South Sudan KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in South Sudan.
- Last reviewed
- Last reviewed:
- Version
- Version 1.1

Direct answer
What does the South Sudan compliance checklist cover?
The South Sudan checklist translates primary KYC, KYB and AML rules into 11 control areas and 40 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Financial Intelligence Unit established under the 2012 Act
- Primary AML rule
- AML/CTF Act No. 29 of 2012
- Suspicion reporting
- Within 24 hours after suspicion; before execution where possible
- Universal CDD threshold
- No current amount verified; identify customers under section 16
- Core AML retention
- At least 5 years from completion
- FATF status
- Increased monitoring at 19 June 2026
Implementation detail
South Sudan compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the reporting-person perimeter, competent authority and product permissions before launch.3 items+
Map each entity and activity to the reporting-person perimeter.
- Implementation action
- Classify banks, financial and microfinance institutions, cash dealers, insurers and intermediaries, securities and futures businesses, money transmitters, gaming operators, foreign-exchange bureaux, accountants, real-estate agents, precious-metal and stone dealers, customs officers, and in-scope legal professionals; confirm later Gazette designations.
- Evidence to retain
- Entity and activity map, statutory category, supervisor, legal opinion and accountable owner.
- Primary citation
- AML/CTF Act 2012, section 5 definition of reporting person
Confirm the competent FIU reporting arrangement before go-live.
- Implementation action
- Obtain current written FIU instructions for registration, form, secure delivery, acknowledgement, information requests and confidentiality; do not assume an online portal or receipt workflow where none is officially confirmed.
- Evidence to retain
- Authority correspondence, reporter mandate, channel test, access controls and current instructions.
- Primary citation
- AML/CTF Act 2012, sections 6 and 8
Obtain every sector licence or approval before regulated activity.
- Implementation action
- Classify banking, foreign exchange, money transfer, electronic money, mobile money, microfinance, insurance, payment, agent and outsourced activity and obtain current Bank of South Sudan or other authority approval before launch.
- Evidence to retain
- Perimeter memo, licence, conditions, approvals, agent register and renewal calendar.
- Primary citation
- Banking Act 2012; Foreign Exchange Business Act 2012; Bank of South Sudan regulations and licensing materials
02Governance and risk assessmentGovernance should meet the Act, sector rules and the risk-based direction of current supervision.3 items+
Maintain internal suspicious-reporting procedures.
- Implementation action
- Designate an officer, give that officer reasonable access to relevant information, require employees to escalate suspicion and require the designee to file qualifying reports.
- Evidence to retain
- Board-approved procedure, officer mandate, access design, escalation tests and filing log.
- Primary citation
- AML/CTF Act 2012, section 19
Train relevant employees.
- Implementation action
- Provide role-based training on applicable law, internal procedures, identifying suspicious activity, secure escalation and tipping-off restrictions, with refreshers proportionate to risk.
- Evidence to retain
- Training content, attendance, assessments, refresh schedule and remediation.
- Primary citation
- AML/CTF Act 2012, section 20(1)
Document institutional risk and control effectiveness.
- Implementation action
- Assess customer, geography, product, channel, transaction, agent and technology risks before launch and periodically; record enhanced measures for higher risks and independent control testing as a prudent response to South Sudan's FATF action plan and BoSS risk-based supervision.
- Evidence to retain
- Risk methodology, assessment, approvals, monitoring, test report and remediation.
- Primary citation
- BoSS 2025 monetary and banking policy; FATF South Sudan statement, 19 June 2026; operational risk control
03Natural-person identificationSection 16 requires reliable official identity evidence and does not establish a verified monetary safe harbour.4 items+
Identify every customer using official evidence.
- Implementation action
- Before a continuing relationship or transaction, obtain an official record reasonably capable of establishing true identity, including a birth certificate or affidavit and a passport or other official identification as applicable; verify authenticity and resolve inconsistencies.
- Evidence to retain
- Identity record, verification result, provenance, discrepancy log and decision timestamp.
- Primary citation
- AML/CTF Act 2012, section 16(1)-(3)
Do not invent a universal CDD threshold.
- Implementation action
- Apply identification to relationships and transactions within section 16 and obtain any current ministerial or supervisory threshold in writing before configuring amount-based exceptions or simplified measures.
- Evidence to retain
- Current legal instruction, threshold configuration, version history and approval.
- Primary citation
- AML/CTF Act 2012, sections 16 and 28
Identify persons acting for another.
- Implementation action
- Determine whether a customer acts for another person, verify the representative and mandate, and establish the true identity of the person for whose account or ultimate benefit the transaction is conducted.
- Evidence to retain
- Representative identity, authority instrument, verification and ultimate-benefit analysis.
- Primary citation
- AML/CTF Act 2012, section 16(3)-(5)
Prevent anonymous or disguised accounts.
- Implementation action
- Block false, disguised and anonymous names and test account-opening and migration controls for circumvention.
- Evidence to retain
- System rule, rejected cases, migration review and test results.
- Primary citation
- AML/CTF Act 2012, section 20(1)
04KYB, registries, and beneficial ownershipVerify legal existence and ultimate benefit while treating the national beneficial-ownership framework as incomplete.4 items+
Verify corporate identity from current registry evidence.
- Implementation action
- Obtain the memorandum and articles, certificate of incorporation, latest annual reports certified by the Directorate of Business Registry, registered office, directors, members and authorised signatories; reconcile all records.
- Evidence to retain
- Certified registry pack, constitutional documents, officer and member lists, mandates and discrepancy log.
- Primary citation
- AML/CTF Act 2012, section 16(2)(c); Companies Act 2012
Identify persons behind nominees, agents and trustees.
- Implementation action
- Take reasonable measures to establish the true identity of each person on whose behalf or for whose ultimate benefit the customer acts, including through trustee, nominee or agent arrangements.
- Evidence to retain
- Ownership and control chart, declarations, corroboration, verified identities and rationale.
- Primary citation
- AML/CTF Act 2012, section 16(3)-(5)
Do not apply an unsupported beneficial-owner percentage.
- Implementation action
- Use ownership, voting, contractual and other-control evidence to identify ultimate natural persons and escalate unresolved control; do not present a shareholder-register entry as verified beneficial ownership or invent a percentage threshold.
- Evidence to retain
- Layered ownership chart, control analysis, source documents, escalation and senior approval.
- Primary citation
- AML/CTF Act 2012, section 16(4); FATF South Sudan statement, 19 June 2026
Maintain and reconcile company records.
- Implementation action
- Collect current registered-office, member, director, share-register and accounting records required by the Companies Act and monitor changes using the current registry process.
- Evidence to retain
- Registry extracts, statutory registers, corporate records, change receipts and reconciliation history.
- Primary citation
- Companies Act 2012, sections 154-160
05PEPs, EDD, and failed CDDForeign PEPs carry express controls; domestic and international-organisation exposure should be addressed through documented risk controls pending updated law.4 items+
Detect foreign PEP exposure.
- Implementation action
- Use appropriate risk-management systems to determine whether the customer is a foreign PEP and screen relevant persons throughout the relationship.
- Evidence to retain
- Screening configuration, match decision, relationship map and refresh log.
- Primary citation
- AML/CTF Act 2012, sections 5 and 16(1)(b)
Apply foreign-PEP approval, source and monitoring measures.
- Implementation action
- Obtain senior-management approval, take reasonable measures to establish source of wealth and source of funds, and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, source analysis, corroboration and monitoring plan.
- Primary citation
- AML/CTF Act 2012, section 16(1)(b)
Control other higher-risk public-function exposure.
- Implementation action
- As a risk-based control, identify domestic PEPs, international-organisation PEPs, family members and close associates and apply proportionate approval, source and monitoring measures; distinguish this control from the narrower express statutory definition.
- Evidence to retain
- Policy basis, screening, relationship analysis, risk decision and approvals.
- Primary citation
- FATF Recommendation 12; operational risk control
Stop when identity or authority cannot be established.
- Implementation action
- Do not onboard or transact where true identity, representation or ultimate benefit cannot be established; assess whether the facts create suspicion and document the report decision.
- Evidence to retain
- Restriction, failed-verification record, escalation, decision and any STR receipt.
- Primary citation
- AML/CTF Act 2012, sections 16 and 18; operational risk control
06Monitoring and suspicious reportingSuspicion must reach the FIU within 24 hours and, where possible, before execution.4 items+
Monitor activity and investigate indicators.
- Implementation action
- Monitor transactions and attempted activity against identity, purpose, ownership, expected activity and risk; preserve the information supporting each disposition.
- Evidence to retain
- Monitoring rules, alerts, investigation notes, supporting data and dispositions.
- Primary citation
- AML/CTF Act 2012, sections 18-20; operational control
Report suspicion within 24 hours.
- Implementation action
- Timestamp when suspicion or reasonable grounds arise, ascertain the purpose, origin, destination and ultimate beneficiary so far as reasonable, and securely report the transaction or proposed transaction to the FIU within 24 hours and before execution wherever possible.
- Evidence to retain
- Suspicion chronology, analysis, STR, secure-delivery evidence and acknowledgement.
- Primary citation
- AML/CTF Act 2012, section 18(1)
Supply requested follow-up information.
- Implementation action
- Authenticate FIU or law-enforcement requests and provide further information about a reported transaction through the authorised secure route while preserving confidentiality.
- Evidence to retain
- Request, authority check, response package, delivery log and receipt.
- Primary citation
- AML/CTF Act 2012, section 18(2)
Prevent tipping off.
- Implementation action
- Restrict access and do not warn an involved person or unauthorised third party that an STR may be prepared, is being prepared or has been sent, or disclose related protected information.
- Evidence to retain
- Need-to-know controls, communications policy, training and access log.
- Primary citation
- AML/CTF Act 2012, section 21
07Payments, wires, thresholds, and agentsThresholds and payment permissions require current authority confirmation; the 2025 payment-system bill remained a draft in August 2026.5 items+
Obtain current transaction-record thresholds before configuration.
- Implementation action
- Request the current Gazette order prescribing the amount under section 17; apply full records where the threshold cannot be verified and never infer it from another requirement.
- Evidence to retain
- Gazette order or authority confirmation, configuration, version and approval.
- Primary citation
- AML/CTF Act 2012, section 17(1)(a)
Obtain the current cross-border cash threshold.
- Implementation action
- Confirm the ministerially prescribed amount and the September 2025 BoSS cash-movement directive before traveller or corporate cash movement; preserve customs declarations and supporting records.
- Evidence to retain
- Current directive, threshold table, declarations, source-of-funds support and escalation.
- Primary citation
- AML/CTF Act 2012, section 24; BoSS cash-movement directive, 17 September 2025
Preserve complete wire-transfer information.
- Implementation action
- Pending verified detailed national wire rules, collect and transmit reliable originator and beneficiary identity, account or reference, amount, currency, date and purpose; repair, reject or escalate deficient transfers according to documented risk.
- Evidence to retain
- Field matrix, validation rules, repair queue, decisions and transfer samples.
- Primary citation
- Banking Act 2012, section 77; operational risk control
Control electronic-money providers and agents.
- Implementation action
- Verify the provider's current BoSS authorisation and the applicable Electronic Money Regulation, including the 2025 amendment published in August 2026; confirm agent, safeguarding, outsourcing, customer and transaction limits before launch.
- Evidence to retain
- Licence, current regulation, agent approvals, contracts, limits, monitoring and incidents.
- Primary citation
- BoSS Electronic Money Regulation 2017 (Amendment) 2025; BoSS regulations and circulars
Do not treat the draft payment-system bill as enacted law.
- Implementation action
- Track enactment and commencement of the National Payment System Bill 2025 and document the present legal basis for each payment activity separately.
- Evidence to retain
- Legislative-status check, current-law memo, licence and change trigger.
- Primary citation
- BoSS validation workshop statement, 12 August 2026
08Targeted financial sanctionsFATF still identifies South Sudan's targeted-financial-sanctions framework as incomplete; screening and escalation remain essential risk controls.3 items+
Screen current UN designations and any operative national directions.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and relevant transactions against the current UN consolidated list and any verified South Sudan direction at onboarding, before activity and on list updates.
- Evidence to retain
- List inventory, update log, screening configuration, alerts and dispositions.
- Primary citation
- UN Security Council consolidated list; FATF South Sudan statement, 19 June 2026
Escalate potential matches without inventing a local freeze deadline.
- Implementation action
- Immediately restrict disposition as permitted, escalate to legal and the competent authority, obtain current written freeze and reporting instructions, and preserve the chronology; do not state that the incomplete national framework supplies a verified automatic deadline.
- Evidence to retain
- Alert chronology, identity and ownership analysis, restriction, authority direction and report.
- Primary citation
- FATF South Sudan statement, 19 June 2026; applicable UN Security Council resolutions
Control false positives, exemptions and release.
- Implementation action
- Require documented authority or legal approval before releasing a sanctions-related restriction and preserve correspondence, licence or exemption and decision rationale.
- Evidence to retain
- Match analysis, authority correspondence, approval, release record and audit trail.
- Primary citation
- Operational control pending completed national TFS framework
09Records and regulator accessRecords must identify the parties and reconstruct transactions for at least five years from completion.4 items+
Retain AML identity and transaction records for at least five years.
- Implementation action
- Keep prescribed transaction details and the identity evidence or information enabling a copy to be obtained for at least five years from completion of the relevant business or transaction.
- Evidence to retain
- Retention schedule, completion trigger, archive sample, retrieval and deletion control.
- Primary citation
- AML/CTF Act 2012, section 17(1)-(3)
Retain copies and a register when originals are released.
- Implementation action
- Where law requires release of an original before five years elapse, retain a copy and maintain the prescribed released-document register.
- Evidence to retain
- Released-document register, copy, authority, custody trail and retrieval test.
- Primary citation
- AML/CTF Act 2012, section 17(4)
Meet separate company-record periods.
- Implementation action
- Map Companies Act records at the registered office, including seven-year and seven-accounting-period categories, separately from the five-year AML clock and preserve the longer applicable period.
- Evidence to retain
- Record-class schedule, statutory-register sample, archive and legal hold.
- Primary citation
- Companies Act 2012, sections 158-160
Respond securely to lawful inspections and requests.
- Implementation action
- Authenticate FIU, BoSS and other competent-authority requests, preserve STR confidentiality, control production and record delivery and acknowledgement.
- Evidence to retain
- Request register, authority check, approval, production index and receipt.
- Primary citation
- AML/CTF Act 2012, sections 8(c)-(d), 18(2), 21 and 22
10Privacy, biometrics, and transfersNo comprehensive generally applicable data-protection statute or regulator was verified; use constitutional, sector and contractual controls without inventing statutory deadlines.3 items+
Map the lawful basis and necessity for identity processing.
- Implementation action
- Document the legal and operational basis for each identity, screening and biometric field, collect only what is necessary, give clear notice and restrict reuse while monitoring for new generally applicable privacy legislation.
- Evidence to retain
- Data map, legal-basis assessment, notice, field justification and change log.
- Primary citation
- Transitional Constitution 2011, Article 22; AML/CTF Act 2012, sections 16-18; operational privacy control
Protect identity and financial data.
- Implementation action
- Apply role-based access, encryption, logging, backup, vendor controls, testing and incident response proportionate to sensitivity; banks and credit-reporting participants must also map applicable BoSS data-security requirements.
- Evidence to retain
- Security standard, access review, encryption evidence, vendor assessment, tests and incident log.
- Primary citation
- BoSS Credit Reporting Systems Regulation 2014, sections 6-9; operational privacy control
Control biometrics and cross-border processing conservatively.
- Implementation action
- Before biometric collection or overseas hosting, complete a documented necessity, proportionality, security, vendor and transfer assessment and obtain current local advice; do not claim an unverified regulator approval or breach deadline.
- Evidence to retain
- Assessment, architecture, contract, security controls, approval and legal update check.
- Primary citation
- Transitional Constitution 2011, Article 22; operational privacy control
11Practical evidence packsMaintain concise packs that reproduce decisions and expose unresolved legal dependencies.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, ultimate-benefit analysis, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting AML/CTF Act 2012, sections 16-20
Maintain a reconstructable reporting pack.
- Implementation action
- Link transactions, alerts, analysis, the 24-hour chronology, approvals, STR delivery, acknowledgement and follow-up while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting AML/CTF Act 2012, sections 18-23
Maintain a launch and legal-change pack.
- Implementation action
- Record current thresholds, FIU procedure, licences, BoSS directions, registry evidence, sanctions instructions, privacy analysis, testing and confirmations before launch and on material change.
- Evidence to retain
- Signed launch pack, source register, uncertainty log and change approvals.
- Primary citation
- Official sources listed below
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Counter Terrorist Financing Act No. 29 of 2012Ministry of Justice and Constitutional Affairs · Primary legislation
- Banking Act No. 22 of 2012Bank of South Sudan · Primary legislation
- Companies Act 2012 and national laws repositoryMinistry of Justice and Constitutional Affairs · Primary legislation
- Bank of South Sudan regulations registerBank of South Sudan · Official regulator repository
- Bank of South Sudan circulars registerBank of South Sudan · Official regulator repository
- Electronic Money Regulation 2017 (Amendment) 2025Bank of South Sudan · Official regulation
- Directive on movement of cash within and across South Sudan bordersBank of South Sudan · Official directive
- Monetary and Banking Policy for 2025Bank of South Sudan · Official policy
- Validation status of the draft National Payment System Bill 2025Bank of South Sudan · Official legislative-status statement
- South Sudan increased-monitoring statement, 19 June 2026FATF · Authoritative current status
- ESAAMLG official publications and regional updatesESAAMLG · Authoritative regional body
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
South Sudan KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Financial Intelligence Unit established under the 2012 Act. Obtain the FIU's current secure filing instructions and acknowledgement process before production use.
When is suspicion reported?+
Within 24 hours after forming suspicion and, wherever possible, before the suspicious transaction or proposed transaction is carried out.
What universal CDD threshold applies?+
No current monetary CDD threshold was verified in the 2012 Act. Section 16 requires customer identification for relationships and transactions; obtain current authority directions before configuring any amount-based exception.
What is the transaction-record or cross-border cash threshold?+
The 2012 Act leaves both amounts to ministerial instruments. Obtain the current Gazette order and BoSS or customs direction; do not infer either amount from another rule.
How is beneficial ownership determined?+
Section 16 requires reasonable measures to establish the true identity of persons for whose account or ultimate benefit a customer acts. FATF still identifies the need for a comprehensive legal framework to collect and verify beneficial-ownership information, so do not invent a percentage or rely only on the member register.
How long are core AML records retained?+
At least five years from completion of the relevant business or transaction under section 17. Separate Companies Act record periods may be longer.
What privacy law applies?+
No comprehensive generally applicable data-protection statute or regulator was verified. Map Article 22 constitutional privacy, AML identity duties, applicable sector rules such as credit-reporting data security, contracts and current local advice.
Is South Sudan on a FATF public list?+
Yes. South Sudan remained under increased monitoring on 19 June 2026. FATF does not call for automatic enhanced due diligence solely because of listing; apply a documented risk-based response.
Can payment or electronic-money services launch without approval?+
No. Obtain applicable BoSS authorisation and current regulations. The National Payment System Bill 2025 was still undergoing validation in August 2026 and must not be treated as enacted law.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 11 September 2026. Confirm current FIU independence, reporting forms and secure channel, ministerial thresholds and orders, Bank of South Sudan directions, company-registry practice, sanctions implementation, privacy and cyber rules, and product-specific permissions with the competent authority and qualified South Sudanese counsel before launch.