Comoros KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Comoros.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Comoros compliance checklist cover?
The Comoros checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Service de Renseignements Financiers (SRF)
- Primary AML rule
- Law No. 12-008/AU of 28 June 2012
- Suspicion reporting
- Immediately to the SRF, including attempted suspicious transactions
- Occasional CDD
- Above KMF 5,000,000; also below the threshold where suspicion or linked activity applies
- Core retention
- At least 5 years under Law No. 12-008/AU
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Comoros compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the entity, activity and competent authority before launch.3 items+
Determine whether each activity is subject to the AML/CFT law.
- Implementation action
- Map every entity, product and channel to the financial-institution or designated non-financial categories and document the SRF and sector supervisor.
- Evidence to retain
- Applicability memo, product map and accountable-owner register.
- Primary citation
- Law No. 12-008/AU, Article 3
Treat the SRF as the financial intelligence unit.
- Implementation action
- Appoint the required correspondent and obtain the current reporting format and secure filing instructions directly from the SRF before operations begin.
- Evidence to retain
- Appointment, authority guidance, tested procedure and access approvals.
- Primary citation
- Law No. 12-008/AU, Articles 18-23 and 25
Obtain authorisation before regulated financial or payment activity.
- Implementation action
- Classify banking, microfinance, payment, remittance, foreign-exchange, insurance and other regulated services and obtain every required approval before launch.
- Evidence to retain
- Perimeter analysis, BCC or sector correspondence and licence register.
- Primary citation
- Law No. 13-003/AU; Law No. 20-005/AU; applicable sector rules
02Governance and risk assessmentThe programme must be documented, risk-based and independently tested.3 items+
Maintain a documented ML/TF risk assessment.
- Implementation action
- Assess customers, products, channels, geography, cash, agents and technology and update the assessment on material change.
- Evidence to retain
- Approved methodology, risk map, controls and version history.
- Primary citation
- Decision No. 12-2023/BCC/DSBR, Articles 1-5
Maintain written controls, training and independent audit.
- Implementation action
- Assign senior accountability and an SRF correspondent, screen staff, train relevant personnel and independently test the programme.
- Evidence to retain
- Appointments, policies, training, audit and remediation log.
- Primary citation
- Law No. 12-008/AU, Article 14
Assess new products and technology before launch.
- Implementation action
- Document ML/TF risks and mitigating controls and, where Article 6 applies, send the assessment to the BCC before effective launch.
- Evidence to retain
- Pre-launch assessment, governing-body approval and BCC transmission.
- Primary citation
- Decision No. 12-2023/BCC/DSBR, Article 6
03Natural-person identificationCDD uses reliable, independent evidence and continues throughout the relationship.3 items+
Identify and verify customers and representatives.
- Implementation action
- Verify identity and address using current official evidence and verify every representative's authority and identity.
- Evidence to retain
- Identity file, address evidence, mandate and verification result.
- Primary citation
- Law No. 12-008/AU, Article 8
Apply occasional-transaction CDD at the statutory trigger.
- Implementation action
- Identify occasional customers above KMF 5,000,000 and also where linked transactions reach the threshold, lawful provenance is uncertain or suspicion exists.
- Evidence to retain
- Aggregation test, identity record and escalation decision.
- Primary citation
- Law No. 12-008/AU, Article 9
Do not proceed where mandatory CDD fails.
- Implementation action
- Do not open, transact or continue the relationship when required CDD cannot be completed and file an STR in the circumstances required by the law.
- Evidence to retain
- Decline or exit decision, investigation and restricted STR record.
- Primary citation
- Law No. 12-008/AU, Article 8
04KYB, registries, and beneficial ownershipCorporate evidence does not replace natural-person ownership and control analysis.3 items+
Verify legal existence, governance and authority.
- Implementation action
- Obtain a current registration extract, constitutional documents, address, directors and signatory powers and reconcile inconsistencies.
- Evidence to retain
- Registry extract, statutes, powers and reconciliation.
- Primary citation
- Law No. 12-008/AU, Article 8; OHADA Uniform Acts
Identify and verify natural-person beneficial owners.
- Implementation action
- Understand the ownership and control structure, identify the natural persons who ultimately own or effectively control the customer, and verify them using reliable independent evidence.
- Evidence to retain
- Ownership chart, source records, control analysis and verified identities.
- Primary citation
- Law No. 12-008/AU, Articles 1 and 8
Do not assume a complete central beneficial-owner register.
- Implementation action
- Obtain current registry and authority evidence, reconcile it to customer-supplied ownership and control records, and document any information gap.
- Evidence to retain
- Registry search, customer declaration and discrepancy log.
- Primary citation
- GIABA 2024 Mutual Evaluation, Immediate Outcome 5 and Recommendation 24 analysis
05PEPs, EDD, and remote onboardingHigher-risk and remote relationships require enhanced controls.3 items+
Detect PEP exposure in customers and beneficial owners.
- Implementation action
- Use risk-sensitive systems to identify domestic, foreign and international-organisation PEPs, family members and close associates.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Decision No. 12-2023/BCC/DSBR, Articles 7-12
Apply PEP approval, source and monitoring measures.
- Implementation action
- Obtain senior approval, establish source of wealth and source of funds, and conduct enhanced ongoing monitoring.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Decision No. 12-2023/BCC/DSBR, Articles 7-8
Control remote-onboarding risk.
- Implementation action
- Apply identity, fraud, device, liveness and exception controls proportionate to the channel and do not lower CDD where suspicion exists.
- Evidence to retain
- Channel assessment, vendor review, tests and exceptions.
- Primary citation
- Law No. 12-008/AU, Article 8; Decision No. 12-2023/BCC/DSBR, Article 3
06Monitoring and suspicious reportingSRF reporting is immediate, traceable and confidential.3 items+
Monitor activity against the current customer profile.
- Implementation action
- Examine unusual, complex or apparently unjustified activity and preserve a reasoned conclusion.
- Evidence to retain
- Alerts, investigation, disposition and rule governance.
- Primary citation
- Law No. 12-008/AU, Articles 8 and 12
Report suspicious and attempted transactions immediately to the SRF.
- Implementation action
- File when funds are suspected or reasonably suspected to be criminal proceeds or connected to terrorism or terrorist financing, including attempts regardless of amount.
- Evidence to retain
- Decision chronology, report, receipt and supplemental-information log.
- Primary citation
- Law No. 12-008/AU, Article 25
Prevent tipping off.
- Implementation action
- Restrict access and do not disclose an STR, its contents or a related inquiry to the customer or an unauthorised third party.
- Evidence to retain
- Access logs, confidentiality procedure and training.
- Primary citation
- Law No. 12-008/AU, Article 28
07Payments, wires, thresholds, and agentsPayment controls preserve required data and separate CDD thresholds from reporting duties.3 items+
Do not treat the KMF 5,000,000 CDD trigger as a universal cash-report threshold.
- Implementation action
- Apply Article 9 identification and aggregation while confirming any current objective-reporting rule or sector threshold directly with the SRF and supervisor.
- Evidence to retain
- CDD trigger logic, authority confirmation and filing matrix.
- Primary citation
- Law No. 12-008/AU, Article 9
Preserve required wire-transfer information.
- Implementation action
- Collect and retain accurate originator and beneficiary information; refuse a transfer lacking required information and inform the SRF.
- Evidence to retain
- Message sample, exception workflow, refusal and SRF notice.
- Primary citation
- Law No. 12-008/AU, Article 11
Retain accountability for third parties and agents.
- Implementation action
- Perform due diligence, obtain required CDD information immediately, secure supporting documents on request and monitor performance; ultimate responsibility remains with the institution.
- Evidence to retain
- Due diligence, contract, retrieval test and monitoring.
- Primary citation
- Decision No. 12-2023/BCC/DSBR, Articles 13-15
08Targeted financial sanctionsUse current UN and national instruments and controlled escalation procedures.3 items+
Screen applicable designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, list updates and before relevant execution.
- Evidence to retain
- List inventory, update logs, screening configuration and dispositions.
- Primary citation
- Law No. 12-008/AU, Article 11; Law No. 21-004/AU
Freeze prohibited property and prevent dealing.
- Implementation action
- Immediately escalate a potential designation match, prevent prohibited movement or availability, and act under current competent-authority instructions.
- Evidence to retain
- Freeze procedure, timestamps, legal basis and authority communication.
- Primary citation
- Law No. 21-004/AU; applicable UN Security Council resolutions
Control false positives and release.
- Implementation action
- Document match analysis and obtain current authority instructions for reporting, false-positive resolution and lawful release; do not invent a national portal or deadline.
- Evidence to retain
- Match rationale, authority instruction, report and reconciliation.
- Primary citation
- Law No. 21-004/AU; GIABA 2024 Mutual Evaluation, Recommendations 6-7
09Records and regulator accessRecords must reconstruct the customer, ownership, transaction and decision.3 items+
Retain transaction records for at least five years.
- Implementation action
- Preserve sufficient domestic and international transaction records for at least five years from the transaction and longer where a legal hold applies.
- Evidence to retain
- Schedule, transaction reconstruction and legal-hold log.
- Primary citation
- Law No. 12-008/AU, Article 12
Retain CDD and analysis records for at least five years.
- Implementation action
- Preserve identity, account, correspondence and analysis records for at least five years after the relationship ends or the occasional transaction, as applicable.
- Evidence to retain
- Archive sample, configuration and retrieval test.
- Primary citation
- Law No. 12-008/AU, Article 12
Respond securely to competent-authority requests.
- Implementation action
- Authenticate requests, protect STR confidentiality, produce reproducibly and log scope, timing and receipt.
- Evidence to retain
- Request, approval, production index and acknowledgement.
- Primary citation
- Law No. 12-008/AU, Articles 13 and 22
10Privacy, biometrics, and transfersIdentity data requires proportionate safeguards even where AML duties mandate collection.3 items+
Map the legal basis and necessity for identity processing.
- Implementation action
- Document purpose, data, access, recipients, security and retention under current Comorian law and AML confidentiality duties.
- Evidence to retain
- Data inventory, legal assessment, notices and access matrix.
- Primary citation
- Law No. 12-008/AU, Articles 13, 21 and 28; applicable Comorian law
Apply enhanced safeguards to biometric and sensitive data.
- Implementation action
- Minimise collection, restrict access, test security and document necessity before biometric or sensitive-data use.
- Evidence to retain
- Impact assessment, security tests, access controls and approval.
- Primary citation
- Risk-based control; confirm current Comorian data-protection requirements
Confirm transfer and incident requirements before production use.
- Implementation action
- Obtain a dated local-law analysis and current authority guidance before configuring international transfers, breach notices or biometric processing.
- Evidence to retain
- Legal update, authority guidance and implemented procedure.
- Primary citation
- Controlled legal uncertainty; no unsupported deadline asserted
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervisory access.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Law No. 12-008/AU, Articles 8 and 12
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Law No. 12-008/AU, Articles 25-29
Primary-source register
11 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 12-008/AU - AML/CFTMinistry of Justice, Comoros · Primary legislation
- Law No. 21-004/AU - terrorism, financing and money launderingBanque Centrale des Comores · Primary legislation
- Decision No. 12-2023/BCC/DSBR - AML/CFT measuresBanque Centrale des Comores · Primary regulation
- Law No. 13-003/AU - banking lawBanque Centrale des Comores · Primary legislation
- Law No. 20-005/AU - payment services and providersBanque Centrale des Comores · Primary legislation
- Comoros Mutual Evaluation Report 2024FATF / GIABA · Authoritative country assessment
- Comoros Follow-up Report 2026FATF / GIABA · Authoritative follow-up assessment
- Comoros country pageFATF · Authoritative country status
- FATF black and grey listsFATF · Authoritative current status
- OHADA legal frameworkOHADA · Official company-law materials
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Comoros KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Service de Renseignements Financiers (SRF) of Comoros.
When is an STR filed?+
Immediately when an obliged person suspects or has reasonable grounds to suspect covered criminal proceeds or a terrorism-financing connection. Attempted suspicious transactions are covered regardless of amount.
Is KMF 5,000,000 a universal cash-report threshold?+
No. Article 9 states an occasional-customer identification trigger. Confirm any current objective-reporting duty or sector threshold directly with the SRF and supervisor.
How is beneficial ownership determined?+
Identify and verify the natural persons who ultimately own or effectively control the customer and understand the legal person's ownership and control structure.
How long are AML records retained?+
The core rule is at least five years, with the trigger depending on whether the record concerns a transaction, an occasional transaction or the end of a business relationship.
Is Comoros on a FATF public list?+
It was not named on the FATF high-risk or increased-monitoring lists current at 19 June 2026. The 2024 mutual evaluation and 2026 follow-up still identify material gaps.
Does privacy law affect KYC data?+
Yes, confidentiality, necessity, security and access controls remain relevant. Obtain current local advice before configuring biometrics, international transfers or incident deadlines.
Can a payment product launch without approval?+
No. Classify the product under current banking, payment and sector rules and obtain every required approval before launch.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 20 August 2026. Confirm reporting-entity status, current SRF filing specifications, sector thresholds, sanctions procedures, company and beneficial-owner information, privacy requirements and product licensing with the competent authority and qualified Comorian counsel before launch.