Grade B AI-Researched

Sudan -- AML/CFT Compliance Regulatory Overview

Published: 2026-08-17 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (1)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

It's crucial to understand that Sudan currently maintains a highly restrictive stance on cryptocurrencies and virtual assets. The Central Bank of Sudan (CBOS) has issued directives and warnings that effectively prohibit the use, trading, or dealing in cryptocurrencies within the regulated financial system. This means that, as of now, there are no specific AML/KYC requirements for legally operating cryptocurrency/virtual asset service providers (VASPs) in Sudan because such entities are not permitted to operate.

However, Sudan does have a general AML/CFT framework for its traditional financial sector, which would be the basis for any future regulation if cryptocurrencies were legalized.

Here's a breakdown of the situation:

1. Current Status of Cryptocurrencies in Sudan

  • De Facto Ban: The Central Bank of Sudan (CBOS) has repeatedly warned against the use of cryptocurrencies, citing risks such as money laundering, terrorism financing, price volatility, and consumer protection issues. These warnings have effectively created a ban on their use within the formal financial system.
  • No Licensed VASPs: Due to this stance, there are no licensed or regulated Virtual Asset Service Providers (VASPs) operating legally in Sudan. Any entity facilitating crypto transactions would be doing so outside the formal regulatory framework and potentially illegally.

2. Sudan's General AML/CFT Framework (Applicable to Traditional Finance)

While not directly for VASPs, this framework would inform any future crypto regulation:

A. AML/CFT Legislation

  • The Anti-Money Laundering and Combating Terrorism Financing Law of 2014 (Law No. 4 of 2014): This is the primary legislation governing AML/CFT in Sudan. It establishes the legal framework for identifying, investigating, and prosecuting money laundering and terrorism financing offenses.
  • Central Bank of Sudan Regulations and Directives: The CBOS issues various circulars, regulations, and guidelines that supplement the AML/CFT Law, providing detailed requirements for financial institutions.

B. Customer Due Diligence (CDD) Requirements (General Principles)

For any regulated financial activity, the following CDD principles are generally applied:

  • Identification and Verification:
    • Individuals: Verifying the identity of customers using reliable, independent source documents, data, or information (e.g., national ID, passport, driving license).
    • Legal Entities/Arrangements: Verifying the legal existence and structure of the entity, its legal name, registration details, address, and identifying the natural persons who are beneficial owners.
  • Beneficial Ownership Identification: Taking reasonable measures to understand the ownership and control structure of legal entities and identify the natural persons who ultimately own or control the customer.
  • Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.
  • Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of the relationship to ensure they are consistent with the institution's knowledge of the customer, their business, and risk profile, including where necessary, the source of funds.
  • Enhanced Due Diligence (EDD): Applied in higher-risk situations, such as relationships with Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or complex transactions. This would likely be a default for crypto if ever legalized, given its inherent risks.

C. Suspicious Transaction Reporting (STR)

  • Obligation to Report: Financial institutions (and potentially other designated non-financial businesses and professions - DNFBPs, if applicable) are obligated to report suspicious transactions to the Financial Information Unit (FIU) of Sudan.
  • Indicators: Reports are based on suspicion that funds are derived from illegal activities, intended for terrorism financing, or that the transaction itself is unusual or lacks a clear economic rationale.

D. Record-Keeping Obligations

  • Financial institutions are typically required to retain all records of customer identification data, account files, business correspondence, and transaction records for a specified period (e.g., at least five years) following the termination of the business relationship or the execution of the transaction. This includes:
    • Identity documents and verification records.
    • Transaction data sufficient to reconstruct individual transactions.
    • Records of STRs and their outcomes.

E. Authority Overseeing Compliance

  • Central Bank of Sudan (CBOS):
    • Role: The primary regulatory and supervisory authority for financial institutions in Sudan. It is responsible for issuing regulations, conducting oversight, and enforcing compliance with AML/CFT requirements in the banking sector.
    • URL: https://cbos.gov.sd/
  • Financial Information Unit (FIU) of Sudan:
    • Role: The central national agency responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs) and other financial information to competent authorities for investigation and prosecution of money laundering and terrorism financing offenses. The FIU operates under the umbrella of the Central Bank or Ministry of Finance, but functions with operational independence for its core tasks.
    • URL: A dedicated, standalone English URL for the FIU of Sudan is not consistently available online. Its functions are often described in reports from the Central Bank or international bodies.

Summary and Outlook

Currently, due to the effective ban on cryptocurrencies by the Central Bank of Sudan, there are no specific AML/KYC requirements for VASPs because such services are not permitted. Any engagement with virtual assets carries significant legal and regulatory risks in Sudan.

If Sudan were to legalize and regulate cryptocurrencies in the future, it would likely adopt an AML/CFT framework based on the recommendations of the Financial Action Task Force (FATF), applying its existing general AML/CFT Law of 2014, and specific regulations issued by the CBOS. These regulations would impose robust CDD, STR, and record-keeping obligations mirroring global standards for VASPs, treating them similarly to traditional financial institutions.

Disclaimer: Regulatory landscapes for cryptocurrencies are dynamic and subject to rapid change. This information is for general guidance and should not be considered legal advice. Parties interested in engaging with virtual assets in Sudan should seek independent legal counsel.

Source Data

80%

De Facto Ban: The Central Bank of Sudan (CBOS) has repeatedly warned against the use of cryptocurrencies, citing risks such as money laundering, terrorism financing, price volatility, and consumer protection issues. These warnings have effectively created a ban on their use within the formal financial system.

80%

No Licensed VASPs: Due to this stance, there are no licensed or regulated Virtual Asset Service Providers (VASPs) operating legally in Sudan. Any entity facilitating crypto transactions would be doing so outside the formal regulatory framework and potentially illegally.

80%

The Anti-Money Laundering and Combating Terrorism Financing Law of 2014 (Law No. 4 of 2014): This is the primary legislation governing AML/CFT in Sudan. It establishes the legal framework for identifying, investigating, and prosecuting money laundering and terrorism financing offenses.

80%

Central Bank of Sudan Regulations and Directives: The CBOS issues various circulars, regulations, and guidelines that supplement the AML/CFT Law, providing detailed requirements for financial institutions.

80%

Individuals: Verifying the identity of customers using reliable, independent source documents, data, or information (e.g., national ID, passport, driving license).

80%

Legal Entities/Arrangements: Verifying the legal existence and structure of the entity, its legal name, registration details, address, and identifying the natural persons who are beneficial owners.

80%

Beneficial Ownership Identification: Taking reasonable measures to understand the ownership and control structure of legal entities and identify the natural persons who ultimately own or control the customer.

80%

Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.

80%

Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutinizing transactions undertaken throughout the course of the relationship to ensure they are consistent with the institution's knowledge of the customer, their business, and risk profile, including where necessary, the source of funds.

80%

Enhanced Due Diligence (EDD): Applied in higher-risk situations, such as relationships with Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or complex transactions. This would likely be a default for crypto if ever legalized, given its inherent risks.

80%

Obligation to Report: Financial institutions (and potentially other designated non-financial businesses and professions - DNFBPs, if applicable) are obligated to report suspicious transactions to the Financial Information Unit (FIU) of Sudan.

80%

Indicators: Reports are based on suspicion that funds are derived from illegal activities, intended for terrorism financing, or that the transaction itself is unusual or lacks a clear economic rationale.

80%

Financial institutions are typically required to retain all records of customer identification data, account files, business correspondence, and transaction records for a specified period (e.g., at least five years) following the termination of the business relationship or the execution of the transaction. This includes:

80%

Identity documents and verification records.

80%

Transaction data sufficient to reconstruct individual transactions.

80%

Records of STRs and their outcomes.

80%

Role: The primary regulatory and supervisory authority for financial institutions in Sudan. It is responsible for issuing regulations, conducting oversight, and enforcing compliance with AML/CFT requirements in the banking sector.

80%

Role: The central national agency responsible for receiving, analyzing, and disseminating suspicious transaction reports (STRs) and other financial information to competent authorities for investigation and prosecution of money laundering and terrorism financing offenses. The FIU operates under the umbrella of the Central Bank or Ministry of Finance, but functions with operational independence for its core tasks.

80%

URL: A dedicated, standalone English URL for the FIU of Sudan is not consistently available online. Its functions are often described in reports from the Central Bank or international bodies.

References

This article was generated by SearXNG+LLM .

Primary Sources

cbos.gov.sd. (n.d.). cbos.gov.sd. Retrieved April 22, 2026, from https://cbos.gov.sd/

Edit History

2026-04-22 — auto-publish-pipeline: reviewed — Auto-promoted to review: grade C
2026-08-17 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →