Somalia KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Somalia.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Somalia compliance checklist cover?
The Somalia checklist translates primary KYC, KYB and AML rules into 11 control areas and 43 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Financial Reporting Center (FRC)
- Primary AML rule
- AML/CFT Amendment Act, 2025
- Suspicion reporting
- Promptly to FRC, including attempts and regardless of amount
- CDD thresholds
- USD 10,000 occasional/linked; USD 1,000 occasional wire
- Core AML retention
- At least 5 years under record-specific clocks
- FATF status
- Not named on FATF public lists at 19 June 2026
Implementation detail
Somalia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve federal coverage, supervisor and licensing before launch.3 items+
Map each entity and activity to the reporting-entity perimeter.
- Implementation action
- Classify financial institutions, covered DNFBPs and virtual-asset service providers under Article 4 and identify the FRC and designated competent supervisor for each activity.
- Evidence to retain
- Applicability memo, entity and product map, supervisor matrix and accountable owner.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 4 and 23
Register and report through the current FRC channel.
- Implementation action
- Register the reporting organisation and authorised users in the production goAML portal, follow current FRC guidance and preserve submission acknowledgements.
- Evidence to retain
- goAML registration, reporter mandate, access controls, channel test and receipts.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 14 and 21; FRC goAML portal
Obtain approval before regulated financial or payment activity.
- Implementation action
- Classify banking, money transfer, mobile money, payment, microfinance, takaful, agent, outsourcing and virtual-asset activities and obtain every applicable federal licence or approval before launch.
- Evidence to retain
- Perimeter analysis, CBS or other licence, conditions, agent approvals and renewal calendar.
- Primary citation
- Financial Institutions Law 2025; CBS regulatory guidelines; AML/CFT Amendment Act 2025, Article 4
02Governance and risk assessmentControls must be approved, risk-based, resourced and independently tested.3 items+
Maintain a written AML/CFT programme.
- Implementation action
- Implement senior-management-approved policies, a sufficiently senior and resourced compliance officer, employee screening, documented training and independent audit.
- Evidence to retain
- Signed policy suite, officer mandate, resources, screening, training and audit reports.
- Primary citation
- AML/CFT Amendment Act 2025, Article 17
Assess institutional risk at least annually.
- Implementation action
- Document customer, geography, product, service, transaction, delivery-channel and technology risks annually, before new-product launch, on material change and when required by the supervisor.
- Evidence to retain
- Risk methodology, annual assessment, launch assessments, approvals and remediation.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 9 and 9A
Control group, agent and outsourced implementation.
- Implementation action
- Apply group-wide information-sharing and control standards where applicable; contract, train and monitor agents and outsourced providers without transferring accountability.
- Evidence to retain
- Group policy, contracts, agent register, monitoring, retrieval tests and exceptions.
- Primary citation
- AML/CFT Amendment Act 2025, Article 17; CBS Mobile Money Regulation, regulation 32-33
03Natural-person identificationIdentify and verify customers and representatives at every statutory trigger.4 items+
Identify and verify customers from reliable independent evidence.
- Implementation action
- Capture identity attributes, verify them using reliable independent documents, data or information, and record purpose and intended nature before establishing the relationship.
- Evidence to retain
- CDD file, evidence provenance, purpose, expected activity and decision timestamp.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(1)
Apply CDD to occasional and linked transactions at USD 10,000.
- Implementation action
- Aggregate apparently linked operations and complete CDD at or above USD 10,000 equivalent; apply CDD regardless of amount for suspicion or doubt about prior identification data.
- Evidence to retain
- Threshold table, aggregation logic, alerts, CDD timestamps and exchange-rate record.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(2)(b), (c) and (e)
Apply CDD to occasional wire transfers at USD 1,000.
- Implementation action
- Identify and verify for occasional wire transfers at or above USD 1,000 equivalent and do not treat the threshold as a monitoring safe harbour.
- Evidence to retain
- Wire trigger rule, identity evidence, aggregation and transaction record.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(2)(d)
Verify representatives and authority.
- Implementation action
- Identify and verify each person acting for a customer and validate the mandate before allowing activity.
- Evidence to retain
- Identity evidence, mandate, authority verification and expiry control.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(1)(b)
04KYB, registries, and beneficial ownershipVerify existence, authority, ownership, control and registry filings.5 items+
Verify legal-person identity and authority.
- Implementation action
- Obtain current Company Registry evidence, proof of existence, legal form, governing powers, registered and principal addresses, senior managers, licences and mandates, and resolve inconsistencies.
- Evidence to retain
- Registry extract, constitutional documents, officer list, licences and discrepancy log.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(7); Company Law 2019
Apply the statutory beneficial-owner cascade.
- Implementation action
- Identify and verify the natural person exercising ultimate control through ownership; if none or doubt remains, identify control through other means; if no natural person is identified, record the relevant senior managing official.
- Evidence to retain
- Ownership chart, control analysis, verified identities and fallback rationale.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(8)(a)
Identify trust and arrangement role holders.
- Implementation action
- Identify and verify settlor, trustees, protector if any, beneficiaries or class, and every other natural person exercising ultimate effective control.
- Evidence to retain
- Trust instrument, role register, verified identities and control analysis.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(8)(b)-(c)
Reconcile beneficial-owner registry information.
- Implementation action
- Obtain the customer's electronic Company Registry and beneficial-owner filings, compare them with declarations and independent evidence, and investigate discrepancies.
- Evidence to retain
- Registry evidence, declarations, corroboration and discrepancy resolution.
- Primary citation
- AML/CFT Amendment Act 2025, Article 23C(1)-(3); MOCI Beneficial Ownership Registry
Control one-month registry change deadlines.
- Implementation action
- For Somali legal persons, file basic and beneficial-owner changes electronically as soon as reasonably practicable and within one month, and notify reporting entities of BO changes within one month of awareness.
- Evidence to retain
- Change chronology, electronic filing, receipt and customer notification.
- Primary citation
- AML/CFT Amendment Act 2025, Article 23C(1)(b), (e) and (h)
05PEPs, EDD, and failed CDDHigher-risk relationships require approval, source evidence and enhanced monitoring.4 items+
Detect PEP exposure for customers and beneficial owners.
- Implementation action
- Use appropriate risk systems to identify foreign, domestic and international-organisation PEPs and relevant family members and close associates.
- Evidence to retain
- Screening, relationship map, match decision and refresh history.
- Primary citation
- AML/CFT Amendment Act 2025, Article 10(1)-(2)
Apply approval, source and monitoring controls.
- Implementation action
- For foreign PEPs and higher-risk domestic or international PEP relationships, obtain senior approval, establish source of wealth and source of funds, review relevant information and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, source analysis, corroboration and monitoring plan.
- Primary citation
- AML/CFT Amendment Act 2025, Article 10(2)
Apply enhanced measures to higher-risk activity.
- Implementation action
- Document proportionate enhanced measures for higher-risk relationships, complex or unusually large transactions, purposeless patterns and designated higher-risk jurisdictions.
- Evidence to retain
- Risk rationale, enhanced measures, transaction review and approval.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 8 and 11
Stop or terminate when required CDD cannot be completed.
- Implementation action
- Do not open, commence or perform the occasional transaction, or terminate the relationship, and submit an STR to the FRC while protecting confidentiality.
- Evidence to retain
- Restriction or exit decision, investigation, STR and receipt.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(10)
06Monitoring and suspicious reportingFRC reporting must be prompt, complete, confidential and traceable.4 items+
Monitor activity against the customer profile.
- Implementation action
- Scrutinise transactions throughout the relationship for consistency with known business, risk profile and source of funds, keeping higher-risk CDD current.
- Evidence to retain
- Alerts, investigation notes, supporting data, dispositions and refresh history.
- Primary citation
- AML/CFT Amendment Act 2025, Article 5(1)(e)
Report suspicion and attempts promptly.
- Implementation action
- Timestamp when suspicion or reasonable grounds arose and promptly report all relevant details to the FRC, including attempted transactions and regardless of amount.
- Evidence to retain
- Decision chronology, STR, goAML delivery evidence and receipt.
- Primary citation
- AML/CFT Amendment Act 2025, Article 14(1)
Report suspected structuring promptly.
- Implementation action
- Detect and report transactions, attempts or series designed to evade statutory or regulatory reporting requirements.
- Evidence to retain
- Aggregation rules, alert, analysis, report and receipt.
- Primary citation
- AML/CFT Amendment Act 2025, Article 14(2A)
Prevent tipping off.
- Implementation action
- Restrict report access and do not disclose that an STR or related information has been or is being reported to the FRC or competent supervisor.
- Evidence to retain
- Need-to-know access, communications controls, training and audit log.
- Primary citation
- AML/CFT Amendment Act 2025, Article 15(2)
07Payments, wires, thresholds, and agentsKeep CDD, cash-reporting, border and wire thresholds distinct.5 items+
Implement the current FRC large-cash reporting rule.
- Implementation action
- Obtain the current threshold, scope, aggregation, form and deadline from FRC regulations and LCTR guidance before configuration; do not infer the amount from the USD 10,000 CDD or border-declaration thresholds.
- Evidence to retain
- Current instrument, configuration approval, LCTR or NIL reports and receipts.
- Primary citation
- AML/CFT Amendment Act 2025, Article 14(2)-(3); FRC LCTR guidance
Declare cross-border cash and bearer instruments at USD 10,000.
- Implementation action
- Inform relevant travellers and logistics operations that USD 10,000 or more, or equivalent, entering or leaving Somalia by person, mail, courier or otherwise requires a truthful written customs declaration.
- Evidence to retain
- Travel or shipment procedure, declaration, supporting records and escalation.
- Primary citation
- AML/CFT Amendment Act 2025, Article 18(1)
Carry complete originator and beneficiary wire information.
- Implementation action
- Collect and include the statutory names, account or unique reference, originator address or alternative identifier and beneficiary information; verify the originator at or above USD 1,000 unless already verified in an existing relationship.
- Evidence to retain
- Field matrix, validation rules, identity evidence and transfer samples.
- Primary citation
- AML/CFT Amendment Act 2025, Article 19(1)-(2)
Control deficient wire transfers.
- Implementation action
- Detect missing information, seek and verify repair data, and apply documented execute, reject, suspend, follow-up and reporting decisions.
- Evidence to retain
- Repair queue, decision rules, samples, escalations and STRs.
- Primary citation
- AML/CFT Amendment Act 2025, Article 19(3)-(6)
Control mobile-money and money-transfer agents.
- Implementation action
- Verify provider and agent authority, contract for AML, records, audit, privacy and incident controls, continuously monitor agents and retain provider responsibility.
- Evidence to retain
- CBS approvals, agent register, contracts, training, monitoring and incidents.
- Primary citation
- CBS Mobile Money Regulation 2020, regulations 32-33; MTB Operations Regulation 2016
08Targeted financial sanctionsUse current UN and Somali lists and act without delay.3 items+
Screen UN and national designations continuously.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, before activity and on updates against current UN and FRC/NAMLC lists.
- Evidence to retain
- List inventory, update log, screening configuration, alerts and dispositions.
- Primary citation
- Targeted Financial Sanctions Act 2023; FRC targeted-sanctions regulations and lists
Freeze designated property and prevent availability.
- Implementation action
- Freeze property owned or controlled by designated persons or entities without delay and prevent direct or indirect funds, assets or services from being made available, subject to current legal instructions.
- Evidence to retain
- Alert chronology, ownership/control analysis, freeze record and blocked-availability controls.
- Primary citation
- Targeted Financial Sanctions Act 2023; FRC targeted-sanctions regulations
Report matches immediately and preserve review rights.
- Implementation action
- Immediately send the required report to FRC through the current route, retain all supporting information, and apply current false-positive, delisting, exemption and release procedures.
- Evidence to retain
- Report, receipt, authority correspondence, review and release decision.
- Primary citation
- FRC Financial Sanctions Targets List; FRC account-freezing guideline
09Records and regulator accessRecords must reconstruct customers, transactions, analysis and decisions.4 items+
Retain transaction records for at least five years.
- Implementation action
- Apply a transaction-date clock to domestic and international transaction records sufficient to reconstruct amounts, currencies and parties.
- Evidence to retain
- Retention schedule, archive sample, reconstruction test and legal holds.
- Primary citation
- AML/CFT Amendment Act 2025, Article 13(1)
Retain CDD and analysis for at least five years after the relationship or occasional transaction.
- Implementation action
- Preserve customer and account files, business correspondence and analysis under the correct relationship-end or occasional-transaction clock.
- Evidence to retain
- Archive configuration, closure trigger, deletion control and retrieval log.
- Primary citation
- AML/CFT Amendment Act 2025, Article 13(2)
Apply the separate ten-year company and trust clocks.
- Implementation action
- Somali legal persons, Registry and relevant custodians must preserve specified basic and BO information for ten years after dissolution; professional trustees retain specified trust information for ten years after involvement ceases.
- Evidence to retain
- Corporate and trust retention mapping, archive samples and dissolution records.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 23C(5) and 23D(1)(e)
Provide records promptly under proper authority.
- Implementation action
- Authenticate requests, protect STR confidentiality, produce controlled records to FRC and competent supervisors or authorities and log scope, approval, delivery and receipt.
- Evidence to retain
- Request register, authority check, production index and acknowledgement.
- Primary citation
- AML/CFT Amendment Act 2025, Articles 13(3), 21 and 23B
10Privacy, biometrics, and transfersAML processing remains subject to the Data Protection Act 2023 and current regulations.5 items+
Register regulated processing roles where required.
- Implementation action
- Determine whether the organisation, processor and data protection officer require registration with the Somalia Data Protection Authority and complete current registration and renewal procedures.
- Evidence to retain
- Role analysis, registration, DPO mandate, renewal and correspondence.
- Primary citation
- Data Protection Act No. 005 of 2023; SDPA registration guidance
Document lawful, fair and proportionate processing.
- Implementation action
- Inventory identity, ownership, screening, biometric, monitoring and reporting data; record purpose, lawful basis, minimisation, accuracy, recipients, access and AML-aligned retention.
- Evidence to retain
- Processing register, basis assessment, notice, access matrix and retention mapping.
- Primary citation
- Data Protection Act No. 005 of 2023
Assess high-risk and sensitive processing.
- Implementation action
- Complete a data-protection impact and security assessment before biometric, national-identifier, criminal-offence or other high-risk processing and apply current DPA approval or DPO requirements.
- Evidence to retain
- Data classification, DPIA, DPO review, security design and authority record.
- Primary citation
- Data Protection Act No. 005 of 2023; SDPA guidance
Notify personal-data breaches through the current route.
- Implementation action
- Detect, contain, assess and document breaches and notify the DPA within the applicable 72-hour procedure where required, including delayed-notification reasons and affected-person communications.
- Evidence to retain
- Incident chronology, risk assessment, DPA notice, receipt and communications.
- Primary citation
- SDPA official breach service and guidance
Control processors, disclosures and cross-border transfers.
- Implementation action
- Map hosting and support locations, bind processors, document transfer conditions and safeguards, and obtain any required DPA authorisation before exporting personal data.
- Evidence to retain
- Processor diligence, contracts, transfer map, safeguards and authority record.
- Primary citation
- Data Protection Act No. 005 of 2023; SDPA cross-border guidance
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting AML/CFT Amendment Act 2025, Articles 5-13
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports, delivery evidence and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting AML/CFT Amendment Act 2025, Articles 14-16
Maintain a launch and legal-change pack.
- Implementation action
- Record licensing, thresholds, sanctions, registry, privacy and local-authority procedures, testing and confirmations before launch and material changes.
- Evidence to retain
- Signed launch pack, source register, uncertainty log and change approvals.
- Primary citation
- Official sources listed below
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Countering the Financing of Terrorism Amendment Act, 2025 - English translationCentral Bank of Somalia · Primary legislation
- AML/CFT laws, regulations, forms and reporting guidanceFinancial Reporting Center · Official FIU repository
- Production goAML reporting portal and guidanceFinancial Reporting Center · Official FIU procedure
- AML/CFT regulations for financial institutionsFinancial Reporting Center · Official regulation
- Targeted financial sanctions regulations and national listsFinancial Reporting Center · Official sanctions framework
- Current banking, money-transfer, mobile-money and financial-sector laws and regulationsCentral Bank of Somalia · Official regulator repository
- Mobile Money Services Regulation 2020, amended 2021Central Bank of Somalia · Official regulation
- Licensing, company registration and Beneficial Ownership RegistryMinistry of Commerce and Industry · Official registry guidance
- Data Protection Act No. 005 of 2023 and regulatory guidanceSomalia Data Protection Authority · Primary legislation and authority guidance
- Data Protection Authority services and breach procedureSomalia Data Protection Authority · Official privacy procedure
- FATF high-risk and monitored jurisdictions current at 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Somalia KYC, KYB and AML questions
Who receives suspicious transaction reports?+
Somalia's Financial Reporting Center (FRC), through the current production goAML channel and FRC procedure.
When is suspicion reported?+
Promptly once suspicion or reasonable grounds arise, including attempted transactions and regardless of amount.
What CDD thresholds apply?+
CDD applies at USD 10,000 for occasional or apparently linked transactions and at USD 1,000 for occasional wire transfers, as well as at relationship establishment, on suspicion regardless of amount, or when prior identification data is doubtful.
What is the large-cash reporting threshold?+
Article 14 leaves the operational amount and extensions to regulation. Obtain the current threshold and procedure from FRC LCTR guidance; do not infer it from the separate CDD or border thresholds.
How is beneficial ownership determined?+
Identify the natural person exercising ultimate control through ownership, then control through other means, and use the relevant senior managing official only where no natural person is identified through the first two steps.
How long are core AML records retained?+
At least five years for transactions and CDD under their separate statutory clocks. Certain company, registry and professional-trustee information has a ten-year clock.
What privacy law applies?+
Data Protection Act No. 005 of 2023 and current Somalia Data Protection Authority regulations and procedures.
Is Somalia on a FATF public list?+
No. Somalia was not named in FATF's public lists dated 19 June 2026. This does not make the jurisdiction low risk.
Can a financial, payment or virtual-asset service launch without approval?+
No. Classify the service and provider model under current federal laws and Central Bank or other sector rules and obtain every applicable licence or approval first.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 9 September 2026. Confirm commencement and official-language reconciliation of the 2025 AML/CFT amendments, current FRC reporting thresholds and goAML specifications, beneficial-owner registry procedures, sanctions-list operations, Data Protection Authority regulations and product-specific permissions with the competent federal authority and qualified Somali counsel before launch.