Ecuador KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Ecuador.

Direct answer
What does the Ecuador compliance checklist cover?
The Ecuador checklist translates primary KYC, KYB and AML rules into 11 control areas and 50 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Analisis Financiero y Economico (UAFE)
- Core framework
- 2024 Organic AML Law, effective 29 July 2025, and Executive Decree 298 of 2 February 2026
- Suspicious reports
- Within 5 business days from compliance-committee awareness, or entity awareness where no committee exists, regardless of amount
- Threshold reports
- USD 10,000 individual or aggregated for the same beneficiary within a 30-day period; file within the first 15 days of the following month
- No-report records
- Register NO ROS and NO RESU within 10 business days after the end of each month in which no corresponding report exists
- Retention
- 10 years after relationship termination, the last transaction or the occasional transaction, as applicable; transfer data also 10 years
- Beneficial owner
- At least 10% capital, control by other means, then highest-ranking managing official fallback
- PEP period
- At least 2 years after leaving office, followed by a documented risk reassessment
- Privacy authority
- Superintendencia de Proteccion de Datos Personales (SPDP)
- Virtual assets
- PSAVs are reporting entities supervised by the Superintendencia de Bancos for AML/CFT/CPF; UAFE status does not replace any permission required for the particular regulated activity
- FATF status
- GAFILAT member; not named on FATF call-for-action or increased-monitoring lists reviewed 1 August 2026
Implementation detail
Ecuador compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingThe 2024 law classifies financial, non-financial and virtual-asset reporting entities. Registration and financial or payment authorization are separate questions.5 items+
Financial reporting entities include regulated financial and insurance actors, payment-system participants, money or value transfer providers, exchanges, securities actors and specified credit, leasing and factoring businesses.
- Implementation action
- Map each entity and product to article 27 and the current sector instrument, identify the supervisor and document the Ecuador nexus.
- Evidence to retain
- Perimeter memorandum, entity and product inventory, supervisor matrix, legal nexus and signed approval.
- Primary citation
- 2024 Organic AML Law arts. 26-27
Article 28 covers specified non-financial activities, including real estate, construction, vehicle and precious-goods businesses, NPOs and defined legal, accounting, company and trust services.
- Implementation action
- Test the exact activity and professional-service conditions; do not classify an entire profession without the statutory transaction nexus.
- Evidence to retain
- Activity map, engagement analysis, statutory limb, exclusions and counsel sign-off.
- Primary citation
- 2024 Organic AML Law arts. 28-30
A PSAV is a reporting entity when, as a business, it exchanges virtual assets for fiat, exchanges one or more virtual assets, transfers virtual assets, custodies or administers virtual assets or instruments controlling them, or participates in or provides financial services related to an issuer's offer or sale of a virtual asset. PSAV AML/CFT/CPF supervision is assigned to the Superintendencia de Bancos.
- Implementation action
- Map every virtual-asset product and role to the article 31 perimeter, document whether the activity is conducted as a business, register with UAFE and resolve any activity-specific permission with the Superintendencia de Bancos.
- Evidence to retain
- Product and activity map, article 31 analysis, business-model evidence, UAFE code, SB correspondence or permission analysis and launch approval.
- Primary citation
- 2024 Organic AML Law arts. 26, 31 and 65
A reporting entity must obtain and maintain the UAFE code of registration and any license or operating registration required by its supervisor.
- Implementation action
- Complete the applicable registration before operating, provision SISLAFT and notify changes within 15 business days.
- Evidence to retain
- UAFE code, supervisor license or registration, SISLAFT access, change log and receipts.
- Primary citation
- 2024 Organic AML Law arts. 56 and 67; Executive Decree 298 arts. 55-59; Organic Administrative Code arts. 158-160
Financial, payment and fintech services require the authorization or qualification prescribed by the Monetary and Financial Code, Fintech Law and BCE or sector rules.
- Implementation action
- Do not accept deposits, provide reserved financial services or operate a covered payment role before the correct authorization; verify the public regulator record.
- Evidence to retain
- Licensing analysis, application, decision, public record, conditions and launch gate.
- Primary citation
- Organic Monetary and Financial Code art. 254; Fintech Law; JPRM-2024-018-M; applicable SB and BCE rules
02Governance and risk assessmentReporting entities must operate a proportionate AML/CFT/CPF program validated and supervised by the competent authority.4 items+
The prevention program must address policies, procedures, internal controls, staff integrity and training, risk-based diligence and conflicts of interest.
- Implementation action
- Build and approve a program proportionate to activity, size, structure and complexity and map every statutory element to an owner and control.
- Evidence to retain
- Approved program, manual, control matrix, ownership, training plan and validation record.
- Primary citation
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 47 and 80
Risk methodology must cover identification, evaluation, monitoring, administration and mitigation across customers, products, geography, channels and transactions.
- Implementation action
- Document inherent and residual risk, control effectiveness, thresholds, overrides and escalation and refresh the assessment at least annually.
- Evidence to retain
- Methodology, risk assessment, data, scoring, approval, annual refresh and remediation.
- Primary citation
- 2024 Organic AML Law arts. 36-39
A reporting entity must designate the required qualified compliance officer and protect SISLAFT credentials and reporting independence.
- Implementation action
- Appoint the officer and substitute where required, confirm qualification, resource the function and govern absence, change and confidential access.
- Evidence to retain
- Appointment, qualification, UAFE record, charter, budget, access log and succession plan.
- Primary citation
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 42-49
New products, practices and technologies require a documented ML/TF/PF assessment before launch.
- Implementation action
- Assess customer, delivery, cyber, impersonation, sanctions, outsourcing and privacy risks and approve measurable launch and monitoring controls.
- Evidence to retain
- Pre-launch assessment, threat model, tests, approval, monitoring metrics and change record.
- Primary citation
- 2024 Organic AML Law art. 38
03Natural-person KYC and representativesCDD must identify and verify the customer and representative, establish purpose and source of funds and continue throughout the relationship.5 items+
The customer or provider must be identified and verified from reliable documents, data or information.
- Implementation action
- Capture the required identity, address, activity, income or funds and purpose data, authenticate evidence and bind it to the applicant.
- Evidence to retain
- Identity file, source data, authenticity result, timestamps, reviewer and exception record.
- Primary citation
- 2024 Organic AML Law arts. 41-43
A representative must be identified, verified and shown to be authorized.
- Implementation action
- Verify the natural person and validate the power, mandate or role before enabling action; restrict access to the authorized scope.
- Evidence to retain
- Representative KYC, mandate, registry or notarial check, authority analysis and expiry control.
- Primary citation
- 2024 Organic AML Law art. 43(b)
CDD is continuous and must test transactions against the known business, activity and risk profile, including source of funds when necessary.
- Implementation action
- Set event- and risk-based refresh, monitor expected activity and resolve material deviations and stale identity evidence.
- Evidence to retain
- Profile, refresh schedule, triggers, alerts, investigations, updates and approvals.
- Primary citation
- 2024 Organic AML Law art. 43(d)-(e)
Verification ordinarily occurs before or while establishing the relationship; delayed completion is limited to controlled cases and must finish within five business days, subject to a possible UAFE extension of up to three business days.
- Implementation action
- Use delayed verification only where essential not to interrupt normal operations and risk is controlled; limit activity, clock the business-day deadline and document any extension.
- Evidence to retain
- Exception rationale, risk controls, deadline, UAFE request and response, verification and approval.
- Primary citation
- 2024 Organic AML Law art. 45; Organic Administrative Code arts. 158-160
If required CDD cannot be completed, the reporting entity must not start the relationship, open an account or execute the transaction. If the relationship has already begun, it must terminate it and submit a ROS to UAFE.
- Implementation action
- Block onboarding and transaction execution, terminate an existing relationship through the controlled process, preserve the failed-CDD record and file the ROS without tipping off.
- Evidence to retain
- System block, failed-CDD analysis, termination approval, ROS, acknowledgement and restricted communication log.
- Primary citation
- 2024 Organic AML Law art. 47
04KYB, registries and beneficial ownershipLegal-person CDD and the SRI beneficial-owner register both require a natural-person outcome, but the reporting entity must independently verify its customer.4 items+
Legal-person and arrangement CDD includes legal name, form, existence, principal address, governing powers, senior managers, business nature and ownership and control structure.
- Implementation action
- Obtain current SCVS or other registry evidence, constitutional documents, RUC, governance and purpose, and reconcile discrepancies.
- Evidence to retain
- Registry extract, constitutional documents, RUC, governance list, business profile and discrepancy log.
- Primary citation
- 2024 Organic AML Law art. 44
A beneficial owner is the natural person who ultimately owns or controls the entity or on whose behalf the transaction occurs.
- Implementation action
- Trace ownership to natural persons, examine contractual and other control and identify trust or arrangement parties and ultimate controllers.
- Evidence to retain
- Ownership chart, cap tables, agreements, trust documents, control analysis and identity evidence.
- Primary citation
- 2024 Organic AML Law arts. 4(f), 43(c) and 92
For a legal person, article 92 uses at least 10% capital, control by other means and then the highest-ranking managing official fallback.
- Implementation action
- Calculate direct and indirect ownership, document decision-unit and appointment rights and use the fallback only after recording why ownership and control tests found no person.
- Evidence to retain
- Calculations, control memorandum, source documents, fallback record and approval.
- Primary citation
- 2024 Organic AML Law art. 92(1)
Every legal person must register its beneficial owners with SRI under the applicable conditions; inaccurate information identified by SRI or SCVS must be corrected within 10 business days, with a possible extension of up to five business days.
- Implementation action
- Maintain the REBEFICS and SRI calendar, reconcile customer and corporate records and clock correction notices in business days.
- Evidence to retain
- BO register, REBEFICS filing, receipt, reconciliation, correction notice and response.
- Primary citation
- 2024 Organic AML Law arts. 91 and 93-94; SRI Resolution NAC-DGERCGC24-00000033; Organic Administrative Code arts. 158-160
05PEPs, enhanced diligence and remote onboardingPEPs, associates and specified high-risk categories require reinforced controls; PEP status alone does not justify denial of service.6 items+
Systems must determine whether a customer or beneficial owner is a domestic or foreign PEP or an associate.
- Implementation action
- Screen at onboarding and continuously, identify the role and dates and map relevant family, close associate and control relationships.
- Evidence to retain
- Screening, role source, relationship analysis, disposition, review date and changes.
- Primary citation
- 2024 Organic AML Law arts. 49-50; Executive Decree 298 arts. 74-75
Foreign PEPs and associates, and higher-risk domestic PEP cases, require senior approval, reasonable source-of-wealth and source-of-funds measures and intensified monitoring.
- Implementation action
- Obtain approval before opening or continuing, corroborate wealth and funds and configure enhanced review and scenarios.
- Evidence to retain
- Approval, wealth analysis, funds trail, supporting records, monitoring plan and periodic review.
- Primary citation
- 2024 Organic AML Law art. 49
PEP status remains for two years after office, after which the reporting entity reassesses risk and documents whether enhanced treatment continues.
- Implementation action
- Clock departure dates, retain PEP controls through the two-year minimum and complete a reasoned reassessment rather than automatic removal.
- Evidence to retain
- Role end date, two-year control, risk reassessment, approval and screening update.
- Primary citation
- Executive Decree 298 art. 76
Irrespective of the entity's own risk score, intensified due diligence applies to every activity and person category listed in article 50, including the specified justice, defence, security, corrections, customs, border, elected-office, state-contractor, natural-resource and professional-football categories.
- Implementation action
- Map the complete statutory category list into onboarding and monitoring, identify qualifying roles and activities, obtain intensified evidence and approval, and retain the legal-category rationale.
- Evidence to retain
- Article 50 category matrix, screening and role evidence, enhanced approval, source-of-funds or wealth support, monitoring plan and review.
- Primary citation
- 2024 Organic AML Law art. 50
Relationships or transactions involving FATF high-risk jurisdictions require intensified measures, while jurisdictions under FATF monitoring require measures proportionate to the identified risk.
- Implementation action
- Ingest current FATF statements, distinguish call-for-action from monitored jurisdictions, configure the required treatment and document country-risk decisions and exceptions.
- Evidence to retain
- Dated FATF lists, country-risk matrix, enhanced or proportionate measures, approval, monitoring and review.
- Primary citation
- 2024 Organic AML Law art. 51
Remote onboarding and external identity providers remain subject to the reporting entity's CDD responsibility and confidentiality duties.
- Implementation action
- Validate the method, test impersonation and liveness, contract for evidence and audit access and independently monitor the provider.
- Evidence to retain
- Remote-flow legal map, vendor review, tests, contract, sample QA, incidents and exit plan.
- Primary citation
- 2024 Organic AML Law arts. 43-45 and 53-54
06Monitoring, suspicious reports and confidentialityEcuador's 2024 law uses a five-business-day awareness-based ROS deadline and covers completed and attempted operations regardless of amount.4 items+
Submit the ROS within five business days from the date the compliance committee becomes aware of the suspicious completed or attempted operation; if the entity has no compliance committee, count from when the reporting entity becomes aware. The duty applies regardless of amount.
- Implementation action
- Escalate immediately, preserve the applicable committee-or-entity awareness timestamp, document grounds and submit the ROS with support through SISLAFT.
- Evidence to retain
- Alert, investigation, committee or entity awareness record, decision, report, support and acknowledgement.
- Primary citation
- 2024 Organic AML Law art. 57; Executive Decree 298 art. 28; Organic Administrative Code arts. 158-160
A reasoned request made within the legal framework may receive a UAFE extension of up to three additional business days; an extension must never be assumed.
- Implementation action
- Treat five business days as the control deadline, request an extension only when justified and preserve UAFE's written response.
- Evidence to retain
- Business-day deadline clock, request, grounds, UAFE response, filing and quality review.
- Primary citation
- 2024 Organic AML Law art. 57; Organic Administrative Code arts. 158-160
If no ROS exists for a month, the reporting entity must register NO ROS in UAFE's reporting system within 10 business days after the end of that month.
- Implementation action
- Reconcile all cases, obtain compliance approval and submit the no-report record within the 10-business-day term.
- Evidence to retain
- Case reconciliation, approval, NO ROS record, receipt and exception log.
- Primary citation
- 2024 Organic AML Law art. 59; UAFE Resolution UAFE-DG-2026-0007; Organic Administrative Code arts. 158-160
Disclosure of a ROS, its existence or UAFE examination to unauthorized persons is prohibited and a very serious infringement.
- Implementation action
- Restrict case access, use neutral communications and route disclosure requests through legal and compliance.
- Evidence to retain
- Access log, confidentiality acknowledgements, communications, training and disclosure approvals.
- Primary citation
- 2024 Organic AML Law arts. 23 and 81(h), (m)
07Payments, wires, thresholds and agentsThreshold reporting, cash restrictions and transfer information apply alongside payment and fintech authorization.5 items+
Within the first 15 days of each month, reporting entities submit RESU for individual operations at or above USD 10,000 and multiple operations that together reach or exceed USD 10,000 for the benefit of the same person within a 30-day period.
- Implementation action
- Aggregate across channels and products for the rolling 30-day period, validate the beneficiary and submit the current UAFE structure; track any sector-specific lower threshold.
- Evidence to retain
- Aggregation logic, test cases, RESU file, reconciliation, receipt and correction log.
- Primary citation
- 2024 Organic AML Law art. 58; Executive Decree 298 art. 61
If no threshold report exists for a month, the entity must register NO RESU in UAFE's reporting system within 10 business days after the end of that month.
- Implementation action
- Reconcile source systems, approve the nil position and submit NO RESU within the 10-business-day term.
- Evidence to retain
- Monthly reconciliation, approval, NO RESU record, receipt and exception handling.
- Primary citation
- 2024 Organic AML Law art. 59; Executive Decree 298 art. 61; Organic Administrative Code arts. 158-160
Except for contractual obligations arising from products, services or operations of national-financial-system entities and BCE under Executive Decree 298 General Provision Five, no person may pay, settle, accept payment or accept settlement of an obligation or transaction equal to or above USD 10,000 using domestic or foreign notes or coins, precious stones or precious metals.
- Implementation action
- Block covered settlement methods at the threshold, route payment through a permitted method and document the legal basis and evidence for any financial-system or BCE exclusion.
- Evidence to retain
- Payment-method rules, threshold tests, blocked transaction, permitted settlement record, exclusion analysis and approval.
- Primary citation
- 2024 Organic AML Law art. 33; Executive Decree 298 General Provision Five
Originator, beneficiary and account or reference information must accompany domestic, cross-border and virtual-asset transfers, including batches, and be retained for 10 years.
- Implementation action
- Validate required fields before release, stop or investigate missing information, screen parties and preserve the complete message.
- Evidence to retain
- Message, field validation, screening, exception, investigation, approval and archive.
- Primary citation
- 2024 Organic AML Law art. 52
Payment aggregators, gateways, processors, switches and SEDPES require the authorization and controls applicable to their BCE and sector role.
- Implementation action
- Obtain authorization before service, maintain UAFE compliance certification, govern agents and vendors and meet data, security and operating requirements.
- Evidence to retain
- BCE or sector authorization, operating scheme, contracts, UAFE certificate, security report and monitoring.
- Primary citation
- Fintech Law; JPRM-2024-018-M; BCE payment-participant authorization requirements
08Targeted financial sanctions and freezingEcuador uses a UAFE-led, judicial freezing process for UN terrorism and proliferation designations. Operators must monitor and escalate matches without delay.5 items+
Reporting entities must monitor UN Security Council lists concerning terrorism and proliferation.
- Implementation action
- Screen customers, beneficial owners, counterparties and transactions against the current UN lists and UAFE communications.
- Evidence to retain
- List source and timestamp, configuration, screening logs, match analysis and escalation.
- Primary citation
- 2024 Organic AML Law arts. 37 and 55; UAFE Resolution UAFE-DG-2022-0095
A potential designation match must be reported through the UAFE process so the competent authorities can seek the applicable preventive judicial measure.
- Implementation action
- Escalate a true match immediately, preserve all funds and transaction facts, follow UAFE instructions and avoid alerting the subject.
- Evidence to retain
- Match worksheet, identifiers, UAFE communication, preservation steps and restricted access.
- Primary citation
- UAFE Resolution UAFE-DG-2022-0095; UAFE UN freezing guide
A competent preventive immobilization or freezing order must be implemented within its exact scope; failure is a very serious infringement.
- Implementation action
- Authenticate the order, block the identified property, prevent value from being made available and confirm execution through the prescribed channel.
- Evidence to retain
- Order, authority validation, block timestamps, asset inventory, confirmation and reconciliation.
- Primary citation
- 2024 Organic AML Law art. 81(k); UAFE UN freezing guide
Separately from UN-list freezing, UAFE may immediately order an exceptional and proportionate immobilization of funds in the national financial system where objective, serious and verifiable indications arise from a ROS, early warning, complaint, national-intelligence information or UAFE intelligence. Financial entities must execute within 72 hours; the measure lasts no more than eight days pending judicial ratification, modification or revocation.
- Implementation action
- Authenticate and execute the UAFE order within 72 hours, restrict the identified funds, preserve confidentiality, track the eight-day maximum and implement only the verified judicial outcome.
- Evidence to retain
- UAFE order, receipt and execution timestamps, restricted-funds inventory, access log, judicial decision and reconciliation.
- Primary citation
- 2024 Organic AML Law art. 17.3; Executive Decree 298 arts. 52-55
Where a covered financial-system or popular-and-solidarity financial entity freezes, immobilizes, retains or detains funds through internal due-diligence processes because of suspected illicit or criminal activity, it must report through the applicable Complementary AML Unit and transfer the funds within five business days to the designated BCE custody account, following the operative authority procedure and preserving the holder's right to challenge the measure.
- Implementation action
- Identify article 48.1 cases separately from UN and UAFE measures, notify the competent complementary unit, transfer the funds to the verified BCE custody account within five business days and preserve challenge and release records.
- Evidence to retain
- Internal decision, suspicion basis, holder and funds record, complementary-unit report, BCE transfer receipt, business-day clock, challenge and disposition.
- Primary citation
- 2024 Organic AML Law art. 48.1; Organic Administrative Code arts. 158-160
09Records and regulator accessRecords must make customer, beneficial-owner, transfer, monitoring and report decisions reconstructable for 10 years and available to competent authorities.4 items+
CDD, transaction, analysis, account and business-correspondence records, with documentary support, must be retained for 10 years after termination of the contractual relationship, the last transaction, or the occasional transaction, as applicable. Transfer originator and beneficiary information must also be retained for 10 years.
- Implementation action
- Map each record to its statutory trigger, maintain the 10-year archive unless a longer sector duty applies and preserve legal holds.
- Evidence to retain
- Retention schedule, relationship and transaction trigger dates, archive, holds, restore tests and destruction approvals.
- Primary citation
- 2024 Organic AML Law arts. 48 and 52
CDD, beneficial-owner, monitoring, report and governance evidence must remain complete, secure and retrievable.
- Implementation action
- Preserve source evidence, metadata, approvals and linked case chronology and test retrieval and integrity periodically.
- Evidence to retain
- Customer and case index, integrity hashes, access logs, backups, sample retrieval and remediation.
- Primary citation
- 2024 Organic AML Law arts. 34-59; applicable sector rule
UAFE and designated supervisors may conduct in-situ and off-site supervision and request information within their competence.
- Implementation action
- Authenticate requests, preserve confidentiality and privilege, collect reproducibly and meet the stated deadline.
- Evidence to retain
- Request, authority check, collection log, production index, delivery and receipt.
- Primary citation
- 2024 Organic AML Law arts. 66-75; Executive Decree 298 art. 73
Electronic reporting corrections and replacements must follow UAFE validation and replacement procedures.
- Implementation action
- Monitor validation messages, correct errors within the operative period and preserve the original, replacement request, authorization and final accepted file.
- Evidence to retain
- Validation result, error analysis, replacement request, approval, final receipt and audit trail.
- Primary citation
- 2024 Organic AML Law art. 81(n)-(p); Executive Decree 298 art. 64; UAFE Resolution 2023-0559
10Privacy, biometrics and transfersAML processing must also satisfy Ecuador's Organic Personal Data Protection Law, its regulation and current SPDP instruments.4 items+
Personal data must be processed on a lawful basis, transparently, for proportionate purposes and no longer than necessary subject to legal retention.
- Implementation action
- Map each KYC field and use to a legal basis, provide required information, restrict reuse and reconcile privacy deletion with AML holds.
- Evidence to retain
- Processing inventory, basis map, notices, retention schedule, access controls and deletion decisions.
- Primary citation
- Organic Personal Data Protection Law arts. 7-12 and 47; General Regulation arts. 8-11
Biometric data is sensitive and high-risk or large-scale processing may require a prior impact assessment and heightened safeguards.
- Implementation action
- Document necessity, proportionality and basis, minimize templates, test attacks, complete the required impact assessment and govern vendors.
- Evidence to retain
- Biometric assessment, impact assessment, consent or other basis, architecture, tests and vendor terms.
- Primary citation
- Organic Personal Data Protection Law arts. 10, 26 and 42; General Regulation arts. 29-32
A qualifying breach is notified to SPDP and ARCOTEL as soon as possible and no later than five business days; the processor notifies the controller within two business days, and affected persons within three business days when their rights are at risk.
- Implementation action
- Maintain business-day statutory clocks, assess risk, issue complete notifications and record reasons for delay and remediation.
- Evidence to retain
- Incident timeline, assessment, regulator and individual notices, processor communication and remediation.
- Primary citation
- Organic Personal Data Protection Law arts. 43 and 46; General Regulation arts. 24-28; Organic Administrative Code arts. 158-160
International transfers require adequate protection, an approved safeguard or a lawful exception; required DPO appointments and the current SPDP transfer rule must be observed.
- Implementation action
- Map transfers and processors, select and document the transfer mechanism, audit safeguards and designate and register the DPO where required.
- Evidence to retain
- Transfer map, adequacy or contract analysis, processor audit, DPO appointment and SPDP records.
- Primary citation
- Organic Personal Data Protection Law arts. 48-50 and 55-59; SPDP Resolution 2026-0004-R
11Practical evidence packsA usable control environment preserves the source, decision, owner and timestamp for every material regulatory conclusion.4 items+
Each product needs an approved perimeter and authorization pack.
- Implementation action
- Record the legal entity, activity, reporting category, supervisor, UAFE code, financial or payment authorization, privacy role and review date.
- Evidence to retain
- Signed perimeter pack, source snapshots, registrations, authorizations, owner and next review.
- Primary citation
- 2024 Organic AML Law arts. 26-32, 56 and 67
Each customer file must evidence identity, authority, beneficial ownership, risk, PEP status and ongoing monitoring.
- Implementation action
- Use a pre-activation quality gate and periodic sample review, and remediate gaps to verified closure.
- Evidence to retain
- Customer index, KYC and KYB evidence, ownership chart, risk score, approvals, monitoring and QA.
- Primary citation
- 2024 Organic AML Law arts. 41-54
Reporting evidence must demonstrate the applicable committee-or-entity awareness timestamp, five-business-day ROS control, threshold aggregation, nil returns, validation and confidentiality.
- Implementation action
- Test cases end to end, reconcile every monthly submission and maintain portal continuity and restricted access.
- Evidence to retain
- Scenario tests, case chronology, ROS, RESU, nil records, receipts, access review and remediation.
- Primary citation
- 2024 Organic AML Law arts. 57-59; Executive Decree 298 arts. 28 and 60-64
Legal change monitoring must cover UAFE, SB, SCVS, SEPS, BCE, SRI, SPDP, FATF and GAFILAT.
- Implementation action
- Assign official sources and owners, review on a defined cadence and trigger impact assessment, controlled versioning, training and release.
- Evidence to retain
- Source register, dated review log, impact assessment, approvals, releases and training.
- Primary citation
- Applicable laws and regulator publications listed in Sources
Primary-source register
28 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- 2024 Organic Law on Prevention, Detection and Combat of Money Laundering and Financing of Other CrimesUAFE · Primary legislation
- Official Gazette Fourth Supplement 610 - 2024 Organic AML LawRegistro Oficial · Official gazette
- Executive Decree 298 - 2026 General AML RegulationSuperintendencia de Economia Popular y Solidaria · Primary regulatory instrument
- Official Gazette Third Supplement 216 - Executive Decree 298Registro Oficial · Official gazette
- UAFE legal and regulatory libraryUAFE · Official regulator library
- ROS and NO ROS current reporting guidanceUAFE · Official reporting guidance
- UAFE report typesUAFE · Official reporting guidance
- UAFE registration-code procedureUAFE · Official registration guidance
- Current reporting-entity designationsUAFE · Official perimeter guidance
- UAFE Resolution 2022-0131 - PSAV designation (legacy reporting deadlines displaced by the 2024 Law and current UAFE rules)UAFE · Primary designation instrument with superseded deadline provisions
- UAFE terrorism and UN freezing portalUAFE · Official sanctions guidance
- UAFE UN sanctions freezing guideUAFE · Official sanctions guidance
- SCVS AML/CFT regulatory directorySuperintendencia de Companias, Valores y Seguros · Official supervisor library
- SRI Resolution NAC-DGERCGC24-00000033 - REBEFICSServicio de Rentas Internas · Primary beneficial-owner regulation
- Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary legislation
- General Regulation to the Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- SPDP resolutions directorySuperintendencia de Proteccion de Datos Personales · Official regulator library
- SPDP Resolution 2026-0004-R - international data transfersSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- Fintech Law - Official Gazette Second Supplement 215Registro Oficial · Primary legislation
- JPRM-2024-018-M - payment systems and fintech activitiesBanco Central del Ecuador · Primary payment regulation
- Payment-system participant authorizationBanco Central del Ecuador · Official licensing guidance
- Superintendencia de Bancos regulatory codificationSuperintendencia de Bancos · Official supervisory rules library
- Organic Administrative Code - computation of administrative termsConsejo de la Judicatura · Primary legislation
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current status
- FATF mutual evaluation of EcuadorFinancial Action Task Force · Official international assessment
- GAFILAT network and evaluation scheduleFinancial Action Task Force · Official international assessment
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Official sanctions list
Direct answers
Ecuador KYC, KYB and AML questions
Who receives suspicious operation reports in Ecuador?+
Reporting entities submit ROS to UAFE through SISLAFT using the current UAFE structure and support requirements.
What is Ecuador's ROS deadline?+
Within five business days from the compliance committee's awareness of the suspicious completed or attempted operation, or from the reporting entity's awareness where it has no committee, regardless of amount. A UAFE extension of up to three business days requires a reasoned request and should never be assumed.
What is the threshold-report rule?+
Individual operations of at least USD 10,000 and multiple operations reaching that amount for the same beneficiary within a month are reported within the first 15 days of the following month, subject to any lower sector threshold.
What if there is no ROS or threshold report?+
NO ROS and NO RESU must be registered in UAFE's reporting system within 10 business days after the end of each month in which no corresponding report exists.
How is beneficial ownership determined?+
For a legal person, the law uses at least 10% capital, control through other means, and then the highest-ranking managing official fallback. Trust and arrangement parties are traced to natural persons.
How long are AML records retained?+
CDD, transaction, analysis, account and business-correspondence records with documentary support are retained for 10 years after relationship termination, the last transaction or the occasional transaction, as applicable. Transfer originator and beneficiary data is also retained for 10 years.
Do payment and fintech services require authorization?+
Yes when they fall within a reserved or regulated role. UAFE reporting status does not replace the BCE, Superintendencia de Bancos or other sector authorization.
Are virtual-asset service providers reporting entities?+
Yes. The perimeter covers business activity involving fiat/virtual-asset or virtual-asset exchanges, transfers, custody or control instruments, and financial services related to an issuer's offer or sale. PSAVs are supervised by the Superintendencia de Bancos for AML/CFT/CPF and maintain a UAFE code, while any activity-specific permission is separate. The four-day ROS and 15-day nil-report deadlines in the 2022 designation instrument are displaced by the 2024 Law and current UAFE rules.
What privacy deadlines apply to a qualifying breach?+
The controller notifies SPDP and ARCOTEL no later than five business days, the processor notifies the controller within two business days, and affected persons are notified within three business days when their rights are at risk.
Is Ecuador on a FATF public list?+
Ecuador was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026. This does not replace a risk-based country assessment.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector rules, UAFE resolutions, SISLAFT manuals or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, supervisor, reporting calendar, technical structure, licensing perimeter, privacy role and later developments with qualified Ecuadorian counsel and the relevant authority before launch.