Rwanda -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
Rwanda, like many other jurisdictions, is in the process of adapting its anti-money laundering and combating the financing of terrorism (AML/CFT) framework to address the unique risks posed by virtual assets (cryptocurrencies) and Virtual Asset Service Providers (VASPs). While a comprehensive, standalone licensing and supervisory framework specifically for VASPs is still evolving, VASPs operating in or serving Rwandan customers are expected to comply with the existing general AML/CFT laws and regulations, applying the principles outlined by the Financial Action Task Force (FATF).
The Rwandan regulatory approach generally categorizes VASPs as "reporting persons" under its AML/CFT legislation, meaning they have the same obligations as traditional financial institutions regarding AML/CFT.
Here's a breakdown of the AML/KYC requirements:
1. AML/CFT Legislation for VASPs in Rwanda
The primary legislative instruments governing AML/CFT in Rwanda, which VASPs are expected to comply with, include:
- Law N° 060/2021 of 14/10/2021 on Preventing and Combating Money Laundering and Financing of Terrorism: This is the overarching AML/CFT law in Rwanda. It establishes the legal framework for identifying, reporting, and preventing money laundering and terrorist financing. It defines "reporting persons" broadly to include any person or entity that, by virtue of their activities, may be exposed to ML/TF risks, which can encompass VASPs even if not explicitly named.
- Ministerial Order N° 001/2022 of 28/01/2022 determining requirements for combating money laundering and financing of terrorism: This order specifies the general AML/CFT compliance requirements for reporting persons.
- Ministerial Order N° 002/2022 of 28/01/2022 determining procedures for combating money laundering and financing of terrorism: This order details the procedural aspects of AML/CFT compliance.
- National Bank of Rwanda (BNR) Circulars and Guidelines: The BNR, as the central bank and financial regulator, has issued warnings regarding the risks associated with cryptocurrencies, underscoring the need for AML/CFT compliance should they operate within Rwanda's financial ecosystem. While not specific VASP licensing, these reinforce the general AML/CFT obligations.
Rwanda aims to align with FATF Recommendation 15, which specifically addresses new technologies, including virtual assets and VASPs, requiring countries to regulate and supervise VASPs for AML/CFT purposes, or apply AML/CFT requirements to them.
2. Customer Due Diligence (CDD) Requirements
VASPs in Rwanda are required to implement robust CDD measures, consistent with those for traditional financial institutions, including:
- Identification and Verification of Customers:
- For Individuals: Obtaining and verifying name, address, date of birth, nationality, national identification number (e.g., Rwandan ID card, passport number), and any other unique identifiers. This typically involves documentary verification (e.g., valid ID document) and, where appropriate, non-documentary methods.
- For Legal Entities (Companies, Corporations, Trusts): Obtaining and verifying the entity's name, legal form, address, registration number, articles of incorporation, bylaws, and proof of existence. Identifying and verifying the identity of beneficial owners (individuals who ultimately own or control the entity, typically 25% ownership threshold or control through other means), as well as persons acting on behalf of the entity (e.g., directors, authorized signatories).
- Understanding the Purpose and Intended Nature of the Business Relationship: VASPs must understand why the customer wants to use their services and the anticipated level and type of activity.
- Ongoing Monitoring: Continuously monitoring the business relationship and transactions undertaken by customers to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes keeping customer information up-to-date.
- Risk-Based Approach: Applying CDD measures based on a risk assessment. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, complex or unusually large transactions) and simplified due diligence (SDD) for lower-risk customers (if permitted and justified). Due to the inherent risks of virtual assets, most VASP activities would generally require standard or enhanced CDD.
3. Suspicious Transaction Reporting (STR) Obligations
VASPs, as reporting persons, are obliged to report any suspicious transactions to the Financial Intelligence Centre (FIC).
- Reporting Threshold: There is no minimum monetary threshold for reporting suspicious transactions. Any transaction, regardless of amount, where there are reasonable grounds to suspect that it may be related to money laundering or terrorist financing, must be reported.
- Content of Report: STRs must contain comprehensive details about the customer, the transaction(s), and the reasons for the suspicion.
- Timing: Reports must be made promptly, typically within a specified number of business days (e.g., 2-5 working days) of forming the suspicion.
- No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been filed or that an investigation is underway.
4. Record-Keeping Obligations
VASPs must maintain comprehensive records to assist in investigations and prove compliance. These include:
- Customer Identification Records: All documents and information obtained during the CDD process (e.g., copies of identification documents, beneficial ownership information).
- Transaction Records: Records of all transactions undertaken, sufficient to permit reconstruction of individual transactions (e.g., sender and receiver details, amounts, type of virtual asset, transaction hash/ID, date and time).
- Business Relationship Records: Records pertaining to the business relationship, correspondence, and decisions made regarding the customer's risk profile.
- Suspicious Transaction Reports (STRs): Copies of all STRs filed and any internal documentation supporting the decision to file (or not to file).
- Duration: Records must generally be kept for a period of at least five (5) years after the end of the business relationship or the date of the transaction.
5. Authority Overseeing Compliance
The primary authority responsible for overseeing AML/CFT compliance for reporting persons, including VASPs, in Rwanda is:
- Financial Intelligence Centre (FIC) of Rwanda
- URL: https://fic.gov.rw/
- Role: The FIC is Rwanda's Financial Intelligence Unit (FIU). It is responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies. It also provides guidance and oversight on AML/CFT compliance for reporting persons.
While the FIC is the main AML/CFT supervisory body, the National Bank of Rwanda (BNR) also plays a significant role in setting financial sector policy and regulation. Although the BNR has not yet issued a specific licensing regime for VASPs, it has issued public warnings about the unregulated nature and risks of virtual assets. Should a formal VASP licensing and supervisory framework be established, the BNR would likely be the prudential regulator.
- National Bank of Rwanda (BNR)
- URL: https://www.bnr.rw/
- Role: Central bank and primary financial sector regulator. While not directly licensing VASPs currently, its guidance and pronouncements on virtual assets influence the regulatory environment.
In summary, any entity providing virtual asset services in Rwanda or to Rwandan residents should assume they fall under the existing AML/CFT framework and comply with the obligations concerning customer due diligence, suspicious transaction reporting, and record-keeping, under the oversight of the Financial Intelligence Centre (FIC) and in consideration of the National Bank of Rwanda's guidance. It is crucial for VASPs to establish robust internal AML/CFT programs, appoint a compliance officer, and provide staff training.
Source Data
Rwanda's operative anti-money-laundering statute is Law nº 001/2025 of 22/01/2025 on the prevention and punishment of money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction, which replaced Law nº 028/2023 of 19/05/2023, itself the repeal of Law nº 75/2019 of 29/01/2020; no Rwandan anti-money-laundering law is numbered 008/2020, and the Financial Intelligence Centre is governed by Law nº 045/2021 of 18/08/2021 as amended by Law nº 002/2025 of 22/01/2025.
Rwanda's anti-money-laundering obligations rest on Law nº 001/2025 of 22/01/2025, not on any law numbered 008/2020; Law nº 028/2023, which it replaced, contains no reference to virtual assets or virtual asset service providers, and preventive duties for virtual asset businesses were created only by Law nº 023/2026 of 25/05/2026 regulating virtual asset business.
Law nº 008/2021 of 16/02/2021 governs partnerships, not payment systems; Rwanda's payment-system statute is Law nº 061/2021 of 14/10/2021, which makes no reference to virtual assets, and virtual asset business is licensed by the Capital Market Authority of Rwanda under Law nº 023/2026 of 25/05/2026, the National Bank of Rwanda being confined to monetary and financial-stability oversight and cooperation rather than licensing.
Law n° 008/2021 of 16/02/2021 governs partnerships and was published in Official Gazette nº Special of 17/02/2021; Rwanda's payment system statute is Law n° 061/2021 of 14/10/2021, and neither law regulates virtual assets or carries anti-money-laundering obligations.
Rwanda's AML/CFT/CPF implementing regulations are made by the Director General of the Financial Intelligence Centre, and since 28 May 2026 the Capital Market Authority of Rwanda licenses and supervises virtual asset service providers under articles 5, 6 and 10 of Law nº 023/2026, the National Bank of Rwanda being confined to the cooperation functions in article 8.
BNR Website: National Bank of Rwanda
Rwanda's Financial Intelligence Centre, established by Law n° 74/2019 of 29/01/2020 and governed by Law n° 045/2021 of 18/08/2021 as amended by Law Nº 002/2025 of 22/01/2025, monitors and gives guidance to reporting persons and supervisory bodies on AML/CFT/CPF obligations, and issued both the AML/CFT/CPF Regulations of 16/02/2022 and the Targeted Financial Sanctions Regulations of 26/08/2021.
FIC Website: Rwanda Financial Intelligence Centre
Requirements for VASPs: Once formally regulated, VASPs in Rwanda (or those dealing with Rwandan entities) must:
Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).
Immediately freeze funds and other assets of designated individuals and entities.
Articles 6 and 7 of Rwanda's Regulations on Targeted Financial Sanctions of 26/08/2021 require a reporting person to report to the Financial Intelligence Centre without delay whether funds or other assets of a designated person were identified and to notify attempted dealings with frozen assets, but virtual asset service providers are not among Rwanda's reporting persons, their obligations arising instead under Law nº 023/2026.
Refrain from making funds or economic resources available, directly or indirectly, to sanctioned parties.
Legal Reference: UN Security Council Sanctions Committees (Lists and Resolutions): https://www.un.org/securitycouncil/sanctions/information
Dealing with U.S. persons (citizens, residents, entities, branches globally).
Utilizing U.S.-based blockchain analytics tools or other U.S. services.
Operating in whole or in part within the U.S.
Requirements for VASPs: Due to the risk of secondary sanctions and disruption of international financial services, prudent VASPs operating in Rwanda should:
Screen all customers, beneficial owners, and counterparties against the UN Security Council Consolidated List and other specific UN sanctions lists (e.g., for specific countries or individuals/entities designated for terrorism financing, proliferation, etc.).
Block transactions and freeze assets of designated individuals and entities.
Refrain from engaging in any activity that could be considered a violation or circumvention of OFAC sanctions.
Legal Reference: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC): https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information
Persons and entities incorporated or constituted under the law of an EU Member State.
Any person or entity in respect of business done in whole or in part within the European Union.
Requirements for VASPs: VASPs in Rwanda dealing with EU persons or entities, or otherwise having an EU nexus, should:
Screen against the EU Consolidated Financial Sanctions List.
Freeze funds and economic resources of designated persons and entities.
Prevent funds or economic resources from being made available to them.
Legal Reference: EU Sanctions Map and Consolidated List: https://www.sanctionsmap.eu/
Customer Due Diligence (CDD) and Know Your Customer (KYC): Perform thorough CDD on all customers, including identifying beneficial owners. This is the foundation for effective sanctions screening.
Onboarding: Screen new customers and their beneficial owners against all relevant sanctions lists (UN, OFAC, EU).
Ongoing Monitoring: Regularly re-screen existing customer bases and monitor for changes in sanctions lists.
Transaction Monitoring: Screen transaction counterparties and involved entities in real-time or near real-time, especially for high-value or high-risk transactions.
Tools and Technology: Utilize reputable sanctions screening software that can handle various lists and languages, and integrate with blockchain analytics tools for tracing funds.
Positive Match Resolution: Establish clear procedures for investigating potential matches, escalating to compliance officers, and taking appropriate action (e.g., blocking funds, filing reports).
Record-Keeping: Maintain detailed records of all screening activities, hits, investigations, and reports filed.
UN Sanctions: Countries subject to comprehensive UN sanctions (e.g., North Korea, Iran in certain contexts).
OFAC Sanctions: Countries subject to comprehensive U.S. embargos (e.g., Cuba, Iran, North Korea, Syria, regions of Ukraine, Venezuela).
EU Sanctions: Countries or regions subject to EU restrictive measures (e.g., specific regions in Ukraine, Belarus, Myanmar, Syria, North Korea, Iran, Venezuela).
Administrative Penalties: The competent supervisory authority (likely the BNR or FIC) can impose administrative fines, revoke licenses, or restrict operations.
Criminal Penalties: Individuals or entities found guilty of money laundering, financing of terrorism, or proliferation can face severe criminal penalties, including:
Imprisonment: For individuals, ranging from several years to life imprisonment, depending on the severity of the offense.
Financial Fines: Substantial fines for both individuals and legal entities.
Confiscation of Assets: Assets involved in or derived from illicit activities can be confiscated.
Rwanda's targeted financial sanctions obligations arise under Law nº 001/2025 of 22/01/2025 and the Financial Intelligence Centre's Regulations of 26/08/2021 on targeted financial sanctions, which bind 'reporting persons' and require screening against both the United Nations Security Council sanctions list and Rwanda's own domestic list of designated persons; there is no Rwandan 'Law No. 008/2020 on AML/CFT-P', and virtual asset service providers are not reporting persons.
Rwanda's domestic list of designated persons is a targeted-financial-sanctions list, not merely a law-enforcement list: under the Financial Intelligence Centre's Regulations of 26/08/2021 the domestic list is published on the website of the Ministry in charge of Justice and is disseminated by the Centre alongside the Security Council sanctions list, and reporting persons must apply freezing measures against both.
Rwanda has an in-force virtual-asset statute: Law nº 023/2026 of 25/05/2026 regulating virtual asset business, gazetted in Official Gazette nº Special of 28/05/2026, under which the Capital Market Authority licenses and supervises virtual asset service providers; the National Bank of Rwanda issued no crypto warning instrument, and its role under art. 8 is cooperation and directives on monetary and financial-stability matters.
Rwanda has moved past discussion of a virtual-asset framework: Parliament enacted Law nº 023/2026 of 25/05/2026 regulating virtual asset business, in force on gazetting on 28/05/2026, and the outstanding step is the making of implementing regulations rather than the drafting of a law.
The National Bank of Rwanda is Rwanda's central bank and prudential supervisor of financial institutions, but it is not the virtual-asset regulator: Law nº 023/2026 makes the Capital Market Authority the Regulatory Authority for virtual asset business, and art. 8 confines the National Bank to collaboration on monetary and financial-stability implications and to issuing directives on matters falling under its own purview.
URL: National Bank of Rwanda Official Website
The Financial Intelligence Centre was established by Law nº 74/2019 of 29/01/2020 and is governed by Law nº 045/2021 of 18/08/2021 as amended by Law nº 002/2025 of 22/01/2025, and it receives, analyses and disseminates financial intelligence; supervision of virtual asset service providers, however, is given to the Capital Market Authority by Law nº 023/2026, whose art. 6 requires the Authority to ensure VASP AML/CFT compliance and to assess virtual-asset risk.
The Financial Intelligence Centre operates its own public website at fic.gov.rw, which publishes its mandate, its establishment under Law nº 74/2019 of 29/01/2020 and its governing Law nº 045/2021 of 18/08/2021 as amended by Law nº 002/2025 of 22/01/2025.
The Ministry of Finance and Economic Planning holds fiscal and economic policy and the Financial Intelligence Centre operates under its supervision, but Rwanda's virtual-asset policy is now set by Law nº 023/2026 of 25/05/2026, which designates the Capital Market Authority as the Regulatory Authority for virtual asset business.
URL: Ministry of Finance and Economic Planning
No National Bank of Rwanda notice, circular or public warning on cryptocurrencies exists; the only traceable episode is Governor John Rwangombwa's remarks at the Monetary Policy and Financial Stability Statement presentation of 6 March 2018 reported in the press, and the legal-tender position now rests on art. 15 of Law nº 023/2026, which provides that virtual assets are not legal tender.
No National Bank of Rwanda cautionary publication dates from December 2017 or January 2018; the earliest traceable central-bank comment on cryptocurrency is Governor John Rwangombwa's statement of 6 March 2018 at the Monetary Policy and Financial Stability Statement presentation, which was reported by the press and issued no document.
Reference: While a direct, stable URL to the specific 2017/2018 circular can be difficult to find due to website updates, the BNR's official position is consistently maintained in its public communications and can be inferred from news archives and BNR publications. General BNR publications can be found on their website: BNR Publications
Rwanda's anti-money-laundering statute is Law nº 001/2025 of 22/01/2025 on the prevention and punishment of money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction, which replaced Law nº 028/2023 of 19/05/2023, itself replacing Law nº 75/2019 of 29/01/2020; ESAAMLG's evaluations of Rwanda cite no Law nº 19/2013 of 25/03/2013 and no Law nº 35/2019 of 24/07/2019.
Rwanda's general AML/CFT framework is Law nº 001/2025 of 22/01/2025, and ESAAMLG records that its only virtual-asset provision is art. 26(b), which requires competent authorities and supervisors to give international cooperation to foreign counterparts on money laundering, predicate offences and terrorist financing related to virtual assets and virtual asset service providers; preventive duties for VASPs come instead from art. 10(2)(g) of Law nº 023/2026, which makes effective AML/CFT/CPF controls a licensing condition.
Date: Original law from 2013, significant amendment in 2019.
Reference: This law is available in the Official Gazette of the Republic of Rwanda. Searching for "Official Gazette Rwanda Law N° 35/2019" would typically lead to its publication. A general source for Rwandan laws is the Ministry of Justice or Rwanda Law Reform Commission portal.
Virtual asset business in Rwanda is regulated by Law nº 023/2026 of 25/05/2026: art. 10 requires a licence from the Capital Market Authority, art. 15 bars natural persons from carrying on virtual asset business and provides that virtual assets are not legal tender and may not be used as a direct means of payment unless authorised by the Central Bank, and mining facilities, crypto ATMs and mixing or tumbling services require approval.
The National Bank of Rwanda has published no consumer warning on virtual assets; investor-protection, market-conduct and asset-protection duties for virtual asset business now sit in arts. 25 to 27 of Law nº 023/2026 and are administered by the Capital Market Authority.
Law nº 023/2026 of 25/05/2026 establishes a licensing regime for virtual asset service providers administered by the Capital Market Authority, with licensing at art. 10, suspension and revocation at art. 11, a regulatory sandbox at art. 13 and the list of licensable services at art. 14; no provider has been licensed because the implementing regulations have not been made.
Virtual asset service providers are not reporting persons under Rwandan AML law: Law nº 001/2025 of 22/01/2025 imposes no preventive obligations on them, and their AML/CFT/CPF duty exists only as a licensing condition under art. 10(2)(g) of Law nº 023/2026, supervised by the Capital Market Authority, so virtual-asset exposure reaches the Financial Intelligence Centre today only through banks and other reporting persons.
No Rwandan Law nº 003/2020 of 20/02/2020 on money laundering exists; the AML statute in force on that date was Law nº 75/2019 of 29/01/2020, and the operative statute today is Law nº 001/2025 of 22/01/2025 on the prevention and punishment of money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction.
Rwanda imposes no virtual-asset travel-rule obligation and no de minimis threshold for virtual asset transfers: ESAAMLG records art. 26(b) of Law nº 001/2025 as that law's only virtual-asset provision and it concerns international cooperation, Recommendation 15 remains partially compliant, and virtual asset service providers acquire AML/CFT duties only as a licensing condition under art. 10(2)(g) of Law nº 023/2026, which the unmade implementing regulations leave inoperable.
Rwanda's Financial Intelligence Centre imposes administrative sanctions on reporting persons under Regulations nº 001/FIC/2026 of 22/06/2026, Official Gazette nº 25 Bis of 22/06/2026, whose Article 30 provides written warning, prohibition of activities, suspension, asset restrictions, restrictions on compensation and publication of the violation, and whose Article 31 provides warning, suspension or dismissal of board members and senior managers. Administrative sanctions on virtual asset service providers instead fall to the Capital Market Authority of Rwanda under Article 32 of Law nº 023/2026 of 25/05/2026, and Article 8 of that Law gives the National Bank of Rwanda a cooperation role together with power to issue directives on matters falling under its own purview, not a virtual-asset licensing or sanctioning power.
Rwanda's published administrative fine schedule for anti-money-laundering breaches is Regulations nº 001/FIC/2026 of 22/06/2026, Official Gazette nº 25 Bis of 22/06/2026, and its amounts run from FRW 500,000 per day under Article 4 to a ceiling of FRW 20,000,000 under Article 19(3) for a reporting person with foreign branches that fails to report a designated-person match. Typical bands are FRW 8,000,000 to 10,000,000 for late registration under Article 3, FRW 2,000,000 to 4,000,000 per report for failure to submit reports under Article 6, and FRW 1,000,000 to 3,000,000 for failure to keep records under Article 26. No fine in that schedule reaches hundreds of millions of Rwandan francs.
17 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by SearXNG+LLM .
Primary Sources
fic.gov.rw. (n.d.). fic.gov.rw. Retrieved April 22, 2026, from https://fic.gov.rw/
Secondary Sources
bnr.rw. (n.d.). bnr.rw. Retrieved April 22, 2026, from https://www.bnr.rw/
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →