El Salvador KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in El Salvador.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the El Salvador compliance checklist cover?
The El Salvador checklist translates primary KYC, KYB and AML rules into 11 control areas and 37 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Investigación Financiera (UIF), an autonomous specialist office attached to the Fiscalía General de la República
- Primary AML rule
- Decree 426 special AML/CFT/CPF law, effective 24 October 2025
- Suspicion reporting
- Analyze within up to 15 business days; report to UIF within 24 hours after a suspicious determination
- Regulated reports
- Report covered linked transactions within 5 business days; transitional thresholds require current-instrument confirmation
- Beneficial owner
- Natural person with at least 25% ownership or voting rights, or control by other means
- Retention
- At least 15 years: transaction completion or relationship/account termination, depending on the record
- Privacy authority
- Agencia de Ciberseguridad del Estado (ACE)
- FATF status
- GAFILAT member; absent from FATF June 2026 public lists as reviewed 6 August 2026
Implementation detail
El Salvador compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingMap the business to Decree 426's closed subject categories and the applicable sector supervisor before onboarding.3 items+
Determine whether the entity is a subject obliged under the new special law.
- Implementation action
- Map each product and legal entity to article 7, including financial institutions, specified lenders, DNFBPs, money/value transport, digital-asset or bitcoin providers and political parties; document any out-of-scope conclusion.
- Evidence to retain
- Perimeter memorandum, product map, legal-entity chart and counsel confirmation.
- Primary citation
- Decree 426 arts. 1, 7-9
Identify the competent supervisor and complete required registrations or authorisations.
- Implementation action
- Confirm SSF, Superintendencia de Obligaciones Mercantiles, CNAD or other article 11-12 supervision; separately test financial, payments, bitcoin and digital-asset licensing before launch.
- Evidence to retain
- Supervisor mapping, licence analysis, registrations, approvals and correspondence.
- Primary citation
- Decree 426 arts. 11-13; Digital Assets Issuance Law arts. 18-20
Treat the regulation and UIF instruction as a controlled transition.
- Implementation action
- At launch and each rules refresh, verify whether the preserved 2000 regulation and current UIF instruction have been replaced under the 2025 law; apply only provisions that do not conflict with Decree 426.
- Evidence to retain
- Dated legal-update check, downloaded instruments and conflict analysis.
- Primary citation
- Decree 426 arts. 55-62; UIF current-law FAQ
02Governance and risk assessmentControls must be proportionate to identified AML/CFT/CPF risk and avoid unsupported blanket exclusion.3 items+
Operate a documented risk-based AML/CFT/CPF system.
- Implementation action
- Assess customer, product, channel, transaction and geographic risks; set simplified, standard or enhanced controls and obtain governance approval.
- Evidence to retain
- Enterprise risk assessment, methodology, risk appetite, control matrix and approval minutes.
- Primary citation
- Decree 426 arts. 9, 13, 15-17
Appoint the required compliance function and deputies.
- Implementation action
- For SSF-, CNAD- and article 7(2)-supervised entities establish a compliance office with principal and alternate; other supervised entities must appoint a principal and alternate unless a statutory exception applies.
- Evidence to retain
- Board resolutions, role profiles, independence record, UIF/supervisor filings and training evidence.
- Primary citation
- Decree 426 arts. 20-22
Create the prevention committee when a compliance office is mandatory.
- Implementation action
- Maintain a committee of at least three members, including one member of the highest governing body and the compliance officer, with recorded decisions.
- Evidence to retain
- Committee charter, appointments, meeting book and action log.
- Primary citation
- Decree 426 art. 23
03Natural-person identificationIdentification and verification must be risk-based, reconstructable and completed for the relationship and relevant occasional activity.3 items+
Identify and verify the customer and any representative.
- Implementation action
- Collect authoritative identity data, verify the document and person, validate authority for representatives, screen, risk-rate and record purpose before activation.
- Evidence to retain
- Identity evidence, liveness or equivalent checks, authority document, screening log and onboarding decision.
- Primary citation
- Decree 426 art. 15
Apply CDD at statutory trigger points.
- Implementation action
- Perform CDD when establishing a relationship, for occasional transactions above the applicable cash-report threshold, on suspicion, or when prior identity data is doubtful; obtain current sector thresholds before deployment.
- Evidence to retain
- Trigger matrix, transaction evidence, refresh record and escalation log.
- Primary citation
- Decree 426 art. 15
Do not maintain anonymous or coded relationships.
- Implementation action
- Require nominative customer records and block product activation where required identity evidence is not provided; consider a suspicious-attempt report after analysis.
- Evidence to retain
- Account configuration, rejection record and documented reporting decision.
- Primary citation
- Decree 426 art. 15
04KYB, registries, and beneficial ownershipCompany verification must combine registry evidence with independent ownership-and-control analysis.4 items+
Verify legal existence, representatives, activity and powers.
- Implementation action
- Obtain a current CNR Registro de Comercio certification or equivalent source, constitutive documents, tax details, business address and authority chain; independently verify material facts.
- Evidence to retain
- Registry certification, formation documents, tax evidence, address check and authority map.
- Primary citation
- Decree 426 art. 15; Commercial Code; CNR Registro de Comercio
Identify natural persons meeting the statutory beneficial-owner test.
- Implementation action
- Trace direct and indirect ownership and voting rights to every natural person at or above 25%, and identify any natural person exercising control by other means.
- Evidence to retain
- Ownership chart, cap table, registry documents, shareholder evidence and control analysis.
- Primary citation
- Decree 426 art. 15
Apply the listed-company exception narrowly.
- Implementation action
- Use the exception only where the client or owner has at least 25% in a listed commercial company subject to market disclosure requirements; document the market and disclosure basis.
- Evidence to retain
- Listing evidence, disclosure-rule analysis and approval.
- Primary citation
- Decree 426 art. 15
Do not treat registry access as proof of a comprehensive public BO register.
- Implementation action
- Use CNR company records as one input and obtain ownership/control evidence directly; confirm current beneficial-ownership filing and access arrangements with CNR and the supervisor.
- Evidence to retain
- CNR search, certified extracts, customer declaration, corroboration and uncertainty log.
- Primary citation
- CNR Registro de Comercio services; controlled uncertainty
05PEPs, EDD, and remote onboardingHigh-risk relationships require verified source information and a documented, individualized decision.3 items+
Identify domestic, foreign and international-organisation PEPs.
- Implementation action
- Screen customers, beneficial owners, representatives and connected parties; continue PEP treatment for five years after the last appointment and apply enhanced diligence to specified family and close associates.
- Evidence to retain
- Screening results, position verification, relationship mapping and five-year control.
- Primary citation
- Decree 426 art. 19
Verify source of wealth and source of funds for high-risk customers.
- Implementation action
- Collect and corroborate wealth and funds evidence proportionate to risk and obtain the required senior approval before activation or continuation.
- Evidence to retain
- Source dossier, corroboration, risk rationale, approval and monitoring plan.
- Primary citation
- Decree 426 arts. 15, 19; current UIF instruction
Make remote onboarding equivalent and auditable.
- Implementation action
- Use authoritative document validation, impersonation and liveness controls, device and channel signals, sanctions/PEP screening, step-up checks and manual exception review.
- Evidence to retain
- Vendor testing, model thresholds, session record, fraud results and exception approvals.
- Primary citation
- Decree 426 arts. 15-17; risk-based implementation control
06Monitoring and suspicious reportingUnusual activity must be analyzed promptly and reports sent confidentially through UIF-authorized channels.4 items+
Monitor relationships and investigate unusual activity.
- Implementation action
- Calibrate scenarios to the risk assessment, preserve alert inputs, investigate context and document whether sufficient grounds for suspicion exist.
- Evidence to retain
- Scenario inventory, alert file, analyst workpaper, disposition and quality review.
- Primary citation
- Decree 426 arts. 9, 15, 24
Complete unusual-operation analysis within the statutory window.
- Implementation action
- Finish analysis within 15 business days of detection; request the single permitted equal extension from UIF through the compliance officer when justified.
- Evidence to retain
- Detection timestamp, case chronology, extension request and UIF response.
- Primary citation
- Decree 426 art. 24
Report suspicious, attempted and suspicious-activity cases to UIF.
- Implementation action
- After determining suspicion, submit the authorized report promptly and no later than 24 hours, regardless of amount, using the current UIF channel and format.
- Evidence to retain
- Decision timestamp, submitted report, receipt, supporting file and access log.
- Primary citation
- Decree 426 arts. 3-4, 24
Protect report confidentiality and prevent tipping off.
- Implementation action
- Restrict report and UIF-request access; do not disclose reports or related requests to customers, users, third parties, auditors or supervisors except as lawfully directed.
- Evidence to retain
- Restricted permissions, disclosure protocol, staff attestations and incident log.
- Primary citation
- Decree 426 arts. 24, 28
07Payments, wires, thresholds, and digital assetsThreshold reporting and regulated financial or digital-asset activity require current parameter and licence checks.4 items+
Report regulated transactions within five business days.
- Implementation action
- Aggregate transactions in one event or over a month where they appear linked, and report covered cash, other-means, local/international electronic-transfer and digital-asset transactions to UIF within five business days.
- Evidence to retain
- Aggregation logic, threshold table, report files, receipts and timeliness metrics.
- Primary citation
- Decree 426 art. 25
Confirm transitional thresholds before configuring production.
- Implementation action
- Reconcile Decree 426, any new regulation and the preserved UIF instruction. UIF's current FAQ states instruction thresholds above USD 10,000 cash, USD 25,000 other means and USD 1,000 electronic transfers; do not generalize them without sector confirmation.
- Evidence to retain
- Dated instrument set, supervisor confirmation, configuration approval and change log.
- Primary citation
- Decree 426 arts. 25, 61; UIF current-law FAQ
Preserve complete originator and beneficiary information for transfers.
- Implementation action
- Collect, validate, transmit and retain the fields required by the applicable BCR/SSF/UIF or CNAD instrument; pause or escalate incomplete transfers under the current sector rule.
- Evidence to retain
- Message fields, validation logs, exception queue and current-rule mapping.
- Primary citation
- Decree 426 arts. 15, 25-26; current sector instruments
Register digital-asset services with CNAD where the territorial and service tests apply.
- Implementation action
- Before offering article 19 digital-asset services from El Salvador or actively marketing them into the country, complete CNAD registration and confirm UIF obligations; separately analyze bitcoin services supervised by SSF.
- Evidence to retain
- Territorial analysis, CNAD registration, public-register check, UIF record and SSF analysis.
- Primary citation
- Digital Assets Issuance Law arts. 18-20; Decree 426 arts. 7, 12
08Targeted financial sanctionsScreening must cover binding designations and produce an immediate, traceable escalation.3 items+
Screen UN and applicable national designations continuously.
- Implementation action
- Screen customers, beneficial owners, representatives and transactions at onboarding, list change and before value movement using UIF-published access points.
- Evidence to retain
- List sources, update logs, screening results, match records and test evidence.
- Primary citation
- Special Law Against Acts of Terrorism art. 37; Decree 426 arts. 10, 32; UIF international-lists portal
Prevent dealing and freeze on a confirmed designation match without delay.
- Implementation action
- Stop transactions immediately, preserve assets and notify through the current UIF/FGR process; do not release funds without competent authority direction.
- Evidence to retain
- Match chronology, freeze record, report receipt, communications and release authority.
- Primary citation
- Special Law Against Acts of Terrorism art. 37; Decree 426 arts. 10, 32
Control false positives, delisting and exceptions.
- Implementation action
- Use a documented escalation that protects confidentiality and obtains UIF/FGR or judicial direction for unfreezing, delisting or permitted access; confirm live procedure before launch.
- Evidence to retain
- Escalation file, identity comparison, authority response and audit trail.
- Primary citation
- UIF sanctions guidance and exercises; controlled uncertainty
09Records and regulator accessThe 2025 law materially extends AML records to at least 15 years.3 items+
Retain reconstructable transaction records for at least 15 years.
- Implementation action
- Preserve domestic and international transaction records for at least 15 years from completion, sufficient to reconstruct each transaction and answer authority requests immediately.
- Evidence to retain
- Retention schedule, transaction archive, retrieval tests and deletion holds.
- Primary citation
- Decree 426 art. 26
Retain customer identification and account files for at least 15 years after exit.
- Implementation action
- Start the period at relationship termination or account closure; preserve legal holds and secure electronic accessibility.
- Evidence to retain
- Closure date, customer file archive, legal-hold record and retrieval test.
- Primary citation
- Decree 426 art. 26
Respond securely to UIF, supervisor, FGR and court requests.
- Implementation action
- Authenticate requests, preserve scope and chain of custody, meet the stated deadline and keep a restricted disclosure log.
- Evidence to retain
- Request register, authentication, production manifest and transmission receipt.
- Primary citation
- Decree 426 arts. 4, 26, 28, 52-53
10Privacy, biometrics, and transfersAML processing must also satisfy the Personal Data Protection Law and ACE policy, subject to lawful AML retention and disclosure duties.4 items+
Document a lawful, transparent and minimized KYC processing design.
- Implementation action
- Map each data element and purpose, provide required notices, identify the lawful basis, minimize collection and reconcile deletion rights with the 15-year AML retention duty.
- Evidence to retain
- Processing register, privacy notice, purpose/basis matrix, retention reconciliation and rights procedure.
- Primary citation
- Personal Data Protection Law arts. 5 and 24; Decree 426 art. 26
Apply enhanced safeguards to sensitive and biometric data.
- Implementation action
- Complete an impact assessment, restrict access, encrypt data, test biometric vendors and document necessity, proportionality and fallback paths.
- Evidence to retain
- Impact assessment, security design, vendor diligence, test results and access logs.
- Primary citation
- Personal Data Protection Law; ACE Policies 001-0309025-DPDP arts. 3-6
Prepare breach notification and response workflows.
- Implementation action
- Detect, contain and assess incidents and maintain a workflow capable of notifying ACE, FGR and affected individuals within 72 hours where the ACE policy requires it.
- Evidence to retain
- Incident plan, severity assessment, decision log, notifications and post-incident review.
- Primary citation
- ACE Policies 001-0309025-DPDP art. 4
Control processors and international transfers.
- Implementation action
- Contract for confidentiality, security, auditability and deletion; assess equivalent protection for international transfers and preserve a current data-flow map.
- Evidence to retain
- Processor contracts, transfer assessment, country map, encryption evidence and approval.
- Primary citation
- Personal Data Protection Law; ACE Policies 001-0309025-DPDP art. 4
11Practical evidence packsEvidence should enable independent reconstruction of onboarding, monitoring, reporting and governance decisions.3 items+
Maintain one indexed file per customer or legal entity.
- Implementation action
- Link identity, KYB, beneficial ownership, screening, risk, approvals, monitoring, refreshes, source evidence and exit decisions under immutable identifiers.
- Evidence to retain
- Evidence index, version history, access history and sample reconstruction test.
- Primary citation
- Decree 426 arts. 15, 19, 26
Test data, screening, reporting and retention controls.
- Implementation action
- Run periodic samples and scenario tests covering identity, 25% and control BO logic, PEP duration, threshold aggregation, ROS clocks, sanctions and 15-year retention.
- Evidence to retain
- Test plan, samples, defects, remediation owners and closure proof.
- Primary citation
- Decree 426 arts. 13, 15, 19, 24-26
Operate a dated legal-change control.
- Implementation action
- Before launch and periodically thereafter check UIF, SSF, BCR, CNAD, CNR, ACE, FATF and GAFILAT sources; route changes into policy, rules, training and customer remediation.
- Evidence to retain
- Source register, legal-change log, impact assessment and deployment record.
- Primary citation
- Decree 426 arts. 55-61; risk-based implementation control
Primary-source register
12 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Special AML/CFT/CPF Law - Decree 426Unidad de Investigación Financiera · Primary legislation
- Current-law frequently asked questionsUnidad de Investigación Financiera · Official current guidance
- UIF instructions and guidesUnidad de Investigación Financiera · Official guidance portal
- International sanctions lists portalUnidad de Investigación Financiera · Official sanctions guidance
- El Salvador 2024 mutual evaluationFATF / GAFILAT · Authoritative mutual evaluation
- FATF high-risk jurisdictions - June 2026Financial Action Task Force · Authoritative current-status statement
- FATF jurisdictions under increased monitoring - June 2026Financial Action Task Force · Authoritative current-status statement
- Registro de Comercio servicesCentro Nacional de Registros · Official company registry portal
- Personal Data Protection Law - Decree 144Asamblea Legislativa · Primary legislation
- ACE personal-data handling policiesAgencia de Ciberseguridad del Estado · Official privacy guidance
- Digital Assets Issuance Law with reformsComisión Nacional de Activos Digitales · Primary legislation
- Digital-asset service-provider registrationComisión Nacional de Activos Digitales · Official licensing guidance
Direct answers
El Salvador KYC, KYB and AML questions
Who receives suspicious reports in El Salvador?+
The Unidad de Investigación Financiera (UIF), the national financial intelligence office attached to the Fiscalía General de la República.
When must a suspicious operation be reported?+
The subject has up to 15 business days from detection to analyze an unusual operation, with one equal extension available on request; after determining suspicion, the authorized report must be sent promptly and within 24 hours.
What regulated-transaction reporting applies?+
Article 25 covers linked cash, other-means, electronic-transfer and digital-asset transactions and requires reporting within five business days. The current UIF FAQ describes transitional instruction thresholds above USD 10,000 cash, USD 25,000 other means and USD 1,000 electronic transfers; confirm the applicable current sector instrument.
What is the beneficial-owner threshold?+
Identify natural persons who directly or indirectly own or control at least 25% of capital or voting rights, plus natural persons exercising control by other means.
How long must AML records be retained?+
At least 15 years. Transaction records run from transaction completion; customer identification and account files run from relationship termination or account closure.
Is the company or beneficial-ownership registry public?+
CNR provides Registro de Comercio services and certifications, but this checklist does not represent that a comprehensive public beneficial-ownership register is available. Confirm current filing fields and access with CNR and the supervisor.
Who supervises digital-asset services?+
CNAD supervises digital-asset service providers under its law and register. SSF supervises providers performing bitcoin operations under the new AML law. The exact service and territorial perimeter must be analyzed before marketing or launch.
Who is the personal-data authority?+
The Agencia de Ciberseguridad del Estado (ACE) is the governing authority under the Personal Data Protection Law and has issued handling and security policies.
Is El Salvador on a FATF public list?+
As reviewed on 6 August 2026, El Salvador was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck both live statements before reliance.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, a licence determination or a substitute for the operative Spanish texts and current supervisor instructions. Reviewed 6 August 2026. Confirm whether replacement regulations or UIF instructions have been issued, the applicable sector reporting parameters, registry access, sanctions escalation route, privacy guidance and licensing perimeter with the UIF, relevant supervisor and qualified Salvadoran counsel before launch.