Grade B AI-Researched

Uganda -- AML/CFT Compliance Regulatory Overview

Published: 2026-04-22 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (2)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

Uganda, like many jurisdictions, is still in the process of developing comprehensive and specific regulatory frameworks for cryptocurrencies and Virtual Asset Service Providers (VASPs). While there isn't standalone legislation specifically for crypto AML/KYC, existing anti-money laundering and combating the financing of terrorism (AML/CFT) laws and regulations are generally interpreted to apply to VASPs, largely driven by international standards set by the Financial Action Task Force (FATF).

The FATF Recommendation 15 (New Technologies) explicitly requires countries to regulate VASPs for AML/CFT purposes, including licensing or registration, and subjecting them to the same AML/CFT obligations as traditional financial institutions. Uganda, as a member of the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), an FATF-style regional body, is expected to implement these recommendations.

Here's a breakdown based on current understanding and the application of existing laws:


AML/CFT Legislation Applicable to VASPs in Uganda

  1. The Anti-Money Laundering Act, 2013 (as amended): This is the primary AML legislation in Uganda. It defines money laundering, establishes the Financial Intelligence Authority (FIA), and outlines obligations for "reporting persons." While it doesn't explicitly mention "cryptocurrency" or "VASP," the broad definitions of "financial institution," "transaction," and "funds" can be interpreted to encompass activities involving virtual assets.
  2. The Anti-Money Laundering Regulations, 2015: These regulations provide more specific details on the implementation of the Act, including customer due diligence, record-keeping, and suspicious transaction reporting.
  3. The Financial Intelligence Authority Act, 2013: This Act establishes the FIA as the central national agency responsible for receiving, analyzing, and disseminating financial intelligence related to money laundering, terrorist financing, and proliferation financing.
  4. Bank of Uganda Act, Cap 51: While the Bank of Uganda (BOU) has primarily issued warnings about the risks associated with cryptocurrencies due to their unregulated nature, any future licensing or regulation of VASPs that touch upon payment systems or financial services would likely involve the BOU.

Note: The Bank of Uganda has generally maintained a cautious stance, warning the public against the risks of dealing in unregulated virtual currencies. As of now, there is no specific licensing regime for pure crypto VASPs in Uganda. However, entities engaging in activities that fall under existing financial services (e.g., remittances using crypto) might be subject to existing regulations governing those services.


AML/KYC Requirements for VASPs (Interpreted)

Based on the above legislation and FATF standards, VASPs are expected to adhere to the following:

1. Customer Due Diligence (CDD) Requirements

VASPs would be treated as "reporting persons" and expected to implement robust CDD measures, which include:

  • Identification and Verification:
    • Individual Customers: Obtain and verify the customer's full name, permanent address, date of birth, national identification number (e.g., National ID, passport), and other relevant identification documents.
    • Legal Entities (Companies, etc.): Obtain and verify the company's registered name, legal form, proof of incorporation, physical address, business registration number, tax identification number, and details of directors, beneficial owners, and authorized signatories.
  • Beneficial Ownership: Identify and verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.
  • Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or the transaction.
  • Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds where necessary.
  • Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers, transactions, or business relationships. This includes:
    • Politically Exposed Persons (PEPs)
    • Customers from high-risk jurisdictions (identified by FATF or local authorities)
    • Transactions involving large amounts or complex structures
    • Transactions with no apparent economic or lawful purpose.
  • Simplified Due Diligence (SDD): May be applied in limited circumstances where the risk of money laundering or terrorist financing is lower, as permitted by the regulations.

2. Suspicious Transaction Reporting (STR)

VASPs, as reporting persons, are obligated to:

  • Report Suspicious Transactions: Report any transaction (attempted or completed) where there is a reasonable suspicion that the funds involved are proceeds of crime, or are linked to money laundering, terrorist financing, or proliferation financing.
  • Report to the FIA: Such reports must be made to the Financial Intelligence Authority (FIA) promptly, and generally within 48 hours of forming the suspicion.
  • No Tipping-Off: Not disclose to the customer or any third party that a suspicious transaction report has been made or that a money laundering investigation is being conducted.

3. Record-Keeping Obligations

VASPs must maintain comprehensive records to assist in investigations and demonstrate compliance:

  • Customer Identification Records: All records obtained during CDD processes (identification documents, verification records, beneficial ownership information).
  • Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, type of transaction, and parties involved. For virtual assets, this would include wallet addresses, transaction hashes, and amounts.
  • Business Correspondence: Records of all relevant business correspondence with customers.
  • Retention Period: Records must be retained for a minimum period of five (5) years after the business relationship has ended or after the date of an occasional transaction.

Authority Overseeing Compliance

The primary authority responsible for overseeing AML/CFT compliance in Uganda, including for reporting persons like VASPs, is:

While the Bank of Uganda (BOU) has a broader mandate over the financial sector, its direct regulatory oversight of pure crypto VASPs in terms of AML/KYC is currently indirect, mainly through its warnings and policy guidance. Should specific regulations for crypto come into force, the BOU would likely play a significant role in licensing and supervision, particularly for entities offering financial services involving virtual assets.

Bank of Uganda Website: https://www.bou.or.ug/


Important Note: The regulatory landscape for virtual assets is rapidly evolving globally and in Uganda. VASPs operating or intending to operate in Uganda should seek independent legal counsel to ensure full compliance with the most current applicable laws and regulations, as interpretations and specific requirements can change.

Source Data

80%

Uganda's Anti-Money Laundering Act, 2013 (Act 12 of 2013), consolidated as Chapter 118, imposes its obligations on accountable persons, defined as any person listed in its Second Schedule, and section 18 establishes the Financial Intelligence Authority; the Act reaches virtual asset service providers by express designation rather than by interpretation, because the Anti-Money Laundering (Amendment of Second Schedule) Instrument, 2020 (Statutory Instrument 136 of 2020) added virtual asset service providers to that Schedule with effect from 27 November 2020, and they stand as paragraph 16 of Schedule 2 in the Financial Intelligence Authority's signed registration guidelines of January 2024, which require every accountable person to register with the Authority.

80%

Uganda's Anti-Money Laundering Regulations, 2015 are Statutory Instrument 75 of 2015, made on 24 December 2015 under the Anti-Money Laundering Act, 2013, and they do carry the implementing detail the claim describes: Part V, regulations 13 to 27, sets out customer due diligence and verification for natural persons, foreign nationals, entities, partnerships and trustees; regulation 42 requires an accountable person to keep transaction and due-diligence records for a minimum of five years from completion of the relevant business or transaction; and regulation 39 governs suspicious transaction reporting to the Financial Intelligence Authority, with regulation 39(3) additionally requiring reports of cash transactions above one thousand currency points.

80%

Uganda has no Financial Intelligence Authority Act, of 2013 or of any year; the Uganda Legal Information Institute's consolidated index of legislation carries no such title. The Financial Intelligence Authority is established by section 18 of the Anti-Money Laundering Act, 2013 (Act 12 of 2013), Chapter 118, which reads 'There is established a Financial Intelligence Authority', and the Authority's functions of receiving, analysing and disseminating financial intelligence flow from that Act rather than from a separate statute.

82%

The Bank of Uganda Act is Chapter 54 under Uganda's current revision, Chapter 51 having been its number only in the Revised Edition of 2000; the Act originates as Statute 5 of 1993, commenced 14 May 1993, and its text contains no provision on virtual assets, cryptocurrency, digital currency or blockchain. The Bank of Uganda's operative virtual-asset instrument is not the Bank of Uganda Act but its circular to National Payment Systems licensees of 29 April 2022, issued under sections 13(1)(b) and (f) of the National Payment Systems Act, 2020, which states that the Bank has licensed no institution to sell or facilitate trade in cryptocurrencies and directs licensees to desist from facilitating cryptocurrency transactions.

80%

Individual Customers: Obtain and verify the customer's full name, permanent address, date of birth, national identification number (e.g., National ID, passport), and other relevant identification documents.

80%

Legal Entities (Companies, etc.): Obtain and verify the company's registered name, legal form, proof of incorporation, physical address, business registration number, tax identification number, and details of directors, beneficial owners, and authorized signatories.

80%

Beneficial Ownership: Identify and verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted.

80%

Purpose and Intended Nature of Business Relationship: Understand the purpose and intended nature of the business relationship or the transaction.

80%

Ongoing Monitoring: Continuously monitor the business relationship and transactions undertaken by the customer to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds where necessary.

80%

Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers, transactions, or business relationships. This includes:

80%

Customers from high-risk jurisdictions (identified by FATF or local authorities)

80%

Transactions involving large amounts or complex structures

80%

Transactions with no apparent economic or lawful purpose.

80%

Simplified Due Diligence (SDD): May be applied in limited circumstances where the risk of money laundering or terrorist financing is lower, as permitted by the regulations.

80%

Report Suspicious Transactions: Report any transaction (attempted or completed) where there is a reasonable suspicion that the funds involved are proceeds of crime, or are linked to money laundering, terrorist financing, or proliferation financing.

80%

Regulation 39 of Uganda's Anti-Money Laundering Regulations, 2015 (Statutory Instrument 75 of 2015) requires an accountable person to report a suspicious transaction to the Financial Intelligence Authority as soon as is practicable and in any case not later than forty-eight hours, on the prescribed form, while section 9(2) of the Anti-Money Laundering Act, 2013 sets the statutory limit as without delay and not later than two working days from the date the suspicion was formed, so the forty-eight-hour figure is the regulation's and the two-working-day figure is the Act's.

80%

No Tipping-Off: Not disclose to the customer or any third party that a suspicious transaction report has been made or that a money laundering investigation is being conducted.

80%

Customer Identification Records: All records obtained during CDD processes (identification documents, verification records, beneficial ownership information).

80%

Transaction Records: Records of all domestic and international transactions, including the amount, currency, date, type of transaction, and parties involved. For virtual assets, this would include wallet addresses, transaction hashes, and amounts.

80%

Section 7(2)(a) of Uganda's Anti-Money Laundering Act 2013 requires an accountable person to keep account files and business correspondence, including the results of any analysis undertaken and copies of documents evidencing the identities of customers and beneficial owners.

80%

Uganda's Anti-Money Laundering Act 2013 s. 7(3) requires records to be kept for a minimum period of ten years from the date on which the evidence of identity of a person was obtained, the date of any transaction or correspondence, or the date on which the account is closed or the business relationship ceases, whichever is the later.

80%

Bank of Uganda Circular on Virtual Currencies (2022): While a direct URL for a circular may be ephemeral, the BOU regularly publishes such statements. A general search for "Bank of Uganda virtual currency statement" often yields news articles or official press releases reflecting this stance. For example, a common reference point is the Bank of Uganda Governor's statements regarding financial innovation and risks.

90%

Virtual asset service providers are accountable persons under Uganda's Anti-Money Laundering Act 2013: Statutory Instrument 136 of 2020, effective 27 November 2020, amended the Second Schedule to add them, they appear as paragraph 16 of Schedule 2 in the FIA's signed January 2024 registration guidelines, and they must register with the Financial Intelligence Authority.

80%

Uganda's Anti-Terrorism Act, 2002 is Act 14 of 2002, assented on 21 May 2002 and commenced on 7 June 2002 and amended in 2015, 2016 and 2017; Part V criminalises financial assistance for terrorism, and the Anti-Terrorism Regulations 2025 made under it implement United Nations Security Council targeted financial sanctions in Uganda.

80%
80%

Uganda's Financial Intelligence Authority receives suspicious transaction reports from accountable persons under s. 9(1) of the Anti-Money Laundering Act 2013 and issues guidelines to them, including the signed Online Registration Guidelines for Accountable Persons of January 2024 that require registration with the Authority.

70%

Uganda implements United Nations Security Council targeted financial sanctions through the Anti-Terrorism Regulations 2025 made under the Anti-Terrorism Act 2002, under which the Financial Intelligence Authority circulates designations to accountable persons within four hours and freezing is required without delay, without prior notice to the designated party, and within twenty-four hours.

75%

Ugandan virtual asset service providers must screen customers and transactions against United Nations designations and freeze the funds of designated persons because SI 136 of 2020 made them accountable persons at paragraph 16 of Schedule 2 to the Anti-Money Laundering Act 2013, and the Anti-Terrorism Regulations 2025 impose the freezing and dealing prohibition on accountable persons.

80%

Extraterritorial Reach: OFAC sanctions have significant extraterritorial reach. Any VASP that uses US dollar clearing, has US customers, servers, or any operational nexus with the US, is directly subject to OFAC regulations, regardless of where they are incorporated. This effectively includes most globally connected VASPs.

75%

Ugandan virtual asset service providers must screen customers and transactions against United Nations designations and freeze the funds of designated persons because SI 136 of 2020 made them accountable persons at paragraph 16 of Schedule 2 to the Anti-Money Laundering Act 2013, and the Anti-Terrorism Regulations 2025 impose the freezing and dealing prohibition on accountable persons.

80%

Jurisdictional Reach: EU sanctions apply to all EU nationals and entities, regardless of where they operate, and to non-EU entities conducting business within the EU. Given global financial interconnectivity, VASPs with any European nexus (customers, partners, funding) must comply.

75%

Ugandan virtual asset service providers must screen customers and transactions against United Nations designations and freeze the funds of designated persons because SI 136 of 2020 made them accountable persons at paragraph 16 of Schedule 2 to the Anti-Money Laundering Act 2013, and the Anti-Terrorism Regulations 2025 impose the freezing and dealing prohibition on accountable persons.

80%

An accountable person in Uganda must report a suspicious transaction to the Financial Intelligence Authority under s. 9(1) of the Anti-Money Laundering Act 2013 regardless of the value of the transaction, without delay and not later than two working days from the date the suspicion was formed, and s. 9(6) bars disclosing to the customer or any other person that a report has been or will be made.

80%

Uganda's Anti-Money Laundering Act, 2013 (Act 12 of 2013) provides for search and seizure of tainted property (sections 61, 66 and 67), restraining orders (sections 71 to 82) and confiscation on conviction (sections 83 and 86), and its interpretation section defines property as assets of every kind whether corporeal or incorporeal, wide enough to reach virtual assets, while the Act itself creates no virtual-asset category and no virtual-asset freezing power.

6 fact(s) collected but awaiting source verification. View in explorer →

References

This article was generated by SearXNG+LLM .

Primary Sources

fia.go.ug. (n.d.). fia.go.ug. Retrieved April 22, 2026, from https://www.fia.go.ug/

Secondary Sources

bou.or.ug. (n.d.). bou.or.ug. Retrieved April 22, 2026, from https://www.bou.or.ug/

Edit History

2026-04-22 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →