Cuba KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Cuba.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Cuba ?
La checklist pour Cuba traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 34 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- National FIU
- Dirección General de Investigación de Operaciones Financieras (DGIOF), within the Banco Central de Cuba
- Core preventive law
- Decree-Law 317 of 2013 and BCC Resolution 51 of 2013, supplemented by sector rules
- Suspicious reporting
- Report promptly to DGIOF when suspicion or reasonable grounds arise, regardless of amount
- CDD
- Identify every customer and verify identity data and documents; identify the beneficial owner
- Records
- Maintain identification and transaction records under the applicable BCC or sector rule; confirm the live sector retention period
- Company records
- The Central Commercial Registry and other competent registries evidence legal existence; access and beneficial-ownership availability require live confirmation
- Privacy
- Law 149 of 2022 on Personal Data Protection, effective 180 days after its 25 August 2022 publication
- Virtual assets
- BCC licensing and DGIOF AML supervision apply under Resolution 215/2021 and subsequent AML rules
- FATF status
- GAFILAT member; not identified on FATF's June 2026 high-risk or increased-monitoring statements; status reviewed 5 August 2026
Détail d’implémentation
Exigences et actions de conformité pour Cuba
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensingResolve the entity, activity and competent authority before applying a sector rule.3 éléments+
Entities and activities designated by Decree-Law 317 must apply preventive controls and report to DGIOF.
- Action d’implémentation
- Map each product and legal entity to Article 4 and the current sector instruction; obtain written perimeter confirmation for ambiguity.
- Preuves à conserver
- Perimeter memo, legal texts, regulator correspondence, licence inventory and launch approval.
- Source primaire
- Decree-Law 317/2013 arts. 4-5
Reserved banking, financial, payment or exchange activity requires the applicable BCC authorisation.
- Action d’implémentation
- Separate regulated functions and block launch until the responsible authority confirms every licence or registration.
- Preuves à conserver
- Product map, applications, authorisations, conditions and public-register checks.
- Source primaire
- Decree-Law 362/2018; current BCC licensing rules
Virtual-asset services within Resolution 215/2021 require a BCC licence and AML controls.
- Action d’implémentation
- Classify custody, exchange, transfer, financial and issuer-related services; verify the current licence and DGIOF registration route.
- Preuves à conserver
- Service taxonomy, BCC decision, DGIOF registration and control assessment.
- Source primaire
- BCC Resolution 215/2021; GAFILAT final Fourth-Round follow-up
02Governance and risk assessmentA documented risk-based programme must reflect the operator's actual sector and exposure.3 éléments+
Reporting entities must identify and evaluate vulnerabilities to ML/TF/PF and illicit capital movements.
- Action d’implémentation
- Assess customers, products, geography, channels and delivery methods; approve risk appetite and remediation.
- Preuves à conserver
- Risk methodology, assessment, data, approvals and remediation log.
- Source primaire
- Decree-Law 317/2013 arts. 5 and 19-20
Internal controls must support prevention, detection, reporting and competent-authority access.
- Action d’implémentation
- Assign accountable leadership and compliance roles, maintain procedures, training, testing and escalation.
- Preuves à conserver
- Governance charter, appointments, manual, training and assurance reports.
- Source primaire
- Decree-Law 317/2013 arts. 5 and 8; applicable sector rule
Material legal and risk changes require controlled updates.
- Action d’implémentation
- Monitor Gaceta Oficial, BCC, DGIOF, FATF and GAFILAT releases and test each parameter change before deployment.
- Preuves à conserver
- Source register, change log, approvals, testing and release record.
- Source primaire
- Implementation control supporting Decree-Law 317/2013
03Natural-person identificationCDD is based on reliable identity evidence, purpose, risk and ongoing consistency.3 éléments+
Reporting entities must always identify customers and verify the authenticity of submitted data and documents.
- Action d’implémentation
- Capture identity and contact data, authenticate reliable documents and bind them to the applicant before activation.
- Preuves à conserver
- Application, document images, validation results, timestamps and reviewer decision.
- Source primaire
- Decree-Law 317/2013 art. 12
CDD includes purpose, intended character and ongoing monitoring consistent with identified risk.
- Action d’implémentation
- Record expected activity, assign risk, refresh on change or doubt and investigate deviations.
- Preuves à conserver
- Purpose statement, profile, rating, refresh history and monitoring cases.
- Source primaire
- Decree-Law 317/2013 art. 9
A person acting for a customer must be identified and their authority verified.
- Action d’implémentation
- KYC the representative, validate the mandate, scope and expiry and link it to the customer.
- Preuves à conserver
- Representative KYC, power, verification and permission record.
- Source primaire
- Decree-Law 317/2013 arts. 9 and 12; applicable sector rule
04KYB and beneficial ownershipLegal existence, authority, ownership and control must be reconstructed from reliable evidence.3 éléments+
Legal-person customers require reliable formation, registration, address, activity and authority evidence.
- Action d’implémentation
- Obtain current registry evidence, constitutional documents, tax details, directors and powers and reconcile discrepancies.
- Preuves à conserver
- Registry extract, formation documents, tax record, governance list and reconciliation.
- Source primaire
- Decree-Law 317/2013 arts. 9 and 12; Commercial Registry rules
CDD must identify the beneficial owner and take reasonable steps to verify that person's identity.
- Action d’implémentation
- Trace natural-person ownership and control through every tier and document the sector-specific test used.
- Preuves à conserver
- Ownership chart, source records, declarations, control analysis and verification.
- Source primaire
- Decree-Law 317/2013 arts. 9 and 12
Registry evidence does not replace independent AML verification.
- Action d’implémentation
- Reconcile customer declarations with the Central Commercial Registry and other competent registers; escalate missing or conflicting data.
- Preuves à conserver
- Registry results, access log, discrepancy case and resolution.
- Source primaire
- Commercial Registry rules; Decree-Law 317/2013 arts. 9 and 12
05PEPs, enhanced diligence and remote onboardingHigher-risk relationships require stronger approval, source and monitoring controls under the applicable sector rule.3 éléments+
Customers and beneficial owners must be assessed for PEP status under the current sector rule.
- Action d’implémentation
- Screen at onboarding and periodically, cover family and close associates where required, and preserve the basis.
- Preuves à conserver
- Declaration, screening, public-source evidence and review history.
- Source primaire
- Applicable BCC or sector AML rule; FATF Recommendation 12 implementation assessed by GAFILAT
Higher-risk and PEP cases require enhanced measures proportionate to risk.
- Action d’implémentation
- Obtain senior approval, establish source of wealth and funds where required and intensify monitoring.
- Preuves à conserver
- Approval, source pack, risk rationale, monitoring plan and reviews.
- Source primaire
- Applicable sector rule; Decree-Law 317/2013 risk-based framework
Remote onboarding must meet the same identification standard and protect personal data.
- Action d’implémentation
- Authenticate document and person, manage impersonation risk, secure the flow and provide manual review.
- Preuves à conserver
- Flow design, vendor diligence, security tests, legal basis and review record.
- Source primaire
- Decree-Law 317/2013 art. 12; Law 149/2022
06Monitoring and suspicious reportingSuspicion is reported promptly and without an amount floor; live submission mechanics must be confirmed.4 éléments+
Reporting entities must monitor activity against customer knowledge, purpose and risk.
- Action d’implémentation
- Implement risk-based scenarios, reconcile complete data, investigate alerts and tune controls.
- Preuves à conserver
- Scenario inventory, data lineage, cases, tuning and validation.
- Source primaire
- Decree-Law 317/2013 arts. 9-10
A suspicious transaction or attempted activity must be reported promptly to DGIOF when suspicion or reasonable grounds arise.
- Action d’implémentation
- Document the grounds, preserve supporting material and submit through the current confidential DGIOF route.
- Preuves à conserver
- Case analysis, decision, report, attachments, timestamp and acknowledgement.
- Source primaire
- Decree-Law 317/2013 arts. 13-14
Suspicious reporting applies independently of transaction amount.
- Action d’implémentation
- Do not suppress or delay escalation because an amount is below a threshold; aggregate linked activity.
- Preuves à conserver
- Rule configuration, linked-case analysis, report decision and testing.
- Source primaire
- Decree-Law 317/2013 art. 14
Reporting and DGIOF information must remain confidential.
- Action d’implémentation
- Restrict access, avoid tipping off and separate customer communications from the reporting decision.
- Preuves à conserver
- Access list, confidentiality controls, training and incident log.
- Source primaire
- Decree-Law 317/2013; BCC Resolution 51/2013
07Payments, wires and threshold reportsDetailed payment fields and threshold reporting are sector-specific and must be confirmed from the live rule.3 éléments+
Specified cash or other operations above a BCC-set threshold may require registration and reporting.
- Action d’implémentation
- Obtain the current sector threshold, currency conversion, aggregation period, report type and filing calendar directly from BCC or DGIOF.
- Preuves à conserver
- Authoritative parameter sheet, configuration, tests, report and receipt.
- Source primaire
- Decree-Law 317/2013 art. 15; BCC Resolution 51/2013 art. 7
Wire transfers must carry and preserve required originator and beneficiary information.
- Action d’implémentation
- Validate required fields before release, reject or escalate incomplete messages and screen all parties.
- Preuves à conserver
- Message sample, validation, screening, exception and decision.
- Source primaire
- Applicable BCC transfer rule; GAFILAT technical-compliance assessment
Agents and outsourced providers do not remove the reporting entity's responsibility.
- Action d’implémentation
- Contract, train, monitor and test delegated onboarding, payment and reporting controls.
- Preuves à conserver
- Contract, agent register, training, testing and remediation.
- Source primaire
- Applicable BCC or sector rule
08Targeted financial sanctionsScreening and freezing must follow current UN and Cuban designation procedures without delay.3 éléments+
Reporting entities must identify designated persons and entities under applicable UN and national measures.
- Action d’implémentation
- Synchronise authoritative lists and screen customers, beneficial owners, transactions and counterparties.
- Preuves à conserver
- List source, version, screening logs, match analysis and disposition.
- Source primaire
- Decree-Law 317/2013 arts. 16-18; BCC Resolution 51/2013 arts. 9-12
Funds or assets connected to a confirmed designation must be frozen without delay under the competent procedure.
- Action d’implémentation
- Block access without warning, notify DGIOF and preserve the complete authority and action chronology.
- Preuves à conserver
- Match record, freeze timestamp, notification, acknowledgement and account controls.
- Source primaire
- Decree-Law 317/2013 arts. 16-18; BCC Resolution 51/2013 arts. 9-12
False-positive, release and exception handling must use the live authority route.
- Action d’implémentation
- Maintain escalation and unfreezing procedures and confirm any humanitarian or other exception before acting.
- Preuves à conserver
- Procedure, authority correspondence, approvals and audit trail.
- Source primaire
- Current DGIOF/BCC sanctions procedure; controlled uncertainty
09Records and authority accessRecords must reconstruct identity, transactions, monitoring and reporting decisions.3 éléments+
Reporting entities must preserve customer-identification and transaction records.
- Action d’implémentation
- Apply the live sector retention period from the correct trigger and preserve legal holds.
- Preuves à conserver
- Retention schedule, source rule, trigger logic, archive samples and deletion tests.
- Source primaire
- Decree-Law 317/2013 art. 9; applicable sector rule
Records must support prompt DGIOF and competent-authority requests.
- Action d’implémentation
- Verify authority, collect complete records securely and preserve production and acknowledgement evidence.
- Preuves à conserver
- Request, authority check, collection log, production and receipt.
- Source primaire
- Decree-Law 317/2013 arts. 6-8; BCC Resolution 51/2013
Every decision must be reconstructable from source to outcome.
- Action d’implémentation
- Preserve versions, timestamps, reviewers, evidence, screening, alerts, approvals and linked reports.
- Preuves à conserver
- Reconstruction test, source hashes, case export and remediation.
- Source primaire
- Implementation control supporting Decree-Law 317/2013
10Privacy, biometrics and transfersLaw 149 applies to personal-data processing, including KYC information and sensitive data.3 éléments+
Personal data must be processed under Law 149 principles and an applicable legal basis.
- Action d’implémentation
- Map each field to purpose, necessity and authority; provide required information and restrict incompatible reuse.
- Preuves à conserver
- Data inventory, legal-basis matrix, notice, purpose register and approvals.
- Source primaire
- Law 149/2022 arts. 1-7
Data subjects have statutory access, correction, updating and cancellation rights subject to lawful limits.
- Action d’implémentation
- Operate authenticated rights workflows and document any AML or legal restriction on disclosure or deletion.
- Preuves à conserver
- Request log, identity check, decision, response and exception rationale.
- Source primaire
- Law 149/2022
Sensitive, biometric and cross-border processing require documented safeguards and current-law analysis.
- Action d’implémentation
- Assess necessity and proportionality, secure templates and transfers, restrict vendors and obtain Cuban advice before launch.
- Preuves à conserver
- Impact assessment, security design, contracts, transfer map and counsel opinion.
- Source primaire
- Law 149/2022; implementing rules; controlled uncertainty
11Practical evidence packsOperational evidence should show what was known, why a rule applied and when action occurred.3 éléments+
Onboarding decisions should be reproducible.
- Action d’implémentation
- Bundle identity, KYB, ownership, authority, screening, purpose, risk, approvals and exceptions.
- Preuves à conserver
- Timestamped onboarding pack with sources, hashes, reviewer and decision.
- Source primaire
- Implementation control supporting Decree-Law 317/2013 arts. 9 and 12
Monitoring and reporting decisions should preserve the complete chronology.
- Action d’implémentation
- Capture rule version, inputs, analysis, requests, suspicion decision, submission and receipt.
- Preuves à conserver
- Alert case, linked activity, notes, report and quality review.
- Source primaire
- Implementation control supporting Decree-Law 317/2013 arts. 13-15
Launch approval must resolve licensing, AML, sanctions, registry, privacy and reporting readiness together.
- Action d’implémentation
- Use a cross-functional go-live gate and block unresolved perimeter, source, portal or evidence defects.
- Preuves à conserver
- Signed checklist, legal opinions, authorisations, tests and residual-risk acceptance.
- Source primaire
- Implementation control; Decree-Law 317/2013; Law 149/2022
Registre des sources primaires
9 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Decree-Law 317 of 2013 - AML/CFT/CPF preventive frameworkGaceta Oficial de la República de Cuba (FAOLEX official-text mirror) · Primary legislation
- BCC Resolution 51 of 2013 - DGIOF functions and reportingGaceta Oficial de la República de Cuba (FAOLEX official-text mirror) · Primary regulation
- Law 149 of 2022 on Personal Data ProtectionWIPO Lex · Primary legislation repository
- Banco Central de CubaBanco Central de Cuba · Official regulator portal
- Cuba mutual evaluationGAFILAT · Authoritative regional assessment
- Final Fourth-Round follow-up report for CubaGAFILAT · Authoritative regional assessment
- Cuba Fifth-Round preparationGAFILAT · Authoritative current-status update
- FATF high-risk jurisdictions subject to a call for actionFinancial Action Task Force · Authoritative current status
- FATF jurisdictions under increased monitoringFinancial Action Task Force · Authoritative current status
Réponses directes
Questions KYC, KYB et AML pour Cuba
Who receives suspicious transaction reports in Cuba?+
The Dirección General de Investigación de Operaciones Financieras (DGIOF), Cuba's FIU within the Banco Central de Cuba.
When must suspicion be reported?+
Decree-Law 317 requires prompt reporting when suspicion or reasonable grounds arise, regardless of amount. Confirm the exact current electronic route and any sector workflow with DGIOF.
Is there one universal threshold report?+
This checklist does not state a universal amount. Decree-Law 317 permits BCC-set threshold reporting, so the current amount, currency conversion, aggregation and report type must be confirmed for the sector.
Who is the beneficial owner?+
CDD must identify the natural person who ultimately owns or controls the customer. Apply the detailed test in the current sector rule and document ownership and control through every tier.
Is registry information publicly accessible?+
Cuba maintains commercial and other legal-person registers, but live access, data fields and beneficial-ownership availability are controlled uncertainties. Obtain current official evidence and do not treat a registry extract as a substitute for AML verification.
How long must AML records be retained?+
Decree-Law 317 requires record custody, while detailed periods and trigger dates are set by applicable sector rules. Confirm the current rule before configuring deletion.
Do virtual-asset services require a licence?+
Specified virtual-asset services fall within the BCC licensing framework under Resolution 215/2021 and subsequent rules. Confirm the current scope, AML registration and conditions before launch.
What happens on a sanctions-list match?+
Follow the current DGIOF/BCC procedure to freeze without delay, report confidentially and preserve the authority and action chronology. Do not notify the customer.
What privacy law applies to KYC and biometrics?+
Law 149 of 2022 governs personal-data processing. Sensitive, biometric, vendor and cross-border designs require a documented legal-basis and safeguards assessment under current implementing rules.
Is Cuba on a FATF public list?+
As reviewed on 5 August 2026, Cuba was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck the live FATF statements before reliance.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice, a licensing decision or a substitute for the operative Spanish texts and current sector instructions. Reviewed 5 August 2026. Cuba's framework is sector-specific and official online access can be inconsistent. Confirm the reporting channel, sector thresholds, retention periods, registry access, sanctions procedure, licence perimeter and any post-review amendments directly with DGIOF, BCC, the competent registry and qualified Cuban counsel before launch.