Soudan KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Soudan.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Soudan ?
La checklist pour Soudan traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 43 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Financial Information Unit established by Article 12 of the 2014 Act
- Primary AML rule
- AML and Terrorism Financing Act 2014
- CBOS rule
- Circular No. 8/2026, effective 30 April 2026
- CBOS occasional CDD
- EUR 15,000 equivalent, single or linked transactions
- CBOS ownership test
- More than 10%, then other control, then senior manager
- Suspicion reporting
- Immediately, including attempts and regardless of value
- Core retention
- At least 5 years under Article 6 and Circular 8/2026
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Soudan
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the statutory reporting perimeter, sector supervisor and licence before activity.3 éléments+
Map every entity and activity to the reporting-person perimeter.
- Action d’implémentation
- Classify financial activities, real-estate transactions, qualifying precious-metal or stone cash transactions, specified legal and accounting work, and company-service activity; confirm any later ministerial designation and the relevant supervisor.
- Preuves à conserver
- Entity map, activity analysis, statutory category, supervisor confirmation and legal opinion.
- Source primaire
- AML and Terrorism Financing Act 2014, Article 3 definitions; Article 4
Apply Circular 8/2026 only to its stated CBOS-supervised perimeter.
- Action d’implémentation
- For banks, exchange companies, money-transfer companies, leasing, microfinance and other CBOS-licensed financial institutions, implement Circular 8/2026; for other reporting persons obtain their supervisor's current rules rather than extending bank-specific numbers automatically.
- Preuves à conserver
- Perimeter decision, licence, supervisor rule register and scoped control matrix.
- Source primaire
- CBOS Circular No. 8/2026, Parts II-III
Obtain each product and channel approval before launch.
- Action d’implémentation
- Identify banking, foreign exchange, remittance, mobile-payment, payment-system, agent, outsourcing and technology activity and obtain current CBOS or other competent-authority approval before promotion or operation.
- Preuves à conserver
- Licence, written approval, conditions, agent register, outsourcing approval and renewal calendar.
- Source primaire
- Banking Business Regulation Act 2026; CBOS electronic-payment notice; Mobile Payment Financial Institutions Regulation 2020
02Governance and risk assessmentThe Act requires risk controls; Circular 8/2026 adds detailed governance for CBOS-supervised institutions.3 éléments+
Maintain a documented institutional risk assessment.
- Action d’implémentation
- Assess customer, geography, product, service, delivery-channel, transaction, technology and proliferation-financing risks and update the assessment at least twice each year where Circular 8/2026 applies.
- Preuves à conserver
- Methodology, semiannual assessments, source inputs, board approval and remediation plan.
- Source primaire
- 2014 Act, Article 6(1); CBOS Circular 8/2026, Part IV, paragraphs 1-3
Maintain an independent compliance function.
- Action d’implémentation
- Appoint a senior compliance manager and deputy with board oversight, access to necessary records, independent decision authority and CBOS approval for transfer or removal where the circular applies.
- Preuves à conserver
- Appointments, CBOS correspondence, charter, access test, board reporting and conflicts register.
- Source primaire
- CBOS Circular 8/2026, paragraph 60(b)
Operate tested internal controls and training.
- Action d’implémentation
- Maintain board-approved customer acceptance, CDD, sanctions, monitoring, reporting, confidentiality, records, group, audit and response procedures; train relevant staff and independently test effectiveness.
- Preuves à conserver
- Policy suite, training records, monitoring tests, internal and external audit reports and remediation.
- Source primaire
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraphs 60-63
03Natural-person identificationIdentify customers, representatives and beneficial owners from reliable independent evidence.5 éléments+
Perform CDD at each statutory trigger.
- Action d’implémentation
- Identify and verify before a relationship, a covered occasional transaction, a domestic or international wire, when prior data is doubtful, or whenever ML, TF or PF suspicion exists.
- Preuves à conserver
- Trigger matrix, identity file, verification results, timestamps and exceptions.
- Source primaire
- 2014 Act, Article 5; CBOS Circular 8/2026, paragraph 7
For CBOS institutions, aggregate linked occasional transactions at EUR 15,000 equivalent.
- Action d’implémentation
- Apply CDD before a single or apparently linked occasional transaction equals or exceeds EUR 15,000 in national or foreign currency; document the rate, aggregation logic and scope. Do not extend this bank-sector trigger to other sectors without authority.
- Preuves à conserver
- Rate source, aggregation rules, alerts, customer file and scoped legal basis.
- Source primaire
- CBOS Circular 8/2026, paragraph 7(2)
Verify a natural person using current official evidence.
- Action d’implémentation
- Obtain valid official identity, full name, nationality, national number, date of birth, permanent residence, contacts, employment or activity, purpose and authorised signers, then corroborate through reliable official databases where available.
- Preuves à conserver
- Certified identity copy, verification queries, address and contact checks, discrepancy log and approval.
- Source primaire
- CBOS Circular 8/2026, paragraphs 12-13
Verify every representative and mandate.
- Action d’implémentation
- Obtain the representative's identity and a valid power or authorisation, test its scope and retain a certified copy before allowing access or instructions.
- Preuves à conserver
- Representative KYC, power, authority check, limits and transaction log.
- Source primaire
- 2014 Act, Article 5(2); CBOS Circular 8/2026, paragraphs 4(2) and 13(2)
Do not continue when CDD cannot be completed.
- Action d’implémentation
- Do not open the account, form the relationship or transact; terminate an existing relationship where required and consider an STR. If further CDD would tip off the customer, stop the CDD step and report instead.
- Preuves à conserver
- Restriction, exit decision, suspicion assessment, approval and any STR receipt.
- Source primaire
- CBOS Circular 8/2026, paragraphs 9-10
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and control; do not confuse customer-level CDD with registry filing.5 éléments+
Verify legal-person identity and authority.
- Action d’implémentation
- Obtain current incorporation and commercial-register evidence, constitutional documents, address, purpose, directors, owners, authorised signers and sector permissions; reconcile inconsistencies before acceptance.
- Preuves à conserver
- Registry extract, constitutional pack, officer and owner lists, mandates, licences and discrepancy log.
- Source primaire
- CBOS Circular 8/2026, paragraph 14; Companies Act 2015 as amended in 2025
Obtain a written beneficial-owner declaration.
- Action d’implémentation
- At account opening or relationship formation, require the customer to disclose each beneficial owner in writing and corroborate the declaration through reliable independent sources.
- Preuves à conserver
- Signed declaration, ownership chart, source documents, independent checks and refresh history.
- Source primaire
- CBOS Circular 8/2026, paragraphs 16-17
For CBOS institutions, identify natural persons owning or controlling more than 10%.
- Action d’implémentation
- Trace direct and indirect ownership and control above 10%; if no verified owner controls through ownership, identify control by other means; if still unresolved, identify the natural person responsible for senior management.
- Preuves à conserver
- Layered ownership chart, percentage calculations, control analysis, fallback decision and verified identities.
- Source primaire
- CBOS Circular 8/2026, paragraph 18(1)
Identify legal-arrangement parties and ultimate controllers.
- Action d’implémentation
- Identify and verify the settlor or creator, trustee, protector if any, beneficiaries and every other natural person exercising final direct or indirect effective control.
- Preuves à conserver
- Instrument, party register, verified identities, control analysis and change monitoring.
- Source primaire
- CBOS Circular 8/2026, paragraphs 15 and 18(3)
Treat commercial-register data as corroboration, not a substitute for CDD.
- Action d’implémentation
- Use the General Commercial Registrar's current Companies Act process to verify existence and filings, but separately establish beneficial ownership and control; obtain current 2025 amendment and live filing procedures before relying on registry completeness.
- Preuves à conserver
- Registry evidence, customer declaration, independent corroboration, discrepancy log and legal update check.
- Source primaire
- Companies Act 2015 as amended in 2025; Ministry of Justice commercial-registration mandate; CBOS Circular 8/2026, paragraphs 16-18
05PEPs, EDD, and remote onboardingUse risk systems for public-function exposure and apply proportionate enhanced measures.4 éléments+
Identify PEPs, family members and close associates.
- Action d’implémentation
- Obtain declarations, check reliable information and databases, map relationships and refresh screening throughout the relationship.
- Preuves à conserver
- Declaration, screening, relationship map, match rationale and refresh log.
- Source primaire
- 2014 Act, Articles 3 and 6(2); CBOS Circular 8/2026, paragraphs 28-30
Apply approval, source and monitoring measures to foreign PEPs.
- Action d’implémentation
- Obtain senior-management approval before starting or continuing, establish source of wealth and funds and conduct enhanced ongoing monitoring.
- Preuves à conserver
- Approval, source analysis, corroboration, monitoring plan and reviews.
- Source primaire
- 2014 Act, Article 6(2); CBOS Circular 8/2026, paragraph 29(a)
Apply the same measures to higher-risk domestic and international-organisation PEPs.
- Action d’implémentation
- Assess risk and apply senior approval, source verification and enhanced monitoring where the domestic or international-organisation PEP relationship is higher risk.
- Preuves à conserver
- Risk assessment, approval, source evidence and monitoring results.
- Source primaire
- 2014 Act, Article 6(2); CBOS Circular 8/2026, paragraph 29(b)
Strengthen non-face-to-face verification.
- Action d’implémentation
- Use authenticated documents, additional identity and source evidence, trustworthy independent references, initial restrictions and enhanced monitoring proportionate to impersonation and fraud risk.
- Preuves à conserver
- Remote-onboarding design, authentication results, restrictions, liveness or equivalent evidence and monitoring.
- Source primaire
- CBOS Circular 8/2026, paragraph 22
06Monitoring and suspicious reportingSuspicious transactions and attempts are reported immediately, regardless of value.5 éléments+
Monitor relationships and investigate unusual activity.
- Action d’implémentation
- Compare transactions and attempts with the customer's identity, purpose, ownership, expected activity, source profile and risk; investigate complex, unusual or economically unclear activity and retain the analysis.
- Preuves à conserver
- Monitoring rules, alerts, investigation notes, source data and dispositions.
- Source primaire
- 2014 Act, Articles 5-6; CBOS Circular 8/2026, paragraphs 19 and 47-48
Report suspicion and attempts immediately and regardless of value.
- Action d’implémentation
- Timestamp reasonable suspicion and have the authorised compliance manager immediately submit the FIU form for a transaction or attempted transaction connected with crime proceeds, ML or TF; include PF suspicion under the circular's internal escalation framework.
- Preuves à conserver
- Suspicion chronology, analysis, FIU form, secure submission record and acknowledgement.
- Source primaire
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraphs 49-51
Submit later related information immediately.
- Action d’implémentation
- Authenticate FIU requests and promptly provide requested or newly available information linked to an earlier report using the authorised secure route.
- Preuves à conserver
- Request, authority verification, supplement, delivery log and receipt.
- Source primaire
- 2014 Act, Article 14; CBOS Circular 8/2026, paragraphs 55-57
Prevent tipping off and protect reporting information.
- Action d’implémentation
- Restrict report and investigation access and do not tell the customer or an unauthorised person that a report has been or will be filed; document permitted communications with competent authorities and counsel.
- Preuves à conserver
- Need-to-know matrix, access logs, communications policy, training and incident review.
- Source primaire
- 2014 Act, Article 9; CBOS Circular 8/2026, paragraphs 58-59
Implement FIU stop and freeze orders exactly.
- Action d’implémentation
- Maintain an always-available process for an FIU transaction stop of up to five days, a Prosecutor-General freeze of up to two weeks and any court extension; do not release without verified authority.
- Preuves à conserver
- Order validation, timestamps, restriction, asset record, extension and release authority.
- Source primaire
- 2014 Act, Article 15
07Payments, wires, thresholds, and agentsWire fields and payment permissions are explicit; other thresholds require scoped current instruments.5 éléments+
Keep required originator and beneficiary information with each wire.
- Action d’implémentation
- Collect verified originator and beneficiary names, account or unique reference and the other required identifying fields; keep information through the payment chain and block an originating transfer lacking mandatory data.
- Preuves à conserver
- Field matrix, validation rules, transfer sample, repair queue and decision log.
- Source primaire
- 2014 Act, Article 7; CBOS Circular 8/2026, paragraphs 33-41
Control incomplete incoming and intermediary transfers.
- Action d’implémentation
- Detect missing fields and apply documented risk rules to execute, reject, suspend, report or seek repair; intermediaries retain technically detached information for at least five years and provide it within one working day on request.
- Preuves à conserver
- Detection rule, repair request, risk decision, report and retrieval test.
- Source primaire
- CBOS Circular 8/2026, paragraphs 39-44
Obtain the current cross-border declaration threshold.
- Action d’implémentation
- Before physical movement of currency or bearer negotiable instruments, confirm the current regulation-set declaration amount and customs procedure; do not substitute the EUR 15,000 bank CDD trigger.
- Preuves à conserver
- Current regulation, threshold configuration, declaration, source evidence and customs receipt.
- Source primaire
- 2014 Act, Articles 31-32
Obtain approval for electronic-payment systems, outsourcing and connections.
- Action d’implémentation
- Secure prior written CBOS approval for the payment service, system, outsourcing, agency and technical connection; document current 2026 banking-law and payment-rule applicability.
- Preuves à conserver
- Approvals, architecture, contracts, licences, agent inventory and test results.
- Source primaire
- CBOS electronic-payment notice; CBOS Circular 1/2013; Banking Business Regulation Act 2026
Control mobile-payment providers and agents.
- Action d’implémentation
- Verify the provider's licence, ensure agents follow CDD and customer-data safeguards, notify CBOS of agent changes without undue delay and monitor transactions and complaints.
- Preuves à conserver
- Licence, agent due diligence, notifications, contracts, CDD samples, monitoring and complaints.
- Source primaire
- Mobile Payment Financial Institutions Regulation 2020, Articles 15 and 19-34
08Targeted financial sanctionsCircular 8/2026 requires real-time screening, freezing without delay and immediate reporting for CBOS institutions.4 éléments+
Screen current UN and Technical Committee sanctions lists in real time.
- Action d’implémentation
- Screen customers, beneficial owners, directors, authorised persons, related parties and transactions against current UN Security Council decisions and Technical Committee lists and test the system periodically.
- Preuves à conserver
- List inventory, update log, screening configuration, test results, alerts and dispositions.
- Source primaire
- CBOS Circular 8/2026, paragraph 61(1)-(2)
Freeze covered assets immediately, without delay or prior notice.
- Action d’implémentation
- Freeze direct and indirect funds and assets owned, controlled, managed or held wholly or partly by a listed person, including persons acting for or under direction, and prevent funds or services being made available.
- Preuves à conserver
- Match analysis, freeze timestamp, ownership and control analysis, asset inventory and system blocks.
- Source primaire
- CBOS Circular 8/2026, paragraph 61(3)-(6)
Immediately notify the Technical Committee and FIU.
- Action d’implémentation
- After freezing, immediately provide the Technical Committee the asset and action details; immediately notify the FIU of listed current or former customers, related persons and attempted transactions involving frozen resources.
- Preuves à conserver
- Committee report, FIU report, delivery evidence, acknowledgement and chronology.
- Source primaire
- CBOS Circular 8/2026, paragraph 61(7)-(10)
Govern false positives, exemptions, humanitarian permissions and release.
- Action d’implémentation
- Compare all identifiers, maintain the restriction while legally required and release or permit activity only under verified Technical Committee or other competent-authority direction, including any applicable UN humanitarian exemption.
- Preuves à conserver
- Identifier analysis, authority correspondence, licence or exemption, approval and release log.
- Source primaire
- Council of Ministers Decisions 358-360/2014; current UN Security Council resolutions; controlled legal procedure
09Records and regulator accessRecords must reconstruct decisions and transactions and remain promptly available.3 éléments+
Retain CDD records for at least five years after exit or the occasional transaction.
- Action d’implémentation
- Keep identity and beneficial-owner evidence, accounting files and correspondence for at least five years after the relationship ends or the occasional transaction date, applying the longer applicable period.
- Preuves à conserver
- Retention schedule, trigger dates, archive samples, retrieval test and deletion controls.
- Source primaire
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraph 48(1)
Retain transaction, attempt and report records for their correct clocks.
- Action d’implémentation
- Keep domestic and international transaction and attempt records for at least five years from execution or attempt; keep FIU reports and supporting documents for at least five years from reporting and criminal-case records until final disposal if longer.
- Preuves à conserver
- Record-class schedule, linked case files, trigger calculation, archive and legal holds.
- Source primaire
- 2014 Act, Article 6(1); CBOS Circular 8/2026, paragraph 48(2)-(5)
Make records promptly available to competent authorities.
- Action d’implémentation
- Authenticate requests, preserve reporting confidentiality and privilege, produce responsive records promptly and record the exact disclosure and receipt.
- Preuves à conserver
- Request register, authority check, production index, approval, delivery and receipt.
- Source primaire
- 2014 Act, Articles 4, 6 and 14; CBOS Circular 8/2026, paragraph 48
10Privacy, biometrics, and transfersNo comprehensive generally applicable data-protection statute or independent privacy authority was verified.3 éléments+
Map necessity and legal authority for identity processing.
- Action d’implémentation
- Document the AML, sector, contractual and operational basis for each identity, screening and biometric field; minimize collection, explain use and restrict incompatible reuse.
- Preuves à conserver
- Data map, legal-basis analysis, notice, field justification, consent where relevant and change log.
- Source primaire
- Electronic Transactions Act 2007; 2014 Act, Articles 5-6; operational privacy control
Secure customer and transaction information.
- Action d’implémentation
- Apply access controls, encryption, logging, segregation, backups, incident response and tested vendor safeguards; payment providers must apply the encryption and customer-data controls in their sector rules.
- Preuves à conserver
- Security standard, access review, encryption evidence, vendor assessment, tests and incident log.
- Source primaire
- Electronic Transactions Act 2007, Article 28; Mobile Payment Financial Institutions Regulation 2020, Articles 15 and 19
Control biometrics and overseas hosting conservatively.
- Action d’implémentation
- Before biometric collection or cross-border processing, assess necessity, proportionality, security, vendor access and transfer risk and obtain current local advice; do not claim an unverified breach deadline or regulator approval.
- Preuves à conserver
- Impact assessment, architecture, contract, security controls, approval and legal update check.
- Source primaire
- Operational privacy control pending comprehensive legislation
11Practical evidence packsMaintain concise evidence packs that reproduce decisions and expose legal dependencies.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting 2014 Act, Articles 5-6 and CBOS Circular 8/2026
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, immediate-reporting chronology, approvals, submission, acknowledgement, follow-up, sanctions actions and access logs.
- Preuves à conserver
- Complete sampled case pack and controlled access log.
- Source primaire
- Operational control supporting 2014 Act, Articles 6, 9 and 14-16
Maintain a launch and legal-change pack.
- Action d’implémentation
- Record current FIU procedure, sector thresholds, licences, 2026 CBOS controls, registry evidence, sanctions instructions, privacy analysis, conflict-related operating constraints, tests and confirmations before launch and on change.
- Preuves à conserver
- Signed launch pack, source register, uncertainty log, tests and approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
13 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Anti-Money Laundering and Terrorism Financing Act 2014Central Bank of Sudan · Primary legislation
- AML/CFT/CPF regulatory and supervisory controls - Circular No. 8/2026Central Bank of Sudan · Official binding circular
- Laws and regulations repositoryCentral Bank of Sudan · Official regulator repository
- Electronic Transactions Act 2007Central Bank of Sudan · Primary legislation
- Mobile Payment Financial Institutions Regulation 2020Central Bank of Sudan · Official regulation
- Electronic payment system operations - Circular No. 1/2013Central Bank of Sudan · Official circular
- Current electronic-payment regulatory clarificationCentral Bank of Sudan · Official regulatory statement
- Companies Act registration mandate and Ministry functionsMinistry of Justice · Official registry authority statement
- Sudan third follow-up report, April 2016MENAFATF · Authoritative regional assessment
- Sudan FATF country pageFATF · Authoritative country record
- FATF jurisdictions under increased monitoring, 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Soudan
Who receives suspicious transaction reports?+
The Financial Information Unit established by Article 12 of the 2014 Act. Obtain the FIU's current form, secure filing route and acknowledgement procedure before production use.
When is suspicion reported?+
Immediately for a suspicious transaction or attempt, regardless of value, under Circular 8/2026 for CBOS-supervised institutions. The 2014 Act also requires immediate reporting by financial and non-financial reporting persons.
What occasional-customer CDD threshold applies?+
For institutions within Circular 8/2026, CDD applies before a single or apparently linked occasional transaction equals or exceeds EUR 15,000 in national or foreign currency. Confirm the rule applicable to non-CBOS sectors separately.
How is beneficial ownership determined?+
For CBOS institutions, identify each natural person owning or controlling more than 10%, then any person controlling by other means, and finally the natural person responsible for senior management if the earlier tests identify no one. Legal arrangements require identification of their principal parties and ultimate controllers.
How long are core AML records retained?+
At least five years, with the trigger depending on record type: relationship end or occasional transaction, transaction or attempt, FIU report, or risk-assessment completion or update. Criminal-case records are held until final disposal if longer.
What happens on a sanctions match?+
A CBOS institution must freeze covered assets immediately, without delay or prior notice, prevent funds or services being made available, and immediately notify the Technical Committee and FIU as applicable.
What cross-border cash threshold applies?+
Article 31 leaves the declaration amount to regulations. Obtain the current customs instrument and do not substitute the EUR 15,000 occasional-customer CDD trigger.
Is Sudan on a FATF public list?+
No. Sudan was not named on either FATF public list dated 19 June 2026. This does not mean that Sudan, a product or a customer is low risk.
Does Sudan have a comprehensive data-protection law?+
No comprehensive generally applicable statute or independent privacy authority was verified. Apply the Electronic Transactions Act, sector confidentiality and security rules, contracts and conservative data-governance controls, and obtain current local advice for biometrics and overseas hosting.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 13 September 2026. Sudan's conflict, institutional relocation and legal transitions can affect practical access and enforcement. Confirm later Gazette amendments, FIU filing mechanics, sector rules, non-bank thresholds, company-register and beneficial-ownership procedures, sanctions-list circulation, privacy and biometric requirements, and product permissions with the competent authority and qualified Sudanese counsel before launch.