São Tomé and Príncipe KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in São Tomé and Príncipe.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the São Tomé and Príncipe compliance checklist cover?
The São Tomé and Príncipe checklist translates primary KYC, KYB and AML rules into 11 control areas and 36 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Unidade de Informação Financeira (UIF)
- Primary AML rule
- Law No. 8/2013 of 15 October 2013
- Suspicion reporting
- Immediately, including attempted transactions, regardless of amount
- Automatic cash report
- No general cash-transaction report identified in the 2024 GIABA assessment
- Core AML retention
- At least 5 years under record-specific clocks
- FATF status
- Not named on FATF public lists at 19 June 2026
Implementation detail
São Tomé and Príncipe compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the covered activity and competent supervisor before launch.3 items+
Map each entity and activity to the AML/CFT perimeter.
- Implementation action
- Classify financial institutions and designated non-financial businesses and professions under Law No. 8/2013, including relevant agents and branches, and identify the FIU and sector supervisor.
- Evidence to retain
- Applicability memo, entity and product map, supervisor matrix and accountable owner.
- Primary citation
- Law 8/2013, Articles 2-3; GIABA MER 2024, Recommendations 10 and 22
Establish the institutional FIU reporting route.
- Implementation action
- Authorise named reporters, obtain the current reporting form and access route directly from the FIU, test secure transmission and preserve institutional acknowledgements; do not use the public tip-off channel as a substitute without FIU confirmation.
- Evidence to retain
- Reporter mandate, FIU instructions, channel test and receipt log.
- Primary citation
- Law 8/2013, Article 21; UIF legislation and contact pages
Obtain approval before regulated financial or payment activity.
- Implementation action
- Classify banking, foreign exchange, money transfer, payment, e-money, agent, outsourcing and other regulated services and obtain Central Bank or other competent approval before launch.
- Evidence to retain
- Perimeter analysis, licence, conditions, agent approvals and renewal calendar.
- Primary citation
- Law 17/2018; Decree-Law 16/2019; GIABA MER 2024, Recommendation 14
02Governance and risk assessmentControls must be documented, risk-based and independently tested.3 items+
Maintain approved AML/CFT controls.
- Implementation action
- Adopt controls for CDD, beneficial ownership, PEPs, monitoring, reporting, sanctions, records, training and assurance proportionate to the institution's risk and sector rules.
- Evidence to retain
- Policy suite, governance approvals, control inventory, training and testing.
- Primary citation
- Law 8/2013; NAP 10/2015; GIABA MER 2024, Recommendations 18 and 23
Assess customer, product and delivery risk.
- Implementation action
- Document ML/TF risks across customers, beneficial owners, countries, products, cash exposure, technologies, agents and delivery channels before launch and after material change.
- Evidence to retain
- Risk methodology, assessment, inputs, approvals and remediation plan.
- Primary citation
- Law 8/2013, Article 11; GIABA MER 2024, Recommendation 1
Govern third parties and outsourcing.
- Implementation action
- Confirm reliance eligibility, obtain CDD information without delay, contract for document access, test retrieval and retain ultimate responsibility for customer identification and verification.
- Evidence to retain
- Due diligence, agreement, retrieval tests, monitoring and exceptions.
- Primary citation
- Law 8/2013, Article 17; GIABA MER 2024, Recommendation 17
03Natural-person identificationApply identification and verification at every statutory trigger.3 items+
Identify and verify customers before establishing a relationship.
- Implementation action
- Capture identity attributes, verify them from reliable independent evidence, record purpose and intended nature and establish an expected activity profile.
- Evidence to retain
- CDD file, evidence provenance, purpose, expected activity and risk decision.
- Primary citation
- Law 8/2013, Article 10(2)-(3); NAP 10/2015
Apply CDD at occasional-transaction and risk triggers.
- Implementation action
- Apply CDD to occasional or apparently linked transactions at or above STN 245,000, and regardless of amount where suspicion arises or prior identification data is doubtful; treat the statutory threshold as a trigger, not a safe harbour.
- Evidence to retain
- Trigger matrix, aggregation logic, alerts and CDD timestamps.
- Primary citation
- Law 8/2013, Article 10(2); GIABA MER 2024, criterion 10.2
Verify representatives and their authority.
- Implementation action
- Identify and verify each person acting for a customer and validate the mandate before permitting activity.
- Evidence to retain
- Identity evidence, mandate, authority verification and expiry control.
- Primary citation
- Law 8/2013, Article 10(12)
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and ultimate natural-person control.4 items+
Verify legal-person identity and authority.
- Implementation action
- Obtain current commercial-register evidence, constitutional documents, registered office, business address, directors, licences and mandates, and resolve inconsistencies.
- Evidence to retain
- DGRN/GUE extract, statutes, officer list, licences, mandate and discrepancy log.
- Primary citation
- Law 8/2013, Article 10; DGRN GUE requirements
Identify and verify the beneficial owner.
- Implementation action
- Use reliable evidence to identify the natural person who ultimately owns or effectively controls the customer; document ownership and control separately and apply a conservative senior-manager fallback where no owner or controller can be identified.
- Evidence to retain
- Ownership chart, control analysis, verified identities and fallback rationale.
- Primary citation
- Law 8/2013, Article 10(2)-(3); GIABA MER 2024, criteria 10.5 and 10.10
Do not treat the company register as a complete BO register.
- Implementation action
- Reconcile registry records, customer declarations and independent evidence, refresh on ownership or control changes and record discrepancies; the 2024 GIABA assessment found no general legal-person BO filing duty or central BO register.
- Evidence to retain
- Registry evidence, declarations, corroboration, refresh log and discrepancies.
- Primary citation
- GIABA MER 2024, Recommendation 24
Identify foreign-trust role holders and control.
- Implementation action
- Where a foreign trust operates, holds assets or has a trustee in the jurisdiction, identify the persons who own or control it and document settlor, trustee, protector, beneficiaries and other effective controllers as a risk-based evidence standard.
- Evidence to retain
- Trust instrument, role register, identity files and control analysis.
- Primary citation
- Law 8/2013, Article 10(3); GIABA MER 2024, Recommendation 25
05PEPs, EDD, and failed CDDHigher-risk relationships require approval, source evidence and enhanced monitoring.3 items+
Detect PEP exposure.
- Implementation action
- Use reasonable measures to determine whether customers and beneficial owners are foreign, domestic or international-organisation PEPs and map family members and close associates.
- Evidence to retain
- Screening, relationship map, match decision and refresh history.
- Primary citation
- Law 8/2013, Article 12; NAP 10/2015; GIABA MER 2024, Recommendation 12
Apply senior approval, source and monitoring controls.
- Implementation action
- For PEP and other high-risk relationships, obtain senior approval, establish source of wealth and source of funds and apply enhanced ongoing monitoring.
- Evidence to retain
- Approval, source analysis, corroboration and monitoring plan.
- Primary citation
- Law 8/2013, Articles 11-12
Stop activity where required CDD cannot be completed.
- Implementation action
- Do not open or execute and address existing relationships consistently with current FIU and supervisory instructions; consider an STR and protect confidentiality.
- Evidence to retain
- Decline, restriction or exit decision, investigation and reporting record.
- Primary citation
- Law 8/2013, Article 10(4); GIABA MER 2024, criterion 10.19
06Monitoring and suspicious reportingFIU reporting must be immediate, complete and confidential.4 items+
Monitor activity against the customer profile.
- Implementation action
- Review transactions for consistency with known business, risk and source of funds and document investigation of complex, unusual or apparently purposeless activity.
- Evidence to retain
- Alerts, investigation notes, supporting data and dispositions.
- Primary citation
- Law 8/2013, Articles 10-11; NAP 11/2015
Report suspicion and attempts immediately.
- Implementation action
- Timestamp when suspicion or reasonable grounds arose and immediately report to the FIU, including attempted transactions and regardless of amount, through the current institutional route.
- Evidence to retain
- Decision chronology, STR, delivery evidence and receipt.
- Primary citation
- Law 8/2013, Article 21; GIABA MER 2024, Recommendation 20
Prevent tipping off.
- Implementation action
- Restrict report access and do not inform customers or third parties that a report or related information was or will be sent, or that an ML/TF investigation exists.
- Evidence to retain
- Need-to-know access, communications controls, training and audit log.
- Primary citation
- Law 8/2013, Article 22(1)
Use the current FIU form and preserve supplements.
- Implementation action
- Obtain the institutional COS form and filing instructions directly from the FIU, submit complete supporting information and preserve later supplements and FIU communications.
- Evidence to retain
- Current form, filing package, supplements, correspondence and acknowledgement.
- Primary citation
- UIF documents and contact pages; NAP 11/2015
07Payments, wires, thresholds, and agentsKeep CDD thresholds, sector triggers and reporting duties distinct.4 items+
Do not invent a general cash-transaction report.
- Implementation action
- Apply CDD, monitoring and STR duties to cash activity, but do not configure an automatic general cash-report threshold unless the FIU or competent supervisor confirms a current instrument; GIABA found no such general duty in 2024.
- Evidence to retain
- Legal register, authority confirmation, monitoring rules and change control.
- Primary citation
- GIABA MER 2024, paragraph 342
Apply sector-specific DNFBP triggers.
- Implementation action
- Confirm current redenominated amounts before implementation; the 2024 assessment records casino CDD at STN 50,000 and dealer-in-precious-metals/stones cash CDD at STN 245,000, alongside activity-based duties for real-estate and professional services.
- Evidence to retain
- Sector applicability memo, current-value confirmation, aggregation tests and CDD records.
- Primary citation
- Law 8/2013, Articles 3 and 10; GIABA MER 2024, criterion 22.1
Carry required wire information and control deficient transfers.
- Implementation action
- Apply Law No. 8/2013 and current Central Bank rules to originator and beneficiary information, retention and risk-based execute, reject, suspend and follow-up decisions; do not rely on the high statutory threshold as a risk safe harbour.
- Evidence to retain
- Field matrix, validation, repair queue, samples and decisions.
- Primary citation
- Law 8/2013, Article 15; GIABA MER 2024, Recommendation 16
Control payment agents and providers.
- Implementation action
- Verify licensing and agent authority, contract for AML, records, audit, privacy and incident controls, monitor performance and retain provider accountability.
- Evidence to retain
- Central Bank approvals, agent register, contracts, monitoring and incidents.
- Primary citation
- Law 17/2018; Decree-Law 16/2019
08Targeted financial sanctionsScreen continuously while controlling the known national implementation delay.3 items+
Screen authoritative UN designations and national notices.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, before activity and on list updates using current UN and national sources.
- Evidence to retain
- List inventory, update log, screening configuration, alerts and dispositions.
- Primary citation
- Law 3/2018; UN consolidated list; GIABA MER 2024, Recommendations 6 and 7
Escalate potential matches immediately.
- Implementation action
- Block execution while confirming a potential match, obtain current legal directions from the competent authority and document the treatment of assets and prohibited availability.
- Evidence to retain
- Alert chronology, escalation, authority direction, asset record and controls.
- Primary citation
- Law 3/2018; GIABA MER 2024, Recommendations 6 and 7
Do not represent gazette publication as FATF-standard immediacy.
- Implementation action
- Maintain a rapid operational process but record that GIABA found the national gazette-dependent mechanism did not implement UN targeted financial sanctions without delay; confirm the current designation, reporting, false-positive and release procedure.
- Evidence to retain
- Gap assessment, authority confirmation, timestamps, reports and release decision.
- Primary citation
- GIABA MER 2024, criteria 6.4 and 7.4
09Records and regulator accessRecords must reconstruct customers, transactions and decisions.3 items+
Retain CDD records for at least five years after relationship end or an occasional transaction.
- Implementation action
- Apply the correct relationship or occasional-transaction clock to customer, representative and beneficial-owner evidence and preserve legal holds.
- Evidence to retain
- Retention schedule, archive sample, deletion control and hold log.
- Primary citation
- Law 8/2013, Article 20(1)(a)
Retain transaction and attempted-transaction records for at least five years.
- Implementation action
- Apply a transaction-based clock and preserve domestic and international transaction records and commercial correspondence in reconstructable form.
- Evidence to retain
- Archive configuration, reconstruction test and retrieval log.
- Primary citation
- Law 8/2013, Article 20(1)(b); GIABA MER 2024, Recommendation 11
Provide records promptly under proper authority.
- Implementation action
- Authenticate requests, protect STR confidentiality, produce controlled records to the FIU and competent authorities and log approval, scope, delivery and receipt.
- Evidence to retain
- Request register, authority check, production index and acknowledgement.
- Primary citation
- Law 8/2013, Articles 20 and 22
10Privacy, biometrics, and transfersAML processing remains subject to Law No. 3/2016.3 items+
Document purpose, proportionality, accuracy and retention.
- Implementation action
- Inventory identity, ownership, screening, biometric, monitoring and reporting data; record the lawful basis, purpose, recipients, access and retention and keep data accurate and no longer than necessary subject to AML clocks.
- Evidence to retain
- Processing register, basis assessment, notice, access matrix and retention mapping.
- Primary citation
- Law 3/2016, Articles 5-6 and 18
Apply the statutory regime to sensitive and biometric data.
- Implementation action
- Complete a specific legal and security assessment before collecting biometrics, national identifiers, offence data or other sensitive information and obtain any required authority approval.
- Evidence to retain
- Data classification, legal assessment, authority record, security design and access review.
- Primary citation
- Law 3/2016
Control disclosures and cross-border transfers.
- Implementation action
- Map hosting, support and recipient locations, document the statutory transfer basis and safeguards and obtain any required authority authorisation before exporting personal data.
- Evidence to retain
- Transfer map, contracts, safeguards, authority record and access logs.
- Primary citation
- Law 3/2016, cross-border transfer provisions
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Law 8/2013, Articles 10-20
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, FIU reports, delivery evidence and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Law 8/2013, Articles 21-22
Maintain a launch and legal-change pack.
- Implementation action
- Record licensing, thresholds, sanctions, registry and privacy procedures, testing and authority confirmations before launch and material changes.
- Evidence to retain
- Signed launch pack, source register, uncertainty log and change approvals.
- Primary citation
- Official sources listed below
Primary-source register
11 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 8/2013 on prevention and combating money laundering and terrorist financingFinancial Intelligence Unit of São Tomé and Príncipe · Primary legislation
- UIF legislation repositoryFinancial Intelligence Unit of São Tomé and Príncipe · Official FIU repository
- UIF suspicious-activity contact and COS form pageFinancial Intelligence Unit of São Tomé and Príncipe · Official FIU procedure
- São Tomé and Príncipe 2024 Mutual Evaluation ReportGIABA · Authoritative regional assessment
- Law No. 3/2018 against terrorism and its financingFinancial Intelligence Unit of São Tomé and Príncipe · Primary legislation
- Law No. 17/2018 - legal regime of the national payment systemCentral Bank of São Tomé and Príncipe · Primary legislation
- Decree-Law No. 16/2019 - payment service providers and system operatorsCentral Bank of São Tomé and Príncipe · Primary legislation
- Guiché Único business-registration requirementsDirectorate-General of Registries and Notaries · Official registry guidance
- Law No. 3/2016 on protection of personal dataWHO Country Planning Cycle Database · Primary legislation copy
- FATF high-risk and monitored jurisdictions current at 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
São Tomé and Príncipe KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Financial Intelligence Unit (UIF), using its current institutional form and filing channel.
When is suspicion reported?+
Immediately once suspicion or reasonable grounds arise, including attempted transactions and regardless of amount.
Is there a general cash transaction report threshold?+
The 2024 GIABA assessment states that cash transaction reporting was not a general requirement. Cash remains subject to CDD, monitoring and STR duties, and current sector instructions must be checked.
How is beneficial ownership determined?+
Identify and verify the natural person who ultimately owns or effectively controls the customer. Because the national cascade and central-register framework have gaps, document both ownership and control and use a conservative senior-manager fallback where needed.
How long are core AML records retained?+
At least five years: CDD records after relationship end or the occasional transaction, and transaction records after the transaction or attempt.
What privacy law applies?+
Law No. 3/2016 governs personal-data processing, including purpose, quality, security, secrecy and international transfers.
Is São Tomé and Príncipe on a FATF public list?+
No. It was not named in FATF's public lists dated 19 June 2026. This does not make it low risk.
Can a payment or fintech service launch without approval?+
No. Classify the service, provider and agent model under Law No. 17/2018 and Decree-Law No. 16/2019 and obtain all applicable approvals first.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 8 September 2026. Confirm current Central Bank instruments, FIU institutional filing access, sanctions-gazette workflow, company-register practice, personal-data authority procedures and product-specific permissions with the competent authority and qualified São Toméan counsel before launch.