Anti-Money Laundering Due Diligence: A Rwanda Guide
Rwanda's rules require defined reporting persons to identify customers, understand who ultimately controls them, respond proportionately to risk and preserve evidence that management can defend.
Contents
Who Rwanda's customer due diligence
rules cover
A customer file must explain a decision
Risk changes the depth of inquiry
Management owns the control system
The 2026 sanctions make weak evidence
costly
The practical compliance rule
Anti-money laundering refers to the laws
and business controls used to stop criminals from disguising unlawful funds as
legitimate money. Customer due diligence is one of those controls. It requires
certain regulated businesses and professionals, legally called reporting
persons, to establish who a customer is, who ultimately owns or controls the
customer, why the relationship exists and whether the customer's activity is
consistent with the known risk.
An identity document can confirm a name. It
cannot, by itself, explain why a transaction makes commercial sense, who
controls a corporate customer or why a business accepted a particular risk.
Customer due diligence is therefore not simply the collection of documents at
onboarding. It is a record of how the business reached and later reviewed a
decision about a customer.
Law Number 001/2025 of 22 January 2025 sets
Rwanda's main preventive duties against money laundering, terrorist financing
and proliferation financing, which concerns funding connected to the spread of
weapons of mass destruction. Law Number 002/2025 supplies the current
definition of a reporting person. On 22 June 2026, Financial Intelligence
Centre Regulations Number 002/FIC/2026 replaced the 2023 anti-money laundering
regulation and addressed registration, risk assessment, customer due diligence,
monitoring and records. The initials "FIC" in the official instrument
number mean Financial Intelligence Centre. Financial Intelligence Centre
Regulations Number 001/FIC/2026 separately defined faults and sanctions.
Together, they require proof of implementation, not merely an approved policy.
Who Rwanda's customer due diligence
rules cover
Not every registered company is
automatically a reporting person. The Financial Intelligence Centre divides
reporting persons into financial institutions and designated non-financial
businesses and professions. The categories include banks, insurers, payment
service providers, regulated capital-market firms, real estate agents, dealers
in precious metals and stones, casinos, trust and company service providers,
auditors, accountants and tax advisers. Legal professionals are covered when
they assist clients outside legal proceedings with specified transactions,
including managing client assets, creating companies or buying and selling
businesses. Virtual asset service providers are also within the statutory
definition.
Coverage should be tested against the
activity performed, not the company's name. A written note should identify the
licence, service and legal provision relied upon, and be reviewed when products
or markets change. Under Article 4 of Financial Intelligence Centre Regulations
Number 002/FIC/2026, a new reporting person registers with the Centre within 30
days after incorporation and notifies changes to its registration information
within seven working days. A bank may request ownership information from another
business, but that request alone does not make the business a reporting person.
A customer file must explain a
decision
Article 7 of the same Regulations requires
basic customer due diligence before a reporting person enters a business
relationship. The measures include identifying and verifying the customer and
beneficial owner, then understanding the purpose and intended nature of the
relationship. The Financial Intelligence Centre explains a beneficial owner as
the natural person who ultimately owns or controls the customer, the person on
whose behalf a transaction is conducted, or the person exercising ultimate
effective control over a legal person or arrangement.
For a corporate customer, a certificate of
incorporation is only a starting point. The file should show how ownership was
traced to a natural person, how a representative's authority was checked, why
the relationship exists, which reliable source was consulted and who reviewed
the result. Where ownership passes through several entities, preserve that
chain rather than stopping at the first shareholder. A supervisor should be
able to reproduce the conclusion without having attended the onboarding.
The Regulations permit simplified measures
where lower risk is established, but reject them where there is suspicion. A
small transaction is not automatically low risk, and a familiar customer is not
automatically verified.
Risk changes the depth of inquiry
Article 5 of the Regulations requires a
documented institutional risk assessment at least annually and after a
significant change in the business, customer profile or services. A customer
may need fresh review after an ownership change, an unexplained payment pattern
or entry into a higher-risk market.
Where higher risk is identified, Article 9
calls for additional customer information, checks on the source of funds or
wealth, reasons for a transaction, senior-management approval and closer
monitoring. Article 10 treats a foreign politically exposed person as high
risk; domestic and international-organisation politically exposed persons are
risk assessed. Article 14 requires the background, source, purpose and findings
for complex or unusual transactions to be recorded in writing.
A risk score should not stand alone. Record
the facts behind it, the extra questions asked, the approval and the event that
will trigger another review. Otherwise, "high", "medium" or
"low" is only a label.
Management owns the control system
Customer due diligence cannot be left to
the employee who meets the customer. Article 6 of the Regulations requires a
managerial-level compliance officer with sufficient authority, resources and
unrestricted access to the board or its relevant committee. The Financial
Intelligence Centre must be notified of the appointment within three working
days and of a later change within 24 hours. Customer due diligence is therefore
a governance responsibility.
The evidence should form one connected
system. The coverage record should lead to the institutional risk assessment,
which should shape onboarding, ownership checks and customer classification.
Monitoring notes should connect unusual activity to escalation. Training
records, audit findings, board minutes and corrective actions should show
whether controls were tested and improved. Financial Intelligence Centre
Guideline Number 001/2025 addresses independent audits, while Guideline Number
002/2025 addresses transparency and beneficial ownership.
Article 43 requires transaction records to
be kept for at least ten years after completion. Customer due diligence
records, account files, correspondence and analysis must remain for at least
ten years after the relationship ends or an occasional transaction. Article 44
also requires an annual compliance report to the supervisor, copied to the
Financial Intelligence Centre.
The 2026 sanctions make weak evidence
costly
For reporting persons supervised by the
Financial Intelligence Centre, Regulations Number 001/FIC/2026 convert several
common gaps into express faults. Failure to identify and verify a customer and
beneficial owner carries a stated fine of between 5 million and 7 million
Rwandan francs in the basic bracket. Failure to update customer or
beneficial-owner information carries a fine of between 3 million and 5 million
Rwandan francs, while failure to keep records in the required manner and period
carries a fine of between 1 million and 3 million Rwandan francs. Higher ranges
apply in several provisions where the reporting person has branches in Rwanda
or abroad. Other reporting persons may also be subject to sector-specific
supervisory rules, so the applicable authority and sanction regime must be
checked.
These provisions expose a costly
misunderstanding. A business may know its customer in the everyday commercial
sense and still fail customer due diligence in the legal sense. Personal
familiarity does not replace verified identity, an ownership trail, a recorded
risk decision or continuing review.
The practical compliance rule
A useful customer due diligence system need
not be large. It must be current, proportionate and able to explain why the
business is covered, who owns or controls the customer, what the relationship
is for, which risks were identified, what changed and where the evidence is
kept.
Due diligence helps a company reject
unsuitable business earlier, answer supervisors faster and protect legitimate
relationships. The safest file is not the thickest. It is the one in which the
evidence, risk judgment and management response still make sense when an
independent reader returns to it years later.
Ronald Serwanga is a Ugandan legal
researcher and an advocate admitted to the Rwanda Bar. He writes for East
Africa Legal Insight.
This business legal article provides
general information for compliance planning. It does not decide whether an
enterprise is a reporting person or replace advice on licensing, suspicious
transaction reporting, sanctions screening or a supervisory investigation.
Sources Mentioned in This Training Article
The authorities referred to above are Law
Number 001/2025 and Law Number 002/2025 of 22 January 2025; Financial
Intelligence Centre Regulations Number 001/FIC/2026 and Number 002/FIC/2026 of
22 June 2026; Financial Intelligence Centre Guideline Number 001/2025 on
independent audits; Guideline Number 002/2025 on transparency and beneficial
ownership; and the Centre's official compliance materials.
Suggested Citation
Ronald Serwanga, "Anti-Money
Laundering Due Diligence: A Rwanda Guide" East Africa Legal Insight (8 August 2026).
Comments
Post a Comment