Libya KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Libya.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Libya compliance checklist cover?
The Libya checklist translates primary KYC, KYB and AML rules into 11 control areas and 33 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Libyan Financial Information Unit
- Primary AML rule
- Resolution No. 1013 of 2017 issuing the AML/CFT Law
- Suspicion reporting
- Without delay; FIU guide says within 24 hours
- Thresholds
- Committee and sector specific; no universal amount asserted
- Core AML retention
- At least 5 years
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Libya compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the reporting entity, regulated activity, territory and supervisor before launch.3 items+
Determine whether each activity is in AML/CFT scope.
- Implementation action
- Map every entity, product, channel and profession to the financial-institution, DNFBP or nonprofit categories under Resolution 1013/2017; identify the FIU and each competent sector supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- Resolution 1013/2017, Articles 1, 12 and 15
Complete current FIU and supervisory registration.
- Implementation action
- Confirm registration required by the competent supervisor, obtain the current FIU reporting form and secure-channel instructions, and test user authority, delivery and receipts.
- Evidence to retain
- Registration, authority correspondence, channel test and contact log.
- Primary citation
- Resolution 1013/2017, Articles 9, 12 and 15; Libyan FIU reporting page
Obtain authorisation before regulated activity.
- Implementation action
- Classify banking, payments, e-money, remittance, foreign exchange, insurance, securities, agent, fintech and virtual-asset activities and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, licences, conditions and renewal calendar.
- Primary citation
- Resolution 1013/2017, Articles 12-15 and 50; applicable Central Bank and sector rules
02Governance and risk assessmentControls must be risk-based, documented, resourced and independently tested.3 items+
Maintain a written ML/TF risk assessment.
- Implementation action
- Assess customers, products, delivery channels, geography, cash, agents, technology, virtual assets and proliferation exposure; update the assessment periodically and before material change.
- Evidence to retain
- Approved methodology, assessment, controls and version history.
- Primary citation
- Resolution 1013/2017, Article 16
Maintain senior compliance ownership and written controls.
- Implementation action
- Establish a management-level compliance arrangement and written CDD, monitoring, reporting, records, confidentiality, employee-screening, training and group controls proportionate to the business.
- Evidence to retain
- Appointment, policies, training, screening and board reporting.
- Primary citation
- Resolution 1013/2017, Articles 32-34
Independently test the programme.
- Implementation action
- Use an adequately resourced internal-audit or independent review function to test design and operation, document deficiencies and track remediation through closure.
- Evidence to retain
- Audit plan, reports, findings and closure evidence.
- Primary citation
- Resolution 1013/2017, Article 32
03Natural-person identificationCDD uses reliable independent evidence and continues through the relationship.3 items+
Identify and verify the customer and representative.
- Implementation action
- Use reliable independent documents, data or information; verify any representative's identity and authority and prohibit anonymous or clearly fictitious-name accounts.
- Evidence to retain
- Identity file, source provenance, mandate and verification result.
- Primary citation
- Resolution 1013/2017, Article 19(1)-(2)
Understand purpose and expected activity.
- Implementation action
- Record the purpose and intended nature of the relationship, expected activity, counterparties, geography and source information sufficient for risk rating and ongoing monitoring.
- Evidence to retain
- Customer profile, expected-activity baseline and approval.
- Primary citation
- Resolution 1013/2017, Article 19(2)
Do not proceed where mandatory CDD fails.
- Implementation action
- Refrain from opening, establishing or executing, or terminate the relationship, when required identification or verification cannot be completed; consider a confidential suspicious report.
- Evidence to retain
- Decline or exit decision, investigation and restricted reporting record.
- Primary citation
- Resolution 1013/2017, Article 25
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and control without inventing a percentage threshold.3 items+
Verify legal existence, activities and authority.
- Implementation action
- Obtain current commercial-registry evidence, constitutional records, registered address, directors, senior managers, shareholders, signatories, licences and mandates; reconcile inconsistencies.
- Evidence to retain
- Registry extract, governing records, powers and discrepancy log.
- Primary citation
- Resolution 1013/2017, Article 19(2)-(3); Commercial Activity Law No. 23 of 2010
Apply the statutory beneficial-owner cascade.
- Implementation action
- Identify natural persons holding a controlling share or controlling through other means; use the responsible manager only when no natural person is identified through those limbs, and verify identities with reliable independent evidence.
- Evidence to retain
- Ownership chart, control analysis, verified identities and fallback rationale.
- Primary citation
- Resolution 1013/2017, Article 19(2)-(3)
Keep company and ownership evidence current.
- Implementation action
- Monitor changes to legal form, registration, ownership, control, directors and authority; refresh registry and customer evidence according to risk and investigate discrepancies.
- Evidence to retain
- Refresh schedule, extracts, declarations and discrepancy decisions.
- Primary citation
- Resolution 1013/2017, Articles 19 and 29; Commercial Activity Law No. 23 of 2010
05PEPs, EDD, and remote onboardingPEPs, higher-risk and non-face-to-face relationships require enhanced controls.3 items+
Detect PEP exposure.
- Implementation action
- Use appropriate risk-management systems to identify whether a customer or beneficial owner is a PEP, including relevant family members and close associates.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Resolution 1013/2017, Article 23
Apply enhanced approval, provenance and monitoring.
- Implementation action
- Obtain senior-management approval, take reasonable measures to establish source of wealth and funds, and apply enhanced ongoing monitoring to PEP relationships.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Resolution 1013/2017, Article 23
Control remote and biometric onboarding.
- Implementation action
- Use sufficient defined measures for non-face-to-face customers; assess impersonation, liveness, device, data minimisation and security before deployment, and preserve a reliable electronic record.
- Evidence to retain
- Remote-onboarding assessment, data review, tests and approvals.
- Primary citation
- Resolution 1013/2017, Articles 16 and 19(7); Electronic Transactions Law No. 6 of 2022
06Monitoring and suspicious reportingFIU reporting must be prompt, complete and confidential.3 items+
Monitor activity against the customer profile.
- Implementation action
- Scrutinise transactions throughout the relationship for consistency with customer, business, risk and source information; examine complex, unusually large or unexplained activity and document conclusions.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- Resolution 1013/2017, Articles 19 and 31
Report suspicion and attempts promptly.
- Implementation action
- Report to the Libyan FIU without delay any suspicious transaction or attempt regardless of value; operationalise the FIU guide's expectation to submit within 24 hours after reasonable grounds arise.
- Evidence to retain
- Decision chronology, STR or SAR, supporting material, delivery and receipt.
- Primary citation
- Resolution 1013/2017, Article 27; FIU Suspicious Transaction Reporting Guide 2023
Prevent tipping off.
- Implementation action
- Restrict access and do not disclose a report, submitted information or related investigation to the customer or unauthorised persons.
- Evidence to retain
- Access logs, confidentiality procedure and training.
- Primary citation
- Resolution 1013/2017, Article 28
07Payments, wires, thresholds, and agentsAmounts are set by current committee or sector instruments rather than one universal threshold.3 items+
Configure only verified CDD thresholds.
- Implementation action
- Apply occasional-transaction CDD and aggregation only at the current amount set by the National Committee or relevant sector rule; retain the authoritative instrument and do not infer a universal threshold.
- Evidence to retain
- Legal mapping, configuration, test cases and approval.
- Primary citation
- Resolution 1013/2017, Articles 18-19; National Committee Decision No. 1 of 2019
Preserve required wire-transfer information.
- Implementation action
- For transfers above the current committee-set amount, obtain and verify originator and beneficiary information, carry it in the payment message, retain it and apply risk-based rules to incomplete transfers.
- Evidence to retain
- Threshold authority, message samples, validation rules and exceptions.
- Primary citation
- Resolution 1013/2017, Article 26; National Committee Decision No. 1 of 2019
Retain accountability for agents and third parties.
- Implementation action
- Verify permissions, conduct due diligence, contract for confidentiality, security and prompt record access, and retain primary responsibility for relied-on CDD and outsourced activity.
- Evidence to retain
- Due diligence, contract, monitoring and retrieval test.
- Primary citation
- Resolution 1013/2017, Articles 22 and 32; applicable Central Bank payment rules
08Targeted financial sanctionsUse current UN and national designations and Libya's statutory implementation process.3 items+
Screen applicable designations promptly.
- Implementation action
- Obtain current UN and communicated national lists and screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, list updates and before execution.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- Resolution 1013/2017, Article 81; Resolution 1037/2017
Freeze covered funds and resources without delay.
- Implementation action
- On a confirmed designation, freeze covered funds and economic resources without prior notice, prevent prohibited availability and notify the implementing authority within three days.
- Evidence to retain
- Freeze procedure, timestamps, legal basis, report and authority communication.
- Primary citation
- Resolution 1013/2017, Article 81(6)-(8); Resolution 1037/2017
Govern false positives, exceptions and release.
- Implementation action
- Escalate potential matches through the current implementing-authority process; permit access, exemption, unfreezing or delisting only on documented lawful authority.
- Evidence to retain
- Match rationale, reports, authority instruction and reconciliation.
- Primary citation
- Resolution 1013/2017, Article 81(10); Resolution 1037/2017
09Records and regulator accessRecords must reconstruct the customer, transaction, ownership and decision.3 items+
Retain core AML records for at least five years.
- Implementation action
- Keep identity, beneficial ownership, account, correspondence and analysis records for at least 5 years after the relationship ends or after an occasional transaction.
- Evidence to retain
- Schedule, configuration, archive sample and legal-hold log.
- Primary citation
- Resolution 1013/2017, Article 29(1)
Retain attempted and completed transaction records.
- Implementation action
- Keep records sufficient to reconstruct attempted and completed transactions for at least 5 years after the attempt or completion, and longer when a competent authority requires it.
- Evidence to retain
- Transaction archive, attempted-transaction log and retrieval test.
- Primary citation
- Resolution 1013/2017, Article 29(1)-(2)
Respond securely to competent requests.
- Implementation action
- Authenticate requests, protect reporting confidentiality, produce reconstructable records promptly and log scope, timing and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- Resolution 1013/2017, Articles 6, 12 and 30
10Privacy, biometrics, and transfersApply Libya's electronic-transactions and sector data rules to the extent they cover the processing; do not present them as a general comprehensive privacy code.3 items+
Map the applicable data rule and processing purpose.
- Implementation action
- Document statutory AML purposes, notices, data categories, access, sharing and retention; separately identify when Electronic Transactions Law Articles 73-79 or a sector rule applies.
- Evidence to retain
- Data inventory, applicability assessment, notices and retention map.
- Primary citation
- Electronic Transactions Law No. 6 of 2022, Articles 73-79; Resolution 1013/2017, Article 29
Protect identity and reporting data.
- Implementation action
- Apply proportionate confidentiality, access, integrity, incident and processor controls, with heightened restrictions for suspicious-report information.
- Evidence to retain
- Risk assessment, contracts, security tests and incident records.
- Primary citation
- Resolution 1013/2017, Article 28; Electronic Transactions Law No. 6 of 2022, Articles 75-76
Control covered cross-border personal-data transfers.
- Implementation action
- Where Article 78 applies, assess the data, purpose, duration, destination law and commitments, relevant rules and security measures before transfer; separately confirm banking-sector requirements.
- Evidence to retain
- Transfer analysis, safeguards, contract and approval.
- Primary citation
- Electronic Transactions Law No. 6 of 2022, Article 78; Central Bank Circular No. 18 of 2025
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, data records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Resolution 1013/2017, Articles 16-25 and 29
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, FIU reports, delivery evidence and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Resolution 1013/2017, Articles 27-32
Maintain a launch and change-control pack.
- Implementation action
- Record licensing, threshold sources, sanctions-list sources, privacy applicability, product risk, testing and authority confirmations before launch and material changes.
- Evidence to retain
- Signed launch pack, legal-source register and change approvals.
- Primary citation
- Operational control supporting Resolution 1013/2017, Articles 12-16 and 50
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Resolution No. 1013 of 2017 issuing the Anti-Money Laundering and Terrorism Financing LawLibya Official Gazette / Law Society of Libya · Primary national legislation
- Official Gazette, 2018 special issue No. 1Libya Ministry of Justice / Law Society of Libya · Official gazette record
- Legislation and regulatory instruments libraryLibyan Financial Information Unit · Official FIU legal materials
- Suspicious transaction reporting instructions and formLibyan Financial Information Unit · Official FIU reporting guidance
- Financial Information Unit annual report 2018-2023Libyan Financial Information Unit · Official FIU report
- Laws library, including Banking Law and Commercial Activity LawCentral Bank of Libya · Official legislation library
- Regulatory Rules of the Libyan National Payment SchemeCentral Bank of Libya · Official payment-system rules
- Electronic Transactions Law No. 6 of 2022Libya House of Representatives / Law Society of Libya · Primary national legislation
- MENAFATF annual report 2024MENAFATF · Authoritative regional assessment record
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
- United Nations Security Council Libya sanctions committeeUnited Nations · Authoritative country sanctions materials
Direct answers
Libya KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Libyan Financial Information Unit, using its current form and secure reporting route.
When is suspicion reported?+
Resolution 1013/2017 requires reporting without delay for transactions and attempts regardless of value. The FIU's 2023 reporting guide says to submit within 24 hours after reasonable grounds arise.
Is there one universal threshold?+
No universal amount is asserted. Resolution 1013/2017 delegates occasional-transaction and wire thresholds to the National Committee, with sector instruments also relevant.
How is beneficial ownership determined?+
Identify natural persons with a controlling share or control by other means; use the responsible manager only when no natural person is identified through those limbs. The core law does not state a percentage in Article 19.
How long are AML records retained?+
At least 5 years after the relationship ends or the occasional transaction, attempt or completed transaction, and longer where a competent authority requires it.
What privacy rules apply?+
Law No. 6 of 2022 contains personal-data rules within its electronic-transactions scope. Confirm its application and any sector rule for each processing activity rather than treating it as a general comprehensive privacy code.
Is Libya on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. MENAFATF's 2024 report records that Libya's second-round evaluation remained deferred because of security conditions.
Can a payment, fintech or virtual-asset product launch without approval?+
No. Classify the activity and obtain every applicable Central Bank or other competent-authority permission before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 31 August 2026. Confirm the current legal and territorial application of national instruments, committee-set CDD and wire thresholds, FIU filing specifications, sanctions communications, registry evidence, data rules and product-specific permissions with the competent authority and qualified Libyan counsel before launch.