KYC, KYB & AML compliance checklist
The Gambia KYC, KYB & AML
An implementation checklist for customer and business verification in The Gambia under the Anti-Money Laundering and Combating of Terrorist Financing Act 2012, FIU guidance, financial-sector supervision and company-registration requirements.
- Reviewed
- 21 July 2026
- Version
- 1.0
- control areas
- 11
- implementation checks
- 33
Direct answer
What does the The Gambia compliance checklist cover?
The The Gambia checklist translates primary KYC, KYB and AML rules into 11 control areas and 33 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML/CFT law
- Anti-Money Laundering and Combating of Terrorist Financing Act 2012
- Financial intelligence unit
- Financial Intelligence Unit of The Gambia
- STR timing
- As soon as practicable and no later than three working days
- Casual-customer CDD
- More than GMD 200,000; suspicion and identity doubt apply regardless of amount
- Large-cash purpose inquiry
- More than USD 10,000 or Gambian-dalasi equivalent
- Core AML retention
- Minimum five years under record-class-specific clocks
- Beneficial ownership
- Natural person with ultimate ownership/control or ultimate effective control; no universal AML percentage
- Company registry
- Companies Department, Ministry of Justice
- Payments and fintech
- Obtain activity-specific CBG classification and authority before launch
- FATF public lists
- Not named in June 2026 statements; GIABA enhanced follow-up is separate
Implementation detail
The Gambia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and regulated activitiesResolve entity, activity and supervisor scope before launch.3 items+
Financial institutions and listed DNFBPs are reporting entities under the 2012 Act.
- Implementation action
- Map each entity, product, profession, branch, agent and outsourced service to the Act's schedules and competent supervisor.
- Evidence to retain
- Perimeter memorandum, entity-product map, licences and supervisor register.
- Primary citation
- 2012 Act, ss.2 and 59; First and Second Schedules
The FIU receives and analyses reports, issues instructions and supervises compliance within its mandate.
- Implementation action
- Register compliance contacts and obtain the FIU's current reporting access, forms and instructions.
- Evidence to retain
- FIU correspondence, access records, contacts and regulatory calendar.
- Primary citation
- 2012 Act, ss.3-7, 18 and 33
Banking, money services, payments, fintech and virtual-asset activity require activity-specific authority.
- Implementation action
- Obtain a written CBG or relevant-authority perimeter decision and every required licence before pilot or launch.
- Evidence to retain
- Classification, application, licence, conditions and approved product map.
- Primary citation
- CBG Banking Supervision and official licensing materials; controlled perimeter dependency
02Governance, risk assessment and control ownershipBuild documented, risk-based and accountable controls.2 items+
Reporting entities maintain customer-identification, records, reporting, employee-screening and technology controls.
- Implementation action
- Approve a risk-based AML/CFT programme covering every entity, product, channel and customer class.
- Evidence to retain
- Programme, risk assessments, procedures, approvals and issue log.
- Primary citation
- 2012 Act, s.39
A compliance officer, staff training and independent audit are required.
- Implementation action
- Appoint an empowered officer, train relevant staff and independently test the control lifecycle.
- Evidence to retain
- Appointment, charter, training records, audit reports and remediation.
- Primary citation
- 2012 Act, s.39
03Natural-person identification and CDDApply statutory triggers without treating thresholds as safe harbours.4 items+
CDD applies before or within a reasonable time of a relationship or transaction, to electronic transfers, suspicion and identity doubt.
- Implementation action
- Configure relationship, transaction, transfer, suspicion and identity-quality triggers and record the applicable basis.
- Evidence to retain
- Trigger matrix, cases, verification timestamps and exceptions.
- Primary citation
- 2012 Act, s.25(1)
Natural persons are identified and verified using official documents and reliable independent sources.
- Implementation action
- Capture name, address, occupation and valid photo identification and authenticate the evidence proportionately.
- Evidence to retain
- Identity file, authenticity result, address evidence and decision.
- Primary citation
- 2012 Act, s.25(1)-(2)(b)
Casual-customer identification applies above GMD 200,000, including connected transactions once the aggregate crosses the threshold.
- Implementation action
- Aggregate apparently connected activity and apply CDD earlier where suspicion or doubt exists.
- Evidence to retain
- Aggregation logic, alerts, identity file and decision.
- Primary citation
- 2012 Act, s.25(2)(e)
For cash above USD 10,000 or its dalasi equivalent, purpose, origin and ultimate destination require reasonable measures.
- Implementation action
- Obtain and corroborate source, purpose and destination evidence before release.
- Evidence to retain
- Customer explanation, source documents, destination evidence and approval.
- Primary citation
- 2012 Act, s.25(4)
04KYB, authority and beneficial ownershipVerify existence, authority and ultimate natural-person ownership or control.4 items+
Legal-entity CDD verifies incorporation, address, directors, principal owners, beneficiaries, control structure and binding powers.
- Implementation action
- Obtain current registry and constitutive evidence and reconcile directors, mandates, ownership and control.
- Evidence to retain
- Registry extract, certificate, constitution, annual return, directors and discrepancy log.
- Primary citation
- 2012 Act, s.25(2)(c); definition of identification record
Representatives and third-party principals require verified identity and authority.
- Implementation action
- Verify each representative and the person for whose ultimate benefit the transaction is conducted.
- Evidence to retain
- Identity files, mandate, board authority and verification result.
- Primary citation
- 2012 Act, s.25(2)(c)(iv) and s.25(3)
A beneficial owner is the natural person who ultimately owns or controls, or exercises ultimate effective control.
- Implementation action
- Trace every ownership layer and test non-ownership control without inventing a universal percentage.
- Evidence to retain
- Ownership chart, source records, control analysis and BO identity files.
- Primary citation
- 2012 Act, s.2 definition of beneficial owner
Company registration evidence must be obtained from the Companies Department and kept current.
- Implementation action
- Confirm the live forms, annual-return position and any beneficial-ownership filing directly with the registry.
- Evidence to retain
- Registry receipt, certified records, annual return and registry correspondence.
- Primary citation
- Companies Act 2013; Ministry of Justice Companies Department guidance
05PEPs, enhanced due diligence and relianceApply stronger controls to higher-risk relationships.3 items+
PEPs require identity verification, senior-management approval, reasonable source-of-wealth measures and enhanced monitoring.
- Implementation action
- Screen customers and beneficial owners, corroborate source evidence and document approval before activation.
- Evidence to retain
- Screening, match decision, source file, approval and monitoring plan.
- Primary citation
- 2012 Act, s.25(2)(d)
Third-party reliance does not remove the reporting entity's duty to obtain information immediately and documents without delay.
- Implementation action
- Assess the intermediary's regulation and controls, contract for access and test retrieval.
- Evidence to retain
- Due diligence, agreement, retrieval tests and monitoring.
- Primary citation
- 2012 Act, s.25(7)
Remote onboarding must achieve reliable independent verification and manage technology misuse risk.
- Implementation action
- Use document-integrity, liveness or presence, device and fraud controls proportionate to risk.
- Evidence to retain
- Remote standard, test results, fraud logs and exceptions.
- Primary citation
- 2012 Act, ss.25(1) and 39(e); recommended implementation control
06Failed CDD, monitoring and suspicious reportingBlock unsafe activity and report suspicion promptly and confidentially.5 items+
If satisfactory identity evidence cannot be obtained, the entity must not establish or maintain the relationship and may report the attempt.
- Implementation action
- Block activation or terminate under controlled procedures and refer the case for confidential STR review.
- Evidence to retain
- Failure reason, block, closure, STR decision and receipt.
- Primary citation
- 2012 Act, s.26
Complex, unusual and large transactions, higher-risk jurisdictions and incomplete wire information receive special monitoring.
- Implementation action
- Examine and record background and purpose and make findings available to FIU or competent authority.
- Evidence to retain
- Alerts, cases, written findings, escalation and refreshed CDD.
- Primary citation
- 2012 Act, s.30
Transactions, attempted transactions and relevant information linked to crime, ML or TF are reportable to the FIU.
- Implementation action
- Escalate immediately, preserve the suspicion timestamp and submit the prescribed STR.
- Evidence to retain
- Internal report, analysis, STR, receipt and timeline.
- Primary citation
- 2012 Act, s.33(1)-(3)
An STR is due as soon as practicable and no later than three working days after suspicion or information.
- Implementation action
- Use a shorter internal SLA measured from the recorded formation or receipt time.
- Evidence to retain
- Trigger timestamp, approval, submission time and SLA monitoring.
- Primary citation
- 2012 Act, s.33(1)
Tipping off is prohibited and good-faith reporting is protected.
- Implementation action
- Restrict access and govern customer communications and lawful disclosures.
- Evidence to retain
- Access logs, communication plan, training and disclosure register.
- Primary citation
- 2012 Act, ss.34-37
07Wires, thresholds, payments and agentsKeep CDD, transaction records and reportable thresholds distinct.3 items+
Wire transfers carry accurate originator information, subject to stated card and inter-institution exceptions.
- Implementation action
- Validate required information through the payment chain and govern incomplete messages.
- Evidence to retain
- Field matrix, validation, repair or reject queue and samples.
- Primary citation
- 2012 Act, ss.29-30
Sector thresholds in the Act are not a universal transaction-reporting threshold.
- Implementation action
- Map each threshold to its exact sector and control and confirm any current FIU threshold-report direction before implementation.
- Evidence to retain
- Threshold matrix, FIU direction, configuration and receipts.
- Primary citation
- 2012 Act, ss.40-43; controlled live-direction dependency
Payment, remittance, e-money, fintech, agent and virtual-asset models require current perimeter confirmation.
- Implementation action
- Do not launch until CBG or the relevant authority confirms licensing, agent and AML/CFT conditions in writing.
- Evidence to retain
- Legal classification, application, authority, agent register and monitoring.
- Primary citation
- CBG official supervision and licensing materials; controlled uncertainty
08Targeted financial sanctions and CPFApply current lists and authority instructions without inventing procedures.2 items+
Terrorist property and court-directed restraint provisions require controlled escalation and preservation.
- Implementation action
- Screen customers, BOs, representatives and transactions against current UN and domestic designations and escalate potential matches immediately.
- Evidence to retain
- List provenance, screening logs, match decisions, holds and authority correspondence.
- Primary citation
- 2012 Act, Parts III, VII and VIII; current procedure must be confirmed
The live freezing, reporting, false-positive and CPF procedure must be confirmed with the competent authority.
- Implementation action
- Maintain a 24/7 escalation route and obtain written instructions before releasing or dealing with potentially affected property.
- Evidence to retain
- Procedure, escalation log, instruction, decision and audit trail.
- Primary citation
- Controlled uncertainty; FIU and competent-authority confirmation required
09Records, access and assuranceRetain reconstructable evidence under the correct clock.3 items+
Identity, transaction, correspondence, FIU report and enquiry records are kept for at least five years under record-class-specific clocks.
- Implementation action
- Map each class to identity collection, transaction/correspondence, and later of closure or relationship cessation and apply legal holds.
- Evidence to retain
- Retention schedule, configuration, samples and deletion tests.
- Primary citation
- 2012 Act, s.27(1)-(2)
Records must reconstruct transactions and be immediately available to FIU or competent authorities.
- Implementation action
- Index linked identity, transaction, investigation and reporting evidence and test retrieval.
- Evidence to retain
- Request register, retrieval tests, access controls and response package.
- Primary citation
- 2012 Act, s.27(3)-(5)
Electronic records require backup, recovery and authentication controls.
- Implementation action
- Test integrity, backup, recovery and authorised access throughout retention.
- Evidence to retain
- Architecture, backup tests, audit logs and recovery evidence.
- Primary citation
- 2012 Act, s.27(4)
10Privacy, biometrics and transfersUse cautious data governance while the public legal framework is confirmed.2 items+
Identity and transaction data must be protected while remaining available for lawful AML/CFT access.
- Implementation action
- Document purpose and necessity, minimise collection, restrict access and preserve AML evidence.
- Evidence to retain
- Data inventory, access matrix, notices, logs and retention mapping.
- Primary citation
- 2012 Act, ss.27 and 35; recommended privacy control
Biometrics, breach notification, data-subject rights and international transfers require a verified current legal basis.
- Implementation action
- Confirm applicable law and regulator expectations before processing; do not invent a deadline or transfer mechanism.
- Evidence to retain
- Legal memo, impact assessment, transfer map, incident playbook and contracts.
- Primary citation
- Controlled uncertainty; 2019 national policy is contextual, not enacted-law authority
11Practical evidence packs and change controlMake decisions reconstructable and keep time-sensitive rules current.2 items+
A complete customer file links identity, KYB, ownership, screening, risk, approval, monitoring and reporting decisions.
- Implementation action
- Block activation when mandatory evidence or approval is missing and preserve the release decision.
- Evidence to retain
- Control checklist, linked file, approvals and release log.
- Primary citation
- 2012 Act, Parts V-VII
FIU instructions, thresholds, sanctions lists, FATF status, registry and licensing requirements require ongoing monitoring.
- Implementation action
- Assign owners and review FIU, CBG, Ministry of Justice, Gazette, FATF and GIABA sources on a governed schedule.
- Evidence to retain
- Legal inventory, source log, change assessments and implementation tickets.
- Primary citation
- Official sources listed below

11 control areas and 33 implementation checks, with direct regulatory sources.
Download the Gambia KYC, KYB & AML checklist
Share your work details for immediate access to the source-linked Gambia implementation checklist. Regulatory review date: 21 July 2026.
Get the PDF immediately
Submit your details and the download starts automatically
Reviewed and source-linked
Version 1.0, reviewed 21 July 2026
Trusted by leading compliance teams
Primary-source register
9 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Combating of Terrorist Financing Act 2012Financial Intelligence Unit of The Gambia · Primary legislation - official FIU copy
- AML/CFT Guidelines for Financial InstitutionsFIU and Central Bank of The Gambia · Official sector guidance
- AML/CFT Guidelines for DNFBPsFinancial Intelligence Unit of The Gambia · Official sector guidance
- FIU downloads and reporting resourcesFinancial Intelligence Unit of The Gambia · Official FIU guidance
- Banking supervision and licensing materialsCentral Bank of The Gambia · Official regulator
- Companies Department registration guidanceMinistry of Justice · Official company registry guidance
- The Gambia second enhanced follow-up report, 2024GIABA · Authoritative regional assessment
- Jurisdictions under Increased Monitoring - June 2026FATF · Authoritative public statement
- High-Risk Jurisdictions subject to a Call for Action - June 2026FATF · Authoritative public statement
Direct answers
The Gambia KYC, KYB and AML questions
Who receives suspicious transaction reports in The Gambia?+
The Financial Intelligence Unit of The Gambia, using its current prescribed form and channel.
When is an STR due?+
As soon as practicable and no later than three working days after forming suspicion or receiving the relevant information.
When does casual-customer identification apply?+
Above GMD 200,000, including connected transactions once the aggregate crosses that amount; suspicion and identity doubt apply regardless of amount.
Does The Gambia use one AML beneficial-ownership percentage?+
The 2012 Act's AML definition states ultimate natural-person ownership or control and ultimate effective control; it does not state one universal percentage.
How long are core AML records kept?+
At least five years, with the start event depending on the record class and the later of closure or relationship cessation where applicable.
Are payment, fintech or virtual-asset services permitted by company registration alone?+
No licence outcome should be inferred. Obtain activity-specific written classification and every required authority from CBG or the competent authority before operations.
What sanctions or CPF deadline applies?+
The reviewed public sources do not support one universal operational deadline. Confirm current lists, freezing and reporting procedures directly with FIU and the competent authority.
Is The Gambia on a FATF public list?+
The Gambia was not named in FATF's June 2026 public statements. GIABA enhanced follow-up is a separate peer-review process.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
VOVE ID Compliance Research · Reviewed 21 July 2026 · Version 1.0
This checklist is general regulatory information, not legal advice or a licence determination. It reflects sources reviewed on 21 July 2026. Confirm FIU registration, current reporting forms and channels, threshold-report treatment, sanctions and CPF procedures; CBG licensing for each payment, remittance, e-money, fintech or virtual-asset model; registry beneficial-ownership filings; and privacy, biometric, breach and transfer requirements with Gambian counsel and the competent authority before launch. VOVE ID supports evidence collection and audit trails; the reporting entity remains responsible for acceptance, reporting, restraint and compliance decisions.