Sao Tomé-et-Principe KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Sao Tomé-et-Principe.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Sao Tomé-et-Principe ?
La checklist pour Sao Tomé-et-Principe traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 36 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Unidade de Informação Financeira (UIF)
- Primary AML rule
- Law No. 8/2013 of 15 October 2013
- Suspicion reporting
- Immediately, including attempted transactions, regardless of amount
- Automatic cash report
- No general cash-transaction report identified in the 2024 GIABA assessment
- Core AML retention
- At least 5 years under record-specific clocks
- FATF status
- Not named on FATF public lists at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Sao Tomé-et-Principe
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the covered activity and competent supervisor before launch.3 éléments+
Map each entity and activity to the AML/CFT perimeter.
- Action d’implémentation
- Classify financial institutions and designated non-financial businesses and professions under Law No. 8/2013, including relevant agents and branches, and identify the FIU and sector supervisor.
- Preuves à conserver
- Applicability memo, entity and product map, supervisor matrix and accountable owner.
- Source primaire
- Law 8/2013, Articles 2-3; GIABA MER 2024, Recommendations 10 and 22
Establish the institutional FIU reporting route.
- Action d’implémentation
- Authorise named reporters, obtain the current reporting form and access route directly from the FIU, test secure transmission and preserve institutional acknowledgements; do not use the public tip-off channel as a substitute without FIU confirmation.
- Preuves à conserver
- Reporter mandate, FIU instructions, channel test and receipt log.
- Source primaire
- Law 8/2013, Article 21; UIF legislation and contact pages
Obtain approval before regulated financial or payment activity.
- Action d’implémentation
- Classify banking, foreign exchange, money transfer, payment, e-money, agent, outsourcing and other regulated services and obtain Central Bank or other competent approval before launch.
- Preuves à conserver
- Perimeter analysis, licence, conditions, agent approvals and renewal calendar.
- Source primaire
- Law 17/2018; Decree-Law 16/2019; GIABA MER 2024, Recommendation 14
02Governance and risk assessmentControls must be documented, risk-based and independently tested.3 éléments+
Maintain approved AML/CFT controls.
- Action d’implémentation
- Adopt controls for CDD, beneficial ownership, PEPs, monitoring, reporting, sanctions, records, training and assurance proportionate to the institution's risk and sector rules.
- Preuves à conserver
- Policy suite, governance approvals, control inventory, training and testing.
- Source primaire
- Law 8/2013; NAP 10/2015; GIABA MER 2024, Recommendations 18 and 23
Assess customer, product and delivery risk.
- Action d’implémentation
- Document ML/TF risks across customers, beneficial owners, countries, products, cash exposure, technologies, agents and delivery channels before launch and after material change.
- Preuves à conserver
- Risk methodology, assessment, inputs, approvals and remediation plan.
- Source primaire
- Law 8/2013, Article 11; GIABA MER 2024, Recommendation 1
Govern third parties and outsourcing.
- Action d’implémentation
- Confirm reliance eligibility, obtain CDD information without delay, contract for document access, test retrieval and retain ultimate responsibility for customer identification and verification.
- Preuves à conserver
- Due diligence, agreement, retrieval tests, monitoring and exceptions.
- Source primaire
- Law 8/2013, Article 17; GIABA MER 2024, Recommendation 17
03Natural-person identificationApply identification and verification at every statutory trigger.3 éléments+
Identify and verify customers before establishing a relationship.
- Action d’implémentation
- Capture identity attributes, verify them from reliable independent evidence, record purpose and intended nature and establish an expected activity profile.
- Preuves à conserver
- CDD file, evidence provenance, purpose, expected activity and risk decision.
- Source primaire
- Law 8/2013, Article 10(2)-(3); NAP 10/2015
Apply CDD at occasional-transaction and risk triggers.
- Action d’implémentation
- Apply CDD to occasional or apparently linked transactions at or above STN 245,000, and regardless of amount where suspicion arises or prior identification data is doubtful; treat the statutory threshold as a trigger, not a safe harbour.
- Preuves à conserver
- Trigger matrix, aggregation logic, alerts and CDD timestamps.
- Source primaire
- Law 8/2013, Article 10(2); GIABA MER 2024, criterion 10.2
Verify representatives and their authority.
- Action d’implémentation
- Identify and verify each person acting for a customer and validate the mandate before permitting activity.
- Preuves à conserver
- Identity evidence, mandate, authority verification and expiry control.
- Source primaire
- Law 8/2013, Article 10(12)
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and ultimate natural-person control.4 éléments+
Verify legal-person identity and authority.
- Action d’implémentation
- Obtain current commercial-register evidence, constitutional documents, registered office, business address, directors, licences and mandates, and resolve inconsistencies.
- Preuves à conserver
- DGRN/GUE extract, statutes, officer list, licences, mandate and discrepancy log.
- Source primaire
- Law 8/2013, Article 10; DGRN GUE requirements
Identify and verify the beneficial owner.
- Action d’implémentation
- Use reliable evidence to identify the natural person who ultimately owns or effectively controls the customer; document ownership and control separately and apply a conservative senior-manager fallback where no owner or controller can be identified.
- Preuves à conserver
- Ownership chart, control analysis, verified identities and fallback rationale.
- Source primaire
- Law 8/2013, Article 10(2)-(3); GIABA MER 2024, criteria 10.5 and 10.10
Do not treat the company register as a complete BO register.
- Action d’implémentation
- Reconcile registry records, customer declarations and independent evidence, refresh on ownership or control changes and record discrepancies; the 2024 GIABA assessment found no general legal-person BO filing duty or central BO register.
- Preuves à conserver
- Registry evidence, declarations, corroboration, refresh log and discrepancies.
- Source primaire
- GIABA MER 2024, Recommendation 24
Identify foreign-trust role holders and control.
- Action d’implémentation
- Where a foreign trust operates, holds assets or has a trustee in the jurisdiction, identify the persons who own or control it and document settlor, trustee, protector, beneficiaries and other effective controllers as a risk-based evidence standard.
- Preuves à conserver
- Trust instrument, role register, identity files and control analysis.
- Source primaire
- Law 8/2013, Article 10(3); GIABA MER 2024, Recommendation 25
05PEPs, EDD, and failed CDDHigher-risk relationships require approval, source evidence and enhanced monitoring.3 éléments+
Detect PEP exposure.
- Action d’implémentation
- Use reasonable measures to determine whether customers and beneficial owners are foreign, domestic or international-organisation PEPs and map family members and close associates.
- Preuves à conserver
- Screening, relationship map, match decision and refresh history.
- Source primaire
- Law 8/2013, Article 12; NAP 10/2015; GIABA MER 2024, Recommendation 12
Apply senior approval, source and monitoring controls.
- Action d’implémentation
- For PEP and other high-risk relationships, obtain senior approval, establish source of wealth and source of funds and apply enhanced ongoing monitoring.
- Preuves à conserver
- Approval, source analysis, corroboration and monitoring plan.
- Source primaire
- Law 8/2013, Articles 11-12
Stop activity where required CDD cannot be completed.
- Action d’implémentation
- Do not open or execute and address existing relationships consistently with current FIU and supervisory instructions; consider an STR and protect confidentiality.
- Preuves à conserver
- Decline, restriction or exit decision, investigation and reporting record.
- Source primaire
- Law 8/2013, Article 10(4); GIABA MER 2024, criterion 10.19
06Monitoring and suspicious reportingFIU reporting must be immediate, complete and confidential.4 éléments+
Monitor activity against the customer profile.
- Action d’implémentation
- Review transactions for consistency with known business, risk and source of funds and document investigation of complex, unusual or apparently purposeless activity.
- Preuves à conserver
- Alerts, investigation notes, supporting data and dispositions.
- Source primaire
- Law 8/2013, Articles 10-11; NAP 11/2015
Report suspicion and attempts immediately.
- Action d’implémentation
- Timestamp when suspicion or reasonable grounds arose and immediately report to the FIU, including attempted transactions and regardless of amount, through the current institutional route.
- Preuves à conserver
- Decision chronology, STR, delivery evidence and receipt.
- Source primaire
- Law 8/2013, Article 21; GIABA MER 2024, Recommendation 20
Prevent tipping off.
- Action d’implémentation
- Restrict report access and do not inform customers or third parties that a report or related information was or will be sent, or that an ML/TF investigation exists.
- Preuves à conserver
- Need-to-know access, communications controls, training and audit log.
- Source primaire
- Law 8/2013, Article 22(1)
Use the current FIU form and preserve supplements.
- Action d’implémentation
- Obtain the institutional COS form and filing instructions directly from the FIU, submit complete supporting information and preserve later supplements and FIU communications.
- Preuves à conserver
- Current form, filing package, supplements, correspondence and acknowledgement.
- Source primaire
- UIF documents and contact pages; NAP 11/2015
07Payments, wires, thresholds, and agentsKeep CDD thresholds, sector triggers and reporting duties distinct.4 éléments+
Do not invent a general cash-transaction report.
- Action d’implémentation
- Apply CDD, monitoring and STR duties to cash activity, but do not configure an automatic general cash-report threshold unless the FIU or competent supervisor confirms a current instrument; GIABA found no such general duty in 2024.
- Preuves à conserver
- Legal register, authority confirmation, monitoring rules and change control.
- Source primaire
- GIABA MER 2024, paragraph 342
Apply sector-specific DNFBP triggers.
- Action d’implémentation
- Confirm current redenominated amounts before implementation; the 2024 assessment records casino CDD at STN 50,000 and dealer-in-precious-metals/stones cash CDD at STN 245,000, alongside activity-based duties for real-estate and professional services.
- Preuves à conserver
- Sector applicability memo, current-value confirmation, aggregation tests and CDD records.
- Source primaire
- Law 8/2013, Articles 3 and 10; GIABA MER 2024, criterion 22.1
Carry required wire information and control deficient transfers.
- Action d’implémentation
- Apply Law No. 8/2013 and current Central Bank rules to originator and beneficiary information, retention and risk-based execute, reject, suspend and follow-up decisions; do not rely on the high statutory threshold as a risk safe harbour.
- Preuves à conserver
- Field matrix, validation, repair queue, samples and decisions.
- Source primaire
- Law 8/2013, Article 15; GIABA MER 2024, Recommendation 16
Control payment agents and providers.
- Action d’implémentation
- Verify licensing and agent authority, contract for AML, records, audit, privacy and incident controls, monitor performance and retain provider accountability.
- Preuves à conserver
- Central Bank approvals, agent register, contracts, monitoring and incidents.
- Source primaire
- Law 17/2018; Decree-Law 16/2019
08Targeted financial sanctionsScreen continuously while controlling the known national implementation delay.3 éléments+
Screen authoritative UN designations and national notices.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, before activity and on list updates using current UN and national sources.
- Preuves à conserver
- List inventory, update log, screening configuration, alerts and dispositions.
- Source primaire
- Law 3/2018; UN consolidated list; GIABA MER 2024, Recommendations 6 and 7
Escalate potential matches immediately.
- Action d’implémentation
- Block execution while confirming a potential match, obtain current legal directions from the competent authority and document the treatment of assets and prohibited availability.
- Preuves à conserver
- Alert chronology, escalation, authority direction, asset record and controls.
- Source primaire
- Law 3/2018; GIABA MER 2024, Recommendations 6 and 7
Do not represent gazette publication as FATF-standard immediacy.
- Action d’implémentation
- Maintain a rapid operational process but record that GIABA found the national gazette-dependent mechanism did not implement UN targeted financial sanctions without delay; confirm the current designation, reporting, false-positive and release procedure.
- Preuves à conserver
- Gap assessment, authority confirmation, timestamps, reports and release decision.
- Source primaire
- GIABA MER 2024, criteria 6.4 and 7.4
09Records and regulator accessRecords must reconstruct customers, transactions and decisions.3 éléments+
Retain CDD records for at least five years after relationship end or an occasional transaction.
- Action d’implémentation
- Apply the correct relationship or occasional-transaction clock to customer, representative and beneficial-owner evidence and preserve legal holds.
- Preuves à conserver
- Retention schedule, archive sample, deletion control and hold log.
- Source primaire
- Law 8/2013, Article 20(1)(a)
Retain transaction and attempted-transaction records for at least five years.
- Action d’implémentation
- Apply a transaction-based clock and preserve domestic and international transaction records and commercial correspondence in reconstructable form.
- Preuves à conserver
- Archive configuration, reconstruction test and retrieval log.
- Source primaire
- Law 8/2013, Article 20(1)(b); GIABA MER 2024, Recommendation 11
Provide records promptly under proper authority.
- Action d’implémentation
- Authenticate requests, protect STR confidentiality, produce controlled records to the FIU and competent authorities and log approval, scope, delivery and receipt.
- Preuves à conserver
- Request register, authority check, production index and acknowledgement.
- Source primaire
- Law 8/2013, Articles 20 and 22
10Privacy, biometrics, and transfersAML processing remains subject to Law No. 3/2016.3 éléments+
Document purpose, proportionality, accuracy and retention.
- Action d’implémentation
- Inventory identity, ownership, screening, biometric, monitoring and reporting data; record the lawful basis, purpose, recipients, access and retention and keep data accurate and no longer than necessary subject to AML clocks.
- Preuves à conserver
- Processing register, basis assessment, notice, access matrix and retention mapping.
- Source primaire
- Law 3/2016, Articles 5-6 and 18
Apply the statutory regime to sensitive and biometric data.
- Action d’implémentation
- Complete a specific legal and security assessment before collecting biometrics, national identifiers, offence data or other sensitive information and obtain any required authority approval.
- Preuves à conserver
- Data classification, legal assessment, authority record, security design and access review.
- Source primaire
- Law 3/2016
Control disclosures and cross-border transfers.
- Action d’implémentation
- Map hosting, support and recipient locations, document the statutory transfer basis and safeguards and obtain any required authority authorisation before exporting personal data.
- Preuves à conserver
- Transfer map, contracts, safeguards, authority record and access logs.
- Source primaire
- Law 3/2016, cross-border transfer provisions
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting Law 8/2013, Articles 10-20
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, approvals, FIU reports, delivery evidence and post-filing controls while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting Law 8/2013, Articles 21-22
Maintain a launch and legal-change pack.
- Action d’implémentation
- Record licensing, thresholds, sanctions, registry and privacy procedures, testing and authority confirmations before launch and material changes.
- Preuves à conserver
- Signed launch pack, source register, uncertainty log and change approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
11 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 8/2013 on prevention and combating money laundering and terrorist financingFinancial Intelligence Unit of São Tomé and Príncipe · Primary legislation
- UIF legislation repositoryFinancial Intelligence Unit of São Tomé and Príncipe · Official FIU repository
- UIF suspicious-activity contact and COS form pageFinancial Intelligence Unit of São Tomé and Príncipe · Official FIU procedure
- São Tomé and Príncipe 2024 Mutual Evaluation ReportGIABA · Authoritative regional assessment
- Law No. 3/2018 against terrorism and its financingFinancial Intelligence Unit of São Tomé and Príncipe · Primary legislation
- Law No. 17/2018 - legal regime of the national payment systemCentral Bank of São Tomé and Príncipe · Primary legislation
- Decree-Law No. 16/2019 - payment service providers and system operatorsCentral Bank of São Tomé and Príncipe · Primary legislation
- Guiché Único business-registration requirementsDirectorate-General of Registries and Notaries · Official registry guidance
- Law No. 3/2016 on protection of personal dataWHO Country Planning Cycle Database · Primary legislation copy
- FATF high-risk and monitored jurisdictions current at 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Sao Tomé-et-Principe
Who receives suspicious transaction reports?+
The Financial Intelligence Unit (UIF), using its current institutional form and filing channel.
When is suspicion reported?+
Immediately once suspicion or reasonable grounds arise, including attempted transactions and regardless of amount.
Is there a general cash transaction report threshold?+
The 2024 GIABA assessment states that cash transaction reporting was not a general requirement. Cash remains subject to CDD, monitoring and STR duties, and current sector instructions must be checked.
How is beneficial ownership determined?+
Identify and verify the natural person who ultimately owns or effectively controls the customer. Because the national cascade and central-register framework have gaps, document both ownership and control and use a conservative senior-manager fallback where needed.
How long are core AML records retained?+
At least five years: CDD records after relationship end or the occasional transaction, and transaction records after the transaction or attempt.
What privacy law applies?+
Law No. 3/2016 governs personal-data processing, including purpose, quality, security, secrecy and international transfers.
Is São Tomé and Príncipe on a FATF public list?+
No. It was not named in FATF's public lists dated 19 June 2026. This does not make it low risk.
Can a payment or fintech service launch without approval?+
No. Classify the service, provider and agent model under Law No. 17/2018 and Decree-Law No. 16/2019 and obtain all applicable approvals first.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 8 September 2026. Confirm current Central Bank instruments, FIU institutional filing access, sanctions-gazette workflow, company-register practice, personal-data authority procedures and product-specific permissions with the competent authority and qualified São Toméan counsel before launch.