Burundi KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Burundi.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Burundi ?
La checklist pour Burundi traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 40 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML/CFT law
- Law No. 1/08 of 27 March 2025 amending Law No. 1/02 of 4 February 2008
- Financial intelligence unit
- Cellule Nationale du Renseignement Financier (CNRF)
- STR timing
- Promptly; without delay after the statutory suspicion trigger
- Threshold reports
- CNRF or competent-authority thresholds - confirm the live instrument
- Core AML retention
- 10 years under relationship- and transaction-specific clocks
- Beneficial ownership
- Identify the natural person who ultimately owns or controls, or on whose behalf activity occurs
- Financial supervisor
- Banque de la Republique du Burundi (BRB) for BRB-supervised entities
- Privacy law
- Law No. 1/03 of 10 March 2026
- Data-breach notice
- Notify the protection body within 72 hours; high-risk individuals within 96 hours
- FATF public lists
- Not named in the June 2026 public statements
Détail d’implémentation
Exigences et actions de conformité pour Burundi
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and regulated activitiesResolve the entity, activity, supervisor and reporting perimeter before onboarding or launch.4 éléments+
The AML/CFT law applies to listed financial institutions, public and private licensing bodies, and designated non-financial businesses and professions.
- Action d’implémentation
- Map each entity, product, branch, agent, distributor and outsourced function to the statutory list and document the responsible supervisor.
- Preuves à conserver
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Source primaire
- Law No. 1/08 of 27 March 2025, arts. 1-3
CNRF is the national FIU and receives, analyses and disseminates suspicious transaction reports.
- Action d’implémentation
- Appoint an authorised correspondent and obtain the current CNRF form, access, submission and acknowledgement instructions before production reporting.
- Preuves à conserver
- Appointment, access record, reporting procedure and test evidence.
- Source primaire
- Law No. 1/08, arts. 4-6; Decree No. 100/009 of 9 February 2026
BRB Regulation No. 02/2026 applies to credit institutions, the National Postal Service, exchange bureaux, payment institutions, financing or guarantee funds and microfinance institutions.
- Action d’implémentation
- Document whether each service is within a BRB-supervised category and obtain the required activity-specific approval before launch.
- Preuves à conserver
- Classification, application, approval, conditions and service map.
- Source primaire
- BRB Regulation No. 02/2026, arts. 1-2
Virtual-asset services are within the AML law's defined regulated perimeter, but the reviewed sources did not establish a standalone live VASP licensing route.
- Action d’implémentation
- Do not launch exchange, transfer, custody or other virtual-asset activity without a written perimeter and licensing decision from BRB and other competent authorities.
- Preuves à conserver
- Legal analysis, authority correspondence, licence or written no-objection and product controls.
- Source primaire
- Law No. 1/08, art. 3 definitions; controlled licensing uncertainty
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.3 éléments+
Reporting institutions must establish AML/CFT policies, procedures, internal controls, employee screening, training and independent control arrangements.
- Action d’implémentation
- Approve and periodically test a control framework covering CDD, BO, PEPs, sanctions, monitoring, reporting, records and training.
- Preuves à conserver
- Policy suite, approvals, control library, training and assurance reports.
- Source primaire
- Law No. 1/08, arts. 75-76; BRB Regulation No. 02/2026, arts. 4 and 18-20
Institutions must identify and assess their ML/TF risks and apply controls proportionate to risk.
- Action d’implémentation
- Assess customers, countries, products, services, transactions, delivery channels and new technologies before launch and on material change.
- Preuves à conserver
- Risk assessment, methodology, source data, change log and approvals.
- Source primaire
- Law No. 1/08, arts. 23-38
BRB-supervised institutions must appoint an AML/CFT officer with adequate authority, independence and access and notify BRB and CNRF.
- Action d’implémentation
- Approve the appointment, formal mandate, resources, escalation rights and group coverage; file required notifications.
- Preuves à conserver
- Appointment, notifications, job mandate, access and board reporting.
- Source primaire
- BRB Regulation No. 02/2026, arts. 18-19
03Natural-person identification and CDDIdentify and verify customers, representatives and ultimate actors using reliable independent evidence.4 éléments+
Regular and occasional customers, and persons acting for them, must be identified and their authority verified through independent and reliable sources.
- Action d’implémentation
- Capture identity attributes, verify evidence provenance, confirm mandates and establish the purpose and expected nature of activity.
- Preuves à conserver
- CDD file, source provenance, verification result, authority and risk decision.
- Source primaire
- Law No. 1/08, art. 53; BRB Regulation No. 02/2026, arts. 5 and 10
Remote onboarding requires adapted identification measures and may use a reliable, independent digital-identification system.
- Action d’implémentation
- Authenticate documents and apply risk-calibrated independent checks, supplementary evidence and escalation without assuming one technology is legally sufficient.
- Preuves à conserver
- Remote-onboarding standard, vendor review, model tests, first-payment control and exceptions.
- Source primaire
- Law No. 1/08, art. 54; BRB Regulation No. 02/2026, art. 7
Anonymous and fictitious-name accounts are prohibited.
- Action d’implémentation
- Block activation until the customer and required actors are identified and verified under the applicable rule.
- Preuves à conserver
- Account controls, test results and rejected-case log.
- Source primaire
- Law No. 1/08, art. 52; BRB Regulation No. 02/2026, art. 5
CDD information must remain accurate and relevant during the relationship.
- Action d’implémentation
- Use risk-based and event-driven refreshes for identity, purpose, expected activity, ownership and authority.
- Preuves à conserver
- Refresh schedule, triggers, updated files and exception testing.
- Source primaire
- Law No. 1/08, art. 65; BRB Regulation No. 02/2026, art. 5
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 éléments+
Businesses and branches register through the ADB commercial register and maintain registrations for later changes.
- Action d’implémentation
- Obtain current registry evidence, constitutive documents, tax number, registered address, managers and representative mandates; reconcile later changes.
- Preuves à conserver
- Commercial-register certificate, NIF, statutes, change filings and discrepancy log.
- Source primaire
- Commercial Code 2015, arts. 34-37; ADB official creation and modification procedures
Institutions must discover and verify the natural person who ultimately owns or controls the customer or on whose behalf a transaction occurs.
- Action d’implémentation
- Trace ownership and control through every layer and record the natural-person conclusion and evidence; do not substitute an undefined percentage.
- Preuves à conserver
- Ownership chart, control analysis, source records and verified BO files.
- Source primaire
- Law No. 1/08, art. 3 definitions and arts. 51, 53 and 64; BRB Regulation No. 02/2026, arts. 3, 5-6
Trustees or equivalent managers must disclose that they act for others at relationship and prescribed occasional-transaction triggers.
- Action d’implémentation
- Identify the arrangement, trustee or manager, settlor, beneficiaries and all persons exercising ultimate control; confirm any live threshold instrument.
- Preuves à conserver
- Instrument, role register, identity files, control analysis and threshold check.
- Source primaire
- Law No. 1/08, art. 55
The 2026 national risk assessment reported that Burundi did not yet have a national BO register.
- Action d’implémentation
- Do not represent ordinary commercial-register evidence as a verified national BO filing; monitor for a new register and reconcile when implemented.
- Preuves à conserver
- Registry checks, customer-supplied ownership evidence, independent corroboration and change-monitoring log.
- Source primaire
- Burundi National Risk Assessment 2026, para. 161
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.4 éléments+
Domestic, foreign and international-organisation PEPs, close family and known associates fall within the statutory PEP framework.
- Action d’implémentation
- Screen customers, beneficial owners, controllers and representatives at onboarding, list updates and periodic review.
- Preuves à conserver
- Screening, match rationale, relationship mapping and review record.
- Source primaire
- Law No. 1/08, art. 3 definitions 35-38
BRB-supervised institutions apply enhanced control to PEP relationships; statutory PEP status continues for two years after the relevant function ends.
- Action d’implémentation
- Require risk-based senior approval, source-of-wealth and source-of-funds evidence and enhanced monitoring, including after office where risk persists.
- Preuves à conserver
- Source file, approval, monitoring plan and two-year status diary.
- Source primaire
- Law No. 1/08, art. 3 definition 38; BRB Regulation No. 02/2026, art. 5
Reliance on a third party does not remove the reporting institution's responsibility.
- Action d’implémentation
- Confirm equivalent CDD and supervision, obtain identity material without delay, contract for access and test retrieval.
- Preuves à conserver
- Due diligence, agreement, retrieval test and exceptions.
- Source primaire
- Law No. 1/08, arts. 46 and 58-60; BRB Regulation No. 02/2026, arts. 8-9
Simplified identification may be allowed only in circumstances defined by the competent authority and may not override suspicion.
- Action d’implémentation
- Use simplified treatment only with the exact current instrument, documented lower-risk basis and a suspicion override.
- Preuves à conserver
- Instrument, risk rationale, approval and monitoring.
- Source primaire
- Law No. 1/08, arts. 56 and 60
06Failed CDD, monitoring and suspicious reportingStop unsafe activity, monitor continuously and report suspicion promptly and confidentially.4 éléments+
If doubt about the true beneficial actor persists after verification, the operation or relationship must end and suspicion must be considered for reporting.
- Action d’implémentation
- Operate a controlled block or exit and preserve the confidential STR decision.
- Preuves à conserver
- Failure reason, block, closure, analysis, STR and acknowledgement.
- Source primaire
- Law No. 1/08, art. 64; BRB Regulation No. 02/2026, art. 6
Complex, abnormally large or unusual activity without apparent economic or lawful purpose requires examination and written documentation.
- Action d’implémentation
- Investigate source, destination, purpose and actors, refresh CDD and retain the confidential written analysis.
- Preuves à conserver
- Alerts, cases, source evidence, report and approval.
- Source primaire
- Law No. 1/08, arts. 66-67 and 72-73; BRB Regulation No. 02/2026, art. 12
Reporting entities that suspect or reasonably suspect criminal proceeds or terrorist-financing links must report promptly to CNRF.
- Action d’implémentation
- Timestamp the trigger and submit using the current CNRF format and route without waiting for proof of an offence.
- Preuves à conserver
- Internal report, analysis, STR, CNRF receipt and timeline.
- Source primaire
- Law No. 1/08, arts. 12-15; BRB Regulation No. 02/2026, art. 14
Suspected activity is withheld before reporting unless non-execution is impossible or would frustrate the investigation; tipping off is prohibited.
- Action d’implémentation
- Govern transaction holds, lawful post-execution reporting and restricted communications; escalate urgent cases to CNRF.
- Preuves à conserver
- Hold decision, exception rationale, access logs and communications record.
- Source primaire
- Law No. 1/08, arts. 16-18; BRB Regulation No. 02/2026, art. 15
07Wires, thresholds, payments and agentsKeep CDD triggers, special examination and threshold reports distinct.4 éléments+
Cash and other threshold reports apply at amounts set by CNRF or the competent authority, including apparently linked operations.
- Action d’implémentation
- Obtain and version-control the live CNRF and BRB threshold instruments; configure aggregation and do not invent a value from the primary law.
- Preuves à conserver
- Current instrument, configuration, tests, reports, receipts and exception record.
- Source primaire
- Law No. 1/08, arts. 41 and 48; BRB Regulation No. 02/2026, arts. 3 and 13
Electronic transfers require verified originator name, account and address or alternative identity information.
- Action d’implémentation
- Validate required data through the chain and preserve originator and beneficiary records.
- Preuves à conserver
- Field matrix, validation, repair queue, samples and decisions.
- Source primaire
- Law No. 1/08, arts. 69-70
Incoming transfers lacking complete originator information must be repaired and verified; if the information is not obtained, refuse and report to CNRF.
- Action d’implémentation
- Define repair, reject, suspend, investigate and report rules with auditable timelines.
- Preuves à conserver
- Repair requests, reject decisions, STRs and testing.
- Source primaire
- Law No. 1/08, art. 71
Payment services and exchange activity require the applicable BRB approval and AML controls.
- Action d’implémentation
- Map the product, agent, outsourcing and settlement chain to the current payments and exchange rules and licence conditions.
- Preuves à conserver
- Licence, conditions, agent register, oversight and audit results.
- Source primaire
- Law No. 1/07 of 11 May 2018; BRB Payment Regulation No. 002/2024; BRB Regulation No. 02/2026
08Targeted financial sanctions and proliferation riskScreen, freeze, restrict and report under the current designation framework.3 éléments+
Funds linked to UN-designated terrorists, terrorist financiers and terrorist organisations are subject to a court-defined freeze, and holders must freeze them immediately.
- Action d’implémentation
- Maintain list-update, screening and rapid escalation controls and obtain competent-authority direction for the specific match.
- Preuves à conserver
- List inventory, update logs, screening, match decision, freeze and legal direction.
- Source primaire
- Law No. 1/08, art. 88
Relevant designated-person funds must be reported promptly to CNRF or another competent authority.
- Action d’implémentation
- Notify through the current route, preserve the receipt and do not release or deal without written authority.
- Preuves à conserver
- Notification, receipt, direction and release decision.
- Source primaire
- Law No. 1/08, art. 89
The reviewed AML statute is framed principally around ML and TF; CPF implementation details require separate confirmation.
- Action d’implémentation
- Screen applicable UN proliferation designations and obtain current Burundi implementation and reporting instructions before dealing.
- Preuves à conserver
- Legal update, screening records, authority correspondence and escalation decision.
- Source primaire
- Controlled uncertainty; CNRF 2026 mutual-evaluation materials
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.3 éléments+
CDD, account, correspondence, identity, BO and analysis records are retained for 10 years after the business relationship ends.
- Action d’implémentation
- Map every record class to the relationship-based clock and apply legal holds.
- Preuves à conserver
- Retention schedule, configuration, sample and deletion test.
- Source primaire
- Law No. 1/08, art. 47(1); BRB Regulation No. 02/2026, art. 11
Domestic and international transaction data sufficient to reconstruct each operation are retained for 10 years after execution.
- Action d’implémentation
- Use transaction-based clocks and retain amount, currency, actors, accounts and supporting evidence.
- Preuves à conserver
- Archive configuration, reconstruction test and retrieval log.
- Source primaire
- Law No. 1/08, art. 47(2)
Required information must be readily accessible to CNRF and other competent authorities.
- Action d’implémentation
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Preuves à conserver
- Request register, retrieval tests, access log and response package.
- Source primaire
- Law No. 1/08, arts. 47 and 74
10Privacy, biometrics, breaches and transfersApply Law No. 1/03 of 10 March 2026 alongside mandatory AML processing.5 éléments+
Personal-data processing must be lawful, fair, purpose-limited, proportionate, accurate, time-limited and secure.
- Action d’implémentation
- Inventory KYC, BO, screening, monitoring and reporting data and document purpose, legal basis, access, recipients and retention.
- Preuves à conserver
- Processing register, basis assessment, notices, access matrix and retention map.
- Source primaire
- Law No. 1/03 of 10 March 2026, arts. 5-8
Biometric identification and other sensitive-data processing are prohibited unless an Article 10 exception applies, with additional safeguards.
- Action d’implémentation
- Before facial, fingerprint, liveness-template or comparable biometric use, document the exact exception, necessity, security and any required impact assessment and authorisation.
- Preuves à conserver
- Legal assessment, explicit consent where applicable, DPIA, authorisation, encryption and access tests.
- Source primaire
- Law No. 1/03, arts. 9-10 and 40-41
High-risk processing requires a prior DPIA and submission to the protection body with an authorisation request.
- Action d’implémentation
- Complete the legal and technical risk analysis, obtain DPO review and do not deploy until the prescribed authorisation process is complete.
- Preuves à conserver
- DPIA, DPO opinion, application, authority decision and remediation.
- Source primaire
- Law No. 1/03, arts. 40-41
Transfers abroad require an adequate destination or safeguards approved by Burundi's personal-data protection body.
- Action d’implémentation
- Map every hosting, support and vendor destination and obtain the required adequacy or safeguards decision before transfer.
- Preuves à conserver
- Transfer map, adequacy analysis, safeguards, approval and access logs.
- Source primaire
- Law No. 1/03, arts. 15-16
A qualifying breach is notified to the protection body within 72 hours; affected individuals are notified within 96 hours where high risk arises.
- Action d’implémentation
- Run a documented breach triage clock, preserve the risk analysis and issue clear notifications with consequences and mitigation.
- Preuves à conserver
- Incident log, discovery time, risk assessment, notices, receipts and remediation.
- Source primaire
- Law No. 1/03, arts. 45-46
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 éléments+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Action d’implémentation
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Preuves à conserver
- Control checklist, linked file, approvals and release log.
- Source primaire
- Law No. 1/08, arts. 47, 51-76
Thresholds, reporting routes, sanctions directions, registers, licences and privacy implementation are time-sensitive.
- Action d’implémentation
- Assign owners to monitor CNRF, BRB, ADB, the personal-data protection body, FATF and ESAAMLG on a documented schedule.
- Preuves à conserver
- Legal inventory, source log, change assessment and implementation tickets.
- Source primaire
- Official sources listed below
Registre des sources primaires
14 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 1/08 of 27 March 2025 amending the AML/CFT lawCNRF Burundi · Primary legislation
- CNRF official portalCNRF Burundi · Official FIU portal
- Decree No. 100/009 of 9 February 2026 on the CNRFMinistry of Finance, Burundi · Primary executive instrument
- BRB Regulation No. 02/2026 on AML/CFTBanque de la Republique du Burundi · Primary regulator rule
- BRB announcement of the 2026 AML/CFT frameworkBanque de la Republique du Burundi · Official regulator guidance
- Law No. 1/03 of 10 March 2026 on personal-data protectionARCT Burundi · Primary legislation
- Official publication page for the 2026 personal-data lawARCT Burundi · Official legal publication
- Burundi National Risk Assessment 2026CNRF Burundi · Official national risk assessment
- Official company-creation procedureAgence de Developpement du Burundi · Official registry procedure
- Burundi Commercial Code 2015Agence de Developpement du Burundi · Primary commercial legislation
- Burundi mutual-evaluation statusFATF · Authoritative assessment index
- Burundi draft mutual-evaluation report review - July 2026CNRF Burundi · Official evaluation status
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Réponses directes
Questions KYC, KYB et AML pour Burundi
Who receives suspicious transaction reports in Burundi?+
The Cellule Nationale du Renseignement Financier (CNRF) receives STRs using its current prescribed format and route.
When is an STR due?+
Promptly and without delay once the entity suspects or has reasonable grounds to suspect the statutory criminal-proceeds or terrorist-financing connection.
What transaction-reporting threshold applies?+
The AML law delegates cash and other reporting thresholds to CNRF or another competent authority. Obtain the current instrument and do not infer a universal value from the statute.
What beneficial-ownership test applies?+
Identify the natural person who ultimately owns or controls the customer, or on whose behalf a transaction occurs. The reviewed primary law does not provide a universal ownership percentage.
Does Burundi have a national beneficial-owner register?+
The official 2026 national risk assessment reported that a national BO register was not yet in place. Continue independent ownership and control verification and monitor implementation.
How long are AML records kept?+
CDD and relationship records are kept for 10 years after the relationship ends; reconstructable transaction data are kept for 10 years after execution.
Do remote onboarding and biometrics need extra controls?+
Yes. Remote onboarding requires adapted reliable identification. Biometric identification is sensitive processing and requires a supported exception, safeguards, and potentially a DPIA and authorisation.
What privacy breach deadlines apply?+
Notify the personal-data protection body within 72 hours of awareness of a qualifying breach, and notify affected individuals within 96 hours where the breach may create a high risk.
Is Burundi on a FATF public list?+
No. Burundi was not named in FATF's June 2026 increased-monitoring or call-for-action statements. Its ESAAMLG mutual evaluation was still being finalised as at 27 July 2026.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 27 July 2026. Confirm current CNRF forms, access and threshold instruments; BRB circulars and licence conditions; sanctions directions; company and beneficial-ownership filing developments; personal-data agency implementation; and all sector overlays with the competent authority and qualified Burundian counsel before launch.