Équateur KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Équateur.
- Dernière revue
- Dernière revue:
- Version
- Version 1.3

Réponse directe
Que couvre la checklist de conformité pour Équateur ?
La checklist pour Équateur traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 50 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- National FIU
- Unidad de Analisis Financiero y Economico (UAFE)
- Core framework
- 2024 Organic AML Law, effective 29 July 2025, and Executive Decree 298 of 2 February 2026
- Suspicious reports
- Within 5 business days from compliance-committee awareness, or entity awareness where no committee exists, regardless of amount
- Threshold reports
- USD 10,000 individual or aggregated for the same beneficiary within a 30-day period; file within the first 15 days of the following month
- No-report records
- Register NO ROS and NO RESU within 10 business days after the end of each month in which no corresponding report exists
- Retention
- 10 years after relationship termination, the last transaction or the occasional transaction, as applicable; transfer data also 10 years
- Beneficial owner
- At least 10% capital, control by other means, then highest-ranking managing official fallback
- PEP period
- At least 2 years after leaving office, followed by a documented risk reassessment
- Privacy authority
- Superintendencia de Proteccion de Datos Personales (SPDP)
- Virtual assets
- PSAVs are reporting entities supervised by the Superintendencia de Bancos for AML/CFT/CPF; UAFE status does not replace any permission required for the particular regulated activity
- FATF status
- GAFILAT member; not named on FATF call-for-action or increased-monitoring lists reviewed 1 August 2026
Détail d’implémentation
Exigences et actions de conformité pour Équateur
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensingThe 2024 law classifies financial, non-financial and virtual-asset reporting entities. Registration and financial or payment authorization are separate questions.5 éléments+
Financial reporting entities include regulated financial and insurance actors, payment-system participants, money or value transfer providers, exchanges, securities actors and specified credit, leasing and factoring businesses.
- Action d’implémentation
- Map each entity and product to article 27 and the current sector instrument, identify the supervisor and document the Ecuador nexus.
- Preuves à conserver
- Perimeter memorandum, entity and product inventory, supervisor matrix, legal nexus and signed approval.
- Source primaire
- 2024 Organic AML Law arts. 26-27
Article 28 covers specified non-financial activities, including real estate, construction, vehicle and precious-goods businesses, NPOs and defined legal, accounting, company and trust services.
- Action d’implémentation
- Test the exact activity and professional-service conditions; do not classify an entire profession without the statutory transaction nexus.
- Preuves à conserver
- Activity map, engagement analysis, statutory limb, exclusions and counsel sign-off.
- Source primaire
- 2024 Organic AML Law arts. 28-30
A PSAV is a reporting entity when, as a business, it exchanges virtual assets for fiat, exchanges one or more virtual assets, transfers virtual assets, custodies or administers virtual assets or instruments controlling them, or participates in or provides financial services related to an issuer's offer or sale of a virtual asset. PSAV AML/CFT/CPF supervision is assigned to the Superintendencia de Bancos.
- Action d’implémentation
- Map every virtual-asset product and role to the article 31 perimeter, document whether the activity is conducted as a business, register with UAFE and resolve any activity-specific permission with the Superintendencia de Bancos.
- Preuves à conserver
- Product and activity map, article 31 analysis, business-model evidence, UAFE code, SB correspondence or permission analysis and launch approval.
- Source primaire
- 2024 Organic AML Law arts. 26, 31 and 65
A reporting entity must obtain and maintain the UAFE code of registration and any license or operating registration required by its supervisor.
- Action d’implémentation
- Complete the applicable registration before operating, provision SISLAFT and notify changes within 15 business days.
- Preuves à conserver
- UAFE code, supervisor license or registration, SISLAFT access, change log and receipts.
- Source primaire
- 2024 Organic AML Law arts. 56 and 67; Executive Decree 298 arts. 55-59; Organic Administrative Code arts. 158-160
Financial, payment and fintech services require the authorization or qualification prescribed by the Monetary and Financial Code, Fintech Law and BCE or sector rules.
- Action d’implémentation
- Do not accept deposits, provide reserved financial services or operate a covered payment role before the correct authorization; verify the public regulator record.
- Preuves à conserver
- Licensing analysis, application, decision, public record, conditions and launch gate.
- Source primaire
- Organic Monetary and Financial Code art. 254; Fintech Law; JPRM-2024-018-M; applicable SB and BCE rules
02Governance and risk assessmentReporting entities must operate a proportionate AML/CFT/CPF program validated and supervised by the competent authority.4 éléments+
The prevention program must address policies, procedures, internal controls, staff integrity and training, risk-based diligence and conflicts of interest.
- Action d’implémentation
- Build and approve a program proportionate to activity, size, structure and complexity and map every statutory element to an owner and control.
- Preuves à conserver
- Approved program, manual, control matrix, ownership, training plan and validation record.
- Source primaire
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 47 and 80
Risk methodology must cover identification, evaluation, monitoring, administration and mitigation across customers, products, geography, channels and transactions.
- Action d’implémentation
- Document inherent and residual risk, control effectiveness, thresholds, overrides and escalation and refresh the assessment at least annually.
- Preuves à conserver
- Methodology, risk assessment, data, scoring, approval, annual refresh and remediation.
- Source primaire
- 2024 Organic AML Law arts. 36-39
A reporting entity must designate the required qualified compliance officer and protect SISLAFT credentials and reporting independence.
- Action d’implémentation
- Appoint the officer and substitute where required, confirm qualification, resource the function and govern absence, change and confidential access.
- Preuves à conserver
- Appointment, qualification, UAFE record, charter, budget, access log and succession plan.
- Source primaire
- 2024 Organic AML Law art. 34; Executive Decree 298 arts. 42-49
New products, practices and technologies require a documented ML/TF/PF assessment before launch.
- Action d’implémentation
- Assess customer, delivery, cyber, impersonation, sanctions, outsourcing and privacy risks and approve measurable launch and monitoring controls.
- Preuves à conserver
- Pre-launch assessment, threat model, tests, approval, monitoring metrics and change record.
- Source primaire
- 2024 Organic AML Law art. 38
03Natural-person KYC and representativesCDD must identify and verify the customer and representative, establish purpose and source of funds and continue throughout the relationship.5 éléments+
The customer or provider must be identified and verified from reliable documents, data or information.
- Action d’implémentation
- Capture the required identity, address, activity, income or funds and purpose data, authenticate evidence and bind it to the applicant.
- Preuves à conserver
- Identity file, source data, authenticity result, timestamps, reviewer and exception record.
- Source primaire
- 2024 Organic AML Law arts. 41-43
A representative must be identified, verified and shown to be authorized.
- Action d’implémentation
- Verify the natural person and validate the power, mandate or role before enabling action; restrict access to the authorized scope.
- Preuves à conserver
- Representative KYC, mandate, registry or notarial check, authority analysis and expiry control.
- Source primaire
- 2024 Organic AML Law art. 43(b)
CDD is continuous and must test transactions against the known business, activity and risk profile, including source of funds when necessary.
- Action d’implémentation
- Set event- and risk-based refresh, monitor expected activity and resolve material deviations and stale identity evidence.
- Preuves à conserver
- Profile, refresh schedule, triggers, alerts, investigations, updates and approvals.
- Source primaire
- 2024 Organic AML Law art. 43(d)-(e)
Verification ordinarily occurs before or while establishing the relationship; delayed completion is limited to controlled cases and must finish within five business days, subject to a possible UAFE extension of up to three business days.
- Action d’implémentation
- Use delayed verification only where essential not to interrupt normal operations and risk is controlled; limit activity, clock the business-day deadline and document any extension.
- Preuves à conserver
- Exception rationale, risk controls, deadline, UAFE request and response, verification and approval.
- Source primaire
- 2024 Organic AML Law art. 45; Organic Administrative Code arts. 158-160
If required CDD cannot be completed, the reporting entity must not start the relationship, open an account or execute the transaction. If the relationship has already begun, it must terminate it and submit a ROS to UAFE.
- Action d’implémentation
- Block onboarding and transaction execution, terminate an existing relationship through the controlled process, preserve the failed-CDD record and file the ROS without tipping off.
- Preuves à conserver
- System block, failed-CDD analysis, termination approval, ROS, acknowledgement and restricted communication log.
- Source primaire
- 2024 Organic AML Law art. 47
04KYB, registries and beneficial ownershipLegal-person CDD and the SRI beneficial-owner register both require a natural-person outcome, but the reporting entity must independently verify its customer.4 éléments+
Legal-person and arrangement CDD includes legal name, form, existence, principal address, governing powers, senior managers, business nature and ownership and control structure.
- Action d’implémentation
- Obtain current SCVS or other registry evidence, constitutional documents, RUC, governance and purpose, and reconcile discrepancies.
- Preuves à conserver
- Registry extract, constitutional documents, RUC, governance list, business profile and discrepancy log.
- Source primaire
- 2024 Organic AML Law art. 44
A beneficial owner is the natural person who ultimately owns or controls the entity or on whose behalf the transaction occurs.
- Action d’implémentation
- Trace ownership to natural persons, examine contractual and other control and identify trust or arrangement parties and ultimate controllers.
- Preuves à conserver
- Ownership chart, cap tables, agreements, trust documents, control analysis and identity evidence.
- Source primaire
- 2024 Organic AML Law arts. 4(f), 43(c) and 92
For a legal person, article 92 uses at least 10% capital, control by other means and then the highest-ranking managing official fallback.
- Action d’implémentation
- Calculate direct and indirect ownership, document decision-unit and appointment rights and use the fallback only after recording why ownership and control tests found no person.
- Preuves à conserver
- Calculations, control memorandum, source documents, fallback record and approval.
- Source primaire
- 2024 Organic AML Law art. 92(1)
Every legal person must register its beneficial owners with SRI under the applicable conditions; inaccurate information identified by SRI or SCVS must be corrected within 10 business days, with a possible extension of up to five business days.
- Action d’implémentation
- Maintain the REBEFICS and SRI calendar, reconcile customer and corporate records and clock correction notices in business days.
- Preuves à conserver
- BO register, REBEFICS filing, receipt, reconciliation, correction notice and response.
- Source primaire
- 2024 Organic AML Law arts. 91 and 93-94; SRI Resolution NAC-DGERCGC24-00000033; Organic Administrative Code arts. 158-160
05PEPs, enhanced diligence and remote onboardingPEPs, associates and specified high-risk categories require reinforced controls; PEP status alone does not justify denial of service.6 éléments+
Systems must determine whether a customer or beneficial owner is a domestic or foreign PEP or an associate.
- Action d’implémentation
- Screen at onboarding and continuously, identify the role and dates and map relevant family, close associate and control relationships.
- Preuves à conserver
- Screening, role source, relationship analysis, disposition, review date and changes.
- Source primaire
- 2024 Organic AML Law arts. 49-50; Executive Decree 298 arts. 74-75
Foreign PEPs and associates, and higher-risk domestic PEP cases, require senior approval, reasonable source-of-wealth and source-of-funds measures and intensified monitoring.
- Action d’implémentation
- Obtain approval before opening or continuing, corroborate wealth and funds and configure enhanced review and scenarios.
- Preuves à conserver
- Approval, wealth analysis, funds trail, supporting records, monitoring plan and periodic review.
- Source primaire
- 2024 Organic AML Law art. 49
PEP status remains for two years after office, after which the reporting entity reassesses risk and documents whether enhanced treatment continues.
- Action d’implémentation
- Clock departure dates, retain PEP controls through the two-year minimum and complete a reasoned reassessment rather than automatic removal.
- Preuves à conserver
- Role end date, two-year control, risk reassessment, approval and screening update.
- Source primaire
- Executive Decree 298 art. 76
Irrespective of the entity's own risk score, intensified due diligence applies to every activity and person category listed in article 50, including the specified justice, defence, security, corrections, customs, border, elected-office, state-contractor, natural-resource and professional-football categories.
- Action d’implémentation
- Map the complete statutory category list into onboarding and monitoring, identify qualifying roles and activities, obtain intensified evidence and approval, and retain the legal-category rationale.
- Preuves à conserver
- Article 50 category matrix, screening and role evidence, enhanced approval, source-of-funds or wealth support, monitoring plan and review.
- Source primaire
- 2024 Organic AML Law art. 50
Relationships or transactions involving FATF high-risk jurisdictions require intensified measures, while jurisdictions under FATF monitoring require measures proportionate to the identified risk.
- Action d’implémentation
- Ingest current FATF statements, distinguish call-for-action from monitored jurisdictions, configure the required treatment and document country-risk decisions and exceptions.
- Preuves à conserver
- Dated FATF lists, country-risk matrix, enhanced or proportionate measures, approval, monitoring and review.
- Source primaire
- 2024 Organic AML Law art. 51
Remote onboarding and external identity providers remain subject to the reporting entity's CDD responsibility and confidentiality duties.
- Action d’implémentation
- Validate the method, test impersonation and liveness, contract for evidence and audit access and independently monitor the provider.
- Preuves à conserver
- Remote-flow legal map, vendor review, tests, contract, sample QA, incidents and exit plan.
- Source primaire
- 2024 Organic AML Law arts. 43-45 and 53-54
06Monitoring, suspicious reports and confidentialityEcuador's 2024 law uses a five-business-day awareness-based ROS deadline and covers completed and attempted operations regardless of amount.4 éléments+
Submit the ROS within five business days from the date the compliance committee becomes aware of the suspicious completed or attempted operation; if the entity has no compliance committee, count from when the reporting entity becomes aware. The duty applies regardless of amount.
- Action d’implémentation
- Escalate immediately, preserve the applicable committee-or-entity awareness timestamp, document grounds and submit the ROS with support through SISLAFT.
- Preuves à conserver
- Alert, investigation, committee or entity awareness record, decision, report, support and acknowledgement.
- Source primaire
- 2024 Organic AML Law art. 57; Executive Decree 298 art. 28; Organic Administrative Code arts. 158-160
A reasoned request made within the legal framework may receive a UAFE extension of up to three additional business days; an extension must never be assumed.
- Action d’implémentation
- Treat five business days as the control deadline, request an extension only when justified and preserve UAFE's written response.
- Preuves à conserver
- Business-day deadline clock, request, grounds, UAFE response, filing and quality review.
- Source primaire
- 2024 Organic AML Law art. 57; Organic Administrative Code arts. 158-160
If no ROS exists for a month, the reporting entity must register NO ROS in UAFE's reporting system within 10 business days after the end of that month.
- Action d’implémentation
- Reconcile all cases, obtain compliance approval and submit the no-report record within the 10-business-day term.
- Preuves à conserver
- Case reconciliation, approval, NO ROS record, receipt and exception log.
- Source primaire
- 2024 Organic AML Law art. 59; UAFE Resolution UAFE-DG-2026-0007; Organic Administrative Code arts. 158-160
Disclosure of a ROS, its existence or UAFE examination to unauthorized persons is prohibited and a very serious infringement.
- Action d’implémentation
- Restrict case access, use neutral communications and route disclosure requests through legal and compliance.
- Preuves à conserver
- Access log, confidentiality acknowledgements, communications, training and disclosure approvals.
- Source primaire
- 2024 Organic AML Law arts. 23 and 81(h), (m)
07Payments, wires, thresholds and agentsThreshold reporting, cash restrictions and transfer information apply alongside payment and fintech authorization.5 éléments+
Within the first 15 days of each month, reporting entities submit RESU for individual operations at or above USD 10,000 and multiple operations that together reach or exceed USD 10,000 for the benefit of the same person within a 30-day period.
- Action d’implémentation
- Aggregate across channels and products for the rolling 30-day period, validate the beneficiary and submit the current UAFE structure; track any sector-specific lower threshold.
- Preuves à conserver
- Aggregation logic, test cases, RESU file, reconciliation, receipt and correction log.
- Source primaire
- 2024 Organic AML Law art. 58; Executive Decree 298 art. 61
If no threshold report exists for a month, the entity must register NO RESU in UAFE's reporting system within 10 business days after the end of that month.
- Action d’implémentation
- Reconcile source systems, approve the nil position and submit NO RESU within the 10-business-day term.
- Preuves à conserver
- Monthly reconciliation, approval, NO RESU record, receipt and exception handling.
- Source primaire
- 2024 Organic AML Law art. 59; Executive Decree 298 art. 61; Organic Administrative Code arts. 158-160
Except for contractual obligations arising from products, services or operations of national-financial-system entities and BCE under Executive Decree 298 General Provision Five, no person may pay, settle, accept payment or accept settlement of an obligation or transaction equal to or above USD 10,000 using domestic or foreign notes or coins, precious stones or precious metals.
- Action d’implémentation
- Block covered settlement methods at the threshold, route payment through a permitted method and document the legal basis and evidence for any financial-system or BCE exclusion.
- Preuves à conserver
- Payment-method rules, threshold tests, blocked transaction, permitted settlement record, exclusion analysis and approval.
- Source primaire
- 2024 Organic AML Law art. 33; Executive Decree 298 General Provision Five
Originator, beneficiary and account or reference information must accompany domestic, cross-border and virtual-asset transfers, including batches, and be retained for 10 years.
- Action d’implémentation
- Validate required fields before release, stop or investigate missing information, screen parties and preserve the complete message.
- Preuves à conserver
- Message, field validation, screening, exception, investigation, approval and archive.
- Source primaire
- 2024 Organic AML Law art. 52
Payment aggregators, gateways, processors, switches and SEDPES require the authorization and controls applicable to their BCE and sector role.
- Action d’implémentation
- Obtain authorization before service, maintain UAFE compliance certification, govern agents and vendors and meet data, security and operating requirements.
- Preuves à conserver
- BCE or sector authorization, operating scheme, contracts, UAFE certificate, security report and monitoring.
- Source primaire
- Fintech Law; JPRM-2024-018-M; BCE payment-participant authorization requirements
08Targeted financial sanctions and freezingEcuador uses a UAFE-led, judicial freezing process for UN terrorism and proliferation designations. Operators must monitor and escalate matches without delay.5 éléments+
Reporting entities must monitor UN Security Council lists concerning terrorism and proliferation.
- Action d’implémentation
- Screen customers, beneficial owners, counterparties and transactions against the current UN lists and UAFE communications.
- Preuves à conserver
- List source and timestamp, configuration, screening logs, match analysis and escalation.
- Source primaire
- 2024 Organic AML Law arts. 37 and 55; UAFE Resolution UAFE-DG-2022-0095
A potential designation match must be reported through the UAFE process so the competent authorities can seek the applicable preventive judicial measure.
- Action d’implémentation
- Escalate a true match immediately, preserve all funds and transaction facts, follow UAFE instructions and avoid alerting the subject.
- Preuves à conserver
- Match worksheet, identifiers, UAFE communication, preservation steps and restricted access.
- Source primaire
- UAFE Resolution UAFE-DG-2022-0095; UAFE UN freezing guide
A competent preventive immobilization or freezing order must be implemented within its exact scope; failure is a very serious infringement.
- Action d’implémentation
- Authenticate the order, block the identified property, prevent value from being made available and confirm execution through the prescribed channel.
- Preuves à conserver
- Order, authority validation, block timestamps, asset inventory, confirmation and reconciliation.
- Source primaire
- 2024 Organic AML Law art. 81(k); UAFE UN freezing guide
Separately from UN-list freezing, UAFE may immediately order an exceptional and proportionate immobilization of funds in the national financial system where objective, serious and verifiable indications arise from a ROS, early warning, complaint, national-intelligence information or UAFE intelligence. Financial entities must execute within 72 hours; the measure lasts no more than eight days pending judicial ratification, modification or revocation.
- Action d’implémentation
- Authenticate and execute the UAFE order within 72 hours, restrict the identified funds, preserve confidentiality, track the eight-day maximum and implement only the verified judicial outcome.
- Preuves à conserver
- UAFE order, receipt and execution timestamps, restricted-funds inventory, access log, judicial decision and reconciliation.
- Source primaire
- 2024 Organic AML Law art. 17.3; Executive Decree 298 arts. 52-55
Where a covered financial-system or popular-and-solidarity financial entity freezes, immobilizes, retains or detains funds through internal due-diligence processes because of suspected illicit or criminal activity, it must report through the applicable Complementary AML Unit and transfer the funds within five business days to the designated BCE custody account, following the operative authority procedure and preserving the holder's right to challenge the measure.
- Action d’implémentation
- Identify article 48.1 cases separately from UN and UAFE measures, notify the competent complementary unit, transfer the funds to the verified BCE custody account within five business days and preserve challenge and release records.
- Preuves à conserver
- Internal decision, suspicion basis, holder and funds record, complementary-unit report, BCE transfer receipt, business-day clock, challenge and disposition.
- Source primaire
- 2024 Organic AML Law art. 48.1; Organic Administrative Code arts. 158-160
09Records and regulator accessRecords must make customer, beneficial-owner, transfer, monitoring and report decisions reconstructable for 10 years and available to competent authorities.4 éléments+
CDD, transaction, analysis, account and business-correspondence records, with documentary support, must be retained for 10 years after termination of the contractual relationship, the last transaction, or the occasional transaction, as applicable. Transfer originator and beneficiary information must also be retained for 10 years.
- Action d’implémentation
- Map each record to its statutory trigger, maintain the 10-year archive unless a longer sector duty applies and preserve legal holds.
- Preuves à conserver
- Retention schedule, relationship and transaction trigger dates, archive, holds, restore tests and destruction approvals.
- Source primaire
- 2024 Organic AML Law arts. 48 and 52
CDD, beneficial-owner, monitoring, report and governance evidence must remain complete, secure and retrievable.
- Action d’implémentation
- Preserve source evidence, metadata, approvals and linked case chronology and test retrieval and integrity periodically.
- Preuves à conserver
- Customer and case index, integrity hashes, access logs, backups, sample retrieval and remediation.
- Source primaire
- 2024 Organic AML Law arts. 34-59; applicable sector rule
UAFE and designated supervisors may conduct in-situ and off-site supervision and request information within their competence.
- Action d’implémentation
- Authenticate requests, preserve confidentiality and privilege, collect reproducibly and meet the stated deadline.
- Preuves à conserver
- Request, authority check, collection log, production index, delivery and receipt.
- Source primaire
- 2024 Organic AML Law arts. 66-75; Executive Decree 298 art. 73
Electronic reporting corrections and replacements must follow UAFE validation and replacement procedures.
- Action d’implémentation
- Monitor validation messages, correct errors within the operative period and preserve the original, replacement request, authorization and final accepted file.
- Preuves à conserver
- Validation result, error analysis, replacement request, approval, final receipt and audit trail.
- Source primaire
- 2024 Organic AML Law art. 81(n)-(p); Executive Decree 298 art. 64; UAFE Resolution 2023-0559
10Privacy, biometrics and transfersAML processing must also satisfy Ecuador's Organic Personal Data Protection Law, its regulation and current SPDP instruments.4 éléments+
Personal data must be processed on a lawful basis, transparently, for proportionate purposes and no longer than necessary subject to legal retention.
- Action d’implémentation
- Map each KYC field and use to a legal basis, provide required information, restrict reuse and reconcile privacy deletion with AML holds.
- Preuves à conserver
- Processing inventory, basis map, notices, retention schedule, access controls and deletion decisions.
- Source primaire
- Organic Personal Data Protection Law arts. 7-12 and 47; General Regulation arts. 8-11
Biometric data is sensitive and high-risk or large-scale processing may require a prior impact assessment and heightened safeguards.
- Action d’implémentation
- Document necessity, proportionality and basis, minimize templates, test attacks, complete the required impact assessment and govern vendors.
- Preuves à conserver
- Biometric assessment, impact assessment, consent or other basis, architecture, tests and vendor terms.
- Source primaire
- Organic Personal Data Protection Law arts. 10, 26 and 42; General Regulation arts. 29-32
A qualifying breach is notified to SPDP and ARCOTEL as soon as possible and no later than five business days; the processor notifies the controller within two business days, and affected persons within three business days when their rights are at risk.
- Action d’implémentation
- Maintain business-day statutory clocks, assess risk, issue complete notifications and record reasons for delay and remediation.
- Preuves à conserver
- Incident timeline, assessment, regulator and individual notices, processor communication and remediation.
- Source primaire
- Organic Personal Data Protection Law arts. 43 and 46; General Regulation arts. 24-28; Organic Administrative Code arts. 158-160
International transfers require adequate protection, an approved safeguard or a lawful exception; required DPO appointments and the current SPDP transfer rule must be observed.
- Action d’implémentation
- Map transfers and processors, select and document the transfer mechanism, audit safeguards and designate and register the DPO where required.
- Preuves à conserver
- Transfer map, adequacy or contract analysis, processor audit, DPO appointment and SPDP records.
- Source primaire
- Organic Personal Data Protection Law arts. 48-50 and 55-59; SPDP Resolution 2026-0004-R
11Practical evidence packsA usable control environment preserves the source, decision, owner and timestamp for every material regulatory conclusion.4 éléments+
Each product needs an approved perimeter and authorization pack.
- Action d’implémentation
- Record the legal entity, activity, reporting category, supervisor, UAFE code, financial or payment authorization, privacy role and review date.
- Preuves à conserver
- Signed perimeter pack, source snapshots, registrations, authorizations, owner and next review.
- Source primaire
- 2024 Organic AML Law arts. 26-32, 56 and 67
Each customer file must evidence identity, authority, beneficial ownership, risk, PEP status and ongoing monitoring.
- Action d’implémentation
- Use a pre-activation quality gate and periodic sample review, and remediate gaps to verified closure.
- Preuves à conserver
- Customer index, KYC and KYB evidence, ownership chart, risk score, approvals, monitoring and QA.
- Source primaire
- 2024 Organic AML Law arts. 41-54
Reporting evidence must demonstrate the applicable committee-or-entity awareness timestamp, five-business-day ROS control, threshold aggregation, nil returns, validation and confidentiality.
- Action d’implémentation
- Test cases end to end, reconcile every monthly submission and maintain portal continuity and restricted access.
- Preuves à conserver
- Scenario tests, case chronology, ROS, RESU, nil records, receipts, access review and remediation.
- Source primaire
- 2024 Organic AML Law arts. 57-59; Executive Decree 298 arts. 28 and 60-64
Legal change monitoring must cover UAFE, SB, SCVS, SEPS, BCE, SRI, SPDP, FATF and GAFILAT.
- Action d’implémentation
- Assign official sources and owners, review on a defined cadence and trigger impact assessment, controlled versioning, training and release.
- Preuves à conserver
- Source register, dated review log, impact assessment, approvals, releases and training.
- Source primaire
- Applicable laws and regulator publications listed in Sources
Registre des sources primaires
28 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- 2024 Organic Law on Prevention, Detection and Combat of Money Laundering and Financing of Other CrimesUAFE · Primary legislation
- Official Gazette Fourth Supplement 610 - 2024 Organic AML LawRegistro Oficial · Official gazette
- Executive Decree 298 - 2026 General AML RegulationSuperintendencia de Economia Popular y Solidaria · Primary regulatory instrument
- Official Gazette Third Supplement 216 - Executive Decree 298Registro Oficial · Official gazette
- UAFE legal and regulatory libraryUAFE · Official regulator library
- ROS and NO ROS current reporting guidanceUAFE · Official reporting guidance
- UAFE report typesUAFE · Official reporting guidance
- UAFE registration-code procedureUAFE · Official registration guidance
- Current reporting-entity designationsUAFE · Official perimeter guidance
- UAFE Resolution 2022-0131 - PSAV designation (legacy reporting deadlines displaced by the 2024 Law and current UAFE rules)UAFE · Primary designation instrument with superseded deadline provisions
- UAFE terrorism and UN freezing portalUAFE · Official sanctions guidance
- UAFE UN sanctions freezing guideUAFE · Official sanctions guidance
- SCVS AML/CFT regulatory directorySuperintendencia de Companias, Valores y Seguros · Official supervisor library
- SRI Resolution NAC-DGERCGC24-00000033 - REBEFICSServicio de Rentas Internas · Primary beneficial-owner regulation
- Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary legislation
- General Regulation to the Organic Personal Data Protection LawSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- SPDP resolutions directorySuperintendencia de Proteccion de Datos Personales · Official regulator library
- SPDP Resolution 2026-0004-R - international data transfersSuperintendencia de Proteccion de Datos Personales · Primary regulatory instrument
- Fintech Law - Official Gazette Second Supplement 215Registro Oficial · Primary legislation
- JPRM-2024-018-M - payment systems and fintech activitiesBanco Central del Ecuador · Primary payment regulation
- Payment-system participant authorizationBanco Central del Ecuador · Official licensing guidance
- Superintendencia de Bancos regulatory codificationSuperintendencia de Bancos · Official supervisory rules library
- Organic Administrative Code - computation of administrative termsConsejo de la Judicatura · Primary legislation
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current status
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current status
- FATF mutual evaluation of EcuadorFinancial Action Task Force · Official international assessment
- GAFILAT network and evaluation scheduleFinancial Action Task Force · Official international assessment
- United Nations Security Council consolidated sanctions listUnited Nations Security Council · Official sanctions list
Réponses directes
Questions KYC, KYB et AML pour Équateur
Who receives suspicious operation reports in Ecuador?+
Reporting entities submit ROS to UAFE through SISLAFT using the current UAFE structure and support requirements.
What is Ecuador's ROS deadline?+
Within five business days from the compliance committee's awareness of the suspicious completed or attempted operation, or from the reporting entity's awareness where it has no committee, regardless of amount. A UAFE extension of up to three business days requires a reasoned request and should never be assumed.
What is the threshold-report rule?+
Individual operations of at least USD 10,000 and multiple operations reaching that amount for the same beneficiary within a month are reported within the first 15 days of the following month, subject to any lower sector threshold.
What if there is no ROS or threshold report?+
NO ROS and NO RESU must be registered in UAFE's reporting system within 10 business days after the end of each month in which no corresponding report exists.
How is beneficial ownership determined?+
For a legal person, the law uses at least 10% capital, control through other means, and then the highest-ranking managing official fallback. Trust and arrangement parties are traced to natural persons.
How long are AML records retained?+
CDD, transaction, analysis, account and business-correspondence records with documentary support are retained for 10 years after relationship termination, the last transaction or the occasional transaction, as applicable. Transfer originator and beneficiary data is also retained for 10 years.
Do payment and fintech services require authorization?+
Yes when they fall within a reserved or regulated role. UAFE reporting status does not replace the BCE, Superintendencia de Bancos or other sector authorization.
Are virtual-asset service providers reporting entities?+
Yes. The perimeter covers business activity involving fiat/virtual-asset or virtual-asset exchanges, transfers, custody or control instruments, and financial services related to an issuer's offer or sale. PSAVs are supervised by the Superintendencia de Bancos for AML/CFT/CPF and maintain a UAFE code, while any activity-specific permission is separate. The four-day ROS and 15-day nil-report deadlines in the 2022 designation instrument are displaced by the 2024 Law and current UAFE rules.
What privacy deadlines apply to a qualifying breach?+
The controller notifies SPDP and ARCOTEL no later than five business days, the processor notifies the controller within two business days, and affected persons are notified within three business days when their rights are at risk.
Is Ecuador on a FATF public list?+
Ecuador was not named on the FATF call-for-action or increased-monitoring lists reviewed 1 August 2026. This does not replace a risk-based country assessment.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector rules, UAFE resolutions, SISLAFT manuals or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, supervisor, reporting calendar, technical structure, licensing perimeter, privacy role and later developments with qualified Ecuadorian counsel and the relevant authority before launch.