السلفادور KYC, KYB & AML compliance checklist
قائمة عملية وموثقة بالمصادر لتنفيذ متطلبات KYC وKYB وAML في السلفادور.
- تاريخ آخر مراجعة
- تاريخ آخر مراجعة:
- الإصدار
- الإصدار 1.0

إجابة مباشرة
ما الذي تغطيه قائمة الامتثال الخاصة بـ السلفادور؟
تحوّل قائمة السلفادور قواعد KYC وKYB وAML الأساسية إلى 11 مجالات رقابية و37 فحوص تنفيذ، وتشمل الجهات المختصة وواجبات الإبلاغ والأدلة الواجب الاحتفاظ بها.
حقائق تنظيمية أساسية
- National FIU
- Unidad de Investigación Financiera (UIF), an autonomous specialist office attached to the Fiscalía General de la República
- Primary AML rule
- Decree 426 special AML/CFT/CPF law, effective 24 October 2025
- Suspicion reporting
- Analyze within up to 15 business days; report to UIF within 24 hours after a suspicious determination
- Regulated reports
- Report covered linked transactions within 5 business days; transitional thresholds require current-instrument confirmation
- Beneficial owner
- Natural person with at least 25% ownership or voting rights, or control by other means
- Retention
- At least 15 years: transaction completion or relationship/account termination, depending on the record
- Privacy authority
- Agencia de Ciberseguridad del Estado (ACE)
- FATF status
- GAFILAT member; absent from FATF June 2026 public lists as reviewed 6 August 2026
تفاصيل التنفيذ
متطلبات وإجراءات الامتثال في السلفادور
افتح كل مجال لمراجعة المتطلب وإجراء التنفيذ المقترح والأدلة الواجب الاحتفاظ بها والمصدر الأساسي.
01Scope, authorities, and licensingMap the business to Decree 426's closed subject categories and the applicable sector supervisor before onboarding.3 عناصر+
Determine whether the entity is a subject obliged under the new special law.
- إجراء التنفيذ
- Map each product and legal entity to article 7, including financial institutions, specified lenders, DNFBPs, money/value transport, digital-asset or bitcoin providers and political parties; document any out-of-scope conclusion.
- الأدلة الواجب الاحتفاظ بها
- Perimeter memorandum, product map, legal-entity chart and counsel confirmation.
- المصدر الأساسي
- Decree 426 arts. 1, 7-9
Identify the competent supervisor and complete required registrations or authorisations.
- إجراء التنفيذ
- Confirm SSF, Superintendencia de Obligaciones Mercantiles, CNAD or other article 11-12 supervision; separately test financial, payments, bitcoin and digital-asset licensing before launch.
- الأدلة الواجب الاحتفاظ بها
- Supervisor mapping, licence analysis, registrations, approvals and correspondence.
- المصدر الأساسي
- Decree 426 arts. 11-13; Digital Assets Issuance Law arts. 18-20
Treat the regulation and UIF instruction as a controlled transition.
- إجراء التنفيذ
- At launch and each rules refresh, verify whether the preserved 2000 regulation and current UIF instruction have been replaced under the 2025 law; apply only provisions that do not conflict with Decree 426.
- الأدلة الواجب الاحتفاظ بها
- Dated legal-update check, downloaded instruments and conflict analysis.
- المصدر الأساسي
- Decree 426 arts. 55-62; UIF current-law FAQ
02Governance and risk assessmentControls must be proportionate to identified AML/CFT/CPF risk and avoid unsupported blanket exclusion.3 عناصر+
Operate a documented risk-based AML/CFT/CPF system.
- إجراء التنفيذ
- Assess customer, product, channel, transaction and geographic risks; set simplified, standard or enhanced controls and obtain governance approval.
- الأدلة الواجب الاحتفاظ بها
- Enterprise risk assessment, methodology, risk appetite, control matrix and approval minutes.
- المصدر الأساسي
- Decree 426 arts. 9, 13, 15-17
Appoint the required compliance function and deputies.
- إجراء التنفيذ
- For SSF-, CNAD- and article 7(2)-supervised entities establish a compliance office with principal and alternate; other supervised entities must appoint a principal and alternate unless a statutory exception applies.
- الأدلة الواجب الاحتفاظ بها
- Board resolutions, role profiles, independence record, UIF/supervisor filings and training evidence.
- المصدر الأساسي
- Decree 426 arts. 20-22
Create the prevention committee when a compliance office is mandatory.
- إجراء التنفيذ
- Maintain a committee of at least three members, including one member of the highest governing body and the compliance officer, with recorded decisions.
- الأدلة الواجب الاحتفاظ بها
- Committee charter, appointments, meeting book and action log.
- المصدر الأساسي
- Decree 426 art. 23
03Natural-person identificationIdentification and verification must be risk-based, reconstructable and completed for the relationship and relevant occasional activity.3 عناصر+
Identify and verify the customer and any representative.
- إجراء التنفيذ
- Collect authoritative identity data, verify the document and person, validate authority for representatives, screen, risk-rate and record purpose before activation.
- الأدلة الواجب الاحتفاظ بها
- Identity evidence, liveness or equivalent checks, authority document, screening log and onboarding decision.
- المصدر الأساسي
- Decree 426 art. 15
Apply CDD at statutory trigger points.
- إجراء التنفيذ
- Perform CDD when establishing a relationship, for occasional transactions above the applicable cash-report threshold, on suspicion, or when prior identity data is doubtful; obtain current sector thresholds before deployment.
- الأدلة الواجب الاحتفاظ بها
- Trigger matrix, transaction evidence, refresh record and escalation log.
- المصدر الأساسي
- Decree 426 art. 15
Do not maintain anonymous or coded relationships.
- إجراء التنفيذ
- Require nominative customer records and block product activation where required identity evidence is not provided; consider a suspicious-attempt report after analysis.
- الأدلة الواجب الاحتفاظ بها
- Account configuration, rejection record and documented reporting decision.
- المصدر الأساسي
- Decree 426 art. 15
04KYB, registries, and beneficial ownershipCompany verification must combine registry evidence with independent ownership-and-control analysis.4 عناصر+
Verify legal existence, representatives, activity and powers.
- إجراء التنفيذ
- Obtain a current CNR Registro de Comercio certification or equivalent source, constitutive documents, tax details, business address and authority chain; independently verify material facts.
- الأدلة الواجب الاحتفاظ بها
- Registry certification, formation documents, tax evidence, address check and authority map.
- المصدر الأساسي
- Decree 426 art. 15; Commercial Code; CNR Registro de Comercio
Identify natural persons meeting the statutory beneficial-owner test.
- إجراء التنفيذ
- Trace direct and indirect ownership and voting rights to every natural person at or above 25%, and identify any natural person exercising control by other means.
- الأدلة الواجب الاحتفاظ بها
- Ownership chart, cap table, registry documents, shareholder evidence and control analysis.
- المصدر الأساسي
- Decree 426 art. 15
Apply the listed-company exception narrowly.
- إجراء التنفيذ
- Use the exception only where the client or owner has at least 25% in a listed commercial company subject to market disclosure requirements; document the market and disclosure basis.
- الأدلة الواجب الاحتفاظ بها
- Listing evidence, disclosure-rule analysis and approval.
- المصدر الأساسي
- Decree 426 art. 15
Do not treat registry access as proof of a comprehensive public BO register.
- إجراء التنفيذ
- Use CNR company records as one input and obtain ownership/control evidence directly; confirm current beneficial-ownership filing and access arrangements with CNR and the supervisor.
- الأدلة الواجب الاحتفاظ بها
- CNR search, certified extracts, customer declaration, corroboration and uncertainty log.
- المصدر الأساسي
- CNR Registro de Comercio services; controlled uncertainty
05PEPs, EDD, and remote onboardingHigh-risk relationships require verified source information and a documented, individualized decision.3 عناصر+
Identify domestic, foreign and international-organisation PEPs.
- إجراء التنفيذ
- Screen customers, beneficial owners, representatives and connected parties; continue PEP treatment for five years after the last appointment and apply enhanced diligence to specified family and close associates.
- الأدلة الواجب الاحتفاظ بها
- Screening results, position verification, relationship mapping and five-year control.
- المصدر الأساسي
- Decree 426 art. 19
Verify source of wealth and source of funds for high-risk customers.
- إجراء التنفيذ
- Collect and corroborate wealth and funds evidence proportionate to risk and obtain the required senior approval before activation or continuation.
- الأدلة الواجب الاحتفاظ بها
- Source dossier, corroboration, risk rationale, approval and monitoring plan.
- المصدر الأساسي
- Decree 426 arts. 15, 19; current UIF instruction
Make remote onboarding equivalent and auditable.
- إجراء التنفيذ
- Use authoritative document validation, impersonation and liveness controls, device and channel signals, sanctions/PEP screening, step-up checks and manual exception review.
- الأدلة الواجب الاحتفاظ بها
- Vendor testing, model thresholds, session record, fraud results and exception approvals.
- المصدر الأساسي
- Decree 426 arts. 15-17; risk-based implementation control
06Monitoring and suspicious reportingUnusual activity must be analyzed promptly and reports sent confidentially through UIF-authorized channels.4 عناصر+
Monitor relationships and investigate unusual activity.
- إجراء التنفيذ
- Calibrate scenarios to the risk assessment, preserve alert inputs, investigate context and document whether sufficient grounds for suspicion exist.
- الأدلة الواجب الاحتفاظ بها
- Scenario inventory, alert file, analyst workpaper, disposition and quality review.
- المصدر الأساسي
- Decree 426 arts. 9, 15, 24
Complete unusual-operation analysis within the statutory window.
- إجراء التنفيذ
- Finish analysis within 15 business days of detection; request the single permitted equal extension from UIF through the compliance officer when justified.
- الأدلة الواجب الاحتفاظ بها
- Detection timestamp, case chronology, extension request and UIF response.
- المصدر الأساسي
- Decree 426 art. 24
Report suspicious, attempted and suspicious-activity cases to UIF.
- إجراء التنفيذ
- After determining suspicion, submit the authorized report promptly and no later than 24 hours, regardless of amount, using the current UIF channel and format.
- الأدلة الواجب الاحتفاظ بها
- Decision timestamp, submitted report, receipt, supporting file and access log.
- المصدر الأساسي
- Decree 426 arts. 3-4, 24
Protect report confidentiality and prevent tipping off.
- إجراء التنفيذ
- Restrict report and UIF-request access; do not disclose reports or related requests to customers, users, third parties, auditors or supervisors except as lawfully directed.
- الأدلة الواجب الاحتفاظ بها
- Restricted permissions, disclosure protocol, staff attestations and incident log.
- المصدر الأساسي
- Decree 426 arts. 24, 28
07Payments, wires, thresholds, and digital assetsThreshold reporting and regulated financial or digital-asset activity require current parameter and licence checks.4 عناصر+
Report regulated transactions within five business days.
- إجراء التنفيذ
- Aggregate transactions in one event or over a month where they appear linked, and report covered cash, other-means, local/international electronic-transfer and digital-asset transactions to UIF within five business days.
- الأدلة الواجب الاحتفاظ بها
- Aggregation logic, threshold table, report files, receipts and timeliness metrics.
- المصدر الأساسي
- Decree 426 art. 25
Confirm transitional thresholds before configuring production.
- إجراء التنفيذ
- Reconcile Decree 426, any new regulation and the preserved UIF instruction. UIF's current FAQ states instruction thresholds above USD 10,000 cash, USD 25,000 other means and USD 1,000 electronic transfers; do not generalize them without sector confirmation.
- الأدلة الواجب الاحتفاظ بها
- Dated instrument set, supervisor confirmation, configuration approval and change log.
- المصدر الأساسي
- Decree 426 arts. 25, 61; UIF current-law FAQ
Preserve complete originator and beneficiary information for transfers.
- إجراء التنفيذ
- Collect, validate, transmit and retain the fields required by the applicable BCR/SSF/UIF or CNAD instrument; pause or escalate incomplete transfers under the current sector rule.
- الأدلة الواجب الاحتفاظ بها
- Message fields, validation logs, exception queue and current-rule mapping.
- المصدر الأساسي
- Decree 426 arts. 15, 25-26; current sector instruments
Register digital-asset services with CNAD where the territorial and service tests apply.
- إجراء التنفيذ
- Before offering article 19 digital-asset services from El Salvador or actively marketing them into the country, complete CNAD registration and confirm UIF obligations; separately analyze bitcoin services supervised by SSF.
- الأدلة الواجب الاحتفاظ بها
- Territorial analysis, CNAD registration, public-register check, UIF record and SSF analysis.
- المصدر الأساسي
- Digital Assets Issuance Law arts. 18-20; Decree 426 arts. 7, 12
08Targeted financial sanctionsScreening must cover binding designations and produce an immediate, traceable escalation.3 عناصر+
Screen UN and applicable national designations continuously.
- إجراء التنفيذ
- Screen customers, beneficial owners, representatives and transactions at onboarding, list change and before value movement using UIF-published access points.
- الأدلة الواجب الاحتفاظ بها
- List sources, update logs, screening results, match records and test evidence.
- المصدر الأساسي
- Special Law Against Acts of Terrorism art. 37; Decree 426 arts. 10, 32; UIF international-lists portal
Prevent dealing and freeze on a confirmed designation match without delay.
- إجراء التنفيذ
- Stop transactions immediately, preserve assets and notify through the current UIF/FGR process; do not release funds without competent authority direction.
- الأدلة الواجب الاحتفاظ بها
- Match chronology, freeze record, report receipt, communications and release authority.
- المصدر الأساسي
- Special Law Against Acts of Terrorism art. 37; Decree 426 arts. 10, 32
Control false positives, delisting and exceptions.
- إجراء التنفيذ
- Use a documented escalation that protects confidentiality and obtains UIF/FGR or judicial direction for unfreezing, delisting or permitted access; confirm live procedure before launch.
- الأدلة الواجب الاحتفاظ بها
- Escalation file, identity comparison, authority response and audit trail.
- المصدر الأساسي
- UIF sanctions guidance and exercises; controlled uncertainty
09Records and regulator accessThe 2025 law materially extends AML records to at least 15 years.3 عناصر+
Retain reconstructable transaction records for at least 15 years.
- إجراء التنفيذ
- Preserve domestic and international transaction records for at least 15 years from completion, sufficient to reconstruct each transaction and answer authority requests immediately.
- الأدلة الواجب الاحتفاظ بها
- Retention schedule, transaction archive, retrieval tests and deletion holds.
- المصدر الأساسي
- Decree 426 art. 26
Retain customer identification and account files for at least 15 years after exit.
- إجراء التنفيذ
- Start the period at relationship termination or account closure; preserve legal holds and secure electronic accessibility.
- الأدلة الواجب الاحتفاظ بها
- Closure date, customer file archive, legal-hold record and retrieval test.
- المصدر الأساسي
- Decree 426 art. 26
Respond securely to UIF, supervisor, FGR and court requests.
- إجراء التنفيذ
- Authenticate requests, preserve scope and chain of custody, meet the stated deadline and keep a restricted disclosure log.
- الأدلة الواجب الاحتفاظ بها
- Request register, authentication, production manifest and transmission receipt.
- المصدر الأساسي
- Decree 426 arts. 4, 26, 28, 52-53
10Privacy, biometrics, and transfersAML processing must also satisfy the Personal Data Protection Law and ACE policy, subject to lawful AML retention and disclosure duties.4 عناصر+
Document a lawful, transparent and minimized KYC processing design.
- إجراء التنفيذ
- Map each data element and purpose, provide required notices, identify the lawful basis, minimize collection and reconcile deletion rights with the 15-year AML retention duty.
- الأدلة الواجب الاحتفاظ بها
- Processing register, privacy notice, purpose/basis matrix, retention reconciliation and rights procedure.
- المصدر الأساسي
- Personal Data Protection Law arts. 5 and 24; Decree 426 art. 26
Apply enhanced safeguards to sensitive and biometric data.
- إجراء التنفيذ
- Complete an impact assessment, restrict access, encrypt data, test biometric vendors and document necessity, proportionality and fallback paths.
- الأدلة الواجب الاحتفاظ بها
- Impact assessment, security design, vendor diligence, test results and access logs.
- المصدر الأساسي
- Personal Data Protection Law; ACE Policies 001-0309025-DPDP arts. 3-6
Prepare breach notification and response workflows.
- إجراء التنفيذ
- Detect, contain and assess incidents and maintain a workflow capable of notifying ACE, FGR and affected individuals within 72 hours where the ACE policy requires it.
- الأدلة الواجب الاحتفاظ بها
- Incident plan, severity assessment, decision log, notifications and post-incident review.
- المصدر الأساسي
- ACE Policies 001-0309025-DPDP art. 4
Control processors and international transfers.
- إجراء التنفيذ
- Contract for confidentiality, security, auditability and deletion; assess equivalent protection for international transfers and preserve a current data-flow map.
- الأدلة الواجب الاحتفاظ بها
- Processor contracts, transfer assessment, country map, encryption evidence and approval.
- المصدر الأساسي
- Personal Data Protection Law; ACE Policies 001-0309025-DPDP art. 4
11Practical evidence packsEvidence should enable independent reconstruction of onboarding, monitoring, reporting and governance decisions.3 عناصر+
Maintain one indexed file per customer or legal entity.
- إجراء التنفيذ
- Link identity, KYB, beneficial ownership, screening, risk, approvals, monitoring, refreshes, source evidence and exit decisions under immutable identifiers.
- الأدلة الواجب الاحتفاظ بها
- Evidence index, version history, access history and sample reconstruction test.
- المصدر الأساسي
- Decree 426 arts. 15, 19, 26
Test data, screening, reporting and retention controls.
- إجراء التنفيذ
- Run periodic samples and scenario tests covering identity, 25% and control BO logic, PEP duration, threshold aggregation, ROS clocks, sanctions and 15-year retention.
- الأدلة الواجب الاحتفاظ بها
- Test plan, samples, defects, remediation owners and closure proof.
- المصدر الأساسي
- Decree 426 arts. 13, 15, 19, 24-26
Operate a dated legal-change control.
- إجراء التنفيذ
- Before launch and periodically thereafter check UIF, SSF, BCR, CNAD, CNR, ACE, FATF and GAFILAT sources; route changes into policy, rules, training and customer remediation.
- الأدلة الواجب الاحتفاظ بها
- Source register, legal-change log, impact assessment and deployment record.
- المصدر الأساسي
- Decree 426 arts. 55-61; risk-based implementation control
سجل المصادر الأساسية
12 مصدرًا مستخدمًا في هذه القائمة
استخدم هذه الروابط للتحقق من التشريعات وإرشادات الجهات الرقابية وإجراءات الإبلاغ والبيانات الدولية.
- Special AML/CFT/CPF Law - Decree 426Unidad de Investigación Financiera · Primary legislation
- Current-law frequently asked questionsUnidad de Investigación Financiera · Official current guidance
- UIF instructions and guidesUnidad de Investigación Financiera · Official guidance portal
- International sanctions lists portalUnidad de Investigación Financiera · Official sanctions guidance
- El Salvador 2024 mutual evaluationFATF / GAFILAT · Authoritative mutual evaluation
- FATF high-risk jurisdictions - June 2026Financial Action Task Force · Authoritative current-status statement
- FATF jurisdictions under increased monitoring - June 2026Financial Action Task Force · Authoritative current-status statement
- Registro de Comercio servicesCentro Nacional de Registros · Official company registry portal
- Personal Data Protection Law - Decree 144Asamblea Legislativa · Primary legislation
- ACE personal-data handling policiesAgencia de Ciberseguridad del Estado · Official privacy guidance
- Digital Assets Issuance Law with reformsComisión Nacional de Activos Digitales · Primary legislation
- Digital-asset service-provider registrationComisión Nacional de Activos Digitales · Official licensing guidance
إجابات مباشرة
أسئلة KYC وKYB وAML في السلفادور
Who receives suspicious reports in El Salvador?+
The Unidad de Investigación Financiera (UIF), the national financial intelligence office attached to the Fiscalía General de la República.
When must a suspicious operation be reported?+
The subject has up to 15 business days from detection to analyze an unusual operation, with one equal extension available on request; after determining suspicion, the authorized report must be sent promptly and within 24 hours.
What regulated-transaction reporting applies?+
Article 25 covers linked cash, other-means, electronic-transfer and digital-asset transactions and requires reporting within five business days. The current UIF FAQ describes transitional instruction thresholds above USD 10,000 cash, USD 25,000 other means and USD 1,000 electronic transfers; confirm the applicable current sector instrument.
What is the beneficial-owner threshold?+
Identify natural persons who directly or indirectly own or control at least 25% of capital or voting rights, plus natural persons exercising control by other means.
How long must AML records be retained?+
At least 15 years. Transaction records run from transaction completion; customer identification and account files run from relationship termination or account closure.
Is the company or beneficial-ownership registry public?+
CNR provides Registro de Comercio services and certifications, but this checklist does not represent that a comprehensive public beneficial-ownership register is available. Confirm current filing fields and access with CNR and the supervisor.
Who supervises digital-asset services?+
CNAD supervises digital-asset service providers under its law and register. SSF supervises providers performing bitcoin operations under the new AML law. The exact service and territorial perimeter must be analyzed before marketing or launch.
Who is the personal-data authority?+
The Agencia de Ciberseguridad del Estado (ACE) is the governing authority under the Personal Data Protection Law and has issued handling and security policies.
Is El Salvador on a FATF public list?+
As reviewed on 6 August 2026, El Salvador was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck both live statements before reliance.
منهجية البحث والمراجعة
تحدد VOVE ID Compliance Research النطاق التنظيمي، وتحول الالتزامات إلى ضوابط تشغيلية، وتربط الادعاءات الجوهرية بالمصادر، وتسجل تاريخ وإصدار كل مراجعة.
General regulatory information, not legal advice, a licence determination or a substitute for the operative Spanish texts and current supervisor instructions. Reviewed 6 August 2026. Confirm whether replacement regulations or UIF instructions have been issued, the applicable sector reporting parameters, registry access, sanctions escalation route, privacy guidance and licensing perimeter with the UIF, relevant supervisor and qualified Salvadoran counsel before launch.