Guinée-Bissau KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Guinée-Bissau.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Guinée-Bissau ?
La checklist pour Guinée-Bissau traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 32 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Cellula Nacional de Tratamento de Informacoes Financeiras (CENTIF-GB)
- Primary AML law
- Law No. 3/2018 of 6 August 2018
- Suspicion reporting
- Without delay to CENTIF-GB; written or traceable, with 48-hour written confirmation where required
- Cash and transfer reports
- Thresholds depend on current BCEAO instructions
- Core retention
- 10 years after relationship end or transaction execution
- FATF status
- Not named on FATF public lists as at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Guinée-Bissau
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the applicable law, entity, activity and supervisor before launch.3 éléments+
Determine whether each activity is a reporting entity.
- Action d’implémentation
- Map every entity, product, channel and agent to the financial-institution, DNFBP or other covered categories and identify CENTIF-GB and the competent national or UMOA supervisor.
- Preuves à conserver
- Applicability memo, product map and accountable-owner register.
- Source primaire
- Law No. 3/2018, Articles 5-6
Treat CENTIF-GB as the financial intelligence unit.
- Action d’implémentation
- Appoint authorised correspondents, obtain the current filing form and route, and test controlled access before operations begin.
- Preuves à conserver
- Correspondent appointment, channel test, procedure and access approvals.
- Source primaire
- Law No. 3/2018, Articles 59-64 and 79-82
Obtain authorisation before regulated activity.
- Action d’implémentation
- Classify banking, payment, e-money, transfer, exchange, microfinance, insurance, securities, DNFBP and virtual-asset activities and obtain every required approval before launch.
- Preuves à conserver
- Perimeter analysis, authority correspondence and licence register.
- Source primaire
- Law No. 3/2018, Articles 87-88; applicable UMOA, BCEAO and sector rules
02Governance and risk assessmentThe programme must be risk-based, documented and independently tested.3 éléments+
Maintain an enterprise-wide ML/TF risk assessment.
- Action d’implémentation
- Assess customers, products, channels, geography, cash, agents, technology and proliferation exposure and update on material change.
- Preuves à conserver
- Approved methodology, assessment, controls and version history.
- Source primaire
- Law No. 3/2018, Articles 10-11 and 90
Maintain written controls and an empowered compliance function.
- Action d’implémentation
- Assign senior accountability and confidential CENTIF-GB reporting authority; maintain screening, training, recruitment and independent-audit controls proportionate to risk.
- Preuves à conserver
- Appointments, policies, training, testing and remediation log.
- Source primaire
- Law No. 3/2018, Articles 11 and 24
Assess new technology before use.
- Action d’implémentation
- Identify and mitigate ML/TF, fraud, security and privacy risks before launching new products, delivery mechanisms or technologies.
- Preuves à conserver
- Pre-launch assessment, approval, tests and residual-risk acceptance.
- Source primaire
- Law No. 3/2018, Article 37
03Natural-person identificationCDD uses reliable evidence and continues through the relationship.3 éléments+
Identify and verify customers and representatives.
- Action d’implémentation
- Verify the customer with reliable documents or information; identify any representative and verify identity and authority.
- Preuves à conserver
- Identity file, source provenance, mandate and verification result.
- Source primaire
- Law No. 3/2018, Articles 18 and 25-28
Understand purpose and expected activity.
- Action d’implémentation
- Record relationship purpose, products, expected volumes, counterparties, geography and source of funds sufficient for risk rating and monitoring.
- Preuves à conserver
- Customer profile, expected-activity baseline and approval.
- Source primaire
- Law No. 3/2018, Articles 19-20
Do not proceed where mandatory CDD fails.
- Action d’implémentation
- Do not open or execute, or terminate as applicable, when required identity or beneficial-owner information cannot be completed; consider confidential reporting.
- Preuves à conserver
- Decline or exit decision, investigation and restricted reporting record.
- Source primaire
- Law No. 3/2018, Articles 28-29 and 79
04KYB, registries, and beneficial ownershipRegistry evidence does not replace natural-person ownership and control analysis.3 éléments+
Verify legal existence, governance and authority.
- Action d’implémentation
- Obtain current RCCM, constitutional, address, director, signatory, tax and licence evidence and reconcile inconsistencies.
- Preuves à conserver
- RCCM extract, statutes, powers, tax record and licence file.
- Source primaire
- Law No. 3/2018, Articles 25-27; OHADA Uniform Acts
Identify natural-person beneficial owners using the statutory test.
- Action d’implémentation
- Identify persons holding directly or indirectly more than 25% of capital or voting rights and persons exercising control by other means; document the analysis for other legal arrangements.
- Preuves à conserver
- Ownership chart, source records, control analysis and verified identities.
- Source primaire
- Law No. 3/2018, Article 1(12) and Article 29
Treat company and beneficial-owner records as corroboration.
- Action d’implémentation
- Obtain and reconcile available RCCM, CFE and company-held information; record gaps and do not assume the central beneficial-owner fields are complete.
- Preuves à conserver
- Registry extracts, company records, discrepancy log and escalation.
- Source primaire
- OHADA framework; GIABA 2022 MER; IMF Country Report 25/167
05PEPs, EDD, and remote onboardingPEPs, higher risk and remote relationships require enhanced controls.3 éléments+
Detect PEP exposure in customers and beneficial owners.
- Action d’implémentation
- Use appropriate systems to identify foreign, domestic and international-organisation PEPs and connected-person risk.
- Preuves à conserver
- Screening, relationship map, match decision and refresh log.
- Source primaire
- Law No. 3/2018, Articles 22 and 54
Apply PEP approval, provenance and monitoring measures.
- Action d’implémentation
- Obtain senior approval, take reasonable measures to establish source of wealth and funds, and conduct enhanced ongoing monitoring.
- Preuves à conserver
- Approval, provenance analysis and monitoring plan.
- Source primaire
- Law No. 3/2018, Article 54
Control non-face-to-face and biometric risk.
- Action d’implémentation
- Apply enhanced identity, fraud, device, liveness, minimisation, security and exception controls proportionate to the remote channel and data used.
- Preuves à conserver
- Remote-onboarding assessment, privacy review, tests and exceptions.
- Source primaire
- Law No. 3/2018, Article 21 and Article 37
06Monitoring and suspicious reportingCENTIF-GB reporting must be prompt, traceable and confidential.3 éléments+
Monitor activity against the customer profile.
- Action d’implémentation
- Examine unusual, complex, linked or apparently purposeless activity and preserve a reasoned conclusion.
- Preuves à conserver
- Alerts, investigation, disposition and rule governance.
- Source primaire
- Law No. 3/2018, Articles 19-20 and 32
Report suspicion without delay to CENTIF-GB.
- Action d’implémentation
- Report amounts or operations suspected, or reasonably suspected, to involve ML/TF; where reporting by phone or electronic means, confirm in writing within 48 hours as Article 81 requires.
- Preuves à conserver
- Decision chronology, report, written confirmation, receipt and supplement log.
- Source primaire
- Law No. 3/2018, Articles 79 and 81
Prevent tipping off.
- Action d’implémentation
- Restrict access and do not disclose a report, its contents or CENTIF-GB follow-up to the customer or unauthorised third parties.
- Preuves à conserver
- Access logs, confidentiality procedure and training.
- Source primaire
- Law No. 3/2018, Article 82
07Payments, wires, thresholds, and agentsPayment controls preserve required data and use only verified thresholds.3 éléments+
Apply cash and transfer reports only at current prescribed thresholds.
- Action d’implémentation
- Obtain the current BCEAO instructions and CENTIF-GB method before configuring cash or fund-transfer reporting; aggregate only as the instrument requires.
- Preuves à conserver
- Current instruction, configuration, filings and receipts.
- Source primaire
- Law No. 3/2018, Articles 13-15 and 79(7)
Preserve required wire-transfer information.
- Action d’implémentation
- Carry required originator and beneficiary information through the payment chain and reject or risk-govern incomplete information as applicable.
- Preuves à conserver
- Message samples, validation rules, exceptions and escalation.
- Source primaire
- Law No. 3/2018, Articles 33-34
Retain accountability for agents and outsourcing.
- Action d’implémentation
- Verify permissions, diligence providers, contract for security and record access, train agents, monitor compliance and test retrieval.
- Preuves à conserver
- Due diligence, contract, training, monitoring and retrieval test.
- Source primaire
- Law No. 3/2018, Articles 24, 52-53 and 87
08Targeted financial sanctionsUse current UN and applicable UMOA designations and controlled national procedures.3 éléments+
Screen applicable designations.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, list updates and before relevant execution.
- Preuves à conserver
- List inventory, update logs, screening configuration and dispositions.
- Source primaire
- Law No. 3/2018, Articles 105-107; UN consolidated list
Freeze covered property without delay or prior notice.
- Action d’implémentation
- Prevent prohibited movement or availability of covered funds and economic resources and escalate immediately under current national and UMOA procedures.
- Preuves à conserver
- Freeze procedure, timestamps, legal basis and authority communication.
- Source primaire
- Law No. 3/2018, Articles 105-107; applicable UMOA instruments
Report and govern matches, false positives and release.
- Action d’implémentation
- Use the current competent-authority process, file a suspicious-operation report where warranted, and release only on documented lawful authority.
- Preuves à conserver
- Reports, receipt, match rationale, authority instruction and reconciliation.
- Source primaire
- Law No. 3/2018, Articles 79 and 105-107
09Records and regulator accessRecords must reconstruct the customer, ownership, transaction and decision.3 éléments+
Retain CDD and transaction records for ten years.
- Action d’implémentation
- Retain identity records for ten years after account closure or relationship end and transaction records for ten years after execution, subject to longer legal holds.
- Preuves à conserver
- Schedule, configuration, archive sample and legal-hold log.
- Source primaire
- Law No. 3/2018, Article 35
Make transaction records reconstructable.
- Action d’implémentation
- Preserve sufficient account, transaction, correspondence, analysis and decision detail for competent-authority use.
- Preuves à conserver
- Transaction reconstruction and retrieval test.
- Source primaire
- Law No. 3/2018, Articles 35-36
Respond securely to competent-authority requests.
- Action d’implémentation
- Authenticate requests, protect reporting confidentiality, produce reproducibly and log scope, timing and receipt.
- Preuves à conserver
- Request, approval, production index and acknowledgement.
- Source primaire
- Law No. 3/2018, Articles 36, 64-67 and 82
10Privacy, biometrics, and transfersApply constitutional confidentiality and security safeguards; confirm sector and implementing rules.3 éléments+
Document lawful and proportionate identity processing.
- Action d’implémentation
- Map purposes, data, authority, notices, access, security and retention; confirm current Guinea-Bissau privacy and sector requirements before production use.
- Preuves à conserver
- Data inventory, legal assessment, notices and approvals.
- Source primaire
- Constitution of Guinea-Bissau, privacy and communications guarantees; Law No. 3/2018, Articles 78 and 89-90
Apply enhanced safeguards to biometric and sensitive data.
- Action d’implémentation
- Minimise collection, restrict access, test security and document a valid legal basis before biometric or sensitive-data use.
- Preuves à conserver
- Impact assessment, legal basis, security tests and approval.
- Source primaire
- Constitutional privacy principles; applicable sector rules
Control processors, incidents and cross-border transfers.
- Action d’implémentation
- Bind processors, preserve confidentiality and security, and obtain current authority or counsel confirmation before configuring transfers or incident notices; do not invent a portal or deadline.
- Preuves à conserver
- Processor contract, transfer assessment, incident procedure and authority guidance.
- Source primaire
- Law No. 3/2018, Articles 78 and 89-91; applicable privacy and sector rules
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervisory access.2 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting Law No. 3/2018
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting Law No. 3/2018, Articles 79-82
Registre des sources primaires
10 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 3/2018 on combating money laundering and terrorist financingProsecutor General's Office of Guinea-Bissau / Official Gazette · Primary national legislation
- 2023 UMOA uniform AML/CFT/CPF lawBCEAO · Primary regional legislative instrument - national enactment pending confirmation
- Guinea-Bissau mutual evaluation reportGIABA · Authoritative country assessment
- GIABA 2023 annual report - first Guinea-Bissau follow-upGIABA · Authoritative follow-up record
- GIABA 2024 annual reportGIABA · Authoritative follow-up status
- Guinea-Bissau 2025 Article IV consultationInternational Monetary Fund · Authoritative implementation-status source
- BCEAO Guinea-Bissau regulatory materialsBCEAO · Official financial regulator materials
- OHADA commercial companies and RCCM frameworkOHADA · Official company-law materials
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Guinée-Bissau
Who receives suspicious-operation reports?+
Guinea-Bissau's CENTIF-GB. Obtain its current prescribed route and form before production use.
When is suspicion reported?+
Without delay under Article 79. Article 81 requires traceable written transmission and written confirmation within 48 hours for reports initially made by phone or electronic means.
Are there cash or transfer thresholds?+
Yes, but Law No. 3/2018 leaves relevant thresholds to BCEAO instructions. Verify the current instruction and CENTIF-GB method before configuration.
How is company beneficial ownership determined?+
Law No. 3/2018 uses direct or indirect holdings above 25% of capital or voting rights, or control by other means. Reconcile this CDD analysis with available registry information.
How long are AML records retained?+
Ten years after account closure or relationship end for identity records, and ten years after execution for transaction records, under Article 35.
Is Guinea-Bissau on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026, but remains in GIABA enhanced follow-up.
Has the 2023 UMOA uniform law replaced Law No. 3/2018?+
Not on the latest authoritative national-implementation evidence reviewed for this edition. Confirm enactment with the Official Gazette, CENTIF-GB and counsel before relying on the transition.
Can a regulated financial or payment product launch without approval?+
No. Classify the activity under current national and UMOA rules and obtain every competent-authority approval before launch.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 28 August 2026. Confirm enactment of the 2023 UMOA uniform law, current CENTIF-GB filing specifications, BCEAO thresholds, targeted-sanctions procedures, beneficial-owner registry operation, privacy requirements and product permissions with the competent authority and qualified Guinea-Bissau counsel before launch.