Soudan du Sud KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Soudan du Sud.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour Soudan du Sud ?
La checklist pour Soudan du Sud traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 40 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Financial Intelligence Unit established under the 2012 Act
- Primary AML rule
- AML/CTF Act No. 29 of 2012
- Suspicion reporting
- Within 24 hours after suspicion; before execution where possible
- Universal CDD threshold
- No current amount verified; identify customers under section 16
- Core AML retention
- At least 5 years from completion
- FATF status
- Increased monitoring at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Soudan du Sud
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the reporting-person perimeter, competent authority and product permissions before launch.3 éléments+
Map each entity and activity to the reporting-person perimeter.
- Action d’implémentation
- Classify banks, financial and microfinance institutions, cash dealers, insurers and intermediaries, securities and futures businesses, money transmitters, gaming operators, foreign-exchange bureaux, accountants, real-estate agents, precious-metal and stone dealers, customs officers, and in-scope legal professionals; confirm later Gazette designations.
- Preuves à conserver
- Entity and activity map, statutory category, supervisor, legal opinion and accountable owner.
- Source primaire
- AML/CTF Act 2012, section 5 definition of reporting person
Confirm the competent FIU reporting arrangement before go-live.
- Action d’implémentation
- Obtain current written FIU instructions for registration, form, secure delivery, acknowledgement, information requests and confidentiality; do not assume an online portal or receipt workflow where none is officially confirmed.
- Preuves à conserver
- Authority correspondence, reporter mandate, channel test, access controls and current instructions.
- Source primaire
- AML/CTF Act 2012, sections 6 and 8
Obtain every sector licence or approval before regulated activity.
- Action d’implémentation
- Classify banking, foreign exchange, money transfer, electronic money, mobile money, microfinance, insurance, payment, agent and outsourced activity and obtain current Bank of South Sudan or other authority approval before launch.
- Preuves à conserver
- Perimeter memo, licence, conditions, approvals, agent register and renewal calendar.
- Source primaire
- Banking Act 2012; Foreign Exchange Business Act 2012; Bank of South Sudan regulations and licensing materials
02Governance and risk assessmentGovernance should meet the Act, sector rules and the risk-based direction of current supervision.3 éléments+
Maintain internal suspicious-reporting procedures.
- Action d’implémentation
- Designate an officer, give that officer reasonable access to relevant information, require employees to escalate suspicion and require the designee to file qualifying reports.
- Preuves à conserver
- Board-approved procedure, officer mandate, access design, escalation tests and filing log.
- Source primaire
- AML/CTF Act 2012, section 19
Train relevant employees.
- Action d’implémentation
- Provide role-based training on applicable law, internal procedures, identifying suspicious activity, secure escalation and tipping-off restrictions, with refreshers proportionate to risk.
- Preuves à conserver
- Training content, attendance, assessments, refresh schedule and remediation.
- Source primaire
- AML/CTF Act 2012, section 20(1)
Document institutional risk and control effectiveness.
- Action d’implémentation
- Assess customer, geography, product, channel, transaction, agent and technology risks before launch and periodically; record enhanced measures for higher risks and independent control testing as a prudent response to South Sudan's FATF action plan and BoSS risk-based supervision.
- Preuves à conserver
- Risk methodology, assessment, approvals, monitoring, test report and remediation.
- Source primaire
- BoSS 2025 monetary and banking policy; FATF South Sudan statement, 19 June 2026; operational risk control
03Natural-person identificationSection 16 requires reliable official identity evidence and does not establish a verified monetary safe harbour.4 éléments+
Identify every customer using official evidence.
- Action d’implémentation
- Before a continuing relationship or transaction, obtain an official record reasonably capable of establishing true identity, including a birth certificate or affidavit and a passport or other official identification as applicable; verify authenticity and resolve inconsistencies.
- Preuves à conserver
- Identity record, verification result, provenance, discrepancy log and decision timestamp.
- Source primaire
- AML/CTF Act 2012, section 16(1)-(3)
Do not invent a universal CDD threshold.
- Action d’implémentation
- Apply identification to relationships and transactions within section 16 and obtain any current ministerial or supervisory threshold in writing before configuring amount-based exceptions or simplified measures.
- Preuves à conserver
- Current legal instruction, threshold configuration, version history and approval.
- Source primaire
- AML/CTF Act 2012, sections 16 and 28
Identify persons acting for another.
- Action d’implémentation
- Determine whether a customer acts for another person, verify the representative and mandate, and establish the true identity of the person for whose account or ultimate benefit the transaction is conducted.
- Preuves à conserver
- Representative identity, authority instrument, verification and ultimate-benefit analysis.
- Source primaire
- AML/CTF Act 2012, section 16(3)-(5)
Prevent anonymous or disguised accounts.
- Action d’implémentation
- Block false, disguised and anonymous names and test account-opening and migration controls for circumvention.
- Preuves à conserver
- System rule, rejected cases, migration review and test results.
- Source primaire
- AML/CTF Act 2012, section 20(1)
04KYB, registries, and beneficial ownershipVerify legal existence and ultimate benefit while treating the national beneficial-ownership framework as incomplete.4 éléments+
Verify corporate identity from current registry evidence.
- Action d’implémentation
- Obtain the memorandum and articles, certificate of incorporation, latest annual reports certified by the Directorate of Business Registry, registered office, directors, members and authorised signatories; reconcile all records.
- Preuves à conserver
- Certified registry pack, constitutional documents, officer and member lists, mandates and discrepancy log.
- Source primaire
- AML/CTF Act 2012, section 16(2)(c); Companies Act 2012
Identify persons behind nominees, agents and trustees.
- Action d’implémentation
- Take reasonable measures to establish the true identity of each person on whose behalf or for whose ultimate benefit the customer acts, including through trustee, nominee or agent arrangements.
- Preuves à conserver
- Ownership and control chart, declarations, corroboration, verified identities and rationale.
- Source primaire
- AML/CTF Act 2012, section 16(3)-(5)
Do not apply an unsupported beneficial-owner percentage.
- Action d’implémentation
- Use ownership, voting, contractual and other-control evidence to identify ultimate natural persons and escalate unresolved control; do not present a shareholder-register entry as verified beneficial ownership or invent a percentage threshold.
- Preuves à conserver
- Layered ownership chart, control analysis, source documents, escalation and senior approval.
- Source primaire
- AML/CTF Act 2012, section 16(4); FATF South Sudan statement, 19 June 2026
Maintain and reconcile company records.
- Action d’implémentation
- Collect current registered-office, member, director, share-register and accounting records required by the Companies Act and monitor changes using the current registry process.
- Preuves à conserver
- Registry extracts, statutory registers, corporate records, change receipts and reconciliation history.
- Source primaire
- Companies Act 2012, sections 154-160
05PEPs, EDD, and failed CDDForeign PEPs carry express controls; domestic and international-organisation exposure should be addressed through documented risk controls pending updated law.4 éléments+
Detect foreign PEP exposure.
- Action d’implémentation
- Use appropriate risk-management systems to determine whether the customer is a foreign PEP and screen relevant persons throughout the relationship.
- Preuves à conserver
- Screening configuration, match decision, relationship map and refresh log.
- Source primaire
- AML/CTF Act 2012, sections 5 and 16(1)(b)
Apply foreign-PEP approval, source and monitoring measures.
- Action d’implémentation
- Obtain senior-management approval, take reasonable measures to establish source of wealth and source of funds, and conduct enhanced ongoing monitoring.
- Preuves à conserver
- Approval, source analysis, corroboration and monitoring plan.
- Source primaire
- AML/CTF Act 2012, section 16(1)(b)
Control other higher-risk public-function exposure.
- Action d’implémentation
- As a risk-based control, identify domestic PEPs, international-organisation PEPs, family members and close associates and apply proportionate approval, source and monitoring measures; distinguish this control from the narrower express statutory definition.
- Preuves à conserver
- Policy basis, screening, relationship analysis, risk decision and approvals.
- Source primaire
- FATF Recommendation 12; operational risk control
Stop when identity or authority cannot be established.
- Action d’implémentation
- Do not onboard or transact where true identity, representation or ultimate benefit cannot be established; assess whether the facts create suspicion and document the report decision.
- Preuves à conserver
- Restriction, failed-verification record, escalation, decision and any STR receipt.
- Source primaire
- AML/CTF Act 2012, sections 16 and 18; operational risk control
06Monitoring and suspicious reportingSuspicion must reach the FIU within 24 hours and, where possible, before execution.4 éléments+
Monitor activity and investigate indicators.
- Action d’implémentation
- Monitor transactions and attempted activity against identity, purpose, ownership, expected activity and risk; preserve the information supporting each disposition.
- Preuves à conserver
- Monitoring rules, alerts, investigation notes, supporting data and dispositions.
- Source primaire
- AML/CTF Act 2012, sections 18-20; operational control
Report suspicion within 24 hours.
- Action d’implémentation
- Timestamp when suspicion or reasonable grounds arise, ascertain the purpose, origin, destination and ultimate beneficiary so far as reasonable, and securely report the transaction or proposed transaction to the FIU within 24 hours and before execution wherever possible.
- Preuves à conserver
- Suspicion chronology, analysis, STR, secure-delivery evidence and acknowledgement.
- Source primaire
- AML/CTF Act 2012, section 18(1)
Supply requested follow-up information.
- Action d’implémentation
- Authenticate FIU or law-enforcement requests and provide further information about a reported transaction through the authorised secure route while preserving confidentiality.
- Preuves à conserver
- Request, authority check, response package, delivery log and receipt.
- Source primaire
- AML/CTF Act 2012, section 18(2)
Prevent tipping off.
- Action d’implémentation
- Restrict access and do not warn an involved person or unauthorised third party that an STR may be prepared, is being prepared or has been sent, or disclose related protected information.
- Preuves à conserver
- Need-to-know controls, communications policy, training and access log.
- Source primaire
- AML/CTF Act 2012, section 21
07Payments, wires, thresholds, and agentsThresholds and payment permissions require current authority confirmation; the 2025 payment-system bill remained a draft in August 2026.5 éléments+
Obtain current transaction-record thresholds before configuration.
- Action d’implémentation
- Request the current Gazette order prescribing the amount under section 17; apply full records where the threshold cannot be verified and never infer it from another requirement.
- Preuves à conserver
- Gazette order or authority confirmation, configuration, version and approval.
- Source primaire
- AML/CTF Act 2012, section 17(1)(a)
Obtain the current cross-border cash threshold.
- Action d’implémentation
- Confirm the ministerially prescribed amount and the September 2025 BoSS cash-movement directive before traveller or corporate cash movement; preserve customs declarations and supporting records.
- Preuves à conserver
- Current directive, threshold table, declarations, source-of-funds support and escalation.
- Source primaire
- AML/CTF Act 2012, section 24; BoSS cash-movement directive, 17 September 2025
Preserve complete wire-transfer information.
- Action d’implémentation
- Pending verified detailed national wire rules, collect and transmit reliable originator and beneficiary identity, account or reference, amount, currency, date and purpose; repair, reject or escalate deficient transfers according to documented risk.
- Preuves à conserver
- Field matrix, validation rules, repair queue, decisions and transfer samples.
- Source primaire
- Banking Act 2012, section 77; operational risk control
Control electronic-money providers and agents.
- Action d’implémentation
- Verify the provider's current BoSS authorisation and the applicable Electronic Money Regulation, including the 2025 amendment published in August 2026; confirm agent, safeguarding, outsourcing, customer and transaction limits before launch.
- Preuves à conserver
- Licence, current regulation, agent approvals, contracts, limits, monitoring and incidents.
- Source primaire
- BoSS Electronic Money Regulation 2017 (Amendment) 2025; BoSS regulations and circulars
Do not treat the draft payment-system bill as enacted law.
- Action d’implémentation
- Track enactment and commencement of the National Payment System Bill 2025 and document the present legal basis for each payment activity separately.
- Preuves à conserver
- Legislative-status check, current-law memo, licence and change trigger.
- Source primaire
- BoSS validation workshop statement, 12 August 2026
08Targeted financial sanctionsFATF still identifies South Sudan's targeted-financial-sanctions framework as incomplete; screening and escalation remain essential risk controls.3 éléments+
Screen current UN designations and any operative national directions.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and relevant transactions against the current UN consolidated list and any verified South Sudan direction at onboarding, before activity and on list updates.
- Preuves à conserver
- List inventory, update log, screening configuration, alerts and dispositions.
- Source primaire
- UN Security Council consolidated list; FATF South Sudan statement, 19 June 2026
Escalate potential matches without inventing a local freeze deadline.
- Action d’implémentation
- Immediately restrict disposition as permitted, escalate to legal and the competent authority, obtain current written freeze and reporting instructions, and preserve the chronology; do not state that the incomplete national framework supplies a verified automatic deadline.
- Preuves à conserver
- Alert chronology, identity and ownership analysis, restriction, authority direction and report.
- Source primaire
- FATF South Sudan statement, 19 June 2026; applicable UN Security Council resolutions
Control false positives, exemptions and release.
- Action d’implémentation
- Require documented authority or legal approval before releasing a sanctions-related restriction and preserve correspondence, licence or exemption and decision rationale.
- Preuves à conserver
- Match analysis, authority correspondence, approval, release record and audit trail.
- Source primaire
- Operational control pending completed national TFS framework
09Records and regulator accessRecords must identify the parties and reconstruct transactions for at least five years from completion.4 éléments+
Retain AML identity and transaction records for at least five years.
- Action d’implémentation
- Keep prescribed transaction details and the identity evidence or information enabling a copy to be obtained for at least five years from completion of the relevant business or transaction.
- Preuves à conserver
- Retention schedule, completion trigger, archive sample, retrieval and deletion control.
- Source primaire
- AML/CTF Act 2012, section 17(1)-(3)
Retain copies and a register when originals are released.
- Action d’implémentation
- Where law requires release of an original before five years elapse, retain a copy and maintain the prescribed released-document register.
- Preuves à conserver
- Released-document register, copy, authority, custody trail and retrieval test.
- Source primaire
- AML/CTF Act 2012, section 17(4)
Meet separate company-record periods.
- Action d’implémentation
- Map Companies Act records at the registered office, including seven-year and seven-accounting-period categories, separately from the five-year AML clock and preserve the longer applicable period.
- Preuves à conserver
- Record-class schedule, statutory-register sample, archive and legal hold.
- Source primaire
- Companies Act 2012, sections 158-160
Respond securely to lawful inspections and requests.
- Action d’implémentation
- Authenticate FIU, BoSS and other competent-authority requests, preserve STR confidentiality, control production and record delivery and acknowledgement.
- Preuves à conserver
- Request register, authority check, approval, production index and receipt.
- Source primaire
- AML/CTF Act 2012, sections 8(c)-(d), 18(2), 21 and 22
10Privacy, biometrics, and transfersNo comprehensive generally applicable data-protection statute or regulator was verified; use constitutional, sector and contractual controls without inventing statutory deadlines.3 éléments+
Map the lawful basis and necessity for identity processing.
- Action d’implémentation
- Document the legal and operational basis for each identity, screening and biometric field, collect only what is necessary, give clear notice and restrict reuse while monitoring for new generally applicable privacy legislation.
- Preuves à conserver
- Data map, legal-basis assessment, notice, field justification and change log.
- Source primaire
- Transitional Constitution 2011, Article 22; AML/CTF Act 2012, sections 16-18; operational privacy control
Protect identity and financial data.
- Action d’implémentation
- Apply role-based access, encryption, logging, backup, vendor controls, testing and incident response proportionate to sensitivity; banks and credit-reporting participants must also map applicable BoSS data-security requirements.
- Preuves à conserver
- Security standard, access review, encryption evidence, vendor assessment, tests and incident log.
- Source primaire
- BoSS Credit Reporting Systems Regulation 2014, sections 6-9; operational privacy control
Control biometrics and cross-border processing conservatively.
- Action d’implémentation
- Before biometric collection or overseas hosting, complete a documented necessity, proportionality, security, vendor and transfer assessment and obtain current local advice; do not claim an unverified regulator approval or breach deadline.
- Preuves à conserver
- Assessment, architecture, contract, security controls, approval and legal update check.
- Source primaire
- Transitional Constitution 2011, Article 22; operational privacy control
11Practical evidence packsMaintain concise packs that reproduce decisions and expose unresolved legal dependencies.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, ultimate-benefit analysis, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting AML/CTF Act 2012, sections 16-20
Maintain a reconstructable reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, the 24-hour chronology, approvals, STR delivery, acknowledgement and follow-up while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting AML/CTF Act 2012, sections 18-23
Maintain a launch and legal-change pack.
- Action d’implémentation
- Record current thresholds, FIU procedure, licences, BoSS directions, registry evidence, sanctions instructions, privacy analysis, testing and confirmations before launch and on material change.
- Preuves à conserver
- Signed launch pack, source register, uncertainty log and change approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
12 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Anti-Money Laundering and Counter Terrorist Financing Act No. 29 of 2012Ministry of Justice and Constitutional Affairs · Primary legislation
- Banking Act No. 22 of 2012Bank of South Sudan · Primary legislation
- Companies Act 2012 and national laws repositoryMinistry of Justice and Constitutional Affairs · Primary legislation
- Bank of South Sudan regulations registerBank of South Sudan · Official regulator repository
- Bank of South Sudan circulars registerBank of South Sudan · Official regulator repository
- Electronic Money Regulation 2017 (Amendment) 2025Bank of South Sudan · Official regulation
- Directive on movement of cash within and across South Sudan bordersBank of South Sudan · Official directive
- Monetary and Banking Policy for 2025Bank of South Sudan · Official policy
- Validation status of the draft National Payment System Bill 2025Bank of South Sudan · Official legislative-status statement
- South Sudan increased-monitoring statement, 19 June 2026FATF · Authoritative current status
- ESAAMLG official publications and regional updatesESAAMLG · Authoritative regional body
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Soudan du Sud
Who receives suspicious transaction reports?+
The Financial Intelligence Unit established under the 2012 Act. Obtain the FIU's current secure filing instructions and acknowledgement process before production use.
When is suspicion reported?+
Within 24 hours after forming suspicion and, wherever possible, before the suspicious transaction or proposed transaction is carried out.
What universal CDD threshold applies?+
No current monetary CDD threshold was verified in the 2012 Act. Section 16 requires customer identification for relationships and transactions; obtain current authority directions before configuring any amount-based exception.
What is the transaction-record or cross-border cash threshold?+
The 2012 Act leaves both amounts to ministerial instruments. Obtain the current Gazette order and BoSS or customs direction; do not infer either amount from another rule.
How is beneficial ownership determined?+
Section 16 requires reasonable measures to establish the true identity of persons for whose account or ultimate benefit a customer acts. FATF still identifies the need for a comprehensive legal framework to collect and verify beneficial-ownership information, so do not invent a percentage or rely only on the member register.
How long are core AML records retained?+
At least five years from completion of the relevant business or transaction under section 17. Separate Companies Act record periods may be longer.
What privacy law applies?+
No comprehensive generally applicable data-protection statute or regulator was verified. Map Article 22 constitutional privacy, AML identity duties, applicable sector rules such as credit-reporting data security, contracts and current local advice.
Is South Sudan on a FATF public list?+
Yes. South Sudan remained under increased monitoring on 19 June 2026. FATF does not call for automatic enhanced due diligence solely because of listing; apply a documented risk-based response.
Can payment or electronic-money services launch without approval?+
No. Obtain applicable BoSS authorisation and current regulations. The National Payment System Bill 2025 was still undergoing validation in August 2026 and must not be treated as enacted law.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 11 September 2026. Confirm current FIU independence, reporting forms and secure channel, ministerial thresholds and orders, Bank of South Sudan directions, company-registry practice, sanctions implementation, privacy and cyber rules, and product-specific permissions with the competent authority and qualified South Sudanese counsel before launch.