AML Compliance in the Democratic Republic of Congo: 2026 Guide for Fintechs and Startups
FATF says DRC has substantially completed its grey-list action plan — here's the enforcement structure that's been built to get there.
The DRC is in the middle of a genuine digital transformation — mobile money and fintech are expanding financial access in a historically cash-heavy economy — while operating under one of the more demanding AML/CFT enforcement environments in the region. VOVE ID helps fintechs and startups build the compliance layer that this combination actually requires.
This guide covers AML obligations for regulated entities in the DRC. For the underlying compliance framework, see our AML Requirements Explained 2026.
Regulatory Framework
- Law No. 04/016 (2004), amended by Law No. 16/002 (2016), establishes the foundation for AML/CFT measures, requiring customer due diligence and suspicious transaction reporting.
- Law No. 22/068 (December 2022) substantially strengthened the framework — banning anonymous accounts, expanding the range of regulated entities (including fintechs, casinos, and real estate), and enhancing PEP checks — aligning the regime with FATF's 40 Recommendations and relevant UN Security Council resolutions. This is the current operative legal basis.
- CENAREF (Cellule Nationale de Renseignements Financiers): the FIU, overseeing suspicious transaction reports and AML investigations.
- Banque Centrale du Congo (BCC): supervises banks, microfinance institutions, and mobile money providers, enforcing risk-based KYC/AML rules through BCC Instruction No. 15.
- GABAC: the DRC is a member of Central Africa's FATF-style regional body.
- FATF grey-list status: the DRC made a high-level political commitment to FATF and GABAC in October 2022 and has been under increased monitoring since, following a 2020 mutual evaluation that identified deficiencies in AML/CFT effectiveness. At its June 2026 plenary, FATF made an initial determination that the DRC has substantially completed its action plan and now warrants an on-site assessment to verify that reforms have taken hold — a meaningful step, though the grey-list status remained formally in force as of that statement.
For customer due diligence requirements for individuals, see our KYC guide for the DRC. For business verification and beneficial ownership requirements, see our KYB guide for the DRC.
KYC, KYB, and AML Processes in the DRC
For individuals (KYC), mandatory documents include the national ID card, passport, voter card (CENI), or driver's license, verified against available identity checks. Enhanced Due Diligence (EDD) is required for PEPs and other high-risk customers.
For KYB, entities provide registration details and beneficial-ownership information from official registries — though fragmented and unevenly digitized systems make this harder than it should be in practice.
For AML specifically, customer due diligence and EDD apply to high-value or suspicious transactions, with STRs filed to CENAREF. Records — for both individuals and businesses — must be retained for 10 years after account closure or relationship termination, under Law No. 04/016 as amended.
While the BCC and international donors actively encourage eKYC to support FATF reform goals, limited API access to government registries still forces significant reliance on manual verification for now.
A National Digital ID Is Entering the Picture
The DRC's national digital identity system, DRCPass (RDC-Pass), moved from a signed public-private partnership with Trident in June 2025 to full public rollout in Kinshasa in June 2026, backed by a $1 billion national digital-development plan through 2030. It's a separate initiative from the compliance work regulated businesses run themselves, but it's likely to gradually improve the identity-verification baseline that AML programs in the country can build on.
Key Challenges for Businesses
- ID coverage gaps: a significant share of the population, especially in rural areas, still lacks formal identification.
- Cash reliance: a large share of the economy remains cash-based, which limits the transaction trail available for monitoring.
- Grey-list-driven scrutiny: reporting expectations and compliance costs remain elevated while the FATF action plan is being verified.
- Technology gaps: legacy systems and fragmented registries slow CDD/EDD in practice.
- Corruption exposure: past investigations into banking-sector governance in the country — including scrutiny from watchdog groups — underline why a defensible, well-documented compliance program matters, both for regulatory standing and reputational risk.
Opportunities and Trends
Mobile money — led by platforms like M-Pesa and Airtel Money — continues to expand access for a still-largely-unbanked population. Biometric identity verification and AI-assisted screening are both gaining adoption, and stronger compliance frameworks are helping attract foreign direct investment into fintech, mobility, and gig-economy platforms.
Where Technology Fits
Digital identity tooling reduces friction in AML/KYC/KYB work by automating document checks, sanctions and PEP screening, and audit-trail generation. VOVE ID, for instance, verifies submitted identity documents with OCR and biometric liveness checks and screens against sanctions and PEP lists — giving fintechs a reusable, audit-ready verification layer rather than a one-off onboarding check, whether onboarding is happening in Kinshasa or a smaller regional market.
For the complete, sourced requirement-by-requirement checklist, see VOVE ID's the DRC compliance checklist.
Conclusion
The DRC's AML/CFT framework has visibly matured since 2022, and FATF's June 2026 assessment suggests the country may be closer to exiting the grey list than at any point since 2022. For fintechs and startups, that doesn't lower the compliance bar — if anything, the on-site verification period ahead makes a defensible, audit-ready compliance program more important, not less.
DRC's compliance bar is rising exactly as the country tries to exit the FATF grey list. VOVE ID helps fintechs verify customers, automate KYC/KYB checks, and keep an audit-ready compliance record through that transition.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.