Peru KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Peru.

Direct answer
What does the Peru compliance checklist cover?
The Peru checklist translates primary KYC, KYB and AML rules into 11 control areas and 46 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- UIF-Peru within the SBS
- Core framework
- Law 27693, Law 29038 and Supreme Decree 020-2017-JUS, plus sector rules
- Suspicious reports
- File with UIF-Peru through the compliance officer immediately and no later than 24 hours after the operation is classified as suspicious
- Default operations register
- Where no sector threshold applies: USD 10,000 individual or USD 50,000 aggregated in a calendar month
- Retention
- Operations register generally 10 years from the operation; a sector rule may set a shorter period, never below 5 years
- Beneficial owner filing test
- At least 10% capital, control by other means, then senior managing official fallback under Legislative Decree 1372
- Privacy authority
- Autoridad Nacional de Proteccion de Datos Personales (ANPD)
- Payment oversight
- BCRP authorization or registration under the 2025 National Payments System regulation, as applicable
- Virtual assets
- PSAVs are UIF-Peru reporting entities under Supreme Decree 006-2023-JUS and SBS Resolution 02648-2024
- FATF status
- GAFILAT member; not named on FATF call-for-action or increased-monitoring lists reviewed 1 August 2026
Implementation detail
Peru compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingPeru's control framework is activity- and supervisor-specific. Resolve the exact legal entity, regulated activity and local nexus before applying any threshold or timetable.4 items+
Only persons within Law 29038, Supreme Decree 020-2017-JUS or a later designation are reporting entities to UIF-Peru.
- Implementation action
- Map every product and activity to the statutory reporting perimeter and identify the competent supervisor; document why non-Peruvian activity is or is not in scope.
- Evidence to retain
- Perimeter memorandum, entity chart, activity inventory, legal nexus analysis and supervisor matrix.
- Primary citation
- Law 29038 art. 3; Supreme Decree 020-2017-JUS art. 2
A reporting entity must implement the AML/CFT prevention system and designate a compliance officer under its applicable sector rule.
- Implementation action
- Obtain required registrations and approvals before operating, appoint the officer and deputy where required, and provision the live UIF reporting channel.
- Evidence to retain
- Registration, appointment, approval, role description, portal access test and governance minutes.
- Primary citation
- Law 27693 arts. 3 and 9-A; Supreme Decree 020-2017-JUS arts. 13-16
Financial, securities, money-transfer and electronic-money activities may require SBS or SMV authorization independently of AML status.
- Implementation action
- Complete a product-by-product licensing analysis and do not accept funds, issue e-money, transfer value or provide regulated securities services before authorization.
- Evidence to retain
- Authorization opinion, application, regulator decision, public-register extract, conditions and launch approval.
- Primary citation
- Law 26702; Securities Market Law; Law 29985; applicable SBS and SMV rules
Payment-arrangement administrators register before operating under article 17. An ESP participating directly or indirectly in a Payment System or Prominent Payment Arrangement requires prior BCRP authorization; other ESPs are subject to informational registration under article 35 and the transition schedule.
- Implementation action
- Classify each payment role and infrastructure, determine whether article 17 registration, article 35 authorization or article 35 registration applies, and complete the applicable process and transition plan.
- Evidence to retain
- Payments perimeter analysis, authorization or registration, transition plan, operating rules and BCRP correspondence.
- Primary citation
- Circular 0022-2025-BCRP arts. 17 and 31-37; First and Second Final and Complementary Provisions
02Governance and risk assessmentThe prevention system must be tailored to the subject's sector, size, products, channels, customers and geographic exposure.4 items+
Reporting entities must identify and manage AML/CFT risks through policies, procedures and internal controls required by the applicable sector rule.
- Implementation action
- Document an enterprise risk assessment covering customers, products, channels, geography, delivery technology and TF/PF exposure; obtain governing-body approval.
- Evidence to retain
- Risk assessment, methodology, data sources, approval, action plan and annual review calendar.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-20; applicable sector rule
The compliance officer must operate independently, preserve confidentiality and report through the governance line required for the sector.
- Implementation action
- Protect the officer's authority, resources, access and escalation rights; prohibit retaliation and manage absence and succession.
- Evidence to retain
- Charter, appointment, budget, access matrix, committee minutes, reports and succession record.
- Primary citation
- Law 27693 art. 10-A; Supreme Decree 020-2017-JUS arts. 14-16
Training, internal review and independent or internal audit obligations vary by sector but form part of the prevention system.
- Implementation action
- Map the exact cadence and audience, train before access to controlled processes and test both design and operating effectiveness.
- Evidence to retain
- Training plan, attendance, assessments, audit plan, findings, remediation and closure evidence.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-20; SBS Resolution 2660-2015; applicable sector rule
New technologies and remote channels must be risk-assessed before launch and monitored after release.
- Implementation action
- Assess impersonation, document fraud, synthetic identity, mule, cyber, outsourcing, sanctions and privacy risks and define measurable launch gates.
- Evidence to retain
- Product risk assessment, threat model, control tests, approval, monitoring dashboard and change log.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable SBS, SMV and BCRP rules
03Natural-person KYC and representativesCDD consists of identification, verification and ongoing monitoring. The sector rule determines the exact data, evidence and permitted remote method.4 items+
A reporting entity must identify the customer using reliable data and verify identity under the applicable risk and sector procedure.
- Implementation action
- Collect required identity, address, occupation, purpose and source information; authenticate evidence and bind it to the applicant before activation unless a lawful delayed-verification case applies.
- Evidence to retain
- Customer file, document images, authenticity results, timestamps, reviewer and exception record.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable sector rule
The person acting for a customer must be identified and their authority verified.
- Implementation action
- Verify the representative as a natural person, validate the power or mandate against reliable evidence and limit access to the authorized scope.
- Evidence to retain
- Representative KYC, power, registry or notarial validation, authority analysis, expiry and approval.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable sector rule
CDD must be updated and transactions monitored for consistency with the customer's profile and risk.
- Implementation action
- Set risk-based refresh events, reconcile identity and profile changes, and investigate material deviations before continuing the relationship.
- Evidence to retain
- Refresh schedule, event triggers, updated evidence, alerts, investigations and approval history.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21
If required CDD cannot be completed, the reporting entity must not start, must not execute, or must terminate the relationship as applicable and assess a suspicious report.
- Implementation action
- Block completion, preserve the failed or attempted transaction, escalate to the compliance officer and document the reporting decision without tipping off.
- Evidence to retain
- System block, failed-CDD record, escalation, analysis, filing receipt if applicable and restricted communication log.
- Primary citation
- Supreme Decree 020-2017-JUS art. 21.3-21.4
04KYB, registries and beneficial ownershipCustomer KYB, SUNARP corporate records, AML beneficial-owner diligence and the SUNAT beneficial-owner declaration are distinct controls.5 items+
A legal-person customer must be identified through reliable constitutional, registry, tax, address, purpose and activity evidence.
- Implementation action
- Obtain current constitutive documents, RUC and SUNARP records, identify directors and representatives and reconcile discrepancies before approval.
- Evidence to retain
- Constitutional documents, RUC, certified registry record, governance list, purpose and discrepancy log.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable sector annex
AML CDD requires the natural person who ultimately owns or controls the customer or on whose behalf the transaction occurs to be identified and reasonably verified.
- Implementation action
- Trace every ownership layer, examine control by other means and document the fallback used by the applicable sector rule when no natural owner or controller is found.
- Evidence to retain
- Ownership chart, cap tables, agreements, control memorandum, identity evidence and sign-off.
- Primary citation
- Law 27693 art. 3; Supreme Decree 020-2017-JUS arts. 17-21
Legislative Decree 1372 separately identifies a beneficial owner at at least 10% capital, control by other means, then the senior managing official.
- Implementation action
- Maintain a separate SUNAT beneficial-owner analysis and declaration calendar; apply the current phased filing resolution and update supporting records.
- Evidence to retain
- Tax BO register, direct and indirect calculations, control analysis, fallback rationale, declaration and receipt.
- Primary citation
- Legislative Decree 1372 arts. 3-6; Supreme Decree 003-2019-EF; current SUNAT filing resolutions
In-scope legal persons and legal arrangements must identify, obtain, update, declare, retain and provide beneficial-owner information and supporting documents, submit Form 3800 to SUNAT by the applicable phased deadline, and file an updated declaration within 30 business days after a reportable change. Under RS 000168-2025/SUNAT, the 2026 tranches include July for more than 25 through 50 UIT, September for more than 10 through 25 UIT, and November for up to 10 UIT and specified other or new entities.
- Implementation action
- Determine the entity's RS 000168-2025/SUNAT tranche and status, calendar the RUC-based due date, submit Form 3800, monitor ownership or control changes and refile within 30 business days.
- Evidence to retain
- Tranche analysis, RUC calendar, Form 3800 data, filing receipt, change log, updated declaration and supporting-document archive.
- Primary citation
- Legislative Decree 1372 arts. 3-7; Supreme Decree 003-2019-EF; RS 000168-2025/SUNAT
A public or registry search does not replace beneficial-owner verification.
- Implementation action
- Use SUNARP and SUNAT information as corroboration, obtain source documents and resolve opaque nominees, foreign layers, trusts and inconsistent ownership.
- Evidence to retain
- Search extracts, source documents, certified foreign records, trust parties, discrepancy investigation and escalation.
- Primary citation
- Legislative Decree 1372 arts. 4-6; Supreme Decree 020-2017-JUS arts. 17-21
05PEPs, enhanced diligence and remote onboardingPEP status and other heightened-risk conditions require enhanced measures under the controlling sector rule; PEP status alone is not proof of crime.4 items+
Reporting entities must identify PEPs using the SBS definition and current functions list, including the January 2025 update.
- Implementation action
- Screen customers, representatives and beneficial owners at onboarding and continuously; verify the role, dates and relevant family or close-associate exposure required by the sector rule.
- Evidence to retain
- PEP search, role evidence, relationship analysis, review date and disposition.
- Primary citation
- SBS Resolution 4349-2016 as amended by SBS Resolution 00199-2025; applicable sector rule
Higher-risk PEP relationships require senior approval, enhanced source-of-wealth and source-of-funds work and intensified monitoring where the sector rule provides.
- Implementation action
- Obtain approval before opening or continuing, corroborate wealth and funds and configure risk-proportionate review and monitoring.
- Evidence to retain
- Approval, wealth narrative, supporting documents, funds trail, monitoring plan and periodic review.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable sector rule
Remote onboarding must use the identity, authentication and evidence methods permitted for the exact regulated sector and product.
- Implementation action
- Map the remote flow to the applicable annex, test liveness and impersonation resistance, provide accessible fallback and retain reconstructable results.
- Evidence to retain
- Legal map, vendor assessment, biometric or liveness tests, device signals, exception flow and monitoring.
- Primary citation
- Applicable SBS or SMV remote-identification rule; Supreme Decree 020-2017-JUS arts. 17-21
Outsourcing identity checks does not transfer the reporting entity's responsibility.
- Implementation action
- Contract for evidence access, audit, incidents, data protection and exit; independently test the service and control material changes.
- Evidence to retain
- Contract, due diligence, control mapping, sample tests, incidents, change approvals and exit plan.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21; applicable outsourcing rule
06Monitoring, suspicious reports and confidentialityThe compliance officer decides whether an operation is suspicious and files the ROS through ROSEL. The operation must be reported immediately and no later than 24 hours after it is classified as suspicious; the time used to classify it depends on its nature and complexity.4 items+
Completed and attempted operations with indicators of ML or TF must be analyzed and, when suspicious, reported to UIF-Peru by the compliance officer.
- Implementation action
- Escalate promptly, preserve the detection and decision timestamps, document facts and indicators and file through the live sector channel.
- Evidence to retain
- Alert, investigation, decision memorandum, report, acknowledgement and case chronology.
- Primary citation
- Law 27693 art. 9-A; Supreme Decree 020-2017-JUS art. 25
A ROS must be communicated immediately and in no case later than 24 hours after the operation is classified as suspicious. The period used to classify an operation depends on its nature and complexity.
- Implementation action
- Record the qualification timestamp, submit through ROSEL within 24 hours, preserve the acknowledgement and escalate any threatened or actual delay.
- Evidence to retain
- Rule inventory, detection and qualification timestamps, report, acknowledgement, filing QA and breach escalation.
- Primary citation
- Supreme Decree 020-2017-JUS art. 25.1-25.3
The existence, content and filing of a ROS and UIF requests are confidential and must not be disclosed to the customer or unauthorized persons.
- Implementation action
- Restrict access, use neutral customer communications and route disclosure requests to legal and compliance.
- Evidence to retain
- Access log, confidentiality acknowledgements, communications, training and disclosure approvals.
- Primary citation
- Law 27693 arts. 12 and 13; Supreme Decree 020-2017-JUS art. 25
Where additional CDD would alert a suspicious customer, the entity should file without taking that additional step and document why.
- Implementation action
- Stop the alerting action, preserve the rationale and file under the sector process while maintaining safe operational controls.
- Evidence to retain
- Tipping-off assessment, compliance approval, filing, restricted notes and monitoring plan.
- Primary citation
- Supreme Decree 020-2017-JUS art. 21.4
07Payments, wires, thresholds and agentsRegister thresholds, payment authorization and transfer-data duties must be applied by sector and role; reporting a threshold operation does not itself make it suspicious.4 items+
Where no sector threshold applies, the operations register captures individual operations of at least USD 10,000 and multiple operations totaling at least USD 50,000 in a calendar month for or benefiting the same person.
- Implementation action
- Confirm no sector threshold displaces the default, aggregate across offices and channels and record on the day of the operation.
- Evidence to retain
- Threshold legal map, aggregation tests, daily register, exchange-rate source and QA results.
- Primary citation
- Supreme Decree 020-2017-JUS art. 24.4-24.5
The operations register must be chronological, precise, complete, confidential and available in the form and frequency required by UIF-Peru or the supervisor.
- Implementation action
- Capture participants, roles, transaction details, accounts, value, currency and other sector fields and reconcile submissions to source systems.
- Evidence to retain
- Data dictionary, register extracts, reconciliation, submission receipts, corrections and access logs.
- Primary citation
- Supreme Decree 020-2017-JUS art. 24
Financial transfers follow the applicable sector rule. From 1 August 2026, PSAVs participating in domestic or cross-border virtual-asset transfers must obtain, retain and securely transmit or make available the prescribed originator and beneficiary information, with additional controls for self-hosted wallets and missing information.
- Implementation action
- For each rail, capture the controlling originator, beneficiary, account, wallet and traceability fields; transmit securely where required, block or withhold value when mandatory data is absent, document the disposition and assess a ROS.
- Evidence to retain
- Transfer message, wallet addresses, identity fields, secure-transmission record, missing-data decision, monitoring and ROS assessment.
- Primary citation
- SBS Resolution 2660-2015 and applicable financial transfer rule; SBS Resolution 02648-2024 arts. 24-25 and Second Final Complementary Provision
Agents and outsourced payment providers do not remove the licensed or registered principal's responsibility.
- Implementation action
- Approve agents before use, allocate CDD and reporting responsibilities, monitor performance and ensure immediate evidence access and termination rights.
- Evidence to retain
- Agent due diligence, contract, register, training, monitoring, incidents and termination plan.
- Primary citation
- Law 29985; Supreme Decree 090-2013-EF; Circular 0022-2025-BCRP
08Targeted financial sanctions and freezingPeru implements UN terrorism and proliferation designations through the UIF-Peru administrative-freezing mechanism. Screening alone is not the legal endpoint.5 items+
Reporting entities must monitor applicable UN Security Council designations and communicate detected funds or assets to UIF-Peru under the prescribed mechanism.
- Implementation action
- Screen customers, beneficial owners, counterparties and transactions against current UN lists and escalate a true match without delay.
- Evidence to retain
- List source and timestamp, screening configuration, match analysis, escalation and UIF communication.
- Primary citation
- SBS Resolution 3862-2016 arts. 2-4 as amended by SBS Resolution 2610-2021
After UIF-Peru orders administrative freezing, the reporting entity must execute and report it without delay.
- Implementation action
- Freeze all in-scope funds or assets immediately on receipt, prevent making value available, notify UIF through the required route and preserve confidentiality.
- Evidence to retain
- UIF order, receipt time, freeze timestamps, asset inventory, confirmation and access log.
- Primary citation
- SBS Resolution 3862-2016 arts. 4-6
When UIF-Peru issues an administrative-freezing measure, the reporting entity must review its operations records and customer, user and provider databases without delay and communicate to UIF-Peru without delay whether funds or other assets are identified, including a negative response when none exist.
- Implementation action
- Run and evidence the directed search immediately, freeze any identified assets, and send either the asset report or the required no-assets response through the prescribed channel without delay.
- Evidence to retain
- UIF measure, search scope and timestamps, systems queried, result, freeze record where applicable, positive or negative UIF communication and acknowledgement.
- Primary citation
- SBS Resolution 3862-2016 as amended
The freeze remains subject to judicial validation or revocation; release requires the authorized instruction.
- Implementation action
- Maintain the block until a verified release instruction, then release only within the instruction's scope and retain the complete legal chain.
- Evidence to retain
- Court and UIF notices, verification, release approval, timestamps and reconciliation.
- Primary citation
- Law 27693 art. 3; SBS Resolution 3862-2016 arts. 5-6
A reporting entity receiving a UIF-Peru national administrative-freezing order concerning funds or assets linked to extortion must execute the order immediately, keep it confidential and maintain the restriction for its legally authorized duration.
- Implementation action
- Authenticate the UIF order, immediately prevent withdrawal, transfer, use, conversion, disposal or movement, preserve confidentiality, track judicial validation or revocation, and release only under article 10-A.7.
- Evidence to retain
- UIF order, receipt and execution timestamps, restricted-asset inventory, access log, judicial notices, release authorization and reconciliation.
- Primary citation
- Law 27693 art. 3-B; Supreme Decree 020-2017-JUS arts. 8-A to 10-A, as inserted by Supreme Decree 007-2025-JUS
09Records and regulator accessRecords must allow UIF-Peru, the supervisor and competent authorities to reconstruct identity, risk, decisions and operations.4 items+
The general operations register and backup are retained for 10 years from the operation, unless a sector rule lawfully sets a shorter period that cannot be below 5 years.
- Implementation action
- Map each record class to its legal trigger, apply a defensible hold process and test retrieval and backup restoration.
- Evidence to retain
- Retention schedule, rule mapping, immutable archive, restore tests, legal holds and deletion approvals.
- Primary citation
- Supreme Decree 020-2017-JUS art. 24.2-24.3
CDD, beneficial-owner, monitoring, reporting and governance evidence must be retained for the period required by the applicable sector rule.
- Implementation action
- Do not apply the operations-register period mechanically to every record; document each sector trigger and preserve linked decision evidence.
- Evidence to retain
- Record inventory, sector schedule, customer closure dates, report links, holds and destruction certificates.
- Primary citation
- Applicable SBS, SMV or sector rule; Supreme Decree 020-2017-JUS arts. 17-25
UIF-Peru, supervisors, courts and competent authorities may require records within their legal competence.
- Implementation action
- Authenticate the request, preserve privilege and confidentiality, collect reproducibly and log the exact production and deadline.
- Evidence to retain
- Request, authority check, collection log, review, production index and receipt.
- Primary citation
- Law 27693 arts. 3 and 8-10; Supreme Decree 020-2017-JUS art. 24
Electronic evidence must remain complete, legible, secure and quickly retrievable throughout retention.
- Implementation action
- Protect metadata, audit access, validate integrity and test that reports, links and source artifacts can be reconstructed.
- Evidence to retain
- Integrity hashes, access logs, backup tests, sample retrieval and remediation.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 24-25; applicable sector rule
10Privacy, biometrics and transfersAML duties provide specific processing purposes but do not displace Peru's personal-data principles, security, transparency and transfer requirements.4 items+
Personal data must have a lawful basis and be processed for specified, proportionate purposes with required notice and security.
- Implementation action
- Map AML and other legal bases by field and purpose, give the required privacy information and restrict reuse and access.
- Evidence to retain
- Processing inventory, legal-basis map, notices, access controls, security tests and retention alignment.
- Primary citation
- Law 29733 arts. 5-12 and 17-20; Supreme Decree 016-2024-JUS
Biometric data is sensitive personal data and remote identity processing requires heightened controls and the consent or other basis allowed by law.
- Implementation action
- Document necessity and proportionality, minimize templates, test presentation-attack resistance, govern vendors and provide a lawful accessible alternative where required.
- Evidence to retain
- Biometric assessment, consent or legal basis, architecture, vendor terms, test results and fallback records.
- Primary citation
- Law 29733 arts. 2 and 13; Supreme Decree 016-2024-JUS
When an incident exposes large volumes or types of personal data, may affect many people, involves sensitive data, or evidently prejudices another right or freedom, the data-bank holder or controller must notify ANPD no later than 48 hours after learning of it. If the incident affects the data subject's other rights, the controller must also notify that person within 48 hours and without undue delay.
- Implementation action
- Start the 48-hour clock when the controller obtains knowledge or evidence of the incident; notify ANPD when article 34.1 applies, notify affected data subjects when article 34.3 applies, explain and evidence any delay, and retain the complete incident record.
- Evidence to retain
- Incident record, knowledge time, impact assessment, ANPD notification, data-subject communication, delay reasons and remediation.
- Primary citation
- Supreme Decree 016-2024-JUS arts. 34-36
International transfers and processors require lawful safeguards, security, instructions and accountability; high-risk processing may warrant an impact assessment and designated data officer.
- Implementation action
- Inventory transfers, execute appropriate clauses, assess destinations and processors, complete required impact work and track the phased data-officer rules.
- Evidence to retain
- Transfer map, contract, destination assessment, processor audit, impact assessment and officer designation where applicable.
- Primary citation
- Law 29733 arts. 11 and 15; Supreme Decree 016-2024-JUS; ANPD transfer guidance
11Practical evidence packsLaunch and ongoing operations should be supported by evidence that can be reviewed without reconstructing the control after the event.4 items+
Each product needs an approved legal and regulatory perimeter pack.
- Implementation action
- Record the entity, product, licenses, supervisor, reporting rule, threshold, timetable, data role and change owner in one controlled pack.
- Evidence to retain
- Signed perimeter pack, source snapshots, authorization evidence, rule owner and review date.
- Primary citation
- Law 27693; Supreme Decree 020-2017-JUS; applicable sector rules
Each customer file must demonstrate identity, authority, beneficial ownership, risk and ongoing monitoring.
- Implementation action
- Use a quality gate before activation and periodic sample testing after activation; remediate gaps to closure.
- Evidence to retain
- Customer index, identity and KYB evidence, ownership chart, risk score, approvals, reviews and QA results.
- Primary citation
- Supreme Decree 020-2017-JUS arts. 17-21
Reporting controls must demonstrate detection, escalation, decision quality, timeliness and confidentiality.
- Implementation action
- Test alerts through filing, threshold aggregation, portal continuity and restricted access at least annually and after material change.
- Evidence to retain
- Scenario inventory, test cases, case files, receipts, metrics, access review and remediation.
- Primary citation
- Law 27693 arts. 9-A and 12-13; Supreme Decree 020-2017-JUS arts. 24-25
Legal and regulatory change must be monitored across SBS, UIF-Peru, SMV, BCRP, SUNAT, ANPD, FATF and GAFILAT.
- Implementation action
- Assign owners, review official sources on a defined cadence and trigger impact assessment, versioning, training and control change.
- Evidence to retain
- Source register, dated review log, impact assessments, approvals, releases and training.
- Primary citation
- Applicable laws and regulator publications listed in Sources
Primary-source register
28 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- General AML/CFT rules and consolidated instrumentsSBS / UIF-Peru · Official regulator library
- Consolidated Regulation of Law 27693SBS / UIF-Peru · Primary regulatory instrument
- Reporting entities and principal obligationsSBS / UIF-Peru · Official regulator guidance
- Information and reports submitted to UIF-PeruSBS / UIF-Peru · Official reporting guidance
- SBS Resolution 2660-2015 - AML/CFT risk management regulationSBS · Primary sector regulation
- Updated PEP functions under Resolution 00199-2025SBS · Official regulator notice
- Legislative Decree 1372 - beneficial ownersDiario Oficial El Peruano / SBS · Primary legislation
- Beneficial-owner declaration and determinationSUNAT · Official tax authority guidance
- Beneficial-owner determination criteriaSUNAT · Official tax authority guidance
- RS 000168-2025/SUNAT - 2026 beneficial-owner declaration timetableSUNAT · Primary tax authority resolution
- SUNAT beneficial-owner declaration timetable and updates FAQSUNAT · Official tax authority guidance
- SUNARP legal-person index search guidanceSUNARP · Official registry guidance
- UN sanctions freezing frameworkSBS / UIF-Peru · Official sanctions guidance
- SBS Resolution 3862-2016 - UN sanctions freezingSBS · Primary regulatory instrument
- Law 29733 - Personal Data Protection LawANPD · Primary legislation
- Supreme Decree 016-2024-JUS - new data-protection regulationANPD · Primary regulatory instrument
- ANPD personal-data rules directoryANPD · Official regulator library
- Circular 0022-2025-BCRP - National Payments System regulationBanco Central de Reserva del Peru · Primary payment regulation
- Electronic-money laws and regulationsSBS · Official regulator library
- SBS Resolution 02648-2024 - PSAV AML/CFT and travel ruleSBS · Primary sector regulation
- PSAV AML/CFT regulation noticeSBS · Official regulator notice
- Supreme Decree 007-2025-JUS - national administrative freezing for extortionSBS / UIF-Peru · Primary regulatory instrument
- SBS authorization frameworkSBS · Official licensing guidance
- SMV legal instruments directorySuperintendencia del Mercado de Valores · Official regulator library
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current status
- GAFILAT member and evaluation scheduleFinancial Action Task Force · Official international assessment
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Official sanctions list
Direct answers
Peru KYC, KYB and AML questions
Who receives suspicious transaction reports in Peru?+
The compliance officer files the ROS with UIF-Peru through the channel prescribed for the reporting entity's sector.
What is the ROS deadline in Peru?+
A ROS must be communicated immediately and no later than 24 hours after the operation is classified as suspicious. The time required to classify the operation depends on its nature and complexity.
What threshold enters the general operations register?+
Only where no sector threshold displaces it: USD 10,000 for an individual operation or USD 50,000 in multiple operations during a calendar month for or benefiting the same person.
How is beneficial ownership determined and declared?+
AML CDD follows the applicable sector rule. Separately, Legislative Decree 1372 uses at least 10% capital, control by other means, and a senior managing official fallback. In-scope entities file Form 3800 under the current phased timetable and update a reportable change within 30 business days; RS 000168-2025/SUNAT places the remaining 2026 tranches in July, September and November according to UIT and entity status.
How long are records retained?+
The general operations register and backup are kept for 10 years from the operation. A sector rule may set a shorter period, but not below five years; other record classes follow their sector rule.
Do payment or e-money products require authorization?+
Often yes. BCRP, SBS or another sector process can apply independently of AML registration, depending on the precise payment, e-money, transfer or financial role.
Are virtual-asset service providers reporting entities?+
Yes. PSAVs within the Peruvian perimeter are UIF-Peru reporting entities under Supreme Decree 006-2023-JUS and SBS Resolution 02648-2024, but AML status should not be mistaken for a general financial license.
What happens on a UN sanctions match?+
Escalate immediately and follow the UIF-Peru mechanism. Once UIF-Peru orders administrative freezing, the reporting entity executes and confirms the freeze without delay.
What privacy rules matter for digital KYC?+
Law 29733 and Supreme Decree 016-2024-JUS govern lawful purpose, notices, sensitive biometric data, security, incidents, processors and international transfers.
Is Peru on a FATF public list?+
Peru was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026. This does not remove the need for a risk-based country assessment.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector rules, current UIF-Peru forms or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, customer, product, sector threshold, filing timetable, reporting channel, data role and later developments with qualified Peruvian counsel and the relevant authority before launch.