Sudan KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Sudan.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Sudan compliance checklist cover?
The Sudan checklist translates primary KYC, KYB and AML rules into 11 control areas and 43 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Financial Information Unit established by Article 12 of the 2014 Act
- Primary AML rule
- AML and Terrorism Financing Act 2014
- CBOS rule
- Circular No. 8/2026, effective 30 April 2026
- CBOS occasional CDD
- EUR 15,000 equivalent, single or linked transactions
- CBOS ownership test
- More than 10%, then other control, then senior manager
- Suspicion reporting
- Immediately, including attempts and regardless of value
- Core retention
- At least 5 years under Article 6 and Circular 8/2026
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Sudan compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the statutory reporting perimeter, sector supervisor and licence before activity.3 items+
Map every entity and activity to the reporting-person perimeter.
- Implementation action
- Classify financial activities, real-estate transactions, qualifying precious-metal or stone cash transactions, specified legal and accounting work, and company-service activity; confirm any later ministerial designation and the relevant supervisor.
- Evidence to retain
- Entity map, activity analysis, statutory category, supervisor confirmation and legal opinion.
- Primary citation
- AML and Terrorism Financing Act 2014, Article 3 definitions; Article 4
Apply Circular 8/2026 only to its stated CBOS-supervised perimeter.
- Implementation action
- For banks, exchange companies, money-transfer companies, leasing, microfinance and other CBOS-licensed financial institutions, implement Circular 8/2026; for other reporting persons obtain their supervisor's current rules rather than extending bank-specific numbers automatically.
- Evidence to retain
- Perimeter decision, licence, supervisor rule register and scoped control matrix.
- Primary citation
- CBOS Circular No. 8/2026, Parts II-III
Obtain each product and channel approval before launch.
- Implementation action
- Identify banking, foreign exchange, remittance, mobile-payment, payment-system, agent, outsourcing and technology activity and obtain current CBOS or other competent-authority approval before promotion or operation.
- Evidence to retain
- Licence, written approval, conditions, agent register, outsourcing approval and renewal calendar.
- Primary citation
- Banking Business Regulation Act 2026; CBOS electronic-payment notice; Mobile Payment Financial Institutions Regulation 2020
02Governance and risk assessmentThe Act requires risk controls; Circular 8/2026 adds detailed governance for CBOS-supervised institutions.3 items+
Maintain a documented institutional risk assessment.
- Implementation action
- Assess customer, geography, product, service, delivery-channel, transaction, technology and proliferation-financing risks and update the assessment at least twice each year where Circular 8/2026 applies.
- Evidence to retain
- Methodology, semiannual assessments, source inputs, board approval and remediation plan.
- Primary citation
- 2014 Act, Article 6(1); CBOS Circular 8/2026, Part IV, paragraphs 1-3
Maintain an independent compliance function.
- Implementation action
- Appoint a senior compliance manager and deputy with board oversight, access to necessary records, independent decision authority and CBOS approval for transfer or removal where the circular applies.
- Evidence to retain
- Appointments, CBOS correspondence, charter, access test, board reporting and conflicts register.
- Primary citation
- CBOS Circular 8/2026, paragraph 60(b)
Operate tested internal controls and training.
- Implementation action
- Maintain board-approved customer acceptance, CDD, sanctions, monitoring, reporting, confidentiality, records, group, audit and response procedures; train relevant staff and independently test effectiveness.
- Evidence to retain
- Policy suite, training records, monitoring tests, internal and external audit reports and remediation.
- Primary citation
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraphs 60-63
03Natural-person identificationIdentify customers, representatives and beneficial owners from reliable independent evidence.5 items+
Perform CDD at each statutory trigger.
- Implementation action
- Identify and verify before a relationship, a covered occasional transaction, a domestic or international wire, when prior data is doubtful, or whenever ML, TF or PF suspicion exists.
- Evidence to retain
- Trigger matrix, identity file, verification results, timestamps and exceptions.
- Primary citation
- 2014 Act, Article 5; CBOS Circular 8/2026, paragraph 7
For CBOS institutions, aggregate linked occasional transactions at EUR 15,000 equivalent.
- Implementation action
- Apply CDD before a single or apparently linked occasional transaction equals or exceeds EUR 15,000 in national or foreign currency; document the rate, aggregation logic and scope. Do not extend this bank-sector trigger to other sectors without authority.
- Evidence to retain
- Rate source, aggregation rules, alerts, customer file and scoped legal basis.
- Primary citation
- CBOS Circular 8/2026, paragraph 7(2)
Verify a natural person using current official evidence.
- Implementation action
- Obtain valid official identity, full name, nationality, national number, date of birth, permanent residence, contacts, employment or activity, purpose and authorised signers, then corroborate through reliable official databases where available.
- Evidence to retain
- Certified identity copy, verification queries, address and contact checks, discrepancy log and approval.
- Primary citation
- CBOS Circular 8/2026, paragraphs 12-13
Verify every representative and mandate.
- Implementation action
- Obtain the representative's identity and a valid power or authorisation, test its scope and retain a certified copy before allowing access or instructions.
- Evidence to retain
- Representative KYC, power, authority check, limits and transaction log.
- Primary citation
- 2014 Act, Article 5(2); CBOS Circular 8/2026, paragraphs 4(2) and 13(2)
Do not continue when CDD cannot be completed.
- Implementation action
- Do not open the account, form the relationship or transact; terminate an existing relationship where required and consider an STR. If further CDD would tip off the customer, stop the CDD step and report instead.
- Evidence to retain
- Restriction, exit decision, suspicion assessment, approval and any STR receipt.
- Primary citation
- CBOS Circular 8/2026, paragraphs 9-10
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and control; do not confuse customer-level CDD with registry filing.5 items+
Verify legal-person identity and authority.
- Implementation action
- Obtain current incorporation and commercial-register evidence, constitutional documents, address, purpose, directors, owners, authorised signers and sector permissions; reconcile inconsistencies before acceptance.
- Evidence to retain
- Registry extract, constitutional pack, officer and owner lists, mandates, licences and discrepancy log.
- Primary citation
- CBOS Circular 8/2026, paragraph 14; Companies Act 2015 as amended in 2025
Obtain a written beneficial-owner declaration.
- Implementation action
- At account opening or relationship formation, require the customer to disclose each beneficial owner in writing and corroborate the declaration through reliable independent sources.
- Evidence to retain
- Signed declaration, ownership chart, source documents, independent checks and refresh history.
- Primary citation
- CBOS Circular 8/2026, paragraphs 16-17
For CBOS institutions, identify natural persons owning or controlling more than 10%.
- Implementation action
- Trace direct and indirect ownership and control above 10%; if no verified owner controls through ownership, identify control by other means; if still unresolved, identify the natural person responsible for senior management.
- Evidence to retain
- Layered ownership chart, percentage calculations, control analysis, fallback decision and verified identities.
- Primary citation
- CBOS Circular 8/2026, paragraph 18(1)
Identify legal-arrangement parties and ultimate controllers.
- Implementation action
- Identify and verify the settlor or creator, trustee, protector if any, beneficiaries and every other natural person exercising final direct or indirect effective control.
- Evidence to retain
- Instrument, party register, verified identities, control analysis and change monitoring.
- Primary citation
- CBOS Circular 8/2026, paragraphs 15 and 18(3)
Treat commercial-register data as corroboration, not a substitute for CDD.
- Implementation action
- Use the General Commercial Registrar's current Companies Act process to verify existence and filings, but separately establish beneficial ownership and control; obtain current 2025 amendment and live filing procedures before relying on registry completeness.
- Evidence to retain
- Registry evidence, customer declaration, independent corroboration, discrepancy log and legal update check.
- Primary citation
- Companies Act 2015 as amended in 2025; Ministry of Justice commercial-registration mandate; CBOS Circular 8/2026, paragraphs 16-18
05PEPs, EDD, and remote onboardingUse risk systems for public-function exposure and apply proportionate enhanced measures.4 items+
Identify PEPs, family members and close associates.
- Implementation action
- Obtain declarations, check reliable information and databases, map relationships and refresh screening throughout the relationship.
- Evidence to retain
- Declaration, screening, relationship map, match rationale and refresh log.
- Primary citation
- 2014 Act, Articles 3 and 6(2); CBOS Circular 8/2026, paragraphs 28-30
Apply approval, source and monitoring measures to foreign PEPs.
- Implementation action
- Obtain senior-management approval before starting or continuing, establish source of wealth and funds and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, source analysis, corroboration, monitoring plan and reviews.
- Primary citation
- 2014 Act, Article 6(2); CBOS Circular 8/2026, paragraph 29(a)
Apply the same measures to higher-risk domestic and international-organisation PEPs.
- Implementation action
- Assess risk and apply senior approval, source verification and enhanced monitoring where the domestic or international-organisation PEP relationship is higher risk.
- Evidence to retain
- Risk assessment, approval, source evidence and monitoring results.
- Primary citation
- 2014 Act, Article 6(2); CBOS Circular 8/2026, paragraph 29(b)
Strengthen non-face-to-face verification.
- Implementation action
- Use authenticated documents, additional identity and source evidence, trustworthy independent references, initial restrictions and enhanced monitoring proportionate to impersonation and fraud risk.
- Evidence to retain
- Remote-onboarding design, authentication results, restrictions, liveness or equivalent evidence and monitoring.
- Primary citation
- CBOS Circular 8/2026, paragraph 22
06Monitoring and suspicious reportingSuspicious transactions and attempts are reported immediately, regardless of value.5 items+
Monitor relationships and investigate unusual activity.
- Implementation action
- Compare transactions and attempts with the customer's identity, purpose, ownership, expected activity, source profile and risk; investigate complex, unusual or economically unclear activity and retain the analysis.
- Evidence to retain
- Monitoring rules, alerts, investigation notes, source data and dispositions.
- Primary citation
- 2014 Act, Articles 5-6; CBOS Circular 8/2026, paragraphs 19 and 47-48
Report suspicion and attempts immediately and regardless of value.
- Implementation action
- Timestamp reasonable suspicion and have the authorised compliance manager immediately submit the FIU form for a transaction or attempted transaction connected with crime proceeds, ML or TF; include PF suspicion under the circular's internal escalation framework.
- Evidence to retain
- Suspicion chronology, analysis, FIU form, secure submission record and acknowledgement.
- Primary citation
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraphs 49-51
Submit later related information immediately.
- Implementation action
- Authenticate FIU requests and promptly provide requested or newly available information linked to an earlier report using the authorised secure route.
- Evidence to retain
- Request, authority verification, supplement, delivery log and receipt.
- Primary citation
- 2014 Act, Article 14; CBOS Circular 8/2026, paragraphs 55-57
Prevent tipping off and protect reporting information.
- Implementation action
- Restrict report and investigation access and do not tell the customer or an unauthorised person that a report has been or will be filed; document permitted communications with competent authorities and counsel.
- Evidence to retain
- Need-to-know matrix, access logs, communications policy, training and incident review.
- Primary citation
- 2014 Act, Article 9; CBOS Circular 8/2026, paragraphs 58-59
Implement FIU stop and freeze orders exactly.
- Implementation action
- Maintain an always-available process for an FIU transaction stop of up to five days, a Prosecutor-General freeze of up to two weeks and any court extension; do not release without verified authority.
- Evidence to retain
- Order validation, timestamps, restriction, asset record, extension and release authority.
- Primary citation
- 2014 Act, Article 15
07Payments, wires, thresholds, and agentsWire fields and payment permissions are explicit; other thresholds require scoped current instruments.5 items+
Keep required originator and beneficiary information with each wire.
- Implementation action
- Collect verified originator and beneficiary names, account or unique reference and the other required identifying fields; keep information through the payment chain and block an originating transfer lacking mandatory data.
- Evidence to retain
- Field matrix, validation rules, transfer sample, repair queue and decision log.
- Primary citation
- 2014 Act, Article 7; CBOS Circular 8/2026, paragraphs 33-41
Control incomplete incoming and intermediary transfers.
- Implementation action
- Detect missing fields and apply documented risk rules to execute, reject, suspend, report or seek repair; intermediaries retain technically detached information for at least five years and provide it within one working day on request.
- Evidence to retain
- Detection rule, repair request, risk decision, report and retrieval test.
- Primary citation
- CBOS Circular 8/2026, paragraphs 39-44
Obtain the current cross-border declaration threshold.
- Implementation action
- Before physical movement of currency or bearer negotiable instruments, confirm the current regulation-set declaration amount and customs procedure; do not substitute the EUR 15,000 bank CDD trigger.
- Evidence to retain
- Current regulation, threshold configuration, declaration, source evidence and customs receipt.
- Primary citation
- 2014 Act, Articles 31-32
Obtain approval for electronic-payment systems, outsourcing and connections.
- Implementation action
- Secure prior written CBOS approval for the payment service, system, outsourcing, agency and technical connection; document current 2026 banking-law and payment-rule applicability.
- Evidence to retain
- Approvals, architecture, contracts, licences, agent inventory and test results.
- Primary citation
- CBOS electronic-payment notice; CBOS Circular 1/2013; Banking Business Regulation Act 2026
Control mobile-payment providers and agents.
- Implementation action
- Verify the provider's licence, ensure agents follow CDD and customer-data safeguards, notify CBOS of agent changes without undue delay and monitor transactions and complaints.
- Evidence to retain
- Licence, agent due diligence, notifications, contracts, CDD samples, monitoring and complaints.
- Primary citation
- Mobile Payment Financial Institutions Regulation 2020, Articles 15 and 19-34
08Targeted financial sanctionsCircular 8/2026 requires real-time screening, freezing without delay and immediate reporting for CBOS institutions.4 items+
Screen current UN and Technical Committee sanctions lists in real time.
- Implementation action
- Screen customers, beneficial owners, directors, authorised persons, related parties and transactions against current UN Security Council decisions and Technical Committee lists and test the system periodically.
- Evidence to retain
- List inventory, update log, screening configuration, test results, alerts and dispositions.
- Primary citation
- CBOS Circular 8/2026, paragraph 61(1)-(2)
Freeze covered assets immediately, without delay or prior notice.
- Implementation action
- Freeze direct and indirect funds and assets owned, controlled, managed or held wholly or partly by a listed person, including persons acting for or under direction, and prevent funds or services being made available.
- Evidence to retain
- Match analysis, freeze timestamp, ownership and control analysis, asset inventory and system blocks.
- Primary citation
- CBOS Circular 8/2026, paragraph 61(3)-(6)
Immediately notify the Technical Committee and FIU.
- Implementation action
- After freezing, immediately provide the Technical Committee the asset and action details; immediately notify the FIU of listed current or former customers, related persons and attempted transactions involving frozen resources.
- Evidence to retain
- Committee report, FIU report, delivery evidence, acknowledgement and chronology.
- Primary citation
- CBOS Circular 8/2026, paragraph 61(7)-(10)
Govern false positives, exemptions, humanitarian permissions and release.
- Implementation action
- Compare all identifiers, maintain the restriction while legally required and release or permit activity only under verified Technical Committee or other competent-authority direction, including any applicable UN humanitarian exemption.
- Evidence to retain
- Identifier analysis, authority correspondence, licence or exemption, approval and release log.
- Primary citation
- Council of Ministers Decisions 358-360/2014; current UN Security Council resolutions; controlled legal procedure
09Records and regulator accessRecords must reconstruct decisions and transactions and remain promptly available.3 items+
Retain CDD records for at least five years after exit or the occasional transaction.
- Implementation action
- Keep identity and beneficial-owner evidence, accounting files and correspondence for at least five years after the relationship ends or the occasional transaction date, applying the longer applicable period.
- Evidence to retain
- Retention schedule, trigger dates, archive samples, retrieval test and deletion controls.
- Primary citation
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraph 48(1)
Retain transaction, attempt and report records for their correct clocks.
- Implementation action
- Keep domestic and international transaction and attempt records for at least five years from execution or attempt; keep FIU reports and supporting documents for at least five years from reporting and criminal-case records until final disposal if longer.
- Evidence to retain
- Record-class schedule, linked case files, trigger calculation, archive and legal holds.
- Primary citation
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraph 48(2)-(5)
Make records promptly available to competent authorities.
- Implementation action
- Authenticate requests, preserve reporting confidentiality and privilege, produce responsive records promptly and record the exact disclosure and receipt.
- Evidence to retain
- Request register, authority check, production index, approval, delivery and receipt.
- Primary citation
- 2014 Act, Articles 4, 6 and 14; CBOS Circular 8/2026, paragraph 48
10Privacy, biometrics, and transfersNo comprehensive generally applicable data-protection statute or independent privacy authority was verified.3 items+
Map necessity and legal authority for identity processing.
- Implementation action
- Document the AML, sector, contractual and operational basis for each identity, screening and biometric field; minimize collection, explain use and restrict incompatible reuse.
- Evidence to retain
- Data map, legal-basis analysis, notice, field justification, consent where relevant and change log.
- Primary citation
- Electronic Transactions Act 2007; 2014 Act, Articles 5-6; operational privacy control
Secure customer and transaction information.
- Implementation action
- Apply access controls, encryption, logging, segregation, backups, incident response and tested vendor safeguards; payment providers must apply the encryption and customer-data controls in their sector rules.
- Evidence to retain
- Security standard, access review, encryption evidence, vendor assessment, tests and incident log.
- Primary citation
- Electronic Transactions Act 2007, Article 28; Mobile Payment Financial Institutions Regulation 2020, Articles 15 and 19
Control biometrics and overseas hosting conservatively.
- Implementation action
- Before biometric collection or cross-border processing, assess necessity, proportionality, security, vendor access and transfer risk and obtain current local advice; do not claim an unverified breach deadline or regulator approval.
- Evidence to retain
- Impact assessment, architecture, contract, security controls, approval and legal update check.
- Primary citation
- Operational privacy control pending comprehensive legislation
11Practical evidence packsMaintain concise evidence packs that reproduce decisions and expose legal dependencies.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting 2014 Act, Articles 5-6 and CBOS Circular 8/2026
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, immediate-reporting chronology, approvals, submission, acknowledgement, follow-up, sanctions actions and access logs.
- Evidence to retain
- Complete sampled case pack and controlled access log.
- Primary citation
- Operational control supporting 2014 Act, Articles 6, 9 and 14-16
Maintain a launch and legal-change pack.
- Implementation action
- Record current FIU procedure, sector thresholds, licences, 2026 CBOS controls, registry evidence, sanctions instructions, privacy analysis, conflict-related operating constraints, tests and confirmations before launch and on change.
- Evidence to retain
- Signed launch pack, source register, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
13 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Terrorism Financing Act 2014Central Bank of Sudan · Primary legislation
- AML/CFT/CPF regulatory and supervisory controls - Circular No. 8/2026Central Bank of Sudan · Official binding circular
- Laws and regulations repositoryCentral Bank of Sudan · Official regulator repository
- Electronic Transactions Act 2007Central Bank of Sudan · Primary legislation
- Mobile Payment Financial Institutions Regulation 2020Central Bank of Sudan · Official regulation
- Electronic payment system operations - Circular No. 1/2013Central Bank of Sudan · Official circular
- Current electronic-payment regulatory clarificationCentral Bank of Sudan · Official regulatory statement
- Companies Act registration mandate and Ministry functionsMinistry of Justice · Official registry authority statement
- Sudan third follow-up report, April 2016MENAFATF · Authoritative regional assessment
- Sudan FATF country pageFATF · Authoritative country record
- FATF jurisdictions under increased monitoring, 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Sudan KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Financial Information Unit established by Article 12 of the 2014 Act. Obtain the FIU's current form, secure filing route and acknowledgement procedure before production use.
When is suspicion reported?+
Immediately for a suspicious transaction or attempt, regardless of value, under Circular 8/2026 for CBOS-supervised institutions. The 2014 Act also requires immediate reporting by financial and non-financial reporting persons.
What occasional-customer CDD threshold applies?+
For institutions within Circular 8/2026, CDD applies before a single or apparently linked occasional transaction equals or exceeds EUR 15,000 in national or foreign currency. Confirm the rule applicable to non-CBOS sectors separately.
How is beneficial ownership determined?+
For CBOS institutions, identify each natural person owning or controlling more than 10%, then any person controlling by other means, and finally the natural person responsible for senior management if the earlier tests identify no one. Legal arrangements require identification of their principal parties and ultimate controllers.
How long are core AML records retained?+
At least five years, with the trigger depending on record type: relationship end or occasional transaction, transaction or attempt, FIU report, or risk-assessment completion or update. Criminal-case records are held until final disposal if longer.
What happens on a sanctions match?+
A CBOS institution must freeze covered assets immediately, without delay or prior notice, prevent funds or services being made available, and immediately notify the Technical Committee and FIU as applicable.
What cross-border cash threshold applies?+
Article 31 leaves the declaration amount to regulations. Obtain the current customs instrument and do not substitute the EUR 15,000 occasional-customer CDD trigger.
Is Sudan on a FATF public list?+
No. Sudan was not named on either FATF public list dated 19 June 2026. This does not mean that Sudan, a product or a customer is low risk.
Does Sudan have a comprehensive data-protection law?+
No comprehensive generally applicable statute or independent privacy authority was verified. Apply the Electronic Transactions Act, sector confidentiality and security rules, contracts and conservative data-governance controls, and obtain current local advice for biometrics and overseas hosting.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 13 September 2026. Sudan's conflict, institutional relocation and legal transitions can affect practical access and enforcement. Confirm later Gazette amendments, FIU filing mechanics, sector rules, non-bank thresholds, company-register and beneficial-ownership procedures, sanctions-list circulation, privacy and biometric requirements, and product permissions with the competent authority and qualified Sudanese counsel before launch.