Costa Rica KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Costa Rica.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Costa Rica ?
La checklist pour Costa Rica traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 33 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- National FIU
- Unidad de Inteligencia Financiera (UIF) within the Instituto Costarricense sobre Drogas
- Core AML framework
- Law 7786, reformed by Laws 8204, 8719, 9387 and 9449, plus sector regulations
- Financial-sector rule
- CONASSIF 12-21 for Article 14 entities
- Articles 15 and 15-bis rule
- SUGEF 13-19 registration and risk-based controls for covered activities
- Suspicious reports
- Directly, immediately and confidentially to UIF, including attempts and regardless of amount
- US$10,000 controls
- Special identification and reporting/data duties apply to defined cash operations and international electronic transfers; this is not a ROS threshold
- AML record retention
- At least 5 years from the applicable transaction or relationship trigger
- RTBF beneficial ownership
- 15% or more participation under the current decree, plus control by other means and senior-manager fallback
- Sanctions timing
- Freeze without delay and communicate a positive match to UIF within no more than 24 hours
- Privacy authority
- Agencia de Proteccion de Datos de los Habitantes (PRODHAB)
- FATF status
- GAFILAT member; not named on the FATF public lists reviewed 1 August 2026
Détail d’implémentation
Exigences et actions de conformité pour Costa Rica
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensingClassify the entity under Article 14, Article 15, Article 15-bis or outside those categories before choosing the rulebook.3 éléments+
Article 14 financial institutions are supervised under CONASSIF 12-21 by the competent financial superintendency.
- Action d’implémentation
- Map the legal entity and each product to SUGEF, SUGEVAL, SUPEN or SUGESE and capture market-specific lineamientos as well as the common rule.
- Preuves à conserver
- Perimeter memo, authorization, supervisor register, rule inventory and launch approval.
- Source primaire
- Law 7786 art. 14; CONASSIF 12-21 arts. 1-4
Covered activities under Articles 15 and 15-bis must register with SUGEF and comply with SUGEF 13-19.
- Action d’implémentation
- Test money transfer, third-party fund management, exchange, credit and listed non-financial activities; obtain registration before using products or accounts for the registered activity.
- Preuves à conserver
- Activity analysis, application, SUGEF registration, registered accounts, conditions and renewals.
- Source primaire
- Law 7786 arts. 15, 15-bis and 15-ter; SUGEF 13-19
Only legally authorized entities may conduct financial intermediation.
- Action d’implémentation
- Assess whether the model habitually takes public funds for lending or investment at its own risk; obtain SUGEF authorization where required and do not rely on AML registration alone.
- Preuves à conserver
- Funds-flow diagram, Law 7558 analysis, SUGEF correspondence and authorization.
- Source primaire
- Organic Law of the BCCR, Law 7558 arts. 116 and 119
02Governance and risk assessmentThe control framework must be approved, risk-based and appropriate to the applicable supervisory category.3 éléments+
Obliged entities must identify and assess customer, product, channel and geographic LC/FT/FPADM risks.
- Action d’implémentation
- Approve an enterprise assessment and translate it into risk appetite, customer scoring, due-diligence levels, scenarios and review frequency.
- Preuves à conserver
- Methodology, data, national-risk inputs, approval, validation and change log.
- Source primaire
- CONASSIF 12-21 arts. 5-13; SUGEF 13-19
The compliance function must have suitable authority, independence, resources and reporting access.
- Action d’implémentation
- Appoint the required officer or liaison for the entity category, document deputies and conflicts, and provide direct escalation to the governing body.
- Preuves à conserver
- Appointment, fit-and-proper evidence, role profile, minutes, budget, training and escalation log.
- Source primaire
- Law 7786 arts. 14-15-bis; CONASSIF 12-21 arts. 14-22; SUGEF 13-19
Controls must be tested and deficiencies remediated under the applicable audit and review rules.
- Action d’implémentation
- Schedule independent, internal or external review as required, assign accountable owners and validate closure with evidence.
- Preuves à conserver
- Audit plan, reports, management responses, remediation tracker and closure tests.
- Source primaire
- CONASSIF 12-21 arts. 23-27; SUGEF 13-19
03Natural-person KYC and representativesCDD must establish identity, authority, purpose, source and expected behaviour using reliable evidence.3 éléments+
Customers must be identified and verified, especially at relationship opening and for cash transactions above US$10,000.
- Action d’implémentation
- Capture official identity, domicile, occupation, purpose, expected activity and source of funds; authenticate evidence and resolve inconsistencies before activation.
- Preuves à conserver
- Identity record, verification result, profile, source evidence, reviewer and exceptions.
- Source primaire
- Law 7786 art. 16; CONASSIF 12-21 arts. 28-36
Representatives and signatories must be identified and their authority validated.
- Action d’implémentation
- Verify the natural person, obtain the current mandate or power, confirm its scope and link it to the represented customer and beneficial owners.
- Preuves à conserver
- Representative KYC, power, National Registry check, scope analysis and expiry control.
- Source primaire
- Law 7786 art. 16(c); CONASSIF 12-21 arts. 28-36
CDD must continue throughout the relationship and activity must remain consistent with the known customer and risk profile.
- Action d’implémentation
- Set risk-based refresh and event triggers, update source and beneficial-owner information and investigate material deviations.
- Preuves à conserver
- Review schedule, event alerts, updated file, discrepancy resolution and approval.
- Source primaire
- CONASSIF 12-21 arts. 28-38; SUGEF 13-19
04KYB, RTBF and beneficial ownershipAML beneficial-owner CDD and the entity's own RTBF filing are related but distinct obligations.3 éléments+
CDD must identify the natural persons who ultimately own or control the customer or receive the benefit.
- Action d’implémentation
- Verify legal existence, purpose and authority; trace direct and indirect ownership, voting and control by other means to natural persons.
- Preuves à conserver
- Registry certificate, constitutional documents, ownership chart, voting analysis, declarations and corroboration.
- Source primaire
- CONASSIF 12-21 arts. 3 and 29; Law 7786 art. 16
RTBF identifies 15% or greater direct or indirect participation and also requires control-by-other-means and senior-manager fallback analysis.
- Action d’implémentation
- Do not treat 15% as the sole test; calculate holdings and voting rights, assess appointment and other control and document the exceptional fallback.
- Preuves à conserver
- Cap table, indirect calculation, control memo, fallback rationale and reviewer sign-off.
- Source primaire
- Law 9416 art. 5; Executive Decree 44390-H arts. 8-10
Covered legal persons and structures must file accurate RTBF declarations annually and on applicable changes under the current schedule.
- Action d’implémentation
- Use Central Directo, track the current joint-resolution filing period, submit event-driven updates and reconcile declarations with corporate and AML records.
- Preuves à conserver
- RTBF declaration, BCCR receipt, source documents, change log and reconciliation.
- Source primaire
- Law 9416 arts. 5-7; Executive Decree 44390-H; Joint Resolution MH-DGT-ICD-RES-0020-2024
05PEPs, EDD and remote onboardingPEPs and higher-risk customers require management attention, source analysis and intensified monitoring.3 éléments+
Systems must determine whether a customer or beneficial owner is a PEP and cover relevant family members and close associates.
- Action d’implémentation
- Screen at onboarding and continuously, research the public function and relationship, and document the classification and review period.
- Preuves à conserver
- Screening, role research, relationship map, disposition and review date.
- Source primaire
- CONASSIF 12-21 arts. 3 and 39-41; General Regulation to Law 7786
PEP and other high-risk relationships require enhanced measures.
- Action d’implémentation
- Obtain senior approval, establish source of wealth and funds, set intensified monitoring and refresh and document why the relationship is accepted or continued.
- Preuves à conserver
- Approval, wealth and funds evidence, monitoring plan, reviews and exceptions.
- Source primaire
- CONASSIF 12-21 arts. 39-43; SUGEF 13-19
Remote onboarding must meet the same identification and accountable risk outcomes as other channels.
- Action d’implémentation
- Use permitted reliable sources, bind identity to the session, test impersonation and presentation attacks and govern vendors and fallback.
- Preuves à conserver
- Method approval, vendor due diligence, device and liveness evidence where used, tests and exceptions.
- Source primaire
- CONASSIF 12-21 arts. 32-36 and applicable superintendency lineamientos
06Monitoring, ROS and confidentialitySuspicion and attempts must be reported immediately, confidentially and independently of threshold-data reports.3 éléments+
Reasonable suspicion must be reported directly, immediately and confidentially to UIF, including attempted operations and regardless of amount.
- Action d’implémentation
- Escalate promptly, record the knowledge time and grounds, submit through the secure current channel and preserve the receipt and supplements.
- Preuves à conserver
- Alert, analysis, decision timeline, ROS, UIF receipt, supplement and access log.
- Source primaire
- Law 7786 art. 25; Executive Decree 40018 arts. 1-4
Unusual activity must be analysed against the customer's known profile before a documented ROS decision.
- Action d’implémentation
- Deploy risk-based scenarios, collect available facts without delaying an immediate report, document the conclusion and keep monitoring after filing.
- Preuves à conserver
- Scenario inventory, alerts, case file, rationale, tuning and quality assurance.
- Source primaire
- CONASSIF 12-21 arts. 46-52; SUGEF 13-19
Customers and unauthorised persons must not be informed of a ROS or related analysis.
- Action d’implémentation
- Restrict case access, separate servicing communications from reporting decisions and train staff on confidentiality and lawful supervisor access.
- Preuves à conserver
- Access roles, confidentiality acknowledgements, training, communications and incident log.
- Source primaire
- Law 7786 art. 25; Executive Decree 40018
07Threshold data, wires, payments and agentsUS$10,000 transaction data, payment-system participation and suspicious reporting are separate controls.3 éléments+
Defined cash operations and electronic transfers from or to another country at US$10,000 or more require the applicable record and information reporting treatment.
- Action d’implémentation
- Implement exact category and aggregation logic, submit through the applicable supervisor format and keep the process separate from ROS assessment.
- Preuves à conserver
- Rules, transaction extract, report file, receipt, exception and reconciliation.
- Source primaire
- Law 7786 arts. 20-24; CONASSIF 12-21 arts. 53-55
SINPE participation and payment services must comply with the BCCR Payment System Regulation and technical admission requirements.
- Action d’implémentation
- Classify the participant type, obtain affiliation or authorization, meet security and operating requirements and reconcile settlement and customer records.
- Preuves à conserver
- BCCR approval, participant agreement, technical certification, settlement controls and incidents.
- Source primaire
- BCCR Payment System Regulation, edition 24, effective 12 December 2025
Agents, correspondents and vendors operate under the accountable entity's responsibility.
- Action d’implémentation
- Contract for CDD, monitoring, evidence access, audit, incident notice and exit; test samples and prohibit use outside authorized activities.
- Preuves à conserver
- Due diligence, contract, training, monitoring, sample tests, incidents and exit plan.
- Source primaire
- CONASSIF 12-21; BCCR Payment System Regulation; applicable correspondent rules
08Targeted financial sanctionsCosta Rica requires direct list monitoring, freezing without delay and rapid UIF communication.3 éléments+
All relevant persons must monitor applicable UN lists and freeze or immobilize funds or assets without delay on a positive match.
- Action d’implémentation
- Screen customers, beneficial owners, representatives, counterparties and assets on list updates and before relevant activity; freeze without prior notice.
- Preuves à conserver
- List source, screening timestamp, match packet, freeze record and access controls.
- Source primaire
- Law 7786 art. 33-bis; Executive Decree 40018 arts. 6-7
A positive match and the freeze must be communicated to UIF within no more than 24 hours.
- Action d’implémentation
- Use the secure UIF platform, preserve the exact detection and freeze time and follow judicial or authority instructions for continuation or release.
- Preuves à conserver
- UIF communication, timestamp, receipt, authority correspondence and release approval.
- Source primaire
- Executive Decree 40018 arts. 6-7
Sanctions controls must include owned, controlled and acting-on-behalf relationships, not only exact customer-name matches.
- Action d’implémentation
- Map ownership and control, use multiple identifiers, investigate potential matches and document false-positive decisions.
- Preuves à conserver
- Ownership analysis, identifiers, screening result, escalation and reviewer approval.
- Source primaire
- Law 7786 art. 33-bis; Executive Decree 40018
09Records and regulator accessRecords must remain complete, secure and rapidly retrievable for the legally defined period.3 éléments+
Identity, account, correspondence and transaction records must be retained for at least five years from the applicable trigger.
- Action d’implémentation
- Define triggers by record class, suspend deletion for investigations and authority requests and document any longer sector period.
- Preuves à conserver
- Retention schedule, system rules, legal holds, deletion log and tested retrieval.
- Source primaire
- Law 7786 arts. 16(d)-(e) and 22
Records must permit reconstruction of transactions and the basis for CDD, risk and reporting decisions.
- Action d’implémentation
- Preserve source documents, versions, approvals, screening, alerts, communications and reports in an auditable sequence.
- Preuves à conserver
- Complete sample file, immutable audit trail, version history and reconstruction test.
- Source primaire
- Law 7786 arts. 16-22; CONASSIF 12-21
Information must be available to UIF and competent supervisors through lawful and secure channels.
- Action d’implémentation
- Maintain current credentials, verify authority, index each production and preserve secure delivery and legal-hold evidence.
- Preuves à conserver
- Request, authority check, production index, delivery receipt and hold.
- Source primaire
- Law 7786 arts. 17-19 and 123; applicable supervisor rules
10Privacy, biometrics and transfersAML duties coexist with informed processing, security, confidentiality and transfer controls under Law 8968.3 éléments+
Personal-data collection generally requires clear prior information and informed, express consent unless a legal exception applies.
- Action d’implémentation
- Map each KYC field to purpose and legal basis, provide the article 5 information, minimise optional data and keep ROS processing confidential.
- Preuves à conserver
- Data inventory, legal-basis record, notice, consent where used and rights log.
- Source primaire
- Law 8968 arts. 4-7; Executive Decree 37554-JP
Sensitive and biometric information requires strict necessity, lawful grounds and proportionate security.
- Action d’implémentation
- Document necessity, limit collection, test accuracy and bias, encrypt templates, restrict access and implement a lawful fallback.
- Preuves à conserver
- Necessity assessment, consent or exception, security design, testing, access and deletion logs.
- Source primaire
- Law 8968 arts. 9-11; Executive Decree 37554-JP arts. 35-37
Transfers to processors or third parties require valid authorization or another lawful basis and must preserve confidentiality and security.
- Action d’implémentation
- Map locations and subprocessors, contract for purpose limits, security, incident handling, deletion and regulator access, and assess each transfer.
- Preuves à conserver
- Data-flow map, transfer assessment, contracts, subprocessor register and incident plan.
- Source primaire
- Law 8968 arts. 11 and 14; Executive Decree 37554-JP
11Fintech, virtual assets and practical evidence packsFintech and virtual-asset models must be classified by function rather than marketing label.3 éléments+
Payment, stored-value, remittance and customer-fund models may trigger BCCR, SUGEF and Law 7786 requirements.
- Action d’implémentation
- Analyse custody, settlement, redemption, cross-border transfer, public-fund taking and third-party fund control; obtain each required approval before launch.
- Preuves à conserver
- Product and funds flows, legal opinions, regulator correspondence, approvals and conditions.
- Source primaire
- Law 7558 arts. 116 and 119; Law 7786 arts. 14-15-bis; BCCR Payment System Regulation
No blanket conclusion should be drawn from using virtual assets; the exact activity and legal perimeter control.
- Action d’implémentation
- Test exchange, transfer, custody, administration, investment and payment functions against Articles 14-15-bis, securities, payments, consumer, tax and sanctions rules and record any regulatory uncertainty.
- Preuves à conserver
- Dated perimeter memo, authority checks, risk assessment, customer restrictions and monitoring plan.
- Source primaire
- Law 7786; SUGEF 13-19; current BCCR and superintendency rules reviewed 1 August 2026
Every implemented control should have a compact and reviewable evidence pack.
- Action d’implémentation
- Assign an owner, applicability decision, procedure, system control, test, exception route and remediation date to every checklist row.
- Preuves à conserver
- Control matrix, RACI, evidence links, test results, gaps, remediation and approval.
- Source primaire
- Recommended implementation control supporting Law 7786 and sector-rule compliance
Registre des sources primaires
16 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law 7786 - current legal textSistema Costarricense de Informacion Juridica · Primary legislation
- CONASSIF 12-21 - Article 14 AML/CFT/CPF regulationSuperintendencia General de Entidades Financieras · Primary sector regulation
- SUGEF 13-19 - Articles 15 and 15-bis regulationSuperintendencia General de Entidades Financieras · Primary sector regulation
- Current SUGEF transversal regulations registerSuperintendencia General de Entidades Financieras · Official regulation register
- Executive Decree 40018 - ROS and targeted financial sanctionsSistema Costarricense de Informacion Juridica · Primary regulation
- Law 9416 - Tax Fraud Law and RTBFSistema Costarricense de Informacion Juridica · Primary legislation
- Executive Decree 44390-H - RTBF regulationSistema Costarricense de Informacion Juridica · Primary regulation
- Joint Resolution MH-DGT-ICD-RES-0020-2024 - RTBF filing rulesSistema Costarricense de Informacion Juridica · Primary administrative resolution
- RTBF 2025 official guideMinisterio de Hacienda · Official filing guidance
- Law 8968 - personal-data protectionSistema Costarricense de Informacion Juridica · Primary legislation
- Costa Rica data-protection legislation registerAgencia de Proteccion de Datos de los Habitantes · Official legislation register
- BCCR Payment System Regulation - edition 24Banco Central de Costa Rica · Primary payment regulation
- SUGEF warning and authorization guidance for unauthorised financial activitySuperintendencia General de Entidades Financieras · Official licensing guidance
- FATF Costa Rica country pageFinancial Action Task Force · Official country and follow-up source
- FATF black and grey listsFinancial Action Task Force · Official current-status source
- FATF Latin America regional body pageFinancial Action Task Force · Official GAFILAT membership source
Réponses directes
Questions KYC, KYB et AML pour Costa Rica
Who receives suspicious-operation reports in Costa Rica?+
The UIF of the Instituto Costarricense sobre Drogas. Reports must be sent directly, immediately and confidentially through the current secure channel.
Are attempted suspicious operations reportable?+
Yes. Executive Decree 40018 expressly covers attempts, regardless of amount.
Is US$10,000 the Costa Rica ROS threshold?+
No. Suspicion has no monetary threshold. US$10,000 is relevant to defined cash and international-transfer identification and information-reporting controls.
What is the Costa Rica beneficial-owner threshold?+
The current RTBF regulation uses 15% or more participation, but control by other means and an exceptional senior-manager fallback must also be assessed.
How long must AML records be kept?+
At least five years from the applicable end-of-transaction or relationship trigger, subject to legal holds and any longer sector rule.
What is the sanctions reporting deadline?+
Freeze or immobilize without delay and communicate a positive match to UIF within no more than 24 hours under Executive Decree 40018.
Does SUGEF AML registration authorize financial intermediation?+
No. Article 15 or 15-bis registration is distinct from prudential authorization. Public-fund-taking and other regulated financial activities require separate analysis and approval.
How are fintech and virtual-asset businesses treated?+
Classification follows the activity, not the label. Test custody, exchange, transfer, payments, remittance, customer-fund management and investment functions against Law 7786, BCCR, SUGEF, securities and other rules.
Is Costa Rica on a FATF public list?+
Costa Rica was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026, but remains subject to GAFILAT follow-up and risk-based controls still apply.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice, a licence decision or a substitute for the operative Spanish text, SUGEF/UIF instructions or regulator confirmation. Reviewed 1 August 2026. Confirm entity, activity, customer, transaction, reporting format, RTBF filing period, sanctions route, privacy role and later developments with qualified Costa Rican counsel and the competent authority before launch.