Seychelles KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Seychelles.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Seychelles ?
La checklist pour Seychelles traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 34 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML/CFT law
- AML/CFT Act 2020, revised to 17 January 2025
- Financial intelligence unit
- Seychelles Financial Intelligence Unit
- STR timing
- Within two business days of suspicion, grounds or information
- One-off CDD threshold
- Above SCR 50,000 in cash or wire transfers, including linked operations
- Cash and wire reports
- SCR 50,000 or more, subject to the exact Schedule 3 scope
- Core AML retention
- Minimum seven years; specified sectors retain digital records for 30 years
- Beneficial ownership
- 10% ownership/control plus control, board-appointment and fallback tests
- Privacy breach notice
- Information Commission within 72 hours; delayed notices need reasons
- VASP perimeter
- FSA licence required for in-scope services under the VASP Act 2024
- FATF public lists
- Not named in the June 2026 public statements
Détail d’implémentation
Exigences et actions de conformité pour Seychelles
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before launch.3 éléments+
Financial institutions, VASPs and listed non-financial businesses and professions may be reporting entities.
- Action d’implémentation
- Map each entity, product, profession, branch, agent and outsourced service to the Act's reporting-entity definition and supervisory allocation.
- Preuves à conserver
- Perimeter memorandum, entity-product map, licences and supervisor confirmation.
- Source primaire
- AML/CFT Act 2020, s.2 and First Schedule, as revised
The FIU receives and analyses reports and may request records; CBS and FSA supervise activities within their statutory remits.
- Action d’implémentation
- Register compliance contacts and obtain the current reporting and supervisory instructions for each entity.
- Preuves à conserver
- FIU access, correspondence, supervisor register and regulatory calendar.
- Source primaire
- AML/CFT Act 2020, ss.10-13 and 48; official CBS and FSA frameworks
Virtual asset services in or from Seychelles require the applicable FSA licence under the 2024 framework.
- Action d’implémentation
- Obtain a written perimeter decision and licence before offering exchange, transfer, custody or other in-scope virtual-asset services.
- Preuves à conserver
- Classification, application, licence, conditions and approved service map.
- Source primaire
- Virtual Asset Service Providers Act 2024; FSA VASP legal framework and FAQs
02Governance, risk assessment and control ownershipBuild documented, risk-based and accountable controls.2 éléments+
Reporting entities must appoint a compliance officer and alternate and maintain an institutional risk assessment.
- Action d’implémentation
- Appoint qualified officers, document authority and assess customer, product, channel, geography and delivery risks before launch and on change.
- Preuves à conserver
- Appointments, fit-and-proper records, risk assessment, approvals and review log.
- Source primaire
- AML/CFT Act 2020, ss.32 and 34; AML/CFT Regulations 2020
Internal controls, employee screening, training and independent testing must be proportionate to risk.
- Action d’implémentation
- Approve a group-aware programme and independently test design and operating effectiveness.
- Preuves à conserver
- Policies, training, screening, audit reports and remediation register.
- Source primaire
- AML/CFT Act 2020, ss.31-34; AML/CFT Regulations 2020
03Natural-person identification and CDDApply statutory triggers without treating thresholds as safe harbours.4 éléments+
CDD applies to relationships, every qualifying one-off transaction, identity doubt and suspicion.
- Action d’implémentation
- Configure relationship, transaction, linked-operation, suspicion and identity-quality triggers and record the applicable basis.
- Preuves à conserver
- Trigger matrix, aggregation results, identity file and decision timestamps.
- Source primaire
- AML/CFT Act 2020, ss.35 and 49
A one-off transaction exceeds SCR 50,000 in cash or wire transfers, singly or through apparently linked operations.
- Action d’implémentation
- Aggregate linked activity and apply CDD regardless of amount where suspicion or identity doubt exists.
- Preuves à conserver
- Aggregation logic, alerts, CDD file and override record.
- Source primaire
- AML/CFT Act 2020, s.49(1)-(2)
Identity must be identified and verified from reliable, independent or otherwise reasonably reliable sources.
- Action d’implémentation
- Capture required identity attributes and authenticate evidence proportionately to risk.
- Preuves à conserver
- Identity evidence, authenticity result, provenance and risk decision.
- Source primaire
- AML/CFT Act 2020, s.35(2)(a)
CDD is completed before or during establishment or a one-off transaction; limited delayed verification needs documented risk controls and prompt completion.
- Action d’implémentation
- Block unrestricted use until verification is complete and document each statutory condition and limit.
- Preuves à conserver
- Verification timestamp, restrictions, exception approval and completion log.
- Source primaire
- AML/CFT Act 2020, s.39
04KYB, authority and beneficial ownershipVerify existence, authority and ultimate natural-person ownership or control.4 éléments+
Legal-person CDD covers name, legal form, existence, governing powers, senior managers, registered office and principal place of business.
- Action d’implémentation
- Obtain current registry and constitutive evidence and reconcile directors, mandates and addresses.
- Preuves à conserver
- Registry extract, certificate, constitution, directors and discrepancy log.
- Source primaire
- AML/CFT Act 2020, s.35(4)
A representative's authority and identity must be verified.
- Action d’implémentation
- Verify each actor and reconcile the mandate to current board or constitutive authority.
- Preuves à conserver
- Identity file, mandate, board resolution and verification result.
- Source primaire
- AML/CFT Act 2020, s.35(4)(b)-(c)
For legal persons, BO determination includes natural persons with 10% or more ownership or control, majority-board appointment rights, other control and a senior-manager fallback.
- Action d’implémentation
- Trace every ownership layer and test ownership, voting, appointment and other-control paths before applying the fallback.
- Preuves à conserver
- Ownership chart, registry records, control analysis and BO identity files.
- Source primaire
- Beneficial Ownership Regulations 2020, reg.3, as consolidated
Trusts and other legal arrangements use role-based tests rather than the 10% legal-person threshold.
- Action d’implémentation
- Identify and verify the settlor, trustees, protector where applicable, beneficiaries or class and every other person exercising ultimate control.
- Preuves à conserver
- Trust instrument, role register, identity files and control analysis.
- Source primaire
- Beneficial Ownership Regulations 2020, reg.3(6)-(7), as consolidated
05PEPs, enhanced due diligence and relianceApply stronger controls to higher-risk relationships.3 éléments+
Domestic, foreign and international-organisation PEPs, immediate family and close associates require EDD and enhanced monitoring.
- Action d’implémentation
- Screen customers and BOs, obtain senior-management approval and establish source of wealth and source of funds.
- Preuves à conserver
- Screening, match rationale, source file, approval and monitoring plan.
- Source primaire
- AML/CFT Act 2020, s.36
Higher-risk situations and relevant higher-risk countries require risk-sensitive EDD.
- Action d’implémentation
- Document enhanced evidence, corroboration, approval and monitoring frequency.
- Preuves à conserver
- EDD standard, jurisdiction assessment, approvals and alert tuning.
- Source primaire
- AML/CFT Act 2020, s.41
Reliance does not transfer responsibility; required information is immediate and copies must be available within three working days of request.
- Action d’implémentation
- Assess the regulated person, contract for access and test document retrieval.
- Preuves à conserver
- Due diligence, agreement, retrieval test and exception log.
- Source primaire
- AML/CFT Act 2020, s.42
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity and report suspicion promptly and confidentially.4 éléments+
Failed CDD prevents a transaction or relationship and requires termination where applicable.
- Action d’implémentation
- Block or terminate under controlled procedures and refer the case for confidential STR assessment.
- Preuves à conserver
- Failure reason, block, closure, STR decision and receipt.
- Source primaire
- AML/CFT Act 2020, s.43
Relationships require ongoing scrutiny, current CDD and examination of complex, unusual or large activity without apparent purpose.
- Action d’implémentation
- Investigate, document background and purpose, refresh CDD and escalate suspicion.
- Preuves à conserver
- Alerts, cases, written findings, refreshed CDD and approvals.
- Source primaire
- AML/CFT Act 2020, s.46
Transactions and attempted transactions linked to criminal conduct, ML or TF are reportable to the FIU within two business days.
- Action d’implémentation
- Record when grounds, suspicion or information arose and submit using the current FIU route within the statutory clock.
- Preuves à conserver
- Internal report, analysis, STR, FIU acknowledgement and timeline.
- Source primaire
- AML/CFT Act 2020, s.48(1)-(4)
Tipping off is prohibited.
- Action d’implémentation
- Restrict case access and govern customer communications, holds and lawful disclosures.
- Preuves à conserver
- Access logs, communications plan, training and disclosure register.
- Source primaire
- AML/CFT Act 2020, s.50
07Wires, thresholds, payments and agentsKeep CDD, transaction records and threshold reports distinct.3 éléments+
Cash transactions of SCR 50,000 or more by reporting entities and specified wire transfers of SCR 50,000 or more are reported under Schedule 3.
- Action d’implémentation
- Configure the exact entity, direction, transaction and aggregation scope; obtain FIU instructions for format and exemptions.
- Preuves à conserver
- Threshold matrix, configuration, reports, acknowledgements and exemption record.
- Source primaire
- AML/CFT Act 2020, s.5 and Schedule 3
Wire transfers carry required originator and beneficiary information and deficient transfers follow risk-based reject, suspend, execute and follow-up rules.
- Action d’implémentation
- Validate fields throughout the payment chain and govern repair or rejection.
- Preuves à conserver
- Field matrix, validation, repair queue and transaction samples.
- Source primaire
- AML/CFT Act 2020, ss.45-45A
Payment, remittance, e-money, agent and fintech models require current activity-specific authority.
- Action d’implémentation
- Do not launch until CBS, FSA or the competent authority confirms every required licence and agent condition.
- Preuves à conserver
- Perimeter advice, application, licence, agent register and monitoring.
- Source primaire
- Official CBS and FSA regulatory frameworks; activity-specific dependency
08Targeted financial sanctions and CPFOperate current screening, freezing and reporting controls.2 éléments+
Seychelles implements targeted financial sanctions through the Prevention of Terrorism and UN implementation framework.
- Action d’implémentation
- Screen customers, BOs, representatives and transactions against current UN and domestic designations and escalate potential matches immediately.
- Preuves à conserver
- List provenance, screening logs, match decisions, holds and authority correspondence.
- Source primaire
- Prevention of Terrorism Act and UN Security Council implementation regulations; CBS AML/CFT framework
Operational freeze, false-positive, reporting and CPF handling must follow the current competent-authority instructions.
- Action d’implémentation
- Maintain a 24/7 escalation route and obtain written instructions before release or dealing with potentially affected property.
- Preuves à conserver
- Procedure, escalation log, instruction, decision and audit trail.
- Source primaire
- Controlled implementation dependency; confirm with FIU and competent authority
09Records, access and assuranceRetain reconstructable evidence under the correct clock.3 éléments+
CDD, transaction, FIU-report and enquiry records are retained for at least seven years under record-class-specific clocks.
- Action d’implémentation
- Map each class to identity collection, transaction or correspondence, or relationship cessation and apply legal holds.
- Preuves à conserver
- Retention schedule, configuration, samples and deletion tests.
- Source primaire
- AML/CFT Act 2020, s.47(1)-(2)
Banks, bureaux de change, insurance companies and securities-exchange infrastructures retain specified records digitally for 30 years after relationship cessation.
- Action d’implémentation
- Apply this sector-specific overlay only to in-scope entities and preserve readable, authenticated records.
- Preuves à conserver
- Entity mapping, archive configuration, integrity and retrieval tests.
- Source primaire
- AML/CFT Act 2020, s.47(3)-(5)
Records must reconstruct transactions and be immediately available to FIU or competent authorities.
- Action d’implémentation
- Index linked identity, transaction, investigation and reporting evidence and test retrieval.
- Preuves à conserver
- Request register, retrieval tests, access controls and response package.
- Source primaire
- AML/CFT Act 2020, s.47(4)-(6)
10Privacy, biometrics and transfersApply the Data Protection Act alongside AML retention and access duties.4 éléments+
Personal data processing requires a lawful basis, minimisation, quality, security, accountability and purpose controls.
- Action d’implémentation
- Document purpose and basis, minimise collection, restrict access and reconcile privacy retention with statutory AML duties.
- Preuves à conserver
- Data inventory, processing record, notices, access matrix and retention mapping.
- Source primaire
- Data Protection Act 2023, ss.15-21
Biometrics are sensitive data and processing is prohibited unless a section 22 exception applies.
- Action d’implémentation
- Document the exact exception, necessity and safeguards before biometric onboarding and complete an impact assessment where high risk.
- Preuves à conserver
- Legal basis, consent where used, DPIA, model tests and access logs.
- Source primaire
- Data Protection Act 2023, ss.2, 22 and 38
The Information Commission must be notified of a personal-data breach within 72 hours of awareness; delay requires reasons, and affected people are promptly informed where the statutory risk test is met.
- Action d’implémentation
- Timestamp awareness, assess impact and operate regulator and data-subject notification playbooks.
- Preuves à conserver
- Incident log, assessment, notifications, delivery evidence and remediation.
- Source primaire
- Data Protection Act 2023, ss.43-44
Cross-border transfers require a comparable level of protection and compliance with section 47 conditions.
- Action d’implémentation
- Assess destination protection, document transfer purpose, notify data subjects where required and obtain Commission authority where applicable.
- Preuves à conserver
- Transfer assessment, data map, notices, contracts and Commission correspondence.
- Source primaire
- Data Protection Act 2023, s.47
11Practical evidence packs and change controlMake decisions reconstructable and keep time-sensitive rules current.2 éléments+
A complete customer file links identity, KYB, ownership, screening, risk, approval, monitoring and reporting decisions.
- Action d’implémentation
- Block activation when mandatory evidence or approval is missing and preserve the release decision.
- Preuves à conserver
- Control checklist, linked file, approvals and release log.
- Source primaire
- AML/CFT Act 2020, Parts VI-VII
FIU directions, thresholds, sanctions lists, FATF status, privacy guidance, registry and licensing requirements require ongoing monitoring.
- Action d’implémentation
- Assign owners and review FIU, CBS, FSA, Registration Division, Information Commission, Gazette, FATF and ESAAMLG sources on a governed schedule.
- Preuves à conserver
- Legal inventory, source log, change assessments and implementation tickets.
- Source primaire
- Official sources listed below
Registre des sources primaires
12 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Consolidated AML/CFT Act 2020, revised to 17 January 2025Central Bank of Seychelles · Primary legislation - official consolidated copy
- Consolidated AML/CFT Regulations 2020 to 17 January 2025Seychelles Financial Intelligence Unit · Primary legislation - official FIU library
- CBS AML/CFT regulatory frameworkCentral Bank of Seychelles · Official regulator framework
- Beneficial Ownership Act 2020Seychelles Registration Division · Primary legislation - official registry source
- Beneficial Ownership legislation and consolidated regulationsSeychelles Financial Intelligence Unit · Primary legislation and official FIU resource
- Beneficial ownership guidance and consolidated frameworkFinancial Services Authority · Official regulator guidance
- Data Protection Act 2023Seychelles Official Gazette · Primary legislation
- Information CommissionSeychelles Information Commission · Official privacy authority
- Virtual Asset Service Providers legal frameworkFinancial Services Authority · Primary legislation and official regulator guidance
- Virtual Asset Service Providers FAQsFinancial Services Authority · Official regulator guidance
- Jurisdictions under Increased Monitoring - June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - June 2026FATF · Authoritative public statement
Réponses directes
Questions KYC, KYB et AML pour Seychelles
Who receives suspicious transaction reports in Seychelles?+
The Seychelles Financial Intelligence Unit, using its current reporting route and prescribed format.
When is an STR due?+
Within two business days of ascertaining reasonable grounds, forming suspicion or receiving relevant information; attempted transactions are included regardless of amount.
What is the one-off CDD threshold?+
A one-off cash or wire transaction above SCR 50,000, including apparently linked operations; suspicion and identity doubt trigger CDD regardless of amount.
What beneficial-ownership threshold applies to legal persons?+
The consolidated BO framework uses 10% ownership or control, plus board-appointment, other-control and senior-management fallback tests. Trusts and other legal arrangements use role-based tests.
How long are AML records kept?+
At least seven years under record-class-specific clocks. Banks, bureaux de change, insurers and securities-exchange infrastructures also have a 30-year digital-retention overlay after relationship cessation.
Are VASPs licensed in Seychelles?+
Yes. In-scope virtual asset services in or from Seychelles require the applicable FSA licence under the VASP Act 2024; obtain an activity-specific perimeter decision.
When must a personal-data breach be reported?+
The Information Commission must be notified within 72 hours after awareness, with reasons for delay; affected individuals are promptly informed where the section 44 test is met.
Is Seychelles on a FATF public list?+
Seychelles was not named in FATF's June 2026 increased-monitoring or call-for-action statements.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
This checklist is general regulatory information, not legal advice or a licence determination. It reflects primary and authoritative sources reviewed on 22 July 2026. Confirm the current FIU reporting portal, exemption mechanics, sector-specific supervision, sanctions and CPF procedure, registry filing workflow, Data Protection Act implementation guidance and each activity-specific licence with Seychelles counsel and the competent authority before launch. VOVE ID supports evidence collection and audit trails; the reporting entity remains responsible for acceptance, reporting, restraint and compliance decisions.