AML Compliance in Egypt: A 2026 Guide for Fintechs and Regulated Businesses
Egypt isn't on the FATF grey list — but Law 80/2002, CBE, and FRA still set a detailed, actively-enforced compliance bar.
Egypt's AML/CFT framework is detailed and actively enforced, even though the country hasn't faced FATF grey-list pressure the way some regional peers have. VOVE ID helps fintechs and regulated businesses build AML compliance into onboarding and monitoring rather than treating it as an afterthought.
This guide covers Egypt's AML framework and reporting obligations. For the underlying concepts, see our AML requirements explained.
Legal Foundation
Anti-Money Laundering Law No. 80 of 2002 and its Executive Regulations are Egypt's core AML/CFT statute, enforced by the Egyptian Money Laundering and Terrorist Financing Combating Unit (EMLCU) — Egypt's financial intelligence unit. The framework applies based on regulated activity, not on whether a business calls itself a "fintech": a technology provider isn't automatically a reporting entity, and which obligations apply depends on the specific licensed service.
Who Supervises What
- Central Bank of Egypt (CBE) — banks, foreign-exchange companies, money-transfer entities, and payment-service providers and operators.
- Financial Regulatory Authority (FRA) — insurance, capital markets, mortgage finance, financial leasing, factoring, consumer finance, and MSME finance, under FRA Decision No. 161 of 2024 for non-bank financial activity.
- EMLCU — the exclusive recipient of suspicious transaction reports across sectors, and default supervisor for any covered institution without another named regulator.
- Sector-specific bodies — the Egyptian Bar Association (lawyers), the Commercial Professions Syndicate (accountants), and GAFI (trust and company service providers) for designated non-financial businesses and professions.
Core AML Requirements
Governance. Appoint an AML/CFT manager and qualified alternate with the independence and board access required by the Executive Regulations, and notify EMLCU of both. FRA-supervised entities must additionally register both roles with FRA under Decision 161/2024.
Customer due diligence. Identify and verify natural persons and representatives using reliable independent evidence; for legal persons, apply the beneficial-ownership cascade — controlling natural person first, then control by other means, and only as a last resort the senior-management fallback (with the reasoning documented).
Sanctions screening. Screen against current UN and Egyptian domestic terrorist lists daily, before onboarding, before transactions, and immediately after every list update. A confirmed UN designation requires an immediate freeze of the full asset perimeter — including jointly held and indirectly controlled assets — with no prior notice to the customer.
PEP controls. Identify PEP exposure among customers and beneficial owners, including family members and close associates; require senior-management approval, establish source of funds and wealth, and apply enhanced continuous monitoring.
Reporting. The AML/CFT manager must notify EMLCU immediately once suspicion exists, regardless of transaction value, through the current EMLCU-prescribed form and secure channel. As of a 16 April 2026 CBE circular, foreign-exchange companies specifically must implement goAML — this is a targeted requirement for that sector, not a blanket rule for every regulated entity, so confirm your own institution's current portal instruction rather than assuming goAML applies by default.
Record retention. Keep transaction, customer, representative, and beneficial-owner records for at least five years from account closure or transaction completion, longer if EMLCU or an investigating authority requires it.
Recent Developments
Egypt's payment sector has seen real regulatory movement: the CBE's Rules for Licensing and Registration of Payment Service Operators and Providers (17 June 2025) required existing payment institutions to regularize their licensing within a one-year transition ending June 2026, and banks must migrate to ISO 20022 messaging for SWIFT transfers from 21 June 2026. Egypt's Personal Data Protection Law (151/2020) transition, overseen by the Personal Data Protection Center, runs through 1 November 2026 — AML recordkeeping obligations override an erasure request where the two conflict.
FATF Status
Egypt was not named in FATF's jurisdictions-under-increased-monitoring or call-for-action statements as of 19 June 2026. That's not a low-risk designation on its own — a documented, risk-based approach is still expected regardless of list status.
Practical Steps
- Map your specific licensed activity to the right supervisor (CBE, FRA, or another named authority) before assuming a generic checklist applies.
- Build the beneficial-ownership cascade into KYB workflows rather than stopping at the first layer of shareholders.
- Confirm your institution's current EMLCU reporting channel and don't assume goAML applies unless your sector circular says so.
- Track the PDPL transition deadline (1 November 2026) alongside AML recordkeeping — the two obligations run in parallel, and AML retention takes precedence over an erasure request.
Final Thoughts
Egypt's AML framework rewards businesses that map their actual regulatory perimeter precisely rather than applying a one-size-fits-all compliance template.
VOVE ID supports identity verification, beneficial-ownership screening, and sanctions monitoring as part of one connected workflow.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. AML requirements may vary depending on jurisdiction, activity, and licensing status. For binding compliance obligations, consult the relevant regulator or a qualified professional.