Cap-Vert KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Cap-Vert.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour Cap-Vert ?
La checklist pour Cap-Vert traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 46 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML law
- Law No. 38/VII/2009, republished by Law No. 120/VIII/2016
- Financial intelligence unit
- Unidade de Informação Financeira (UIF)
- STR timing
- Immediately on knowledge, suspicion or sufficient grounds
- Cash threshold reports
- CVE 1,000,000 for listed cash operations, including linked operations
- General occasional CDD
- CVE 1,000,000, including apparently linked transactions
- Core AML retention
- At least 7 years under transaction- and relationship-specific clocks
- Beneficial ownership
- Identify the natural person who ultimately owns or controls, or on whose behalf activity occurs
- Financial supervisor
- Banco de Cabo Verde (BCV) for BCV-supervised financial entities
- Privacy authority
- Comissão Nacional de Proteção de Dados (CNPD)
- Data-breach notice
- Notify CNPD within 72 hours unless the breach is unlikely to create risk
- FATF public lists
- Not named in the 19 June 2026 public statements
Détail d’implémentation
Exigences et actions de conformité pour Cap-Vert
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and regulated activitiesResolve the entity, activity, supervisor and reporting perimeter before onboarding or launch.4 éléments+
The AML law applies to listed financial institutions and designated non-financial businesses and professions headquartered in Cabo Verde, including their branches, subsidiaries and other representations at home or abroad.
- Action d’implémentation
- Map each entity, product, branch, agent, distributor and outsourced function to the statutory list and document the competent supervisor.
- Preuves à conserver
- Perimeter memorandum, entity-product map, licences and supervisor correspondence.
- Source primaire
- Law No. 120/VIII/2016, arts. 4, 5 and 7
UIF is the national centre for receiving, requesting, analysing and disseminating information arising from suspicious-transaction reports.
- Action d’implémentation
- Appoint an authorised reporting contact and obtain the current UIF form, channel, access and acknowledgement instructions before production reporting.
- Preuves à conserver
- Appointment, access record, reporting procedure, test and acknowledgements.
- Source primaire
- Decree-Law No. 9/2012; Law No. 120/VIII/2016, arts. 5-6 and 34
BCV regulates and supervises financial institutions for compliance with the AML law and its sector notices.
- Action d’implémentation
- Classify every financial service and obtain the required BCV authorisation and registration before launch.
- Preuves à conserver
- Classification, authorisation, registration, conditions and service map.
- Source primaire
- Law No. 120/VIII/2016, arts. 5-7; Financial System Framework Law and LAIF
Professional virtual-asset activity in Cabo Verde requires prior registration with BCV and remains subject to AML/CFT obligations.
- Action d’implémentation
- Do not provide exchange, transfer, custody, administration or related virtual-asset services until the BCV registration and any other required approval are effective.
- Preuves à conserver
- Service analysis, application, BCV registration, conditions and control implementation.
- Source primaire
- Law No. 30/X/2023, arts. 2-3; BCV Notice No. 2/2024
02Governance, risk assessment and control ownershipBuild documented, risk-based controls with accountable governance.4 éléments+
Reporting entities must identify, assess, understand, document and keep current their customer, geographic, product, transaction and delivery-channel ML risks.
- Action d’implémentation
- Approve a methodology, assess risks before launch and on material change, and make the assessment available to the competent authorities.
- Preuves à conserver
- Risk assessment, methodology, source data, change log and approvals.
- Source primaire
- Law No. 120/VIII/2016, art. 10(4)-(6)
Written policies, procedures and controls must be approved by senior management and proportionate to the entity's nature, size and activity.
- Action d’implémentation
- Maintain a control framework covering CDD, BO, PEPs, sanctions, monitoring, reporting, records, training and group controls.
- Preuves à conserver
- Policy suite, control library, approvals, testing and remediation.
- Source primaire
- Law No. 120/VIII/2016, arts. 10 and 28
Reporting entities must designate a management-level compliance owner and maintain independent internal control and audit arrangements.
- Action d’implémentation
- Approve the mandate, authority, resources, access, escalation rights and independent assurance plan.
- Preuves à conserver
- Appointment, mandate, board reporting, audit plan and reports.
- Source primaire
- Law No. 120/VIII/2016, art. 28
Employees and managers require continuous, role-appropriate AML training, and training records are retained for five years.
- Action d’implémentation
- Deliver induction and periodic training, test understanding and retain attendance, content and results for the statutory period.
- Preuves à conserver
- Training plan, materials, attendance, test results and five-year archive.
- Source primaire
- Law No. 120/VIII/2016, art. 29
03Natural-person identification and CDDIdentify and verify customers, representatives and ultimate actors using valid independent evidence.5 éléments+
Customers and beneficial owners must be identified and verified when opening an account or establishing a business relationship.
- Action d’implémentation
- Capture the statutory natural-person attributes and verify them against a valid official document bearing photograph and signature.
- Preuves à conserver
- CDD file, document provenance, verification result, purpose and risk decision.
- Source primaire
- Law No. 120/VIII/2016, arts. 12 and 14
CDD also applies to occasional transactions and domestic or international transfers at or above CVE 1,000,000, including apparently linked transactions.
- Action d’implémentation
- Aggregate linked activity across channels and block completion until identification and verification are complete.
- Preuves à conserver
- Aggregation logic, threshold tests, CDD file and release decision.
- Source primaire
- Law No. 120/VIII/2016, arts. 12(2) and 15(2)
Suspicion or doubt about previously obtained identification triggers CDD regardless of amount or exemption.
- Action d’implémentation
- Refresh and independently verify the customer, representative and beneficial owner without applying a monetary floor.
- Preuves à conserver
- Trigger record, refreshed evidence, investigation and decision.
- Source primaire
- Law No. 120/VIII/2016, arts. 12(2)(d)-(e) and 15(2)
Anonymous, numbered, coded, fictitious-name and otherwise unidentified relationships are prohibited.
- Action d’implémentation
- Block activation and transaction capability until the required actors are identified and verified.
- Preuves à conserver
- Account controls, test results and rejected-case log.
- Source primaire
- Law No. 120/VIII/2016, art. 12(3)
Representatives must be identified and their authority to act verified.
- Action d’implémentation
- Verify the representative's identity, mandate, scope, validity and relationship to the customer before accepting instructions.
- Preuves à conserver
- Identity file, mandate, authority check and expiry monitoring.
- Source primaire
- Law No. 120/VIII/2016, arts. 12(7), 14 and 15
04KYB, authority and beneficial ownershipVerify legal existence, representatives, ownership and ultimate natural-person control.4 éléments+
Legal-person identification includes name, nature and legal form, registered office, managers or directors and persons empowered to bind the entity.
- Action d’implémentation
- Obtain a current commercial-registry certificate, constitutive documents, tax identifier, governing body and authority evidence; reconcile inconsistencies.
- Preuves à conserver
- Registry certificate, statutes, NIF, officer list, mandates and discrepancy log.
- Source primaire
- Law No. 120/VIII/2016, art. 14(3)-(4); Commercial Registration Code
Reporting entities must understand the customer's ownership and control structure and determine the natural person who ultimately owns or controls it.
- Action d’implémentation
- Trace every ownership and control layer to natural persons and document the statutory conclusion without substituting an unsupported universal percentage.
- Preuves à conserver
- Ownership chart, control analysis, source records and verified BO files.
- Source primaire
- Law No. 120/VIII/2016, arts. 2, 12 and 15
Where the customer may be acting for another person, the entity must identify the person or entity on whose behalf the customer acts, including beneficial owners.
- Action d’implémentation
- Investigate nominee, agency and third-party funding indicators and verify the ultimate actor before proceeding.
- Preuves à conserver
- Agency analysis, declarations, source evidence and escalation record.
- Source primaire
- Law No. 120/VIII/2016, art. 12(6)
Commercial-register information must be kept updated, but the reviewed authoritative material does not establish a comprehensive public national BO register with a universal filing percentage.
- Action d’implémentation
- Verify basic registry information and independently establish ownership and control; confirm current BO filing rules with DGRNI and counsel.
- Preuves à conserver
- Registry extracts, customer ownership evidence, independent corroboration and update log.
- Source primaire
- Commercial Registration Code, art. 13; GIABA 2019 MER, Recommendation 24; controlled uncertainty
05PEPs, enhanced due diligence and relianceApply stronger approval, evidence and monitoring where risk is higher.5 éléments+
The PEP framework covers domestic and foreign PEPs, relevant international-organisation functions, family members and recognised close associates.
- Action d’implémentation
- Screen customers, beneficial owners, controllers and representatives at onboarding, list updates and periodic review.
- Preuves à conserver
- Screening, match rationale, relationship mapping and review record.
- Source primaire
- Law No. 120/VIII/2016, art. 2 definitions and art. 24
PEP relationships require risk-based identification, senior-management approval, source-of-wealth and source-of-funds measures and enhanced continuous monitoring.
- Action d’implémentation
- Obtain supported source evidence and senior approval before establishing or continuing the relationship.
- Preuves à conserver
- Source file, approval, monitoring plan and alert reviews.
- Source primaire
- Law No. 120/VIII/2016, art. 24
Former PEP controls continue while the person's profile or activity presents increased ML risk; the law does not set a fixed exit period.
- Action d’implémentation
- Document a risk-based decision before reducing controls and continue enhanced treatment while residual risk remains.
- Preuves à conserver
- Former-PEP assessment, approval and periodic review.
- Source primaire
- Law No. 120/VIII/2016, art. 24(2)
Remote and anonymity-favouring activity requires enhanced measures and may be supplemented with additional documents or information.
- Action d’implémentation
- Authenticate evidence, apply independent checks and escalate higher-risk remote cases without assuming one technology is legally sufficient.
- Preuves à conserver
- Remote-onboarding standard, vendor review, tests and exceptions.
- Source primaire
- Law No. 120/VIII/2016, arts. 10(5) and 22(3)-(4)
Reliance on a third party does not transfer the reporting entity's responsibility.
- Action d’implémentation
- Confirm equivalent obligations and supervision, obtain identity material immediately on request, contract for access and test retrieval.
- Preuves à conserver
- Third-party due diligence, agreement, retrieval test and exceptions.
- Source primaire
- Law No. 120/VIII/2016, art. 20
06Failed CDD, monitoring and suspicious reportingStop unsafe activity, monitor continuously and report suspicion immediately and confidentially.5 éléments+
If required ownership, control, purpose, identity or source/destination information cannot be obtained, the relationship or operation must be refused or ended and an STR considered.
- Action d’implémentation
- Operate a controlled block or exit and preserve the confidential STR decision.
- Preuves à conserver
- Failure reason, block, closure, analysis, STR and acknowledgement.
- Source primaire
- Law No. 120/VIII/2016, arts. 15(3), 21 and 22(7)
Unusual, complex, high-volume, atypical or apparently purposeless activity requires careful examination and a written record.
- Action d’implémentation
- Investigate the nature, purpose, frequency, actors, amount, source, destination and payment method and retain the analysis.
- Preuves à conserver
- Alerts, cases, supporting evidence, written examination and approval.
- Source primaire
- Law No. 120/VIII/2016, arts. 22 and 26
An STR is sent to UIF immediately when the entity knows, suspects or has sufficient grounds to suspect completed, ongoing or attempted laundering activity.
- Action d’implémentation
- Timestamp the trigger and submit through the current UIF route without waiting for proof or a completed transaction.
- Preuves à conserver
- Internal report, analysis, STR, UIF receipt and timeline.
- Source primaire
- Law No. 120/VIII/2016, art. 34(1)
The entity must abstain from executing suspected activity and notify UIF, subject to the statutory exception where suspension is impossible or could prejudice prevention or investigation.
- Action d’implémentation
- Govern holds, urgent consultation, lawful post-execution reporting and restricted communications.
- Preuves à conserver
- Hold decision, exception rationale, UIF contact, receipt and access log.
- Source primaire
- Law No. 120/VIII/2016, art. 32
The existence of an STR, UIF request or investigation must not be disclosed to the customer or an unauthorised third party.
- Action d’implémentation
- Restrict access, use neutral customer communications and log every disclosure and escalation.
- Preuves à conserver
- Tipping-off policy, access controls, communications and testing.
- Source primaire
- Law No. 120/VIII/2016, art. 33
07Wires, thresholds, payments and agentsKeep CDD triggers, cash reports, wire information and product licensing distinct.5 éléments+
Listed cash operations at or above CVE 1,000,000 must be reported to UIF regardless of suspicion, including apparently linked operations and subject to the statutory activity-based exception.
- Action d’implémentation
- Configure aggregation by customer and connected activity, apply the exact covered categories and retain report receipts and exception rationale.
- Preuves à conserver
- Configuration, tests, reports, receipts and exception record.
- Source primaire
- Law No. 120/VIII/2016, art. 34(2)-(4)
Cross-border physical carriage of currency, bearer instruments or electronic money at or above CVE 1,000,000 requires a written customs declaration.
- Action d’implémentation
- Do not treat the border declaration as an ordinary customer-reporting threshold; give travellers current customs instructions where relevant.
- Preuves à conserver
- Procedure, declaration guidance and escalation record.
- Source primaire
- Law No. 120/VIII/2016, art. 11
Domestic wire transfers require specified originator and beneficiary names, account or unique reference data and alternative originator identity information.
- Action d’implémentation
- Validate mandatory fields before release and preserve the complete payment-chain record.
- Preuves à conserver
- Field matrix, validation, repair queue, samples and decisions.
- Source primaire
- Law No. 120/VIII/2016, art. 27(1)-(2)
Cross-border transfers at or above CVE 1,000,000 must carry the required originator information throughout the payment chain; deficient transfers require risk-based execute, reject or suspend decisions.
- Action d’implémentation
- Implement field validation, repair, reject, suspend, beneficiary verification and follow-up rules.
- Preuves à conserver
- Payment messages, repair requests, decisions, monitoring and tests.
- Source primaire
- Law No. 120/VIII/2016, art. 27(3)-(11)
Money or value transfer providers must maintain an up-to-date agent list and include agents within their AML programme and monitoring.
- Action d’implémentation
- Maintain the regulator-ready agent register, due diligence, training, control testing and termination process.
- Preuves à conserver
- Agent register, contracts, training, monitoring and remediation.
- Source primaire
- Law No. 120/VIII/2016, art. 18
08Targeted financial sanctions and proliferation riskScreen, freeze, restrict and report under the current UN and domestic implementation framework.3 éléments+
Relevant UN Security Council resolutions take effect in Cabo Verde's legal order, and terrorist-fund freezes require immediate implementation.
- Action d’implémentation
- Maintain current UN lists, screen customers and transactions, prevent dealing and escalate true matches immediately.
- Preuves à conserver
- List inventory, update logs, screening, match decision and freeze record.
- Source primaire
- Constitution of Cabo Verde, art. 12(3); Law No. 119/VIII/2016; BCV/AGMVM AML/CFT portal
Terrorist-financing and proliferation-financing targeted-sanctions implementation has documented technical-compliance gaps in GIABA assessments.
- Action d’implémentation
- Obtain current BCV, UIF, prosecutor or other competent-authority instructions for the specific designation and do not invent a notification deadline or release route.
- Preuves à conserver
- Legal update, authority correspondence, notification, direction and release decision.
- Source primaire
- GIABA 2019 MER and 2021 FUR, Recommendations 6-7; controlled procedure uncertainty
Virtual-asset service providers are subject to the communications, reporting and monitoring framework applicable to terrorist- and proliferation-related targeted sanctions.
- Action d’implémentation
- Integrate UN-list screening, asset controls and authority escalation into the registered VASP control framework.
- Preuves à conserver
- VASP policy, screening configuration, tests, escalation and reports.
- Source primaire
- Law No. 30/X/2023, art. 3; GIABA sixth enhanced FUR 2025, Recommendation 15
09Records, access and assuranceRetain reconstructable records under the correct statutory clock.4 éléments+
Identity, beneficial-owner and transaction records and required written reports are retained for at least seven years after the transaction or end of the relationship, as applicable.
- Action d’implémentation
- Map every record class to its transaction- or relationship-based clock and apply legal holds.
- Preuves à conserver
- Retention schedule, configuration, samples and deletion tests.
- Source primaire
- Law No. 120/VIII/2016, art. 25(1)
Financial institutions retain account-opening forms and related correspondence for at least seven years after account closure or the end of the relationship.
- Action d’implémentation
- Link account records to the relationship closure event and test complete retrieval.
- Preuves à conserver
- Archive configuration, closure trigger, sample and retrieval log.
- Source primaire
- Law No. 120/VIII/2016, art. 25(2)
Required records must be supplied to UIF and competent authorities on request.
- Action d’implémentation
- Index linked identity, transaction, investigation and reporting evidence and test controlled export.
- Preuves à conserver
- Request register, retrieval tests, access logs and response package.
- Source primaire
- Law No. 120/VIII/2016, arts. 25(3) and 31
Wire originator and beneficiary information is retained under the general seven-year rule.
- Action d’implémentation
- Preserve complete payment messages, repairs, screening and disposition evidence for reconstructability.
- Preuves à conserver
- Wire archive, reconstruction test and exception records.
- Source primaire
- Law No. 120/VIII/2016, arts. 25 and 27(11)
10Privacy, biometrics, breaches and transfersApply the amended personal-data framework alongside mandatory AML processing.5 éléments+
Personal-data processing must respect privacy and data-protection rights and have a lawful basis, specified purpose, proportionate scope, accuracy, security and retention controls.
- Action d’implémentation
- Inventory KYC, BO, screening, monitoring and reporting data and document purpose, basis, recipients, access and retention.
- Preuves à conserver
- Processing register, basis assessment, notices, access matrix and retention map.
- Source primaire
- Law No. 133/V/2001 as amended by Law No. 121/IX/2021, arts. 4, 6 and 7
Biometric data are special-category data and processing is prohibited unless a statutory exception or CNPD authorisation applies.
- Action d’implémentation
- Before facial, fingerprint, liveness-template or comparable biometric use, document the exact exception, necessity, safeguards and notification or authorisation requirements.
- Preuves à conserver
- Legal assessment, consent where applicable, CNPD filing, encryption and access tests.
- Source primaire
- Amended personal-data law, arts. 5 and 8
High-risk processing requires a DPIA before processing and before notification to CNPD, including large-scale special-data processing and qualifying automated profiling.
- Action d’implémentation
- Complete the DPIA, obtain DPO advice where appointed, communicate the result with the required CNPD notification and track remediation.
- Preuves à conserver
- DPIA, DPO opinion, CNPD submission and remediation.
- Source primaire
- Amended personal-data law, art. 29
A personal-data breach must be notified to CNPD within 72 hours after awareness unless it is unlikely to create risk; a high-risk breach is communicated to affected people without unjustified delay.
- Action d’implémentation
- Run a documented breach-triage clock, preserve the risk analysis and issue required notices with consequences and mitigation.
- Preuves à conserver
- Incident log, awareness time, risk assessment, notices, receipts and remediation.
- Source primaire
- Amended personal-data law, arts. 27-28
Foreign transfers require an adequate protection level determined by CNPD or a statutory derogation or CNPD-authorised safeguards.
- Action d’implémentation
- Map hosting, support and vendor destinations and document the adequacy, derogation or authorised contractual safeguards before transfer.
- Preuves à conserver
- Transfer map, adequacy decision, derogation analysis, safeguards and CNPD authorisation.
- Source primaire
- Amended personal-data law, arts. 35-36
11Practical evidence packs and change controlMake every acceptance, escalation and regulatory decision reconstructable.2 éléments+
A complete customer file links identity, KYB, BO, screening, risk, approval, monitoring and reporting decisions.
- Action d’implémentation
- Block activation where mandatory evidence or approval is missing and preserve the release decision.
- Preuves à conserver
- Control checklist, linked file, approvals and release log.
- Source primaire
- Law No. 120/VIII/2016, arts. 8-34
Thresholds, UIF routes, sanctions directions, registers, licences and privacy procedures are time-sensitive.
- Action d’implémentation
- Assign owners to monitor UIF, BCV, DGRNI, CNPD, the Official Gazette, FATF and GIABA on a documented schedule.
- Preuves à conserver
- Legal inventory, source log, change assessment and implementation tickets.
- Source primaire
- Official sources listed below
Registre des sources primaires
15 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 120/VIII/2016 republishing the amended AML lawBanco de Cabo Verde · Primary legislation
- BCV anti-money-laundering framework and supervisory roleBanco de Cabo Verde · Official regulator guidance
- UIF official role and mandateMinistry of Justice, Cabo Verde · Official FIU guidance
- BCV Notice No. 5/2017 AML/CFT preventive controlsBanco de Cabo Verde · Primary regulator rule
- Law No. 119/VIII/2016 on terrorism and terrorist financingOfficial Gazette of Cabo Verde · Primary legislation
- UN sanctions and AML/CFT resourcesBanco de Cabo Verde / AGMVM · Official regulator guidance
- Law No. 30/X/2023 on virtual assets and digital banksBanco de Cabo Verde · Primary legislation
- BCV announcement of Notice No. 2/2024 for VASP registrationBanco de Cabo Verde · Official regulator guidance
- Company and registry services portalMinistry of Justice, Cabo Verde · Official registry portal
- Law No. 121/IX/2021 amending the personal-data regimeComissão Nacional de Proteção de Dados · Primary legislation
- CNPD legislation indexComissão Nacional de Proteção de Dados · Official authority index
- Cabo Verde sixth enhanced follow-up report - May 2025FATF / GIABA · Authoritative follow-up assessment
- Cabo Verde mutual evaluation report - 2019FATF / GIABA · Authoritative mutual evaluation
- Jurisdictions under Increased Monitoring - 19 June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - 19 June 2026FATF · Authoritative public statement
Réponses directes
Questions KYC, KYB et AML pour Cap-Vert
Who receives suspicious transaction reports in Cabo Verde?+
The Unidade de Informação Financeira (UIF) receives reports through its current prescribed channel.
When is an STR due?+
Immediately when the reporting entity knows, suspects or has sufficient grounds to suspect that completed, ongoing or attempted activity may constitute money laundering.
What cash-reporting threshold applies?+
Listed cash operations at or above CVE 1,000,000, including apparently linked operations, are reported to UIF regardless of suspicion, subject to the exact statutory categories and exception.
When does general occasional-transaction CDD apply?+
At or above CVE 1,000,000 for one or apparently linked occasional transactions, and regardless of amount when suspicion or identification doubt exists.
What beneficial-ownership test applies?+
Identify the natural person who ultimately owns or controls the customer, or on whose behalf a transaction occurs. The reviewed primary AML law does not set a universal ownership percentage.
How long are AML records kept?+
Core identity, beneficial-owner, transaction and written-analysis records are kept for at least seven years under the applicable transaction or relationship clock.
Must virtual-asset service providers register?+
Yes. Professional virtual-asset activity in Cabo Verde requires prior BCV registration under Law No. 30/X/2023 and Notice No. 2/2024 and remains subject to AML/CFT duties.
What privacy breach deadline applies?+
Notify CNPD within 72 hours after awareness unless the breach is unlikely to create risk; communicate a high-risk breach to affected people without unjustified delay.
Is Cabo Verde on a FATF public list?+
No. Cabo Verde was not named in FATF's 19 June 2026 increased-monitoring or call-for-action statements, though GIABA kept it in enhanced follow-up in May 2025.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative materials reviewed on 28 July 2026. Confirm the live UIF filing route and forms, BCV and sector instructions, targeted-financial-sanctions workflow, company and beneficial-ownership filing requirements, data-protection notifications, product licences and all later legal changes with the competent authority and qualified Cabo Verdean counsel before launch.