Uruguay KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Uruguay.

Direct answer
What does the Uruguay compliance checklist cover?
The Uruguay checklist translates primary KYC, KYB and AML rules into 11 control areas and 35 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Información y Análisis Financiero (UIAF) within BCU
- Core AML framework
- Law 19.574, amended by Law 20.469 in March 2026, and Decree 379/018
- Suspicious reports
- Immediately after an operation, completed or attempted, is classified as suspicious
- Beneficial owner
- Natural person with final control; 15% ownership or voting rights is an express limb
- CDD failure
- Do not start or continue; consider or file a ROS as the facts require
- Retention
- At least five years; regulation or sector rules can require up to ten years
- PEP window
- Current and former PEP status remains relevant for at least five years
- Targeted sanctions
- Freeze without delay on applicable list matches and notify UIAF immediately
- Privacy breach
- Notify URCDP within 72 hours after learning of a qualifying security breach
- Virtual assets
- Circular 2507 applications open 1 September 2026; existing PSAVs may apply through 31 March 2027 and continue while processed
- FATF status
- GAFILAT member; not named on FATF public lists reviewed 1 August 2026
Implementation detail
Uruguay compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingResolve the exact legal and supervisory perimeter before configuring controls.3 items+
Financial obliged subjects fall under Law 19.574 article 12 and BCU/UIAF supervision.
- Implementation action
- Map the legal entity, product and reserved activity to the current BCU compilation and authorization or registration requirement.
- Evidence to retain
- Perimeter opinion, activity map, authorization, register extract and supervisor matrix.
- Primary citation
- Law 19.574 art. 12
DNFBPs and other non-financial obliged subjects fall under current article 13, as amended by Law 20.469.
- Implementation action
- Test every service against the current list, including professional, real-estate, corporate-service, free-zone and covered support activities; identify SENACLAFT duties.
- Evidence to retain
- Applicability matrix, service catalogue, customer and transaction nexus, registration and counsel sign-off.
- Primary citation
- Law 19.574 art. 13; Law 20.469 art. 1
A technology or cross-border label does not remove authorization or AML obligations.
- Implementation action
- Assess solicitation, customer location, custody, settlement, issuance, transfer and local operational facts before launch.
- Evidence to retain
- Product flows, nexus memorandum, geofencing, terms, regulator correspondence and launch gate.
- Primary citation
- Law 19.574 arts. 12-13; applicable BCU rules
02Governance and risk assessmentControls must reflect documented customer, product, channel and geographic risk.3 items+
Obliged subjects must conduct and document a risk analysis and apply proportionate policies and procedures.
- Implementation action
- Assess inherent and residual risk, define scoring and overrides and connect results to simplified, standard or enhanced diligence.
- Evidence to retain
- Enterprise and customer risk methods, data inputs, validation, approvals and change log.
- Primary citation
- Law 19.574 arts. 14-17; Decree 379/018 arts. 5-13
CDD information and risk assessment must remain current throughout the relationship.
- Implementation action
- Set event-driven and risk-based refresh cycles; rescreen and reassess on ownership, activity, product or jurisdiction changes.
- Evidence to retain
- Refresh policy, trigger events, reviews, screening history, profile changes and exceptions.
- Primary citation
- Law 19.574 arts. 15-16
New products, technologies and delivery methods require risk review before material use.
- Implementation action
- Gate launch through AML, sanctions, privacy, security and licensing review and verify performance after deployment.
- Evidence to retain
- New-product assessment, scenarios, approvals, test results and post-launch review.
- Primary citation
- Decree 379/018 art. 7; applicable BCU governance rules
03Natural-person KYC and representativesCDD must bind the customer and representative to reliable evidence and the intended relationship.3 items+
Identify and verify the customer using reliable documents, data or information.
- Implementation action
- Capture required identity data, authenticate evidence, bind the applicant to it and resolve inconsistencies before activation.
- Evidence to retain
- Identity record, document images, authenticity and liveness output where used, timestamps and reviewer.
- Primary citation
- Law 19.574 arts. 14-16; Decree 379/018 arts. 7-12
Identify a representative and verify the power to act.
- Implementation action
- Verify the natural person, obtain the current mandate and confirm scope, validity and revocation against reliable evidence.
- Evidence to retain
- Representative KYC, mandate, registry or notarial check, authority decision and expiry control.
- Primary citation
- Law 19.574 art. 15
If required CDD cannot be completed, do not begin or continue and assess suspicious reporting.
- Implementation action
- Block activation or execution, preserve attempted activity, terminate where required and make a documented ROS decision without tipping off.
- Evidence to retain
- System block, failure record, termination, escalation, ROS decision and communication log.
- Primary citation
- Law 19.574 art. 16; Decree 379/018 art. 9
04KYB and beneficial ownershipCompany existence, authority, ownership and control must be verified and reconciled.3 items+
Legal-person CDD must establish legal existence, structure, purpose, address, managers and authority.
- Implementation action
- Obtain current registry and tax records, constitutional documents, management and signatory evidence and reconcile discrepancies.
- Evidence to retain
- Registry extract, RUT evidence, statutes, management list, address, signatory proof and discrepancy log.
- Primary citation
- Law 19.574 arts. 14-16; Decree 379/018
Identify the natural person who ultimately owns or controls the customer; 15% capital or voting rights is an express limb.
- Implementation action
- Trace direct and indirect ownership and voting rights, then contractual or de facto control; identify the person on whose behalf funds or activity occur.
- Evidence to retain
- Ownership chart, percentage calculations, agreements, control memo, declaration and corroboration.
- Primary citation
- Law 19.574 art. 15
Covered entities must report and update beneficial-owner information in the BCU registry under Law 19.484 and its regulations.
- Implementation action
- Determine filing scope, submit current information, report changes within the applicable 30-day or 90-day period and retain supporting records at least five years.
- Evidence to retain
- Registry filing, receipt, ownership records, change log, deadline control and retention schedule.
- Primary citation
- Law 19.484; Decree 166/017; Decree 43/026
05PEPs, EDD and relianceHigher risk requires added approval, source work and intensified monitoring.3 items+
Domestic, foreign and international-organization PEP status remains relevant during office and for at least five years afterward.
- Implementation action
- Screen customers, representatives, beneficial owners, family and close associates and document role, dates and relationship.
- Evidence to retain
- Screening, role analysis, relationship map, adjudication, approval and review date.
- Primary citation
- Law 19.574 art. 20
High-risk cases require enhanced due diligence, including source and approval measures proportionate to the risk.
- Implementation action
- Obtain senior approval, corroborate source of funds and wealth where applicable and apply intensified monitoring and refresh.
- Evidence to retain
- EDD memorandum, approval, source evidence, scenario settings, alert history and review.
- Primary citation
- Law 19.574 arts. 18-20; Decree 379/018 art. 13
Simplified diligence is available only in regulated lower-risk cases and never displaces sanctions monitoring or suspicion controls.
- Implementation action
- Define minimum measures and disqualifiers, record the low-risk basis and escalate any contradictory fact.
- Evidence to retain
- Simplified policy, risk evidence, approval, continuous screening and exceptions.
- Primary citation
- Law 19.574 arts. 17-18, as amended by Law 20.469
06Monitoring and suspicious reportingROS duties are suspicion-based and separate from objective or sector-specific reports.3 items+
Monitor activity against the customer profile and examine unusual or complex transactions and attempted transactions.
- Implementation action
- Run risk-calibrated scenarios, investigate promptly, document explanation and source and update risk where facts change.
- Evidence to retain
- Scenario inventory, alert, transaction trail, investigation, disposition and quality review.
- Primary citation
- Law 19.574 arts. 15-16; Decree 379/018 arts. 7 and 89-90
A suspicious operation report is sent to UIAF immediately once the completed or attempted operation is classified as suspicious.
- Implementation action
- Preserve the decision timestamp, file through the current UIAF channel and retain the report and acknowledgement.
- Evidence to retain
- Alert, investigation, decision, ROS, submission timestamp, receipt and correction log.
- Primary citation
- Decree 379/018 arts. 89-90; BCU UIAF ROS guidance
Tipping off and unauthorized disclosure of ROS information are prohibited.
- Implementation action
- Restrict case access, separate customer communications from reporting and log every legally authorized disclosure.
- Evidence to retain
- Access controls, training, communications review, disclosure log and incident record.
- Primary citation
- Law 19.574 arts. 21-23
07Thresholds, transfers and cash controlsThreshold controls depend on activity and sector; there is no universal transaction-report threshold.3 items+
CDD applies whenever suspicion or identity doubt exists, regardless of a sector threshold.
- Implementation action
- Configure thresholds only as additional triggers and ensure suspicion, linked operations and evasion attempts override them.
- Evidence to retain
- Rules inventory, scenario tests, aggregation logic, overrides and alert samples.
- Primary citation
- Decree 379/018 art. 7
Sector and activity thresholds vary; for example, covered art or precious-goods transactions aggregate at USD 15,000 annually under Decree 379/018.
- Implementation action
- Maintain a current activity-specific threshold matrix and do not transplant one sector's amount into another.
- Evidence to retain
- Legal mapping, threshold table, currency source, system configuration and test cases.
- Primary citation
- Decree 379/018 art. 64 and sector chapters
Persons outside BCU supervision carrying more than USD 10,000 equivalent across the border must follow the applicable declaration regime.
- Implementation action
- Identify relevant cash or bearer-instrument handling, inform affected operations and preserve declarations and escalations.
- Evidence to retain
- Procedure, declaration, amount and currency record, receipt and incident log.
- Primary citation
- Decree 379/018 art. 100
08Sanctions and targeted financial measuresApplicable list matches require action without delay and immediate UIAF notice.3 items+
Law 19.749 requires preventive freezing without delay for applicable United Nations and other covered list matches.
- Implementation action
- Screen at onboarding, on list updates and before execution; validate matches promptly and freeze without advance notice where required.
- Evidence to retain
- List sources, screening logs, match packet, action timestamp and frozen-assets record.
- Primary citation
- Law 19.749
A freeze and relevant incoming assets must be notified immediately to UIAF for the statutory judicial process.
- Implementation action
- Use the current notification channel, preserve funds as directed and maintain the court and release timeline.
- Evidence to retain
- UIAF notice, receipt, court record, incoming-funds log, release or continuation instruction.
- Primary citation
- Law 19.749
Sanctions screening must cover customers, beneficial owners, representatives and relevant transaction parties.
- Implementation action
- Map every field and party, test aliases and transliteration and monitor feed and system failures.
- Evidence to retain
- Coverage map, test cases, alert samples, feed monitoring, incidents and remediation.
- Primary citation
- Law 19.749; Law 19.574 arts. 14-16
09Records, audit and regulator responseRecords must reconstruct the customer, transaction, alert and decision.3 items+
CDD and transaction records must be retained at least five years after an occasional transaction or relationship; regulation or sector rules can reach ten years.
- Implementation action
- Apply the longest applicable event-based period, preserve legal holds and test retrieval throughout the lifecycle.
- Evidence to retain
- Retention matrix, closure event, repository inventory, retrieval test, hold and disposal logs.
- Primary citation
- Law 19.574 art. 21
UIAF, BCU and SENACLAFT can require records within their competence.
- Implementation action
- Authenticate requests, preserve confidentiality and privilege, produce responsive records and track remediation.
- Evidence to retain
- Request, authority validation, production set, delivery receipt, privilege log and remediation tracker.
- Primary citation
- Law 19.574 arts. 6, 12-13 and 22
Independent review should test control effectiveness and reporting timeliness under the applicable sector rules.
- Implementation action
- Set competence and independence, sample end-to-end cases, validate data lineage and verify corrective-action closure.
- Evidence to retain
- Audit scope, workpapers, samples, report, actions and closure validation.
- Primary citation
- Applicable BCU compilation or SENACLAFT rule; Law 19.574 arts. 12-16
10Privacy, biometrics and transfersAML processing must also meet Uruguay's proactive privacy-accountability rules.4 items+
Law 18.331 requires lawful, purpose-limited, proportionate and secure processing with documented accountability.
- Implementation action
- Map roles, fields, purposes and legal grounds; provide transparency and reconcile data-subject rights with mandatory AML retention and reporting.
- Evidence to retain
- Data inventory, legal-basis register, notice, request procedure, retention reconciliation and security assessment.
- Primary citation
- Law 18.331 arts. 4-12
Biometric processing is expressly regulated and can require a data-protection impact assessment and privacy-by-design controls.
- Implementation action
- Assess necessity and alternatives before use, complete the required impact analysis, limit templates and access and provide an accessible fallback.
- Evidence to retain
- DPIA, necessity analysis, architecture, consent or legal ground, retention, access review and fallback test.
- Primary citation
- Law 18.331 arts. 4, 12 and 18 bis; URCDP Resolution 30/020
Notify URCDP within 72 hours after learning of a qualifying breach and notify significantly affected people in clear language.
- Implementation action
- Maintain detection, assessment and notification workflows, record the knowledge time and submit a detailed follow-up after remediation.
- Evidence to retain
- Incident log, impact analysis, URCDP notice, affected-person notice, timestamps and final report.
- Primary citation
- Decree 64/020 art. 4
International transfers require an adequate destination or a documented statutory route or exception.
- Implementation action
- Map every vendor, group and authority transfer, document the route and safeguards and control onward transfers and deletion.
- Evidence to retain
- Transfer register, adequacy or exception record, contract, due diligence and deletion proof.
- Primary citation
- Law 18.331 art. 23
11Payments, virtual assets and launch evidencePayment and PSAV permissions are activity-specific and newly time-sensitive.4 items+
Electronic-money issuance and other reserved payment activities require BCU authorization or registration as applicable.
- Implementation action
- Classify issuing, acquiring, processing, transfer, wallet and settlement functions against Law 19.210 and the current payment rules before launch.
- Evidence to retain
- Product flow, perimeter opinion, application, authorization or registration, conditions and register check.
- Primary citation
- Law 19.210 art. 4; BCU Payment System Rules
Law 20.345 brought PSAVs into BCU's perimeter and Circular 2507 establishes prior authorization and operating requirements.
- Implementation action
- Classify exchange, transfer, custody, administration, platform and related services; build the governance, capital, safeguards, conduct, technology and AML application pack.
- Evidence to retain
- Service classification, application plan, corporate records, control manuals, capital and guarantee evidence, contracts and approvals.
- Primary citation
- Law 20.345; BCU Circular 2507
PSAV applications open 1 September 2026; existing providers may apply through 31 March 2027 and continue while the application is processed.
- Implementation action
- Do not claim present authorization before the window opens; determine existing-provider status, calendar the deadline and control launch or continuity under the transition.
- Evidence to retain
- Transition memorandum, activity evidence, application calendar, submission receipt when available and regulator correspondence.
- Primary citation
- BCU Circular 2507, transitional provision to art. 127.27
Launch requires source-backed closure and end-to-end dry testing without fictional regulator submissions.
- Implementation action
- Test onboarding, KYB, ROS timing, sanctions, retention, privacy, breach and licensing gates; close blockers and obtain legal, compliance, privacy, security and product sign-off.
- Evidence to retain
- Completed checklist, source register, tests, defects and closure, approvals and monitoring owner.
- Primary citation
- Law 19.574 arts. 12-23; BCU Circular 2507
Primary-source register
25 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law 19.574 - current consolidated AML/CFT textIMPO · Primary legislation
- Law 20.469 of 19 March 2026IMPO · Primary amending legislation
- Decree 379/018 implementing AML dutiesIMPO · Primary regulation
- UIAF suspicious operation reporting guidanceBanco Central del Uruguay · Official reporting guidance
- UIAF Annual Report 2024Banco Central del Uruguay · Official FIU report
- UIAF Circular of 24 April 2026Banco Central del Uruguay · Official current instruction
- Law 19.749 on targeted financial sanctionsIMPO · Primary legislation
- Law 19.484 on fiscal transparency and beneficial ownershipIMPO · Primary legislation
- Decree 166/017 on beneficial-owner reportingIMPO · Primary regulation
- Decree 43/026 updating beneficial-owner rulesIMPO · Primary regulation
- BCU beneficial-owner registry guidanceBanco Central del Uruguay · Official registry guidance
- Law 18.331 on personal dataIMPO · Primary legislation
- Decree 64/020 on privacy accountability and breach responseIMPO · Primary regulation
- URCDP role and authorityUnidad Reguladora y de Control de Datos Personales · Official authority description
- URCDP general personal-data guideUnidad Reguladora y de Control de Datos Personales · Official guidance
- URCDP Resolution 30/020 on biometrics and DPIAsUnidad Reguladora y de Control de Datos Personales · Official regulatory decision
- Law 19.210 on financial inclusion and payment servicesIMPO · Primary legislation
- BCU Payment System RulesBanco Central del Uruguay · Official regulatory directory
- Law 20.345 on virtual assets and PSAVsIMPO · Primary legislation
- BCU Circular 2507 - PSAV regulationBanco Central del Uruguay · Primary regulatory instrument
- BCU announcement of the PSAV rulesBanco Central del Uruguay · Official current announcement
- FATF mutual evaluation of UruguayFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
- United Nations Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
Direct answers
Uruguay KYC, KYB and AML questions
Who receives suspicious operation reports?+
The UIAF within Banco Central del Uruguay receives ROS through its current channel. BCU supervises financial subjects; SENACLAFT supervises the non-financial subjects assigned to it.
When is a ROS due?+
Immediately once a completed or attempted operation is classified as suspicious. Preserve the classification time, submission and acknowledgement.
Is there one universal reporting threshold?+
No. Objective and systematic reports are sector- and activity-specific. Suspicion and identity doubt override monetary thresholds.
What beneficial-owner percentage applies?+
Fifteen percent of capital or voting rights is an express limb, but the analysis must also identify control by other means and the person on whose behalf funds or activity occur.
How long are AML records kept?+
At least five years after an occasional transaction or the end of the relationship. Regulation or sector rules can require up to ten years, and legal holds may require longer.
Can onboarding continue if CDD fails?+
No. Do not start or continue the relationship or transaction, preserve the facts and assess or file a ROS as required without tipping off.
What is the privacy breach deadline?+
A qualifying breach must be reported to URCDP within 72 hours after it becomes known. Significantly affected people must also receive clear notice, followed by a detailed report after remediation.
Are PSAVs already able to apply under Circular 2507?+
Applications open on 1 September 2026. Existing providers have through 31 March 2027 to apply and may continue while the application is processed. New providers should not operate before obtaining the required authorization.
Does a payment registration cover virtual-asset services?+
No. Classify payment and PSAV functions separately. Law 20.345 and Circular 2507 create a distinct BCU authorization framework for covered virtual-asset services.
Is Uruguay on a FATF public list?+
Uruguay was not named on the FATF increased-monitoring or call-for-action lists dated 19 June 2026 and reviewed 1 August 2026. It is a GAFILAT member and its evaluation history remains relevant.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, current BCU compilations, UIAF instructions, SENACLAFT rules or official forms. Reviewed 1 August 2026. Uruguay amended its AML law in March 2026 and adopted PSAV rules in July 2026; confirm commencement, transition, entity, activity, threshold, reporting channel and later developments with qualified Uruguayan counsel and the competent authority before launch.