Guinea-Bissau KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Guinea-Bissau.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Guinea-Bissau compliance checklist cover?
The Guinea-Bissau checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Cellula Nacional de Tratamento de Informacoes Financeiras (CENTIF-GB)
- Primary AML law
- Law No. 3/2018 of 6 August 2018
- Suspicion reporting
- Without delay to CENTIF-GB; written or traceable, with 48-hour written confirmation where required
- Cash and transfer reports
- Thresholds depend on current BCEAO instructions
- Core retention
- 10 years after relationship end or transaction execution
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Guinea-Bissau compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the applicable law, entity, activity and supervisor before launch.3 items+
Determine whether each activity is a reporting entity.
- Implementation action
- Map every entity, product, channel and agent to the financial-institution, DNFBP or other covered categories and identify CENTIF-GB and the competent national or UMOA supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- Law No. 3/2018, Articles 5-6
Treat CENTIF-GB as the financial intelligence unit.
- Implementation action
- Appoint authorised correspondents, obtain the current filing form and route, and test controlled access before operations begin.
- Evidence to retain
- Correspondent appointment, channel test, procedure and access approvals.
- Primary citation
- Law No. 3/2018, Articles 59-64 and 79-82
Obtain authorisation before regulated activity.
- Implementation action
- Classify banking, payment, e-money, transfer, exchange, microfinance, insurance, securities, DNFBP and virtual-asset activities and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, authority correspondence and licence register.
- Primary citation
- Law No. 3/2018, Articles 87-88; applicable UMOA, BCEAO and sector rules
02Governance and risk assessmentThe programme must be risk-based, documented and independently tested.3 items+
Maintain an enterprise-wide ML/TF risk assessment.
- Implementation action
- Assess customers, products, channels, geography, cash, agents, technology and proliferation exposure and update on material change.
- Evidence to retain
- Approved methodology, assessment, controls and version history.
- Primary citation
- Law No. 3/2018, Articles 10-11 and 90
Maintain written controls and an empowered compliance function.
- Implementation action
- Assign senior accountability and confidential CENTIF-GB reporting authority; maintain screening, training, recruitment and independent-audit controls proportionate to risk.
- Evidence to retain
- Appointments, policies, training, testing and remediation log.
- Primary citation
- Law No. 3/2018, Articles 11 and 24
Assess new technology before use.
- Implementation action
- Identify and mitigate ML/TF, fraud, security and privacy risks before launching new products, delivery mechanisms or technologies.
- Evidence to retain
- Pre-launch assessment, approval, tests and residual-risk acceptance.
- Primary citation
- Law No. 3/2018, Article 37
03Natural-person identificationCDD uses reliable evidence and continues through the relationship.3 items+
Identify and verify customers and representatives.
- Implementation action
- Verify the customer with reliable documents or information; identify any representative and verify identity and authority.
- Evidence to retain
- Identity file, source provenance, mandate and verification result.
- Primary citation
- Law No. 3/2018, Articles 18 and 25-28
Understand purpose and expected activity.
- Implementation action
- Record relationship purpose, products, expected volumes, counterparties, geography and source of funds sufficient for risk rating and monitoring.
- Evidence to retain
- Customer profile, expected-activity baseline and approval.
- Primary citation
- Law No. 3/2018, Articles 19-20
Do not proceed where mandatory CDD fails.
- Implementation action
- Do not open or execute, or terminate as applicable, when required identity or beneficial-owner information cannot be completed; consider confidential reporting.
- Evidence to retain
- Decline or exit decision, investigation and restricted reporting record.
- Primary citation
- Law No. 3/2018, Articles 28-29 and 79
04KYB, registries, and beneficial ownershipRegistry evidence does not replace natural-person ownership and control analysis.3 items+
Verify legal existence, governance and authority.
- Implementation action
- Obtain current RCCM, constitutional, address, director, signatory, tax and licence evidence and reconcile inconsistencies.
- Evidence to retain
- RCCM extract, statutes, powers, tax record and licence file.
- Primary citation
- Law No. 3/2018, Articles 25-27; OHADA Uniform Acts
Identify natural-person beneficial owners using the statutory test.
- Implementation action
- Identify persons holding directly or indirectly more than 25% of capital or voting rights and persons exercising control by other means; document the analysis for other legal arrangements.
- Evidence to retain
- Ownership chart, source records, control analysis and verified identities.
- Primary citation
- Law No. 3/2018, Article 1(12) and Article 29
Treat company and beneficial-owner records as corroboration.
- Implementation action
- Obtain and reconcile available RCCM, CFE and company-held information; record gaps and do not assume the central beneficial-owner fields are complete.
- Evidence to retain
- Registry extracts, company records, discrepancy log and escalation.
- Primary citation
- OHADA framework; GIABA 2022 MER; IMF Country Report 25/167
05PEPs, EDD, and remote onboardingPEPs, higher risk and remote relationships require enhanced controls.3 items+
Detect PEP exposure in customers and beneficial owners.
- Implementation action
- Use appropriate systems to identify foreign, domestic and international-organisation PEPs and connected-person risk.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Law No. 3/2018, Articles 22 and 54
Apply PEP approval, provenance and monitoring measures.
- Implementation action
- Obtain senior approval, take reasonable measures to establish source of wealth and funds, and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Law No. 3/2018, Article 54
Control non-face-to-face and biometric risk.
- Implementation action
- Apply enhanced identity, fraud, device, liveness, minimisation, security and exception controls proportionate to the remote channel and data used.
- Evidence to retain
- Remote-onboarding assessment, privacy review, tests and exceptions.
- Primary citation
- Law No. 3/2018, Article 21 and Article 37
06Monitoring and suspicious reportingCENTIF-GB reporting must be prompt, traceable and confidential.3 items+
Monitor activity against the customer profile.
- Implementation action
- Examine unusual, complex, linked or apparently purposeless activity and preserve a reasoned conclusion.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- Law No. 3/2018, Articles 19-20 and 32
Report suspicion without delay to CENTIF-GB.
- Implementation action
- Report amounts or operations suspected, or reasonably suspected, to involve ML/TF; where reporting by phone or electronic means, confirm in writing within 48 hours as Article 81 requires.
- Evidence to retain
- Decision chronology, report, written confirmation, receipt and supplement log.
- Primary citation
- Law No. 3/2018, Articles 79 and 81
Prevent tipping off.
- Implementation action
- Restrict access and do not disclose a report, its contents or CENTIF-GB follow-up to the customer or unauthorised third parties.
- Evidence to retain
- Access logs, confidentiality procedure and training.
- Primary citation
- Law No. 3/2018, Article 82
07Payments, wires, thresholds, and agentsPayment controls preserve required data and use only verified thresholds.3 items+
Apply cash and transfer reports only at current prescribed thresholds.
- Implementation action
- Obtain the current BCEAO instructions and CENTIF-GB method before configuring cash or fund-transfer reporting; aggregate only as the instrument requires.
- Evidence to retain
- Current instruction, configuration, filings and receipts.
- Primary citation
- Law No. 3/2018, Articles 13-15 and 79(7)
Preserve required wire-transfer information.
- Implementation action
- Carry required originator and beneficiary information through the payment chain and reject or risk-govern incomplete information as applicable.
- Evidence to retain
- Message samples, validation rules, exceptions and escalation.
- Primary citation
- Law No. 3/2018, Articles 33-34
Retain accountability for agents and outsourcing.
- Implementation action
- Verify permissions, diligence providers, contract for security and record access, train agents, monitor compliance and test retrieval.
- Evidence to retain
- Due diligence, contract, training, monitoring and retrieval test.
- Primary citation
- Law No. 3/2018, Articles 24, 52-53 and 87
08Targeted financial sanctionsUse current UN and applicable UMOA designations and controlled national procedures.3 items+
Screen applicable designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, list updates and before relevant execution.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- Law No. 3/2018, Articles 105-107; UN consolidated list
Freeze covered property without delay or prior notice.
- Implementation action
- Prevent prohibited movement or availability of covered funds and economic resources and escalate immediately under current national and UMOA procedures.
- Evidence to retain
- Freeze procedure, timestamps, legal basis and authority communication.
- Primary citation
- Law No. 3/2018, Articles 105-107; applicable UMOA instruments
Report and govern matches, false positives and release.
- Implementation action
- Use the current competent-authority process, file a suspicious-operation report where warranted, and release only on documented lawful authority.
- Evidence to retain
- Reports, receipt, match rationale, authority instruction and reconciliation.
- Primary citation
- Law No. 3/2018, Articles 79 and 105-107
09Records and regulator accessRecords must reconstruct the customer, ownership, transaction and decision.3 items+
Retain CDD and transaction records for ten years.
- Implementation action
- Retain identity records for ten years after account closure or relationship end and transaction records for ten years after execution, subject to longer legal holds.
- Evidence to retain
- Schedule, configuration, archive sample and legal-hold log.
- Primary citation
- Law No. 3/2018, Article 35
Make transaction records reconstructable.
- Implementation action
- Preserve sufficient account, transaction, correspondence, analysis and decision detail for competent-authority use.
- Evidence to retain
- Transaction reconstruction and retrieval test.
- Primary citation
- Law No. 3/2018, Articles 35-36
Respond securely to competent-authority requests.
- Implementation action
- Authenticate requests, protect reporting confidentiality, produce reproducibly and log scope, timing and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- Law No. 3/2018, Articles 36, 64-67 and 82
10Privacy, biometrics, and transfersApply constitutional confidentiality and security safeguards; confirm sector and implementing rules.3 items+
Document lawful and proportionate identity processing.
- Implementation action
- Map purposes, data, authority, notices, access, security and retention; confirm current Guinea-Bissau privacy and sector requirements before production use.
- Evidence to retain
- Data inventory, legal assessment, notices and approvals.
- Primary citation
- Constitution of Guinea-Bissau, privacy and communications guarantees; Law No. 3/2018, Articles 78 and 89-90
Apply enhanced safeguards to biometric and sensitive data.
- Implementation action
- Minimise collection, restrict access, test security and document a valid legal basis before biometric or sensitive-data use.
- Evidence to retain
- Impact assessment, legal basis, security tests and approval.
- Primary citation
- Constitutional privacy principles; applicable sector rules
Control processors, incidents and cross-border transfers.
- Implementation action
- Bind processors, preserve confidentiality and security, and obtain current authority or counsel confirmation before configuring transfers or incident notices; do not invent a portal or deadline.
- Evidence to retain
- Processor contract, transfer assessment, incident procedure and authority guidance.
- Primary citation
- Law No. 3/2018, Articles 78 and 89-91; applicable privacy and sector rules
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervisory access.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Law No. 3/2018
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Law No. 3/2018, Articles 79-82
Primary-source register
10 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 3/2018 on combating money laundering and terrorist financingProsecutor General's Office of Guinea-Bissau / Official Gazette · Primary national legislation
- 2023 UMOA uniform AML/CFT/CPF lawBCEAO · Primary regional legislative instrument - national enactment pending confirmation
- Guinea-Bissau mutual evaluation reportGIABA · Authoritative country assessment
- GIABA 2023 annual report - first Guinea-Bissau follow-upGIABA · Authoritative follow-up record
- GIABA 2024 annual reportGIABA · Authoritative follow-up status
- Guinea-Bissau 2025 Article IV consultationInternational Monetary Fund · Authoritative implementation-status source
- BCEAO Guinea-Bissau regulatory materialsBCEAO · Official financial regulator materials
- OHADA commercial companies and RCCM frameworkOHADA · Official company-law materials
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Guinea-Bissau KYC, KYB and AML questions
Who receives suspicious-operation reports?+
Guinea-Bissau's CENTIF-GB. Obtain its current prescribed route and form before production use.
When is suspicion reported?+
Without delay under Article 79. Article 81 requires traceable written transmission and written confirmation within 48 hours for reports initially made by phone or electronic means.
Are there cash or transfer thresholds?+
Yes, but Law No. 3/2018 leaves relevant thresholds to BCEAO instructions. Verify the current instruction and CENTIF-GB method before configuration.
How is company beneficial ownership determined?+
Law No. 3/2018 uses direct or indirect holdings above 25% of capital or voting rights, or control by other means. Reconcile this CDD analysis with available registry information.
How long are AML records retained?+
Ten years after account closure or relationship end for identity records, and ten years after execution for transaction records, under Article 35.
Is Guinea-Bissau on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026, but remains in GIABA enhanced follow-up.
Has the 2023 UMOA uniform law replaced Law No. 3/2018?+
Not on the latest authoritative national-implementation evidence reviewed for this edition. Confirm enactment with the Official Gazette, CENTIF-GB and counsel before relying on the transition.
Can a regulated financial or payment product launch without approval?+
No. Classify the activity under current national and UMOA rules and obtain every competent-authority approval before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 28 August 2026. Confirm enactment of the 2023 UMOA uniform law, current CENTIF-GB filing specifications, BCEAO thresholds, targeted-sanctions procedures, beneficial-owner registry operation, privacy requirements and product permissions with the competent authority and qualified Guinea-Bissau counsel before launch.