Lesotho KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Lesotho.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Lesotho ?
La checklist pour Lesotho traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 32 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Financial Intelligence Unit of Lesotho
- Primary AML rules
- MLPCA 2008 as amended; MLPCR 2019
- Suspicion reporting
- Immediately to the FIU; in any case no later than 7 days
- Thresholds
- Sector and transaction specific; do not use one universal amount
- Core AML retention
- At least 5 years after relationship end or occasional transaction
- FATF status
- Not named on FATF public lists as at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Lesotho
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the accountable entity, activity and supervisor before launch.3 éléments+
Determine whether each activity is accountable.
- Action d’implémentation
- Map every entity, product, channel and agent to the Act, the 2019 Regulations and applicable financial-institution, DNFBP or designated-business categories; identify the FIU and sector supervisor.
- Preuves à conserver
- Applicability memo, product map and accountable-owner register.
- Source primaire
- MLPCA 2008, section 2 and Schedule 1; MLPCR 2019, regulations 1 and 22
Register with the FIU when the prescribed obligation applies.
- Action d’implémentation
- Obtain the current FIU form and submission route; register within the applicable period and notify changes within 60 days without assuming an unverified portal.
- Preuves à conserver
- Registration, receipt, change log and channel test.
- Source primaire
- MLPCR 2019, regulation 21
Obtain authorisation before regulated activity.
- Action d’implémentation
- Classify banking, payments, e-money, money transfer, exchange, microfinance, insurance, securities, agent and virtual-asset activities and obtain every required approval before launch.
- Preuves à conserver
- Perimeter analysis, authority correspondence and licence register.
- Source primaire
- Financial Institutions Act 2012; Payment Systems Act 2014; applicable CBL and sector instruments
02Governance and risk assessmentControls must be risk-based, documented and independently tested.3 éléments+
Maintain a documented ML/TF risk assessment.
- Action d’implémentation
- Assess customers, products, channels, geography, cash, agents, technology and proliferation exposure; apply enhanced measures where risk is higher and never simplify when suspicion exists.
- Preuves à conserver
- Approved methodology, assessment, controls and version history.
- Source primaire
- MLPCR 2019, regulations 5 and 10
Maintain written controls and senior compliance ownership.
- Action d’implémentation
- Designate a knowledgeable senior officer and maintain CDD, PEP, reporting, records, confidentiality, employee-screening and training controls proportionate to risk.
- Preuves à conserver
- Appointment, policies, training, screening and remediation log.
- Source primaire
- MLPCR 2019, regulations 12-14
Independently test the programme.
- Action d’implémentation
- Maintain an independent audit function and supervise branches, subsidiaries and representative offices for compliance.
- Preuves à conserver
- Audit plan, reports, findings and closure evidence.
- Source primaire
- MLPCR 2019, regulation 15
03Natural-person identificationCDD uses reliable independent evidence and continues through the relationship.3 éléments+
Identify and verify the customer and representative.
- Action d’implémentation
- Use reliable independent documents, data or information; verify any representative's identity and authority before reliance.
- Preuves à conserver
- Identity file, source provenance, mandate and verification result.
- Source primaire
- MLPCR 2019, regulations 3 and 6; MLPCA 2008, sections 16-17
Understand purpose and expected activity.
- Action d’implémentation
- Record relationship purpose, intended nature, expected volumes, counterparties, geography and source of funds sufficient for risk rating and monitoring.
- Preuves à conserver
- Customer profile, expected-activity baseline and approval.
- Source primaire
- MLPCR 2019, regulation 4
Do not proceed where mandatory CDD fails.
- Action d’implémentation
- Do not open or establish the relationship when identity, beneficial ownership, ownership/control structure or purpose cannot be completed; terminate existing relationships in the circumstances prescribed and consider confidential reporting.
- Preuves à conserver
- Decline or exit decision, investigation and restricted reporting record.
- Source primaire
- MLPCR 2019, regulation 7
04KYB, registries, and beneficial ownershipCDD control analysis and company-register disclosure are related but distinct.3 éléments+
Verify legal existence, governance and authority.
- Action d’implémentation
- Obtain a current company extract, incorporation and governing records, registered and principal addresses, directors, shareholders, signatories, licences and mandates; reconcile inconsistencies.
- Preuves à conserver
- Registry extract, constitutional records, powers and discrepancy log.
- Source primaire
- MLPCR 2019, regulation 3(4); Companies Act 2011
Identify natural-person beneficial owners for CDD.
- Action d’implémentation
- Identify the natural persons with controlling ownership, then control by other means, and use relevant senior management only when no natural person is identified through ownership or control; apply the trust and legal-arrangement tests separately.
- Preuves à conserver
- Ownership chart, control analysis, verified identities and fallback rationale.
- Source primaire
- MLPCR 2019, regulation 6(5)-(6)
Apply the company-register test and deadlines separately.
- Action d’implémentation
- For a Lesotho company, identify each natural person meeting any 2024 test, including direct or indirect ownership of more than 10% of shares or votes, appointment/removal power, influence or ultimate effective control; maintain and file confirmed particulars within the applicable 7-day periods and record changes.
- Preuves à conserver
- Company BO register, identity evidence, filing receipt and change log.
- Source primaire
- Companies (Beneficial Ownership) Regulations 2024, regulations 3-8
05PEPs, EDD, and remote onboardingPEPs and higher-risk or remote relationships require enhanced controls.3 éléments+
Detect PEP exposure.
- Action d’implémentation
- Use appropriate systems to identify domestic, foreign and international-organisation PEP exposure in customers, beneficial owners and connected persons.
- Preuves à conserver
- Screening, relationship map, match decision and refresh log.
- Source primaire
- MLPCA 2008, section 2; MLPCR 2019, regulations 12 and Schedule 5
Apply enhanced approval, provenance and monitoring.
- Action d’implémentation
- For PEP and other higher-risk relationships, obtain senior approval, establish source of wealth and funds to the extent required by risk, and conduct enhanced ongoing monitoring.
- Preuves à conserver
- Approval, provenance analysis and monitoring plan.
- Source primaire
- MLPCR 2019, regulations 5 and 10; Schedule 5
Control remote and biometric onboarding.
- Action d’implémentation
- Assess identity, impersonation, device, liveness, minimisation, sensitive-data and security risks before deployment; document a valid processing basis and exceptions.
- Preuves à conserver
- Remote-onboarding assessment, privacy review, tests and approvals.
- Source primaire
- MLPCR 2019, regulations 5 and 12; Data Protection Act 2012, sections 15-22 and 29-37
06Monitoring and suspicious reportingFIU reporting must be immediate, complete and confidential.3 éléments+
Monitor activity against the customer profile.
- Action d’implémentation
- Scrutinise transactions throughout the relationship for consistency with customer, business, risk and source-of-funds knowledge and investigate unusual activity.
- Preuves à conserver
- Alerts, investigation, disposition and rule governance.
- Source primaire
- MLPCR 2019, regulation 4(b)
Report suspicion and attempts immediately.
- Action d’implémentation
- Submit the prescribed report to the FIU immediately upon forming suspicion and in any case no later than 7 days, regardless of amount; include attempted transactions and explain any delay in writing.
- Preuves à conserver
- Decision chronology, report, delay explanation if any, receipt and supplements.
- Source primaire
- MLPCR 2019, regulation 19(1)-(10)
Prevent tipping off.
- Action d’implémentation
- Restrict access and do not disclose the report, its contents or filing; do not seek abnormal information from the customer in a way that would reveal the process.
- Preuves à conserver
- Access logs, confidentiality procedure and training.
- Source primaire
- MLPCR 2019, regulation 19(11)-(14); MLPCA 2008, section 22
07Payments, wires, thresholds, and agentsThresholds are scoped by sector and instrument, not universal.3 éléments+
Configure only verified thresholds.
- Action d’implémentation
- Apply the M25,000 casino and specified designated-business cash triggers and M100,000 precious-metal or precious-stone cash trigger only to their stated categories; obtain current FIU or supervisor instruments for any other prescribed threshold.
- Preuves à conserver
- Legal mapping, configuration, test cases, filings and receipts.
- Source primaire
- MLPCR 2019, regulations 22-23
Preserve required wire-transfer information.
- Action d’implémentation
- Carry complete originator and beneficiary information, monitor missing data, and reject, suspend or escalate incomplete transfers under the applicable ordering, intermediary and beneficiary rules.
- Preuves à conserver
- Message samples, validation rules, exceptions and escalation.
- Source primaire
- MLPCR 2019, regulations 40-45
Retain accountability for agents and third parties.
- Action d’implémentation
- Verify permissions, conduct due diligence, contract for confidentiality, security and prompt record access, and keep ultimate responsibility for relied-on CDD.
- Preuves à conserver
- Due diligence, contract, monitoring and retrieval test.
- Source primaire
- MLPCR 2019, regulations 9 and 12; CBL Agent Banking Regulations 2024
08Targeted financial sanctionsUse current UN and communicated domestic lists under the statutory process.3 éléments+
Screen applicable designations.
- Action d’implémentation
- Regularly obtain current UN lists and screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, list updates and before execution.
- Preuves à conserver
- List inventory, update logs, screening configuration and dispositions.
- Source primaire
- MLPCR 2019, regulations 27(2)-(3) and 27(10)
Freeze covered property without delay or notice.
- Action d’implémentation
- On a designation and freezing order, freeze covered funds or assets without delay and prior notice and prevent funds, assets, economic resources or services from being made available.
- Preuves à conserver
- Freeze procedure, timestamps, legal basis and authority communication.
- Source primaire
- MLPCR 2019, regulations 28-30
Govern false positives, exceptions and release.
- Action d’implémentation
- Escalate matches through the current FIU, supervisor or competent-authority process; permit access or release only on documented lawful authority and preserve the full rationale.
- Preuves à conserver
- Reports, match rationale, authority instruction and reconciliation.
- Source primaire
- MLPCR 2019, regulations 31-33
09Records and regulator accessRecords must reconstruct the customer, transaction, ownership and decision.3 éléments+
Retain AML records for at least five years.
- Action d’implémentation
- Retain CDD, account, correspondence, analysis and domestic or international transaction records for at least 5 years from relationship termination or the occasional transaction, and longer when directed for up to a further 5 years.
- Preuves à conserver
- Schedule, configuration, archive sample and legal-hold log.
- Source primaire
- MLPCR 2019, regulation 11
Retain company BO history for the separate period.
- Action d’implémentation
- Keep required company beneficial-owner information for at least 10 years after a person ceases to be a beneficial owner and preserve dissolved-company information as required.
- Preuves à conserver
- BO history, filing records and retention test.
- Source primaire
- Companies (Beneficial Ownership) Regulations 2024, regulations 12-13
Respond securely to competent requests.
- Action d’implémentation
- Authenticate requests, protect FIU-report confidentiality, produce records swiftly and reproducibly, and log scope, timing and receipt.
- Preuves à conserver
- Request, approval, production index and acknowledgement.
- Source primaire
- MLPCR 2019, regulations 11 and 16-17
10Privacy, biometrics, and transfersIdentity processing must comply with the Data Protection Act and AML holds.3 éléments+
Document a lawful, minimal and transparent processing basis.
- Action d’implémentation
- Map purpose, legal basis, data, notice, recipients, rights and retention; notify the Data Protection Commission before processing where section 25(5) applies.
- Preuves à conserver
- Data inventory, legal assessment, notices and Commission record.
- Source primaire
- Data Protection Act 2012, sections 15-19 and 25
Protect data and govern processors and incidents.
- Action d’implémentation
- Apply reasonable technical and organisational safeguards, bind agents by written confidentiality and security terms, and notify the Commission and affected subjects as soon as reasonably possible after a qualifying compromise.
- Preuves à conserver
- Risk assessment, contracts, security tests and incident records.
- Source primaire
- Data Protection Act 2012, sections 20-23
Control sensitive data and cross-border processing.
- Action d’implémentation
- Treat biometrics and other sensitive data under the Act's prohibitions and exceptions; document legal authority and take reasonable steps concerning an overseas agent's compliance before transfer or access.
- Preuves à conserver
- Sensitive-data assessment, transfer analysis and approval.
- Source primaire
- Data Protection Act 2012, sections 22 and 29-37
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.2 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting MLPCR 2019, regulations 3-15
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting MLPCR 2019, regulation 19
Registre des sources primaires
11 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Money Laundering and Proceeds of Crime Act 2008LesLII / Office of Parliamentary Counsel of Lesotho · Primary national legislation - consolidation notes outstanding 2016 amendment
- Money Laundering and Proceeds of Crime (Amendment) Act 2016LesLII / Office of Parliamentary Counsel of Lesotho · Primary amending legislation
- Money Laundering and Proceeds of Crime Regulations 2019LesLII / Office of Parliamentary Counsel of Lesotho · Primary national regulations
- Companies Act 2011LesLII / Office of Parliamentary Counsel of Lesotho · Primary company legislation
- Companies (Beneficial Ownership) Regulations 2024Lesotho Digital Business Registrations / Registrar of Companies · Primary company regulations
- Data Protection Act 2012LesLII / Office of Parliamentary Counsel of Lesotho · Primary privacy legislation
- Central Bank of Lesotho legislation and regulationsCentral Bank of Lesotho · Official financial regulator materials
- Financial Intelligence Unit of LesothoFinancial Intelligence Unit of Lesotho · Official FIU materials
- Lesotho second-round mutual evaluation reportESAAMLG · Authoritative country assessment
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Lesotho
Who receives suspicious transaction reports?+
The Financial Intelligence Unit of Lesotho, using its current prescribed form and route.
When is suspicion reported?+
Immediately upon forming suspicion and in any case no later than 7 days. Attempted transactions are included and amount is irrelevant.
Is there one universal threshold?+
No. The 2019 Regulations include specific M25,000 and M100,000 triggers for stated DNFBP and designated-business categories, while other reporting or CDD thresholds may depend on applicable instruments.
How is beneficial ownership determined?+
CDD follows controlling ownership, control by other means, then senior-management fallback. Separately, the 2024 company-register rules include a more-than-10% shares or voting-rights test plus appointment, influence and ultimate-control tests.
How long are AML records retained?+
At least 5 years after termination of the business relationship or the occasional transaction, with a competent authority able to direct up to a further 5 years. Company BO records have separate 10-year rules.
What is the breach-notification deadline?+
The Data Protection Act requires notification to the Commission and affected data subjects as soon as reasonably possible after discovering a qualifying compromise; it does not state a fixed hour count.
Is Lesotho on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026, but remains in ESAAMLG enhanced follow-up.
Can a regulated payment or financial product launch without approval?+
No. Classify the activity and obtain each required Central Bank or other competent-authority approval before launch.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 29 August 2026. Confirm current FIU registration and filing specifications, prescribed transaction-reporting thresholds, sanctions communications, Data Protection Commission procedures, and product-specific permissions with the competent authority and qualified Lesotho counsel before launch.