KYC, KYB & AML compliance checklist
Seychelles KYC, KYB & AML
An implementation checklist for customer and business verification under Seychelles' consolidated AML/CFT framework, beneficial-ownership regime, Data Protection Act 2023 and regulated financial-services perimeter.
- Reviewed
- 22 July 2026
- Version
- 1.0
- control areas
- 11
- implementation checks
- 34
Direct answer
What does the Seychelles compliance checklist cover?
The Seychelles checklist translates primary KYC, KYB and AML rules into 11 control areas and 34 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML/CFT law
- AML/CFT Act 2020, revised to 17 January 2025
- Financial intelligence unit
- Seychelles Financial Intelligence Unit
- STR timing
- Within two business days of suspicion, grounds or information
- One-off CDD threshold
- Above SCR 50,000 in cash or wire transfers, including linked operations
- Cash and wire reports
- SCR 50,000 or more, subject to the exact Schedule 3 scope
- Core AML retention
- Minimum seven years; specified sectors retain digital records for 30 years
- Beneficial ownership
- 10% ownership/control plus control, board-appointment and fallback tests
- Privacy breach notice
- Information Commission within 72 hours; delayed notices need reasons
- VASP perimeter
- FSA licence required for in-scope services under the VASP Act 2024
- FATF public lists
- Not named in the June 2026 public statements
Implementation detail
Seychelles compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before launch.3 items+
Financial institutions, VASPs and listed non-financial businesses and professions may be reporting entities.
- Implementation action
- Map each entity, product, profession, branch, agent and outsourced service to the Act's reporting-entity definition and supervisory allocation.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor confirmation.
- Primary citation
- AML/CFT Act 2020, s.2 and First Schedule, as revised
The FIU receives and analyses reports and may request records; CBS and FSA supervise activities within their statutory remits.
- Implementation action
- Register compliance contacts and obtain the current reporting and supervisory instructions for each entity.
- Evidence to retain
- FIU access, correspondence, supervisor register and regulatory calendar.
- Primary citation
- AML/CFT Act 2020, ss.10-13 and 48; official CBS and FSA frameworks
Virtual asset services in or from Seychelles require the applicable FSA licence under the 2024 framework.
- Implementation action
- Obtain a written perimeter decision and licence before offering exchange, transfer, custody or other in-scope virtual-asset services.
- Evidence to retain
- Classification, application, licence, conditions and approved service map.
- Primary citation
- Virtual Asset Service Providers Act 2024; FSA VASP legal framework and FAQs
02Governance, risk assessment and control ownershipBuild documented, risk-based and accountable controls.2 items+
Reporting entities must appoint a compliance officer and alternate and maintain an institutional risk assessment.
- Implementation action
- Appoint qualified officers, document authority and assess customer, product, channel, geography and delivery risks before launch and on change.
- Evidence to retain
- Appointments, fit-and-proper records, risk assessment, approvals and review log.
- Primary citation
- AML/CFT Act 2020, ss.32 and 34; AML/CFT Regulations 2020
Internal controls, employee screening, training and independent testing must be proportionate to risk.
- Implementation action
- Approve a group-aware programme and independently test design and operating effectiveness.
- Evidence to retain
- Policies, training, screening, audit reports and remediation register.
- Primary citation
- AML/CFT Act 2020, ss.31-34; AML/CFT Regulations 2020
03Natural-person identification and CDDApply statutory triggers without treating thresholds as safe harbours.4 items+
CDD applies to relationships, every qualifying one-off transaction, identity doubt and suspicion.
- Implementation action
- Configure relationship, transaction, linked-operation, suspicion and identity-quality triggers and record the applicable basis.
- Evidence to retain
- Trigger matrix, aggregation results, identity file and decision timestamps.
- Primary citation
- AML/CFT Act 2020, ss.35 and 49
A one-off transaction exceeds SCR 50,000 in cash or wire transfers, singly or through apparently linked operations.
- Implementation action
- Aggregate linked activity and apply CDD regardless of amount where suspicion or identity doubt exists.
- Evidence to retain
- Aggregation logic, alerts, CDD file and override record.
- Primary citation
- AML/CFT Act 2020, s.49(1)-(2)
Identity must be identified and verified from reliable, independent or otherwise reasonably reliable sources.
- Implementation action
- Capture required identity attributes and authenticate evidence proportionately to risk.
- Evidence to retain
- Identity evidence, authenticity result, provenance and risk decision.
- Primary citation
- AML/CFT Act 2020, s.35(2)(a)
CDD is completed before or during establishment or a one-off transaction; limited delayed verification needs documented risk controls and prompt completion.
- Implementation action
- Block unrestricted use until verification is complete and document each statutory condition and limit.
- Evidence to retain
- Verification timestamp, restrictions, exception approval and completion log.
- Primary citation
- AML/CFT Act 2020, s.39
04KYB, authority and beneficial ownershipVerify existence, authority and ultimate natural-person ownership or control.4 items+
Legal-person CDD covers name, legal form, existence, governing powers, senior managers, registered office and principal place of business.
- Implementation action
- Obtain current registry and constitutive evidence and reconcile directors, mandates and addresses.
- Evidence to retain
- Registry extract, certificate, constitution, directors and discrepancy log.
- Primary citation
- AML/CFT Act 2020, s.35(4)
A representative's authority and identity must be verified.
- Implementation action
- Verify each actor and reconcile the mandate to current board or constitutive authority.
- Evidence to retain
- Identity file, mandate, board resolution and verification result.
- Primary citation
- AML/CFT Act 2020, s.35(4)(b)-(c)
For legal persons, BO determination includes natural persons with 10% or more ownership or control, majority-board appointment rights, other control and a senior-manager fallback.
- Implementation action
- Trace every ownership layer and test ownership, voting, appointment and other-control paths before applying the fallback.
- Evidence to retain
- Ownership chart, registry records, control analysis and BO identity files.
- Primary citation
- Beneficial Ownership Regulations 2020, reg.3, as consolidated
Trusts and other legal arrangements use role-based tests rather than the 10% legal-person threshold.
- Implementation action
- Identify and verify the settlor, trustees, protector where applicable, beneficiaries or class and every other person exercising ultimate control.
- Evidence to retain
- Trust instrument, role register, identity files and control analysis.
- Primary citation
- Beneficial Ownership Regulations 2020, reg.3(6)-(7), as consolidated
05PEPs, enhanced due diligence and relianceApply stronger controls to higher-risk relationships.3 items+
Domestic, foreign and international-organisation PEPs, immediate family and close associates require EDD and enhanced monitoring.
- Implementation action
- Screen customers and BOs, obtain senior-management approval and establish source of wealth and source of funds.
- Evidence to retain
- Screening, match rationale, source file, approval and monitoring plan.
- Primary citation
- AML/CFT Act 2020, s.36
Higher-risk situations and relevant higher-risk countries require risk-sensitive EDD.
- Implementation action
- Document enhanced evidence, corroboration, approval and monitoring frequency.
- Evidence to retain
- EDD standard, jurisdiction assessment, approvals and alert tuning.
- Primary citation
- AML/CFT Act 2020, s.41
Reliance does not transfer responsibility; required information is immediate and copies must be available within three working days of request.
- Implementation action
- Assess the regulated person, contract for access and test document retrieval.
- Evidence to retain
- Due diligence, agreement, retrieval test and exception log.
- Primary citation
- AML/CFT Act 2020, s.42
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity and report suspicion promptly and confidentially.4 items+
Failed CDD prevents a transaction or relationship and requires termination where applicable.
- Implementation action
- Block or terminate under controlled procedures and refer the case for confidential STR assessment.
- Evidence to retain
- Failure reason, block, closure, STR decision and receipt.
- Primary citation
- AML/CFT Act 2020, s.43
Relationships require ongoing scrutiny, current CDD and examination of complex, unusual or large activity without apparent purpose.
- Implementation action
- Investigate, document background and purpose, refresh CDD and escalate suspicion.
- Evidence to retain
- Alerts, cases, written findings, refreshed CDD and approvals.
- Primary citation
- AML/CFT Act 2020, s.46
Transactions and attempted transactions linked to criminal conduct, ML or TF are reportable to the FIU within two business days.
- Implementation action
- Record when grounds, suspicion or information arose and submit using the current FIU route within the statutory clock.
- Evidence to retain
- Internal report, analysis, STR, FIU acknowledgement and timeline.
- Primary citation
- AML/CFT Act 2020, s.48(1)-(4)
Tipping off is prohibited.
- Implementation action
- Restrict case access and govern customer communications, holds and lawful disclosures.
- Evidence to retain
- Access logs, communications plan, training and disclosure register.
- Primary citation
- AML/CFT Act 2020, s.50
07Wires, thresholds, payments and agentsKeep CDD, transaction records and threshold reports distinct.3 items+
Cash transactions of SCR 50,000 or more by reporting entities and specified wire transfers of SCR 50,000 or more are reported under Schedule 3.
- Implementation action
- Configure the exact entity, direction, transaction and aggregation scope; obtain FIU instructions for format and exemptions.
- Evidence to retain
- Threshold matrix, configuration, reports, acknowledgements and exemption record.
- Primary citation
- AML/CFT Act 2020, s.5 and Schedule 3
Wire transfers carry required originator and beneficiary information and deficient transfers follow risk-based reject, suspend, execute and follow-up rules.
- Implementation action
- Validate fields throughout the payment chain and govern repair or rejection.
- Evidence to retain
- Field matrix, validation, repair queue and transaction samples.
- Primary citation
- AML/CFT Act 2020, ss.45-45A
Payment, remittance, e-money, agent and fintech models require current activity-specific authority.
- Implementation action
- Do not launch until CBS, FSA or the competent authority confirms every required licence and agent condition.
- Evidence to retain
- Perimeter advice, application, licence, agent register and monitoring.
- Primary citation
- Official CBS and FSA regulatory frameworks; activity-specific dependency
08Targeted financial sanctions and CPFOperate current screening, freezing and reporting controls.2 items+
Seychelles implements targeted financial sanctions through the Prevention of Terrorism and UN implementation framework.
- Implementation action
- Screen customers, BOs, representatives and transactions against current UN and domestic designations and escalate potential matches immediately.
- Evidence to retain
- List provenance, screening logs, match decisions, holds and authority correspondence.
- Primary citation
- Prevention of Terrorism Act and UN Security Council implementation regulations; CBS AML/CFT framework
Operational freeze, false-positive, reporting and CPF handling must follow the current competent-authority instructions.
- Implementation action
- Maintain a 24/7 escalation route and obtain written instructions before release or dealing with potentially affected property.
- Evidence to retain
- Procedure, escalation log, instruction, decision and audit trail.
- Primary citation
- Controlled implementation dependency; confirm with FIU and competent authority
09Records, access and assuranceRetain reconstructable evidence under the correct clock.3 items+
CDD, transaction, FIU-report and enquiry records are retained for at least seven years under record-class-specific clocks.
- Implementation action
- Map each class to identity collection, transaction or correspondence, or relationship cessation and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, samples and deletion tests.
- Primary citation
- AML/CFT Act 2020, s.47(1)-(2)
Banks, bureaux de change, insurance companies and securities-exchange infrastructures retain specified records digitally for 30 years after relationship cessation.
- Implementation action
- Apply this sector-specific overlay only to in-scope entities and preserve readable, authenticated records.
- Evidence to retain
- Entity mapping, archive configuration, integrity and retrieval tests.
- Primary citation
- AML/CFT Act 2020, s.47(3)-(5)
Records must reconstruct transactions and be immediately available to FIU or competent authorities.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test retrieval.
- Evidence to retain
- Request register, retrieval tests, access controls and response package.
- Primary citation
- AML/CFT Act 2020, s.47(4)-(6)
10Privacy, biometrics and transfersApply the Data Protection Act alongside AML retention and access duties.4 items+
Personal data processing requires a lawful basis, minimisation, quality, security, accountability and purpose controls.
- Implementation action
- Document purpose and basis, minimise collection, restrict access and reconcile privacy retention with statutory AML duties.
- Evidence to retain
- Data inventory, processing record, notices, access matrix and retention mapping.
- Primary citation
- Data Protection Act 2023, ss.15-21
Biometrics are sensitive data and processing is prohibited unless a section 22 exception applies.
- Implementation action
- Document the exact exception, necessity and safeguards before biometric onboarding and complete an impact assessment where high risk.
- Evidence to retain
- Legal basis, consent where used, DPIA, model tests and access logs.
- Primary citation
- Data Protection Act 2023, ss.2, 22 and 38
The Information Commission must be notified of a personal-data breach within 72 hours of awareness; delay requires reasons, and affected people are promptly informed where the statutory risk test is met.
- Implementation action
- Timestamp awareness, assess impact and operate regulator and data-subject notification playbooks.
- Evidence to retain
- Incident log, assessment, notifications, delivery evidence and remediation.
- Primary citation
- Data Protection Act 2023, ss.43-44
Cross-border transfers require a comparable level of protection and compliance with section 47 conditions.
- Implementation action
- Assess destination protection, document transfer purpose, notify data subjects where required and obtain Commission authority where applicable.
- Evidence to retain
- Transfer assessment, data map, notices, contracts and Commission correspondence.
- Primary citation
- Data Protection Act 2023, s.47
11Practical evidence packs and change controlMake decisions reconstructable and keep time-sensitive rules current.2 items+
A complete customer file links identity, KYB, ownership, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation when mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- AML/CFT Act 2020, Parts VI-VII
FIU directions, thresholds, sanctions lists, FATF status, privacy guidance, registry and licensing requirements require ongoing monitoring.
- Implementation action
- Assign owners and review FIU, CBS, FSA, Registration Division, Information Commission, Gazette, FATF and ESAAMLG sources on a governed schedule.
- Evidence to retain
- Legal inventory, source log, change assessments and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 34 implementation checks, with direct regulatory sources.
Download the Seychelles KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Seychelles implementation checklist. Regulatory review date: 22 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.0, reviewed 22 July 2026
Trusted by leading compliance teams
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Consolidated AML/CFT Act 2020, revised to 17 January 2025Central Bank of Seychelles · Primary legislation - official consolidated copy
- Consolidated AML/CFT Regulations 2020 to 17 January 2025Seychelles Financial Intelligence Unit · Primary legislation - official FIU library
- CBS AML/CFT regulatory frameworkCentral Bank of Seychelles · Official regulator framework
- Beneficial Ownership Act 2020Seychelles Registration Division · Primary legislation - official registry source
- Beneficial Ownership legislation and consolidated regulationsSeychelles Financial Intelligence Unit · Primary legislation and official FIU resource
- Beneficial ownership guidance and consolidated frameworkFinancial Services Authority · Official regulator guidance
- Data Protection Act 2023Seychelles Official Gazette · Primary legislation
- Information CommissionSeychelles Information Commission · Official privacy authority
- Virtual Asset Service Providers legal frameworkFinancial Services Authority · Primary legislation and official regulator guidance
- Virtual Asset Service Providers FAQsFinancial Services Authority · Official regulator guidance
- Jurisdictions under Increased Monitoring - June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - June 2026FATF · Authoritative public statement
Direct answers
Seychelles KYC, KYB and AML questions
Who receives suspicious transaction reports in Seychelles?+
The Seychelles Financial Intelligence Unit, using its current reporting route and prescribed format.
When is an STR due?+
Within two business days of ascertaining reasonable grounds, forming suspicion or receiving relevant information; attempted transactions are included regardless of amount.
What is the one-off CDD threshold?+
A one-off cash or wire transaction above SCR 50,000, including apparently linked operations; suspicion and identity doubt trigger CDD regardless of amount.
What beneficial-ownership threshold applies to legal persons?+
The consolidated BO framework uses 10% ownership or control, plus board-appointment, other-control and senior-management fallback tests. Trusts and other legal arrangements use role-based tests.
How long are AML records kept?+
At least seven years under record-class-specific clocks. Banks, bureaux de change, insurers and securities-exchange infrastructures also have a 30-year digital-retention overlay after relationship cessation.
Are VASPs licensed in Seychelles?+
Yes. In-scope virtual asset services in or from Seychelles require the applicable FSA licence under the VASP Act 2024; obtain an activity-specific perimeter decision.
When must a personal-data breach be reported?+
The Information Commission must be notified within 72 hours after awareness, with reasons for delay; affected individuals are promptly informed where the section 44 test is met.
Is Seychelles on a FATF public list?+
Seychelles was not named in FATF's June 2026 increased-monitoring or call-for-action statements.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 22 July 2026 · Version 1.0
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative sources reviewed on 22 July 2026. Confirm the current FIU reporting portal, exemption mechanics, sector-specific supervision, sanctions and CPF procedure, registry filing workflow, Data Protection Act implementation guidance and each activity-specific licence with Seychelles counsel and the competent authority before launch. VOVE ID supports evidence collection and audit trails; the reporting entity remains responsible for acceptance, reporting, restraint and compliance decisions.