Anti-Money Laundering Due Diligence: A Rwanda Guide

Rwanda's rules require defined reporting persons to identify customers, understand who ultimately controls them, respond proportionately to risk and preserve evidence that management can defend.

Contents

Who Rwanda's customer due diligence rules cover

A customer file must explain a decision

Risk changes the depth of inquiry

Management owns the control system

The 2026 sanctions make weak evidence costly

The practical compliance rule


Anti-money laundering refers to the laws and business controls used to stop criminals from disguising unlawful funds as legitimate money. Customer due diligence is one of those controls. It requires certain regulated businesses and professionals, legally called reporting persons, to establish who a customer is, who ultimately owns or controls the customer, why the relationship exists and whether the customer's activity is consistent with the known risk.

An identity document can confirm a name. It cannot, by itself, explain why a transaction makes commercial sense, who controls a corporate customer or why a business accepted a particular risk. Customer due diligence is therefore not simply the collection of documents at onboarding. It is a record of how the business reached and later reviewed a decision about a customer.

Law Number 001/2025 of 22 January 2025 sets Rwanda's main preventive duties against money laundering, terrorist financing and proliferation financing, which concerns funding connected to the spread of weapons of mass destruction. Law Number 002/2025 supplies the current definition of a reporting person. On 22 June 2026, Financial Intelligence Centre Regulations Number 002/FIC/2026 replaced the 2023 anti-money laundering regulation and addressed registration, risk assessment, customer due diligence, monitoring and records. The initials "FIC" in the official instrument number mean Financial Intelligence Centre. Financial Intelligence Centre Regulations Number 001/FIC/2026 separately defined faults and sanctions. Together, they require proof of implementation, not merely an approved policy.

Who Rwanda's customer due diligence rules cover

Not every registered company is automatically a reporting person. The Financial Intelligence Centre divides reporting persons into financial institutions and designated non-financial businesses and professions. The categories include banks, insurers, payment service providers, regulated capital-market firms, real estate agents, dealers in precious metals and stones, casinos, trust and company service providers, auditors, accountants and tax advisers. Legal professionals are covered when they assist clients outside legal proceedings with specified transactions, including managing client assets, creating companies or buying and selling businesses. Virtual asset service providers are also within the statutory definition.

Coverage should be tested against the activity performed, not the company's name. A written note should identify the licence, service and legal provision relied upon, and be reviewed when products or markets change. Under Article 4 of Financial Intelligence Centre Regulations Number 002/FIC/2026, a new reporting person registers with the Centre within 30 days after incorporation and notifies changes to its registration information within seven working days. A bank may request ownership information from another business, but that request alone does not make the business a reporting person.

A customer file must explain a decision

Article 7 of the same Regulations requires basic customer due diligence before a reporting person enters a business relationship. The measures include identifying and verifying the customer and beneficial owner, then understanding the purpose and intended nature of the relationship. The Financial Intelligence Centre explains a beneficial owner as the natural person who ultimately owns or controls the customer, the person on whose behalf a transaction is conducted, or the person exercising ultimate effective control over a legal person or arrangement.

For a corporate customer, a certificate of incorporation is only a starting point. The file should show how ownership was traced to a natural person, how a representative's authority was checked, why the relationship exists, which reliable source was consulted and who reviewed the result. Where ownership passes through several entities, preserve that chain rather than stopping at the first shareholder. A supervisor should be able to reproduce the conclusion without having attended the onboarding.

The Regulations permit simplified measures where lower risk is established, but reject them where there is suspicion. A small transaction is not automatically low risk, and a familiar customer is not automatically verified.

Risk changes the depth of inquiry

Article 5 of the Regulations requires a documented institutional risk assessment at least annually and after a significant change in the business, customer profile or services. A customer may need fresh review after an ownership change, an unexplained payment pattern or entry into a higher-risk market.

Where higher risk is identified, Article 9 calls for additional customer information, checks on the source of funds or wealth, reasons for a transaction, senior-management approval and closer monitoring. Article 10 treats a foreign politically exposed person as high risk; domestic and international-organisation politically exposed persons are risk assessed. Article 14 requires the background, source, purpose and findings for complex or unusual transactions to be recorded in writing.

A risk score should not stand alone. Record the facts behind it, the extra questions asked, the approval and the event that will trigger another review. Otherwise, "high", "medium" or "low" is only a label.

Management owns the control system

Customer due diligence cannot be left to the employee who meets the customer. Article 6 of the Regulations requires a managerial-level compliance officer with sufficient authority, resources and unrestricted access to the board or its relevant committee. The Financial Intelligence Centre must be notified of the appointment within three working days and of a later change within 24 hours. Customer due diligence is therefore a governance responsibility.

The evidence should form one connected system. The coverage record should lead to the institutional risk assessment, which should shape onboarding, ownership checks and customer classification. Monitoring notes should connect unusual activity to escalation. Training records, audit findings, board minutes and corrective actions should show whether controls were tested and improved. Financial Intelligence Centre Guideline Number 001/2025 addresses independent audits, while Guideline Number 002/2025 addresses transparency and beneficial ownership.

Article 43 requires transaction records to be kept for at least ten years after completion. Customer due diligence records, account files, correspondence and analysis must remain for at least ten years after the relationship ends or an occasional transaction. Article 44 also requires an annual compliance report to the supervisor, copied to the Financial Intelligence Centre.

The 2026 sanctions make weak evidence costly

For reporting persons supervised by the Financial Intelligence Centre, Regulations Number 001/FIC/2026 convert several common gaps into express faults. Failure to identify and verify a customer and beneficial owner carries a stated fine of between 5 million and 7 million Rwandan francs in the basic bracket. Failure to update customer or beneficial-owner information carries a fine of between 3 million and 5 million Rwandan francs, while failure to keep records in the required manner and period carries a fine of between 1 million and 3 million Rwandan francs. Higher ranges apply in several provisions where the reporting person has branches in Rwanda or abroad. Other reporting persons may also be subject to sector-specific supervisory rules, so the applicable authority and sanction regime must be checked.

These provisions expose a costly misunderstanding. A business may know its customer in the everyday commercial sense and still fail customer due diligence in the legal sense. Personal familiarity does not replace verified identity, an ownership trail, a recorded risk decision or continuing review.

The practical compliance rule

A useful customer due diligence system need not be large. It must be current, proportionate and able to explain why the business is covered, who owns or controls the customer, what the relationship is for, which risks were identified, what changed and where the evidence is kept.

Due diligence helps a company reject unsuitable business earlier, answer supervisors faster and protect legitimate relationships. The safest file is not the thickest. It is the one in which the evidence, risk judgment and management response still make sense when an independent reader returns to it years later.

Ronald Serwanga is a Ugandan legal researcher and an advocate admitted to the Rwanda Bar. He writes for East Africa Legal Insight.

This business legal article provides general information for compliance planning. It does not decide whether an enterprise is a reporting person or replace advice on licensing, suspicious transaction reporting, sanctions screening or a supervisory investigation.

Sources Mentioned in This Training Article

The authorities referred to above are Law Number 001/2025 and Law Number 002/2025 of 22 January 2025; Financial Intelligence Centre Regulations Number 001/FIC/2026 and Number 002/FIC/2026 of 22 June 2026; Financial Intelligence Centre Guideline Number 001/2025 on independent audits; Guideline Number 002/2025 on transparency and beneficial ownership; and the Centre's official compliance materials.

Suggested Citation

Ronald Serwanga, "Anti-Money Laundering Due Diligence: A Rwanda Guide" East Africa Legal Insight (8 August 2026).


Comments