Somalie KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Somalie.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Somalie ?
La checklist pour Somalie traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 43 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Financial Reporting Center (FRC)
- Primary AML rule
- AML/CFT Amendment Act, 2025
- Suspicion reporting
- Promptly to FRC, including attempts and regardless of amount
- CDD thresholds
- USD 10,000 occasional/linked; USD 1,000 occasional wire
- Core AML retention
- At least 5 years under record-specific clocks
- FATF status
- Not named on FATF public lists at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Somalie
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve federal coverage, supervisor and licensing before launch.3 éléments+
Map each entity and activity to the reporting-entity perimeter.
- Action d’implémentation
- Classify financial institutions, covered DNFBPs and virtual-asset service providers under Article 4 and identify the FRC and designated competent supervisor for each activity.
- Preuves à conserver
- Applicability memo, entity and product map, supervisor matrix and accountable owner.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 4 and 23
Register and report through the current FRC channel.
- Action d’implémentation
- Register the reporting organisation and authorised users in the production goAML portal, follow current FRC guidance and preserve submission acknowledgements.
- Preuves à conserver
- goAML registration, reporter mandate, access controls, channel test and receipts.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 14 and 21; FRC goAML portal
Obtain approval before regulated financial or payment activity.
- Action d’implémentation
- Classify banking, money transfer, mobile money, payment, microfinance, takaful, agent, outsourcing and virtual-asset activities and obtain every applicable federal licence or approval before launch.
- Preuves à conserver
- Perimeter analysis, CBS or other licence, conditions, agent approvals and renewal calendar.
- Source primaire
- Financial Institutions Law 2025; CBS regulatory guidelines; AML/CFT Amendment Act 2025, Article 4
02Governance and risk assessmentControls must be approved, risk-based, resourced and independently tested.3 éléments+
Maintain a written AML/CFT programme.
- Action d’implémentation
- Implement senior-management-approved policies, a sufficiently senior and resourced compliance officer, employee screening, documented training and independent audit.
- Preuves à conserver
- Signed policy suite, officer mandate, resources, screening, training and audit reports.
- Source primaire
- AML/CFT Amendment Act 2025, Article 17
Assess institutional risk at least annually.
- Action d’implémentation
- Document customer, geography, product, service, transaction, delivery-channel and technology risks annually, before new-product launch, on material change and when required by the supervisor.
- Preuves à conserver
- Risk methodology, annual assessment, launch assessments, approvals and remediation.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 9 and 9A
Control group, agent and outsourced implementation.
- Action d’implémentation
- Apply group-wide information-sharing and control standards where applicable; contract, train and monitor agents and outsourced providers without transferring accountability.
- Preuves à conserver
- Group policy, contracts, agent register, monitoring, retrieval tests and exceptions.
- Source primaire
- AML/CFT Amendment Act 2025, Article 17; CBS Mobile Money Regulation, regulation 32-33
03Natural-person identificationIdentify and verify customers and representatives at every statutory trigger.4 éléments+
Identify and verify customers from reliable independent evidence.
- Action d’implémentation
- Capture identity attributes, verify them using reliable independent documents, data or information, and record purpose and intended nature before establishing the relationship.
- Preuves à conserver
- CDD file, evidence provenance, purpose, expected activity and decision timestamp.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(1)
Apply CDD to occasional and linked transactions at USD 10,000.
- Action d’implémentation
- Aggregate apparently linked operations and complete CDD at or above USD 10,000 equivalent; apply CDD regardless of amount for suspicion or doubt about prior identification data.
- Preuves à conserver
- Threshold table, aggregation logic, alerts, CDD timestamps and exchange-rate record.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(2)(b), (c) and (e)
Apply CDD to occasional wire transfers at USD 1,000.
- Action d’implémentation
- Identify and verify for occasional wire transfers at or above USD 1,000 equivalent and do not treat the threshold as a monitoring safe harbour.
- Preuves à conserver
- Wire trigger rule, identity evidence, aggregation and transaction record.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(2)(d)
Verify representatives and authority.
- Action d’implémentation
- Identify and verify each person acting for a customer and validate the mandate before allowing activity.
- Preuves à conserver
- Identity evidence, mandate, authority verification and expiry control.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(1)(b)
04KYB, registries, and beneficial ownershipVerify existence, authority, ownership, control and registry filings.5 éléments+
Verify legal-person identity and authority.
- Action d’implémentation
- Obtain current Company Registry evidence, proof of existence, legal form, governing powers, registered and principal addresses, senior managers, licences and mandates, and resolve inconsistencies.
- Preuves à conserver
- Registry extract, constitutional documents, officer list, licences and discrepancy log.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(7); Company Law 2019
Apply the statutory beneficial-owner cascade.
- Action d’implémentation
- Identify and verify the natural person exercising ultimate control through ownership; if none or doubt remains, identify control through other means; if no natural person is identified, record the relevant senior managing official.
- Preuves à conserver
- Ownership chart, control analysis, verified identities and fallback rationale.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(8)(a)
Identify trust and arrangement role holders.
- Action d’implémentation
- Identify and verify settlor, trustees, protector if any, beneficiaries or class, and every other natural person exercising ultimate effective control.
- Preuves à conserver
- Trust instrument, role register, verified identities and control analysis.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(8)(b)-(c)
Reconcile beneficial-owner registry information.
- Action d’implémentation
- Obtain the customer's electronic Company Registry and beneficial-owner filings, compare them with declarations and independent evidence, and investigate discrepancies.
- Preuves à conserver
- Registry evidence, declarations, corroboration and discrepancy resolution.
- Source primaire
- AML/CFT Amendment Act 2025, Article 23C(1)-(3); MOCI Beneficial Ownership Registry
Control one-month registry change deadlines.
- Action d’implémentation
- For Somali legal persons, file basic and beneficial-owner changes electronically as soon as reasonably practicable and within one month, and notify reporting entities of BO changes within one month of awareness.
- Preuves à conserver
- Change chronology, electronic filing, receipt and customer notification.
- Source primaire
- AML/CFT Amendment Act 2025, Article 23C(1)(b), (e) and (h)
05PEPs, EDD, and failed CDDHigher-risk relationships require approval, source evidence and enhanced monitoring.4 éléments+
Detect PEP exposure for customers and beneficial owners.
- Action d’implémentation
- Use appropriate risk systems to identify foreign, domestic and international-organisation PEPs and relevant family members and close associates.
- Preuves à conserver
- Screening, relationship map, match decision and refresh history.
- Source primaire
- AML/CFT Amendment Act 2025, Article 10(1)-(2)
Apply approval, source and monitoring controls.
- Action d’implémentation
- For foreign PEPs and higher-risk domestic or international PEP relationships, obtain senior approval, establish source of wealth and source of funds, review relevant information and conduct enhanced ongoing monitoring.
- Preuves à conserver
- Approval, source analysis, corroboration and monitoring plan.
- Source primaire
- AML/CFT Amendment Act 2025, Article 10(2)
Apply enhanced measures to higher-risk activity.
- Action d’implémentation
- Document proportionate enhanced measures for higher-risk relationships, complex or unusually large transactions, purposeless patterns and designated higher-risk jurisdictions.
- Preuves à conserver
- Risk rationale, enhanced measures, transaction review and approval.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 8 and 11
Stop or terminate when required CDD cannot be completed.
- Action d’implémentation
- Do not open, commence or perform the occasional transaction, or terminate the relationship, and submit an STR to the FRC while protecting confidentiality.
- Preuves à conserver
- Restriction or exit decision, investigation, STR and receipt.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(10)
06Monitoring and suspicious reportingFRC reporting must be prompt, complete, confidential and traceable.4 éléments+
Monitor activity against the customer profile.
- Action d’implémentation
- Scrutinise transactions throughout the relationship for consistency with known business, risk profile and source of funds, keeping higher-risk CDD current.
- Preuves à conserver
- Alerts, investigation notes, supporting data, dispositions and refresh history.
- Source primaire
- AML/CFT Amendment Act 2025, Article 5(1)(e)
Report suspicion and attempts promptly.
- Action d’implémentation
- Timestamp when suspicion or reasonable grounds arose and promptly report all relevant details to the FRC, including attempted transactions and regardless of amount.
- Preuves à conserver
- Decision chronology, STR, goAML delivery evidence and receipt.
- Source primaire
- AML/CFT Amendment Act 2025, Article 14(1)
Report suspected structuring promptly.
- Action d’implémentation
- Detect and report transactions, attempts or series designed to evade statutory or regulatory reporting requirements.
- Preuves à conserver
- Aggregation rules, alert, analysis, report and receipt.
- Source primaire
- AML/CFT Amendment Act 2025, Article 14(2A)
Prevent tipping off.
- Action d’implémentation
- Restrict report access and do not disclose that an STR or related information has been or is being reported to the FRC or competent supervisor.
- Preuves à conserver
- Need-to-know access, communications controls, training and audit log.
- Source primaire
- AML/CFT Amendment Act 2025, Article 15(2)
07Payments, wires, thresholds, and agentsKeep CDD, cash-reporting, border and wire thresholds distinct.5 éléments+
Implement the current FRC large-cash reporting rule.
- Action d’implémentation
- Obtain the current threshold, scope, aggregation, form and deadline from FRC regulations and LCTR guidance before configuration; do not infer the amount from the USD 10,000 CDD or border-declaration thresholds.
- Preuves à conserver
- Current instrument, configuration approval, LCTR or NIL reports and receipts.
- Source primaire
- AML/CFT Amendment Act 2025, Article 14(2)-(3); FRC LCTR guidance
Declare cross-border cash and bearer instruments at USD 10,000.
- Action d’implémentation
- Inform relevant travellers and logistics operations that USD 10,000 or more, or equivalent, entering or leaving Somalia by person, mail, courier or otherwise requires a truthful written customs declaration.
- Preuves à conserver
- Travel or shipment procedure, declaration, supporting records and escalation.
- Source primaire
- AML/CFT Amendment Act 2025, Article 18(1)
Carry complete originator and beneficiary wire information.
- Action d’implémentation
- Collect and include the statutory names, account or unique reference, originator address or alternative identifier and beneficiary information; verify the originator at or above USD 1,000 unless already verified in an existing relationship.
- Preuves à conserver
- Field matrix, validation rules, identity evidence and transfer samples.
- Source primaire
- AML/CFT Amendment Act 2025, Article 19(1)-(2)
Control deficient wire transfers.
- Action d’implémentation
- Detect missing information, seek and verify repair data, and apply documented execute, reject, suspend, follow-up and reporting decisions.
- Preuves à conserver
- Repair queue, decision rules, samples, escalations and STRs.
- Source primaire
- AML/CFT Amendment Act 2025, Article 19(3)-(6)
Control mobile-money and money-transfer agents.
- Action d’implémentation
- Verify provider and agent authority, contract for AML, records, audit, privacy and incident controls, continuously monitor agents and retain provider responsibility.
- Preuves à conserver
- CBS approvals, agent register, contracts, training, monitoring and incidents.
- Source primaire
- CBS Mobile Money Regulation 2020, regulations 32-33; MTB Operations Regulation 2016
08Targeted financial sanctionsUse current UN and Somali lists and act without delay.3 éléments+
Screen UN and national designations continuously.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, before activity and on updates against current UN and FRC/NAMLC lists.
- Preuves à conserver
- List inventory, update log, screening configuration, alerts and dispositions.
- Source primaire
- Targeted Financial Sanctions Act 2023; FRC targeted-sanctions regulations and lists
Freeze designated property and prevent availability.
- Action d’implémentation
- Freeze property owned or controlled by designated persons or entities without delay and prevent direct or indirect funds, assets or services from being made available, subject to current legal instructions.
- Preuves à conserver
- Alert chronology, ownership/control analysis, freeze record and blocked-availability controls.
- Source primaire
- Targeted Financial Sanctions Act 2023; FRC targeted-sanctions regulations
Report matches immediately and preserve review rights.
- Action d’implémentation
- Immediately send the required report to FRC through the current route, retain all supporting information, and apply current false-positive, delisting, exemption and release procedures.
- Preuves à conserver
- Report, receipt, authority correspondence, review and release decision.
- Source primaire
- FRC Financial Sanctions Targets List; FRC account-freezing guideline
09Records and regulator accessRecords must reconstruct customers, transactions, analysis and decisions.4 éléments+
Retain transaction records for at least five years.
- Action d’implémentation
- Apply a transaction-date clock to domestic and international transaction records sufficient to reconstruct amounts, currencies and parties.
- Preuves à conserver
- Retention schedule, archive sample, reconstruction test and legal holds.
- Source primaire
- AML/CFT Amendment Act 2025, Article 13(1)
Retain CDD and analysis for at least five years after the relationship or occasional transaction.
- Action d’implémentation
- Preserve customer and account files, business correspondence and analysis under the correct relationship-end or occasional-transaction clock.
- Preuves à conserver
- Archive configuration, closure trigger, deletion control and retrieval log.
- Source primaire
- AML/CFT Amendment Act 2025, Article 13(2)
Apply the separate ten-year company and trust clocks.
- Action d’implémentation
- Somali legal persons, Registry and relevant custodians must preserve specified basic and BO information for ten years after dissolution; professional trustees retain specified trust information for ten years after involvement ceases.
- Preuves à conserver
- Corporate and trust retention mapping, archive samples and dissolution records.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 23C(5) and 23D(1)(e)
Provide records promptly under proper authority.
- Action d’implémentation
- Authenticate requests, protect STR confidentiality, produce controlled records to FRC and competent supervisors or authorities and log scope, approval, delivery and receipt.
- Preuves à conserver
- Request register, authority check, production index and acknowledgement.
- Source primaire
- AML/CFT Amendment Act 2025, Articles 13(3), 21 and 23B
10Privacy, biometrics, and transfersAML processing remains subject to the Data Protection Act 2023 and current regulations.5 éléments+
Register regulated processing roles where required.
- Action d’implémentation
- Determine whether the organisation, processor and data protection officer require registration with the Somalia Data Protection Authority and complete current registration and renewal procedures.
- Preuves à conserver
- Role analysis, registration, DPO mandate, renewal and correspondence.
- Source primaire
- Data Protection Act No. 005 of 2023; SDPA registration guidance
Document lawful, fair and proportionate processing.
- Action d’implémentation
- Inventory identity, ownership, screening, biometric, monitoring and reporting data; record purpose, lawful basis, minimisation, accuracy, recipients, access and AML-aligned retention.
- Preuves à conserver
- Processing register, basis assessment, notice, access matrix and retention mapping.
- Source primaire
- Data Protection Act No. 005 of 2023
Assess high-risk and sensitive processing.
- Action d’implémentation
- Complete a data-protection impact and security assessment before biometric, national-identifier, criminal-offence or other high-risk processing and apply current DPA approval or DPO requirements.
- Preuves à conserver
- Data classification, DPIA, DPO review, security design and authority record.
- Source primaire
- Data Protection Act No. 005 of 2023; SDPA guidance
Notify personal-data breaches through the current route.
- Action d’implémentation
- Detect, contain, assess and document breaches and notify the DPA within the applicable 72-hour procedure where required, including delayed-notification reasons and affected-person communications.
- Preuves à conserver
- Incident chronology, risk assessment, DPA notice, receipt and communications.
- Source primaire
- SDPA official breach service and guidance
Control processors, disclosures and cross-border transfers.
- Action d’implémentation
- Map hosting and support locations, bind processors, document transfer conditions and safeguards, and obtain any required DPA authorisation before exporting personal data.
- Preuves à conserver
- Processor diligence, contracts, transfer map, safeguards and authority record.
- Source primaire
- Data Protection Act No. 005 of 2023; SDPA cross-border guidance
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting AML/CFT Amendment Act 2025, Articles 5-13
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, approvals, reports, delivery evidence and post-filing controls while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting AML/CFT Amendment Act 2025, Articles 14-16
Maintain a launch and legal-change pack.
- Action d’implémentation
- Record licensing, thresholds, sanctions, registry, privacy and local-authority procedures, testing and confirmations before launch and material changes.
- Preuves à conserver
- Signed launch pack, source register, uncertainty log and change approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
12 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Anti-Money Laundering and Countering the Financing of Terrorism Amendment Act, 2025 - English translationCentral Bank of Somalia · Primary legislation
- AML/CFT laws, regulations, forms and reporting guidanceFinancial Reporting Center · Official FIU repository
- Production goAML reporting portal and guidanceFinancial Reporting Center · Official FIU procedure
- AML/CFT regulations for financial institutionsFinancial Reporting Center · Official regulation
- Targeted financial sanctions regulations and national listsFinancial Reporting Center · Official sanctions framework
- Current banking, money-transfer, mobile-money and financial-sector laws and regulationsCentral Bank of Somalia · Official regulator repository
- Mobile Money Services Regulation 2020, amended 2021Central Bank of Somalia · Official regulation
- Licensing, company registration and Beneficial Ownership RegistryMinistry of Commerce and Industry · Official registry guidance
- Data Protection Act No. 005 of 2023 and regulatory guidanceSomalia Data Protection Authority · Primary legislation and authority guidance
- Data Protection Authority services and breach procedureSomalia Data Protection Authority · Official privacy procedure
- FATF high-risk and monitored jurisdictions current at 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Somalie
Who receives suspicious transaction reports?+
Somalia's Financial Reporting Center (FRC), through the current production goAML channel and FRC procedure.
When is suspicion reported?+
Promptly once suspicion or reasonable grounds arise, including attempted transactions and regardless of amount.
What CDD thresholds apply?+
CDD applies at USD 10,000 for occasional or apparently linked transactions and at USD 1,000 for occasional wire transfers, as well as at relationship establishment, on suspicion regardless of amount, or when prior identification data is doubtful.
What is the large-cash reporting threshold?+
Article 14 leaves the operational amount and extensions to regulation. Obtain the current threshold and procedure from FRC LCTR guidance; do not infer it from the separate CDD or border thresholds.
How is beneficial ownership determined?+
Identify the natural person exercising ultimate control through ownership, then control through other means, and use the relevant senior managing official only where no natural person is identified through the first two steps.
How long are core AML records retained?+
At least five years for transactions and CDD under their separate statutory clocks. Certain company, registry and professional-trustee information has a ten-year clock.
What privacy law applies?+
Data Protection Act No. 005 of 2023 and current Somalia Data Protection Authority regulations and procedures.
Is Somalia on a FATF public list?+
No. Somalia was not named in FATF's public lists dated 19 June 2026. This does not make the jurisdiction low risk.
Can a financial, payment or virtual-asset service launch without approval?+
No. Classify the service and provider model under current federal laws and Central Bank or other sector rules and obtain every applicable licence or approval first.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 9 September 2026. Confirm commencement and official-language reconciliation of the 2025 AML/CFT amendments, current FRC reporting thresholds and goAML specifications, beneficial-owner registry procedures, sanctions-list operations, Data Protection Authority regulations and product-specific permissions with the competent federal authority and qualified Somali counsel before launch.