Madagascar KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Madagascar.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Madagascar compliance checklist cover?
The Madagascar checklist translates primary KYC, KYB and AML rules into 11 control areas and 33 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- SAMIFIN
- Primary AML rule
- Law 2018-043, amended by Law 2023-026
- Suspicion reporting
- Without delay, including attempted transactions
- Registry BO threshold
- 25% or more, then control and fallback cascade
- Core AML retention
- At least 5 years
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Madagascar compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the reporting entity, activity and supervisor before launch.3 items+
Determine whether each activity is in AML/CFT/CPF scope.
- Implementation action
- Map every entity, product, channel and profession to the financial-institution, DNFBP, nonprofit or other covered categories and identify SAMIFIN and the competent supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- Law 2018-043, Articles 4 and 8; Decree 2024-1352, Article 11
Establish the current SAMIFIN reporting route.
- Implementation action
- Obtain the current form or electronic-platform procedure, designate authorised reporters, test secure delivery and preserve acknowledgements.
- Evidence to retain
- Registration, user authority, channel test and receipt log.
- Primary citation
- Law 2018-043, Articles 23, 27 and 28, as amended by Law 2023-026
Obtain authorisation before regulated activity.
- Implementation action
- Classify banking, payment, money or value transfer, e-money, insurance, microfinance, agent, foreign-exchange, securities, fintech and crypto-asset activities and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, licences, conditions and renewal calendar.
- Primary citation
- Law 2018-043, Articles 4, 8, 20 and 31; Decree 2024-1352, Article 11; applicable CSBF rules
02Governance and risk assessmentControls must be risk-based, documented, current and independently tested.3 items+
Maintain a documented ML/TF/PF risk assessment.
- Implementation action
- Assess customers, geography, products, channels, cash, agents, technology, virtual assets and proliferation exposure; update before material change and retain supporting evidence.
- Evidence to retain
- Approved methodology, assessment, controls and version history.
- Primary citation
- Law 2018-043, Article 6; Decree 2024-1352, Articles 4-6
Transmit the annual risk assessment where required.
- Implementation action
- Provide the supported assessment to SAMIFIN and the relevant supervisory authority before 31 December each year and retain it for at least five years from transmission.
- Evidence to retain
- Submitted assessment, delivery receipt and retention control.
- Primary citation
- Decree 2024-1352, Article 5
Maintain governance, training and independent control.
- Implementation action
- Implement written customer diligence, monitoring, reporting, records, confidentiality, employee training and internal-control measures proportionate to the business and track remediation.
- Evidence to retain
- Policies, appointments, training, testing and management reporting.
- Primary citation
- Law 2018-043, Articles 6 and 19
03Natural-person identificationIdentify and verify customers and representatives before or during the permitted point of engagement.3 items+
Identify and verify the customer and address.
- Implementation action
- Use current reliable official documents and independent information before opening an account, taking custody or establishing another business relationship; record any representative and authority.
- Evidence to retain
- Identity file, address evidence, source provenance and mandate.
- Primary citation
- Law 2018-043, Articles 13-14
Understand purpose and intended nature.
- Implementation action
- Record the purpose and nature of the relationship, expected activity, counterparties, geography and source information sufficient for risk rating and monitoring.
- Evidence to retain
- Customer profile, expected-activity baseline and approval.
- Primary citation
- Law 2018-043, Article 13(9), inserted by Law 2023-026, Article 8
Do not proceed where mandatory diligence fails.
- Implementation action
- Do not establish the relationship or execute the transaction, or terminate an existing relationship, when mandatory diligence cannot be completed; submit a suspicious transaction report without delay.
- Evidence to retain
- Decline or exit decision, investigation and restricted reporting record.
- Primary citation
- Law 2018-043, Article 15 bis, inserted by Law 2023-026, Article 9
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and control and keep the analysis current.3 items+
Verify legal existence and authority.
- Implementation action
- Obtain current registry, constitutional, address, director, shareholder, signatory, licence and mandate evidence; reconcile material discrepancies.
- Evidence to retain
- Registry extract, governing records, powers and discrepancy log.
- Primary citation
- Law 2018-043, Articles 12-15; Decree 2024-1352, Articles 7-9
Apply the registry beneficial-owner cascade accurately.
- Implementation action
- For registry duties, identify natural persons holding at least 25% of capital or voting rights, including joint factual control below that level; then test control by other means, principal-manager fallback and legal-representative fallback.
- Evidence to retain
- Ownership chart, control analysis, verified identities and fallback rationale.
- Primary citation
- Order 11689/2024-MEF, Article 3
Keep beneficial-owner registers accurate and current.
- Implementation action
- Maintain the required physical and electronic special register, verify supporting evidence, make initial, annual and change declarations to the tax authority and report known mismatches through the prescribed route.
- Evidence to retain
- Registers, declarations, verification record and discrepancy report.
- Primary citation
- Order 11689/2024-MEF, Articles 4 and 12-14; Tax Procedures Code Articles IV-22 to IV-41
05PEPs, EDD, and remote onboardingHigher-risk and non-face-to-face relationships require enhanced, evidenced controls.3 items+
Detect PEP and higher-risk exposure.
- Implementation action
- Use appropriate systems to determine whether the customer or beneficial owner is a foreign or domestic PEP, a close family member or associate, or otherwise high risk.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Law 2018-043, Articles 4(21) and 16(b)
Apply enhanced approval, provenance and monitoring.
- Implementation action
- For covered PEP and high-risk relationships, obtain required senior approval, establish source of wealth and funds, and apply enhanced ongoing monitoring.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Law 2018-043, Articles 13(8) and 16(b), as amended by Law 2023-026
Control remote and biometric onboarding.
- Implementation action
- Assess impersonation, liveness, document authenticity, data minimisation, security and fallback review before deploying remote or biometric checks; confirm any current supervisor conditions.
- Evidence to retain
- Remote-onboarding assessment, data review, tests and approvals.
- Primary citation
- Law 2018-043, Articles 6 and 13; Law 2014-038 on personal data
06Monitoring and suspicious reportingSAMIFIN reporting must be immediate, complete and confidential.3 items+
Monitor and examine unusual activity.
- Implementation action
- Scrutinise transactions against the customer profile; examine complex, unusually large, unexplained or high-risk activity and document the purpose, parties and conclusion.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- Law 2018-043, Articles 13 and 16
Report suspicion and attempts without delay.
- Implementation action
- Report to SAMIFIN as soon as suspicion is identified, including attempted transactions and relevant ML, TF or PF suspicion, regardless of whether execution was prevented or suspicion arose later.
- Evidence to retain
- Decision chronology, report, supporting material, delivery and receipt.
- Primary citation
- Law 2018-043, Article 27, replaced by Law 2023-026, Article 14
Prevent tipping off and protect reporting data.
- Implementation action
- Restrict access and do not disclose the report or its existence to the customer or any unauthorised person; use the current form, platform or other accepted written channel.
- Evidence to retain
- Access logs, confidentiality procedure, training and acknowledgement.
- Primary citation
- Law 2018-043, Article 28
07Payments, wires, thresholds, and agentsUse verified sector instructions; do not infer one universal transaction threshold.3 items+
Configure only current, applicable thresholds.
- Implementation action
- Map customer-diligence, cash, casino, cross-border declaration and sector reporting thresholds to the current instrument and aggregation rule; do not apply the casino or nonprofit amounts universally.
- Evidence to retain
- Threshold register, authoritative instruments, tests and approval.
- Primary citation
- Law 2018-043, Articles 11, 14, 21 and 22; applicable SAMIFIN and supervisor directives
Preserve required wire-transfer information.
- Implementation action
- Carry required originator and beneficiary information through the payment chain, identify incomplete transfers and reject, suspend or report them under current CSBF instructions.
- Evidence to retain
- Message samples, validation rules, exceptions and reports.
- Primary citation
- Law 2018-043, Article 16(d), as amended by Law 2023-026, Articles 10-11; Decree 2024-1352, Article 10
Retain accountability for agents and third parties.
- Implementation action
- Verify permissions, include money or value transfer agents and sub-agents in the AML programme, report their list to the competent authority, monitor them and preserve prompt access to relied-on diligence.
- Evidence to retain
- Agent register, due diligence, contracts, monitoring and retrieval test.
- Primary citation
- Law 2018-043, Article 16(d)-(e), as amended by Law 2023-026, Article 11
08Targeted financial sanctionsImplement current UN and national designations through Madagascar's 2025 framework.3 items+
Screen current designation lists promptly.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, list updates and before execution using current UN and national lists.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- Law 2018-043, Articles 55 and 55 ter as amended; Decree 2025-171
Freeze covered funds and assets within the required process.
- Implementation action
- Implement national-list freezing within 24 hours and without prior notice; when any list is communicated, immediately check databases, freeze covered assets, prohibit availability and report results and measures to SAMIFIN.
- Evidence to retain
- Freeze procedure, timestamps, asset record and FIU report.
- Primary citation
- Decree 2025-171, Articles 20-22 and 25-27
Report attempts and govern release.
- Implementation action
- Report attempted transactions involving frozen assets to SAMIFIN and permit delisting, unfreezing or access only through the documented CNSFC and ministerial process.
- Evidence to retain
- Attempt report, match rationale, authority decision and reconciliation.
- Primary citation
- Decree 2025-171, Articles 28 and 33-48
09Records and regulator accessRecords must reconstruct customers, ownership, transactions and decisions.3 items+
Retain customer identity records for at least five years.
- Implementation action
- Keep customer and beneficial-owner identity evidence for at least five years after account closure or the end of the relationship, subject to longer applicable holds.
- Evidence to retain
- Schedule, archive sample, deletion control and legal-hold log.
- Primary citation
- Law 2018-043, Article 17(1); Decree 2024-1352, Article 7
Retain transaction and analysis records for at least five years.
- Implementation action
- Keep transaction records and Article 16 reports for at least five years after execution and keep books, customer correspondence and transaction analyses for at least five years after the relationship ends.
- Evidence to retain
- Transaction archive, analysis file and retrieval test.
- Primary citation
- Law 2018-043, Article 17(2)-(3)
Respond securely to competent requests.
- Implementation action
- Authenticate requests, protect reporting confidentiality, produce reconstructable records within the specified time and format, and log the disclosure and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- Law 2018-043, Articles 18 and 25
10Privacy, biometrics, and transfersAML processing remains subject to Madagascar's personal-data framework.3 items+
Map lawful purpose, data and formalities.
- Implementation action
- Document AML purposes, data categories, notices, access, sharing, retention and any CMIL declaration or authorisation required for the processing.
- Evidence to retain
- Data inventory, legal-basis assessment, notices and filing record.
- Primary citation
- Law 2014-038, Chapters III-V
Apply heightened controls to sensitive and biometric data.
- Implementation action
- Confirm the conditions for identity, criminal-offence, health or biometric processing; minimise collection and protect confidentiality, integrity, access and incident response.
- Evidence to retain
- Impact assessment, security tests, access review and incident records.
- Primary citation
- Law 2014-038 on personal data; Law 2018-043, Article 28
Control cross-border personal-data transfers.
- Implementation action
- Assess the destination, safeguards, processor terms and any CMIL procedure before transferring personal data abroad; separately confirm banking secrecy and supervisor requirements.
- Evidence to retain
- Transfer assessment, safeguards, contract and approval.
- Primary citation
- Law 2014-038, cross-border transfer provisions; Law 2018-043, Article 16(e)
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, data records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Law 2018-043, Articles 6 and 13-17
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, SAMIFIN reports, delivery evidence and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Law 2018-043, Articles 16-19 and 27-28
Maintain a launch and change-control pack.
- Implementation action
- Record licensing, threshold sources, sanctions lists, privacy formalities, product risk, testing and authority confirmations before launch and material changes.
- Evidence to retain
- Signed launch pack, legal-source register and change approvals.
- Primary citation
- Operational control supporting Law 2018-043, Articles 6, 8, 16 and 31
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 2018-043 on money laundering and terrorist financingMadagascar National Assembly · Primary national legislation
- Official AML/CFT/CPF laws, decrees and orders librarySAMIFIN · Official FIU legislation library
- Law No. 2023-026 amending Law No. 2018-043Madagascar / SAMIFIN · Primary amending legislation
- Decree No. 2024-1352 implementing the amended AML/CFT lawMadagascar / SAMIFIN · Primary implementing regulation
- Decree No. 2025-171 on targeted financial sanctionsMadagascar / SAMIFIN · Primary sanctions regulation
- Order No. 11689/2024-MEF on beneficial-owner registersMadagascar Ministry of Economy and Finance / SAMIFIN · Primary registry regulation
- Practical guide to AML/CFT/CPF duties for DNFBPsSAMIFIN · Official FIU guidance
- SAMIFIN suspicious transaction report routeSAMIFIN · Official FIU reporting page
- Law No. 2014-038 on protection of personal dataMadagascar National Assembly · Primary privacy legislation
- Madagascar 12th enhanced follow-up report and fifth technical-compliance reratingESAAMLG · Authoritative regional assessment
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Madagascar KYC, KYB and AML questions
Who receives suspicious transaction reports?+
SAMIFIN, Madagascar's Financial Intelligence Unit, through its current form, electronic platform or other accepted written route.
When is suspicion reported?+
Without delay as soon as suspicion is identified, including attempted transactions and cases discovered after execution.
Is there one universal transaction threshold?+
No universal amount is asserted. Apply only the current threshold and aggregation rule for the customer, product, transaction and sector; casino and nonprofit amounts are not universal.
How is registry beneficial ownership determined?+
Start with natural persons holding at least 25% of capital or voting rights, while accounting for joint factual control below that level; then test other control, principal-manager fallback and legal-representative fallback.
How long are core AML records retained?+
Generally at least five years, with the trigger depending on the record: account closure or relationship end for identity records, transaction execution for transaction records, and relationship end for books, correspondence and analysis.
What privacy rules apply?+
Law No. 2014-038 governs personal-data processing. Confirm CMIL formalities, sensitive or biometric conditions and transfer safeguards for the proposed implementation.
Is Madagascar on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. It remains in ESAAMLG enhanced follow-up after the 2018 mutual evaluation.
Can a payment, fintech or crypto-asset product launch without approval?+
No. Classify the product, provider and agent model and obtain every applicable CSBF or other competent-authority permission before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 1 September 2026. Confirm current SAMIFIN and CSBF filing, threshold, onboarding and transfer instructions, registry procedures, sanctions communications, privacy formalities and product-specific permissions with the competent authority and qualified Malagasy counsel before launch.