Eswatini KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Eswatini.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Eswatini compliance checklist cover?
The Eswatini checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Eswatini Financial Intelligence Centre (EFIC)
- Primary AML law
- Act No. 6 of 2011, amended in 2016 and 2024
- STR timing
- Promptly - defined by the 2024 amendment as as soon as possible, no later than 5 days
- Cash reporting
- E25,000 or more, including qualifying same-day aggregation; within 2 working days
- Core retention
- At least 5 years from the statutory trigger; longer on authority request
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Eswatini compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the accountable-institution category, supervisor and product permission before launch.3 items+
Determine whether each entity and activity is an accountable institution.
- Implementation action
- Map each product, entity and channel to Schedule 3 and document the competent AML supervisor; distinguish CBE-regulated banking, remittance and payment activity from FSRA and other sectors.
- Evidence to retain
- Perimeter memo, Schedule 3 mapping and supervisor confirmation.
- Primary citation
- MLTFP Act 2011, sections 2 and 3 and Schedule 3, as amended in 2016 and 2024
Register and maintain reporting access with EFIC.
- Implementation action
- Complete the current accountable-institution registration process, nominate authorised contacts and test access to the applicable EFIC reporting workspace before accepting customers.
- Evidence to retain
- Registration confirmation, authorised-user list and access test.
- Primary citation
- MLTFP Act, sections 19 and 31; EFIC compulsory-registration directive and reporting portal
Obtain activity-specific financial permission.
- Implementation action
- Confirm CBE, FSRA or other sector approval for banking, remittance, payment, mobile-money, insurance, securities, credit and virtual-asset activity; sandbox participation is not a production licence.
- Evidence to retain
- Licence analysis, application, approval and conditions register.
- Primary citation
- Financial Institutions Act 2005; National Payment Systems Act 2023; MLTFP Act section 18bis as amended in 2024; applicable FSRA laws
02Governance and risk assessmentControls must be risk-based, resourced and demonstrable.3 items+
Identify, understand and mitigate ML, TF and PF risk.
- Implementation action
- Maintain an approved assessment covering customers, products, geography, transactions, delivery channels, new technology and national risk findings; refresh it on material change.
- Evidence to retain
- Methodology, assessment, approvals and change log.
- Primary citation
- MLTFP Act sections 6, 6ter and 6quat, as amended in 2024
Maintain accountable compliance governance.
- Implementation action
- Appoint an AML reporting officer, resource the control function, train relevant staff, independently test the programme and track remediation.
- Evidence to retain
- Appointment, policies, training records, audit plan and remediation log.
- Primary citation
- MLTFP Act section 18; CBE Financial Integrity supervision materials
Control group, branch and third-party reliance.
- Implementation action
- Apply group-wide AML/CFT programmes, protect shared information, address stricter Eswatini requirements in foreign operations and retain ultimate responsibility for relied-on CDD and records.
- Evidence to retain
- Group policy, transfer controls, third-party diligence and retrieval tests.
- Primary citation
- MLTFP Act sections 6(6), 6septies, 8(7)-(8) and 18(2bis)-(2ter), as amended
03Natural-person identificationIdentify and verify before or during every statutory trigger.3 items+
Identify and verify customers, beneficial owners and representatives.
- Implementation action
- Use reliable independent sources to verify the customer, every beneficial owner and anyone acting for the customer; authenticate authority before access or execution.
- Evidence to retain
- Identity record, verification provenance, mandate and result.
- Primary citation
- MLTFP Act section 6bis(1)-(2), as amended in 2024
Apply CDD to relationships, transactions, electronic transfers, suspicion and doubts.
- Implementation action
- Configure triggers for entering or continuing a relationship, any transaction without a relationship, electronic funds transfers, suspicion, and doubts about earlier identification; do not reuse the former E2,500 occasional-transaction exemption removed in 2024.
- Evidence to retain
- Trigger logic, completed CDD file and exception log.
- Primary citation
- MLTFP Act section 6bis(1) and 2024 amendment sections 3 and 7
Do not proceed when CDD cannot be completed.
- Implementation action
- Do not open or maintain the account, start the relationship or perform the transaction; terminate where required and file an STR, unless continuing CDD would tip off the customer, in which case stop that process and report promptly.
- Evidence to retain
- Failure decision, termination record, STR and restricted-access chronology.
- Primary citation
- MLTFP Act sections 6bis(2bis) and 13bis, inserted in 2024
04KYB, registries, and beneficial ownershipLegal existence and natural-person control require separate proof.3 items+
Understand and verify each legal person or arrangement.
- Implementation action
- Obtain name, legal form, nature of business, proof of existence, registered and principal addresses, directors, binding powers, owners, beneficiaries and control structure; verify representatives.
- Evidence to retain
- Registry evidence, constitution, licences, powers and reconciliation.
- Primary citation
- MLTFP Act section 6bis(2)(c), as amended in 2024
Trace beneficial ownership through ownership and other control.
- Implementation action
- Identify and verify natural persons who ultimately own or control directly or indirectly, including through a chain or other means; if none is identified, verify senior management and record the basis.
- Evidence to retain
- Ownership and control chart, source records, identities and fallback rationale.
- Primary citation
- MLTFP Act sections 2 and 6bis(1), as amended in 2024
Apply the legal-arrangement tests.
- Implementation action
- For trusts and similar arrangements identify and verify settlors, trustees, protectors, beneficiaries or classes and every other natural person exercising ultimate effective control.
- Evidence to retain
- Trust instrument, party identities, control analysis and reliable-source checks.
- Primary citation
- MLTFP Act definition of beneficial owner and sections 6bis(2quin) and 6sext, inserted in 2024
05PEPs, EDD, and remote onboardingHigher-risk and non-face-to-face cases need enhanced, documented controls.3 items+
Detect domestic, foreign and international-organisation PEP exposure.
- Implementation action
- Screen customers, beneficial owners and connected persons at onboarding and throughout the relationship, including existing customers who become PEPs.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- MLTFP Act section 2 PEP definition and section 6bis(2)(c)-(d), as amended in 2024
Apply approval, wealth, funds and enhanced monitoring controls.
- Implementation action
- Obtain senior-management approval, establish source of wealth and source of funds and conduct enhanced ongoing monitoring for PEPs and other higher-risk areas.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- MLTFP Act sections 6bis(2)(d), 6bis(2ter)-(2quat) and 6ter
Assess remote onboarding and new technology before use.
- Implementation action
- Document identity, impersonation, device, fraud, cybersecurity, privacy and ML/TF/PF risks before launch; use proportionate liveness and exception controls and confirm supervisor expectations.
- Evidence to retain
- Pre-launch assessment, tests, approval and exceptions.
- Primary citation
- MLTFP Act section 6(1), as amended in 2024; Data Protection Act 2022 sections 14-17
06Monitoring and suspicious reportingReporting must be prompt, confidential and reconstructable.3 items+
Conduct ongoing due diligence and transaction monitoring.
- Implementation action
- Test activity against customer knowledge, commercial activity, risk profile and source of funds; investigate inconsistencies and refresh CDD.
- Evidence to retain
- Alerts, investigation, disposition and profile refresh.
- Primary citation
- MLTFP Act section 11, substituted in 2024
Report suspicious transactions, attempts and relevant information promptly.
- Implementation action
- File with EFIC as soon as possible and no later than five days after suspicion forms; include grounds and attempted activity. Use the current authorised workspace and do not use email where the 2025 SharePoint directive applies.
- Evidence to retain
- Decision log, STR, submission proof and receipt.
- Primary citation
- MLTFP Act sections 2 and 12, as amended in 2024; EFIC STR Directive 01/2025
Prevent tipping off and protect reporting information.
- Implementation action
- Restrict report and inquiry access, avoid customer disclosure, and stop CDD that would tip off while filing the required STR.
- Evidence to retain
- Access controls, logs, escalation procedure and training.
- Primary citation
- MLTFP Act sections 13bis, 15, 16 and 30
07Payments, wires, thresholds, and agentsKeep cash reporting distinct from CDD and wire-transfer rules.3 items+
Report qualifying cash of E25,000 or more.
- Implementation action
- File a CTR within two working days for physical cash received or paid at or above E25,000, including qualifying same-direction aggregation within one calendar day; monitor structuring separately for suspicion.
- Evidence to retain
- Aggregation logic, CTR, transmission proof and review samples.
- Primary citation
- MLTFP Act section 12bis; EFIC Cash Threshold Reporting Guideline, effective 1 October 2024
Carry complete originator and beneficiary information on wires.
- Implementation action
- Collect, verify, transmit and retain required payer and payee information; use risk-based rules to execute, reject or suspend deficient transfers and follow up missing data.
- Evidence to retain
- Payment messages, validation rules, exception decisions and records.
- Primary citation
- MLTFP Act sections 7 and 10, substituted in 2024
Apply licence, agent and transfer controls to payments and virtual assets.
- Implementation action
- Obtain CBE or other competent approval, diligence agents and outsourcers, preserve record access, and apply the 2024 originator, beneficiary, screening and freezing rules to virtual-asset transfers; confirm the operative VASP licensing framework before launch.
- Evidence to retain
- Permission, contracts, monitoring, travel-rule records and authority confirmation.
- Primary citation
- National Payment Systems Act 2023; MLTFP Act sections 7(18)-(19), 18bis(d) and 18ter, inserted in 2024
08Targeted financial sanctionsUse current lists and act within the domestic 24-hour definition of without delay.3 items+
Screen UN and EFIC sanctions updates continuously.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions against the current UN consolidated list and EFIC updates, with event-driven rescreening.
- Evidence to retain
- List inventory, update timestamps, configuration and dispositions.
- Primary citation
- Anti-Money Laundering (UNSCR) Regulations 2016; EFIC TFS directives; UN consolidated list
Freeze and prohibit designated dealings without delay.
- Implementation action
- For a confirmed designation, apply the domestic freeze and transaction prohibition within 24 hours, preserve timestamps and do not wait for ordinary transaction processing.
- Evidence to retain
- Match analysis, freeze record, timestamps and blocked-transaction log.
- Primary citation
- MLTFP Act section 2 definition of without delay and section 7(17)-(18), as amended in 2024; UNSCR Regulations 2016
Report and govern false positives, exemptions and release.
- Implementation action
- Follow the current EFIC and UNSCR Implementation Committee route, document the legal basis for each hold or release, and act only on competent authority.
- Evidence to retain
- Report, authority correspondence, exemption or release decision and reconciliation.
- Primary citation
- UNSCR Regulations 2016, including regulations 4, 20-21, 29 and 31-32; current EFIC TFS directive
09Records and regulator accessRecords must reconstruct customers, ownership, transactions and decisions.3 items+
Retain the full statutory record set for at least five years.
- Implementation action
- Keep CDD, account files, business correspondence, transactions, analysis, reports and FIU enquiries for at least five years from the applicable identity, transaction, account-closure or relationship-cessation trigger.
- Evidence to retain
- Schedule, archive sample, trigger mapping and deletion control.
- Primary citation
- MLTFP Act section 8(1)-(2), including paragraph (e) inserted in 2024
Extend records when a competent authority requires it.
- Implementation action
- Suspend disposal for specified records on an EFIC, law-enforcement or supervisor request and retain ultimate responsibility where storage is outsourced.
- Evidence to retain
- Hold notice, custodian instructions and retrieval test.
- Primary citation
- MLTFP Act section 8(6)-(8)
Produce records immediately and securely.
- Implementation action
- Authenticate requests, protect STR confidentiality, export reproducibly and log scope, timing and acknowledgement.
- Evidence to retain
- Request, approval, production index and receipt.
- Primary citation
- MLTFP Act section 8(3)-(5)
10Privacy, biometrics, and transfersReconcile AML duties with the Data Protection Act 2022.3 items+
Use a lawful basis, notice, minimisation and retention controls.
- Implementation action
- Document the legal basis and purpose for each identity-data use, provide required collection information, collect only adequate and relevant data and delete or de-identify when no longer authorised, subject to AML holds.
- Evidence to retain
- Data inventory, legal-basis map, notice and retention schedule.
- Primary citation
- Data Protection Act 2022 sections 9-13
Secure sensitive and biometric information and processors.
- Implementation action
- Identify foreseeable risk, apply and test reasonable safeguards, restrict sensitive-data processing and bind processors by written confidentiality and security obligations.
- Evidence to retain
- Risk assessment, security tests, access matrix and processor contract.
- Primary citation
- Data Protection Act 2022 sections 14-16 and 22-31
Notify compromises and control cross-border transfers.
- Implementation action
- Notify the Commission and affected data subjects as soon as reasonably possible when unauthorised access or acquisition is reasonably believed; assess SADC necessity or non-SADC adequacy and document any statutory derogation or Commission authorisation.
- Evidence to retain
- Incident chronology, notices, transfer assessment and safeguards.
- Primary citation
- Data Protection Act 2022 sections 17 and 32-33
11Practical evidence packsMaintain compact evidence that reproduces regulated decisions.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy notices and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting MLTFP Act sections 6-8 and Data Protection Act sections 9-16
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, CTRs, STRs, sanctions actions and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting MLTFP Act sections 8 and 11-16
Primary-source register
14 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Money Laundering and Financing of Terrorism (Prevention) Act No. 6 of 2011 - consolidated issueGovernment of Eswatini · Primary legislation
- Money Laundering and Financing of Terrorism (Prevention) (Amendment) Act No. 5 of 2016Government of Eswatini Gazette · Primary legislation
- Anti-Money Laundering, Counter Financing of Terrorism and Proliferation Financing (Miscellaneous Amendments) Act 2024Government of Eswatini / EFIC · Primary legislation
- Anti-Money Laundering (United Nations Security Council Resolutions) Regulations 2016Government of Eswatini Gazette · Primary regulations
- Cash Threshold Reporting Guideline - September 2024Eswatini Financial Intelligence Centre · Official regulatory guidance
- STR Directive 01/2025 - mandatory SharePoint filingEswatini Financial Intelligence Centre · Official regulatory directive
- EFIC compliance guidance and current directivesEswatini Financial Intelligence Centre · Official regulator portal
- Eswatini fourth enhanced follow-up report - August 2025FATF / ESAAMLG · Authoritative country assessment
- Eswatini mutual evaluation report - June 2022ESAAMLG / EFIC · Authoritative country assessment
- Data Protection Act 2022Government of Eswatini Gazette · Primary legislation
- Financial Regulation and Financial Integrity DivisionCentral Bank of Eswatini · Official regulator guidance
- National Payment Systems and licensed payment service providersCentral Bank of Eswatini · Official regulator guidance
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Eswatini KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Eswatini Financial Intelligence Centre (EFIC). Accountable institutions should use their current authorised EFIC workspace; the April 2025 directive discontinued email filing for the institutions within its scope.
When is an STR required?+
Promptly after suspicion forms. The 2024 amendment defines promptly as urgent action as soon as possible but no later than five days. Attempted transactions and relevant TF/PF information are included.
What is the cash-reporting threshold?+
Physical cash received or paid at E25,000 or more, including qualifying same-direction aggregation within a calendar day, reported within two working days under the September 2024 EFIC guideline.
Is there a general occasional-transaction CDD exemption?+
No threshold exemption should be configured from the former E2,500 rule: the 2024 amendment deleted the statutory definition of occasional transaction and replaced the CDD triggers.
How is beneficial ownership handled?+
Trace natural persons who ultimately own or control directly or indirectly, including control other than ownership. If no beneficial owner is identified, verify senior management and document the basis. Trust parties have express tests.
How long are AML records retained?+
At least five years from the applicable identity, transaction, account-closure or relationship-cessation trigger, and longer for specified records when EFIC, law enforcement or a supervisor requires it.
Is Eswatini on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. This is not a low-risk finding.
Can payment or virtual-asset services launch without a licence?+
No. Obtain the activity-specific CBE, FSRA or other competent approval. The 2024 law creates VASP control and travel-rule duties, but the current operative licensing mechanics must be confirmed before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 August 2026. Confirm current EFIC portal access and directives, gazetted thresholds, supervisor rules, company and beneficial-ownership filing mechanics, sanctions updates, product permissions and data-protection procedures with the competent authority and qualified Eswatini counsel before launch.