Guinea KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Guinea.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Guinea compliance checklist cover?
The Guinea checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Cellule Nationale de Traitement des Informations Financieres (CENTIF)
- Primary AML law
- Law L/2021/0024/AN of 17 August 2021
- Suspicion reporting
- Immediately to CENTIF, including attempts, regardless of amount
- Objective reports
- Cash and cross-border-wire thresholds require a current BCRG instruction
- Core retention
- 10 years after relationship end or occasional transaction
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Guinea compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the entity, activity and supervisor before launch.3 items+
Determine whether each activity is a reporting entity.
- Implementation action
- Map each entity, product, channel and agent to the financial-institution, DNFBP, virtual-asset or covered public-authority categories and identify CENTIF and the competent supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- Law L/2021/0024/AN, Articles 5-9 and 56
Treat CENTIF as Guinea's financial intelligence unit.
- Implementation action
- Appoint authorised correspondents, obtain CENTIF's current filing route and prescribed form, and test controlled access before operations begin.
- Evidence to retain
- Correspondent appointment, channel test, procedure and access approvals.
- Primary citation
- Law L/2021/0024/AN, Articles 75-94
Obtain authorisation before regulated financial activity.
- Implementation action
- Classify banking, inclusive finance, payment, e-money, transfer, exchange, insurance, securities and virtual-asset activities and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, authority correspondence and licence register.
- Primary citation
- Law L/2021/0024/AN, Articles 20 and 42; applicable BCRG and sector laws
02Governance and risk assessmentThe programme must be documented, risk-based and independently tested.3 items+
Maintain an enterprise-wide ML/TF risk assessment.
- Implementation action
- Assess customers, products, channels, geography, cash, agents, technology, virtual assets and proliferation exposure and update the assessment on material change.
- Evidence to retain
- Approved methodology, assessment, controls and version history.
- Primary citation
- Law L/2021/0024/AN, Articles 21-23
Maintain written controls and an empowered compliance function.
- Implementation action
- Assign senior accountability and confidential CENTIF reporting authority; maintain screening, recruitment, training and independent audit controls proportionate to risk.
- Evidence to retain
- Appointments, policies, training, testing and remediation log.
- Primary citation
- Law L/2021/0024/AN, Articles 50-53; BCRG Instruction No. 109
Assess new technology before use.
- Implementation action
- Identify and mitigate ML/TF, fraud, cybersecurity and privacy risks before launching a new product, distribution mechanism or technology.
- Evidence to retain
- Pre-launch assessment, approval, tests and residual-risk acceptance.
- Primary citation
- Law L/2021/0024/AN, Article 23; Law L/2016/037/AN
03Natural-person identificationCDD uses reliable independent evidence and continues through the relationship.3 items+
Identify and verify customers and representatives.
- Implementation action
- Verify the customer using reliable independent information; identify anyone acting for the customer and verify identity and authority.
- Evidence to retain
- Identity file, source provenance, mandate and verification result.
- Primary citation
- Law L/2021/0024/AN, Articles 25-26
Understand purpose and expected activity.
- Implementation action
- Record relationship purpose, products, expected volumes, counterparties, geography and source of funds sufficient for risk rating and monitoring.
- Evidence to retain
- Customer profile, expected-activity baseline and approval.
- Primary citation
- Law L/2021/0024/AN, Article 26
Do not proceed where mandatory CDD fails.
- Implementation action
- Do not open or execute, or terminate as applicable, when required CDD cannot be completed; consider a confidential suspicious-operation report.
- Evidence to retain
- Decline or exit decision, investigation and restricted reporting record.
- Primary citation
- Law L/2021/0024/AN, Articles 32-33
04KYB, registries, and beneficial ownershipRegistry evidence does not replace natural-person ownership and control analysis.3 items+
Verify legal existence, governance and authority.
- Implementation action
- Obtain current RCCM, constitutional, address, director, signatory, tax and licence evidence and reconcile inconsistencies.
- Evidence to retain
- RCCM extract, statutes, powers, tax record and licence file.
- Primary citation
- Law L/2021/0024/AN, Article 27; OHADA Uniform Acts
Identify natural-person beneficial owners through ownership, control and fallback tests.
- Implementation action
- Identify natural persons with ultimate controlling interests, then control by other means, and use the principal-manager fallback only where no person is identified under the first two tests.
- Evidence to retain
- Ownership chart, source records, control analysis and verified identities.
- Primary citation
- Law L/2021/0024/AN, Article 27(3)
Treat company and beneficial-owner records as corroboration.
- Implementation action
- Obtain and reconcile available RCCM and company-held beneficial-owner information; record gaps and do not assume a fully operational central register.
- Evidence to retain
- Registry extracts, company records, discrepancy log and escalation.
- Primary citation
- OHADA company and RCCM framework; GIABA Guinea MER 2023
05PEPs, EDD, and remote onboardingHigher-risk and remote relationships require enhanced controls.3 items+
Detect PEP exposure in customers and beneficial owners.
- Implementation action
- Use appropriate systems to identify domestic, foreign and international-organisation PEP exposure and connected-person risk.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Law L/2021/0024/AN, Articles 35-37
Apply PEP approval, provenance and monitoring measures.
- Implementation action
- Obtain senior-management approval, take reasonable measures to establish source of wealth and funds, and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Law L/2021/0024/AN, Article 36
Control non-face-to-face and biometric risk.
- Implementation action
- Apply enhanced identity, fraud, device, liveness, sensitive-data and exception controls proportionate to the remote channel and data used.
- Evidence to retain
- Remote-onboarding assessment, impact review, tests and exceptions.
- Primary citation
- Law L/2021/0024/AN, Article 34; Law L/2016/037/AN
06Monitoring and suspicious reportingCENTIF reporting is immediate, traceable and confidential.3 items+
Monitor activity against the current customer profile.
- Implementation action
- Examine unusual, complex, linked or apparently purposeless activity and preserve a reasoned conclusion.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- Law L/2021/0024/AN, Articles 26 and 39
Report suspicion and attempted suspicious operations immediately to CENTIF.
- Implementation action
- File immediately when funds or property are suspected, or reasonably suspected, to be criminal proceeds or linked to terrorist financing, including attempts regardless of amount, using CENTIF's current form and route.
- Evidence to retain
- Decision chronology, report, receipt and supplemental-information log.
- Primary citation
- Law L/2021/0024/AN, Articles 45 and 87
Prevent tipping off.
- Implementation action
- Restrict access and do not disclose a suspicious-operation report or related CENTIF information to the customer or unauthorised third parties.
- Evidence to retain
- Access logs, confidentiality procedure and training.
- Primary citation
- Law L/2021/0024/AN, Articles 49 and 94
07Payments, wires, thresholds, and agentsPayment controls preserve required data and apply only verified thresholds.3 items+
Apply objective reporting only at currently prescribed thresholds.
- Implementation action
- Obtain the current BCRG instruction and CENTIF method before configuring cash and cross-border-wire reporting; aggregate as the instrument requires and retain the legal basis.
- Evidence to retain
- Current instruction, configuration, filings and receipts.
- Primary citation
- Law L/2021/0024/AN, Article 46
Preserve required wire-transfer information.
- Implementation action
- Carry required originator and beneficiary information through the payment chain and risk-govern missing or incomplete information.
- Evidence to retain
- Message samples, validation rules, exceptions and escalation.
- Primary citation
- Law L/2021/0024/AN, Articles 40-43
Retain accountability for agents and outsourcing.
- Implementation action
- Verify permissions, diligence providers, contract for security and record access, train agents, monitor compliance and test retrieval.
- Evidence to retain
- Due diligence, contract, training, monitoring and retrieval test.
- Primary citation
- Law L/2021/0024/AN, Article 50(2); applicable BCRG sector rules
08Targeted financial sanctionsUse current UN designations and Guinea's controlled legal process.3 items+
Screen applicable UN and national designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, list updates and before relevant execution.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- Law L/2021/0024/AN, Articles 20 and 44; UN consolidated list
Freeze covered property without delay or prior notice.
- Implementation action
- Prevent prohibited movement or availability of covered funds and economic resources and escalate immediately under the current competent-authority process.
- Evidence to retain
- Freeze procedure, timestamps, legal basis and authority communication.
- Primary citation
- Law L/2021/0024/AN, Articles 20 and 44
Report and govern matches, false positives and release.
- Implementation action
- Use the current national reporting and challenge process, file a suspicious-operation report where warranted, and release only on documented lawful authority.
- Evidence to retain
- Reports, receipt, match rationale, authority instruction and reconciliation.
- Primary citation
- Law L/2021/0024/AN, Articles 20, 44-45
09Records and regulator accessRecords must reconstruct the customer, ownership, transaction and decision.3 items+
Retain CDD and transaction records for 10 years.
- Implementation action
- Retain CDD, account, correspondence, analysis and transaction records for 10 years after relationship end or the occasional transaction, subject to longer legal holds.
- Evidence to retain
- Schedule, configuration, archive sample and legal-hold log.
- Primary citation
- Law L/2021/0024/AN, Article 54
Make transaction records reconstructable.
- Implementation action
- Preserve sufficient detail to reconstruct individual domestic and international operations and associated decisions.
- Evidence to retain
- Transaction reconstruction and retrieval test.
- Primary citation
- Law L/2021/0024/AN, Article 54(2)
Respond securely to competent-authority requests.
- Implementation action
- Authenticate requests, protect reporting confidentiality, produce reproducibly and log scope, timing and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- Law L/2021/0024/AN, Articles 47, 54-55 and 88
10Privacy, biometrics, and transfersPersonal-data duties apply alongside AML confidentiality and retention.3 items+
Document lawful and transparent identity processing.
- Implementation action
- Map purposes, data, legal basis, notices, rights, recipients, security and retention and complete currently required declarations or authorisations.
- Evidence to retain
- Data inventory, legal assessment, notices and authority record.
- Primary citation
- Law L/2016/037/AN, personal-data provisions
Apply enhanced safeguards to biometric and sensitive data.
- Implementation action
- Minimise collection, restrict access, test security and document an applicable statutory basis before biometric or sensitive-data use.
- Evidence to retain
- Impact assessment, legal basis, security tests and approval.
- Primary citation
- Law L/2016/037/AN
Control processors, incidents and cross-border transfers.
- Implementation action
- Bind processors, preserve confidentiality and security, and obtain current authority guidance before configuring transfers or incident notices; do not invent a portal or deadline.
- Evidence to retain
- Processor contract, transfer assessment, incident procedure and authority guidance.
- Primary citation
- Law L/2016/037/AN
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervisory access.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Law L/2021/0024/AN
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Law L/2021/0024/AN, Articles 45-49 and 87-94
Primary-source register
10 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law L/2021/0024/AN on AML/CFTBCRG · Primary national legislation
- BCRG Instruction No. 109 applying the AML/CFT law to financial institutionsBCRG · Primary supervisory instruction
- BCRG AML/CFT application instruction for inclusive financial institutionsBCRG · Primary supervisory instruction
- Guinea second enhanced follow-up report - November 2025GIABA · Authoritative country assessment
- Guinea mutual evaluation materialsGIABA · Authoritative country assessment
- BCRG compliance and supervisory materialsBCRG · Official regulator materials
- Law L/2016/037/AN on cybersecurity and personal dataSupreme Court of Guinea · Primary national legislation
- OHADA commercial companies and RCCM frameworkOHADA · Official company-law materials
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Guinea KYC, KYB and AML questions
Who receives suspicious-operation reports?+
Guinea's Cellule Nationale de Traitement des Informations Financieres (CENTIF). Obtain and use CENTIF's current prescribed route and form.
When is suspicion reported?+
Immediately when the institution suspects or has reasonable grounds to suspect criminal proceeds or terrorist-financing links, including attempts regardless of amount.
Are there objective threshold reports?+
Article 46 covers cash and cross-border-wire reports, but leaves thresholds to BCRG instruction and methods to CENTIF. Verify the current instruments before configuration.
How is beneficial ownership determined?+
Article 27 follows ultimate controlling ownership, control by other means and principal-manager fallback; no fixed ownership percentage should be invented for this CDD test.
How long are AML records retained?+
Ten years after relationship end or the occasional transaction under Article 54, subject to longer legal holds.
Is Guinea on a FATF public list?+
Guinea was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. It remains in GIABA enhanced follow-up.
Does personal-data law apply?+
Yes. Law L/2016/037/AN applies to personal-data processing. Confirm current authority, declaration, authorisation, transfer and incident mechanics before production use.
Can a financial or payment product launch without approval?+
No. Classify the activity under current Guinean sector rules and obtain every BCRG or other competent-authority approval before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 27 August 2026. Confirm reporting-entity status, current CENTIF filing specifications, BCRG thresholds and sector instructions, beneficial-owner register implementation, targeted-sanctions workflow, personal-data authority formalities and product permissions with the competent authority and qualified Guinean counsel before launch.