacy
- Law 149 of 2022 on Personal Data Protection, effective 180 days after its 25 August 2022 publication
- Virtual assets
- BCC licensing and DGIOF AML supervision apply under Resolution 215/2021 and subsequent AML rules
- FATF status
- GAFILAT member; not identified on FATF's June 2026 high-risk or increased-monitoring statements; status reviewed 5 August 2026
Implementation detail
Cuba compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingResolve the entity, activity and competent authority before applying a sector rule.3 items+
Entities and activities designated by Decree-Law 317 must apply preventive controls and report to DGIOF.
- Implementation action
- Map each product and legal entity to Article 4 and the current sector instruction; obtain written perimeter confirmation for ambiguity.
- Evidence to retain
- Perimeter memo, legal texts, regulator correspondence, licence inventory and launch approval.
- Primary citation
- Decree-Law 317/2013 arts. 4-5
Reserved banking, financial, payment or exchange activity requires the applicable BCC authorisation.
- Implementation action
- Separate regulated functions and block launch until the responsible authority confirms every licence or registration.
- Evidence to retain
- Product map, applications, authorisations, conditions and public-register checks.
- Primary citation
- Decree-Law 362/2018; current BCC licensing rules
Virtual-asset services within Resolution 215/2021 require a BCC licence and AML controls.
- Implementation action
- Classify custody, exchange, transfer, financial and issuer-related services; verify the current licence and DGIOF registration route.
- Evidence to retain
- Service taxonomy, BCC decision, DGIOF registration and control assessment.
- Primary citation
- BCC Resolution 215/2021; GAFILAT final Fourth-Round follow-up
02Governance and risk assessmentA documented risk-based programme must reflect the operator's actual sector and exposure.3 items+
Reporting entities must identify and evaluate vulnerabilities to ML/TF/PF and illicit capital movements.
- Implementation action
- Assess customers, products, geography, channels and delivery methods; approve risk appetite and remediation.
- Evidence to retain
- Risk methodology, assessment, data, approvals and remediation log.
- Primary citation
- Decree-Law 317/2013 arts. 5 and 19-20
Internal controls must support prevention, detection, reporting and competent-authority access.
- Implementation action
- Assign accountable leadership and compliance roles, maintain procedures, training, testing and escalation.
- Evidence to retain
- Governance charter, appointments, manual, training and assurance reports.
- Primary citation
- Decree-Law 317/2013 arts. 5 and 8; applicable sector rule
Material legal and risk changes require controlled updates.
- Implementation action
- Monitor Gaceta Oficial, BCC, DGIOF, FATF and GAFILAT releases and test each parameter change before deployment.
- Evidence to retain
- Source register, change log, approvals, testing and release record.
- Primary citation
- Implementation control supporting Decree-Law 317/2013
03Natural-person identificationCDD is based on reliable identity evidence, purpose, risk and ongoing consistency.3 items+
Reporting entities must always identify customers and verify the authenticity of submitted data and documents.
- Implementation action
- Capture identity and contact data, authenticate reliable documents and bind them to the applicant before activation.
- Evidence to retain
- Application, document images, validation results, timestamps and reviewer decision.
- Primary citation
- Decree-Law 317/2013 art. 12
CDD includes purpose, intended character and ongoing monitoring consistent with identified risk.
- Implementation action
- Record expected activity, assign risk, refresh on change or doubt and investigate deviations.
- Evidence to retain
- Purpose statement, profile, rating, refresh history and monitoring cases.
- Primary citation
- Decree-Law 317/2013 art. 9
A person acting for a customer must be identified and their authority verified.
- Implementation action
- KYC the representative, validate the mandate, scope and expiry and link it to the customer.
- Evidence to retain
- Representative KYC, power, verification and permission record.
- Primary citation
- Decree-Law 317/2013 arts. 9 and 12; applicable sector rule
04KYB and beneficial ownershipLegal existence, authority, ownership and control must be reconstructed from reliable evidence.3 items+
Legal-person customers require reliable formation, registration, address, activity and authority evidence.
- Implementation action
- Obtain current registry evidence, constitutional documents, tax details, directors and powers and reconcile discrepancies.
- Evidence to retain
- Registry extract, formation documents, tax record, governance list and reconciliation.
- Primary citation
- Decree-Law 317/2013 arts. 9 and 12; Commercial Registry rules
CDD must identify the beneficial owner and take reasonable steps to verify that person's identity.
- Implementation action
- Trace natural-person ownership and control through every tier and document the sector-specific test used.
- Evidence to retain
- Ownership chart, source records, declarations, control analysis and verification.
- Primary citation
- Decree-Law 317/2013 arts. 9 and 12
Registry evidence does not replace independent AML verification.
- Implementation action
- Reconcile customer declarations with the Central Commercial Registry and other competent registers; escalate missing or conflicting data.
- Evidence to retain
- Registry results, access log, discrepancy case and resolution.
- Primary citation
- Commercial Registry rules; Decree-Law 317/2013 arts. 9 and 12
05PEPs, enhanced diligence and remote onboardingHigher-risk relationships require stronger approval, source and monitoring controls under the applicable sector rule.3 items+
Customers and beneficial owners must be assessed for PEP status under the current sector rule.
- Implementation action
- Screen at onboarding and periodically, cover family and close associates where required, and preserve the basis.
- Evidence to retain
- Declaration, screening, public-source evidence and review history.
- Primary citation
- Applicable BCC or sector AML rule; FATF Recommendation 12 implementation assessed by GAFILAT
Higher-risk and PEP cases require enhanced measures proportionate to risk.
- Implementation action
- Obtain senior approval, establish source of wealth and funds where required and intensify monitoring.
- Evidence to retain
- Approval, source pack, risk rationale, monitoring plan and reviews.
- Primary citation
- Applicable sector rule; Decree-Law 317/2013 risk-based framework
Remote onboarding must meet the same identification standard and protect personal data.
- Implementation action
- Authenticate document and person, manage impersonation risk, secure the flow and provide manual review.
- Evidence to retain
- Flow design, vendor diligence, security tests, legal basis and review record.
- Primary citation
- Decree-Law 317/2013 art. 12; Law 149/2022
06Monitoring and suspicious reportingSuspicion is reported promptly and without an amount floor; live submission mechanics must be confirmed.4 items+
Reporting entities must monitor activity against customer knowledge, purpose and risk.
- Implementation action
- Implement risk-based scenarios, reconcile complete data, investigate alerts and tune controls.
- Evidence to retain
- Scenario inventory, data lineage, cases, tuning and validation.
- Primary citation
- Decree-Law 317/2013 arts. 9-10
A suspicious transaction or attempted activity must be reported promptly to DGIOF when suspicion or reasonable grounds arise.
- Implementation action
- Document the grounds, preserve supporting material and submit through the current confidential DGIOF route.
- Evidence to retain
- Case analysis, decision, report, attachments, timestamp and acknowledgement.
- Primary citation
- Decree-Law 317/2013 arts. 13-14
Suspicious reporting applies independently of transaction amount.
- Implementation action
- Do not suppress or delay escalation because an amount is below a threshold; aggregate linked activity.
- Evidence to retain
- Rule configuration, linked-case analysis, report decision and testing.
- Primary citation
- Decree-Law 317/2013 art. 14
Reporting and DGIOF information must remain confidential.
- Implementation action
- Restrict access, avoid tipping off and separate customer communications from the reporting decision.
- Evidence to retain
- Access list, confidentiality controls, training and incident log.
- Primary citation
- Decree-Law 317/2013; BCC Resolution 51/2013
07Payments, wires and threshold reportsDetailed payment fields and threshold reporting are sector-specific and must be confirmed from the live rule.3 items+
Specified cash or other operations above a BCC-set threshold may require registration and reporting.
- Implementation action
- Obtain the current sector threshold, currency conversion, aggregation period, report type and filing calendar directly from BCC or DGIOF.
- Evidence to retain
- Authoritative parameter sheet, configuration, tests, report and receipt.
- Primary citation
- Decree-Law 317/2013 art. 15; BCC Resolution 51/2013 art. 7
Wire transfers must carry and preserve required originator and beneficiary information.
- Implementation action
- Validate required fields before release, reject or escalate incomplete messages and screen all parties.
- Evidence to retain
- Message sample, validation, screening, exception and decision.
- Primary citation
- Applicable BCC transfer rule; GAFILAT technical-compliance assessment
Agents and outsourced providers do not remove the reporting entity's responsibility.
- Implementation action
- Contract, train, monitor and test delegated onboarding, payment and reporting controls.
- Evidence to retain
- Contract, agent register, training, testing and remediation.
- Primary citation
- Applicable BCC or sector rule
08Targeted financial sanctionsScreening and freezing must follow current UN and Cuban designation procedures without delay.3 items+
Reporting entities must identify designated persons and entities under applicable UN and national measures.
- Implementation action
- Synchronise authoritative lists and screen customers, beneficial owners, transactions and counterparties.
- Evidence to retain
- List source, version, screening logs, match analysis and disposition.
- Primary citation
- Decree-Law 317/2013 arts. 16-18; BCC Resolution 51/2013 arts. 9-12
Funds or assets connected to a confirmed designation must be frozen without delay under the competent procedure.
- Implementation action
- Block access without warning, notify DGIOF and preserve the complete authority and action chronology.
- Evidence to retain
- Match record, freeze timestamp, notification, acknowledgement and account controls.
- Primary citation
- Decree-Law 317/2013 arts. 16-18; BCC Resolution 51/2013 arts. 9-12
False-positive, release and exception handling must use the live authority route.
- Implementation action
- Maintain escalation and unfreezing procedures and confirm any humanitarian or other exception before acting.
- Evidence to retain
- Procedure, authority correspondence, approvals and audit trail.
- Primary citation
- Current DGIOF/BCC sanctions procedure; controlled uncertainty
09Records and authority accessRecords must reconstruct identity, transactions, monitoring and reporting decisions.3 items+
Reporting entities must preserve customer-identification and transaction records.
- Implementation action
- Apply the live sector retention period from the correct trigger and preserve legal holds.
- Evidence to retain
- Retention schedule, source rule, trigger logic, archive samples and deletion tests.
- Primary citation
- Decree-Law 317/2013 art. 9; applicable sector rule
Records must support prompt DGIOF and competent-authority requests.
- Implementation action
- Verify authority, collect complete records securely and preserve production and acknowledgement evidence.
- Evidence to retain
- Request, authority check, collection log, production and receipt.
- Primary citation
- Decree-Law 317/2013 arts. 6-8; BCC Resolution 51/2013
Every decision must be reconstructable from source to outcome.
- Implementation action
- Preserve versions, timestamps, reviewers, evidence, screening, alerts, approvals and linked reports.
- Evidence to retain
- Reconstruction test, source hashes, case export and remediation.
- Primary citation
- Implementation control supporting Decree-Law 317/2013
10Privacy, biometrics and transfersLaw 149 applies to personal-data processing, including KYC information and sensitive data.3 items+
Personal data must be processed under Law 149 principles and an applicable legal basis.
- Implementation action
- Map each field to purpose, necessity and authority; provide required information and restrict incompatible reuse.
- Evidence to retain
- Data inventory, legal-basis matrix, notice, purpose register and approvals.
- Primary citation
- Law 149/2022 arts. 1-7
Data subjects have statutory access, correction, updating and cancellation rights subject to lawful limits.
- Implementation action
- Operate authenticated rights workflows and document any AML or legal restriction on disclosure or deletion.
- Evidence to retain
- Request log, identity check, decision, response and exception rationale.
- Primary citation
- Law 149/2022
Sensitive, biometric and cross-border processing require documented safeguards and current-law analysis.
- Implementation action
- Assess necessity and proportionality, secure templates and transfers, restrict vendors and obtain Cuban advice before launch.
- Evidence to retain
- Impact assessment, security design, contracts, transfer map and counsel opinion.
- Primary citation
- Law 149/2022; implementing rules; controlled uncertainty
11Practical evidence packsOperational evidence should show what was known, why a rule applied and when action occurred.3 items+
Onboarding decisions should be reproducible.
- Implementation action
- Bundle identity, KYB, ownership, authority, screening, purpose, risk, approvals and exceptions.
- Evidence to retain
- Timestamped onboarding pack with sources, hashes, reviewer and decision.
- Primary citation
- Implementation control supporting Decree-Law 317/2013 arts. 9 and 12
Monitoring and reporting decisions should preserve the complete chronology.
- Implementation action
- Capture rule version, inputs, analysis, requests, suspicion decision, submission and receipt.
- Evidence to retain
- Alert case, linked activity, notes, report and quality review.
- Primary citation
- Implementation control supporting Decree-Law 317/2013 arts. 13-15
Launch approval must resolve licensing, AML, sanctions, registry, privacy and reporting readiness together.
- Implementation action
- Use a cross-functional go-live gate and block unresolved perimeter, source, portal or evidence defects.
- Evidence to retain
- Signed checklist, legal opinions, authorisations, tests and residual-risk acceptance.
- Primary citation
- Implementation control; Decree-Law 317/2013; Law 149/2022
Primary-source register
9 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Decree-Law 317 of 2013 - AML/CFT/CPF preventive frameworkGaceta Oficial de la República de Cuba (FAOLEX official-text mirror) · Primary legislation
- BCC Resolution 51 of 2013 - DGIOF functions and reportingGaceta Oficial de la República de Cuba (FAOLEX official-text mirror) · Primary regulation
- Law 149 of 2022 on Personal Data ProtectionWIPO Lex · Primary legislation repository
- Banco Central de CubaBanco Central de Cuba · Official regulator portal
- Cuba mutual evaluationGAFILAT · Authoritative regional assessment
- Final Fourth-Round follow-up report for CubaGAFILAT · Authoritative regional assessment
- Cuba Fifth-Round preparationGAFILAT · Authoritative current-status update
- FATF high-risk jurisdictions subject to a call for actionFinancial Action Task Force · Authoritative current status
- FATF jurisdictions under increased monitoringFinancial Action Task Force · Authoritative current status
Direct answers
Cuba KYC, KYB and AML questions
Who receives suspicious transaction reports in Cuba?+
The Dirección General de Investigación de Operaciones Financieras (DGIOF), Cuba's FIU within the Banco Central de Cuba.
When must suspicion be reported?+
Decree-Law 317 requires prompt reporting when suspicion or reasonable grounds arise, regardless of amount. Confirm the exact current electronic route and any sector workflow with DGIOF.
Is there one universal threshold report?+
This checklist does not state a universal amount. Decree-Law 317 permits BCC-set threshold reporting, so the current amount, currency conversion, aggregation and report type must be confirmed for the sector.
Who is the beneficial owner?+
CDD must identify the natural person who ultimately owns or controls the customer. Apply the detailed test in the current sector rule and document ownership and control through every tier.
Is registry information publicly accessible?+
Cuba maintains commercial and other legal-person registers, but live access, data fields and beneficial-ownership availability are controlled uncertainties. Obtain current official evidence and do not treat a registry extract as a substitute for AML verification.
How long must AML records be retained?+
Decree-Law 317 requires record custody, while detailed periods and trigger dates are set by applicable sector rules. Confirm the current rule before configuring deletion.
Do virtual-asset services require a licence?+
Specified virtual-asset services fall within the BCC licensing framework under Resolution 215/2021 and subsequent rules. Confirm the current scope, AML registration and conditions before launch.
What happens on a sanctions-list match?+
Follow the current DGIOF/BCC procedure to freeze without delay, report confidentially and preserve the authority and action chronology. Do not notify the customer.
What privacy law applies to KYC and biometrics?+
Law 149 of 2022 governs personal-data processing. Sensitive, biometric, vendor and cross-border designs require a documented legal-basis and safeguards assessment under current implementing rules.
Is Cuba on a FATF public list?+
As reviewed on 5 August 2026, Cuba was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck the live FATF statements before reliance.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, a licensing decision or a substitute for the operative Spanish texts and current sector instructions. Reviewed 5 August 2026. Cuba's framework is sector-specific and official online access can be inconsistent. Confirm the reporting channel, sector thresholds, retention periods, registry access, sanctions procedure, licence perimeter and any post-review amendments directly with DGIOF, BCC, the competent registry and qualified Cuban counsel before launch.