Burkina Faso KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Burkina Faso.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Burkina Faso ?
La checklist pour Burkina Faso traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 40 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML/CFT/CPF law
- Law No. 046-2024/ALT of 30 December 2024
- Financial intelligence unit
- CENTIF Burkina Faso
- STR timing
- Immediately after suspicion or reasonable grounds arise
- Cash transaction report
- XOF 15 million or more, including apparently linked operations
- Core AML retention
- 10 years under record-class-specific clocks
- Beneficial ownership
- Controlling ownership, other control, then senior-manager fallback
- Payments authority
- BCEAO within the UMOA framework
- Privacy authority
- Commission de l'Informatique et des Libertes (CIL)
- VASP perimeter
- Prior competent-authority approval or authorisation required
- FATF public lists
- Removed from increased monitoring in October 2025
Détail d’implémentation
Exigences et actions de conformité pour Burkina Faso
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before onboarding or launch.4 éléments+
Financial institutions and listed designated non-financial businesses and professions are reporting persons.
- Action d’implémentation
- Map each entity, product, profession, branch, distributor, agent and outsourced function to Law No. 046-2024/ALT and document the responsible supervisor.
- Preuves à conserver
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Source primaire
- Law No. 046-2024/ALT, arts. 2-4 and 107
CENTIF receives and analyses suspicious transaction reports and may request information.
- Action d’implémentation
- Appoint an authorised correspondent and obtain the current CENTIF access, form and acknowledgement instructions before production reporting.
- Preuves à conserver
- Appointment, access record, reporting procedure and test evidence.
- Source primaire
- Law No. 046-2024/ALT, arts. 60, 64 and 95-103
In-scope virtual-asset services require prior approval or authorisation from the competent authority.
- Action d’implémentation
- Obtain a written perimeter assessment and the required approval before exchange, transfer, custody or other in-scope virtual-asset activity.
- Preuves à conserver
- Classification, application, approval, conditions and service map.
- Source primaire
- Law No. 046-2024/ALT, arts. 58-59
Regulated payment services require the applicable BCEAO authorisation.
- Action d’implémentation
- Map each payment, e-money, acquiring, transfer, remittance, initiation and agent function to the current UMOA payment-services framework.
- Preuves à conserver
- Licence or exemption analysis, BCEAO register check and partner file.
- Source primaire
- BCEAO Instruction No. 001-01-2024 and current authorised-institution register
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.3 éléments+
Reporting persons must maintain internal organisation, controls and risk management proportionate to their activities.
- Action d’implémentation
- Approve policies for CDD, BO, PEPs, sanctions, monitoring, reporting, recordkeeping, training, screening and independent testing.
- Preuves à conserver
- Policy suite, approvals, control library, training and audit reports.
- Source primaire
- Law No. 046-2024/ALT, arts. 12-14
Money-laundering, terrorist-financing and proliferation-financing risks must be identified, assessed, documented and kept current.
- Action d’implémentation
- Assess customers, geographies, products, services, transactions, channels, new products and technologies before launch and on material change.
- Preuves à conserver
- Risk assessment, methodology, source data, change log and approvals.
- Source primaire
- Law No. 046-2024/ALT, art. 15
Institutions must be able to justify that customer controls are proportionate to risk.
- Action d’implémentation
- Define risk-rating logic, control variants, approval levels and review cycles, then test their operation.
- Preuves à conserver
- Risk model, decision records, samples and assurance results.
- Source primaire
- Law No. 046-2024/ALT, arts. 19-21 and 84-85
03Natural-person identification and CDDIdentify and verify customers, actors and beneficial owners at every statutory trigger.4 éléments+
Before a relationship or assisted transaction, collect and verify identity from reliable, independent sources and understand purpose and intended nature.
- Action d’implémentation
- Capture identity attributes, verify evidence provenance, identify the beneficial owner and establish the expected activity profile.
- Preuves à conserver
- CDD file, source provenance, verification result, purpose and risk decision.
- Source primaire
- Law No. 046-2024/ALT, arts. 16-17
CDD also applies to transfers, suspicion, identity doubt and applicable occasional or linked transactions.
- Action d’implémentation
- Configure relationship, transfer, cash aggregation, suspicion and identity-quality triggers; do not treat a threshold as a safe harbour.
- Preuves à conserver
- Trigger matrix, aggregation results, alerts and CDD timestamps.
- Source primaire
- Law No. 046-2024/ALT, arts. 17 and 49; UMOA Decision No. 021
Limited delayed verification must finish as soon as possible and before the first transaction, with effective risk controls.
- Action d’implémentation
- Block transaction capability until verification is complete and document why each statutory condition is satisfied.
- Preuves à conserver
- Deferral approval, restrictions, completion timestamp and exception testing.
- Source primaire
- Law No. 046-2024/ALT, art. 18
Remote relationships require particular and sufficient preventive measures.
- Action d’implémentation
- Use risk-calibrated document, device, liveness, biometric or equivalent safeguards and manual escalation without assuming one technology is legally sufficient.
- Preuves à conserver
- Remote-onboarding standard, vendor review, model tests and exceptions.
- Source primaire
- Law No. 046-2024/ALT, art. 22
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 éléments+
Legal-person and legal-arrangement CDD covers legal name, form, constitutive documents, powers, management and addresses.
- Action d’implémentation
- Obtain current RCCM and constitutional evidence and verify every representative's identity and authority.
- Preuves à conserver
- Registry extract, statutes, managers, addresses, mandate and discrepancy log.
- Source primaire
- Law No. 046-2024/ALT, arts. 17 and 26
The BO cascade tests controlling ownership, then control by other means, then the relevant senior managing official.
- Action d’implémentation
- Trace every ownership layer and control right; document why each stage did or did not identify a natural person before using the fallback.
- Preuves à conserver
- Ownership chart, control analysis, fallback rationale and verified BO files.
- Source primaire
- Law No. 046-2024/ALT, art. 26
Trusts and comparable arrangements use role-based BO tests.
- Action d’implémentation
- Identify and verify the settlor, trustee, protector, beneficiaries or class and every other natural person exercising ultimate control.
- Preuves à conserver
- Instrument, role register, identity files and control analysis.
- Source primaire
- Law No. 046-2024/ALT, art. 26
Companies must keep accurate, current shareholder, member and BO information; the national BO register is established by law.
- Action d’implémentation
- Maintain event-driven updates, reconcile RCCM and BO-register data and complete filings under the current competent-authority procedure.
- Preuves à conserver
- Registers, update log, filing receipts, supporting documents and discrepancies.
- Source primaire
- Law No. 046-2024/ALT, arts. 76-79 and 122; current competent-authority implementation instruments
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.4 éléments+
PEP relationships require risk systems, senior-management approval, source-of-wealth and source-of-funds measures, and enhanced monitoring.
- Action d’implémentation
- Screen customers and BOs for domestic, foreign and international-organisation PEP exposure and connected-person risk.
- Preuves à conserver
- Screening, match rationale, source file, approval and monitoring plan.
- Source primaire
- Law No. 046-2024/ALT, art. 29
Institutions reassess identified PEP customer profiles every three years and retain risk-based treatment where warranted.
- Action d’implémentation
- Schedule the statutory reassessment and document any change to status or controls.
- Preuves à conserver
- Review diary, reassessment, decision and approval.
- Source primaire
- Law No. 046-2024/ALT, art. 29
Higher-risk relationships require enhanced measures; simplified treatment needs a demonstrated lower-risk basis and cannot override suspicion.
- Action d’implémentation
- Document control changes, corroboration, approvals and monitoring intensity for each risk treatment.
- Preuves à conserver
- EDD or SDD rationale, evidence, approval and review.
- Source primaire
- Law No. 046-2024/ALT, arts. 30 and 84-85
Reliance on a third party does not remove the institution's responsibility for CDD.
- Action d’implémentation
- Assess eligibility, obtain required information immediately, contract for document access and test retrieval.
- Preuves à conserver
- Due diligence, agreement, retrieval test and exceptions.
- Source primaire
- Law No. 046-2024/ALT, arts. 35-38
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity, monitor continuously and report suspicion immediately and confidentially.4 éléments+
If required CDD cannot be completed, do not open or execute, or terminate the relationship, and submit an STR.
- Action d’implémentation
- Operate a controlled block or exit and preserve the confidential STR decision.
- Preuves à conserver
- Failure reason, block, closure, STR and acknowledgement.
- Source primaire
- Law No. 046-2024/ALT, art. 25
Relationships and transactions require ongoing scrutiny, current CDD and written examination of complex, unusual or apparently purposeless activity.
- Action d’implémentation
- Investigate source, destination, purpose and BO, refresh CDD and retain the confidential written analysis.
- Preuves à conserver
- Alerts, cases, report, refreshed CDD and review.
- Source primaire
- Law No. 046-2024/ALT, arts. 19-21
Reporting persons must immediately report suspected sums, transactions and attempted transactions to CENTIF.
- Action d’implémentation
- Timestamp when suspicion or reasonable grounds arose and file using the current prescribed route and model; send changes or supplements without delay.
- Preuves à conserver
- Internal report, analysis, STR, CENTIF receipt and timeline.
- Source primaire
- Law No. 046-2024/ALT, art. 60
Suspicious activity is withheld before reporting unless the statutory post-execution conditions apply; tipping off is prohibited.
- Action d’implémentation
- Govern holds, lawful release, post-execution reporting and restricted communications.
- Preuves à conserver
- Hold decision, exception rationale, access logs and communications record.
- Source primaire
- Law No. 046-2024/ALT, arts. 61 and 63
07Wires, cash thresholds, payments and agentsKeep CDD triggers, special examination and threshold reports distinct.4 éléments+
Cash transactions of XOF 15 million or more, including apparently linked operations, are reported to CENTIF.
- Action d’implémentation
- Aggregate linked activity, configure the exact in-scope entity and transaction logic, and obtain current CENTIF reporting instructions.
- Preuves à conserver
- Threshold configuration, tests, reports, receipts and exception record.
- Source primaire
- Law No. 046-2024/ALT, art. 72; UMOA Decision No. 021, art. 8
Multiple cash transactions exceeding XOF 9 million in one day or at unusual frequency trigger identification and verification for financial institutions.
- Action d’implémentation
- Aggregate by person and account across channels and apply CDD regardless of amount where suspicion exists.
- Preuves à conserver
- Aggregation logic, customer match, CDD file and testing.
- Source primaire
- Law No. 046-2024/ALT, art. 17(i); UMOA Decision No. 021, art. 3
Payment in cash or bearer title at XOF 50 million or more, and unusual or unjustified operations at XOF 10 million or more, require special examination.
- Action d’implémentation
- Investigate origin, destination, purpose and BO and retain a confidential report.
- Preuves à conserver
- Scenario, investigation, source evidence, report and approval.
- Source primaire
- Law No. 046-2024/ALT, art. 21; UMOA Decision No. 021, art. 4
Wire transfers must carry required originator and beneficiary information and deficient transfers require governed handling.
- Action d’implémentation
- Validate required data throughout the chain and define reject, suspend, execute, investigate and follow-up rules.
- Preuves à conserver
- Field matrix, validation, repair queue, samples and decisions.
- Source primaire
- Law No. 046-2024/ALT, arts. 39-47
08Targeted financial sanctions and CPFScreen, freeze, restrict and report without delay under the current designation framework.3 éléments+
Reporting persons must implement internal procedures for targeted financial sanctions.
- Action d’implémentation
- Screen customers, BOs, controllers, representatives and transactions at onboarding, list updates and before relevant activity.
- Preuves à conserver
- List inventory, update logs, screening results and match files.
- Source primaire
- Law No. 046-2024/ALT, arts. 89 and 124
Property of a designated person or entity is frozen immediately after notification, without prior notice, and must not be made available.
- Action d’implémentation
- Maintain a 24/7 freeze and escalation path covering direct, indirect, owned and controlled exposure.
- Preuves à conserver
- Procedure, system test, match decision, freeze and audit trail.
- Source primaire
- Law No. 046-2024/ALT, art. 89
CENTIF and the competent authority are informed immediately of relevant funds, frozen assets, measures and attempted operations.
- Action d’implémentation
- Use the current competent-authority route and obtain written direction before release or dealing.
- Preuves à conserver
- Notifications, receipts, directions and release decision.
- Source primaire
- Law No. 046-2024/ALT, arts. 90-91
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.4 éléments+
Customer identity, profile and analysis records are kept for 10 years after account closure or relationship cessation.
- Action d’implémentation
- Map every customer record class to the relationship-based clock and apply legal holds.
- Preuves à conserver
- Retention schedule, configuration, sample and deletion test.
- Source primaire
- Law No. 046-2024/ALT, art. 23
Transaction, accounting and business-correspondence records are kept for 10 years after execution.
- Action d’implémentation
- Use transaction-based clocks and retain enough information to reconstruct individual operations.
- Preuves à conserver
- Archive configuration, reconstruction test and retrieval log.
- Source primaire
- Law No. 046-2024/ALT, art. 23
Corporate and BO information is retained for at least 10 years after dissolution or the end of the relevant professional relationship.
- Action d’implémentation
- Assign an archive owner and preserve current and historic ownership evidence.
- Preuves à conserver
- Dissolution checklist, archive, access controls and retrieval test.
- Source primaire
- Law No. 046-2024/ALT, art. 79
Required records must be available to CENTIF, supervisors, judicial authorities and authorised investigators.
- Action d’implémentation
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Preuves à conserver
- Request register, retrieval tests, access log and response package.
- Source primaire
- Law No. 046-2024/ALT, arts. 24 and 103
10Privacy, biometrics and transfersApply Law No. 001-2021/AN alongside AML collection, retention and disclosure duties.4 éléments+
Personal-data processing requires a lawful basis, defined purpose, proportionality, security, transparency and rights controls.
- Action d’implémentation
- Inventory identity, BO, screening, monitoring and reporting data; document purpose, basis, access, recipients, location and retention.
- Preuves à conserver
- Processing register, basis assessment, notices, access matrix and retention map.
- Source primaire
- Law No. 001-2021/AN, arts. 12-25
Processing normally requires the applicable CIL declaration, opinion or authorisation before implementation unless exempt.
- Action d’implémentation
- Classify each processing operation under the normal, simplified, opinion, authorisation or exemption route and retain the CIL receipt or decision.
- Preuves à conserver
- Formality matrix, filing, receipt or authorisation and change log.
- Source primaire
- Law No. 001-2021/AN, arts. 26-33
Private-sector biometric processing, national identifiers, file interconnections and certain offence data require prior CIL authorisation.
- Action d’implémentation
- Do not deploy facial, fingerprint, liveness-template or comparable biometric processing until the exact legal route and authorisation are confirmed.
- Preuves à conserver
- Legal assessment, necessity record, CIL authorisation, security design and tests.
- Source primaire
- Law No. 001-2021/AN, art. 31
Transfers to a foreign country require prior CIL authorisation and an adequate-protection or permitted-exception analysis.
- Action d’implémentation
- Map every hosting, support, analytics and vendor destination; obtain the required CIL decision before transfer and document safeguards.
- Preuves à conserver
- Transfer map, adequacy analysis, contracts, CIL authorisation and access logs.
- Source primaire
- Law No. 001-2021/AN, arts. 31 and 42-44
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 éléments+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Action d’implémentation
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Preuves à conserver
- Control checklist, linked file, approvals and release log.
- Source primaire
- Law No. 046-2024/ALT, arts. 12-26
Time-sensitive thresholds, lists, reporting routes, registers and licences require governed change monitoring.
- Action d’implémentation
- Assign owners to review ALT, Ministry of Finance, CENTIF, BCEAO, UMOA, CEFORE, CIL, FATF and GIABA sources on a documented schedule.
- Preuves à conserver
- Legal inventory, source log, change assessment and implementation tickets.
- Source primaire
- Official sources listed below
Registre des sources primaires
16 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 046-2024/ALT of 30 December 2024 on AML/CFT/CPFLegislative Assembly of Burkina Faso · Primary legislation
- Official legislative record for Law No. 046-2024/ALTLegislative Assembly of Burkina Faso · Official legislative record
- Official adoption announcement for the 2024 AML/CFT/CPF lawMinistry of Finance, Burkina Faso · Official promulgation context
- 2023 UMOA uniform AML/CFT/CPF lawBCEAO · Primary regional legal framework
- UMOA Decision No. 021 of 21 December 2023 setting implementation thresholdsBCEAO · Primary regional decision
- BCEAO Instruction No. 003-03-2025 on customer identification and knowledgeBCEAO · Primary regulator instruction
- BCEAO Instruction No. 001-03-2025 on AML/CFT/CPF organisation and controlBCEAO · Primary regulator instruction
- BCEAO Instruction No. 001-01-2024 on payment services in the UMOABCEAO · Primary regulator instruction
- CENTIF Burkina Faso official portalCENTIF Burkina Faso · Official FIU portal
- Official CEFORE company-creation portalMaison de l'Entreprise du Burkina Faso · Official registry procedure
- Law No. 001-2021/AN on personal-data protectionCommission de l'Informatique et des Libertes · Primary legislation
- CIL processing declaration and authorisation portalCommission de l'Informatique et des Libertes · Official data-protection authority procedure
- Burkina Faso country assessment and follow-upFATF · Authoritative assessment index
- Burkina Faso removed from increased monitoring - 24 October 2025FATF · Authoritative public statement
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Réponses directes
Questions KYC, KYB et AML pour Burkina Faso
Who receives suspicious transaction reports in Burkina Faso?+
CENTIF Burkina Faso receives reports using the current prescribed model and route.
When is an STR due?+
Immediately after suspicion or reasonable grounds arise. Attempted transactions are included, and relevant supplementary information is sent without delay.
What cash transaction report threshold applies?+
Institutions and designated non-financial businesses report cash transactions of XOF 15 million or more, whether a single operation or apparently linked operations.
What beneficial-ownership test applies?+
For legal persons, identify the natural person with controlling ownership, then control by other means, and only then the relevant senior managing official. Trusts and similar arrangements use role-based tests.
How long are AML records kept?+
Customer identity, profile and analysis records are kept for 10 years after relationship cessation; transaction and correspondence records are kept for 10 years after execution.
Do virtual-asset and payment services require authorisation?+
Yes, where the activity falls within the regulated perimeter. Obtain a current activity-specific decision from the competent authority before launch.
Do biometrics and foreign transfers require CIL authorisation?+
Yes. Private-sector biometric processing and transfers to a foreign country are among the processing operations subject to prior CIL authorisation under Law No. 001-2021/AN.
Is Burkina Faso on a FATF public list?+
No. FATF removed Burkina Faso from increased monitoring on 24 October 2025, and it was not named in FATF's June 2026 increased-monitoring or call-for-action statements.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 25 July 2026. Confirm the live CENTIF reporting route and forms, activity-specific licences, sanctions instructions, beneficial-owner filing workflow, CIL formalities and all sector overlays with the competent authority and qualified Burkinabe counsel before launch.