Grade B AI-Researched

Bosnia and Herzegovina -- AML/CFT Compliance Regulatory Overview

Published: 2026-08-17 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (1)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

Bosnia and Herzegovina (BiH) has significantly updated its Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) framework to include virtual assets and Virtual Asset Service Providers (VASPs), aligning with international standards set by the Financial Action Task Force (FATF) and the European Union's 5th Anti-Money Laundering Directive (5AMLD).

AML/CFT Legislation

The primary legislation governing AML/CFT in Bosnia and Herzegovina is:

  1. Zakon o sprečavanju pranja novca i finansiranja terorističkih aktivnosti (Law on Prevention of Money Laundering and Financing of Terrorist Activities)Official Gazette of BiH, No. 104/08, 104/13, 91/17, 102/19 and 13/20.

    • Crucial Amendment: The latest significant amendments, particularly those published in Official Gazette of BiH, No. 13/20 (Law on Amendments to the Law on Prevention of Money Laundering and Financing of Terrorism), explicitly brought Virtual Asset Service Providers (VASPs) under the scope of obliged entities. This amendment defined virtual assets and established obligations for entities dealing with them.

Definition of Virtual Asset Service Providers (VASPs)

Under the amended AML Law, VASPs are classified as "obliged entities" and are subject to the same AML/CFT requirements as traditional financial institutions. A VASP is generally defined in line with FATF recommendations, encompassing entities that conduct one or more of the following activities or operations for or on behalf of another natural or legal person:

  • Exchange between virtual assets and fiat currencies.
  • Exchange between one or more forms of virtual assets.
  • Transfer of virtual assets.
  • Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
  • Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.

Customer Due Diligence (CDD) Requirements

VASPs in BiH must implement a risk-based approach to CDD, meaning the extent of due diligence should be proportionate to the assessed money laundering and terrorist financing risks. Key CDD requirements include:

  1. Identification and Verification of the Customer:

    • Identifying the customer (and any person acting on behalf of the customer) and verifying their identity using reliable, independent source documents, data, or information.
    • For natural persons: full name, address, date and place of birth, unique identification number (e.g., ID card, passport number).
    • For legal entities: name, legal form, address of registered office, registration number, names of directors/authorized persons, and proof of incorporation.
  2. Identification of the Beneficial Owner:

    • Identifying the beneficial owner(s) and taking reasonable measures to verify their identity.
    • Understanding the ownership and control structure of the customer (for legal entities or arrangements).
  3. Purpose and Intended Nature of the Business Relationship:

    • Understanding the purpose and intended nature of the business relationship or occasional transaction.
  4. Ongoing Monitoring:

    • Conducting ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure that transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
    • Keeping documents, data, or information up-to-date.

Types of CDD:

  • Standard CDD: Applied to regular customer relationships.
  • Simplified CDD (SCDD): Applicable only in cases of demonstrably lower risk, specified by law or regulation.
  • Enhanced CDD (EDD): Required for higher-risk situations, including:
    • Transactions or business relationships with Politically Exposed Persons (PEPs).
    • Cross-border correspondent relationships involving virtual assets.
    • Transactions or relationships involving high-risk geographic areas.
    • Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.
    • Situations where the customer is not physically present for identification purposes.

Suspicious Transaction Reporting (STR)

VASPs, as obliged entities, have a legal obligation to report suspicious transactions to the Financial Intelligence Department of the State Investigation and Protection Agency (SIPA FID).

  • Obligation to Report: If a VASP knows, suspects, or has reasonable grounds to suspect that funds or other assets are derived from criminal activity, or are related to terrorist financing, they must immediately report such suspicions.
  • No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that a suspicious transaction report is being, or has been, submitted, or that an investigation is being conducted.

Record-Keeping Obligations

VASPs must retain specific records for a prescribed period to enable the reconstruction of transactions and provide evidence for investigations.

  • Type of Records:
    • Records of identity documents obtained during CDD.
    • Account files, business correspondence, and transaction records.
    • Records of analysis performed, supporting the determination of whether a transaction is suspicious.
  • Retention Period: All relevant records must be retained for a period of five (5) years after the termination of a business relationship or after the date of an occasional transaction.

Overseeing Authority for Compliance

The primary authority responsible for overseeing AML/CFT compliance for VASPs and other obliged entities in Bosnia and Herzegovina is:

  • State Investigation and Protection Agency (SIPA) - Financial Intelligence Department (FID)

    SIPA's Financial Intelligence Department (FID) acts as the Financial Intelligence Unit (FIU) for Bosnia and Herzegovina. It is responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies for further investigation. It also provides guidance and oversight to obliged entities regarding their AML/CFT obligations.

  • URL: You can find more information on SIPA's official website:

    • SIPA Official Website: https://sipa.gov.ba/en/
    • While there isn't always a direct sub-page specifically for "Financial Intelligence Department" with a unique URL, its functions are integral to SIPA's overall mission.

In addition to SIPA FID, sector-specific regulators (like banking agencies for traditional financial institutions) might have a role in overseeing AML compliance within their respective regulated sectors, but for VASPs, SIPA FID is the central body for STRs and overall AML/CFT supervision.

It is important for VASPs operating or intending to operate in Bosnia and Herzegovina to seek specific legal advice to ensure full compliance with these evolving requirements.

Source Data

80%

Zakon o sprečavanju pranja novca i finansiranja terorističkih aktivnosti (Law on Prevention of Money Laundering and Financing of Terrorist Activities) – Official Gazette of BiH, No. 13/2024.

80%

Crucial Amendment: The latest significant amendments, particularly those published in Official Gazette of BiH, No. 13/20 (Law on Amendments to the Law on Prevention of Money Laundering and Financing of Terrorism), explicitly brought Virtual Asset Service Providers (VASPs) under the scope of obliged entities. This amendment defined virtual assets and established obligations for entities dealing with them.

80%

Exchange between virtual assets and fiat currencies.

80%

Exchange between one or more forms of virtual assets.

80%

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

80%

Participation in and provision of financial services related to an issuer's offer and/or sale of a virtual asset.

80%

Identifying the customer (and any person acting on behalf of the customer) and verifying their identity using reliable, independent source documents, data, or information.

80%

For natural persons: full name, address, date and place of birth, unique identification number (e.g., ID card, passport number).

80%

For legal entities: name, legal form, address of registered office, registration number, names of directors/authorized persons, and proof of incorporation.

80%

Identifying the beneficial owner(s) and taking reasonable measures to verify their identity.

80%

Understanding the ownership and control structure of the customer (for legal entities or arrangements).

80%

Understanding the purpose and intended nature of the business relationship or occasional transaction.

80%

Conducting ongoing monitoring of the business relationship and transactions undertaken throughout the course of the relationship to ensure that transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

80%

Keeping documents, data, or information up-to-date.

80%

Standard CDD: Applied to regular customer relationships.

80%

Simplified CDD (SCDD): Applicable only in cases of demonstrably lower risk, specified by law or regulation.

80%

Enhanced CDD (EDD) is required only for specific high-risk activities in Bosnia & Herzegovina, not universally for all higher‑risk situations.

80%

Transactions or business relationships with Politically Exposed Persons (PEPs).

80%

Cross-border correspondent relationships involving virtual assets.

80%

Transactions or relationships involving high-risk geographic areas.

80%

Complex, unusually large transactions, and all unusual patterns of transactions that have no apparent economic or lawful purpose.

80%

Situations where the customer is not physically present for identification purposes.

80%

Obligation to Report: If a VASP knows, suspects, or has reasonable grounds to suspect that funds or other assets are derived from criminal activity, or are related to terrorist financing, they must immediately report such suspicions.

80%

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or to third parties that a suspicious transaction report is being, or has been, submitted, or that an investigation is being conducted.

80%

Records of identity documents obtained during CDD.

80%

Account files, business correspondence, and transaction records.

80%

Records of analysis performed, supporting the determination of whether a transaction is suspicious.

80%

Retention Period: All relevant records must be retained for a period of five (5) years after the termination of a business relationship or after the date of an occasional transaction.

80%

State Investigation and Protection Agency (SIPA) - Financial Intelligence Department (FID)

80%

While there isn't always a direct sub-page specifically for "Financial Intelligence Department" with a unique URL, its functions are integral to SIPA's overall mission.

3 fact(s) collected but awaiting source verification. View in explorer →

References

This article was generated by SearXNG+LLM .

Primary Sources

sipa.gov.ba. (n.d.). sipa.gov.ba. Retrieved April 22, 2026, from https://sipa.gov.ba/en/

Edit History

2026-04-22 — auto-publish-pipeline: reviewed — Auto-promoted to review: grade C
2026-08-17 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →