Guatemala KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Guatemala.
- Last reviewed
- Last reviewed:
- Version
- Version 1.1

Direct answer
What does the Guatemala compliance checklist cover?
The Guatemala checklist translates primary KYC, KYB and AML rules into 11 control areas and 36 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Intendencia de Verificación Especial (IVE), within the Superintendencia de Bancos
- Current rules
- Decrees 67-2001 and 58-2005 remain applicable through 16 September 2026
- Enacted transition
- Decree 15-2026 enters into force on 17 September 2026
- Suspicion reporting
- Report suspicious transactions to IVE immediately after the compliance-officer determination
- Cash record threshold
- Current rule: above USD 10,000; Decree 15-2026: USD 10,000 or more from 17 September 2026
- Retention
- At least 5 years after transaction completion or relationship termination, according to record type
- Company registry
- Registro Mercantil General, Ministry of Economy
- Privacy position
- No enacted comprehensive private-sector data-protection law identified; constitutional and sector rules still apply
- FATF status
- GAFILAT member; absent from FATF June 2026 public lists as reviewed 7 August 2026
Implementation detail
Guatemala compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingMap every entity and service to the statutory obliged-person categories and its sector licence before launch.4 items+
Determine obliged-person status for the current and incoming regimes.
- Implementation action
- Map each entity, product and channel to the current Decree 67-2001/58-2005 perimeter and separately to Decree 15-2026 articles 3-5; preserve effective-dated counsel support.
- Evidence to retain
- Two-period perimeter memorandum, product map, entity chart and legal sign-off.
- Primary citation
- Decree 67-2001 art. 18; Agreement 118-2002 art. 5; Decree 58-2005 art. 15; Decree 15-2026 arts. 3-5
Register with IVE and identify the competent supervisor where required.
- Implementation action
- Complete current IVE registration and appoint the required contact before regulated operations; separately identify SIB, Junta Monetaria or other sector oversight.
- Evidence to retain
- Registration receipt, supervisor map, correspondence and renewal calendar.
- Primary citation
- Decree 67-2001 arts. 18, 32-33; Agreement 118-2002 arts. 5, 36
Complete product-specific licensing analysis.
- Implementation action
- Test banking, finance, insurance, securities, money transmission, payments, remittance and virtual-asset activities against current sector law and IVE instructions; do not infer authorisation from AML registration.
- Evidence to retain
- Licence memorandum, approvals, legal opinions and launch conditions.
- Primary citation
- Financial-sector laws and current SIB/Junta Monetaria/IVE instruments; controlled uncertainty
Implement the enacted 17 September 2026 transition.
- Implementation action
- Maintain an effective-dated change plan for Decree 15-2026, including expanded scope, risk assessment/manual, compliance function, 15% beneficial-owner test, prompt RTS, cash records at USD 10,000 or more and updated instructions; do not apply repeals before commencement.
- Evidence to retain
- Transition plan, gap assessment, board approval, rule releases, training and launch evidence.
- Primary citation
- Decree 15-2026 arts. 2-5, 8-18, 21-34 and commencement provision
02Governance and risk assessmentThe compliance programme must reflect the institution's actual customers, products, channels and locations.3 items+
Maintain a documented AML/CFT risk assessment and control programme.
- Implementation action
- Assess customer, product, service, channel and geographic risk; assign proportionate controls and obtain governing-body approval.
- Evidence to retain
- Risk assessment, methodology, risk appetite, control matrix and minutes.
- Primary citation
- Decree 67-2001 arts. 19-20; Agreement 118-2002 arts. 9-11; Decree 58-2005 art. 15
Appoint an eligible compliance officer and provide independence and resources.
- Implementation action
- Obtain the approvals required for the relevant obliged-person class, notify IVE, define direct escalation and appoint cover.
- Evidence to retain
- Appointment, eligibility file, IVE notice, mandate, budget and reporting records.
- Primary citation
- Decree 67-2001 art. 19; Agreement 118-2002 arts. 21-22, 36
Train personnel and independently test the programme.
- Implementation action
- Deliver role-based onboarding and recurring training and arrange periodic independent review with tracked remediation.
- Evidence to retain
- Curriculum, attendance, assessments, review reports and closure evidence.
- Primary citation
- Decree 67-2001 art. 19; Agreement 118-2002 arts. 10-11
03Natural-person identificationCustomer records must identify the person, purpose and expected activity and remain current.3 items+
Identify and reasonably verify customers and representatives.
- Implementation action
- Collect official identity, address, occupation or activity, purpose and expected activity; validate representatives and their authority before activation.
- Evidence to retain
- Identity copy, validation results, address evidence, authority record and onboarding decision.
- Primary citation
- Decree 67-2001 arts. 21-22; Agreement 118-2002 arts. 12-14; current IVE FEIC instructions
Keep customer information current.
- Implementation action
- Refresh information according to risk and current IVE instructions, investigate material changes and retain the prior version.
- Evidence to retain
- Refresh schedule, changed-field log, corroboration and approval.
- Primary citation
- Decree 67-2001 arts. 21-23; Agreement 118-2002 arts. 13-14
Reject anonymous or fictitious relationships and control failed CDD.
- Implementation action
- Block activation where identity or authority cannot be established; document whether attempted or suspicious conduct requires an IVE report.
- Evidence to retain
- System configuration, rejection file, escalation and reporting decision.
- Primary citation
- Decree 67-2001 arts. 20-22; Agreement 118-2002 arts. 12-16
04KYB, registries, and beneficial ownershipRegistry documents are a starting point and do not replace natural-person ownership and control analysis.3 items+
Verify legal existence, activity and representation.
- Implementation action
- Obtain current Registro Mercantil certifications, constitutive documents, tax identifier, address and appointment/power evidence and independently verify material facts.
- Evidence to retain
- Registry extract, deeds, tax record, address check and authority map.
- Primary citation
- Commercial Code art. 334; Decree 67-2001 arts. 21-23; Registro Mercantil official services
Identify and verify the natural persons who ultimately own or control the customer.
- Implementation action
- Under current law apply the controlling IVE instruction for the sector. From 17 September 2026, implement Decree 15-2026's natural-person ownership/control test, including the 15% threshold and control/benefit routes, against the exact final text and regulations.
- Evidence to retain
- Effective-dated ownership chart, cap table, shareholder documents, control analysis and identity files.
- Primary citation
- Current IVE instructions; Decree 15-2026 art. 2(b), arts. 21-27
Do not treat the commercial registry as a comprehensive public BO register.
- Implementation action
- Use registry evidence together with customer declarations and independent corroboration; confirm current BO filing fields and competent-authority access with IVE and Registro Mercantil.
- Evidence to retain
- Registry search, declarations, corroboration and uncertainty log.
- Primary citation
- Registro Mercantil official scope; controlled uncertainty
05PEPs, enhanced diligence, and remote onboardingHigher-risk relationships require additional information, approval and monitoring.3 items+
Identify PEPs, family members and close associates under current IVE rules.
- Implementation action
- Screen customers, beneficial owners and representatives at onboarding and refresh; document position, relationship, risk and the applicable post-office period.
- Evidence to retain
- Screening record, position source, relationship map and review schedule.
- Primary citation
- Current IVE PEP and FEIC instructions; Agreement 118-2002 arts. 12-15
Apply enhanced diligence proportionate to risk.
- Implementation action
- Obtain senior approval and corroborate source of funds and, where risk requires, source of wealth; increase review and monitoring frequency.
- Evidence to retain
- Source dossier, approval, risk rationale and monitoring plan.
- Primary citation
- Decree 67-2001 arts. 19-22; current IVE instructions
Make remote onboarding equivalent and auditable.
- Implementation action
- Validate authoritative documents, person presence or equivalent fraud controls, device/channel signals and sanctions/PEP results; route exceptions to manual review.
- Evidence to retain
- Vendor tests, session evidence, fraud results and exception approvals.
- Primary citation
- Current IVE FEIC instructions; risk-based implementation control
06Monitoring and suspicious reportingUnusual activity must be examined and suspicious activity reported confidentially to IVE.4 items+
Monitor and document unusual transactions.
- Implementation action
- Calibrate scenarios to risk and expected activity, preserve alert inputs, investigate context and maintain a numbered case file even when suspicion is not established.
- Evidence to retain
- Scenario inventory, alert, workpaper, disposition and quality review.
- Primary citation
- Decree 67-2001 art. 26; Agreement 118-2002 art. 15
Report suspicious transactions to IVE immediately after determination.
- Implementation action
- The compliance officer must use the current IVE form and channel once the activity is determined suspicious; retain the transmission acknowledgement and supporting file.
- Evidence to retain
- Decision timestamp, report, receipt, support and access log.
- Primary citation
- Decree 67-2001 art. 26; Agreement 118-2002 art. 16
Apply CFT reporting to suspicious funds and transactions.
- Implementation action
- Report to IVE using the current procedure where there are reasonable grounds concerning terrorist financing, irrespective of amount, and preserve the decision trail.
- Evidence to retain
- Case analysis, CFT report, receipt and chronology.
- Primary citation
- Decree 58-2005 arts. 16-18; Agreement 86-2006
Prevent tipping off and restrict access.
- Implementation action
- Do not disclose an IVE report or request to the customer or unauthorized persons; enforce need-to-know access and incident escalation.
- Evidence to retain
- Permissions, confidentiality attestations, disclosure log and incident record.
- Primary citation
- Decree 67-2001 art. 27; Decree 58-2005 art. 19
07Cash, transfers, and regulated activityThresholds have distinct triggers and must not be generalized beyond their operative provision or IVE instruction.4 items+
Apply the correct effective-dated cash record trigger.
- Implementation action
- Through 16 September 2026 record cash transactions above USD 10,000 or equivalent under the current rule. From 17 September configure Decree 15-2026's daily record for cash transactions at or above USD 10,000, subject to final IVE forms.
- Evidence to retain
- Effective-dated threshold rule, boundary tests, form, receipt and exception log.
- Primary citation
- Decree 67-2001 art. 24; Agreement 118-2002 arts. 19-20; Decree 15-2026 art. 31
Support cross-border currency declarations at USD 10,000 or more.
- Implementation action
- For covered transport into or out of Guatemala, use the SAT/IVE declaration procedure and escalate undeclared or suspicious movement.
- Evidence to retain
- Declaration, transport record, review and escalation.
- Primary citation
- Decree 67-2001 art. 25; Agreement 118-2002 art. 37
Preserve required originator and beneficiary transfer information.
- Implementation action
- Collect, validate, transmit and retain fields required by the current sector rule; hold or escalate incomplete transfers under that rule.
- Evidence to retain
- Message fields, validation logs, exception queue and rule mapping.
- Primary citation
- Decree 67-2001 arts. 21-24; applicable SIB/Junta Monetaria/IVE instruments
Confirm virtual-asset, remittance, payment and money-transmission perimeter.
- Implementation action
- Obtain current IVE and sector-regulator confirmation for the exact service, custody, exchange, transfer, territorial and solicitation model before launch.
- Evidence to retain
- Product analysis, authority correspondence, registration and licence evidence.
- Primary citation
- Current IVE obliged-person designations and sector law; controlled uncertainty
08Targeted financial sanctionsSanctions controls must use binding current lists and an authority-confirmed escalation path.3 items+
Screen UN designations and applicable domestic measures.
- Implementation action
- Screen customers, beneficial owners, representatives and transactions at onboarding, list change and before value movement.
- Evidence to retain
- List sources, update logs, results, match files and test evidence.
- Primary citation
- Decree 58-2005; Agreement 86-2006; UN Security Council consolidated list
Act without delay on a confirmed designation match.
- Implementation action
- Prevent dealing, preserve assets and notify IVE and other competent authority through the current legal procedure; do not release without authority.
- Evidence to retain
- Match chronology, restriction record, notice, receipt and release authority.
- Primary citation
- Decree 58-2005 and Agreement 86-2006; current IVE procedure
Control false positives, delisting and permitted access.
- Implementation action
- Use identity comparison and a confidential escalation route; obtain IVE or competent-authority direction for release, exceptions or delisting and confirm the live process before launch.
- Evidence to retain
- Comparison file, escalation, authority response and audit trail.
- Primary citation
- Current IVE/competent-authority procedure; controlled uncertainty
09Records and authority accessRecords must be reconstructable, protected and retrievable throughout the statutory period.3 items+
Retain transaction records for at least five years.
- Implementation action
- Preserve records sufficient to reconstruct domestic and international transactions for at least five years after completion, subject to any longer sector rule or authority hold.
- Evidence to retain
- Retention schedule, archive, retrieval tests and holds.
- Primary citation
- Decree 67-2001 art. 23; Agreement 118-2002 art. 14
Retain customer files for at least five years after relationship termination.
- Implementation action
- Preserve identification, verification, ownership, risk, monitoring and correspondence from the documented end date and suspend deletion for legal holds.
- Evidence to retain
- Closure record, archive, deletion control and retrieval test.
- Primary citation
- Decree 67-2001 art. 23; Agreement 118-2002 art. 14
Respond securely to IVE and lawful authority requests.
- Implementation action
- Authenticate the request, preserve scope and chain of custody, meet the stated deadline and log secure production.
- Evidence to retain
- Request register, authentication, manifest and transmission receipt.
- Primary citation
- Decree 67-2001 arts. 28, 33; Decree 58-2005 arts. 20-23
10Privacy, biometrics, and transfersGuatemala has no enacted comprehensive private-sector data law identified as at review; constitutional, access-to-information, confidentiality, cybercrime and sector rules still constrain KYC processing.3 items+
Document lawful, necessary and secure KYC processing.
- Implementation action
- Map data and purpose, give clear notice, minimize collection, restrict access and reconcile deletion with AML retention and authority-disclosure duties.
- Evidence to retain
- Data map, notice, access matrix, retention analysis and rights workflow.
- Primary citation
- Constitution arts. 24, 30-31; Decree 57-2008 arts. 9, 30-35; AML confidentiality duties
Apply enhanced safeguards to biometrics and sensitive data.
- Implementation action
- Assess necessity and proportionality, encrypt data, test vendors, limit reuse and offer a controlled fallback where practicable.
- Evidence to retain
- Impact assessment, vendor diligence, security tests, access logs and fallback design.
- Primary citation
- Constitutional privacy and sector confidentiality; risk-based implementation control
Control processors, incidents and international access.
- Implementation action
- Contract for confidentiality, security, incident notice, auditability, return/deletion and lawful authority access; maintain a tested response plan and data-flow map.
- Evidence to retain
- Contracts, incident plan, transfer map, tests and decisions.
- Primary citation
- Sector confidentiality and cybercrime rules; controlled uncertainty
11Practical evidence packsEvidence must permit independent reconstruction of every onboarding, monitoring and reporting decision.3 items+
Maintain one indexed evidence file per customer or entity.
- Implementation action
- Link identity, KYB, ownership/control, screening, risk, approvals, monitoring, refreshes and exit under immutable identifiers.
- Evidence to retain
- Evidence index, version history, access history and reconstruction test.
- Primary citation
- Decree 67-2001 arts. 21-23; Agreement 118-2002 arts. 12-16
Test identity, reporting, screening and retention controls.
- Implementation action
- Sample customer files and test cash logic, suspicious-report workflow, sanctions updates and five-year retention; assign and close defects.
- Evidence to retain
- Test plan, samples, defects, owners and closure proof.
- Primary citation
- Decree 67-2001 arts. 19-26; Agreement 118-2002 arts. 9-20
Operate a dated legal-change control.
- Implementation action
- Monitor Congress, Diario de Centro América, SIB/IVE, Junta Monetaria, Registro Mercantil, FATF, GAFILAT and CFATF; track Decree 15-2026 regulations and instructions into controls before 17 September 2026.
- Evidence to retain
- Source register, change log, impact assessment and deployment record.
- Primary citation
- Decree 15-2026 commencement provision; risk-based implementation control
Primary-source register
13 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Integrated AML/CFT Law - Decree 15-2026 (effective 17 September 2026)Congress of Guatemala · Enacted primary legislation
- Law Against Money or Other Asset Laundering - Decree 67-2001Superintendencia de Bancos · Primary legislation currently applicable
- Terrorist-Financing Law - Decree 58-2005Congress of Guatemala · Primary legislation currently applicable
- Regulation to Decree 67-2001 - Government Agreement 118-2002Superintendencia de Bancos · Primary regulation
- Regulation to the Terrorist-Financing Law - Government Agreement 86-2006Superintendencia de Bancos · Primary regulation
- Superintendencia de Bancos and IVE official portalSuperintendencia de Bancos · Official regulator portal
- Registro Mercantil GeneralMinisterio de Economía · Official company registry portal
- Access to Public Information Law - Decree 57-2008Congress of Guatemala · Primary legislation
- Guatemala mutual evaluation 2016FATF / GAFILAT / CFATF · Authoritative mutual evaluation
- FATF high-risk jurisdictions - June 2026Financial Action Task Force · Authoritative current-status statement
- FATF jurisdictions under increased monitoring - June 2026Financial Action Task Force · Authoritative current-status statement
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Authoritative sanctions list
- Decree 15-2026 commencement noticeCongress of Guatemala · Official applicability notice
Direct answers
Guatemala KYC, KYB and AML questions
Who receives suspicious transaction reports in Guatemala?+
The Intendencia de Verificación Especial (IVE), within the Superintendencia de Bancos.
When must a suspicious transaction be reported?+
Once the compliance officer determines that a transaction is suspicious, the obliged person must communicate it immediately to IVE using the current form and channel.
What cash threshold applies?+
Through 16 September 2026, Decree 67-2001 requires records above USD 10,000. From 17 September, Decree 15-2026 article 31 uses USD 10,000 or more. Cross-border transport has a separate USD 10,000-or-more declaration trigger.
What beneficial-owner test applies?+
Through 16 September 2026 apply the controlling current IVE instruction. From 17 September, Decree 15-2026 introduces a 15% natural-person ownership threshold plus control and benefit routes; reconcile the exact final text and implementing rules.
How long must AML records be kept?+
At least five years, with the trigger depending on whether the record concerns a completed transaction or a terminated customer relationship; longer sector rules or legal holds may apply.
Is there a public comprehensive beneficial-ownership register?+
This checklist does not represent that Guatemala has a comprehensive public BO register. Registro Mercantil certifies company and representative information; obtain ownership/control evidence independently and confirm competent-authority access.
Does Guatemala have a comprehensive data-protection law?+
No enacted comprehensive private-sector data-protection law was identified as at 7 August 2026. Constitutional privacy, habeas-data rules for public records, confidentiality, cybercrime and sector requirements still apply.
Is Guatemala on a FATF public list?+
As reviewed on 7 August 2026, Guatemala was not named in FATF's June 2026 high-risk or increased-monitoring statements. Recheck both live statements before reliance.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed 7 August 2026; legal applicability is stated as of that date. Decree 15-2026 becomes applicable on 17 September 2026. Confirm transitional regulations, IVE instructions, reporting forms/channels, sanctions procedures, privacy requirements and product-specific licensing with IVE, the competent supervisor and qualified Guatemalan counsel before launch.