الإكوادور KYC, KYB & AML compliance checklist
قائمة عملية وموثقة بالمصادر لتنفيذ متطلبات KYC وKYB وAML في الإكوادور.
- تاريخ آخر مراجعة
- تاريخ آخر مراجعة:
- الإصدار
- الإصدار 1.3

إجابة مباشرة
ما الذي تغطيه قائمة الامتثال الخاصة بـ الإكوادور؟
تحوّل قائمة الإكوادور قواعد KYC وKYB وAML الأساسية إلى 11 مجالات رقابية و50 فحوص تنفيذ، وتشمل الجهات المختصة وواجبات الإبلاغ والأدلة الواجب الاحتفاظ بها.
حقائق تنظيمية أساسية
- National FIU
- Unidad de Analisis Financiero y Economico (UAFE)
- Core framework
- 2024 Organic AML Law, effective 29 July 2025, and Executive Decree 298 of 2 February 2026
- Suspicious reports
- Within 5 business days from compliance-committee awareness, or entity awareness where no committee exists, regardless of amount
- Threshold reports
- USD 10,000 individual or aggregated for the same beneficiary within a 30-day period; file within the first 15 days of the following month
- No-report records
- Register NO ROS and NO RESU within 10 business days after the end of each month in which no corresponding report exists
- Retention
- 10 years after relationship termination, the last transaction or the occasional transaction, as applicable; transfer data also 10 years
- Beneficial owner
- At least 10% capital, control by other means, then highest-ranking managing official fallback
- PEP period
- At least 2 years after leaving office, followed by a documented risk reassessment
- Privacy authority
- Superintendencia de Proteccion de Datos Personales (SPDP)
- Virtual assets
- PSAVs are reporting entities supervised by the Superintendencia de Bancos for AML/CFT/CPF; UAFE status does not replace any permission required for the particular regulated activity
- FATF status
- GAFILAT member; not named on FATF call-for-action or increased-monitoring lists reviewed 1 August 2026
تفاصيل التنفيذ
متطلبات وإجراءات الامتثال في الإكوادور
افتح كل مجال لمراجعة المتطلب وإجراء التنفيذ المقترح والأدلة الواجب الاحتفاظ بها والمصدر الأساسي.
01Scope, authorities and licensingThe 2024 law classifies financial, non-financial and virtual-asset reporting entities. Registration and financial or payment authorization are separate questions.5 عناصر+
Financial reporting entities include regulated financial and insurance actors, payment-system participants, money or value transfer providers, exchanges, securities actors and specified credit, leasing and factoring businesses.
- إجراء التنفيذ
- Map each entity and product to article 27 and the current sector instrument, identify the supervisor and document the Ecuador nexus.
- الأدلة الواجب الاحتفاظ بها
- Perimeter memorandum, entity and product inventory, supervisor matrix, legal nexus and signed approval.
- المصدر الأساسي
- 2024 Organic AML Law arts. 26-27
Article 28 covers specified non-financial activities, including real estate, construction, vehicle and precious-goods businesses, NPOs and defined legal, accounting, company and trust services.
- إجراء التنفيذ
- Test the exact activity and professional-service conditions; do not classify an entire profession without the statutory transaction nexus.
- الأدلة الواجب الاحتفاظ بها
- Activity map, engagement analysis, statutory limb, exclusions and counsel sign-off.
- المصدر الأساسي
- 2024 Organic AML Law arts. 28-30
A PSAV is a reporting entity when, as a business, it exchanges virtual assets for fiat, exchanges one or more virtual assets, transfers virtual assets, custodies or administers virtual assets or instruments controlling them, or participates in or provides financial services related to an issuer's offer or sale of a virtual asset. PSAV AML/CFT/CPF supervision is assigned to the Superintendencia de Bancos.
- إجراء التنفيذ
- Map every virtual-asset product and role to the article 31 perimeter, document whether the activity is conducted as a business, register with UAFE and resolve any activity-specific permission with the Superintendencia de Bancos.
- الأدلة الواجب الاحتفاظ بها
- Product and activity map, article 31 analysis, business-model evidence, UAFE code, SB correspondence or permission analysis and launch approval.
- المصدر الأساسي
- 2024 Organic AML Law arts. 26, 31 and 65
A reporting entity must obtain and maintain the UAFE code of registration and any license or operating registration required by its supervisor.
- إجراء التنفيذ
- Complete the applicable registration before operating, provision SISLAFT and notify changes within 15 business days.
- الأدلة الواجب الاحتفاظ بها
- UAFE code, supervisor license or registration, SISLAFT access, change log and receipts.
- المصدر الأساسي
- 2024 Organic AML Law arts. 56 and 67; Executive Decree 298 arts. 55-59; Organic Administrative Code arts. 158-160
Financial, payment and fintech services require the authorization or qualification prescribed by the Monetary and Financial Code, Fintech Law and BCE or sector rules.
- إجراء التنفيذ
- Do not accept deposits, provide reserved financial services or operate a covered payment role before the correct authorization; verify the public regulator record.
- الأدلة الواجب الاحتفاظ بها
- Licensing analysis, application, decision, public record, conditions and launch gate.
- المصدر الأساسي
- Organic Monetary and Financial Code art. 254; Fintech Law; JPRM-2024-018-M; applicable SB and BCE rules
02Governance and risk assessmentReporting entities must operate a proportionate AML/CFT/CPF program validated and supervised by the competent authority.4 عناصر+
The prevention program must address policies, procedures, internal controls, staff integrity and training, risk-based diligence and conflicts of interest.
- إجراء التنفيذ
- Build and approve a program proportionate to activity, size, structure and complexity and map every statutory element to an owner and control.
- الأدلة الواجب الاحتفاظ بها
- Approved program, manual, control matrix, ownership, training plan and validation record.
- المصدر الأساسي
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 47 and 80
Risk methodology must cover identification, evaluation, monitoring, administration and mitigation across customers, products, geography, channels and transactions.
- إجراء التنفيذ
- Document inherent and residual risk, control effectiveness, thresholds, overrides and escalation and refresh the assessment at least annually.
- الأدلة الواجب الاحتفاظ بها
- Methodology, risk assessment, data, scoring, approval, annual refresh and remediation.
- المصدر الأساسي
- 2024 Organic AML Law arts. 36-39
A reporting entity must designate the required qualified compliance officer and protect SISLAFT credentials and reporting independence.
- إجراء التنفيذ
- Appoint the officer and substitute where required, confirm qualification, resource the function and govern absence, change and confidential access.
- الأدلة الواجب الاحتفاظ بها
- Appointment, qualification, UAFE record, charter, budget, access log and succession plan.
- المصدر الأساسي
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 42-49
New products, practices and technologies require a documented ML/TF/PF assessment before launch.
- إجراء التنفيذ
- Assess customer, delivery, cyber, impersonation, sanctions, outsourcing and privacy risks and approve measurable launch and monitoring controls.
- الأدلة الواجب الاحتفاظ بها
- Pre-launch assessment, threat model, tests, approval, monitoring metrics and change record.
- المصدر الأساسي
- 2024 Organic AML Law art. 38
03Natural-person KYC and representativesCDD must identify and verify the customer and representative, establish purpose and source of funds and continue throughout the relationship.5 عناصر+
The customer or provider must be identified and verified from reliable documents, data or information.
- إجراء التنفيذ
- Capture the required identity, address, activity, income or funds and purpose data, authenticate evidence and bind it to the applicant.
- الأدلة الواجب الاحتفاظ بها
- Identity file, source data, authenticity result, timestamps, reviewer and exception record.
- المصدر الأساسي
- 2024 Organic AML Law arts. 41-43
A representative must be identified, verified and shown to be authorized.
- إجراء التنفيذ
- Verify the natural person and validate the power, mandate or role before enabling action; restrict access to the authorized scope.
- الأدلة الواجب الاحتفاظ بها
- Representative KYC, mandate, registry or notarial check, authority analysis and expiry control.
- المصدر الأساسي
- 2024 Organic AML Law art. 43(b)
CDD is continuous and must test transactions against the known business, activity and risk profile, including source of funds when necessary.
- إجراء التنفيذ
- Set event- and risk-based refresh, monitor expected activity and resolve material deviations and stale identity evidence.
- الأدلة الواجب الاحتفاظ بها
- Profile, refresh schedule, triggers, alerts, investigations, updates and approvals.
- المصدر الأساسي
- 2024 Organic AML Law art. 43(d)-(e)
Verification ordinarily occurs before or while establishing the relationship; delayed completion is limited to controlled cases and must finish within five business days, subject to a possible UAFE extension of up to three business days.
- إجراء التنفيذ
- Use delayed verification only where essential not to interrupt normal operations and risk is controlled; limit activity, clock the business-day deadline and document any extension.
- الأدلة الواجب الاحتفاظ بها
- Exception rationale, risk controls, deadline, UAFE request and response, verification and approval.
- المصدر الأساسي
- 2024 Organic AML Law art. 45; Organic Administrative Code arts. 158-160
If required CDD cannot be completed, the reporting entity must not start the relationship, open an account or execute the transaction. If the relationship has already begun, it must terminate it and submit a ROS to UAFE.
- إجراء التنفيذ
- Block onboarding and transaction execution, terminate an existing relationship through the controlled process, preserve the failed-CDD record and file the ROS without tipping off.
- الأدلة الواجب الاحتفاظ بها
- System block, failed-CDD analysis, termination approval, ROS, acknowledgement and restricted communication log.
- المصدر الأساسي
- 2024 Organic AML Law art. 47
04KYB, registries and beneficial ownershipLegal-person CDD and the SRI beneficial-owner register both require a natural-person outcome, but the reporting entity must independently verify its customer.4 عناصر+
Legal-person and arrangement CDD includes legal name, form, existence, principal address, governing powers, senior managers, business nature and ownership and control structure.
- إجراء التنفيذ
- Obtain current SCVS or other registry evidence, constitutional documents, RUC, governance and purpose, and reconcile discrepancies.
- الأدلة الواجب الاحتفاظ بها
- Registry extract, constitutional documents, RUC, governance list, business profile and discrepancy log.
- المصدر الأساسي
- 2024 Organic AML Law art. 44
A beneficial owner is the natural person who ultimately owns or controls the entity or on whose behalf the transaction occurs.
- إجراء التنفيذ
- Trace ownership to natural persons, examine contractual and other control and identify trust or arrangement parties and ultimate controllers.
- الأدلة الواجب الاحتفاظ بها
- Ownership chart, cap tables, agreements, trust documents, control analysis and identity evidence.
- المصدر الأساسي
- 2024 Organic AML Law arts. 4(f), 43(c) and 92
For a legal person, article 92 uses at least 10% capital, control by other means and then the highest-ranking managing official fallback.
- إجراء التنفيذ
- Calculate direct and indirect ownership, document decision-unit and appointment rights and use the fallback only after recording why ownership and control tests found no person.
- الأدلة الواجب الاحتفاظ بها
- Calculations, control memorandum, source documents, fallback record and approval.
- المصدر الأساسي
- 2024 Organic AML Law art. 92(1)
Every legal person must register its beneficial owners with SRI under the applicable conditions; inaccurate information identified by SRI or SCVS must be corrected within 10 business days, with a possible extension of up to five business days.
- إجراء التنفيذ
- Maintain the REBEFICS and SRI calendar, reconcile customer and corporate records and clock correction notices in business days.
- الأدلة الواجب الاحتفاظ بها
- BO register, REBEFICS filing, receipt, reconciliation, correction notice and response.
- المصدر الأساسي
- 2024 Organic AML Law arts. 91 and 93-94; SRI Resolution NAC-DGERCGC24-00000033; Organic Administrative Code arts. 158-160
05PEPs, enhanced diligence and remote onboardingPEPs, associates and specified high-risk categories require reinforced controls; PEP status alone does not justify denial of service.6 عناصر+
Systems must determine whether a customer or beneficial owner is a domestic or foreign PEP or an associate.
- إجراء التنفيذ
- Screen at onboarding and continuously, identify the role and dates and map relevant family, close associate and control relationships.
- الأدلة الواجب الاحتفاظ بها
- Screening, role source, relationship analysis, disposition, review date and changes.
- المصدر الأساسي
- 2024 Organic AML Law arts. 49-50; Executive Decree 298 arts. 74-75
Foreign PEPs and associates, and higher-risk domestic PEP cases, require senior approval, reasonable source-of-wealth and source-of-funds measures and intensified monitoring.
- إجراء التنفيذ
- Obtain approval before opening or continuing, corroborate wealth and funds and configure enhanced review and scenarios.
- الأدلة الواجب الاحتفاظ بها
- Approval, wealth analysis, funds trail, supporting records, monitoring plan and periodic review.
- المصدر الأساسي
- 2024 Organic AML Law art. 49
PEP status remains for two years after office, after which the reporting entity reassesses risk and documents whether enhanced treatment continues.
- إجراء التنفيذ
- Clock departure dates, retain PEP controls through the two-year minimum and complete a reasoned reassessment rather than automatic removal.
- الأدلة الواجب الاحتفاظ بها
- Role end date, two-year control, risk reassessment, approval and screening update.
- المصدر الأساسي
- Executive Decree 298 art. 76
Irrespective of the entity's own risk score, intensified due diligence applies to every activity and person category listed in article 50, including the specified justice, defence, security, corrections, customs, border, elected-office, state-contractor, natural-resource and professional-football categories.
- إجراء التنفيذ
- Map the complete statutory category list into onboarding and monitoring, identify qualifying roles and activities, obtain intensified evidence and approval, and retain the legal-category rationale.
- الأدلة الواجب الاحتفاظ بها
- Article 50 category matrix, screening and role evidence, enhanced approval, source-of-funds or wealth support, monitoring plan and review.
- المصدر الأساسي
- 2024 Organic AML Law art. 50
Relationships or transactions involving FATF high-risk jurisdictions require intensified measures, while jurisdictions under FATF monitoring require measures proportionate to the identified risk.
- إجراء التنفيذ
- Ingest current FATF statements, distinguish call-for-action from monitored jurisdictions, configure the required treatment and document country-risk decisions and exceptions.
- الأدلة الواجب الاحتفاظ بها
- Dated FATF lists, country-risk matrix, enhanced or proportionate measures, approval, monitoring and review.
- المصدر الأساسي
- 2024 Organic AML Law art. 51
Remote onboarding and external identity providers remain subject to the reporting entity's CDD responsibility and confidentiality duties.
- إجراء التنفيذ
- Validate the method, test impersonation and liveness, contract for evidence and audit access and independently monitor the provider.
- الأدلة الواجب الاحتفاظ بها
- Remote-flow legal map, vendor review, tests, contract, sample QA, incidents and exit plan.
- المصدر الأساسي
- 2024 Organic AML Law arts. 43-45 and 53-54
06Monitoring, suspicious reports and confidentialityEcuador's 2024 law uses a five-business-day awareness-based ROS deadline and covers completed and attempted operations regardless of amount.4 عناصر+
Submit the ROS within five business days from the date the compliance committee becomes aware of the suspicious completed or attempted operation; if the entity has no compliance committee, count from when the reporting entity becomes aware. The duty applies regardless of amount.
- إجراء التنفيذ
- Escalate immediately, preserve the applicable committee-or-entity awareness timestamp, document grounds and submit the ROS with support through SISLAFT.
- الأدلة الواجب الاحتفاظ بها
- Alert, investigation, committee or entity awareness record, decision, report, support and acknowledgement.
- المصدر الأساسي
- 2024 Organic AML Law art. 57; Executive Decree 298 art. 28; Organic Administrative Code arts. 158-160
A reasoned request made within the legal framework may receive a UAFE extension of up to three additional business days; an extension must never be assumed.
- إجراء التنفيذ
- Treat five business days as the control deadline, request an extension only when justified and preserve UAFE's written response.
- الأدلة الواجب الاحتفاظ بها
- Business-day deadline clock, request, grounds, UAFE response, filing and quality review.
- المصدر الأساسي
- 2024 Organic AML Law art. 57; Organic Administrative Code arts. 158-160
If no ROS exists for a month, the reporting entity must register NO ROS in UAFE's reporting system within 10 business days after the end of that month.
- إجراء التنفيذ
- Reconcile all cases, obtain compliance approval and submit the no-report record within the 10-business-day term.
- الأدلة الواجب الاحتفاظ بها
- Case reconciliation, approval, NO ROS record, receipt and exception log.
- المصدر الأساسي
- 2024 Organic AML Law art. 59; UAFE Resolution UAFE-DG-2026-0007; Organic Administrative Code arts. 158-160
Disclosure of a ROS, its existence or UAFE examination to unauthorized persons is prohibited and a very serious infringement.
- إجراء التنفيذ
- Restrict case access, use neutral communications and route disclosure requests through legal and compliance.
- الأدلة الواجب الاحتفاظ بها
- Access log, confidentiality acknowledgements, communications, training and disclosure approvals.
- المصدر الأساسي
- 2024 Organic AML Law arts. 23 and 81(h), (m)
07Payments, wires, thresholds and agentsThreshold reporting, cash restrictions and transfer information apply alongside payment and fintech authorization.5 عناصر+
Within the first 15 days of each month, reporting entities submit RESU for individual operations at or above USD 10,000 and multiple operations that together reach or exceed USD 10,000 for the benefit of the same person within a 30-day period.
- إجراء التنفيذ
- Aggregate across channels and products for the rolling 30-day period, validate the beneficiary and submit the current UAFE structure; track any sector-specific lower threshold.
- الأدلة الواجب الاحتفاظ بها
- Aggregation logic, test cases, RESU file, reconciliation, receipt and correction log.
- المصدر الأساسي
- 2024 Organic AML Law art. 58; Executive Decree 298 art. 61
If no threshold report exists for a month, the entity must register NO RESU in UAFE's reporting system within 10 business days after the end of that month.
- إجراء التنفيذ
- Reconcile source systems, approve the nil position and submit NO RESU within the 10-business-day term.
- الأدلة الواجب الاحتفاظ بها
- Monthly reconciliation, approval, NO RESU record, receipt and exception handling.
- المصدر الأساسي
- 2024 Organic AML Law art. 59; Executive Decree 298 art. 61; Organic Administrative Code arts. 158-160
Except for contractual obligations arising from products, services or operations of national-financial-system entities and BCE under Executive Decree 298 General Provision Five, no person may pay, settle, accept payment or accept settlement of an obligation or transaction equal to or above USD 10,000 using domestic or foreign notes or coins, precious stones or precious metals.
- إجراء التنفيذ
- Block covered settlement methods at the threshold, route payment through a permitted method and document the legal basis and evidence for any financial-system or BCE exclusion.
- الأدلة الواجب الاحتفاظ بها
- Payment-method rules, threshold tests, blocked transaction, permitted settlement record, exclusion analysis and approval.
- المصدر الأساسي
- 2024 Organic AML Law art. 33; Executive Decree 298 General Provision Five
Originator, beneficiary and account or reference information must accompany domestic, cross-border and virtual-asset transfers, including batches, and be retained for 10 years.
- إجراء التنفيذ
- Validate required fields before release, stop or investigate missing information, screen parties and preserve the complete message.
- الأدلة الواجب الاحتفاظ بها
- Message, field validation, screening, exception, investigation, approval and archive.
- المصدر الأساسي
- 2024 Organic AML Law art. 52
Payment aggregators, gateways, processors, switches and SEDPES require the authorization and controls applicable to their BCE and sector role.
- إجراء التنفيذ
- Obtain authorization before service, maintain UAFE compliance certification, govern agents and vendors and meet data, security and operating requirements.
- الأدلة الواجب الاحتفاظ بها
- BCE or sector authorization, operating scheme, contracts, UAFE certificate, security report and monitoring.
- المصدر الأساسي
- Fintech Law; JPRM-2024-018-M; BCE payment-participant authorization requirements
08Targeted financial sanctions and freezingEcuador uses a UAFE-led, judicial freezing process for UN terrorism and proliferation designations. Operators must monitor and escalate matches without delay.5 عناصر+
Reporting entities must monitor UN Security Council lists concerning terrorism and proliferation.
- إجراء التنفيذ
- Screen customers, beneficial owners, counterparties and transactions against the current UN lists and UAFE communications.
- الأدلة الواجب الاحتفاظ بها
- List source and timestamp, configuration, screening logs, match analysis and escalation.
- المصدر الأساسي
- 2024 Organic AML Law arts. 37 and 55; UAFE Resolution UAFE-DG-2022-0095
A potential designation match must be reported through the UAFE process so the competent authorities can seek the applicable preventive judicial measure.
- إجراء التنفيذ
- Escalate a true match immediately, preserve all funds and transaction facts, follow UAFE instructions and avoid alerting the subject.
- الأدلة الواجب الاحتفاظ بها
- Match worksheet, identifiers, UAFE communication, preservation steps and restricted access.
- المصدر الأساسي
- UAFE Resolution UAFE-DG-2022-0095; UAFE UN freezing guide
A competent preventive immobilization or freezing order must be implemented within its exact scope; failure is a very serious infringement.
- إجراء التنفيذ
- Authenticate the order, block the identified property, prevent value from being made available and confirm execution through the prescribed channel.
- الأدلة الواجب الاحتفاظ بها
- Order, authority validation, block timestamps, asset inventory, confirmation and reconciliation.
- المصدر الأساسي
- 2024 Organic AML Law art. 81(k); UAFE UN freezing guide
Separately from UN-list freezing, UAFE may immediately order an exceptional and proportionate immobilization of funds in the national financial system where objective, serious and verifiable indications arise from a ROS, early warning, complaint, national-intelligence information or UAFE intelligence. Financial entities must execute within 72 hours; the measure lasts no more than eight days pending judicial ratification, modification or revocation.
- إجراء التنفيذ
- Authenticate and execute the UAFE order within 72 hours, restrict the identified funds, preserve confidentiality, track the eight-day maximum and implement only the verified judicial outcome.
- الأدلة الواجب الاحتفاظ بها
- UAFE order, receipt and execution timestamps, restricted-funds inventory, access log, judicial decision and reconciliation.
- المصدر الأساسي
- 2024 Organic AML Law art. 17.3; Executive Decree 298 arts. 52-55
Where a covered financial-system or popular-and-solidarity financial entity freezes, immobilizes, retains or detains funds through internal due-diligence processes because of suspected illicit or criminal activity, it must report through the applicable Complementary AML Unit and transfer the funds within five business days to the designated BCE custody account, following the operative authority procedure and preserving the holder's right to challenge the measure.
- إجراء التنفيذ
- Identify article 48.1 cases separately from UN and UAFE measures, notify the competent complementary unit, transfer the funds to the verified BCE custody account within five business days and preserve challenge and release records.
- الأدلة الواجب الاحتفاظ بها
- Internal decision, suspicion basis, holder and funds record, complementary-unit report, BCE transfer receipt, business-day clock, challenge and disposition.
- المصدر الأساسي
- 2024 Organic AML Law art. 48.1; Organic Administrative Code arts. 158-160
09Records and regulator accessRecords must make customer, beneficial-owner, transfer, monitoring and report decisions reconstructable for 10 years and available to competent authorities.4 عناصر+
CDD, transaction, analysis, account and business-correspondence records, with documentary support, must be retained for 10 years after termination of the contractual relationship, the last transaction, or the occasional transaction, as applicable. Transfer originator and beneficiary information must also be retained for 10 years.
- إجراء التنفيذ
- Map each record to its statutory trigger, maintain the 10-year archive unless a longer sector duty applies and preserve legal holds.
- الأدلة الواجب الاحتفاظ بها
- Retention schedule, relationship and transaction trigger dates, archive, holds, restore tests and destruction approvals.
- المصدر الأساسي
- 2024 Organic AML Law arts. 48 and 52
CDD, beneficial-owner, monitoring, report and governance evidence must remain complete, secure and retrievable.
- إجراء التنفيذ
- Preserve source evidence, metadata, approvals and linked case chronology and test retrieval and integrity periodically.
- الأدلة الواجب الاحتفاظ بها
- Customer and case index, integrity hashes, access logs, backups, sample retrieval and remediation.
- المصدر الأساسي
- 2024 Organic AML Law arts. 34-59; applicable sector rule
UAFE and designated supervisors may conduct in-situ and off-site supervision and request information within their competence.
- إجراء التنفيذ
- Authenticate requests, preserve confidentiality and privilege, collect reproducibly and meet the stated deadline.
- الأدلة الواجب الاحتفاظ بها
- Request, authority check, collection log, production index, delivery and receipt.
- المصدر الأساسي
- 2024 Organic AML Law arts. 66-75; Executive Decree 298 art. 73
Electronic reporting corrections and replacements must follow UAFE validation and replacement procedures.
- إجراء التنفيذ
- Monitor validation messages, correct errors within the operative period and preserve the original, replacement request, authorization and final accepted file.
- الأدلة الواجب الاحتفاظ بها
- Validation result, error analysis, replacement request, approval, final receipt and audit trail.
- المصدر الأساسي
- 2024 Organic AML Law art. 81(n)-(p); Executive Decree 298 art. 64; UAFE Resolution 2023-0559
10Privacy, biometrics and transfersAML processing must also satisfy Ecuador's Organic Personal Data Protection Law, its regulation and current SPDP instruments.4 عناصر+
Personal data must be processed on a lawful basis, transparently, for proportionate purposes and no longer than necessary subject to legal retention.
- إجراء التنفيذ
- Map each KYC field and use to a legal basis, provide required information, restrict reuse and reconcile privacy deletion with AML holds.
- الأدلة الواجب الاحتفاظ بها
- Processing inventory, basis map, notices, retention schedule, access controls and deletion decisions.
- المصدر الأساسي
- Organic Personal Data Protection Law arts. 7-12 and 47; General Regulation arts. 8-11
Biometric data is sensitive and high-risk or large-scale processing may require a prior impact assessment and heightened safeguards.
- إجراء التنفيذ
- Document necessity, proportionality and basis, minimize templates, test attacks, complete the required impact assessment and govern vendors.
- الأدلة الواجب الاحتفاظ بها
- Biometric assessment, impact assessment, consent or other basis, architecture, tests and vendor terms.
- المصدر الأساسي
- Organic Personal Data Protection Law arts. 10, 26 and 42; General Regulation arts. 29-32
A qualifying breach is notified to SPDP and ARCOTEL as soon as possible and no later than five business days; the processor notifies the controller within two business days, and affected persons within three business days when their rights are at risk.
- إجراء التنفيذ
- Maintain business-day statutory clocks, assess risk, issue complete notifications and record reasons for delay and remediation.
- الأدلة الواجب الاحتفاظ بها
- Incident timeline, assessment, regulator and individual notices, processor communication and remediation.
- المصدر الأساسي
- Organic Personal Data Protection Law arts. 43 and 46; General Regulation arts. 24-28; Organic Administrative Code arts. 158-160
International transfers require adequate protection, an approved safeguard or a lawful exception; required DPO appointments and the current SPDP transfer rule must be observed.
- إجراء التنفيذ
- Map transfers and processors, select and document the transfer mechanism, audit safeguards and designate and register the DPO where required.
- الأدلة الواجب الاحتفاظ بها
- Transfer map, adequacy or contract analysis, processor audit, DPO appointment and SPDP records.
- المصدر الأساسي
- Organic Personal Data Protection Law arts. 48-50 and 55-59; SPDP Resolution 2026-0004-R
11Practical evidence packsA usable control environment preserves the source, decision, owner and timestamp for every material regulatory conclusion.4 عناصر+
Each product needs an approved perimeter and authorization pack.
- إجراء التنفيذ
- Record the legal entity, activity, reporting category, supervisor, UAFE code, financial or payment authorization, privacy role and review date.
- الأدلة الواجب الاحتفاظ بها
- Signed perimeter pack, source snapshots, registrations, authorizations, owner and next review.
- المصدر الأساسي
- 2024 Organic AML Law arts. 26-32, 56 and 67
Each customer file must evidence identity, authority, beneficial ownership, risk, PEP status and ongoing monitoring.
- إجراء التنفيذ
- Use a pre-activation quality gate and periodic sample review, and remediate gaps to verified closure.
- الأدلة الواجب الاحتفاظ بها
- Customer index, KYC and KYB evidence, ownership chart, risk score, approvals, monitoring and QA.
- المصدر الأساسي
- 2024 Organic AML Law arts. 41-54
Reporting evidence must demonstrate the applicable committee-or-entity awareness timestamp, five-business-day ROS control, threshold aggregation, nil returns, validation and confidentiality.
- إجراء التنفيذ
- Test cases end to end, reconcile every monthly submission and maintain portal continuity and restricted access.
- الأدلة الواجب الاحتفاظ بها
- Scenario tests, case chronology, ROS, RESU, nil records, receipts, access review and remediation.
- المصدر الأساسي
- 2024 Organic AML Law arts. 57-59; Executive Decree 298 arts. 28 and 60-64
Legal change monitoring must cover UAFE, SB, SCVS, SEPS, BCE, SRI, SPDP, FATF and GAFILAT.
- إجراء التنفيذ
- Assign official sources and owners, review on a defined cadence and trigger impact assessment, controlled versioning, training and release.
- الأدلة الواجب الاحتفاظ بها
- Source register, dated review log, impact assessment, approvals, releases and training.
- المصدر الأساسي
- Applicable laws and regulator publications listed in Sources
سجل المصادر الأساسية
28 مصدرًا مستخدمًا في هذه القائمة
استخدم هذه الروابط للتحقق من التشريعات وإرشادات الجهات الرقابية وإجراءات الإبلاغ والبيانات الدولية.
- 2024 Organic Law on Prevention, Detection and Combat of Money Laundering and Financing of Other CrimesUAFE · Primary legislation
- Official Gazette Fourth Supplement 610 - 2024 Organic AML LawRegistro Oficial · Official gazette
- Executive Decree 298 - 2026 General AML RegulationSuperintendencia de Economia Popular y Solidaria · Primary regulatory instrument
- Official Gazette Third Supplement 216 - Executive Decree 298Registro Oficial · Official gazette
- UAFE legal and regulatory libraryUAFE · Official regulator library
- ROS and NO ROS current reporting guidanceUAFE · Official reporting guidance
- UAFE report typesUAFE · Official reporting guidance
- UAFE registration-code procedureUAFE · Official registration guidance
- Current reporting-entity designationsUAFE · Official perimeter guidance
- UAFE Resolution 2022-0131 - PSAV designation (legacy reporting deadlines displaced by the 2024 Law and current UAFE rules)UAFE · Primary designation instrument with superseded deadline provisions
- UAFE terrorism and UN freezing portalUAFE · Official sanctions guidance
- UAFE UN sanctions freezing guideUAFE · Official sanctions guidance
- SCVS AML/CFT regulatory directorySuperintendencia de Companias, Valores y Seguros · Official supervisor library
- SRI Resolution NAC-DGERCGC24-00000033 - REBEFICSServicio de Rentas Internas · Primary beneficial-owner regulation
- Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary legislation
- General Regulation to the Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- SPDP resolutions directorySuperintendencia de Proteccion de Datos Personales · Official regulator library
- SPDP Resolution 2026-0004-R - international data transfersSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- Fintech Law - Official Gazette Second Supplement 215Registro Oficial · Primary legislation
- JPRM-2024-018-M - payment systems and fintech activitiesBanco Central del Ecuador · Primary payment regulation
- Payment-system participant authorizationBanco Central del Ecuador · Official licensing guidance
- Superintendencia de Bancos regulatory codificationSuperintendencia de Bancos · Official supervisory rules library
- Organic Administrative Code - computation of administrative termsConsejo de la Judicatura · Primary legislation
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current status
- FATF mutual evaluation of EcuadorFinancial Action Task Force · Official international assessment
- GAFILAT network and evaluation scheduleFinancial Action Task Force · Official international assessment
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Official sanctions list
إجابات مباشرة
أسئلة KYC وKYB وAML في الإكوادور
Who receives suspicious operation reports in Ecuador?+
Reporting entities submit ROS to UAFE through SISLAFT using the current UAFE structure and support requirements.
What is Ecuador's ROS deadline?+
Within five business days from the compliance committee's awareness of the suspicious completed or attempted operation, or from the reporting entity's awareness where it has no committee, regardless of amount. A UAFE extension of up to three business days requires a reasoned request and should never be assumed.
What is the threshold-report rule?+
Individual operations of at least USD 10,000 and multiple operations reaching that amount for the same beneficiary within a month are reported within the first 15 days of the following month, subject to any lower sector threshold.
What if there is no ROS or threshold report?+
NO ROS and NO RESU must be registered in UAFE's reporting system within 10 business days after the end of each month in which no corresponding report exists.
How is beneficial ownership determined?+
For a legal person, the law uses at least 10% capital, control through other means, and then the highest-ranking managing official fallback. Trust and arrangement parties are traced to natural persons.
How long are AML records retained?+
CDD, transaction, analysis, account and business-correspondence records with documentary support are retained for 10 years after relationship termination, the last transaction or the occasional transaction, as applicable. Transfer originator and beneficiary data is also retained for 10 years.
Do payment and fintech services require authorization?+
Yes when they fall within a reserved or regulated role. UAFE reporting status does not replace the BCE, Superintendencia de Bancos or other sector authorization.
Are virtual-asset service providers reporting entities?+
Yes. The perimeter covers business activity involving fiat/virtual-asset or virtual-asset exchanges, transfers, custody or control instruments, and financial services related to an issuer's offer or sale. PSAVs are supervised by the Superintendencia de Bancos for AML/CFT/CPF and maintain a UAFE code, while any activity-specific permission is separate. The four-day ROS and 15-day nil-report deadlines in the 2022 designation instrument are displaced by the 2024 Law and current UAFE rules.
What privacy deadlines apply to a qualifying breach?+
The controller notifies SPDP and ARCOTEL no later than five business days, the processor notifies the controller within two business days, and affected persons are notified within three business days when their rights are at risk.
Is Ecuador on a FATF public list?+
Ecuador was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026. This does not replace a risk-based country assessment.
منهجية البحث والمراجعة
تحدد VOVE ID Compliance Research النطاق التنظيمي، وتحول الالتزامات إلى ضوابط تشغيلية، وتربط الادعاءات الجوهرية بالمصادر، وتسجل تاريخ وإصدار كل مراجعة.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector rules, UAFE resolutions, SISLAFT manuals or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, supervisor, reporting calendar, technical structure, licensing perimeter, privacy role and later developments with qualified Ecuadorian counsel and the relevant authority before launch.