Lesotho KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Lesotho.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Lesotho compliance checklist cover?
The Lesotho checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Financial Intelligence Unit of Lesotho
- Primary AML rules
- MLPCA 2008 as amended; MLPCR 2019
- Suspicion reporting
- Immediately to the FIU; in any case no later than 7 days
- Thresholds
- Sector and transaction specific; do not use one universal amount
- Core AML retention
- At least 5 years after relationship end or occasional transaction
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Lesotho compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the accountable entity, activity and supervisor before launch.3 items+
Determine whether each activity is accountable.
- Implementation action
- Map every entity, product, channel and agent to the Act, the 2019 Regulations and applicable financial-institution, DNFBP or designated-business categories; identify the FIU and sector supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- MLPCA 2008, section 2 and Schedule 1; MLPCR 2019, regulations 1 and 22
Register with the FIU when the prescribed obligation applies.
- Implementation action
- Obtain the current FIU form and submission route; register within the applicable period and notify changes within 60 days without assuming an unverified portal.
- Evidence to retain
- Registration, receipt, change log and channel test.
- Primary citation
- MLPCR 2019, regulation 21
Obtain authorisation before regulated activity.
- Implementation action
- Classify banking, payments, e-money, money transfer, exchange, microfinance, insurance, securities, agent and virtual-asset activities and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, authority correspondence and licence register.
- Primary citation
- Financial Institutions Act 2012; Payment Systems Act 2014; applicable CBL and sector instruments
02Governance and risk assessmentControls must be risk-based, documented and independently tested.3 items+
Maintain a documented ML/TF risk assessment.
- Implementation action
- Assess customers, products, channels, geography, cash, agents, technology and proliferation exposure; apply enhanced measures where risk is higher and never simplify when suspicion exists.
- Evidence to retain
- Approved methodology, assessment, controls and version history.
- Primary citation
- MLPCR 2019, regulations 5 and 10
Maintain written controls and senior compliance ownership.
- Implementation action
- Designate a knowledgeable senior officer and maintain CDD, PEP, reporting, records, confidentiality, employee-screening and training controls proportionate to risk.
- Evidence to retain
- Appointment, policies, training, screening and remediation log.
- Primary citation
- MLPCR 2019, regulations 12-14
Independently test the programme.
- Implementation action
- Maintain an independent audit function and supervise branches, subsidiaries and representative offices for compliance.
- Evidence to retain
- Audit plan, reports, findings and closure evidence.
- Primary citation
- MLPCR 2019, regulation 15
03Natural-person identificationCDD uses reliable independent evidence and continues through the relationship.3 items+
Identify and verify the customer and representative.
- Implementation action
- Use reliable independent documents, data or information; verify any representative's identity and authority before reliance.
- Evidence to retain
- Identity file, source provenance, mandate and verification result.
- Primary citation
- MLPCR 2019, regulations 3 and 6; MLPCA 2008, sections 16-17
Understand purpose and expected activity.
- Implementation action
- Record relationship purpose, intended nature, expected volumes, counterparties, geography and source of funds sufficient for risk rating and monitoring.
- Evidence to retain
- Customer profile, expected-activity baseline and approval.
- Primary citation
- MLPCR 2019, regulation 4
Do not proceed where mandatory CDD fails.
- Implementation action
- Do not open or establish the relationship when identity, beneficial ownership, ownership/control structure or purpose cannot be completed; terminate existing relationships in the circumstances prescribed and consider confidential reporting.
- Evidence to retain
- Decline or exit decision, investigation and restricted reporting record.
- Primary citation
- MLPCR 2019, regulation 7
04KYB, registries, and beneficial ownershipCDD control analysis and company-register disclosure are related but distinct.3 items+
Verify legal existence, governance and authority.
- Implementation action
- Obtain a current company extract, incorporation and governing records, registered and principal addresses, directors, shareholders, signatories, licences and mandates; reconcile inconsistencies.
- Evidence to retain
- Registry extract, constitutional records, powers and discrepancy log.
- Primary citation
- MLPCR 2019, regulation 3(4); Companies Act 2011
Identify natural-person beneficial owners for CDD.
- Implementation action
- Identify the natural persons with controlling ownership, then control by other means, and use relevant senior management only when no natural person is identified through ownership or control; apply the trust and legal-arrangement tests separately.
- Evidence to retain
- Ownership chart, control analysis, verified identities and fallback rationale.
- Primary citation
- MLPCR 2019, regulation 6(5)-(6)
Apply the company-register test and deadlines separately.
- Implementation action
- For a Lesotho company, identify each natural person meeting any 2024 test, including direct or indirect ownership of more than 10% of shares or votes, appointment/removal power, influence or ultimate effective control; maintain and file confirmed particulars within the applicable 7-day periods and record changes.
- Evidence to retain
- Company BO register, identity evidence, filing receipt and change log.
- Primary citation
- Companies (Beneficial Ownership) Regulations 2024, regulations 3-8
05PEPs, EDD, and remote onboardingPEPs and higher-risk or remote relationships require enhanced controls.3 items+
Detect PEP exposure.
- Implementation action
- Use appropriate systems to identify domestic, foreign and international-organisation PEP exposure in customers, beneficial owners and connected persons.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- MLPCA 2008, section 2; MLPCR 2019, regulations 12 and Schedule 5
Apply enhanced approval, provenance and monitoring.
- Implementation action
- For PEP and other higher-risk relationships, obtain senior approval, establish source of wealth and funds to the extent required by risk, and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- MLPCR 2019, regulations 5 and 10; Schedule 5
Control remote and biometric onboarding.
- Implementation action
- Assess identity, impersonation, device, liveness, minimisation, sensitive-data and security risks before deployment; document a valid processing basis and exceptions.
- Evidence to retain
- Remote-onboarding assessment, privacy review, tests and approvals.
- Primary citation
- MLPCR 2019, regulations 5 and 12; Data Protection Act 2012, sections 15-22 and 29-37
06Monitoring and suspicious reportingFIU reporting must be immediate, complete and confidential.3 items+
Monitor activity against the customer profile.
- Implementation action
- Scrutinise transactions throughout the relationship for consistency with customer, business, risk and source-of-funds knowledge and investigate unusual activity.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- MLPCR 2019, regulation 4(b)
Report suspicion and attempts immediately.
- Implementation action
- Submit the prescribed report to the FIU immediately upon forming suspicion and in any case no later than 7 days, regardless of amount; include attempted transactions and explain any delay in writing.
- Evidence to retain
- Decision chronology, report, delay explanation if any, receipt and supplements.
- Primary citation
- MLPCR 2019, regulation 19(1)-(10)
Prevent tipping off.
- Implementation action
- Restrict access and do not disclose the report, its contents or filing; do not seek abnormal information from the customer in a way that would reveal the process.
- Evidence to retain
- Access logs, confidentiality procedure and training.
- Primary citation
- MLPCR 2019, regulation 19(11)-(14); MLPCA 2008, section 22
07Payments, wires, thresholds, and agentsThresholds are scoped by sector and instrument, not universal.3 items+
Configure only verified thresholds.
- Implementation action
- Apply the M25,000 casino and specified designated-business cash triggers and M100,000 precious-metal or precious-stone cash trigger only to their stated categories; obtain current FIU or supervisor instruments for any other prescribed threshold.
- Evidence to retain
- Legal mapping, configuration, test cases, filings and receipts.
- Primary citation
- MLPCR 2019, regulations 22-23
Preserve required wire-transfer information.
- Implementation action
- Carry complete originator and beneficiary information, monitor missing data, and reject, suspend or escalate incomplete transfers under the applicable ordering, intermediary and beneficiary rules.
- Evidence to retain
- Message samples, validation rules, exceptions and escalation.
- Primary citation
- MLPCR 2019, regulations 40-45
Retain accountability for agents and third parties.
- Implementation action
- Verify permissions, conduct due diligence, contract for confidentiality, security and prompt record access, and keep ultimate responsibility for relied-on CDD.
- Evidence to retain
- Due diligence, contract, monitoring and retrieval test.
- Primary citation
- MLPCR 2019, regulations 9 and 12; CBL Agent Banking Regulations 2024
08Targeted financial sanctionsUse current UN and communicated domestic lists under the statutory process.3 items+
Screen applicable designations.
- Implementation action
- Regularly obtain current UN lists and screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, list updates and before execution.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- MLPCR 2019, regulations 27(2)-(3) and 27(10)
Freeze covered property without delay or notice.
- Implementation action
- On a designation and freezing order, freeze covered funds or assets without delay and prior notice and prevent funds, assets, economic resources or services from being made available.
- Evidence to retain
- Freeze procedure, timestamps, legal basis and authority communication.
- Primary citation
- MLPCR 2019, regulations 28-30
Govern false positives, exceptions and release.
- Implementation action
- Escalate matches through the current FIU, supervisor or competent-authority process; permit access or release only on documented lawful authority and preserve the full rationale.
- Evidence to retain
- Reports, match rationale, authority instruction and reconciliation.
- Primary citation
- MLPCR 2019, regulations 31-33
09Records and regulator accessRecords must reconstruct the customer, transaction, ownership and decision.3 items+
Retain AML records for at least five years.
- Implementation action
- Retain CDD, account, correspondence, analysis and domestic or international transaction records for at least 5 years from relationship termination or the occasional transaction, and longer when directed for up to a further 5 years.
- Evidence to retain
- Schedule, configuration, archive sample and legal-hold log.
- Primary citation
- MLPCR 2019, regulation 11
Retain company BO history for the separate period.
- Implementation action
- Keep required company beneficial-owner information for at least 10 years after a person ceases to be a beneficial owner and preserve dissolved-company information as required.
- Evidence to retain
- BO history, filing records and retention test.
- Primary citation
- Companies (Beneficial Ownership) Regulations 2024, regulations 12-13
Respond securely to competent requests.
- Implementation action
- Authenticate requests, protect FIU-report confidentiality, produce records swiftly and reproducibly, and log scope, timing and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- MLPCR 2019, regulations 11 and 16-17
10Privacy, biometrics, and transfersIdentity processing must comply with the Data Protection Act and AML holds.3 items+
Document a lawful, minimal and transparent processing basis.
- Implementation action
- Map purpose, legal basis, data, notice, recipients, rights and retention; notify the Data Protection Commission before processing where section 25(5) applies.
- Evidence to retain
- Data inventory, legal assessment, notices and Commission record.
- Primary citation
- Data Protection Act 2012, sections 15-19 and 25
Protect data and govern processors and incidents.
- Implementation action
- Apply reasonable technical and organisational safeguards, bind agents by written confidentiality and security terms, and notify the Commission and affected subjects as soon as reasonably possible after a qualifying compromise.
- Evidence to retain
- Risk assessment, contracts, security tests and incident records.
- Primary citation
- Data Protection Act 2012, sections 20-23
Control sensitive data and cross-border processing.
- Implementation action
- Treat biometrics and other sensitive data under the Act's prohibitions and exceptions; document legal authority and take reasonable steps concerning an overseas agent's compliance before transfer or access.
- Evidence to retain
- Sensitive-data assessment, transfer analysis and approval.
- Primary citation
- Data Protection Act 2012, sections 22 and 29-37
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting MLPCR 2019, regulations 3-15
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting MLPCR 2019, regulation 19
Primary-source register
11 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Money Laundering and Proceeds of Crime Act 2008LesLII / Office of Parliamentary Counsel of Lesotho · Primary national legislation - consolidation notes outstanding 2016 amendment
- Money Laundering and Proceeds of Crime (Amendment) Act 2016LesLII / Office of Parliamentary Counsel of Lesotho · Primary amending legislation
- Money Laundering and Proceeds of Crime Regulations 2019LesLII / Office of Parliamentary Counsel of Lesotho · Primary national regulations
- Companies Act 2011LesLII / Office of Parliamentary Counsel of Lesotho · Primary company legislation
- Companies (Beneficial Ownership) Regulations 2024Lesotho Digital Business Registrations / Registrar of Companies · Primary company regulations
- Data Protection Act 2012LesLII / Office of Parliamentary Counsel of Lesotho · Primary privacy legislation
- Central Bank of Lesotho legislation and regulationsCentral Bank of Lesotho · Official financial regulator materials
- Financial Intelligence Unit of LesothoFinancial Intelligence Unit of Lesotho · Official FIU materials
- Lesotho second-round mutual evaluation reportESAAMLG · Authoritative country assessment
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Lesotho KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Financial Intelligence Unit of Lesotho, using its current prescribed form and route.
When is suspicion reported?+
Immediately upon forming suspicion and in any case no later than 7 days. Attempted transactions are included and amount is irrelevant.
Is there one universal threshold?+
No. The 2019 Regulations include specific M25,000 and M100,000 triggers for stated DNFBP and designated-business categories, while other reporting or CDD thresholds may depend on applicable instruments.
How is beneficial ownership determined?+
CDD follows controlling ownership, control by other means, then senior-management fallback. Separately, the 2024 company-register rules include a more-than-10% shares or voting-rights test plus appointment, influence and ultimate-control tests.
How long are AML records retained?+
At least 5 years after termination of the business relationship or the occasional transaction, with a competent authority able to direct up to a further 5 years. Company BO records have separate 10-year rules.
What is the breach-notification deadline?+
The Data Protection Act requires notification to the Commission and affected data subjects as soon as reasonably possible after discovering a qualifying compromise; it does not state a fixed hour count.
Is Lesotho on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026, but remains in ESAAMLG enhanced follow-up.
Can a regulated payment or financial product launch without approval?+
No. Classify the activity and obtain each required Central Bank or other competent-authority approval before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 29 August 2026. Confirm current FIU registration and filing specifications, prescribed transaction-reporting thresholds, sanctions communications, Data Protection Commission procedures, and product-specific permissions with the competent authority and qualified Lesotho counsel before launch.