Dominican Republic KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Dominican Republic.

Direct answer
What does the Dominican Republic compliance checklist cover?
The Dominican Republic checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Análisis Financiero (UAF)
- Core AML framework
- Law 155-17 and implementing Decree 408-17
- Suspicious reports
- Within five business days after the transaction or attempted transaction is identified as suspicious
- Cash transaction report
- USD 15,000 equivalent aggregate within 24 hours; casino threshold USD 3,000
- Routine cash-report timing
- First ten calendar days of the following month
- Beneficial owner
- Natural person with final effective control; 20% ownership is an express statutory and regulatory limb, with control and senior-manager fallback
- Retention
- At least ten years after an occasional transaction or the end of the relationship
- PEP window
- Current or former prominent function within the previous three years, with risk-based treatment of family and close associates
- Privacy framework
- Law 172-13; document necessity, consent or statutory grounds and secure identity data
- Payments
- Banco Central authorization and the current Payment Systems Regulation apply by activity
- FATF status
- GAFILAT member; not named on FATF public increased-monitoring or call-for-action lists reviewed 1 August 2026
Implementation detail
Dominican Republic compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingClassification determines the supervisor, report channel and additional rulebook.4 items+
Law 155-17 applies to the financial subjects in article 32 and DNFBPs in article 33.
- Implementation action
- Map every entity, product, customer type and Dominican nexus to the statutory category and applicable sector supervisor before onboarding.
- Evidence to retain
- Perimeter memorandum, organization chart, activity map, supervisor matrix and counsel approval.
- Primary citation
- Law 155-17 arts. 31-33
Each obliged subject remains accountable for the AML/CFT duties attached to its category.
- Implementation action
- Maintain an inventory of Law 155-17, Decree 408-17, sector rules, UAF formats and effective dates; assign owners for change monitoring.
- Evidence to retain
- Legal inventory, change log, governance approvals and implementation tracker.
- Primary citation
- Law 155-17 arts. 34-35; Decree 408-17 art. 2
Banking, payment and other reserved financial activities require the authorization applicable to the legal entity and service.
- Implementation action
- Obtain a written perimeter decision and all approvals before marketing or operating a reserved activity; verify the live authority register.
- Evidence to retain
- Perimeter opinion, application, authorization, register extract, conditions and launch gate.
- Primary citation
- Monetary and Financial Law 183-02; Payment Systems Regulation
Cross-border or technology delivery does not itself remove Dominican regulatory obligations.
- Implementation action
- Assess establishment, customer location, solicitation, settlement, custody and local-agent facts; obtain local advice for material uncertainty.
- Evidence to retain
- Nexus analysis, product diagrams, customer terms, geofencing and legal sign-off.
- Primary citation
- Law 155-17 arts. 32-35; applicable sector rules
02Governance and risk assessmentThe program must be risk-based, documented and independently tested.4 items+
An obliged subject must maintain risk policies, hiring and training controls, discipline, ethics and independent external audit.
- Implementation action
- Approve an entity-specific AML/CFT program, name control owners and test operating effectiveness at the required frequency.
- Evidence to retain
- Board approval, manual, training, screening, disciplinary standard, ethics code and audit report.
- Primary citation
- Law 155-17 art. 34
Risk methods must consider customers, products, services, geography and delivery channels.
- Implementation action
- Document inherent risk, controls, residual risk, scoring, overrides and review frequency; connect results to simplified, standard or enhanced measures.
- Evidence to retain
- Enterprise and customer risk assessments, methodology, data inputs, validation and change log.
- Primary citation
- Law 155-17 arts. 36-37
A senior-level compliance officer must have authority and access appropriate to the role.
- Implementation action
- Appoint and resource the officer, define escalation and succession and protect direct access to senior management.
- Evidence to retain
- Appointment, role profile, fit assessment, committee minutes, budget and succession plan.
- Primary citation
- Law 155-17 art. 44
New products, practices and technologies must be assessed for ML/TF risk before launch.
- Implementation action
- Gate material product and channel changes through AML, sanctions, privacy and security review and retest after deployment.
- Evidence to retain
- New-product assessment, threat scenarios, approvals, test results and post-launch review.
- Primary citation
- Law 155-17 art. 45
03Natural-person KYC and representativesIdentity must be verified from reliable, independent information and linked to the person using the account or service.4 items+
Identify and verify a natural-person customer using reliable and independent sources.
- Implementation action
- Capture required identity data, authenticate evidence, bind the applicant to it and resolve discrepancies before activation.
- Evidence to retain
- Identity record, document images, authenticity and liveness results where used, timestamps and reviewer.
- Primary citation
- Law 155-17 art. 38
Identify a representative and verify the authority to act for the customer.
- Implementation action
- Verify the representative, obtain the current mandate or power and check scope, validity and revocation.
- Evidence to retain
- Representative KYC, mandate, notarial or registry check, authority decision and expiry control.
- Primary citation
- Law 155-17 art. 38
Understand the purpose and intended nature of the relationship.
- Implementation action
- Collect occupation or business, purpose, expected activity, source information proportionate to risk and intended counterparties or corridors.
- Evidence to retain
- Customer profile, expected activity, source evidence, discrepancy resolution and approval.
- Primary citation
- Law 155-17 arts. 38-39
If identity cannot be established and verified, the relationship or transaction must not proceed and suspicion must be considered.
- Implementation action
- Block activation or execution, preserve the attempted activity, escalate and make a documented suspicious-report decision without tipping off.
- Evidence to retain
- System block, refusal or failure record, escalation, report decision and communication log.
- Primary citation
- Law 155-17 art. 62
04KYB and beneficial ownershipLegal existence, authority, ownership and control are separate verification tasks.4 items+
For a legal person, verify name, tax identifier, legal form and existence, ownership and control, senior management and principal address.
- Implementation action
- Obtain current formation and registry records, tax status, governing documents and signatory authority; reconcile inconsistencies.
- Evidence to retain
- Registry extract, RNC evidence, constitutional documents, address, management list and discrepancy log.
- Primary citation
- Law 155-17 art. 40
Identify and take reasonable measures to verify the natural-person beneficial owner.
- Implementation action
- Trace direct, indirect, contractual and de facto control to natural persons; corroborate declarations with reliable independent evidence.
- Evidence to retain
- Ownership chart, cap table, voting agreements, control analysis, declarations and reviewer sign-off.
- Primary citation
- Law 155-17 arts. 2(5), 38 and 40
The implementing hierarchy uses 20% ownership, then control by other means, then senior-management fallback.
- Implementation action
- Do not stop at the percentage test; document each step and the reason for any senior-manager fallback.
- Evidence to retain
- Percentage calculation, indirect ownership, control memorandum, fallback rationale and approval.
- Primary citation
- Decree 408-17 art. 4
Tax beneficial-owner information and supporting documents must be filed and kept current under the DGII regime.
- Implementation action
- Include required information in the annual declaration, report changes within the applicable maximum six-month period and keep supporting records ten years.
- Evidence to retain
- DGII declaration, change log, filing receipt, source records, retention schedule and response pack.
- Primary citation
- Decree 408-17 arts. 38-44; DGII beneficial-owner guidance
05PEPs, EDD and relianceHigher-risk relationships require additional approval, source work and monitoring.4 items+
PEPs and customers connected to FATF high-risk jurisdictions are treated as high risk under Law 155-17.
- Implementation action
- Screen customers, representatives and beneficial owners; determine the office, time window, family or associate connection and jurisdiction risk.
- Evidence to retain
- Screening result, role analysis, relationship mapping, list version, adjudication and review date.
- Primary citation
- Law 155-17 arts. 2 and 46
PEP enhanced measures include senior approval, source of funds and wealth work and intensified monitoring.
- Implementation action
- Obtain approval before starting or continuing, corroborate source evidence proportionate to risk and set enhanced scenarios and reviews.
- Evidence to retain
- Approval, source-of-funds and wealth evidence, risk rationale, alert history and periodic review.
- Primary citation
- Decree 408-17 art. 18
Simplified diligence is permitted only for demonstrated lower risk and not where suspicion or high risk exists.
- Implementation action
- Define eligible cases, minimum measures and disqualifiers; record the evidence and approval for every simplified decision.
- Evidence to retain
- Simplified-DD policy, low-risk assessment, controls, approval and monitoring.
- Primary citation
- Law 155-17 arts. 42 and 46
Delegation does not transfer legal responsibility and information and records must be available without delay.
- Implementation action
- Contract for immediate evidence access, audit rights, incident notice and exit; independently test vendor or group controls.
- Evidence to retain
- Contract, due diligence, data-location map, sample retrieval tests, incidents and exit plan.
- Primary citation
- Law 155-17 art. 47; Decree 408-17 art. 22
06Monitoring and suspicious reportingOngoing monitoring and prompt UAF reporting apply to completed and attempted activity.4 items+
Monitor transactions against the customer profile and examine unusual or complex activity, including source, origin and destination where needed.
- Implementation action
- Implement risk-calibrated scenarios, investigate alerts, document explanations and update the profile when facts change.
- Evidence to retain
- Scenario inventory, alert, transaction trail, investigation, disposition, profile update and quality review.
- Primary citation
- Law 155-17 art. 39
A suspicious transaction report must be sent to UAF within five business days after a completed or attempted transaction is identified as suspicious.
- Implementation action
- Record the decision timestamp, prepare and submit the ROS through the current UAF channel and preserve the acknowledgement.
- Evidence to retain
- Alert, investigation, decision, report, submission timestamp, receipt and correction log.
- Primary citation
- Law 155-17 art. 55; DGII AML FAQ
Reporting and investigation information is confidential and tipping off is prohibited.
- Implementation action
- Restrict access, separate customer communications from the report process and log any legally authorized disclosure.
- Evidence to retain
- Access controls, confidentiality training, communications review, disclosure log and incident record.
- Primary citation
- Law 155-17 arts. 57-58 and 63
UAF and competent authorities can require information in the form and time directed.
- Implementation action
- Maintain authenticated request handling, searchable records and an escalation path capable of meeting a shortened official deadline.
- Evidence to retain
- Request, authority verification, production log, delivery receipt and remediation tracker.
- Primary citation
- Decree 408-17 arts. 24-26
07Threshold reports, transfers and cash controlsObjective reporting and payment restrictions are separate from suspicious reporting.4 items+
Cash transactions at or above USD 15,000 equivalent, aggregated for the same beneficiary within 24 hours, are reportable; casinos use USD 3,000.
- Implementation action
- Apply currency conversion and 24-hour aggregation, retain the decision and use the current sector format.
- Evidence to retain
- Threshold logic, exchange-rate source, aggregation record, report, receipt and exception testing.
- Primary citation
- Law 155-17 arts. 52-54
Monthly cash reports are submitted in the first ten calendar days of the following month and copies are retained ten years.
- Implementation action
- Run completeness reconciliation, file by the applicable date and retain the report and acknowledgement under access control.
- Evidence to retain
- Monthly reconciliation, calendar, submitted report, receipt and retention record.
- Primary citation
- Law 155-17 art. 53; DGII AML FAQ
Wire transfers must carry required originator and beneficiary information through the payment chain.
- Implementation action
- Collect, validate, transmit and preserve required fields; stop or escalate missing or inconsistent information under policy.
- Evidence to retain
- Message fields, validation result, exception queue, escalation and audit sample.
- Primary citation
- Law 155-17 arts. 48-49; Decree 408-17 arts. 20-21
Statutory cash-payment restrictions and indexed values must be checked against the current CONCLAFIT instrument.
- Implementation action
- Do not hardcode an old peso amount; maintain a dated threshold table and require traceable payment evidence where applicable.
- Evidence to retain
- Current resolution, threshold table, system configuration, payment proof and review log.
- Primary citation
- Law 155-17 art. 64; CONCLAFIT Resolution 2025-01; Decree 408-17 arts. 29-33
08Sanctions and targeted financial measuresList screening and freezing are distinct from ordinary transaction monitoring.4 items+
Obliged subjects must implement targeted financial sanctions and applicable United Nations list measures without delay.
- Implementation action
- Screen at onboarding, on list updates and before relevant execution; validate potential matches promptly and prevent prohibited dealing.
- Evidence to retain
- List sources and timestamps, screening logs, matching rules, adjudication and block record.
- Primary citation
- Decree 407-17; Law 155-17 arts. 64-65 framework
A confirmed targeted-financial-sanctions match requires immediate action and notification through the prescribed authorities and channel.
- Implementation action
- Freeze or immobilize without prior notice, preserve incoming funds as directed, notify the competent authorities and document legal review.
- Evidence to retain
- Match packet, action timestamp, frozen-assets record, notices, receipts and counsel note.
- Primary citation
- Decree 407-17
False positives must be resolved through controlled evidence and escalation, not arbitrary deletion from screening.
- Implementation action
- Use documented identifiers, independent review and a time-limited allowlist with re-screening on data or list changes.
- Evidence to retain
- Adjudication, identifiers, reviewer, allowlist controls, expiry and re-screen history.
- Primary citation
- Decree 407-17; UAF sanctions guidance
Sanctions controls must cover customers, beneficial owners, representatives and relevant transaction parties.
- Implementation action
- Map every screened party and field, test aliases and non-Latin names and monitor list-feed and system failures.
- Evidence to retain
- Coverage map, test cases, alert samples, feed monitoring, incidents and remediation.
- Primary citation
- Law 155-17 arts. 38-40 and 46; Decree 407-17
09Records, audit and regulator responseRecords must reconstruct the relationship, transaction and compliance decision.4 items+
CDD, transaction, account, correspondence and analysis records must be kept at least ten years after the occasional transaction or relationship ends.
- Implementation action
- Apply event-based retention, preserve the legal hold and ensure records are intelligible and retrievable throughout the period.
- Evidence to retain
- Retention schedule, closure event, record inventory, retrieval test, hold log and disposal evidence.
- Primary citation
- Law 155-17 art. 43
Required records must be available to UAF, supervisors and other competent authorities.
- Implementation action
- Authenticate requests, preserve confidentiality and privilege, produce only responsive records and track delivery.
- Evidence to retain
- Request protocol, production set, privilege review, receipt and remediation tracker.
- Primary citation
- Law 155-17 arts. 56-57; Decree 408-17 arts. 24-25
External audit must assess the design and effectiveness of the AML/CFT program.
- Implementation action
- Set independence and competence criteria, sample end-to-end controls and verify corrective-action closure.
- Evidence to retain
- Audit scope, independence, workpapers, report, management actions and closure validation.
- Primary citation
- Law 155-17 art. 34; Decree 408-17 art. 23
A filing, alert or investigation hold overrides routine deletion.
- Implementation action
- Connect legal and investigation holds to all customer, vendor and backup repositories and test release authorization.
- Evidence to retain
- Hold notice, repository map, preservation confirmation, release approval and disposal log.
- Primary citation
- Law 155-17 arts. 43, 55-56
10Privacy, biometrics and transfersAML necessity does not remove privacy, security and transparency duties.4 items+
Law 172-13 requires lawful, purpose-limited and proportionate personal-data processing with notice and consent or an applicable legal ground.
- Implementation action
- Map controller and processor roles, purposes, fields, grounds and AML exceptions; give a clear privacy notice and reconcile data-subject requests with retention law.
- Evidence to retain
- Data inventory, role map, legal-basis register, notice, request procedure and retention reconciliation.
- Primary citation
- Law 172-13 arts. 5, 27 and related principles
Sensitive data requires heightened handling and, absent an exception, express written consent.
- Implementation action
- Classify identity, financial, sanctions and biometric data; document the exact statutory need or consent and minimize access and collection.
- Evidence to retain
- Data classification, consent or exception record, access matrix, minimization review and audit log.
- Primary citation
- Law 172-13 arts. 75-76
Controllers and processors must maintain appropriate technical and organizational security and confidentiality.
- Implementation action
- Encrypt sensitive identity data, separate duties, monitor access, manage incidents and require equivalent vendor controls.
- Evidence to retain
- Risk assessment, control set, access reviews, incident log, vendor assessment and remediation.
- Primary citation
- Law 172-13 security and confidentiality provisions
International transfers require a documented lawful route, including consent or a statutory exception as applicable.
- Implementation action
- Map vendor, group and authority transfers, record the route and purpose, contract for safeguards and control onward transfers and deletion.
- Evidence to retain
- Transfer register, consent or exception, contract, destination review, onward-transfer controls and deletion proof.
- Primary citation
- Law 172-13 art. 80
11Payments, virtual assets and launch evidencePayment authorization, AML status and virtual-asset treatment require separate decisions.4 items+
Payment-system operators and electronic-payment entities must meet the applicable Banco Central authorization and operating rules.
- Implementation action
- Classify issuing, acquiring, processing, transfer, wallet and settlement functions and obtain every required approval before launch.
- Evidence to retain
- Product flow, perimeter opinion, application, authorization, conditions and live-register check.
- Primary citation
- Payment Systems Regulation approved 28 August 2025
The current Payment Systems Regulation excludes products or services based on virtual assets from the electronic-payment-entity permission.
- Implementation action
- Do not treat a payment authorization as approval for a virtual-asset product; obtain a separate written legal and supervisory perimeter decision.
- Evidence to retain
- Asset and service classification, counsel opinion, regulator correspondence, restrictions and launch gate.
- Primary citation
- Payment Systems Regulation approved 28 August 2025
Virtual assets are not legal tender and are not backed by the Banco Central; regulated institutions cannot assume permission absent an express rule or authorization.
- Implementation action
- Use accurate customer disclosures, prohibit unsupported payment-system use and assess AML, securities, custody, exchange and cross-border facts separately.
- Evidence to retain
- Legal opinion, product restrictions, customer disclosure, monitoring and approval.
- Primary citation
- Banco Central cryptocurrency statement; Payment Systems Regulation
Launch requires source-backed closure of every applicable control and successful end-to-end dry tests.
- Implementation action
- Test onboarding, KYB, reporting clocks, threshold aggregation, sanctions, retention, privacy and incidents without sending fictional data to regulator systems; close blockers and sign off.
- Evidence to retain
- Completed checklist, source register, test results, defects and closure, approvals and monitoring owner.
- Primary citation
- Law 155-17 arts. 34-65; Decree 408-17
Primary-source register
20 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law 155-17 against money laundering and terrorist financingDirección General de Impuestos Internos · Primary legislation
- Decree 408-17 implementing Law 155-17Superintendencia de Bancos · Primary regulation
- DGII AML/CFT frequently asked questionsDirección General de Impuestos Internos · Official compliance guidance
- DGII beneficial-owner guidanceDirección General de Impuestos Internos · Official filing guidance
- Official notice implementing CONCLAFIT Resolution 2025-01Dirección General de Impuestos Internos · Official current threshold notice
- Law 172-13 on personal dataNational Competitiveness Council · Primary legislation
- Payment Systems Regulation approved 28 August 2025Banco Central de la República Dominicana · Primary regulatory instrument
- Electronic payment entity authorization requirementsBanco Central de la República Dominicana · Official authorization guidance
- Banco Central statement on cryptocurrenciesBanco Central de la República Dominicana · Official perimeter statement
- FATF Dominican Republic country pageFinancial Action Task Force · Official country and assessment page
- Dominican Republic follow-up reportFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
- United Nations Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
- Monetary and Financial Law 183-02 directoryBanco Central de la República Dominicana · Primary financial framework
- UAF institutional portalUnidad de Análisis Financiero · Official authority and reporting information
- Decree 407-17 targeted-financial-sanctions textLegal Consultancy of the Executive Branch · Primary regulation
- Official explanation of Decree 407-17Legal Consultancy of the Executive Branch · Official implementation summary
- Banking-sector AML/CFT instructive, Circular 003-18Superintendencia de Bancos · Official sector instruction
- DGII register and tax services portalDirección General de Impuestos Internos · Official company and tax source
Direct answers
Dominican Republic KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Unidad de Análisis Financiero (UAF) is the national FIU. Obliged subjects submit through the current UAF-prescribed channel and format, commonly goAML, while sector supervisors oversee compliance.
When is a suspicious report due?+
Law 155-17 requires reporting within five business days after a completed or attempted transaction is identified as suspicious. Preserve the decision timestamp and current UAF acknowledgement.
What is the cash transaction threshold?+
The general statutory threshold is USD 15,000 equivalent, including transactions aggregated for the same beneficiary within 24 hours. Casinos use USD 3,000. Sector rules can add requirements.
When is the routine cash report filed?+
It is filed in the first ten calendar days of the following month, with a copy retained for ten years.
What beneficial-owner percentage applies?+
Twenty percent is an express ownership limb, but it is not the whole test. Trace natural-person control by other means and use the senior-management fallback only after documenting why no other natural person was identified.
How long are AML records kept?+
At least ten years after an occasional transaction or the end of the business relationship, subject to longer sector or legal-hold requirements.
Can onboarding continue if identity cannot be verified?+
No. The relationship or transaction should not proceed, and the facts must be assessed for a suspicious report without tipping off the person.
Does outsourcing transfer AML responsibility?+
No. The obliged subject remains responsible and must have immediate access to information and documents, effective oversight, audit rights and an exit plan.
Are virtual assets legal tender or automatically covered by a payment license?+
No. The Banco Central says virtual assets are not legal tender or backed by it, and the current payment regulation does not make virtual-asset products part of an electronic-payment-entity authorization. Obtain a service-specific perimeter decision.
Is the Dominican Republic on a FATF public list?+
It was not named on the FATF increased-monitoring or call-for-action lists dated 19 June 2026 and reviewed 1 August 2026. It is a GAFILAT member and its evaluation history still informs risk.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector rules, official report formats or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, aggregation, reporting channel, current indexed thresholds, licensing perimeter and later developments with qualified Dominican counsel and the competent authority before launch.