Guatemala KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Guatemala.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour Guatemala ?
La checklist pour Guatemala traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 36 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- National FIU
- Intendencia de Verificación Especial (IVE), within the Superintendencia de Bancos
- Current rules
- Decrees 67-2001 and 58-2005 remain applicable through 16 September 2026
- Enacted transition
- Decree 15-2026 enters into force on 17 September 2026
- Suspicion reporting
- Report suspicious transactions to IVE immediately after the compliance-officer determination
- Cash record threshold
- Current rule: above USD 10,000; Decree 15-2026: USD 10,000 or more from 17 September 2026
- Retention
- At least 5 years after transaction completion or relationship termination, according to record type
- Company registry
- Registro Mercantil General, Ministry of Economy
- Privacy position
- No enacted comprehensive private-sector data-protection law identified; constitutional and sector rules still apply
- FATF status
- GAFILAT member; absent from FATF June 2026 public lists as reviewed 7 August 2026
Détail d’implémentation
Exigences et actions de conformité pour Guatemala
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingMap every entity and service to the statutory obliged-person categories and its sector licence before launch.4 éléments+
Determine obliged-person status for the current and incoming regimes.
- Action d’implémentation
- Map each entity, product and channel to the current Decree 67-2001/58-2005 perimeter and separately to Decree 15-2026 articles 3-5; preserve effective-dated counsel support.
- Preuves à conserver
- Two-period perimeter memorandum, product map, entity chart and legal sign-off.
- Source primaire
- Decree 67-2001 art. 18; Agreement 118-2002 art. 5; Decree 58-2005 art. 15; Decree 15-2026 arts. 3-5
Register with IVE and identify the competent supervisor where required.
- Action d’implémentation
- Complete current IVE registration and appoint the required contact before regulated operations; separately identify SIB, Junta Monetaria or other sector oversight.
- Preuves à conserver
- Registration receipt, supervisor map, correspondence and renewal calendar.
- Source primaire
- Decree 67-2001 arts. 18, 32-33; Agreement 118-2002 arts. 5, 36
Complete product-specific licensing analysis.
- Action d’implémentation
- Test banking, finance, insurance, securities, money transmission, payments, remittance and virtual-asset activities against current sector law and IVE instructions; do not infer authorisation from AML registration.
- Preuves à conserver
- Licence memorandum, approvals, legal opinions and launch conditions.
- Source primaire
- Financial-sector laws and current SIB/Junta Monetaria/IVE instruments; controlled uncertainty
Implement the enacted 17 September 2026 transition.
- Action d’implémentation
- Maintain an effective-dated change plan for Decree 15-2026, including expanded scope, risk assessment/manual, compliance function, 15% beneficial-owner test, prompt RTS, cash records at USD 10,000 or more and updated instructions; do not apply repeals before commencement.
- Preuves à conserver
- Transition plan, gap assessment, board approval, rule releases, training and launch evidence.
- Source primaire
- Decree 15-2026 arts. 2-5, 8-18, 21-34 and commencement provision
02Governance and risk assessmentThe compliance programme must reflect the institution's actual customers, products, channels and locations.3 éléments+
Maintain a documented AML/CFT risk assessment and control programme.
- Action d’implémentation
- Assess customer, product, service, channel and geographic risk; assign proportionate controls and obtain governing-body approval.
- Preuves à conserver
- Risk assessment, methodology, risk appetite, control matrix and minutes.
- Source primaire
- Decree 67-2001 arts. 19-20; Agreement 118-2002 arts. 9-11; Decree 58-2005 art. 15
Appoint an eligible compliance officer and provide independence and resources.
- Action d’implémentation
- Obtain the approvals required for the relevant obliged-person class, notify IVE, define direct escalation and appoint cover.
- Preuves à conserver
- Appointment, eligibility file, IVE notice, mandate, budget and reporting records.
- Source primaire
- Decree 67-2001 art. 19; Agreement 118-2002 arts. 21-22, 36
Train personnel and independently test the programme.
- Action d’implémentation
- Deliver role-based onboarding and recurring training and arrange periodic independent review with tracked remediation.
- Preuves à conserver
- Curriculum, attendance, assessments, review reports and closure evidence.
- Source primaire
- Decree 67-2001 art. 19; Agreement 118-2002 arts. 10-11
03Natural-person identificationCustomer records must identify the person, purpose and expected activity and remain current.3 éléments+
Identify and reasonably verify customers and representatives.
- Action d’implémentation
- Collect official identity, address, occupation or activity, purpose and expected activity; validate representatives and their authority before activation.
- Preuves à conserver
- Identity copy, validation results, address evidence, authority record and onboarding decision.
- Source primaire
- Decree 67-2001 arts. 21-22; Agreement 118-2002 arts. 12-14; current IVE FEIC instructions
Keep customer information current.
- Action d’implémentation
- Refresh information according to risk and current IVE instructions, investigate material changes and retain the prior version.
- Preuves à conserver
- Refresh schedule, changed-field log, corroboration and approval.
- Source primaire
- Decree 67-2001 arts. 21-23; Agreement 118-2002 arts. 13-14
Reject anonymous or fictitious relationships and control failed CDD.
- Action d’implémentation
- Block activation where identity or authority cannot be established; document whether attempted or suspicious conduct requires an IVE report.
- Preuves à conserver
- System configuration, rejection file, escalation and reporting decision.
- Source primaire
- Decree 67-2001 arts. 20-22; Agreement 118-2002 arts. 12-16
04KYB, registries, and beneficial ownershipRegistry documents are a starting point and do not replace natural-person ownership and control analysis.3 éléments+
Verify legal existence, activity and representation.
- Action d’implémentation
- Obtain current Registro Mercantil certifications, constitutive documents, tax identifier, address and appointment/power evidence and independently verify material facts.
- Preuves à conserver
- Registry extract, deeds, tax record, address check and authority map.
- Source primaire
- Commercial Code art. 334; Decree 67-2001 arts. 21-23; Registro Mercantil official services
Identify and verify the natural persons who ultimately own or control the customer.
- Action d’implémentation
- Under current law apply the controlling IVE instruction for the sector. From 17 September 2026, implement Decree 15-2026's natural-person ownership/control test, including the 15% threshold and control/benefit routes, against the exact final text and regulations.
- Preuves à conserver
- Effective-dated ownership chart, cap table, shareholder documents, control analysis and identity files.
- Source primaire
- Current IVE instructions; Decree 15-2026 art. 2(b), arts. 21-27
Do not treat the commercial registry as a comprehensive public BO register.
- Action d’implémentation
- Use registry evidence together with customer declarations and independent corroboration; confirm current BO filing fields and competent-authority access with IVE and Registro Mercantil.
- Preuves à conserver
- Registry search, declarations, corroboration and uncertainty log.
- Source primaire
- Registro Mercantil official scope; controlled uncertainty
05PEPs, enhanced diligence, and remote onboardingHigher-risk relationships require additional information, approval and monitoring.3 éléments+
Identify PEPs, family members and close associates under current IVE rules.
- Action d’implémentation
- Screen customers, beneficial owners and representatives at onboarding and refresh; document position, relationship, risk and the applicable post-office period.
- Preuves à conserver
- Screening record, position source, relationship map and review schedule.
- Source primaire
- Current IVE PEP and FEIC instructions; Agreement 118-2002 arts. 12-15
Apply enhanced diligence proportionate to risk.
- Action d’implémentation
- Obtain senior approval and corroborate source of funds and, where risk requires, source of wealth; increase review and monitoring frequency.
- Preuves à conserver
- Source dossier, approval, risk rationale and monitoring plan.
- Source primaire
- Decree 67-2001 arts. 19-22; current IVE instructions
Make remote onboarding equivalent and auditable.
- Action d’implémentation
- Validate authoritative documents, person presence or equivalent fraud controls, device/channel signals and sanctions/PEP results; route exceptions to manual review.
- Preuves à conserver
- Vendor tests, session evidence, fraud results and exception approvals.
- Source primaire
- Current IVE FEIC instructions; risk-based implementation control
06Monitoring and suspicious reportingUnusual activity must be examined and suspicious activity reported confidentially to IVE.4 éléments+
Monitor and document unusual transactions.
- Action d’implémentation
- Calibrate scenarios to risk and expected activity, preserve alert inputs, investigate context and maintain a numbered case file even when suspicion is not established.
- Preuves à conserver
- Scenario inventory, alert, workpaper, disposition and quality review.
- Source primaire
- Decree 67-2001 art. 26; Agreement 118-2002 art. 15
Report suspicious transactions to IVE immediately after determination.
- Action d’implémentation
- The compliance officer must use the current IVE form and channel once the activity is determined suspicious; retain the transmission acknowledgement and supporting file.
- Preuves à conserver
- Decision timestamp, report, receipt, support and access log.
- Source primaire
- Decree 67-2001 art. 26; Agreement 118-2002 art. 16
Apply CFT reporting to suspicious funds and transactions.
- Action d’implémentation
- Report to IVE using the current procedure where there are reasonable grounds concerning terrorist financing, irrespective of amount, and preserve the decision trail.
- Preuves à conserver
- Case analysis, CFT report, receipt and chronology.
- Source primaire
- Decree 58-2005 arts. 16-18; Agreement 86-2006
Prevent tipping off and restrict access.
- Action d’implémentation
- Do not disclose an IVE report or request to the customer or unauthorized persons; enforce need-to-know access and incident escalation.
- Preuves à conserver
- Permissions, confidentiality attestations, disclosure log and incident record.
- Source primaire
- Decree 67-2001 art. 27; Decree 58-2005 art. 19
07Cash, transfers, and regulated activityThresholds have distinct triggers and must not be generalized beyond their operative provision or IVE instruction.4 éléments+
Apply the correct effective-dated cash record trigger.
- Action d’implémentation
- Through 16 September 2026 record cash transactions above USD 10,000 or equivalent under the current rule. From 17 September configure Decree 15-2026's daily record for cash transactions at or above USD 10,000, subject to final IVE forms.
- Preuves à conserver
- Effective-dated threshold rule, boundary tests, form, receipt and exception log.
- Source primaire
- Decree 67-2001 art. 24; Agreement 118-2002 arts. 19-20; Decree 15-2026 art. 31
Support cross-border currency declarations at USD 10,000 or more.
- Action d’implémentation
- For covered transport into or out of Guatemala, use the SAT/IVE declaration procedure and escalate undeclared or suspicious movement.
- Preuves à conserver
- Declaration, transport record, review and escalation.
- Source primaire
- Decree 67-2001 art. 25; Agreement 118-2002 art. 37
Preserve required originator and beneficiary transfer information.
- Action d’implémentation
- Collect, validate, transmit and retain fields required by the current sector rule; hold or escalate incomplete transfers under that rule.
- Preuves à conserver
- Message fields, validation logs, exception queue and rule mapping.
- Source primaire
- Decree 67-2001 arts. 21-24; applicable SIB/Junta Monetaria/IVE instruments
Confirm virtual-asset, remittance, payment and money-transmission perimeter.
- Action d’implémentation
- Obtain current IVE and sector-regulator confirmation for the exact service, custody, exchange, transfer, territorial and solicitation model before launch.
- Preuves à conserver
- Product analysis, authority correspondence, registration and licence evidence.
- Source primaire
- Current IVE obliged-person designations and sector law; controlled uncertainty
08Targeted financial sanctionsSanctions controls must use binding current lists and an authority-confirmed escalation path.3 éléments+
Screen UN designations and applicable domestic measures.
- Action d’implémentation
- Screen customers, beneficial owners, representatives and transactions at onboarding, list change and before value movement.
- Preuves à conserver
- List sources, update logs, results, match files and test evidence.
- Source primaire
- Decree 58-2005; Agreement 86-2006; UN Security Council consolidated list
Act without delay on a confirmed designation match.
- Action d’implémentation
- Prevent dealing, preserve assets and notify IVE and other competent authority through the current legal procedure; do not release without authority.
- Preuves à conserver
- Match chronology, restriction record, notice, receipt and release authority.
- Source primaire
- Decree 58-2005 and Agreement 86-2006; current IVE procedure
Control false positives, delisting and permitted access.
- Action d’implémentation
- Use identity comparison and a confidential escalation route; obtain IVE or competent-authority direction for release, exceptions or delisting and confirm the live process before launch.
- Preuves à conserver
- Comparison file, escalation, authority response and audit trail.
- Source primaire
- Current IVE/competent-authority procedure; controlled uncertainty
09Records and authority accessRecords must be reconstructable, protected and retrievable throughout the statutory period.3 éléments+
Retain transaction records for at least five years.
- Action d’implémentation
- Preserve records sufficient to reconstruct domestic and international transactions for at least five years after completion, subject to any longer sector rule or authority hold.
- Preuves à conserver
- Retention schedule, archive, retrieval tests and holds.
- Source primaire
- Decree 67-2001 art. 23; Agreement 118-2002 art. 14
Retain customer files for at least five years after relationship termination.
- Action d’implémentation
- Preserve identification, verification, ownership, risk, monitoring and correspondence from the documented end date and suspend deletion for legal holds.
- Preuves à conserver
- Closure record, archive, deletion control and retrieval test.
- Source primaire
- Decree 67-2001 art. 23; Agreement 118-2002 art. 14
Respond securely to IVE and lawful authority requests.
- Action d’implémentation
- Authenticate the request, preserve scope and chain of custody, meet the stated deadline and log secure production.
- Preuves à conserver
- Request register, authentication, manifest and transmission receipt.
- Source primaire
- Decree 67-2001 arts. 28, 33; Decree 58-2005 arts. 20-23
10Privacy, biometrics, and transfersGuatemala has no enacted comprehensive private-sector data law identified as at review; constitutional, access-to-information, confidentiality, cybercrime and sector rules still constrain KYC processing.3 éléments+
Document lawful, necessary and secure KYC processing.
- Action d’implémentation
- Map data and purpose, give clear notice, minimize collection, restrict access and reconcile deletion with AML retention and authority-disclosure duties.
- Preuves à conserver
- Data map, notice, access matrix, retention analysis and rights workflow.
- Source primaire
- Constitution arts. 24, 30-31; Decree 57-2008 arts. 9, 30-35; AML confidentiality duties
Apply enhanced safeguards to biometrics and sensitive data.
- Action d’implémentation
- Assess necessity and proportionality, encrypt data, test vendors, limit reuse and offer a controlled fallback where practicable.
- Preuves à conserver
- Impact assessment, vendor diligence, security tests, access logs and fallback design.
- Source primaire
- Constitutional privacy and sector confidentiality; risk-based implementation control
Control processors, incidents and international access.
- Action d’implémentation
- Contract for confidentiality, security, incident notice, auditability, return/deletion and lawful authority access; maintain a tested response plan and data-flow map.
- Preuves à conserver
- Contracts, incident plan, transfer map, tests and decisions.
- Source primaire
- Sector confidentiality and cybercrime rules; controlled uncertainty
11Practical evidence packsEvidence must permit independent reconstruction of every onboarding, monitoring and reporting decision.3 éléments+
Maintain one indexed evidence file per customer or entity.
- Action d’implémentation
- Link identity, KYB, ownership/control, screening, risk, approvals, monitoring, refreshes and exit under immutable identifiers.
- Preuves à conserver
- Evidence index, version history, access history and reconstruction test.
- Source primaire
- Decree 67-2001 arts. 21-23; Agreement 118-2002 arts. 12-16
Test identity, reporting, screening and retention controls.
- Action d’implémentation
- Sample customer files and test cash logic, suspicious-report workflow, sanctions updates and five-year retention; assign and close defects.
- Preuves à conserver
- Test plan, samples, defects, owners and closure proof.
- Source primaire
- Decree 67-2001 arts. 19-26; Agreement 118-2002 arts. 9-20
Operate a dated legal-change control.
- Action d’implémentation
- Monitor Congress, Diario de Centro América, SIB/IVE, Junta Monetaria, Registro Mercantil, FATF, GAFILAT and CFATF; track Decree 15-2026 regulations and instructions into controls before 17 September 2026.
- Preuves à conserver
- Source register, change log, impact assessment and deployment record.
- Source primaire
- Decree 15-2026 commencement provision; risk-based implementation control
Registre des sources primaires
13 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Integrated AML/CFT Law - Decree 15-2026 (effective 17 September 2026)Congress of Guatemala · Enacted primary legislation
- Law Against Money or Other Asset Laundering - Decree 67-2001Superintendencia de Bancos · Primary legislation currently applicable
- Terrorist-Financing Law - Decree 58-2005Congress of Guatemala · Primary legislation currently applicable
- Regulation to Decree 67-2001 - Government Agreement 118-2002Superintendencia de Bancos · Primary regulation
- Regulation to the Terrorist-Financing Law - Government Agreement 86-2006Superintendencia de Bancos · Primary regulation
- Superintendencia de Bancos and IVE official portalSuperintendencia de Bancos · Official regulator portal
- Registro Mercantil GeneralMinisterio de Economía · Official company registry portal
- Access to Public Information Law - Decree 57-2008Congress of Guatemala · Primary legislation
- Guatemala mutual evaluation 2016FATF / GAFILAT / CFATF · Authoritative mutual evaluation
- FATF high-risk jurisdictions - June 2026Financial Action Task Force · Authoritative current-status statement
- FATF jurisdictions under increased monitoring - June 2026Financial Action Task Force · Authoritative current-status statement
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Authoritative sanctions list
- Decree 15-2026 commencement noticeCongress of Guatemala · Official applicability notice
Réponses directes
Questions KYC, KYB et AML pour Guatemala
Who receives suspicious transaction reports in Guatemala?+
The Intendencia de Verificación Especial (IVE), within the Superintendencia de Bancos.
When must a suspicious transaction be reported?+
Once the compliance officer determines that a transaction is suspicious, the obliged person must communicate it immediately to IVE using the current form and channel.
What cash threshold applies?+
Through 16 September 2026, Decree 67-2001 requires records above USD 10,000. From 17 September, Decree 15-2026 article 31 uses USD 10,000 or more. Cross-border transport has a separate USD 10,000-or-more declaration trigger.
What beneficial-owner test applies?+
Through 16 September 2026 apply the controlling current IVE instruction. From 17 September, Decree 15-2026 introduces a 15% natural-person ownership threshold plus control and benefit routes; reconcile the exact final text and implementing rules.
How long must AML records be kept?+
At least five years, with the trigger depending on whether the record concerns a completed transaction or a terminated customer relationship; longer sector rules or legal holds may apply.
Is there a public comprehensive beneficial-ownership register?+
This checklist does not represent that Guatemala has a comprehensive public BO register. Registro Mercantil certifies company and representative information; obtain ownership/control evidence independently and confirm competent-authority access.
Does Guatemala have a comprehensive data-protection law?+
No enacted comprehensive private-sector data-protection law was identified as at 7 August 2026. Constitutional privacy, habeas-data rules for public records, confidentiality, cybercrime and sector requirements still apply.
Is Guatemala on a FATF public list?+
As reviewed on 7 August 2026, Guatemala was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck both live statements before reliance.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed 7 August 2026; legal applicability is stated as of that date. Decree 15-2026 becomes applicable on 17 September 2026. Confirm transitional regulations, IVE instructions, reporting forms/channels, sanctions procedures, privacy requirements and product-specific licensing with IVE, the competent supervisor and qualified Guatemalan counsel before launch.