KYC, KYB & AML compliance checklist
Sierra Leone KYC, KYB & AML
An implementation checklist for customer and business verification in Sierra Leone under the 2024 AML/CFT/CPF Act, payment-system rules, sanctions controls and company-registration requirements.
- Reviewed
- 18 July 2026
- Version
- 1.0
- control areas
- 11
- implementation checks
- 38
Direct answer
What does the Sierra Leone compliance checklist cover?
The Sierra Leone checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML/CFT/CPF law
- Act 4 of 2024, Gazette 44 of 6 June 2024
- Financial intelligence unit
- Financial Intelligence Agency (FIA)
- STR timing
- As soon as practicable and no later than two days after suspicion or information
- Occasional-transaction CDD
- SLE 30,000 or more, including linked transactions within 24 hours
- Wire-transfer CDD
- SLE 3,000 or more for domestic or international wires
- Core AML retention
- At least five years, with the start event determined by record class
- Sanctions asset report
- As soon as reasonably practicable and within two working days under section 42
- Beneficial ownership
- Natural persons who ultimately own/control or exercise ultimate effective control; no universal AML percentage
- Payments and VASPs
- Activity-specific BSL or relevant-supervisor authority required before operations
- FATF public lists
- Not named in FATF statements dated 19 June 2026; GIABA enhanced follow-up continues
Implementation detail
Sierra Leone compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before launch.3 items+
Financial institutions and listed DNFBPs are reporting entities under the 2024 Act.
- Implementation action
- Map each entity, product, profession, branch, agent and outsourced service to the First Schedule and its supervisor.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor register.
- Primary citation
- 2024 Act, ss.1-2 and First Schedule
The FIA receives, analyses and disseminates reports and may issue binding guidelines and directives.
- Implementation action
- Register compliance contacts and obtain the current FIA reporting access, formats and instructions.
- Evidence to retain
- FIA correspondence, access records, contacts and regulatory calendar.
- Primary citation
- 2024 Act, ss.3, 20 and 167
Payment services, money transmission, financial services and VASP activity require applicable authority before operations.
- Implementation action
- Obtain a written BSL or relevant-supervisor perimeter decision and every licence or registration before pilot or launch.
- Evidence to retain
- Classification, application, licence, conditions and approved product map.
- Primary citation
- 2024 Act, ss.59 and 103; National Payment Systems Act 2022
02Governance, risk assessment and control ownershipBuild documented, risk-based and accountable controls.3 items+
Reporting entities identify and assess customer, product, delivery, geography and technology risks and apply mitigation.
- Implementation action
- Maintain enterprise, product and customer risk assessments and assess new products before launch.
- Evidence to retain
- Methodology, assessments, approvals, overrides and remediation.
- Primary citation
- 2024 Act, ss.51-53
Risk assessments are refreshed on events and at the Act's risk-tier intervals and submitted after completion.
- Implementation action
- Confirm the applicable tier, calendar the statutory review and one-calendar-month submission, and preserve receipts.
- Evidence to retain
- Risk classification, calendar, assessment, submission and receipt.
- Primary citation
- 2024 Act, s.53(1)-(3)
A senior compliance officer and internal AML/CFT/CPF programme, training and independent assurance are required.
- Implementation action
- Appoint an empowered officer, approve procedures, train relevant staff and test the lifecycle.
- Evidence to retain
- Appointment, charter, procedures, training and audit reports.
- Primary citation
- 2024 Act, ss.70-72, 159-160
03Natural-person identification and CDDApply every statutory trigger without treating thresholds as safe harbours.4 items+
Identity verification applies at account or relationship opening, SLE 30,000 occasional activity, SLE 3,000 wires, suspicion and identity doubt.
- Implementation action
- Configure all triggers, including linked occasional transactions within 24 hours and amount-independent suspicion.
- Evidence to retain
- Trigger matrix, aggregation tests, cases and exceptions.
- Primary citation
- 2024 Act, ss.55-56 and 60
Natural persons are verified from reliable independent official documents and address evidence.
- Implementation action
- Capture and authenticate identity, address, occupation and national-identification or passport evidence.
- Evidence to retain
- Identity file, authenticity result, address proof and screening decision.
- Primary citation
- 2024 Act, ss.56(1)-(2), 57(3)(c)
Purpose, intended nature, expected activity and source/destination information are understood proportionately.
- Implementation action
- Create an expected-activity profile and investigate material deviations.
- Evidence to retain
- Purpose statement, profile, source evidence, alerts and reviews.
- Primary citation
- 2024 Act, ss.55, 57(3), 68
Deferred verification is exceptional, risk-controlled and cannot exceed two calendar months.
- Implementation action
- Restrict activity, set a shorter completion SLA and close or consider an STR if evidence remains incomplete.
- Evidence to retain
- Exception approval, restrictions, completion or closure and STR decision.
- Primary citation
- 2024 Act, s.57(6)-(8)
04KYB, authority and beneficial ownershipVerify existence, authority and ultimate natural-person ownership or control.4 items+
Legal-entity CDD verifies legal existence, registered office, directors, powers, owners, beneficiaries and control structure.
- Implementation action
- Obtain current NIB evidence and constitutive records and reconcile directors, mandates and ownership.
- Evidence to retain
- Registry extract, certificate, constitution, annual return, directors and discrepancy log.
- Primary citation
- 2024 Act, ss.1, 56(3)-(4), 57(3)(d)
Representatives require verified identity and authority.
- Implementation action
- Verify each representative separately and validate the mandate before activity.
- Evidence to retain
- Identity file, mandate, board authority and verification result.
- Primary citation
- 2024 Act, ss.55(5)(a), 57(3)(d)(iii)
Beneficial owners are natural persons who ultimately own or control or exercise ultimate effective control.
- Implementation action
- Trace every ownership layer, test non-ownership control and verify each identified natural person without inventing a universal percentage.
- Evidence to retain
- Ownership chart, source records, control analysis and BO identity files.
- Primary citation
- 2024 Act, s.1 definitions of beneficial owner and customer due diligence; s.57
Trust information covers settlor, trustees, protector, beneficiaries or class and every natural person exercising ultimate effective control.
- Implementation action
- Verify the trust instrument, roles, powers and relevant natural persons.
- Evidence to retain
- Trust deed, role register, control analysis and identity files.
- Primary citation
- 2024 Act, s.57(13)
05PEPs, enhanced due diligence and remote onboardingApply stronger controls to higher risk and non-face-to-face relationships.4 items+
Systems determine whether customers, beneficial owners and relevant insurance beneficiaries are PEPs.
- Implementation action
- Screen before activation and continuously and resolve family and close-associate exposure.
- Evidence to retain
- Screening, match decision, role and relationship evidence.
- Primary citation
- 2024 Act, ss.1 and 63
PEPs require senior-management approval, reasonable source-of-wealth and source-of-funds measures and enhanced monitoring.
- Implementation action
- Corroborate source evidence, document approval and configure enhanced monitoring.
- Evidence to retain
- Source file, approval, monitoring plan and reviews.
- Primary citation
- 2024 Act, s.63
Remote CDD must be no less effective than in-person CDD and use additional independent or confirmatory evidence.
- Implementation action
- Use document-integrity, liveness/presence, independent-data, device and fraud controls proportionate to risk.
- Evidence to retain
- Remote standard, test results, fraud logs and exceptions.
- Primary citation
- 2024 Act, s.62
Third-party reliance does not transfer ultimate responsibility and requires immediate information and documents without delay.
- Implementation action
- Assess supervision and jurisdiction, contract for access and test document retrieval.
- Evidence to retain
- Due diligence, agreement, retrieval tests and monitoring.
- Primary citation
- 2024 Act, s.61
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity and report suspicion promptly and confidentially.5 items+
Failed CDD prevents account establishment or continuation and may require an STR.
- Implementation action
- Block activation or terminate under controlled procedures and send the case to confidential reporting review.
- Evidence to retain
- Failure reason, block, closure, STR decision and receipt.
- Primary citation
- 2024 Act, ss.55(6), 57(2), 65, 153
Ongoing monitoring keeps customer and BO information current and examines complex, unusual and large activity.
- Implementation action
- Configure risk and event refresh, transaction scenarios and documented investigation of unusual activity.
- Evidence to retain
- Refresh schedule, alerts, cases, findings and updated CDD.
- Primary citation
- 2024 Act, ss.68 and 53(4)
Suspected transactions, attempts, information or facts linked to ML, TF or PF are reportable to FIA.
- Implementation action
- Escalate immediately, preserve the suspicion timestamp and submit the prescribed STR.
- Evidence to retain
- Internal report, analysis, STR, receipt and timeline.
- Primary citation
- 2024 Act, ss.76-78
An STR is due as soon as practicable and no later than two days after suspicion or information.
- Implementation action
- Use a shorter internal SLA measured from the recorded formation or receipt time.
- Evidence to retain
- Trigger timestamp, approval, submission time and SLA monitoring.
- Primary citation
- 2024 Act, s.76(1)
Tipping off is prohibited and good-faith reporting is protected.
- Implementation action
- Restrict access and govern customer communications and lawful disclosures.
- Evidence to retain
- Access logs, communication plan, training and disclosure register.
- Primary citation
- 2024 Act, ss.80-83
07Wires, thresholds, payments and agentsKeep CDD, internal lists and FIA-prescribed reports distinct.4 items+
Wire transfers carry required originator and beneficiary information and deficient messages require governed action.
- Implementation action
- Validate fields through the chain and execute, reject, suspend or report under risk-based procedures.
- Evidence to retain
- Field matrix, validation, repair/reject queue and samples.
- Primary citation
- 2024 Act, ss.67 and 69
The Act requires an internal list for currency-exchange and money-transmission cash transactions of SLE 3,000 or more.
- Implementation action
- Maintain the list and do not misstate it as a universal FIA filing threshold; apply current FIA cash/foreign-report thresholds separately.
- Evidence to retain
- Scope memo, internal list, FIA directive and report receipts.
- Primary citation
- 2024 Act, ss.66(4) and 76(6)
Licensed payment providers and operators comply with AML rules and ensure agent compliance.
- Implementation action
- Include agents in the programme, maintain a current list and monitor outsourced controls.
- Evidence to retain
- Licence, agent register, contracts, monitoring and remediation.
- Primary citation
- National Payment Systems Act 2022, ss.22 and 36; 2024 Act, ss.59(4), 69(13)
VASPs must identify risks, obtain relevant-supervisor registration and licence before operating and transmit originator/beneficiary information.
- Implementation action
- Do not launch until the competent supervisor confirms perimeter, authority and transfer-data requirements.
- Evidence to retain
- Legal classification, registration, licence, travel-rule design and tests.
- Primary citation
- 2024 Act, s.103
08Targeted financial sanctionsScreen current domestic, UN and ECOWAS designations and act promptly.3 items+
Business relationships and dealings with sanctioned persons, entities, groups and specified sanctioned-country interests are prohibited.
- Implementation action
- Screen customers, BOs, representatives, counterparties, vessels and transactions at onboarding and list change.
- Evidence to retain
- List provenance, screening logs, match decisions and population reconciliation.
- Primary citation
- 2024 Act, ss.35-39
Suspected sanctioned ownership or control is referred immediately in writing to the Director-General or competent authority.
- Implementation action
- Maintain a 24/7 escalation route, hold relevant activity and seek written verification without alerting the subject.
- Evidence to retain
- Match analysis, request, hold and response.
- Primary citation
- 2024 Act, s.41
Assets held for sanctioned persons or entities are reported as soon as reasonably practicable and within two working days.
- Implementation action
- Inventory affected assets and report through the current FIA or competent-authority procedure.
- Evidence to retain
- Asset inventory, trigger time, report and receipt.
- Primary citation
- 2024 Act, s.42
09Records, access and assuranceRetain reconstructable evidence under the correct clock.3 items+
CDD, transaction, unusual-activity findings and STR records are kept for at least five years under class-specific clocks.
- Implementation action
- Map each record class to transaction completion, relationship end or report date and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, samples and deletion tests.
- Primary citation
- 2024 Act, s.66
Records must reconstruct transactions and be immediately or swiftly available to FIA and competent authorities.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test retrieval.
- Evidence to retain
- Request register, retrieval tests, access controls and response package.
- Primary citation
- 2024 Act, ss.66 and 69(11)
Governed backups and authentication are required for machine-readable or electronic records.
- Implementation action
- Test backup, recovery, integrity and authorised access for the full retention period.
- Evidence to retain
- Architecture, backup tests, audit logs and recovery evidence.
- Primary citation
- 2024 Act, s.66(5)
10Privacy, identity data and transfersApply verified sector rules and cautious data governance while national privacy law remains in transition.3 items+
Payment providers process and retain necessary personal data and follow statutory consent, fraud-prevention and disclosure rules.
- Implementation action
- Document necessity and permissions, minimise fields and prohibit unauthorised sale or sharing.
- Evidence to retain
- Data inventory, notices, permissions, access logs and sharing register.
- Primary citation
- National Payment Systems Act 2022, s.21
Sensitive identity and biometric processing requires documented necessity, security and access governance even where no comprehensive statute is asserted.
- Implementation action
- Complete legal, privacy and security assessments before biometric use and contractually control processors.
- Evidence to retain
- Assessment, data flow, access controls, testing and vendor assurance.
- Primary citation
- Recommended control; sector duties and applicable law must be confirmed
Cross-border transfers, incidents and deletion require a verified legal basis and sector procedure.
- Implementation action
- Confirm current Sierra Leone requirements with counsel and regulators before implementation; do not invent a notification deadline.
- Evidence to retain
- Legal memo, transfer map, incident playbook, contracts and decisions.
- Primary citation
- Controlled uncertainty; National Payment Systems Act 2022, s.21 where applicable
11Practical evidence packs and change controlMake decisions reconstructable and keep time-sensitive rules current.2 items+
A complete customer file links identity, KYB, ownership, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation when mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- 2024 Act, Part IX
FIA directives, thresholds, sanctions lists, FATF status, company law, licensing and privacy requirements require ongoing monitoring.
- Implementation action
- Assign owners and review FIA, BSL, NIB, Gazette, FATF and GIABA sources on a governed schedule.
- Evidence to retain
- Legal inventory, source log, change assessments and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 38 implementation checks, with direct regulatory sources.
Download the Sierra Leone KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Sierra Leone implementation checklist. Regulatory review date: 18 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.0, reviewed 18 July 2026
Trusted by leading compliance teams
Primary-source register
10 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- AML/CFT/CPF Act, 2024 (Act 4 of 2024)Sierra Leone Gazette text via SierraLII · Primary legislation reproduction
- National Payment Systems Act, 2022Sierra Leone Gazette text via SierraLII · Primary legislation reproduction
- Bank of Sierra LeoneBank of Sierra Leone · Official regulator
- BSL legislation and regulatory frameworkBank of Sierra Leone · Official regulator
- National Investment Board Act, 2022Sierra Leone Gazette text via SierraLII · Primary legislation reproduction
- NIB business registration and corporate affairsNational Investment Board · Official company registry guidance
- NIB business forms including beneficial ownershipNational Investment Board · Official company registry guidance
- Sierra Leone fifth enhanced follow-up report, 2025GIABA · Authoritative regional assessment
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Direct answers
Sierra Leone KYC, KYB and AML questions
Who receives suspicious transaction reports in Sierra Leone?+
The Financial Intelligence Agency. Use its current prescribed form and channel.
When is an STR due?+
As soon as practicable and no later than two days after forming suspicion or receiving the relevant information.
When does occasional-transaction CDD apply?+
At SLE 30,000 or more, including apparently linked transactions within 24 hours; suspicion and identity doubt apply regardless of amount.
Does Sierra Leone use one AML beneficial-ownership percentage?+
The 2024 Act's AML definition does not state one universal percentage. Identify natural persons who ultimately own or control or exercise ultimate effective control.
How long are core AML records kept?+
At least five years, with the start event depending on the record class.
Are payment or virtual-asset services permitted by company registration alone?+
No. Obtain the applicable BSL or relevant-supervisor classification, registration and licence before operations.
How quickly are sanctioned assets reported?+
As soon as reasonably practicable and in any event within two working days under section 42, using the current competent-authority procedure.
Is Sierra Leone on a FATF public list?+
Sierra Leone was not named in FATF's public statements dated 19 June 2026. GIABA enhanced follow-up is a separate peer-review process.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 18 July 2026 · Version 1.0
This checklist is general regulatory information, not legal advice or a licence determination. It reflects sources reviewed on 18 July 2026. Confirm FIA directives, reporting channels and threshold-report specifications; BSL licensing and product conditions; NIB company-law commencement, forms and beneficial-ownership procedures; sanctions instructions; and applicable privacy requirements with Sierra Leone counsel and the competent authority before launch. VOVE ID supports evidence collection and audit trails; the reporting entity remains responsible for acceptance, reporting, restraint and compliance decisions.