Eritrea KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Eritrea.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Eritrea compliance checklist cover?
The Eritrea checklist translates primary KYC, KYB and AML rules into 11 control areas and 32 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Legally established; July 2025 evaluation reported it was not operational
- Primary AML law
- Proclamation No. 175/2014, amended by No. 181/2018
- CDD threshold
- Occasional transactions above USD 10,000 or equivalent, including linked operations
- Suspicion reporting
- Promptly to the FIU; attempts and all amounts included, but route/timing remain unspecified
- Core retention
- 10 years after transaction completion or relationship termination
- FATF status
- Not named on FATF public lists as at 19 June 2026
Implementation detail
Eritrea compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the legal perimeter and authority before launch.3 items+
Determine whether each activity is regulated or subject to AML/CFT duties.
- Implementation action
- Map each entity, product and channel to financial-institution or DNFBP categories and document the responsible licensing and AML authority.
- Evidence to retain
- Perimeter memo, product map and authority correspondence.
- Primary citation
- Proclamation No. 175/2014 as amended; ESAAMLG MER 2025, Recommendations 22, 26 and 28
Treat the FIU as the statutory STR recipient without assuming it is operational.
- Implementation action
- Before launch, obtain written confirmation of current FIU status, form, channel, acknowledgement and contingency procedure from the Ministry of Finance and National Development or Bank of Eritrea.
- Evidence to retain
- Current authority instructions, access approval, channel test and escalation plan.
- Primary citation
- Proclamation No. 175/2014, Articles 20-23; ESAAMLG MER 2025, IO.6 and Recommendation 29
Obtain approval before regulated financial activity.
- Implementation action
- Confirm Bank of Eritrea permission for banking, foreign exchange, inward remittance, insurance and any new payment or digital-finance model; do not infer permission from an adjacent licence.
- Evidence to retain
- Licence analysis, application, approval and conditions register.
- Primary citation
- Financial Institutions Proclamation No. 94/1997; ESAAMLG MER 2025, Recommendations 14, 15 and 26
02Governance and risk assessmentUse documented risk and accountable controls despite the developing national framework.3 items+
Assess customer, product, geography, transaction and channel risk.
- Implementation action
- Maintain an approved ML/TF/PF assessment and update it for material change; do not treat the country's closed financial system as proof of low risk.
- Evidence to retain
- Methodology, assessment, approval and change log.
- Primary citation
- Proclamation No. 175/2014, Article 6(17); Legal Notice No. 130/2018, Article 17; ESAAMLG MER 2025, Recommendation 1
Maintain compliance management, screening, training and independent testing.
- Implementation action
- Appoint a sufficiently senior compliance officer, screen staff, train relevant personnel, test controls and track remediation.
- Evidence to retain
- Appointment, policies, training, audit plan and remediation log.
- Primary citation
- Proclamation No. 175/2014, Article 19; ESAAMLG MER 2025, Recommendation 18
Review new technology before use.
- Implementation action
- Assess ML/TF/PF, fraud, cybersecurity and identity risks before introducing remote onboarding, payment technology or materially changed products.
- Evidence to retain
- Pre-launch assessment, tests, approval and residual-risk acceptance.
- Primary citation
- Prudent control responding to ESAAMLG MER 2025, Recommendation 15 deficiencies
03Natural-person identificationCDD relies on current, reliable and independent evidence.3 items+
Identify and verify customers before the relationship or occasional transaction.
- Implementation action
- Verify natural-person identity from reliable independent material and record provenance, validity and exceptions.
- Evidence to retain
- Identity record, verification result and source provenance.
- Primary citation
- Proclamation No. 175/2014, Articles 6(3)-(4); Legal Notice No. 130/2018, Article 14
Apply CDD at the statutory triggers.
- Implementation action
- Perform CDD when establishing a relationship, for occasional transactions above USD 10,000 or equivalent including linked operations, on suspicion regardless of amount, and when prior identification data is doubtful.
- Evidence to retain
- Trigger logic, linked-transaction review and completed CDD file.
- Primary citation
- Proclamation No. 175/2014, Article 6(3)
Verify representatives and authority.
- Implementation action
- Identify and verify anyone acting for a customer and authenticate the mandate before granting access or execution.
- Evidence to retain
- Identity record, mandate, validation and access log.
- Primary citation
- Proclamation No. 175/2014, Article 6(6)-(7)
04KYB, registries, and beneficial ownershipBasic registration does not establish beneficial ownership.3 items+
Verify legal existence, governance, address and authority.
- Implementation action
- Obtain current Business Licensing Office evidence, constitutional records, senior-management details, registered and principal addresses and signatory powers.
- Evidence to retain
- Registry record, constitution, licences, powers and reconciliation.
- Primary citation
- Proclamation No. 175/2014, Article 6(6); Legal Notice No. 130/2018, Article 14(4)
Identify and reasonably verify natural-person beneficial owners.
- Implementation action
- Trace controlling ownership to natural persons using reliable sources and document any unresolved control gap; do not invent an ownership percentage.
- Evidence to retain
- Ownership chart, source records, verified identities and gap analysis.
- Primary citation
- Proclamation No. 175/2014, Articles 2(2) and 6(7); ESAAMLG MER 2025, Recommendation 10
Do not rely on a comprehensive beneficial-owner register.
- Implementation action
- Collect ownership and control evidence directly and reconcile it with basic registry and licensing data; escalate bearer, nominee or opaque structures.
- Evidence to retain
- Source comparison, discrepancy review and escalation.
- Primary citation
- ESAAMLG MER 2025, Recommendation 24
05PEPs, EDD, and remote onboardingHigher-risk relationships need proportionate enhanced measures.3 items+
Detect PEP exposure in customers and beneficial owners.
- Implementation action
- Use risk-management systems to identify domestic and foreign PEPs, family members and close associates at onboarding and during the relationship; separately assess international-organisation functions.
- Evidence to retain
- Screening, relationship map, match decision and refresh log.
- Primary citation
- Proclamation No. 175/2014, Article 2(23); Legal Notice No. 130/2018, Article 17; ESAAMLG MER 2025, Recommendation 12
Apply approval, source and monitoring controls to PEPs and other high risk.
- Implementation action
- Obtain senior approval, establish source of wealth and source of funds, and conduct enhanced ongoing monitoring proportionate to risk.
- Evidence to retain
- Approval, provenance analysis and monitoring plan.
- Primary citation
- Legal Notice No. 130/2018, Article 17; ESAAMLG MER 2025, Recommendation 12
Do not launch remote onboarding on assumed legal sufficiency.
- Implementation action
- Confirm acceptable electronic evidence and signatures with the Bank of Eritrea, then use proportionate liveness, device, fraud and exception controls.
- Evidence to retain
- Authority confirmation, design assessment, tests and exceptions.
- Primary citation
- Prudent control; ESAAMLG MER 2025, Recommendation 15
06Monitoring and suspicious reportingReporting must be prompt, confidential and reconstructable despite unresolved mechanics.3 items+
Monitor activity against customer knowledge and risk.
- Implementation action
- Scrutinise transactions throughout the relationship, keep CDD current and examine unusual or inconsistent activity.
- Evidence to retain
- Alerts, investigation, disposition and profile refresh.
- Primary citation
- Proclamation No. 175/2014, Article 7(1)
Report suspicious transactions and attempts regardless of amount.
- Implementation action
- File promptly when reasonable grounds exist, including attempted transactions, using the current authority-confirmed route; record the decision and transmission chronology.
- Evidence to retain
- Decision log, report, transmission proof and receipt or contingency record.
- Primary citation
- Proclamation No. 175/2014, Article 23, as amended by Proclamation No. 181/2018, Article 7
Prevent tipping off and restrict disclosure.
- Implementation action
- Limit access to reports and related inquiries and do not disclose them to the customer or unauthorised persons.
- Evidence to retain
- Access controls, logs, confidentiality procedure and training.
- Primary citation
- Proclamation No. 175/2014, Article 24; ESAAMLG MER 2025, Recommendation 21
07Payments, wires, thresholds, and partnersSeparate binding thresholds from safer operational controls.3 items+
Do not invent an automatic cash-reporting threshold.
- Implementation action
- Obtain any current objective-reporting directive, scope, aggregation, frequency and channel directly from the FIU or Bank of Eritrea before configuring production rules.
- Evidence to retain
- Authority-confirmed rule, configuration, filings and receipts.
- Primary citation
- ESAAMLG MER 2025, IO.4 and Recommendation 20
Control originator and beneficiary information on wires.
- Implementation action
- Capture and validate payer and payee information and use documented rules to execute, reject, suspend and follow up deficient transfers; treat USD 10,000 as the assessed domestic de minimis, not the FATF standard.
- Evidence to retain
- Messages, validation rules, exception decisions and retention proof.
- Primary citation
- Proclamation No. 175/2014, Articles 9 and 11; Legal Notice No. 130/2018, Article 16; ESAAMLG MER 2025, Recommendation 16
Retain responsibility for providers and agents.
- Implementation action
- Verify permission, diligence providers, contract for security and record access, monitor performance and test retrieval.
- Evidence to retain
- Due diligence, approval, contract, monitoring and retrieval test.
- Primary citation
- Applicable Bank of Eritrea approval; ESAAMLG MER 2025, Recommendations 14 and 17
08Targeted financial sanctionsThe 2025 evaluation found no adequate TFS legal basis or implementation mechanism.3 items+
Screen current UN designations as a risk and correspondent control.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions against the current UN consolidated list and applicable counterparty requirements.
- Evidence to retain
- List inventory, update logs, configuration and dispositions.
- Primary citation
- UN Security Council consolidated list; ESAAMLG MER 2025, Recommendations 6-7
Do not assert a domestic immediate-freeze power that has not been verified.
- Implementation action
- For a confirmed match, prevent voluntary execution where lawfully possible, preserve assets and evidence, and obtain urgent written direction from the competent Eritrean authority and counsel.
- Evidence to retain
- Match analysis, hold basis, timestamps and authority direction.
- Primary citation
- ESAAMLG MER 2025, Recommendations 6-7
Document reporting, false-positive and release authority.
- Implementation action
- Establish the current national route and act only on documented lawful authority; do not reuse the former country-specific UN sanctions regime, terminated in 2018.
- Evidence to retain
- Procedure, authority correspondence, decisions and reconciliation.
- Primary citation
- UN Security Council Resolution 2444 (2018); ESAAMLG MER 2025, IO.10-11
09Records and regulator accessRecords must reconstruct customers, ownership, transactions and decisions.3 items+
Retain CDD and relationship records for at least ten years.
- Implementation action
- Keep CDD, account files and business correspondence for ten years after relationship termination or the occasional transaction.
- Evidence to retain
- Schedule, archive sample, deletion control and legal holds.
- Primary citation
- Proclamation No. 175/2014, Article 11(1)
Retain transaction records for at least ten years.
- Implementation action
- Keep domestic and international transaction records for ten years after completion in a form sufficient to reconstruct individual transactions; prudently retain investigation analysis too.
- Evidence to retain
- Reconstruction test, analysis file and archive controls.
- Primary citation
- Proclamation No. 175/2014, Article 11(2)-(3)
Produce records securely to competent authorities.
- Implementation action
- Authenticate requests, protect STR confidentiality, produce reproducibly and log scope, timing and acknowledgement.
- Evidence to retain
- Request, approval, production index and receipt.
- Primary citation
- Proclamation No. 175/2014, Article 11; ESAAMLG MER 2025, Recommendation 11
10Privacy, biometrics, and transfersThe 2025 evaluation records no comprehensive data-protection framework.3 items+
Map legal basis, purpose, access, security and retention for identity data.
- Implementation action
- Reconcile AML retention and authority-access duties with contract, confidentiality, employment and sector rules; minimise collection and document access.
- Evidence to retain
- Data inventory, legal assessment, notice and access matrix.
- Primary citation
- Applicable sector/confidentiality rules; ESAAMLG MER 2025 contextual findings
Apply enhanced controls to biometric and sensitive data.
- Implementation action
- Document necessity, minimise collection, encrypt data, restrict access and independently test vendors and biometric security.
- Evidence to retain
- Impact assessment, vendor review, tests and approval.
- Primary citation
- Prudent security control; no comprehensive national biometric rule verified
Confirm transfers and incidents before production.
- Implementation action
- Obtain current primary guidance on cross-border transfers, competent authority and incident reporting; do not invent a portal, adequacy test or deadline.
- Evidence to retain
- Counsel memo, authority guidance, transfer assessment and incident plan.
- Primary citation
- Current Eritrean and applicable sector rules; controlled uncertainty
11Practical evidence packsMaintain compact evidence that reproduces regulated decisions.2 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack.
- Primary citation
- Operational control supporting Proclamation No. 175/2014, Articles 6, 7 and 11
Maintain a reconstructable monitoring and reporting pack.
- Implementation action
- Link transactions, alerts, analysis, approvals, reports and post-filing controls while protecting confidentiality.
- Evidence to retain
- Complete sampled case pack and access log.
- Primary citation
- Operational control supporting Proclamation No. 175/2014, Articles 11, 23 and 24
Primary-source register
9 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Combating Financing of Terrorism Proclamation No. 175/2014Government of Eritrea (reproduced by Africa Laws) · Primary legislation reproduction
- Eritrea Mutual Evaluation Report - July 2025ESAAMLG / FATF · Authoritative country assessment
- Eritrea mutual-evaluation publication pageFATF · Authoritative country assessment
- ESAAMLG publication notice for Eritrea MERESAAMLG · Authoritative regional-body notice
- FATF black and grey listsFATF · Authoritative current status
- Financial Institutions Proclamation No. 94/1997Government of Eritrea (Library of Congress copy) · Primary legislation reproduction
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
- Security Council Resolution 2444 (2018)United Nations · Primary international instrument
- Housing and Commerce Bank of Eritrea AML/CFT Policy 2024Housing and Commerce Bank of Eritrea · Official bank implementation context
Direct answers
Eritrea KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The legally established Financial Intelligence Unit. The July 2025 evaluation reported that it was not operational, so obtain current filing and contingency instructions before launch.
When is an STR required?+
Promptly on reasonable grounds of suspicion, including attempted transactions and regardless of amount. The assessed framework did not specify a precise deadline, form or method.
What is the occasional-transaction CDD threshold?+
Above USD 10,000 or equivalent, including linked operations. Suspicion and doubts about prior identity data trigger CDD regardless of that threshold.
Is there an automatic cash-reporting threshold?+
No universal operative threshold was verified. Obtain any current directive, scope, aggregation and channel directly from the FIU or Bank of Eritrea.
How is beneficial ownership handled?+
Financial institutions must identify and reasonably verify natural persons with controlling ownership. The assessed law lacked other-control and senior-manager fallback tests, and no comprehensive BO register was available.
How long are records retained?+
CDD and relationship records for ten years after termination or the occasional transaction; transaction records for ten years after completion.
Is Eritrea on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. This is not a low-risk finding.
Can virtual-asset services launch under a clear licence?+
The 2025 evaluation found no VASP licensing or registration framework. Do not launch without current written confirmation from competent Eritrean authorities.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 24 August 2026. Confirm post-assessment legal changes, FIU operational status and filing instructions, Bank of Eritrea directives, sanctions authority, business-register evidence, data rules and each product licence with the competent authority and qualified Eritrean counsel before launch.