Madagascar KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Madagascar.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Réponse directe
Que couvre la checklist de conformité pour Madagascar ?
La checklist pour Madagascar traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 33 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- SAMIFIN
- Primary AML rule
- Law 2018-043, amended by Law 2023-026
- Suspicion reporting
- Without delay, including attempted transactions
- Registry BO threshold
- 25% or more, then control and fallback cascade
- Core AML retention
- At least 5 years
- FATF status
- Not named on FATF public lists as at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Madagascar
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the reporting entity, activity and supervisor before launch.3 éléments+
Determine whether each activity is in AML/CFT/CPF scope.
- Action d’implémentation
- Map every entity, product, channel and profession to the financial-institution, DNFBP, nonprofit or other covered categories and identify SAMIFIN and the competent supervisor.
- Preuves à conserver
- Applicability memo, product map and accountable-owner register.
- Source primaire
- Law 2018-043, Articles 4 and 8; Decree 2024-1352, Article 11
Establish the current SAMIFIN reporting route.
- Action d’implémentation
- Obtain the current form or electronic-platform procedure, designate authorised reporters, test secure delivery and preserve acknowledgements.
- Preuves à conserver
- Registration, user authority, channel test and receipt log.
- Source primaire
- Law 2018-043, Articles 23, 27 and 28, as amended by Law 2023-026
Obtain authorisation before regulated activity.
- Action d’implémentation
- Classify banking, payment, money or value transfer, e-money, insurance, microfinance, agent, foreign-exchange, securities, fintech and crypto-asset activities and obtain every required approval before launch.
- Preuves à conserver
- Perimeter analysis, licences, conditions and renewal calendar.
- Source primaire
- Law 2018-043, Articles 4, 8, 20 and 31; Decree 2024-1352, Article 11; applicable CSBF rules
02Governance and risk assessmentControls must be risk-based, documented, current and independently tested.3 éléments+
Maintain a documented ML/TF/PF risk assessment.
- Action d’implémentation
- Assess customers, geography, products, channels, cash, agents, technology, virtual assets and proliferation exposure; update before material change and retain supporting evidence.
- Preuves à conserver
- Approved methodology, assessment, controls and version history.
- Source primaire
- Law 2018-043, Article 6; Decree 2024-1352, Articles 4-6
Transmit the annual risk assessment where required.
- Action d’implémentation
- Provide the supported assessment to SAMIFIN and the relevant supervisory authority before 31 December each year and retain it for at least five years from transmission.
- Preuves à conserver
- Submitted assessment, delivery receipt and retention control.
- Source primaire
- Decree 2024-1352, Article 5
Maintain governance, training and independent control.
- Action d’implémentation
- Implement written customer diligence, monitoring, reporting, records, confidentiality, employee training and internal-control measures proportionate to the business and track remediation.
- Preuves à conserver
- Policies, appointments, training, testing and management reporting.
- Source primaire
- Law 2018-043, Articles 6 and 19
03Natural-person identificationIdentify and verify customers and representatives before or during the permitted point of engagement.3 éléments+
Identify and verify the customer and address.
- Action d’implémentation
- Use current reliable official documents and independent information before opening an account, taking custody or establishing another business relationship; record any representative and authority.
- Preuves à conserver
- Identity file, address evidence, source provenance and mandate.
- Source primaire
- Law 2018-043, Articles 13-14
Understand purpose and intended nature.
- Action d’implémentation
- Record the purpose and nature of the relationship, expected activity, counterparties, geography and source information sufficient for risk rating and monitoring.
- Preuves à conserver
- Customer profile, expected-activity baseline and approval.
- Source primaire
- Law 2018-043, Article 13(9), inserted by Law 2023-026, Article 8
Do not proceed where mandatory diligence fails.
- Action d’implémentation
- Do not establish the relationship or execute the transaction, or terminate an existing relationship, when mandatory diligence cannot be completed; submit a suspicious transaction report without delay.
- Preuves à conserver
- Decline or exit decision, investigation and restricted reporting record.
- Source primaire
- Law 2018-043, Article 15 bis, inserted by Law 2023-026, Article 9
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and control and keep the analysis current.3 éléments+
Verify legal existence and authority.
- Action d’implémentation
- Obtain current registry, constitutional, address, director, shareholder, signatory, licence and mandate evidence; reconcile material discrepancies.
- Preuves à conserver
- Registry extract, governing records, powers and discrepancy log.
- Source primaire
- Law 2018-043, Articles 12-15; Decree 2024-1352, Articles 7-9
Apply the registry beneficial-owner cascade accurately.
- Action d’implémentation
- For registry duties, identify natural persons holding at least 25% of capital or voting rights, including joint factual control below that level; then test control by other means, principal-manager fallback and legal-representative fallback.
- Preuves à conserver
- Ownership chart, control analysis, verified identities and fallback rationale.
- Source primaire
- Order 11689/2024-MEF, Article 3
Keep beneficial-owner registers accurate and current.
- Action d’implémentation
- Maintain the required physical and electronic special register, verify supporting evidence, make initial, annual and change declarations to the tax authority and report known mismatches through the prescribed route.
- Preuves à conserver
- Registers, declarations, verification record and discrepancy report.
- Source primaire
- Order 11689/2024-MEF, Articles 4 and 12-14; Tax Procedures Code Articles IV-22 to IV-41
05PEPs, EDD, and remote onboardingHigher-risk and non-face-to-face relationships require enhanced, evidenced controls.3 éléments+
Detect PEP and higher-risk exposure.
- Action d’implémentation
- Use appropriate systems to determine whether the customer or beneficial owner is a foreign or domestic PEP, a close family member or associate, or otherwise high risk.
- Preuves à conserver
- Screening, relationship map, match decision and refresh log.
- Source primaire
- Law 2018-043, Articles 4(21) and 16(b)
Apply enhanced approval, provenance and monitoring.
- Action d’implémentation
- For covered PEP and high-risk relationships, obtain required senior approval, establish source of wealth and funds, and apply enhanced ongoing monitoring.
- Preuves à conserver
- Approval, provenance analysis and monitoring plan.
- Source primaire
- Law 2018-043, Articles 13(8) and 16(b), as amended by Law 2023-026
Control remote and biometric onboarding.
- Action d’implémentation
- Assess impersonation, liveness, document authenticity, data minimisation, security and fallback review before deploying remote or biometric checks; confirm any current supervisor conditions.
- Preuves à conserver
- Remote-onboarding assessment, data review, tests and approvals.
- Source primaire
- Law 2018-043, Articles 6 and 13; Law 2014-038 on personal data
06Monitoring and suspicious reportingSAMIFIN reporting must be immediate, complete and confidential.3 éléments+
Monitor and examine unusual activity.
- Action d’implémentation
- Scrutinise transactions against the customer profile; examine complex, unusually large, unexplained or high-risk activity and document the purpose, parties and conclusion.
- Preuves à conserver
- Alerts, investigation, disposition and rule governance.
- Source primaire
- Law 2018-043, Articles 13 and 16
Report suspicion and attempts without delay.
- Action d’implémentation
- Report to SAMIFIN as soon as suspicion is identified, including attempted transactions and relevant ML, TF or PF suspicion, regardless of whether execution was prevented or suspicion arose later.
- Preuves à conserver
- Decision chronology, report, supporting material, delivery and receipt.
- Source primaire
- Law 2018-043, Article 27, replaced by Law 2023-026, Article 14
Prevent tipping off and protect reporting data.
- Action d’implémentation
- Restrict access and do not disclose the report or its existence to the customer or any unauthorised person; use the current form, platform or other accepted written channel.
- Preuves à conserver
- Access logs, confidentiality procedure, training and acknowledgement.
- Source primaire
- Law 2018-043, Article 28
07Payments, wires, thresholds, and agentsUse verified sector instructions; do not infer one universal transaction threshold.3 éléments+
Configure only current, applicable thresholds.
- Action d’implémentation
- Map customer-diligence, cash, casino, cross-border declaration and sector reporting thresholds to the current instrument and aggregation rule; do not apply the casino or nonprofit amounts universally.
- Preuves à conserver
- Threshold register, authoritative instruments, tests and approval.
- Source primaire
- Law 2018-043, Articles 11, 14, 21 and 22; applicable SAMIFIN and supervisor directives
Preserve required wire-transfer information.
- Action d’implémentation
- Carry required originator and beneficiary information through the payment chain, identify incomplete transfers and reject, suspend or report them under current CSBF instructions.
- Preuves à conserver
- Message samples, validation rules, exceptions and reports.
- Source primaire
- Law 2018-043, Article 16(d), as amended by Law 2023-026, Articles 10-11; Decree 2024-1352, Article 10
Retain accountability for agents and third parties.
- Action d’implémentation
- Verify permissions, include money or value transfer agents and sub-agents in the AML programme, report their list to the competent authority, monitor them and preserve prompt access to relied-on diligence.
- Preuves à conserver
- Agent register, due diligence, contracts, monitoring and retrieval test.
- Source primaire
- Law 2018-043, Article 16(d)-(e), as amended by Law 2023-026, Article 11
08Targeted financial sanctionsImplement current UN and national designations through Madagascar's 2025 framework.3 éléments+
Screen current designation lists promptly.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and relevant transactions at onboarding, list updates and before execution using current UN and national lists.
- Preuves à conserver
- List inventory, update logs, screening configuration and dispositions.
- Source primaire
- Law 2018-043, Articles 55 and 55 ter as amended; Decree 2025-171
Freeze covered funds and assets within the required process.
- Action d’implémentation
- Implement national-list freezing within 24 hours and without prior notice; when any list is communicated, immediately check databases, freeze covered assets, prohibit availability and report results and measures to SAMIFIN.
- Preuves à conserver
- Freeze procedure, timestamps, asset record and FIU report.
- Source primaire
- Decree 2025-171, Articles 20-22 and 25-27
Report attempts and govern release.
- Action d’implémentation
- Report attempted transactions involving frozen assets to SAMIFIN and permit delisting, unfreezing or access only through the documented CNSFC and ministerial process.
- Preuves à conserver
- Attempt report, match rationale, authority decision and reconciliation.
- Source primaire
- Decree 2025-171, Articles 28 and 33-48
09Records and regulator accessRecords must reconstruct customers, ownership, transactions and decisions.3 éléments+
Retain customer identity records for at least five years.
- Action d’implémentation
- Keep customer and beneficial-owner identity evidence for at least five years after account closure or the end of the relationship, subject to longer applicable holds.
- Preuves à conserver
- Schedule, archive sample, deletion control and legal-hold log.
- Source primaire
- Law 2018-043, Article 17(1); Decree 2024-1352, Article 7
Retain transaction and analysis records for at least five years.
- Action d’implémentation
- Keep transaction records and Article 16 reports for at least five years after execution and keep books, customer correspondence and transaction analyses for at least five years after the relationship ends.
- Preuves à conserver
- Transaction archive, analysis file and retrieval test.
- Source primaire
- Law 2018-043, Article 17(2)-(3)
Respond securely to competent requests.
- Action d’implémentation
- Authenticate requests, protect reporting confidentiality, produce reconstructable records within the specified time and format, and log the disclosure and receipt.
- Preuves à conserver
- Request, approval, production index and acknowledgement.
- Source primaire
- Law 2018-043, Articles 18 and 25
10Privacy, biometrics, and transfersAML processing remains subject to Madagascar's personal-data framework.3 éléments+
Map lawful purpose, data and formalities.
- Action d’implémentation
- Document AML purposes, data categories, notices, access, sharing, retention and any CMIL declaration or authorisation required for the processing.
- Preuves à conserver
- Data inventory, legal-basis assessment, notices and filing record.
- Source primaire
- Law 2014-038, Chapters III-V
Apply heightened controls to sensitive and biometric data.
- Action d’implémentation
- Confirm the conditions for identity, criminal-offence, health or biometric processing; minimise collection and protect confidentiality, integrity, access and incident response.
- Preuves à conserver
- Impact assessment, security tests, access review and incident records.
- Source primaire
- Law 2014-038 on personal data; Law 2018-043, Article 28
Control cross-border personal-data transfers.
- Action d’implémentation
- Assess the destination, safeguards, processor terms and any CMIL procedure before transferring personal data abroad; separately confirm banking secrecy and supervisor requirements.
- Preuves à conserver
- Transfer assessment, safeguards, contract and approval.
- Source primaire
- Law 2014-038, cross-border transfer provisions; Law 2018-043, Article 16(e)
11Practical evidence packsMaintain concise packs that reproduce decisions and support supervision.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, KYB, beneficial ownership, screening, risk, approvals, data records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack.
- Source primaire
- Operational control supporting Law 2018-043, Articles 6 and 13-17
Maintain a reconstructable monitoring and reporting pack.
- Action d’implémentation
- Link transactions, alerts, analysis, approvals, SAMIFIN reports, delivery evidence and post-filing controls while protecting confidentiality.
- Preuves à conserver
- Complete sampled case pack and access log.
- Source primaire
- Operational control supporting Law 2018-043, Articles 16-19 and 27-28
Maintain a launch and change-control pack.
- Action d’implémentation
- Record licensing, threshold sources, sanctions lists, privacy formalities, product risk, testing and authority confirmations before launch and material changes.
- Preuves à conserver
- Signed launch pack, legal-source register and change approvals.
- Source primaire
- Operational control supporting Law 2018-043, Articles 6, 8, 16 and 31
Registre des sources primaires
12 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 2018-043 on money laundering and terrorist financingMadagascar National Assembly · Primary national legislation
- Official AML/CFT/CPF laws, decrees and orders librarySAMIFIN · Official FIU legislation library
- Law No. 2023-026 amending Law No. 2018-043Madagascar / SAMIFIN · Primary amending legislation
- Decree No. 2024-1352 implementing the amended AML/CFT lawMadagascar / SAMIFIN · Primary implementing regulation
- Decree No. 2025-171 on targeted financial sanctionsMadagascar / SAMIFIN · Primary sanctions regulation
- Order No. 11689/2024-MEF on beneficial-owner registersMadagascar Ministry of Economy and Finance / SAMIFIN · Primary registry regulation
- Practical guide to AML/CFT/CPF duties for DNFBPsSAMIFIN · Official FIU guidance
- SAMIFIN suspicious transaction report routeSAMIFIN · Official FIU reporting page
- Law No. 2014-038 on protection of personal dataMadagascar National Assembly · Primary privacy legislation
- Madagascar 12th enhanced follow-up report and fifth technical-compliance reratingESAAMLG · Authoritative regional assessment
- FATF high-risk and monitored jurisdictionsFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Madagascar
Who receives suspicious transaction reports?+
SAMIFIN, Madagascar's Financial Intelligence Unit, through its current form, electronic platform or other accepted written route.
When is suspicion reported?+
Without delay as soon as suspicion is identified, including attempted transactions and cases discovered after execution.
Is there one universal transaction threshold?+
No universal amount is asserted. Apply only the current threshold and aggregation rule for the customer, product, transaction and sector; casino and nonprofit amounts are not universal.
How is registry beneficial ownership determined?+
Start with natural persons holding at least 25% of capital or voting rights, while accounting for joint factual control below that level; then test other control, principal-manager fallback and legal-representative fallback.
How long are core AML records retained?+
Generally at least five years, with the trigger depending on the record: account closure or relationship end for identity records, transaction execution for transaction records, and relationship end for books, correspondence and analysis.
What privacy rules apply?+
Law No. 2014-038 governs personal-data processing. Confirm CMIL formalities, sensitive or biometric conditions and transfer safeguards for the proposed implementation.
Is Madagascar on a FATF public list?+
It was not named on FATF's high-risk or increased-monitoring lists current at 19 June 2026. It remains in ESAAMLG enhanced follow-up after the 2018 mutual evaluation.
Can a payment, fintech or crypto-asset product launch without approval?+
No. Classify the product, provider and agent model and obtain every applicable CSBF or other competent-authority permission before launch.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 1 September 2026. Confirm current SAMIFIN and CSBF filing, threshold, onboarding and transfer instructions, registry procedures, sanctions communications, privacy formalities and product-specific permissions with the competent authority and qualified Malagasy counsel before launch.